Confidential Transactions from Basic Principles
cryptoservices.github.io
cryptoservices.github.io
an early writeup: https://people.xiph.org/~greg/confidential_values.txt
http://diyhpl.us/wiki/transcripts/gmaxwell-confidential-tran... which is a transcript of https://www.youtube.com/watch?v=LHPYNZ8i1cU
The actual borromean ring signature paper (compiled into pdf): http://diyhpl.us/~bryan/papers2/bitcoin/Borromean%20ring%20s...
Confidential transactions was later extended to confidential assets: https://blockstream.com/bitcoin17-final41.pdf and https://blog.chain.com/hidden-in-plain-sight-transacting-pri...
Then I explain a chameleon hash function as a hash function where you can generate collisions if you know a trapdoor, which is just a pedersen forgery... then you feed the output of the chameleon into its input, and... and the result is a schnorr signature.
So each idea builds on the last.
In step 2, e = H(Q || M) should be e = H(Q || M || P). That binds the signature to the public key, if you don't have that then the scheme is not sound in the usual models (UF-CMA +ROM etc.).
EDIT: see "How not to prove yourself", Asiacrypt 2012, eprint 2016/771.
That particular bug seems explicitly covered by this cryptography, using the rangeproofs. But if there were ever some other subtle bug that created money out of thin air, would you be ever able to detect it? The schemes mentioned all seem to sanity-check individual transactions, and not accounts or the money supply as a whole.
The article mentions Monero and CryptoNote, for example: https://getmonero.org/2017/05/17/disclosure-of-a-major-bug-i...
And that page says: "This effectively allows someone to create an infinite amount of coins in a way that is impossible to detect without knowing about the exploit and explicitly writing code to check for it."
It seems like a formal correctness proof would be very important for cryptocurrencies with such strong privacy guarantees.
I mean, you have to keep your savings somewhere, right? You need savings for when you retire. And no alternative offers 100% anonymity, so in that case you would risk your anonymity for the security of your savings, right?
I’m not saying cryptocurrency will comprise even a minor part of your retirement savings any time soon, but perhaps in 10/20/30 years?
The problem is that non-private cryptocurrencies are permanent records of financial activity. I would rather risk soundness now than privacy forever, especially when there are post-quantum paths forward and our current assumptions are reasonable.