The Abolition of the House

2026-06-05 · 6,059 words · Singular Grit Substack · View on Substack

On how three cryptographic primitives — dealerless dealing, broadcast encryption, and exchangeable goods

On how three cryptographic primitives — dealerless dealing, broadcast encryption, and exchangeable goods — dissolve the trusted operator that every game has required, and remake the game from a service rendered into a protocol enacted among the players themselves


Keywords: games; the trusted operator; broadcast encryption; mental poker; dealerless protocols; traitor tracing; revocation; digital scarcity; programmable property; selective disclosure; information asymmetry; portable assets; provable fairness; collusion.

Abstract. The four essays preceding this one developed, separately, the means to deal cards without a dealer, to make a digital object genuinely scarce and ownable, to relocate the social power these imply, and to find the physical floor beneath every key. This essay gathers them and turns them upon a single application — the game — and upon the single institution that organized play has always required: the trusted operator, which in the language of the gaming hall is simply called the house. I argue that a game operator is, on inspection, not one trusted party but three, bundled into one coat for the sole reason that one trusted party was historically the cheapest way to provide all three services at once. The house is trusted to run fair mechanics — to shuffle, deal, and randomize without cheating; it is trusted to keep the secrets — your hand, the face-down card, the fog over the map — and to reveal them only to those entitled and only when due; and it is trusted to custody the property — the chips, the items, the rare card, the balance. Each of these three trust burdens, I show, has its own and separate cryptographic dissolution: dealerless dealing for fairness, broadcast encryption with traitor tracing for secrecy, and programmable digital scarcity for property. Taken one at a time they are interesting; taken together they are decisive, for when all three are supplied the operator has nothing left to do and quietly ceases to exist. What remains is a game that is fair without a referee, confidential without an observer, and propertied without a custodian — a protocol enacted directly among the players, with assets that are real and that cross the boundary of any single game. I develop the synthesis, the new kinds of games it makes buildable, and — holding both faces, as this series has throughout — the costs it does not abolish: the collusion cryptography cannot reach, the physical secret beneath every credential, the power that relocates rather than vanishes, and the recourse that disappears along with the custodian.


I. The house as a trinity of trust

Consider what is actually being trusted when one sits down to a game run by another party, for the matter is so familiar that its structure has become invisible, and the structure is the whole of the argument. Whether the game is dealt across green baize in a hall of mirrors, or served from a distant machine to ten thousand screens, or printed as a deck of collectible cards by a publisher who decrees which of them shall be rare, or maintained as a persistent world upon a company’s servers, the operator who stands at the centre is trusted to perform three services which are, on the slightest reflection, entirely distinct from one another.

The first is fairness of mechanism: that the shuffle is honest and the deal unrigged, that the die is fair and the random draw truly random, that the operator has not arranged the order of the cards to favour the favoured or to fleece the mark. The second is keeping of secrets: that the hidden information of the game — the cards in your hand that I must not see, the face-down card that no one may see until it is turned, the portion of the map that the fog conceals — is held faithfully and disclosed to each participant only in the measure and at the moment the rules allow. The third is custody of property: that the chips represent value the house will honour, that the rare item in your inventory will not be duplicated into worthlessness or confiscated on a whim, that the balance in your account is yours and will be paid. These three — fairness, secrecy, property — are not one thing but three things, and we have bundled them into the single institution of the house for the same reason we once bundled so much else into single trusted institutions: because, in a world without the right cryptography, one trusted party was the cheapest and often the only way to provide all three together. The thesis of this essay is that each of the three has now acquired its own separate dissolution, and that what can be dissolved separately can be dissolved together, leaving the coat with no body inside it.

