Scribe: Private Web2-to-Web3 eligibility proofs for decentralized applications with transparent STARKs
Abstract
Decentralized applications increasingly require eligibility checks based on Web2-held attributes, yet provider-side signing and centralized attestations limit deployability and can expose sensitive user data. This paper presents Scribe , a distributed eligibility verification service that bridges TLS-derived Web2 evidence to decentralized applications without any modification to Web2 servers. In Scribe, a client engages in a standard TLS session with a Web2 service and, using a DECO/TLSNotary-style provenance workflow, obtains an attestation node signature on a commitment to an extracted value. The client then generates a transparent zero-knowledge proof that verifies the attestation and proves compliance with an application policy without revealing the underlying value. Each proof outputs an application-scoped spend tag (nullifier) to provide replay resistance. An aggregator verifies proofs off-chain, maintains a Merkle-indexed spent-tag set, and publishes batched state roots to an on-chain anchor. Root publications are authorized using a post-quantum signature scheme, providing post-quantum integrity for the on-chain state without requiring on-chain proof verification. We specify the protocol and establish provenance binding, policy soundness, privacy, and replay resistance under stated trust assumptions.
// Source
Authors: Zhede Gu, Hushuang Zeng, Libing Qin, Shengsi Luo, Chen Yuyan, Yongguang Yan
Institutions: China Southern Power Grid (China), Guangxi Hydraulic Power Machinery Research Institute, Power Grid Corporation (India)