Secure multiparty Bitcoin anonymization
blog.ezyang.com
blog.ezyang.com
Of course, people might contribute too many recipient addresses trying to get free money, but this can never work - the transaction would be quickly aborted.
Wait... how do we exclude dishonest participants? We're trying to exchange bitcoins with random strangers on the internet here.
Then you could have everyone ante 1/16th bitcoin or whatever minimum is sensible and dispense with the power of two thing, because everybody would have hundreds of wallets in the transaction.
Or does that just create a lot of correlations when those coins get consolidated?
In this case, the transaction fee will have to be paid out of another wallet, not subtracted from the BTC involved in the transaction. Furthermore, this wallet must also be anonymous (e.g. to get anonymity, you must have some anonymity to begin with). But an important concern is how to pay for the transaction, when the size of Bitcoin you are anonymizing is about the same amount of the transaction cost anyway! One mitigating factor may be that it is really easy to find lots of participants willing to perform this mix, so a few benificient participants (who ostensibly want to be able to mix things) pay the entirety of the transaction fee for large, mini-mixes, and then uses the results of the mini-mix to pay for their bigger mixing.
BTW what are the specific resource requirements of SMP sort using currently accepted crypto primitives? I didn't get into digesting the linked paper just to see if they were working towards something feasible or if they required akin to one public key op per boolean gate.
The resource requirements are not well studied, since none of the literature attempts to handle sorting larger than 32-bit integers. However, on order of minutes would be my expectation.