Jan 1, 2024·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
With the rise of decentralized systems and applications that run over multiple blockchains, there is a growing need for architectures and bridges that ensure the trusted transfer of data and assets between the chains. zkBridge (ACM CCS'22) is a cross-chain bridge protocol that was proposed for non-permissioned blockchain and uses a network of relays, each working (for example as a light node) on a blockchain. A relay communicates with a corresponding smart contract on another chain to transfer data from the first chain to the second, and the smart contract on the second chain is used to verify the correctness of the received data from the first chain. zkBridge designs and implements optimized zero-knowledge proofs, that minimize the work of the smart contract on the second chain to verify the correctness of the received data. In this paper, we consider applications that work across two or more permissioned blockchains. We propose sigBridge that uses the framework of zkBridge but replaces the costly zero-knowledge proof computation with a pair of algorithms based on the consensus algorithm of the first chain. The algorithms will be run by a relay node on the first chain and a smart contract on the second chain and provide verifiability of data and asset transfer from the first chain to the second. The pair of algorithms are significantly more efficient compared to generating zero-knowledge proofs, verifying them, or running the full consensus algorithm of the first blockchain. We then show how a decentralized user-centric resource-sharing application will work over this architecture. We give a proof-of-concept implementation of an attribute-based access control system for a resource-sharing application that runs over two private Ethereum blockchains, and report the computation costs of the protocol.
Haotian Deng, Tao Liu, Xiaochen Ma, Weijie Wang · 7 authors
The space-air-ground integrated networks (SAGINs) are pivotal for modern communication and surveillance, with a growing number of connected devices. The proliferation of IoT devices within these networks introduces new risks due to potential erroneous synergistic interactions that could compromise system integrity and security. This paper addresses the challenges in coordination, synchronization, and security within SAGINs by introducing a novel static program analysis (SPA) technique using zero-knowledge (ZK) proofs. This approach ensures the detection of risky interactions without compromising sensitive source code, thus safeguarding intellectual property and privacy. The proposed method overcomes the incompatibility between SPA and ZK systems by developing an imperative programming language for SAGINs and a specialized abstract domain for interaction threats. The system translates network control algorithms into arithmetic circuits suitable for ZK analysis, maintaining high accuracy in detecting risks. Evaluations of real-world scenarios demonstrate the system’s efficacy in identifying risky interactions with minimal computational overhead. This research presents the first ZK-based SPA scheme for SAGINs, enhancing security and confidentiality in network analysis while adhering to privacy regulations.
As the practical applications of fully homomorphic encryption (FHE), secure multi‐party computation (MPC) and zero‐knowledge (ZK) proof continue to increase, so does the need to design and analyze new symmetric‐key primitives that can adapt to these privacy‐preserving protocols. These designs typically have low multiplicative complexity and depth with the parameter domain adapted to their application protocols, aiming to minimize the cost associated with the number of nonlinear operations or the multiplicative depth of their representation as circuits. In this paper, we propose two differential fault attacks against a one‐way function RAIN used for Rainier (CCS 2022), a signature scheme based on the MPC‐in‐the‐head approach and an FHE‐friendly cipher HERA used for the RtF framework (Eurocrypt 2022), respectively. We show that our attacks can recover the keys for both ciphers by only injecting a fault into the internal state and requiring only one normal and one faulty ciphertext blocks. Thus, we can use only the practical complexity of 2 26.6 /2 28.8 /2 30.4 bit operations to break the full‐round RAIN with 128/192/256‐bit keys. For full‐round HERA with 80/128‐bit key, our attack is practical with complexity the complexity of 2 20 encryptions with about 2 16 memory.
Remote attestation (RA) protocols have been widely used to evaluate the integrity of software on remote devices.Currently, the state-of-the-art RA protocols lack a crucial feature: transparency.This means that the details of the final attestation verification are not openly accessible or verifiable by the public.Furthermore, the interactivity of these protocols often limits attestation to trusted parties who possess privileged access to confidential device data, such as pre-shared keys and initial measurements.These constraints impede the widespread adoption of these protocols in various applications.In this paper, we introduce zRA, a non-interactive, transparent, and publicly provable RA protocol based on zkSNARKs.zRA enables verification of device attestations without the need for pre-shared keys or access to confidential data, ensuring a trustless and open attestation process.This eliminates the reliance on online services or secure storage on the verifier side.Moreover, zRA does not impose any additional security assumptions beyond the fundamental cryptographic schemes and the essential trust anchor components on the prover side (i.e., ROM and MPU).The zero-knowledge attestation proofs generated by devices have constant size regardless of the network complexity and number of attestations.Moreover, these proofs do not reveal sensitive information regarding internal states of the device, allowing verification by anyone in a public and auditable manner.We conduct an extensive security analysis and demonstrate scalability of zRA compared to prior work.Our analysis suggests that zRA excels especially in peer-to-peer and Pub/Sub network structures.To validate the practicality, we implement an open-source prototype of zRA using the Circom language.We show that zRA can be securely deployed on public permissionless blockchains, serving as an archival platform for attestation data to achieve resilience against DoS attacks.
<abstract> <p>This paper proposes a deterministic nonce generation technique to address the catastrophic issues associated with nonce reuse in message signing and to enhance the efficiency of Schnorr multi-signature schemes. Additionally, this research aims to reduce computational complexity and bandwidth requirements in digital and multi-signature schemes while maintaining robust security against common attacks. The proposed method was inspired by the EdDSA approach. The methodology includes a comprehensive mathematical analysis of digital signature algorithms and a rigorous examination of their vulnerabilities to well-known cryptographic attacks. This analysis evaluates the effectiveness and robustness of the proposed nonce generation technique within the frameworks of the Schnorr digital signature and the two-round MuSig schemes. Techniques and tools employed in this research involve deterministically generating nonces by hashing the private key and subsequently hashing the result with the message. Furthermore, it is proposed to exclude the public nonce R from the challenge calculations and to allow signers to directly prove possession of their secret keys through the aggregated public key, thereby eliminating the need for non-interactive zero-knowledge (NIZK) proofs. The findings demonstrate significant reductions in computational complexity and operational requirements, thereby improving bandwidth efficiency and making this method well-suited for resource-constrained devices. The approach also exhibits strong resistance to various attacks, including nonce reuse, key cancellation, rogue keys, and virtual machine rewinding.</p> </abstract>
Open access
Handwritten Text Recognition Techniques
Advanced Steganography and Watermarking Techniques
In an era marked by rapid technological advancement, the fusion of Artificial Intelligence (AI), Machine Learning (ML), and Distributed Ledger Technology (DLT), commonly referred to as blockchain, represents a pioneering frontier in healthcare and psychology.This paper explores the transformative potential of integrating these technologies to reimagine traditional practices and unlock novel approaches to patient care, diagnostics, therapy, and mental health management.Specifically, it investigates the unique and complementary roles that AI, ML, and DLT can play within healthcare and psychology, presenting a detailed roadmap for researchers, practitioners, and stakeholders.Through AI and ML's advanced analytics and predictive capabilities, and blockchain's secure, decentralized data management, this paper demonstrates how these technologies can collectively enhance diagnostic precision, personalize treatment plans, optimize resource allocation, and streamline administrative workflows.Central to this study is a proposed technical architecture, illustrating how AI, ML, and DLT can be integrated within healthcare workflows.This includes using blockchain for secure, verifiable patient data storage and off-chain AI/ML processing for real-time, data-driven insights.Additionally, this paper discusses practical methods, such as zero-knowledge proofs and federated learning, to maintain privacy and regulatory compliance in handling sensitive health data, especially in mental health contexts.Addressing the importance of ethical considerations, this paper highlights best practices in responsible innovation, emphasizing transparency, accountability, and fairness in the deployment of these technologies.Compliance with frameworks like GDPR and HIPAA is discussed as crucial for ensuring patient rights and establishing trust in data handling practices.Moreover, the paper underscores the need for interdisciplinary collaboration, identifying structured models for joint efforts between healthcare professionals, data scientists, and blockchain developers.Examples include cross-disciplinary training sessions, shared project management How to cite this paper:
Open access
Artificial Intelligence in Healthcare and Education
Decentralized identity represents an innovative approach based on blockchain to achieve effective identity management. This method utilizes decentralized identifiers and verifiable credentials to enable trusted authentication, free circulation of identity information, and self-sovereign control over identity data functionalities. The current decentralized identity systems rely on entirely anonymous identifiers, lacking robust identity regulation. Furthermore, they face challenges such as identity attribute leakage during verifiable credential presentation and the issuers’ struggle to reliably revoke credentials. To address these issues, efficient and practical schemes have been designed based on BBS signature, zero-knowledge proof, dynamic accumulator, and blockchain technology: one for decentralized identifiers management and the other for verifiable credential privacy protection, both of which are supervised and revocable. The former ensures the privacy of subject identity while achieving regulatability and revocability of identity data by the regulator. The latter facilitates selective disclosure of anonymous credentials and reliable revocation. A security analysis shows that the proposed scheme meets anonymity, non-forgeability, regulatory reliability, and revocability reliability, and offers comprehensive and effective privacy protection measures. The experimental results demonstrate that the algorithms designed operate at a millisecond level, which satisfies the demands of blockchain identity management scenarios.
The application of Artificial Intelligence (AI) in educational analytics has ushered in unprecedented enhancement in student learning prediction, learning at scale, auto-grading, and institution-level decision-making. However, the increased generation and processing of student information precipitate unprecedented concerns in privacy and security, spanning breaches and inference attacks through adversarial manipulations, unauthorized third-party information extraction, and AI model explainability restrictions. In this article, we provide a critical overview of privacy-preserving AI-based educational analytics databases, from state-of-the-art approaches such as Differential Privacy (DP), Federated Learning (FL), Homomorphic Encryption (HE), Secure Multi-Party Computation (SMPC), and Blockchain. Global regulation compliance regimes such as the General Data Protection Regulation (GDPR), the Family Educational Rights and Privacy Act (FERPA), and the California Consumer Privacy Act (CCPA) are reviewed, with the ethical trade-offs and conflicts between utility and privacy preservation laid bare. Projected future directions from Zero-Knowledge Proofs (ZKP) and decentralized AI platforms through hybrid AI-privacy architecture and explainable AI (XAI) are discussed.
Large language models (LLMs) have brought significant advancements to artificial intelligence, particularly in understanding and generating human language. However, concerns over management burden and data security have grown alongside their capabilities. To solve the problem, we design a blockchain‐based distributed LLM framework, where LLM works in the distributed mode and its outputs can be stored and verified on a blockchain to ensure integrity, transparency, and traceability. In addition, a multiparty signature‐based authentication mechanism is necessary to ensure stakeholder consensus before publication. To address these requirements, we propose a threshold elliptic curve digital signature algorithm that counters malicious adversaries in environments with three or more participants. Our approach relies on discrete logarithmic zero‐knowledge proofs and Feldman verifiable secret sharing, reducing complexity by forgoing multiplication triple protocols. When compared with some related schemes, this optimization speeds up both the key generation and signing phases with constant rounds while maintaining security against malicious adversaries.
This article explores the importance of putting users at the center of consent processes, in Single Sign On (SSO) systems to tackle privacy issues and empower user independence. It dives into the world of SSO systems shedding light on their privacy weaknesses and the need for users to have control over how their data is shared. By looking at privacy focused SSO solutions and their drawbacks the article suggests a plan to give users control over their data sharing preferences during authentication. The main elements of this plan include a user consent management interface, consent choices, educational materials, preference persistence and tracking logs. Additionally it talks about the obstacles in implementing consent driven SSO systems like creating consent APIs and incorporating privacy boosting technologies such as zero knowledge proofs and decentralized identity frameworks. By tackling these hurdles and promoting designs that prioritize users the article aims to help create authentication solutions that prioritize privacy in line, with changing regulations and user desires.
Innocent Pangapanga‐Phiri, Hambulo Ngoma, Christian Thierfelder
Abstract Smallholder farming systems need climate-proofing and sustainable intensification practices such as conservation agriculture (CA), are promising options. However, there is a general perception that the adoption of CA systems in southern Africa is low. Sentinel sites, where CA has been promoted for a long time, offer forward-looking new insights. This paper, thus, takes a deep dive at Nkhotakota district of Malawi to understand what could have led to the success of CA promotion and subsequent perceived high adoption. We use survey data from 620 farmers, with 298 farmers sampled from treatment areas – known to have had contact with host farmers and 320 from a control group. Overall, 31% of the farmers in both groups adopted full CA over at least a 2-year period. We also find that about 57% of farmers in the treatment area adopted full CA and only 7% of farmers in the control areas. This highlights that longer-term CA promotion with dedicated extension support can enhance the uptake of CA practices. In essence, this paper offers a different perspective to the current narrative that CA systems are too complex and knowledge intensive to be adopted despite its long-term promotion and significant investments. However, there are some nuances: sustained adoption even in sentinel sites is neither 100% nor persistent over the long term. We find an appreciable adoption decay, showing large declines from highs of 57 and 7% in adoption for at least 2 years for treatment and control, respectively, to 12% in the treatment group and practically zero in the control when we condition full CA adoption to at least 7 years. This means that fewer farmers adopted CA for a longer period and suggests some dis-adoption over time even in sentinel sites. The key adoption enablers in the sentinel sites include the availability of training, dedicated longer-term extension support coupled with farmer experiential learning through demonstration plots managed by host farmers. Based on our findings, there is need to consistently promote CA using farmer-centric approaches that include peer-to-peer learning over long periods. This allows farmers time to experiment with different CA options, enable behavioral and lasting change. At policy level, there is need to build and strengthen farmer groups to facilitate easier access to inputs like leguminous crop seeds for farmers practicing CA and to offer market-smart incentives to induce initial adoption in the short term to facilitate sustained adoption.
Zeng Huang, Ming‐Tian Zhang, Tengfei Liu, Anjia Yang
Federated learning is an important distributed model training technique in Internet of Things (IoT), in which participant selection is a key component that plays a role in improving training efficiency and model accuracy. This module enables a central server to select a subset of participants to perform model training based on data and device information. By doing so, selected participants are rewarded and actively perform model training, while participants that are detrimental to training efficiency and model accuracy are excluded. However, in practice, participants may suspect that the central server may have miscalculated and thus not made the selection honestly. This lack of trustworthiness problem, which can demotivate participants, has received little attention. Another problem that has received little attention is the leakage of participants’ private information during the selection process. We will therefore propose a federated learning framework with auditable participant selection. It supports smart contracts in selecting a set of suitable participants based on their training loss without compromising the privacy. Considering the possibility of malicious campaigning and impersonation of participants, the framework employs commitment schemes and zero-knowledge proofs to counteract these malicious behaviors. Finally, we analyze the security of the framework and conduct a series of experiments to demonstrate that the framework can effectively improve the efficiency of federated learning.
Commitment schemes are cryptographic schemes that can be applied to zero-knowledge proof construction and blockchain construction. Recently, lattice-based cryptography has been intensively investigated due to the promising potential in quantum cryptography. Accordingly, commitment schemes based on lattice assumptions have been studied for practical applications. Notably, applications often require committing an arbitrary message with low communication costs, so commitment schemes must be satisfied with fewer length restrictions and fewer extensions to the messages. Several studies have been conducted to achieve the problem, including the study published by Baum et al. in 2018. However, the scheme in question still utilizes the message domain for extraneous purposes. We design a length-extension-free commitment scheme ComMWMin which the length of the message string is large relative to the length of the commitment string, improving on the commitment scheme of Baum et al. Furthermore, we prove that the hiding and binding properties of ComMWMare based on the hardness of the decisional search knapsack problem and extended search knapsack problems, respectively. Finally, we evaluate the computation costs of generating commitment value between ours and Baum et al.’s commitment scheme.
Charity donations are a critical mechanism for social resource distribution. However, traditional donation systems, typically centralized, are prone to issues such as data redundancy, vulnerability to single-point failures, and a deficiency in transparency and traceability. Although blockchain-based donation programs have emerged to address trust issues inherent in centralized models, they often neglect critical security concerns like privacy protection and identity authentication. This paper introduces Eisdspa, a blockchain-based donation system designed to offer identity authentication, auditability, and privacy protection. Specifically, we introduce an identity credential system that facilitates anonymous donations, shielding the identities of both donors and donees through the use of BBS+ signatures and zero-knowledge proofs of knowledge (ZKPoKs). Additionally, we ensure the integrity of goods donations by offering robust auditability and protecting user privacy with Pedersen commitments and ZKPoKs. We formally define the privacy aspects of Eisdspa and conduct a security analysis of the system under the random oracle model. A prototype implementation of the scheme, along with a comparative analysis with existing solutions, highlights the benefits of Eisdspa. Moreover, we assess the computational efficiency of Eisdspa, with experimental results indicating its high performance in computational overhead.