Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results · page 120 of 177

Clear filters
Oct 21, 2022·arXiv (Cornell University)
2 cites
TAP: Transparent and Privacy-Preserving Data Services

Daniël Reijsbergen, Aung Htein Maw, Zheng Yang, Tien Tuan Anh Dinh · 5 authors

Users today expect more security from services that handle their data. In addition to traditional data privacy and integrity requirements, they expect transparency, i.e., that the service's processing of the data is verifiable by users and trusted auditors. Our goal is to build a multi-user system that provides data privacy, integrity, and transparency for a large number of operations, while achieving practical performance. To this end, we first identify the limitations of existing approaches that use authenticated data structures. We find that they fall into two categories: 1) those that hide each user's data from other users, but have a limited range of verifiable operations (e.g., CONIKS, Merkle2, and Proofs of Liabilities), and 2) those that support a wide range of verifiable operations, but make all data publicly visible (e.g., IntegriDB and FalconDB). We then present TAP to address the above limitations. The key component of TAP is a novel tree data structure that supports efficient result verification, and relies on independent audits that use zero-knowledge range proofs to show that the tree is constructed correctly without revealing user data. TAP supports a broad range of verifiable operations, including quantiles and sample standard deviations. We conduct a comprehensive evaluation of TAP, and compare it against two state-of-the-art baselines, namely IntegriDB and Merkle2, showing that the system is practical at scale.

Open access
Data Quality and Management
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Oct 21, 2022·Journal of Artificial Intelligence & Cloud Computing
0 cites
AI Enabled Security for Ethereum Blockchain Transactions

Ohm Patel

This article seeks to discuss the opportunity for security enhancement in the Ethereum blockchain by introducing AI into the Ethereum blockchain ecosystem. Integrating AI with blockchain includes revolutionary approaches to protecting transactions by using techniques like anomaly detection, fraud, and predictive analysis. Hopwood et al. provide a background to blockchain technology with much focus on security in decentralized networks, especially Ethereum. It explores the basics of blockchain security based on cryptographic techniques, consensus algorithms, and the weaknesses of smart contracts. The discussion then turns to opportunities for AI technologies in blockchain security and the example of how the technologies can identify and prevent various activities. The most elaborate part of the paper is the Sequencer Level Security (SLS) protocol, a relatively new one that offers an improved model of transaction security that isolates the undesirable ones. The rollups and Layer 2 solutions involve the presented case of the Zircuit prototype and the implementation of SLS. The paper also discusses how AI may enhance personal data protection in blockchain environments via methods such as decentralized identity and zero-knowledge proofs. Legal and ethical issues are discussed with reference to data protection laws, including GDPR and CPRA, and their effects on the incorporation of AI and blockchain systems. Finally, it envisions the future trends, issues, and opportunities of AI and blockchain security based on a suggested research agenda. Based on this all-around assessment, AI plays a pivotal part in enhancing the security and privacy of Ethereum blocks.

Open access
Blockchain Technology Applications and Security
Original source
Oct 18, 2022·Research Square
0 cites
A Key Management Protocol for Heterogeneous Sensor Networks Based on Zero Trust Security and Chaotic Neural Networks

Guogang Li, Tong Xie, Cheng Zou, Wenlong Fu

Abstract Aiming at the node security risks and key management vulnerabilities in heterogeneous sensor networks, a key management protocol for heterogeneous sensor networks based on zero-trust security and chaotic neural networks (KMPHSN-ZTSCNN) was proposed. Based on the singular matrix decomposition of difficulty and Hopfield overload chaos neural network classification features, using blockchain and zero-knowledge proof to realize sensor network node registration and authentication, it relies on channel state information (CSI) and adjustable mathematical function to generate dynamically changing keys to complete continuous verification and achieve zero-trust security authentication to ensure data security. The protocol can dynamically allocate different keyspace sizes according to the security level of the group, node storage capacity and computing capacity, and can adapt to the asymmetric structure of heterogeneous sensor networks. Theoretical proof and experimental performance analysis show that the protocol is feasible and can meet the security requirements of heterogeneous sensor networks.

Open access
Security in Wireless Sensor Networks
Original source
Oct 17, 2022·Journal of Parallel and Distributed Computing
223 cites
A blockchain-orchestrated deep learning approach for secure data transmission in IoT-enabled healthcare system

Prabhat Kumar, Randhir Kumar, Govind P. Gupta, Rakesh Tripathi · 6 authors

The integration of the Internet of Things (IoT) with traditional healthcare systems has improved quality of healthcare services. However, the wearable devices and sensors used in Healthcare System (HS) continuously monitor and transmit data to the nearby devices or servers using an unsecured open channel. This connectivity between IoT devices and servers improves operational efficiency, but it also gives a lot of room for attackers to launch various cyber-attacks that can put patients under critical surveillance in jeopardy. In this article, a Blockchain-orchestrated Deep learning approach for Secure Data Transmission in IoT-enabled healthcare system hereafter referred to as “BDSDT” is designed. Specifically, first a novel scalable blockchain architecture is proposed to ensure data integrity and secure data transmission by leveraging Zero Knowledge Proof (ZKP) mechanism. Then, BDSDT integrates with the off-chain storage InterPlanetary File System (IPFS) to address difficulties with data storage costs and with an Ethereum smart contract to address data security issues. The authenticated data is further used to design a deep learning architecture to detect intrusion in HS network. The latter combines Deep Sparse AutoEncoder (DSAE) with Bidirectional Long Short-Term Memory (BiLSTM) to design an effective intrusion detection system. Experiments on two public data sources (CICIDS-2017 and ToN-IoT) reveal that the proposed BDSDT outperformed state-of-the-arts in both non-blockchain and blockchain settings and have obtained accuracy close to 99% using both datasets.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Biometric Identification and Security
Original source
Oct 17, 2022·arXiv (Cornell University)
12 cites
Scaling up Trustless DNN Inference with Zero-Knowledge Proofs

