Paper 2017/974

Obscuro: A Bitcoin Mixer using Trusted Execution Environments

Muoi Tran, Loi Luu, Min Suk Kang, Iddo Bentov, and Prateek Saxena

Abstract

Bitcoin provides only pseudo-anonymous transactions, which can be exploited to link payers and payees – defeating the goal of anonymous payments. To thwart such attacks, several Bitcoin mixers have been proposed, with the objective of providing unlinkability between payers and payees. However, existing Bitcoin mixers can be regarded as either insecure or inefficient. We present Obscuro, a highly efficient and secure Bitcoin mixer that utilizes trusted execution environments (TEEs). With the TEE’s confidentiality and integrity guarantees for code and data, our mixer design ensures the correct mixing operations and the protection of sensitive data (i.e., private keys and mixing logs), ruling out coin theft and address linking attacks by a malicious service provider. Yet, the TEE-based implementation does not prevent the manipulation of inputs (e.g., deposit submissions, blockchain feeds) to the mixer, hence Obscuro is designed to overcome such limitations: it (1) offers an indirect deposit mechanism to prevent a malicious service provider from rejecting benign user deposits; and (2) scrutinizes blockchain feeds to prevent deposits from being mixed more than once (thus degrading anonymity) while being eclipsed from the main blockchain branch. In addition, Obscuro provides several unique anonymity features (e.g., minimum mixing set size guarantee, resistant to dropping user deposits) that are not available in existing centralized and decentralized mixers. Our prototype of Obscuro is built using Intel SGX and we demonstrate its effectiveness in Bitcoin Testnet. Our implementation mixes 1000 inputs in just 6.49 seconds, which vastly outperforms all of the existing decentralized mixers.

Note: Make a clarification in the discussion section.

Metadata
Available format(s)
PDF
Publication info
Published elsewhere. Major revision. ACSAC ’18
DOI
10.1145/3274694.3274750
Keywords
BitcoinAnonymityMixerTrusted Execution EnvironmentsIntel SGX
Contact author(s)
muoitran @ comp nus edu sg
History
2018-12-31: last of 3 revisions
2017-10-05: received
See all versions
Short URL
https://ia.cr/2017/974
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2017/974,
      author = {Muoi Tran and Loi Luu and Min Suk Kang and Iddo Bentov and Prateek Saxena},
      title = {Obscuro: A Bitcoin Mixer using Trusted Execution Environments},
      howpublished = {Cryptology {ePrint} Archive, Paper 2017/974},
      year = {2017},
      doi = {10.1145/3274694.3274750},
      url = {https://eprint.iacr.org/2017/974}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.