<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-10-03T23:39:27Z</responseDate>
  <request identifier="27859" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:27859</identifier>
        <datestamp>2026-10-02T17:40:21Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>The Consensus Number of Untraceable Cryptocurrencies</dc:title>
          <dc:creator>Cachin, Christian</dc:creator>
          <dc:creator>Lehnherr, David</dc:creator>
          <dc:creator>Villacis, Juan</dc:creator>
          <dc:creator>Wicht, François-Xavier</dc:creator>
          <dc:subject>Consensus number</dc:subject>
          <dc:subject>untraceability</dc:subject>
          <dc:subject>privacy-preserving cryptocurrencies</dc:subject>
          <dc:subject>wait-freedom</dc:subject>
          <dc:subject>masking sets</dc:subject>
          <dc:subject>concurrent objects</dc:subject>
          <dc:description>Privacy-preserving cryptocurrencies hide which account funds a transfer among a set of candidate accounts, called its masking set. To prevent the hidden account from being spent twice, classical schemes retain the candidates and append a nullifier that marks the spent account without revealing it. Their ledgers therefore grow with every transfer. Constant-state schemes instead consume and replace the entire masking set. Here, we study the synchronization cost of this second design.&#13;
We introduce the constant untraceable asset transfer (CUAT) object. A CUAT transfer atomically replaces every account in its masking set; hence two transfers with intersecting sets cannot both succeed. We capture this contention by a conflict graph on transfer invocations, whose edges join invocations with intersecting masking sets. In one-round protocols, the relevant sets form a clique at a critical configuration. In general protocols, only sets from opposite valency classes must intersect.&#13;
Under weak untraceability, which considers one transaction in isolation, CUAT has unbounded consensus number even for one-round protocols. Under strong untraceability, which considers the complete history, accounts in a common masking set must have equal incidence. This condition makes both the one-round consensus power and CUAT’s consensus number grow quadratically with the masking-set size. Cyclic and projective-plane constructions establish the corresponding one-round lower bounds, while a recursive grid construction shows that CUAT’s consensus number is exactly the square of the masking-set size. CUAT is also not starvation-free.&#13;
The full version studies the complementary linear untraceable asset transfer (LUAT) object, which retains its masking set and records a nullifier. Its state grows, but its consensus number is two for every masking-set size and under either untraceability notion, and it is starvation-free. Thus LUAT pays for untraceability in storage, whereas CUAT pays in synchronization and fairness.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>Christian Cachin and David Lehnherr and Juan Villacis and François-Xavier Wicht</dc:contributor>
          <dc:date>2026</dc:date>
          <dc:relation>Is Part Of LIPIcs, Volume 395, 8th Conference on Advances in Financial Technologies (AFT 2026)</dc:relation>
          <dc:type>InProceedings</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/LIPIcs.AFT.2026.5</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-278593</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.AFT.2026.5</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
