TamgaNetwork
All posts
Technical·6 min

Selective disclosure and zero-knowledge: show the fact, not the data

Prove you are over 18 without revealing your birth date. The mathematics behind sharing less while proving more.

The most powerful idea in modern digital identity is also the simplest to state: you should share only what a verifier needs, and nothing more. Two layers of cryptography make it real — selective disclosure and zero-knowledge proofs.

Selective disclosure (SD-JWT)

A credential is a set of claims. Instead of signing the raw values, the issuer signs a set of salted hashes of them. To reveal a claim, the holder discloses its salt and value; the verifier recomputes the hash and checks it against the signed set. Undisclosed claims reveal nothing — the salt makes them non-invertible.

salted-hash disclosure
for each claim c_i with random salt s_i:
    d_i = H( s_i || c_i )
issuer signs the set  D = { d_1, ..., d_n }

reveal claim i:  holder shows (s_i, c_i)
verify:          H(s_i||c_i) == d_i  AND  d_i in D  AND  Sig_issuer(D) ok

Zero-knowledge: a fact without the value

Selective disclosure still shows a revealed field in full. Zero-knowledge proofs go further: you prove a predicate over a hidden value. The classic example — proving “age ≥ 18” without disclosing the birth date — becomes a range proof over a signed commitment. The verifier learns only a boolean.

predicate proof
issuer signs commitment  C = Commit(birth_date, r)
holder proves in zero knowledge:
    exists (birth_date, r):  C = Commit(...)  AND  today - birth_date >= 18y
verifier learns ONLY the boolean  (range proof: Bulletproofs / BBS+)

With BBS+ signatures, presentations also become unlinkable — two verifiers cannot tell they saw the same person. These primitives are on our roadmap and enter as they mature and pass audit. More: Selective disclosure and SD-JWT.