LibraryPrivacy2016Design paperCorpus record
Ring Confidential Transactions
Monero. Shen Noether.
The research note Monero used to hide amounts, not just the signer. It extends ring signatures so a spender can prove a balance inside a ring without publishing the values.
Ring Confidential Transactions hide the amount inside a Monero-style ring, and still let the network check that inputs cover outputs and that a coin is spent only once.
The five-minute read
CryptoNote left the amount on the table
A ring only hides the signer if every member has the same visible denomination. The amount is then a fingerprint. This paper's job is to close that hole without giving up the ring.
Amounts become commitments
Each output commits to a value. The chain sees the commitment, not the number. A verifier can still check a linear relation among commitments.
The balance is a proof, not a sum you can read
A range proof shows each output is a non-negative amount in a bounded range, so a sender cannot hide a negative output that mints value. The sum of inputs and outputs is checked on the commitments.
The ring still does the linking
Confidential amounts do not by themselves hide which input was real. The ring signature, now over commitments rather than plain amounts, still does that work.
Range proofs dominate the size
The paper's cost is mostly the proof that amounts are well formed. Later Bulletproofs and similar schemes exist because that cost was the practical limit. They are not this paper.
One action, walked through
- The sender opens their own outputs, which are commitments plus the secrets only they know.
- They select decoy outputs from the chain. Those decoys are also commitments. The sender does not know the decoys' amounts, and does not need to.
- They build new output commitments for the recipient and for any change.
- A range proof is attached so every new amount is in range, and the ring signature shows one input set balances the outputs.
- The network verifies the proofs and records a key image. It never writes the amount into a public column.
The argument, unpacked
Hiding the amount changes the decoy math
Once amounts are hidden, decoys no longer have to share a denomination. That is the point. It also means a bad commitment scheme, or a range proof that does not bind, can be used to print money inside a proof nobody can inspect by eye.
What a node is allowed to know
A node must learn that the transaction is solvent and that the key image is fresh. It must not learn the amount or which ring member was real. Any feature that asks the node to know more, including a public fee that is not accounted for, has to be fitted into that list on purpose.
Confidential is not shielded in the Zerocash sense
RingCT still publishes a ring. The anonymity set is the ring, not the entire history of commitments. Someone comparing this paper to Zerocash should say that out loud. The set is smaller, the setup assumptions are different, and the transaction is larger for a different reason.
What has to be true
- The commitment scheme is binding and hiding under the stated assumptions.
- Range proofs are sound. A broken range proof is an inflation bug, not a privacy bug.
- Rings are large enough, and decoy selection is not itself a fingerprint.
- Fees and other public fields cannot be used to reconstruct the hidden amounts.
What happened after the paper
Monero deployed RingCT and later replaced the range proofs to shrink transactions. Ring size became mandatory. Those parameter changes are subsequent decisions. This paper is the argument that amounts can sit inside the ring at all.
What to check before you use the idea
- Is the anonymity set a ring of a stated size, or a global note pool?
- Which range proof is verified, and what is its size on the wire?
- Can a public fee, a unique denomination, or a timing pattern undo the hidden amount?
- What stops a negative output from creating value?
Terms
- Confidential transaction
- A transaction whose amounts are commitments. Solvency is checked without revealing the numbers.
- Range proof
- A proof that a committed number lies between zero and a maximum, so it cannot be negative or unbounded.
- RingCT
- The combination of a ring signature with confidential amounts, so both the signer and the values stay off the public columns.
- Binding
- The property that a commitment cannot be opened to two different amounts. Without it, the proof of balance is theatre.
The problem the paper names
CryptoNote-style rings hide which output was spent. They do not hide the amount. If denominations are visible, or if amounts are unique, the ring is easier to peel apart. The paper treats amount privacy as part of the signature, not as encryption bolted on beside it.
What the design proposes
- Commitments hide values. The signature proves the commitments in a ring are well formed.
- A range proof keeps a hidden amount from being negative or overflowing.
- The network still sees enough to reject a double-spend and to check that inputs cover outputs plus the fee.
How the mechanism is specified
- Confidential transactions (the Greg Maxwell construction on Bitcoin) are combined with a ring so the real input is not identified.
- The verifier checks a single statement: some input in the ring opens consistently, and value is conserved.
- Fees can remain public so the inclusion market still works.
What this page does not treat as proven
- This is not a Monero 'project white paper' in the ICO sense. It is the amount-privacy note the project adopted.
- Later Monero changes, including proof systems after this note, are not described here.
- Ring size and decoy selection still dominate practical privacy, and the paper does not pick a production policy.
Why a venture studio still reads it
A payments venture that publishes amounts 'for analytics' does not have this design. If the amount must be visible to a named party, that view should be a key or a reporting channel, not a return to a fully public ledger by default.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
