Unconditionally Secure Commitment and Oblivious Transfer Schemes

Total Page:16

File Type:pdf, Size:1020Kb

Unconditionally Secure Commitment and Oblivious Transfer Schemes Unconditionally Secure Commitment and Oblivious Transfer Schemes Using Private Channels and a Trusted Initializer Ronald L Rivest Lab oratory for Computer Science Massachusetts Institute of Technology Cambridge MA rivestmitedu November Abstract We present a new and very simple commitmentscheme that do es not dep end on any assumptions ab out computational complexity the Sender and Receiver may both be computationally unb ounded In stead the scheme utilizes a trusted initializer who participates only in an initial setup phase The scheme also utilizes private channels between each pair of parties The Sender is able to easily commit to a large value the scheme is not just a bitcommitment scheme We also observe that outofn oblivious transfer is easily handled in the same mo del using a simple OT proto col due to Bennett et al Keywords bitcommitment commitmentscheme unconditional secu rity trusted third party trusted initializer oblivious transfer Intro duction A commitment scheme must sp ecify a Commit proto col and a Reveal proto col involving a Sender Alice and a Receiver Bob Alice has a secret value x that she commits to in the Commit proto col although Bob learns nothing ab out x then Later Alice discloses x in the Reveal proto col Bob may reject the value Alice reveals if it is inconsistent with the information he received during Commit Alice may not change her mind ab out the value to be revealed once Commit is nished Thus a commitmentscheme must satisfy the following requirements Correctness If b oth parties are honest and follow the proto cols then dur ing the Reveal proto col Bob will learn the value x that Alice wished to commit to Privacy Bob learns nothing ab out x during the Commit proto col Binding After the Commit proto col has nished there is only one value of x that Bob will accept during the Reveal proto col If x is required to b e a single bit wesay that the commitmentscheme is a bit commitment scheme otherwise we use the more general term commitmentscheme There are many applications for commitment schemes Sealedbid auc tions are one obvious example x represents Alices bid Commitment schemes are useful for identication schemes multiparty proto cols and are an an essential comp onent of many zeroknowledge pro of schemes Previous Work on Commitment Schemes Since commitmentschemes were rst intro duced by Blum in for the problem of coin ipping by telephone commitmentschemes have b een an active area of research However one must face the facts of life It is wel l known and easy to see that in a twoplayer scenario with only noiseless communication OT Oblivous Transfer and BC Bit Commitment with informationtheoretic security is not possible even if only passive cheating is assuming and players are al lowed innite computing power page Therefore researchers have fo cussed primarily on commitmentschemes based on computational assumptions where bind ing or privacy dep ends on the Sender or Receiver resp ectively b eing computationally b ounded or commitmentschemes based on other mo dels of communication involv ing noisy channels or quantum mechanics If the scheme requires that the Sender be computationally b ounded in order to achieve binding we say that it is computational ly binding other wise it is unconditional ly binding some authors would call this information theoretical ly binding Similarly if the scheme requires that the Receiver be computational bounded in order to achieve privacy we say that it is computational ly pri vate otherwise it is unconditional ly private some authors would call this informationtheoretical ly privateorunconditional ly hidingoruncondition al ly concealing It is typically enough to assume that only one of the Sender or Receiver be computationally b ounded so that one achieves an asymmetric result either computational binding and unconditional privacy or unconditional binding and computational privacy Commitment schemes that are computationally binding and uncondi tionally private have b een prop osed bymany researchers including Blum Goldwasser Micali and Rivest implicit in their signature scheme Brassard Chaum and Crep eau Brassard Crep eau and Yung Halevi and Micali and Halevi Brassard and Yung develop a very gen eral framework and theory for all bit commitment schemes having uncon ditional privacy based on oneway group actions Damgard Pedersen and Ptzmann show that the existence of statistically hiding bit com mitment schemes which provide nearly p erfect unconditional privacy is equivalent to the existence of failstop signature schemes Naor presents a commitment scheme that is unconditionally bind ing and computationally private based on any pseudorandom generator or equivalently based on any oneway function Ohta Okamoto and Fujioka show that Naors scheme is secure against divertibility and note that the nonmalleable bitcommitment scheme of Dolev Dwork and Naor can also b e used to provide such protection OstrovskyVenkatesan and Yung examine in some detail bit commitmentschemes when at least one of the SenderReceiver is computationally unb ounded and in particular show that when the Sender is computationally unb ounded a commitment scheme may b e based on any hardonaverage problem in PSPACE Some researchers have explored informationtheoretic mo dels based on the assumption of noisy communication channels For example Crep eau improves on his earlier work with Kilianby giving ecient algorithms for bit commitment and oblivious transfer over a binary symmetric channel Later Damgard Kilian and Salvail explore such questions further based on unfair noisy channels and related assumptions Other researchers have explored bit commitment in mo dels of quan tum computation Brassard et al prop osed a quantum bit commitment scheme but a subtle aw was discovered Mayers proved general quan tum bit commitment to be imp ossible as did Lo and Chau More re cently Salvail shows that under certain restricted assumptions ab out the Senders ability to make measurements quantum bit commitment is still p ossible Bit commitmentschemes o ccur within a wide variety of mo dels and ap plications not all of whichare mentioned ab ove or whicht in the ab ove taxonomy Just to pick one interesting example BenOr Goldwasser Kil ian and Wigderson utilize a bit commitment scheme in a multiprover mo del of twoprovers who cant communicate with each other one com mits a bit to a verier and the other reveals it Our Mo del We b elieve it is of interest to lo ok for practical commitment schemes that work when b oth the Sender and the Receiver are computationally unb ounded What would one use for a commitmentscheme for example if it turns out that P NP The normal mo del twoparty proto col with noiseless channel do es not admit a solution How can one most simply extend the mo del to permit a solution In this pap er we make the following assumptions which suce There is a trusted third party Ted Ted is honest and b oth Alice and Bob trust that Ted will execute his role correctly There are private channels between each pair of parties Alice and Bob can each communicate privately with Ted and with each other We desire that if p ossible Ted should never nd out the value of x Alice and Bob trust Ted to be honest but the value of x is none of Teds business and Alice and Bob prefer that he never learns x This requirement rules out the obvious solution wherein Alice gives x to Ted during Commit and Ted gives x to Bob during Reveal We further desire that if p ossible Ted should not participate in the Commit and Reveal proto cols We prefer a solution wherein Ted only participates in an initial Setup proto col In such a scheme Ted is done b efore Alice may even have decided which x to commit to This rules out the obvious solution wherein Ted gives Alice a random string r during Setup Alice gives Bob r x during CommitandTed gives Bob r during Reveal We call a trusted third party who participates only in a setup phase b efore the other parties may even have their inputs a trusted initializer Proto cols using trusted initializers are much easier to implement than more typical proto cols using trusted third parties since the initialization can be p erformed wellinadvance of the actual proto col and the trusted partydoes not need to b e available to participate in the actual heart of the proto col Our commitment scheme Our commitmentscheme is illustrated in Figure All computations are p erformed mo dulo p for some xed suitably large globally known prime number p We assume that Alices secret value x satises x p The communications patterns are very simple during Setup Ted sends some dierent information to Alice and Bob