zkay: Specifying and Enforcing Data Privacy in Smart Contracts
Samuel Steffen, Benjamin Bichsel, Mario Gersbach, Noa Melchior, Petar Tsankov, Martin T. Vechev
Abstract
Privacy concerns of smart contracts are a major roadblock preventing their wider adoption. A promising approach to protect private data is hiding it with cryptographic primitives and then enforcing correctness of state updates by Non-Interactive Zero-Knowledge (NIZK) proofs. Unfortunately, NIZK statements are less expressive than smart contracts, forcing developers to keep some functionality in the contract. This results in scattered logic, split across contract code and NIZK statements, with unclear privacy guarantees. To address these problems, we present the zkay language, which introduces privacy types defining owners of private values. zkay contracts are statically type checked to (i) ensure they are realizable using NIZK proofs and (ii) prevent unintended information leaks. Moreover, the logic of zkay contracts is easy to follow by just ignoring privacy types. To enforce zkay contracts, we automatically transform them into contracts equivalent in terms of privacy and functionality, yet executable on public blockchains. We evaluated our approach on a proof-of-concept implementation generating Solidity contracts and implemented 10 interesting example contracts in zkay. Our results indicate that zkay is practical: On-chain cost for executing the transformed contracts is around 1M gas per transaction ( 0.50US$) and off-chain cost is moderate.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- ZeeStar: Private Smart Contracts by Homomorphic Encryption and Zero-knowledge ProofsSamuel Steffen, Benjamin Bichsel, Roger Baumgartner, Martin T. VechevS&P 2022 · 64 citations
- Qanaat: A Scalable Multi-Enterprise Permissioned Blockchain System with Confidentiality GuaranteesMohammad Javad Amiri, Boon Thau Loo, Divy Agrawal, Amr El AbbadiVLDB 2022 · 26 citations
- Zapper: Smart Contracts with Data and Identity PrivacySamuel Steffen, Benjamin Bichsel, Martin T. VechevCCS 2022 · 17 citations
- Behavioral simulation for smart contractsSidi Mohamed Beillahi, Gabriela F. Ciocarlie, Michael Emmi, Constantin EneaPLDI 2020 · 15 citations
- Understanding Solidity Event Logging Practices in the WildLantian Li, Yejian Liang, Zhihao Liu, Zhongxing YuFSE 2023 · 13 citations
Builds on9
- Hawk: The Blockchain Model of Cryptography and Privacy-Preserving Smart ContractsAhmed E. Kosba, Andrew Miller, Elaine Shi, Zikai Wen et al.S&P 2016 · 2,201 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Arbitrum: Scalable, private smart contractsHarry A. Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matthew Weinberg et al.USENIX Security 2018 · 353 citations
- Bolt: Anonymous Payment Channels for Decentralized CurrenciesMatthew Green, Ian MiersCCS 2017 · 281 citations
Related papers
- ZENO: A Type-based Optimization Framework for Zero Knowledge Neural Network InferenceBoyuan Feng, Zheng Wang, Yuke Wang, Shu Yang et al.ASPLOS 2024 · 13 citations
- Taypsi: Static Enforcement of Privacy Policies for Policy-Agnostic Oblivious ComputationQianchuan Ye, Benjamin DelawareOOPSLA 2024 · 1 citation
- Jigsaw: Doubly Private Smart ContractsSanjam Garg, Aarushi Goel, Dimitris Kolonelos, Rohit SinhaS&P 2026 · 4 citations
- Ou: Automating the Parallelization of Zero-Knowledge ProtocolsYuyang Sang, Ning Luo, Samuel Judson, Ben Chaimberg et al.CCS 2023 · 2 citations
- AuditPay: Anonymous Payments with Controlled OversightElkana Tovey, Yossi Gilad, Aviv ZoharCCS 2026
