Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results · page 123 of 177

Clear filters
May 2, 2022
1 cites
Polynomial Commitment-Based Zero-Knowledge Proof Schemes

Becky Mundele, Chenchen Han

Blockchain technology is one of the most popular information technologies at present, and its security features are realized through various cryptographic tools. Zero-knowledge proofs are such a tool that can increase data security and improve users’ privacy, and zero-knowledge proof schemes constructed with polynomial commitments have advantages in terms of verification time and proof size. Benefiting from the development of blockchain technology, zero-knowledge proof has also ushered in rapid development. This paper analyzes the research status of zero-knowledge proof schemes based on polynomial commitment construction, and introduces the construction and security of polynomial commitments. Finally, blockchain and some other potential commitment schemes that can be used for zero-knowledge proofs and blockchain construction are introduced as future research directions and engineering applications.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Original source
May 1, 2022·Lehigh Preserve
0 cites
Accelerating zkSNARKs on Modern Architectures

Maxim Vezenov

Zero-knowledge proofs (ZKPs) enable a prover to convince a verifier that a given statement is true without revealing anymore information other than the fact the statement is true. Although this high-level description makes it sound simple, zero-knowledge proofs open up multiple use cases with regards to private transactions, verifiable outsourced computation, and much more. zkSNARKs are a particularly useful ZKP construction as the proof is very small and very fast to verify no matter the problem size. The cost of constructing the proof itself remains a massive bottleneck and current implementations of zkSNARKs are lacking in their ability to meet mainstream demand of this technology. However, the processes necessary to construct a zkSNARK proof, number theoretic transformations (NTT) and multi-scalar multiplication (MSM), are both highly parallel. CUDA programming on NVIDIA GPUs is inherently tuned to the type of programming zkSNARK proof require. In this thesis we explore techniques for how zkSNARKs are created and methods for accelerating zkSNARK creation on the GPU.

Open access
Cryptography and Data Security
Distributed systems and fault tolerance
Cryptography and Residue Arithmetic
Original source
Apr 30, 2022
5 cites
A Futuristic Survey on Learning Techniques for Internet of Things (IoT) Security : Developments, Applications, and Challenges

Chintan Patel, Shubham Vyas, Pallabi Saikia, Denish kalariya · 5 authors

In today's era, internet-connected things provide immense opportunities to the world for enhancing the quality of lives through better data processing and intelligent decision making. Since the last decade, IoT brought numerous changes in people's personal as well as professional lives. With the enhancement in quality of lives, IoT also comes up with challenges such as security and privacy of data and devices. Every day, the attacker generates new zero-day attacks for IoT devices and data, and it's important to detect and protect the IoT eco-system from this type of attacks. Numerous researchers have proposed security schemes and methods to protect the IoT eco-system through either cryptography way or learning technique based way. AI and ML learning techniques have got immense popularity in handling the IoT security challenges as they are automatic in nature and can outperform provided the sufficient quality and quantity of data. Moreover, the AI techniques, including ML, DL and FL helps in intelligent decision-making and can also generate knowledge through its learning techniques. AI needs data to process, and IoT supplies the necessary data to process. In this paper, we provide a state-of-the-art survey for IoT security solutions proposed based on learning techniques. We provide an in-depth review of available learning techniques to solve critical security challenges such as IoT authentication, access control, anomaly detection and malware analysis. At the end, we also highlighted various futuristic technologies that can invigorate IoT research and help in the design of full proof IoT eco-system.

Open access
2 source records
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Anomaly Detection Techniques and Applications
Original source
Apr 26, 2022·Digital Communications and Networks
25 cites
Blockchain-based continuous data integrity checking protocol with zero-knowledge privacy protection

Yi-Ting Huang, Yong Yu, Huilin Li, Yannan Li · 5 authors

The cloud computing technology has emerged, developed, and matured in recent years, consequently commercializing remote outsourcing storage services. An increasing number of companies and individuals have chosen the cloud to store their data. However, accidents, such as cloud server downtime, cloud data loss, and accidental deletion, are serious issues for some applications that need to run around the clock. For some mission and business-critical applications, the continuous availability of outsourcing storage services is also necessary to protect users' outsourced data during downtime. Nevertheless, ensuring the continuous availability of data in public cloud data integrity auditing protocols leads to data privacy issues because auditors can obtain the data content of users by a sufficient number of storage proofs. Therefore, protecting data privacy is a burning issue. In addition, existing data integrity auditing schemes that rely on semi-trusted third-party auditors have several security problems, including single points of failure and performance bottlenecks. To deal with these issues, we propose herein a blockchain-based continuous data integrity checking protocol with zero-knowledge privacy protection. We realize a concrete construction by using a verifiable delay function with high efficiency and proof of retrievability, and prove the security of the proposal in a random oracle model. The proposed construction supports dynamic updates for the outsourced data. We also design smart contracts to ensure fairness among the parties involved. Finally, we implement the protocols, and the experimental results demonstrate the efficiency of the proposed protocol.

