Zerocash: Decentralized Anonymous Payments from Bitcoin

Eli Ben-Sasson, A. Chiesa, Christina Garman, M. Green, Ian Miers, Eran Tromer, M. Virza
{"title":"Zerocash: Decentralized Anonymous Payments from Bitcoin","authors":"Eli Ben-Sasson, A. Chiesa, Christina Garman, M. Green, Ian Miers, Eran Tromer, M. Virza","doi":"10.1109/SP.2014.36","DOIUrl":null,"url":null,"abstract":"Bit coin is the first digital currency to see widespread adoption. While payments are conducted between pseudonyms, Bit coin cannot offer strong privacy guarantees: payment transactions are recorded in a public decentralized ledger, from which much information can be deduced. Zero coin (Miers et al., IEEE S&P 2013) tackles some of these privacy issues by unlinking transactions from the payment's origin. Yet, it still reveals payments' destinations and amounts, and is limited in functionality. In this paper, we construct a full-fledged ledger-based digital currency with strong privacy guarantees. Our results leverage recent advances in zero-knowledge Succinct Non-interactive Arguments of Knowledge (zk-SNARKs). First, we formulate and construct decentralized anonymous payment schemes (DAP schemes). A DAP scheme enables users to directly pay each other privately: the corresponding transaction hides the payment's origin, destination, and transferred amount. We provide formal definitions and proofs of the construction's security. Second, we build Zero cash, a practical instantiation of our DAP scheme construction. In Zero cash, transactions are less than 1 kB and take under 6 ms to verify - orders of magnitude more efficient than the less-anonymous Zero coin and competitive with plain Bit coin.","PeriodicalId":196038,"journal":{"name":"2014 IEEE Symposium on Security and Privacy","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-05-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1619","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE Symposium on Security and Privacy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SP.2014.36","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1619

Abstract

Bit coin is the first digital currency to see widespread adoption. While payments are conducted between pseudonyms, Bit coin cannot offer strong privacy guarantees: payment transactions are recorded in a public decentralized ledger, from which much information can be deduced. Zero coin (Miers et al., IEEE S&P 2013) tackles some of these privacy issues by unlinking transactions from the payment's origin. Yet, it still reveals payments' destinations and amounts, and is limited in functionality. In this paper, we construct a full-fledged ledger-based digital currency with strong privacy guarantees. Our results leverage recent advances in zero-knowledge Succinct Non-interactive Arguments of Knowledge (zk-SNARKs). First, we formulate and construct decentralized anonymous payment schemes (DAP schemes). A DAP scheme enables users to directly pay each other privately: the corresponding transaction hides the payment's origin, destination, and transferred amount. We provide formal definitions and proofs of the construction's security. Second, we build Zero cash, a practical instantiation of our DAP scheme construction. In Zero cash, transactions are less than 1 kB and take under 6 ms to verify - orders of magnitude more efficient than the less-anonymous Zero coin and competitive with plain Bit coin.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Zerocash:比特币的去中心化匿名支付
比特币是第一种被广泛采用的数字货币。虽然支付是在假名之间进行的,但比特币无法提供强有力的隐私保证:支付交易记录在一个分散的公共分类账中,从中可以推断出许多信息。零币(Miers等人,IEEE标准普尔2013)通过将交易与支付源断开连接来解决其中一些隐私问题。然而,它仍然显示支付的目的地和金额,并且功能有限。在本文中,我们构建了一个完整的基于分类账的数字货币,具有强大的隐私保证。我们的结果利用了零知识简洁非交互式知识论证(zk-SNARKs)的最新进展。首先,我们制定和构建去中心化匿名支付方案(DAP方案)。DAP方案允许用户直接私下支付,相应的交易隐藏了支付的来源、目的地和转账金额。我们提供了构造安全性的正式定义和证明。其次,我们构建Zero cash,这是我们的DAP方案构建的一个实际实例。在零现金中,交易小于1 kB,验证时间不到6毫秒——比不那么匿名的零币效率高几个数量级,与普通比特币竞争。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Wysteria: A Programming Language for Generic, Mixed-Mode Multiparty Computations From Zygote to Morula: Fortifying Weakened ASLR on Android Quantifying Information Flow for Dynamic Secrets KCoFI: Complete Control-Flow Integrity for Commodity Operating System Kernels Analyzing Forged SSL Certificates in the Wild
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1