It is worth dwelling on why the bundle held together for so long, for the reason is not historical accident but technical necessity, and seeing the necessity clearly is what lets us recognize its passing. To provide fair mechanism one needed a party trusted to randomize honestly; to keep secrets, a party trusted not to peek; to custody property, a party trusted neither to steal nor to duplicate. In the absence of any means to obtain these three guarantees without a trusted party, the cheapest arrangement by far was to find a single party one could trust for all three at once and to call it the house — and so the casino, the card room, and later the server became the universal form of organized play, not because anyone preferred a master but because no alternative was known. The modern online operator did not loosen this bundle but drew it tighter, adding to the three classical trusts a fourth and a fifth — the matchmaking that pairs the players, the anti-cheat that polices them — and concentrating ever more of the game into a single point that had to be trusted absolutely and could betray or fail catastrophically. The bundle was always a response to a constraint; and when the constraint is lifted, as the cryptography of the last decades has lifted it, the bundle has no further reason to cohere, and may be taken apart trust by trust.

II. Fairness without a dealer

The first of the three was the burden of the first essay in this series, and it need only be recalled here in its capacity as one leg of a tripod. The old and elegant problem of playing a fair game of cards over a distance, with no trusted dealer and no party able to cheat, was posed and largely solved a long generation ago: a protocol by which mutually distrustful players jointly shuffle and encrypt a deck such that no one of them knows the order, none can alter it undetected, and each card can be revealed selectively to the player entitled to it and to no other [5]. The construction was refined and made rigorous, given proofs that it concealed what it claimed to conceal and resisted the coalitions of cheating players who would otherwise conspire [6, 7], and it drew upon two foundational tools that recur throughout this synthesis: the sharing of a secret among many parties so that no one alone can reconstruct it [9], and the general result, astonishing when first proven, that any computation whatever which a trusted party could perform can instead be performed jointly by the distrustful parties themselves, revealing nothing but the result [10]. To this was added the means to prove that a shuffle was a genuine permutation and not a substitution — a verifiable shuffle, by which the honesty of the rearrangement is demonstrated to all without revealing the arrangement itself [8].

The upshot, for our purposes, is simply stated: the first leg of the house — the fair deal — needs no dealer. The randomness can be produced jointly and verified publicly; the shuffle can be proven honest without being revealed; the cards can be concealed from all and opened selectively to the entitled. The croupier’s hands, which we watched so anxiously across the baize, are revealed as a thing we no longer require, for the players can shuffle for themselves and prove to one another that they have shuffled fairly. One leg of the tripod is sawn through. But a deal that is fair is not yet a game, for a game of any depth turns on what is hidden, and the keeping of the hidden is the second and the subtler burden.

III. Secrecy without a keeper: the discipline of broadcast encryption

Pause over how much of the pleasure and the substance of games lives precisely in controlled asymmetry of knowledge — in the fact that I know my hand and you do not, that the face-down card is a mystery to the whole table, that the general cannot see the army behind the hill, that the murderer’s identity is concealed until the reveal. Strip the secrecy from such games and nothing remains; they are not games of skill or nerve or deduction but mere exercises in arithmetic performed in the open. The hidden information is the game. And the keeping of that hidden information has, historically, been the second great service of the operator: the server holds every secret — every hand, every hidden tile, every unexplored region — and discloses to each player exactly the fragment that player is entitled to see, trusting itself not to peek, not to leak, and not to whisper to a favoured confederate. To remove the operator from the game, one must therefore find a way to keep the secrets without a keeper, and the cryptographic discipline that addresses this directly is the one this series has not yet treated: broadcast encryption.

The primitive was named and first formally studied three decades ago, and it answers a question that is exactly the question games pose [1]. The question is this: how may one transmit information so that precisely a chosen subset of the recipients can read it, and no one outside the subset can, even should every excluded party pool its keys in collusion? The early constructions were combinatorial and the schemes have grown vastly more efficient since, to the point where one can broadcast to any chosen subset of a vast population with ciphertexts and keys of constant or near-constant size, fully resistant to collusion by any number of the excluded [4]. Mapped onto a game, the correspondence is immediate and exact. The hidden state of the game is not held by an operator and parcelled out; it is distributed already enciphered, so that each fragment of secret knowledge can be opened only by exactly those players the rules entitle to it — your hand readable by you alone, the face-down communal card by no one until the protocol opens it to all at once, the contents of a region by those whose pieces can see it. The subset who may read is chosen by the rules, enforced by the mathematics, and verified by the participants; there is no observer in the middle who could peek, because there is no decipherable plaintext in the middle at all.

One must be candid about how this composes with the dealerless deal of the previous section, for the two are not the same mechanism, and the honesty of the synthesis depends on the seam between them being shown rather than concealed. The joint shuffle produces the concealed cards; what governs which player may open which card, how the right to open is withdrawn when a player departs, and how the leakage of an opening-key is traced, is the discipline of selective, revocable, traceable disclosure that broadcast encryption names and supplies. In the fully dealerless setting the sealing of a secret is not performed by a single trusted sender, as the textbook primitive assumes, but emerges from the joint construction itself; broadcast encryption is therefore better understood here as the conceptual home and the source of machinery for the subset-access problem — who may see, who has left, who has leaked — than as a black box dropped in unaltered. A concrete hand makes the composition vivid. The players jointly shuffle and seal the deck, no one knowing its order; each player’s two concealed cards are sealed so that he alone may open them; the community cards are sealed so that none may open them until the protocol, at the appointed moment, opens each to the whole table at once; a player who abandons the hand surrenders his concealed cards without their ever being revealed, and a player expelled for cheating is struck from every future disclosure. At no point does any party hold a plaintext it is trusted not to read, because at no point is there a trusted party at all.

To this the discipline adds two faculties that games have always needed and never cleanly possessed. The first is revocation: membership in a game is not static — players join, players leave, players are removed for misconduct — and the schemes developed for the hardest case, that of receivers who cannot be assumed to be online or to have remembered any prior message, allow the set of those who can decrypt to be changed at will, a departed or expelled player simply ceasing to be among those any future secret will open to [3]. The second, and the more striking for games, is traitor tracing: the means, when a secret has leaked or an unauthorized decoder has appeared, to identify which legitimate key-holder’s key was used to produce the leak [2]. Here one must be exact and refuse the overclaim, for the faculty is precise and its boundary matters. Traitor tracing catches the redistribution of keys and the manufacture of pirate decoders — the player who extracts and sells or shares the cryptographic credential by which secrets are opened; it stamps such leakage with the identity of the leaker, so that the betrayal is not anonymous and the traitor may be named and removed. What it does not and cannot do is prevent a player from simply telling a confederate what he has seen with his own eyes — of which more, honestly, below. But within its true boundary the faculty is real and valuable, and it gives hidden-information games a structural handle on credential-leakage and decoder-piracy that the trusted-operator model never possessed either.

The second leg of the tripod is thus sawn through. The secret needs no trusted keeper, for it can be distributed already sealed to exactly its rightful readers, the readership revised as players come and go, and the leakage of keys made traceable to the one who leaked. The general who could see the whole board, the server that held every hand, the broadcaster who knew every secret before the audience did — these are revealed, like the croupier, as conveniences we can dispense with. What remains is property, the third leg, and here the dissolution comes not from concealment but from its opposite: from making certain things at last truly, scarcely, portably real.

IV. Property without a custodian: the exchangeable good

The third service of the house was the keeping of the stakes, and it was the burden of the second essay in this series, recalled now as the final leg. A game’s chips, its items, its rare cards, its balances, have always been the property of the player only in a courtesy sense, for their existence and their integrity depended wholly upon the operator’s database and the operator’s goodwill: the item could be duplicated into worthlessness, the balance frozen, the rare card reprinted, the whole inventory annihilated should the operator close its doors, and the player had, in the end, no thing he could hold but only an entry in a ledger he did not control. The achievement of genuine digital scarcity changes the contract at its root. An item can now be made a real bearer object — scarce by construction, owned by possession of a key rather than by an operator’s say-so, transferable directly from one holder to another, and governed by rules its creator composes and embeds: open and freely tradeable, or carrying a royalty to its maker on each resale, as the creator chooses [11, 13]. The means of representing such ownable, transferable, rule-bearing objects has been given standard form [12], and the older cryptographic lineage of unforgeable, privacy-preserving tokens stands behind it [14].