During Commit Alice sends one number to Bob During Reveal Alice sends three numbers to Bob Each proto col is thus minimal just one pass and For the Setup phase Ted randomly cho oses twonumb ers a Z R p b Z These numb ers dene a line R p y ax b mo d p Ted sends the values a and b privately to Alice Ted also picks another value x uniformly at random from Z and computes the value p y ax b mo d p Ted privately sends Bob the pair x y this is a p oint on the line For the Commit phase Alice computes the value y ax b mo d p and privately sends the value y to Bob For the Reveal phase Alice privately sends Bob her secret value x and also the pair a b Bob checks that x y andx y satisfy equations and If so he accepts x otherwise he rejects T Setup S a Z R p S S b Z R p x y a b S S x Z R p S y ax b mo d p S Sw A B Commit x
Recommended publications
  • Imperfect Oblivious Transfer Extended Abstract
    Imperfect Oblivious Transfer Extended Abstract Ryan Amiri,1 Petros Wallden,2 and Erika Andersson1 1SUPA, Institute of Photonics and Quantum Sciences, Heriot-Watt University, Edinburgh EH14 4AS, United Kingdom∗ 2LFCS, School of Informatics, University of Edinburgh, 10 Crichton Street, Edinburgh EH8 9AB, United Kingdom I. INTRODUCTION Oblivious transfer (OT) is one of the most widely used and fundamental primitives in cryptography. Its importance stems from the fact that it can be used as the foundation for secure two-party computations; with oblivious transfer, all secure two-party computations are possible [1],[2]. Unfortunately, it has been shown that unconditionally secure oblivious transfer is not possible, and that even quantum mechanics cannot help [3], [4]. In fact, the results of Lo actually go further, and show that it is impossible to securely evaluate any one sided two-party computation. Since then it has been an interesting and productive open question to determine the optimal security parameters achievable for some important two-party computations. In this paper we address the theoretical question \How close to ideal can unconditionally secure OT protocols be?" Our paper contains two main contributions: 1. For general 2-round OT protocols, we increase the lower bound on the minimum cheating probabilities achievable for Alice and Bob, i.e. we show that any OT protocol with at most two rounds of (classical or quantum) communication must have a cheating probability of at least 2=3. If the states in the final round of the (honest) protocol are pure, this bound is increased to 0:749. In the case that the final round contains pure states, we extend our 0:749 bound to general N-round OT protocols.
    [Show full text]
  • Mechanics of Mobilecoin: First Edition
    Mechanics of MobileCoin: First Edition exploring the foundations of a private digital currency April 6, 2021, Preview (10/11) v0.0.39 koe1,2 DRAFT INFORMATION: This is just a draft, and may not always be available wher- ever it is currently hosted. The final version will be available at https://github.com/ mobilecoinfoundation. License: `Mechanics of MobileCoin: First Edition' is released into the public domain. 1 [email protected] 2 Author `koe' worked on this document as part of a private contract with, then as an employee of, MobileCoin, Inc. Abstract Cryptography. It may seem like only mathematicians and computer scientists have access to this obscure, esoteric, powerful, elegant topic. In fact, many kinds of cryptography are simple enough that anyone can learn their fundamental concepts. It is common knowledge that cryptography is used to secure communications, whether they be coded letters or private digital interactions. Another application is in so-called cryptocurrencies. These digital moneys use cryptography to assign and transfer ownership of funds. To ensure that no piece of money can be duplicated or created at will, cryptocurrencies usually rely on `blockchains', which are public, distributed ledgers containing records of currency transactions that can be verified by third parties [115]. It might seem at first glance that transactions need to be sent and stored in plain text format to make them publicly verifiable. In truth, it is possible to conceal a transaction's participants, as well as the amounts involved, using cryptographic tools that nevertheless allow transactions to be verified and agreed upon by observers [151]. This is exemplified in the cryptocurrency MobileCoin.
    [Show full text]
  • Perfectly Hiding Commitment Scheme with Two-Round from Any One-Way Permutation ∗
    Perfectly Hiding Commitment Scheme with Two-Round from Any One-Way Permutation ¤ Chunming Tang1;y Dingyi Pei1 Zhuojun Liu2 Zheng-an Yao3 Mingsheng Wang4 1 School of Mathematics and Information Sciences, Guangzhou University, China(510006) 2 Key Laboratory of Mathematics Mechanization, AMSS, CAS, China(100080) 3 School of Mathematics and Statistics, Zhongshan University, China(510006) 4 State Key Laboratory of Information Security, Institute of Software, CAS China(100080) Abstract Commitment schemes are arguably among the most important and useful primitives in cryp- tography. According to the computational power of receivers, commitments can be classi¯ed into three possible types: computational hiding commitments, statistically hiding commitments and perfect computational commitments. The ¯st commitment with constant rounds had been constructed from any one-way functions in last centuries, and the second with non-constant rounds were constructed from any one-way functions in FOCS2006, STOC2006 and STOC2007 respectively, furthermore, the lower bound of round complexity of statistically hiding commit- n ments has been proven to be logn rounds under the existence of one-way function. Perfectly hiding commitments implies statistically hiding, hence, it is also infeasible to con- struct a practically perfectly hiding commitments with constant rounds under the existence of one-way function. In order to construct a perfectly hiding commitments with constant rounds, we have to relax the assumption that one-way functions exist. In this paper, we will construct a practically perfectly hiding commitment with two-round from any one-way permutation. To the best of our knowledge, these are the best results so far. Keywords: Cryptography, perfectly hiding commitments, one-way permutation, §-protocol.
    [Show full text]
  • Generation and Distribution of Quantum Oblivious Keys for Secure Multiparty Computation
    applied sciences Article Generation and Distribution of Quantum Oblivious Keys for Secure Multiparty Computation Mariano Lemus 1,2, Mariana F. Ramos 3,4, Preeti Yadav 1,2, Nuno A. Silva 3,4 , Nelson J. Muga 3,4 , André Souto 2,5,6,* , Nikola Paunkovi´c 1,2 , Paulo Mateus 1,2 and Armando N. Pinto 3,4 1 Departamento de Matemática, Instituto Superior Técnico, Av. Rovisco Pais 1, 1049-001 Lisboa, Portugal; [email protected] (M.L.); [email protected] (P.Y.); [email protected] (N.P.); [email protected] (P.M.) 2 Instituto de Telecomunicações, Av. Rovisco Pais 1, 1049-001 Lisboa, Portugal 3 Departamento de Eletrónica, Telecomunicações e Informática, Universidade de Aveiro, Campus Universitário de Santiago, 3810-193 Aveiro, Portugal; [email protected] (M.F.R.); [email protected] (N.A.S.); [email protected] (N.J.M.); [email protected] (A.N.P.) 4 Instituto de Telecomunicações, Campus Universitário de Santiago, 3810-193 Aveiro, Portugal 5 Departamento de Informática, Faculdade de Ciências da Universidade de Lisboa, Campo Grande 016, 1749-016 Lisboa, Portugal 6 LASIGE, Faculdade de Ciências da Universidade de Lisboa, Campo Grande 016, 1749-016 Lisboa, Portugal * Correspondence: [email protected] Received: 15 May 2020; Accepted: 10 June 2020; Published: 12 June 2020 Featured Application: Private data mining. Abstract: The oblivious transfer primitive is sufficient to implement secure multiparty computation. However, secure multiparty computation based on public-key cryptography is limited by the security and efficiency of the oblivious transfer implementation. We present a method to generate and distribute oblivious keys by exchanging qubits and by performing commitments using classical hash functions.
    [Show full text]
  • Quantum Bit Commitment and Coin Tossing Protocols
    Quantum Bit Commitment and Coin Tossing Protocols Gilles Brassard * Claude Crepeau t Departement d'informatique et de R.O. Laboratoire de Recherche en Informatique Universite de Montreal University de Paris-Sud C.P. 6128, succ. "A" Batiment 490 Montreal, Quebec CANADA H3C 3J7 91405 Orsay FRANCE 1 Introduction In the late 1960's a physicist, Stephen Wiesner, had the idea that the uncertainty principle could be used for cryptography (though he published his result much later [Wie83]). One of his ideas was that it would be possible to use a stream of polarized photons to transmit two messages in a way that would make only one of them readable at the receiver's choosing. This notion, which he called "multiplexing", is remarkably similar to the "one-out-of-two oblivious transfer" to be reinvented many years later [EGL83], and it even predates Rabin's notion of oblivious transfer [Rab81] by more than a decade. In the late 1970's, Wiesner's invention was brought back to life by the work of Charles H. Bennett and Gilles Brassard, which resulted in a CRYPTO '82 paper [BBBW82]. Subsequently, Bennett and Brassard used quantum cryptographic principles to implement basic cryptographic protocols, such as secret key exchange and coin tossing by telephone [BB84]. There has been recently much excitement in the field of quantum cryptography because a working prototype of the quantum key exchange channel has been successfully built at the IBM T. J. Watson Research Laboratory, Yorktown Heights [BBBSS90]. In recent times, the importance of cryptographic primitives has been brought to light by the work of many researchers whose goal is to characterize precisely the primitives sufficient for the implementation of various cryptographic protocols.
