Zerocash: Decentralized Anonymous Payments from Bitcoin

Zerocash: децентрализованные анонимные платежи на основе Bitcoin
Matthew Green, Eran Tromer, Eli Ben Sasson, Alessandro Chiesa, Christina Garman, Ian Miers, Madars Virza
2014-05-01

Bitcoindecentralized anonymous paymentsprivacy-preserving digital currencyzero-knowledge proofszk-SNARKs
Bit coin is the first digital currency to see widespread adoption. While payments are conducted between pseudonyms, Bit coin cannot offer strong privacy guarantees: payment transactions are recorded in a public decentralized ledger, from which much information can be deduced. Zero coin (Miers et al., IEEE S&P 2013) tackles some of these privacy issues by unlinking transactions from the payment's origin. Yet, it still reveals payments' destinations and amounts, and is limited in functionality. In this paper, we construct a full-fledged ledger-based digital currency with strong privacy guarantees. Our results leverage recent advances in zero-knowledge Succinct Non-interactive Arguments of Knowledge (zk-SNARKs). First, we formulate and construct decentralized anonymous payment schemes (DAP schemes). A DAP scheme enables users to directly pay each other privately: the corresponding transaction hides the payment's origin, destination, and transferred amount. We provide formal definitions and proofs of the construction's security. Second, we build Zero cash, a practical instantiation of our DAP scheme construction. In Zero cash, transactions are less than 1 kB and take under 6 ms to verify - orders of magnitude more efficient than the less-anonymous Zero coin and competitive with plain Bit coin.
1
Constructs Zerocash, a practical ledger-based digital currency using zk-SNARKs to achieve strong transaction privacy.
2
Introduces decentralized anonymous payment schemes that hide transaction origins, destinations, and transferred amounts.
3
Provides formal security definitions and proofs for the proposed decentralized anonymous payment construction.
4
Zerocash offers stronger privacy and broader functionality than Bitcoin and Zerocoin while remaining competitive with plain Bitcoin in efficiency.
5
Zerocash transactions are under 1 kB and verify in under 6 ms, making them orders of magnitude more efficient than Zerocoin.

ledger-based digital currency with decentralized anonymous payment transactions (Zerocash)

strong privacy guarantees, specifically hiding payment origins, destinations, and transferred amounts while maintaining efficient transaction verification

Publication Details
Publication Date
2014-05-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Matthew Green
Eran Tromer
Eli Ben Sasson
Alessandro Chiesa
Christina Garman
Ian Miers
Madars Virza
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%