Daniel Kang, Tatsunori Hashimoto, Ion Stoica, Yi Sun

As ML models have increased in capabilities and accuracy, so has the complexity of their deployments. Increasingly, ML model consumers are turning to service providers to serve the ML models in the ML-as-a-service (MLaaS) paradigm. As MLaaS proliferates, a critical requirement emerges: how can model consumers verify that the correct predictions were served, in the face of malicious, lazy, or buggy service providers? In this work, we present the first practical ImageNet-scale method to verify ML model inference non-interactively, i.e., after the inference has been done. To do so, we leverage recent developments in ZK-SNARKs (zero-knowledge succinct non-interactive argument of knowledge), a form of zero-knowledge proofs. ZK-SNARKs allows us to verify ML model execution non-interactively and with only standard cryptographic hardness assumptions. In particular, we provide the first ZK-SNARK proof of valid inference for a full resolution ImageNet model, achieving 79\% top-5 accuracy. We further use these ZK-SNARKs to design protocols to verify ML model execution in a variety of scenarios, including for verifying MLaaS predictions, verifying MLaaS model accuracy, and using ML models for trustless retrieval. Together, our results show that ZK-SNARKs have the promise to make verified ML model inference practical.

Open access
2 source records
COVID-19 diagnosis using AI
Medical Imaging Techniques and Applications
Advanced Neural Network Applications
Original source
Oct 16, 2022·The Medical Journal of Australia
22 cites
Climate change, society, and health inequities

Sharon Friel

Climate change will widen health inequities; action on the social determinants of health is essential In a conversation recently, a former senior public servant suggested to me that the social determinants of health are too theoretical. It is true that there are a number of theoretical perspectives associated with social determinants. A key one, from Nobel Laureate Amartya Sen,1 highlights the importance of having the freedoms and capabilities to lead a flourishing life. According to theory, these are shaped by the conditions in which people are born, live, work and age, which are unequally distributed.2 There is, however, nothing theoretical about the manifestation of social inequities and their impact on peoples’ health. Every day, people living in Australia embody stark inequities in income, working conditions, lived environment, and access to quality health and social care. For example, before the coronavirus disease 2019 (COVID-19) pandemic, Australians in the top 20% income bracket received six times more money than the lowest 20%.3 Three million Australians were estimated to be living below the poverty line in 2017, including 18% of all children.3 Before the pandemic, more than a million people were in rental stress, and waiting lists for social housing were into the hundreds of thousands.4 Within the first few months of 2020, 880 000 Australians lost their jobs, with women, young people, and those in precarious employment disproportionally affected.3 Workers in casual employment accounted for 63% of job losses between February and May 2020.3 Since the COVID-19 pandemic began, Australia’s 31 billionaires have increased their wealth by $85 billion.5 People embody these inequities,6 which makes them sick and contributes to high levels of premature death. In 2017, 17% of Victorians reported high psychological distress. In 2020, that rose to 44% and to 60% among those who lost their jobs.7 Across Australia, people living in the lowest socio-economic quintile had mortality rates twice as high as those in the highest quintile, and these inequities widened between 2011 and 2016.8 Despite narrowing, the gap in life expectancy between Indigenous and non-Indigenous Australians remains high.9 What do social determinants have to do with climate change and planetary health? The fires, hail, floods and droughts that Australia has endured in recent years10 affect everyone, but not everyone experiences them equally.11 Affluent people can afford to live in insulated buildings with air conditioning and air purifiers, or add flood proofing and extra drainage. Meanwhile, people who are poor, older individuals, people with disabilities, and those who are socially marginalised are the least able to adapt to the changing climate, unable to escape the fires and heat, and live in dwellings and environments that amplify its effects.11 As has happened in other countries experiencing similar impacts from climate change, having lost homes and livelihoods, and fearful for the future, some people may leave their communities and perhaps the country.12 This will exacerbate inequities, with those who have more financial and social capital having more options — wealthy Australians are already buying land in Tasmania to escape the worst ravages of climate change.13 For people living in caravan parks in Lismore, New South Wales, having insurance is a stretch.13 Moving is not an option. This climate change-exacerbated social inequity adds to existing inequities in disease burdens and premature mortality — this is climate change interacting with the social determinants of health inequities.11 Planetary health inequity is a concept that recognises the impact of climate change on social and health inequities. It also recognises the importance for health equity of considering planetary systems — if we do not have a functioning Earth system, we have social disruption and risk to human survival. Planetary health inequity therefore embodies the common drivers of climate change and health inequity. These common drivers comprise major structural forces. Power asymmetries between actors, institutions and ideas, a neoliberal fetishism of market forces and individualism, hyperglobalisation, and the associated norms and values that permeate institutions and communities affect policy decisions that structure society and differentially affect daily living conditions and, ultimately, health.14-18 These structural social determinants of health inequity overlap substantially with the drivers of climate change and can be described collectively as the global “consumptogenic system”. The consumptogenic system is characterised by institutions, policies, business practices, and social norms that embed and entrench principles of extractive capitalism and colonialism.19 Such a system encourages and rewards excessive production and hyperconsumerism of fossil fuel-reliant goods and services that are unhealthy and inequitably valued and distributed.20 If left on the current trajectory, the consumptogenic system will amplify potentially irreversible consequences for environmental degradation, inequalities and poor health. Governments have the chance to advance planetary health equity goals by addressing the consumptogenic system and inequitable distribution of resources that create negative health outcomes and climate change. The issue is not that it is too theoretical, the issue is the often lack of political will to address inequality, adopt a social model of health, and tackle climate change. In the May 2022 federal election, the Australian electorate demanded change. Encouragingly, the new Labor government promised to do better by the people and, although not in the language of the social determinants, their proposed action plan21 will go some of the way to advance planetary health equity goals. But it must go further. Achieving the transformative goal of planetary health equity requires a “social vaccine”22 (Box), the targets of which are the conditions underpinning four basic requirements for health and equity to flourish: a life with security, opportunities that are fair, a planet that is habitable by humans and supports biodiversity, and governance that is just. Achieving these conditions requires the ambition, design and implementation of policies that ensure a fair social foundation and economic environment operating within the ecological ceiling.23 In Australia, as elsewhere, we have long needed policy that helps with adaptation to the damage already done by climate change. Good social and planning policy that ensures access to safe, stable and affordable housing, decent working conditions for all, income support levels that enable living with dignity, and inclusive infrastructure development is good climate adaptation policy. They are also good health equity policies. Adaptation is essential. So too is mitigation. The Climate Change Bill 2022 commits Australia to a greenhouse gas emissions reduction target of a 43% reduction from 2005 levels by 2030. This target should be considered only a starting point. A roadmap to net zero and an empowered secure Climate Change Authority is essential. Adequate climate change mitigation and planetary health equity will not be achieved unless there is ambitious and immediate action that disrupts the consumptogenic system. The targets should be the institutions, actors, structures and discourses that embed, facilitate and normalise the global dominance of a consumptogenic system addicted to growth regardless of the environmental, social and health costs. At the very least, any new fossil fuel project must be assessed for potential damage to species and environments through its impacts on climate change. Fundamentally, however, disruption of this system requires Australia and the rest of the world to stop extracting, burning and investing in oil, coal, gas and other fossil fuels, with government vetoing all new fossil fuel developments. The absence of an overarching framework guiding the actions of all Australian Government departments in a mission towards planetary health equity is problematic. This lack of authorising environment enables at best an ineffective siloed, scattergun approach; at worst policy silence. Implementing a national strategy that brings together climate change, inequality and health, such as the proposed Climate and Health Alliance’s Healthy, Regenerative and Just framework, is essential.24 An engaged strong civil society is key to the delivery of a social vaccine. Implementing a progressive policy framework will confront stubborn resistance and challenge the power of dominant vested interests. Public-interest coalitions can support governments to act, as well as hold them to account.25 Climate change and health alliances are essential — doctors and other health professionals have knowledge, opportunity and political leverage that can help ensure actions are taken.24 This article has laid out ways of advancing planetary health equity goals. To help achieve these, the health community must advocate for and engage in intersectoral policy discussions relating to the social determinants and the structural consumptogenic system. Acting immediately on these issues is critically important if we are to avert a planetary health inequity crisis. No relevant disclosures. Commissioned; externally peer reviewed. Open access publishing facilitated by Australian National University, as part of the Wiley - Australian National University agreement via the Council of Australian University Librarians.

