# How to implement KYC and Proof of uniqueness with Polygon ID - Miros | PolygonID

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2023-10-07
- Duration: 30:44
- Watch: https://streameth.org/watch/yt-lBdaDTkyyoU
- YouTube: https://www.youtube.com/watch?v=lBdaDTkyyoU

## Description

Digital Identity Trust (How to implement KYC and Proof of uniqueness with Polygon ID) - Miros | PolygonID

## Transcript

thank you hello everyone I don't know how you are surviving this first teeth Belgrade but I'm suffering big time you can hear it probably in my voice so I am Serbian but I live abroad for some years and these guys they are crazy you've seen it yourself so I mean huge kudos to the organizers for doing this for the first time and I'm super happy to be an honored to be part of this so today we are a bit stealing the show right Sebastian was talking about um about the marketplace and probably we'll see uh a few same slides that I stole from him so thank you Sebastian for that um as it was announced I would like to to talk about um I mean like trust and digital identity but focus a bit on the kyc and the proof of uniqueness and I will explain why um what we are trying to do right we want to we want to explain to all of you guys that is not that complex to build stuff with our Tech I mean the feedback that we are getting from one hackathon to another from one conference to another is that people are just they get they got they get lost in the process they take like uh the full day to just set up the system and that's for hackathon that is like 48 hours that's just not cool right so I'll try to just lean on a bit to this and and explain but first let's start for for some like uh well first is a disclaimer right so this is an homage for for my Dev team they um we adore Pepe uh as uh uh give not not not none else connection with the coin on anything else so there will be a few peppers and I hope you will enjoy them as much as we do so um self-sovereign identity right the Sesame as a solution but I don't want to to grow like too much in going like very wide and explaining like things that that probably have been explained too many times already but what we are trying to solve right um to to switch from account based credentials and and Sebastian was mentioning like federalized identities login with with Google login with Facebook LinkedIn whatever you don't own that right they can shut down they can cancel your Google account and you are out of everything that you had access to but not also then you don't own that um you cannot earn from that so they are earning from stuff that is yours that they own in your name and God knows what they can do with that we all know like you know Black Market of of private data so um what we are building is technology for our users to have an ability to manage their identity and to own it and then the data lives in the issuer um in the issuer CRM because of course somebody needs to issue a credential and in the wallet of the user but it doesn't leave the wallet of the user I'll I'll go to that later on it's based on the public infrastructure private portable reusable let's go um I'm just gonna run through through these they have a lot of text I left it there for people that would be just taking on the presentation and checking it and home with like popcorns and I know that you will do this so it's based on the ZK technology circum identity all these things that that lay below and that are like a part of them of the ZK VM Tech stack and and actually circum is practically becoming like uh some sort of standard right for um for the ZK so everything that is built in the polygon ID lies on this like very solid and and and very um like big foundations I I would dare to say that um there is something which we call ZK query language which we build for the verifications right so there's like a simple language for a verifier to build a query to ask something um from from a user I'll go to that later on open source everything is open source Sebastian already said we like few months ago we shifted to MIT and Apache you can build whatever you want on top of this so and please do that um it's based on the standardized the ID VC and and on-chain verification I'll go back to that later on so Main benefits interacting directly with the smart contracts and this is something that I will try to highlight during the presentation at the end what you can do passwordless login reusable kyc proof of uniqueness um any kind of onboarding I mean if you've been here in the morning you've heard a bunch of these things from Sebastian and I mean we are just talking one on this the same things like all the time but I want to come to [Music] um the PDF doesn't the PDF loves me but the ppth doesn't love me as you can see here so we want to um we want to build trust and and to enable the users that they can prove that they are humans then they are unique within a given context um they are compliant then they can reuse this compliancy and reputated and trustworthy to build what right like the ultra big goal would be digital democracy let's go step by step um civil proof protocols and and dabs reputation passwordless login I'm just repeating but this is Builder stage right so how do I build well we have uh somebody somebody like this right um our tooling is practically covering all these three aspects of this trust triangle as it is called so you have on one side you have the issuer which is an entity that is issuing a credential to a holder that is um keeping this credential and based on that creating zero knowledge proof for the queries that come from the verifier so we have the issuer node self-hosted um by your yourselves right which is a source of trust we are offering native SDK and web SDK for the wallet wallet holder Integrations and then the verifier SDK on the side that is consuming the credentials so yeah that's so nice and it's after lunch I need to check if I mean I see like few people already