Abstract A zero-knowledge proof or protocol is a cryptographic technique for verifying private data without revealing it in its clear form. In this paper, we evaluate the potential for zero-knowledge distributed ledger technology to alleviate asymmetry of information in the asset-backed securitization market. To frame this inquiry, we conducted market data analyses, a review of prior literature, stakeholder interviews with investors, originators and security issuers and collaboration with blockchain engineers and researchers. We introduce a new system which could enable all market participants in the securitization lifecycle (e.g. investors, rating agencies, regulators and security issuers) to interact on a unique decentralized platform while maintaining the privacy of loan-level data, therefore providing the industry with timely analytics and performance data. Our platform is powered by zkLedger (Narula et al. 2018), a zero-knowledge protocol developed by the MIT Media Lab and the first system that enables participants of a distributed ledger to run publicly verifiable analytics on masked data.
Software-defined industrial network has emer-ged as an autonomous ecosystem where the network control relies on a centralized controller to provide seamless data transfer. However, the reliance on a centralized controller can lead to several challenges, such as single point of failure. An adversary can initiate a denial of service attack and limit the availability of the controller by projecting malicious or uncontrolled traffic flows. To overcome this, in this article, a deep-learning-based blockchain framework is designed for providing secure software-defined industrial network. In this framework, a blockchain mechanism is designed wherein all the switch are registered, verified (using zero-knowledge proof), and, thereafter, validated in the blockchain using a voting-based consensus mechanism. A deep Boltzmann machine based flow analyzer is deployed at the control plane to identify the anomalous switch requests. The evaluation is performed using a mininet emulator wherein the results obtained depict the superiority of the proposed framework.
Abstract Port Knocking is a method for authenticating clients through a closed stance firewall, and authorising their requested actions, enabling severs to offer services to authenticated clients, without opening ports on the firewall. Advances in port knocking have resulted in an increase in complexity in design, preventing port knocking solutions from realising their potential. This paper proposes a novel port knocking solution, named Crucible, which is a secure method of authentication, with high usability and features of stealth, allowing servers and services to remain hidden and protected. Crucible is a stateless solution, only requiring the client memorise a command, the server’s IP and a chosen password. The solution is forwarded as a method for protecting servers against attacks ranging from port scans, to zero-day exploitation. To act as a random oracle for both client and server, cryptographic hashes were generated through chaotic systems.
zkSNARKS can be described as zero-knowledge: No secret information is revealed by the proof; Succinct: The size of the proof that is generated is small; Non-interactive: no challenge-response protocol; and ARgument of Knowledge: It is computationally intractable for the prover to produce a fake proof.
Paul B. Romesser, Grace L. Smith, Christopher H. Crane
Locally advanced rectal cancer (LARC) treatment traditionally includes preoperative chemoradiation, radical surgery, and postoperative chemotherapy (1). Although highly effective, this standard leads to substantial rates of long-term morbidity, including permanent colostomy, low anterior resection syndrome, urinary dysfunction, and sexual dysfunction (1–3). Patients with mid- and low rectal cancers who achieve a clinical complete response (cCR) present a dilemma to the thoughtful surgeon because the preoperative discussion must include the very real possibility that the specimen would not contain cancer. Patients’ refusal of radical surgery and surgeons’ desire to balance oncologic outcomes with quality of life (QOL) have led investigators to embark on organ preservation strategies in complete responders. Although the nonoperative management (NOM, also known as watch-and-wait) strategy has been increasingly accepted, radical surgery is still considered the standard, and randomized evidence determining the comparative effectiveness of NOM remains to be established. In this issue of the Journal, Miller and colleagues evaluate other important considerations of effectiveness, specifically the cost-effectiveness and quality-adjusted survival of NOM (4). The NOM strategy was initially introduced by Habr-Gamma and colleagues in 2004 (5). Patients with LARC who achieved a substantial clinical response to chemoradiation were offered NOM if they were agreeable to stringent monthly clinical reassessments (5). The 5-year overall survival and disease-free survival of the 72 patients who underwent NOM were 100% and 92%, respectively (5). Importantly, all of the patients with regrowth of the primary tumor were successfully salvaged with mesorectal excision. Although initially controversial, this pioneering work provided proof of principle that the majority of patients