The modern anonymous credential (how ZK landed in Google Wallet)

The modern anonymous credential (how ZK landed in Google Wallet)

🎙 Abhi Shelat 👥 75K 📅 August 14, 2025 ⏱ 62 min 👁 698 📄 expert opinion 🧭 2026-08-06
Available in: English (current) Français

Keywords

anonymous credentialszero-knowledgeselective disclosuredevice bindingISO/IEC 18013-5

Summary

Abhi Shelat, in this talk at the Simons Institute, discusses the modern anonymous credential system, focusing on how zero-knowledge techniques have been integrated into Google Wallet. He begins by highlighting the problem of uploading ID photos online, which exposes sensitive data to state-level actors. He then traces the history of digital credentials back to 1985, noting that despite extensive cryptographic research, deployment only happened recently. The ISO/IEC 18013-5 standard, developed by non-cryptographers, introduced a two-round protocol for selective disclosure using salted hashes and Reed-Solomon encoding. This protocol is now used by Apple and Google. A key challenge is device binding to prevent credential copying and replay attacks, which is addressed using secure elements that only support RSA and ECDSA signatures. Shelat explains the limitations of this approach, such as the lack of support for bilinear pairings, and discusses the issue of accessibility, noting that only 1% of phones under $400 have the necessary secure element. He concludes by reflecting on the gap between cryptographic research and real-world deployment, suggesting that the community should learn from the ISO group’s practical approach.

180 words

Critical Evaluation

The talk provides a valuable perspective on the real-world deployment of cryptographic protocols, specifically the ISO/IEC 18013-5 standard for mobile driver’s licenses. Shelat’s expertise is evident, and he effectively bridges the gap between theoretical cryptography and practical implementation. The discussion of the protocol’s design, including the use of salted hashes and Reed-Solomon encoding, is technically accurate and well-explained. The emphasis on device binding and the constraints of secure elements highlights a critical practical issue that is often overlooked in academic research. The talk also raises important questions about accessibility and the digital divide, as the secure element requirement may exclude low-cost phones. However, the talk is primarily an opinion piece based on Shelat’s experience, and some claims, such as the percentage of phones with secure elements, are not rigorously sourced. The lack of a formal evaluation of the protocol’s security properties is a minor weakness, but the talk is not intended as a formal analysis. Overall, the content is informative and thought-provoking, offering insights into the challenges of deploying cryptographic solutions in the real world. The title accurately reflects the content, and the talk is well-structured, with clear explanations and relevant examples. The audience questions add depth to the discussion, addressing issues such as attribute selection and device compatibility. The talk does not include any promotional content, and the focus remains on technical and societal aspects. The main limitation is the lack of empirical data to support some claims, but this does not significantly detract from the overall value of the presentation.

252 words

Title / Content Match

The title accurately reflects the content, focusing on modern anonymous credentials and their implementation in Google Wallet, with a discussion of zero-knowledge techniques.

Quality & Reliability

8/10

The talk is given by an expert (Abhi Shelat, Northeastern/Google) and presents technical details of the ISO/IEC mdoc protocol, including cryptographic mechanisms. The content is grounded in real deployments (Apple/Google) and references standards. However, it is an opinion/experience talk, not a peer-reviewed study, and some claims (e.g., phone statistics) are anecdotal.

Key Moments

Cited Sources

Concurring Sources

  • ISO/IEC 18013-5:2021 — The standard for mobile driver's licenses, which the talk discusses in detail.

Contribution & Novelties

The talk provides a unique insider perspective on the deployment of anonymous credentials in Google Wallet, highlighting the practical challenges and the gap between academic cryptography and industry standards. It emphasizes the importance of understanding real-world constraints, such as secure element limitations and accessibility issues.

Pour aller plus loin :

  • ISO/IEC 18013-5:2021 — The standard for mobile driver’s licenses, directly relevant to the protocol discussed.
  • Zero-knowledge proof — Foundational concept underlying selective disclosure.
  • Reed-Solomon error correction — Technique used in the protocol for encoding attributes.

85 words

Radar Profile

The radar profile shows high scores in information quantity, quality, technical level, and reliability, indicating a well-rounded and technically sound presentation. The talk excels in providing detailed technical information and expert insights, with a strong reliability based on the speaker's experience and the use of established standards.

Reliability 8/10