Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results ยท page 155 of 177

Clear filters
Jul 1, 2015
38 cites
Du-Vote: Remote Electronic Voting with Untrusted Computers

Gurchetan S. Grewal, Mark Ryan, Liqun Chen, Michael R. Clarkson

Du-Vote is a new remote electronic voting protocol that eliminates the often-required assumption that voters trust general-purpose computers. Trust is distributed in Du-Vote between a simple hardware token issued to the voter, the voter's computer, and a server run by election authorities. Verifiability is guaranteed with high probability even if all these machines are controlled by the adversary, and privacy is guaranteed as long as at least either the voter's computer, or the server and the hardware token, are not controlled by the adversary. The design of the Du-Vote protocol is presented in this paper. A new non-interactive zero-knowledge proof is employed to verify the server's computations. Du-Vote is a step towards tackling the problem of internet voting on user machines that are likely to have malware. We anticipate that the methods of Du-Vote can be used in other applications to find ways of achieving malware tolerance, that is, ways of securely using platforms that are known or suspected to have malware.

Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
May 31, 2015ยทํ•œ๊ตญํ†ต์‹ ํ•™ํšŒ๋…ผ๋ฌธ์ง€
0 cites
Generalization of Zero-Knowledge Proof of Polynomial Equality

Myungsun Kim, Bolam Kang

๋ณธ ๋…ผ๋ฌธ์—์„œ๋Š” ๋ฏธ๋ฆฌ ์•Œ๋ ค์ง„ ์ž„์˜์˜ ๋‹คํ•ญ์‹๊ณผ ์•”ํ˜ธํ™”๋œ ๋‹คํ•ญ์‹์˜ ๊ณฑ์…ˆ์„ ์ˆ˜ํ–‰ํ•œ ํ›„, ํ•ด๋‹น ๊ณฑ์…ˆ์ด ์ •๋‹นํ•˜๊ฒŒ ์ˆ˜ํ–‰๋˜์—ˆ์Œ์„ ๋ณด์ด๊ธฐ ์œ„ํ•ด ์ฆ๋ช…์ž (Prover)์™€ ๊ฒ€์ฆ์ž (Verifier)๊ฐ„์˜ ๋‹คํ•ญ์‹ ์ƒ๋“ฑ์„ฑ ์˜์ง€์‹์ฆ๋ช… (Zero-knowledge Proof) ํ”„๋กœํ† ์ฝœ์„ ์ผ๋ฐ˜ํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ๋‹ค๋ฃฌ๋‹ค. ์ด๋ฅผ ์œ„ํ•˜์—ฌ ๋‹คํ•ญ์‹์˜ ์ƒ๋“ฑ์„ฑ์„ ์ฆ๋ช…ํ•˜๋Š” ์ผ๋ฐ˜ํ™”๋œ ํ”„๋กœํ† ์ฝœ์„ ์ œ์‹œํ•˜๊ณ  ๋žœ๋ค์˜ค๋ผํด (Random Oracle) ๋ชจ๋ธ์—์„œ ์•ˆ์ „์„ฑ์„ ์ฆ๋ช…ํ•œ๋‹ค. ์ด๋Ÿฌํ•œ ๊ธฐ๋ฒ•์€ ์•ˆ์ „ํ•œ ์ง‘ํ•ฉ์—ฐ์‚ฐ ๊ธฐ๋ฒ•์„ ํฌํ•จํ•˜์—ฌ ๋‹คํ•ญ์‹์— ๊ธฐ๋ฐ˜ํ•œ ๋‹ค์ž๊ฐ„ ์—ฐ์‚ฐ๊ธฐ๋ฒ• (Secure Multi-party Computation)์— ์ ์šฉ๋  ์ˆ˜ ์žˆ๋‹ค. In this paper, we are interested in a generalization of zero-knowledge interactive protocols between prover and verifier, especially to show that the product of an encrypted polynomial and a random polynomial, but published by a secure commitment scheme was correctly computed by the prover. To this end, we provide a generalized protocol for proving that the resulting polynomial is correctly computed by an encrypted polynomial and another committed polynomial. Further we show that the protocol is also secure in the random oracle model. We expect that our generalized protocol can play a role of building blocks in implementing secure multi-party computation including private set operations.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Security in Wireless Sensor Networks
Original source
May 29, 2015ยทHAL (Le Centre pour la Communication Scientifique Directe)
0 cites
Applications of Structure-Preserving Cryptography and Pairing-Based NIZK Proofs

Benoรฎt Libert

This habilitation thesis deals with cryptographic primitives that preserve the algebraic structure of underlying objects (messages, keys, etc) and their applications to the design of non-interactive zero-knowledge proofs and privacy-enhancing cryptographic primitives.In 2008, Groth and Sahai showed how to make these proof systems relatively efficient in abelian groups endowed with a bilinear map. These techniques, however, require to work with lower-level primitives where handled objects all live in a cyclic abelian group. Among other things, we need to sign messages without destroying their algebraic structure (in particular, without hashing them first) so as to be able to efficiently prove properties about hidden signed messages. The first part of this thesis describes a structure-preserving signature scheme which was the first efficient realization under previously studied algorithmic assumptions. These tools are also utilized in the design of a novel revocation mechanism for group signatures, which allow users to anonymously sign messages on behalf of a population they belong to. The second part of this thesis considers structure-preserving signatures endowed with homomorphic properties. We show how to use them in the design of non-malleable cryptographic primitives. Using linearly homomorphic structurepreserving signatures, we notably obtain non-malleable commitments to group elements and non-interactive zero-knowledge proofs, as well as public-key encryption schemes that resist chosen-ciphertext attacks.

Open access
Cryptography and Data Security
Geometric and Algebraic Topology
Complexity and Algorithms in Graphs
Original source
May 14, 2015ยทInverse Problems
32 cites
Multiwave imaging in an enclosure with variable wave speed

Sebastiรกn Acosta, Carlos Montalto

In this paper we consider the mathematical model of thermo- and photo-acoustic tomography for the recovery of the initial condition of a wave field from knowledge of its boundary values. Unlike the free-space setting, we consider the wave problem in a region enclosed by a surface where an impedance boundary condition is imposed. This condition models the presence of physical boundaries such as interfaces or acoustic mirrors which reflect some of the wave energy back into the enclosed domain. By recognizing that the inverse problem is equivalent to a statement of boundary observability, we use control operators to prove the unique and stable recovery of the initial wave profile from knowledge of boundary measurements. Since our proof is constructive, we explicitly derive a solvable equation for the unknown initial condition. This equation can be solved numerically using the conjugate gradient method. We also propose an alternative approach based on the stabilization of waves. This leads to an exponentially and uniformly convergent Neumann series reconstruction when the impedance coefficient is not identically zero. In both cases, if well-known geometrical conditions are satisfied, our approaches are naturally suited for variable wave speed and for measurements on a subset of the boundary.

