Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for Services
Matteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca Nizzardo
摘要
Zero Knowledge Contingent Payment (ZKCP) protocols allow fair exchange of sold goods and payments over the Bitcoin network. In this paper we point out two main shortcomings of current proposals for ZKCP, and propose ways to address them. First we show an attack that allows a buyer to learn partial information about the digital good being sold, without paying for it. This break in the zero-knowledge condition of ZKCP is due to the fact that in the protocols we attack, the buyer is allowed to choose common parameters that normally should be selected by a trusted third party. We implemented and tested this attack: we present code that learns, without paying, the value of a Sudoku cell in the "Pay-to-Sudoku" ZKCP implementation [18] . We also present ways to fix this attack that do not require a trusted third party. Second, we show that ZKCP are not suited for the purchase of digital services rather than goods. Current constructions of ZKCP do not allow a seller to receive payments after proving that a certain service has been rendered, but only for the sale of a specific digital good. We define the notion of Zero-Knowledge Contingent Service Payment (ZKCSP) protocols and construct two new protocols, for either public or private verification. We implemented our ZKCSP protocols for Proofs of Retrievability, where a client pays the server for providing a proof that the client's data is correctly stored by the server.We also implement a secure ZKCP protocol for "Pay-to-Sudoku" via our ZKCSP protocol, which does not require a trusted third party. A side product of our implementation effort is a new optimized circuit for SHA256 with less than a quarter than the number of AND gates of the best previously publicly available one. Our new SHA256 circuit may be of independent use for circuit-based MPC and FHE protocols that require SHA256 circuits. Zero-Knowledge Contingent Service Payments (ZKCSP): paying for digital services We extend the idea of ZKCP to a new class of problems: paying for digital services. Consider Alice, a user of a subscription online file storage service, FileBox. FileBox offers a service that for a small fee, it will provide a succinct proof-of-retrievability (PoR) [43] to its users demonstrating that all of that user's files are being stored. Alice would like to pay for this service, and thus we have a far exchange problem: Alice wants to pay once she receives proof that the files are being stored, whereas FileBox will only send the proof once it has been paid.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper23
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra 等S&P 2018 · 被引用 1,285 次
- Arbitrum: Scalable, private smart contractsHarry A. Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matthew Weinberg 等USENIX Security 2018 · 被引用 353 次
- Transparent Polynomial Delegation and Its Applications to Zero Knowledge ProofJiaheng Zhang, Tiancheng Xie, Yupeng Zhang, Dawn SongS&P 2020 · 被引用 192 次
- DECO: Liberating Web Data Using Decentralized Oracles for TLSFan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder 等CCS 2020 · 被引用 110 次
- MAD-HTLC: Because HTLC is Crazy-Cheap to AttackItay Tsabary, Matan Yechieli, Alex Manuskin, Ittay EyalS&P 2021 · 被引用 87 次
相关 Paper
- WI Is Not Enough: Zero-Knowledge Contingent (Service) Payments RevisitedGeorg FuchsbauerCCS 2019 · 被引用 37 次
- ZKCPlus: Optimized Fair-exchange Protocol Supporting Practical and Flexible Data ExchangeYun Li, Cun Ye, Yuguang Hu, Ivring Morpheus 等CCS 2021 · 被引用 26 次
- WI is Almost Enough: Contingent Payment All Over AgainKy Nguyen, Miguel Ambrona, Masayuki AbeCCS 2020 · 被引用 13 次
- GZKP: A GPU Accelerated Zero-Knowledge Proof SystemWeiliang Ma, Qian Xiong, Xuanhua Shi, Xiaosong Ma 等ASPLOS 2023 · 被引用 47 次
- DIZK: A Distributed Zero Knowledge Proof SystemHoward Wu, Wenting Zheng, Alessandro Chiesa, Raluca Ada Popa 等USENIX Security 2018 · 被引用 152 次
