Distributed Shuffling in Adversarial Environments

Kasper Green Larsen, Aarhus University
Maciej Obremski, National University of Singapore
Mark Simkin, Ethereum Foundation

We study mix-nets in the context of cryptocurrencies. Here we have many computationally weak shufflers that speak one after another and want to joinlty shuffle a list of ciphertexts $(c_1, \dots, c_n)$. Each shuffler can only permute $k << n$ ciphertexts at a time. An adversary $\mathcal{A}$ can track some of the ciphertexts and adaptively corrupt some of the shufflers. We present a simple protocol for shuffling the list of ciphertexts efficiently. The main technical contribution of this work is to prove that our simple shuffling strategy does indeed provide good anonynmity guarantees and at the same time terminates quickly. Our shuffling algorithm provides a strict improvement over the current shuffling strategy in Ethereum's block proposer elections. Our algorithm is secure against a stronger adversary, provides provable security guarantees, and is comparably in efficiency to the current approach.

Shuffling Leader Election Mix-Nets
