Chapter 3 · 3/5
Zero-knowledge proofs
Proving you are over 18 without showing your date of birth: how mathematics makes it possible.
6 min
With selective disclosure you can show your date of birth and hide your name. But what if you don't want to show your date of birth either? The concert door's question was never "What is your date of birth?" but "Are you over 18?" This page explains how to prove just that.
Proving without showing
A classic example: you want to prove to a colour-blind friend that the two balls you hold are different colours. They put the balls behind their back, swap them or don't, then show you. Every time, you say correctly whether they swapped. After twenty rounds your friend is convinced the balls differ, yet still has no idea which ball is which colour.
That is the spirit of a zero-knowledge proofA mathematical method that proves a statement true without revealing the data that makes it true.: the other side becomes convinced the statement is true, but learns nothing about the data behind it. Modern systems do this not with rounds but with a single mathematical proof that is computed once and checked once.
How the age proof works in Tamga
- The issuer issues and signs the identity credential exactly as today. Nothing changes on the issuer's side, which matters: institutions on the network do not need to set up anything new.
- When a site or a gate asks "Over 18?", the wallet produces a proof. It says: "I hold a credential signed by this institution, and the date of birth in it is more than 18 years ago."
- The verifier checks the proof. It sees only two things: that the statement is true, and which institution issued the credential. It does not see the date of birth, the document number or even the credential itself.
Tamga uses an open-source system called Longfellow ZKAn open-source zero-knowledge proof system for mdoc credentials, developed by Google and independently security-reviewed., which Europe's age-verification work is also built on. Only reviewed proof circuits whose identifiers are published in the trust list are accepted, so nobody can fool a verifier with a home-made "proof".
Does it work everywhere?
Producing a proof takes some computing power on the phone, and some older devices or verifiers may not support it yet. Then the wallet falls back: instead of the date of birth it shows one of several single-use copies of the credential that contain only "over 18: yes". The next page explains those copies.
Why it matters
Age checks are becoming mandatory online: alcohol, gambling, certain content, some platforms. Uploading ID photos creates leak risks and makes people trackable. Zero-knowledge proofs show that the rule can be enforced without exposing the person.
Summary
- A zero-knowledge proof shows a statement is true without revealing the data that makes it true.
- In Tamga issuers change nothing; the wallet builds the proof from today's signed credential.
- The verifier sees only the result and the issuer; two presentations cannot be linked.
Go deeper
Technical details and binding rules: