New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Check your user's humanity, nationality or age with privacy-preserving ID proofs! | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

This workshop shows how to use the Proof of Passport SDK to check user's identity in a few lines of code. Let users generate zk proofs of age, nationality, humanity or non-inclusion in the OFAC list by scanning the NFC chip in their passport or ID card, and without ever having to reveal any private information. Come try it now! Speaker(s): Michael Elliot, Florent, Rémi, Théo Madzou Skill level: Beginner Track: Developer Experience Keywords: Tooling, Quadratic Voting, Identity, compliance Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] okay 10 okay good right uh first thing thank you for coming to this Workshop uh my name is Remy and today we're going to talk about ZK and identities and more precisely about ZK and passport so this Workshop is going to be splitted in two parts first I am going to present you open passports and in the second time Michael and Theo are going to present you ZK passport which is another Z passport project project sweet so back one year ago we realized that the identity Market is really inefficient because it's actually not private nor secure right now if you want to prove your identity online most of the time you're are going to go through the whole carc process which is actually not needed and what's going to happen is you are going to take a picture of your ID documents and send it to the application maybe do a proof of liveliness or take a pi of you maybe move the head a bit around to be sure that it's really you and send it to the application too and then you are going to pray you are going to pray that this information is kept secure and that there will be no daic and sper there is and there is so many like a massive one just happened two weeks ago in France for example also it's not even secure from the point of view of the application because um a picture of an ID document or proof of loveliness is proof so easily using generative AI which is not good at all and what's even more stupid is that when you are do when you do a traditional kawy you give all your information which is most of the time not needed you would like to give some kind of more granular information about yourself such as prove that you are above a certain age or that you are part of a specific country without tring anything else so what can we do fortunately for us at the international civil aviation organization already built a nice tool on which we can piggy backton which is the electronic passport it's issued in 172 countries and carry on an electronic chip with inside a bunch of data about you which is signed by the iser country so this logo is the one of the E passports if you go this one on yours it's obviously an electronic on and these are pretty cool because as the data is signed inside of it that mean that we can verify that inside the ZK proof and by doing so we can already Target several issues related to Identity the first one is of course the Cil resistance how to prove that it's a human who's behind an action a vote a tweet or anything else the second one is the selective disclos I talked a bit about this one before you may want to prove something really specific about yourself without revealing anything else the last one is the compliance as you can perform uh computation inside zero knowledge circuits you can actually prove that you are not part of a list of country or that you are not part of the ofac list without revealing anything else so how can we do that for example so the ofac list is is the list of the people that us company are forbidden to deal with so mostly terrorists and you can actually parse this ofac list into a sparse Merkel tree and then you can do a proof of non-inclusion of your name and surname inside this spars marry sweets also as you going to verify signature passport uh Z proof of passport are totally unforgeable which is one point for crypto you can't actually Pro crypto that's not possible sweet so now let's take the a look at the passports so in the passport there is different data groups uh for example the dg1 is the mostly the information that is contained in the main page of your passports the dig2 is the image which is signed which is pretty cool too because we could imagine to do some kind of Z machine learning tricks to do the proof of liveliness with the phone that could be really cool so these data groups are hashed concatenate together and hashed again and the final result is signed by the isure country or more precisely it is signed by the document signing certificate which is an intermed certificate that can sign up to 100K passport and this document signing certificate is signed by the country signing certificate Authority which rotates um every 3 to 5 years upon the country and those certificates are actually issued in public Registries maintained by the international civil aviation organization so that's actually why it's so easy to verify passports because we have access to the public Keys okay I kind of lied when I said that it was that easy because um countries didn't agree on one signature algorithm and Ash function so this is all The Primitives that are currently available in the passport signatures there is even an count such as Germany that use four different ones including ecdsa with shaan which is qu kind of surprising yeah okay so if you want to see if open passports currently support your country you can refer to this map uh you can go to map. open passport. app or or scan the square code basically the countries in dark green are the one that are currently supported uh the one in green are the one issuing e passport we should support them soon and yeah if you pass the mouse on The Country um okay so that's a static screenshot but if you go on the screen and you pass the mouse on your country you will be able to see which kind of signature algorithm and as function your country is currently using sweet um so my guess is that it's time for demo time like that you will have a better idea of what we are doing all right so what's going to happen when you need to prove your identity using open passports is that you're going to scan a QR code scan this Square code if you don't have the mobile application it's going to install it and then the first step will be to scan your passports or for demos like this one you can actually generate a mock passport inside the application so if you don't have the passport on you that's that's fine you can generate one so let's do this because obviously I don't want to show my passport in front of everyone so sweet that's my new identity okay so next step when you onboarded the passport should just have like to scan the QR code once again and that's it on the phone there is written rainbow Chaser is requesting to prove your own a valid passport which means that I'm going to generate a ZK proof and not disclose any information besides the fact that I own a valid passport that's it so let's do it let's generate the ZK proof there is a web soet connection between the front end and the mobile application for the technical side we're using gr6 and sycom now we are move we are currently moving to Noir and the proofing time is around 8 second with Cy so sweet the proof has been verified all right now let's say that you're an application that want to gate gatekeep the contents uh to users that are above a certain age let's see how you can actually do that technically using open passports so you are going to use a really straightforward flow because we are in web 2 we are of chain so it's going to be pretty easy so what we're going to do is first obviously generate a proof of passport and by that I mean verify the Integrity of the data verify the signature of the passport and disclose the fact that you are older than 18 years old and along with that we are going to send the document signing certificate to the to the application like that the application will be able to verify that these document signing certificates have been signed by one of the country signing certificate Authority so technically what we going to do in the front end is import open passport SL core and instantiate open passport verifier class so what you just have to do is to declare a scope which is basically just an app ID and then the mode that you want to use use so in our case we're of chain so let's use proof of chain right you can you will also need to set the minimum age to 18 and exclude countries like Germany for absolutely no reason I'm sorry about that okay so this is the information you can um work with using open passports right now we are going to add more of them right now you can deal with ag so get keep on age you can use nationality so get keep so you can require user to be part of a specific country require them to be not