sleeping but let's let's continue um what is the what's there I've been in in bit more details so for the wallets there is a flatter SDK repo we released just a few days ago and Android wrapper on top of that a native wrapper we are going to be working on the iOS and react native in like near future and on the other on the other side for the web-based wallets there is a JavaScript SDK so with this we have an idea to cover like most of of the possible like holder Integrations on the other side there is this your node of course at the end of presentation there will be a QR code for the for the GitHub but you know just put polygon ID on GitHub and you'll find our organization with all these reports and then on the verification side which I want to focus a bit um there is off chain with the library that you can Implement yourself and then the on chain which is a bit maybe more interesting for the web 3 world which is gives you an ability to interact directly with a smart contract so I will have just go through like a few steps later on how you can do this and and issue um yourself or somebody else an ERC token for example it's super simple and I don't want to to go like in in a lot of details here sorry it's like a crazy Serbian rakia right um the issuer node has the API which you can use as just the API there's also a UI on top of that facilitating but it has like completely the same the same features and um all this is in one big Docker container Plug and Play right we try to to do this there is inside there is ready there is post credit there is hashicorp Vault but the point is that what you need to use let's say as is is the additional node API all these other components you can replace with what you want you know what what you use you don't you don't need to use the hashicorp you can use another thing if it's if it's for you but the ownership is on let's say on on your side as developers as people that are implementing this and then to publish the identity state any kind of of node okay um on the verifier and there is a library which you just integrate in in your API or or however the business logic is right the I'll just highlight something here The Challenge for us and then this is where we are struggling a lot is that we are trying to build a tech for everything in identity right we are not focused on a niche and that's as you can imagine a challenge and then you know you need to you know like like a like a like a French key right you need to have like super um modal tools that can cover all the possible use cases that we are imagining but what I'm trying here to to tell you guys you need to tell us what do you need so we can adjust the tooling or build something if something is missing because um this will only work if you guys are implementing this if not it's a just that code sitting there um just one thing like very briefly it's very important to understand I mean words matter here like the proof of uniqueness proof of personhood and proof of of human there are a lot of things that are being mentioned you know and thrown out here and there and there is a blog post that we've wrote some time ago that goes in a bit in more details but it's important to understand that proof of uniqueness is not the same as a proof of personhood and we've seen lately with the famous AI you know like everyone is or hyped or scared of this but the real problem is that the AI introduces um a lot of potential vulnerabilities so um what are the threats right um a person or a a boat or the the human-like AI which we are getting closer and closer to um they may be able to to demonstrate that they are a human to pass through all these like uh um reverse Turing tests and and all this infra that has been built so far which is proving very fast to be unreliable right and and that's a that is that is a civil attack right civil attack is that when you have one entity operating as I know all you guys do you have multiple accounts right and then you use one account to operate on something you use another account to to operate on something else but it is you know this is also a challenge right so you need it all depends on on what you want to build so in some use cases is is good that you have an option to have um multiple identities right for yourself but there are other use cases where you need to be like very straightforward voting that you have like one um entity interacting with the system equals one vote not more not less and and how it works so far is right all the credentials passport IDs and all this stuff but again the same as with you know like logging with Google Facebook or whatever the problem is um once you scan your passport or an ID and you send it somewhere forget about it it has been multiplied I mean my passport um photo God knows where it lives um I don't own it I don't control it I cannot revoke it so how do we want to how do we want to to change this what's what's the way to um to address this well here enter the verifiable credentials so we are using as the the w3c standard for verifiable credentials and with using them um and the ZK proves a lot of rakia um we are managing to keep the the information really private so I'll just very briefly explain how it works I'm um I'm a holder and I go to um adapt that I'm using regularly and I want them to issue me a credential that I'm a daily user of this dap because with this I can go to my favorite newsletter and if I can prove that I'm a daily user of this app I will get like a free premium subscription right but I don't want them to know anything else I just want them to have an answer to the question am I a daily user of this app yes or no not more not less so I can go there I can get a credential issued to my wallet and then when I'm interacting with my newsletter they based on the ZK query they will create a question you know is this true right when I get this this question my device and this is again something that is very important is that we are creating zero knowledge proof on the device itself what leaves the device is the zero knowledge proof all the credentials all the data they stay at the user but as as there are a lot of use cases not only for compliance but there are others where sometimes you would be um it would be necessary or you could be like forced as a user to reveal certain part of the data as is okay you need to prove me that you are older than 18 but I want to know your full name because I need this right so we have a a feature which is called selective disclosure where when you are creating the ZK uh query from the verifier side you can say I want the proof for this this and that but this information I want raw right as is that is for the user to accept that or not do they want to share the proof for the stuff that are being asked as a proof and the information uh at row right but it's it's the the ownership let's say of that the control of that is on the user side right me as a user of the app I will say yes I want to share this or no okay so with our technology you can build solutions that provide the ability for a user to to Simply provide proof of uniqueness for as I said for voting for those for like a bunch of use cases that that that where this is needed right so what are the possible ways to handle a proof of uniqueness um from from from the let's say perspective of issuing credentials um and this is a sensitive topic right because it um it's like you need to trust the issuer and also the Israel is responsible for the what kind of proof of uniqueness does it offer to the issuers so like there's it's not the same right if I do uh um if I issue to to to to somebody here um a credentials saying hey you are unique and if you can get the uniqueness credential from the government institution right it's not the same weight so then on the verifier side when you are verifying this you would not um you will not give them the same weight so the proof of uniqueness is a responsibility um of the issue and and we have like there are a few ideas how you can how you can do this right and you can issue a credential um linked with some biometrics um with the with a hash of whatever thumb print Iris scan or something like that you can add some trusted Hardware together and then verify the credential and then you know the harder response or there is a very simple you know usually they're simple answers to complicated questions but what when we were thinking about this and we said like why would not the issuer just issue a unique identifier that would need to be disclosed and then on the verifier side I could just have a database of all these um IDs and I can just check do I have the same there yes or no but again it all depends on the level of security that you need right this is how deep you want to go so our polygon idzk approved stored on chain no can you verify them on chain yes and pepper is verifying this um so how does the the verification work the consuming of the proof I already mentioned that there is a this zika query language where you define what you want to verify or better said what will be the zero knowledge proof that you are going to receive right because you need to verify this on the other end and I will again um highlight that this is there is an off chain uh which happens inside the script that you set up as a verifier in your app or um direct interaction with a smart contract for the on-chain verification so what about the kyc well implementing from the purely technical perspective and again highlighting we are offering the tech you guys need to think about how to use this but for the kyc for example from the technical perspective is is practically not very different from from implementing the proof of uniqueness and it also again depends on the weight of the issuer right like how this issuer what's the um you know who is issuing this and and how trusted is this source so we already have a few Partners issuing kyc credentials we have others uh that are able to issue the kyc credential based on the already adopted like widely adopted um identity verification providers such as on Fido so if you you know if you were opening a bank account of a Neo Bank you know how this works but what is what is good here that for example in this example you will go through a regular kyc process right and the issuer we get this data but then based on this data the usual will give you a credential which you hold as a user and then when you need to prove to your bank or whoever this is that you are trying to interact you will only share the zero knowledge proof so they will not see your data and they will not own your data and theoretically but this all depends on the ecosystem is that this credential that you have that you passed qac once you can reuse it like multiple times you have the credential right so you can interact with one verifier or another or third or a fifth and create the zero knowledge proof based on the same data and this is like a huge like cost benefit for the whole ecosystem so um what are the credentials that are available today then you can use um the few of them you can just visit these links and go there with your polygon ID app and see if you are satisfying the requirements to get these credentials and and just you know check it out see how it works do I need to say more um bear with me just few minutes so um an example of the eardrop okay in in few steps I I wanted to do a video but it just it didn't work so um first one is well you you need to you need to issue a credential right so we have a demo issuer you can go there um select there are like multiple example claims that we are offering there is a kyc age credential then with your example app that we have which is called polygon ID and you have it in both Android and iOS app stores you scan the QR code except a credential and then okay I got a credential that is uh um holds the data that I have I'm of certain age right then I go to demo verifier and also