New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Keynote: Programmable Cryptography and Ethereum by gubsheep | Devcon SEA

DevconThu, Oct 9, 2025, 12:00 AM

Programmable Cryptography is a "second generation" of cryptographic primitives - primitives that allow arbitrary programs to be executed "inside of" or "on top of" cryptographic objects. Programmable cryptography provides three key affordances that complement and amplify the affordances of Ethereum--verifiability, confidentiality, and non-interactivity. We'll discuss how these technologies can reshape the Internet over the next 50 years. Speaker(s): gubsheep Skill level: Beginner Track: Applied Cryptography Keywords: Cryptography, Use cases of cryptography Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] [Music] awesome it's great to see everyone at Devcon um thank you all for coming today I'm going to be talking about programmable cryptography and ethereum as a quick introduction I'm gub sheep I'm one of the co-founders of zerox Park we're an organization that emerged out of the ethereum ecosystem about 3 years ago and since we first coined the term programmable cryptography in 2022 we've been working to accelerate the development of the field from a technical ecosystem and conceptual perspective our goal is to take programmable cryptography from research to production and to harness its powers for a new Digital Universe a lot of this talk will center around the following question how do we compute together specifically how do we as in a group of multiple people perform a computation or execute a program together now to give some context on this question I want to take us back about 30 or 40 years to the earliest days of the internet in the beginning the internet was a peer-to-peer Network for essentially transmitting bits between equal peers this means that you could do things like send a document to another IP address using protocols like FTP or SMTP at this point there was not yet any notion of you know web servers as we traditionally think about them today or the client server model rather the internet instead of being an answer to the question of how do we compute together was more of a peer-to-peer Network for communicating together but Computing is something much more than that and pretty early on people started to realize that it's useful to be able to do more than just send data back and forth it would be useful to be able to run programs on this data that's being passed around on the internet but with the existing setup of the internet in the early days there was a problem in the days of the early internet the abil the ability to compute was limited to individual machines running programs over their own data so you could only run a program over data that lives physically on your own device you know that makes sense so most apps looked like single player programs imagine games like solitire you know a single player game or something like Flappy Bird um or tools like spreadsheets or word processors or photo editing tools or a calculator that just runs locally on your own device but of course we want wanted to do more you know we wanted to compute together and to have services like marketplaces or ride sharing apps or social networks or massively multiplayer games or global payment systems or dating apps or all sorts of things and so we came up with a way of sort of simulating this idea of computing together while in reality we were actually still sticking to the single player compute model and that first solution the strategy for the last 30 years has to has been to pick one very important note like Dave over here in the middle and to promote Dave such that we all give Dave uh all of our data and now Dave can basically run something like the Facebook backend as if it was a single player application running just on Dave's machine so this has been the status quo for many decades and uh you know from this example we can sort of see why servers came to exist in the first place web servers do several things that individuals and pure peer-to-peer inter uh pure peer-to-peer Networks like the early internet can't do alone web servers allow us to coordinate on and perform computations over multiple people's state that state might be private to some particular subset it might be public um it allows us to decide which state is canonical and web servers also provide strong uptime and liveness guarantees that don't necessarily exist in a peer-to-peer Network so um this has taken us pretty far but uh you know one question question is is can we do better right there's been a lot of problems that have Arisen as a result of this being the fundamental architecture and in fact these problems are a big part of why many of us today are in this room you can feel free to choose the problems you care about there's all sorts of things um and when we return back to the question then of how do we compute together we have to ask is there a better way that we could go about this right and one of the really interesting discoveries of the last decade is that that blockchains cryptoeconomics and ethereum have given us new answers to this question for the first time in decades right so now ethereum allows us to run a single computer collectively in a way that's sort of very different than the traditional model where we promote that one single node Dave to be a very important node that we give all of our data to so ethereum has given us extraordinary things you know many of which we saw this morning because we have the ability to have decentralized consus over global State we have neutral and autonomous marketplaces Financial derivatives prediction markets we have payment systems that no single Authority controls we have permissionless identity Registries spinning up we have interoperable and composable games um but we also can't do everything that we want yet in fact nearly everything that I showed on the previous slide is still beyond the capabilities of ethereum alone and not just as a result of performance but as a result of fundamental architecture and capability limitation so enter programmable cryptography programmable cryptography is a technology that can give us many more answers to the question of how do we compute together and it can give us these answers both independently and in combination with ethereum so what is programmable cryptography for those of you who aren't familiar with the term programmable cryptography refers to a second generation of cryptographic Primitives that have started to emerge and become viable in the past two to 5 years these include Technologies like general purpose zero knowledge proofs multi-party computation fully homomorphic encryption witness encryption