Open access
Health disparities and outcomes
Climate Change and Health Impacts
Employment and Welfare Studies
Original source
Oct 14, 2022·Research Square
0 cites
The secure judgment of graphic similarity against malicious adversaries

Xin Liu, Yang Xu, Gang Xu, Xiu‐Bo Chen

Abstract With the the advent era of big data, the secure computation calculates data on the premise of protecting data privacy, to realize the availability and invisibility of data. Secure multi-party computation, as one of three major technical tools of privacy computing, can still securely carry out data collaborative computation without a trusted third party. As an important branch of secure multi-party computation, the secure computing geometric problem can solve practical problems in the military, national defense, finance, life, and other fields, which has important research significance. In this paper, the graphic similarity problem is studied. Firstly, this paper proposes the adjacency matrix vector coding method of isomorphic graphics and uses the Paillier variant cryptosystem to securely solve the graphic similarity judgment under the semi-honest model. By using an elliptic curve cryptosystem and zero-knowledge proof to solve the possible malicious attacks under the semi-honest model, a graphic similarity judgment protocol under the malicious model is designed. The protocol can resist malicious attacks, has high computational efficiency, and has wide application value.

Open access
Biometric Identification and Security
Topological and Geometric Data Analysis
Chaos-based Image/Signal Encryption
Original source
Oct 12, 2022·IEEE Transactions on Network and Service Management
9 cites
Towards Data Redaction in Bitcoin

Vincenzo Botta, Vincenzo Iovino, Ivan Visconti

A major issue for many applications of blockchain technology is the tension between immutability and compliance to regulations. For instance, the GDPR in the EU requires to guarantee, under some circumstances, the right to be forgotten. This could imply that at some point one might be forced to delete some data from a locally stored blockchain, therefore irreparably hurting the security and transparency of such decentralized platforms. Motivated by such data protection and consistency issues, in this work we design and implement a mechanism for securely deleting data from Bitcoin blockchain. We use zero-knowledge proofs to allow any node to delete some data from Bitcoin transactions, still preserving the public verifiability of the correctness of the spent and spendable coins. Moreover, we specifically use STARK proofs to exploit the transparency that they provide. Our solution, unlike previous approaches, avoids the complications of asking nodes to reach consensus on the content to delete. In particular, our design allows every node to delete some specific data without coordinating this decision with others. In our implementation, data removal can be performed (resp., verified) in minutes (resp., seconds) on a standard laptop rather than in days as required in previous designs based on consensus.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 12, 2022·IEEE Transactions on Dependable and Secure Computing
23 cites
SofitMix: A Secure Offchain-Supported Bitcoin-Compatible Mixing Protocol

Haomeng Xie, Shufan Fei, Zheng Yan, Yang Xiao

Privacy preservation is highly expected in the Bitcoin Network. However, only applying pseudonyms cannot completely ensure anonymity/unlinkability between payers and payees. Current approaches mainly depend on a mixer service, which obfuscates payer-payee relationships of transactions. While the mixer service improves transaction privacy, it still suffers from some severe security threats (e.g., DoS attack and collusion attack), and does not support effective and reliable off-chain payment in a parallel mode. In this article, we propose a mixing protocol for the Bitcoin Network based on zero-knowledge proof, called SofitMix. It is the first mixing protocol that can effectively resist both the DoS attack and the collusion attack. It can also support a set of parallel off-chain payments in a reliable way no matter whether some payers abort a transaction. We analyze and prove SofitMix security following the Universal Composability model with regard to fair exchange, unlinkability, collusion-resistance, DoS-resistance and Sybil-resistance. Through a proof-of-concept implementation, we demonstrate its validity and fairness. We also show its advance on off-chain payment reliability and DoS attack resistance, compared to TumbleBit.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Oct 11, 2022·Sensors
46 cites
Health-zkIDM: A Healthcare Identity System Based on Fabric Blockchain and Zero-Knowledge Proof

Tianyu Bai, Yangsheng Hu, Jianfeng He, Hongbo Fan · 5 authors

The issue of identity authentication for online medical services has been one of the key focuses of the healthcare industry in recent years. Most healthcare organizations use centralized identity management systems (IDMs), which not only limit the interoperability of patient identities between institutions of healthcare, but also create isolation between data islands. The more important matter is that centralized IDMs may lead to privacy disclosure. Therefore, we propose Health-zkIDM, a decentralized identity authentication system based on zero-knowledge proof and blockchain technology, which allows patients to identify and verify their identities transparently and safely in different health fields and promotes the interaction between IDM providers and patients. The users in Health-zkIDM are uniquely identified by one ID registered. The zero-knowledge proof technology is deployed on the client, which provides the user with a proof of identity information and automatically verifies the user's identity after registration. We implemented chaincodes on the Fabric, including the upload of proof of identity information, identification, and verification functions. The experiences show that the performance of the Health-zkIDM system can achieve throughputs higher than 400 TPS in Caliper.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
IoT and Edge/Fog Computing
Original source
Oct 6, 2022
0 cites
Invoice factoring through blockchain technology

Nasibeh Mohammadzadeh

(English) Invoice factoring has been a popular way to provide cash flow for businesses. The primary function of a factoring system is to prevent an invoice from being factored twice. In order to prevent double factoring, many factoring ecosystems use one or several centralized entities to register factoring agreements. However, this puts a lot of power in the hands of these centralized entities and makes it difficult for users to dispute situations in which factoring data is unavailable, wrongly recorded or manipulated by negligence or on purpose. This thesis presents our research around the current problems of invoice factoring and our new solutions to solve this process using the blockchain technology. A public blockchain can keep a permanent, secure, ordered and transparent record of transactions which are then available for everyone at any time to view and verify. In this thesis, we start proposing a base solution, and we gradually enhance it. In the base protocol, we propose an architecture for invoicing registration based on a general blockchain. The blockchain platform builds trust between the parties by executing transactions correctly. We employed a smart contract to complete the registration process, and prevent double factoring. The smart contract provides for auditing and dispute resolution in such a way that privacy is protected and relevant information is always available. In the second protocol, we add a relayer to our architecture for easier on-boarding. Only the relayer is required to submit blockchain transactions, and pay the corresponding fees. Other participants can proxy their transactions through the relayer, and pay the relayer in fiat money. We also enhance our identity management and authentication using the concept of verifiable credentials (VC) in order to better comply with the Know-Your-Customer (KYC) regulation. In fact, in this architecture, participants use their decentralized identifiers (DIDs) and the DIDComm protocol for asynchronous and secure off-chain interactions. In the final protocol, we greatly enhance our smart contract with respect to the conditions it checks before registering an invoice factoring. We integrate non-interactive zero-knowledge proofs and cryptographic commitments into our solution. With these cryptographic tools in place, we can prevent a special type of denial of service (DoS) attack and better verify invoice details without compromising privacy. Our protocols are very efficient in terms of blockchain costs. In particular, we only need one transaction to register an invoice factoring, and most of the details are recorded in low-cost blockchain storage. Our evaluations and comparison with the literature reveals that our protocols are superior to the related works with respect to efficiency, security, privacy, and ease of use. (Català) La venda de factures o "invoice factoring" ha estat una forma popular de proporcionar flux de caixa a les empreses. La funció principal d'un sistema de venda de factures és evitar que una factura sigui venuda dues vegades. Per evitar la doble venda, molts ecosistemes de factoring utilitzen entitats centralitzades per registrar els acords de venda de factures. Això, però, posa molt poder en mans d'aquestes entitats centralitzades i dificulta que els usuaris puguin impugnar o rebatre situacions en què les dades de venda no estan disponibles, es registren erròniament o es manipulen ja sigui per negligència o a propòsit. Aquesta tesi presenta la nostra recerca al voltant dels problemes actuals dels sistemes de registre de venda de factures i les nostres novedosses solucions per resoldre aquest procés utilitzant la tecnologia "blockchain" (cadena de blocs). Mitjançant una blockchain pública es pot mantenir un registre permanent, segur, ordenat i transparent de transaccions que estan disponibles per a tothom en qualsevol moment per poder ser observades i verificades. A la tesi, comencem proposant una solució base i la anem ampliant i millorant gradualment. La primera proposta és un protocol que utilitza una arquitectura amb blockchain. La plataforma blockchain genera confiança entre les parts ja que garanteix la correcta execució de les transaccions. En aquest sentit, fem servir un contracte intel·ligent per completar el procés de registre i evitar la doble venda. El contracte intel·ligent permet l'auditoria i la resolució de disputes de manera que protegim la privadesa i fem que la informació rellevant estigui sempre disponible. Al segon protocol, afegim un "relay" o retransmissor a la nostra arquitectura per facilitar la incorporació d'usuaris al sistema. El retransmissor és l'únic que envia transaccions a la cadena de blocs i el que paga les taxes corresponents. Els altres participants poden delegar l'enviament de les seves transaccions al repetidor i pagar amb diners fiduciaris. En aquesta proposta també millorem la gestió de la identitat i de l'autenticació utilitzant el concepte de credencials verificables (Verifiable Credentials o VC) per complir millor amb la normativa "Conegui el seu client" (Know Your Customer o KYC). De fet, en aquesta arquitectura, els participants utilitzen els seus identificadors descentralitzats (Decentralized Identifier o DID) i el protocol DIDComm per a les interaccions asíncrones i segures fora de la cadena. Al protocol final, millorem en gran mesura el nostre contracte intel·ligent pel que fa a les condicions que comprova abans de registrar una venda de factura. En aquesta última solució, integrem proves no interactives de coneixement nul (Zero Knowledge Proofs o ZKP) i compromisos criptogràfics. Amb aquestes eines, podem evitar un tipus especial d'atac de denegació de servei (Denial of Service o DoS) i verificar millor els detalls de les factures sense comprometre la privadesa. Els nostres protocols són molt eficients en termes de cost per comissions. En particular, només necessitem una transacció per registrar una factura i la majoria dels detalls es registren a l'emmagatzematge de la cadena de blocs de baix cost. Les nostres avaluacions i la comparació amb la literatura revelen que els nostres protocols són superiors als treballs relacionats pel que fa a l'eficiència, la seguretat, la privadesa i facilitat d'ús.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Oct 6, 2022·IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences
8 cites
Secure Revocation Features in eKYC - Privacy Protection in Central Bank Digital Currency

Kazuo Takaragi, Takashi Kubota, Sven Wohlgemuth, Katsuyuki Umezawa · 5 authors

Central bank digital currencies require the implementation of eKYC to verify whether a trading customer is eligible online. When an organization issues an ID proof of a customer for eKYC, that proof is usually achieved in practice by a hierarchy of issuers. However, the customer wants to disclose only part of the issuer's chain and documents to the trading partner due to privacy concerns. In this research, delegatable anonymous credential (DAC) and zero-knowledge range proof (ZKRP) allow customers to arbitrarily change parts of the delegation chain and message body to range proofs expressed in inequalities. That way, customers can protect the privacy they need with their own control. Zero-knowledge proof is applied to prove the inequality between two time stamps by the time stamp server (signature presentation, public key revocation, or non-revocation) without disclosing the signature content and stamped time. It makes it possible to prove that the registration information of the national ID card is valid or invalid while keeping the user's personal information anonymous. This research aims to contribute to the realization of a sustainable financial system based on self-sovereign identity management with privacy-enhanced PKI.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Oct 4, 2022·arXiv (Cornell University)
2 cites
Blockchain-Based Decentralized Knowledge Marketplace Using Active Inference

Shashank Joshi, Arhan Choudhury

A knowledge market can be described as a type of market where there is a consistent supply of data to satisfy the demand for information and is responsible for the mapping of potential problem solvers with the entities which need these solutions. It is possible to define them as value-exchange systems in which the dynamic features of the creation and exchange of intellectual assets serve as the fundamental drivers of the frequency, nature, and outcomes of interactions among various stakeholders. Furthermore, the provision of financial backing for research is an essential component in the process of developing a knowledge market that is capable of enduring over time, and it is also an essential driver of the progression of scientific investigation. This paper underlines flaws associated with the conventional knowledge-based market, including but not limited to excessive financing concentration, ineffective information exchange, a lack of security, mapping of entities, etc. The authors present a decentralized framework for the knowledge marketplace incorporating technologies such as blockchain, active inference, zero-knowledge proof, etc. The proposed decentralized framework provides not only an efficient mapping mechanism to map entities in the marketplace but also a more secure and controlled way to share knowledge and services among various stakeholders.

