Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results · page 150 of 177

Clear filters
Aug 5, 2017·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Generalized Π-Armendariz Authentication Cryptosystem

Areej M. Abduldaim, Nadia M. G. Al-Saidi

Algebra is one of the important fields of mathematics. It concerns with the study and manipulation of mathematical symbols. It also concerns with the study of abstractions such as groups, rings, and fields. Due to the development of these abstractions, it is extended to consider other structures, such as vectors, matrices, and polynomials, which are non-numerical objects. Computer algebra is the implementation of algebraic methods as algorithms and computer programs. Recently, many algebraic cryptosystem protocols are based on non-commutative algebraic structures, such as authentication, key exchange, and encryption-decryption processes are adopted. Cryptography is the science that aimed at sending the information through public channels in such a way that only an authorized recipient can read it. Ring theory is the most attractive category of algebra in the area of cryptography. In this paper, we employ the algebraic structure called skew -Armendariz rings to design a neoteric algorithm for zero knowledge proof. The proposed protocol is established and illustrated through numerical example, and its soundness and completeness are proved.

Open access
Cryptographic Implementations and Security
Coding theory and cryptography
Chaos-based Image/Signal Encryption
Original source
Aug 1, 2017·Neurosurgery
7 cites
Strategies for Autonomous Sensor–Brain Interfaces for Closed-Loop Sensory Reanimation of Paralyzed Limbs

Timothy H. Lucas, Xilin Liu, Milin Zhang, Sri Sritharan · 10 authors

BCI: brain–computer interface DCN: dorsal column nuclei ICMS: intracortical microstimulation LED: light-emitting diode PDMS: polydimethylsiloxane RF: radiofrequency The dexterous hand is a defining feature of human existence. Evolved over tens of millions of years, modern humans are able to perform remarkable tasks with their hands. From typing hundreds of words per minute to playing Rachmaninoff's Piano Concerto No. 2, the dexterous hand defines us. Unfortunately, a number of maladies rob us of this defining human characteristic. In the most extreme case, paralyzed individuals lose communication between the brain and the periphery. This condition affects an estimated 5.4 million people, or 2% of the US population.1 At present, no effective treatment restores function to these individuals. Regaining hand function is a principal concern for paralyzed patients. Toward this aim, significant advances in motor—or efferent—brain–computer interface (BCI) systems have occurred in recent years. Efferent BCI systems extract movement-relevant information from electrocorticography (ECoG) or electroencephalography (EEG). These analogue signals are transformed into control commands to drive robotic arms2 or evoke muscle contractions in paralyzed limbs.3-8 In the later example, compound wrist flexion may be evoked by brain-controlled functional electrical stimulation of forearm flexors. Planned clinical trials aim to capitalize upon these scientific advances to test efferent BCI across a range of conditions and control routines. While these proof-of-principal systems are encouraging, a number of substantial hurdles remain. Perhaps the most pressing barrier to restoring dexterous hand movements is the lack of systems to restore somatosensory feedback. Even in the presence of intact descending motor systems, precise hand movements are abolished when somatosensation is missing.9-16 Indeed, the majority of efferent BCI systems currently in testing rely solely upon visual guidance. This constraint is unnatural and unlikely to be useful if deployed clinically. Visual guidance requires constant vigilance and introduces substantial time-lags to error correct each movement. To restore naturalistic movements, bi-directional BCI systems that link movements and real-time sensory feedback must be developed. The feedback loop of bi-directional BCI is closed with sensory feedback. Unfortunately, the field of sensory—or afferent—brain–computer interface has not kept pace with the maturation of efferent systems. This is due, in part, to the challenges concerning sensory research in animals. Sensory perception is a uniquely subjective experience that does not lend itself readily to the quantitative metrics. For decades, experimentalists have attempted to characterize the perceptual experiences associated with stimulation of the sensory cortices, including primary somatosensory cortex (S1), secondary somatosensory cortex (S2), and parietal association areas in animal models. From this body of literature, we know that intracortical microstimulation (ICMS) of S1 yields sufficient percepts to permit limited binary decisions, such as differentiating between 2 stimulation frequencies or amplitudes.17-21 Despite exhaustive investigation, no study has convincingly reproduced the complex sensory phenomena that are fundamental to our routine encounters with the physical world. Compounding the problem, very limited human data are available to assess the efficacy of S1 stimulation. Animal studies do not answer the question of how stimulation feels. To answer these qualitative questions, we need human data. Most human data have been obtained during brief testing sessions in awake craniotomies or during stimulation in patients with implanted ECoG electrodes.22-24 Invariably, these patients reported that S1 stimulation yielded only vague ‘tingling’ sensations with modest regional localization. Flesher and colleagues recently reported the first human data using ICMS encoding in S1 with chronic penetrating arrays.25 In this experiment, a 28-yr-old male with a spinal cord injury underwent implantation of 2 32-channel multi-electrode arrays into primary somatosensory cortex (S1). Over the course of several months, the investigators mapped perceptual responses to ICMS up to 100 μA. The majority of responses (93%) were categorized as ‘possibly natural,’ ‘pressure’ sensations. The perceptual intensity was modulated by stimulation amplitude with increased pressure corresponding to increase stimulus amplitude. This finding mirrors that of ICMS in primary visual cortex where phosphine brightness is modulated by stimulus amplitude.26 These data constitute a substantial step toward clinical sensory BCI. However, there were a number of findings that tempered enthusiasm for immediately clinical implementation. For instance, none of the S1 electrodes activated sensory representations of the distal fingers where feedback is most needed. Instead, the majority of responses were localized to the palmar crease region of the hand proximal to the fingers. Also, the detection thresholds of a many electrode sites rose significantly over the short course of the study, raising the concern that the effect of S1 encoding will fade over time. Finally, few of the stimuli evoked properly ‘naturalistic’ percepts. These limitations and the disappointing results from similar work in visual cortex raise the question of whether cortical ICMS encoding is the optimal solution for sensory restoration. These unanswered questions motivate our research program. Our work aims to bridge the divide between current state-of-the-art and the clinical needs of our patients. Our overarching strategy is to develop closed-loop, autonomous bidirectional brain–machine interface systems. These systems, as conceived, provide real-time communication between the brain and body. Because the field of efferent BCI has vastly outpaced that of afferent BCI, our work primarily focuses on developing sensory-brain interfaces to couple with existing BCIs (see Bouton et al27 for example). Our strategy focuses on 3 critical intersections of engineering and neuroscience. The first is development of a suite of sensors that serve as mechanoreceptors for the paralyzed, insensate hand. The second is development of a chronic neural interface for artificial sensory encoding. The third is a body area network that links peripheral sensors with novel neural interfaces. The integration of these components is illustrated in Figure 1.FIGURE 1: Body area network. Fully integrated system with implantable force and flex sensors (1, 2), wearable analyzer (3), electrogoniometer (4), and neural interface (5).In this brief overview, we outline our approach, preliminary data, and future directions. This work collectively represents a fruitful collaboration between neurosurgery and electrical engineering. We are grateful to the National Science Foundation for funding our work. RESEARCH APPROACH Our research strategy follows 3 central aims: development of novel sensors, characterization of novel neural interfaces, and development of an autonomous body-area network. Novel Sensors Hand somatosensation can be characterized by a multidimensional space with axes defined by sensory modality (eg, light touch, proprioception), somatotopy, temporal dynamics, the influence of descending central inputs, and brain state. Restoring native somatosensation is perhaps too lofty a goal for a first-generation sensor–brain interface. Instead, we reduce the dimensionality of the problem to a single sensory modality at a single somatotopic location. We have developed a number of force sensors and a proprioceptive sensor as our first aim. The design of our force sensors is constrained by the form and function of the human hand. Relevant design features include: sensor sensitivity, range, power, form-factor, and complexity. Sensitivity is defined as a sensor's accuracy to convert mechanical force into voltage changes on the sensor. Dynamic range captures the extremes of mechanical force spanning interactions between the hand and the physical environment. The feature of power concerns both the requirements of the sensor (active or passive) as well as the sensor's efficiency to convert physical energy into electrical energy. For wireless sensors, the power feature also includes power harvesting and wireless transmission of data. Form-factor is defined as the mechanical properties of the sensor (size, shape) as well as the flexibility and elasticity of the substrate. Finally, the complexity of the sensor constrains fabrication and durability. These competing design constraints inevitably require engineering trade-offs. In the interest of brevity, we focus on 2 prototype force sensors and a proprioceptive sensor to illustrate these engineering trade-offs in the context of sensor–brain interface. First we consider scattering force sensors and optical force sensors before moving toward proprioceptive electrogoniometers. Scattering force sensors operate under the principle of radiofrequency (RF) back scatter. RF identification is a common technique used to track tags, like those attached to garments at a department store to prevent theft or those implanted subdermally in house pets to identify them when they are lost. The central concept is that RF energy polarizes conductive elements, such as the linear segments of an antenna, and scatter energy back in a measurable way. Deformations of the segment length or shape cause a shift in the back-scatter pattern as the polarization of each segment is related to its orientation in a pulsed electromagnetic field. By calibrating the back-scatter patterns induced by force-induced deformations of RF antenna segments, one may indirectly measure forces applied to a flexible antenna implanted under the skin. In the first series of experiments, our group characterized the back-scatter signatures of a number of antenna designs serving as passive sensor nodes. An advantage of passive sensors is that they do not require active power supplies. Therefore, flexible antennas can be implanted under the skin without the need of wires or batteries. Initial antennas were made with copper tape for rapid prototyping. Antenna shapes were constructed into space filling curves (eg, Hilbert, Peano curves) that varied in the number and length of conductive segments (Figure 2). Changes in size and shape of copper RF antennas were associated with reproducible batter scatter properties.FIGURE 2: Passive scattering force sensor design. A, Antenna shapes with different linear segments in second order Hilbert and Peano curves. B and C, Polarization of antenna segments within electromagnetic field. D, Radiofrequency response curves as a function of area of RF tag (left), and shifts in curves with ±2% change in area (right). E, Prototype indium–gallium tags in PDMS substrate. Central reservoir visible in series with antenna segments. F, RF tuning curve of indium–gallium tags in response to forces applied to central reservoir. Rapid shift noted in low end of force axes indicates appropriate sensitivity for precise finger grip.To build force sensitivity, our second series of experiments examined the flexibility of antennas across a range of forces routinely encountered by the human hand. Liquid metal indium–gallium antennas were designed within a flexible, skin-like polydimethylsiloxane (PDMS) substrate. Indium–gallium is a highly conductive eutectic alloy whose melting point is sufficiently low (∼ –2°F) to allow the alloy to remain in liquid phase at room temperature. Channels were laser-etched into the PDMS in the shape of space filling curves to house the alloy (Figure 2). Force sensitivity was amplified by creating a central compressible metal reservoir in series with the channels. When force was applied, the liquid metal filled the channel segments proportionally. As each successful segment of the antenna was filled with conductive metal, the RF back-scatter properties shifted (Figure 2). As can be seen in the RF response curve, the antenna was sufficiently sensitive to capture force changes within 5 N of fingertip pressure, appropriate for precision grip activities. These experiments verified the feasibility of force sensing RF tags. However, limitations to this technique include the need for sensitive detecting antennas to measure back scatter. For this reason, we examined force sensor designs that were independent of RF signal. Optical force sensing is a method to detect fingertip pressure without electromagnetic interference. An optical force sensor layers PDMS membrane on SiO2 within an implantable chip (Figure 3) that could be implanted subdermally. At one end of the floor of the sensor, an internal 80 μm2 light-emitting diode (LED) emits light. The light is reflected by the internal ceiling of the chip that is constructed of PDMS in an inverse lenticular structure. Reflected light is detected by a photodiode at the opposite end of the sensor. The intervening SiO2 acts as an optical waveguide. In the absence of force (or compressing pressure), the waveguide allows reflected light to excite the photodiode with an efficient electric-to-optical conversion, a high sensitivity (0.02 kPa−1) and a pressure sensing resolution (38 mPa). When force is applied, the PDMS ceiling bows downward, opening light channels in the membrane. This allows light to escape, which in turn decreases the voltage at the photodiode monotonically, and yields a scaled readout.FIGURE 3: Optical force sensor design. A, Side view of optical sensor in absence of load. Directional path of light shown in yellow reflected from internal surface of PDMS ceiling. LED emitter located in lower left of sensor; photodiode (PD) located in lower right. B, Applied forces reduce light received by photodiode end. C, Diagram of optical force sensor circuit. D, Idealized relationship between applied force and photodiode voltageBoth scatter sensors and optical sensors achieved their desired engineering goals of converting force into measurable data. Neither system represented optimal solutions. In the case of scatter sensors, environmental noise may obscure the back-scatter energy detected by a horn antenna. In the case of optical sensors, an active circuit is required. On-going experiments aim to address these limitations by increasing the signal-to-noise ratio (RF sensors) and integrating rechargeable power (optical sensors). Beyond touch sensation, proprioception is a fundamental sensory modality that informs us about limb position. To restore proprioception across large joints, we developed a wireless electrogoniometer.28 Unlike other electrogoniometers that require strain gauges or power-hungry potentiometers, our system was designed to have very low power requirements (∼20 μW) both in terms of sensing and wireless data transmission. This was achieved using a pair of impulse-radio ultrawide band wireless smart sensor nodes interfacing with low-power 3-axis accelerometers through event-driven analog-to-digital converters. Electrogoniometers are designed to operate across large joints, such as the elbow, which are too large for strain sensors or other position sensors. On-going experiments aim to combine multiple sensor modalities in the same organism. Novel Central Nervous System Targets Our second aim is to identify optimal sensory encoding nodes along the neuraxis. Cortical encoding has been attempted for decades in animals, and recently in humans, with mixed results. It remains to be seen how well S1 ICMS will faithfully reproduce naturalistic perception. ICMS in other sensory areas, like primary visual cortex, generates phosphenes but not complex visual images.26 This may be due to the fact that cortical representations are distributed. Complex experiential phenomena, like rich somatosensory percepts, are therefore unlikely to be reproduced with focal stimulation without activation of a larger network. Upstream sensory circuits have To to this we developed the first chronic neural interface of the dorsal column nuclei to and stimulation in awake The a for sensory encoding. These nuclei on the dorsal surface of the and proprioceptive signals from primary (Figure from the high information to the for sensory the descending from that may sensory column nuclei interface. A, between and nuclei and in are readily with of the B, implanted in the of a at of in for several C, of of electrode in to studies of the were limited to or In our first of in were implanted with multi-electrode arrays to the feasibility of a chronic interface. Over several months, we that these arrays are and well in without data from implanted yielded a number of Over were The most was that over that are frequencies occurred with a in the we that could be over multiple in with chronic by the results of we designed a series of stimulation In experiments, we the at sensory encoding through at in a highly precise stimulation of the evoked responses in primary sensory stimulation evoked and field in the S1 (Figure which is to from sensory The induced for up to This finding may the of perceptual experiences primary that circuits between and S1 have a function for sensory To test perceptual thresholds of were on a detection and When stimuli were with to detect the electrical stimuli over rose to thresholds for are to cortical thresholds This that encoding experiments to characterize the efficacy of evoked Cortical responses to encoding. A, evoked responses to stimulation. to the which B, of frequencies stimulation. the stimulus at a well the stimulus feasibility of and encoding testing not from these experiments have for somatosensory currently will characterize responses and their to nodes including the and sensory Novel BCI Novel systems are to link peripheral sensor nodes and sensory encoding We developed a bidirectional brain–machine the as our third aim. This when links a suite of implantable and wearable peripheral sensor nodes with neural and electrodes (Figure the system and its nodes are to as a body area network. At the of the are wireless including a neural a neural a sensor and a The of a neural neural feature neural and associated The neural feature are for or field the system includes an neural energy and a detection with control is in the form of a that sensor data from peripheral sensors to desired patterns related to somatosensory cortex (Figure of brain–computer interface A, intersections between BCI systems and in the case of paralyzed or feedback control from nodes within in B, control loop integrating neural and stimulation in the flexibility to paralyzed or neural may be to or or stimulation with a voltage of Our the to current the that that neural and current current stimulation with a to a phase that neural However, changes due to during the Over millions of develop and in that the interface and To properly for this we a feedback that the phase when a point is detected (Figure The of this circuit is an error that error by the during stimulus the are the range, stimulation are as error that this method over that the system will have in experiments are to test this principle A, and of between phase and phase shown Idealized shown in shown in B, the on of point body area network requires real-time communication between the is with an impulse-radio band The and components to and between For clinical communication between nodes must be and operate within an of data The features an data of 2 in The error was over a of 3 of these are well within the desired for human moving toward human a number of must be of the system must be in must also be to To whether of the system was and effective at percepts, we designed in experiments on the the were to a to the by visual a pattern the is were to ICMS by the as a on the (Figure As the animal the stimulation As significantly in the presence of perception. When the was during was are able to systems to perception in a and effective In feasibility testing of novel systems. A, B, design is to in by ICMS as Idealized illustrated from with and optimal in presence of In our strategy to develop a sensor–brain interface system focuses on 3 aims: development of novel sensors, characterization of novel neural and development of autonomous body-area network. We have made in each of these areas, but substantial work We to our systems up to channel peripheral sensors and our In we our systems to animal models. It is our goal to this sensor brain interface with existing efferent systems to a bidirectional BCI to paralyzed This work was in by the National Science The have no or interest in of the or in this