functional encryption obfuscation and more these Advanced Technologies are the ones in bold here and one of the key features is that they share sort of an underlying theoretical common backbone and that they generalize familiar generation one cryptographic Technologies like signatures and encryption so you can sort of see a lot of these Technologies in the shape of a detect where protocols higher up on the stack generalize things lower down on the stack so programmable cryptography moves us from a world where we have proofs for specific functions you know in the world of generation one or special purpose cryptography to being able to perform proofs of any function or any computation we can go from being able to verify specific claims to being able to verify any claim and in general we move from special purpose protocols to general purpose cryptography compilers to make a hardware analogy this is sort of like the transition from special purpose Hardware like an alarm clock or a four function calculator to something like a CPU which is generally programmable what's changed in the last couple of years to make this an area of technology to focus on now well first off there's been significant technological advancements over the past two to five years that have made programmable cryptography more approachable on the theoretical level every item on that previous texure that we just showed up here is sound and has a theoretical construction that is believed to be secure in fact candidate schemes even for the most expensive protocols like obfuscation may even be practical on the engineering level some of the first branches of programmable cryptography like general purpose zero knowledge proofs uh have become practical for developers today to start using even developers who aren't cryptography specialists in addition to the technology advancements there have also been significant conceptual advances over the last one to two years we've recognized programmable cryptography for the first time as a unified set of capabilities with a common foundation and we've started to understand how we can Leverage The Power of programmable cryptography to build powerful systems that were not possible before rather than simply seeing things like ZK snarks as a one-off way to perform a certain kind of hack to be able to introduce a specific kind of privacy feature onto a specific kind of blockchain architecture we sort of understand how to use the general programmability of these tools okay so let's return to our question of how do we compute together um I want to think about this phrase multi-party programming you know the act of multiple people coming together and trying to perform some computation together again this has been the strategy for the last 30 years but abstractly from first principles if you think about this idea of multiple people coming together to run a program you might abstractly want something that looks like this so you have some sort of network you have some sort of participants in the network that want to do some action and they you know gather all their respective data that's relevant to the computation and they produce the results of the computation and they want to be able to do so with privacy Integrity interoperability guarantees and for this to be practically feasible so let's zoom in and look at the anatomy of such a program the general pattern here is slightly more complex than this diagram that we're zooming in on but not by much essentially in one of these multiparty programs there might be three kinds of data that we would be interested in running our program on there's some sort of global public data that everybody knows and then there's data that might belong to or live on the machines of specific participants in the computation and then there might also be data that only the program knows and we'd like to be able to run some kind of program over all three types of data to produce an output now ethereum gets us part of the way there ethereum allows us to collectively run a world computer that takes in some Global public State and perform a verifiable computation together on that but like other peer-to-peer systems and blockchains historically full multi-party programming has not been possible with this model being able to do this with all of those different kinds of state so everything I've been saying so far has been a little bit abstract and I want to dig into a specific example lately there's been a lot of interest in decentralized social media in particular we've seen uh protocols and applications like farcaster blue sky noer and mastedon start to emerge and communities to get built on top of these um one thing that's really interesting about this trend to me and one pattern that I've observed is that people tend to frame the problem of decentralized social media or building a decentralized social app in terms of building a decentralized Twitter we always very specifically use Twitter my question is why do we always talk about decentralized Twitter why don't people talk about you know one of the other social medias out there like building decentralized Facebook you know there could be cultural reasons behind this maybe people interested in in decentralization tend to have congregated on Twitter um but I think that there's also a deeper technical reason behind this as well and the reason for that is that the state topology of Facebook is much more complicated than the simplified model of Twitter you know in Twitter everyone can see everything and everyone broadcasts every post to everybody else so now you sort of need to reduce this down to some sort of decentralized messaging protocol you know in essence so the state topology of Twitter might look something like this you know it's a it's a very homogeneous simple thing to read Reon about whereas the state topology of Facebook is much more complex right you might have things like friends of friends can see my timeline we might have private groups where things happen you might have personalized recommendations based off of how your history intersects with other people's history or apis that behave differently depending on the combination of multiple people's settings um this person's a third degree connection and that influences my recommendation somehow etc etc so the state topology of Facebook looks much more complicated and in the general case emulating those kinds of more complex topologies or multi-party programs is impossible to achieve empirically with only generation one cryptography and even some forms of consensus another issue that really shines a light on the fundamental limitations of of our existing tool Stacks is some applications have what we might think of as private