Identity & security

x/veid — VEID

Identity verification and trust scoring — the patented core of the protocol.

Reference

What it does

The veid module implements VirtEngine's identity layer. Users capture identity evidence on-device — documents with OCR, a selfie with active liveness, biometric hardware attestation (fingerprint or iris), and device integrity attestation via Play Integrity or App Attest. The evidence is sealed into encrypted identity scopes, signed by both an approved client and the user, and submitted on-chain.

Validators — the same set that secures consensus — decrypt submitted scopes with their keys, score them with shared machine-learning models, and commit an identity trust score to the ledger by consensus. This validator-run identity verification network is the method protected by patent AU2024203136B2.

The module's zero-knowledge subsystem (x/veid/zk) lets users then prove facts about their verified identity — that a score clears a threshold, that an attribute holds — without revealing documents, biometrics, or the score itself.

Why it exists: An open compute marketplace needs ways to assess risk without forcing every customer through one identity gate. VEID provides privacy-preserving verification signals that a provider may require for a specific offer; tenants can also consider escrow, provider evidence, terms, and history. Verification does not prove hardware ownership, delivery, or service quality.

State

Primary objects

ConceptDefinition
Identity scopeA separately approved, purpose-specific bundle of minimum derived identity data for one verification dimension; it excludes original document images and full OCR output.
Trust scoreThe consensus-committed score validators assign after ML evaluation of submitted scopes.
ZK verification tierA zero-knowledge proof surface that reveals only a threshold or attribute fact — never the data.
Active livenessA challenge–response selfie flow proving a live human, resistant to photos, replays, and injection.

Messages

Messages & queries

Message and query surfaces are documented at implementation level in the module docs ↗ and the source ↗. The objects above are the state those messages create and transition.

Connections

Module interactions

Flows

Core flow

  1. Capture — Evidence on-device. Document OCR, liveness challenge, biometric and device attestation — all captured on the handset.
  2. Seal — Scopes are sealed. Evidence bundles are encrypted to validator keys and signed by both an approved client and the user.
  3. Score — Validators score. Decryption, shared-model scoring, and a consensus-committed trust score recorded through the registry.
  4. Gate — Proofs inform specific choices. VEID is not a universal marketplace or deployment prerequisite. Any supported requirement is scoped to a service or individual offer and disclosed before use.

Questions

Asked about x/veid

What is an identity scope?

An encrypted, signed bundle of identity evidence for one verification dimension — the unit validators decrypt, score, and commit outcomes for.

x/veidregistry module

Who sees my documents and biometrics?

Nobody on the public ledger. Scopes are encrypted to validator recipients for scoring, and the verification surfaces expose only zero-knowledge proofs — never raw documents, biometrics, or scores.

What is VEID?

What is active liveness?

A challenge–response selfie flow proving a live human is present — resistant to photos, replays, and injection — performed on-device before anything is sealed.

More questions → FAQ

Related

Related modules