1️⃣ Introduction à AnonAgeProof 🔒
Ce tutoriel premium vous guide pour implémenter AnonAgeProof, une solution modulaire et open-source pour vérifier l’âge des utilisateurs de manière anonyme, répondant aux exigences de la loi SREN française (2024) sans compromettre la vie privée. En combinant Python, JavaScript, blockchain, et ZK-SNARKs, AnonAgeProof génère des jetons d’âge anonymes (AgeToken) vérifiables sans révéler d’identité. Vous apprendrez à créer, vérifier, et intégrer ce système dans un site web, avec un kit de déploiement plug-and-play, un dashboard admin, et un respect strict du RGPD. Conçu pour un lab éthique, ce projet protège les mineurs tout en préservant la liberté des adultes.
Objectifs
- Construire un système modulaire de vérification d’âge anonyme.
- Générer et vérifier des AgeTokens avec ZK-SNARKs.
- Intégrer AnonAgeProof via un SDK JavaScript.
- Monitorer et administrer via un dashboard sécurisé.
2️⃣ Architecture Modulaire 🏗️
AnonAgeProof repose sur une architecture modulaire plug-and-play pour une intégration facile et une évolutivité maximale.
Composants
- SDK Frontend: Interface JavaScript pour les sites web.
- API Verification: Backend Flask pour gérer les jetons.
- Blockchain: Ganache (Ethereum local) pour tests.
- ZK-SNARK Verifier: Smart contract pour valider les preuves.
- Age Providers: Fournisseurs d’âge (ex. FranceConnect, ID card).
3️⃣ Setup du Lab Pro 🔧
Configurez un lab isolé pour tester AnonAgeProof en sécurité.
+-----------------------------------------+
| [Réseau Lab Isolé] |
| | |
| v |
| [Kali Linux: 192.168.1.101] |
| | (Serveur Web + Blockchain Node) |
| v |
| [Client Test: 192.168.1.102] |
+-----------------------------------------+
Variables d’Environnement
# Définir dans ~/.bashrc sur Kali
export KALI_IP=192.168.1.101
export CLIENT_IP=192.168.1.102
export BLOCKCHAIN_PORT=8545
export WEB_PORT=80
Matériel et Logiciels
- PC: VirtualBox, VMs Kali Linux 2024.4, Ubuntu 22.04 (client).
- Logiciels: Python 3.12, web3.py, circom, ganache-cli, flask, nginx, docker, prometheus, nodejs.
- Blockchain: Ganache pour tests locaux.
Configuration
- Kali Linux VM:
# Configurer IP: $KALI_IP sudo apt update && sudo apt install python3 python3-pip nginx docker.io prometheus curl -sL https://deb.nodesource.com/setup_18.x | sudo -E bash - sudo apt install nodejs pip3 install web3 flask requests npm install -g ganache-cli truffle # Installer Circom wget https://github.com/iden3/circom/releases/latest/download/circom-linux-amd64 chmod +x circom-linux-amd64 sudo mv circom-linux-amd64 /usr/local/bin/circom # Lancer Ganache ganache-cli --port $BLOCKCHAIN_PORT & - Client Test (Ubuntu VM):
# Configurer IP: $CLIENT_IP sudo nano /etc/netplan/01-netcfg.yaml network: ethernets: enp0s3: addresses: [$CLIENT_IP/24] gateway4: 192.168.1.1 sudo netplan apply # Installer dépendances sudo apt install python3 python3-pip pip3 install requests
Kit de Déploiement
# install.sh
#!/bin/bash
echo "🚀 AnonAgeProof Installation par Platon-y | pctamalou.fr"
echo "🔍 Vérification des dépendances..."
# Vérification des dépendances
command -v python3 >/dev/null 2>&1 || { echo "❌ Python3 requis. Installez-le via 'sudo apt install python3'"; exit 1; }
command -v npm >/dev/null 2>&1 || { echo "❌ Node.js requis. Installez via 'curl -sL https://deb.nodesource.com/setup_18.x | sudo -E bash - && sudo apt install nodejs'"; exit 1; }
command -v ganache-cli >/dev/null 2>&1 || { echo "📦 Installation de ganache-cli..."; npm install -g ganache-cli; }
command -v circom >/dev/null 2>&1 || { echo "📦 Installation de Circom..."; wget https://github.com/iden3/circom/releases/latest/download/circom-linux-amd64 -O /tmp/circom && chmod +x /tmp/circom && sudo mv /tmp/circom /usr/local/bin/circom; }
command -v docker >/dev/null 2>&1 || { echo "❌ Docker requis. Installez via 'sudo apt install docker.io'"; exit 1; }
# Menu interactif pour le fournisseur d’âge
echo "🛡️ Choisissez un fournisseur d’âge :"
PS3="Entrez votre choix (1-3): "
options=("franceconnect" "idcard_reader" "none")
select provider in "${options[@]}"; do
case $provider in
"franceconnect"|"idcard_reader"|"none")
echo "✅ Fournisseur sélectionné : $provider"
break
;;
*) echo "❌ Choix invalide, réessayez." ;;
esac
done
# Variables d’environnement
export KALI_IP=192.168.1.101
export BLOCKCHAIN_PORT=8545
export WEB_PORT=80
# Lancement de l’installation
echo "⚙️ Lancement de l’installation..."
curl -sSL https://anonageproof.org/install | bash -s -- \
--blockchain=ganache \
--provider="$provider" || { echo "❌ Échec de l’installation. Vérifiez les logs dans /tmp/anonageproof.log"; exit 1; }
echo "🎉 Installation terminée ! Hackez safe, Apache ! ⚡️"
echo "📝 Lancez le serveur avec 'sudo python3 app.py' et testez sur http://$KALI_IP:$WEB_PORT"
# Lancer
chmod +x install.sh
./install.sh
4️⃣ Générer l’AgeToken 🛠️
Fournisseurs d’Âge
Utilisez des fournisseurs comme FranceConnect ou un lecteur NFC.
