Many-out-of-Many Proofs and Applications to Anonymous Zether
Benjamin E. Diamond
Abstract
Anonymous Zether, proposed by Bünz, Agrawal, Zamani, and Boneh (FC'20), is a private payment design whose wallets demand little bandwidth and need not remain online; this unique property makes it a compelling choice for resource-constrained devices. In this work, we describe an efficient construction of Anonymous Zether. Our protocol features proofs which grow only logarithmically in the size of the "anonymity sets" used, improving upon the linear growth attained by prior efforts. It also features competitive transaction sizes in practice (on the order of 3 kilobytes). Our central tool is a new family of extensions to Groth and Kohlweiss's one-out-of-many proofs (Eurocrypt 2015), which efficiently prove statements about many messages among a list of commitments. These extensions prove knowledge of a secret subset of a public list, and assert that the commitments in the subset satisfy certain properties (expressed as linear equations). Remarkably, our communication remains logarithmic; our computation increases only by a logarithmic multiplicative factor. This technique is likely to be of independent interest. We present an open-source, Ethereum-based implementation of our Anonymous Zether construction. * I would like to thank Markulf Kohlweiss and Michele Ciampi for many helpful discussions and suggestions. Overview of our contribution One-out-of-many proofs, introduced by Groth and Kohlweiss [GK15], allow a prover to demonstrate knowledge of a secret element among a public list of commitments, together with an opening of this commitment
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e4cbdfec-4d63-43e4-aed2-55b883a825efCited by top-tier papers9
- ZeeStar: Private Smart Contracts by Homomorphic Encryption and Zero-knowledge ProofsSamuel Steffen, Benjamin Bichsel, Roger Baumgartner, Martin T. VechevS&P 2022 · 64 citations
- Zapper: Smart Contracts with Data and Identity PrivacySamuel Steffen, Benjamin Bichsel, Martin T. VechevCCS 2022 · 17 citations
- Riggs: Decentralized Sealed-Bid AuctionsNirvan Tyagi, Arasu Arun, Cody Freitag, Riad S. Wahby et al.CCS 2023 · 15 citations
- mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-OptimalHongxiao Wang, Ron Steinfeld, Markku-Juhani O. Saarinen, Muhammed F. Esgin et al.USENIX Security 2026 · 2 citations
- FC-GUARD: Enabling Anonymous yet Compliant Fiat-to-Cryptocurrency ExchangesShaoyu Li, Hexuan Yu, Md Mohaimin Al Barat, Yang Xiao et al.INFOCOM 2026 · 1 citation
Builds on3
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- FlyClient: Super-Light Clients for CryptocurrenciesBenedikt Bünz, Lucianna Kiffer, Loi Luu, Mahdi ZamaniS&P 2020 · 151 citations
- MatRiCT: Efficient, Scalable and Post-Quantum Blockchain Confidential Transactions ProtocolMuhammed F. Esgin, Raymond K. Zhao, Ron Steinfeld, Joseph K. Liu et al.CCS 2019 · 104 citations
Related papers
- k-out-of-n Proofs and Applications to Privacy-Preserving CryptocurrenciesMin Zhang, Yu Chen, Xiyuan FuEUROCRYPT 2026
- PriDe CT: Towards Public Consensus, Private Transactions, and Forward Secrecy in Decentralized PaymentsYue Guo, Harish Karthikeyan, Antigoni Polychroniadou, Chaddy HuussinS&P 2024 · 7 citations
- Compressing Proofs of k-Out-Of-n Partial KnowledgeThomas Attema, Ronald Cramer, Serge FehrCRYPTO 2021 · 42 citations
- Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsTianyu Zheng, Shang Gao, Yubo Song, Bin XiaoS&P 2023
- Lether: Practical Post-Quantum Account-Based Private Blockchain PaymentsHongxiao Wang, Muhammed F. Esgin, Ron Steinfeld, Siu-Ming YiuCCS 2026
