This paper analyses 26 time series that measure daily data for different attributes of the Bitcoin network and studies how the virtual currency behaves compared to a basket of currencies containing the Brazil Real (BRL), the Chinese Yuan (CNY), the Euro (EUR), and the Japan Yen (JPY) against the US Dollar (USD). \nBasic statistics about the time series have been taken and stationarity has been studied in order to build sterilized fact data and meaningful cointegrations have been found among them. By applying a Vector Autoregressive (VAR) model, a regression has been built among the currencies and the Granger causality test has been applied in order to determine whether one time series (of a given currency) is useful in forecasting another and to observe causal relationships among the currencies studied.
The Fiat-Shamir paradigm was proposed as a way to remove interaction from 3-round proof of knowledge protocols and derive secure signature schemes. This generic transformation leads to very efficient schemes and has thus grown quite popular. However, this transformation is proven secure only in the random oracle model. In FOCS 2003, Goldwasser and Kalai showed that this transformation is provably insecure in the standard model by presenting a counterexample of a 3-round protocol, the Fiat-Shamir transformation of which is (although provably secure in the random oracle model) insecure in the standard model, thus showing that the random oracle is uninstantiable. In particular, for every hash function that is used to replace the random oracle, the resulting signature scheme is existentially forgeable. This result was shown by relying on the non-black-box techniques of Barak (FOCS 2001). An alternative to the Fiat-Shamir paradigm was proposed by Fischlin in Crypto 2005. Fischlin’s transformation can be applied to any so called 3-round “Fiat-Shamir proof of knowledge’ ’ and can be used to derive non-interactive zero-knowledge proofs of knowledge as well as signature schemes. An attractive property of this transformation is that it provides online extractability (i.e., the extractor works without having to rewind the prover). Fischlin remarks that in comparison to the Fiat-Shamir transformation, his construction tries to
In 2009, a curious new virtual currency called Bitcoin made its first appearance on the Internet. While it remains a “niche” currency relative to other major denominations like the U.S. dollar, Bitcoin has experienced significant growth since its inception. The total number of Bitcoins in circulation is about 12.5 million, with a recent market price of about $500 each. Today, Bitcoin’s total market capitalization is about $6 billion, and in the past it has been as high as $13 billion. The average number of Bitcoin transactions per day has averaged over 60,000 since January 2014, reflecting between $20 million and $100 million worth of transactions per day. The numbers show that in the five years since its first appearance, Bitcoin has grown tremendously in popular knowledge and usage. Although it is clear that Bitcoin can be used to purchase goods and services, and can be given an explicit dollar value, questions remain about the economic and legal status of Bitcoin and other virtual currencies that have emerged in its wake. Members of the Bitcoin developer and user community believe “Bitcoin is an innovative payment network and new kind of money.” Others, like the U.S. Internal Revenue Service, take the position that Bitcoin is a type of commodity or property. Whether Bitcoin is a new form of virtual money or simply an electronic commodity requires an investigation into what constitutes money, and an assessment of whether Bitcoin comfortably fits into the parameters of what we consider to be money. This paper finds that, at this stage in its development, Bitcoin is not money and more closely resembles a commodity or property. This paper begins by giving a brief overview of Bitcoin and how it operates. It then describes two major theories of money — the conventional and constitutional theories — that differ in their accounts of how money emerges within a society or political grouping. The paper assesses how well Bitcoin fits under each theory by assessing Bitcoin’s economic properties and implementation. It then turns to the impact of the Bitcoin on the two theories of money, finding it likely does not support the conventional creation story of money and instead lends credence to the constitutional theory.
In 1601, Elizabeth I and her government devalued the Irish coin from nine ounces fine to three ounces fine of silver in order to finance the high cost of the Nine Years War in Ireland. 1 This unilateral move by the English government, combined with the failure to remove the old sterling from circulation, caused catastrophic problems throughout Ireland. 2 In addition to rapid inflation in common foodstuffs, the people in Ireland would only accept the new coin at its reduced intrinsic value rather than face value. 3 Further, merchants refused to accept the devalued coin in commercial transactions leading to a shortage of vital goods from England. 4
Simon Barber, Xavier Boyen, Elaine Shi, Ersin Uzun
Abstract. Bitcoin is a distributed digital currency which has attracted a substan-tial number of users. We perform an in-depth investigation to understand what made Bitcoin so successful, while decades of research on cryptographic e-cash has not lead to a large-scale deployment. We ask also how Bitcoin could become a good candidate for a long-lived stable currency. In doing so, we identify several issues and attacks of Bitcoin, and propose suitable techniques to address them. 1
Bitcoin is a digital, decentralized, partially anonymous currency, not backed by any government or other legal entity, and not redeemable for gold or other commodity. It relies on peer-to-peer networking and cryptography to maintain its integrity. Compared to most currencies or online payment services, such as PayPal, bitcoins are highly liquid, have low transaction costs, and can be used to make micropayments. This new currency could also hold the key to allowing organizations such as Wikileaks, hated by governments, to receive donations and conduct business anonymously. Although the Bitcoin economy is flourishing, Bitcoin users are anxious about Bitcoin's legal status. This Article examines a few relevant legal issues, such as the recent conviction of the Liberty Dollar creator, the Stamp Payments Act, and the Federal Securities Acts.