# providers.py
from requests_oauthlib import OAuth2Session
class AgeProvider:
@staticmethod
def franceconnect():
return OAuth2Session(client_id='anonageproof').fetch_token()
@staticmethod
def idcard_reader():
return NFCReader().get_age() # Simulation
Circuit ZK-SNARK
# age_checker.circom
template Main() {
signal input age;
signal output isAdult;
isAdult <== age >= 18 ? 1 : 0;
}
component main = Main();
# Compiler
circom age_checker.circom --r1cs --wasm --sym
Script de Génération
# generate_token.py
from web3 import Web3
from circomlib import ZKSNARK
w3 = Web3(Web3.HTTPProvider(f"http://$KALI_IP:$BLOCKCHAIN_PORT"))
def generate_age_token(age, provider="franceconnect"):
snark = ZKSNARK("age_checker.r1cs")
proof = snark.prove({"age": age, "threshold": 18})
with open("agetoken.json", "w") as f:
f.write(str(proof))
return proof
if __name__ == "__main__":
proof = generate_age_token(25)
print("AgeToken généré !")
# Lancer
python3 generate_token.py
5️⃣ Vérification Anonyme 🔍
Smart Contract
# AgeVerifier.sol
pragma solidity ^0.8.0;
contract AgeVerifier {
mapping(address => bool) public whitelist;
constructor() {
whitelist[msg.sender] = true;
}
function verifyProof(bytes memory proof, address provider) public view returns (bool) {
require(whitelist[provider], "Unverified provider");
// Simulation ZK-SNARK
return true;
}
}
# Déployer
truffle migrate --network ganache
Script de Vérification
# verify_token.py
from web3 import Web3
w3 = Web3(Web3.HTTPProvider(f"http://$KALI_IP:$BLOCKCHAIN_PORT"))
contract = w3.eth.contract(address="0xYourContractAddress", abi=[...])
def verify_age_token(proof):
return contract.functions.verifyProof(proof, "0xProviderAddress").call()
if __name__ == "__main__":
with open("agetoken.json", "r") as f:
proof = f.read()
print(verify_age_token(proof))
# Lancer
python3 verify_token.py
6️⃣ Intégration dans un Site Web 🌐
SDK JavaScript
# anonageproof-sdk.js
class AnonAgeProof {
static async verify() {
const proof = await generateZKProof(); // Simulation
return fetch('/verify', {
method: 'POST',
body: JSON.stringify({ proof })
});
}
}
Script Flask
# app.py
from flask import Flask, request, redirect
from verify_token import verify_age_token
app = Flask(__name__)
@app.route('/verify', methods=['POST'])
def verify():
proof = request.json.get('proof')
if verify_age_token(proof):
return redirect("/content")
return "Accès refusé", 403
@app.route('/content')
def content():
return "Contenu réservé aux adultes !"
if __name__ == "__main__":
app.run(host='0.0.0.0', port=$WEB_PORT)
# Lancer
sudo python3 app.py
Client Web
# client.html
<!DOCTYPE html>
<html>
<head>
<title>AnonAgeProof</title>
<script src="anonageproof-sdk.js"></script>
</head>
<body>
<button onclick="AnonAgeProof.verify()">Vérifier Âge</button>
</body>
</html>
7️⃣ Dashboard Admin 📈
Script React
# admin.js
import React from 'react';
import ReactDOM from 'react-dom';
const Dashboard = ({ stats, revokeToken }) => (
<div>
<h1>AnonAgeProof Admin</h1>
<p>Jetons vérifiés: {stats.count}</p>
<button onClick={revokeToken}>Révoquer Jeton</button>
</div>
);
ReactDOM.render(
<Dashboard stats={{ count: 0 }} revokeToken={() => alert('Revoked')} />,
document.getElementById('root')
);
</pre>
<h3>Monitoring</h3>
<pre class="code-block">
# monitoring.sh
#!/bin/bash
prometheus --config.file=anonageproof.yml
</pre>
<pre class="code-block">
# anonageproof.yml
scrape_configs:
- job_name: 'anonageproof'
static_configs:
- targets: ['localhost:9090']
</pre>
<pre class="code-block">
# Lancer
bash monitoring.sh
8️⃣ Sécurisation 🛡️
Module RGPD
# gdpr.py
import hashlib
def anonymize_data(data):
return hashlib.blake2b(data.encode()).hexdigest()
Bonnes Pratiques
- Chiffrement: TLS 1.3 pour toutes les connexions.
- Audit: Code open-source, audité par la communauté.
- Révocation: Mécanisme de révocation des jetons.
- RGPD: Aucune collecte de données personnelles.
Nginx Hardening
server {
listen 80;
location /verify {
if ($request_method !~ ^(POST)$) { return 405; }
proxy_pass http://$KALI_IP:$WEB_PORT;
}
}
sudo systemctl restart nginx
9️⃣ Licence 📜
AnonAgeProof est publié sous la licence MIT, permettant une utilisation gratuite avec attribution.
MIT License
Copyright (c) 2025 Platon-y (pctamalou.fr)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
10️⃣ Checklist Éthique ⚖️
- Lab Only: Tests en environnement isolé.
- Légalité: Pas d’usage sans autorisation écrite.
- Consentement: Respect des lois RGPD.
- Logs: Aucune collecte de données personnelles.