Zether: Towards Privacy in a Smart Contract World

被引:131
作者
Bunz, Benedikt [1 ]
Agrawal, Shashank [2 ]
Zamani, Mahdi [2 ]
Boneh, Dan [1 ]
机构
[1] Stanford Univ, Stanford, CA 94305 USA
[2] Visa Res, Palo Alto, CA USA
来源
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2020 | 2020年 / 12059卷
关键词
IDENTIFICATION; SIGNATURES;
D O I
10.1007/978-3-030-51280-4_23
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart contract platforms such as Ethereum and Libra provide ways to seamlessly remove trust and add transparency to various distributed applications. Yet, these platforms lack mechanisms to guarantee user privacy, even at the level of simple payments, which are essential for most smart contracts. In this paper, we propose Zether, a trustless mechanism for privacy-preserving payments in smart contract platforms. We take an account-based approach similar to Ethereum and Libra for efficiency and usability. Zether is implemented as a smart contract that keeps account balances encrypted and exposes methods to deposit, transfer, and withdraw funds to/from accounts through cryptographic proofs at only a small cost. We address several technical challenges to protect Zether against replay attacks and front-running situations and develop a mechanism to enable interoperability with arbitrary smart contracts, making applications like auctions, payment channels, and voting privacy-preserving. To make Zether efficient, we propose Sigma-Bullets, a zero-knowledge proof system that is optimized for Sigma-protocols. We implement Zether as an Ethereum smart contract and show its practicality by measuring the amount of gas used by the Zether contract. A Zether confidential transaction costs about 0.014 ETH or approximately $1.51 (as of early 2019), which can be drastically reduced with minor changes to Ethereum that we describe in the paper.
引用
收藏
页码:423 / 443
页数:21
相关论文
共 38 条
[1]  
Abdalla M, 2002, LECT NOTES COMPUT SC, V2332, P418
[2]  
[Anonymous], 1996, EXTROPY J TRANSHUMAN
[3]  
Ben-Sasson E, 2014, PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, P781
[4]   Zerocash: Decentralized Anonymous Payments from Bitcoin [J].
Ben-Sasson, Eli ;
Chiesa, Alessandro ;
Garmant, Christina ;
Green, Matthew ;
Miers, Ian ;
Tromer, Eran ;
Virza, Madars .
2014 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2014), 2014, :459-474
[5]  
Boneh D., 2018, A Graduate Course in Applied Cryptography
[6]  
Bonneau J., 2015, IACR Cryptol. ePrint Arch.
[7]   Mixcoin: Anonymity for Bitcoin with Accountable Mixes [J].
Bonneau, Joseph ;
Narayanan, Arvind ;
Miller, Andrew ;
Clark, Jeremy ;
Kroll, Joshua A. ;
Felten, Edward W. .
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2014, 2014, 8437 :486-504
[8]   Short Accountable Ring Signatures Based on DDH [J].
Bootle, Jonathan ;
Cerulli, Andrea ;
Chaidos, Pyrros ;
Ghadafi, Essam ;
Groth, Jens ;
Petit, Christophe .
COMPUTER SECURITY - ESORICS 2015, PT I, 2015, 9326 :243-265
[9]  
Bowe S., 2018, Report 2018/962
[10]  
Bunz B., 2019, 2019191 CRYPT EPRINT