Shielded Bitcoin: a no-fork privacy proposal

Shielded Bitcoin: a no-fork privacy proposal (AI-generated image)
AI-generated image

A team of researchers has introduced Shielded BitcoinA proposed metaprotocol designed to enable private transactions directly at the network's base layer. This technical development aims to offer a high level of confidentiality without requiring soft forks or altering the original protocol's consensus rules.

The initiative proposes a paradigm shift in how on-chain privacy is managed, using embedded data structures and advanced cryptography to create a secure and independently verifiable environment.

Buy Bitcoin

What is Shielded Bitcoin and what is its main objective?

The inherent transparency of public blockchains allows any user to audit the transaction history. However, this feature also presents significant challenges to financial privacy. To address this, researchers Clara Shikhelman, Misha Komarov, and Aleksei Moskvin, from the team at [[alloc] init], have designed Shielded Bitcoin.

This is a privacy metaprotocol that operates at the network's base layer. Instead of proposing changes to the core code that would require community consensus (like a soft fork), this system uses existing arbitrary data spaces, such as the OP_RETURN field or the witness space, to embed encrypted information. To the main network, a Shielded Bitcoin transaction is simply a block of data with an identifying prefix (e.g., "shbtc:"). The network does not verify or enforce these rules; its sole function is to ensure data availability on the blockchain.

Fundamental differences: Notes versus UTXOs

To understand how this metaprotocol works, it's essential to contrast it with the traditional model. Typically, the network uses an unspent transaction output (UTXO) model. When you perform a transfer, you consume an existing UTXO and create a new one. Nodes remove the spent UTXO from their active database and add the new one.

Shielded Bitcoin, on the other hand, uses a system based on "notes" and a "nullifier set." In this design, indexers build a Merkle tree that records every note created. This tree grows indefinitely, and no elements are ever removed from it. When a user spends a note, instead of deleting it from the public record, they publish an encrypted proof and a nullifier. The nullifier acts as a unique fingerprint that proves a specific note has been spent, but without revealing which note it is. Indexers simply check that the nullifier has not been used previously, thus preventing double-spending.

The indispensable role of indexers

Since standard nodes on the main network ignore the content of arbitrary data, the metaprotocol relies on "Shielded Bitcoin Indexers." These are specialized nodes that passively monitor the blockchain, extract transactions containing the metaprotocol prefix, and validate their cryptographic content.

It's entirely possible for someone to send an invalid Shielded Bitcoin transaction and pay the corresponding fees to have it included in a block by the miners. However, when the indexer processes that block, it will detect that the transaction failed its cryptographic validation and simply ignore it. In this way, the actual state of the balances within the metaprotocol remains intact and secure, depending solely on cryptography and not on miner validation.

Advanced cryptography and key management

The key management system in Shielded Bitcoin is sophisticated and reminiscent of the structure of hierarchical deterministic wallets (HD). It all starts with a master secret key, from which multiple keys with specific functions are derived:

  • sk_spend: The primary private key used to authorize the expenditure of funds.
  • sk_nf: Used to generate the nullifiers that invalidate spent notes.
  • vk_in: It allows you to decrypt and view incoming notes.
  • vk_out: It allows you to view outgoing transactions.
  • sk_view: It is used to generate the receiving addresses.

When you want to receive funds, you generate a diversifying value (similar to a derivation path) and multiply it by your key. sk_view to create a unique public address. The issuer, for its part, generates a random value (r_seedand uses an ephemeral key to create a shared secret with you. This shared secret encrypts the note, ensuring that only you, with your view key, can decrypt the amount and details. If you'd like to learn more about how cryptography protects digital assets, you can consult the educational resources available at Bit2Me Academy.

Zero-knowledge tests (ZK-proofs)

The core of Shielded Bitcoin's security lies in zero-knowledge proofs. For an incoming transaction to be considered valid by the indexers, it must include a public nullifier and a zero-knowledge proof that mathematically demonstrates four non-negotiable conditions:

  1. The note being spent exists and is included in the Merkle tree of valid notes.
  2. The transaction has been successfully authorized by the key sk_spend .
  3. The nullifier has been correctly derived from the original note.
  4. There has been no inflation; that is, the sum of the outgoing notes does not exceed the sum of the incoming notes.

These tests guarantee that, although the system is completely opaque regarding who sends what to whom, the mathematical rules of issuance and spending are strictly adhered to.

PIPEs v2: the custodian-free anchoring mechanism

One of the biggest challenges for any metaprotocol or secondary layer is how to transfer value from the base layer to the new system (peg-in) and vice versa (peg-out) without relying on trusted third parties. Shielded Bitcoin proposes using PIPEs v2, a witness encryption scheme.

PIPEs allow a private key to be encrypted using a conditional program or mechanism. This key will only be revealed if the user can provide zero-knowledge proof demonstrating that a specific condition has been met on the chain (for example, that an anchoring transaction has been confirmed). This theoretical design would allow the bridge between the main network and the metaprotocol to operate autonomously, without the need for operators, federations, or entities to safeguard user funds.

FAQ

Does Shielded Bitcoin require changes to the main network?

No. Because it functions as a metaprotocol, transactions are inserted as arbitrary data using existing fields. The main network processes them like any other standard transaction, while the actual validation rests solely with the indexers specific to this system.

How does the system guarantee that coins are not created out of thin air?

Supply integrity is maintained through zero-knowledge proofs (ZK-proofs). Each transaction must include a mathematical proof certifying that the funds spent originate from a valid note and that the amount withdrawn does not exceed the amount received, preventing any hidden inflation.

What happens if someone sends an invalid transaction to the network?

Since the main network does not verify the metaprotocol rules, the invalid transaction will be recorded on the blockchain even if the fees are paid. However, indexers will detect it as erroneous because it failed the cryptographic proof and will ignore it, so it will not affect the actual balance.

Is it necessary to rely on a third party to use this protocol?

No. The proposed design eliminates the need for coordinators or custodians. Users only need to run their own node and indexer along with their private keys to interact with the system in a completely sovereign and private manner.

Start with Bit2Me

The Shielded Bitcoin proposal represents a deep technical approach for those seeking greater privacy in their transactions without relying on third-party solutions or modifications to the underlying consensus mechanism. By leveraging advanced cryptography, zero-knowledge proofs, and metaprotocols, the ecosystem continues to explore ways to expand its functional capabilities in a decentralized manner.

Staying up-to-date with these kinds of developments is essential to understanding the technological evolution of the sector and how the infrastructures of the future are built. You can closely follow these and other technical innovations through the crypto ecosystem news, where we analyze the impact of the new proposals on the industry.

Investing in cryptoassets is not fully regulated, may not be suitable for retail investors due to high volatility and there is a risk of losing all invested amounts.

Generative artificial intelligence tools were used to create this article.