Scalable and privacy-preserving off-chain computations
Jacob Eberhardt · DepositOnce · 2021
Blockchains are distributed systems that allow mutually distrusting parties to process transactions in a censorship-resistant way while establishing an immutable transaction history without trusting a third party. These properties, however, do not come for free. Unlike other large-scale distributed systems, blockchains do not scale. They suffer from low transaction throughput and high costs resulting from redundant transaction processing and consensus overhead. Furthermore, there is no privacy protection in blockchain networks: All transaction data is necessarily exposed to the network for independent validation, essentially making it public. In this thesis, we introduce off-chaining to address the privacy and scalability challenges faced by today’s blockchains: Instead of technically modifying blockchains themselves, we propose to move computations and data off the blockchain — without compromising its desirable properties in the process. Off-chaining reduces the work a blockchain has to perform and improves its privacy properties by avoiding publishing data in the first place. As a first contribution, we identify off-chaining patterns that can be instantiated in the context of blockchain-based applications and provide solutions to recurring design problems. As a second contribution, we provide an in-depth analysis and comparison of off-chain computation approaches, which represent a particularly powerful privacy- and scalability-engineering abstraction. We identify zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs), a class of cryptographic protocols, as the most suitable approach. Developers, however, are ill-equipped to instantiate zk-SNARK-based off-chain computations to address blockchain-based applications’ privacy and scalability needs. Their instantiation is complex and error-prone; suitable programming abstractions and software tools are missing. To bridge this gap, we present ZoKrates, the first language and toolbox for zk-SNARK-based verifiable off-chain computations that allows non-expert developers to specify and execute off-chain computations in a usable and efficient manner as our third contribution. As our fourth contribution, we demonstrate the viability of ZoKrates, and more generally, off-chaining, to address privacy and scalability concerns in an extensive evaluation in the context of three relevant blockchain-based applications: decentralized energy trading, scalable blockchain relays, and privacy-preserving token transfers. Beyond these use cases, the open-source software that originated in the context of this thesis has found independent application in academia and industry.