{"title":"Token-Guided Flow Tracing for Auditable Zero-Knowledge Smart Contract Transfers","authors":"Junhee Lee, Jihye Kim, Hyunok Oh, Heejin Park","doi":"10.1049/ise2/1765419","DOIUrl":null,"url":null,"abstract":"<p>Private transfers on public smart contract blockchains hide transaction values and private transfer links, but accountable privacy requires controlled auditability. Existing auditable zero-knowledge transfer systems make per-transaction audit information available to an authorized auditor, but their audit model may allow the auditor to inspect transactions beyond the flow connected to the authorized audit target. In such a model, granting audit capability for one investigation can expose unrelated transactions or allow tracing to continue farther than intended. In this paper, we propose token-guided flow tracing for auditable zero-knowledge smart contract transfers, enabling audit authorization to be scoped to a transaction flow and epoch range. The construction separates audit authorization from audit capability by introducing a tracing-token manager and an auditor. The auditor can open audit information only when it holds the auditor secret key, an epoch secret key for an authorized epoch, and a tracing token associated with the target transaction flow. Direction-specific tracing tokens confine tracing to the authorized direction, while epoch public keys and a binary key-derivation tree support compact authorization of audit intervals. We analyze security through ledger indistinguishability, transaction nonmalleability, balance, audit correctness, and restricted audit authorization. Restricted audit authorization is established in an honest authorization model that assumes the tracing-token manager and the auditor do not collude beyond explicit audit authorizations; under these assumptions, the auditor cannot open or trace transactions outside the authorized flow, direction, and epoch scope. Our implementation adds 16,349 transfer-circuit constraints, about 178,000 gas to each accepted transfer, and 448 bytes to the serialized transfer transaction, showing that scoped auditability can be added with moderate on-chain overhead.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0000,"publicationDate":"2026-08-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/1765419","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Information Security","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1049/ise2/1765419","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Private transfers on public smart contract blockchains hide transaction values and private transfer links, but accountable privacy requires controlled auditability. Existing auditable zero-knowledge transfer systems make per-transaction audit information available to an authorized auditor, but their audit model may allow the auditor to inspect transactions beyond the flow connected to the authorized audit target. In such a model, granting audit capability for one investigation can expose unrelated transactions or allow tracing to continue farther than intended. In this paper, we propose token-guided flow tracing for auditable zero-knowledge smart contract transfers, enabling audit authorization to be scoped to a transaction flow and epoch range. The construction separates audit authorization from audit capability by introducing a tracing-token manager and an auditor. The auditor can open audit information only when it holds the auditor secret key, an epoch secret key for an authorized epoch, and a tracing token associated with the target transaction flow. Direction-specific tracing tokens confine tracing to the authorized direction, while epoch public keys and a binary key-derivation tree support compact authorization of audit intervals. We analyze security through ledger indistinguishability, transaction nonmalleability, balance, audit correctness, and restricted audit authorization. Restricted audit authorization is established in an honest authorization model that assumes the tracing-token manager and the auditor do not collude beyond explicit audit authorizations; under these assumptions, the auditor cannot open or trace transactions outside the authorized flow, direction, and epoch scope. Our implementation adds 16,349 transfer-circuit constraints, about 178,000 gas to each accepted transfer, and 448 bytes to the serialized transfer transaction, showing that scoped auditability can be added with moderate on-chain overhead.
期刊介绍:
IET Information Security publishes original research papers in the following areas of information security and cryptography. Submitting authors should specify clearly in their covering statement the area into which their paper falls.
Scope:
Access Control and Database Security
Ad-Hoc Network Aspects
Anonymity and E-Voting
Authentication
Block Ciphers and Hash Functions
Blockchain, Bitcoin (Technical aspects only)
Broadcast Encryption and Traitor Tracing
Combinatorial Aspects
Covert Channels and Information Flow
Critical Infrastructures
Cryptanalysis
Dependability
Digital Rights Management
Digital Signature Schemes
Digital Steganography
Economic Aspects of Information Security
Elliptic Curve Cryptography and Number Theory
Embedded Systems Aspects
Embedded Systems Security and Forensics
Financial Cryptography
Firewall Security
Formal Methods and Security Verification
Human Aspects
Information Warfare and Survivability
Intrusion Detection
Java and XML Security
Key Distribution
Key Management
Malware
Multi-Party Computation and Threshold Cryptography
Peer-to-peer Security
PKIs
Public-Key and Hybrid Encryption
Quantum Cryptography
Risks of using Computers
Robust Networks
Secret Sharing
Secure Electronic Commerce
Software Obfuscation
Stream Ciphers
Trust Models
Watermarking and Fingerprinting
Special Issues. Current Call for Papers:
Security on Mobile and IoT devices - https://digital-library.theiet.org/files/IET_IFS_SMID_CFP.pdf