there is like a list of examples of the queries that you can ask so there is one called sigon chain age and a with this you are asking does this holder can this holder prove me on chain that um they the birth date is less than given here okay you can of course change it and just play with this you get a verification code from that and then for the user would be I just go scan the QR code and what happens is there's a zero knowledge proof created on your phone it asks you to sign a transaction in the in the chain you need to have some some testing on on this is on Mumbai right so you need to have some testing mapping if you need it you can talk to me but if you need more there are faucets for this and what happens there's a um there's a smart contract which upon receiving the zero knowledge proof and verifying that will um do an airdrop for you so it's like a dummy erc20 token then you receive in your in your wallet so this way you have proven that you can receive the share drop without revealing your actual birth date okay so it's just am I able to satisfy this criteria yes or no but the beauty of this is this all happens instantly and you can like automize stuff directly so users could be practically just by interacting with the smart contracts receiving like um I mean it's like again I'm going to go back I don't need to imagine like the use cases for this you guys could need to imagine use cases for this so I will be here um Monday to Wednesday on the hackathon and I would like to see as much as possible people playing with this uh find me there reach out and and and I can show you this like demo it literally takes like two minutes to go through all this and then um in the in the code that we have on the GitHub you have all the examples of the smart contracts and stuff so I really invite you to just go this play with that and try to figure a use case um well again all this cannot work if there's not an ecosystem right if if we are not if there are no credentials offered there that users can retrieve and if there are no verifiers they are going to be consuming these the the proofs of these credentials then then nothing will happen right um as uh as mentioned before we have a lot of Partners we are trying to just increase this number on a on a daily basis you probably you know if you are following us on Twitter um sometimes we get annoying you know just sharing all the time the information about new partners but we are very keen to build this ecosystem because we strongly believe that this is the only way that that all this can can work and we can get some some real adoption but once more for the last time is for you guys to build this we are building the tech polygon is not issuing any credentials on its own polygon is not verifying any credentials on its own we are offering the technology for you guys to develop self-sovereign identity Solutions all the code is in the GitHub as I said before SDK issuer node is a Docker container um mobile app for flatter Android JavaScript SDK all this is compatible with the ID and and and and verifiable credentials and just to mention because I haven't I haven't done it in this presentation like apart from selective disclosure which is like a super nice feature that we love a lot and it's like um giving a lot of opportunities for for different use cases there's also another one which is called the ID profiles and and I'll explain this and then I would like to see somebody playing with this and and make up some um some use case for that so what we did we added for a holder um the option to create practically infinite number of dids okay so you have you have your when you create your digital identity you get your private key and you get your original did right the master the ID the first one but you are able for any interaction that you are doing to create a new one okay so you as a user can have anonymity for example with the same issue or with the same verifier you can use like different profiles and they cannot there's no way for them to realize that this is the same entity behind the same person it can be a person but it can be a a thing right operating these the IDS um and this is also an anti-tracking thing right so you're able to create like multiple uh the IDS for any interaction and and this is I mean it's very interesting feature and and I would like to see if possible on hackathon someone playing with this as I said everything is open source let's make something together [Applause] thank you questions he was ready I mean I know him I was ready he was here first sitting before everything started preparing hit me so do you have plans also to build a hardware like the orb so you can also scan our retinas and help enslave us all there are other people doing already that right no we are not into into into Hardware uh business but you know I want to highlight something and and thank you for for the question because I mean it opens a very uh sensitive topic like Biometrics immutability blockchain um we need to be very careful with the things that we do right because we are not storing proofs on chain and Hey I was talking uh yesterday with some people and then they asked me like why because this is cryptography that is safe today at 5 10 whatever n years from now who knows you know and if it's there in the blockchain it's there in the blockchain and this particularly goes for for for biometrics I would um I would feel personally like this is like a red line that I I won't cross like putting my my Biometrics on chain but I mean there is you know you can change your fingerprint you can even have you know like a plastic surgery you can do like uh you can replace your iris even but imagine if tomorrow somebody has an idea to put the the DNA on blockchain then what end game so no we are not doing this more questions no everyone is Keen for that coffee so thank you again and thank you all for being here and um yeah let's make something together [Applause] small break
