What we think about Proof of personhood based on biometrics passports

By Agora Citizen Network (@agoracitizen.network)
Published:

Countries that issue electronic passports follow the standard designed by ICAO: biometric passports have a chip inside with digitally signed information. There are a couple of open-source projects that use the chip in electronic passports via NFC scan to generate proofs using the underlying key pair. The biometrics themselves do not need to be extracted (and it would be illegal for unauthorized personnel to extract it anyway).

A context-aware & unique yet anonymous identifier can be generated based on the underlying unique private key that the passport chip contains. Note that the issuing government knows the list of public keys associated with the passports they issued, so as is, this anonymous identifier would not be issuer unlinkable. It can be used to prove “humanity” (or more accurately, “ownership of a unique passport”), nationality, age, etc.

We are personally in contact with three distinct teams developing proof of passport solutions:

On Rarimo specifically

A key breakthrough in Rarimo’s solution is Issuer Unlinkability, meaning that while the government can know who registered to Rarimo (dictionary attack by hashing all the public keys corresponding to the passports they issued), the issuing government cannot know which passport was used by which “verifier” app. This is achieved by adding a registration step to append the passports’ public keys into a giant Merkle tree that lives in a smart contract, and then binding a zk proof of Merkle tree membership with the unlinkable proof of passports used by the apps.

The trade-off for this solution is that the registration step is globally accessible on the blockchain. If the issuing government is an authoritarian regime and if there aren’t many apps that use Rarimo, or if the apps that can be accessed are all controversial from the government’s point of view, then merely having registered could lead to repercussions. The latter is unlikely as there are already many non-sensitive apps that use this protocol (notably airdrop solutions). The other projects do not have this registration step and send the proof linkable to the passport’s public key directly to the third-party app’s server (e.g., Agora server). It would then be up to the responsibility of the third-party app to safeguard who can access this data and create mechanisms to unlink content from this public key. However, data leaks are frequent, even from the largest and most secure companies. And in the case of passport data, if the originating government wants to access the data, either by force or by legal means, it will be hard for the app to protect against such attacks on user privacy. Thus, instead of merely learning that some citizens have registered, the government could learn which app the citizen used, which is worse. Note that despite Rarimo using a smart contract for registration, the registration gas fees are paid entirely by Rarimo, and this complexity is hidden from the end-users.

Rarimo also implements a way to enforce uniqueness-check when requesting for an anonymous proof of passport as a third-party social app. An API for on-chain access as well as off-chain access (based on QR code or deep-link flows) are on the way and should be available by Autumn 2024. All of this combined can provide a comprehensive privacy-preserving yet verifiable and unique authentication system.

Besides passport scanning, Rarimo aims to provide a solution that integrates various identity solutions (Verifiable Credentials, Polygon ID, World ID, mDL, SBT, etc.) into one unified identity layer. Their identity layer is “Merkelized”: it uses the same registration step as the passport verification. The main advantage of this on-chain registration process is that it can turn linkable credentials into unlinkable ones in a trustless way. This is particularly interesting, as unlinkable credentials in practice are the exceptions, not the norm.

Below is the diagram showing the passport registration step and the proof reuse from an ecosystem of third-party apps:

Passport Registration Diagram

Advantages

Limitations

Could it be useful for our requirements?

While Verifiable Credentials are the holy grail of credential infrastructure, they are not yet available in most parts of the world, and when they are, they are rarely of the issuer-unlinkable flavor. On the other hand, biometric passports are already there, and these proof of passports are more privacy-preserving and user-friendly than full-blown KYC. As a result, proof of passports unlocks the development of a privacy-preserving yet verifiable authentication system right now. In particular, Rarimo provides a trustless solution for using passport scanning in an issuer-unlinkable way.

The main limitation for passport scanning is that it ostracizes the part of the population that doesn't own a passport. This can be mitigated by integrating other proof of identity solutions as well. In the long term, besides passport scanning, Rarimo is a promising option for unifying various credential standards, including the issuer-linkable ones, in a trustless and issuer-unlinkable way.