The third leg is sawn through: the stake needs no custodian, for it can be a thing the player truly holds. But notice the new property that emerges here, which no operator-bound item ever possessed and which matters more for games than the mere fact of ownership — portability. An item whose existence depends on an operator’s server is a prisoner of that server; it cannot leave the game it was born in, because outside that game it does not exist. An item that is real bearer property is under no such confinement. It wanders, as money wanders, into any market or any game that will recognize and accept it; the sword earned in one world may be borne into another that honours the same standard; the card bought once may be played in any compatible game; the asset may be lent, sold, inherited, or simply carried away, because it is a thing and not a permission. And with portability comes a price discovered rather than decreed: the value of an operator-bound item was whatever the operator’s store chose to charge, set by fiat and confined to a single game, whereas the value of a bearer asset that trades across many games and markets is found the way the price of any freely traded thing is found — by the meeting of those who wish to hold it with those who wish to part with it, across every venue that will accept it. The rare card ceases to be rare because a publisher declares it so and printed few; it is rare because few exist and many desire them, and its worth becomes the worth the open market assigns rather than the number on an operator’s price-list. The operator who custodied the stake did so as a jailer as much as a guardian, and the exchangeable good walks out of the jail. With this the third leg falls, and all three having fallen, we may at last say what is left when the house is gone.

V. The synthesis: the game as protocol, not service

Set the three dissolutions side by side and the conclusion assembles itself. Fairness without a dealer; secrecy without a keeper; property without a custodian. The operator was trusted for exactly these three things and for nothing else of substance, and each has now its own and independent abolition; and what can be abolished independently can be abolished together. When the deal is dealt by the players jointly and proven fair, when the secrets are sealed already to their rightful readers and traceable when leaked, when the stakes are real objects the players hold for themselves — then the party in the middle has been relieved of every duty it ever discharged, and, like a functionary whose every function has been automated, it has no remaining reason to draw breath. The house is not defeated or evicted; it is rendered unnecessary, which is a deeper thing, and it simply ceases to be.

What remains when it ceases is worth naming precisely, for it is the integrating insight toward which the four prior essays were severally pointing. A game ceases to be a service rendered by an operator and becomes a protocol enacted among participants — the way a conversation is not a service one purchases from a conversation-provider but an activity free people simply conduct among themselves. The deepest reconception is this: the house, the single most universal institution of organized play, stands revealed as a bundle of three trust-economies, no one of which any longer requires a trusted party to operate; and a game, stripped of the operator that delivered it, is revealed as what it perhaps always was beneath the institution — a structure of agreed rules, of knowledge hidden and revealed by those rules, and of things worth holding, enacted directly among the players. The operator was never the game. The operator was the scaffolding we erected around the game because we could not otherwise trust the shuffle, keep the secret, or honour the stake. The scaffolding can now come down, and the game stands without it.

VI. The new games this makes buildable

It would be a thin achievement if all of this merely reproduced, without an operator, the games we already have; the synthesis is interesting precisely because it makes buildable several classes of game that the operator-bound model could not support at all, and these deserve concrete statement.

The first is the game of persistent and portable assets. Because the items are real bearer property rather than entries in one operator’s ledger, they outlive any single game and move between games: an economy of objects that compose across worlds as money composes across shops, a sword or a card or a parcel of land that is earned in one place, sold in a second, and wielded in a third, with genuine ownership, lending, inheritance, and resale. The player accumulates not a hoard trapped in one company’s servers but a portfolio of things he holds, and the things have lives longer than the games that mint them.

The second is operator-independent competitive integrity. A tournament or a ranked ladder whose fairness and confidentiality rest on the joint protocol rather than on an organizer’s honesty cannot be secretly rigged by that organizer, for there is no privileged seat from which to rig it; the absence of a house edge is not a promise to be believed but a property to be verified, and the suspicion that has always haunted high-stakes play — that the operator sees what it should not, or arranges what it should not — is answered structurally rather than by reputation.

The third is cross-game composability and emergent economies. Where assets are bearer instruments recognized across games, secondary markets arise without anyone building them, player-made games can share a common substrate of objects, and value flows between games as it flows between any two parties who trade — a fluidity of economic life across the boundaries of particular games that the walled gardens of operator-bound worlds could never permit, since each garden’s currency died at its wall.

The fourth is disclosure as a designed structure. Because broadcast encryption makes “who may see what, and when” a thing one explicitly constructs rather than a thing a trusted broadcaster does invisibly, a game may reveal exactly the right information to exactly the right audience at exactly the right time, with no trusted intermediary in the disclosure: a move committed in sealed form and proven later, a reveal delayed to spectators while immediate to players, a selective disclosure to an adjudicator without disclosure to opponents. The architecture of revelation becomes part of the game’s design, available to the designer as a first-class material.

And the fifth is the collusion-traceable hidden-information game. The oldest plague of multiplayer games of hidden knowledge is the secret sharing of that knowledge among confederates; and while, as I will insist below, cryptography cannot abolish the confederate, the tracing of traitors gives at least the leakage of credentials and the manufacture of shared decoders an identity, so that one whole avenue of organized cheating — the wholesale extraction and redistribution of the means to see what one should not — is made detectable and attributable in a way it never was when an operator simply hoped its system would not be pirated.

Beneath all five lies a shift in the very epistemics of fair play that deserves its own remark. Under the operator, the fairness of a game was a claim — asserted by the house, perhaps audited by a regulator the player also had to trust, and in the end believed rather than known. Under the protocol, fairness becomes a verifiable artifact: the transcript of a joint shuffle proven to be a true permutation, the public randomness anyone may check, the disclosure that demonstrably opens to exactly the entitled and to no others. The player need no longer trust that the game was fair; he, or anyone acting on his behalf, may verify that it was. This is the same movement from believed-claim to checkable-proof that runs through the whole of this series, and in games it dissolves the gambler’s oldest anxiety — that the house sees what he cannot and arranges what he must not — by removing the privileged vantage from which such arrangement was ever possible, and replacing the regulator’s promise with a proof the player may examine for himself.

VII. The honest counterweight

This series has held, in every essay, that the same achievement which liberates also costs, and that to celebrate the liberation while concealing the cost is the work of a salesman and not of an honest mind. The abolition of the house is no exception, and its costs must be stated as plainly as its powers.

The first and most important is that collusion is mitigated, not solved, and the boundary must not be blurred, for there are two quite different things that go by the name of collusion and the cryptography reaches only one of them. There is collusion within the protocol — the pooling of keys, the joint reconstruction of a secret that no single colluder could open alone — and against this the constructions are built to be resistant: the broadcast schemes secure against coalitions of the excluded, and the poker protocols designed, from early on, expressly to minimize the effect of player coalitions even where such coalitions could not be wholly abolished [15, 4]. And there is collusion outside the protocol — the player who simply tells a confederate, by a telephone in the next room or a mouth at the next chair, what he has honestly and legitimately seen with his own eyes. Against this second kind no mathematics avails, and none ever will, for the protocol cannot reach beyond the screen into the room where two people have agreed to share what each is entitled to know. Two persons in one room, or many accounts driven by a single ring, defeat the most perfect concealment by the oldest method in the world, which is to share what one has fairly seen. Traitor tracing catches the leakage and redistribution of keys and decoders; it does not catch the whispered word, and any honest account of these games must say so plainly, and design its incentives, its table structures, and its economic consequences around the collusion that no cipher will ever prevent. The confederate is older than cryptography, and will outlive it.

The second cost is the physical floor beneath every one of these primitives, which the fourth essay in this series laid bare: each of them — the joint deck, the sealed secret, the borne asset — rests upon private keys, and a key is a physical secret with a location, in a chip, on a disk, in a human memory, and it can be stolen, extracted, coerced, or lost. And here the abolition of the custodian exacts a peculiarly sharp price, for the player who holds his own stake as a bearer object holds it with no custodian to appeal to: the key stolen is the asset gone, finally, with no operator to restore the balance, no registrar to reverse the theft, no court of the game to make him whole. The same dissolution that freed the stake from the jailer stripped it of the guardian, and no-custodian means, with full and unforgiving symmetry, no-recourse.

The third cost is that power relocates rather than vanishing, exactly as the third essay argued of the wider case. “No operator” does not mean “no one with power over the game”; it means the power has moved — to the authors of the protocol, who are the new rule-givers; to the issuers of the assets, who compose the rules those assets obey and who are, in their quiet way, a new kind of house; to the maintainers of the standards that let assets cross between games; and to the large holders whose accumulated stakes confer influence. A game that proclaims itself to have no house while an unnamed party sets the rules of its tradeable goods has not abolished the house; it has merely hidden it, and the honest builder names the parties that remain.

The fourth cost is simple feasibility, soberly stated. Joint dealing, broadcast encryption to large dynamic sets, and the settlement of real assets all carry genuine costs — in rounds of interaction, in the size of ciphertexts and proofs, in the throughput and latency of whatever substrate records the assets — and the naïve composition of all three does not scale to a fast game with many players for free. The synthesis is buildable; it is not buildable carelessly, and to pretend the cryptography is free is itself a species of the overclaiming this series exists to refuse.

VIII. What a builder should take from this

If the analysis is right, then certain disciplines follow for anyone who would build games in this manner, and they are disciplines of clarity more than of cleverness. The first is to unbundle deliberately: to recognize that fairness, secrecy, and property are three distinct trust problems with three distinct solutions, and to resist the standing temptation to let one trusted component creep back in to serve all three at once because it is convenient — for the convenient trusted helper is the house returning by the side door, and the whole achievement is to keep it out. The second is to make the asset real, or not to call it owned: a thing whose existence depends on one’s own server is not the player’s property however it is described, and the discipline of genuine scarcity, with its portability and its harsh absence of recourse, must be embraced honestly and completely or not invoked at all.

The third discipline is to treat disclosure as a first-class design decision: who sees what, when, with what revocation when players leave, and with what tracing when keys are leaked — these are now things one designs, explicitly and visibly, rather than things a trusted server does in the dark, and the design of a game’s structure of revelation deserves the same care as the design of its rules of play. The fourth, inherited directly from the third and fourth essays of this series, is to name the residual trusted parties and the physical roots honestly: the asset-issuer who sets the rules, the authors who maintain the protocol, the keys whose physical custody is the true perimeter of every player’s security. A trust surface unnamed is a trust surface unguarded, and the builder who claims to have abolished all trust has merely stopped looking for the trust that remains. And the fifth is to build for the collusion one cannot prevent: to design the incentives, the structures, the table arrangements, and the economic consequences around the simple, permanent fact that confederates can share what they have seen, and that no theorem will stop them — so that the game remains good even where the cryptography reaches its honest limit.

IX. Coda: the game without a master

The four essays before this one abolished, in their turns, the dealer who dealt the cards, and the impossibility of owning what could be freely copied; and they asked who should keep the keys when the keepers had been dismissed, and found, beneath every key, the body that holds it. This essay has named the application in which those threads are gathered — the game — and the institution they jointly dissolve — the house: that trinity of trust, fairness and secrecy and property bundled into one coat, which we wore for so long because we had no other way to play together without a master to referee, conceal, and hold. The coat, we now find, may be taken off, for each of its three functions has been independently rendered unnecessary, and a game stripped of its operator is revealed as something both older and freer than the service we had mistaken it for — a structure of agreed rules, of knowledge hidden and shown, and of things worth holding, enacted directly among the players who need no master to enact it, and now need none.

