Léo Robert, Daiki Miyahara, Pascal Lafourcade, Takaaki Mizuki
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
4,228 results · page 126 of 177
Léo Robert, Daiki Miyahara, Pascal Lafourcade, Takaaki Mizuki
No abstract is available for this record.
David Cerezo Sánchez
Optimal simple rules for the monetary policy of the first stochastically dominant crypto-currency are derived in a Dynamic Stochastic General Equilibrium (DSGE) model, in order to provide optimal responses to changes in inflation, output, and other sources of uncertainty. The optimal monetary policy stochastically dominates all the previous crypto-currencies, thus the efficient portfolio is to go long on the stochastically dominant crypto-currency: a strategy-proof arbitrage featuring a higher Omega ratio with higher expected returns, inducing an investment-efficient Nash equilibrium over the crypto-market. Zero-knowledge proofs of the monetary policy are committed on the blockchain: an implementation is provided.
Jonathan Heiss, Robert Muth, Frank Pallas, Stefan Tai
Many service systems rely on verifiable identity-related information of their users. Manipulation and unwanted exposure of this privacy-relevant information, however, must at the same time be prevented and avoided. Peer-to-peer blockchain-based decentralization with a smart contract-based execution model and verifiable off-chain computations leveraging zero-knowledge proofs promise to provide the basis for next-generation, non-disclosing credential management solutions. In this paper, we propose a novel credential on-chaining system that ensures blockchain-based transparency while preserving pseudonymity. We present a general model compliant to the W3C verifiable credential recommendation and demonstrate how it can be applied to solve existing problems that require computational identity-related attribute verification. Our zkSNARKs-based reference implementation and evaluation show that, compared to related approaches based on, e.g., CL-signatures, our approach provides significant performance advantages and more flexible proof mechanisms, underpinning our vision of increasingly decentralized, transparent, and trustworthy service systems.
Suthee Ruangwises, Toshiya Itoh
Shikaku is a pencil puzzle consisting of a rectangular grid, with some cells containing a number. The player has to partition the grid into rectangles such that each rectangle contains exactly one number equal to the area of that rectangle. In this paper, we propose two physical zero-knowledge proof protocols for Shikaku using a deck of playing cards, which allow a prover to physically show that he/she knows a solution of the puzzle without revealing it. Most importantly, in our second protocol we develop a general technique to physically verify a rectangle-shaped area with a certain size in a rectangular grid, which can be used to verify other problems with similar constraints.
Hamza Baniata, Attila Kertész
Trusted online credential management solutions are needed for instant and practical verification. Most of the available frameworks targeting this field violate the privacy of end-users or lack sufficient solutions in terms of security and Quality-of-Service (QoS). In this paper, we propose a Privacy-aware Fog-enhanced Blockchain-based online credential management solution, namely PriFoB. Our proposed solution adopts a public permissioned Blockchain model with different reliable encryption schemes, standardized Zero-Knowledge-Proofs (ZKPs) and Digital Signatures (DSs) within a Fog–Blockchain integrated framework, which is also GDPR compliant. We deploy both the Proof-of-Authority (PoA) and the Signatures-of-Work (SoW) consensus algorithms for efficient and secure handling of Verifiable Credentials (VCs) and global accreditation of VC issuers, respectively. Furthermore, we propose a novel three-dimensional DAG-based model of the Distributed Ledger (3DDL), and provide a ready-to-deploy PriFoB implementation. We discuss insights regarding the utilization and the potential of PriFoB, and evaluate it in terms of security, privacy, latency, throughput and power utilization. We analyze its performance in different layers of a Fog-enabled cloud architecture with simulation and emulation, and we show that PriFoB outperforms several Blockchain-based solutions utilizing Ethereum, Hyperledger Fabric, Hyperledger Besu and Hyperledger Indy platforms.
Jayamine Alupotha, Xavier Boyen, Matthew McKague
Confidential Transactions (CT) hide coin amounts even from verifiers without the help of trusted third parties. Aggregable CTs are a scalable category of CTs with “spent coin record trimming”. For example, if Alice sends coins to Bob, who had sent similar coins to Charles, the aggregated transaction shows only that Alice sent coins to Charles by deleting Bob’s coin records. Since the number of spent coin records grows linearly with the number of transactions, faster than the number of accounts, cash systems based on aggregable CTs are highly scalable. However, existing quantum-safe aggregable CT protocols have large unspent coin records, and existing efficient aggregable CTs are vulnerable to quantum attacks. We introduce two aggregable CT protocols, based on new efficient homomorphic zero-knowledge proofs, from either the plain or Module Short Integer Solution (SIS and MSIS) problems, both believed to be secure against quantum adversaries. We further implement the MSIS-based aggregable CT protocol as a C library. Our experiments on 104transactions show that aggregation reduces the cash system’s size by 40%–54% when the output/input rate is in the range 1/1–2/1. For example, a cash system of 1.73 GB can be reduced to 0.98 GB when the output/input rate is 1.5, which has been the historical real-world average rate.