Open access
2 source records
Blockchain Technology Applications and Security
Scientific Computing and Data Management
cs.CR
Original source
Oct 3, 2022·Multidisciplinary Research in Computing Information Systems
1 cites
DIGITAL IDENTITY MANAGEMENT SYSTEMS: A CROSSSECTORAL SECURITY AND PRIVACY PERSPECTIVE

Dr. Muhammad Zain Abbas

As the digital ecosystem evolves, secure and efficient Digital IdentityManagement Systems (DIMS) have become pivotal in managing identities acrossgovernmental, financial, healthcare, and commercial sectors. This paper offers across-sectoral examination of DIMS, emphasizing security and privacy concerns andtheir mitigation strategies. Drawing on current technologies such as blockchain,biometrics, and zero-knowledge proofs, the study explores how these systems canprotect sensitive information while ensuring interoperability and compliance withregulatory frameworks. Through comparative analysis, graphical insights, and realworld case studies, the paper underscores the need for standardized and resilientidentity infrastructures that balance user privacy and system functionality

Open access
Information and Cyber Security
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Oct 1, 2022
2 cites
Post-Quantum Zero Knowledge, Revisited or: How to Do Quantum Rewinding Undetectably

Alex Lombardi, Fermi Ma, Nicholas Spooner

When do classical zero-knowledge protocols remain secure against quantum attacks? In this work, we develop the techniques, tools, and abstractions necessary to answer this question for foundational protocols:1)We prove that the Goldreich-Micali-Wigderson protocol for graph non-isomorphism and the Feige-Shamir protocol for NP remain zero-knowledge against quantum adversaries. At the heart of our proof is a new quantum rewinding technique that enables extracting information from multiple invocations of a quantum adversary without disturbing its state.2)We prove that the Goldreich-Kahan protocol for NP is post-quantum zero knowledge using a simulator that can be seen as a natural quantum extension of the classical simulator.Our results achieve negligible simulation error, appearing to contradict a recent impossibility result due to Chia-Chung-Liu-Yamakawa (FOCS 2021). This brings us to our final contribution:3.We introduce coherent-runtime expected quantum polynomial time, a simulation notion that (a) precisely captures all of our zero-knowledge simulators, (b) cannot break any polynomial hardness assumptions, (c) implies strict polynomial-time ε-simulation and (d) is not subject to the CCLY impossibility. In light of our positive results and the CCLY negative results, we propose coherent-runtime simulation to be the appropriate quantum analogue of classical expected polynomial-time simulation.

Open access
Adversarial Robustness in Machine Learning
Security and Verification in Computing
Cryptography and Data Security
Original source
Sep 29, 2022·Measurement and Control
5 cites
Secure device control scheme with blockchain in a smart home

Junbeom Park, Seongju Chang

The Internet of Things (IoT) and blockchain technologies characterizing the era of the fourth industrial revolution have enabled smart home networks to support their various systems and services. In a blockchain-based smart-home network environment, all connected IoT devices must be controlled safely and efficiently. Nevertheless, existing block-chain-based smart-home IoT systems pose a delay issue due to the necessary block generation time. In addition, IoT devices installed in smart homes should be able to prevent forgery attacks such as spoofing because they are often directly associated with personal information. In this study, we proposed an enhanced method to control smart home devices safely and efficiently by applying the zero-knowledge proof combined with a blockchain-based IoT system to protect the public keys of home network devices and the communication among them. The proposed model was approximately 10 s faster than the block generation-based model when it communicated three times in rinkeby, which is one of the test networks of Ethereum.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Sep 24, 2022
0 cites
Augmented Efficient Zero-Knowledge Contingent Payments in Cryptocurrencies without Scripts

Peifang Ni

Zero-Knowledge Contingent Payment presents how Bitcoin contracts can provide a solution for the so-called fair exchange problem.Banasik, W. et al. first presented an efficient ZeroKnowledge Contingent Payment protocol for a large class of NP-relations, which is a protocol for selling witness. It obtains fairness in the following sense: if the seller aborts the protocol without broadcasting the final message then the buyer finally gets his payment back. However, we find that the seller in the protocol could refuse to broadcast the final signature of the transaction without any compensation for the buyer. As a result, the buyer cannot get the witness from the final signature of the transaction and has the payment for the witness locked until finishing the large computation for a secret signing key. In this paper, we fix this problem by augmenting the efficient Zero-Knowledge Contingent Payment protocol. We present a new protocol where the seller needs to provide the deposit before the zero-knowledge proof of knowledge of the witness being sold. And then the buyer could obtain the seller's witness if the seller broadcasts the final signature of the transaction and gets the payment and his deposit. Otherwise, the buyer could get back the payment and obtain the seller's deposit. This new augmented protocol is constructed without any new assumptions.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Sep 23, 2022·arXiv (Cornell University)
0 cites
FIAT: Fine-grained Information Audit for Trustless Transborder Data Flow

Shuhao Zheng, Yanxi Lin, Yang Yu, Ye Yuan · 6 authors

Auditing the information leakage of latent sensitive features during the transborder data flow has attracted sufficient attention from global digital regulators. However, there is missing a technical approach for the audit practice due to two technical challenges. Firstly, there is a lack of theory and tools for measuring the information of sensitive latent features in a dataset. Secondly, the transborder data flow involves multi-stakeholders with diverse interests, which means the audit must be trustless. Despite the tremendous efforts in protecting data privacy, an important issue that has long been neglected is that the transmitted data in data flows can leak other regulated information that is not explicitly contained in the data, leading to unaware information leakage risks. To unveil such risks trustfully before the actual data transfer, we propose FIAT, a Fine-grained Information Audit system for Trustless transborder data flow. In FIAT, we use a learning approach to quantify the amount of information leakage, while the technologies of zero-knowledge proof and smart contracts are applied to provide trustworthy and privacy-preserving auditing results. Experiments show that large information leakage can boost the predictability of uninvolved information using simple machine-learning models, revealing the importance of information auditing. Further performance benchmarking also validates the efficiency and scalability of the FIAT auditing system.

Open access
2 source records
cs.IT
eess.SY
Privacy-Preserving Technologies in Data
Original source
Sep 22, 2022
0 cites
ARCHITech : Advanced Research of Cryptographic Techniques to build efficient blockchains with privacy and security

Anais Querol Cruz

Internet fue concebido hace décadas como un protocolo de intercambio de información telemáticamente a través de redes de máquinas interconectadas. Pero hace tiempo que sufre de problemas estructurales como la centralización de servicios y el alto nivel de confianza que se debe depositar en los servidores; perpetuando cuellos de botella y ciberataques. En este escenario nació blockchain, una tecnología descentralizada y transparente que ha llegado para mejorar la web que conocemos. Las cadenas de bloques, son listas de registros enlazados entre sí, securizados utilizando métodos criptográficos y repartidos a lo largo de los nodos de la red. Su utilidad principal es la de almacenar información de una forma verificable e inmutable; es decir, que un usuario pueda comprobar la integridad de los datos de las mismas. Si bien parece que la transparencia no puede conjugarse con la naturaleza de los datos más sensibles, la criptografía moderna ofrece herramientas como las pruebas de conocimiento cero (ZKPs), que permiten armonizar privacidad y transparencia. Eso es, verificar propiedades de la blockchain sin filtrar información privada. Además, otros mecanismos como los argumentos sucintos (SNARKs), permiten comprobarlo de forma eficiente sin perder seguridad. Junto con metodologías basadas en compromisos criptográficos (CP), es posible combinar estos métodos para construir sistemas para demostrar afirmaciones cada vez más complejas. El objetivo de mi tesis es mejorar estos métodos para que se puedan aplicar a casos de uso realistas. Para ello, propongo unos bloques modulares que respetan la privacidad y se combinan entre sí de forma fácil y segura con un compilador para que los desarrolladores puedan crear blockchains transparentes y descentralizadas con todas las garantías de privacidad y seguridad de forma eficiente. Para ello, propongo una serie de CP-SNARKs eficientes para verificar propiedades frecuentes a la hora de diseñar estos sistemas, como lo son multiplicaciones matriciales, relaciones lineales, chequeo de sumas o autopermutaciones. Estos módulos se pueden interconectar para construir argumentos más complejos. Gracias a nuestro compilador podemos reutilizar SNARKs con conocimiento cero (zkSNARKs) existentes. Combinando nuestros componentes, presentamos el primer zkSNARK universal con clave lineal. Por otra parte, diseñamos una familia de zkSNARKs universales, actualizables y lineales (y sus variantes CP-SNARKs) para un nuevo sistema de restricciones de propósito general llamado R1CS-lite más eficiente que R1CS. Nuestro mecanismo funciona en dos fases: la primera, pruebas para un objeto abstracto llamado PHPs; la segunda, compilación a zkSNARKs mediante CP-SNARKs modulares para tres relaciones principales—apertura de compromisos polinomiales, igualdad de ecuaciones, y grado de polinomios. Las distintas configuraciones derivan en las distintas variantes de nuestros esquemas. Por último, nos interesamos en el estudio de zkSNARKs en entornos distribuidos. Aquí, la prueba se genera de forma fragmentada por los distintos nodos y es agregada por un único coordinador, preservando la privacidad entre entidades. Mostramos un mecanismo para obtener PHPs bivariables, que se compilan a zkSNARKs paralelas. ----------ABSTRACT---------- The Internet was conceived decades ago as a protocol for the telematic interchange of information through networks of interconnected machines. But it has been some time since it suffers from some structural problems such as services centralization and the high level of trust to be deposited on servers; perpetuating bottlenecks and cyberattacks. In this scenario blockchain was born, a decentralized and transparent technology that has arrived to improve the web we all know. Blockchains, as their name suggests, are lists of linked registers, secured using cryptographic methods and disseminated across the nodes of the network. Their main utility is to store data in a verifiable and immutable way: meaning, that users can check the integrity of this information. Even if it looks like transparency cannot marry to the nature of sensitive data, modern cryptography offers tools such as zero-knowledge proofs (ZKPs), which can harmonize privacy and transparency. That is, verifying properties of the blockchain filtering no private information. Moreover, other mechanisms like succinct arguments (SNARKs), allow for checking them efficiently without detriment to security. Together with the commit-and-prove (CP) approach, these methods can be put together to build systems to prove even more complex claims. The goal of my thesis is to enhance these methods so that they can be applied to realistic use cases. To this effect, I propose some privacy-preserving modular blocks (CP-SNARKs) that can be combined with each other easily and in a secure way with a compiler, so as that developers can create transparent and decentralized blockchains with all guarantees of privacy and security in an efficient manner. With this goal in mind, I propose a series of efficient CP-SNARKs to verify frequent properties when designing these systems, such as matrix multiplications, linear relations, sum-checks, or self-permutations. These modules can be interconnected to build more complex arguments. Thanks to our compiler we can also reuse other existing zeroknowledge SNARKs (zkSNARKs). Combining our components, we present the first universal zkSNARK with linear length keys. On the other hand, we design a family of universal and updateable zkSNARKs with linear SRS (and their CP-SNARKs variants) for a new general-purpose constraint system called R1CS-lite which is more efficient than R1CS. Ours is a two-fold mechanism: first, proofs for an abstract object called PHPs; second, compiling to zkSNARKs through modular CP-SNARKs for three main relations—opening of polynomial commitments, equality of equations, and degree of polynomials. Distinct configurations derive from the different variants of our schemes. Lastly, we put our focus on the study of zkSNARKs in distributed environments. Here, the proof is generated in a fragmented way by the independent nodes and is aggregated by an only coordinator, preserving privacy among entities. We show a mechanism to obtain bivariate PHPs, which can be compiled to parallel zkSNARKs using our previous compiler.