part of a country list or ask them to disclose their nationality and you can also ask them to generate a proof that they are not part of Thea list right so once uh once the the first class inst instantiated what you want to do is generating a QR code and for that you just have to import open passport QR code from open passport QR codes uh that's a react that's a react component and pass the open passport verifier that you just interet before inside these components and that's it the last thing you want to do is in the UN unsuccess call back function you want to write some code to send the attestation to the back end to verify the proof in the back end too okay so we saw that before right so I told you that uh the connection between the phone and the computer is done using a web soet server by default you you can use the one of open passport but if you want to use your own we actually provide you a web socket repository on GitHub you just have like to clone it and to start it it's pretty easy for the back end it's also really easy you just have to one more time uh instantiate the same open passport verifier class with the same scope and the same circuits which is still proof of chain and to verify the attestation you just have to call open passport verifier do verify and verify the attestation and that's it like that you know if the proof is verified okay now let's say that you are a defi application so you want to use the same flow but this time on chain it's going to be a little bit different because you can't actually send the document signing certificate to the D because a document signing certificate is too big to pass in the C data right so now you want to use uh ZK proof for the Sy and Nest to so what you're going to do is to send this document signing certificate to a remote prover we actually need to do that because uh document signing certificate are most of the time RSA with 4,000 key bits lens so it's actually take too much time on client side proving but it's not disclosing any personal information so um you send this to remote approver it's going to send you back a DSC proof and you're going to send to the DAP in the C data the passport proof and the DSC proof so um if you want to run once again there is a model prover that uh we allow you to use the open passwort one but if you want to run your own you can it's pretty easy you just have like to run the to for the code and to run it that's it right so this time what you want to do in the front end it's pretty much the same actually uh the only difference is you want to change offchain for onchain and as we are in defi we want to enable Offa check because we W don't want terrorist to use our application and exclude some countries such as iron uh there is typing so if if you just type the ey letter it will propose you directly all the all the cont sweet and for the C code it's pretty much the same all right now uh it's time for niik to present you how you can verify this proof on chain using our smart contract SDK okay thank you hi um uh my name is niik um I'm work I'm most working for a contract SDK at the open passport and I will explain like how to integrate open passport contract your smart contract um so like the smart contract you can do the pretty much the same thing what you did on the offchain so like you can Lal like you can generate a proof which reveals like nationality like age and you can Ral it to the on chain so first uh the how to integrate our contract so um since uh the passwort has like so many like um like signature algorithm and we need to have like a like a different kind of verifiers for each algorithm So like um there is um so firstly like we generate like a like a verifi that grow 16 verifiers for each signature algorithm and we will like a manage in the generic verifier and like Dr verifier is kind of handle like like like what kind of proof is be like verified on like what kind of contract and also like we also have this open passport verifier open passport verifier is basically are doing like uh data formatting or something so like so this blue part is like handled by us like it's managed by us like we're going to update and we're going to add more verifiers to it and what you need to do is like just import a open pass verifier to your smart contract and how you do it is like like this so like firstly like you need to import the interface of our open pass verifier uh it's is easy you can uh uh install uh it's already published as npm package and like Define your like a uh open password verifier instance and set your address on the Constructor or whatever like not not only the Constructor but you can set the our like our open pass verifier address to contract all right and then like um after you integrate our smart contract uh how to call I'll explain that how to call the smart contract so like uh this is a graph how so like this on the right side this is like a input what what you need to input to have when you call the smart contract and the left side is like the function name uh when you call the smart contract and then I at the first I the part um so um um the currently like our open passport circum circuit is like uh we're going to uh like we verify all the dg1 like data and we going to put like some kind zero mask for like which we don't want to reveal the data so like only the bite data which want to reveal is like uh like a coming uh like it's it can be like a public value and um we also want we also need to uh like a format the like a bite data into like our readable data into like string or like into like un and then we need to do like those kind of like formatting uh like our executions and anyways like a the in the in the your proof like um like your like a hidden data is already hidden so it's like a zerob byte like to reduce the gas cost on the on chain uh I recommend you to choose like a uh what kind of data you want to leave and you uh like choose like uh like you should set the colors uh like what I what your attribute you want to R so like uh firstly you should Define the like you in 256 array named sectors and then like you just put like U what you want to leave so like uh so those open passport attribute sector is already defined it's also already defined in the library and you will choose like you want what your data you want to Ral and also like there is also a comb find attribute selector functions and you call like this uh like uh U 256 array and you generate a combine selectors so yeah um after you uh generate the combine selectors um you can actually leave the data from the passport and this is a red part so after you get a combine structor um You can call a pass uh like a open passport verifier do verifier and verify and do this and disc call attributes and you can call the attestation and combine the sectors and you will get like the passport attribute and you will get like for example if you want to get a nationality uh you can call as like um open passport attributes. nationality all right so yes thank you Nico all right now let's take another example um voting in this case you want to Target some Maximum privacy preserving like you want to have the biggest anony anonymity sets and have actually no way of linking your nullifier with what action you are going to do and with the proof you want to send so let me explain that when you generate a proof of passports you have to have a nullifier and this nullifier has to be generated deterministically on your passport data but for use cases that requires a really really strong privacy privacy you need to hide this nullifier because maybe country maybe some countries actually keep the passport data and it means that country could actually reforge that nullifier so to avoid that what are what you can actually do using open passports is to use a two-time flow so first you going to register to a commitment maret tree and in the second time you are going to reuse these commitments and this time do a proof of inclusion of your commitment in the commitment Merry and now you can disclose whatever data that you want and there is actually no way of linking uh the final proof with your initial deterministic nullifier so this flow is the same either you want to do it onchain or offchain so as I said the first step is uh send passport proof with only your commitment you don't disclose anything and your initial nullifier you want also to um generate a DSC proof and to verify that inside a commitment Merk tree so this commitment Merkel tree can be either on chain or offchain if you want to do it on chain for doing stuff such as a gated tornado cach for example that you could get on the fact that people are not on Thea list or just to be able to nullify people um you can just use the open passport smart contract uh Library SDK and there is this open passport merry reader uh repository that will allow you to listen the blockchain listen all the events