Zerocash: Decentralized Anonymous Payments from Bitcoin

被引:1039
作者
Ben-Sasson, Eli [1 ]
Chiesa, Alessandro [2 ]
Garmant, Christina [3 ]
Green, Matthew [3 ]
Miers, Ian [3 ]
Tromer, Eran [4 ]
Virza, Madars [2 ]
机构
[1] Technion, Haifa, Israel
[2] MIT, Cambridge, MA 02139 USA
[3] Johns Hopkins Univ, Baltimore, MD 21218 USA
[4] Tel Aviv Univ, Tel Aviv, Israel
来源
2014 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2014) | 2014年
关键词
Bitcoin; decentralized electronic cash; zero knowledge;
D O I
10.1109/SP.2014.36
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Bitcoin is the first digital currency to see widespread adoption. While payments are conducted between pseudonyms, Bitcoin cannot offer strong privacy guarantees: payment transactions are recorded in a public decentralized ledger, from which much information can be deduced. Zerocoin (Miers et al., IEEE S&P 2013) tackles some of these privacy issues by unlinking transactions from the payment's origin. Yet, it still reveals payments' destinations and amounts, and is limited in functionality. In this paper, we construct a full-fledged ledger-based digital currency with strong privacy guarantees. Our results leverage recent advances in zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARKs). First, we formulate and construct decentralized anonymous payment schemes (DAP schemes). A DAP scheme enables users to directly pay each other privately: the corresponding transaction hides the payment's origin, destination, and transferred amount. We provide formal definitions and proofs of the construction's security. Second, we build Zerocash, a practical instantiation of our DAP scheme construction. In Zerocash, transactions are less than 1 kB and take under 6 ms to verify orders of magnitude more efficient than the less-anonymous Zerocoin and competitive with plain Bitcoin.
引用
收藏
页码:459 / 474
页数:16
相关论文
共 34 条
  • [1] [Anonymous], PROPOSED BIP DEALING
  • [2] [Anonymous], SEC 1 ELL CURV CRYPT
  • [3] Barber S., FC 12
  • [4] Bellare M., CRYPTO 06
  • [5] Bellare M., ASIACRYPT 01
  • [6] Ben-Sasson E., 2013879 EPRINT
  • [7] Ben-Sasson E., 2013, BITCOIN 2013 FUTURE
  • [8] Ben-Sasson E., 2014, CRYPTOLOGY EPRINT AR
  • [9] Ben-Sasson E., CRYPTO 13
  • [10] Bitansky N., TCC 13