Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for Services

Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for Services
复制标题

DOI:
10.1145/3133956.3134060
复制
发表时间:
2017-10
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Matteo Campanelli;R. Gennaro;Steven Goldfeder;Luca Nizzardo
Matteo Campanelli;R. Gennaro;Steven Goldfeder;Luca Nizzardo
中科院分区:
其他
文献类型:
--
作者:
Matteo Campanelli;R. Gennaro;Steven Goldfeder;Luca Nizzardo

文献摘要

被引文献

相似文献

零知识或有支付(ZKCP)协议允许通过比特币网络公平交换出售的商品和付款。在本文中,我们指出了两个主要的缺点,目前的建议ZKCP,并提出了解决这些问题的方法。首先,我们展示了一种攻击,它允许买方了解有关正在出售的数字商品的部分信息,而无需支付费用。这种对ZKCP零知识条件的突破是由于这样一个事实,即在我们攻击的协议中,买方被允许选择通常应由可信第三方选择的公共参数。我们实现并测试了这种攻击:我们提出的代码,学习,而无需支付,数独细胞的价值在“付费数独”ZKCP实现。我们还提出了修复这种攻击的方法,不需要可信的第三方。其次,我们表明ZKCP不适合购买数字服务,而不是商品。目前ZKCP的结构不允许卖方在证明提供了某种服务后收到付款,而只能用于特定数字商品的销售。我们定义了零知识条件服务支付(ZKCSP)协议的概念,并构造了两个新的协议,无论是公共或私人验证。我们实现了我们的ZKCSP协议,用于证明可检索性,其中客户端向服务器付费,以提供客户端数据被服务器正确存储的证明。我们还通过我们的ZKCSP协议实现了一个安全的ZKCP协议,用于“Pay-to-Sudoku”,它不需要可信的第三方。我们的实现工作的一个副产品是一个新的优化电路的SHA 256与不到四分之一的与门的数量比以前最好的公开。我们的新SHA 256电路可以独立用于需要SHA 256电路的基于电路的MPC和FHE协议。
Zero Knowledge Contingent Payment (ZKCP) protocols allow fair exchange of sold goods and payments over the Bitcoin network. In this paper we point out two main shortcomings of current proposals for ZKCP, and propose ways to address them. First we show an attack that allows a buyer to learn partial information about the digital good being sold, without paying for it. This break in the zero-knowledge condition of ZKCP is due to the fact that in the protocols we attack, the buyer is allowed to choose common parameters that normally should be selected by a trusted third party. We implemented and tested this attack: we present code that learns, without paying, the value of a Sudoku cell in the "Pay-to-Sudoku" ZKCP implementation. We also present ways to fix this attack that do not require a trusted third party. Second, we show that ZKCP are not suited for the purchase of digital services} rather than goods. Current constructions of ZKCP do not allow a seller to receive payments after proving that a certain service has been rendered, but only for the sale of a specific digital good. We define the notion of Zero-Knowledge Contingent Service Payment (ZKCSP) protocols and construct two new protocols, for either public or private verification. We implemented our ZKCSP protocols for Proofs of Retrievability, where a client pays the server for providing a proof that the client's data is correctly stored by the server.We also implement a secure ZKCP protocol for "Pay-to-Sudoku" via our ZKCSP protocol, which does not require a trusted third party. A side product of our implementation effort is a new optimized circuit for SHA256 with less than a quarter than the number of AND gates of the best previously publicly available one. Our new SHA256 circuit may be of independent use for circuit-based MPC and FHE protocols that require SHA256 circuits.