Open access
EEG and Brain-Computer Interfaces
Neuroscience and Neural Engineering
Muscle activation and electromyography studies
Original source
Aug 1, 2017·arXiv
39 cites
Transforming face-to-face identity proofing into anonymous digital identity using the Bitcoin blockchain

Daniel Augot, Hervé Chabanne, Olivier Clémot, William R. George

The most fundamental purpose of blockchain technology is to enable persistent, consistent, distributed storage of information. Increasingly common are authentication systems that leverage this property to allow users to carry their personal data on a device while a hash of this data is signed by a trusted authority and then put on a blockchain to be compared against. For instance, in 2015, MIT introduced a schema for the publication of their academic certificates based on this principle. In this work, we propose a way for users to obtain assured identities based on face-to-face proofing that can then be validated against a record on a blockchain. Moreover, in order to provide anonymity, instead of storing a hash, we make use of a scheme of Brands to store a commitment against which one can perform zero-knowledge proofs of identity. We also enforce the confidentiality of the underlying data by letting users control a secret of their own. We show how our schema can be implemented on Bitcoin's blockchain and how to save bandwidth by grouping commitments using Merkle trees to minimize the number of Bitcoin transactions that need to be sent. Finally, we describe a system in which users can gain access to services thanks to the identity records of our proposal.

Open access
2 source records
cs.CR
cs.IT
Blockchain Technology Applications and Security
Original source
Jul 21, 2017
0 cites
Advanced cryptographic techniques for building verifiable and transparent electronic voting protocols

Alex Escala Ribas

Electronic voting presents many challenges due to its multiple security requirements. Some of the challenges are related to guaranteeing voters' privacy and system's transparency, which are hard to satisfy simultaneously. Electronic voting also presents other challenges such as usability, particularly from the voter's side. We study two particular problems of electronic voting. Cast-as-intended verifiability comprises those mechanisms which assure the voter that her cast ballot corresponds to her chosen voting options. Current proposals put the verification burden on the voter, something which is undesirable in real-world elections, where both technically skilled and non-skilled voters participate. In this thesis, we introduce the concept of universal cast-as-intended verifiability, which provides mechanisms which allow any entity to check that any ballot corresponds to the voter's selections - without revealing them. We formally define what universal cast-as-intended verifiability is and we give an electronic voting protocol satisfying this property. The other problem we have studied is the problem of invalid votes in electronic elections. Since a common selling point of electronic voting is that it avoids voters inadvertently spoiling their votes, deliberately spoiled ballots appearing in the tallying phase of an electronic election can cause mistrust on the system. Indeed, election stakeholders might think that the system is flawed or that it was exploited somehow. To avoid this situation, we define the concept of vote validatability, which states the electronic voting system should be able to detect spoiled ballots before they are successfully cast. In addition to formally defining this notion, we design an electronic voting protocol satisfying this property. All these security requirements of electronic voting systems are implemented with cryptographic tools. In addition to encryption and signature schemes, another essential primitive for building electronic voting protocols is zero-knowledge proofs. Zero-knowledge proofs allow a prover to convince a verifier that a statement is true without leaking any other information. These zero-knowledge proofs can be used to, for example, prove that the tally of the election was done properly. Recently, Groth and Sahai constructed efficient non-interactive zero-knowledge proofs for a wide range of statements including, among others, statements appearing in electronic voting. In this thesis we give two contributions on Groth-Sahai proofs. On the one hand, we give a framework for deriving cryptographic assumptions from which to build secure cryptographic protocols. In particular, we build new Groth-Sahai proofs improving the efficiency of currently known constructions. Independently, we show how the original Groth-Sahai proofs can be extended to be compatible with even more statements, how to improve their out-of-the-box efficiency for many of these statements and how to improve their re-usability efficiency among multiple statements. Els sistemes de vot electrònic presenten molts reptes a causa dels seus múltiples requeriments. Alguns d'aquests reptes estan relacionats amb garantir la privacitat del votant i la transparència del sistema, requisits que són difícils de satisfer al mateix temps. D'altra banda, els sistemes de vot electrònic presenten altres reptes com la usabilitat, sobretot de cara als votants. En aquesta tesi estudiem dos problemes del vot electrònic. La verificabilitat "cast-as-intended" tracta d'obtenir mecanismes que garanteixin al votant que el seu vot correspon a les seves preferències. Les propostes actuals posen la càrrega de la verificació en el votant, cosa que no és desitjable en eleccions del món real, on participen votants amb diferents graus de coneixements tècnics. Nosaltres introduïm el concepte de "universal cast-as-intended verifiability", que proporciona mecanismes per a que qualsevol entitat de l'elecció pugui comprovar que qualsevol vot conté les preferències del votant que l'ha emès - sense revelar el contingut del vot. A banda de definir formalment el concepte de "universal cast-as-intended verifiability" també proposem un protocol de vot electrònic que satisfà aquesta propietat. L'altre problema que hem estudiat és el problema dels vots invàlids en eleccions electròniques. Un dels avantatges del vot electrònic és que permet evitar que els votants emetin vots nuls sense voler. Per això, si durant el recompte de l'elecció apareixen vots nuls construïts intencionadament es pot crear desconfiança en el sistema de vot. Els usuaris del sistema de vot poden pensar que el sistema té forats de seguretat o que ha estat atacat. Per evitar aquesta situació, definim el concepte de "vote validatability", una propietat dels sistemes de vot electrònic que garanteix que els vots nuls es poden identificar en el moment que s'emeten. En aquesta tesi hem definit formalment aquesta propietat i hem dissenyat un protocol que la satisfà. Tots aquests requisits de seguretat dels protocols de vot electrònic s'implementen amb eines criptogràfiques. Les principals eines que s'utilitzen són esquemes de xifrat, esquemes de firma i proves de coneixement zero. Una prova de coneixement zero permet a una entitat convèncer una altra entitat que una sentència és certa sense donar cap altra informació que la certesa de la sentència. Aquestes proves de coneixement zero es poden fer servir, per exemple, per demostrar que el recompte de l'elecció s'ha fet correctament. Recentment, Groth i Sahai han construït proves de coneixement zero que es poden fer servir per un ampli ventall de sentències com per exemple sentències que apareixen en protocols de vot electrònic. En aquesta tesi hem fet dos contribucions sobre les proves de Groth i Sahai. Per una banda donem un marc teòric que permet derivar hipòtesis criptogràfiques per construir protocols criptogràfics. En particular, construïm noves proves de Groth i Sahai millorant l'eficiència de les construccions existents. De manera independent, indiquem com les proves de Groth i Sahai es poden estendre per fer-les compatibles amb un ventall més ampli de sentències, millorem l'eficiència de les proves de Groth i Sahai per moltes d'aquestes sentències i, en particular, quan es fan servir per demostrar múltiples sentències.

Open access
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Advanced Authentication Protocols Security
Original source
Jun 23, 2017·International Journal of Advanced Research in Computer Science
1 cites
AN EFFICIENT AUTHENTICATION PROTOCOL USING ZERO KNOWLEDGE PROPERTY AND PAIRING ON ELLIPTIC CURVES

Manoj Kumar

The systematic introduction to zero knowledge proof protocol has important theoretical guidance and practical significance on attracting more scholars involved in research as well as expanding application fields. Zero-knowledge proofs were first conceived in 1985 by Shafi Golwasser, Silvio Micalli and Charles Rackoff in a draft of the knowledge complexity of interactive proof systems. The goal of the present paper is to introduce a new identity based scheme which is a combination of zero-knowledge interactive proof and weil pairing on elliptic curves. The concept of weil pairing was first introduced by Andre Weil in 1940. It plays an important role in the theoretical study of the arithmetic of elliptic curves and Abelian varieties. It has also recently become extremely useful in cryptologic constructions related to these objects.

Open access
Cryptography and Residue Arithmetic
Cryptography and Data Security
Polynomial and algebraic computation
Original source
Jun 20, 2017·Journal of Zankoy Sulaimani - Part A
5 cites
Hollow and Semihollow Modules

Payman Ali, Basil Al-Hashimi

Let be an associative ring with identity and be a non-zero unitary left module over . is called a hollow (semihollow) module if every proper (finitely generated proper) submodule of is a small submodule of . The purpose of this work is, to give a comprehensive study of hollow modules and semihollow modules. Moreover, we study the class of modules with finite spanning dimension. We supply the details of the proofs for almost all the results and we illustrate the concepts by examples. Also, we add some results that seem to be new to the best of our knowledge.

Open access
Rings, Modules, and Algebras
Original source
Jun 1, 2017
23 cites
A code-based blind signature

Olivier Blazy, Philippe Gaborit, Julien Schrek, Nicolas Sendrier

In this paper we give the first blind signature protocol for code-based cryptography. Our approach is different from the classical original RSA based blind signature scheme, it is done in the spirit of the Fischlin approach [9] which is based on proofs of knowledge. To achieve our goal we consider a new tool for zero-knowledge (ZK) proofs, the Concatenated Stern ZK protocol, which permits to obtain an authentication protocol for concatenated matrices. A signature is then obtained from the usual Fiat-Shamir heuristic. We describe our blind signature protocol for cryptography based on Hamming metric and show how it can be extended to rank based cryptography. The security of our blind protocol is based on the security of a trapdoor function for the syndrome decoding problem: the CFS signature scheme for Hamming distance and on the more recent RankSign protocol for rank metric. We give proofs in the random oracle model (ROM) for our blind signature scheme, which rely on the Syndrome Decoding problem. The parameters we obtain for our protocol are practical for rank metric (200kBytes) for the signature length and 15kBytes for public key size) and a little less practical for Hamming distance.

Open access
Cryptography and Data Security
Coding theory and cryptography
graph theory and CDMA systems
Original source
May 26, 2017·Medical Physics
1 cites
Due to potential concerns of bias and conflicts of interest, regulatory bodies should not do evaluation methodology research related to their regulatory missions

Dev P. Chakraborty, Robert M. Nishikawa, Colin G. Orton

One of the major roles of regulatory bodies is to enforce rules and thus maintain standards. They also often do research related to their missions, some of which might be used to establish the standards they are regulating and how they should be evaluated. This has led some to believe that, due to potential concerns of bias and conflicts of interest, regulatory bodies should not do evaluation methodology research related to their regulatory missions. This is the claim that is debated in this month's Point/Counterpoint. Arguing for the Proposition is Dev P. Chakraborty, Ph.D. Dr. Chakraborty earned his Ph.D. in solid state physics from the University of Rochester, New York in 1977 then, in 1979, began his career in medical physics working with Ivan Brezovich in the Department of Radiology, University of Alabama at Birmingham, AL, where he worked until 1988 before moving to the Department of Radiology, University of Pennsylvania, Philadelphia. He subsequently moved to the University of Pittsburgh, Pittsburgh, PA, in 1997, where he was Professor in the Department of Bioengineering before assuming his current position at ExpertCAD Analytics, LLC in 2016. He has published over 75 papers in peer-reviewed journals, many in the field of observer performance analysis. Arguing against the Proposition is Robert M. Nishikawa, Ph.D. Dr. Nishikawa received his B.Sc. in physics in 1981 and his M.Sc. and Ph.D. in Medical Biophysics in 1984 and 1990, respectively, all from the University of Toronto. While at the University of Chicago, he developed computer-aided diagnosis systems for classifying and detecting clustered calcifications in mammograms. He has seven patents on CAD-related technologies and has over 200 publications in breast imaging. He is currently a Professor and Director of the Clinical Translational Medical Physics Laboratory in the Department of Radiology at the University of Pittsburgh. He has won 24 awards including two for “best” paper, two innovation awards, and one teaching award. He is a fellow of the American Association of Physicists in Medicine, the Society of Breast Imaging, the College of American Institute for Medical and Biological Engineering, and a Distinguished Investigator, Academy of Radiology Research. His research interests are in computer-aided diagnosis, breast imaging, image quality assessment, and evaluation of medical technologies. The Food and Drug Administration (FDA) and the Center for Devices and Radiological Health (CDRH) both regulate imaging devices and claim leadership roles in how they are evaluated. To demonstrate that the CDRH leadership in imaging device evaluation research biases research in this area and results in suboptimal evaluation of new imaging devices, I will present a single extended example. CDRH scientists are leading proponents of FROC/ROC1, 2 methods for analyzing observer outcome studies. An alternative and often more efficacious approach is the JAFROC method3 pioneered in my laboratory. Does a computer-aided detection (CAD) manufacturer adopt evaluation methods developed by Chakraborty3 or does the manufacturer feel pressure to adopt the FDA's methods?1, 2 Chakraborty's methods/software (JAFROC) have been used in over 104 publications, but only 24 are from the US and none from the FDA. The chances that this low number is a fluke are astronomically small, especially given the much larger total numbers of published US studies relative to non-US studies. This is strong evidence the FDA has influenced US-researchers against using JAFROC. Most clinical trials, including the American College of Radiology Imaging Network (ACRIN) Digital Mammographic Imaging Screening Trial (DMIST),4 have used the lower power ROC paradigm for localization tasks, which is inappropriate and unethical:5 lower power means the study is either of dubious value or it is overly expensive. The location-specific method favored by the FDA1, 2 is based on the FROC curve: one can hardly do worse. FROC data consist of mark-rating pairs; marks are locations of suspicious regions and the rating is the associated confidence level. Based on a proximity criterion, a mark close to a lesion is scored as lesion localization (LL) and otherwise, it is non-lesion localization (NL). Lesion localization fraction (LLF) is defined as the number of LLs ≥ threshold divided by the total number of lesions. The non-lesion localization fraction (NLF) is the number of NLs ≥ threshold rating divided by the total number of images. The FROC curve (plot of LLF (ordinate) vs. NLF) rises with infinite slope from (0,0). The slope then decreases monotonically and the curve ends abruptly at an unpredictable point. The FROC is not contained within the unit square. This makes it impossible to define a meaningful area measure. The FROC is defined by marks: unmarked nondiseased cases, which represent perfect decisions, do not contribute to the area under the curve (AUC) under the FROC. In screening mammography, about 995 cases out of 1000 are nondiseased. The perfect radiologist, who marks all lesions and does not mark any nondiseased case, yields zero FROC AUC, receiving no credit for the 995 correct decisions. JAFROC is based on the AFROC (alternative-FROC) curve. The y-axis is similar to LLF, but the x-axis is the ROC false-positive fraction defined by the highest ratings on nondiseased cases, and the AFROC plot includes a connection from the uppermost operating point to (1,1). Unlike the FROC AUC, the AFROC AUC for the perfect observer is unity, not zero. JAFROC is ignored in FDA's Guidance Document,2 as are positive statements about JAFROC from the late Drs. Wagner and Metz,6 and there is not one reference to Chakraborty's work. The FDA's bias has doomed progress in breast cancer CAD (40,000 deaths/yr). Besides using incorrect FROC methodology, it has set a low (second reader) bar for CAD to be considered a “success”. The end result: massive clinical trials7 have shown that CAD is actually detrimental to the outcome and there has been a call to end CAD Medicare reimbursement.8 Regulation is necessary to balance the costs and benefits of implementing a product or activity. This raises two important issues. First, it is important to quantify costs and benefits accurately. Second, it is equally important for impartiality to acquire correct balances. The proposition directly addresses the second issue, but the first issue is necessary to discuss also. I will restrict my discussion to medical imaging devices for clarity. There are many well-established methods to determine the benefits of medical imaging devices.9 There are, however, situations where researchers need new evaluation methods, either for a new technology or to simplify tests for an existing type of technology. This requires research to develop and validate the new methodologies. The regulatory agencies need to understand the strengths and weaknesses of any tests presented to them as evidence for the effectiveness of a product. This would require regulatory agencies to either develop the expertise in-house or to rely on the scientific literature. That latter is insufficient for two reasons. First, regulatory science is not a well-funded branch of science. Therefore, unless the regulatory bodies perform the research, a disconnect may occur between developing the technologies and measuring their benefits and costs. This will either slow down approval of new technologies or lead to unbalanced regulations, or both. Second, reviewing the literature may be effective in understanding the basics of the evaluation methodology, but it is usually insufficient to understand the limitations of the method. Understanding the limitations is best done by applying the method, using simulations to a variety of situations, and evaluating the results. That is basically research and regulatory bodies benefit from conducting the studies themselves. While we can quantify benefits and costs, it is often difficult to decide on the proper balance of the two, particularly in an unbiased manner. Part of the difficulty arises from benefit and cost estimates not having the same units. A prime example of this, while not exactly in the regulatory domain, is the United States Preventative Services Task Force (USPSTF) recommendations on mammographic screening.10 We can evaluate the benefits of screening as lower mortality from breast cancer and costs as false-positive screens — recalling a woman for further imaging when, in fact, she does not have a breast cancer. It is not clear how to balance lives saved against more imaging and potentially an unnecessary biopsy. The USPSTF placed more weight on false-positive screens and chose not to recommend periodic screening for all women under the age of 50, compared to, for example, the American College of Radiology which supports annual screening of women 40 and older.11 Some proponents of screening argue that the USPSTF was biased in making their recommendations.12 There is no clear solution for this potential bias, but I do not believe that researching evaluation methodology is the right place to start. On the contrary, I believe there is less potential for bias when people are more knowledgeable — unless they are predisposed to a bias to begin with. Which is to say a bias can exist whether knowledge is obtained first hand or from reviewing the literature. I agree with my colleague that the FDA/CDRH needs to be current on the science. If regulatory science is not a well-funded branch of science, that makes it even more important to be current on the existing science, both from a revered in-house predecessor6 and from academia.3 I also agree that there is need for developing new evaluation methods, but then why is the new FDA/CRDH still wedded to the 1940s ROC paradigm; what is new about it? The “mechanistic” approach13 that they are enamored with does not advance the state-of-the-art in general-paradigm multireader multicase (MRMC) analysis, rather it explains and generalizes the variance-component decomposition used in Dorfman/Berbaum/Metz analysis14 in a mathematically appealing way. But, and this is the serious limitation, it applies only to the Wilcoxon ROC statistic; it is not even applicable to fitted ROC curves, let alone FROC methodology. In my Opening Statement, I cited the “power” imbalance when it comes to reviewing/vetting the work of the FDA/CDRH, and examples of questionable work. I could go on, especially how they validate methodologies. It is a brave and knowledgeable researcher who can properly review a paper15 listing as institution of origin: “NIBIB/CDRH Laboratory for the Assessment of Medical Imaging Systems”. Any applicant for an NIH grant in methodology development, and I see there is a recent funding opportunity announcement (PAR-17-125), would be well advised to cite this paper, never mind that it is about ROC analysis, while CAD provides FROC data, so at the very least the title of the paper is misleading. The cited work remains true to model observer philosophy, which assumes the lesion location is known, ignoring the fact that if location were known, there would be no need for a radiologist to find it. This entire debate would be of academic interest, but it was not for the implications for patient care: lives literally depend on the selection of proper imaging technology. Conducting ROC studies for search tasks is not only bad science but it is also unethical and a disservice to patients and taxpayers. My colleague Dev Chakraborty argues, I believe because it is not explicitly stated that the FDA, but principally the CDRH, is biased because it “forces” companies to use ROC analysis instead of JAFROC analysis, which Dev developed; and that this bias exists because members of the CDRH have done ROC research, but not FROC research. That is an interesting premise. Dev supports his assertion with statistics that are consistent with his view, but it does not constitute proof. Here is my prospective on Dev's claim of bias. First, I know many of the people at the CDRH. In my view, they are among the leaders in the field, both in terms of their scientific rigor and in their vision. The CDRH has a long history of significant and cutting edge research and establishing methodology for evaluating screen-film systems, digital systems, computer-aided diagnosis systems, ultrasound, and others. I have not seen signs of bias in my interactions with members of the CDRH. Certainly, the members have preferences, but they remain open-minded and fair. It is important to note that just as there are differences in approach between scientists in academia and industry, there are differences between scientists in the public service sector and academia (and industry). Scientists in the public are much more open to sharing data and ideas. Second, companies applying for FDA approval are, in my experience working with them, very conservative in their approach, and they basically follow any FDA precedent or previous approved applications. This is because the approval process can be time-consuming and expensive. Companies usually overpower their observer studies to include more readers and cases than what is required by an 80% power calculation. They do not want to risk having a null result because the observer study was underpowered. Furthermore, and more importantly, it is much easier and less risky just to copy a previously approved application. This will result in the same methods being perpetuated over time. So, when a company develops a new method, even if there are some benefits to it over existing techniques, they are less likely to use the new method in FDA submissions. This is the company's choice, not an FDA edict. So, while Dr. Chakraborty has presented evidence, it is all circumstantial and, until he produces a “smoking gun”, I believe that his assertion of bias at the CDRH is false. The authors have no relevant conflicts of interest to disclose.

Open access
Global Cancer Incidence and Screening
Digital Radiography and Breast Imaging
AI in cancer detection
Original source
Apr 8, 2017·Jurnal Teknik Informatika dan Sistem Informasi
11 cites
IMPLEMENTASI TWO FACTOR AUTHENTICATION DAN PROTOKOL ZERO KNOWLEDGE PROOF PADA SISTEM LOGIN

Willy Sudiarto Raharjo, Ignatia Dhian Estu Karisma Ratri, Henry Susilo

Abstract — This paper describes a login system utilizing Two Factor Authentication and Zero Knowledge Proof using Schnorr NIZK. The proposed system is designed to prevent password leak when being sent over insecure network or when used in an untrusted devices. Zero Knowledge Proof is used  for maintaining the confidentiality of the password and Two Factor Authentication is used to secure login process on untrusted devices. The proposed system has been tested and initial results indicates that such system is able to secure the login process without leaking the user’s password. Keywords— Authentication, Security, Two Factor Authentication, Password, Zero Knowledge Proof

Open access
User Authentication and Security Systems
Digital and Cyber Forensics
Original source
Apr 7, 2017·arXiv (Cornell University)
6 cites
A Zero Knowledge Sumcheck and its Applications

Alessandro Chiesa, Michael A. Forbes, Nicholas Spooner

Many seminal results in Interactive Proofs (IPs) use algebraic techniques based on low-degree polynomials, the study of which is pervasive in theoretical computer science. Unfortunately, known methods for endowing such proofs with zero knowledge guarantees do not retain this rich algebraic structure. In this work, we develop algebraic techniques for obtaining zero knowledge variants of proof protocols in a way that leverages and preserves their algebraic structure. Our constructions achieve unconditional (perfect) zero knowledge in the Interactive Probabilistically Checkable Proof (IPCP) model of Kalai and Raz [KR08] (the prover first sends a PCP oracle, then the prover and verifier engage in an Interactive Proof in which the verifier may query the PCP). Our main result is a zero knowledge variant of the sumcheck protocol [LFKN92] in the IPCP model. The sumcheck protocol is a key building block in many IPs, including the protocol for polynomial-space computation due to Shamir [Sha92], and the protocol for parallel computation due to Goldwasser, Kalai, and Rothblum [GKR15]. A core component of our result is an algebraic commitment scheme, whose hiding property is guaranteed by algebraic query complexity lower bounds [AW09,JKRS09]. This commitment scheme can then be used to considerably strengthen our previous work [BCFGRS16] that gives a sumcheck protocol with much weaker zero knowledge guarantees, itself using algebraic techniques based on algorithms for polynomial identity testing [RS05,BW04]. We demonstrate the applicability of our techniques by deriving zero knowledge variants of well-known protocols based on algebraic techniques, including the protocols of Shamir and of Goldwasser, Kalai, and Rothblum, as well as the protocol of Babai, Fortnow, and Lund [BFL91].

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Formal Methods in Verification
Original source
Mar 31, 2017·IEEE photonics journal
8 cites
Ultra-long Distance Distributed Intrusion Detecting System Assisted With In-line Amplification

Macheng Lai, Kuan Peng, Yiyang Luo, Xiaolei Li · 8 authors

An ultra-long distance distributed intrusion detecting system assisted with power amplification and sensitivity enhancement is proposed and demonstrated. First, through introducing multiple bidirectional amplifiers into the unbalanced Mach-Zehnder/Sagnac interferometer-based fiber sensing link, the sensing distance is remarkably extended, and second, the signal-to-noise ratio of this sensing system is significantly improved from less than 2 to 6-8 dB by coating the sensing fiber with organic silicone polymer. Furthermore, the high-order downtrend fitting function is adopted to implement the intrusion locating of ultralong distance sensing; the zero-padding fast Fourier transform algorithm and multiple-averaging method are jointly utilized for the improvement of the locating accuracy. Experimentally, a proof-of-concept distributed intrusion detecting system is constructed with the employment of bidirectional amplification. In particular, the ultra-long sensing distance up to 226.337 km is implemented, which is the reported longest distributed sensing system to the best of our knowledge.

Open access
Advanced Fiber Optic Sensors
Photonic and Optical Devices
Advanced Photonic Communication Systems
Original source
Mar 18, 2017·arXiv (Cornell University)
146 cites
Prio: Private, Robust, and Scalable Computation of Aggregate Statistics

Henry Corrigan-Gibbs, Dan Boneh

This paper presents Prio, a privacy-preserving system for the collection of aggregate statistics. Each Prio client holds a private data value (e.g., its current location), and a small set of servers compute statistical functions over the values of all clients (e.g., the most popular location). As long as at least one server is honest, the Prio servers learn nearly nothing about the clients' private data, except what they can infer from the aggregate statistics that the system computes. To protect functionality in the face of faulty or malicious clients, Prio uses secret-shared non-interactive proofs (SNIPs), a new cryptographic technique that yields a hundred-fold performance improvement over conventional zero-knowledge approaches. Prio extends classic private aggregation techniques to enable the collection of a large class of useful statistics. For example, Prio can perform a least-squares regression on high-dimensional client-provided data without ever seeing the data in the clear.

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Mar 1, 2017·Cryptologia
7 cites
How to explain modern security concepts to your children

Xavier Bultel, Jannik Dreier, Pascal Lafourcade, Malika More

At the main cryptography conference, CRYPTO, in 1989, Quisquater and colleagues published a paper showing how to explain the complex notion of zero-knowledge proof in a simpler way that children can understand. In the same line of work, this article presents simple and intuitive explanations of various modern security concepts and technologies, including symmetric encryption, public key encryption, homomorphic encryption, intruder models (CPA, CCA1, CCA2), and security properties (OW, IND, NM). The explanations given in this article may also serve in demystifying such complex security notions for non-expert adults.

Open access
Cryptography and Data Security
Chaos-based Image/Signal Encryption
Cryptographic Implementations and Security
Original source
Feb 24, 2017·Jurnal Teknik ITS
1 cites
Implementasi Teknologi Nfc Pada Ponsel Pintar Sebagai Agen Autentikasi Dalam Sistem E-Vote

Muhamad Ardhinata Juari, Supeno Djanali, Hudan Studiawan

Sistem pemungutan suara di Indonesia yang lebih dikenal dengan nama pemilihan umum (pemilu) sampai saat ini masih dilaksanakan secara manual. Dalam sistem tersebut, dibutuhkan waktu yang lama serta tenaga yang besar untuk menghitung hasil dari pemlihan umum tersebut. Sistem manual juga memiliki banyak kelemahan yang bisa dimanfaatkan oleh pihak tertentu untuk memanipulasi hasil pemilihan umum . Untuk mengatasi masalah ini, salah satu solusinya adalah dengan menerapkan sistem pemilihan umum dengan sistem berbasis perangkat elektronik yang lebih dikenal dengan istilah E-Vote . Berbagai macam metode telah diterapkan dalam sistem E-Vote untuk mengatasi kecurangan, salah satunya dengan menggunakan sistem enkripsi-dekripsi data dari pemilih ke sistem. Namun hal ini kurang efektif apabila kecurangan terjadi ketika data sudah dirubah sebelum masuk ke sistem. Dengan menerapkan mekanisme rantai kepercayaan (chain of trust) untuk mendeteksi adanya perubahan surat suara serta sistem autentikasi digital, mekanisme keamanan bagi peserta pemungutan suara bisa diwujudkan. Proses autentikasi digital menggunakan ponsel pintar dengan teknologi NFC dipadukan dengan sistem enkripsi asimetris dan digital signature . Pemilih bisa mendeteksi adanya perubahan surat suara melalui digital signature yang ada dan sistem E-Vote bisa mengenali peserta dari kunci publik yang ditawarkan oleh autentikator. Kemudian sistem E-Vote bisa memverifikasi keaslian kunci publik peserta melalui autentikasi berbasis zero-knowledge proof challenge . Hasil pilihan peserta kemudian dikirimkan ke autentikator untuk ditandatangani dan tandatangan tersebut digunakan sebagai bukti peserta telah melakukan pemilihan. Dari hasil uji coba yang dilakukan, terbukti bahwa autentikator bisa mendeteksi ketidaksamaan antara data dengan signature, dan autentikator bisa melakukan autentikasi dengan sistem E-Vote dengan tepat. Data hasil pilihan peserta bisa diverifikasi dengan signature yang ada untuk memeriksa integritas data.

Open access
Internet Traffic Analysis and Secure E-voting
Information Retrieval and Data Mining
Blockchain Technology in Education and Learning
Original source
Feb 1, 2017
6 cites
Investigation into Practical Implementations of a Zero Knowledge Protocol.

