[MINUTES] CCG Asia-Pacific 2026-06-11

This meeting focused on the advancements and applications of post-quantum
Zero-Knowledge Proofs (ZKPs), particularly in the context of digital
identity and credentials. The discussion highlighted the increasing
importance of quantum-resistant cryptographic solutions due to the
anticipated threat of large-scale quantum computers. The presenters shared
their work on implementing post-quantum ZKP systems, specifically using the
PLONK2 proof system, and demonstrated their application in proving the
validity of post-quantum digital signatures and enabling privacy-preserving
age verification. The conversation also touched upon the challenges and
optimizations required for integrating these complex cryptographic
primitives into practical systems.

*Topics Covered:*

   - *Introduction to CCG and APEC Region Calls:* Denken Chen provided an
   overview of the Credential Community Group (CCG) and its initiatives,
   including the APEC region-specific calls and the distribution of recordings
   and information to a global audience.
   - *Zero-Knowledge Proofs (ZKPs) Overview:* Pochun Kuo offered a
   fundamental explanation of ZKPs, likening them to a more generalized form
   of digital signatures where a prover can demonstrate knowledge of a secret
   without revealing it.
   - *Merkle Trees and Data Integrity:* The concept of Merkle trees was
   explained as a method for efficiently proving the existence of data within
   a larger dataset, serving as a foundational idea for some post-quantum ZKP
   constructions.
   - *Post-Quantum Cryptography and ZKPs:* The threat posed by quantum
   computers to current cryptographic standards was discussed, emphasizing the
   need for post-quantum ZKPs and outlining two main categories: hash-based
   and lattice-based ZKPs.
   - *PLONK2 Proof System:* Pochun Kuo elaborated on the PLONK2 proving
   system, chosen for its efficiency, fast verification, and short proof
   sizes, and explained its underlying principles of succinct non-interactive
   arguments of knowledge.
   - *Polynomial Commitments and Proof Generation:* The meeting delved into
   the technical aspects of how functions are encoded and committed to using
   polynomial commitments and techniques like Fast Fourier Transform (FFT) and
   Reed-Solomon codes to achieve succinctness.
   - *Post-Quantum Digital Signature Verification:* The core application of
   post-quantum ZKPs was demonstrated through proving the verification of
   post-quantum digital signature schemes like Angler DSA and Falcon, a
   challenging task due to the computational expense of certain cryptographic
   operations.
   - *Privacy-Preserving Digital Identity and Credentials:* The
   presentation showcased how ZKPs can be used to prove attributes from
   digital identities, such as age verification, without disclosing
   unnecessary personal information, aligning with principles of data
   minimization and privacy.
   - *Optimization Techniques and Recursive Proofs:* Pochun Kuo discussed
   the optimization efforts made to handle computationally expensive
   operations like rejection sampling in digital signature verification and
   introduced the concept of recursive proofs to further enhance efficiency.
   - *Future Vision of Digital Identity:* The meeting concluded with a
   vision of self-sovereign identity, where individuals control their data and
   use ZKPs to selectively disclose information, moving away from centralized
   databases and password-based authentication towards a world where "we trust
   mathematics."

*Action Items:*

   - Denken Chen will share Pochun Kuo's slides with the CCG mailing list
   and via email.
   - Participants are encouraged to complete the feedback survey to help
   improve future APEC region calls.
   - Dan Yamamoto and Pochun Kuo will potentially follow up on the mailing
   list to discuss optimizing ZK circuits for PLONK2 in Rust.

Text: https://meet.w3c-ccg.org/archives/w3c-ccg-asia-pacific-2026-06-11.md

Video: https://meet.w3c-ccg.org/archives/w3c-ccg-asia-pacific-2026-06-11.mp4
*CCG Asia-Pacific - 2026/06/11 01:59 EDT - Transcript* *Attendees*

Dan Yamamoto, Denken Chen, Jesse Wright, Pochun Kuo, 大寶
*Transcript*

Pochun Kuo: Hello. Okay.

Denken Chen: Hi. let's wait for a few minutes for other folks to join.

Pochun Kuo: Should I share my slide first?

Denken Chen: I will share some updates from the community group first and
for about five to 10 minutes then we can started your presentations.

Pochun Kuo: Okay. Next.

Denken Chen: I know that some other people will be joining us but probably
will be a little bit late so let's just get started and so welcome to D3C's
CCG GCO this series is specifically for APEC regions. So at this time we
are trying to do some bouncy calls and inviting speakers and today we have
from Taiwan to presenting this topic. And before started a few other
relevant information needs to be noticed.
00:05:00

Denken Chen: If you are going to attend this call and this call will be
recorded and will be distributed to our mailing list and please follow the
code of ethic and professional conduct. So we encourage any friendly
conversation and if you are going to have a substantive contribution to CCG
work, you have to be member of CCG and sign the IPR agreement and a little
bit about our credential community group because I know some people are not
familiar with us yet.

Denken Chen: We are trying to reach to more APC people here and whenever we
re inviting Ape experts here the recording will be distributed to Europeans
and Americas. So all the expert usually will share the experience in the
mailing list. So this is our G. we have an official website here. You can
get it from w3-cc.org and we have the mailing list and we have a weekly
meeting for the Atlantic course and for our APE monthly codes and
previously probably relevant to our topic the CCG is finishing the final
commutic group report about the content safe crypto suite.

Denken Chen: This is going to take some more time to incubate and whenever
it's mature enough usually we will move it to other working groups.
expected should be verifiable credentials working group. So if you are
interested in this work you can reach out to our mailing list and also we
already have a candidate recommendation that's in V's working group data
integrity BPS crypto suit it's a zero knowledge proof and an early stand
almost finished standards and

Denken Chen: In CCG we have a data integrity course this that will discuss
many crypto suite that including content save and zero knowledge proof
relatively specs. So for example previously this one last year we have in
tone from Ethereum foundation have their ZKP solutions to have some early
discussion of the possibility using that zero knowledge proof to put it
into the data integrity specifications. Yeah. So those are probably related
informations we could talk about then later.

Denken Chen: And lastly, I will share the feedback survey in case I forgot.
so if you join this session or if you are watching the video online, please
finish this survey for us. It'll be interesting and helpful for me to
organize a better APAC region cause including the best way to distribute
the information or the best call time for everyone. Okay. So, let's hand it
over to go drink. Thanks.

Pochun Kuo: let me share my slide. Okay, I can full screen. So, everyone
can see my slide. great. Yeah, thanks for the introduction. Yeah, so my
name is Pinor.

Pochun Kuo: Today I want to introduce the topic we actually work for three
or five years on the real marage proof. So now is my startup have already
operate for almost two years. We are working focus on the narrative proof
with quantum safe algorithm. So here is a brief introduced to myself. This
is my name encrypted by Chinese. Yeah, I'm also a professor in National
Jenzu University and I got my BS PhD from National Taiwan University.
00:10:00

Pochun Kuo: Yeah, my academic experience all in postquantum cryptography
especially in latest space system. Yeah. And I also submit a post content
digital signature skin to N and we are worse in the candidate. Yeah. So
today is my agenda today. Yeah.

Pochun Kuo: So I will briefly introduce ZKP and go to the main topic today
the postcon zest knock and talk about how we prove the anga and the falcon
so that we can prove the credential in the postpont setting. So in one
sentence our goal is proving the verification in the post content digital
signature algorithm by post nt real knowledge proof system. Okay, I think
most of the people know what is the ZKP. So I think I can just give a brief
introduce to this slide.

Pochun Kuo: Yeah, DKP I think the easy way to understand ZK is that we can
review in the digital signature skin the prover which means that he has the
secret key he want to he can sign the message for if he has the secret He
can sign a message and everyone has a public key can verify the signature.
In the ZKP aspect, we can see this procedure as that he is trying to
demonstrate that he know the secret key and prove he has the secret key
without leak any information about the secret key.

Pochun Kuo: And everyone can verify this and check that he has already
checked the message and he has the secret key and I can verify the
signature without get any information about his secret key. This is the
digital signature So in this aspect we know that the digital signature is a
kind of reality proof right but the real knowledge proof is much more
general which means that there's a people he has a secret key and he can
prove that he knows something like he knows some x such that the y is equal
to the f ofx

Pochun Kuo: can prove that he know the X and everyone can check this
without knowing any information about the input. Yeah, this is what we want
to build for. so what is the Proof is that the prover can work harder and a
general generate a proof. Usually we require the proof is a short proof so
the verifier can verify the proof efficiently. Yeah, here is the introduced
to the hash function in cryptography.

Pochun Kuo: I think I don't need to talk much about the h function. I think
we can just go to the micro tree. Yeah, mro tree is a very typical way to
prove an x is in the leaf of the tree. But is for example we can have the
scenario that we have a lot of data maybe like a lot of photo in your
iPhone. there is add photo in your iPhone but you don't want to store all
the photo in your iPhone. You want to store the photo Google in the cloud.
00:15:00

Pochun Kuo: But somehow you will think maybe Google will lie to you he can
forge the photo make some metification to the photo. So a way to check that
the Google didn't lie to you is that you can h the photo and store the hash
value for each photo right but if the number of the photo increase then the
number of the hash value you need to store increased.

Pochun Kuo: So a way to keep the number of the hash value to be a constant
time is that we can use the MCO tree. We can hash the two hash value into
one and the hash len to the example So when you want to see the number
three photo third photo then you can ask the Google send the photo and the
proof is the authenticate root bureau O one o2 then you can check the h of
the value into the m root which is then you can check the data is correct

Pochun Kuo: This is one example of the proof. Yeah. And the moco tree is
also the very co idea to build the postcontent real proof. so I introduced
to the post content real proof. Yeah, just like the encryption scheme or
the digital signature before we have a digital signature encryption scheme
like I say or ECC based but shows algorithm which is the quantum algorithm
that can solve factoring problem which means that he can find the large
period art for

Pochun Kuo: the methical problem like the factoring or discrete lo problem.
Yeah. So the similar scenario happened to the zonar proof because some
bonar proof system grow 16 prank bully proof or some similar systems are
built from the assumption from pre-content assumption like I say or ecc
which means that if you have a large scale quantum computer then you can
forge the proof or derive the winies from other proof.

Pochun Kuo: So I think the America government Klay will move to post
quantum encryption and digital signature when in 2030 and the Google put
this date earlier is 2029 because Google think the large scale quantum
computer may be built earlier.

Pochun Kuo: So I think the ZKP has a very similar situation when we want to
use the ZKP maybe there we need a two or three years to use the ZKP but
after two or three years there is a quantum computer so why not we just use
the post quantum ZKP in first then we don't need to do the migration change
the proving system we used Fortunately, Some cryptographer proposed some
postcontent zk. There are two main type of the post content zk.

Pochun Kuo: If you use the assumption to category the ZKP there's one from
H and the other one is from ladies and most of them is defaultly used the
non trusty setup. Yeah, here is the brief survey for the post content
proving system. There is one category that the assumption based on hash
function and there's a kind of len is the fi best the zk stock aurora rat
shift pranky 2. Yeah. All the multi- party computation in the head here is
sound like Liro.
00:20:00

Pochun Kuo: is that used by Google and they use this province system and
built the credential war in Ingret and here's another type is void in the
head is also a special kind of NPC in the head like limbo or fac is a
signature skin that they s post quantum digital signature code and now it
is in the third round. Yeah. And there is another category that based on
latest problem. there are two main type.

Pochun Kuo: One is the paromial comminous skin type like the latest base
prank and another one is folding skin like the latest fold or lower and in
our proving system we select proni 2 because it is relatively well
established and time tested. data is proposed from the blockchain area. So
we think that maybe more people are analysis the security. And it is much
more fast. It has the much faster verification and the short proof in
practice.

