不可追踪加密货币的共识数
The Consensus Number of Untraceable Cryptocurrencies
浏览论文内容
中文总结 AI 辅助
研究不可追踪加密货币两种设计(LUAT 和 CUAT)对同步的影响,通过形式化在共识层次结构中定位,分析其共识数、无饥饿性等特性,发现二者为相同隐私在存储、同步和公平性方面付出不同代价。
中文摘要 AI 辅助
发送方不可追踪性将加密货币转移所花费的账户隐藏在一组候选账户(其掩码集)之中。转移对该集合的操作区分了两种设计:经典方案保留整个集合并附加一个标记已花费账户的无效值,因此账本随每次转移而增长;恒定状态方案则消耗并替换整个集合。我们研究这种选择如何影响同步。我们将这两种设计形式化为线性和恒定不可追踪资产转移对象(LUAT 和 CUAT),并确定它们在共识层次结构中的位置。在 LUAT 中,来自不同账户的转移可交换,其共识数为 2,与标准资产转移的共识数 1 不同,且与掩码集大小和不可追踪性概念无关,并且 LUAT 无饥饿现象。将账户划分为固定掩码集可使耗尽的集合被垃圾回收而不增加该数字。在 CUAT 中,一次转移会消耗并替换其掩码集的每个账户,因此两个掩码集相交的转移不能同时生效。我们用掩码集上的冲突图来形式化这一点,其边连接共享一个账户的集合。在弱不可追踪性(孤立保护交易)下,对于一轮协议,共识数已经无界。在强不可追踪性(防止观察完整历史)下,当任何两个共享一个掩码集的账户在历史中出现在相同数量的掩码集中时,不可追踪性在历史上成立。这种均匀关联限制了冲突图,并且匹配构造达到了这一点,因此共识数被精确确定并随掩码集大小呈二次增长。最后,CUAT 不是无饥饿的。因此,这两个对象以不同方式为相同的隐私付出代价:LUAT 在存储方面,CUAT 在同步和公平性方面。
英文摘要
Sender untraceability hides the account spent by a cryptocurrency transfer among a set of candidates, its masking set. What a transfer does to that set separates two designs: classical schemes retain the whole set and append a nullifier marking the spent account, so the ledger grows with every transfer; constant-state schemes instead consume and replace the entire set. We ask how this choice affects synchronization. We formalize the two designs as the linear and constant untraceable asset transfer objects (LUAT and CUAT) and locate them in the consensus hierarchy. In LUAT, transfers from distinct accounts commute. Its consensus number is 2, compared with 1 for standard asset transfer, independently of the masking-set size and of the untraceability notion, and LUAT is starvation-free. Partitioning the accounts into fixed masking sets lets exhausted sets be garbage-collected without increasing that number. In CUAT, a transfer consumes and replaces every account of its masking set, so two transfers whose sets intersect cannot both take effect. We formalize this with the conflict graph on masking sets, whose edges join sets sharing an account. Under weak untraceability, which protects a transaction in isolation, the consensus number is unbounded already for one-round protocols. Under strong untraceability, which protects against an observer of the complete history, untraceability holds on a history exactly when any two accounts sharing a masking set occur in the same number of the masking sets in it. This uniform incidence bounds the conflict graph, and matching constructions attain it, so the consensus number is determined exactly and grows quadratically in the masking-set size. Finally, CUAT is not starvation-free. The two objects therefore pay for the same privacy differently: LUAT in storage, CUAT in synchronization and fairness.