New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Ensuring Privacy in Digital Identity to Prevent a Dystopian Crisis | Devcon SEA

DevconThu, Oct 9, 2025, 12:00 AM

This talk will explore introducing a method for privacy-preserving proof of user uniqueness in contexts like elections using DIDs, ZK, and VCs for verifying credentials without revealing unique identifiers while ensuring compatibility with multiple trust sources. This enables self-sovereign digital identity, allowing selective disclosure of verified credentials while protecting personal data, supporting privacy-preserving KYC, sybil resistance, compliant access to financial services, and more. Speaker(s): Jordi Baylina, Oleksandr Brezhniev Skill level: Intermediate Track: Cypherpunk & Privacy Keywords: Identity, Zero-Knowledge, Security, zk, proof Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] [Music] hello everybody I'm Jord valina Sasha from priv ID um what's digital identity to make it easy digital identity is when you sign in to a page actually are using your your digital uh identity currently digital identity is uh controlled by very few corporations here Facebook Twitter and so on just a side note uh here in the web three it's not even governed by governments I mean governments here could be a good allies to uh Implement self Sovereign identity because probably the governments they don't want to uh uh give the identity to these big corporations so it's very it's fragmented I mean it's not very fragmented but I mean There is five four five six seven uh big corporations that holds most of the people's uh identity and this fragmentation and other things that gives us a really bad ux I mean I'm sure that maybe not here but in a lot of uh a lot of users has problems with passwords and managing passwords managing uh connections uh emails and all this kind of uh digital identity so when we when we go to web three and we are building daps actually we need identity too I mean we have the two exceptions I mean when you are transferring phones maybe you don't need an identity you just well you need a you have some sort of identity which is an account but you don't really need identity but if you want to do any other application I don't know voting or you want to do um I mean you want to connect to Ada or something you will need some sort uh of login I mean you need some sort of identity so we need identity in the web three and when we go to Identity with web three we may end up doing uh very much the same I mean if this is controlled by very few corporations then what is happening is that even more fragmented and the ux is even even worse okay so and not only that I mean the digit the when we go to the cites there are other risks and other important things that are happening of course we have the the the Privacy thing if we are publishing data this this L can be leakage easily and there are a lot of challenge that we need to uh solve on that so how this solution needs to be of course needs to be self Sovereign I mean needs to be the centralizes each one needs to hold the the their own identity and you are kind of a server of your identity I mean you you are the the identity uh the protocol privacy needs to be by by default and by Design I mean privacy needs to be here is where zero knowledge is important I mean the centralized identity without zero knowledge is impossible to to make here I want to do a a note and is that the zero knowledge technology has been evolve a lot if you in the last in the last years if you if you just go back three years ago um it was difficult to build identity systems because you end up using your own cryptography you end up using um I mean you had to do identity but in a specific way so that you can apply zero knowledge currently the zero knowledge technology and thank you to all these layer tools and all these Evolution that happens in the last year it's much more powerful much more faster it's perfectly possible to use normal cryptography that means that you can use current attestations I mean the when the the signatures of of the governments the signatures of the organizations that are already happening so a lot of attestations real attestations that are actually happen you can use them in zero knowledge so you can build this decentralized database of that attestation it's a single database where everybody just uh share just have access to a small bar of that and then you can single source of Truth and then you can prove things uh around that and finally of course this needs to be a open standard simple standard it will not come for big corporations it will come from The Roots it will come from the like the cpip I mean this needs to be something that should be uh simple so as an example of how to connect this uh identity to this uh uh to this U identity so to these signatur to this statis that already happen in the world uh I'm going to give the the word to to Sasha that will explain the work that we are doing in prad Sasha thank you thank you Jordan so yeah what what's Prado ID Prado ID is a self sovering identity solution but also it's a middleware it's it's in infrastructure so that you are able to build your own applications that are um that have identity that can work on different chains multiple devices and um it's based on um industry standards it's based on w3c dads and verifiable credentials so it's a um interoperable system that you're able to to use and build on top of it and also it's it's powered by zero knowledge proofs so whenever you are using it you're not sharing your actual data you're sharing only proof that you're eligible to do something like you're over 18 to purchase liquor in the store yeah without providing whole document without sharing your picture without sharing your actual date of birth your passport number and so on and key features that we have is that we are unifying um this fragmented identity we are bringing all different chains together we are making it work on different multiple devices at the same time and also we are unifying web 2 and web 3 systems so it's usable and on D apps and on your regular