Pochun Kuo: Also most of the proofing system say that he has a very short
proof but in practice the pranky to provide the proof less than 200
kilobyte. Some of the proving system takes a few megabytes and the show
proof is relative to the size of the function they use and also the size of
input. So maybe the function is too large. The megabyte is still called
short proof. Yeah. So we use the pronison which is also the z case knock.

Pochun Kuo: The case knock is yeah it's like this real knowledge is
succinct non-interactive argument of knowledge that is it can prove
generate the proof pi but the verifier can verify the proof and check that
the proof knows the winter W so that the public value y is equal to the
function f which takes the inputs x and w is the winter which is the
private input and x is the public input. Yeah.

Pochun Kuo: And in this kind of proofing system if we call it small means
compared to f that the proof pi is in the scale of log f then we say it is
log f means that if we use the circuit model to model f then the size of
the circuit you take the log of the size of circuit.

Pochun Kuo: So in this kind of proof things that we can think what we can
do with the ZK stock this kind of proving system and how to compress the
proof not only in the proving system but that if it proof has already
generate the proof then we can further compress the proof again. How can we
do this? Yeah.
00:25:00

Pochun Kuo: and how to encode the function we want to prove efficiently.
This is the main technique that we improve in the proving system. Yeah, I
think we can give a example that people can more easily to understand what
happened in the proving system. Yeah. this scenario is like The prover can
prove that he knows the two integers p and q. So that n is equal to p * q.
Yeah, this scenario is actually very useful.

Pochun Kuo: For example, the Google you want to log into the Google and
Google in the same time you will receive lots of the request. If there are
some adversary that want to deny the Google service, he can just send a lot
of the large number even the number is not from two primes smart mrication.
So then Google will need to do lots of the encryption for the adversary.

Pochun Kuo: So one method to solve this problem is that Google can ask us.
You need to provide the proof proof that the P and Q and you send the N
equal to PQ to me then I will encrypt the N to you right. So that the
adversary cannot just select the random number and send to the Google and
do the DOS to the Google. Let's see how we prove these argument. First the
proverse samples random number RP and RQ. And he built three function FQ
and FPQ.

Pochun Kuo: FPQ is equal to P multiply X + P and the RQ is like this and
the F PQ is equal to FP mult*ly FQ two. Yeah, you can check the p then the
proof how to commit the three function to the verifier. The method is like
the mer tree.

Pochun Kuo: we can compute the function value of the of one, fp of two, fp
of three, da da da da to fp of 1 million. So we compute a million value for
fp then we can treat this 1 million value to the leaf of the mco tree. So
we can compute the Merco tree and get the root of the Merco tree and then
we send the Merkel root to the verifier. So the commit FP of X is like
this. I compute the loss of the value for FP and compute the micro tree for
FP and just send the micro root to the verifier.

Pochun Kuo: So the is similar to the FQ and the Q. So verifier get three M
route for each function and he select the challenge R to the after prover
received the challenge R, he revealed the FQ of R and FPQ of R. And also he
sent the FPQ of little to verifiers.

Pochun Kuo: Of course for each value the proofer need to send the ML proof
for that so that the verifier can check that the value was in the MO tree
the value is correct the prover didn't line to the verifier and the
verifier not only check the MO proof it also check the
00:30:00

Pochun Kuo: Multiply FQ of R is equal to FPQ of R. Which means that the
proven nose P and Q and P multiply Q is equal to N. Right? Of course the
verifier also need to check F of FPQ of zero is equal to N. Yeah. Yeah. So
in this setting the verify can check that out proven no P and DQ and with
certain certain probability. Yeah.

Pochun Kuo: If the verifier think the soundness is not enough, he can ask
the prover to prove this again and again until the soundness is good enough
to the verifier. how to check the soundness of the protocol is correct is
that since the verifier check the product of the polomial is correct which
means that if the provers p and q he can forge the parromial and these two
paromal

Pochun Kuo: multiply together is equal to the third one which means that he
is very lucky to guess the correct value. But what is pro the probability
that the prover gets the correct value? the value is that because he know
anything about the n he can just guess the value.

