Privacy Aspects and Subliminal Channels in Zcash
Alex Biryukov, Daniel Feher, Giuseppe Vitto
Abstract
In this paper we analyze two privacy and security issues for the privacy-oriented cryptocurrency Zcash. First we study shielded transactions and show ways to fingerprint user transactions, including active attacks. We introduce two new attacks which we call Danaan-gift attack and Dust attack. Following the recent Sapling update of Zcash protocol we study the interaction between the new and the old zk-SNARK protocols and the effects of their interaction on transaction privacy. In the second part of the paper we check for the presence of subliminal channels in the zk-SNARK protocol and in Pedersen Commitments. We show presence of efficient 70-bit channels which could be used for tagging of shielded transactions which would allow the attacker (malicious transaction verifier) to link transactions issued by a maliciously modified zk-SNARK prover, while would be indistinguishable from regular transactions for the honest verifier/user. We discuss countermeasures against both of these privacy issues. CCS CONCEPTS • Security and privacy → Distributed systems security; Privacypreserving protocols; Cryptanalysis and other attacks; • General and reference → Empirical studies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9e8a8f8a-2410-4bcf-9f37-7c56ffecb841Cited by top-tier papers4
- On How Zero-Knowledge Proof Blockchain Mixers Improve, and Worsen User PrivacyZhipeng Wang, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou et al.WWW 2023 · 69 citations
- On the Anonymity Guarantees of Anonymous Proof-of-Stake ProtocolsMarkulf Kohlweiss, Varun Madathil, Kartik Nayak, Alessandra ScafuroS&P 2021 · 13 citations
- Aardvark: An Asynchronous Authenticated Dictionary with Applications to Account-based CryptocurrenciesDerek Leung, Yossi Gilad, Sergey Gorbunov, Leonid Reyzin et al.USENIX Security 2022
- Remote Side-Channel Attacks on Anonymous TransactionsFlorian Tramèr, Dan Boneh, Kenny PatersonUSENIX Security 2020
Builds on1
Related papers
- Breaking and Fixing Virtual Channels: Domino Attack and DonnerLukas Aumayr, Pedro Moreno-Sanchez, Aniket Kate, Matteo MaffeiNDSS 2023
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy et al.USENIX Security 2021 · 410 citations
- Ouroboros Crypsinous: Privacy-Preserving Proof-of-StakeThomas Kerber, Aggelos Kiayias, Markulf Kohlweiss, Vassilis ZikasS&P 2019 · 82 citations
- Spartan and Bulletproofs are Simulation-Extractable (for Free!)Quang Dao, Paul GrubbsEUROCRYPT 2023 · 26 citations
- Curve Trees: Practical and Transparent Zero-Knowledge AccumulatorsMatteo Campanelli, Mathias Hall-Andersen, Simon Holmgaard KampUSENIX Security 2023
