Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results · page 165 of 177

Clear filters
Jan 1, 2010·Lecture notes in computer science
17 cites
Strong Cryptography from Weak Secrets

Xavier Boyen, Céline Chevalier, Georg Fuchsbauer, David Pointcheval

No abstract is available for this record.

Open access
2 source records
Cryptography and Data Security
Cryptographic Implementations and Security
Complexity and Algorithms in Graphs
Original source
Jan 1, 2010·HAL (Le Centre pour la Communication Scientifique Directe)
37 cites
Batch Groth-Sahai

Olivier Blazy, Georg Fuchsbauer, Malika IzabachÚne, Amandine Jambert · 6 authors

No abstract is available for this record.

Open access
2 source records
Cryptography and Data Security
Chaos-based Image/Signal Encryption
Complexity and Algorithms in Graphs
Original source
Jan 1, 2010·Lecture notes in computer science
45 cites
A Formal Model of Identity Mixer

Jan Camenisch, Sebastian Mödersheim, Dieter Sommer

No abstract is available for this record.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
Access Control and Trust
Original source
Jan 1, 2010·IACR Cryptology ePrint Archive
10 cites
A Certifying Compiler for Zero-Knowledge Proofs of Knowledge Based on Sigma-Protocols.

José Bacelar Almeida, Endre Bangerter, Manuel Barbosa, Stephan Krenn · 6 authors

Abstract. Zero-knowledge proofs of knowledge (ZK-PoK) are important building blocks for numerous cryptographic applications. Although ZK-PoK have very useful properties, their real world deployment is typically hindered by their significant complexity compared to other (noninteractive) crypto primitives. Moreover, their design and implementation is time-consuming and error-prone. We contribute to overcoming these challenges as follows: We present a comprehensive specification language and a certifying compiler for ZK-PoK protocols based on ÎŁ-protocols and composition techniques known in literature. The compiler allows the fully automatic translation of an abstract description of a proof goal into an executable implementation. Moreover, the compiler overcomes various restrictions of previous approaches, e.g., it supports the important class of exponentiation homomorphisms with hidden-order co-domain, needed for privacy-preserving applications such as idemix. Finally, our compiler is certifying, in the sense that it automatically produces a formal proof of security (soundness) of the compiled protocol (currently covering special homomorphisms) using the Isabelle/HOL theorem prover.

Open access
Logic, Reasoning, and Knowledge
Original source
Jan 1, 2010·IACR Cryptology ePrint Archive
51 cites
ZKPDL: A Language-Based System for Efficient Zero-Knowledge Proofs and Electronic Cash

Sarah Meiklejohn, C. Chris Erway, Alptekın KĂŒpĂ§ĂŒ, Theodora Hinkle · 5 authors

In recent years, many advances have been made in cryptography, as well as in the performance of communication networks and processors. As a result, many advanced cryptographic protocols are now efficient enough to be considered practical, yet research in the area remains largely theoretical and little work has been done to use these protocols in practice, despite a wealth of potential applications. This paper introduces a simple description language, ZKPDL, and an interpreter for this language. ZKPDL implements non-interactive zero-knowledge proofs of knowledge, a primitive which has received much attention in recent years. Using our language, a single program may specify the computation required by both the prover and verifier of a zero-knowledge protocol, while our interpreter performs a number of optimizations to lower both computational and space overhead. Our motivating application for ZKPDL has been the efficient implementation of electronic cash. As such, we have used our language to develop a cryptographic library, Cashlib, that provides an interface for using e-cash and fair exchange protocols without requiring expert knowledge from the programmer. 1

Open access
Cryptography and Data Security
Cryptographic Implementations and Security
Advanced Authentication Protocols Security
Original source
Jan 1, 2010·Lecture notes in computer science
37 cites
Concurrent Non-Malleable Zero Knowledge Proofs

Huijia Lin, Rafael Pass, Wei-Lung Dustin Tseng, Muthuramakrishnan Venkitasubramaniam

No abstract is available for this record.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
Cryptographic Implementations and Security
Original source
Dec 1, 2009
1 cites
An investigation into graph isomorphism based zero-knowledge proofs.

Eric Ayeh

Zero-knowledge proofs protocols are effective interactive methods to prove a node's identity without disclosing any additional information other than the veracity of the proof. They are implementable in several ways. In this thesis, I investigate the graph isomorphism based zero-knowledge proofs protocol. My experiments and analyses suggest that graph isomorphism can easily be solved for many types of graphs and hence is not an ideal solution for implementing ZKP.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Distributed systems and fault tolerance
Original source
Nov 27, 2009·Annals of Emergency Medicine
8 cites
A Consideration of the Measurement and Reporting of Interrater Reliability

Frank C. Day, David L. Schriger

Discussion Points1Cruz et al1Cruz C.O. Meshberg E.G. Shofer F.S. et al.Interrater reliability and accuracy of clinicians and trained research assistants performing prospective data collection in emergency department patients with potential acute coronary syndrome.Ann Emerg Med. 2009; 54: 1-7Abstract Full Text Full Text PDF PubMed Scopus (13) Google Scholar contains 2 parts, a comparison of the values gathered by trained research assistants and physicians about historical information in chest pain patients and the comparison of these participants' recordings with a “correct” value for each item.A. For each part, indicate whether the authors are studying reliability or validity and explain the difference between these concepts.B. What did the authors use as their criterion standard for the validity analysis?C. What are potential problems with their method of defining the criterion (gold) standard? Can you think of alternative approaches?D. The authors report crude agreement and interquartile range for their validity analysis. What part of a distribution is described by the interquartile range? List other statistics used to describe the validity of a measure and why they might be preferable to reporting crude agreement.2Tabled 1MD Recorded “Yes”MD Recorded “No”TotalRA recorded yes1176123RA recorded no18220Total1358143MD, Medical doctor; RA, research assistant. Open table in a new tab A. Calculate the crude percentage agreement for this table. What is the range of possible values for percentage agreement?B. Calculate Cohen's Îș for this table. What is the formula for Îș for raters making a binary assessment (eg, yes/no or true/false)? Discuss the purpose of Cohen's Îș, its range, and the interpretations of key values such as –1, 0, and 1.C. What other measures can be used to measure reliability for binary, categorical, and continuous data? 3Cruz et al quote the oft-cited Landis and Koch2Landis J.R. Koch G.C. The measurement of observer agreement for categorical data.Biometrics. 1977; 33: 159-174Crossref PubMed Scopus (49675) Google Scholar article stating that a Îș of “less than 0.2 represents poor agreement; 0.21 to 0.40, fair agreement; 0.41 to 0.60, moderate agreement; 0.61 to 0.80, good agreement; and 0.81 to 1.00, excellent agreement.” Consider studies of the agreement of airline pilots deciding whether it is safe to land and psychologists deciding whether interviewees have type A or type B personalities. the studies the Îș the by Landis and Koch be 2 are in of a and to such as is a a or by a in the for and in the for are and the are to a for each that they percentage agreement is and Îș is of are and are that the is the for a the the this the percentage agreement and Îș for the the of the are and of the are by the of the are and of the are by the the are and of the are by the and of the are and of the are by the Discuss the of percentage agreement and Îș in these Consider the 2 and percentage agreement and Îș for is Îș the What this that the table the described and that that to 2 in the raters are that are and the raters are that be with with or in with each of Îș the in these 2 the of Îș, that such that and or are for the and percentage agreement and Îș for these is the measure for Consider the of the raters in the in this be reliability is might this be the percentage agreement Îș for the in of et The are to indicate the in the and 2 Open table in a new tab A. in the table are with the the pain it to the it to the it to the for these Can you explain why these have percentage agreement you is the the Can you the between the of the in the table and the to Îș percentage the problems with percentage agreement and Îș in these you think it be the in the of each table of reporting the percentage agreement or et al contains 2 parts, a comparison of the values gathered by trained research assistants and physicians historical information in chest pain and the comparison of these participants' recordings with a “correct” value for each For each part, indicate whether the authors are studying reliability or validity and explain the difference between these part is assessment of and the is assessment of The between reliability and validity is the that the in a that a a The reliability of a to the agreement the the or assessment of validity a observer a or the criterion standard is to be validity studies report the of the observer statistics such as and or reliability such as percentage agreement or What did the authors use as their criterion standard for the validity the and the research it is that their is they a research the of the 2 is What are potential problems with their method of defining the standard? Can you think of alternative a standard for this is For can be 2 the and is For a you have pain in the might that is a for in the is a might that is its the with is the criterion standard for this the the have or the the information The of is that have to the emergency have the of reporting part of a to their and the the a be or the other of the physicians the in a that to the or or in the a the the or are or whether they are to the and the patients be in or to the authors have to the in the research and each and the of to a in accuracy with The authors report crude agreement and interquartile range for their validity analysis. What part of a distribution is described by the interquartile range? List other statistics used to describe the validity of a measure and why they might be preferable to reporting crude interquartile range to the of a of is a that represents the the to the this is the and the the can be by the to the that a distribution the is used to these The is the the the and the the The is the difference between the and is a by than the range of a and it is data are in the of a the and are to and and the the or you the to the and you the or a to in the research and did the authors report the percentage agreement with the “correct” by the criterion agreement is a for a reliability is the to describe this validity assessment of a observer with a criterion that are to a validity report statistics such as and or reliability such as percentage agreement or percentage agreement is a to report Consider the table for the the of the chest pain or 1MD Recorded “Yes”MD Recorded “No”TotalRA recorded recorded Open table in a new tab Calculate the crude percentage agreement for this table. What is the range of possible values for percentage 2 and 2 crude percentage agreement for this table is agreement can range between and Calculate Cohen's Îș for this table. What is the formula for Îș for raters making a binary assessment (eg, yes/no or true/false)? Discuss the purpose of Cohen's Îș, its range, and the interpretations of key values such as –1, 0, and Îș by A of agreement for Scopus Google Scholar in is to to is with the method as For it is to to the by with and the and and The and of the a to these the of the they are to as that the values of a to can The is in the the The agreement for this table the 2 raters recorded the or are and Îș the to the percentage of agreement to for each agreement and these are to the the values Îș is as The value of to The value of to The percentage agreement to to the of this that agreement or have that the agreement to is these 2 the Îș formula as a of agreement for A of agreement for Scopus Google Scholar to measure agreement Îș can range that agreement than by to agreement percentage of percentage agreement to A Îș of that agreement is that by percentage of the Îș is that the of the agreement table of the in that are and the these and agreement be a of the explain these in in What other measures can be used to measure reliability for binary, categorical, and continuous can be with a of excellent for Scholar that is about is and that method is for is to of data are a of such as or and in a such as to A binary is a categorical with 2 or or as can of values be and measurement accuracy continuous is to the reliability are for use with continuous and whether a is to their measure data with a a of indicate that the 2 are with each other are as in the of the or be a in the with is that 2 be as in the Open table in a new tab The A new measure of Scholar and The and measurement of between Google Scholar measure the of between 2 and is a to measure the of a in a of agreement of A of agreement in a value of a between 2 a of in a value of A of is that its range the a as this and between and a Scholar and is to in of to measure can be used to measure in PubMed Scopus Google Scholar The the raters a to the and that physicians use a to the of acute coronary in each of patients The 2 for each for each the the raters for each The in for is with the of the is in the patients than is in the A that the raters have good a the for each to be the each are the the be as the raters are A of have the of the statistics can to the that the the about agreement and are the by the is a of agreement data that the difference in for each their for agreement between of PubMed Scopus Google Scholar Consider a that measures 2 in et al quote the oft-cited Landis and Koch that a Îș of “less than 0.2 represents poor agreement; 0.21 to 0.40, fair agreement; 0.41 to 0.60, moderate agreement; 0.61 to 0.80, good agreement; and 0.81 to 1.00, excellent agreement.” Consider studies of the agreement of airline pilots deciding whether it is safe to land and psychologists deciding whether interviewees have type A or type B personalities. the studies the Îș the by Landis and Koch be their Îș values to by Landis and Koch2Landis J.R. Koch G.C. The measurement of observer agreement for categorical data.Biometrics. 1977; 33: 159-174Crossref PubMed Scopus (49675) Google Scholar and by for and Scholar the of values of Îș to the and excellent is with A Îș of might be good the of is as than agreement is the be a Îș of it safe to (eg, a of historical that are used to patients for might be their are (eg, a of and data that are used to patients with pain can be they are is be used by of agreement as or in between of the a 2 are in of a and to such as is a a or by a in the for and in the for are and the are to a for each that they percentage agreement is and Îș is of of are and are that the is the for a the the this the percentage agreement and Îș for the the of the are and of the are by the of the are and of the are by the the are and of the are by the of the are and of the are by the Discuss the of percentage agreement and Îș in these is to that in Îș can are and percentage agreement is that 2 raters of these are between and or the and 2 2 of the possible that whether the or or each that of the with possible percentage agreement and and 2 possible The of the each the Îș a than the are and Open table in a new tab that in these 2 of the raters are to and The agreement be the in the value of percentage agreement to as for Îș, Îș is in than in raters are performing in percentage agreement the of are and are can be by the and and The in each about are the for the is that in and in and Open table in a new tab by the might in a or or agreement a or these to and the percentage agreement and Îș range between and to and and Open table in a new tab a possible of are and are by the and The in raters that of the are might in Îș is for this table the agreement is than that to and in and Open table in a new tab The might in a table. that that of the and of the as have that this raters the as the percentage agreement and Îș range between and and and to and and and and Open table in a new tab of Open table in a new tab that the of the raters is the each raters can the they the percentage of can in a range of Îș, agreement be the range of Îș as the of The of the Îș is that agreement to as the is of that that is and can to Îș values that agreement is agreement the problems of Full Text PDF PubMed Scopus Google agreement the Full Text PDF PubMed Scopus Google Consider the 2 and percentage agreement and Îș for is Îș the What this the in The percentage agreement is the in of these Îș is in the table its are Îș the and this to the and to agreement by agreement is are with the are is the are of Îș Îș that are is to be this 2 raters or each of a fair with of and is they have of and and that their agreement to be have to than for to about or raters are that the be to raters to have of and and to by of the Îș that indicate agreement to are in the in in the raters making it Îș is used to measure the reliability of 2 that a or of The the that of the be to agreement in the the they be this be For that the percentage agreement is a and as reporting the table is the method of reliability the of Îș, the that such that and or are for the and percentage agreement and Îș for these is the measure for Consider the of the raters in the in this be reliability is might this be to between 2 the raters with a percentage whether the values of they are are or in is and the other are the be or that in this the of the raters the values of the and the the values of these the raters have they to of to to or they the of the they their of the to their a it is the value of the that that value of the and agreement is by is that is to table and have to it and The table and the are