ZK/SEC Research notes from zkSecurity
All posts
Proof is in the Pudding · Part 7 of 11

Archetype x zkSecurity - Proof is in the Pudding: The Other Dark Forest (Offchain Public Keys)

Offchain public keys

For the 7th session of Proof is in the Pudding, we teamed up with Archetype to explore the fascinating realm of offchain public keys, what we call "the other dark forest."

In this session, we examined how protocols like zkLogin, ZK Email, and ZKPassport handle authentication using offchain cryptographic keys. We explored the fundamental challenge of unlinkability in privacy-preserving protocols and discussed how replacing traditional signature verifications with zero-knowledge proofs can enable more powerful and interesting ZK applications.

We covered:

  • zkLogin: How Sui's zkLogin enables wallet creation using familiar OAuth credentials like Google or Apple IDs, discussing the architecture and security model behind proving OAuth JWT signatures in zero knowledge
  • Client-side proving: The practical considerations and trade-offs of generating proofs on user devices versus server-side proving
  • Verifying signatures in ZK: The technical challenges and opportunities that arise when you verify cryptographic signatures inside zero-knowledge circuits
  • ZK Email: How zero-knowledge proofs can be used to verify email authenticity while preserving privacy, enabling use cases like anonymous proof of email domain ownership
  • ZKPassport: How biometric passports with digital signatures can be verified in zero knowledge, and the broader landscape of different authentication types and their ZK-friendly properties
  • Selective disclosure: How ZK proofs enable users to prove specific claims about their credentials without revealing the underlying data

This session provides a comprehensive look at how zero-knowledge proofs are transforming authentication and identity systems by enabling privacy-preserving verification of offchain credentials.

If you enjoy this video, check out our previous episodes:

Keep reading
Recommended

Archetype x zkSecurity (Whiteboard Session) - Proof is in the Pudding: GKR and How to Prove False Statements

In our third whiteboard session with Archetype, we dive into the fascinating world of cryptographic protocols by breaking down the intricacies of the Fiat-Shamir security model and the GKR protocol. Whether you're a cryptography enthusiast or just curious about how these complex mechanisms enhance security, this is a chance to explore the theories with us in a friendly and digestible way. Don't miss the opportunity to expand your understanding of this cutting-edge topic!

ZK/SEC · February 25, 2025

Public report of Reclaim protocol's ChaCha20 circuit

We audited Reclaim protocol's ChaCha20 circuits, diving deep into bit-level operations for a secure and efficient design. After a few iterations, we switched from a word-based to a bit-focused circuit approach, achieving a 10% enhancement in performance and size. We used Circom for implementation, with a focus on Groth16 system constraints. Our findings led Reclaim to revamp their strategy, honing in on bitwise logic for an effective flow without costly re-encodings. Curious about the technical journey and the final audit insights? We’ve got the details covered!

ZK/SEC · October 02, 2023

Renegade Audit: When ZK meets MPC

We recently had the pleasure of auditing Renegade's circuits and smart contracts, and it was a great experience. Over three weeks, our team explored their top-notch code and documentation, with the Renegade team providing awesome support throughout. Curious how it all went? Dive into our full report for the inside scoop!

ZK/SEC · July 22, 2024