Algebraic Zero Knowledge Contingent Payment
摘要
In this work, we introduce Modular Algebraic Proof Contingent Payment ( \(\textsf{MAPCP}\) ), a novel zero-knowledge contingent payment (ZKCP) construction. Unlike previous approaches, \(\textsf{MAPCP}\) is the first that simultaneously avoids using zk-SNARKs as the tool for zero-knowledge proofs and HTLC contracts to exchange a secret for a payment atomically. As a result, \(\textsf{MAPCP}\) sidesteps the common reference string ( \(\textit{crs} \) ) creation problem and is compatible with virtually any cryptocurrency, even those with limited or no smart contract support. Moreover, \(\textsf{MAPCP}\) contributes to fungibility, as its payment transactions seamlessly blend with standard cryptocurrency payments. We analyze the security of \(\textsf{MAPCP}\) and demonstrate its atomicity, meaning that, (i) the buyer gets the digital product after the payment is published in the blockchain (buyer security); and (ii) the seller receives the payment if the buyer gets access to the digital product (seller security). Moreover, we present a construction of \(\textsf{MAPCP}\) in a use case where a customer pays a notary in exchange for a document signature. Moreover, we implement \(\textsf{MAPCP}\) and evaluate its performance in a use case where a customer pays a notary in exchange for a document signature. Our results show that \(\textsf{MAPCP}\) imposes a small computation and communication overhead even on commodity hardware, proving its practicality.