Introducing CoinShuffle++: Enhancements for Peer-to-Peer Coin Mixing

21 replies 273 views
nonce_2021Senior Member
Posts: 3 · Reputation: 1032
#1Nov 29, 2017, 10:43 PM
Hey everyone, I'm Tim from Saarland University, and along with Pedro and Aniket from Purdue, we’re excited to share our updated project: CoinShuffle++. It's a new and improved version of our original CoinShuffle, aimed at better privacy for Bitcoin users.
4 Reply Quote Share
0xOmegaFull Member
Posts: 6 · Reputation: 394
#2Nov 30, 2017, 03:33 AM
Sounds cool! Any way I can help out? I'm a PHP and JS dev.
3 Reply Quote Share
humblesageSenior Member
Posts: 4 · Reputation: 869
#3Nov 30, 2017, 09:24 AM
This looks really promising, thanks for sharing! About the protocol's ability to identify bad actors, it seems like a double-edged sword. If a few participants decide to coordinate, could that compromise the anonymity? What do you think?
1 Reply Quote Share
Posts: 48 · Reputation: 19
#4Nov 30, 2017, 12:29 PM
Yeah, that's the concern. Blacklisting certain outputs could help, but it feels basic.
4 Reply Quote Share
humblesageSenior Member
Posts: 4 · Reputation: 869
#5Nov 30, 2017, 01:14 PM
Got it now, the protocol aims to wrap up things for honest users even with a few bad apples. If you've got one troublemaker among a small group, it still stands a chance to work.
4 Reply Quote Share
paul_b34rHero Member
Posts: 1 · Reputation: 2794
#6Nov 30, 2017, 05:28 PM
Right! I meant to bring up the previous discussions we had on this. My understanding was a bit off at first, but I'm following now.
2 Reply Quote Share
greg.bullNewbie
Posts: 1 · Reputation: 5
#7Nov 30, 2017, 10:14 PM
Funny you mention that, jl777 was onto something similar months back. My past critiques still stand. Not having read your paper, but seeing the notation about rounds with malicious peers raises a flag for me.
0 Reply Quote Share
Posts: 1 · Reputation: 176
#8Dec 1, 2017, 12:10 AM
You’re hitting on key issues here!
2 Reply Quote Share
alex2018Full Member
Posts: 2 · Reputation: 329
#9Dec 2, 2017, 02:27 AM
Following this thread. Grateful for the work you're doing on enhancing privacy!
6 Reply Quote Share
humblesageSenior Member
Posts: 4 · Reputation: 869
#10Dec 2, 2017, 04:21 AM
Just brainstorming...but what if we tackle the problem of a misbehaving node by completing every combo of participants? You know, like doing multiple coinjoins at once to cover all bases?
4 Reply Quote Share
alex2018Full Member
Posts: 2 · Reputation: 329
#11Dec 2, 2017, 06:03 AM
Exactly what the protocol aims for! If you have five users and one acts up, the other four can still finish with some extra rounds.
3 Reply Quote Share
hash07Full Member
Posts: 1 · Reputation: 296
#12Dec 4, 2017, 04:35 PM
Nice to hear!
1 Reply Quote Share
humblesageSenior Member
Posts: 4 · Reputation: 869
#13Dec 4, 2017, 09:07 PM
Quick question, is CoinShuffle still active or is it considered outdated? Just trying to get the lay of the land.
2 Reply Quote Share
Gr1mSeedNewbie
Posts: 2 · Reputation: 13
#14Dec 5, 2017, 01:48 AM
Not the author, but I’ve skimmed the thread. Tim here is one of the original creators, and he’s laid out the differences in the new paper.
4 Reply Quote Share
nonce_2021Senior Member
Posts: 3 · Reputation: 1032
#15Dec 5, 2017, 03:34 AM
In the step KE, how do you determine NPK[] before getting input from p?
1 Reply Quote Share
Gr1mSeedNewbie
Posts: 2 · Reputation: 13
#16Dec 5, 2017, 06:13 AM
Good point! That part needed fixing. It should actually be VK[] instead of NPK[]. Better safe than sorry when hashing.
4 Reply Quote Share
WildWhaleMember
Posts: 1 · Reputation: 211
#17Dec 5, 2017, 11:29 AM
A couple of thoughts: 1. Why do we need sid' if we're using it already in the hash? Seems redundant. 2. I’m curious about the commitment phase. How does a malicious peer profit from not including the DC-PAD?
4 Reply Quote Share
im_byteFull Member
Posts: 1 · Reputation: 592
#18Dec 5, 2017, 11:43 AM
Tim already tackled some of this. We include peer views in the hash to avoid mishaps. Commitments are key for ensuring we finish the process.
4 Reply Quote Share
nonce_2021Senior Member
Posts: 3 · Reputation: 1032
#19Dec 5, 2017, 12:41 PM
Just read through your paper. Forgive my skimming! But how do you plan to prevent that attack where subsets to inputs and outputs match? Seems tricky.
1 Reply Quote Share
AtomicSeedFull Member
Posts: 12 · Reputation: 621
#20Dec 5, 2017, 05:39 PM
Great catch! We ask users to contribute equally in the mixing, which does limit flexibility. But it's essential for security. Can you clarify what part you’re worried about?
4 Reply Quote Share

Related topics