who achieve a cCR to preoperative chemoradiation can be managed without radical surgery. Multiple groups have subsequently reported 70–80% durable local disease control in LARC complete responders on NOM, and close surveillance has led to timely salvage surgery with no clear oncologic disadvantage (6–13). Miller and colleagues developed a decision-analytic Markov model to evaluate cost-effectiveness of this strategy compared with standard radical surgery (4). Importantly, with respect to clinical interpretation and application, this analysis includes only patients who have achieved cCR to neoadjuvant therapy. NOM was found to have incremental cost savings of $28 500 and $32 100 and incremental benefit in quality-adjusted-life years of 0.527 and 0.601 compared with low anterior resection and abdominoperineal resection, respectively. The main cost differences were predominantly driven by the upfront cost of surgery, which was absent or deferred in patients managed with NOM and statistically significantly offset the added cost of enhanced screening. Results were presented from a US payer perspective and validate similar findings demonstrating cost-effectiveness of NOM from a UK payer perspective (14). The model by Miller and colleagues (4) further suggests quality-adjusted survival benefit from NOM, based on population-based QOL and health utility data. This finding highlights the need for ongoing studies of NOM to detail patient-reported QOL measures that encompass pain, symptoms, body image, and sexual function, data that will ultimately be needed to inform individual treatment decision making about NOM for clinically eligible patients. In the setting of unavoidably increasing limits on health-care resources, the authors’ finding of the incremental cost savings of NOM after cCR also suggests that developing therapeutic strategies to optimize and expand cCR rates could substantially affect not only individual patient outcomes but also public health. There is considerable interest in expanding the pool of eligible patients for organ preservation by increasing the cCR. One strategy that appears to be successful is giving the adjuvant chemotherapy component of treatment before surgery, either before chemoradiation (induction) or after completion of chemoradiation (consolidation). This strategy has become known as total neoadjuvant therapy (TNT). The TIMING trial (NCT00335816) showed that delivering increasing number of cycles (zero, two, four, or six cycles) of consolidative FOLFOX in sequential cohorts of patients with LARC increased the pathologic complete response (pCR) rate to 25%, 30%, and 38%, respectively, compared with 18% for chemoradiation alone, suggesting that giving all of the chemotherapy upfront while increasing the time to surgery increases the pCR (15). A recent meta-analysis of 10 comparative studies demonstrated that TNT increased the likelihood of a pCR by 39% (16). An ongoing, randomized phase II trial of TNT compares sequencing 5-Fluorouracil, Leucovorin, and Oxaliplatin before or after chemoradiation, in which patients with LARC who achieve a cCR are offered NOM (NCT02008656) (17). A similar trial has recently been reported with planned surgery showing a slight increase in pCR with consolidation (18). Efforts also continue in earnest to develop selective radiosensitizers that may improve pCR. NRG-GI002 is an ongoing phase II study evaluating sequential experimental arms integrating radiosensitizers into a TNT platform in patients with high-risk LARC. (NCT02921256). Although TNT strategies have resulted in higher response rates, approximately two-thirds of patients with LARC still require radical surgery (19). As efforts continue, better regimens will likely emerge that will improve complete response rates, which will change the proportion of patients eligible for NOM and ultimately increase the acceptance of the NOM approach. Although the results from Miller et al. will not likely persuade nonbelievers, they do provide an important contribution to our understanding of the advantages of a NOM strategy (4). Although the concept of organ preservation for patients with LARC is appealing, prospective randomized cooperative group studies are needed to confirm the oncologic noninferiority of NOM and the applicability of NOM to routine community oncological practice. In Brazil, Cecconello and colleagues are conducting a randomized phase II trial comparing the 3-year disease-free survival of NOM and radical surgery in LARC patients who achieve a cCR after preoperative chemoradiation (NCT02052921) (20). Although this is an important first step, widespread adoption of NOM will likely be limited and the use of NOM will likely remain controversial until randomized phase III data demonstrate noninferiority and improved patient reported outcomes. The feasibility of randomizing patients to radical surgery vs organ preservation will likely be challenging in the United States because of patient preferences either for or against radical surgery. Nevertheless, outcomes data from prospective randomized trials are critical to provide the knowledge needed to harmonize the insights gained from a cost-effectiveness model of NOM with real-world clinical practice. P. B. Romesser is a consultant for EMD Serono for work on radiation sensitizers. The other authors have no disclosures.