agreement and Îș and and the of the the problems in raters to the and their of the their with the agreement is to the and Îș is for this the percentage agreement Îș for the et The are to indicate the in the in the table are with the the pain it to the it to the it to the for these Can you explain why these have percentage agreement you is the the percentage table Îș its are than of the table. the of the and with the of the and for each and and and and each these 2 Îș these values to percentage agreement to of reliability is that the reliability data in the agreement is to it is is in that it for agreement that by think of and Îș a and are and the to use the values to that each and research these of the and they information about the or of chest pain that might their the of Îș are and that the it to the than pain the agreement A B Open table in a new tab The in these to a the table agreement for these the data a of the agreement with for or raters to a that by to that agreement of agreement for the to with are with part of that be to assessment of and raters their in and to their in a is criterion standard to the validity of be that of the in this did in their of of these the of be a to defining and for the of agreement than Can you the between the of the in the table and the to Îș percentage that Îș is to a to percentage agreement percentage agreement is and is with a The of a with data that the are as in the to as agreement and Îș a percentage that the in Îș the in of the et al article have to with the of the than of the of in the of the are to have of the reliability of the the problems with percentage agreement and Îș in these you think it be the in the of each of reporting the percentage agreement or that this of the and that can a table data is to a reliability such as of reporting the reliability data than percentage agreement or information in it is to in the Discussion Points1Cruz et al1Cruz C.O. Meshberg E.G. Shofer F.S. et al.Interrater reliability and accuracy of clinicians and trained research assistants performing prospective data collection in emergency department patients with potential acute coronary syndrome.Ann Emerg Med. 2009; 54: 1-7Abstract Full Text Full Text PDF PubMed Scopus (13) Google Scholar contains 2 parts, a comparison of the values gathered by trained research assistants and physicians about historical information in chest pain patients and the comparison of these participants' recordings with a “correct” value for each item.A. For each part, indicate whether the authors are studying reliability or validity and explain the difference between these concepts.B. What did the authors use as their criterion standard for the validity analysis?C. What are potential problems with their method of defining the criterion (gold) standard? Can you think of alternative approaches?D. The authors report crude agreement and interquartile range for their validity analysis. What part of a distribution is described by the interquartile range? List other statistics used to describe the validity of a measure and why they might be preferable to reporting crude agreement.2Tabled 1MD Recorded “Yes”MD Recorded “No”TotalRA recorded yes1176123RA recorded no18220Total1358143MD, Medical doctor; RA, research assistant. Open table in a new tab A. Calculate the crude percentage agreement for this table. What is the range of possible values for percentage agreement?B. Calculate Cohen's Îș for this table. What is the formula for Îș for raters making a binary assessment (eg, yes/no or true/false)? Discuss the purpose of Cohen's Îș, its range, and the interpretations of key values such as –1, 0, and 1.C. What other measures can be used to measure reliability for binary, categorical, and continuous data? 3Cruz et al quote the oft-cited Landis and Koch2Landis J.R. Koch G.C. The measurement of observer agreement for categorical data.Biometrics. 1977; 33: 159-174Crossref PubMed Scopus (49675) Google Scholar article stating that a Îș of “less than 0.2 represents poor agreement; 0.21 to 0.40, fair agreement; 0.41 to 0.60, moderate agreement; 0.61 to 0.80, good agreement; and 0.81 to 1.00, excellent agreement.” Consider studies of the agreement of airline pilots deciding whether it is safe to land and psychologists deciding whether interviewees have type A or type B personalities. the studies the Îș the by Landis and Koch be 2 are in of a and to such as is a a or by a in the for and in the for are and the are to a for each that they percentage agreement is and Îș is of are and are that the is the for a the the this the percentage agreement and Îș for the the of the are and of the are by the of the are and of the are by the the are and of the are by the and of the are and of the are by the Discuss the of percentage agreement and Îș in these Consider the 2 and percentage agreement and Îș for is Îș the What this that the table the described and that that to 2 in the raters are that are and the raters are that be with with or in with each of Îș the in these 2 the of Îș, that such that and or are for the and percentage agreement and Îș for these is the measure for Consider the of the raters in the in this be reliability is might this be the percentage agreement Îș for the in of et The are to indicate the in the and 2 Open table in a new tab A. in the table are with the the pain it to the it to the it to the for these Can you explain why these have percentage agreement you is the the Can you the between the of the in the table and the to Îș percentage the problems with percentage agreement and Îș in these you think it be the in the of each table of reporting the percentage agreement or et al1Cruz C.O. Meshberg E.G. Shofer F.S. et al.Interrater reliability and accuracy of clinicians and trained research assistants performing prospective data collection in emergency department patients with potential acute coronary syndrome.Ann Emerg Med. 2009; 54: 1-7Abstract Full Text Full Text PDF PubMed Scopus (13) Google Scholar contains 2 parts, a comparison of the values gathered by trained research assistants and physicians about historical information in chest pain patients and the comparison of these participants' recordings with a “correct” value for each item.A. For each part, indicate whether the authors are studying reliability or validity and explain the difference between these concepts.B. What did the authors use as their criterion standard for the validity analysis?C. What are potential problems with their method of defining the criterion (gold) standard? Can you think of alternative approaches?D. The authors report crude agreement and interquartile range for their validity analysis. What part of a distribution is described by the interquartile range? List other statistics used to describe the validity of a measure and why they might be preferable to reporting crude agreement.2Tabled 1MD Recorded “Yes”MD Recorded “No”TotalRA recorded yes1176123RA recorded no18220Total1358143MD, Medical doctor; RA, research assistant. Open table in a new tab A. Calculate the crude percentage agreement for this table. What is the range of possible values for percentage agreement?B. Calculate Cohen's Îș for this table. What is the formula for Îș for raters making a binary assessment (eg, yes/no or true/false)? Discuss the purpose of Cohen's Îș, its range, and the interpretations of key values such as –1, 0, and 1.C. What other measures can be used to measure reliability for binary, categorical, and continuous data? 3Cruz et al quote the oft-cited Landis and Koch2Landis J.R. Koch G.C. The measurement of observer agreement for categorical data.Biometrics. 1977; 33: 159-174Crossref PubMed Scopus (49675) Google Scholar article stating that a Îș of “less than 0.2 represents poor agreement; 0.21 to 0.40, fair agreement; 0.41 to 0.60, moderate agreement; 0.61 to 0.80, good agreement; and 0.81 to 1.00, excellent agreement.” Consider studies of the agreement of airline pilots deciding whether it is safe to land and psychologists deciding whether interviewees have type A or type B personalities. the studies the Îș the by Landis and Koch be 2 are in of a and to such as is a a or by a in the for and in the for are and the are to a for each that they percentage agreement is and Îș is of are and are that the is the for a the the this the percentage agreement and Îș for the the of the are and of the are by the of the are and of the are by the the are and of the are by the and of the are and of the are by the Discuss the of percentage agreement and Îș in these Consider the 2 and percentage agreement and Îș for is Îș the What this that the table the described and that that to 2 in the raters are that are and the raters are that be with with or in with each of Îș the in these 2 the of Îș, that such that and or are for the and Calculate percentage agreement and Îș for these is the measure for Consider the of the raters in the in this be reliability is might this be the percentage agreement Îș for the in of et The are to indicate the in the and 2 Open table in a new tab A. in the table are with the the pain it to the it to the it to the for these Can you explain why these have percentage agreement you is the the Can you the between the of the in the table and the to Îș percentage the problems with percentage agreement and Îș in these you think it be the in the of each table of reporting the percentage agreement or et al contains 2 parts, a comparison of the values gathered by trained research assistants and physicians historical information in chest pain and the comparison of these participants' recordings with a “correct” value for each For each part, indicate whether the authors are studying reliability or validity and explain the difference between these part is assessment of and the is assessment of The between reliability and validity is the that the in a that a a The reliability of a to the agreement the the or assessment of validity a observer a or the criterion standard is to be validity studies report the of the observer statistics such as and or reliability such as percentage agreement or What did the authors use as their criterion standard for the validity the and the research it is that their is they a research the of the 2 is What are potential problems with their method of defining the standard? Can you think of alternative a standard for this is For can be 2 the and is For a you have pain in the might that is a for in the is a might that is its the with is the criterion standard for this the the have or the the information The of is that have to the emergency have the of reporting part of a to their and the the a be or the other of the physicians the in a that to the or or in the a the the or are or whether they are to the and the patients be in or to the authors have to the in the research and each and the of to a in accuracy with The authors report crude agreement and interquartile range for their validity analysis. What part of a distribution is described by the interquartile range? List other statistics used to describe the validity of a measure and why they might be preferable to reporting crude interquartile range to the of a of is a that represents the the to the this is the and the the can be by the to the that a distribution the is used to these The is the the the and the the The is the difference between the and is a by than the range of a and it is data are in the of a the and are to and and the the or you the to the and you the or a to in the research and did the authors report the percentage agreement with the “correct” by the criterion agreement is a for a reliability is the to describe this validity assessment of a observer with a criterion that are to a validity report statistics such as and or reliability such as percentage agreement or et al contains 2 parts, a comparison of the values gathered by trained research assistants and physicians historical information in chest pain and the comparison of these participants' recordings with a “correct” value for each For each part, indicate whether the authors are studying reliability or validity and explain the difference between these The part is assessment of and the is assessment of The between reliability and validity is the that the in a that a a The reliability of a to the agreement the the or assessment of validity a observer a or the criterion standard is to be validity studies report the of the observer statistics such as and or reliability such as percentage agreement or What did the authors use as their criterion standard for the validity the and the research it is that their is they a research the of the 2 is What are potential problems with their method of defining the standard? Can you think of alternative a standard for this is For can be 2 the and is For a you have pain in the might that is a for in the is a might that is its the with What is the criterion standard for this the the have or the the information The of is that have to the emergency have the of reporting part of a to their and the the a be or the other of the physicians the in a that to the or or in the a the the or are or whether they are to the and the patients be in or to A the authors have to the in the research and each and the of to a