Moshe Babaioff, Shahar Dobzinski, Sigal Oren, Aviv Zohar
Many large decentralized systems rely on information propagation to ensure their proper function. We examine a common scenario in which only participants that are aware of the information can compete for some reward, and thus informed participants have an incentive not to propagate information to others. One recent example in which such tension arises is the 2009 DARPA Network Challenge (finding red balloons). We focus on another prominent example: Bitcoin, a decentralized electronic currency system. Bitcoin represents a radical new approach to monetary systems. It has been getting a large amount of public attention over the last year, both in policy discussions and in the popular press. Its cryptographic fundamentals have largely held up even as its usage has become increasingly widespread. We find, however, that it exhibits a fundamental problem of a different nature, based on how its incentives are structured. We propose a modification to the protocol that can eliminate this problem. Bitcoin relies on a peer-to-peer network to track transactions that are performed with the currency. For this purpose, every transaction a node learns about should be transmitted to its neighbors in the network. The current implemented protocol provides an incentive to nodes to not broadcast transactions they are aware of. Our solution is to augment the protocol with a scheme that rewards information propagation. Since clones are easy to create in the Bitcoin system, an important feature of our scheme is Sybil-proofness. We show that our proposed scheme succeeds in setting the correct incentives, that it is Sybil-proof, and that it requires only a small payment overhead, all this is achieved with iterated elimination of dominated strategies. We complement this result by showing that there are no reward schemes in which information propagation and no self-cloning is a dominant strategy.
Anonymity in Bitcoin, a peer-to-peer electronic currency system, is a complicated issue. Within the system, users are identified by public-keys only. An attacker wishing to de-anonymize its users will attempt to construct the one-to-many mapping between users and public-keys and associate information external to the system with the users. Bitcoin tries to prevent this attack by storing the mapping of a user to his or her public-keys on that user's node only and by allowing each user to generate as many public-keys as required. In this chapter we consider the topological structure of two networks derived from Bitcoin's public transaction history. We show that the two networks have a non-trivial topological structure, provide complementary views of the Bitcoin system and have implications for anonymity. We combine these structures with external information and techniques such as context discovery and flow analysis to investigate an alleged theft of Bitcoins, which, at the time of the theft, had a market value of approximately half a million U.S. dollars.
Traditional electricity meters are replaced by Smart Meters in customers' households. Smart Meters collects fine-grained utility consumption profiles from customers, which in turn enables the introduction of dynamic, time-of-use tariffs. However, the fine-grained usage data that is compiled in this process also allows to infer the inhabitant's personal schedules and habits. We propose a privacy-preserving protocol that enables billing with time-of-use tariffs without disclosing the actual consumption profile to the supplier. Our approach relies on a zero-knowledge proof based on Pedersen Commitments performed by a plug-in privacy component that is put into the communication link between Smart Meter and supplier's back-end system. We require no changes to the Smart Meter hardware and only small changes to the software of Smart Meter and back-end system. In this paper we describe the functional and privacy requirements, the specification and security proof of our solution and give a performance evaluation of a prototypical implementation.
In this paper, we prove classical coin-flipping secure in the presence of quantum adversaries. The proof uses a recent result of Watrous [Wat09] that allows quantum rewinding for protocols of a certain form. We then discuss two applications. First, the combination of coin-flipping with any non-interactive zero-knowledge protocol leads to an easy transformation from non-interactive zero-knowledge to interactive quantum zero-knowledge. Second, we discuss how our protocol can be applied to a recently proposed method for improving the security of quantum protocols [DFL+09], resulting in an implementation without set-up assumptions. Finally, we sketch how to achieve efficient simulation for an extended construction in the common-reference-string model.
