vix.ing · top · new · best · stats · spec

Counting Down Thunder: Timing Attacks on Privacy in Payment Channel Networks

2020/06/22 by Elias Rohrer, Rohrer, Elias, Florian Tschorsch +1 · 1 citation
Computer Science · #Blockchain Technology Applications and Security #Cryptography and Security (cs.CR) #Distributed systems and fault tolerance #FOS: Computer and information sciences #Networking and Internet Architecture (cs.NI) #Peer-to-Peer Network Technologies

paper · pdf · doi:10.48550/arxiv.2006.12143

openalex publication_date 2020/06/22 · openalex created_date 2020/07/02 · openalex updated_date 2026/07/28

Abstract

The Lightning Network is a scaling solution for Bitcoin that promises to enable rapid and private payment processing. In Lightning, multi-hop payments are secured by utilizing Hashed Time-Locked Contracts (HTLCs) and encrypted on the network layer by an onion routing scheme to avoid information leakage to intermediate nodes. In this work, we however show that the privacy guarantees of the Lightning Network may be subverted by an on-path adversary conducting timing attacks on the HTLC state negotiation messages. To this end, we provide estimators that enable an adversary to reduce the anonymity set and infer the likeliest payment endpoints. We developed a proof-of-concept measurement node that shows the feasibility of attaining time differences and evaluate the adversarial success in model-based network simulations. We find that controlling a small number malicious nodes is sufficient to observe a large share of all payments, emphasizing the relevance of the on-path adversary model. Moreover, we show that adversaries of different magnitudes could employ timing-based attacks to deanonymize payment endpoints with high precision and recall.

Citations

Cited by

Related