PriDe CT: Towards Public Consensus, Private Transactions, and Forward Secrecy in Decentralized Payments
Yue Guo, Harish Karthikeyan, Antigoni Polychroniadou, Chaddy Huussin
Abstract
Anonymous Zether, proposed by Bünz et al. (FC, 2020) and subsequently improved by Diamond (IEEE S&P, 2021) is an account-based confidential payment mechanism that works by using a smart contract to achieve privacy (i.e. identity of receivers to transactions and payloads are hidden). In this work, we look at simplifying the existing protocol while also achieving batching of transactions for multiple receivers, while ensuring consensus and forward secrecy. To the best of our knowledge, this work is the first to formally study the notion of forward secrecy in the setting of blockchain, borrowing a very popular and useful idea from the world of secure messaging. Specifically, we introduce:•FUL-Zether, a forward-secure version of Zether (Bünz et al. , FC, 2020),•PRIvate DEcentralized Confidential Transactions (PriDe CT), a much-simplified version of Anonymous Zether that achieves competitive performance and enables batching of transactions for multiple receivers.•PRIvate DEcentralized Forward-secure Until Last update Confidential Transactions (PriDeFUL CT), a forward-secure version of PriDe CT.We also present an open-source, Ethereum-based implementation of our system. PriDe CT uses linear homomor-phic encryption as Anonymous Zether but with simpler zero-knowledge proofs. PriDeFUL CT uses an updatable public key encryption scheme to achieve forward secrecy by introducing a new DDH-based construction in the standard model.In terms of transaction sizes, Quisquis (Asiacrypt, 2019), which is the only cryptocurrency that supports batchability (albeit in the UTXO model), has 15 times more group elements than PriDe CT. Meanwhile, for a ring of N receivers, Anonymous Zether requires 6 log N more terms even without accounting for the ability to batch in PriDe CT. Further, our implementation indicates that, for N = 32, even if there were 7 intended receivers, PriDe CT outperforms Anonymous Zether in proving time and gas consumption.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-OptimalHongxiao Wang, Ron Steinfeld, Markku-Juhani O. Saarinen, Muhammed F. Esgin et al.USENIX Security 2026 · 2 citations
- Lether: Practical Post-Quantum Account-Based Private Blockchain PaymentsHongxiao Wang, Muhammed F. Esgin, Ron Steinfeld, Siu-Ming YiuCCS 2026
Related papers
- k-out-of-n Proofs and Applications to Privacy-Preserving CryptocurrenciesMin Zhang, Yu Chen, Xiyuan FuEUROCRYPT 2026
- Many-out-of-Many Proofs and Applications to Anonymous ZetherBenjamin E. DiamondS&P 2021 · 38 citations
- Practical Mempool Privacy via One-time Setup Batched Threshold EncryptionArka Rai Choudhuri, Sanjam Garg, Guru-Vamsi Policharla, Mingyuan WangUSENIX Security 2025
- Efficiently-Thresholdizable Batched Identity Based Encryption, with ApplicationsAmit Agarwal, Rex Fernando, Benny PinkasCRYPTO 2025 · 12 citations
- Mempool Privacy via Batched Threshold Encryption: Attacks and DefensesArka Rai Choudhuri, Sanjam Garg, Julien Piet, Guru-Vamsi PolicharlaUSENIX Security 2024 · 41 citations