and reconstruct the uh Merkel Tree on an AWS instance for example of whatever s and if you want to do this offchain this repository allow allow you allows you still to run everything of chain just with typescript code so it can verify the proof create a Mer tree store the value inside and you will be able to call it to rrive the whole tree sweet so what we did also for Defcon is the cursive exhibition and for that we create a little game which is known as steal the flag so this game uh is using open passport of course and it's pretty simple what you want to do in this game is to steal the flag that is displayed on screen right now there is no flag because the game didn't start it but if one of you if one of you scan this sare code and generate a proof of passport he would be able to replace the background with its country flag so let's let's do it okay so now the application tell me that uh open passports I'm not sharing my screen anymore but what it's saying is basically just that open passport is requiring me to disclose uh the country of my passport and that's it so let's generate this proof once again it's using web soet so yeah I think there is okay that's fine and that's it it's also playing your national an and the counter is starching for the Bahamas and by the end of Deon we will elect the winner of this small experiments sweets so thanks for your attention that's the end of this presentation here is the C code that links to the GitHub repository uh you can also try by yourself the open passport playground if you want to try the whole flow as I said before if you don't have your passport that's not a big deal because you can generate one inside the application so try it give us your feedback because it's so valuable and yeah thank you for your time and I would be happy to answer to your questions for all right all right any questions there's one here yeah oh yes please I yeah I I can also repeat it so uh why if this is like open source and we have everything available why aren't all the countries supported already um do you mean like why are not all the countries supported in open passport right now very good question so um there's a lot of different identity systems in different countries and most of the time when it's a national ID like an ID card it only has one signat algorithm but the thing is that passports are such a like wide um specification that is used by many different countries that can also have each of them their own like security preferences the specs are like kind of vague actually and so there's many different signature algorithms that many different countries use so if you go on map. openen passport.

app you'll see a detailed like map of all of the different countries which ones are supported right now and which signat algorithm each of them uses so right now we support a lot of them like most of Europe the US for instance because it's like the most common signature algorithms but there are some countries okay I won't name them but maybe like Austria or maybe Germany or maybe Iran it's like I think we can name them like um oh maybe it's display on screen oh no the screen is not sharing anymore they they require a bit more work because they have like um like they used a lot of different signator algorithms like RSA with multiple exponents so it's just a bit more work but I think in like less than a few months we can confidently say that we can basically support the whole world all right any questions hello um I had like two questions the first being like open passport as I see on the website is mostly like proof of personhood right so we have other Solutions working like World ID who are working like with a similar Solutions like proof of person W and civil resistance so the first question would be how is this like a better solution than that the second part being uh so with open passport we are generating ZK proofs of uh like passport basically the user so in order to in order to uh have this like a global acceptance we would need um to have like government involved in this or not for the ZK proofs to be like used everywhere the ones that are generated using open passport so two two very good questions the first one is um how is that different from World ID so what IDE is what uh Walt is doing I guess it was called Walt before now it's Walt so I think what the the work that W is doing is also quite important because they're trying to tackle civil resistance at the biometric level the the tradeoffs here with what we're doing is a bit different because world there's a um like if they can actually make the thing work and ship their their Hardware all over the world and like everybody um like gets like their I scanned and everything it could definitely be a very good system because then it does not rely on state so we don't even have this just assumptions of passports or ID cards but you know it's like quite hard to execute on there's a lot of different attack vectors on the hardware especially now with the new OP that can be managed by anybody even without an operator um and they also have to like ship it everywhere it's not clear if everybody can have access to a or so like we we also chat a lot with them we support a lot what they're doing they're also supporting us um but I think the trade of Si a bit different and with this kind of system just like with uh what an is working on and like we're planning on integrating Adu in this we can have like we can support a lot more people a lot faster basically because people just need their phones um and um the other question which was about uh do we need like governments to collaborate with this the really great part about this is that passports are already deployed right and the public keys are already public uh unlike International Registries so we don't really need to ask countries which is kind of great um there are some identity systems not passports but others in which the public keys are not public and so we need to actually ask the countries so for Nico worked on Mind dou cards which are the identity cards of um of Japan and like the they need to like ask for the government for an API key to to check that the the the like people's cards are actual cards they don't have like all the public Keys available but we have them so um we don't really need to you know we can just like W shop on what the governments already created of course if we could like have better communication with them we could also have them have better standards like already have um like selective disclosure directly in passports but you know it's like very long processes so we we can go faster bying this okay that sounds good uh the other question that just came in my mind is like how how will you have handle like the fake passports that people generate like we have seen incidents where people have like five passports generated that are fake basically um does open passport handle has something to handle that situations good question so what I really like about this is that today most most of kyc works on just you send a photo of your passport okay this is really bad first because of the data is stored and so if it's leaked like all of your private data gets leaked and now people can like have phone numbers or like bank accounts with your data but also as you know generative models like just got way way better and so now it's just possible to easily generate like huge databases of fake people and like kyc on websit so this is why we like cryptography like maybe AI can generate fake images but I'm not sure AI will like break the the discrete logarithm problem for like RSA in the cdsa soon so that's great um but if your question is more about actual physical IAL fake passports um I think what like my guess is that today most of the fake passports they they they look good from the outside but they don't actually have a chip with a signature because this is really hard to get you have to actually get the private keys from the countries and you have to get the right country right so it's like actually very like challenging I I would not be surprised if there were like some fake passports that had the whole signature thing and everything I just think it's probably quite rare and that's kind of good for us right um but in this case yeah if the whole passport is fake and the the government kind of failed yeah of course like you can do a proov there but I guess that's like the trust assumption testing okay uh I had a followup question to your penultimate resp response about Japan's public key so if the public key isn't public and only you have it then if I'm doing a proof of my identity that I'm a Japan citizen am I offloading that to you where you have the public and you're not sharing it with me or do you share it with your users so good question moo would be able to maybe give more background but my guess is that um you you have to call an API to check for a