applications and also on like regular stores where you would go and buy things of chain offline and um very important that for many things you need to do it only once like if you go and pass KC you would do it only once then your credentials your uh data would be stored on your device under your control and you would be sharing some pieces of it uh on on request you would be sharing just proofs for example that you're over 18 as I said or maybe for for some cases you would be selectively disclosing some data maybe it would be a uh for example SE number in in in your ticket credential let's say yeah something like that and we have two other very important features and very useful one is privacy preserving proof of uniqueness and another decentralized trustless issuance where smart contract is issuing your credentials so that's why it could be um trustless in terms that you are not trusting any specific centralized authority to issue your credential you can do it on on chain in a decentralized manner but also it could be done in privacy preserving manner so what's how how it's working this proof of uniqueness that that we have it's um based on credentials it could be different kinds of credentials it could be yeah it could be biometrical data yeah but also it could be like phone number or credential that you uh have from your uh employer that your employee and then you can use it to do for example voting in a company um Anonymous survey without disclosing Who You Are and without doing your iris SC to prove that you're unique yeah uh employer already knows that your unique you it can control this data and issue you credential and then you are able to to use it to prove uniqueness uh without disclosing who you actually are and do specific action only once like voting and if it's not only limited to um by credential so you you are you can use it uh on on a specific credential for for specific use case but also we have a special way to distinguish between different sessions even inside um one application for example if you're doing multiple votings um M or multiple surveys then you can um give a different contexts um for the user and um nullifier your unique identifier for for this purpose would be different between uh each session so that you would be anonymous you you would not be it would not be possible to track um who is actually um voting between these different session s and as I said there's different use cases you can use it even for um Nationwide voting for example it could be biometrical based on biometrical document uh like um atar card and then you would prove that you're unique and you eligible to vote and count this vote only once and decentralized Trust trustless issuance is a feature that allows you to to do this in a privacy preserving manner so that even there is no centralized issuer that knows who you are so that issuer would be able to track who is it acting um and um possibly de anonymize you so now I will show you how how it works and first demo is just a simple very very simple uh application where you able to prove that you your ownership of ethereum address so you would receive a credential that you're owner of AUM address thank okay so what what you need to do is actually you you're just authenticating uh to uh the system and then you send a transaction and that's it credential is issued data was already on chain so nothing needs to be additionally proven so it's it's very simple and voila you have a credential in the same way we can do balance credential proof of ownership of nft or um any data that is available on chain and now I will show you demo of how it works with um atar cart so we have integration with uh project by PC uh Unown atar and um big thanks to to yanis from Anar who helped us and build first proof of concept and we are now iterating over it and um improving to to embedd it into our uh solution so what is happening now is that um maybe some of you had uh interacted with Anar to to get a cheaper ticket to Devcon so so you would essentially scan a c code from atar and this uh C code leads to to your data that is stored on um government website that is fetched uh to you and then zero knowledge circuit uh is running on your side and verifies that this data is correct and issues your credential so this credential it's it's uh on your device actual data is not leaving your device it's it's it's there and zero knowledge proof is uh generated on on your device not on some server or or issuer software and yeah and that's how it works so you you receive a credential uh initial generation takes a a bit more time but later you can use it uh very quickly and and easily and that's how how you can create a query to to this credential and use it for for for example for voting yeah so in this example I'm creating a request to prove that you're over 18 and that you are a unique person based on a nonat hard credential I need to f a few Fields including uh identifier of the iser and then we see wallet interface so previously I was showing you Mobile Wallet interface and uh right now just because we have a Multi-Device experience if you have um created your wallet with the same ethereum address then you can use it on mobile but also in the web so you you are generating proof based on that credential that you have received and voila uh um you proved that you are over 18 and that you're unique user based on your uh Anonymous atar credential thank you thank you very much uh for giving us yeah a tour of digital identity I'll get you to stand over here and uh we can go into the Q&A so there were quite a few questions um so we can yeah take a look at them here so with Selective disclosure how do you prevent abuses from Services asking you to share all your data even if they don't need everything so yeah like I think the example with the passport is a nice one why not just say like okay so what's your passport number and your date of birth and your first name and your last name and the code everything like this so how do you prevent this this is this is more a challenge of a UI that than a actual technical all the data is