Peter Marleau, Rebecca Krentz-Wee

In recent years, the concept of Zero Knowledge Protocols (ZKP) as a useful approach to nuclear warhead verification has become increasingly popular. Several implementations of ZKP have been proposed, driving technology development toward proof of concept demonstrations. Whereas proposed implementations seem to fall within the general class of template-based techniques, all physical implementations of ZKPs proposed to date have a complication: once the instrumentation is prepared, it is no longer authenticatable; the instrument physically contains sensitive information. In this work we explore three different concepts that may offer more authenticatable and practical ZKP implementations and evaluate the sensitive information that may be at risk when doing so: sharing a subset of detector counts in a preloaded image (with spatial information removed), real-time image subtraction, and a new concept, CONfirmation using a Fast-neutron Imaging Detector with Anti-image NULL-positive Time Encoding (CONFIDANTE). CONFIDANTE promises to offer an almost ideal implementation of ZKP: a positive result is indicated by a constant rate at all times enabling the monitoring party the possibility of full access to the instrument before, during, and after confirmation. A prototype of CONFIDANTE was designed, built, and its performance evaluated in a series of measurements of several objects including a set of plutonium dioxide Hemispheres. Very encouraging results proving feasibility are presented. 1 Rebecca is currently a graduate student in Nuclear Engineering at UC Berkeley

Open access
Semantic Web and Ontologies
Original source
Jan 13, 2017·Open Repository and Bibliography (University of Luxembourg)
0 cites
On Composability and Security of Game-based Password-Authenticated Key Exchange

Marjan Škrobot

The main purpose of Password-Authenticated Key Exchange (PAKE) is to allow secure authenticated communication over insecure networks between two or more parties who only share a low-entropy password. It is common practice that the secret key derived from a PAKE execution is used to authenticate and encrypt some data payload using symmetric key protocols. Unfortunately, most PAKEs of practical interest, including three protocols considered in this thesis, are studied using so-called game-based models, which -- unlike simulation models -- do not guarantee secure composition per se. However, Brzuska et al. (CCS 2011) have shown that a middle ground is possible in the case of authenticated key exchange that relies on Public-Key Infrastructure (PKI): the game-based models do provide secure composition guarantees when the class of higher-level applications is restricted to symmetric-key protocols. The question that we pose in this thesis is whether or not a similar result can be exhibited for PAKE. Our work answers this question positively. More specifically, we show that PAKE protocols secure according to the game-based Real-or-Random (RoR) definition of Abdalla et al. (PKC 2005) allow for automatic, secure composition with arbitrary, higher-level symmetric key protocols. Since there is evidence that most PAKEs secure in the Find-then-Guess (FtG) model of Bellare et al. (EUROCRYPT 2000) are in fact secure according to the RoR definition, we can conclude that nearly all provably secure PAKEs enjoy a certain degree of composition, one that at least covers the case of implementing secure channels. Although many different protocols that accomplish PAKE have been proposed over last two decades, only a few newcomers managed to find their way to real world applications - albeit lacking an intense and prolonged public scrutiny. As a step in the direction of providing one, this dissertation considers the security and efficiency of two relatively recently proposed PAKE protocols - Dragonfly and J-PAKE. In particular, we prove the security of a very close variant of Dragonfly employing the standard FtG model which incorporates forward secrecy. Thus, our work confirms that Dragonfly's main flows are sound. Furthermore, we contribute to the discussion by proposing and examining (in the RoR model of security) two variants of J-PAKE - which we call RO-J-PAKE and CRS-J-PAKE - that each makes the use of two less zero-knowledge proofs than the original protocol, at the cost of an additional security assumption. Our work reveals that CRS-J-PAKE has an edge in terms of efficiency over J-PAKE for both standard group choices: subgroups of finite fields and elliptic curves. The same is true for RO-J-PAKE, but only when instantiated with elliptic curves.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Digital Rights Management and Security
Original source
Jan 9, 2017·Hardy-Ramanujan Journal
0 cites
A note on Hardy's theorem

Usha K. Sangale

Hardy's theorem for the Riemann zeta-function ζ(s) says that it admits infinitely many complex zeros on the line (s) = 1 2. In this note, we give a simple proof of this statement which, to the best of our knowledge, is new.

Open access
Analytic Number Theory Research
Limits and Structures in Graph Theory
Meromorphic and Entire Functions
Original source
Jan 4, 2017·American Journal of Hematology
1 cites
Sepsis and persisting neutropenia in a drug addict