Japanese citizen this is for the Japanese ID card system not for the passports for the passports we can already do what we okay but for the Japanese ID system you would each time you want to verify you have to go through an API by the Japanese government so I guess there's like censorship here but um yeah is that is that right um yes if you want to like a check the validity of that card every time you need to check the like a government API and like like like you need to like this is the valid this card is valid or not but still uh the like RSA key inside the card is still available after it's the car is re So like um it can be used as like a kind of wallet like you can use the operation like wallet operation even after the col is rebooked like for Civ resistance like for the ekyc um you need to call the J government API yeah thanks so there is also question from the community the first one is can you answer that open passports is not selling user information uh like which apps at which apps a user connected to yeah good good question so um the nice thing about everything we're doing is that it's open source like the circuits are open source because it's the ZK part the contracts are open source they're going to be on shine anyway the whole app is open source and it's not even just like we open source stuff it's like we're building in public like you can just see on the report like us commiting and doing everything so so you can like um yeah basically see everything that's happening um again like when you do an app on stores there's always like I mean you never know if like the card on the GitHub is actually the one that's on the store it's kind of a general problem with apps um I think that like Apple and Google Play Store are like every time doing kind of verifications uh every time does like an update but yeah I guess there's some just assumption on the fact that the app is not completely compromised uh if you don't want to do this trust assumption you can just build the app yourself on your computer load it on your phone and then you know exactly what's running and then maybe um another another question in the case of pornography on Spain they want to implement some kind of verification based on dni so I guess national identity system um is so does this kind of solution solve this problem better our opinion is that yes because the question is if you're going to go on an adult website and have to prove that you're above 18 or above 21 do you really want to send your um like passport photo or something that's kind of sensitive um maybe for banking it's sensitive but in another way I think for adult websit it's like more sensitive and like your personal life like if there's a you know if there's a leak you don't want like people to to have this data and like link it to you or something so um I think this is where it's very important and also there's not really the compliance requirements that you have with banking in which you have to check every transaction do monitoring for adult websites is probably okay like I can prove that I'm 18 um and um that's why we're like super excited by use cases for op passport for this another question is is this open passport SDK made with ZK circuits or what technology is behind it so that's a good question um open passport SDK is mostly used to verify the proof so it's not there is no circuits inside of inside of it in a sense that it's just verifying the proof so it's actually using ZK in the sense that it's going to verify a ZK proof but the generation of the proof is only made locally on the phone on the phone are there plans to expand information to include financial data well I I would say that we we like you can already use open passport for like transactions um one thing that we kind of excited about is what we recently prototyped the ofac um non-inclusion proof so you can for instance prove that you're not on the OFA list and I think something that's exciting in finance for that is like you can have a wallet that says every time you do transaction it's going to take the the passport data that you already loaded inside your phone and it's going to do a proof that you're not on the ofac list live and what is nice about that is that the ofac list gets updated right and so you can do always a life proof every time you do do a transaction you wouldn't necessarily need to scan your password every time but you can do it once in a while to like we can force you to do it once in a while so that uh we can make sure you didn't like steal a passport or something um and then it could be for instance like enshrined in a layer one or Layer Two that like all the transactions have to have this kind of compliance system or you could have a defy protocol in which you say okay like this function when you call it there's a modifier on the function and I want you to um like only include this function in a compliant transaction so those are things we're excited about all right uh can we scroll a bit on the questions yeah perfect uh when do you think it is necessary to do onchain and offchain validations when is it better to use one instead of the other in a practical way so that's a really good question uh the first way the first answer is it's going to depend on the Privacy larer that you want um that there is a like really clean answer which would be uh if the application is a web to application just prove it of chain and if it's a d then prove it onchain but uh let's say that you want a maximum of uh privacy and you want to use the two time flow that we talked about before so first you're going to register and generate a commitment and in the second time you want to reuse this commitment to then generate a zkp so in this way maybe it's better to actually generate the first proof and Val verify it on chain because like that it could kind of centralize every uh users and have the biggest anonymity sets yeah so another another question is do you have an SDK to included in Native Native mobile applications okay so there's kind of two answers right now if you want to verify proofs in your mobile app people you can already integrate it but people have to uh like download the Open passport uh mobile app to like do their proof and then you can verify it in your um in your app one thing we like thinking a lot about is making a more General um like package or SDK that you can add to do proofs and passport scanning on your own app so for instance you want a fully integrated flow you don't want people to have to download the Open passport mobile app because it's like some friction you have to download a new app um and so you would just be able to integrate it directly in your app and that would be also really nice um another thing that we're working on is like app Clips so app clipse is basically like something that um iOS provides uh it's like you can easily open like a a small version of an app without having to go on the store and uh click on download and everything thing uh and like we tried the flow it's like very great it's coming soon too so yeah okay are there example of some corrupt countries issuing sign e passports that's a really good question I think the answer is quite all of them in a small amounts uh because most of the time for Secret Agency they will need to like create a real passport so that's that's part of the game but uh they should not cheat that much and there is probably some specific country I won't name them but it's pretty easy to guess which one of them and that's why you can actually exclude this country when you generate when you want user to disclose their nationality yeah the kind of philosophy we have is that um you like because all the passport data is there when you scan the passport as an app developer you can have the flexibility to choose what you want so if like one day one country's like certificates get compromis you can just exclude this country or like this specific certificate or like go more into the granularity or like say okay this signature algorithm is not secure anymore and like now people can forge proofs with shaan let's say um so now like we can just exclude like people uh that have like this specific um uh signature algorithm or like find a better way to include them like in another way or like if they renew their passport uh like only support the new ones so yeah all right um I think we're getting close to the end of our side um so we might just um welcome ZK passport to the stage so ZK passport is another team working on um passport verification bit of a different stock different philosophy and um they can tell you more about their approach thanks Floren uh Round of Applause for the open passport team everyone [Applause] hi I'm Michael Elliot I'm a co-founder of zik passport and this is Theo mzu and we're going to go through I guess some of you may already be familiar with what Zig passport is uh how it works but today we're