Open access
Photoacoustic and Ultrasonic Imaging
Ultrasonics and Acoustic Wave Propagation
Numerical methods in inverse problems
Original source
May 1, 2015
71 cites
Security of the J-PAKE Password-Authenticated Key Exchange Protocol

Michel Abdallaโ‹†, Fabrice Benhamouda, Philip MacKenzie

J-PAKE is an efficient password-authenticated key exchange protocol that is included in the Open SSL library and is currently being used in practice. We present the first proof of security for this protocol in a well-known and accepted model for authenticated key-exchange, that incorporates online and offline password guessing, concurrent sessions, forward secrecy, server compromise, and loss of session keys. This proof relies on the Decision Square Diffie-Hellman assumption, as well as a strong security assumption for the non-interactive zero-knowledge (NIZK) proofs in the protocol (specifically, simulation-sound extractability). We show that the Schnorr proof-of-knowledge protocol, which was recommended for the J-PAKE protocol, satisfies this strong security assumption in a model with algebraic adversaries and random oracles, and extend the full J-PAKE proof of security to this model. Finally, we show that by modifying the recommended labels in the Schnorr protocol used in J-PAKE, we can achieve a security proof for J-PAKE with a tighter security reduction.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
May 1, 2015
44 cites
Virtual Proofs of Reality and their Physical Implementation

Ulrich Rรผhrmair, J. L. Martรญnez-Hurtado, Xiaolin Xu, Christian Kraeh ยท 8 authors

We discuss the question of how physical statements can be proven over digital communication channels between two parties (a "prover" and a "verifier") residing in two separate local systems. Examples include: (i) "a certain object in the prover's system has temperature XยฐC", (ii) "two certain objects in the prover's system are positioned at distance X", or (iii) "a certain object in the prover's system has been irreversibly altered or destroyed". As illustrated by these examples, our treatment goes beyond classical security sensors in considering more general physical statements. Another distinctive aspect is the underlying security model: We neither assume secret keys in the prover's system, nor do we suppose classical sensor hardware in his system which is tamper-resistant and trusted by the verifier. Without an established name, we call this new type of security protocol a "virtual proof of reality" or simply a "virtual proof" (VP). In order to illustrate our novel concept, we give example VPs based on temperature sensitive integrated circuits, disordered optical scattering media, and quantum systems. The corresponding protocols prove the temperature, relative position, or destruction/modification of certain physical objects in the prover's system to the verifier. These objects (so-called "witness objects") are prepared by the verifier and handed over to the prover prior to the VP. Furthermore, we verify the practical validity of our method for all our optical and circuit-based VPs in detailed proof-of-concept experiments. Our work touches upon, and partly extends, several established concepts in cryptography and security, including physical unclonable functions, quantum cryptography, interactive proof systems, and, most recently, physical zero-knowledge proofs. We also discuss potential advancements of our method, for example "public virtual proofs" that function without exchanging witness objects between the verifier and the prover.

Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Security and Verification in Computing
Biometric Identification and Security
Original source
May 1, 2015
132 cites
Secure Sampling of Public Parameters for Succinct Zero Knowledge Proofs

Eli Benโ€Sasson, Alessandro Chiesa, Matthew Green, Eran Tromer ยท 5 authors

Non-interactive zero-knowledge proofs (NIZKs) are a powerful cryptographic tool, with numerous potential applications. However, succinct NIZKs (e.g., zk-SNARK schemes) necessitate a trusted party to generate and publish some public parameters, to be used by all provers and verifiers. This party is trusted to correctly run a probabilistic algorithm (specified by the the proof system) that outputs the public parameters, and publish them, without leaking any other information (such as the internal randomness used by the algorithm), violating either requirement may allow malicious parties to produce convincing "proofs" of false statements. This trust requirement poses a serious impediment to deploying NIZKs in many applications, because a party that is trusted by all users of the envisioned system may simply not exist. In this work, we show how public parameters for a class of NIZKs can be generated by a multi-party protocol, such that if at least one of the parties is honest, then the result is secure (in both aforementioned senses) and can be subsequently used for generating and verifying numerous proofs without any further trust. We design and implement such a protocol, tailored to efficiently support the state-of-the-art NIZK constructions with short and easy-to-verify proofs (Parno et al. IEEE S&P '13, Ben-Sasson et al. USENIX Sec '14, Danezis et al., ASIACRYPT '14). Applications of our system include generating public parameters for systems such as Zero cash (Ben-Sasson et al. IEEE S&P '13) and the scalable zero-knowledge proof system of (Ben-Sasson et al. CRYPTO '14).

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Security and Verification in Computing
Original source
Apr 1, 2015ยทProceedings of the Royal Society of Edinburgh Section A Mathematics
2 cites
A generalized Calderรณn formula for open-arc diffraction problems: theoretical considerations

Stรฉphane K. Lintner, Oscar P. Bruno

We deal with the general problem of scattering by open arcs in two-dimensional space. We show that this problem can be solved by means of certain second-kind integral equations of the form , where and are first-kind integral operators whose composition gives rise to a generalized Calderรณn formula of the form in a weighted, periodized Sobolev space. (Here is a continuous and continuously invertible operator and is a compact operator.) The formulation provides, for the first time, a second-kind integral equation for the open-arc scattering problem with Neumann boundary conditions. Numerical experiments show that, for both the Dirichlet and Neumann boundary conditions, our second-kind integral equations have spectra that are bounded away from zero and infinity as k โ†’ โˆž; to the authorsโ€™ knowledge these are the first integral equations for these problems that possess this desirable property. This situation is in stark contrast with that arising from the related classical open-surface hypersingular and single-layer operators N and S , whose composition NS maps, for example, the function ฯ• = 1 into a function that is not even square integrable. Our proofs rely on three main elements: algebraic manipulations enabled by the presence of integral weights; use of the classical result of continuity of the Cesร ro operator; and explicit characterization of the point spectrum of , which, interestingly, can be decomposed into the union of a countable set and an open set, both of which are tightly clustered around . As shown in a separate contribution, the new approach can be used to construct simple, spectrally accurate numerical solvers and, when used in conjunction with Krylov-subspace iterative solvers such as the generalized minimal residual method, it gives rise to a dramatic reduction in the number of iterations compared with those required by other approaches.

Open access
Electromagnetic Scattering and Analysis
Electromagnetic Simulation and Numerical Methods
Numerical methods in engineering
Original source
Mar 31, 2015ยทInternational Journal of Security and Its Applications
1 cites
A Cross-domain Authentication Method for Cloud Computing

Chen Xu, Jingsha He

The use of security certificates under the Cloud environment is the foundation to establish mutual trust between the Cloud and the user. In this paper, we propose an authentication method based on zero-knowledge proof and the mind of key escrow. With the method, authentication will not only satisfy the requirement anonymity and security but also can recover the real identity information in special circumstances with the cooperation of multiple parties. We will show that this proposed method is more suitable for promotion through analysis and comparison with an existing scheme.