Roman M. Shapiro, Michelle P. Zeller, Theodore E. Warkentin

A 38-year-old woman was brought in to the emergency room (ER) because of altered level of consciousness. She had a known history of seizure disorder but was not on any prescription medications. She also had a history of intravenous (IV) drug abuse, including cocaine, methamphetamine, and heroin. She recently described herself as being “pill-sick” which according to her partner meant that she felt unwell after a recent administration of an illicit drug. In the ER, she was hypoxemic and was intubated. She was febrile, her blood pressure was 90 systolic, heart rate 120/min, and oxygen saturation undetectable by the digital probe. Admission hemoglobin was 11.6 g/dL (mean corpuscular volume [MCV] 86), white blood count 0.8 × 109/L (absolute neutrophil count [ANC], 0.2), and platelet count 97 × 109/L. Rare nucleated red blood cells were seen, but no myeloblasts or other primitive cells. Coagulation studies showed INR 3.1, activated partial thromboplastin time (aPTT) 81 s, and fibrinogen 1.9 g/L. The serum creatinine was 320 µmol/L (reference range, 50–98); serum lactate measured 13.0 mmol/L (reference range, 0.5–2.2). A chest X-ray showed multiple pulmonary infiltrates and right-sided pleural effusion. A CT head scan was negative for any acute abnormality. CT chest was suspicious for a right-sided empyema, but no vegetations were seen on the heart valves. The most striking finding on her admission blood work was leukopenia with near-absence of neutrophils in the peripheral blood. The clinical picture of hypotension, tachycardia, lactic acidosis, renal failure, pulmonary infiltrates, and pleural effusion in the setting of IV drug abuse, together with thrombocytopenia, coagulopathy, and normoblastemia, suggests septicemia in the setting of pneumonia or right-sided infective endocarditis, most likely complicated by disseminated intravascular coagulation (DIC)–although fibrin D-dimer levels would be helpful in supporting the last diagnosis. Severe sepsis can result in a transient leukopenia/neutropenia,1 although complete absence of circulating neutrophils is unusual and points to a possible de novo neutropenic disorder such as drug-induced agranulocytosis2, 3 (although the patient was not receiving any prescription medications). Current guidelines do not recommend starting this patient on G-CSF on admission due to lack of proven mortality benefit.4, 5 Circulating nucleated red blood cells (normoblastemia) portend a poor prognosis in a critically ill patient.6 She had a central venous catheter inserted into her right internal jugular vein and was transferred to the intensive care unit (ICU) on vasopressin and norepinephrine. Blood and urine cultures were sent and the patient was started on piperacillin-tazobactam and vancomycin. Repeat blood work showed progressive thrombocytopenia, with the platelet count measuring 9 × 109/L 20 h later, and with the leukocytes and ANC remaining profoundly reduced at 0.1 and 0, respectively. Repeat coagulation studies showed INR 3.9, aPTT >150, fibrinogen 2.0, and D-dimer > 20,000 μg/L fibrin equivalent units (reference range, <500), antithrombin activity 0.26 U/mL (reference range, 0.77–1.25), and protein C activity 0.14 U/mL (reference range, 0.70–1.80). Chemistry studies showed lactate dehydrogenase (LDH) 769 U/mL (reference range, 100–220), creatine kinase (CK) 3,800 U/mL (reference range, <168), total bilirubin 182 μmol/L (reference range, <21), conjugated bilirubin 117 μmol/L (reference range, <8.6), alanine aminotransferase (ALT) 67 U/L (reference range, <28), alkaline phosphatase 68 U/mL (reference range, 40–120), and creatinine (following initiation of continuous renal replacement therapy [CRRT]) had declined to 130 μmol/L. She was noted to have cold and dusky extremities and several necrotic ulcers were noted over the dorsum of her left hand. All peripheral pulses were intact, without peripheral cyanosis or other evidence of overt limb ischemia. She was started on IV heparin with dose adjusted by anti-factor Xa levels and given antithrombin concentrates (988 units, administered at 12-h intervals) as well as frozen plasma by infusion. HIV testing was ordered, along with hepatitis B and C serology. The fibrin D-dimer was measured to evaluate the presence of DIC. Although D-dimer levels are elevated in many or most hospital patients, greatly elevated levels as seen in this patient (>20,000) are consistent with a diagnosis of DIC.7 The elevated LDH, CK, bilirubin, and creatinine values likely reflect tissue (muscle) injury and organ (liver, renal) dysfunction.8, 9 The antithrombin and protein C activity levels were measured because of the potential role for acquired severe depletion of protein C and antithrombin activity in predisposing to ischemic limb necrosis/gangrene with pulses in critically ill patients who have DIC and acute ischemic hepatitis (“shock liver”).10 Though this patient had only mildly increased liver enzymes, the possibility of chronic liver disease due to viral hepatitis (frequently observed in IV drug abusers) or another etiology could represent an alternative at-risk scenario for limb ischemia.11 Although treatment for DIC-associated limb ischemia is uncertain, we followed a recent suggestion12 to treat with unfractionated heparin, antithrombin concentrates, and plasma infusion. In this patient, the presence of necrotic ulcers on the dorsum of her left hand along with cool, dusky extremities, and elevated LDH and CK levels (indicating possible tissue ischemia13), prompted her medical team to initiate preemptive heparin therapy to minimize the risk of developing acral limb ischemia/gangrene in the setting of liver dysfunction. Of note, with this therapy, the appearance of the limbs improved, becoming warm and of normal color, and there was no development of overt limb ischemia at any later time. On the fourth hospital day, the patient's blood work yielded a hemoglobin 6.7 g/dL, MCV 85.6, WBC 0.2 × 109/L (with ANC 0), platelet count 8 × 109/L, INR 1.2, aPTT 64, anti-factor Xa level 0.18 U/mL (therapeutic range, 0.35–0.70), fibrinogen 3.3, D-dimer 11,500, total bilirubin 270 μmol/L. Blood cultures and pleural fluid cultures were positive for methicillin-sensitive Staphylococcus aureus (MSSA), while hepatitis B and C serology came back negative. Antinuclear antibody (ANA) was sent as part of an autoimmune screen. Bone marrow aspirate and biopsy were attempted in order to better characterize the cause of her persistent profound neutropenia but the patient was too hemodynamically unstable to have the procedure done. She was started on G-CSF (300 μg/day). At this point, the differential diagnosis for neutropenia included septic shock, chronic liver disease, HIV, autoimmune disease, or drug-induced neutropenia/agranulocytosis. As she was receiving appropriate antibiotics since admission, it seemed less likely that infection was the cause of ongoing neutropenia. Severe sepsis is associated with bone marrow dysfunction, but more often as a result (not a cause) of underlying bone marrow suppression.1, 14, 15 Certain infections are known to cause neutropenia, including tuberculosis, HIV, cytomegalovirus, Epstein-Barr virus, and any of the hepatitis viruses.16-19 Although this patient had risk factors for HIV and viral hepatitis, serological studies ruled out these infections. A common association of infection with profound neutropenia occurs following systemic antineoplastic chemotherapy (“febrile neutropenia”). For patients who develop severe sepsis with persisting neutropenia, the pathophysiology is believed sometimes to be hematopoietic stem cell “exhaustion.”14 However, this tends to occur in infants and the elderly where the bone marrow reserve of granulocytic precursors is smaller than in adults.14, 15 The finding of an ANC of zero on presentation to hospital also argues against sepsis-induced bone marrow exhaustion. As persisting absence of circulating neutrophils strongly indicated the possibility of drug-induced agranulocytosis, a thorough re-review of any medications the patient might have received prior to and following admission was undertaken. Although both vancomycin and piperacillin-tazobactam may cause neutropenia,3 these antibiotics were only started after the patient already had an ANC of zero; and because only 4 days had elapsed following admission, the timeline was too soon for superimposed antibiotic-induced neutrophil-reactive antibodies to be plausible. Accordingly, further consideration for a medication or other drug taken prior to admission was given. Of the illicit IV drugs she used, cocaine has been associated with agranulocytosis due to the presence of levamisole as an adulterant.20, 21 On the sixth day of admission, her bloodwork yielded a hemoglobin 8.1 g/dL, WBC 0.6 × 109/L with ANC 0, platelet count 19 × 109/L, INR 1.2, aPTT 46. Her HIV test as well as ANA came back negative. Repeat blood cultures from the fourth day of hospital admission also came back negative. She continued to be hemodynamically unstable requiring increasing vasopressor and inotropic support. Blood culture obtained on the sixth day of hospitalization from the dialysis catheter site yielded budding yeast cells and pseudohyphae (after 28-h incubation), and the infectious disease consultant diagnosed superimposed Candida albicans infection in this patient with persisting profound neutropenia. Despite adding anidulafungin, she died on the eighth day due to multiorgan failure as a result of septic shock. Her ANC remained at 0 throughout her hospitalization. Figure 1 summarizes the patient's clinical course, including serial platelet count and ANC values (panel A), fibrinogen and INR values (panel B), aPTT and anti-factor Xa levels (panel C), with evidence for initially disturbed “procoagulant-anticoagulant” balance,10, 12 with greatly elevated fibrin D-dimer levels and markedly reduced antithrombin and protein C activity levels (panel D), which improved during treatment with heparin, antithrombin concentrates, and frozen plasma infusion. Summary of the patient's clinical course. (A) Serial platelet count and absolute neutrophil count (ANC) levels; timing and dose of intravenous heparin infusion rate is also shown. (B) Serial INR (international normalized ratio) and fibrinogen levels. (C) Serial partial thromboplastin time (aPTT) and anti-factor Xa levels. (D) Serial D-dimer, antithrombin (AT) and protein C (PC) activity levels; timing and dosing of AT concentrates and of plasma infusion are also shown. The patient died 7 days following admission Persistence of agranulocytosis unresponsive to G-CSF suggested an ongoing profound bone marrow suppression effect. Levamisole-induced agranulocytosis appeared likely given this patient's known habitual use of cocaine: it is estimated that 70%–80% of all cocaine in North America contains levamisole as an adulterant.21 Studies on levamisole identified long-term exposure to the drug as a significant risk factor for development of agranulocytosis.21, 22 Drug clearance is normally rapid with normally functioning kidneys, but this patient was anuric. Furthermore, levamisole is not cleared by dialysis, suggesting that plasma levels would not be lowered by CRRT.23 As this patient was injecting cocaine in the dorsum of her hand and had several necrotic lesions located at prior injection sites, the possibility of a persistent depot of levamisole was also considered to explain sustained agranulocytosis due to prolonged exposure to the drug or a relevant metabolite. Neutropenia is a common phenomenon frequently encountered in patients on antineoplastic chemotherapy, as an infection-related event, in certain autoimmune conditions, and in nutritional deficiency.2, 3 In contrast, agranulocytosis is a rare immune-mediated phenomenon triggered by certain medications3 or IV drugs.20, 21 Several medications have a known association with agranulocytosis, with the more common mechanism presumed to be antibodies to a neoepitope formed by a combination of the medication (or metabolite) and a receptor on the neutrophil membrane.24, 25 However, definitive proof is often lacking because detection of such antibodies is challenging and rarely performed. On some occasions, drug-dependent anti-neutrophil antibodies have been detected in the serum of patients with agranulocytosis.25, 26 A recent review of drug-induced agranulocytosis identified medications with the greatest likelihood of inducing agranulocytosis (Table 1), including clozapine, propylthiouracil, carbamazepine, trimethoprim-sulfamethoxazole, beta-lactams, and levamisole, among others.3 Among these, clozapine has the highest frequency of triggering agranulocytosis, estimated at 1 in 125 patients.24, 25 Beta-lactams Vancomycin Dapsone Trimethoprim-sulfamethoxazole 25 days24 82 days27 39 days24 UNKa 0.42/106 per year28 UNK UNK 5.6/106 per year29 Immune-mediated25 Immune-mediated25 Reactive metabolite induces apoptosis25 Immune-mediated29 Diclofenac Sulfasalazine UNK 42 days24 0.14/106 per year28 1:1600 in IBD29 1:6100 in RA29 Inhibit myelopoiesis25 Direct toxicity, immune-mediated30 Methimazole Propylthiouracil 42 days24 36 days24 0.25/106 per year28 0.2-0.5% 31 Immune-mediated32 Reactive metabolite induces apoptosis25, 33, immune-mediated29 Clozapine Chlorpromazine 56 days24 45 days24 0.8% 29 UNK Reactive metabolite induces apoptosis25, 33, inhibit myelopoiesis25 Inhibit myelopoiesis29 Phenytoin Carbamazepine 14 days33 49 days24 UNK 0.09/106 per year28 Reactive metabolite induces apoptosis25 Inhibit myelopoiesis29 Procainamide Captopril Ticlopidine 47 days24 32 days24 39 days24 UNK UNK 0.39/106 per year28 Reactive metabolite induces apoptosis25 Immune-mediated25 Reactive metabolite Induces apoptosis25 Levamisole Deferiprone Rituximabb 60 days24 UNK 4 cycles24 UNK 0.2-0.4/100 patient years29 UNK Immune-mediated25 UNK Immune-mediated25 Among IV drug users, levamisole is becoming a more recognized etiological agent due to its near-ubiquitous presence in cocaine distributed in North America.21, 22 Its association with agranulocytosis was first recognized in patients who received levamisole for treatment of rheumatoid arthritis during in the 1990s.22 Due to its relatively high risk for causing agranulocytosis, levamisole was withdrawn from the market in 2000, but it continues to find use in the veterinary world as an antihelminthic.21, 34 Its physical resemblance to cocaine and the relative ease of acquisition at a low price explain its common use as an adulterant in the manufacture of cocaine.23 Pharmacokinetic studies of levamisole injected into the muscle and fat of animals yielded a short plasma half-life and rapid elimination via the urinary tract within 24 hours.35, 36 However, repeated exposure to low doses of the drug over a period of months can induce the formation of antibodies implicated in agranulocytosis.26 The clinical presentation of patients who develop agranulocytosis during exposure to levamisole-adulterated cocaine is variable, with many patients either asymptomatic or developing a nonspecific flu-like illness. Around 50% of patients may initially present to the ER with mouth ulcers or odynophagia.21 A vasculitic rash has been associated with levamisole exposure that develops in the setting of an occlusive thrombotic vasculopathy. The latter most frequently involves the cheeks and ears and tends to be ANCA-positive.37 However, as there are cases of levamisole-induced agranulocytosis not associated with positive ANA or ANCA, the absence of these autoimmune markers does not rule out levamisole as the culprit drug38 (note: we did not measure ANCA in our patient case). In addition, case reports of patients who develop an autoimmune marker such as ANA, c-ANCA, p-ANCA, or antiphospholipid antibody in the setting of known levamisole exposure describe the disappearance of this marker within 14 months of discontinuation of drug exposure.21 It is not yet clear why a relatively high proportion (approximately 2%–4%) of patients who habitually use cocaine and who are likely chronically exposed to levamisole develop agranulocytosis.21 In previous studies of rheumatoid arthritis patients, risk factors for levamisole-induced agranulocytosis included female sex, HLA-B27, and frequency of drug exposure.21, 39 The expected time for recovery of drug-induced agranulocytosis after stopping the offending drug, without the addition of growth factor support, is a median of 9 days;40 the addition of G-CSF reduces the time for neutrophil recovery to approximately 4-7 days.40 When severe agranulocytosis persists beyond this period, unusual circumstances have been reported. For example, some patients with persisting agranulocytosis unresponsive to G-CSF have parvovirus B19 infection, and recover after administration of IVIgG (implicating removal of circulating virus by IgG anti-parvovirus antibody, reversing virus-induced inhibition of granulopoiesis).41 The typical course of levamisole-associated agranulocytosis usually involves improvement in the neutrophil count beginning several days after discontinuation of the drug, with recombinant G-CSF hastening recovery.21 Given that levamisole is normally metabolized in the liver and secreted via the renal system, the presence of significant liver and/or kidney dysfunction is likely to significantly prolong its half-life.21, 23 Furthermore, hemodialysis does not clear the drug.23 When injected intramuscularly or into adipose tissue a depot of the drug may develop that results in continuous long-term exposure. Given our had an ANC of zero that persisted for 8 days following admission (until death) without any other clear precipitant or cause identified and despite starting G-CSF, we hypothesize that the combination of an intramuscular or subcutaneous depot of levamisole, together with absent renal clearance and hepatic dysfunction, resulted in ongoing exposure to levamisole (or a metabolite) that potentiated pathological effects of levamisole-dependent anti-neutrophil antibodies. The recommended management of levamisole-induced agranulocytosis is drug withdrawal and supportive care.21 Reported experience, mainly based on cocaine users who were not critically ill, typically show rapid recovery within a few days of drug discontinuation. There is a paucity of data in patients who are critically ill with multiorgan dysfunction; indeed, to our knowledge, presentation as septic shock (due to MSSA septicemia) in the setting of agranulocytosis presumed to be caused by levamisole-adulterated cocaine has not been previously reported. The authors have no conflicts of interest to report.