Global state so this is State that's part of the application that is computed on and is necessary for the operation of the system but which no user of the system knows or owns so you can imagine having a bit in this system that doesn't actually physically live on anybody's computer but is a necessary input to some of the computations that are running you know in a social media you might have a list of all the user IDs that have been reported at least three times for bad behavior or something like the naughty list and one of the issues here is well if you try to emulate this in a decentralized fashion and nobody has that array stored locally but you still want to be able to perform computations on that well that seems paradoxical another pretty clear example of this is in some kinds of games um you might have strategy games where there's multiple players each player can see some part of the world or the global map but there's also stuff going on in the fog of war that nobody has access to maybe NPCs are moving around or some processes are running and so these are things that only the server knows but because they can eventually interact with with a given player State you might need to ensure that somehow this state is still being updated and operated on in a consistent way despite the fact that it doesn't actually live anywhere so in short you know why is it hard to be to build something like a decentralized Facebook well first off if you have a transparent data layer individuals can't really have their own State a lot of decentralized systems need their state to be public so it can be verified and the system itself might also have some notion of global private State and it seems almost paradoxical to imagine a system made up of a bunch of users that's performing a computation on a variable that no single person owns or can read or has so enter programmable cryptography programmable cryptography has the ability to potentially start to emulate some of these capabilities if we break down what we would need from our multi-party programming model we can write down a couple of things that we would need to have happen in order to be able to emulate these capabilities in their full generality we would need verifiable computation because you know rather than one trusted actor running the program we might have this world where programs can be run across multiple different computers or by someone who you don't even know and you don't even have to care about who's running the computation we'll need execution on private State because if that program is physically running somewhere it has to be running on state that might exist in some other part of the network that the person who's executing the code doesn't actually have access to the internal state of we want data interoperability we want the ability for you know the outputs of certain programs or certain services to be usable in other ones we want consensus so that everybody can agree on the canonical program State or the canonical state of a given multiplayer service and we want non- interactivity to be able to scale to billions of participants a lot of this mental model is spiritually very similar to uh what vital discussed in one of his recent blog posts uh with the three Egyptian God protocols looking forward to the far future of ethereum so let's take a a quick look at each of these in succession let's look at verifiable computation so we want to live in a world where we can execute programs over a network and these programs might be running somewhere untrusted they might be running in a place that I can't determine in you know in advance ahead of time um and we somehow want to still know that that program is running correctly well this is the sort of guarantee that general purpose zkps like snarks and Starks give us and we've seen phenomenal progress in this domain over the past couple of years with the ability to even run virtual machines performant inside of verifiable ZK snark protocols in terms of programming on private State well one of the Dual problems to the world where we have multiple actors who might be running the program is that if those actors are running the program they might be running it on state that lives elsewhere in the network and because of that they need to be able to execute code on top of state that they don't know or perhaps nobody knows so this is something that is at least partially solved by Technologies like fully homomorphic encryption and we've started to see the first tool Stacks like Phantom Zone or open if become possible for developers to use in fact we have a demonstration of a game running inside of this sort of hallucinated server downstairs if you check out the Frog Community Hub there's a game called frog Zone where there's a back end that holds about 500 bits of game State that's running inside of fully homomorphic encryption that you can play we want data interoperability we want for the outputs from one service or computation on this network to be usable elsewhere this is one of the big problems with the internet today and for this we've seen various groups projects and companies start to approach the idea of proof carrying data the idea that I can take data in that is cryptographically verified I can perform operations or run programs on it and I can get an output that is just as verifiable and inherits the interpretability and the verifiability of the inputs to that transformation process projects like ZK email TLS notary zass and many other ZK ID projects are starting to build up towards a future where data is default interoperable self-verifying and self-describing we want consensus and data availability this is something that actually no amount of cryptography can give us but we want to make sure that even if a program is being run somewhere even if it's being run correctly and with confidentiality and it's producing some sort of outputs we want everybody for be we want for everybody to be able to retrieve those outputs it's not enough to just know that something was done correctly sometimes there's actual pieces of the state that you need to be able to retrieve and this is what blockchains give us this is what the big innovation in cryptoeconomics and consensus over the past decade decade decade and a half have been and finally we want to be able to do all of these things in a scalable way many of our strategies today for carrying out these functions rely on these very interactive protocols where everyone must be online at once so imagine a world where we're all emulating the execution of a social media backend whether that's Twitter or Facebook or whatever social media you want we don't want to have to require that all of a billion people or billions