Edgar González Fernández, Guillermo Morales-Luna, Feliú Sagols
Current requirements for ensuring data exchange over the internet to fight against security breaches have to consider new cryptographic attacks. The most recent advances in cryptanalysis are boosted by quantum computers, which are able to break common cryptographic primitives. This makes evident the need for developing further communication protocols to secure sensitive data. Zero-knowledge proof systems have been around for a while and have been considered for providing authentication and identification services, but it has only been in recent times that its popularity has risen due to novel applications in blockchain technology, Internet of Things, and cloud storage, among others. A new zero-knowledge proof system is presented, which bases its security in two main problems, known to be resistant, up to now, against quantum attacks: the graph isomorphism problem and the isomorphism of polynomials problem.
Muhammad Ajmal Azad, Samiran Bag, Feng Hao, Andrii Shalaginov
The Internet of Things (IoT) is the network of connected computing devices that have the ability to transfer valued data between each other via the Internet without requiring human intervention. In such a connected environment, the social IoT (SIoT) has become an emerging trend where multiple IoT devices owned by users support communication within a social circle. Trust management in the SIoT network is imperative as trusting the information from compromised devices could lead to serious compromises within the network. It is important to have a mechanism where the devices and their users evaluate the trustworthiness of other devices and users before trusting the information sent by them. The privacy preservation, decentralization, and self-enforcing management without involving trusted third parties are the fundamental challenges in designing a trust management system for SIoT. To fulfill these challenges, this article presents a novel framework for computing and updating the trustworthiness of participants in the SIoT network in a self-enforcing manner without relying on any trusted third party. The privacy of the participants in the SIoT is protected by using homomorphic encryption in the decentralized setting. To achieve the properties of self-enforcement, the trust score of each device is automatically updated based on its previous trust score and the up-to-date tally of the votes by its peers in the network with zero-knowledge proofs (ZKPs) to enforce that every participant follows the protocol honestly. We evaluate the performance of the proposed scheme and present evaluation benchmarks by prototyping the main functionality of the system. The performance results show that the system has a linear increase in computation and communication overheads with more participants in the network. Furthermore, we prove the correctness, privacy, and security of the proposed system under a malicious adversarial model.
Modern machine learning techniques have achieved surprisingly good standard test accuracy, yet classical machine learning theory has been unable to explain the underlying reason behind this success. The phenomenon of adversarial examples further complicates our understanding of what it means to have good generalization ability. Classifiers that generalize well to the test set are easily fooled by imperceptible image modifications, which can often be computed without knowledge of the classifier itself. The adversarial error of a classifier measures the error under which each test data point can be modified by an algorithm before it is given as input to the classifier. Followup work has showed that a tradeoff exists between optimizing for standard generalization error versus for adversarial error. This calls into question whether standard generalization error is the correct metric to measure. We try to understand the generalization capability of modern machine learning techniques through the lens of adversarial examples. To reconcile the apparent tradeoff between the two competing notions of error, we create new security definitions and classifier constructions which allow us to prove an upper bound on the adversarial error that decreases as standard test error decreases. We introduce a cryptographic proof technique by defining a security assumption in a simpler attack setting and proving a security reduction from a restricted black-box attack problem to this security assumption. We then investigate the double descent curve in the interpolation regime, where test error can continue to decrease even after training error has reached zero, to give a natural explanation for the observed tradeoff between adversarial error and standard generalization error. The second part of our work investigates further this notion of a black-box model by looking at the separation between being able to evaluate a function and being able to actually understand it. This is formalized through the notion of function obfuscation in cryptography. Given some concrete implementation of a function, the implementation is considered obfuscated if a user cannot produce the function output on a test input without querying the implementation itself. This means that a user cannot actually learn or understand the function even though all of the implementation details are presented in the clear. As expected this is a very strong requirement that does not exist for all functions one might be interested in. In our work we make progress on providing obfuscation schemes for simple, explicit function classes. The last part of our work investigates non-statistical biases and algorithms for nonconvex optimization problems. We show that the continuous-time limit of stochastic gradient descent does not converge directly to the local optimum, but rather has a bias term which grows with the step size. We also construct novel, non-statistical algorithms for two parametric learning problems by employing lattice basis reduction techniques from cryptography.
In this thesis, we present novel methods for verifying, implementing and specifying protocols. In particular, we focus properties modeling data protection and the protection of privacy. In the first part of the thesis, the author introduces protocol verification and presents a model for verification that encompasses so-called Zero-Knowledge (ZK) proofs. These ZK proofs are a cryptographic primitive that is particularly suited for hiding information and hence serves the protection of privacy. The here presented model gives a list of criteria which allows the transfer of verification results from the model to the implementation if the criteria are met by the implementation. In particular, the criteria are less demanding than the ones of previous work regarding ZK proofs. The second part of the thesis contributes to the area of protocol implementations. Hereby, ZK proofs are used in order to improve multi-party computations. The third and last part of the thesis explains a novel approach for specifying data protection policies. Instead of relying on policies, this approach relies on actual legislation. The advantage of relying on legislation is that often a fair balancing is introduced which is typically not contained in regulations or policies.
An increasing number of wind farms and mining operations located far off the coast will lead to the development of offshore substations. To avoid the large costs associated with platforms and floaters, such a substation can be placed on the seabed and controlled remotely. The conventional solution is to place the power components, e.g. switchgear placed inside thick-walled pressure-proof vessels to protect them from water and high pressure on the seabed. For current switching in medium voltage applications, there are mainly two options: vacuum circuit breakers or gas circuit breakers (filled at atmospheric or slightly elevated pressure). Whichever option is chosen, power cable feed-throughs or penetrators from the high-pressure water environment into the low pressure inside the vessel are required. These features add substantial technical complexity and costs, in particular at large sea depths. A novel concept is used in this thesis, where the interruption chamber of the circuit breaker can be gradually filled as the switchgear is lowered until finally reaching the same pressure as on the seabed. Reducing the differential pressure on the encapsulation will reduce the overall cost and complexity of such subsea substations. The gas pressures in this case may be in the range of up to tens of bars.\nIf the temperature and pressure of a gas exceed its critical point, it enters a supercritical state. In this state, the physical properties are between that of a gas and a liquid. The properties include high diffusivity, high heat conductivity, high heat capacity, high dielectric strength and an absence of vapour bubbles. These properties of the supercritical fluid are believed to be in favour of a successful current interruption medium. However, there is a distinct lack of knowledge on arc properties and the current interruption capability of extremely high-pressure gasses as well as on the supercritical region. In this thesis, nitrogen (N2) is chosen for its low critical point (33.5 bar, 126 K), good insulation strength and environment-friendly nature. As the critical temperature of N2 is lower than room temperature, the transition to supercritical state can be achieved by pressurizing N2 above 33.5 bar.\nThis thesis reports on the experimental investigation of the characteristics of N2 arc as a function of filling pressure as well as in the supercritical state. For the bulk of the study, filling pressures of 1, 20, 40 and 80 bar are investigated, the latter two being in the supercritical state. A fixed electrode arrangement is used where the arc is initiated by the melting of a copper ignition wire. The investigated arc current amplitude is in the range of 85 A to 450 A at a frequency of 190 Hz to 950 Hz. Based on the focus area of different phases of the arc, this thesis can primarily be divided into three major parts. First, the arc properties during the high-current phase, i.e. during current peak time, are investigated for free-burning and tube-constricted arcs. In the second phase, the investigation is focused near the current zero (CZ) where the thermal phase of the arc is studied. In the final phase, the post-arc dielectric recovery characteristics are studied. The effect of the forced gas flow is investigated in both the thermal and dielectric phase of the arc.\nBased on the experimental results, the arc voltage is found to increase with the filling pressure without any abrupt change during the transition from gas to the supercritical state. Increased current density due to the constriction of the arc at high filling pressure turned out to be the dominant factor for the high arc voltage. When the free-burning arc is physically constricted by means of burning inside a tube, an inverse relation between the arc voltage and the inner tube diameter is observed at 1 bar, as expected. At higher filling pressures, however, such a simple relationship does not exist. The reduced arc radius and the increased absorption of radiation at high filling pressures may limit the interaction between the arc and the tube.\nThe energy deposition in the arc increases while the arc radius decreases with increasing filling pressure. The arc gets constricted and as a result the temperature of the arc core increases. In the free-burning arc, in the absence of forced cooling, the arc core fails to dissipate the stored thermal energy quickly. As a result, without efficient cooling a high post-arc current is often observed at a high filling pressure compared to at 1 bar. The high energy deposition in the post-arc channel due to increased post-arc current causes an early re-ignition at high N2 pressure compared to at 1 bar. A forced gas flow, however, significantly enhances cooling at high filling pressures and improves the interruption performance.\nIn the free-burning arc arrangement, the post-arc dielectric strength of the gap increases rapidly with increasing filling pressure, only after a critical time delay following CZ. This critical time delay is probably linked to the temperature decay of the gap. Below the critical time delay, however, the dielectric strength of the gap is lower at a higher filling pressure in contrast to at 1 bar, similar to what is observed in the thermal re-ignitions of the freeburning arc. Forced gas flow significantly enhances the dielectric recovery of the arc channel at a high filling pressure, also in the thermal phase. The experiments indicate that although the thermal phase is the critical phase of the ultrahigh-pressure N2 arc interruption, the dielectric phase is inherently superior at a high filling pressure compared to atmospheric pressure. With the help of efficient cooling, the thermal phase can be improved, and hence the ultrahigh-pressure N2 reveals its potential to be used as a current interruption medium.
Arterial hypertension affects a third of the world's population and is a significant risk factor for cardiovascular disease. Blood pressure (BP) is one of the most relevant parameters used for monitoring of possible hypertension states in patients at risk of cardiovascular disease. Hence, there exists a need for new monitoring solutions, which allow to increase the frequency between BP assessments, but also allow to reduce the level of occlusion in the attempts. Moens-Korteweg equation is among the main principles to estimate BP by dispensing of any inflatable cuff. This principle might lead to an indirect estimation of BP by measuring the time it takes the pressure pulse to propagate between two pre-established vascular points, accordingly the pulse transit time (PTT) method. This thesis proposes a wearable PTT-based method to estimate central aortic BP (CABP) and, the main milestones of this work included: proof of concept of the proposed method (pilot work), the development of a wearable device (including two stages of validation), the proposition of a miniaturized version (integrated circuit) of the analog front-end of the wearable hardware, and, the development of a novel PTT-based model (PTTBM, i.e., the mathematical relationship between measured variables and estimated BP) suitable for the proposed wearable methodology to estimate BP. The main contributions found at each milestone are presented. One of the contributions of this thesis is the use of the PTT-principle for estimating CABP instead of the peripheral BP (PBP) (as typically used in the literature). The pilot work showed the feasibility of CABP estimation from the PTT principle by using electrocardiogram (ECG) and ballistocardiogram (BCG) recordings from off-the-shelf equipment. Results showed that CABP was more correlated with the proposed methodology in comparison to all PBP variables assessed; confirming