i-TiRE: Incremental Timed-Release Encryption or How to use Timed-Release Encryption on Blockchains?
Leemon Baird, Pratyay Mukherjee, Rohit Sinha
Abstract
Timed-release encryption can encrypt a message to a future time such that it can only be decrypted after that time. Potential applications include sealed bid auctions, scheduled con dential transactions, and digital time capsules. To enable such applications as decentralized smart contracts, we explore how to use timed-release encryption on blockchains. Practical constructions in the literature rely on a trusted server (or servers in a threshold setting), which periodically publishes an epoch-speci c decryption key based on a long-term secret. Their main idea is to model time periods or epochs as identities in an identity-based encryption scheme. However, these schemes su er from a fatal aw: an epoch's key does not let us decrypt ciphertexts locked to prior epochs. Paterson and Quaglia [SCN'10] address this concern by having encryption specify a range of epochs when decryption is allowed. However, we are left with an e ciency concern: in each epoch, the server(s) must publish (via a smart contract transaction) a decryption key of size logarithmic in the lifetime (total number of epochs). For instance, on Ethereum, for a modest lifetime spanning 2 years of 1-minute long epochs, a server must spend over 0.30 in the above setting. Moreover, ciphertexts are also compact (logarithmic in the total lifetime), and encryption and decryption are on the order of few milliseconds. Furthermore, we decentralize the trust among a number of servers, so as to tolerate up to a threshold number of (malicious) corruptions. Our construction is based on bilinear pairing, and adapts ideas from Canetti et al.'s binary tree encryption [Eurocypt 2003] and Naor et al. 's distributed pseudorandom functions [Eurocrypt 1999].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c3607184-5074-487d-a867-ae589a890f05Cited by top-tier papers1
Ask how each one uses itBuilds on2
Related papers
- Efficient Batch Threshold Encryption Using Partial Fraction TechniquesDan Boneh, Rohit Nema, Arnab Roy, Ertem Nusret TasCRYPTO 2026 · 1 citation
- Riggs: Decentralized Sealed-Bid AuctionsNirvan Tyagi, Arasu Arun, Cody Freitag, Riad S. Wahby et al.CCS 2023 · 15 citations
- OpenSquare: Decentralized Repeated Modular Squaring ServiceSri Aravinda Krishnan Thyagarajan, Tiantian Gong, Adithya Bhat, Aniket Kate et al.CCS 2021
- Resilient Alerting Protocols for BlockchainsMarwa Mouallem, Lorenz Breidenbach, Ittay Eyal, Ari JuelsCCS 2026
- BEAST-MEV: Batched Threshold Encryption with Silent Setup for MEV preventionJan Bormet, Arka Rai Choudhuri, Sebastian Faust, Sanjam Garg et al.CCS 2026 · 12 citations