yours so at the end because you are holding the data here is you I mean you are going to give the thata only if they ask to you here is more about the the wallet and so you hold data and it's about the UI that ensures that so that interprets the query that they are doing and tells very clear to the user exactly what information they are giving here again this is not easy it's a UI it's a UI ux uh challenge here of course a lot of uh social hacking can be uh but and that's something that's relatively new because I mean we are users we are not used to whole data in general and uh but this is something that here UI me it's a lot of work here in in in in priv ID with developing the wallet we have been working really hard on on on on this front and I tell you that's not uh not easy you there is but there is there are ways that uh a lot of things that can be improved and there are ways to to do this to do these things maybe you can warn the users like uh you're going You're about to leak everything if you uh if you if you allow this uh cool so er another question if we want to apply this at organization level can we have shared verifiable credentials among multiple organization members right now we do not support um I identities for organizations but we are working on this we we have a few ideas how to implement this and that would be in future releases yes nice but what what's clear is that I mean and this is the thing I mean the identity is one and then can be many organizations that can do claims on your same identity and uh the other thing is the so this is and this is the way to go so it's like can have like many claims doing working in your identity even you as identity you can do claim claims which is something that in the in the in the Legacy world is not doesn't used to happen there is a lot of things I mean all the interactions that the humans are doing uh say serious interactions they can be converted to a claim I mean anything that you are doing you are accessing to a web page you can have a claim on that I mean it's everything can be converted to a claim and then you can prove you can use that to prove something you can put that in a database and do a query on this database and you can prove that I don't know you access 10 times this web page in the last month and you you can do these things like that yeah I have different like tokens and things I know they do this sometimes uh so how does it work if I lose access to the keys can I export them yeah basically you need to back up your keys yes but um what we are trying to solve right now is for to to be able to on board web to users we need something that is not key based like we we need a social login or this kind of um login systems to work with your identity and we are working on enabling users to control their identity with regular uh existing web to login systems yes is important to to to mention that U sing means that you are holding your keys okay maybe you want to delegate this um keeping to somebody else but the first thing is that you you should be able to choose that's the first first thing okay so that's that would say the first condition but even that here requires a lot of uh educ education this is very much like holding the keys of your ethereum wallet I mean you need to be responsible so here there is a lot of usage uh learnings in there social recovery is the the other point which is also an interesting topic uh yeah but this is a way to go is in that direction yeah so I also saw some other yeah like CK email and things like this are doing like the account recovery and all sorts of interesting privacy preserving is ways of doing maybe you don't do it for like your your millions of Bitcoin that you hold but like for other accounts I think it can be good uh we still have another minute or to so we can go through another question if you're happy to uh how does it work oh I'm sorry if so how does it compare to World ID does it also use semaphor uh it's it's different we are not using semor um but it's also based on Merkel trees um just like semaphor is a is a Merkel tree uh essentially but we are using uh it a bit differently and um yeah we we I think the the biggest uh difference is that compared to World ID we have many issues we support all evm chains natively you just need to deploy a smart contract and then you would be able to verify proofs and uh we have all different kinds of credentials not only your iris data that somehow is stored on on their side and and then you have a credential that yeah I think this is a super interesting point especially for like the cipher Punk crowd who are the type of community I think who does like to reason between these different different types of because I think it's quite important Point actually that yeah there are multiple issuers and like I mean like there are different ways to do things and like which is good for your application or another and it's yeah it's good seor is a good example of these Legacy days where you need to use a specific cryptography to do a identity the cool thing now is that you can connect to semaphor for example I mean of course you need to implement it and maybe it's not worthy but you can connect to semaphor the same way that you can connect to the uh uh to the government provider or a passport or a email from someplace or or even I mean you can connect to different sources of attestations including semaphor I mean is not an exception uh in order to have a CL in order to use this claim in order to build a proof that you want to prove something you could prove that you have uh some account in semaphore and maybe a government ID and you can put that in the same circuit and this is the the this and this is possible thank you to zero knowledge and this is this is what it's happening right now I love it very cool well that's the that's all we've got time for but yeah thank you for being the final talk in the uh Cipher Punk and privacy session today uh thank you very much again if you'd like to thank the speakers you um so uh yeah that's it for us

Automatic transcript — names and jargon may be misspelled.