top of page
PHC_icon.png

Proof of Humanness over Bots 

Designing Personhood Credentials

PHC_banner.png

Team

Pennsylvania State University

Role

Student UX Researcher

Duration

4 months (2025)

PHC_banner.png

Challenge

Advances in AI have broken traditional verification: bots now defeat CAPTCHA, and synthetic identities bypass KYC checks. Personhood Credentials (PHCs) promise to prove that a user is a real and unique human without disclosing personal information, using mechanisms such as zero-knowledge proofs. Yet PHCs differ fundamentally from conventional authentication, so users may misread them as just another sign-in method and misjudge their privacy guarantees. These misunderstandings create real vulnerabilities: users may reject a protection they need and remain exposed to bot-driven fraud or adopt it with misplaced expectations about how their biometric data is handled.

PHC Challenge.png

Solution

A qualitative interview study (N=27) with participants from the US and the EU/UK, combining scenario-based sessions with participatory sketch sessions to surface perceptions, preference factors, and design ideas for PHC systems. I synthesized the user findings into integrated interface designs that make PHC guarantees visible and controllable across the credential journey. 

Study Design

Designed a four-part semi-structured interview protocol: current verification practices, an educational video on PHC concepts with knowledge checks before and after, scenario-based exploration of PHC use, and a participatory sketch session run in a think-aloud manner.

Developed six application scenarios ranging from finance and healthcare to social media and LLM applications, each pairing different credential requirements such as government IDs and biometrics.

Interviewed 27 participants until thematic saturation was reached, complemented by a post-survey quantifying credential and issuer preferences for each scenario.

Conducted a policy and standards analysis of 13 documents, from eIDAS and NIST digital identity guidelines to W3C standards and US state laws, mapping their alignment with user-centric themes such as transparency and privacy control.

PHC Study Design.png

Results

Analyzed the data with thematic analysis, iterating the codebook between coders and grouping codes into themes aligned with the research questions.

Uncovered a core comprehension gap: participants rarely grasped PHC cryptographic protections such as zero-knowledge proofs, reasoning instead by analogy to physical IDs and assuming stored data could always be stolen.

Showed that preferences are context-dependent: government-issued IDs and government issuers were most trusted for sensitive services, while private issuers and lighter credentials such as phone numbers were acceptable for social media and LLM applications.

Identified issuers as a critical yet previously underexamined determinant of trust, alongside architecture preferences spanning centralized and decentralized issuance.

PHC Results.png

Design for Secure Outcomes

Distilled participant sketches into concrete design themes, such as time-bounded credentials and sensitivity-based credential choice, together with visually interactive human checks and periodic re- verification against misuse.

Delivered design implications as integrated interface mockups, covering tiered assurance levels for verification choice, portable credentials usable across services, and layered safeguards through dynamic multi-factor verification.

Contributed as the first user study focused on PHCs, laying the groundwork for user-centered identity verification in an AI-mediated web.

PHC Design.png
bottom of page