Featured Developer Sponsor • Zero-Token Protection
Verifiable Shuffle & Mixnet Architecture Studio
Model network-level metadata privacy and electronic voting verifiability. Simulate Chaumian Poisson-delay mixnets, Sphinx packet transformations, ElGamal homomorphic re-encryption, and Bayer-Groth zero-knowledge proofs of shuffle.
Chaumian Mixnet
Sphinx Packets
Bayer-Groth ZKP
Poisson Delays
Mixing network topology and routing strategy
Number of ciphertexts shuffled per mixing epoch
Randomized hold interval per mix node
Executes ElGamal re-encryption and ZK proof
Mixnet Pipeline: Senders -> Node 1 (Shuffle) -> Node 2 (Re-Encrypt) -> Node 3 -> Output
Input Ciphertexts
Re-Encrypted Packets
Verified Output
Permutation State
π ∈ S_8 (Secret)
40,320 Permutations
Bayer-Groth ZKP
✓ Valid
Soundness 2^-128
Traffic Correlation
0.00%
Global Adversary Blind
Verification Time
1.84 ms
Multi-Exponentiation
Sphinx Packet Size
1,024 Bytes
Constant Across Hops
Cover Traffic Injection
25% Decoy
Poisson Background Noise
Live ElGamal Homomorphic Re-Encryption & Shuffle Trace
| Slot | Input Ciphertext C_i | Secret Mapping π(i) | Blinding Scalar r'_i | Shuffled Output C'_j |
|---|
Production Verifiable Shuffle Code (Rust & Python)
Verifiable Mixnet Cryptographic Foundations
1. Homomorphic Re-Encryption
Given ElGamal public key \(h = g^s\), any party can re-randomize ciphertext \(C = (c_1, c_2)\) by picking random scalar \(r'\) and computing \(C' = (c_1 \cdot g^{r'}, c_2 \cdot h^{r'})\). The decrypted plaintext is identical, but the ciphertext is bitwise uncorrelated.
2. Bayer-Groth Multi-Exponentiation
The prover commits to permutation matrix columns using generalized Pedersen vector commitments. Verifier challenges collapse \(N\) polynomial equations into a single multi-exponentiation, allowing an entire election of 100,000 ballots to be verified in seconds.
3. Poisson Continuous Delays
Rather than releasing batches all at once (which still creates timing markers), mix nodes forward each packet after an exponentially distributed delay \(P(t) = \lambda e^{-\lambda t}\). Packets continuously weave together, defeating statistical timing correlation.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement