New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Semaphore V4 by Cedoor | Devcon SEA

DevconThu, Oct 9, 2025, 12:00 AM

Semaphore is a protocol enabling individuals to prove group membership and send messages (such as votes or endorsements) anonymously. The latest version enhances efficiency and simplifies the use of libraries and contracts. This presentation will cover the new features, project vision, and the importance and challanges of zero-knowledge technologies. Speaker(s): Cedoor Skill level: Intermediate Track: Applied Cryptography Keywords: Privacy, Zero-Knowledge, User Experience, proof-of, membership Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] [Music] hi so hi folks uh I will start introducing myself and then I'll present uh some news regarding semaphor and our future plans so I'm Cedar I work as a software engineer with a PSC team and in the past years I have mainly focused on improving the developer experience of some PSC projects I'm talking um about what semop for is seop for V before so some news and then our road map so first of all semop for as as far as I know is one of the simplest client side zero protocols so the core circuits only contains 22 lines of code without documentation and like empty lines generating approv only takes less than one second on browsers and verifying approv on chain only consumes less than 300,000 units of gas which means like around 5 cents on arbitro but what is it so semop for is a zero knowledge protocol that allows users to prove their membership in a group and send messages such as votes or feedback without revealing their identity in addition it also provides an alfier mechanis to present user from reusing existing proofs so semor is basically a general purpose protocol so you can use it for any use case where you need a layer of privacy we have been working on SEMA 4 for a few years now and we have mainly focused on developer experience until V3 but with the latest version before we also focused on interoperability and efficiency and onchain costs in particular we um have made two important Chang we have a new identity schema which uses EDSA D EDSA Keir and we have optimized the data structure for groups so let's go a little bit deeper we replace the whole identity schema um with an eddsa keeper EDSA is one of the most efficient public key cryptography algorithms using zero circuits and it makes the new version of spma for much more compatible with other existing protocols which use eddsa in the old schema the public commitment which is like the public identifier of the semor identity was a posidon hash of a secret in the new schema the public commit commitment is the posidon hash of the EDSA publicy and in addition um it also allows user to sign messages and verify signatures inside and outside ziky proofs or Secrets which has been and will be hopefully pretty useful for some applications like Zupas which uses SEMA 4 before so then we optimize the old data structure the incremental Miracle tree and we created a new data structure which is based on the old one the lean incremental mirle tree um so just small improvements that made it much more efficient especially when the tree doesn't have many leaves so for small groups the key improvements are true zero ashes are no longer required and the Tre grows dynamically now so zero hashes um I just want to show like the difference between these two trees uh in the old implementation if the parent node has one child it will be calculated as the hash of that child node and the zero hash in the new implementation on the right um the parent node can actually equal the no the child node itself so no need to calculate any Ash in those cases the second important change is about the dynamic dep in the old implementation the tree has a static dep each insertion needs to update a number of nodes which equals the static depth of the tree and in the new implementation the tree um the tree depth grows with the number of leaves which means each insertion would only require updating a number of nodes proportional to the current number of leaves so this is quite complex so please if you want to to know more about this data structure uh go to the um paper we published a few months ago in the zik kit repository below finally uh what we would like to to do in the next months we would like to have a new Explorer like which people can use to see on chain groups and um which admins can use to create and manage groups we would like to work on a new version of rln uh which is pretty similar to semop for they share the same code but rln works um with an additional layer to prevent spam we would like to add additional tutorials to the documentation and possibly have like specifications for SEMA for before something that people asked us a lot of times uh we will also explore and consider improving systems of course and try to keep ourselves updated on the latest um Technologies to improve the key requirements of the protocol so some links you can use to connect and ask us any questions um yeah thank you very much thank you Sor any questions oh there's one there do you want to give it a go it's on your side hello test thank you for your speech it was good I'm just curious to know more about semor business model the tech sounds amazing but I'm curious is there a way to generate a profit from this no I mean we are funded by the TM foundation and um we are not thinking about any way to make profit okay thank you I think we're also not allowed to speak about profits just from what I heard okay thank you okay hi uh I was wondering to upgrade or migrate from previous version does that mean like pre existing project need to generate new identities yes yeah you need to generate a new identity and one way is to derive the secret for of the new identity of like the semop for V before from the identity of sem for free so using the same secret and deriving the private key from the previous secret I have a question for the how the protocol Works do all the notes need to be on online at the same time where are you sorry I oh sorry hi do do all the notes who want to take part in this protocol need need to be online at the same time or is it possible to establish the group without um all the participants seeing the other participant at any point in time can you repeat your question sorry about it's about the liveness of the participants yeah so can we establish a semaphor based Comm communication for example um even if some of the notes are only online for a certain short period of time or do they all have to be online at the same time to calculate these secrets uh yes they have to be online yes on chain at the same time okay thank you any other questions oh we have one at the front row here oh hi what are the advantages of using the the lean IMT now data structure for like um the dnamic the depth of the tree uh I think one advantage Advantage is that with the old static um with the old incremental Merle 3 with static depth um we had a range of redep supported reeps from 16 to 32 and even if the group is small like with 10 members you had to use um a mirle 3 with a static depth which was like 16 so bigger storage then yes for storage and like the the generation of the proof as well needs more time because the circuits has more constraints okay see thank you yeah okay we still have some time for questions if you have any

Automatic transcript — names and jargon may be misspelled.