Open access
Reliability and Agreement in Measurement
Hemodynamic Monitoring and Therapy
Meta-analysis and systematic reviews
Original source
Nov 24, 2009·Journal of Magnetic Resonance Imaging
9 cites
Special issue: Nephrogenic systemic fibrosis

Tim Leiner, Walter Kucharczyk

“Bad times have a scientific value. These are occasions a good learner would not miss” Ralph Waldo Emerson (1803–1882) MRI contrast agents have been routinely used to enhance various structures, organs and lesions in the body for over 20 years now. There is strong evidence that these agents are highly efficacious, and routine clinical practice seems unthinkable without them. Almost all MR contrast agents are based on chelated heavy metals from the lanthanide group of elements, mainly gadolinium (Gd3+). Gadolinium is a rare earth metal that is known to be highly toxic in the free, unchelated form. However, when caged in a chelating molecule (from the Greek “χηλαÎč”, meaning “lobster claw”), gadolinium chelates can be safely administered by means of intravenous injection because the kidneys rapidly excrete them. Since the late 1980s, many toxicological and pharmacokinetics studies have been conducted by the major contrast vendors with various gadolinium-based contrast agents (GBCA). In all of these studies an extremely favorable safety profile was found. Therefore, the recent discovery of the association between administration of GBCA and nephrogenic systemic fibrosis (NSF) came as a surprise to almost everyone involved, although in retrospect maybe we should not have been so surprised. Perhaps after giving GBCA to over 200 million patients and rarely experiencing any adverse effects of any kind, we thought we could administer these drugs with impunity. On the other hand, would we not expect some adverse effects eventually to surface? We were injecting a heavy metal (albeit as a chelate), in ever larger doses, often multiple times, and often in patients with severely compromised renal excretion, knowing that these agents were primarily excreted by the kidneys. NSF is a rare, idiopathic systemic fibrosing disorder and is characterized clinically by pain, dermopathy, and joint contractures. NSF affects the skin, skeletal muscle, esophagus, lungs, heart, and kidneys. The first suggestion of the link between GBCA and NSF by Grobner et al. 3 years ago (1), sparked intense interest in this subject, illustrating just how important MR contrast media are today. It is now clear that NSF is a condition that almost exclusively affects patients with severely limited renal function. However, despite the deluge of publications on this subject—as of October 9, 2009, there were over 438 publications available on PubMed—surprisingly little is known about the exact pathogenesis of the disease, and who exactly is at risk for developing the disease. The discovery of NSF has been unfortunate for patients, and particularly patients with acute or chronic kidney disease (CKD) with severely impaired renal function. Worldwide, regulatory agencies have issued warnings on the use of GBCA in patients with severe CKD, which has led to a virtual cessation of use of contrast-enhanced MRI in this vulnerable patient group. Patients with CKD are a difficult population for the imaging community. MRI has always been and remains of high value in this patient group, because it is well known that administration of iodinated contrast agents is contraindicated, especially in the presence of residual renal function. Because of all the attention NSF has attracted, many clinicians are now ordering CT examinations instead of MRI. Many radiologists have experienced situations in their own practices where contrast-enhanced MRI examinations on their patients have been substituted with contrast-enhanced CT because of fear of NSF with GBCA-MRI only to have these patients go on to develop renal failure due to contrast induced nephropathy (CIN). While the desire to avoid NSF is understandable, care should be taken that contrast-enhanced MRI is not withheld in more patients than absolutely necessary. Paradoxically, the current FDA advice to only give GBCA to patients with estimated glomerular filtration rates (eGFR) greater than 60 mL/min/1.73 m2 may do more harm than good as there is no evidence of NSF occurring in patients with eGFR >30 mL/min/1.73 m2. The FDA guidelines can lead to patients in the eGFR 30–60 mL/min group being exposed to the high risk for negative effects from the administration of iodinated contrast agents, even though they have a negligible risk for development of NSF. Furthermore, whereas the FDA regards all GBCA as having an equal risk for inducing NSF, the FDA guidelines take no account of the chemical structure of the compound, and especially of the kinetic stability, which seems to be an important factor to consider. To date, no unequivocal NSF cases have been reported in patients who exclusively received macrocyclic agents with high kinetic stability, although some reports have suggested this possibility (2) . It is indeed highly likely that there is a relation between GBCA and NSF. The incidence of biopsy-confirmed NSF cases has dropped to nearly zero after the FDA warning and the institution of similar measures by the European Medicines Agency and similar regulatory bodies in other parts of the world. There have been no cases of NSF with onset after August 2008 reported by any of the GBCA vendors. Convincing proof is lacking that NSF can develop without administration of GBCA. NSF only occurs in patients with severe renal impairment (eGFR < 30). The few cases of NSF in cases with eGFR > 30 have been in situations of acute renal failure where the GFR was decreasing rapidly and did not accurately reflect renal excretory function (4, 5). Accumulating evidence suggests that GBCA with low kinetic stability confers a higher risk for NSF (4, 5). No unequivocal NSF cases have been reported after sole administration of GBCA with high kinetic stability. Higher cumulative doses of low kinetic stability GBCA confer a higher risk for NSF in patients with severely impaired renal function (6-8). Risk is relative, not absolute. Not only is the risk of NSF with GBCA-MRI small compared with the risk of CIN with iodinated CT, but also with risk of severe allergic reactions with iodine and allergic reactions with GBCA. The concern about NSF has masked our concerns for GBCA's other potential adverse effects. A survey of major American centers published in 1999 by Murphy et al indicated an incidence of severe allergic reactions to GBCA of approximately 20 cases per million doses administered (9). This is approximately 10-fold greater than the incidence of NSF. And what of the risk of making an incorrect diagnosis because the most appropriate imaging study was not done? Why do some patients with severely impaired renal function get NSF, whereas others, with similar degrees of impairment, do not? In fact, the vast majority of patients with severely impaired renal function do not get NSF, even when administered a high dose of low kinetic stability GBCA. This remains one of the most puzzling questions in the NSF saga. Which patients need to be screened for renal disease, and what is the safest and most cost-effective way to do this? Is a questionnaire sufficient? Or does every patient need to have their creatinine measured before a contrast-enhanced MRI examination can be performed? Or should laboratory screening only apply to certain subgroups of patients? Is the class of macrocyclic GBCA inert regardless of renal function, and can they be administered safely in patients with stage 4 and 5 CKD without causing NSF? At what level of renal function do the risks for NSF outweigh the risk for complications associated with administration of iodinated contrast agents? In other words: Is the newest generation of iodinated contrast agents safe or unsafe in patients with CKD? Can these agents be administered safely? In this special issue of the Journal of Magnetic Resonance Imaging, we present a series of review articles with the aim of summarizing the current knowledge about NSF in relation to administration of GBCA, and to answer some of the questions posed above. The issue begins with a summary of Dr. Jeff Weinreb's excellent keynote lecture as given at the 17th annual meeting of the ISMRM in May of this year (10). Subsequent articles cover a wide variety of related topics, ranging from a basic primer on gadolinium chemistry (11), the role of thermodynamic and kinetic parameters in gadolinium chelate stability (12), the biodistribution of GBCA, including gadolinium deposition (13), and biological effector mechanisms (14-16), to the clinical spectrum of NSF (17), to practical insights on measurement of renal function (18) as well as a review on how to remove gadolinium by dialysis (19). We present current guidelines for injection of GBCA as used in the United States, Canada, Europe (20) and Japan (21). Furthermore, risk factors for NSF are reviewed (22), and NSF is discussed in the context of renovascular (23) and liver disease (24). The issue of relative risk of NSF versus CIN is addressed in the excellent review by Martin and other experts on this topic (25). Finally, retrospective reviews of data from China (26) and the United States (27) confirm the safety of low-dose contrast-enhanced MRI, even in patients with renal impairment. It is our sincere hope that the material selected for this special issue will help with the further understanding of the relationship between the administration of GBCA and the development of NSF, and that the material in this issue will form the basis for further research and subsequent rational choices in patient management that ultimately lead to better clinical care for patients. We hope that by bringing together the most recent insights regarding the pathogenesis and strategies on how to avoid NSF in patients at high risk, contrast-enhanced MRI will again be used whenever indicated, except in that very small number of patients that are truly and significantly at risk. As Emerson eloquently stated: “Bad times have a scientific value. These are occasions a good learner would not miss”. We extend our gratitude to Dr. Leon Partain, Editor-in-Chief, for his support for this project and his insightful suggestions, and to the dedicated and skilled editorial office staff Martha Tanner, Barbara Sammons, and Kerry King. Finally, we would like to thank the contributors, all of whom are highly regarded experts in the field, for their time and effort to create this special issue of the Journal.

