New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Anon-Aadhaar Protocol using Halo2 and Noir by Hridam Basu | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

We will introduce the Anon-Aadhaar protocol which is an anonymity layer on top of a social security like Scheme (Aadhaar card) for Indian citizens using Zero-knowledge proofs. This can be used for getting many basic services in India like electricity, banking, etc. We will describe the implementation results of the protocol using Halo2 and Noir. We will also provide a comparative analysis of benchmarks using different backends like Circom, Halo2 and Noir. Speaker(s): Hridam Basu Skill level: Intermediate Track: Applied Cryptography Keywords: Anonymity, Identity, ZKP, noir Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] hello everyone my name is Ram Basu and I'm going to be talking about an another protocol using hello to anir uh so uh without further Ado let's go into the talk so here's a brief outline of the talk I'll firstly introduce the uh protocol was the Anon protocol and then I'll go into the details of the circuit and the features and how you basically implement it and then uh I'll go into the details of the implementations like Hello to and Noir and then I'll end with applications so uh the Anon Adar is basically a zero knowledge proof of identity protocol uh with uh for Indian citizens uh which uh basically preserves the privacy and doesn't reveal the sensitive information which are uh there in any Social Security card so the Adar is basically a social security card for Indians and it also provides a set of tools uh for generating and verifying proofs and uh it authenticates users and also verifies the proofs on chain so uh there are a lot of problems with the previous uh proof of identity Solutions like in vanilla uh you know kyc Solutions you need to reveal the full identity and then uh if there's a centralized database like the adhar scheme uh so uh these database are ideally uh vulnerable to um database hacks and privacy leaks and there was a lot of criticism for the Indian government uh since the time it came out and of course like if you put all this information on Chen it's uh also really bad so uh there are a lot of other ways to do identity Solutions uh one is Biometrics where you can basically uh do like you know uh fingerprint scan or ID scan uh for creating immutable records uh also there's a concept of an aggregation where you are basically combining activity data from various sources and you can basically uh provide a comprehensive trust score uh including some social graph analysis and then there's the third uh category of leveraging document signatures uh and this potentially uses some cryptographic signatures to verify and authenticate users on chain so uh the Anon Adar protocol is in uh the last category and uh in the previous slide and basically uh how we do it is basically we check both the uh sha to 56 hash and the RSA signature of Adar identity and uh you know this basically is was originally built um at PC uh with circom and uh you know there were uh three libraries basically one uh was the typescript SDK uh which is in the core uh repo and then there's the solidity library for the contracts and also there's a react Library so uh what's the problem statement so a government potentially like uh will sign an issue an identity uh to a user or a citizen in this case and the citizen basically uh uh gives this uh uh identity uh in the form of a scanner we'll see in the next slide uh to Constructor proof uh uh in this case a zero knowledge proof which will basically hide all the sensitive information and then there's a verifier which verifies the proof of identity from the uh approver so uh I think this audience is fairly knowledgeable about ZK snacks but I'll briefly go over it for completeness so ZK snacks are basically a way to prove the validity of a statement without uh revealing the witnesses or the private inputs and S is the most important uh you know acronym uh keyword in the acronym here so succinctness which means that it offers short proofs and short verification time which is basically ideal for onchain verification so uh and the two properties correctness and uh soundness uh which basically means that you know the um like it ensures proof validity and also prevents forgery so uh this is a circuit so uh in this part uh basically it's the you know sha and the uh uh RSA signature which I described in the previous slide then there's the uh extracting the fields from the sign data uh so the photob byes are uh extracted and it's used to compute the nullifier here so along with a nullifier seed which which is also uh uh you know obtained as a public input uh here and then there's the other part which is the uh conversion of time stamp from IST timestamp uh to the UTC Unix uh timestamp universal time stamp and uh there's an algorithm for it I'm not going to go into the details of it and then there's the third part which is the signal hash so this is basically preventing front Runing attacks uh so There's a constraint which we apply on the signal hash so in the work it the private inputs are only the signature and the signed data uh these are all public and then this part is the conditional disclosure of secret so if the uh these four