Pochun Kuo: So to guess the correct value is that the total probability of
the number which means the size of the field right and if the degree of the
polomial is he has the opportunity to guess correctly. So the total chance
the guess is the size of field the times to the degree of the polomial.

Pochun Kuo: Yeah. This is from the swast zapole lema. So if you believe the
toy example is correct then I can tell you the prank to actually just
upgrade all the procedure into the general case. just like this. for
example in the first the prover can encode for general function which is
described in the red shift paper. It can encode any function into the FPFQ
in the general encoding scheme. Yeah.

Pochun Kuo: and after he can encode for the general function he can commit
the function to the verifier but just like I described about it need to
compute the loss of the value for each function like a 1 million or one
billion. So in the efficient way is that use the face for transform which
is the fast resment code.

Pochun Kuo: Yeah, phase retorment code is the way that compute the function
value and this procedure is called read sermon interactive oracle proof
proic proximity yeah algorithm. Yeah. So actually he just used this
procedure to achieve the succinctness for the proto and the last step is
that they use the BCS the non-interactive skin to transform the interactive
skin to the non-inactive skin.
00:35:00

Pochun Kuo: Yeah, this is transformation is the upgrade version of VIA
Shamir. So yeah. Okay, I think that's all about the proving system. It's a
brief introduction to the proving system. Okay, let's go back to what we
want to prove. We just give the interface of the neuron proving system that
is if you want to prove the function and the function takes two type of the
input. One is the public input and another one is the private input. We
call the winies and it output the value s.

Pochun Kuo: Okay, you can feed this as the input of the proving system and
the prover can pro generate the proof take the function public input and
the output and the witness the prover can generate the proof And the
verifier can get the proof and all the public information like the function
like the input and the output of the function. then he can verify the proof
is true or false.

Pochun Kuo: So our goal is that we want to prove the digital identity that
is issued by government Taiwan government and u and in the digital identity
that we can use in the internet. But in the traditional setting, if I want
to buy the alcohol, I need to show my identity and the identity. There is a
lots of information like my name, my birthday, and my ID number, but I just
want to buy the alcohol. I don't want to tell the sto the shop who I am and
what is my ID number.

Pochun Kuo: Even for the birthday, I don't want to show all the information
to the shop, I just want to prove a lot I have the legal digital identity
and I have already 13 years old. I don't want to disclose all the detail
about my birthday. So in the ZKP setting what is the target What I want to
prove is that the digital identity is correct which means that I have the
signature issue by the government is a valid signature right.

Pochun Kuo: So I just prove that the verification algorithm in the post
content digital signature scheme which output true and the date today minus
my birthday is more than 18 years old. This is what I want to prove. I can
minimize all the information that we want to discuss. Okay.

Pochun Kuo: So in the scenario that we want to prove the identity is that
it does I want to prove the winter is the message which is my name my ID
number and my birthday and the signature the government sent to me which is
the government's use their secret key to sign my ID number. Yeah. So, I
prove that I have this winter and there are some information in the message
which is my birthday. because I want to prove I have already 18 years old.
Yeah. Yeah. Of course. Okay.
00:40:00

Pochun Kuo: Proof of age is in this slide. Yeah. You can check the disc
description that we want to prove in the recap system. So I think the later
one prove the age is much more easier but the formal one the verification
of the digital signature skin is much more hard because if you see the
angular DSA Okay, which is now the NIST post quantum digital signature
standard.

Pochun Kuo: Yeah, you need to prove all the algorithm in the ZKP systems
and here are some technique that if there are some information from the
public then we can put most of them the compute in outside because everyone
can compute the result of the public information and

Pochun Kuo: put the result to the proving system and for the private input
we can do the similar things but in the angro DSA the ca in the signature
is a part of signature we need to prove the sample B function is the reject
sampling procedure to sample a latest point for the digital signature skin
and the rejection sample which means that it takes a lot of the shri hash
function.

Pochun Kuo: Function is very very expensive in a proving system. This is
the bottleneck in our construction. We try to optimize this and we spend a
lots of time to prove this. one of the bottleneck is that we need to use a
large number of the H function to bound this to achieve the constant
circuit because the number of H function is variant from different
signature but we need to keep it constant otherwise it will leak to some
information about the signature.