Diego F. Aranha, Emil Madsen Bennedsen, Matteo Campanelli, Chaya Ganesh · 6 authors
No abstract is available for this record.
Taochun Wang, Huimin Shen, Jian Chen, Fulong Chen · 6 authors
With the continuous innovative development and popularization of mobile smart devices , the application of Mobile Crowd Sensing (MCS) continues to be studied extensively. However, existing centralized MCS applications that use servers for task publishing and data collection exhibit common problems, such as single points of failure and security vulnerabilities . Accordingly, we proposed a hybrid blockchain-based identity authentication scheme for MCS called HBIA, which uses blockchain technology to resolve the single-point failure problem. HBIA builds a cluster structure based on factors such as geographical location and balance, and uses it to construct a hybrid blockchain , with the cluster head node and internal cluster node authenticating on the public and private chains, respectively. We also implemented zero-knowledge proof (ZKP) to ensure the privacy of participants’ identities, thus balancing the contradiction between blockchain transparency and security. In addition, HBIA uses the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) technology to enable off-chain computing and on-chain verification, further reducing the blockchain’s workload. Finally, HBIA was evaluated based on the pavement crack detection task and tested on the Ethereum public test network known as Ropsten. The test results indicate that the identity authentication scheme proposed in this paper is superior to existing schemes in terms of authentication time.
Bright Chibunna Ubamadu, Damodar Bihani, Andrew Ifesinachi Daraojimba, Grace Omotunde Osho · 6 authors
The advent of blockchain technology has revolutionized the way decentralized applications (dApps) and smart contracts are developed and deployed. However, the barrier of gas fees continues to hinder mass adoption, especially in resource-constrained environments. This paper proposes a novel, practical model for gasless smart contract transactions by integrating facial recognition technology within blockchain ecosystems. Our approach leverages zero-knowledge proofs and meta-transaction protocols to enable trustless authentication and transaction signing through biometric facial data, thereby eliminating the need for users to maintain a cryptocurrency balance for transaction execution. The proposed model is built on a multi-layered architecture that incorporates a decentralized identity (DID) framework, a biometric verification engine, and a relayer network that pays the gas on behalf of the user. Using facial recognition as a biometric key, users can trigger and authorize smart contract functions without direct wallet interaction or private key exposure. The system enhances security by utilizing advanced liveness detection and encrypted facial signature hashing, preventing spoofing and ensuring that only legitimate users gain access to the network. Furthermore, it supports user onboarding via identity verification processes that comply with global KYC (Know Your Customer) standards, thus bridging the gap between user accessibility and regulatory requirements. A simulation environment was developed using Solidity, OpenZeppelin libraries, AWS Rekognition for facial analysis, and the Biconomy SDK for meta-transactions. Performance metrics indicate significant improvements in user onboarding time, cost-efficiency, and fraud prevention compared to traditional models. The model also reduces environmental impact by lowering the computational overhead associated with repeated gas-based authentication. This paper provides a blueprint for developers, policymakers, and fintech stakeholders to adopt gasless blockchain frameworks supported by biometric security. It presents a scalable and user-friendly solution that could unlock broader blockchain adoption in finance, healthcare, and identity management sectors. The fusion of facial recognition with smart contract automation signifies a leap towards a more inclusive, secure, and cost-efficient decentralized future.
Ward Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai · 5 authors
Abstract We construct an efficient dynamic group signature (or more generally an accountable ring signature) from isogeny and lattice assumptions. Our group signature is based on a simple generic construction that can be instantiated by cryptographically hard group actions such as the CSIDH group action or an MLWE-based group action. The signature is of size $$O(\log N)$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>O</mml:mi> <mml:mo>(</mml:mo> <mml:mo>log</mml:mo> <mml:mi>N</mml:mi> <mml:mo>)</mml:mo> </mml:mrow> </mml:math> , where N is the number of users in the group. Our idea builds on the recent efficient OR-proof by Beullens, Katsumata, and Pintore (Asiacrypt’20), where we efficiently add a proof of valid ciphertext to their OR-proof and further show that the resulting non-interactive zero-knowledge proof system is online extractable . Our group signatures satisfy more ideal security properties compared to previously known constructions, while simultaneously having an attractive signature size. The signature size of our isogeny-based construction is an order of magnitude smaller than all previously known post-quantum group signatures (e.g., 6.6 KB for 64 members). In comparison, our lattice-based construction has a larger signature size (e.g., either 126 KB or 89 KB for 64 members depending on the satisfied security property). However, since the $$O(\cdot )$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>O</mml:mi> <mml:mo>(</mml:mo> <mml:mo>·</mml:mo> <mml:mo>)</mml:mo> </mml:mrow> </mml:math> -notation hides a very small constant factor, it remains small even for very large group sizes, say $$2^{20}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:msup> <mml:mn>2</mml:mn> <mml:mn>20</mml:mn> </mml:msup> </mml:math> .