A Publicly Veriable Secret Sharing (PVSS) scheme, as introduced by Stadler, has a feature
where anyone, besides the participants, can verify the validity of the shares distributed by
the dealer. Schoenmakers added a new feature, by providing a proof of correctness of the
shares released by the players in the reconstruction process. This protocol is claimed to
be an improvement on Stadler's and Fujisaki-Okamoto's, both in eciency and in the type
of intractability assumptions. However, Young-Yung improved Schoenmakers' PVSS, using a
Discrete-Log instead of a Decision Die-Hellman. In this paper, a new PVSS is presented,
having an intrinsic dierence with its predecessors, that is, the participants can prove the validity
of their given shares, implicitly, proving their membership by a zero-knowledge protocol. This
feature prevents cheaters from participating in the reconstruction process to gain valid shares.
Hence, the new proposed PVSS is more secure than previous ones. Besides, the dealer only
sends the amount of commitments limited to the threshold value, regardless of the number of
shareholders; this leads to a more dynamic protocol.
In quantum zero knowledge, the assumption was made that the verifier is only using unitary operations. Under this assumption, many nice properties have been shown about quantum zero knowledge, including the fact that Honest-Verifier Quantum Statistical Zero Knowledge ($HVQSZK$) is equal to Cheating-Verifier Quantum Statistical Zero Knowledge ($QSZK$) (see ~\cite{Wat02,Wat06}). In this paper, we study what happens when we allow an honest verifier to flip some coins in addition to using unitary operations. Flipping a coin is a non-unitary operation but doesn\'t seem at first to enhance the cheating possibilities of the verifier since a classical honest verifier can flip coins. In this setting, we show an unexpected result: any classical Interactive Proof has an Honest-Verifier Quantum Statistical Zero Knowledge proof with coins. Note that in the classical case, honest verifier $SZK$ is no more powerful than $SZK$ and hence it is not believed to contain even $NP$. On the other hand, in the case of cheating verifiers, we show that Quantum Statistical Zero Knowledge where the verifier applies any non-unitary operation is equal to Quantum Zero-Knowledge where the verifier uses only unitaries. One can think of our results in two complementary ways. If we would like to use the honest verifier model as a means to study the general model by taking advantage of their equivalence, then it is imperative to use the unitary definition without coins, since with the general one this equivalence is most probably not true. On the other hand, if we would like to use quantum zero knowledge protocols in a cryptographic scenario where the honest-but-curious model is sufficient, then adding the unitary constraint severely decreases the power of quantum zero knowledge protocols.
We present two universally composable and practical protocols by which a dealer can, verifiably and non-interactively, secret-share an integer among a set of players. Moreover, at small extra cost and using a distributed verifier proof, it can be shown in zero-knowledge that three shared integers a, b, c satisfy ab = c. This implies by known reductions non-interactive zero-knowledge proofs that a shared integer is in a given interval, or that one secret integer is larger than another. Such primitives are useful, e.g., for supplying inputs to a multiparty computation protocol, such as an auction or an election. The protocols use various set-up assumptions, but do not require the random oracle model.
This paper proves that several interactive proof systems are zero-knowledge against general quantum attacks. This includes the well-known Goldreich–Micali–Wigderson classical zero-knowledge protocols for graph isomorphism and graph 3-coloring (assuming the existence of quantum computationally concealing commitment schemes in the second case). Also included is a quantum interactive proof system for a complete problem for the complexity class of problems having honest verifier quantum statistical zero-knowledge proofs, which therefore establishes that honest verifier and general quantum statistical zero-knowledge are equal: $\mathrm{QSZK}= \mathrm{QSZK}_{\mathrm{HV}}$. Previously no nontrivial interactive proof systems were known to be zero-knowledge against quantum attacks, except in restricted settings such as the honest verifier and common reference string models. This paper therefore establishes for the first time that true zero-knowledge is indeed possible in the presence of quantum information and computation.
Blockchain technology has been gaining great interest from a variety of sectors including healthcare, supply chain, and cryptocurrencies. However, Blockchain suffers from a limited ability to scale (i.e., low throughput and high latency). Several solutions have been proposed to tackle this. In particular, sharding has proved to be one of the most promising solutions to Blockchain's scalability issue. Sharding can be divided into two major categories: (1) Sharding-based Proof-of-Work (PoW) Blockchain protocols, and (2) Sharding-based Proof-of-Stake (PoS) Blockchain protocols. The two categories achieve good performances (i.e., good throughput with a reasonable latency), but raise security issues. This article focuses on the second category. In this paper, we start by introducing the key components of sharding-based PoS Blockchain protocols. We then briefly introduce two consensus mechanisms, namely PoS and practical Byzantine Fault Tolerance (pBFT), and discuss their use and limitations in the context of sharding-based Blockchain protocols. Next, we provide a probabilistic model to analyze the security of these protocols. More specifically, we compute the probability of committing a faulty block and measure the security by computing the number of years to fail. We achieve a number of years to fail of approximately 4000 in a network of 4000 nodes, 10 shards, and a shard resiliency of 33%.