Web3 access controls: How zero-knowledge encryption can secure user access

Check out all the on-demand sessions from the Intelligent Security Summit here.


But while its concrete definition — and indisputable arrival — remain pending, one for-sure consensus is that this next iteration of the World Wide Web will effectively eliminate the password. No more coming up with unique passwords containing a confusing mix of upper and lowercase letters, numbers and special characters. 

So, then, how will we access it? And how will we know that that access is secure? 

The key, according to experts, is next-level authentication methods enabled by zero-knowledge encryption and proofs. 

Event

Intelligent Security Summit On-Demand

Learn the critical role of AI & ML in cybersecurity and industry specific case studies. Watch on-demand sessions today.


Watch Here

“Zero-knowledge encryption is a fundamental technology for realizing the potential of Web3,” said Alex Pruden, CEO of privacy platform provider Aleo. “This is the most important new technology that no one is paying attention to. From identity to machine learning, from commerce to gaming, (zero knowledge) will change the way we interact online.”

But what is zero-knowledge encryption?

With zero-knowledge encryption, data is secured with unique user keys. Admins and developers do not know them or have access to them, meaning that no one but the user can access their encrypted files, Pruden explained. 

This is enabled through zero-knowledge proofs, which can “verifiably prove” that a statement is true without disclosing the underlying information. Unlike more familiar forms of encryption — such as end-to-end models used in private messaging apps, by which only users and senders can view information — zero-knowledge cryptography allows for information to be “private and usable at the same time,” said Pruden. 

He offered what he described as a “trivial example” of the concept: You can prove that you know the solution to a sudoku puzzle without revealing just how you know it. Or, you can simply give a “yes” or “no” answer to the question of whether you are over age 18 — without having to reveal your actual age or birthday. 

This allows for a “more granular set of use cases” than traditional encryption, said Pruden; it can answer the question, “How can I prove a fact about something without revealing the something?”

“With a zero-knowledge proof, you can verify that you’re a trusted individual without exposing any information about yourself,” he said. 

Pruden ultimately called the method “extremely well suited” to identity verification in Web3, because it protects individuals and the various systems that organizations must keep secure. 

And…what exactly is Web3?

While the Web3 framework is still a work in progress, its premise was coined by Gavin Wood, cofounder of Ethereum. It is what is known as “read-write-own,” according to the decentralized open-source blockchain, “embraces decentralization and is being built, operated and owned by its users.”

Gartner similarly identifies Web3 as “a new stack of technologies built on blockchain protocols that support the development of decentralized web applications and enable users to control their own identity, content and data.”

These include privacy-preserving protocols, decentralized governance and decentralized application platforms, explained Avivah Litan, Gartner distinguished research VP.

“These innovations will eventually support a decentralized web that will integrate with the current Web 2.0 we use every day,” she writes.

Ultimately, Web3 supports user ownership of data and algorithms through decentralized identity (DCI) constructs, tokenization and self-hosted wallets, she explained. DCI uses decentralized computing, which leverages zero-knowledge proofs and “least privilege.” 

This means that users “can assert aspects of their identity” without sharing data. “This will increase the focus on and awareness of privacy,” Litan writes, “with users having control and making conscious decisions about which identity attributes are being shared with service providers.”

Several disruptive benefits

And, in the long term, a “portable and reusable” DCI that enables privacy and security “will be a required building block of the transition away from Web2 toward Web3 and to enable interoperability across emerging metaverse environments,” writes Litan. 

Ultimately, Gartner predicts that by 2027, social media platforms will shift from a “customer as product” to a “platform as customer” model of decentralized identity. 

“The current paradigm of users having to prove their identity repeatedly across online services is not efficient, scalable or secure,” Gartner stated in its report on top predictions for IT organizations and users in 2023 and beyond. 

Web3 enables new decentralized identity standards with “several disruptive benefits,” according to Gartner, including giving users more control over what data they share, ultimately removing the need for repeated identity proofing across services and supporting common authentication services. 

Zero-knowledge encryption in Web3

Pruden pointed to pervasive database hacks that compromise login information, financial information and other personally identifiable information (PII).

It’s these “honeypots” of valuable data that decentralized identity aims to eliminate, he said. Transforming this existing model, logins can simply require zero-knowledge proofs that verify credentials; and payments can be completed without handing over credit card or other sensitive banking or financial data.

In the end, the user maintains ownership of their credentials and only provides proofs when they need to authenticate themselves for a given service, Pruden said.

This is also a better model for organizations, he pointed out, because they no longer have the potential liability of maintaining and securing “user secrets.” 

And, by incorporating zero-knowledge encryption into the infrastructural level of the decentralized internet, any applications will be able to incorporate privacy into their functions.

In the same way that transparent layer security (TLS) encryption enables web commerce, “this is a key unlock,” said Pruden.

Zero knowledge does this for Web3, he said, “but also makes it possible for Web2 and Web3 to interoperate seamlessly.”

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.

Read More
Taryn Plumb

Latest

The Outer Worlds 2 studio Obsidian accused of “violating state wage and hour laws” for profit in California lawsuit

The company denied the allegations earlier this year Image credit: Microsoft Obsidian Entertainment, developers of The Outer Worlds 2 and Avowed, have been sued in California for allegedly engaging "in a systematic pattern of wage and hour violations". The case was initially filed in the Superior Court of Orange County by plaintiff Victoria Turner in

PlayStation CEO Responds to Reports They Are No Longer Releasing Single-Player Games on PC

by William D'Angelo , posted 2 days ago / 15,994 Views Sony Interactive Entertainment CEO Hideaki Nishino was asked about the recent reports that claim first-party narrative single-player PlayStation games would no longer release on PC and remains exclusive to PlayStation consoles, while live service titles would still come to PC to reach a wider

2026 World Cup: How Portugal can get the best from Cristiano Ronaldo – Ex-Super Eagles captain Oliseh

Soccer Cristiano Ronaldo of Portugal. Copyright: xBahhoxKarax Former Super Eagles...

Newsletter

Don't miss

The Outer Worlds 2 studio Obsidian accused of “violating state wage and hour laws” for profit in California lawsuit

The company denied the allegations earlier this year Image credit: Microsoft Obsidian Entertainment, developers of The Outer Worlds 2 and Avowed, have been sued in California for allegedly engaging "in a systematic pattern of wage and hour violations". The case was initially filed in the Superior Court of Orange County by plaintiff Victoria Turner in

PlayStation CEO Responds to Reports They Are No Longer Releasing Single-Player Games on PC

by William D'Angelo , posted 2 days ago / 15,994 Views Sony Interactive Entertainment CEO Hideaki Nishino was asked about the recent reports that claim first-party narrative single-player PlayStation games would no longer release on PC and remains exclusive to PlayStation consoles, while live service titles would still come to PC to reach a wider

2026 World Cup: How Portugal can get the best from Cristiano Ronaldo – Ex-Super Eagles captain Oliseh

Soccer Cristiano Ronaldo of Portugal. Copyright: xBahhoxKarax Former Super Eagles...

2026 World Cup: Ex-Nigeria striker warns ‘tactically dull’ South Africa ahead of must-win Korea clash

Soccer South Africa head coach Hugo Broos. Copyright: Imago Former...

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID