25 Jun 20266 Min Read

Edge Scaling Architecture for Inline Fayda Verification

የፋይዳ ብሔራዊ መለያ አረጋጋጭ የመዳረሻ (Edge) ቴክኒክ ግንባታ

Title: Edge Scaling Architecture for Inline Fayda Verification: A HighThroughput Engineering Blueprint


1. Executive Summary
As Ethiopia transitions toward a unified digital economy, the National ID Program (Fayda) serves as the foundational trust layer. However, the centralized verification of millions of retail transactions per second presents a significant bottleneck. This paper proposes a decentralized "Edge Scaling Architecture" that utilizes ZeroKnowledge Proof (ZKP) protocols at peripheral nodes to ensure highthroughput, lowlatency, and privacypreserving authentication at the point of sale (PoS).


2. The Architectural Challenge
The current verification model relies on a hubandspoke system where every retail transaction must ping a central MOSIPbased server. This architecture faces two primary risks:
Latency Spikes: During peak hours, roundtrip times (RTT) for biometric or OTP verification can exceed acceptable retail thresholds (typically <2 seconds).
Privacy Leakage: Transmitting raw identity data across networks increases the surface area for data interception.


3. Proposed Edge Infrastructure
To mitigate these risks, we propose deploying "Verification Edge Gateways" at the tier1 network periphery (ISP level or major retail hubs). These nodes act as intermediate trust execution environments (TEEs).

Key Components:
Local Cryptographic Caches: Storing nonsensitive, hashed metadata to facilitate rapid lookup.
Inline ZKP Accelerators: Hardwareaccelerated modules (FPGA/ASIC) dedicated to verifying ZeroKnowledge Proofs generated by the user’s mobile device or smart card.


4. Inline ZeroKnowledge Protocol (IZKP)
The core of the system is the implementation of zkSNARKs (ZeroKnowledge Succinct NonInteractive Argument of Knowledge). Instead of sending the full Fayda profile to the cloud, the process follows these steps:

1. Commitment: The user’s device generates a cryptographic commitment of their ID data.

2. Challenge/Response: The Edge node issues a computational challenge.

3. Proof Generation: The device generates a small, verifiable proof that the user possesses a valid Fayda ID and meets specific transaction criteria (e.g., "Is over 18" or "Account balance > X") without revealing the ID number or actual balance.

4. Verification: The Edge node verifies the proof in milliseconds and authorizes the transaction locally, syncing the state to the central ledger asynchronously.


5. HighThroughput Engineering
By offloading the verification logic to the edge, the central Fayda core is relieved from handling repetitive authentication pings.
Horizontal Scalability: New edge nodes can be added dynamically as retail density increases.
OfflineFirst Capability: Edge nodes can maintain a shortterm "Signed Revocation List" to prevent fraud even if the connection to the central server is temporarily lost.


6. Security and Compliance
This architecture adheres to "Privacy by Design" principles. Since the edge node never "sees" the raw Fayda data—only the mathematical proof of its validity—the risk of a mass data breach at the peripheral level is nullified. Furthermore, it aligns with Ethiopia’s Data Protection Proclamation by minimizing data transit.


7. Conclusion
Edgebased inline verification represents the next evolution of national ID systems. By combining edge computing with ZeroKnowledge cryptography, the Fayda ecosystem can support the highvelocity demands of a modern retail economy while guaranteeing absolute user privacy and system resilience.

የፋይዳ ብሔራዊ መለያ አረጋጋጭ የመዳረሻ (Edge) ቴክኒክ ግንባታ

ርዕስ፦ የፋይዳ መለያን በጫፍ ቴክኖሎጂ (Edge Computing) እና በሚስጥራዊ ኮድ (ZeroKnowledge) ለማረጋገጥ የተነደፈ የቴክኒክ መዋቅር ጥናት


1. ማጠቃለያ
ኢትዮጵያ ወደ ዲጂታል ኢኮኖሚ የምታደርገውን ሽግግር ተከትሎ፣ የፋይዳ ብሔራዊ መለያ የመተማመኛ መሠረት ሆኖ እያገለገለ ይገኛል። ሆኖም ግን፣ በሚሊዮን የሚቆጠሩ የችርቻሮ ክፍያዎችን በአንድ ማዕከላዊ አገልጋይ (Server) ብቻ ማረጋገጥ ከፍተኛ የፍጥነት መገታት (Bottleneck) ሊያስከትል ይችላል። ይህ የጥናት ሰነድ በንግድ ስፍራዎች አቅራቢያ በሚገኙ የዳርቻ የመረጃ ማዕከላት (Edge Nodes) ላይ የሚተገበር፣ ከፍተኛ ፍጥነት ያለው እና የተጠቃሚን ሚስጥር የማይሰርቅ (ZeroKnowledge Proof) የማረጋገጫ ሥርዓትን ያቀርባል።


