Zero Knowledge · Zero Knowledge Podcast

zkPDF and zkID with Vikas Rushi and Ying Tong

August 13, 2025·1 hr 9 min·5 clips
How can zero-knowledge proofs verify the content of a government-signed PDF without revealing your personal data?
1. Zero Knowledge podcast hosts Anna Rose and Kobi interview Vikas Rushi from PSE (Ethereum Foundation's Privacy and Scaling Explorations) and Ying Tong about ZK-PDF and ZK-ID. 2. Vikas is a PSE researcher who came to ZK through AnonAadhaar at ETH India 2023, then worked with ZK Email and Open Passport before joining PSE; Ying Tong is a recurring guest who previously discussed programmable privacy and co-organized a community privacy residency in Taipei in early 2025. 3. The episode's thesis is that ZK proofs can enable selective disclosure of real-world document data — PDFs and government credentials — without requiring full document upload to verifiers, and that the EU digital identity wallet's current design fails to achieve this. 4. ZK-PDF is described as a proof-of-concept within PSE for generating zero-knowledge proofs about the content of digitally signed PDFs, specifically enabling selective disclosure of specific facts without revealing the complete document. 5. The primary motivating use case is India's DigiLocker, where the Indian government uses a single signing key to digitally sign all documents — Aadhaar cards, tax documents (PAN cards), education certificates, healthcare records — for a population of 1.3 billion Aadhaar holders. 6. Standard KYC processes that require uploading a full PDF to a provider leak all personal data; ZK-PDF replaces this with proofs of specific statements (such as salary above a threshold or a document being government-issued) without transmitting the underlying data. 7. PDF parsing was far more complex than anticipated: the format's 30-year history has accumulated hierarchical data structures, cross-border references, multiple compression and encoding algorithms, and multi-language support (including Chinese and Japanese text). 8. Every major Rust PDF parsing library wraps native C code, making it incompatible with ZKVMs like SP1 and RISC-0; Vikas had to rewrite the entire parsing logic with a single ZKVM-compatible dependency. 9. Benchmarks: a 104KB DigiLocker PAN card PDF takes 31 seconds and 29 million SP1 cycles to generate a Groth16 proof; a 5MB multilingual PDF takes approximately 3 minutes. 10. Ying Tong proposes an optimization where the issuer generates the Groth16 proof alongside the signed document, achieving 'issuer unlinkability' — the issuer cannot observe how the user presents the credential in subsequent verifications. 11. ZK-PDF can be combined with ZK Email: email attachments that are PDFs could be proven using ZK Email's signature layer plus ZK-PDF's parsing, enabling proofs about invoice or payment PDF attachments received via email. 12. DocuSign PDFs use a chain-of-certificates model where multiple signers each contribute keys in sequence; a proof-of-concept with the ZK Email team demonstrated that ASN.1 content including issuer public keys could be verified using string matching within this framework. 13. Vikas describes ZK-PDF's future direction as becoming a primitive like ZK-TLS, ZK Regex, or ZK Email — an SDK that hackathon participants and companies can incorporate rather than a standalone product. 14. The ZK-ID effort is motivated by the EU digital identity wallet, which is expected to be widely deployed as soon as 2026 with no official connection to the Ethereum Foundation or PSE, but whose requirements the PSE team wants to satisfy. 15. The EU digital identity wallet's device binding requirement distinguishes it from ZK Passport and other static ZK identity systems: holders must sign a verifier-provided session nonce with their phone's secure element at each verification, proving live possession of the specific device. 16. A consortium of cryptographers published a document to the EU Commission identifying that the EU digital ID wallet's existing salted-hash selective disclosure design (SD-JWT and MDL formats) is fully linkable by both credential issuers and verifiers. 17. The ZK-ID effort, alongside Google's Longfellow project which Anna Rose notes was a previous podcast guest, is proposing replacing the salted-hash design with genuine anonymous credential primitives using ZK proofs. 18. The EU Commission has an open GitHub discussion inviting cryptographic expertise, specifically asking how long ZKPs take on average mobile phones, how large proofs will be, and what storage requirements exist — framing the feedback process as practical communication to policymakers. 19. This episode is best for ZK practitioners, identity system researchers, and developers interested in how ZK proofs apply to real-world documents and government credential systems. 20. Listeners without background in ZK proof systems, verifiable credentials, or PDF formats will struggle to follow the technical depth of either the ZK-PDF or ZK-ID discussions.

As heard by us

Two concrete ZK problems, handled as one steady conversation about proofs, PDFs, and digital identity.

ZK-PDF and ZK-ID give the episode a concrete edge by tying zero-knowledge ideas to things people already handle: PDFs, invoices, bank statements, and digital identities.

Read the full review in PlayNext →

Why you'd press play

If PDFs and digital identity keep showing up in your work, this one pays off.

Read the full recommendation in PlayNext →
Listen to the show on