Australian not-for-profit · ACN 699 651 771Open research · Open software · Public benefitPublic record

Research topic · VirtEngine

Decentralized identity

Can a person prove who they are — strongly enough for finance-grade infrastructure — without surrendering their documents, biometrics, or behaviour to a central database?

The VEID research stream explores privacy-preserving identity verification and selective disclosure. Source identity-document images and full OCR output remain on the user's device; only minimum derived data may be submitted for a separately approved scope. This identity signal is optional for general marketplace participation.

01 research

The question

Digital infrastructure keeps demanding stronger identity — to prevent Sybil attacks, satisfy AML/CTF obligations, and gate high-stakes operations — while every strengthening step has historically meant more personal data pooled in more central databases. The research question is whether the trade-off is real: can verification strength and data minimisation increase together?

The foundation's constitution forces this question rather than merely permitting it: clause 39 mandates privacy-by-design, minimised collection, minimised central custody, encryption and selective disclosure where feasible, and independent auditability.

02 research

Approach

VEID, the VirtEngine identity layer, is the working testbed. The privacy-preserving design keeps source document images and full OCR output on the user's device. Any minimum derived fields or features submitted for verification require separate, purpose-specific approval; other evidence follows its own scope notice.

The intended disclosure model is to share a verification result or selected proof rather than source documents. The x/veid module tree in the open repository includes a zero-knowledge proof package (x/veid/zk); capabilities described in repository designs should not be read as a guarantee that every proof flow is deployed or available.

03 research

Current work and artifacts

The open repository carries the on-chain modules (x/veid, x/veidregistry, x/mfa, x/roles), a mobile capture reference application (mobile/veid-capture-app), and public documentation including a biometric hardware attestation design document, a consent framework, and a biometric data addendum. The identity.org.au property presents the citizen-facing account of the same work.

Open problems under active study include: liveness robustness against generative-AI presentation attacks, the recoverability/unlinkability tension in credential re-issuance, and how relying services should consume tiered verification scores without re-identifying users across contexts.

Artifacts — verify, don't trust

  • x/veid + x/veid/zk modules on-chain identity scoring and zero-knowledge proof verification, Apache 2.0
  • Biometric hardware attestation design docs/veid/biometric-hardware-attestation.md in the open repository
  • VEID capture reference app mobile/veid-capture-app — document, selfie, liveness, attestation flows
  • Identity program page the foundation's program account of VEID — pipeline, tiers, consent, service
  • identity.org.au public plain-language home of the VEID research