2. የመዋቅር ፈተናዎች
አሁን ያለው የመለያ ማረጋገጫ ዘዴ ሁሉም የክፍያ መረጃዎች ወደ ማዕከላዊው የፋይዳ መረጃ ቋት እንዲሄዱ ይፈልጋል። ይህ አካሄድ ሁለት ዋና ችግሮች አሉት፦
የፍጥነት መዘግየት (Latency): በግዢ ወቅት በሺዎች የሚቆጠሩ ሰዎች መለያቸውን በአንድ ጊዜ ለማረጋገጥ ሲሞክሩ፣ መረጃው ሄዶ እስኪመለስ የሚፈጀው ጊዜ ከችርቻሮ ንግድ ፍላጎት (ከ2 ሰከንድ በታች) ሊበልጥ ይችላል።
የመረጃ ደህንነት ስጋት: የግል መረጃዎችን በየቀኑ በኔትወርክ ላይ ማመላለስ ለመረጃ ጠላፊዎች ዕድል ሊሰጥ ይችላል።


3. የዳርቻ (Edge) መሠረተልማት
እነዚህን ችግሮች ለመቅረፍ "የዳርቻ ማረጋገጫ በሮች" (Verification Edge Gateways) በኢንተርኔት አቅራቢዎች ወይም በትልልቅ የገበያ ማዕከላት አቅራቢያ እንዲገነቡ ይመከራል። እነዚህ ማዕከላት እንደ መካከለኛ ታማኝ አካል ሆኖ ያገለግላሉ።

ዋና ዋና ክፍሎች፦
የተመሰጠሩ መረጃዎች መከማቻ (Local Cryptographic Caches): ሚስጥራዊ ያልሆኑ ነገር ግን ለማረጋገጥ የሚረዱ መረጃዎችን በቅርብ በመያዝ ፍጥነትን ይጨምራሉ።
የፍጥነት ማሳለጫ መሣሪያዎች (ZKP Accelerators): ሚስጥራዊ ኮዶችን በፍጥነት ለመፍታት የሚያስችሉ ልዩ የሃርድዌር ክፍሎች።


4. ሚስጥራዊ የማረጋገጫ ዘዴ (ZeroKnowledge Protocol)
የዚህ ሥርዓት አስኳል "ዜሮኖውሌጅ" (ZeroKnowledge Proof) የተሰኘው የሳይበር ደህንነት ዘዴ ነው። ይህ ቴክኖሎጂ አንድ ግለሰብ ማንነቱን ሳያሳይ፣ መለያው ትክክል መሆኑን ብቻ በሒሳባዊ ቀመር ለማረጋገጥ ያስችላል።

1. የምስጠራ ዝግጅት: የተጠቃሚው ስልክ የግል መረጃውን ሳይገልጽ የምስጠራ ኮድ ያመነጫል።

2. የማረጋገጫ ጥያቄ: የዳርቻው ማዕከል (Edge Node) መረጃው ትክክል መሆኑን የሚያረጋግጥ የሒሳብ ጥያቄ ለስልኩ ይልካል።

3. ማረጋገጫ መስጠት: ስልኩ የተጠቃሚውን ሙሉ መረጃ (ለምሳሌ ስም፣ የልደት ቀን) ሳይልክ፣ "ይህ ሰው ዕድሜው ከ18 በላይ ነው" ወይም "ይህ ሰው ትክክለኛ የፋይዳ መለያ አለው" የሚል አጭር ማረጋገጫ ብቻ ይልካል።

4. ማጽደቅ: ማዕከሉ ማረጋገጫውን በሴኮንድ ስብርባሪ ውስጥ መርምሮ ግብይቱን ይፈቅዳል።


5. ከፍተኛ የሥራ አፈጻጸም
የማረጋገጫ ሥራውን ወደ ዳርቻ ማዕከላት በማውረድ፣ የማዕከላዊው የፋይዳ መረጃ ቋት ላይ የሚፈጠረውን ጫና መቀነስ ይቻላል።
ተለዋዋጭነት: የገበያ ስፍራዎች ሲበዙ ተጨማሪ የዳርቻ ማዕከላትን በቀላሉ መጨመር ይቻላል።
ያለ ኢንተርኔት የመሥራት አቅም: ከዋናው ማዕከል ጋር ያለው ግንኙነት ቢቋረጥ እንኳ፣ የዳርቻ ማዕከላቱ ለተወሰነ ጊዜ ግብይቶችን የማረጋገጥ አቅም ይኖራቸዋል።


6. ደህንነት እና ሕጋዊ ተገዥነት
ይህ መዋቅር "ሚስጥርን አስቀድሞ መጠበቅ" (Privacy by Design) በሚለው መርህ ላይ የተመሠረተ ነው። የዳርቻ ማዕከላት የተጠቃሚውን ጥሬ መረጃ ስለማያዩ፣ የመረጃ ስርቆት ቢከሰት እንኳ ምንም የሚወጣ የግል መረጃ አይኖርም። ይህ ከኢትዮጵያ የመረጃ ደህንነት አዋጅ ጋር ሙሉ በሙሉ የተጣጣመ ነው።


7. ማጠቃለያ
የዳርቻ ማረጋገጫ መዋቅር ለወደፊቱ የፋይዳ ሥርዓት ወሳኝ የቴክኖሎጂ እርምጃ ነው። የዳርቻ ኮምፒውቲንግን እና የዜሮኖውሌጅ ምስጠራን በማቀናጀት፣ የኢትዮጵያን የችርቻሮ ንግድ ቀልጣፋ፣ ደህንነቱ የተጠበቀ እና ሚስጥራዊነቱ የተጠበቀ ማድረግ ይቻላል።
Full Read
© 2026 TIMONA Intelligence Hub