slides-datenspuren.tex (21505B)
1 \documentclass[aspectratio=169,t]{beamer} 2 3 \input texinputs/taler-macros 4 5 \usepackage{svg} 6 \svgsetup{inkscapearea=page} 7 \usepackage{tikz} 8 \usepackage{ragged2e} 9 \usepackage{graphicx} 10 \usepackage{bbding} 11 \usepackage{minted} 12 \usepackage{qrcode} 13 \usetikzlibrary{positioning,fit,patterns} 14 15 % 16 % Presentation at "Datenspuren 2026" 17 % Copyright (C) 2026 Iván Ávalos, .... 18 % 19 % This program is free software: you can redistribute it and/or modify 20 % it under the terms of the GNU General Public License as published by 21 % the Free Software Foundation, either version 3 of the License, or 22 % (at your option) any later version. 23 % 24 % This program is distributed in the hope that it will be useful, 25 % but WITHOUT ANY WARRANTY; without even the implied warranty of 26 % MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 27 % GNU General Public License for more details. 28 % 29 % You should have received a copy of the GNU General Public License 30 % along with this program. If not, see <http://www.gnu.org/licenses/>. 31 % 32 33 % *Especially* edit these... 34 % \setbeameroption{show notes on second screen=right} % Both 35 36 37 \newcommand{\SPEAKER}{Iván Ávalos} 38 \newcommand{\DATE}{19.09.2026} 39 40 \newcommand{\TITLE}{GNU Taler: Lose your phone, lose your money?} 41 \newcommand{\SUB}{Datenspuren 2026} 42 \newcommand{\AUTHOR}{Iván Ávalos} 43 \newcommand{\INST}{https://www.taler.net/} 44 45 % Do not edit this part 46 \title{\TITLE} 47 \subtitle{\SUB} 48 \date{\DATE} 49 \author[\SPEAKER]{\AUTHOR} 50 \institute{\INST} 51 52 \usepackage{amsmath} 53 \usepackage{multimedia} 54 \usepackage[percent]{overpic} 55 \usepackage{url} 56 \usepackage[absolute,overlay]{textpos} 57 \usepackage{listings} 58 59 \usepackage{tikz, xcolor} 60 \usetikzlibrary{shapes,arrows,positioning} 61 \tikzset{ 62 %Define standard arrow tip 63 >=stealth', 64 %Define style for boxes 65 punkt/.style={ 66 rectangle, 67 rounded corners, 68 draw=black, very thick, 69 minimum width=3.5em, 70 minimum height=2em, 71 text centered}, 72 % Define arrow style 73 pull/.style={ 74 <->, 75 thick,draw=red, 76 shorten <=2pt, 77 shorten >=2pt,}, 78 % Define arrow style 79 pil/.style={ 80 ->, 81 thick, 82 shorten <=2pt, 83 shorten >=2pt,} 84 } 85 86 \usetikzlibrary{shapes,arrows} 87 \usetikzlibrary{positioning} 88 \usetikzlibrary{calc} 89 90 91 \begin{document} 92 93 \frame{\maketitle} 94 95 \begin{frame}{What is GNU Taler?} 96 \begin{columns}[T] 97 \begin{column}{0.62\textwidth} 98 \begin{itemize} 99 \item \textbf{Private} like cash, but digital! 100 \item Your money is stored locally \textbf{in your wallet}. 101 \item Your bank has no record of your purchases. 102 \item Not a new currency nor married to any. 103 \item Pay online without registration. 104 \item 100\% free software! 105 \end{itemize} 106 \end{column} 107 \begin{column}{0.36\textwidth} 108 \centering 109 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/wallet} 110 \end{column} 111 \end{columns} 112 \end{frame} 113 114 \begin{frame}{How does it work?}{General overview} 115 \centering 116 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/TalerDiagram} 117 \end{frame} 118 119 %% \begin{frame}{How does it work?}{Withdraw coins} 120 %% \centering 121 %% \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/flow1} 122 %% \end{frame} 123 124 %% \begin{frame}{How does it work?}{Pay anonymously} 125 %% \centering 126 %% \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/flow2} 127 %% \end{frame} 128 129 %% \begin{frame}{How does it work?