Harmanpreet Singh Grover
Les protocoles à connaissance nulle nous donnent une façon par laquelle un prouver(s) peut convaincre un vérificateur(s) qu’un énoncé est vrai sans lui dévoiler quoi que ce soit d’autre. Ces preuves à connaissance nulle nous apportent une solution élégante au problème de s’identifier sans pour autant révéler un quelconque secret. Dans ce travail, notre point de mire porte sur les protocoles multi-prouveurs relativistes à connaissance nulle pour paires distanciées de prouveurs-vérificateurs. Initialement, nous démontrons que le protocole expérimental multi-prouveurs relativiste à connaissance nulle décrit dans le papier récent de \cite{alikhani2020experimental} est sécuritaire face à des prouveurs classiques. Ensuite, nous prouvons que ce même protocole constitue une preuve de connaissance pour le même langage. Enfin, nous démontrons que ce même protocole satisfait une forme plus forte de « à connaissance nulle » en exhibant une paire de simulateurs non-signalant contrairement aux simulateurs habituels qui sont signalants. La sécurité du protocole est obtenue grâce au principe physique de la relativité restreinte
Tom Godden, Ruben De Smet, Christophe Debruyne, Thibaut Vandervelden · 6 authors
Driven by the increased consciousness in data ownership and privacy, zero-knowledge proofs (ZKPs) have become a popular tool to convince a third party of the truthfulness of a statement without disclosing any further information. As ZKPs are rather complex to design, frameworks that transform high-level languages into ZKPs have been proposed. We propose Circuitree, a Datalog reasoner in zero-knowledge. Datalog is a high-level declarative logic language that is generally used for querying. Furthermore, as a logic language, it can also be used to solve logic problems. An application using Circuitree can efficiently generate ZKPs, based on Datalog rules and encrypted data, to prove that a certain conclusion follows from a Datalog ruleset and encrypted input data. Compared to existing frameworks, which generally use their own limited imperative languages, Circuitree uses an existing high-level declarative language. We point out several applications for Circuitree, including EU Digital COVID Certificates and privacy-preserving access control for peer-to-peer (p2p) networks. Circuitree’s performance is evaluated for access control in a p2p network. First results show that our approach allows for fast proofs and proof verification for this application.
Brian Chen, Yevgeniy Dodis, Esha Ghosh, Eli Goldin · 7 authors
No abstract is available for this record.
Alex Chinco
The conventional wisdom is that you must reveal something about how you pick stocks in order to prove that you have stock-picking skill. In this paper I show that, prior to executing any trades, it is possible to prove you have stock-picking skill without revealing any additional information about your underlying trading signal. Here is how the protocol works. The evaluator presents you with a sequence of paired return data sets, one real and the other suitably randomized. A profitable trading signal will only be able to predict the cross-section of returns in the real data set. So by repeatedly using your trading signal to identify the real data set, you can prove that you have stock-picking skill without revealing anything else about your underlying signal. This protocol represents a zero-knowledge proof of stock-picking skill—i.e., a proof which reveals nothing except for the validity of your claim. Zero-knowledge proofs allow any skilled stock picker to advertise his ability without fear of his trading signal getting scooped. As a result, they have important implications for how the active-management industry is organized.
Dor Bitan, Ran Canetti, Shafi Goldwasser, Rebecca Wexler
The use of hidden investigative software to collect evidence of crimes presents courts with a recurring dilemma: On the one hand, there is often clear public interest in keeping the software hidden to preserve its effectiveness in fighting crimes. On the other hand, criminal defendants have rights to inspect and challenge the full evidence against them, including law enforcement's investigative methods. In fact, in the U.S. adversarial legal system, the defendant's rights to scrutinize the government's tools are crucial to the truth-seeking process and to keeping law enforcement conduct lawful and constitutional. Presently, courts balance these conflicting interests on a case-by-case basis through evidentiary privilege law, often voicing their frustration with the challenging dilemma they face. We demonstrate how judicious use of a sophisticated cryptographic tool called Zero Knowledge Proofs (ZKPs) could help to mitigate this dilemma: Based on actual court cases where evidence was collected using a modified version of a peer-to-peer software, we demonstrate how law enforcement could, in these cases, augment their investigative software with a ZKP-based mechanism that would allow them to later provide full responses to challenges made by a defense expert -- and allow a defense expert to independently verify law enforcement claims -- while keeping the software hidden. We demonstrate the technical feasibility of our mechanism via a proof-of-concept implementation. We also propose legal analysis that justifies its use, discusses its merits, and considers the legal implications that the very existence of such a mechanism might have, even in cases where it has not been used. Our proof-of-concept may also extend to other verification dilemmas in the legal landscape.
