3 ms·
The ID could be site unique. So for example, your ID card could have [Name, Pubkey, DOB] signed by the issuer, where pubkey is a pubkey for the ID card holder
by nullc 1y ago
The ID could be site unique.
So for example, your ID card could have [Name, Pubkey, DOB] signed by the issuer, where pubkey is a pubkey for the ID card holder that supports unique signatures. The card has contains the private key and can sign with it.
Then to gain access to AdultsOnly.com you sign "AdultsOnly.com" and hash the result. This value is your site-identity.
You hand the site the site identity and a zero knowledge proof that you know a [Name, Pubkey, DOB] and valid issuer signature with DOB<=DATE and pubkey matching the signature that went into the hash.
Now they know you have an ID by that issuer with an acceptable DOB, and they know that one ID == one account (so no leaked/cracked ID being used to let everyone in). But they cannot link IDs between different sites or with names... if the private keys are not possessed by the state (e.g. generated by you when you get your ID) not even the state could help convert ID to names or link IDs between different sites.
- deleted 1y ago[deleted]
- JohnFen 1y agoYes, I fully understand how that works. I don't trust it (or, more properly, I think that it's unwise to to trust that it's being done properly).