Open access
Cloud Data Security Solutions
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Apr 21, 2022·Energies
25 cites
Towards a Blockchain-Based Peer-to-Peer Energy Marketplace

Yeray Mezquita, Ana BelĂ©n Gil GonzĂĄlez, A. Martı́n del Rey, Javier Prieto · 5 authors

Blockchain technology is used as a distributed ledger to store and secure data and perform transactions between entities in smart grids. This paper proposes a platform based on blockchain technology and the multi-agent system paradigm to allow for the creation of an automated peer-to-peer electricity market in micro-grids. The use of a permissioned blockchain network has multiple benefits as it reduces transaction costs and enables micro-transactions. Moreover, an improvement in security is obtained, eliminating the single point of failure in the control and management of the platform along with creating the possibility to trace back the actions of the participants and a mechanism of identification. Furthermore, it provides the opportunity to create a decentralized and democratic energy market while complying with the current legislation and regulations on user privacy and data protection by incorporating Zero-Knowledge Proof protocols and ring signatures.

Open access
Blockchain Technology Applications and Security
Smart Grid Security and Resilience
Smart Grid Energy Management
Original source
Apr 16, 2022·Transactions on Machine Learning and Artificial Intelligence
0 cites
An Introduction to Data Encryption and Future Trends in Lightweight Cryptography and Securing IoT Environments

Sikha Bagui, Raffaele Galliera

This paper presents an overview of the basic concepts of cryptography and encryption. The work aims at presenting the main concepts and concerns of encryption on a high-level of abstraction, allowing non-domain expert readers to navigate through these topics. Less traditional arguments are also shown, from the relevance of Key Management Services with its usage in Envelope Encryption, to Zero Knowledge proofs and their innovative applications. The crucial importance of securing communications between IoT devices and widely used algorithms to do so, are also discussed.

Open access
Chaos-based Image/Signal Encryption
IoT and Edge/Fog Computing
Cryptographic Implementations and Security
Original source
Apr 4, 2022·arXiv (Cornell University)
2 cites
Generalized Triangular Dynamical System: An Algebraic System for Constructing Cryptographic Permutations over Finite Fields

Arnab Roy, Matthias Steiner

In recent years a new class of symmetric-key primitives over $\mathbb{F}_p$ that are essential to Multi-Party Computation and Zero-Knowledge Proofs based protocols have emerged. Towards improving the efficiency of such primitives, a number of new block ciphers and hash functions over $\mathbb{F}_p$ were proposed. These new primitives also showed that following alternative design strategies to the classical Substitution-Permutation Network (SPN) and Feistel Networks leads to more efficient cipher and hash function designs over $\mathbb{F}_p$ specifically for large odd primes $p$. In view of these efforts, in this work we build an \emph{algebraic framework} that allows the systematic exploration of viable and efficient design strategies for constructing symmetric-key (iterative) permutations over $\mathbb{F}_p$. We first identify iterative polynomial dynamical systems over finite fields as the central building block of almost all block cipher design strategies. We propose a generalized triangular polynomial dynamical system (GTDS), and based on the GTDS we provide a generic definition of an iterative (keyed) permutation over $\mathbb{F}_p^n$. Our GTDS-based generic definition is able to describe the three most well-known design strategies, namely SPNs, Feistel networks and Lai--Massey. Consequently, the block ciphers that are constructed following these design strategies can also be instantiated from our generic definition. Moreover, we find that the recently proposed \texttt{Griffin} design, which neither follows the Feistel nor the SPN design, can be described using the generic GTDS-based definition. We also show that a new generalized Lai--Massey construction can be instantiated from the GTDS-based definition. We further provide generic analysis of the GTDS including an upper bound on the differential uniformity and the correlation.

Open access
2 source records
cs.CR
Coding theory and cryptography
Cryptographic Implementations and Security
Original source
Apr 2, 2022·arXiv (Cornell University)
0 cites
Polynomial Bounds On Parallel Repetition For All 3-Player Games With Binary Inputs

Uma Girish, Kunal Mittal, Ran Raz, Wei Zhan

We prove that for every 3-player (3-prover) game $\mathcal G$ with value less than one, whose query distribution has the support $\mathcal S = \{(1,0,0), (0,1,0), (0,0,1)\}$ of hamming weight one vectors, the value of the $n$-fold parallel repetition $\mathcal G^{\otimes n}$ decays polynomially fast to zero; that is, there is a constant $c = c(\mathcal G)>0$ such that the value of the game $\mathcal G^{\otimes n}$ is at most $n^{-c}$. Following the recent work of Girish, Holmgren, Mittal, Raz and Zhan (STOC 2022), our result is the missing piece that implies a similar bound for a much more general class of multiplayer games: For $\textbf{every}$ 3-player game $\mathcal G$ over $\textit{binary questions}$ and $\textit{arbitrary answer lengths}$, with value less than 1, there is a constant $c = c(\mathcal G)>0$ such that the value of the game $\mathcal G^{\otimes n}$ is at most $n^{-c}$. Our proof technique is new and requires many new ideas. For example, we make use of the Level-$k$ inequalities from Boolean Fourier Analysis, which, to the best of our knowledge, have not been explored in this context prior to our work.

Open access
Complexity and Algorithms in Graphs
Machine Learning and Algorithms
Computability, Logic, AI Algorithms
Original source
Apr 1, 2022·Computer
0 cites
Elliptic Curve Pairings

Joshua Brian Fitzgerald

Elliptic curve pairings are a powerful tool and a popular way to construct zero-knowledge proofs, which are beginning to be used in blockchains as a way to provide privacy in the transaction ledger.

Open access
Cryptography and Residue Arithmetic
Original source
Mar 31, 2022·Distributed Ledger Technologies Research and Practice
16 cites
ElectAnon: A Blockchain-based, Anonymous, Robust, and Scalable Ranked-choice Voting Protocol

Ceyhun Onur, Arda Yurdakul

Remote voting has become more critical in recent years, especially since the COVID-19 outbreak. Blockchain technology and its benefits such as decentralization, security, and transparency have given rise to proposals for blockchain-based voting systems. However, the traceability of blockchain transactions violates voter anonymity in existing proposals. Besides, transaction costs also need to be considered. Solutions that may cause repeated elections should be avoided for a low-cost scalable voting system. In this work, we propose ElectAnon, a blockchain-based, self-tallying, and ranked-choice voting protocol focusing on anonymity, robustness, and scalability. ElectAnon achieves anonymity by enabling voters to register with identity commitments and cast their votes via zero-knowledge proofs. Robustness is realized by removing the direct control of the authorities in the voting process by using timed-state machines. Each voter encodes the ballot into a single integer and blinds the vote off-chain while making the verification on-chain. This makes the protocol infinitely scalable in the number of voters. ElectAnon is also a solution for governance in Decentralized Autonomous Organizations (DAO): It includes a candidate proposal module and an algorithm-agnostic mechanism to plug-in different tallying methods easily. The Merkle forest extension is proposed for conducting even more trustless elections. ElectAnon is implemented with smart contracts based on Ethereum Virtual Machine (EVM) and a zero-knowledge gadget, Semaphore. The implementation also includes two different sophisticated tallying methods, Borda Count and Tideman. Experimental results show that a 40-voter and 10-candidate election can be implemented with the gas consumption reduced up to 89% compared to previous works. While other studies could not exceed a 25,000-voter setup, ElectAnon has been observed to run safely for 1,000,000 voters. The implementation can be found at https://github.com/ceyonur/electanon .

Open access
3 source records
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Mar 30, 2022·International Journal of Environmental Research and Public Health
30 cites
A Blockchain Secured Pharmaceutical Distribution System to Fight Counterfeiting

Kavyan Zoughalian, Jims Marchang, Bogdan Ghita

Counterfeiting drugs has been a global concern for years. Considering the lack of transparency within the current pharmaceutical distribution system, research has shown that blockchain technology is a promising solution for an improved supply chain system. This study aims to explore the current solution proposals for distribution systems using blockchain technology. Based on a literature review on currently proposed solutions, it is identified that the secrecy of the data within the system and nodes' reputation in decision making has not been considered. The proposed prototype uses a zero-knowledge proof protocol to ensure the integrity of the distributed data. It uses the Markov model to track each node's 'reputation score' based on their interactions to predict the reliability of the nodes in consensus decision making. Analysis of the prototype demonstrates a reliable method in decision making, which concludes with overall improvements in the system's confidentiality, integrity, and availability. The result indicates that the decision protocol must be significantly considered in a reliable distribution system. It is recommended that the pharmaceutical distribution systems adopt a relevant protocol to design their blockchain solution. Continuous research is required further to increase performance and reliability within blockchain distribution systems.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Supply Chain and Inventory Management
Original source
Mar 30, 2022
7 cites
CIRCOM: A Robust and Scalable Language for Building Complex Zero-Knowledge Circuits

José L. Muñoz, Marta Bellés, Miguel Isabel, Albert Rubio · 5 authors

A zero-knowledge (ZK) proof guarantees that the result of a computation is correct while keeping part of the computation details private. Some ZK proofs are tiny and can be verified in short time, which makes them one of the most promising technologies for solving two key aspects: the challenge of enabling privacy to public and transparent distributed ledgers and, enhancing the scalability limitations of distributed ledgers. Most practical ZK systems require the computation to be expressed as an arithmetic circuit that is encoded as a set of equations called rank-1 constraint system (R1CS).<br>In this paper, we present \circom, a programming language and a compiler for designing arithmetic circuits that are compiled to R1CS. More precisely, with \circom, programmers can design arithmetic circuits, and the compiler outputs (i) a file with the R1CS description, (ii) \wasm and \cpp programs to efficiently compute all values of the circuit. We also provide an open-source library called \circomlib, with multiple circuit templates. Moreover, \circom can be complemented with \snarkjs, a tool for generating and validating ZK proofs from R1CS. Altogether, our software tools abstract the complexity of the proving mechanisms and provide a friendly interface to model low-level descriptions of arithmetic circuits.

Open access
2 source records
Cryptography and Data Security
Logic, Reasoning, and Knowledge
Adversarial Robustness in Machine Learning
Original source
Mar 29, 2022·Academic Emergency Medicine
10 cites
A candle in the dark: The role of indirect evidence in emergency medicine clinical practice guidelines

Christopher R. Carpenter, Lucas Oliveira J. e Silva, Suneel Upadhye, Joshua Broder · 5 authors

Emergency medicine is often a specialty defined by diagnostic uncertainty when worried patients present with constellations of symptoms seeking explanation and relief. Abdominal pain is a common chief complaint among adult emergency department (ED) patients, with recurrent symptoms in the subsequent days, weeks, months, and even years, sometimes prompting repeat evaluations.1 The differential diagnosis is broad and diverse, including multiple organs and systems and extraabdominal causes. Ideally, clinical practice guidelines (CPGs) synthesize the entirety of evidence for questions relevant to an explicitly defined patient population and outcomes, but until now no CPG existed for the scenario of recurrent abdominal pain. Consequently, significant practice variation exists in the diagnostic and therapeutic approach to this clinical condition.2 The Society for Academic Emergency Medicine (SAEM) second "Guidelines for Reasonable and Appropriate Care in the Emergency Department 2 (GRACE-2)" article provides that CPG with adherence to Grading of Recommendations, Assessment, Development and Evaluations (GRADE) methodology including incorporation of patient priorities and external stakeholders.3 Through adherence to the GRADE methodology we aimed to create rigorous and trustworthy guidelines. The GRACE-2 writing team deliberated to select topics and questions and to explicitly define a clinically meaningful population, ultimately settling on definitions of recurrence within 30 days and adults with "low-risk" abdominal pain. Identifying no well-accepted or validated definition of "low risk" (as opposed to a risk model like the HEART score for chest pain4), the GRACE-2 writing team devised a definition of "low risk" that resonated with our clinical intuition and excluded populations that emergency physicians would routinely identify as moderate or high risk. Subsequently, the GRACE-2 writing team worked with medical librarians to focus searches based on the patient-intervention-control-outcome-time (PICOT) template5 and completed systematic reviews for each question before developing the recommendations.6, 7 The PICOT-oriented literature search revealed no studies that aligned with our definition of low risk and few that defined recurrence within our predefined time frame. However, that does not mean that our search rendered zero published evidence around which GRACE-2 could contemplate actionable recommendations via the GRADE Evidence to Decision (EtD) framework.8, 9 We had to make a decision about how to classify and incorporate the published research that we did identify. GRADE provides a framework for evidence synthesis and development of clinical guidelines and recommends inclusion of both direct and indirect evidence into CPGs, while providing guidance around the distinction between the two.8-12 Therefore, we decided to classify evidence as "direct" if each element of the PICOT question matched the study's inclusion criteria and outcomes assessed. "Indirect" evidence was defined by deviation from any component of the PICOT question (Table 1). These definitions are necessary for guideline developers who need to evaluate the domain of indirectness when rating the certainty of evidence.10, 12 Since the overall value of CPGs rests upon the rigor and transparency of the evidentiary search, quality assessment, and synthesis in conjunction with an explicit and representative assessment of anticipated benefits or potential harms of the subsequent recommendations, weighing the pros and cons of including indirect evidence is merited while considering if and how to incorporate the GRACE-2 recommendations into ED practice. Not emergency department Not adult Not recurrent Not undifferentiated abdominal pain Not low risk Initial CT identified explanatory pathology like kidney stone Repeat CT >12 months after initial CT GRADE recognizes indirectness as a key domain in the assessment of certainty of evidence.10, 12 Whenever systematic review authors or guideline developers identify important indirectness issues from a body of evidence that deviates from the original PICOT question, the certainty of evidence must be downgraded by one or two levels.10, 12 Despite such guidance from GRADE, conceptualization of what type of indirect evidence could be synthesized and used by CPGs remains debatable, especially when there is insufficient direct evidence.13 Also, a second layer of complexity is added when guideline developers need to evaluate the directness of research evidence for all criteria of the GRADE EtD framework including values, resources, cost-effectiveness, equity, acceptability, and feasibility. This cognitive framework can quickly diffuse into uncertainties. Nonetheless, indirect evidence is not fundamentally or inevitably flawed. For example, a study might be rated as indirect because the age range of enrolled subjects does not perfectly match the intended population or because the time frame of follow-up slightly exceeds the desired target. Such evidence may provide a very reasonable estimate of the range of expected outcomes in the intended population. In addition, many randomized controlled trials employ so many exclusion criteria and carefully controlled experimental conditions that the results may not predict outcomes in a broader ED population. GRADE attempts to distill value from the broad range of available evidence, rather than taking a nihilistic attitude that rejects evidence on the basis of any imperfection. Nihilism suggests "we know nothing" and have no basis for any decision—but emergency medicine requires that physicians make the best decision possible based on the available, if imperfect, evidence in a more pragmatic approach. GRADE recommends that if a large body of indirect evidence that can be convincingly linked to the PICOT support the management strategy, recommendations should be made.14 Specifically, GRADE states that "clinicians will rarely explore the evidence as thoroughly as a guideline panel, nor devote as much thought to the trade-offs, or the possible underlying values and preferences in the population. We therefore encourage panels to deal with their discomfort and to make recommendations even when confidence in effect estimate is low and/or desirable and undesirable consequences are closely balanced."15 The ideal strategy to dealing with absent direct evidence for a certain question during CPG development is not fully established among guideline developers, and each panel along with their methodologists need to individualize such decisions according to resource availability (e.g., methodological expertise, funding) and feasibility. Murad et al.,13 for example, suggest five strategies for supplementing systematic review findings when evidence on benefits or harms is found to be insufficient, including: (1) reconsider eligible study designs, (2) summarize indirect evidence, (3) summarize contextual and implementation evidence, (4) consider modeling, and (5) incorporate unpublished health system data in the evidence synthesis. In GRACE-2, summary of indirect evidence was chosen as the main approach and different "bodies of indirect evidence" were systematically synthesized.6, 7 As three out of four questions in GRACE-2 were related to diagnostic tests, we also faced the reality that direct evidence evaluating the impact of different testing strategies on patient-important outcomes (i.e., diagnostic randomized trials) seldom exists, which ultimately leads to the use of different types of indirect evidence such as diagnostic accuracy.16-18 Even within the adaptive framework of GRADE, indirect evidence may leave the PICOT question unanswered, and subsequent recommendations are often necessarily weak or nonexistent. Strong and definitive recommendations necessitate multiple studies evaluating the identical patient population and diagnostic approach quantifying the same outcomes in similar time frames with minimal concerns about health inequities, resource consumption, imprecision, or feasibility. Indirect evidence alone is unlikely to justify strong recommendations, but does provide substantive proof of the scope of the problem relative to the paucity of evidence. If the indirect evidence was excluded, CPG stakeholders would not be cognizant that this research was identified and reviewed in developing the recommendations. Clinicians, educators, and researchers would remain unaware of how little empiric evidence exists around which to shape decision making or how future investigators could more directly address the knowledge void. GRACE-2 is not alone in identifying a painfully surprising gap between what emergency medicine thinks is common knowledge and high-quality research to justify those beliefs. One reflection of this is that the majority of American College of Emergency Physician Clinical Policy recommendations are not level A.19 Ultimately, concerns about the directness of evidence for CPGs represent an existential crisis for emergency medicine. As society's safety net for potentially life-threatening medical, surgical, or psychiatric illness, emergency medicine's breadth of knowledge must remain broad and open-ended as clinical science continues to expand the horizons of possibility. The hierarchy of evidence-based medicine places CPGs at the top of the information pyramid, yet guidelines for common syndromic presentations like acute abdominal pain do not exist in emergency medicine. Certainly, our specialty could await others to create CPGs for these conditions, but those organizations are most likely to view patient encounters through the lens of an established or highly suspected diagnosis. In contrast, emergency physicians confront undifferentiated patients with constellations of signs and symptoms in a chaotic environment. We navigate the challenges of accurate and timely diagnosis, often with imperfect data. Paradoxically, we face expectations of constraint with testing—often without evidence-based guidance for when to safely limit workups—while avoiding critical misses. Experience with other organization's CPGs has shown that ED clinicians are often noncompliant with their recommendations, which commonly do not account for the real-life conditions of emergency care. The consequence is an unfair judgment that emergency physicians engage in inferior, non–evidence-based, and excessively costly health care by external stakeholders.20-23 The Association of Academic Chairs of Emergency Medicine's 2030 research goals focus on increasing the proportion of NIH R01-funded emergency medicine investigators, who will someday close the knowledge gap for prevalent conditions that currently remain underinvestigated.24 The absence of direct evidence and the imperfection of indirect evidence for high-priority emergency medicine CPGs illustrates the importance of forming a National Institute of Emergency Care. In addition to supporting the next generation of independent health-outcomes researchers, a central prioritizing body could ensure that the most pertinent questions affecting patient care on a daily basis are the focus of funding opportunities.19, 25 Until that day, GRACE-2 provides a synthesis of evidence and corresponding recommendations derived using GRADE methodology upon which to guide imaging and therapy decisions for adults with low-risk and recurrent abdominal pain. Medicine is equal parts science and art with clinical judgment based on hermeneutic thinking to generate a holistic understanding of an individual patient's current condition.26 Our vision is for the inclusion of direct and indirect evidence in this CPG to ground that decision making in a realistic understanding of our current state of knowledge, while catalyzing more pertinent research in the near future.

Open access
Clinical practice guidelines implementation
Healthcare cost, quality, practices
Emergency and Acute Care Studies
Original source
Mar 29, 2022·arXiv (Cornell University)
2 cites
ZK-SecreC: a Domain-Specific Language for Zero Knowledge Proofs

Dan Bogdanov, Joosep JÀÀger, Peeter Laud, HÀrmel Nestra · 10 authors

We present ZK-SECREC, a domain-specific language for zero-knowledge (ZK) proofs. We focus on its type system, making the point that this is the most appropriate mechanism for tracking information flows in a statement that is meant to be proved using a zero-knowledge protocol. The appropriateness stems from the necessary distinctions between the two involved parties and between the computations made locally or on top of the protocol. The appropriateness also stems from how the types match with the major steps of typical ZK protocols, including the generation of Common Reference Strings. We compare the type system of ZK-SECREC with those of the previously proposed languages for ZK proofs and privacy-preserving computations, and show how ZK-SECREC handles certain aspects better.

Open access
3 source records
Security and Verification in Computing
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Mar 24, 2022·Security and Communication Networks
0 cites
Research on the Millionaires’ Problem under the Malicious Model Based on the Elliptic Curve Cryptography

Xin Liu, Yang Xu, Gang Xu, Baoshan Li

With the rapid development of blockchain, big data, cloud computing, and artificial intelligence, the security of multisource data collaborative computing has become increasingly prominent. Secure multiparty computing has become the core technology of privacy collaborative computing. Millionaires’ problem is the cornerstone of secure multiparty computation. Firstly, this paper proposes a 0-1 coding rule, which is used to solve the millionaires’ problem under the semihonest model. Aiming at the possible malicious behaviors of the protocol under the semihonest model, the millionaires’ problem protocol under the malicious model based on the elliptic curve cryptography is designed by using cryptographic tools such as the zero-knowledge proof and the cut-choose method. This protocol not only can effectively solve the millionaires’ problem but also can safely and effectively prevent malicious behaviors. Meanwhile, the security ordering designed by the protocol can be effectively applied to a quality evaluation in the blockchain.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Mar 23, 2022·IEEE Transactions on Industrial Informatics
195 cites
Permissioned Blockchain and Deep Learning for Secure and Efficient Data Sharing in Industrial Healthcare Systems

