开放“零知识证明”技术,以提升年龄验证中的隐私保护。
Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

原始链接: https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/

为支持保护隐私的数字身份解决方案,我们已将零知识证明(ZKP)库开源。零知识证明是一种强大的密码学工具,允许用户在无需共享额外个人数据的情况下,验证特定信息(例如证明其年龄已满 18 岁)。 通过将该代码库公开,我们旨在支持: * **用户:** 提供更安全、更具私密性的数字体验。 * **企业:** 简化以隐私为核心的验证工具的集成。 * **开发者与研究人员:** 提供一套高效、高性能的工具包,用于构建和创新以隐私为中心的应用程序。 此次发布符合欧盟即将实施的《eIDAS 条例》,该条例鼓励在欧盟数字身份钱包(EUDI Wallet)中集成隐私保护技术。通过分享这些工具,我们旨在加速欧盟及全球范围内安全且以隐私为先的基础设施建设。 我们诚邀社区探索我们的代码库并开始构建:https://github.com/google/longfellow-zk

Google 近期开源了零知识证明(ZKP)库以支持欧盟的年龄验证要求,这在 Hacker News 上引发了激烈辩论。 支持者认为,零知识证明为侵入式身份验证提供了一种保护隐私的替代方案,允许用户在无需共享多余个人数据的情况下证明自己符合年龄要求。他们认为,这是应对监管必然性时所采取的“最小权限”原则。 然而,批评者将该技术视为大规模监控的“特洛伊木马”。他们认为: * **“陷阱”:** 零知识证明并未解决身份验证的核心问题。其实施需要依赖“受信任的”验证基础设施,而这些设施可被利用于更深层次的监控、内容审查或设备认证。 * **范围蔓延:** 人们担心,一旦年龄验证常态化,该技术将扩展至其他属性验证,最终将互联网访问权限与政府许可的凭证绑定。 * **社会政治层面的越权:** 许多人认为,“年龄验证”只是削弱在线匿名性的借口。解决网络伤害的方案应是家长控制或网站级标签,而非基于身份的门槛限制。 怀疑论者的共识是,技术上的“修补”往往掩盖了互联网向更受控、更需许可的方向发展的趋势,这实际上是以牺牲基本的数字自由为代价,来优先满足政府和企业的便利。
相关文章

原文

Today, we open sourced our Zero-Knowledge Proof (ZKP) libraries, fulfilling a promise and building on our partnership with Sparkasse to support EU age assurance.

Open sourcing these powerful cryptographic tools will make it much easier for private and public sector developers to build their own privacy-enhancing applications and digital ID solutions, meeting an urgent need.

In layperson’s terms, ZKP makes it possible for people to prove that something about them is true without exchanging any other data. So, for example, a person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all.

The goal of sharing ZKP with the open source and cryptography communities reflects our commitment to helping all parties in the ecosystem:

  • Web and app users benefit from being inhabitants of a more private and secure digital ecosystem.
  • Businesses and other relying organizations of all sizes can easily leverage this open source solution to meet their privacy needs.
  • Developers can freely use the ZKP codebase to build privacy-focused applications.
  • Researchers can use this more efficient and performant ZKP implementation to help create new applications and uses of technology.

The European Union’s eIDAS Regulation set to take effect in 2026 encourages Member States to integrate privacy-enhancing technologies like ZKP into the European Digital Identity Wallet (“EUDI Wallet”). With our commitment to making these ZKP tools openly available, Member States can integrate this into their future EUDI Wallets, accelerating their development.

We're so excited for this new chapter for Zero-Knowledge Proofs and invite you to explore the ZKP codebase on https://github.com/google/longfellow-zk.

联系我们 contact @ memedata.com