going to have a workshop on how to actually plug into it and uh to be able to leverage these identity proofs for your own projects or adaps and so we've built out this SDK uh in typescript which allows you to use use this query Builder yeah go ahead and with this query Builder as you can see up here uh you can as a for as a high level overview here of how it works you just request uh you specify which credentials it is that you're interested in that you'd like the user to prove and then the rest is sort of handled for you you get this URL back which can be displayed as a QR code they'll scan that it'll bring up the uh the is passport app on whether it's iOS or Android so the Adas there you can try this out on your s I'm going to pull out this as a QR code so you can scan it from your site so if you want to join in oh sorry I went away so you can scan this uh a replit um a repple so you can try it out for Kit try it out on repel directly or maybe try to do that locally but the idea is that you can import rdk um yes please just going to bring It full screen so it's easy to see oh okay well thanks should be a bit easier to see now I'm going to keep this out for a few seconds yep I think it's good to go yeah so so the idea here is that we have this repet that we made um so you're able to Fork this repet and easily kind of get going by yourselves um and test this in the browser yeah so I'm going to show it out how it looks like so essentially also this it heads up we don't have any fixture data yet so you will need to use your own passport uh to to be able to actually generate these proofs yeah you need to have your passport to test the flow so you will generate uh a QR code with this example I was considering lending mine to people that don't have it but it may be a bit of a security issue so yes so you have to have your passort to do the entire flow but I'm going to show it to you so this is the deployed repet so you click on generate new request it uh generates the QR code with rdk you scan this with any QR Code Reader so it pulls it out on my phone and I'm going to on this side wait if the Wii is good enough did you want to tether no I think it's a more Wi-Fi issue because all the website no through my tether through my cellular oh yeah yeah go ahead let see if it shows up well you could do your own phone yep okay let me try again oh jeez do I have connection all right oh it works better um so yeah oh it disappeared why isn't oh there it is so the request was received so this is like a little message that will be use the camera you can show you what's on your phone oh no no no I don't want to okay yeah so generating the proof I generated the proof on the mobile my mobile phone and now you get back my details so first name country and that you can edit easily in the app by playing around with our uh different function disclose function uh greater than equal if you want to make a comparison with the age the birth date or the data from the passport uh so for example I'm going to go here on the repet so what we do here is like disclose nationality disclose first name but for example we could add uh another disclose of like the let's say what should I disclose um my information oh wait last name yeah last name let's go last name so for example this might be a good proof for social media where you just want to prove your first and last name but nothing else you're already sharing that information publicly anyway on maybe you know X meta Twitter and this could be like attached to the profile there or maybe you know WC farcaster could I maybe just get a show of hands of how many people have their own passports with them right cool so five or six people will be able to do this today we should have maybe given that as a heads up with the passport but at least you'll be able to see the flow and how it's achievable when you you know you get home and you're able to uh use your actual passport then so that's useful yeah so here I'm going to add another state variable so I can stall my last name I got air completion that's pretty nice um so I'm going to complete and here we go so from the result so the way the result is uh structured is they going to have the query result with the name of the field and whatever function you require require disclose or like if you're doing comparison it would be equal greater than or others and then you would get the result so in most cases that would be a bulling if you do a comparison but here you directly disclose the data and you will get you can actually log the proof like the proof would be right here although I don't think I see the logs here but anyway and I can add oh wait field for the first to last name so when I generated the request now come on all right did I do anything Jesus TR issue with the Wi-Fi off damn me tried to reload this has anyone of you been able to pull out the repet no do you want the QR code again by any chance do you want the QR code again oh yes okay um uh you can Fork it uh you can directly Fork the page and you can create a replate account or I guess you could create like an xgs cuz like we I just Ed an xgs template so you could create an xgs B plate like a simple app and just integrate our as SDK I'm going to also show our QR code towards the SDK repo so you can get the link uh great the connection is not good going to switch back to the main Wi-Fi so this is directly the QR code for the repo of the SDK so it's not on mpm yet so you can pull out directly the G uh URL and send me email address so they can actually be added oh yeah can you just plug yes also um so we're available aailable on both IOS and Android however currently the Android version is only available uh for internal testers because we kind of like released it too um too late but if you're on Android and you wanted to join uh please just uh this is my telegram handle please just um just reach out to me now and send me your email address and I can add you to the internal Google Play Store uh app so that you can get the Android version just one sec also you can just message me I'm ZK Mike okay here's the uh the QR code so yeah again if you're on Android uh and you want to get access to the Android app just message me your email address and I'll add you to the um the Play Store app okay I can give you my phone just check it Wasing my pH my sell might be better though plug this if you're having issues still let me know you can use my phone to Heather my cellular is better okay so now it works uh after fixing those issue with Wi-Fi so uh you got the QR code here which is essentially embedding uh nationality for first name and last name request so in one more field compared to before I'm going to scan it again with my app zik passport app Paul had the request on my side I'm being asked for my last name now just waiting for request received I can accept it's generating the proof this is all done over a websocket Ander an encrypt it using ecdh to set up the shed secret and ecdss p256 K1 for the encryption and you can see my last name in addition to my first name now so this is you can play around with the disclosed function you also have uh greater than equal functions for example for age like if you want to prove that you're over 18 and in this case it would essentially send out the bullion whether that is true or false and that's the only information you're going to get back from the user so I probably going to try to set up this so let's say is over 18 true actually it's more 18 or plus okay so now I'm also ask my age or age comparison going to set it back oh is it not showing up I forgot to uh wait oops all right well uh what is it oh wait let me actually look back into SD Define my types one one details regarding this is that the whole SDK is strongly typed in typescript so generally you will have like Auto completion that's pretty so you know what to uh expect and what to put in yeah okay yeah it is it's fine H where is was I was I don't theed getting Z I guess this is spe so maybe now we can move on to also just describing the subcircuit design we have and um and the reasoning behind why we've designed it this way so on on mobile uh you you're really constrained by the number of um by the amount of memory that you can actually use and so we can't have our circuit size blow out too large too big or it won't work on mobile and you want to have client side proving on mobile because you want to keep privacy you want to keep your private you know passport data local to your device it's not our t-shirts uh own your identity the meaning behind that is self- custodial identity where you own your own data and so and also on that topic um after this Workshop uh there's plenty of t-shirts we have um so just uh yeah after we finish please feel free to to go over to the corner here and you can you can grab your your your T-shirt um we got a new batch in today because we ran out so uh yeah do