our hypothesis that the CABP is the most suitable parameter to collate through the time elapsed from ECG R-wave to the BCG J-wave. That is, considered featured time (RJ-interval) includes the time of a pulse pressure propagating at an aortic district. Bland-Altman plots showed an almost zero mean error (\u\ < 0.02mmHg) and bounded standard deviation o < 5mmHg for all systolic and mean central BP readings. Pilot work provided a landmark in order to develop a compact device that allows the integration of wireless blood pressure monitoring into a wearable system. Another contribution of this thesis is the proposition of a wearable device for PTT-computing by also including design considerations for the signal conditioning chains for ECG and BCG signals. The proposed design procedure takes care of minimizing the impact of spurious delays between physiological signals, which eventually degrade the PTT computation. Further, such a procedure could be suitable for any PTT-acquisition. Filtering with low and controlled delay is required for this biomedical application, and proposed conditioning chains provide less than 2ms group-delay, showing the effectiveness of the proposed approach. In order to provide the methodology with higher autonomy and integration, a highly miniaturized implementation of the filtering approach was also proposed. It includes the design of proposed architectures in CMOS technology to implement the particular low-delay filtering at reduced bandwidth featuring ultra-low-power characteristics. Results show that less than 2ms delay for the ECG QRS-complex can be achieved with a total current consumption of IDD = 2:1nA at VDD = 1:2V of power supply. Such development meant another significant contribution of this work in the conception of highly autonomous wearable devices for PTT acquisition. The first stage of validations on the wearable CABP estimation showed that, when considering data from one volunteer, results achieved with off-the-shelf equipment could be replicated by using a proposed wearable device, and the method could be further validated by using the wearable version. Additionally, CABP estimation from the proposed wearable device could be feasible by using three feature times (FTs) as CABP surrogates; that is, RI, RJ, and IJ intervals (from ECG and BCG wearable recordings). The first validation of the method also showed that CABP could be accurately predicted by the proposed methodology when in the order of daily calibrations are performed. The second stage of validations involved a study with a group of volunteers, and new alternatives were explored (twentyseven: nine PTTBMs along the three FTs) for the CABP estimation. We found that CABP could be accurately estimated (inside AAMI requirements) through the presented methodology by using four of the explored alternatives, whereas the RI interval, an FT lacking any PTT assessment, emerged as the best surrogate for the CABP estimation. Hence, a principle different from the traditional PTT-based method arises as a more advantageous method for the CABP estimation in the light of evidence reported in this validation, and, to our knowledge, this is the first time that CABP has been successfully estimated from a wearable device. The final significant contribution of this thesis meant the last chain-link in the process to achieve an utterly original method to estimate CABP. A novel PTTBM to estimate CABP is proposed, which uses a ow-driven two-element Windkesel network constructed from FTs extracted from the wearable recordings. When classic PTTBMs are applied, the fitting of parameters often leads to values without a physiological basis. Opposite to that in the proposed PTTBM, the parameters have a clear physiological meaning, and the parameter fitting led to values that are consistent with this meaning and more stable throughout calibrations. In conclusion, this thesis introduces a novel device that exploits an alternative and indirect method for CABP estimation. Variants of the principle used, accordingly, PTT method, have been previously explored to estimate PBP but not for central aortic BP. Additionally, the device was designed to be wearable; that is, it is attached to the clothes, causing low discomfort for the user during the measurement, thus, allowing continuous and ambulatory monitoring of aortic pressure. The developed wearable system, validated in a series of volunteers, showed promising results towards the continuous CABP monitoring.