Open access
Blood disorders and treatments
Hematological disorders and diagnostics
Sepsis Diagnosis and Treatment
Original source
Jan 1, 2017·Journal of Environmental Engineering (Transactions of AIJ)
0 cites
STUDY ON EVALUATION METHOD OF SOLAR SHADING FOR BLIND CONTROL BASED ON LUMINANCE IMAGES

Yoshikane Kojima, Yoshiki Nakamura, Yōkō Kato, Chikako Ohki · 6 authors

Japan establishes the goals to realize ZEBs (net zero energy building) in average newly constructed public and private buildings by 2030. The primary energy consumption of the illumination in the office building accounts for around 20% of the whole building. Therefore, thorough saving energy is demanded for illumination to achieve ZEB. The effective method for the saving energy of illumination is the use of day light. The natural light of the workplace in office building is generally adopted through a side window. Venetian blinds are installed in the window for solar shading. In the automatic blind control system installed at the large scale building, slats of blind are uniformly controlled by illuminance censor fixed on the top of the building. This is not able to detect direct sunlight and the light from adjacency building at the side window. We devised technique to detect not only the direct sunlight but also the dazzling borrowed light from adjacency building based on a luminance image provided with a CCD camera for the purpose of the development of the higher precise judgment of solar shading. We built the system which could perform shading immediately at the time of the detection and introduced it into the actual work office. As a result of proof experiment, the following knowledge was provided in conclusion. 1) A method to measure high range of luminance including direct sun light and the borrowed light by a fisheye lens and the CCD camera which attached two kinds of filters which varied in the spectral transmittance was showed. 2) Using luminance contrast (C value) and the logarithm luminance mean (A value) to be provided by N filter and the averaging filter developed by Nakamura, detect direct rays of the sun and borrowed light can be identified in luminance image. 3) The threshold of C value: 0.4 and A value: 4.5 that can detect direct rays of the sun and borrowed light using the luminance image measured at single shutter speed of 1/200 second by the CCD camera are identified for speedup of the control. 4) The evaluation method proposed in this study applied to blind control system in actual workplace could detect direct sun light and borrowed light of neighboring buildings with high precision and was able to confirm the usefulness and effectiveness. 5) The possibility that could contribute to increase of the day lighting and view-related improvement by controlling every window is showed 6) The result of this study showed the possibility that could help it toward the spread of blind control systems with higher precision.

Open access
Color Science and Applications
Original source
Jan 1, 2017·eCommons (Cornell University)
0 cites
Exploration of Methods for Serial Microcrystallography at Storage Ring X-ray Sources

Jennifer L. Wierman

Protein crystallography has made the largest contribution to our knowledge of protein structure. However, it is well known that many biologically important proteins do not readily form large enough crystals for traditional crystallography. Successful serial microcrystallography (SMX) studies have been performed at X-ray Free-Electron Lasers, but they are limited in experimental availability. We look to more accessible light sources, such as storage ring sources, for the development of SMX. However, improvements to the conventional experiment are required to make SMX viable at storage rings. Here, we explore several devices and techniques designed given this consideration. To isolate crystal diffraction, the sample environment should contribute zero background scatter outside the crystal, since excess scatter obscures the weak microcrystal signal. We will show the feasibility of using atomically-thin, gas-tight graphene to reduce background scatter as a crystal mount and suggest using it as a window material for SMX. We will also explore two microcrystal delivery devices, a microfluidic chip and a viscous jet injector, for use in SMX. While both of these devices show promise for optimizing various aspects of the crystal delivery system, both contribute more background scatter than is acceptable for an ideal SMX experiment at a storage ring source. Merging diffraction from multiple microcrystals is necessary when a complete data set cannot be determined from a single microcrystal. When microcrystal diffraction is weak enough that Bragg peaks are no longer visible, merging through conventional techniques fails since crystal orientation cannot be obtained through Bragg peak indexing. We will explore proof-of-principle experiments which show that indexing data frames on a per-frame basis is unnecessary for a structure solution, when reciprocal space intensities can be reconstructed using the EMC algorithm. In principle, serial microcrystallography is feasible at storage ring sources if improvements in beamline setups, sample chamber construction and microcrystal diffraction analysis evolve to optimize the diffraction of microcrystals.

Open access
Enzyme Structure and Function
X-ray Spectroscopy and Fluorescence Analysis
Advanced X-ray Imaging Techniques
Original source
Jan 1, 2017·ANU Open Research (Australian National University)
0 cites
The Riemann Roch Theorem (for algebraic curves)

Weiqiong Zheng

The Riemann-Roch theorem is a useful tool to calculate the dimension of the space of meromorphic functions with prescribed zeros and poles. There are severals versions of the theorem such as the Riemann-Roch theorem for line bundles, for (algebraic) curves, for surfaces and for higher dimensions. In this thesis, we will focus on the Riemann-Roch theorem for algebraic curves over an algebraically closed eld, which is a very important result in complex analysis and algebraic geometry. The study of the elds of rational functions on curves can be very useful in the proof. So we will recall some pre-knowledges in commutative algebra and some facts about a ne varieties. Then talk about function elds, discrete valuation rings and Weil di erentials to prove the theorem, using the methods of Andre Weil.

Open access
Algebraic Geometry and Number Theory
Meromorphic and Entire Functions
History and Theory of Mathematics
Original source
Jan 1, 2017·Scholarship - Claremont (Claremont Colleges)
0 cites
The Frontiers of Technology in Warhead Verification

Henrietta N Toivanen

How might new technical verification capabilities enhance the prospects of success in future nuclear arms control negotiations? Both theory and evidence suggest that verification technologies can influence the dynamics of arms control negotiations by shaping and constraining the arguments and strategies that are available to the involved stakeholders. In the future, new technologies may help transcend the specific verification challenge of high-security warhead authentication, which is a verification capability needed in future disarmament scenarios that address fewer warheads, limit new categories of warheads, and involve nuclear weapons states other than the United States and Russia. Under these circumstances, the core challenge is maintaining the confidentiality of the classified information related to the warheads under inspection, while providing transparency in the verification process. This analysis focuses on a set of emerging warhead authentication approaches that rely on the cryptographic concept of zero-knowledge proofs and intend to solve the paradox between secrecy and transparency, making deeper reductions in warhead arsenals possible and thus facilitating future nuclear arms control negotiations.

Open access
Anthropology: Ethics, History, Culture
Original source
Jan 1, 2017·Research Repository (Delft University of Technology)
1 cites
Enhancing Privacy in Smart Home Ecosystems Using Cryptographic Primitives and a Decentralized Cloud Entity

Rogier Vrooman

Within the phenomenon known as the Internet of Things (IoT), an enormous growth is taking place. IoT systems exist in different ways, ranging from industrial applications to user focused systems. A specific subset of a user-focused IoT system is found as Smart Home environments. At Smart Homes, themultiple Smart Objects or Smart Devices are working together, frequently based on sensor input, to increase the comfort and user experience of the home inhabitant(s) and guest(s). Smart Objects can have automated tasks, home security enabling functions or efficiency improving functionality. Apart from great applications of Smart Home devices, threats from a cyber security perspective are present: cyber risks arise due to a variety of threats on such IoT systems. We show that in the development of new Smart Home products or systems, vendors fail to meet requirements for security and privacy are not met. Comparing the current state of the market, the four most used Smart Home ecosystems (Samsung Smartthings, Apple Homekit, Amazon Echo and IFTTT) are surveyed based on three key focus areas: 1. The regulatory compliance of the systems according to the upcoming General Data Protection Regulation (GDPR). 2. The commercial threats due to data profiling. 3. The risk of data leaks due to insufficient security. This analysis results in four key observations: 1. Security- and Privacy-By-Design is usually not in place due to the fact that the focus lies on launching a product as soon as possible, e.g. due to market competition; 2. Vendors process (meta)data on the vendors locations resulting in data profiling, which can compromise user privacy; 3. Smart Home ecosystems are not ready for the GDPR; 4. A trade off between privacy, security and utility usually results to the detriment of the first two and favors the latter. We propose a new design for a Smart Home ecosystem. In this design, the focus lies at the privacy of the end-user. We design a network for device-fitting encrypted communication between Smart Devices and User Devices and the Privacy Enforcing Arbiter (or Peter). Peter functions like a hub in the network, managing among others all traffic, user privileges and key distribution. With Peter, the centralized cloud party (vendor) for data storage and data analysis is replaced with a decentralized personal storage and computation entity at home. With our network design, we facilitate the use of IoT devices in home in a privacy-friendly way. Within the network, devices are authenticated using PhysicallyUnclonable Function technology and users are authenticated with a Zero Knowledge Proof. We analyze the privacy and security of our proposed network, based on a series of possible cyber attacks and the upcoming GDPR. Furthermore, we analyze the computational complexity and scalability of the network, based on market conform device power.

Open access
Privacy, Security, and Data Protection
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source