Pochun Kuo: So to do this we need to spend much more time to compute the
circuit. Yeah. This is the one bottleneck about the annual DSA. Yeah. And
for the Falcon is the draft standard in the post content digital signature
skin. The verification for the Falcon is much more easier. We just need to
check the signature the S1 s2 and compute + S2 multiply H.

Pochun Kuo: Is the public key of the falcon is equal to the hash of
message. Yeah. So you can see that in the right hand side is only the hash
of the message. So we can take the hash of the message as the public input
since maybe someone can think that the hash value of the message you can
protect the message. This is a simple version of our construction.
00:45:00

Pochun Kuo: But here is the problem is that even people didn't know the
information about the message but people know the hash of the message which
means that if I to and they want to to B prove something to C it didn't
know all the message in my identity but is the same one right he knows
Someone proved this to her be knows it's the same people prove this to he
So this is called the linkability where people know who you are but you are
the same people. Yeah, but I think for some application this simple version
is enough.

Pochun Kuo: Yeah, we also proved the unlinkability version which takes the
n as the winter and prove the hash of message is very similar to what
happened in the angular DSA because the hash of message is also the way to
sample a point in the latest It also used the reject sample. So it's very
expensive. We need to call multiple times. And another technique that we
use is the recursive proof. Okay, let's see the traditional setting is in
the upside of the slide.

Pochun Kuo: You want to prove the postcontent DSA the verify but then you
use the green box you use the reality proof system to prove this function
and generate a proof then you can use the verification of the realar proof
system to check the proof right but we can use this framework again that is
now you have a proof And you have the zonary verification function. Okay, I
can use the bonar pro system to prove the verification again just like the
blue box here and it can generate the proof prime.

Pochun Kuo: Then we can verify the proof prime which it means that we can
verify the proof generate by the neuron proof which prove the post content
digital signature algorithm. Yeah. So we implement this and get this
result. For two digital signature skin, we have the fully unlinkability
version in the white current. And for the Falcon, we have the simple
version. Yeah. Which is not unlinkability but it provide a very efficient
way to prove.

Pochun Kuo: And for the method we talk about the recursive proof is in the
blue column. Yeah, you can see in the recursive setting the total proving
time is less than 2 seconds and the verification time is very very fast. It
just take a few millisecond and the proof size is less than 200 kilobyte. I
think it's useful in the practice since I think every time you use the M
WhatsApp and send the photo to your friend the photo takes one mega or two
mega just cost less than one second right. Yeah. And the ping time less
than two second is actually just take a one second and a little bit more.

Pochun Kuo: I think it's enough to do the facetoface proof that is you can
prove this to the whiskey shop or the convenience store and take some goods
there because when you use the credit card sometimes you need to wait for
the transaction for a three or five second right and then for the memory it
takes around 200 megabytes. I think it has already afford for the most
mainstream cell phone. Yeah. Yeah. I think time is very close.
00:50:00

Pochun Kuo: is our survey for what ZKP can reshape the world just in the
very early days three 30 years ago it's the era of the password remember
that time we need to registide foreign and the older websites And the
forward has my identity. He knows who I am. they knows my birthday,
everything about me. And every time I log into the system, I give my
account and the password.

Pochun Kuo: later in the 2000 the single site on style is very popular
which means that I can use the Google, Facebook or APO to log in to another
forum or website if people use the two factor to log into the system which
is much more secure. But in this time all of my information is still store
in the Google server. Everything is so in the cloud. But what we want to
achieve is the self storage identity which means that all the information
about myself is still in my computer in my local site.

Pochun Kuo: I don't want to leak the information to the website unless he
really need to check the information. if that scenario happened I can
control the information that we want to disclose to the website. Yes. So I
think the KP is the best tool to achieve this scenario. So our slogan is
that build a world with digital privacy. Yeah, I think I don't need to talk
too much more detail about this. What I want talk to talk is the technical
side, right? Yeah. Here is some benefit in our view. of the ZKP.