you want to take it away there uh yes so um regarding the circuit composition um wait who in the crowd was in the talk yesterday we gave cuz I I made a quick overview but that was not very deep I was hoping to go more into details so actually now I'm going to do it uh so yeah you had that idea of um certificate trust chain which is similar to the SSL certificates if you know how that works so essentially the passport data is signed by the state but there's two certificates in the chain there's an intermediate certificate which is called the document signing certificate the DSC which is essentially signing directly the data that DSC is directly in the chip of the passport nearly all the time there was exception and then you have the root certificate which is actually the source of trust the root of trust which is that the certific ific that sign the intermediary certificate and that is a kind of certificate you can maybe get from the government website or a registry provided by the IAL the international civil aviation organization which is the one that set out the standard and managed by the United Nations or sometime you may not find it and you have to find other ways to get it so the idea is that within our circuits within our zeron knowledge circuit so in Noir we do the verification of those two signatures which allows us to prove the that those data were signed by the state and then attest the validity and authenticity of the document uh and the way we organize our circuit is that we divide it in subcircuits we don't want to have like a single big circuits because otherwise we would have too many constraints which would blow up the memory consumption and memory consumption is very important on mobile so we need to Res to restrict it so we have four main sub circuit one that will verify the signature of the root certificate over the intermediate certificate which is on the left one that will verify the signature over the passport data which is the second one and then one which will verify the um Integrity of the data I we'll go back to that real quick and then the final one which is the disclosure so if you want to disclose information so like when you play with the SDK this is essentially the one that's going to dis disclose whatever you ask for so like disclose field directly or do a comparison of age or any kind of like stuff you can build with the SDK so we're trying to be very flexible here so this approach as two Advantage so we split the circuit in smaller circuits that can be executed uh sequentially it may take more time to generate the proof but at least the ram consumption will be uh not as much so we can actually work without making the app crash and the second one is it makes it quite modular which is very important in the context of passport uh because in this standard uh there's a lot of flexibility in the kind of signature algorithm that can be used so you need to have like a specific circuit that implements specific signature algorithm verification so we have different circuit for all those kind of signature algorithm we're going to add more we support some of them we're going to add more over the next few weeks and few months to support all the passports and the idea is that you can just swap whichever signature algorithm uh circuit you need uh so you going to one for RSA of different key size one for cdsa for different curves so you can just swap it up so it's very modular um so those are the two also means we can add new circuits as new signature algorithms get added by governments so yeah without changing too much and Noir being like no couple with honk and the backend B being um uh kind of proving scheme having a universal setup we don't need to worry about generating a trusted setup every time so managing new circuits and updating current ones is much easier than using circom with graph 16 for example also if anyone's trying this out with repet and they're having issues please just feel free to put your hand up and I can come over and and try to help debug um so more details on regarding the passport Integrity check so this is really corol to kind of Link the signature to the data that we use to generate the proof uh essentially the data of the passport that we use is mostly derived from one data group so they call those data groups it's like the dg1 data group one and this is essentially the data of the MZ the machine rable Zone the two bottom lines you can see when you open your passport those kind of character with the little angular brackets that's kind of like the F of characters so those contain issuing country and Country of nationality birth date expiry date document number gender name first name so you have most of the that you need from just this single data group and this data group among all the others so they can be up to 16 data groups most of the time there's only about five or six or seven uh only the two first one are mandatory so the data group one we just talk about the data group two which is the photo like the the one you see on like a JPEG of your of your yeah of your face 20 yeah like a full jpeg like generally a couple dozen of kilobytes um and the rest of the other data group you can have like the fingerprint the iris those two data group tend to be restricted so we can't actually read them we know they're there but we can't read them the state need to authorize you specifically to be able to this is where like countries would give access to other countries they trust yeah otherwise you know you'd be going to airports around the world and they' just be scanning everything which is not ideal you got a couple free form data group as well and some other data group including like an interesting one the 15 data group 15 that means that when you have this data group a passport can actually sign stuff not all countries support this one so it's unfortunate that would be an interesting primitive to have it's quite powerful actually it kind of it essentially makes these passports into a type of Hardware wallet allowing you to sign over yeah data now for example my passport doesn't have this data group it uses another kind of like it does have a private key inside but that private key cannot sign uh deterministic messages like challenges it's only like uh indeterministic stuff CU some countries don't like the idea of being able to sign whatever you want with your passport may give too much power to the citizens perhaps who knows so yeah so that's unfortunate so all those data groups are all the data of those data group are hatched uh using a different kind of senat algorithm per country again that's up to them but generally is going to be sha 256 sha 384 or sha 512 like different V of shatu something else is quite interesting this is all um encoded in what's called LDS on on the passport logical data structure and so that's the current version that's used around the world but there's also a V2 coming out at some point lds2 and so lds1 supports the ability to read data but lds2 supports the ability to write data as well so you can imagine governments maybe using this so so when you travel around instead of getting like a physical stamp on your passport with the ink you'd actually get like a digital stamp that you've traveled somewhere so that that could be cool and then you'd be able to generate Z knowledge proofs from that data that you know a government has attested to the fact that you traveled through their airport um and that could be a cool you know use case for that and or a privacy nightmare depending how you look at it I suppose so all those hashes are then group together and hash into a final hash which is what is actually signed there's some ping adding to this but the overall idea is there so the final Ash of all those hashes is signed and this is what we call the sign attributes so the E content is the Gathering of all those hashes and then the final hashes the attributes and so from those sign attributes this is since if you verify the signature over that message and you few what we do in our circuits is that we go from the dig1 get all the other hashes that are provided we group them we we do the whole process kind of we verify that indeed the data after being hashed from dig1 gives back the same message Mage that's being signed so that way we sure that the data we using is the data that that was signed so that's the data Integrity check down here and then finally there's the disclose subcircuit and this is where you're actually able to generate proofs to reveal selectively information mostly from dg1 because that's where all the um the interesting information lives and so you can just do a simple um so when you're actually specifying what is that you want to disclose whether it's the first name last name uh you know this country this kind of stuff gender is even possible um you create like a bite mask um and that bite mask um combined with