But the master’s abolition is not the players’ liberation merely; it is the players’ responsibility assumed, and the honest mind will not pretend otherwise. The fairness they no longer delegate to a trusted dealer, they must now produce and verify among themselves. The secrets they no longer entrust to a faithful keeper, they must now keep with their own keys, in their own hardware, under their own discipline. The stakes they no longer leave in a custodian’s vault, they must now hold for themselves, with all the dignity of true ownership and all the peril of a theft that no one will reverse. And the power that no longer sits in the operator’s chair has not left the room; it has moved to the makers of the rules and the issuers of the goods, who must be watched the more carefully for sitting in no obvious seat. This is the bargain the abolition of the house offers, and it is the same bargain that all the great disintermediations offer: liberty in exact proportion to the burden one is willing to carry oneself. The house falls; the game remains; and what was a service purchased from a master becomes, once more, a thing that free people do among themselves — fairly, secretly, and for stakes they truly own — with all the liberty, and all the weight, that this has always meant.


References

[1] A. Fiat and M. Naor. “Broadcast Encryption.” In Advances in Cryptology — CRYPTO ‘93, LNCS 773, pp. 480–491. Springer, 1994.

[2] B. Chor, A. Fiat, and M. Naor. “Tracing Traitors.” In Advances in Cryptology — CRYPTO ‘94, LNCS 839, pp. 257–270. Springer, 1994. (Journal version: B. Chor, A. Fiat, M. Naor, and B. Pinkas, IEEE Transactions on Information Theory, 46(3):893–910, 2000.)

[3] D. Naor, M. Naor, and J. Lotspiech. “Revocation and Tracing Schemes for Stateless Receivers.” In Advances in Cryptology — CRYPTO 2001, LNCS 2139, pp. 41–62. Springer, 2001.

[4] D. Boneh, C. Gentry, and B. Waters. “Collusion Resistant Broadcast Encryption with Short Ciphertexts and Private Keys.” In Advances in Cryptology — CRYPTO 2005, LNCS 3621, pp. 258–275. Springer, 2005.

[5] A. Shamir, R. L. Rivest, and L. M. Adleman. “Mental Poker.” In D. A. Klarner (ed.), The Mathematical Gardner, pp. 37–43. Wadsworth International, 1981. (Originally MIT Laboratory for Computer Science technical memo, 1979.)

[6] S. Goldwasser and S. Micali. “Probabilistic Encryption and How to Play Mental Poker Keeping Secret All Partial Information.” In Proc. 14th ACM Symposium on Theory of Computing (STOC), pp. 365–377. ACM, 1982.

[7] A. Barnett and N. P. Smart. “Mental Poker Revisited.” In Cryptography and Coding 2003, LNCS 2898, pp. 370–383. Springer, 2003.

[8] C. A. Neff. “A Verifiable Secret Shuffle and Its Application to E-Voting.” In Proc. 8th ACM Conference on Computer and Communications Security (CCS), pp. 116–125. ACM, 2001.

[9] A. Shamir. “How to Share a Secret.” Communications of the ACM, 22(11):612–613, 1979.

[10] O. Goldreich, S. Micali, and A. Wigderson. “How to Play Any Mental Game, or A Completeness Theorem for Protocols with Honest Majority.” In Proc. 19th ACM Symposium on Theory of Computing (STOC), pp. 218–229. ACM, 1987.

[11] N. Szabo. “Formalizing and Securing Relationships on Public Networks.” First Monday, 2(9), 1997.

[12] W. Entriken, D. Shirley, J. Evans, and N. Sachs. “EIP-721: Non-Fungible Token Standard.” Ethereum Improvement Proposals, 2018.

[13] S. Nakamoto. “Bitcoin: A Peer-to-Peer Electronic Cash System.” Self-published white paper, 2008.

[14] D. Chaum. “Blind Signatures for Untraceable Payments.” In Advances in Cryptology — CRYPTO ‘82, pp. 199–203. Plenum Press, 1983.

[15] C. Crépeau. “A Secure Poker Protocol That Minimizes the Effect of Player Coalitions.” In Advances in Cryptology — CRYPTO ‘85, LNCS 218, pp. 73–86. Springer, 1986.


← Back to Substack Archive