3 ms·
You can prove that you possess a digital signature from some authority over a statement that says that you are 18 or that you have $1,000,000. However, you don'
by schoen 2mo ago
You can prove that you possess a digital signature from some authority over a statement that says that you are 18 or that you have $1,000,000. However, you don't have to reveal that actual statement or signature. Typically, that would be because the statement contains your offline identity and you don't want to reveal that to the verifier.
This setting is generally "proof of attribute" or "proof of group membership" although in practice it is most often more like "proof of possession of a credential". An interesting example demonstrated a few years ago is that you could prove that you possess a passport from a certain country without revealing anything else about your identity (as the passports are digitally signed by their issuing authorities using publicly-known keys). You could then have, for example, an online forum or poll that only allows participation of people with a certain credential, yet the forum or poll operator never learns the offline identities of the members or participants.
There are some logistical issues with this depending on the purpose for which the verifier is relying on the statement, including what happens if a prover submits the same credential twice, and what happens if a prover borrows a credential from someone else. In some settings this is OK or unlikely, while in other settings it might effectively blow up the whole application!
- teravor 2mo agoin that scenario you can obtain a nullifier which serves as your identifier but prevents you from generating a new one without another valid passport. the nullifier can then be your cryptographic identity as a member of some group. without disclosing the actual member. it will likely be some time before such structures see use. imagine a physical meeting between 1000 people and they all exchange some random-seeming string (prepared ahead of time), then they join a special group chat where they know there can only be 1000 members and each one corresponds to someone who was present in the meeting. but unless they out themselves (or everyone else does) they will never know who is who. and yet the group chat can be entirely p2p and no one can cheat. and there could be spy cameras watching every exchange in the meeting and all the exchanged notes and it wouldn't matter. that way that works is by using a ZKP to prove that a previously secret but now disclosed nullifier string is a cryptographic relation to one member of the sorted list of all the exchanged strings in the meeting. and the nullifier happens to be a public key hash.