Template-Type: ReDIF-Paper 1.0 Author-Name: Bernardo David Author-Name-First: Bernardo Author-Name-Last: David Author-Email: bernardo@bmdavid.com Author-Workplace-Name: IT University of Copenhagen, Copenhagen, Denmark Author-Name: Lorenzo Gentile Author-Name-First: Lorenzo Author-Name-Last: Gentile Author-Email: lorg@itu.dk Author-Workplace-Name: IT University of Copenhagen, Copenhagen, Denmark Author-Name: Mohsen Pourpouneh Author-Name-First: Mohsen Author-Name-Last: Pourpouneh Author-Email: mohsen@ifro.ku.dk Author-Workplace-Name: Department of Food and Resource Economics, University of Copenhagen Title: FAST: Fair Auctions via Secret Transactions Abstract: Auctioning an asset with sealed bids has been shown to be economically optimal but requires trusting an auctioneer who analyzes the bids and determines the winner. Many privacy preserving computation protocols for auctions have been proposed, aiming at eliminating the need for a trusted third party. However, they lack fairness, meaning that the adversary learns the outcome of the auction before honest parties and may choose to make the protocol fail without suffering any consequences. In this work, we propose efficient protocols for both first and second price sealed bid auctions with fairness against rational adversaries, leveraging secret cryptocurrency transactions and public smart contracts. In our approach, the bidders jointly compute the winner of the auction while preserving the privacy of losing bids and ensuring that cheaters are financially punished by losing a secret collateral deposit. We guarantee that it is never profitable for rational adversaries to cheat by making the deposit equal to the bid plus the cost of running the protocol, i.e., once a party commits to a bid it is guaranteed that it has the funds and it cannot walk away from the protocol without forfeiting the bid. Moreover, our protocols guarantee that the winner is determined and the auction payments are completed even if the adversary misbehaves, so that it cannot force the protocol to fail and then rejoin the auction with an adjusted bid. Our constructions are more efficient than the state-of-the-art even though they achieve stronger security guarantees, i.e., fairness. Interestingly, we show how the second price can be computed with a minimal increase of the complexity of the simpler first price case. Moreover, in case there is no cheating, only collateral deposit and refund transactions must be sent to the smart contract, significantly saving on-chain storage. Length: 46 pages Creation-Date: 2021-03 File-URL: http://okonomi.foi.dk/workingpapers/WPpdf/WP2021/IFRO_WP_2021_02.pdf File-Format: Application/pdf Number: 2021/02 Classification-JEL: D40, D44, C57 Keywords: Cryptographic Protocols, Multiparty Computation, Financial Cryptography, Auctions, Fairness, Blockchain Handle: RePEc:foi:wpaper:2021_02