Merve Can Kuş Khalilov, Albert Lévi
Bitcoin is one of the best-known cryptocurrencies, which captivated researchers with its innovative blockchain structure. Examinations of this public blockchain resulted in many proposals for improvement in terms of anonymity and privacy. Generally used methods for improvement include mixing protocols, ring signatures, zero-knowledge proofs, homomorphic commitments, and off-chain storage systems. To the best of our knowledge, in the literature, there is no study examining Bitcoin in terms of differential privacy, which is a privacy notion coming up with some mechanisms that enable running useful statistical queries without identifying any personal information. In this paper, we provide a theoretical examination of differential privacy in Bitcoin. Our motivation arises from the idea that the Bitcoin public blockchain structure can benefit from differential privacy mechanisms for improved privacy, both making anonymization and privacy breaches by direct queries impossible, and preserving the checkability of the integrity of the blockchain. We first examine the current Bitcoin implementation for four query functions using the differential privacy formulation. Then, we present the feasibility of the utilization of two differential privacy mechanisms in Bitcoin; the noise addition to the transaction amounts and the user graph perturbation. We show that these mechanisms decrease the fraction of the cases violating differential privacy, therefore they can be used for improving anonymity and privacy in Bitcoin. Moreover, we showcase the noise addition to transaction amounts by using IBM Differential Privacy Library. We compare four differential privacy mechanisms for varying privacy parameter values and determine the feasible mechanisms and the parameters.
Xavier Bultel
Peg solitaire is a very popular traditional single-player board game, known to be NP-complete. In this paper, we present a zero-knowledge proof of knowledge for solutions of peg solitaire instances. Our proof is straightforward, in the sense that it does not use any reduction to another NP-complete problem, and uses the standard design of sigma protocols. Our construction relies on cryptographic commitments, which can be replaced by envelopes to make the protocol physical. As a side contribution, we introduce the notion of isomorphisms for peg solitaire, which is the key tool of our protocol.
Vadim Lyubashevsky, Ngoc Khanh Nguyen
No abstract is available for this record.
Elvira Albert, Marta Bellés-Muñoz, Miguel Isabel, Clara Rodríguez-Núñez · 5 authors
Abstract The most widely used Zero-Knowledge (ZK) protocols require provers to prove they know a solution to a computational problem expressed as a Rank-1 Constraint System (R1CS). An R1CS is essentially a system of non-linear arithmetic constraints over a set of signals, whose security level depends on its non-linear part only, as the linear (additive) constraints can be easily solved by an attacker. Distilling the essential constraints from an R1CS by removing the part that does not contribute to its security is important, not only to reduce costs (time and space) of producing the ZK proofs, but also to reveal to cryptographic programmers the real hardness of their proofs. In this paper, we formulate the problem of distilling constraints from an R1CS as the (hard) problem of simplifying constraints in the realm of non-linearity. To the best of our knowledge, it is the first time that constraint-based techniques developed in the context of formal methods are applied to the challenging problem of analysing and optimizing ZK protocols.
Aleksander Berentsen, Jeremias Lenzi, Remo Nyffenegger
No abstract is available for this record.
Jonathan Bootle, Alessandro Chiesa, Siqi Liu
No abstract is available for this record.
Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Titouan Tanguy, Michiel Verbauwhede
No abstract is available for this record.
Xavier Arnal, Abraham Cano, Tamara Finogina, Javier Herranz
No abstract is available for this record.
VILMA MATTILA, PRATEEK DWIVEDI, PRATIK GAURI, DHANRAJ DADHICH
Since public blockchains are permissionless, it is subject to passive adversarial attack. In 5irechain we have addressed the security problem related to this passive adversarial activity by applying 5ireHE, a homomorphic encryption technique that encrypts the transactional details using the receiver’s public key. Since the transaction is encrypted by the receiver’s public key, it is harder for other validators to validate the transaction in 5ire. In this paper, we introduce ZKP for validating the transaction in a sense that validator can check if the sender’s previous balance and the remaining balance are in harmony with the amount of the transaction despite the difference in public keys that are used for the encryption of transaction and the encryption of account balance.