Omniring: Scaling Private Payments Without Trusted Setup
Russell W. F. Lai, Viktoria Ronge, Tim Ruffing, Dominique Schröder, Sri Aravinda Krishnan Thyagarajan, Jiafan Wang
摘要
Monero is the largest cryptocurrency with built-in cryptographic privacy features. The transactions are authenticated using zero-knowledge spend proofs, which provide a certain level of anonymity by hiding the source accounts from which the funds are sent among a set of other accounts. Due to its similarities to ring signatures, this core cryptographic component is called Ring Confidential Transactions (RingCT). Because of its practical relevance, several works attempt to analyze the security of RingCT. Since RingCT is rather complex, most of them are either informal, miss fundamental functionalities, or introduce undesirable trusted setup assumptions. Regarding efficiency, Monero currently deploys a scheme in which the size of the spend proof is linear in the ring size. This limits the ring size to only a few accounts, which in turn limits the acquired anonymity significantly and facilitates de-anonymization attacks.
As a solution to these problems, we present the first rigorous formalization of RingCT as a cryptographic primitive. We then propose a generic construction of RingCT and prove it secure in our formal security model. By instantiating our generic construction with new efficient zero-knowledge proofs, we obtain Omniring, a fully-fledged RingCT scheme in the discrete logarithm setting that provides the highest concrete and asymptotic efficiency as of today. Omniring is the first RingCT scheme which 1) does not require a trusted setup or pairing-friendly elliptic curves, 2) has a proof size logarithmic in the size of the ring, and 3) allows to share the same ring between all source accounts in a transaction, thereby enabling significantly improved privacy level without sacrificing performance. Our zero-knowledge proofs rely on novel enhancements to the Bulletproofs framework (S&P 2018), which we believe are of independent interest.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- MatRiCT+: More Efficient Post-Quantum Private Blockchain PaymentsMuhammed F. Esgin, Ron Steinfeld, Raymond K. ZhaoS&P 2022 · 被引用 59 次
- Verifiable Timed Signatures Made PracticalSri Aravinda Krishnan Thyagarajan, Adithya Bhat, Giulio Malavolta, Nico Döttling 等CCS 2020 · 被引用 58 次
- Foundations of Coin Mixing ServicesNoemi Glaeser, Matteo Maffei, Giulio Malavolta, Pedro Moreno-Sanchez 等CCS 2022 · 被引用 37 次
- Lockable Signatures for Blockchains: Scriptless Scripts for All SignaturesSri Aravinda Krishnan Thyagarajan, Giulio MalavoltaS&P 2021 · 被引用 35 次
- A Security Framework for Distributed LedgersMike Graf, Daniel Rausch, Viktoria Ronge, Christoph Egger 等CCS 2021 · 被引用 21 次
它引用的顶会 Paper5
- Hawk: The Blockchain Model of Cryptography and Privacy-Preserving Smart ContractsAhmed E. Kosba, Andrew Miller, Elaine Shi, Zikai Wen 等S&P 2016 · 被引用 2,201 次
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra 等S&P 2018 · 被引用 1,285 次
- TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment HubEthan Heilman, Leen Alshenibr, Foteini Baldimtsi, Alessandra Scafuro 等NDSS 2017 · 被引用 322 次
- P2P Mixing and Unlinkable Bitcoin TransactionsTim Ruffing, Pedro Moreno-Sanchez, Aniket KateNDSS 2017 · 被引用 134 次
- Succinct Arguments for Bilinear Group Arithmetic: Practical Structure-Preserving CryptographyRussell W. F. Lai, Giulio Malavolta, Viktoria RongeCCS 2019 · 被引用 50 次
相关 Paper
- Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsTianyu Zheng, Shang Gao, Yubo Song, Bin XiaoS&P 2023
- A Holistic Security Analysis of Monero TransactionsCas Cremers, Julian Loss, Benedikt WagnerEUROCRYPT 2024 · 被引用 4 次
- Just One Bit Vector: Complement-Free Ring Confidential Transactions with Transparent SetupHao Gao, Qianhong Wu, Bo Qin, Fudong Wu 等USENIX Security 2026
- SMILE: Set Membership from Ideal Lattices with Applications to Ring Signatures and Confidential TransactionsVadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor SeilerCRYPTO 2021 · 被引用 49 次
- BulletCT: Towards More Scalable Ring Confidential Transactions With Transparent SetupNan Wang, Qianhui Wang, Dongxi Liu, Muhammed F. Esgin 等USENIX Security 2025