}{Deposit coins} 130 %% \centering 131 %% \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/flow3} 132 %% \end{frame} 133 134 \begin{frame}{How does it work?}{Blind signatures} 135 \centering 136 \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/blind-signature-coin} 137 \end{frame} 138 139 \begin{frame}{Self-custody: bug or feature?} 140 \begin{columns}[T] 141 \begin{column}{0.62\textwidth} 142 \begin{itemize} 143 \item Your money and purchase history are stored \textbf{locally} in your wallet. 144 \item You are responsible for keeping them safe against \textbf{loss}, 145 \textbf{theft}, or \textbf{unauthorized access}. 146 \item Your bank and exchange have no record of your individual purchases. 147 \item You can only spend money from the wallet(s) where you have it stored. 148 \item \textbf{If you lose your phone, you lose your money!} 149 150 ... unless... 151 \end{itemize} 152 \end{column} 153 \begin{column}{0.36\textwidth} 154 \centering 155 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/cliff} 156 \end{column} 157 \end{columns} 158 \end{frame} 159 160 \begin{frame}{...you do backups!} 161 \begin{columns}[T] 162 \begin{column}{0.62\textwidth} 163 \begin{itemize} 164 \item Create a copy of your wallet regularly. 165 \item Simple, right? However: 166 \begin{itemize} 167 \item What is the size of the backup? 168 \item Where do you store the backups? 169 \item How do you keep them safe and private? 170 \item Is deleted data really gone? 171 \item How often do you backup? 172 \item What happens if you restore a backup twice in two different wallets? 173 \item ...and then try to spend the same money on both at the same time? 174 \end{itemize} 175 \end{itemize} 176 \end{column} 177 \begin{column}{0.36\textwidth} 178 \centering 179 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/copies} 180 \end{column} 181 \end{columns} 182 \end{frame} 183 184 \begin{frame}{What is the size of the backup?} 185 \begin{columns}[T] 186 \begin{column}{0.62\textwidth} 187 \begin{itemize} 188 \item Each coin in the wallet is represented by a \textbf{keypair} and a \textbf{signature}. 189 \item Transaction history (purchases, withdrawals, etc.) can grow indefinitely. 190 \item Purchases can contain images, such as merchant logo and product 191 images, which are often stored multiple times. 192 \item Large old wallets will take longer to backup/restore and require more storage. 193 \end{itemize} 194 \end{column} 195 \begin{column}{0.36\textwidth} 196 \centering 197 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/size} 198 \end{column} 199 \end{columns} 200 \end{frame} 201 202 \begin{frame}{Where do you store the backups?} 203 \begin{center} 204 \includesvg[width=\textwidth,height=0.50\textheight,keepaspectratio]{assets/storage} 205 \end{center} 206 \begin{itemize} 207 \item If storing them \textbf{locally}, do you trust the storage medium? 208 \item If storing them \textbf{remotely}, do you trust the service provider? 209 \end{itemize} 210 \end{frame} 211 212 \begin{frame}{How do you keep them safe and private?} 213 \begin{center} 214 \includesvg[width=\textwidth,height=0.40\textheight,keepaspectratio]{assets/eyebackup} 215 \end{center} 216 \begin{itemize} 217 \item \textbf{Goal \#1:} prevent unauthorized access and protect against tampering. 218 \begin{itemize} 219 \item Which encryption scheme and at which level to encrypt? 220 \end{itemize} 221 \item \textbf{Goal \#2:} disclose as little as possible about the wallet contents. 