    [Show full text]
  • A Review on Quantum Cryptography and Quantum Key Distribution
    3rd International Conference on Multidisciplinary Research & Practice P a g e | 463 A Review on Quantum Cryptography and Quantum Key Distribution Ritu Rani Lecturer, Department of Physics, CRM Jat College, Hisar Abstract: - Quantum cryptography uses our current knowledge key. The main disadvantage of a secret-key cryptosystem is of physics to develop a cryptosystem that is not able to be related to the exchange of keys. Symmetric encryption is defeated - that is, one that is completely secure against being based on the exchange of a secret (keys). Secret key compromised without knowledge of the sender or the receiver of cryptography systems are often classified to be either stream the messages. Quantum cryptography promises to reform secure ciphers or block ciphers. Stream ciphers work on a single bit communication by providing security based on the elementary laws of physics, instead of the current state of mathematical at a time and also use some kind of feedback mechanism so algorithms or computing technology. This paper describes an that the key changes regularly. The goal of position-based overview about Quantum cryptography and Quantum key quantum cryptography is to use the geographical location of a distribution technology, and how this technology contributes to player as its (only) credential. A quantum cryptographic the network security. protocol is device-independent if its security does not rely on Keywords:- Quantum cryptography, public-key encryption, trusting that the quantum devices used are truthful. Thus the Secret key encryption, Quantum key distribution technology security analysis of such a protocol needs to consider scenarios of imperfect or even malicious devices.
    [Show full text]
  • A New and Efficient Signature on Commitment Values
    International Journal of Network Security, Vol.7, No.1, PP.101–106, July 2008 101 A New and Efficient Signature on Commitment Values Fangguo Zhang1,3, Xiaofeng Chen2,3, Yi Mu4, and Willy Susilo4 (Corresponding author: Fangguo Zhang) Department of Electronics and Communication Engineering, Sun Yat-Sen University1 Guangzhou 510275, P. R. China (Email: [email protected]) Department of Computer Science, Sun Yat-Sen University, Guangzhou 510275, P. R. China2 Guangdong Key Laboratory of Information Security Technology Guangzhou 510275, P. R. China3 School of IT and Computer Science University of Wollongong, Wollongong, NSW 2522, Australia4 (Received July 15, 2006; revised and accepted Nov. 8, 2006) Abstract user, it cannot be transferred to any one else, i.e. “non- transferability”. It is desirable that the overheads of com- We present a new short signature scheme based on a vari- munication and computation imposed by a credential sys- ant of the Boneh-Boyen’s short signatures schemes. Our tem to users and services must not heavily affect their short signature scheme is secure without requiring the performance. random oracle model. We show how to prove a commit- The studies of anonymous credential have gone through ted value embedded in our short signature. Using this several stages. After its introduction by Chaum, Brands primitive, we construct an efficient anonymous credential presented a public key based construction of anonymous system. credential in which a user can provide in zero knowledge Keywords: Anonymity, anonymous credentials, commit- that the credentials encoded by its certificate satisfy a ment, signature given linear Boolean formula [6]. This scheme allows only one show, namely, two transactions from the same user can be found performed by the same user.
    [Show full text]
  • One-Way Functions Imply Secure Computation in a Quantum World
    One-Way Functions Imply Secure Computation in a Quantum World James Bartusek* Andrea Coladangelo† Dakshita Khurana‡ Fermi Ma§ Abstract We prove that quantum-hard one-way functions imply simulation-secure quantum oblivious transfer (QOT), which is known to suffice for secure computation of arbitrary quantum functionalities. Further- more, our construction only makes black-box use of the quantum-hard one-way function. Our primary technical contribution is a construction of extractable and equivocal quantum bit commit- ments based on the black-box use of quantum-hard one-way functions in the standard model. Instantiating the Crépeau-Kilian (FOCS 1988) framework with these commitments yields simulation-secure QOT. arXiv:2011.13486v2 [quant-ph] 13 Aug 2021 *UC Berkeley. Email: [email protected] †UC Berkeley. Email: [email protected] ‡UIUC. Email: [email protected] §Princeton University and NTT Research. Email: [email protected] 1 Contents 1 Introduction 3 1.1 OurResults ...................................... ......... 4 1.2 RelatedWork ..................................... ......... 6 1.3 ConcurrentandIndependentWork. .............. 6 2 Technical Overview 8 2.1 Recap: Quantum Oblivious Transfer from Commitments . .................. 8 2.2 Our Construction: A High-Level Overview . ................ 10 2.3 Making Any Quantum (or Classical) Commitment Equivocal ................... 11 2.4 An Extractability Compiler for Equivocal Commitments . .................... 13 2.5 Putting it Together: From Commitments to Secure Computation.
    [Show full text]
  • Practical and Provably-Secure Commitment Schemes from Collision-Free Hashing
    Practical and Provably-Secure Commitment Schemes from Collision-Free Hashing Shai Halevi ? Silvio Micali MIT { Laboratory for Computer Science, 545 Technology Square, Cambridge, MA 02139 Abstract. We present a very practical string-commitment scheme which is provably secure based solely on collision-free hashing. Our scheme en- ables a computationally bounded party to commit strings to an unbounded one, and is optimal (within a small constant factor) in terms of interac- tion, communication, and computation. Our result also proves that constant round statistical zero-knowledge arguments and constant-round computational zero-knowledge proofs for NP exist based on the existence of collision-free hash functions. 1 Introduction String commitment is a fundamental primitive for cryptographic protocols. A commitment scheme is an electronic way to temporarily hide a value that cannot be changed. Such a scheme emulates by means of a protocol the following two- stage process. In Stage 1 (the Commit stage), a party called the Sender locks a message in a box, and sends the locked box to another party called the receiver. In Stage 2 (the De-commit stage), the Sender provides the Receiver with the key to the box, thus enabling him to learn the original message. Commitment-schemes are very useful building blocks in the design of larger cryptographic protocols. They are typically used as a mean of flipping fair coins between two players, and also play a crucial part in some zero-knowledge proofs and in various types of signature schemes. Commitment schemes can also be used in scenarios like bidding for a contract, where committing to a bid rather than sending it in the clear can eliminate the risk of it being \leaked" to the competitors.
    [Show full text]
  • Ring Confidential Transactions
    ISSN 2379-5980 (online) DOI 10.5195/LEDGER.2016.34 RESEARCH ARTICLE Ring Confidential Transactions Shen Noether,∗ Adam Mackenzie, the Monero Research Lab† Abstract. This article introduces a method of hiding transaction amounts in the strongly decentralized anonymous cryptocurrency Monero. Similar to Bitcoin, Monero is a cryptocur- rency which is distributed through a proof-of-work “mining” process having no central party or trusted setup. The original Monero protocol was based on CryptoNote, which uses ring signatures and one-time keys to hide the destination and origin of transactions. Recently the technique of using a commitment scheme to hide the amount of a transaction has been dis- cussed and implemented by Bitcoin Core developer Gregory Maxwell. In this article, a new type of ring signature, A Multilayered Linkable Spontaneous Anonymous Group signature is described which allows one to include a Pedersen Commitment in a ring signature. This construction results in a digital currency with hidden amounts, origins and destinations of transactions with reasonable efficiency and verifiable, trustless coin generation. The author would like to note that early drafts of this were publicized in the Monero Community and on the #bitcoin-wizards IRC channel. Blockchain hashed drafts are available showing that this work was started in Summer 2015, and completed in early October 2015.17 An eprint is also available at http://eprint.iacr.org/2015/1098. 1. Introduction Recall that in Bitcoin each transaction is signed by the owner of the coins being sent and these signatures verify that the owner is allowed to send the coins. This is entirely analogous to the signing of a check from your bank.