Pochun Kuo: Yeah, we can do the data minimization in the digital world and
we can remove the need for centralized database as much as possible and it
also enable the cross bounder and the cross principle usability which means
that in the same processes I can use for example

Pochun Kuo: for MA, Facebook, for APO, we can just use the same proving
system to prove my identity for multiple plform. And for the regulation, I
think the KP is the best way to protect our privacy and follows the GB GDPR
or some regulation in different countries.

Pochun Kuo: Yeah, it can be not only to provide a lot of the benefit, it
also reduce the loss of the risk a lot the data bridge. Because we can
replace the password with the proof. We don't need to send the password
anymore because the password is the best way for the hacker. he can just
steal your password. Very easy. Lots of way to steal your password. If we
use approve, we can just use the proof for different scenario so that we
don't need to use the same password every time.

Pochun Kuo: And also it has the principle of the list disclosure of my
information just what I talk a lot before. So here is maybe the takeaway
information. We always to prove the information not to post our information
and most of the important is that in the ZKP setting is that we trust
mathematics. Yeah. Instead of institute okay that's all my talk today. Yeah.
00:55:00

Pochun Kuo: Thanks everyone. So any questions here?

Denken Chen: Yeah, I definitely have some questions.

Denken Chen: But leave to the audience and if you have any question, you
can leave a message or just raise your hand or open your mic. Yes, Dan,
please.

Dan Yamamoto: Thank you very much interesting presentation. Yeah, I study
lots of things and actually I'm currently using DK language named no to
construct the similar anonymous credential system as a prototype or
experiment.

Dan Yamamoto: But the problem is no is currently only supporting
traditional proof system based on pairing friendly elliptic curve. So it's
not postquantum. So I'm really interested in postquantum version of
programming system. Yeah. I love Noir because it's really easy to construct
ZK circuit. We can use rustl language to design our zik circuit by using
noir.

Dan Yamamoto: So my question is about PL2 you are using how can we design
or implement various VK sockets using funky2. Are there any for example
Rust language or Python language to implement PL2 Z socket or…

Dan Yamamoto: not? So yeah that's my first question.

Pochun Kuo: Yeah.

Pochun Kuo: The prognative is the opensource. so you can check this if you
use the rust language to program The circuit type is called prankish. Yeah.
Another one is called R1 CS. We use R1 CS. we use Aurora before we think
the prankish is much more efficient to encode the general function. So we
switch to pranky too and use the prankish. Yeah.

Pochun Kuo: So I think you can try to use this one because some of the
previous just use the same circuit model, you can just put your program
into the prank key too then you can get the post version. But somehow this
is the simple way to use that because if you know more about the provinia
system then the more optimized way that you can optimize your function.

Pochun Kuo: For example, in our scenario, if the naive way to implement the
verification of the digital signature comparing to our optimized code is
three times slower than our optimized version. So I will think you can
first step you can try to use your code after that maybe we can have some
discussion I can help you to optimize your code. Yeah. Yeah.

Pochun Kuo: Of course,…

Dan Yamamoto: Okay.

Pochun Kuo: we are try to write the paper explain what is the optimization
method we use.
01:00:00

Pochun Kuo: Yeah, thanks.

Dan Yamamoto: Yeah. Thank you.

Pochun Kuo: Thanks for the question.

Denken Chen: And we are running out of time.

Denken Chen: So Bjon if you are okay with sharing the slides with me so I
can share the slides within the mailing list and also the email. I think we
can follow up in the mailing days to discuss with other folks and thanks
everyone for joining us and including everyone watching the recording and
we after survey I pass it again so please help us to finish the survey so
we can organize this event much better in the future.

Pochun Kuo: pressure. Thanks. Thanks.

Denken Chen: Thank you for joining us. See you next month. Thank you.
Thanks.
Meeting ended after 01:01:21 👋

*This editable transcript was computer generated and might contain errors.
People can also change the text after it was created.*

Received on Sunday, 21 June 2026 22:47:36 UTC