Open access
Lanthanide and Transition Metal Complexes
Advanced MRI Techniques and Applications
MRI in cancer diagnosis
Original source
Nov 6, 2009·Clinical Chemistry
11 cites
Adventures in Clinical Chemistry and Proteomics: A Personal Account

Norman G. Anderson

My 90 years have witnessed a basic transformation in the understanding of disease in terms of molecules, largely through the application of new instruments and technologies. The ultimate distillation of what really works at this level—the quantitative measurements that generate clinical insight from specimens like blood—is clinical chemistry. This field has fascinated me for a long time, partly because of my interest in inventing or improving analytical instruments, and partly as an anchor to real-world biology that is frequently missing in academic research. A second thread of interest to me is how successful research gets done, and how to know when a solitary inventor is needed and when it takes an army. Here I recount some personal experiences relevant to these interests, ranging across several fields and in organizations of widely varying scale, all ultimately linked to clinical chemistry and the human proteome. Interdisciplinary R&D has always fascinated me, and my introduction to it occurred in unusual times, during World War II. I was on active duty in the US Navy before Pearl Harbor as a Photographer’s Mate 2nd Class, and was discharged at the war’s end as a Lieutenant (jg) line officer, with zero instruction in between on how to be a naval officer. Despite (or because of) this fortuitous absence of formal tuition, I found that much of the fun and adventure in life lies in the cracks between disciplines, and that these cracks can be wider in large organizations (like a Navy in wartime) than smaller ones. Flying in blimps off the Carolina coast during the height of antisubmarine warfare, it occurred to me that maybe, lacking a bombsight, we couldn’t actually sink a German submarine if we found it. After developing proper instrumentation, I found experimentally this was largely true, and a proper bombsight was developed. This was the start of a series of projects that put together all sorts of technologies, raised interesting questions, and whose results were usually translated into immediate action. Transferred to the Pacific and the submarine service, I worked as a movie photographer on a project to be called “The Silent Service.” This was authorized by a personal letter from Franklin Delano Roosevelt, which proved to be a magical passport to getting things done far from home. As I was shooting background footage of 2 submarines I had arranged to do the required postrefit maneuvers, a radioman came topside to say that Truman had announced use of the atomic bomb. This ended the war and with it my introduction to interdisciplinary work with effectively unlimited resources. Suddenly I found myself at Duke University immersed in the culture of Little Science. I was taught (by a future president of the National Academy of Sciences) that proteins and nucleic acids were too complex to ever be sequenced, that chromatography, while interesting, could never be quantitative, and that no one knew for certain where and how genetic information was stored. The general attitude was very different from the “win at all costs” approach adopted in war—it was painstaking and slow, but it was biology. I began to realize I had been contaminated by the notion of Big Science, but felt I should learn to be comfortable at both ends of the Big Science–Little Science spectrum (1). This pendulum has swung back and forth for me several times, and is an invigorating oscillation. Returning to the Big end, I obtained an Atomic Energy Commission (AEC)1 postdoctoral fellowship in the Biology Division of the Oak Ridge National Laboratory (ORNL). My PhD thesis had concerned subcellular components isolated using very simple centrifuges, and my hope at Oak Ridge was to extend this work to proteins in different subcellular particles using some new type of centrifuges, yet to be conceived. ORNL’s unprecedented facilities, with staffs running into the tens of thousands, included almost all disciplines of science and engineering. Almost anything one could reasonably imagine was either available or could be designed and built quickly, even if it happened to involve nonstandard laboratory supplies like large titanium forgings. The saying, “Why use lead when gold will do?” reflects a little of the flavor. Separation, either physical (as in the case of uranium isotopes) or chemical (as was the case for plutonium), and accurate analysis were the key technologies at most of the Manhattan Project facilities. My initial laboratories were in the same valley that housed more than a thousand giant Calutrons (preparative mass spectrometers) used to enrich kilograms of U-235. After World War II, this facility was used to go straight through the atomic table, isolating and characterizing all the stable isotopes. I wondered if the same sort of effort and philosophy could be adapted to the comfortable field of biology? Could one ever separate the components of living cells into a “parts list” for man? If so, it should provide a powerful way to study and ultimately understand disease. As it happened, the major nuclear weapons laboratories needed new missions after the success of the Manhattan Project. I suggested one in the winter of 1959–60 entitled “The Cell Fractionation Project,” an effort to separate and characterize all the molecules in cells, which much later became the Molecular Anatomy Program. It appealed to nearly everyone at ORNL except my fellow biologists, who did not like big projects (unless it was mouse genetics). We had thought about sequencing DNA but were assured by biochemists that, while RNA could in theory be sequenced, DNA simply could not be for purely chemical reasons (this was before the discovery of restriction enzymes or dideoxy sequencing). So the thinking focused on proteins. Protein fractionation had been advancing on multiple fronts during the preceding decades. In the 1930s and ’40s, Svedberg had developed the analytical ultracentrifuge which showed, unexpectedly, that proteins had well-defined masses, and Tiselius, who once described to me how he had inadvertently left his gardening shoes on when he went to hand out Nobel Prizes, had developed electrophoresis by which plasma proteins could be classified into 4 discrete groups (albumin and the famous α, ÎČ, and Îł globulins). By the mid-1950s, Sober and Peterson had begun to fractionate proteins on cellulose columns, and Waldo Cohn, who had pioneered separating fission products on ion-exchange columns at Oak Ridge, began to work on nucleic acids, convincing Moore and Stein to use ion exchange in place of starch columns for amino acid analysis. Precipitation was explored in parallel by Gerhard Schwick at the Behring Institute in Germany. He isolated dozens of human plasma proteins, made antibodies to them, and distributed these worldwide. This approach with distributable reagents allowed specific protein assays to be performed on clinical samples, thus starting immunodiagnostics on the present road to broad coverage of the human proteome. While largely forgotten in the field of proteomics, this effort has survived through multiple commercial marriages with Hoechst, then Dade Behring, and finally Siemens Diagnostics. My own work really began with the invention of the zonal centrifuge (2) to fractionate subcellular particles. In this device, the volume limitation inherent in swinging bucket gradient separations was surmounted by using large, hollow, bowl-shaped (zonal) rotors. In these, gradients and samples were caused to flow through rotating seals into a rotor spinning at low speed and then accelerated to maximum speed to effect a separation based on either sedimentation rate or isopycnic banding density (or, in later designs, both). This was followed by deceleration to a low speed and recovery of the gradient as isolated fractions by displacement from either the center or the edge. I had designed and built a slow and crude proof-of-principle zonal rotor and then had arranged to have one built commercially, which was unfortunately unstable at high speed. Instability of a large rotor at 40 000 rpm, especially if it leads to catastrophic self-disassembly (a phrase we adopted from Los Alamos, which knew about such things) is undesirable. We needed real engineering expertise in rotating systems, an unusual discipline but one that was by chance very popular at Oak Ridge. Gas centrifugation for uranium enrichment had been tried and abandoned in 1943 because of its high cost. Subsequently it was discovered that a captured German Luftwaffe engineer named Guernot Zippe had designed for the Russians a remarkably simple centrifuge that used very little power and was surprisingly efficient. The need to catch up with this development accounted for the presence of an engineering staff working at top speed (in all meanings of the phrase) in Oak Ridge. The resulting urgency, money, and minimal administration helped as usual to eliminate the curse of delayed gratification, chief destroyer of creativity. We built (and sometimes blew up) a lot of centrifuges, and they became progressively better at separating biological materials. In the early ’60s, Robert Huebner of the National Institute for Allergy and Infectious Diseases and others found that many animal cancers were caused by viruses, especially if the viruses were given to newborns. Numerous groups were set up across the US to attempt to isolate cancer viruses, grow them in culture, test them in primates, and see if a cancer vaccine was possible. When these efforts failed to find culturable human cancer viruses, I suggested to Huebner that we try to isolate them by physical means, using density gradient centrifugation, instead of relying on growth in culture. If this were successful, then similar physical methods could be used for large-scale purification of virus for a vaccine. The US Food and Drug Administration (FDA) was insistent that any killed virus vaccine should contain no (or at least very little) cancer cell DNA to be sure that the vaccine itself did not cause cancer. To make a pure virus vaccine for large-scale human use by physical means would require a liquid centrifuge of a size never before built. Testing these systems required large quantities of virus, and neither Sabin nor Salk, who were very cooperative, had poliovirus in the quantities we needed (milligrams rather than infectious doses). Initially we settled on seawater obtained from the Woods Hole laboratory and discovered to our surprise that the ocean has about the same viral load as a viremic human’s blood (3). For more realistic development, though, we obtained a batch of human viral vaccine that did not meet FDA standards and thus could not be sold. To avoid risk of viral contamination to ORNL’s enormous mouse genetics facility, we relocated the centrifuge development program to the most distant site available on the Oak Ridge reservation, which was, fortunately, right next to the giant Oak Ridge Gaseous Diffusion Plant, locus of the gas centrifuge project. Our “lab” was a mothballed power plant, whose Manhattan Project pedigree was visible on the wall as a framed single-page purchase order for “One coal-fired steam-driven electrical generating plant, 237 megawatt.” It had railroad tracks coming in one end of the 100-yard long main floor and a 30-ton overhead crane for moving large equipment, among other conveniences. We needed a general theory on which to base our search for viruses in tissue homogenates. To see the possibilities of such a separation, I plotted the sedimentation coefficient S against the banding density ρ for viruses and for the major subcellular particles and discovered that viruses generally are found in the middle of this plot in an otherwise thinly populated area away from nuclei, mitochondria, proteins, etc. (4). This plot was key to the whole project, and it suggested that we combine sequentially rate and banding techniques into one 2-dimensional (2D) S–ρ separation. This theoretical plot was converted into a real one in which bacteriophage were recovered from rat liver and other tissue homogenates (5), perhaps the first integrated high-resolution 2D separation in biology. As it became clear that no cancer viruses were being found around which to design a vaccine purification system, I decided that we should work on an existing vaccine that required better purification. We would thus be ready if a human cancer virus was actually found. At that time, egg-grown influenza vaccines contained appreciable amounts of egg proteins, resulting in many deaths from anaphylactic shock each year and the requirement that they be given under close medical supervision. We approached Eli Lilly about designing a centrifugal system specifically to purify influenza vaccine. Their batch size was 100 L, and the purification run had to be completed in an 8-h day. Knowing these parameters and both the sedimentation coefficient and banding density of influenza, it was possible to design a rotor system that used continuous flow to band the virus from 100-L batches in a narrow gradient that could be recovered at the end of a run. The result was the K-II continuous-sample-flow-with-banding ultracentrifuge (6). Use of this centrifuge essentially eliminated vaccination deaths from anaphylactic shock and allowed vaccination in supermarkets under minimal supervision. Almost 40 years later, it is still in use around the world with minimal modifications for vaccine manufacture, and we have recently proposed its use to isolate the viral load from 100-L batches of pooled diagnostic serum discarded in clinical reference laboratories each week (7). The viral DNA and RNA, concentrated and free of host nucleic acids, could then be shotgun-sequenced to screen for new viruses, while providing a running index of the known viruses “going around.” separations of cell components many To specific across these we used from clinical chemistry. I once to had most of the that be some other way to clinical chemistry. He that this was not possible. I thought about this a It was my introduction to clinical and clinical chemistry. The was to a system for between samples and reagents in parallel rather than It out that centrifugal is an way to and liquid while at the of a rotor spinning a provide measurements that very accurate The rate was in that we needed to a like the to it. these in the early was given ORNL’s but we that a a caused no The resulting was named the Energy centrifugal It was a commercial success for and and in many it did to the and it still be the system for very accurate The the rotor of an early centrifugal system At right is a of the system used to and measurements from at the of the spinning in during one of the Despite the success of zonal and the centrifugal the National that human cancer was to viral with interest in me to to the University of I was to be in by my who had completed a PhD at the University of under Nobel and done a with had famous on 2D electrophoresis and had the we set up a laboratory and a research to the most we ever had worked out a which was, of a In a system and the major plasma proteins by with the whole of Behring The of plasma proteins, called was many and Protein on were clear We found the 2D of plasma proteins to be and to an but it was more to a than a clinical 2D plasma and serum from the same The and the and on with This was in of plasma proteins, The plasma and genetic 2nd It became clear that to 2D we needed once the of a National and this with an to the biology at For several we worked in during the week and at on designing together what we called the system for and running large of 2D in parallel Our initial analysis system was an designed to 2 by between them, a used by to the This was by an and large for these we explored the protein called of human as as rat liver and many other We were to host the first 2 major on 2D first at and the second at the both as of (in and The results at these 2D are in some surprisingly similar to the of with the of protein using mass perhaps was before DNA we felt that of all the human proteins by cell fractionation and 2D electrophoresis was the way to in biology the effect that the had in chemistry. This was as the Protein at providing a for and ultimately what is systems biology. an effort would require large and so, with several we suggested of a Protein the general we had in Oak Ridge, to and this who was the of the US at the time, was in research with on and on in his in the on these a Protein was and in a was out the and size of a on the human and a new of much to and more to the the National Laboratory it that study of proteins was to a in the that time, the in biology to the Big Science approach of the National We left in and set up Biology to 2D and protein index and the the years a with in protein and finally a successful initial in the year an 2D electrophoresis system running 100 we explored in rat the of and to the of human a approach we had developed at Oak Ridge we the first columns that the plasma proteins used as the of the system columns with fractionation the of 2D from the most plasma proteins to more than The of mass for protein allowed finally to all the or we had in of and analysis quantitative of in specific protein this I to a in centrifugal systems, developing a large-scale centrifugal for and a centrifuge for viruses from clinical samples, banding them or them in to a plasma This has to and concentrated viruses from serum in about 2 in quantities that the of thus the way and sequencing of human viral it is a little for my own the broad of a approach to understanding the human and it for has recently begun to To start the of a human has the means to the proteins, and perhaps most that are really about of them rather than the 100 000 we were once to the and to on a protein of each this like a to at a or several large-scale are with an effort to the of all the proteins. because is really this is being done at Big Science like the at (in a large The resulting should provide a for understanding and thus the of cell and In and are of a project antibodies to each human and then to see where these proteins are in and success in this a broad for major clinical in will be the to be protein real with clinical to be into A new of mass for is that can ultimately in terms of and while and this it possible to specific assays for proteins starting from a and project to quantitative, and specific assays for all human proteins a of assays in the present protein and even into the clinical laboratory mass is for better of and It to me that this of project, up basic clinical research and clinical chemistry at the same time, is even more than the human and for a of Big Science thinking in the protein If all this to it will a in clinical it at the of biological and at the of clinical would be Atomic Energy Oak Ridge National US Food and Drug Energy Protein Biology initial and they have to the of this and have the to the and of or analysis and of or the for and of the of of any of of The organizations no in the design of of and of or or of I in to the of I have not and I my many and for at Oak Ridge, and through the especially of which extend through his

Open access
Advanced Proteomics Techniques and Applications
Genetics, Bioinformatics, and Biomedical Research
Molecular Biology Techniques and Applications
Original source
Oct 1, 2009·TUbilio (Technical University of Darmstadt)
9 cites
On the Design and Implementation of Efficient Zero-Knowledge Proofs of Knowledge

Endre Bangerter, Stephan Krenn, Ahmad‐Reza Sadeghi, Thomas Schneider · 5 authors

Abstract. Zero-knowledge proofs of knowledge (ZK-PoK) play an important role in many cryptographic applications. Direct anonymous attestation (DAA) and the identity mixer anonymous authentication system are first real world applications using ZK-PoK as building blocks. But although being used for many years now, design and implementation of sound ZK-PoK remains challenging. In fact, there are security flaws in various protocols found in literatur. Especially for non-experts in the field it is often hard to design ZK-PoK, since a unified and easy to use theoretical framework on ZK-PoK is missing. With this paper we overcome important challenges and facilitate the design and implementation of efficient and sound ZK-PoK in practice. First, Camenisch et al. have presented at EUROCRYPT 2009 a first unified and modular theoretical framework for ZK-PoK. This is compelling, but makes use of a rather inefficient 6-move protocol. We extend and improve their framework in terms of efficiency and show how to realize it using efficient 3-move ÎŁ-protocols. Second, we perform an exact security and efficiency analysis for our new protocol and various protocols found in the literature. The analysis yields novel- and perhaps surprising- results and insights. It reveals for instance that using a 2048 bit RSA modulus, as specified in the DAA standard, only guarantees an upper bound on the success probability of a malicious prover between 1/2 4 and 1/2 24. Also, based on that analysis we show how to select the most efficient protocol to realize a given proof goal. Finally, we also provide low-level support to a designer by presenting a compiler realizing our framework and optimization techniques, allowing easy implementation of efficient and sound protocols.