Ordinos is a novel verifiable tally-hiding e-voting system. At its heart, a homomorphic encryption scheme and secure multi-party computation (MPC) are used to tally votes and securely determine the voting result, without necessarily revealing the full tally (e.g., the number of votes per candidate)The proof of concept implementation of Ordinos is based on a threshold variant of the Paillier encryption scheme and two MPC protocols for the comparison of encrypted numbers (greater-than and equality). Due to the threshold construction, the decryption key is shared among a set of trustees. The MPC protocols for comparison require precomputed encrypted randomness of certain shape. Formerly, a trusted party was employed to generate the key shares and randomness and distribute them to the trustees. In this thesis, the trusted party was replaced by MPC protocols that allow to generate the key shares and randomness among the trustees. The protocols provide security against malicious parties in the honest-majority setting. The key generation follows a proposal by Nishide and Sakurai (2010) that is based on verifiable secret sharings and zero-knowledge proofs for committed values. We introduce a few adaptations to reduce its runtime using mostly standard techniques. The generation of randomness is based on the Paillier encryption scheme as an arithmetic black box and standard zero-knowledge proofs for Paillier encrypted values. The protocols were implemented and their performance was evaluated in a local network. Most notablythe implemented key generation protocol for threshold Paillier showed an expected average runtime around 95 minutes for generating 2048-bit keys among 3 trustees with a threshold of 2. Since existing implementations provide security only in the semi-honest setting, this is the first time that an approach with security against malicious parties was implemented and evaluated. Overall, the distributed generation of both key shares and randomness takes considerably more time compared to the use of a trusted party, but avoids security risks and trust problems that occur with trusted parties.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
In this note, we report several solutions to the STARK-Friendly Hash Challenge: a competition with the goal of finding collisions for several hash functions designed specifically for zero-knowledge proofs (ZKP) and multiparty computations (MPC). We managed to find collisions for 3 instances of 91-bit hash functions. The method used is the classic parallel collision search with distinguished points from van Oorshot and Wiener (1994). As this is a general attack on hash functions, it does not exhibit any particular weakness of the chosen hash functions. The crucial part is to optimize the implementations to make the attack cost realistic, and we describe several arithmetic tricks.
By design, smart contracts' data and computations are public to all participants. In this paper, we study how to create smart contracts with parameters that need to stay secret. We propose a way to keep some of the parameters off-chain, while guaranteeing correctness of the computation, using a combination of a commitment scheme and a zero-knowledge proof system. We describe an implementation of our construction, based on ethereum smart contracts and zk-SNARKS. We also provide a small example and a cost analysis of our approach.
New Zealand biodiversity is highly endemic and suffers from extreme loss due to habitat destruction and invasive mammalian predators. Building on New Zealand’s expertise in mammal eradications on offshore islands, the New Zealand government recently announced NZ$28 million to initiate the process to eradicate invasive rats, possums, and mustelids from the New Zealand mainland by 2050. Predator Free 2050 Ltd was established to distribute these funds to groups who could demonstrate local eradication and landscape scale suppression of predators, and lever additional funding to achieve their goals. Not surprisingly, this programme has raised a few eyebrows, enthralled people, angered others, or kick-started a tranche of new biodiversity protection projects across the country. Whatever one’s perspective, the bar has been set very high, and consequently has engaged a lot of people in the thinking, planning, and on-the-ground action. This is one of the most exciting times in New Zealand’s history to be either managing predators or studying them. The challenge is huge, and the opportunities tremendous, but we won’t get there unless we address a number of important knowledge gaps. Manaaki Whenua Landcare Research is one of many New Zealand research providers helping to fill these gaps. Achieving eradication of predators at a national scale requires quantum leaps in pest management, including: 1) new tools and strategies for removing predators; 2) more accurate methods of detecting predators at very low abundance; 3) statistical methods for declaring success; and 4) public co-operation and involvement in the programme. Manaaki Whenua scientists have recently developed a long-life novel lure using kairomones emitted by ferrets. Adding ferret odour to regular bait increased stoat detection rates by 200%, and in kill traps, ferret odour increased stoat kills by 150%. Responses were not limited to stoats, as weasel and hedgehog detections increased by similar amounts with ferret odour. We have also developed a free decision-support tool (TrapSim) to simulate the effects of varying trapping and poisoning regimes. The tool is being further developed to include predator reinvasion and the variation between individuals in their interaction rates with control devices. We have also developed software to help managers estimate the minimum amount of surveillance needed to achieve the required sensitivity and the target probability of eradication. Declaring local eradication reliably is a critical part of moving from one eradication zone to the next. Lack of detections does not necessarily mean eradication, as this depends on the detection network and the probability that a predator can be detected if it is present. We modified software created for determining proof-of-freedom from animal diseases for proof-of-eradication of pests. This allows managers to declare the probability of eradication based on Bayesian statistical methods, given zero detections. Motion-triggered cameras are excellent devices to detect pests at very low densities, but they suffer from the time required to process thousands of images. We are co-developing artificial intelligence that automatically culls out images with no animals and learns to identify animal species when animals are present. This will be a huge cost saver. A key component of the success of this programme is demonstrating the biodiversity, economic, and social benefits. We conduct repeated surveys of urban and rural public to gauge the extent to which the programme affects people’s lives in terms of fewer encounters with pests, more encounters with native biodiversity, perverse outcomes, and greater awareness and understanding about their local biodiversity. Regardless of whether the programme succeeds in the next 30 years, the research and technological advances that are already happening will be hugely beneficial for pest management. Technical challenges, however, are only part of the solution. Working in a populated and agricultural landscape, maintaining the initial enthusiasm we are currently experiencing, and ensuring the majority of the population remains on board, are all enormous challenges.
