On the Anonymity Guarantees of Anonymous Proof-of-Stake Protocols
Markulf Kohlweiss, Varun Madathil, Kartik Nayak, Alessandra Scafuro
摘要
In proof-of-stake (PoS) blockchains, stakeholders that extend the chain are selected according to the amount of stake they own. In S&P 2019 the "Ouroboros Crypsinous" system of Kerber et al. (and concurrently Ganesh et al. in EUROCRYPT 2019) presented a mechanism that hides the identity of the stakeholder when adding blocks, hence preserving anonymity of stakeholders both during payment and mining in the Ouroboros blockchain. They focus on anonymizing the messages of the blockchain protocol, but suggest that potential identity leaks from the network-layer can be removed as well by employing anonymous broadcast channels.In this work we show that this intuition is flawed. Even ideal anonymous broadcast channels do not suffice to protect the identity of the stakeholder who proposes a block.We make the following contributions. First, we show a formal network-attack against Ouroboros Crypsinous, where the adversary can leverage network delays to distinguish who is the stakeholder that added a block on the blockchain. Second, we abstract the above attack and show that whenever the adversary has control over the network delay – within the synchrony bound – loss of anonymity is inherent for any protocol that provides liveness guarantees. We do so, by first proving that it is impossible to devise a (deterministic) state-machine replication protocol that achieves basic liveness guarantees and better than (1−2f) anonymity at the same time (where f is the fraction of corrupted parties). We then connect this result to the PoS setting by presenting the tagging and reverse tagging attack that allows an adversary, across several executions of the PoS protocol, to learn the stake of a target node, by simply delaying messages for the target. We demonstrate that our assumption on the delaying power of the adversary is realistic by describing how our attack could be mounted over the Zcash blockchain network (even when Tor is used). We conclude by suggesting approaches that can mitigate such attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper7
- Ouroboros Genesis: Composable Proof-of-Stake Blockchains with Dynamic AvailabilityChristian Badertscher, Peter Gazi, Aggelos Kiayias, Alexander Russell 等CCS 2018 · 被引用 306 次
- P2P Mixing and Unlinkable Bitcoin TransactionsTim Ruffing, Pedro Moreno-Sanchez, Aniket KateNDSS 2017 · 被引用 134 次
- HoneyBadgerMPC and AsynchroMix: Practical Asynchronous MPC and its Application to Anonymous CommunicationDonghang Lu, Thomas Yurek, Samarth Kulshreshtha, Rahul Govind 等CCS 2019 · 被引用 120 次
- Anonymity Trilemma: Strong Anonymity, Low Bandwidth Overhead, Low Latency - Choose TwoDebajyoti Das, Sebastian Meiser, Esfandiar Mohammadi, Aniket KateS&P 2018 · 被引用 99 次
- SABRE: Protecting Bitcoin against Routing AttacksMaria Apostolaki, Gian Marti, Jan Müller, Laurent VanbeverNDSS 2019 · 被引用 86 次
相关 Paper
- Ouroboros Crypsinous: Privacy-Preserving Proof-of-StakeThomas Kerber, Aggelos Kiayias, Markulf Kohlweiss, Vassilis ZikasS&P 2019 · 被引用 82 次
- The Combinatorics of the Longest-Chain Rule: Linear Consistency for Proof-of-Stake BlockchainsErica Blum, Aggelos Kiayias, Cristopher Moore, Saad Quader 等SODA 2020 · 被引用 18 次
- Everything is a Race and Nakamoto Always WinsAmir Dembo, Sreeram Kannan, Ertem Nusret Tas, David Tse 等CCS 2020 · 被引用 3 次
- On the Limits of Consensus under Dynamic Availability and ReconfigurationJavier Nieto, Joachim Neu, Ling RenCCS 2026 · 被引用 2 次
- Proof-of-Stake SidechainsPeter Gazi, Aggelos Kiayias, Dionysis ZindrosS&P 2019 · 被引用 222 次