    [Show full text]
  • Oblivious Transfer of Bits
    Oblivious transfer of bits Abstract. We consider the topic Oblivious transfer of bits (OT), that is a powerful primitive in modern cryptography. We can devide our project into these parts: In the first part: We would clarify the definition OT, we would give a precise characterization of its funcionality and use. Committed oblivious transfer (COT) is an enhancement involving the use of commitments, which can be used in many applications of OT covering particular malicious adversarial behavior, it cannot be forgotten. In the second part: We would describe the history of some important discoveries, that preceded present knowledge in this topic. Some famous discovers as Michael O. Rabin or Claude Crépeau could be named with their works. In the third part: For OT, many protocols covering the transfer of bits are known, we would introduce and describe some of them. The most known are Rabin's oblivious transfer protocol, 1-2 oblivious transfer, 1-n oblivious transfer. These would be explained with examples. In the fourth part: We also need to discuss the security of the protocols and attacs, that are comitted. Then security of mobile computing. In the fifth part: For the end, we would give some summary, also interests or news in this topic, maybe some visions to the future evolution. 1 Introduction Oblivious transfer of bits (often abbreviated OT) is a powerful primitive in modern cryptography especially in the context of multiparty computation where two or more parties, mutually distrusting each other, want to collaborate in a secure way in order to achieve a common goal, for instance, to carry out an electronic election, so this is its applicability.
    [Show full text]
  • Ringct 2.0: a Compact Accumulator-Based (Linkable Ring Signature) Protocol for Blockchain Cryptocurrency Monero
    RingCT 2.0: A Compact Accumulator-Based (Linkable Ring Signature) Protocol for Blockchain Cryptocurrency Monero Shi-Feng Sun1;2, Man Ho Au1 ?, Joseph K. Liu3, Tsz Hon Yuen4, Dawu Gu2 1Hong Kong Polytechnic University, Hong Kong E-mail: csssun,[email protected] 2Shanghai Jiao Tong University, China E-mail: [email protected] 3Monash University, Australia E-mail: [email protected] 4 Huawei, Singapore E-mail: [email protected] Abstract. In this work, we initially study the necessary properties and security re- quirements of Ring Confidential Transaction (RingCT) protocol deployed in the pop- ular anonymous cryptocurrency Monero. Firstly, we formalize the syntax of RingCT protocol and present several formal security definitions according to its application in Monero. Based on our observations on the underlying (linkable) ring signature and commitment schemes, we then put forward a new efficient RingCT protocol (RingCT 2.0), which is built upon the well-known Pedersen commitment, accumu- lator with one-way domain and signature of knowledge (which altogether perform the functions of a linkable ring signature). Besides, we show that it satisfies the secu- rity requirements if the underlying building blocks are secure in the random oracle model. In comparison with the original RingCT protocol, our RingCT 2.0 protocol presents a significant space saving, namely, the transaction size is independent of the number of groups of input accounts included in the generalized ring while the original RingCT suffers a linear growth with the number of groups, which would allow each block to process more transactions. 1 Introduction 1.1 Monero: A Blockchain-based Cryptocurrency A cryptocurrency is a digital asset designed to work as a medium of exchange using cryp- tography to secure the transactions and to control the creation of additional units of the currency.
    [Show full text]