an actual output dg1 like the reveal dg1 in the circuit it will reveal where there's a you know a one uh bit or a one bit sorry just like a0x FF and so all the characters the 93 characters at the dg1 you're revealing selectively um information in that way and then there's also other Poss circuits that are a bit more Dynamic like a like a proving that you're over a certain age so essentially you'd have as a public input you'd have the age that you're trying to prove that you're over and you'd also have the current date as a public input and then it would in the circuit it would be responsible for extracting out the date of birth that's in the digi1 and then doing like a Delta check between the current date that's the public input and your date of birth and that must be over the the input age the public age input and that's the only way you could generate a valid proof um for proof over a certain age and so we can also create new circuits in the future because of this modular design to to allow for disclosure yeah and so the way we kind of make the circuit link to each other because if you execute them separately without any glue it doesn't mean too much because you can easily cheat like with the data you put in you cheap which is why you need commitment so you have like commitment between uh each circuit so like the the first SEC on the left which verify the signature of the intermediate certificate commits to the public key of the intermediary certificate that commitment is checked into the Su circuit that it in this it is indeed you have the public key of the DC including that commitment that was generated by the other circuit and by commitment you can just imagine that as like a hash over the data that you're trying to pass to the next circuit but then also you obscure the values of the hash um did it called a pre-image by using this secret so that no one can like figure out what it was that was being passed between circuits Y and so you have a commitment that it's linking the two others from the third the two the second and the third centur over the sign attributes so that way you know that that message that was verified against the signature the message was verified against is indeed the same you checking the data Integrity checked against so you're sure that that data Integrity checks does match with the signature and then the final glue is like with the digi one so like the data group have the data from so you want to make sure that the dict distri check is done over the same dg1 that you're going to disclose so all this together makes it so that they're all linked together you cannot cheat the prover cannot cheat trying to prove wrong data cuz they're on committed subcircuit relationships yeah and then we also have this idea of the nullifier so from some of the data from the passport we derive a a private nullifier what I called it secret yes we're calling a secret nullifier here but private nullifier is also possible and we the reason maybe we could change this to private is because the government may know probably knows the data on that passport so while it's private and not something you're sharing around publicly there is an inate may know so we call it the private nullifier and so that nli that information is also um added with ass salt a private salt that's generated by the user on his mobile phone so that allows to add some Randomness to it and allows for full privacy so even the government knows the passport data they can no longer deterministically find the actual nullifier because you've obscured it with his salt and that's important and the actual final nullifier that's revealed to the service is scoped uh to the domain name of the Service Plus another Subs scope that allows the service like so essentially the service is like the developer that's asking a request of data from the passport of the user it allows it to essentially restrict a specific use case you could have like a Subs scope name voting a Subs scope name proof of personhood whatever you need to do when could be a poll a specific poll like you know poll ID 420 and then for the actual service scope itself we use the domain name um so that's the same domain name that must match on the website you're at and so in the QR code that's also encoded which is why the request comes up so quickly but you're act the client side app is actually also checking that that is indeed the correct um domain name so you can't just spoof some other service's domain name which is also quite important yeah so and essentially that pretty much wrapped it up just to clarify the the reason for the service scope and why this is important if you just use the same nullifier that was Global um it it'd be easier obviously but it means that if I were to use you know service a over here and I would have vote in some kind of poll that would be another fire that would be used to ensure I don't double vote and then if I were to go to service B over here and vote there they could easily compare or maybe it's public even and see that I actually am the same person that use these two different services so the service scope allows for privacy between different services and then again the subs scope even more privacy that's more granular should we um open up some questions yeah I guess I can open up some question did um anyone oh wait it didn't well hey I'm going to I'm going to jump the que okay um so all the all the circuit stuff is really cool and that's like the theoretical uh stuff that makes the possible but productional iing it is what I think is like happening now that hasn't been happening like before now so I'm interested about actually the toolkit for hunk and like the client the either mobile or or or desktop side proving that like is performant what are the what are the tools that you're using for that for home proving on mobile sure whatever whatever you're proving so originally like bber didn't work well mobile so we worked on some mobile tooling uh for generating the proof using Hong on mobile so like essentially the way it works is that we have uh bindings to the b b C+ plus Coast base so the C back end used by honk uh in Rust and those bindings we use them into Library that allows us to Jin the proof um for any kind of targets actually works on Mac OS as well but then we optimize it for IOS and Android and that Rose code we bind we Bridge it to Swift and cotlin on IOS and Android respectively which our own app is in react native we then link that to the JavaScript code uh so that's a lot of bridging all the way from C++ to JavaScript and the iOS library is called SWA that we built out to use this on mobile um and so a port Mano of Swift and Noir SW yeah the other one is called Noir Android or Noir Droid still deciding on the name I'm not sure which one is better maybe you have an opinion not sure but that's the general idea awesome thank you uh so we get some question here regarding the age one I I saw uh about a government using a particular type of um age verification I think this is just generally speaking this works really well for age gating you know ad websites or gambling websites because essentially you've got a government somewhere attesting to this information about the citizens of the country and then you can use Zer proofs so whether it's an e passport or some other system you can use zero knowledge proofs here with our system to just prove that you're over 18 uh and reveal nothing else so whether it's their system that they use or this um I think it's it's a wonderful solution I can't think of a better solution than that um so I believe the two bottom question ours right the two bottom ones what was it like oh no okay there's more than IM okay which one oh oh There was a question about difference between op passport and ZK passport um I'm going to cover this real quick I think this been ask in a panel as well where Michael and Flor where speaking so yeah projects are quite similar uh we cover like a similar idea so they use circom originally for their circuits they are mostly supported by PSC from the etherum foundation uh we are more uh we kind of use Noir from the get-go we did use circum at some point to get things working especially for the defon integration at the time Noir was not stable enough for us but now it is so we are fully using Noir like completely 100% normal circum normal growth 16 whatsoever normal Zed key um so the difference is uh we tend to put a lot of focus on um um I would say UI and ux and also a bit of devx because we want to have like a good SDK and everything so like right now what we you do so is a typescript SDK strongly typed but what's coming up in the next few weeks or few months it will be a react SDK so the idea of that is that you have a single component you plug it in no no API key you set what you want from the passport and that will be all will take care of all the rest the QR code generation