I have a new proposal on how refreshes can be made more private.
The core of my proposal focuses on breaking the link between input attestation and output declaration.
VTXO ATTESTATION
Attestation works by having the user generate keypairs to register with a denomination of the vtxo value being attested to. We call the public keys of these keypairs slot_pubkeys. The ASP knows which vtxo each slot_pubkey belongs to.
The ASP then coordinates with the participant to start a musig2 signing session for the forfeit and computes their partial signature. Unlike the normal Bark flow, this forfeit will omit its hashlock.
The ASP then publishes the public points corresponding to each partial signature scalar which is necessary for our output declaration mechanism.
OUTPUT DECLARATION
Output declaration works by having the user create a ring proof using the slot_pubkeys of all participants for the denomination of the output being declared. Each branch contains two public points, and the proof requires knowledge of both corresponding secrets.
The first public key in each branch is the slot_pubkey and the other is the desired output public key minus the forfeit point for that slot. Each branch therefore contains the tuple: (slot_pubkey[j], output_pubkey - forfeit_point[j]). The proof also includes a nullifier derived from the real slot to prevent using the same slot multiple times.
To construct their output, the user generates an offset keypair and sets output_pubkey = forfeit_point[j] + offset_pubkey, where j is the slot they own. This means they know the private key corresponding to output_pubkey - forfeit_point[j], allowing them to satisfy the second part of their real ring branch. They cannot yet sign for output_pubkey itself because they do not know the ASP’s partial-signature scalar corresponding to forfeit_point[j].
After every ring proof is submitted, the ASP creates the vtxo tree and the users submit their forfeits. If a user later exits and the ASP claims the forfeited vtxo, the completed forfeit signature reveals the ASP’s partial-signature scalar to that user. The user can add this scalar to their offset secret to recover the private key for their submitted output.
Additional details for the proposal can be found here:
It’s still a work in progress so feedback is welcome ![]()