USENIX Security2026Top-tier venue
Just One Bit Vector: Complement-Free Ring Confidential Transactions with Transparent Setup
Hao Gao, Qianhong Wu, Bo Qin, Fudong Wu, Zhenyang Ding
Abstract
Ring Confidential Transactions (RingCTs) rely on their signature schemes to ensure transaction validity while preserving user privacy. In the discrete-logarithm setting, state-of-theart RingCT signatures leverage Bulletproof as their backbone. In this work, we conduct a thorough analysis of existing Bulletproof-based RingCT signatures and identify two pervasive sources of inefficiency: (i) redundant complement advice induced by binary constraints, and (ii) substantial overhead incurred by defenses against the Knowledge-of-Known-Discrete-Logarithm (KKDL) issue. We present new techniques that eliminate the first inefficiency and significantly reduce the second. We introduce the Weighted-Norm Inner Linear Argument (WNILA) as a new compression pivot and leverage it to design zero-knowledge proofs that capture constraints arising in RingCT without introducing complement advice. We then adopt the techniques of Omniring and Lin et al. to unify the K-Weight and K-Link techniques proposed by ZGSX23 and BulletCT. Building on this framework, we derive three RingCT signature schemes: UniBit, UniBit + , and UniBitRange. We implement all three schemes and benchmark them against BulletCT and Omniring ⋆ under practical parameter regimes. Our experimental results demonstrate 2.5-40× improvements in signing and verification speed over Omniring ⋆ , and 1.6-2.3× signing speedups together with up to 1.65× verification speedup over BulletCT, while achieving comparable signature sizes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 807c26dd-3b7b-46b5-bbce-f1d70de6acceBuilds on6
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Bulletproofs++: Next Generation Confidential Transactions via Reciprocal Set Membership ArgumentsLiam Eagen, Sanket Kanjalkar, Tim Ruffing, Jonas NickEUROCRYPT 2024 · 14 citations
- Omniring: Scaling Private Payments Without Trusted SetupRussell W. F. Lai, Viktoria Ronge, Tim Ruffing, Dominique Schröder et al.CCS 2019 · 1 citation
- BulletCT: Towards More Scalable Ring Confidential Transactions With Transparent SetupNan Wang, Qianhui Wang, Dongxi Liu, Muhammed F. Esgin et al.USENIX Security 2025
- Ring Referral: Efficient Publicly Verifiable Ad hoc Credential Scheme with Issuer and Strong User Anonymity for Decentralized Identity and MoreThe-Anh Ta, Xiangyu Hui, Sid Chi-Kin ChauS&P 2025
Related papers
- Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsTianyu Zheng, Shang Gao, Yubo Song, Bin XiaoS&P 2023
- SwiftRange: A Short and Efficient Zero-Knowledge Range Argument For Confidential Transactions and MoreNan Wang, Sid Chi-Kin Chau, Dongxi LiuS&P 2024 · 13 citations
- DualRing: Generic Construction of Ring Signatures with Efficient InstantiationsTsz Hon Yuen, Muhammed F. Esgin, Joseph K. Liu, Man Ho Au et al.CRYPTO 2021 · 83 citations
- MatRiCT: Efficient, Scalable and Post-Quantum Blockchain Confidential Transactions ProtocolMuhammed F. Esgin, Raymond K. Zhao, Ron Steinfeld, Joseph K. Liu et al.CCS 2019 · 104 citations
- A Holistic Security Analysis of Monero TransactionsCas Cremers, Julian Loss, Benedikt WagnerEUROCRYPT 2024 · 4 citations
