Protocol papers
Privacy papers: what is hidden, and from whom.
These papers do not all hide the same thing. Say whether the design hides the link, the amount, or the history.
How to read this shelf
Each card opens a study. The study is a reading of a public paper, not the paper and not a description of today's network. Status is a design paper unless the record says historical or failure case.
How to read this page
Research status is named on the page. Primary sources are linked. This is a mechanism and operating note, not investment suitability, legal advice, a security guarantee or an implementation certificate.
CryptoNote · 2013 · Design paper
CryptoNote v 2.0
The public design paper behind unlinkable payments. Monero adopted the construction and then replaced pieces of it. The historic library only has a third-party review of CryptoNote, not this document.
Zerocoin · 2013 · Design paper
Zerocoin: Anonymous Distributed E-Cash from Bitcoin
A 2013 proposal to add an anonymity layer on top of Bitcoin by burning a coin into a commitment and later redeeming a different coin with a zero-knowledge proof of membership.
Zerocash · 2014 · Design paper
Zerocash: Decentralized Anonymous Payments from Bitcoin
The 2014 paper that showed how a payment ledger can hide sender, receiver and amount, while still letting the network check that coins were not created or double-spent. Zcash is an implementation of this line of work, not a co-author of the paper.
Monero · 2016 · Design paper
Ring Confidential Transactions
The research note Monero used to hide amounts, not just the signer. It extends ring signatures so a spender can prove a balance inside a ring without publishing the values.
Mimblewimble · 2016 · Design paper
Mimblewimble
A short 2016 note on a ledger that stores confidential transactions and can delete spent history. Grin and Beam are later implementations. The note itself is the primary text.