Open access
Cryptography and Data Security
Security and Verification in Computing
Advanced Authentication Protocols Security
Original source
Jul 31, 2009·Bulletin of the Korean Mathematical Society
0 cites
VERIFICATION OF A PAILLIER BASED SHUFFLE USING REPRESENTATIONS OF THE SYMMETRIC GROUP

Soojin Cho, Manpyo Hong

We use an idea of linear representations of the symmetric group to reduce the number of communication rounds in the verification protocol, proposed in Crypto 2005 by Peng et al., of a shuffling. We assume Paillier encryption scheme with which we can apply some known zero-knowledge proofs following the same line of approaches of Peng et al. Incidence matrices of 1-subsets and 2-subsets of a finite set is intensively used for the implementation, and the idea of <TEX>$\lambda$</TEX>-designs is employed for the improvement of the computational complexity.

Open access
Coding theory and cryptography
Cryptographic Implementations and Security
graph theory and CDMA systems
Original source
Jun 1, 2009·Popular Culture Review
0 cites
Return of the Patriarchs: Authority, Gender, and Reason in Post‐9/11 American Cinema

Dan C. Shoemaker

In 1957, in his book Mythologies, Roland Barthes recommended mapping the multiple terrains in which various myths and ideologies were spoken (149). This paper follows in those footsteps by examining a pattern of discourse in American films after the events of September 11, 2001. An analysis of three recent films (and a comparison to a film from an earlier era) will reveal that the timbre of our discourse has modulated toward reliance upon (and valorization of) patriarchal authority, and away from reason. The author's fundamental theoretical assumption is that the relationship between American society and its cultural production is interactive, reciprocal, and mutually informing; films not only reflect society, but help to shape it. Since films are the result of conscious acts of representation and not some automatic process of reflection, films should be taken seriously as ideologically driven acts of speech. Million Dollar Baby won the Academy Award for Best Picture of 2004, as well as Oscars for director Clint Eastwood and lead actress Hilary Swank. The religious right criticized the film for its apparent endorsement of euthanasia, but may have missed the point. Million Dollar Baby is actually a film about then-Secretary of State Donald Rumsfeld and the Bush Administration's doctrine of preemptive war. The film stars Hilary Swank as Maggie, a bootstrapping, working poor waitress determined to make it as a professional boxer. Clint Eastwood stars as gym owner and boxing coach Frankie Dunn, who reluctantly takes Maggie under his wing. The narration by Morgan Freeman's character, Scrap, obscures the dynamics of the story. Maggie is the million dollar baby of the title, but whose baby is she? She is Frankie's. Indeed, the relationship between Frankie and Maggie becomes familial. Frankie has a grown daughter who returns his letters to her unopened and unread. The origin of the rift between Frankie and his daughter is unexplained by the film; the audience is not told what happened, and all we see are after-effects. Getting only one side of the story encourages us to sympathize with Frankie (at least he is trying to get it right, we reason). Before long, Maggie slips into the role of surrogate daughter. Maggie calls Frankie “Boss,” but “Daddy” would be more appropriate. Her relations with her own family are frustrating and are an early clue about the film's conservative ideology. When Maggie wins enough money as a boxer, she buys her mother a house. Instead of being grateful, her mother (Margo Martindale) complains that the acquisition of a home is going to upset her welfare scam. Maggie's family also includes her sister Mardell (Riki Lindhome), an unwed mother, and her brother JD (Marcus Chait), soon to be released from jail. Now, whose stereotypes are these? Maggie's mother and siblings are cartoons of welfare-state parasites, the kind of sly poor folk whom conservatives theorize are sapping our nation of its vigor. Maggie's family is portrayed without a shred of sympathy. We do not feel for their poverty, ignorance, or lack of options; instead, the one-dimensional scripting encourages us to see them as selfish, ungrateful, and criminal. Following the debacle with Maggie's mom is a scene which plays a key part in foreshadowing coming events. Maggie tells Frankie about the time her father euthanized her beloved dog as an act of mercy, and then the pair stop at a diner and have some lemon pie. They bond. Subsequently, Maggie demonstrates her loyalty to Frankie by refusing to abandon him in favor of a more successful manager with better connections. Frankie's key piece of advice to Maggie, which he repeats several times throughout the movie, is this: Always protect yourself. That is the same advice Donald Rumsfeld and the rest of the Bush administration invoked to justify going to war in Iraq: we had to protect ourselves from weapons of mass destruction. Despite the constant reiteration of this advice, Maggie fails to keep her guard up and is clocked by a nasty boxer identified as a former East German prostitute (Trifecta: a figure not only representing two major military enemies of the U.S.A. in the 20th century, but also moral turpitude). After getting sucker-punched by her opponent, Maggie falls, sustaining spinal cord injuries that leave her permanently paralyzed and bedridden. She then requests that Frankie treat her as her father had treated her dog. It is at this point that it becomes clear that the film is about Frankie, and not about Maggie. The balance of the movie is about the difficulty of Frankie's choice. As a Catholic, Frankie thinks mercy killing is a sin. As Maggie's surrogate father, he cannot bear to see her suffer. What, then, to do? Well, thank God our patriarchs are old and wise, and are capable of making the tough decisions. The entire narrative logic of the film endorses the assumption that our elders know what they are doing, and the young do not. Frankie's priest is a younger man, whom Frankie treats mostly with disdain. In a sub-plot of the film, Scrap is called upon to defend Danger, a hapless wannabe boxer who is pummeled by a gym bully. The skilled, older boxer (even when reduced to the status of a janitor) is more than a match for the guileless youth of the bully; in fact, Scrap puts him away with one hand. For her part, Maggie demonstrates that she has finally learned Frankie's lesson about defending herself when she refuses to sign her financial assets over to her parasitic family. In every instance throughout the film, the logic of the narrative supports the idea that the combination of age and male gender confers wisdom. Frankie ultimately decides to end Maggie's suffering. In their last conversation, Frankie tells Maggie that the Gaelic nickname he gave her, Mo Cuishle, means “my darling, my blood.” Family feeling triumphs over religion and law; Frankie knows that euthanasia is illegal, but he does it because he feels it is right. Insert your own joke about Bush administration policies and scandals here. Scrap's narration turns out to be a letter to Frankie's estranged daughter, explaining that Frankie never came back to the gym after ending Maggie's misery. “No matter where he is, I thought you should know what kind of man your father really was,” Scrap concludes. The final image of the film is Frankie back at the diner, presumably having some of that lemon pie. The tone is nostalgic and sentimental. It is an odd chord to strike in a film about senseless tragedy and loss, and it only makes sense if we are supposed to identify with Frankie. This is a textbook example of how hegemony is supposed to work under patriarchy; we are presumed to mistake the patriarch's interests and point of view for our own. While democracy and maturity both involve necessary measures of self-determination in order to be free and responsible, patriarchy requires submission to the dictates of the father-figure. In his book Moral Politics, the cognitive linguist George Lakoff delineates paradigmatic differences in the politics of conservatives and progressives. Lakoff asserts that that the two groups both employ the metaphor of the family to conceptualize and articulate their political positions, but differ in the kind of family they theorize. According to Lakoff, conservatives embrace a Strict Parent model of family. In this model, a Strict Parent is deemed necessary because the world is thought to be a dangerous place, and children therefore need to be disciplined in order to survive the Darwinian ordeal of existence. Any leniency toward or indulgence of children is considered a moral lapse, because it fosters weakness that will ultimately endanger the child. In the Strict Parent paradigm, being strong is the same thing as being moral. Since morality and strength are thought to be the same thing, and since success is proof of strength and fitness for survival, success is also considered a sign of morality. Therefore, failure is a sign of weakness and immorality. The people who succeed or fail do so not because of structural inequalities (such as institutional discrimination against race, class, or gender), but because of their personal characters. Strength of character is formed through children learning self-discipline and self-reliance, qualities which are deemed necessary to succeed in life's harsh contest. These qualities are presumably learned through obedience to the authority of the Strict Parent, usually the father. Since the success or failure of children and (by extension) society is dependent on the discipline of the father, the exercise of parental authority is itself considered moral, justified, and paramount; conversely, threats to that authority are seen as immoral, unjustified, and misguided (Lakoff, 67-84). When the Strict Parent is a father, and when the family metaphor is extended to the whole of society and its institutions, Lakoff's Strict Parent model is a good description of the logic of patriarchy. If Lakoff is correct in his assessment of the Strict Parent model, it goes a long way toward explaining the conservative obsession with fathers and fatherhood. It also helps explain the logic behind the 2005 version of War of the Worlds, in which the solution to the problem of invasion is the restoration of patriarchal authority. The narrator of the classic novel The War of the Worlds is an unnamed character much like the author H.G. Wells himself, a writer with some scientific knowledge. Few of the characters in the novel are given names, and most are referred to by their occupation or station, for example, the curate, the artilleryman, etc. A few chapters detail the exploits of the narrator's brother, a medical student, after the arrival of the Martians (Mac Adam, xxvi-xxvii). The hero of the 1953 film version is atomic scientist Clayton Forrester (Gene Barry) who wants to get a good look at the Martians as much as he wants to escort his love-object Sylvia to safety. Sylvia (Ann Robinson) is a pretty weak movie heroine, even by 1950s standards: she is weepy and hysterical much of the time, and her skill-set seems mostly comprised of serving coffee, square-dancing, cooking breakfast, and driving a school-bus. Obviously, an update of the story would have to entail some changes; the characters would have to be drawn in such a way that contemporary audiences could recognize them as being realistic. The choices made in changing the story to update it for Steven Spielberg's 2005 version are therefore legitimate topics of criticism. Significantly, instead of replacing Sylvia with a modern woman, the character is simply written out of the 2005 remake. There are no adult women characters for the balance of the movie, or women whose actions matter to the resolution of the problem. Any trace of feminism's impact on our culture is erased. What we are offered instead is the story of a father and his children. In the 2005 version of War of the Worlds, the protagonist is Ray Ferrier (Tom Cruise), not a scientist but an Everyman. At the start of the film, we see Ray finish his shift as a longshoreman and race home in his vintage Mustang. Ray is late to pick up his kids from his pregnant ex-wife, Mary Ann (Miranda Otto), and her new husband, Tim (David Alan They have in a new which Ray to as a As the it becomes apparent that Ray is not the is a and he is an on his has no in his and no when he tells his kids to order out for Ray does not know how to with his and does not know how to his daughter even her is The narrative of the film mostly on as a father as he to escort his children to the Martians our The key in the film is or not Ray is good under When the Martians it It may as well While the of the film is an invasion which the audience knows is the of the film is to with the of This is through the of of and destruction. The of is the that when the from their of the of the film is on we see it in his the of the is in and the are the of When the and turns its on the feeling the scene much the of on of people from the of and by the of the The is the by the that Tim and Mary house. This no narrative and does to the but is of the that in on September The of is the of you seen this that Ray and his children with the to the These of were all over in the as the to who may or may not have in the If we of this recent version of War of the Worlds as a that is about that then are a of about the film that are is the of the in to their to the invasion is a to up with the to the to do so is by his who you leave who will protect a that both lack of in does to and a military that is the What is so is that his need not in of having to do but in of having to see the to it. This is in to the (and of who is from what is going on her on two when she is from at the and when Ray her he their children two about War on all those young who the military after to in and those of us on the home who have from or about what has going on because of the as when the a under the of to of war to The thing is the film's of in whose Ray and The character is an of two characters from the the and the discourse that of the artilleryman, but his is to that of the in the the protagonist the when the is on the of their in a to Martians (Mac Adam, In the 1953 film, the is to the character of of the and the What is so about the character and his in the 2005 version is the in which the and characters are and the logic to justify his What are the qualities that make a to Ray and is a and his him as events This is an but one which Ray never no is made to to stop a of with the of his is At with the but he is when the the in which the characters are After and after the Martians upon the of about in the under the and a This is the from the but to it is the that the a nation never an over not only from our own but also from the Significantly, this is one that to in and What is his own to a Ray not only because he is and but because fails to the of their and because the the of the Martians and a These for are to right of the to the war does not the of the world may in be dangerous to our own and is the of old who are on The of Tim as in of that with this conservative logic on a In a with and its logic of family for killing is to protect and his child. Always protect it for the In the film's only a and Tim is presumably to with a look at the look at the war look at or or The film's narrative has Ray to in Mary Ann him for is having the to the military he into is the film's last of This is in that it is the time Ray as and his patriarchal authority. had referred to his father as him to him from a after him had to do so in the narrative as in the film, Ray had to his him by his but his to be called if you your kids to for your authority, them to war. The film's is taken from the of the and also in the 1953 version is the For those with the the invasion of is when the are by the to which have of the has to the between and for example The and A is the with the novel and film version of War of the H.G. Wells some to God for on to defend our from While to God is religion is also the of in the in the figure of the The 1950s film a but the of the Spielberg's version of the film is of God or religion the when God is mostly as the of triumphs over the Martians because has has that is to upon the but not the from this as is from the discourse of is the of The of and by are the from right and The version of by does not involve the or the of our better obedience to the will of God the father and to the as the of as by on God in a film to this author's by written after The film in at a film in and released in the on only a of with its on in of The film released on in of and has since of a in some and about the film's on The story two from and who get into a with some the in calls and to the of the but the are not the an and that God wants them to all that which is so that which is good may and They out to do with the of their a in the The of that the leave behind them is by at the and the to piece the events which the audience as a When he finally that the are out the he decides to help them than from the of the the of the a out of who is only as We are told is a and but one with he would not women or children. for the The when the in and it is a himself, he is their long the with their by an of the and their father. They in a in which their is by who patriarchal authority. The act as George Bush with that God is on their and with that their is There are no or characters in the The we is the who is for and in a scene about the of her The film with on the about the and of as if of morality. the of Bush administration policies the who process if you are you are the right While this author through written after it is that the film Obviously, the Bush administration not and patriarchal were in American culture the events of September What, then, are the of this If patriarchal have through American culture for what right has the author to the of films to the of the administration in and right politics in that we the back to of the film of that to the of the which a of the same In the like The and The work is not considered to be The film version of to the of the follows the of the a and by is as a but but usually right. of the of the film or not is in his right a in (and surrogate to him of In the the is to be a and is as not only but The of to the of the is the has and A scientist thinks the will itself but that the be from the by a The of the film the to the right at the right time to the the to the world are by the of religious will is written the are you that man even in his to not for us to but we If God that man should without a then does he us the will to to the of the but it a in American thought and cultural production that we could Following War in order to American from right and and American culture the of What this from into or an that it be seen in an and personal had to be to and of and that were to the not only the of but also the of the We see this in a of culture from the the of and on and in and some of the of Ray and the culture and both the and While upon his to have his way for much of to the of the his is on scientific and his to him in the In his own actions not through but by the authority of and have two for to authority. is to and is not. In a or the of God is and is for In the scientific are to and The differences between two have for both and American political asserts a logic to that of the people in know what they are they know what they are because they are the people in knows simply because he is the father. In the Strict Parent model by Lakoff, the in authority is presumed to have that through strength of as the authority is justified, and on or even of are presumed to be such logic is at with which free and September 11, the American people were from an The world to which they and The events of that our that the world us because we are the good In such a strong who a and may and the of is in a of requires us to for and to make our on not authority. The of as by and American who to should be as to that were in culture that The films under are not but As and we should be A culture that obedience to authority is not a culture that endorses free or kind of If we do not this lesson of the century, we may well be to some