Open access
Cloud Data Security Solutions
Cryptography and Data Security
Access Control and Trust
Original source
Mar 31, 2015ยทInternational Journal of Security and Its Applications
4 cites
Efficient Zero-Knowledge Proofs of Knowledge of Double Discrete Logarithm

Bin Lian, Gongliang Chen, Jianhua Li

Zero-knowledge proof protocol is a basic cryptographic technique. And zero-knowledge proof of double discrete logarithm has some particular properties, so it has been widely applied in many security systems. But the efficient problem of zero-knowledge proof of double discrete logarithm has not been solved to this day, since there are some special difficulties in computing this kind of knowledge proof. Hence, the time complexity and the space complexity of existing schemes are all O(k), where k is a security parameter. After redesigning the basic construction of knowledge proof, we provide a new zero-knowledge proof of double discrete logarithm, which is the first scheme with O(1) time complexity and O(1) space complexity. If introducing an off-line TTP (trusted third party), we can provide two additional zeroknowledge proof schemes of double discrete logarithm, one is even more efficient than the first one, the other one solves another open problem, which is how to efficiently prove the equality of double discrete logarithms in zero-knowledge way, and the existing techniques cannot solve this problem. We also provide the detailed security proofs of our designs and efficiency analysis, comparing with the existing schemes. The significant improvement in efficiency of this basic cryptographic technique is also helpful for many security systems.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Mar 2, 2015ยทLecture notes in computer science
4 cites
Simulating Auxiliary Inputs, Revisited

Maciej Skรณrski

For any pair $(X,Z)$ of correlated random variables we can think of $Z$ as a randomized function of $X$. Provided that $Z$ is short, one can make this function computationally efficient by allowing it to be only approximately correct. In folklore this problem is known as \emph{simulating auxiliary inputs}. This idea of simulating auxiliary information turns out to be a powerful tool in computer science, finding applications in complexity theory, cryptography, pseudorandomness and zero-knowledge. In this paper we revisit this problem, achieving the following results: \begin{enumerate}[(a)] We discuss and compare efficiency of known results, finding the flaw in the best known bound claimed in the TCC'14 paper "How to Fake Auxiliary Inputs". We present a novel boosting algorithm for constructing the simulator. Our technique essentially fixes the flaw. This boosting proof is of independent interest, as it shows how to handle "negative mass" issues when constructing probability measures in descent algorithms. Our bounds are much better than bounds known so far. To make the simulator $(s,ฮต)$-indistinguishable we need the complexity $O\left(s\cdot 2^{5\ell}ฮต^{-2}\right)$ in time/circuit size, which is better by a factor $ฮต^{-2}$ compared to previous bounds. In particular, with our technique we (finally) get meaningful provable security for the EUROCRYPT'09 leakage-resilient stream cipher instantiated with a standard 256-bit block cipher, like $\mathsf{AES256}$.

Open access
2 source records
Cryptography and Data Security
Complexity and Algorithms in Graphs
Cryptographic Implementations and Security
Original source
Feb 9, 2015ยทClinical Orthopaedics and Related Research
6 cites
Not the Last Word: Specialization and its Discontents

