发表机构
Aarhus University; University of Bern; National University of Singapore; Nanyang Technological University(奥胡斯大学; 伯尔尼大学; 新加坡国立大学; 南洋理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对现有追踪方案权限无界的问题,提出临时硬币追踪ECT,其追踪能力受跳数等限制,给出两种基于加密的构造并定义安全隐私保证。
AI 中文摘要
隐私保护支付系统已被充分理解,但其在受监管环境(如央行数字货币CBDC、机构稳定币及其他合规支付基础设施)中的应用,因担心被滥用从事非法活动而受限。监管机构通过一套互补措施识别、追踪并制止犯罪主体,追踪是关键工具之一:执法部门根据外部证据(如用户涉嫌洗钱等犯罪),沿账本追踪嫌疑人资金以查明洗钱路径及同谋。但文献中提出的追踪方案赋予当局无限权限:一旦启动,追踪会在交易图中传播或持续至用户所有未来交易,最终可能 deanonymize 整个账本,仅靠当局的善意或委员会的诚实确保监控具有针对性和临时性。我们提出临时硬币追踪ECT,其追踪能力在设计上受限制,同时体现在同时追踪用户数量和每次追踪的跳数上。当局发放追踪标签,该标签每经过一跳就会降级;在协议定义的跳数后,标签会坍缩为与未标记硬币无法区分的值。在追踪周期内,该限制是绝对的:无论动机如何,任何当局都无法让标签超出其预算。我们形式化ECT,定义其安全与隐私保证,并给出两种构造,一种基于指数ElGamal,另一种基于Damgård-Jurik加密。
英文摘要
Privacy-preserving payment systems are well understood, yet concerns about their misuse for financial crime have led to only limited adoption in regulated settings such as central bank digital currencies (CBDCs) and institutional stablecoins. Tracing is one tool for addressing these concerns: acting on external evidence implicating a user, law enforcement follows the suspect's funds through the ledger to uncover laundering routes and accomplices. Existing coin-tracing schemes, however, provide no cryptographic bound on tracing reach: once initiated, a trace may propagate indefinitely through the transaction graph or persist across all future transactions of a targeted user. Keeping surveillance targeted and temporary therefore depends on the restraint of the authority or a committee. We introduce ephemeral coin tracing (ECT), a primitive that bounds tracing reach by construction. Each account carries an encrypted tag that records which traced identifiers its funds carry while hiding its tracing status from users. When funds move, the sender's tag degrades and merges with the recipient's tag. Each tracing contribution expires independently after a policy-defined number of hops and then becomes unrecoverable even to the tracing authority, without affecting other live contributions in the same tag. Public parameters also bound how many identifiers a tag can distinguish simultaneously. We formalize ECT and give constructions based on exponential ElGamal, Damgård-Jurik encryption, and Ring-LWE, the last providing post-quantum security.