222 \begin{itemize} 223 \item How to minimize metadata being leaked to the backup service? 224 \end{itemize} 225 \end{itemize} 226 \end{frame} 227 228 \begin{frame}{Is deleted data really gone?} 229 \centering 230 \includesvg[width=\textwidth,height=0.50\textheight,keepaspectratio]{assets/deletion} 231 \begin{itemize} 232 \item ...both from the wallet and from all backups? 233 \item ...as well as the evidence that it was deleted? 234 \end{itemize} 235 \end{frame} 236 237 \begin{frame}{How often do you backup?} 238 \begin{columns}[T] 239 \begin{column}{0.70\textwidth} 240 \begin{itemize} 241 \item Once a day, once a week, once a month? 242 \begin{itemize} 243 \item \textbf{Achtung!} Money can be lost if backups happen too 244 seldom... and backing up too often can be costly. 245 \end{itemize} 246 \item Before a withdrawal completes? 247 \item When a payment is \textbf{prepared} (nonce and seed exist)? 248 \begin{itemize} 249 \item \textbf{Achtung!} Timing can reveal behavioral patterns! 250 \end{itemize} 251 \item Again, how much time/bandwidth for each backup? 252 \begin{itemize} 253 \item Is it all in one go or incremental? 254 \item If fast and efficient, it can be done more often. 255 \end{itemize} 256 \end{itemize} 257 \end{column} 258 \begin{column}{0.30\textwidth} 259 \centering 260 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/time} 261 \end{column} 262 \end{columns} 263 \end{frame} 264 265 \begin{frame}{Restore a backup twice and pay twice?} 266 \begin{center} 267 \includesvg[width=\textwidth,height=0.50\textheight,keepaspectratio]{assets/doublespend} 268 \end{center} 269 \begin{itemize} 270 \item Double spending is impossible, since the exchange keeps track of spent coins. 271 \item Wallets still need to handle this gracefully and select only unspent coins. 272 \begin{itemize} 273 \item (Exchange can tell you which of your coins were already spent.) 274 \end{itemize} 275 \end{itemize} 276 \end{frame} 277 278 \begin{frame}{After many discussions...} 279 \centering 280 \includesvg[width=\textwidth,height=0.60\textheight,keepaspectratio]{assets/discussions} 281 \end{frame} 282 283 \begin{frame}{Incremental Wallet Backup and Sync}{Design Document \#92} 284 \begin{itemize} 285 \item \textbf{Incremental}: uploads only new changes, not the full wallet 286 \item \textbf{Encrypted}: backup data stays end-to-end encrypted 287 \item \textbf{Two-layer storage}: block DLL for state, hash-indexed object store for blobs 288 \item \textbf{Efficient}: restore only downloads new and updated blocks (TODO) 289 \item \textbf{Conflict-free}: CRDT-based merging keeps multiple devices consistent 290 \item \textbf{Plausible deniability}: removed data is silently redacted from the backup 291 \end{itemize} 292 \textit{Still a work in progress!} 293 \end{frame} 294 295 \begin{frame}{Architectural overview}{DD92: Incremental Wallet Backup and Sync} 296 \centering 297 \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/architecture} 298 \end{frame} 299 300 \newsavebox{\blockstorebox} 301 \begin{frame}[fragile]{Block store}{DD92: Incremental Wallet Backup and Sync} 302 \begin{columns}[T] 303 \begin{column}{0.60\textwidth} 304 \fontsize{10pt}{12pt}\selectfont 305 \begin{itemize} 306 \item Each block contains a set of wallet \textbf{increments} (i.e. changes in state) 307 \item Identified in the double-linked list by a \textbf{nonce}. 308 \item \textbf{Versioned} to prevent “downgrade” attacks. 309 \item \textbf{Encrypted} using its own symmetric key derived by the wallet per block (\textit{libsodium secretbox}). 310 \item \textbf{Kilobyte-padded} to minimize metadata leakage based on size. 311 \item Every DLL operation must be \textbf{authenticated} via a signature generated by the wallet. 312 \item \textbf{Bloom filter} is used to efficiently compare and find updated blocks to restore (TODO). 313 \end{itemize} 314 \end{column} 315 \begin{column}{0.40\textwidth} 316 \begin{lrbox}{\blockstorebox} 317 \begin{minipage}{\columnwidth} 318 \begin{verbatim} 319 +---------------------------- 320 | version number (2 byte) | 321 +---------------------------- 322 | nonce (24 byte) | 323 +---------------------------- 324 | serial (8 byte) | 325 +---------------------------- 326 | JSON length n (4 byte) | 327 +---------------------------- 328 | gzipped JSON (n byte) | 329 +---------------------------- 330 | padding (to next full KB) | 331 +---------------------------- 332 \end{verbatim} 333 \end{minipage} 334 \end{lrbox} 335 \resizebox{\columnwidth}{!}{\usebox{\blockstorebox}} 336 \end{column} 337 \end{columns} 338 \end{frame} 339 340 \begin{frame}[fragile]{Object store}{DD92: Incremental Wallet Backup and Sync} 341 \begin{columns}[T] 342 \begin{column}{0.60\textwidth} 343 \fontsize{10pt}{12pt}\selectfont 344 \begin{itemize} 345 \item Allows binary objects to be stored \textbf{deduplicated} in the backup. 346 \item Objects can be referenced by blocks using an identifier derived 347 from the object's hash and the secret key of the wallet. 348 \item \textbf{Encrypted} using a symmetric key derived from the 349 object's hash and the wallet private backup key (also 350 \textit{libsodium secretbox}). 351 \item \textbf{Reference counted:} objects with count zero are garbage 352 collected after a configured period of time. 353 \end{itemize} 354 \end{column} 355 \begin{column}{0.40\textwidth} 356 \begin{lrbox}{\blockstorebox} 357 \begin{minipage}{\columnwidth} 358 \begin{verbatim} 359 +---------------------------- 360 | version number (2 byte) | 361 +---------------------------- 362 | data length n (4 byte) | 363 +---------------------------- 364 | gzipped data (n byte) | 365 +---------------------------- 366 | padding (to next full KB) | 367 +---------------------------- 368 \end{verbatim} 369 \end{minipage} 370 \end{lrbox} 371 \resizebox{\columnwidth}{!}{\usebox{\blockstorebox}} 372 \end{column} 373 \end{columns} 374 \end{frame} 375 376 %% \begin{frame}[fragile]{Signatures}{DD92: Incremental Wallet Backup and Sync} 377 %% \begin{minted}{c} 378 %% // Authorizes the append or in-place update of a block. 379 %% struct SyncBlockUploadSignaturePS { 380 %% struct GNUNET_CRYPTO_SignaturePurpose purpose; 381 %% struct SYNC_BlockNonce prev_nonce; ///< all-zeros if first block 382 %% struct SYNC_BlockNonce next_nonce; ///< all-zeros if last block 383 %% struct SYNC_BlockNonce nonce; 384 %% struct GNUNET_HashCode old_hash; ///< all-zeros for appends 385 %% struct GNUNET_HashCode new_hash; 386 %% struct GNUNET_HashCode refs_hash; ///< over object_refs 387 %% }; 388 %% \end{minted} 389 %% \end{frame} 390 391 \begin{frame}[fragile]{Increment}{DD92: Incremental Wallet Backup and Sync} 392 \begin{columns}[T] 393 \begin{column}{0.55\textwidth} 394 \fontsize{10pt}{12pt}\selectfont 395 \begin{itemize} 396 \item Describes a change in the wallet state. 397 \item Is or will be contained within a block. 398 \item For each increment type is defined: 399 \begin{itemize} 400 \item a CRDT merge strategy (e.g. last write wins, lexicographic order) 401 \item a primary key (e.g. \texttt{exchange\_base\_url}) 402 \item a deletion group (e.g. \texttt{exchanges}) 403 \end{itemize} 404 \end{itemize} 405 \end{column} 406 \begin{column}{0.45\textwidth} 407 \begin{lrbox}{\blockstorebox} 408 \begin{minipage}{\columnwidth} 409 \begin{minted}[fontsize=\footnotesize]{typescript} 410 interface AddExchangeInc { 411 type: "add-exchange"; 412 exchangeBaseUrl: string; 413 tosAcceptedEtag: string; 414 tosAcceptedEtagTimestamp: Timestamp; 415 } 416 \end{minted} 417 \end{minipage} 418 \end{lrbox} 419 \resizebox{\columnwidth}{!}{\usebox{\blockstorebox}} 420 \end{column} 421 \end{columns} 422 \end{frame} 423 424 \begin{frame}[fragile]{Increment set}{DD92: Incremental Wallet Backup and Sync} 425 \begin{itemize} 426 \item Smallest wire protocol unit. 427 \item Local changes in the wallet are collected in a temporary buffer. 428 \item When a backup cycle runs, the increment set is packed into a block, 429 encrypted, and uploaded to the sync server. 430 \end{itemize} 431 \begin{minted}{typescript} 432 interface IncrementSet { 433 addExchangeIncs?: AddExchangeInc[]; 434 setGlobalExchangeTrustIncs?: SetGlobalExchangeTrustInc[]; 435 addBankAccountIncs?: AddBankAccountInc[]; 436 // ... 437 } 438 \end{minted} 439 \end{frame} 440 441 \begin{frame}{Backup cycle}{DD92: Incremental Wallet Backup and Sync} 442 \begin{enumerate} 443 \item \textbf{Fetch} all new and updated blocks. 444 \item \textbf{Verify} upload signature of all fetched blocks. 445 \item \textbf{CRDT-merge} remote increments with local increments. 446 \item Locally \textbf{delete} data that was removed from the backup. 447 \item Pack all local winning increments into a block. 448 \item \textbf{Encrypt} and \textbf{upload} block to the backup service. 449 \item If anything was deleted locally, upload/\textbf{update} the redacted blocks as well. 450 \item If the remote backup was updated in between, repeat from 1. 451 \end{enumerate} 452 \end{frame} 453 454 \begin{frame}{Backup schedule}{DD92: Incremental Wallet Backup and Sync} 455 \begin{columns}[T] 456 \begin{column}{0.80\textwidth} 457 \fontsize{10pt}{12pt}\selectfont 458 \begin{itemize} 459 \item A backup runs at \textbf{critical points} of wallet operations, and on 460 a schedule otherwise (\textbf{hourly} at most). 461 \item A \textbf{critical point} is one past which losing the device loses 462 money or user data that cannot be reconstructed. 463 \item Examples: 464 \begin{itemize} 465 \item \textbf{Withdrawing}: the keys that allow you to collect the money 466 after the withdrawal completes exist only in the wallet. 467 \item \textbf{Paying a merchant}: the secrets that allow a purchase to be 468 completed must survive your wallet. 469 \item \textbf{Receiving money}: the key that collects the money is stored 470 nowhere else. 471 \item \textbf{Depositing}: without its keys, a refund can never be claimed. 472 \end{itemize} 473 \end{itemize} 474 \end{column} 475 \begin{column}{0.20\textwidth} 476 \centering 477 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/catch} 478 \end{column} 479 \end{columns} 480 \end{frame} 481 482 \begin{frame}{Deletion}{DD92: Incremental Wallet Backup and Sync} 483 \begin{columns}[T] 484 \begin{column}{0.62\textwidth} 485 \begin{itemize} 486 \item \textbf{Tombstoneless deletion}: nothing marks what was removed, 487 blocks are silently redacted. 488 \item \textbf{Plausible deniability}: after deletion, not even the 489 evidence that something was deleted remains. 490 \item \textbf{Retroactive redaction}: deleted objects vanish from every 491 block that referenced them, and the blocks are rewritten. 492 \item \textbf{Cascading groups}: deleting an entity removes everything 493 that referenced it. 494 \end{itemize} 495 \end{column} 496 \begin{column}{0.38\textwidth} 497 \centering 498 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/tombstone} 499 \end{column} 500 \end{columns} 501 \end{frame} 502 503 \begin{frame}{Demoooooo!!!} 504 \centering 505 \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/demo} 506 \end{frame} 507 508 \begin{frame}{Limitations} 509 \begin{columns}[T] 510 \begin{column}{0.62\textwidth} 511 \begin{itemize} 512 \item The service never sees your data --- but it can see 513 \textbf{volume} and \textbf{timing}. 514 \item \textbf{Padding} hides content, not~activity. 515 \item \textbf{Timing} reveals behavior: a backup before\\ a withdrawal, 516 or after a payment. 517 \item \textbf{Critical-point backups} cannot be dropped,\\ only 518 jittered. 519 \item Server must still be trusted to honor block deletion requests and 520 never keep older versions of the blocks. 521 \end{itemize} 522 \end{column} 523 \begin{column}{0.38\textwidth} 524 \centering 525 \includesvg[width=\textwidth,height=0.90\textheight,keepaspectratio]{assets/trust} 526 \end{column} 527 \end{columns} 528 \end{frame} 529 530 \begin{frame}{Future work} 531 \begin{columns}[T] 532 \begin{column}{0.60\textwidth} 533 \begin{itemize} 534 \item \textbf{Reconciliation}: fetch only the differences, \\ not the whole list. 535 \begin{itemize} 536 \item Invertible bloom filters. 537 \end{itemize} 538 \item \textbf{Linked devices}: add, expire, revoke. 539 \item \textbf{Less metadata}: e.g. jitter the schedule. 540 \item \textbf{Anastasis integration}: \\ backup your backup key! 541 \item Proper security audit. 542 \item First production release! 543 \end{itemize} 544 \end{column} 545 \begin{column}{0.40\textwidth} 546 \centering 547 \includesvg[width=\textwidth,height=0.60\textheight,keepaspectratio]{assets/todo} 548 \end{column} 549 \end{columns} 550 \end{frame} 551 552 \begin{frame}{References} 553 \centering 554 \qrcode[height=0.50\textheight]{https://docs.taler.net/design-documents/092-incremental-backup-sync.html}\\[1.2em] 555 {\small Design Document \#92: Incremental Wallet Backup and Sync}\\[0.6em] 556 {\footnotesize\url{https://docs.taler.net/design-documents/092-incremental-backup-sync.html}} 557 \end{frame} 558 559 \begin{frame}{Acknowledgements} 560 \begin{minipage}{0.45\textwidth} \ \\ 561 {\tiny Funded by the European Union (Project 101135475).} 562 563 \begin{center} 564 \includegraphics[width=0.5\textwidth]{./texinputs/images/bandera.jpg} 565 \end{center} 566 \end{minipage} 567 \hfill 568 \begin{minipage}{0.45\textwidth} 569 {\tiny Funded by SERI (HEU-Projekt 101135475-TALER).} 570 571 \begin{center} 572 \includegraphics[width=0.65\textwidth]{./texinputs/images/sbfi.jpg} 573 \end{center} 574 \end{minipage} 575 576 \vfill 577 578 {\tiny Views and opinions expressed are however those of the author(s) only 579 and do not necessarily reflect those of the European Union. Neither the 580 European Union nor the granting authority can be held responsible for 581 them.} 582 \end{frame} 583 584 \begin{frame}{Contact} 585 \begin{columns}[c] 586 \begin{column}{0.62\textwidth} 587 \begin{itemize} 588 \item \textbf{\SPEAKER} 589 \item Email: \texttt{avalos@taler.net} 590 \item Web (personal): \url{https://avalos.ch/} 591 \item Web (Taler): \url{https://www.taler.net/} 592 \end{itemize} 593 \vskip1.2em 594 {\large Questions? Let's talk!} 595 \end{column} 596 \begin{column}{0.38\textwidth} 597 \centering 598 \end{column} 599 \end{columns} 600 \end{frame} 601 602 \end{document}