Opt-In Audibility for Bitcoin Transactions via Cryptographic Commitments in Taproot Change Outputs

dc.contributor.authorChandra, Pratyakshen
dc.contributor.committeechairMATSUO, SHINICHIROen
dc.contributor.committeememberMeng, Naen
dc.contributor.committeememberCameron, Melissaen
dc.contributor.departmentComputer Science and#38; Applicationsen
dc.date.accessioned2026-07-28T08:00:09Zen
dc.date.available2026-07-28T08:00:09Zen
dc.date.issued2026-07-27en
dc.description.abstractBitcoin transactions carry no native mechanism for linking an on-chain payment to its real- world commercial purpose. A self-custodying user who wishes to demonstrate that a specific transaction corresponds to a specific invoice — for tax reporting, corporate audit, or reg- ulatory compliance — has no standardised, cryptographically sound way to do so without revealing their full wallet history. Existing approaches either lack on-chain binding (BIP-70, manual record-keeping), impose visible overhead and privacy costs (OP_RETURN commit- ments), or operate on different platforms entirely (Zcash viewing keys, Lightning invoices). This thesis presents an opt-in auditability protocol that embeds a cryptographic commit- ment to a structured invoice inside a standard Taproot change output using a pay-to-contract key tweak. The commitment adds zero bytes to the transaction, produces an output that is byte-for-byte indistinguishable from any other Pay-to-Taproot output, and requires no changes to Bitcoin's consensus rules. A new invoice format — the Signed Bitcoin Invoice (SBI) — organises payment metadata into a Merkle tree with per-field blinding nonces, en- abling field-level selective disclosure to auditors via inclusion proofs. An optional verifiable credential, embedded as a Merkle leaf, binds the merchant's identity to the payment address, providing pre-payment address authenticity verification. Five security properties (commitment binding, commitment hiding, disclosure soundness, disclosure privacy, and non-repudiation) are formally argued via reductions to standard cryp- tographic assumptions. A game-theoretic analysis demonstrates that the invisibility of the mechanism is a prerequisite for the opt-in property to remain voluntary under regulatory pressure.en
dc.description.abstractgeneralWhen you pay for something with a bank transfer, your bank keeps a record of the merchant's name, the amount, the date, and a reference number. If a tax auditor later asks what the payment was for, the bank's record provides the answer. Bitcoin works differently. When you send bitcoin to someone, the network records only that a certain amount moved from one digital address to another. It does not record who the recipient was in the real world, what you were paying for, or which invoice the payment settled. There is no bank in the middle keeping a receipt. This creates a problem for people and businesses who use bitcoin and also need to comply with tax laws, corporate auditing rules, or financial regulations. Today, the only way to prove what a bitcoin payment was for is to hand over extensive private financial records to auditors or chain analysis companies — revealing far more information than necessary. This thesis proposes a solution. When making a bitcoin payment, the sender's wallet software can embed a hidden fingerprint of the invoice inside the transaction itself, using a mathematical technique that is already part of Bitcoin's existing technology (called Taproot). This fingerprint is completely invisible — no one looking at the transaction on the blockchain can tell it is there. It adds no extra cost to the transaction. Later, if an auditor asks about the payment, the sender can reveal selected details from the invoice (for example, the amount and the merchant's name, but not the itemised pricing) and mathematically prove that those details were locked in at the time of payment. The result is a system where bitcoin users can prove compliance when asked, reveal only what is necessary, and maintain their financial privacy the rest of the timeen
dc.description.degreeMaster of Scienceen
dc.format.mediumETDen
dc.identifier.othervt_gsexam:47300en
dc.identifier.urihttps://hdl.handle.net/10919/143684en
dc.language.isoenen
dc.publisherVirginia Techen
dc.rightsIn Copyrighten
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/en
dc.subjectBitcoinen
dc.subjectBlockchain Analysisen
dc.subjectBlockchain Securityen
dc.titleOpt-In Audibility for Bitcoin Transactions via Cryptographic Commitments in Taproot Change Outputsen
dc.typeThesisen
thesis.degree.disciplineComputer Science & Applicationsen
thesis.degree.grantorVirginia Polytechnic Institute and State Universityen
thesis.degree.levelmastersen
thesis.degree.nameMaster of Scienceen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Chandra_P_T_2026.pdf
Size:
875.92 KB
Format:
Adobe Portable Document Format

Collections