Paper 2026/1258

Beyond Anonymity Sets: A Security Model for Distributed Shuffling in Adversarial Environments

Adrian Cinal, NASK National Research Institute
Oliwer Sobolewski, NASK National Research Institute
Gabriel Wechta, NASK National Research Institute
Filip Zagorski, University of Wroclaw
Abstract

Distributed shuffling is a core primitive underlying mix-nets, electronic voting, and, more recently, single secret leader election (SSLE) protocols for proof-of-stake blockchains. In these settings, a collection of resource-constrained parties jointly permutes a list of ciphertexts or commitments in order to conceal the correspondence between inputs and outputs. Existing security analyses of such protocols typically rely on heuristic anonymity measures or implicitly assume honest behavior; therefore, they fail to capture statistical dependencies that arise when shuffling is partial and some participants are corrupted. In this work, we introduce a new security model for distributed shuffling that accurately reflects the setting of real-world attacks by explicitly accounting for adversarial corruption and information leakage. Our model allows an adversary to corrupt a subset of shufflers and track selected elements throughout the execution, as well as query the resulting permutation afterwards. We then turn to studying Whisk in this model, the shuffle-based SSLE mechanism proposed for Ethereum. Leveraging Markov-chain techniques, we show that security can only be guaranteed for more stringent parameters than currently proposed. We evaluate the performance impact of changing these parameters on the Ethereum network.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. ACM CCS'26
Keywords
proof of stakeSSLEsingle secret leader electionEthereumDOS attackanonymitymixing timeMarkov chain
Contact author(s)
adrian cinal @ nask pl
oliwer sobolewski @ nask pl
gabriel wechta @ nask pl
filip zagorski @ gmail com
History
2026-08-22: revised
2026-06-15: received
See all versions
Short URL
https://ia.cr/2026/1258
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1258,
      author = {Adrian Cinal and Oliwer Sobolewski and Gabriel Wechta and Filip Zagorski},
      title = {Beyond Anonymity Sets: A Security Model for Distributed Shuffling in Adversarial Environments},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1258},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1258}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.