4 ms·
> Finally, you also may want to disclose derived information - such as just that I have a vaccination in the last x months, rather than the precise date or loca
by erhaetherth 3y ago
> Finally, you also may want to disclose derived information - such as just that I have a vaccination in the last x months, rather than the precise date or location, or just that I'm of legal age to purchase alcohol in my country, rather than my birthdate. These sorts of predicate proofs are also of interest to the group, although the algorithms and representations aren't as far along yet.
That sounds kind of crazy. I can't imagine how you'd prove derived data. Very cool though. Thanks!
- dwaite 3y agoYes, crazy moon math! I am not a cryptographer, and try to be careful when I wave my hands around. Cryptocurrencies seemed to accelerate the revision, implementation and deployment of newer cryptographic techniques. Range proofs are used in that space to obscure transaction amounts, using techniques like bulletproofs. A more primitive but easier example to understand would be a hash chain, https://en.wikipedia.org/wiki/Hash_chain https://en.wikipedia.org/wiki/Hash_chain. The issuing authority signs a hash of some shared secret seed value x times, where x is my age. If I want to prove I'm over 18, I hash the seed value x - 18 times and give it along with the signed hash. The verifier hashes it 18 times to get the signed value and thus knows I'm "at least" 18 years old. If I include a second hash of 150 minus my age, I can use that to disclose that I'm under a certain age as well. Together, I can establish an age range. Range proofs will really loosen the amount of design consideration you need to make when creating credentials with strong privacy considerations. For example, even processing metadata like expiry times for a credential leaks correlatable information, unless you take additional care. The renewal date for a corresponding physical document may be spread out evenly over the year and often stays consistent, so the expiry time of the physical document might divide people into one of 365 groups without some (potentially painful) additional considerations. A range proof instead would say 'the current is within the validity period of the document'. At the extreme this gets to verifiable computation, where I can verify that an output was created from an input document and a set of instructions. However, I can do so without seeing the input document. With this, you could externalize the entirety of processing, and rather than getting personal information back get a message saying "yes this meets your policy".