Meeting Summary:
The Encrypt the Mempool tech working group discussed three main topics. First, they debated whether a non-PQ temporary solution for enshrinement was acceptable, with Gottfried and Loring highlighting that the answer depends on the specific design and its upgradability to a PQ-safe scheme. Next, they reviewed Yannick’s table on the validator whitelist approach, focusing on how to prove and mitigate confidentiality and availability attacks, with a consensus that availability attacks can be detected and penalized by the protocol, while confidentiality attacks are harder to address and may rely on social accountability. The group also discussed the acceptability of validators managing the whitelist and the potential voting mechanisms involved. Lastly, they briefly mentioned a note from Anders on achieving censorship resistance for the original EIP-815 trusted set, but deferred a detailed discussion until his return.
Click to expand detailed summary
Loring led the Encrypt the Mempool meeting number 9, noting that regular contributors Justin and Anders were on holiday. The meeting focused on continuing discussions about enshrinement and the validator whitelist approach from the previous week’s conversation with Nicholas Raycroft. The agenda included three main topics: enshrinement solutions, proving validator whitelist violations, and achieving censorship resistance for the original EIP8105 trusted set. The meeting began with Loring asking for summaries of the previous week’s cryptographer discussion about enshrinement solutions, specifically regarding non-PQ temporary solutions.
The group discussed the challenges of implementing a temporary non-PQ solution versus a permanent PQ solution, with Gottfried emphasizing that the approach depends heavily on the chosen design and upgrade path. Loring identified three key questions for consideration: implementation effort for core developers, effectiveness duration of the temporary solution, and transition difficulty to a permanent PQ solution. The discussion concluded with plans to address validator whitelist topics, including proofs of withholding and key selling automation.
Jannik discussed the concepts of confidentiality and availability attacks in the context of key sharing and committee mechanisms. He explained that confidentiality attacks are generally undetectable but can be mitigated through social accountability and large setups, while availability attacks can be detected by the protocol itself through timeless committees and addressed with economic penalties or automatic removal of the publisher. Jannik noted that confidentiality attacks primarily affect the user who chose the key publisher, while availability attacks impact a broader range of people, including those who didn’t choose the publisher.
Loring and Jannik discussed mitigation strategies for key publishers, with Jannik confirming that exclusion from the whitelist would be the ultimate mitigation by preventing them from providing keys. Jannik explained that while pre-emptive prevention is ideal, post-attack exclusion may be necessary, though it should be done carefully to avoid false positives or censorship. The main open question raised by Jannik was whether it’s acceptable for the validator set to take responsibility for voting on key publishers or selecting a committee to do so.
Jannik and Gottfried discussed the challenges of implementing a key publisher selection mechanism for confidential transactions. They explored various voting mechanisms and considered the potential for market concentration and “enshittification” among key publishers. The conversation highlighted the need to balance simplicity with effective governance, including questions about thresholds, ranked voting, and the role of delegators like home stakers in the process. Jannik acknowledged the need to further develop options for the voting mechanism, particularly regarding delegation and threshold requirements.
The team discussed key publisher selection and validation processes. Jannik clarified that validators would need to continuously re-vote for key publishers rather than removing them from a whitelist, and he indicated there should be no maximum number of key publishers as long as they don’t engage in availability attacks. The group agreed that validators should maintain low barriers for entry to prevent decryption service attacks, with economic selection mechanisms handling service provider choice rather than imposing additional requirements like commercial versus public good status. The discussion concluded with a brief mention of reviewing Anders’ note on achieving censorship resistance for EIP8105, though no summary was provided as Anders was unavailable.
The team discussed a GitHub issue related to the Encrypt the Mempool project, with Loring noting that the link was available for review. Boma shared a specific GitHub pull request, and the group agreed to bring up further discussion about project management aspects at the next meeting when Justin returns. Loring announced upcoming working group meetings, one for MarCom in a week and another tech working group in two weeks.
Next Steps:
- Jannik: Write down the options and considerations for the validator whitelist voting mechanism (e.g., delegation, independent voting, quorum, bandwidth concerns) and prepare to discuss them in the next call.
- All participants: Review Anders’ note on achieving censorship resistance for the original EIP-8105 trusted set (link in the GitHub issue) and provide feedback before the next meeting.
- Loring: Bring up the topic of Justin Chaglia’s contribution (shared by Boma) in the next call when Justin is back.
Recording Access: