Coin Brief ENDE

rippled adds a transaction to rotate or recover keys for confidential MPT balances

The XRP Ledger's reference server, rippled, has merged a new transaction type for confidential Multi-Purpose Tokens: ConfidentialMPTHolderKeyUpdate. The pull request was merged into the development branch on 2 October. It lets the holder of a confidential MPT balance replace the ElGamal key under which that balance is encrypted, without the issuer's involvement in the ordinary case.

Three modes, chosen by flag.

  • Rotation (tfHolderKeyRotation): the holder still has the current private key. They submit a new public key together with their spending and inbox balances re-encrypted under it, and the key and balances change at once.
  • Recovery (tfHolderKeyRecovery): the holder has lost the private key. They submit only a new public key, which is recorded as a pending RecoveryKey field on their MPToken entry. Balances are not touched until the issuer separately completes the recovery.
  • Cancel (tfCancelRecovery): the holder withdraws a pending recovery request.

The rules in the code. The transaction requires the existing ConfidentialTransfer amendment and is registered under its own, ConfidentialMPTKeyRotation, so it does nothing on mainnet until validators vote that in. The issuer of a token cannot use it on that token. A holder cannot open a second recovery while one is pending, cancelling requires a pending request, and a successful rotation clears any pending recovery key. Malformed ciphertexts are rejected before the transaction is applied. The change adds one new field, RecoveryKey, to the MPToken ledger object, and comes with around 700 lines of new tests.

What it is not. It is not a release. The code is on rippled's development branch and will reach validators only in a future version, after which the amendment has to win a vote.

rippled adds a transaction to rotate or recover keys for confidential MPT balances
rippled adds a transaction to rotate or recover keys for confidential MPT balances — Coin Brief

What it means

Confidential balances raise a problem transparent ones do not: if the encryption key is lost, nobody can read the balance, including the holder. This transaction answers it in two ways. Rotation is self-service, and recovery deliberately is not: it needs the issuer, which makes issuer-assisted recovery part of the design of a confidential token on the XRP Ledger, and something holders and issuers should agree on before balances are encrypted.

Primary source
XRPLF/rippled (GitHub)
https://github.com/XRPLF/rippled/pull/8266