Joseph Bernstein

The practice of orthopaedic surgery has become highly specialized. According to a recent American Academy of Orthopaedic Surgeons (AAOS) census, 77% of members reported a specialty interest [1]. Along those lines, Morrell et al. [12] estimate that at least 90% of graduating orthopaedic surgery residents pursue fellowship training. It would be no surprise, therefore, to discover that the AAOS Board of Specialty Societies boasts 22 member groups. To some, greater specialization is no doubt a step in the wrong direction. Back in the days of the giants, this nostalgic argument goes, a โ€œrealโ€ surgeon would be happy to fix a femur fracture and straighten a spine on the same day. (In fact, the true giants would fix a fracture and straighten a spine only after removing an appendix and delivering a baby or two.) Today's orthopaedic surgeons, by contrast, are feckless and feeble. A more reasonable view acknowledges the benefits of specialization. For one, surgeons who do only one procedure are apt to become quite efficient [6]. Better still, the high-volume specialist-surgeon will produce superior results [7]. Specialization similarly enhances career prospects: The Top Doctor lists are filled almost exclusively with specialists and academic advancement criteria emphasize depth over breadth. Of course, a reasonable view would also acknowledge the costs of specialization. Specialistsโ€”like all of usโ€”see the world through the prism of experience. As such, they can easily overlook or discount important findings. This so-called โ€œavailability biasโ€ would spur a neurosurgeon to attribute index finger pain to a cervical radiculopathy and a hand surgeon to blame the median nerveโ€”with both of them relatively blinded to the possibility that a metabolic abnormality, say, is the true cause. Yet even if specialists could break free of their cognitive constraints, patients may still pay as they shuffle from expert to expert in search of total care. This cost comprises not only hassle and dollars, but a potential for poor communication and other forms of uncoordinated care [3]. There is, furthermore, a problem of distribution. Specialists quite rationally tend to congregate in larger urban areas: Places with enough patients to keep them busy in their own narrow practice enclaves. Hence, specialization can lead to a manpower shortage (and impeded access to care) in small towns and a glut (with overtreatment) in big cities. In addition, too much specialization within a surgeon's practice exposes that surgeon to the risk his or her practice might implode if the demand for a particular service disappears. Simply put: The surgeon who knows how to do only knee replacements will be out of work if a medical cure for arthritis is discovered. Of course, it is highly unlikely that a medical cure for arthritis will be discovered so quickly that the surgeon will be unable to adapt, but the risk is not zero. (Those who place the risk at zero have never witnessed a cardiothoracic surgeon crying about the discovery of coronary stents). Maintaining mastery over many surgical procedures is an excellent hedge against the possibility that one of these procedures falls out of favor. But there is an even more pressing reason for surgeons to resist too much specialization: It just might be bad for the soul. In his classic book The Wealth of Nations, Adam Smith noted that the division of labor leads to โ€œuniversal opulence.โ€ Smith clearly recognized the benefits specialization and is rightly considered one of its greatest champions. But Smith went on to assert โ€œThe man whose whole life is spent in performing a few simple operations โ€ฆ generally becomes as stupid and ignorant as it is possible for a human creature to become.โ€ According to Smith, repeatedly doing the same operation (a word we may want to take in its modern medical sense) creates a โ€œtorpor of [the] mind.โ€ This torpor, Smith claims, is a state in which the specialist becomes unable to conceive of any โ€œgenerous, noble, or tender sentiment, and consequently of forming any just judgment concerning many even of the ordinary duties of private life.โ€ In modern parlance: Burnout. So what to do? Because specialization imposes costs on patients, it may be reasonable to insist on professional rules to limit it somewhat. (The broad ABOS recertification examination can be considered such a step, as are normative standards that ask orthopaedic surgeons to provide general emergency room coverage in their community). In addition, our leaders should educate young orthopaedic surgeons about specialization's hidden costs. This knowledge will let enlightened self-interestโ€”what Smith called the โ€œinvisible handโ€โ€”motivate the correct course of action. Pierre J. Hoffmeyer MD Professor of Orthopaedic Surgery University Hospital of Geneva Hyperspecialization in orthopaedic surgery is here to stay. This is especially true in economically favored regions benefitting from high levels of resources [4]. Hyperspecialization has political support because of increasing public pressure stemming from the needs and demands of an aging and active population [2]. In this setting of economic affluence, orthopaedic surgeons have been able to narrow their surgical practice to one joint, to one disease process, or even to one technique. The corollary is that as the number of hyperspecialized experts increases, the quality of the holistic approach towards musculoskeletal care diminishes. How this situation of increasing hyperspecialization will progress will depend on many issues touching on education, legal environment, and economics. Young surgeons training in academic centers are educated by teachers who themselves are highly specialized. These specialists serve not only as mentors but also as role models. It is likely that trainees will follow in the footsteps of their teachers. It is doubtful that this situation is likely to change soon given the structure and organization of most major teaching institutions. The legal environment plays a major role in the molding of surgical practice. In fact, the first question facing a surgeon entangled in a medicolegal issue is how competent he or she is in performing a given procedure. A diploma attesting to the completion of a general orthopaedic education is no longer sufficient to demonstrate competence. Today, proofs of fellowship training as well as the performance of the appropriate numbers of specialized interventions have become mandatory if the surgeon is to convince opposing parties that he or she is competent to safely and effectively perform a given operation. This vision of capability embodied by the high-volume surgeon specialist will undoubtedly persevere [2, 8]. Arguably, regional economics differentiate surgical practice in affluent constituencies from less-prosperous areas. Well-equipped regions with high-quality infrastructures allowing rapid travel to centers of highly specialized expertise will have a large range of hyperspecialized surgeons providing expertise in all the domains of orthopaedics and traumatology. For the individual patient, this could mean better care, fewer complications, and improved efficiency for a given procedure [8, 11]. Conversely, hyperspecialization will entail higher costs because of the increased number of specialists working in a technology-rich environment. For less-favored regions, one surgeon will have to tackle a broad spectrum of diseases, master many techniques, and be knowledgeable in many areas. He or she will have to deal with a variety of situations, but perhaps not as efficiently or complication-free for a given procedure as the hyperspecialized surgeon. Although a generalist approach might appear to be cheaper in the short-term, patients may not always benefit from the latest, safest, and most efficient techniques [2, 11]. Since it appears hyperspecialists are here to stay, solutions must be found. The obvious answer lies in education. All practitioners of orthopaedic surgery, regardless of specialization, must possess a broad base of knowledge in the musculoskeletal field. One should not confound technical and procedural skills with overall expertise and knowledge [13]. The education of surgical trainees and fellows needs to emphasize the necessity of a broad culture in terms of diseases and trauma of the musculoskeletal system regardless of the field of hyperspecialization. This knowledge should be controlled in the recertification process, specializing on the joint, technique, or disease in which the surgeon is focused as well as on his or her general level of knowledge in the broader field of orthopaedics and traumatology. Augusto Sarmiento MD Professor and Chairman Emeritus University of Miami Dr. Bernstein identifies several important issues concerning exaggerated subspecialization in medicine and does not hide his personal concerns regarding its uncontrolled explosion. However, his attempts to propose solutions to the problem do not match his clear exposure of the unhealthy consequences of failure to arrest the progression of the trend. His suggestions along this line are rather timid and sometimes even unrealistic, such as โ€œasking orthopaedic surgeons to provide general emergency room coverage in their community.โ€ This suggestion falls in shallow water even if the fear of litigation could be eliminated. Dr. Bernstein further suggests, โ€œIn addition, our leaders should educate young orthopaedic surgeons about specialization's hidden costs.โ€ In this instance, who will educate the โ€œleadersโ€ who have been the ones primarily responsible for the creation and perpetuation of the problem? I commend CORRยฎ for publishing this thoughtful article on a subject that needs a forceful and aggressive debate. However, in his column, Dr. Bernstein underestimates the fact that greed has crept into our profession to the point where many consider it as being primarily a profitable business. Unfortunately, greed is at the very essence of the subspecialization problem. The current situation will not be assuaged with warm compresses and a few aspirins. The entire issue of education of the physician must be brought to the frontline [14-16]. This is a golden opportunity for orthopaedics, as a major and instrumental profession, to provide leadership to a force that requires active input from a variety of disciplines within the medical establishment as well as from other social and political bodies. Harmful, exaggerated fragmentation of our discipline has allowed several traditional medical and paramedical professions to assume the care of musculoskeletal conditions, long a territory exclusively managed by the orthopaedist. For example, podiatrists and chiropractors have expanded the scope of their disciplines into orthopaedic territory, and more recently, nurse practitioners and physician assistants have claimed the right to provide care for conditions they consider themselves qualified to treat. If we cannot appropriately correct the already ridiculous degree of fragmentation in orthopaedics, the overall situation will continue to deteriorate to a degree that could seriously compromise the vitality of our profession. K. Daniel Riew MD Professor, Department of Orthopaedic Surgery Washington University in St. Louis Dr. Bernstein's article is an excellent summary of the benefits and risks of overspecialization. His arguments against specialization are all valid. I would add what Konrad Lorenz said about scientists, (even more appropriate for specialists): They โ€œare people who know more and more about less and less, until they know everything about nothingโ€ [5]. But as a hyperspecialist who specializes only in cervical spine, I have to respectfully disagree with the final message. In my opinion, not only is specialization inevitable, it is the correct path for science, education, and patient benefit. The history of medicine has demonstrated an inexorable path towards subspecialization. In The Evolution of Orthopaedic Surgery [9], author Leslie Klenerman tells us how orthopaedics became a specialty and seceded from general surgery: โ€œIt is little more than a generation since orthopaedic surgery began its astounding and near exponential ascent from relative obscurity under the dominance of general surgery to itself become a major influence.โ€ But Klenerman notes that the forces are inexorably pushing the subspecialties away from orthopaedics: โ€œHow much longer will the interests of specialization within it, allow it to remain united before it too falls victim to the fragmentation that destroyed the supremacy of its erstwhile master?โ€ The desire to subspecialize is driven by at least three factors. First, we live in a world of information overload. MEDLINE adds more than 5000 articles per weekday. Even if we assume that only 1% of these pertain to orthopaedics, it is nearly impossible for most busy physicians to stay current with all the articles. Would we want the next generation of surgeons to be trained by generalists who cannot keep up, or specialists, current with the literature in their area? Second, legally, general practitioners are held to the same standards as subspecialists. Therefore, if a generalist mismanages a cervical spine fracture, they will be held to the same standards as a cervical spine surgeon. Unless they are current with all aspects of cervical spine care, they are placing themselves at medicolegal risk. Third, in surgery, volume drives success, improves outcomes, shortens operative times, decreases complications, and improves efficiency. We are the cognoscenti when it comes to orthopaedic problems. Who among us would choose to have a delicate tumor removed from our dominant hand by a general orthopaedic surgeon, instead of a hyperspecialized hand surgeon who has great experience with such tumors? Knowing that the results would be highly likely to be better, would we not want the same for all of our family and friends? If we would want these for our loved ones, do our patients deserve any less? A generalist still serves a useful purpose and there are many downsides to everyone becoming a hyperspecialist. However, in my opinion, this is not an adequate reason to recommend that we remain a โ€œjack of all trades and a master of none.โ€

Open access
Diversity and Career in Medicine
Healthcare Systems and Technology
Musculoskeletal Disorders and Rehabilitation
Original source
Jan 23, 2015ยทHAL (Le Centre pour la Communication Scientifique Directe)
11 cites
Efficient Distributed Privacy-Preserving Reputation Mechanism Handling Non-Monotonic Ratings

Paul Lajoie-Mazenc, Emmanuelle Anceaume, Gilles Guette, Thomas Sirvent ยท 5 authors

โ€”Open and large-scale systems do not encourage their users to behave trustworthily, which may entail non-negligible risks when interacting with unknown users, for instance when buying an item on an e-commerce platform. Reputation mech-anisms reduce these risks by associating a reputation score to each user, summarizing their past behavior. To be useful to users, reputation mechanisms need to guarantee two main properties: the non-monotonicity of reputation scores, in order to exactly reflect the users' behavior, and the privacy of their users, so that the history of their transactions is not publicly available. We propose a distributed privacy-preserving reputation mechanism handling non-monotonic ratings. Our proposition relies on two distinct distributed third parties and on cryptographic tools, including zero-knowledge proofs of knowledge, anonymous proxy signatures, and verifiable secret sharing. We show that this proposal is computationally efficient, and thus practical. To the best of our knowledge, this solution is the first one that preserves users' privacy and handles both positive and negative ratings without relying on a central authority.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Jan 21, 2015ยทThe Open Cybernetics & Systemics Journal
2 cites
Secret Sharing Member Expansion Protocol Based on ECC

Feng Wang, Yujie Wu, Daofeng Li

The protocols for member expansion in secret sharing schemes are very useful for key management in dynamic topology networks. In order to reduce the computation complexity of the existed protocols for member expansion in secret sharing schemes, a new protocol is proposed based on the problem of elliptic curve discrete logarithm. This paper examines fifteen most recent patens that were awarded in the area of secret sharing. Unlike traditional detailed patent reviews that are focused on applying the simple secret sharing method, the proposed protocol has the following merits: 1) there is no trust center ; 2) only requesting broadcast 2 1 t + times to generate the sub-secret for the new participant and the new participant can verify the truth of the sub-secret; 3) the old participants can verify the new sub-secret by the noninteractive zero-knowledge proof protocol; 4) In the sub-secret generation stage, not only sub-secrets of old participants but also the sub-secret of new participant is secure. Compared to the existed protocols, the proposed protocol has lower computational complexity and less communications. Therefore, the proposed protocol has higher performance and is suitable for resource-constrained terminals of dynamic networks.

Open access
Cryptography and Data Security
Cryptography and Residue Arithmetic
Chaos-based Image/Signal Encryption
Original source
Jan 9, 2015ยทIEEE Transactions on Computers
18 cites
Zero Knowledge Grouping Proof Protocol for RFID EPC C1G2 Tags

Saravanan Sundaresan, Robin Doss, Wanlei Zhou

In this paper, we propose a novel zero knowledge grouping proof protocol for RFID Systems. Over the years, several protocols have been proposed in this area but they are either found to be vulnerable to certain attacks or do not comply with the EPC Class 1 Gen 2 (C1G2) standard because they use hash functions or other complex encryption schemes. Also, the unique design requirements of grouping proofs have not been fully addressed by many. Our protocol addresses these important security and design gaps in grouping proofs. We present a novel approach based on pseudo random squares and quadratic residuosity to realize a zero knowledge system. Tag operations are limited to functions such as modulo (MOD), exclusive-or (XOR) and 128 bit Pseudo Random Number Generators (PRNG). These can be easily implemented on passive tags and hence achieves compliance with the EPC Global standard while meeting the security requirements.

Open access
RFID technology advancements
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Jan 1, 2015ยทSIAM Review
0 cites
Education

Louis F. Rossi

In this issue, we present two very different papers written in two very different styles. The first is a survey of the multiple timescales method for approximating solutions to differential equations. Multiple timescale methods are common in the literature and an integral part of many graduate programs. However, like riding a bicycle, you need some practice, experience, and insight to use it properly and have meaningful results. The second is an exposition on the Mountain Pass Lemma and related mathematical ideas underlying the existence of saddle points. Despite its name, the second article is no ordinary hike through the hills. In โ€œProfits and Pitfalls of Timescales in Asymptotics,โ€ author Ferdinand Verhulst presents a survey of multiple timescale methods. A colleague of mine once sarcastically pointed out that a tremendous amount of insight can be gleaned from the observation that in almost all problems, parameters are either larger than one or smaller than one, leading to an asymptotic approximation in one form or another. However, one does not have to look far to find problems where it is hard to handle the resulting asymptotic series using a simple Taylor series. Multiple timescales can resolve these problems, but the challenge remains of how to know what the multiple timescales should be without having special knowledge of the problem. Verhulst does an admirable job presenting the basic ideas behind determining timescales a priori using two basic concepts: normal forms and bifurcation theory. In the former case, one transforms the problem into a simpler expression to reveal underlying timescales. In the latter case, understanding the dynamics of a system in terms of bifurcations reveals the qualitative structure of the solution and therefore the timescales. Thus, the author puts order to a body of knowledge that can often appear to students as a disjoint collection of tricks for special problems. In โ€œMountain Passes and Saddle Points,โ€ author James Bisgard develops the Mountain Pass Lemma of Ambrosetti and Rabinowitz which specifies sufficient conditions for the existence of saddle points. Beginning with accessible examples of smooth functions $F: R^2 \rightarrow R$, we can think of $F$ as the height of the landscape. The central element of this manuscript is a very clear proof of the Mountain Pass Lemma, which essentially states that if there is a local minimum in a valley surrounded by a mountain range and there is a point somewhere beyond the mountain range that is lower than the local minimum, then with an additional special requirement, it can be shown that there must be a mountain pass (saddle point) somewhere. While it may seem that there should always be a mountain pass without any additional requirements, the authors present some counterexamples early in the paper to show that this is not a trivial issue. (I could not resist the urge to fire up my tablet and explore some of the sample surfaces.) The special requirement is the Palais--Smale condition, which is the seemingly peculiar condition that every sequence $x_n$ having two properties, (1) that the height above these points is bounded and (2) that the $\| \nabla F(x_n) \|$ approaches zero, must have a convergent subsequence. The author goes on to extend the Mountain Pass Lemma to domains of any finite dimension and from there to Hilbert spaces. Finally, the author uses the concepts involved in the proof to develop methods for finding saddle points. In summary, the Education section in this issue has something for everyone. The first offering focuses on methods and techniques and would be ideal for a graduate course on perturbation methods or applied mathematics. The second paper is analytic, anchored to theorems and proofs but having ample discussion. It would find a home in an undergraduate and graduate real analysis course. Both take a fresh look at classic subjects in mathematics and could be used to liven up traditional courses in most undergraduate and graduate programs.

Open access
2 source records
Numerical methods for differential equations
Differential Equations and Numerical Methods
Graph theory and applications
Original source
Jan 1, 2015ยทRePEc: Research Papers in Economics
0 cites
The economic gains to accounting for fishery induced evolution

Amanda Faig, Faig, Amanda

Ecologists warn that the rapid evolution occurring as a result of high-intensity commercial fishing could have significant economic and ecological effects. So far, fishery managers do not take this rapid evolution (called fisheries-induced evolution or FIE) into consideration when determining fishery policy. I model the interactions between the genetics, population structure, and economics of the fishery in order to determine how beneficial altering the fishery managers decision framework to include fisheries induced evolution would be to fishery profit and yield. My model is based on North-East Arctic Cod, which are long lived and for which an abundance of information exists, including proof of FIE. I compare the steady state reached by a `myopic' fishery manager who sets effort and mesh size policy while ignoring evolution, to the steady state reached by a fishery manager who dynamically optimizes his strategy with the knowledge of how evolution will respond. This paper shows that accounting for evolution can increase steady state profits by 29-34%, however this benefit decreases and is eventually eliminated as the discount rate increases from zero. An important auxiliary benefit to accounting for evolution is the effect optimal management has on fishery biomass, maturation rates, and yield.

Open access
2 source records
Marine and fisheries research
Evolutionary Game Theory and Cooperation
Economic theories and models
Original source
Jan 1, 2015ยทNeural Regeneration Research
13 cites
To myelinate or not to myelinate: fine tuning cAMP signaling in Schwann cells to balance cell proliferation and differentiation

Paula V. Monje

cAMP signaling and the control of Schwann cell fate: The ubiquitous second messenger cyclic adenosine monophosphate (cAMP) controls a variety of cellular responses in a cell type-specific and stimulus-dependent manner through an elaborate network of signaling intermediaries that connect stimulation of cell membrane receptors (typically G protein-coupled receptors, GPCRs) to transcription factor activation. Schwann cells (SCs) are highly responsive to cAMP throughout their lifespan, as extensive research has shown that SC survival, lineage specification, proliferation and differentiation into myelin-forming cells require cAMP signaling. The first evidence concerning the relevance of cAMP to SC function was documented in the 1970s with the discovery that mitotic cell division of isolated SCs was enhanced by cAMP-stimulating agents. Further mechanistic studies indicated that cAMP acts together with growth factors such as neuregulin to synergistically increase the rate of S-phase entry. In addition, cAMP has been known since the 1980s to directly drive the expression of proteins and lipids specific to the myelin sheath, including protein zero, periaxin, myelin associated glycoprotein (MAG) and galactocerebroside (Jessen et al., 1991). Yet, it was not until recent years that the molecular basis of cAMP-mediated signal transduction in SCs began to be understood. As described below, emerging data from independent in vitro and in vivo approaches have highlighted the identity of some key molecular players operating both upstream and downstream of cAMP biosynthesis that act in conjunction with other signals to differentially control SC proliferation and differentiation. It is understood that myelination in SCs is an inducible process sensitive to extracellular signals. Whereas oligodendrocytes autonomously turn on the expression of myelin-related genes upon or even when deprived of axon contact, SCs tend to remain indefinitely undifferentiated despite maintaining extensive contact with axons. Examples provided by in vitro myelination studies and models of nerve regeneration in vivo have shown that some SCs may effectively extend their processes along those of axons and form a basal lamina, a pre-requisite for myelination, yet still do not proceed to form a myelin sheath. If axon contact is not sufficient for myelination, what are the factors limiting the process? In a recent study, we argued that one such factor is cAMP, as activation of cAMP signal transduction in SCs is sufficient to bundle and synchronize the differentiating responses of axon-associated SCs in such a way as to accelerate and greatly enhance myelin formation in vitro (Bacallao and Monje, 2015). By promoting the transition from an immature (proliferative) to a differentiated (growth arrested) state, cAMP acts in concert with, but still independently of, other axonal signals such as neuregulin to initiate myelin membrane wrapping. Indeed, cAMP seems to function as an on/off control switch for myelination, as the simple removal of the cAMP stimulus is sufficient to readily suppress the expression of myelin-associated genes and shift the SC's phenotype back to an immature proliferative state that resembles the one derived through dedifferentiation in response to nerve injury (Monje et al., 2010). Though at first glance it may seem contradictory to assert that a single second messenger could positively control proliferation and differentiation, a specific cellular outcome is achieved via the use of distinct and independent signaling mechanisms (Figure 1A). Whereas the synergistic effect of cAMP on SC proliferation is achieved through gating or cross-talk with signals emanating from ligand-activated receptor tyrosine kinases such as neuregulin-activated ErbB/HER receptors (Monje et al., 2008), the effect of cAMP on differentiation is direct and seems not to require the concurrent activation of receptor tyrosine kinase pathways. The use of separate transduction elements also contributes to the specificity of outcome. As such, SC proliferation rather than differentiation relies on the activation of the transmembrane adenylyl cyclase (tmAC)-dependent, protein kinase A (PKA)-dependent pathway. SC myelination, by contrast, seems to be controlled by non-canonical cAMP signaling, as this process is mediated by effectors and upstream activators that have been relatively understudied in comparison to the classical tmAC-PKA pathway. Novel transduction elements reported to control myelination include: (1) the exchange protein activated by cAMP (EPAC), which is a guanine nucleotide exchange factor for the small GTP-binding protein Rap1 and transduces cAMP signals through direct binding to cAMP (Bacallao and Monje, 2013); (2) the soluble adenylyl cyclase (sAC), which is an ubiquitous forskolin- and GPCR-insensitive adenylyl cyclase subtype that generates cAMP in various cell compartments (Bacallao and Monje, 2015); and (3) the adhesion receptor Gpr126, which is a highly conserved orphan GPCR that signals via G protein activation and cAMP to control myelination in vivo (Mogha et al., 2013). These signal transduction molecules represent attractive targets to control the state of differentiation that is conducive to myelination independently of the control of proliferation.Figure 1: Balancing Schwann cell (SC) fate via cyclic adenosine monophosphate (cAMP).A mechanistic model for the differential control of SC proliferation and differentiation by cAMP signals based on available data (A) and a suggested general strategy for otimizing cAMP-mediated, SC-dependent regeneration and myelination (B). Krox-20, a cAMP-dependent transcription factor that is a master regulator of myelination; O1: The myelin lipid galactocerebroside; EPAC: exchange protein activated by cAMP; GPCR: G protein-coupled receptor; PKA: protein kinase A; sAC: soluble adenylyl cyclase; tmAC: transmembrane adenylyl cyclase.Manipulating and optimizing cAMP signaling in SCs for therapeutic applications: Our improved understanding of cAMP regulation of SC fate, along with the well-recognized role of cAMP in promoting axon growth in different types of neurons (Spencer and Filbin, 2004), can be exploited to delineate novel approaches to improve the outcome of SC-mediated nerve repair. The basic argument discussed herein postulates that balancing proliferation and differentiation through differential targeting of the cAMP signaling system may have an impact on the extent to which endogenous or transplanted SCs promote peripheral and central axon regeneration and myelination, thus contributing to functional repair. SCs have been grafted in the injured or dysmyelinated CNS and PNS for decades on the assumption that they can foster axon growth and subsequently form a myelin sheath to insulate regenerated and/or spared axons. Because the benefits of SC transplantation can be improved significantly if additional treatments are provided, attempts have been made to combine SC transplants with modulators of intracellular cAMP levels to augment nervous tissue repair (Fortun et al., 2009). One advantage of targeting the cAMP signaling system is that a single therapeutic approach can potentially improve various aspects linked to functional repair. Another advantage is that many of the molecular players within this system lend themselves suitable to pharmacological intervention; in addition, extensive information is available on their mechanism of action at the cellular and molecular levels. Considering the sophistication of cAMP networks, the potential for cross-talk, and the multiple cellular targets that are expected to react to cAMP stimulation, one may reason that any given cAMP therapy should be tailored to a desired cellular outcome. Most studies performed so far have relied on the use of broad-spectrum cAMP-stimulating agents administered either locally or systemically [see (Knott et al., 2014) for a recent review]. Though useful for proof of principle and feasibility assessment, this type of traditional approach may limit our understanding of the mechanism of action by which a given treatment promotes repair. An example is provided by a SC transplantation study in the contused spinal cord which showed a dramatic increase in axon growth and myelination within the SC transplants upon co-administration of dibutyryl-cAMP (a non-hydrolyzable cAMP analog) and rolipram (a phosphodiesterase, PDE, IV inhibitor); yet, whether the effect of cAMP was mediated by the SCs, the neurons or both could not be defined simply on the basis of the results obtained (Pearse et al., 2004). The implementation of a cAMP-based strategy designed to modulate the rate and/or extent of myelin formation by SCs, alone or while concurrently preventing myelin loss, seem in principle rather straightforward based on our current knowledge on how the initiation and maintenance of myelination is controlled by cAMP. Yet, a strategy for SC-mediated nerve repair is more challenging, as treatment should balance at least two independent events: (1) promotion of axonal growth, which can be achieved by targeting cAMP-dependent pathways within the SCs and/or the neurons; and (2) promotion of myelination, which can be achieved by targeting pathways within the SCs. Novel research in the SC field has suggested that axon regeneration and SC differentiation are highly interdependent events (Jessen and Mirsky, 2008). Whereas the initiation and maintenance of an immature SC phenotype may foster axon growth, a premature or exacerbated differentiation of the SC may determine a poor or suboptimal regenerative response. The axon growth-promoting benefits of the SCs themselves are expected to be reduced upon their differentiation into myelin-forming cells. Not only do SCs cease to proliferate, migrate and secrete neurotrophic factors as they undergo differentiation, but the expression of myelin-specific proteins such as MAG on their surface may elicit a stop signal for axonal growth, a phenomenon which is particularly relevant in the context CNS regeneration. The present line of reasoning implies that several independent parameters should be considered when optimizing cAMP therapies for SC-mediated repair and myelination. These parameters include: (1) the properties and specificity of the cAMP-inducing treatment on downstream effectors, (2) the possibility of positive or negative cross-talk of cAMP signaling with other pathways; (3) the timing of administration and the duration of the cAMP stimulus; (4) the expected cell type-specific outcome of cAMP elevation in SCs and neurons; and (5) the effect of environmental or context-specific factors. Multiple tools currently available offer an exceptional opportunity to fine-tune cAMP signaling into a desired cellular outcome. Selective targeting and specificity of signaling is plausible if we understand that cAMP does not act as a unitary signaling pathway but orchestrates many differentially regulated pathways that are built around a common second messenger. First generation cAMP-modulating agents, which offered low or little power for target discrimination, can nowadays be replaced by the wide range of chemical agents (activators and inhibitors) with potential to distinguish among distinct cAMP-specific PDEs, adenylyl cyclase subtypes and downstream cAMP effectors. Novel pathway-specific, cell permeable cAMP derivatives offer the possibility to potently and selectively manipulate PKA and EPAC activation within living cells (Holz et al., 2008). We and others have used some of these analogs to more selectively control the rate of proliferation (via PKA) and differentiation (via EPAC) of SCs in vitro. Isoform-specific EPAC antagonists have also become available, which brings the unique potential to block EPAC signaling while maintaining PKA-initiated pathways. Differential targeting of tmAC and sAC activities can also provide a feasible route for selective pathway modulation based on their clearly different modes of activation and inhibition. Non-pharmacological treatments such as electrical stimulation, which is known to stimulate sAC, may contribute to modulating the potency and pathway specificity through cAMP in selected cell populations. In optimizing the timing and duration of treatment, one should consider that SC differentiation may counterbalance axon growth. Thus, cAMP therapies aimed to increase myelination may be better implemented independently of those aimed to increase axon regeneration or alternatively, during the later stages of the regeneration process. Additive or synergistic effects on SC-mediated axon regeneration may be achieved if treatments aimed at enhancing SC proliferation (by targeting SCs) are coupled to those aimed at enhancing axon growth (by targeting the neurons) as long as these are provided while concurrently halting or delaying SC differentiation (Figure 1B). A faster or more efficient myelination may be derived from the synchronization of the differentiating responses expected to result from cAMP elevation in SCs, if a similar phenomenon is observed during nerve development or repair in vivo. Despite no evidence so far indicates that the environment per se would preclude cAMP-induced SC proliferation and/or differentiation, the scenarios may differ considerably in light of the expected effects of cAMP on axon regeneration in PNS and CNS neurons. To conclude, our significantly expanded understanding of cAMP signal transduction in SCs offers a unique opportunity for new therapeutic developments for SC-mediated nervous tissue repair. A re-interpretation of already available data in the context of new discoveries in signal transduction research is also needed, as the field continues to evolve swiftly. Remaining challenges include achieving complete elucidation of the non-canonical cAMP pathway that underlies myelination as well as a more in-depth understanding of the receptor-ligand interactions that differentially mediate the cAMP-dependent control of SC proliferation and myelination in vivo. In light of the revitalized concept that SCs myelinate (or not) as determined at least in part by cAMP, there is, in my opinion, extensive room for innovation in addressing the treatment of nerve system injuries and myelin diseases through cAMP-based therapies. This work was supported by NIH-NINDS Grants NS009923 and NS084326, The Miami Project to Cure Paralysis and The Buoniconti Fund.

Open access
Nerve injury and regeneration
Neurogenesis and neuroplasticity mechanisms
Signaling Pathways in Disease
Original source
Jan 1, 2015ยทRWTH Publications (RWTH Aachen)
0 cites
Design and Implementation of Efficient Multi-Party Protocols for Privacy-Preserving Reconciliation

Georg Neugebauer, Susanne Wetzel, Ulrike Meyer

Today's Internet is full of applications by which users share potentially private information with each other. Recently, the privacy concerns of users are rising and users gradually become more suspicious with respect to the use of their (personal) information. In this thesis, we aim at bringing secure multi-party computation closer to common Internet users. The main goal is to design and implement privacy-preserving reconciliation-based applications for multiple users which are secure against passive and active attackers. Additionally, our solutions should be efficient enough to be practical and usable enough even for non-technical users.As a main contribution in theory, we present different privacy-preserving multi-party reconciliation protocols based on an additively homomorphic cryptosystem that are secure against passive attackers (semi-honest model). We also propose reconciliation protocols that are secure against active attackers (malicious model) by applying zero-knowledge proof techniques. The stronger security model comes at the price of efficiency. As a prerequisite, we develop several novel cryptographic tools in the areas of privacy-preserving set operations and zero-knowledge proofs of knowledge. We also analyze to what extent fully homomorphic cryptosystems can be used for multi-party privacy-preserving reconciliation protocols. As a main contribution in practice, we introduce SMC-MuSe, a framework for Secure Multi-Party Computation on MultiSets. SMC-MuSe is a carefully designed framework for secure multi-party computation including an implementation of different cryptographic components, a support infrastructure, multi-party privacy-preserving reconciliation protocols, and two user-friendly applications for the desktop and mobile environment. We also evaluate the efficiency of the SMC-MuSe framework. In particular, we measure the computation and communication overhead of all implemented components within the SMC-MuSe framework. As a third line of work, we propose different application scenarios in the areas of event scheduling, e-voting, and electronic auctions for reconciliation protocols. We examine the practicability of one particular user-friendly application of SMC-MuSe by conducting a user study on our Android application Prefer. The user study shows that Prefer is a useful and very interesting application for today's smartphone users. Finally, we show the potential of reconciliation protocols for common Internet users by conducting a user study on privacy-preserving reconciliation in the Internet. The user study shows that our reconciliation protocols are useful in different application scenarios for common Internet users.

Open access
Security in Wireless Sensor Networks
Cooperative Communication and Network Coding
Cryptography and Data Security
Original source
Jan 1, 2015ยทDukeSpace (Duke University)
3 cites
Dirichlet Process Mixture Models for Nested Categorical Data

Jingchen Hu

<p>This thesis develops Bayesian latent class models for nested categorical data, e.g., people nested in households. The applications focus on generating synthetic microdata for public release and imputing missing data for household surveys, such as the 2010 U.S. Decennial Census.</p><p>The first contribution is methods for evaluating disclosure risks in fully synthetic categorical data. I quantify disclosure risks by computing Bayesian posterior probabilities that intruders can learn confidential values given the released data and assumptions about their prior knowledge. I demonstrate the methodology on a subset of data from the American Community Survey (ACS). The methods can be adapted to synthesizers for nested data, as demonstrated in later chapters of the thesis.</p><p>The second contribution is a novel two-level latent class model for nested categorical data. Here, I assume that all configurations of groups and units are theoretically possible. I use a nested Dirichlet Process prior distribution for the class membership probabilities. The nested structure facilitates simultaneous modeling of variables at both group and unit levels. I illustrate the modeling by generating synthetic data and imputing missing data for a subset of data from the 2012 ACS household data. I show that the model can capture within group relationships more effectively than standard one-level latent class models.</p><p>The third contribution is a version of the nested latent class model adapted for theoretically impossible combinations, e.g. a household with two household heads or a child older than her biological father. This version assigns zero probability to those impossible groups and units. I present a proof that the Markov Chain Monte Carlo (MCMC) sampling strategy estimates the desired target distribution. I illustrate this model by generating synthetic data and imputing missing data for a subset of data from the 2011 ACS household data. The results indicate that this version can estimate the joint distribution more effectively than the previous version.</p>

Open access
Bayesian Methods and Mixture Models
Statistical Methods and Bayesian Inference
Census and Population Estimation
Original source
Jan 1, 2015ยทKyushu University Institutional Repository (QIR) (Kyushu University)
0 cites
Zero-Knowledge Protocols for Code-Based Public-Key Encryption and Their Applications

Rong Hu

Cryptography relies on Mathematics in all its aspects, beginning from the constructions relying on various mathematical theories, continuing with security evaluation of cryptographic systems, and proving their security, and finally ending in implementation.Recently, new security threats are posed by the emerging quantum computing technology.Specifically, quantum algorithms can break some public-key encryption schemes such as RSA and Elgamal, which are widely used for protection of computer systems and networks.This issue demands us to develop a new generation of cryptographic systems, which will serve as secure alternatives to the currently used ones.Such the new systems are referred to as the post-quantum cryptography.One promising direction in post-quantum cryptography is the systems whose security is based on hardness of mathematical problems arising in the context of coding theory.In particular, the problem of decoding random linear codes has been studied for over 30 years, and still no polynomial-time solution has been proposed, even when using quantum algorithms.In this thesis, we focus on this area, which is called the code-based cryptography.The first code-based public-key encryption (PKE) scheme was introduced by R.J. McEliece in 1978.Since then, various code-based public-key encryption, digital signature and identification schemes were introduced, but currently, one of the main challenges is to introduce more advanced cryptographic functionalities based on coding.In this thesis, first, we give a brief introduction about post-quantum cryptography and codebased cryptography, and then we provide the background information about the cryptographic primitives, which we will study, as well as the relevant notions and results from coding theory and cryptography.Next, we introduce our contributions as follows.Firstly, we study zero-knowledge (ZK) identification schemes based q-ary linear codes.We show that when q < 5, a straightforward generalization of Stern's ZK identification scheme (1993) is more efficient in terms of both communication and computation, as compared to the ZK identification scheme by Cayrel, Vron and El Yousfi Alaoui (2010), which is specifically designed for q-ary codes.Secondly, we introduce the first proof of plaintext knowledge (PPK) for the McEliece PKE and the Niederreiter PKE.These protocols allow the encryptor to prove the knowledge of the plaintext contained in a given ciphertext to any party, who does not hold the secret key for decryption.We also provide a performance evaluation for the proposed schemes.

Open access
Coding theory and cryptography
Cryptography and Data Security
Cryptographic Implementations and Security
Original source
Jan 1, 2015ยทeScholarship@McGill (McGill)
5 cites
Cryptography from post-quantum assumptions

Raza Ali Kazmi

In this thesis we present our contribution in the field of post-quantum cryptography. We introduce a new notion of weakly Random-Self-Reducible public-key cryptosystem and show how it can be used to implement secure Oblivious Transfer. We also show that two recent (Post-quantum) cryptosystems can be considered as weakly Random-Self-Reducible. We introduce a new problem called Isometric Lattice Problem and reduce graph isomorphism and linear code equivalence to this problem. We also show that this problem has a perfect zero-knowledge interactive proof with respect to a malicious verifier; this is the only hard problem in lattices that is known to have this property.

Open access
Cryptography and Data Security
Coding theory and cryptography
Cryptographic Implementations and Security
Original source
Jan 1, 2015ยทAdvances in engineering research/Advances in Engineering Research
3 cites
A TCM-Based Remote Anonymous Attestation Protocol for Power Information System

Ruizhong Chen, Lihao Wei, Hong Zou, Meijie Zhai

Project development in a power enterprise always needs to authorize external devices access to the enterprise intranet for testing. In order to avoid an external device with a virus and pose a security risk to the power information system, external devices should have strict security assessment before access the enterprise intranet. But after the security assessment, the device user still be possible to change the platform configuration. Remote attestation is one of important measures when two sides need to communicate. It is concernful to attest the remote platform is trusty but not revealing the any private information of the platform. For this reason, we designed a novel remote anonymous attestation protocol based on TCM. The proposed protocol does not need extra zero knowledge proof and the involvement of the third trusted party and the composite signature scheme is proved secure against existential forgery on adaptively chosen message. So this protocol has better security and execution property.

Open access
Cryptography and Data Security
Security and Verification in Computing
Cloud Data Security Solutions
Original source