WI is Almost Enough: Contingent Payment All Over Again
Ky Nguyen, Miguel Ambrona, Masayuki Abe
Abstract
The problem of fair exchange consists of interchanging goods between two parties that do not trust each other. Despite known impossibility results, recent works leverage the block-chain and zero-knowledge proofs to implement zero-knowledge contingent payment (zkCP) systems that make fair exchange of digital goods possible. Implementing these systems in a secure and efficient way is a big challenge, as evidenced by several unsuccessful attempts from the literature. Campanelli et al. (ACM CCS 2017) discovered a vulnerability on an existing zkCP proposal based on SNARKs (succinct non-interactive arguments of knowledge) and suggested several repairs. Fuchsbauer (ACM CCS 2019) found a flaw in the mentioned countermeasures. In particular, he showed that witness-indistinguishability (WI) is not sufficient for the zkCP schemes proposed by Campanelli et al. to be secure. In this work, we observe that a slightly stronger notion of WI, that we coin trapdoor subversion WI (tS-WI), rules out Fuchsbauer's attack. We formally define security properties for CP systems and show that, under tS-WI, Campanelli et al.'s proposal indeed satisfies these properties. Additionally, we explore alternative approaches to implement ZK (other than SNARKs) and develop a prototype, using it to demonstrate their potential. Our new ideas result in a protocol to sell ECDSA signatures with contingent payment that can be executed in less than milliseconds over a LAN network.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e1dcf5eb-515f-4731-97c9-5cc3b78d71dcCited by top-tier papers2
- BlindHub: Bitcoin-Compatible Privacy-Preserving Payment Channel Hubs Supporting Variable AmountsXianrui Qin, Shimin Pan, Arash Mirzaei, Zhimei Sui et al.S&P 2023
- A Secure Sequencer and Data Availability Committee for RollupsMargarita Capretto, Martín Ceresa, Antonio Fernández Anta, Pedro Moreno-Sanchez et al.CCS 2025
Related papers
- WI Is Not Enough: Zero-Knowledge Contingent (Service) Payments RevisitedGeorg FuchsbauerCCS 2019 · 37 citations
- ZKCPlus: Optimized Fair-exchange Protocol Supporting Practical and Flexible Data ExchangeYun Li, Cun Ye, Yuguang Hu, Ivring Morpheus et al.CCS 2021 · 26 citations
- Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for ServicesMatteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca NizzardoCCS 2017 · 170 citations
- FairSwap: How To Fairly Exchange Digital GoodsStefan Dziembowski, Lisa Eckey, Sebastian FaustCCS 2018 · 229 citations
- Efficient Proofs of Possession for Legacy SignaturesAnna P. Y. Woo, Alex Ozdemir, Chad Sharp, Thomas Pornin et al.S&P 2025