parameters there's four parameters in the Adar data like age gender State and pin code you can choose to reveal it so if you choose to reveal it then only these will be revealed at the end right so um yeah so basically uh this is the uh Madar app where you can download the uh any Indian can download the uh um uh like AAR card or there's a scanner and it hides all the sensitive information uh and like this name gender and so on and uh you so these are the features of the uh anadar protocol like the user nullifier this basically prevents uh double spending attacks uh Prim stamp this is acting as a time waste OTP system the public key hash is basically uh ensures that the signus public key same with the public key generated by the uid which is the authority and also the signal hash which is used to prevent front running attacks so uh I'll skip over the challenges and caveat but mainly this says that there's a lot of uh you know problem with uh getting signed documents by the government and what kind of data the government chooses to sign uh so uh Halo 2 is using uh you know plish proof system and has a recursive proof support so um this is some of the libraries that I used for Halo 2 and I wrote each of the separate circuits that I shown in the circuit slide a separate and combined them into one circuit and tested it with d data so this is the uh results uh for Halo 2 so most of the stuff is very uh you know efficient in milliseconds for proving and micros seconds and milliseconds for verification except the RSA part and uh the onchain verification cost is also pretty uh you know efficient it's like 6.5 million gas for the halo2 gas cost and for Noir uh you know it's one of the foremost proving systems by Aztec and uh it it basically we can write custom circuits and prove backend using barenberg CLI uh and same algorithm as Noir like Halo 2 implementation elliptic curves and uh b254 and the versions are given here and these are the results for Noir uh5 seconds uh roughly for proving time under for all of the parts of the circuit and 0.05 seconds roughly for the verification time uh the gas cost is like uh you know under 3 million for each of them so the code is enti open source you can check it out uh and in summary you know no is much much faster than Halo 2 in terms of all three parameters uh bottleneck in Halo 2 is RSA and but circom however beats Noir and hello 2 for onchain verification cost if you use Noir Ultra hon backend it's coming so it might be more efficient so uh there are lots of applications I won't go into the details of it like you can check it out in the Anon author page so there's pread ID SEMA 4 and Anon checkin and like uh you know quadratic funding and lots of others so these are some of the references and I'll end here thank you so much for your attention and I'll happy to take questions well thank you very much for uh presenting this uh we can probably take one question from the audience so um maybe let's see what are the plans to make it work in a real world local government office any ties up with the Indian government plan yeah this is a very good question I actually I'm in the process of like you know independently doing this work uh so you know there can be lots of applications uh and other government countries of course like there are other projects like open passport and like you know ZK passport uh who are do doing similar work and I'm also uh in talks with them so there is a plan to commercialize it in short but uh like you know there's a lot of bureaucracy involved particularly with the Indian government if you talk about it and with other governments we can figure it out but it's a separate thing from this because PC is uh you know usually uh you know not for-profit organization but yeah I'll be happy happy to take this question offline and you know if somebody's interested in the audience we would like to collaborate with them sure you guys know how where to find him so maybe we can take another question so let's see uh did you do the comparison between Noir and Halu 2 for benchmarking only or they were complimentary uh so yeah I mean uh like not for uh yeah we did it for benchmarking uh with respect to circom because the original library is in circom and we implemented it because uh like we wanted to understand if Halo to or cir Noir would be better in some aspects of course like you know Halo 2 had a steep learning curve but Noir was really good I mean it's uh very easy to you know implement it and also very efficient and uh you know like depends on the details of implementation but Noir is pretty good almost like circum but circum still beats in terms of the gas cost today maybe in future who who knows no might beat it yeah fantastic I think we're running out of time so uh do you want to take another one or sure sure sure yeah uh do you prefer something yeah isn't the onchain address pous only uh yeah I mean the onchain address is definitely uh like like like I don't know the question but generally like we can hide using ZK proofs all the information uh so definitely that's there fantastic well we're running out of time so thank you Freedom again for your wonderful presentation please give him another run of Applause thank you very much thank you so much

Automatic transcript — names and jargon may be misspelled.