the progress with all the UI updates and a callback with the results so we really put a lot of focus on that yeah and I think we're also discussing with them something that makes the most sense to the duplicate effort is to actually merge the two projects together it doesn't make sense because they want to switch Noir as well so you're going to have two projects working on with the same stack same proving scheme same language so it makes more sense to merge uh that's something we working on there a question about how can you ensure it's not um like forged you'd have to to actually break like RSA encryption for that to be the case so you can be you can have uh the the assurance that it's genuine unforged uh passport proof because of the cryptography involved the oh that's a great question yeah about the the last one here is there anything done to address the I borrowed my friend's passport issue so the way that we can solve this we'll be doing this quite soon actually as a feature we're going to build up is you can generate a face fingerprint from the photo the jpeg on the passport that's also been attested to by the government so you can trust it and then we'll have the users uh with their iPhone they'll they'll scan their face all local I leaves the device you scan your face it'll derive a face fingerprint from that that's going to be you have the guarantee of the te on the the iPhone so it's a trusted execution environment and we can use the Apper test service to ensure that so in other words you know it's our code running that dve the face fingerprint um and not a like a jail broker in iPhone and then you can compare those two face fingerprints in zero knowledge to prove that you are the same person that's scanning the passport that is also on the passport which I think is just magic that that's pretty cool to be able to do that to a service like provide that to a service yeah I did already yeah okay um so we got a question how will this affect kyc requirements if none of your personal information is passed onto the service provider uh yeah so this is often a requirement for AML and CTF in many countries that you should be able to give out the information in case of a suspicion of Fraud and like or money laundering or terrorism financing so yes it might be a bit of an issue for full kyc uh if you have like full self custodial um identity um but I believe that with blockchain where we have like more of a gray area we have an opportunity to nurge into a different direction so and actually that's probably where we're heading with obsidian uh the wallet with building on Aztec so Aztec is a privacy preserving layer to for ethereum um so using Noir as the smart contract language and the idea of obsidian is that so it's going to be one of the first wallet on Aztec and it's going to integrate natively ZK passport so you're going to have privacy compliance and identity at the wallet level natively so essentially we're going to be able to provide to dabs an easy way to request proof of identity and compliance proofs and then it's going to be very smooth for the user it's not going going going to realize it it's going to be self custodial now we've been kind of entertaining the idea with circle of like a compliant usdc on Aztec using obsidian so every time you would make a transaction you would have a check that would be done that would include for example a local check against ofac list and another sdn list so that can cover it moderate risk not high risk I would say so this is like a a a way toward compliance um on Shain and compliance with using self custodial method instead of having to store the data now yeah you're not going to be able to use ZK passwort for full kyc in the traditional world but if we Nerge in that direction maybe the mind of regulators can change if can see applications into this space yeah and the reason this works really well for a private stable coin like usdc on aate network is because every time you transfer that uscc around you're generating proofs again so you're actually checking against the current ofac sdn list and sanction country list um so instead of it's kind of inverted a little bit so instead of giving that to some provider that's checking themselves every day you yourself are checking just by the fact that you're generating a proof but all privately um and there be some other cool checks there as well you could have like a you limit you provide like this super generous limit of say 100,000 usdc per month that is enough for like 99.999% of people but it's going to really uh mitigate and and prevent a lot of Bad actors from using this with like hacked funds that kind of stuff um and that's going to be using the the nullifier that you saw before and that's going to allow you to transfer privately usdc and then offramp if you wanted to to like a you know to coinbase binance wherever and not have to worry about getting your account banned because it's like a privacy coin that's it um that's it any other questions that we haven't covered that maybe some wants to answered feel free to raise your hand and we can yeah where where cany the backround of the slides oh the slides um we can share them with you if you like if you just message me on telegram I can send you them through cool ZK Mike okay anything else you want to cover I think this one you say you wanted to cover something in the slides that we didn't quite get to the sub I think the subse was pretty muchy much cover everything on it and where's this we'd also love to hear about any ideas that anyone has oh we got some questions popping up great hey um so there was that question about the kyc requirements are you guys aware of any governments that are moving towards except C A ZK proof of a passport as essentially the same thing as having provided your passport yeah great question I think a lot of this is really sort of Uncharted Territory and so uh we have the opportunity to get in front of finset and speak with them I think that's really a matter of just having those conversations with with Regulators uh and and and showing them you know explaining how the tech works it it may take a lot of time and effort uh but I think once um you this new paradigm of of zero knowledge proofs and how it can really uh unlock these new features um they can see that that it's actually working um I think that'll really help to to warm the government to these kind of new approaches and there's also ways that this can this can work off chain but provide way more security than just a photograph of your passport and that whole model I think would be completely broken it already is broken but it's going to become more broken with the generative AI these kind of things um due to the fact that it's it's unforgeable uh these these proofs are onetime use as well so you know you can't replay them easily and so in the example of needing the data to to check it maybe every you know every day against the obac sdn list for banks and and some financial institutions that need that kind of security you could simply just have it like off chain so you can generate a proof that reveals your full name date of birth and Country and maybe maybe a passport number if you wanted to um and you might ask oh but that's already available you know if you send a photograph in yeah but it's a photograph of your passport if it's a proof it's unforgeable so they can take that um they can have it on their server it's never revealed publicly um and they can do their their daily checks against the fact SN sanctions lists and they have a far increased you know um ability to be sure that it's actually authentic and I think yeah it's just going to take time for governments to to start realizing that this Tech it's it's still very new tech it's is like bleeding edge um to kind of warm up to this thanks um yeah and I think if anyone has any great ideas about you know use cases or want any help please reach out to us on telegram uh ZK Mike or even just Twitter please just read out to us ZK passport and we'd love to to reply and yeah brainstorm some new ideas with you guys um if you hav anything think you're building also please tweet that out to us um and we'll like we help to promote it and share it and also uh work with you guys to to build out cool use cases um and ultimately what we're building here is is public goods open source uh you know reputable uh identity infrastructure for web 3 and so we want as many projects to build on this and be able to unlock these identity Primitives to make use of the them in really cool interesting and novel ways and so I think um that pretty much sums up our workshop for today so yeah thanks everybody for coming this has been really fun I really appreciate it and if you guys would like some T-shirts we have uh the last batch available in the corner here so please help your

Automatic transcript — names and jargon may be misspelled.