Randhir Kumar, Prabhat Kumar, Rakesh Tripathi, Govind P. Gupta · 6 authors

The industrial healthcaresystem has enabled the possibility of realizing advanced real-time monitoring of patients and enriched the quality of medical services through data sharing among intelligent wearable devices and sensors. However, this connectivity brings the intrinsic vulnerabilities related to security and privacy due to the need of continuous communication and monitoring over public network (insecure channel). Motivated from the aforementioned discussions, we integrate permissioned blockchain and smart contract with deep learning (DL) techniques to design a novel secure and efficient data sharing framework named PBDL. Specifically, PBDL first has a blockchain scheme to register, verify (using zero-knowledge proof), and validate the communicating entities using the smart contract-based consensus mechanism. Second, the authenticated data are used to propose a novel DL scheme that combines stacked sparse variational autoencoder (SSVAE) with self-attention-based bidirectional long short term memory (SA-BiLSTM). In this scheme, SSVAE encodes or transforms the healthcare data into new format, and SA-BiLSTM identifies and improves the attack detection process. The security analysis and experimental results using IoT-Botnet and ToN-IoT datasets confirm the superiority of the PBDL framework over existing state-of-the-art techniques.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
User Authentication and Security Systems
Original source
Mar 21, 2022·Security and Communication Networks
11 cites
Blockchain-Based Privacy-Preserving Vaccine Passport System

Yangzhou Cao, Jiageng Chen, Yajun Cao

In this study, we propose a blockchain-based privacy-preserving vaccine passport system for the global prevention and control of infectious diseases. The system operates a double-chain framework which consists of a public blockchain and a consortium blockchain. Among them, the combination of the immutability of the public blockchain and Internet of Things (IoT) technology in the supply chain ensures the openness and transparency of the cold chain logistics records of the vaccines covering the stages from auditing to the target vaccination hospitals. The system adopts the consortium blockchain to achieve the balance between the protection of users’ vaccination privacy and auditing by the government departments. Specifically, a distributed system-based threshold signature is adopted in the vaccine qualification phase to resist collusion between the vaccine manufacturing company and vaccine approval institutions. The cryptographic tools such as the anonymous credentials, zero-knowledge protocols, and range proofs ensure that users do not disclose any private information other than proving that they have a legally valid vaccine passport when users display the vaccine passports to customs. At the same time, customs can apply various vaccine prevention policies based on the conditions on the specific vaccine passports. Regarding the security properties of the system, a formal security model is given along with the corresponding security proofs.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Mar 21, 2022·2022 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops)
1 cites
A New Zero-Trust Aided Smart Key Authentication Scheme in IoV

Yangxu Song, Frank Jiang, Syed Wajid Ali Shah, Robin Doss

With the development of 5G networking technology on the Internet of Vehicle (IoV), there are new opportunities for numerous cyber-attacks, such as in-vehicle attacks like hijacking occurrences and data theft. While numerous attempts have been made to protect against the potential attacks, there are still many unsolved problems such as developing a fine-grained access control system. This is reflected by the granularity of security as well as the related data that are hosted on these platforms. Among the most notable trends is the increased usage of smart devices, IoV, cloud services, emerging technologies aim at accessing, storing and processing data. Most popular authentication protocols rely on knowledge-factor for authentication that is infamously known to be vulnerable to subversions. Recently, the zero-trust framework has drawn huge attention; there is an urgent need to develop further the existing Continuous Authentication (CA) technique to achieve the zero-trustiness framework. In this paper, firstly, we develop the static authentication process and propose a secured protocol to generate the smart key for user to unlock the vehicle. Then, we proposed a novel and secure continuous authentication system for IoVs. We present the proof-of-concept of our CA scheme by building a prototype that leverages the commodity fingerprint sensors, NFC, and smartphone. Our evaluations in real-world settings demonstrate the appropriateness of CA scheme and security analysis of our proposed protocol for digital key suggests its enhanced security against the known attack-vector.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Biometric Identification and Security
Original source
Mar 17, 2022·Electronic Markets
150 cites
The transparency challenge of blockchain in organizations

Johannes Sedlmeir, Jonathan Lautenschlager, Gilbert Fridgen, Nils Urbach

Abstract This position paper discusses the challenges of blockchain applications in businesses and the public sector related to an excessive degree of transparency. We first point out the types of sensitive data involved in different patterns of blockchain use cases. We then argue that the implications of blockchains’ information exposure caused by replicated transaction storage and execution go well beyond the often-mentioned conflicts with the GDPR’s “right to be forgotten” and may be more problematic than anticipated. In particular, we illustrate the trade-off between protecting sensitive information and increasing process efficiency through smart contracts. We also explore to which extent permissioned blockchains and novel applications of cryptographic technologies such as self-sovereign identities and zero-knowledge proofs can help overcome the transparency challenge and thus act as catalysts for blockchain adoption and diffusion in organizations.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
FinTech, Crowdfunding, Digital Finance
Original source
Mar 16, 2022·Science China Information Sciences
2 cites
Lattice-based group encryptions with only one trapdoor

Jing Pan, Jiang Zhang, Fangguo Zhang, Xiaofeng Chen · 5 authors

No abstract is available for this record.

Open access
Cryptography and Data Security
Nanocluster Synthesis and Applications
Cryptographic Implementations and Security
Original source
Mar 14, 2022·New Generation Computing
36 cites
Card-Based ZKP for Connectivity: Applications to Nurikabe, Hitori, and Heyawake

Léo Robert, Daiki Miyahara, Pascal Lafourcade, Takaaki Mizuki

Abstract During the last years, several card-based Zero-Knowledge Proof (ZKP) protocols for Nikoli’s puzzles have been designed. Although there are relatively simple card-based ZKP protocols for a number of puzzles, such as Sudoku and Kakuro, some puzzles face difficulties in designing simple protocols. For example, Slitherlink requires novel and elaborate techniques to construct a protocol. In this study, we focus on three Nikoli puzzles: Nurikabe, Hitori, and Heyawake. To date, no card-based ZKP protocol for these puzzles has been developed, partially because they have a relatively tricky rule that colored cells should form a connected area (namely a polyomino); this rule, sometimes referred to as “Bundan-kin” (in Japanese), complicates the puzzles, as well as facilitating difficulties in designing card-based ZKP protocols. We address this challenging task and propose a method for verifying the connectivity of hidden colored cells in a ZKP manner, such that we construct card-based ZKP protocols for the three puzzles.

Open access
graph theory and CDMA systems
Cancer Treatment and Pharmacology
Interconnection Networks and Systems
Original source
Mar 10, 2022·Al-Mustansiriyah Journal of Sciences
3 cites
Secure E-Learning System Based on ZNP and AES

Rand Mohammed Rafee, Bashar M. Nema

A secure electronic learning platform has been created to enable teachers and students to log into their accounts to learn efficiently and safely at any place and time. This platform has been proposed due to the urgent need to develop the education system and move it from traditional to interactive e-learning. In this paper, an application implemented that access remotely using a web browser interface and saved on a server depends on a Zero-Knowledge Proof (ZKP) system with an RSA algorithm was employed to solve registration and login challenges and securely transfer passwords. Using adapted AES to encrypt each user's personal information, Exams, and save it in in encrypted form in the database. The simulated results in this paper indicate the existence of a secure e-learning system, where security was achieved by performing the registration and login process without sending the password in its explicit form over an insecure network such as the Internet, in addition to encrypting the necessary information to be stored in an incomprehensible manner in the database, in the case of presence of an attack on the database.

Open access
Advanced Malware Detection Techniques
Chaos-based Image/Signal Encryption
User Authentication and Security Systems
Original source
Mar 10, 2022·International Journal of Scientific Research in Science and Technology
0 cites
Using Zero-Knowledge Proof for Secure Data Transmission on Distributed Network

E. Jansirani, N. Kowsalya

Data security plays a major role in computer network. Because it helps to transmit data in secure way over the Internet. So we need to use strong security method for secure data transaction. Cryptography is a security tool which helps to transmit information from one place to another place over computer network. Cryptography follows encryption and decryption methods for data transmission. Cryptographic technique is completely based on key generation because it needs keys to transmit data between users. However cryptography works well in secure data transmission but it needs keys to provide security for data. In cryptography generation of keys taking more time than transmission of data. So in this paper we discuss about Zero-Knowledge Proof (ZKP) which is also based on cryptographic technique. ZKP is also useful in secure data transmission without sharing key values between users. This paper tells about overview of ZKP and how it is useful in data transmission.

Open access
Cryptography and Data Security
Chaos-based Image/Signal Encryption
Cryptographic Implementations and Security
Original source