World has made ProveKit open-source to enable private ID verification on common smartphones.
The technology behind World ID allows individuals to verify their age, nationality, or valid ID status without disclosing the personal information associated with it. World is unveiling one of the privacy technologies supporting World ID, enabling developers to create identity verifications that can be conducted directly on a user's device instead of transmitting sensitive data to external parties.
The company has launched ProveKit, an open-source toolkit designed for zero-knowledge proofs. This toolkit enables individuals to verify certain personal attributes, such as being above a specific age, possessing a valid ID, or satisfying nationality or residency criteria, without revealing any underlying personal data.
For users, the practical benefit is clear. Instead of providing a passport or ID and relying on another entity to keep it secure, individuals can potentially demonstrate just the necessary information. For instance, a service verifying if someone is over 18 could receive confirmation that the criterion is met without needing to see the person's name, date of birth, or a copy of their ID.
This rollout comes at a time when the dangers of the current system are increasingly apparent. Security researcher Brian Krebs reported that a dark web service named Nexus is offering digital scans of over 153 million driver's licenses from individuals in the U.S. and Canada. These scans appear to have been obtained from a widely used identity verification provider serving multiple Fortune 500 clients. The FBI has initiated an investigation into the breach's source. The leaked records reportedly include scans of both sides of the licenses, along with infrared and ultraviolet images, and timestamps relating to everyday activities like car rentals or visiting dispensaries, all gathered simply because a business requested to see an ID.
This is precisely the scenario that ProveKit aims to rectify. Instead of a person providing their actual license or passport—which then must be stored and becomes a target—ProveKit enables individuals to verify only the specific information a service needs, such as confirming their age or validating a document, while the actual ID remains on their device. Had the sensitive images involved in the Nexus breach not been collected and centrally stored, they would not have been at risk of theft.
ProveKit creates proofs locally on a smartphone or browser, which means that personal data does not have to be transmitted to an external server for handling. World claims that proofs can be generated within seconds on standard smartphones and under 30 seconds on lower-end devices used for testing. The system can function offline and with limited memory.
This aspect could enhance the practicality of zero-knowledge technology beyond the cryptocurrency realm. Although privacy-preserving identity systems have existed for years, the creation of complex cryptographic proofs has often required computational resources and infrastructure that complicate deployment on regular consumer devices. ProveKit is specifically designed to enable local proof generation on the devices people already use.
The technology is not merely theoretical. ProveKit is already integrated into World ID, facilitating privacy-preserving verification across World’s identity network. For instance, World ID Credentials can store data obtained from NFC-enabled IDs locally on a user's device. ProveKit can then be utilized to verify specific attributes from those credentials without exposing the entire document. According to World, this information remains inaccessible to World Foundation, Tools for Humanity, or other third parties, starkly contrasting with the centralized storage of documents implicated in the Nexus breach.
For developers, World is releasing ProveKit as a ready-to-use open-source codebase. It supports Noir, a Rust-inspired programming language developed by Aztec for creating zero-knowledge applications, enabling developers to generate various types of provable claims.
The toolkit is also crafted with long-term security in mind, targeting 128-bit post-quantum security, requiring no trusted setup, and employing the WHIR hash-based commitment scheme. Its implementation has been verified by independent audits from Least Authority.
Opening this technology could expand World’s privacy model far beyond just World ID. Websites with age restrictions, financial services, online marketplaces, travel platforms, and other applications often require users to submit far more personal information than is truly necessary for verification, contributing to the kind of data over-collection that enabled a service like Nexus to thrive.
ProveKit proposes an alternative approach: verifying the fact rather than the identity behind it.
World is already developing ProveKit v2, which aims to create smaller and faster proofs while lowering memory demands and enhancing on-chain verification efficiency. As incidents like the Nexus breach push companies to reconsider their management of identity documents, tools like ProveKit suggest a method for conducting ID verification that eliminates the risk of maintaining a large repository of scanned licenses.
Other articles
World has made ProveKit open-source to enable private ID verification on common smartphones.
World has made ProveKit available as open-source, a zero-knowledge proving toolkit that enables developers to create identity verification processes directly on users' devices. Individuals can demonstrate their age, nationality, or ownership of an ID without disclosing the personal information behind it.