James Bartusek, Andrea Coladangelo, Dakshita Khurana, Fermi Ma
We investigate the round complexity of maliciously-secure two-party quantum computation (2PQC) with setup, and obtain the following results:
- A three-message protocol (two-message if only one party receives output) in the common random string (CRS) model assuming classical two-message oblivious transfer (OT) with post-quantum malicious security. This round complexity is optimal for the sequential communication setting. Under the additional assumption of reusable malicious designated-verifier non-interactive zero-knowledge (MDV-NIZK) arguments for NP, our techniques give an MDV-NIZK for QMA. Each of the assumptions mentioned above is known from the quantum hardness of learning with errors (QLWE).
- A protocol with two simultaneous rounds of communication, in a quantum preprocessing model, assuming sub-exponential QLWE. In fact, we construct a three-round protocol in the CRS model with only two rounds of online communication, which implies the above result. Along the way, we develop a new delayed technique that we call simulation via teleportation, which may be useful in other settings.
In addition, we perform a preliminary investigation into barriers and possible approaches for two-round 2PQC in the CRS model, including an impossibility result for a natural class of simulators, and a proof-of-concept construction from a strong form of quantum virtual black-box (VBB) obfuscation.
Prior to our work, maliciously-secure 2PQC required round complexity linear in the size of the quantum circuit.
This paper describes preliminary results on a Proportional plus Adaptive Disturbance Observer (P+ADOB) controller applied to velocity regulation tasks in a servo system. Adaptation law is obtained to estimate the servo system input gain, which is subsequently employed in the design of a Disturbance Observer. Compared with previous approaches, this feature relaxes the assumption on exact knowledge on the input gain, and only upper and lower bounds on this term are assumed known. A stability proof assuming constant disturbances allows concluding that the estimate of the input gain is bounded, and the velocity tracking error converges to zero. Real-time experiments illustrate the performance of the proposed controller.
Max Hoffmann, Michael Klooß, Markus Raiber, Andy Rupp
Abstract Black-box accumulation (BBA) is a building block which enables a privacy-preserving implementation of point collection and redemption, a functionality required in a variety of user-centric applications including loyalty programs, incentive systems, and mobile payments. By definition, BBA+ schemes (Hartung et al. CCS ‘17) offer strong privacy and security guarantees, such as unlinkability of transactions and correctness of the balance flows of all (even malicious) users. Unfortunately, the instantiation of BBA+ presented at CCS ‘17 is, on modern smartphones, just fast enough for comfortable use. It is too slow for wearables, let alone smart-cards. Moreover, it lacks a crucial property: For the sake of efficiency, the user’s balance is presented in the clear when points are deducted. This may allow to track owners by just observing revealed balances, even though privacy is otherwise guaranteed. The authors intentionally forgo the use of costly range proofs, which would remedy this problem. We present an instantiation of BBA+ with some extensions following a different technical approach which significantly improves efficiency. To this end, we get rid of pairing groups, rely on different zero-knowledge and fast range proofs, along with a slightly modified version of Baldimtsi-Lysyanskaya blind signatures (CCS ‘13). Our prototype implementation with range proofs (for 16 bit balances) outperforms BBA+ without range proofs by a factor of 2.5. Moreover, we give estimates showing that smart-card implementations are within reach.