of people are online all the time to do decryptions or various kinds of cryptographic interactions what we'd like is for only the inv D parties in any given interaction to need to be online to participate and this is what the most advanced branches of the programmable cryptography TCH Tre like obfuscation or functional encryption or witness encryption give us as of about three or four years ago obfuscation and functional encryption are known to actually be sound um so while this is the furthest along in the tech tree that we're working on advancing we know that it is possible so to summarize there's a couple of questions that we can look back on and ask one is what can cryptography do that ethereum alone cannot do in short as we've seen cryptography allows us to build Rich applications with complex interoperable state it allows us to answer questions like how can domains that use different data schemas proof systems or semantics talk to each other how can applications hold state with complex predicates on who can see it who can read it who can write to it who can operate on it and how can an application have St that nobody knows conversely we can also ask what can ethereum do that no amount of cryptography can do and while we're just starting to understand the limits and the boundaries of these Technologies in short we might say that blockchains give us things like consensus data availability and ordering a ZK proof allows you to prove any fact that you want about a hash or a hash pre-image or a public key but how do we decide which hashes and public keys are meaningful how do we come to consensus on which of these hashes actually reflect something that we care about in the world how can you prove that something didn't happen you can't easily do this with cryptography except in very special purpose cases or how can you determine which of two cryptographically sound operations happen first or that data has been made available or that participants in a network are live or incentivized to be online again these are things that pure mathematics and pure cryptography alone cannot do but blockchains in Synergy with these things can bring as well those are some great questions gab sheep and I'm sorry to cut you off a little bit but because of time is it all right if we can move on to the Q&A section so we can listen to a bit of the questions from the audience for sure yeah so to sum it all up um the one challenge that I'll give to everybody is to think about the question how do we compute together how can we use these Technologies to pull forward a future where multi-party programming actually reflects the natural first principles model so thank you everybody and we'll take some questions now hello hello all right let's hear for gub sheep straight away our first question on the board what is the coolest thing in ZK research right now for fast client side proving yeah so I'm extremely interested in some of the projects that have started to really take client side proving seriously I think that because of the economic incentives of things like rollups and bridges we've seen a lot of advances on making Z proof generation very efficient on big and beefy servers you know things like sequencers or or block producers or things like that um because of the increased focus on ZK identity by the space in the last couple of years we're starting to see the first projects from groups like Iden 3 or PSE experimenting with using new proof systems in order to build fast client side mobile proving libraries that actually run natively so I think that there's a lot of lwh hanging fruit here um and I think that uh hopefully one of these teams is able to uh start pulling out something where someday we might be able to even run a zkv on the phone efficiently I think that would be huge for the space and um lots of research needed definitely lots of areas for experimenting and trying new things let's go to the second question which got the three highest votes will this enable decentralized llm into inference while preserving the privacy of user prompts if so how far away is it if not what tech do we still need to enable this yeah this is a really interesting question uh I think a lot of folks are curious about what the intersection between Technologies like ZK or verif verifiability and AI is going to look like in the near future um in general I am I have two minds about this I think that trying to plug in our bleeding edge llms or bleeding edge machine learning models into programmable cryptography is likely going to be something that takes uh a lot more time than you know a lot of the other use cases that we might have around things like Identity or proof in data largely because AI is something that will eat up as much compute as you're willing to give it and if programmable cryptography causes you to incur like a 1,000x overhead then there's many use cases that it's just really hard to to justify but I am very interested in this idea that perhaps in the future where a lot of the internet is made up of different autonomous agents or machines or Bots they might be speaking in cryptography to each other so how Bots might make sense of the semantic contents of what each other is saying is they might be speaking in proof caring data sending bits of cryptographically verifiable things you know we could imagine these things combating stuff like misinformation or the lack of interoperability between different Services um personally I'm very interested in that interesting let's go on we got time for maybe one or two more questions why haven't traditional companies invested in this area of research why do you think G sheep yeah I think that one thing which I think we'll probably also be discussing in the panel following this is that um the reality is that the economic incentive over the last 5 years has driven research and development largely towards use cases that involve things like server side proving and with a focus on verifiability technology rather than confidentiality technology in particular because blockchains have created such a phenomenal Financial incentive to actually build out these businesses a lot of the oxygen in the room gets sucked in that direction so what we've been trying to do at zerx Park and and a a couple of our other partners is start to direct attention towards these other further out potentially more speculative use cases use cases that don't have as strong of an immediate financial incentivization Loop um but I think we're going to see this pattern play out more and more as these use cases start to become a reality excellent that's all the time we have for Q&A let's give our speaker another

Automatic transcript — names and jargon may be misspelled.