Every time I sign up for something regulated, it’s the same routine: passport, address, documents, proof of this, proof of that.

Then I hand all of it to another company and basically trust them to keep it Safe.

That’s what made Citadel click for me.

The idea is pretty simple instead of repeatedly handing over the underlying data y0u keep control of your identity and prove only what the other side actually needs to know.

Say a service needs to know whether you passed KYC.

It doesn’t necessarily need your passport sitting in its database. You could prove that you’re KYC verified, eligible for something, or hold a certain credential without revealing all the information behind that claim.

That’s the interesting pArt of using zero-knowledge proofs here. The service gets the answer it needs without getting the whole file.

And there’s another part I initially overlooked linkability.

A credential system can become less private if the credential itself turns into some public identifier that follows your activity around. Citadel’s design uses private credentials and service specific sessions instead, which is a much cleaner model for keeping identity and activity from being trivially coNnected.

The bigger idea is that you could verify your identity once and reuse that proof across different services, instead of restarting the same KYC process every time.

There’s still a catch, though.

Self-sovereign identity doesn’t make the hard problems disappear. You still have key and credential management, and institutions still need to accept this kind of proof as satisfying their compliance requirements.

So maybe the harder problem isn’t the cryptography at all.

Is the real challenge getting institutions comfortable with user-controlled identity instead of the databases they’ve spent years building?

@Dusk_Foundation
$DUSK #dusk