New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Building zk identity on-chain (Permisionless registries)

Devcon 7 SEAThu, Nov 14, 2024, 06:00 AM · 06:45

Speaker

Discussing the creation of an on-chain registry system for storing zero-knowledge (zk) identities. This system will enable individuals to self-issue and control their data without a central authority, showcasing the ZK passport use case.

Transcript

Tanya Cushman Reviewer Reviewer Tanya Cushman I'm really into graphs in terms of identity, but what I'm not into, I'm going to talk about that. So I work on Rarimo, and we focus on this kind of ZK permissionless identities. If you're trying to use your identity on chain, it doesn't matter. Now, you tap it, you scan it, you push your fingerprint to it, you kind of rely on a service or a company that acts as a kind of an attester to your identity. This dependency is kind of problematic because like forget like this kind of risk of like collusion or like a certain company going mad trying to take over the world.

The problem that we already see is that such systems don't scale, especially under the regulatory pressure. So if somebody wants to just impose a ban on the system, they know exactly which hardware operator to go after. And we've seen it already in multiple cases across the world. To kind of solve this challenge, we had to go to the fundamentals of building the permissionless systems. And during the research, we found out that mostly these dependencies, apart from being this kind of a business, issuer business on its own, is based on the so-called kind of trilemma.

So in a fully decentralized environment, such as like blockchains, you couldn't have two properties, such as uniqueness and privacy at the same time. Because if you want to generate a nullifier, and to make it verifiable, you need to push it on-chain, you're losing the privacy. If you enable the client-side blinding of it, then the user is able to generate as many nullifiers and unique numbers as possible. And that means that you won't have a uniqueness for certain cases. So our solution to solve that was to kind of zoom out and create a shared ZK registry on chain.

And on an example of biometric passports that we already have, and the fact is that passports contain the chip and all the information and signature to verify certain attributes about ourselves. So with the passports, we can enable the client-side issuance using your phone, then forming a list of uniqueness hashes directly on-chain, but as a concept introduces kind of a shared permissionless registry of unique identifiers, the more apps you have, it's super hard to deduce for exactly what activities those identities have been used. So more passports, more identities, more stuff you put within this registry, the privacy strengthens. So even if somebody has a copy, like a government has a copy of your passport, somebody gets on hold of it, all they can understand is that you registered in this vast, decentralized, permissionless registry, but never understand you came there to get your meme coins or vote against the regimes. We actually battle-tested this permissionless registry with Russian elections, where just Russian citizens could tap their passports and vote against the regimes.

The next day after the app was released, Kremlin just like had no idea where to target and what to take down. So all they did, they filed a complaint to an Apple store that a certain app was violating the counterfeiting national IDs, which is kind of bullshit. So the advantage of such systems is that as they're nor hardware, nor the client-side software dependent, the next day the new apps would pop up and people would continue to vote. And that's basically the true power of decentralization. So even when building these identity systems, we should focus on this new way of full decentralization and empowering users.

Because that's the systems that scale. Those registries could have passports as a single instance, and they could extend to much wider things, like you can build different commitment trees, ZK reputation systems, or just put even the sanctions or some kind of banned list and make it publicly verifiable. And the cool part about it is that anyone can do it and use it. So as a next step, this idea of permissionless on-chain registries, we want to propose it as an ERC and are happy to get the community feedback, engagement from all these people working in the identities. But the existing implementation of registry that is live then used by different countries different applications we will be bringing on Ethereum as a roll-up because I believe this is the biggest alignment from a vision perspective because at a near future, everyone, just like using your phone, should run a node and secure a network, and the very same phone simultaneously should be managing your entire identity.

Thank you.

Automatic transcript — names and jargon may be misspelled.