Open access
Blockchain Technology Applications and Security
Original source
Sep 22, 2022·arXiv (Cornell University)
0 cites
Making Quantum Local Verifiers Simulable with Potential Applications to Zero-Knowledge

Lijie Chen, Ramis Movassagh

Recently Chen and Movassagh proposed the quantum Merkle tree, which is a quantum analogue of the well-known classical Merkle tree. It gives a succinct verification protocol for quantum state commitment. Although they only proved security against semi-honest provers, they conjectured its general security. Using the proposed quantum Merkle tree, they gave a quantum analogue of Kilian's succinct argument for NP, which is based on probabilistically checkable proofs (PCPs). A nice feature of Kilian's argument is that it can be extended to a zero-knowledge succinct argument for NP, if the underlying PCP is zero-knowledge. Hence, a natural question is whether one can also make the quantum succinct argument by Chen and Movassagh zero-knowledge as well. This work makes progress on this problem. We generalize the recent result of Broadbent and Grilo to show that any local quantum verifier can be made simulable with a minor reduction in completeness and soundness. Roughly speaking, a local quantum verifier is simulable if in the yes case, the local views of the verifier can be computed without knowing the actual quantum proof; it can be seen as the quantum analogue of the classical zero-knowledge PCPs. Hence we conjecture that applying the proposed succinct quantum argument of Chen and Movassagh to a simulable local verifier is indeed zero-knowledge.

Open access
Cryptography and Data Security
Original source
Sep 16, 2022·Research Square
1 cites
An Effective Security Comparison Protocol in Cloud Computing

Yuling Chen, Junhong Tao, Tao Li, Jiangyuan Cai · 5 authors

Abstract Secure comparison protocol is an important branch of secure multi-party computation(SMPC), which compares the size of input data without disclosing any information between participants. The development of cloud computing provides an application platform for SMPC, but it also brings new challenges. In cloud computing with SMPC, clients need to process their own data and submit the processed data to a cloud server, which then performs the computation. In this process, not only the clients need to maintain an honest state at all times, but sensitive data on the cloud server side may also be exposed. In this paper, zero-knowledge proof and homomorphic encryption techniques are used to improve Damgård-Geisler-KrØigaard(DGK) comparison protocol. The improved secure comparison protocol can not only safely calculate private data, but also be applicable to malicious participant model. Finally, the security analysis shows that the proposed scheme not only ensures the privacy security of participants, but also ensures the data fairness of comparison protocols.

Open access
Cloud Data Security Solutions
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Sep 13, 2022·Security and Communication Networks
7 cites
A Novel Biometric Identification Scheme Based on Zero-Knowledge Succinct Noninteractive Argument of Knowledge

Chunjie Guo, Lin You, Gengran Hu

Biometric identification is a convenient and reliable method in identity authentication. The widespread adoption of biometric identification requires strong privacy protection against possible theft or loss of biometric data. Existing techniques for privacy-preserving biometric identification mainly rely on traditional cryptographic technology such as oblivious transfer and homomorphic encryption, which will incur huge expenses to the system and cannot be applied to large-scale practical applications. For these issues, we propose a biometric identification scheme by constructing zero-knowledge succinct noninteractive argument of knowledge (zk-SNARK). Our scheme not only reduces the communication overhead, which only needs to send 8 constants to the verifier but also can protect the fingerprint template from disclosure. The time complexity of proof generation and proof verification are about O(C) and <a:math xmlns:a="http://www.w3.org/1998/Math/MathML" id="M1"> <a:mi>O</a:mi> <a:mfenced open="(" close=")" separators="|"> <a:mrow> <a:mi>x</a:mi> </a:mrow> </a:mfenced> <a:mo>+</a:mo> <a:mi mathvariant="normal">log</a:mi> <a:mtext> </a:mtext> <a:mtext> </a:mtext> <a:mi>C</a:mi> </a:math> , respectively, and the size of the proof is only 8 constants, where C and x represent the size of the circuit and the public input, respectively. We have implemented the proposed authentication solution on a public data set of fingerprint images and evaluated the performance and security.

Open access
Cryptography and Data Security
Biometric Identification and Security
User Authentication and Security Systems
Original source
Sep 9, 2022·arXiv (Cornell University)
18 cites
On the Computational Hardness Needed for Quantum Cryptography

Zvika Brakerski, Ran Canetti, Luowen Qian

In the classical model of computation, it is well established that one-way functions (OWF) are minimal for computational cryptography: They are essential for almost any cryptographic application that cannot be realized with respect to computationally unbounded adversaries. In the quantum setting, however, OWFs appear not to be essential (Kretschmer 2021; Ananth et al., Morimae and Yamakawa 2022), and the question of whether such a minimal primitive exists remains open. We consider EFI pairs - efficiently samplable, statistically far but computationally indistinguishable pairs of (mixed) quantum states. Building on the work of Yan (2022), which shows equivalence between EFI pairs and statistical commitment schemes, we show that EFI pairs are necessary for a large class of quantum-cryptographic applications. Specifically, we construct EFI pairs from minimalistic versions of commitments schemes, oblivious transfer, and general secure multiparty computation, as well as from QCZK proofs from essentially any non-trivial language. We also construct quantum computational zero knowledge (QCZK) proofs for all of QIP from any EFI pair. This suggests that, for much of quantum cryptography, EFI pairs play a similar role to that played by OWFs in the classical setting: they are simple to describe, essential, and also serve as a linchpin for demonstrating equivalence between primitives.

Open access
Cryptography and Data Security
Benford’s Law and Fraud Detection
Computability, Logic, AI Algorithms
Original source