Open access
Cinema and Media Studies
Contemporary Literature and Criticism
Original source
Apr 1, 2009·Anesthesiology
9 cites
Critical Thinking in Anesthesia

Steven L. Shafer

SCIENTIFICALLY based professionals face the dilemma described by James Oberg, National Aeronautics and Space Administration engineer and space journalist: “You must keep an open mind, but not so open that your brains fall out.”1Startling advances, such as the role of Helicobacter pylori in the etiology of stomach ulcers,2remind us of the need to be receptive to unexpected discoveries that challenge our beliefs.As practitioners of a science-based profession, physicians have a responsibility to patients to (1) critically interpret their medical history, (2) critically read and evaluate the scientific literature, and (3) critically plan their therapy using evidenced-based medicine. How well do we meet this standard?Anesthesiologists are arguably the most experienced practitioners of cardiopulmonary resuscitation. For example, my general anesthetics typically start with a ventilatory arrest (usually by intent), followed by need for cardiovascular support. The 2005 American Heart Association guidelines for cardiopulmonary resuscitation assess the evidence for “best practices” in resuscitation.3Class I recommendations describe interventions that unambiguously improve outcome and should always be provided. These include defibrillation, tracheal intubation, and (remarkably) taping the endotracheal tube. Class IIa recommendations, whose benefits almost always exceed risks, include many widely accepted interventions, such as administering oxygen, confirming carbon dioxide returning from the airway, the use of various airway maintenance devices, proper use of a defibrillator, magnesium for the treatment of torsade de pointes, fibrinolysis for suspected pulmonary embolus, and use of the impedance threshold device to improve recovery.In all probability, you have never heard of the impedance threshold device, also a class IIa recommendation, despite the fact improved outcome has been demonstrated in more than 50 animal and clinical trials of resuscitation. The device is a special valve that attaches to a facemask or advanced airway device (fig. 1). In the absence of a positive-pressure breath, it seals off the airway when the chest recoils during the decompression phase of cardiopulmonary resuscitation, thereby generating more negative pressure in the thorax to draw more blood into the great vessels and heart. This also decreases intracranial pressure. The device doubles cardiac output during cardiopulmonary resuscitation. According to a recent meta-analysis, the impedance threshold device nearly doubled short- and long-term survival after cardiac arrest, at a cost of approximately $99 per unit.The American Heart Association Guidelines characterize epinephrine and amiodarone as class IIb recommendations, meaning that benefit may exceed risk. Lidocaine and atropine are class III recommendations, indicating insufficient evidence. What does it mean that few anesthesiologists have ever used the impedance threshold device, which roughly doubles survival at nominal cost, and has stronger evidence for benefit than epinephrine, amiodarone, lidocaine, and atropine, mainstays of current practice? In my view, it means that we are not as scientifically based in our practice as we would like to believe. Instead, our clinical practice reflects traditions and beliefs instilled during training, which only gradually adapt to scientific progress.As practitioners of a science-based profession, we also have a responsibility to the society in which we live to function as role models for critical thinking. The public is surprisingly naive about the scientific method. How else can one explain the marketing of such unlikely marvels as running your car on water,†a heater that produces more energy than used,‡or curing cancer with magnets?§Consider the following urban legend: A businessman in New Orleans meets a prostitute in a bar. They go to her hotel room, where he blacks out. The next morning he awakens in a bathtub, with a note telling him to call 911. The dispatcher tells him to feel for a tube protruding from his lower back. He finds one, and is told his kidney has been stolen.Clinicians will readily dismiss this story because of the impossibility of performing a donor nephrectomy in a hotel room, and the sheer weirdness of awakening from surgery and anesthesia in a bathtub with a tube in your back. However, the claim has been so widely circulated that the National Kidney Foundation issued a formal repudiation.∄However, when this “innocent” urban myth circulated in South America, there was a 90% decrease in cadaveric kidney donations.4Considering that many individuals waiting for transplants die before receiving a transplant, this “harmless” urban legend may have resulted in significant morbidity and mortality. Ignorance has consequences!You have likely received e-mails promising fortunes in exchange for some nominal effort, such as helping transfer money from Nigeria or contacting an agency that has chosen your e-mail address in a previously unknown lottery. When the victim attempts to procure the money, he or she is instructed to pay increasingly large advance fees to facilitate the transaction. Such transparently bogus schemes net billions of dollars every year from gullible individuals.#Millions of gullible individuals firmly believe in alien abductions, crystal healing, channeling, psychic power, touch therapy, and implausible dietary wonders because they do not have the intellectual tools to evaluate fraudulent claims. More broadly, our political process, our allocation of national resources, our foreign policy, and our stewardship of the planet all suffer from an endemic resistance to think critically as a society. As physicians, we need to lead by example.If we are to be role models of critical thinking, we need to understand how to evaluate claims based on evidence. James Lett, Professor of Anthropology at Indian River Community College, proposed a taxonomy of six essential elements for reasoning from evidence: falsifiability, logic, comprehensiveness, honesty, replicability, and sufficiency (table 1).5Falsifiability refers to whether a claim can be disproved by evidence. If the truth of a claim is completely immune from all evidence against it, the claim cannot be evaluated scientifically. For example, some cultures believe that everything has a spirit, including the rocks, the trees, and even the wind. This belief does not yield any testable predictions. How can you disprove that the wind has a spirit? As these beliefs cannot be proved or disproved from evidence, they are simply beyond the realm of science.A lot of “new age” thinking suffers from lack of falsifiability. Can people really channel their thoughts through crystals? If this leads to testable predictions, then it can be prospectively evaluated. If not, the claim is scientifically meaningless. The same is true for many claims from practitioners of “alternative medicine.” How can one evaluate a treatment that promises to “improve your well-being”? If that cannot be defined, it cannot be tested.Infinite excuses are often used to protect pseudoscientific viewpoints from falsifiability. For example, creation “scientists” hold that God created the earth and its life forms based on literal reading of the Bible. The mountain of evidence for evolution through natural selection, drawn from epidemiology, evolutionary biology, comparative biology, geology, statistical modeling, paleontology, molecular biology, and genetics, including the sequencing of the genomes of many species, is entirely dismissed. Why are dinosaur bones buried in the earth? “God wanted it that way!” Not only is creation “science” devoid of falsifiable propositions, but infinite excuses preclude rational debate about the merits of creationism.Similarly, believers that the earth has been visited by extraterrestrials answer all criticism regarding the complete lack of evidence for extraterrestrial visitation on the basis that the evidence is suppressed by the government. It is all kept under lock and key in Area 51! This permits infinite excuses and prevents falsifiability of the claims. This is the essence of junk science.Logic involves valid methods of inference. Some methods are self-evident. If I say that all dogs have fleas, and Roxy is a dog, it follows that Roxy has fleas. However, if I say that all dogs have fleas, and Roxy has fleas, it does not follow that Roxy is a dog. Roxy could be the neighbor’s kid.Logic can be devilishly confusing. Consider the 1960s television game show Let’s Make a Deal hosted by Monty Hall. This show was based on a stage with three doors. Behind one of the doors was a valuable prize, frequently “Monty’s Cookie Jar” stuffed with money. Behind the other two doors were joke prizes, typically goats. The contestant was instructed to pick one of the doors. Let’s assume the contestant picks door 1.At this point in the show, Monty would typically open one of the two doors not chosen by the contestant, invariably revealing a goat to howls of inexplicable laughter from the audience. (Since Monty knew where the cookie jar was, did they think that Monty would reveal the cookie jar and spoil the game?) Let’s assume that Monty has opened door 3, revealing the goat. Ha ha! At this point the contestant is offered a choice: stay with door 1, the original selection, or switch to door 2. Nearly all contestants chose to stay with door 1.The logic could not be simpler: There are just three doors, and one question: stay or switch? It is remarkably nonobvious that the probability of winning Monty’s Cookie Jar is doubled by switching to door 2. The reason is that in opening door 3, Monty has told the contestant nothing about door 1. There was a one-third probability that this was the correct choice when the choice was made, and there is still a one-third probability after door 3 is opened. There was a two-thirds probability that Monty’s Cookie Jar was behind doors 2 or 3, and that is still the case. However, because there is zero chance that Monty’s Cookie Jar is behind door 3, there is a two-thirds probability that it is behind door 2. Therefore, the probability of winning Monty’s Cookie Jar is doubled by switching.**The same problem has confounded research in psychology for several decades. In studies of cognitive dissonance, a monkey is offered a choice between a red and a blue M&M. Let us assume that the monkey selects red. The monkey is then given a choice between a blue and a green M&M. The monkey is approximately twice as likely to pick green. Assuming that there was a 50:50 chance that the monkey would pick either color, the preference for green was assumed to represent “cognitive dissonance,” psychological angst over the selection of the previously rejected blue M&M. This has been the basis of decades of research in cognitive dissonance.However, there is not a 50:50 chance of the monkey picking a green M&M versus blue M&M. As pointed out by Keith Chen,6this is the Monty Hall problem. Assume that the monkey has a true preference among the three colors. Figure 2shows the six possible preferences. The monkey’s preference for the red M&M over the blue M&M rejects half of the possible preferences, shown as a line through three of the six possible preferences in figure 2. Among the remaining three possible rank orders, green is preferred over blue in two cases, and blue is preferred over green in one case. Therefore, the animal is twice as likely to pick the green M&M as to pick the blue M&M, not 50:50 as was assumed. The Monty Hall and monkey M&M choice problems are striking for the nonobviousness of the correct answer, which is particularly remarkable given the exceedingly simply structure: three doors or three M&Ms.Logic can be distorted by the ambiguity in our language. For example, many would agree that a ham sandwich was better than nothing. It is similarly evident that nothing is better than eternal happiness. If both statements are true, does it not logically follow that a ham sandwich is better than eternal happiness?Logic also involves statistics. Statistics can be thought of has having two flavors: Fisherian and Bayesian. Fisherian statistics involves the of the probability of in a based on of statistics in scientific are The problem with Fisherian statistics is that they are For example, assume you a clinical that does not its but a significant What is the probability that an of the will the at I would have thought that if in the there is a in probability of a significant in a of the However, that is not As pointed out by by is only a probability of a in a to have a 90% probability of the at the in the must be or statistics go to the of (fig. a with an in out the between evidence and a was from in his in his of probability a a to the evidence for the and the which can be as the probability that is true, given that the evidence in is the probability of the true in the the probability of the evidence, if the is true, in the to the probability of the evidence in the can be in the following The probability your after the is based on the probability how likely the was before the were and on the of the that the If a is then it evidence to our thinking. However, if a is evidence support. of example, it would be an claim that a did not ventilatory A this at would not be to this However, the that a 3 was for and is a A in and at would evidence of the of a 3 that not all evidence is the claims in and have more than medical claims in have formal for evidence, such as the evaluate the of clinical a to the of evidence on the probability of the the logic we typically to as clinical If you a with chest you would not a However, the same chest in a would about a This reflects clinical people are not likely to have However, in we have a are more likely to have than are and evidence chest also evidence, such as in the can readily the an claim was were by was because the was that were by This claim was followed by of a of pylori by one of the on to the 2005 in or As we our beliefs about when with the evidence that stomach really were a of pylori of anesthesia is a are so we that a given a of and has an of How likely is it that the is if the to from A to increasingly evidence of For A through the likely is that the is However, it would be to dismiss the evidence in how the it all into the us how to keep an open your brains fall out. scientific is with such that it is immune to evidence. However, claims evidence. For that claim that the earth is the scientific is show evidence to your claim of a The same to claim that the story of creation in is true, claim that can into the and claim to have been by means that the evidence used to evaluate the truth of must be There is a to evidence that with For example, in the a at to were to which of (fig. the was Some did better than and some did In view, more than demonstrated did than was that did than were using their to his He from his he the remaining the was better than evidence of from psychic power, his are a of the of claims to our that the of For example, it is that have been it all the to anesthesia so such are the in and that and anesthesia that general anesthesia is so and that special is the of of anesthesia that permits an that of anesthesia is and means that the evidence must be evaluated It also means that if the evidence you you must your For example, that God all in the the does not molecular biology, and have used to for in the is the of out in at For example, in of the James of the we the a that every out the of a in New out the logic of this that the the of a in New The which that the the of including the and of the and a of other by my a about the of a in then believe one can in of the of and a of the of evidence and his or her In the of The that has not Instead, has on to two more The The which that we would all in and that did not The The which that the extraterrestrials a that a of in a your a scientific which that evidence is a with a based on not based on evidence. The evidence is then and or if it does not the A in the that could be to the of that the of the to a of were from and to the It did not that the scientific evidence of was into and was to be true as a of was in the in the but has never to be a for by most in the The debate over evolution is not out in the scientific literature, because the evidence for does not to the of scientific Instead, the are advanced on the where claims can be the of the following from a a of does not the meaning of the in the we should never the Bible. God just He to and of is is we should never think it to the of creation to be literal with the always means a in the and the and the as literal the is the of we should the of the of by several is an of a The is claims of including the claim that the earth is more than a few are The on to the scientific basis of carbon based on by do not have the of scientific The this does not have the scientific to evaluate the evidence that carbon is the to the does not between evidence and evidence on an that claims the is true and can many to the story in the is by a of the are of evolution against claims of Not in the is the the claims of by of the This was in a and was by the for insufficient scientific the lack of scientific of and the should be in as an to is As by all its to a to evolutionary must critical of including the need to critically assess scientific evidence. all must the of the complete lack of it is to represent as a scientific to which is by a of and scientific is the the in his 2005 in Area is not that on three any one of which is to preclude a that is They are the of by and the of to the same and that creation in the and (3) negative on evolution have been by the scientific is possible that the correct is the If is true after is not the of this This is about reasoning from evidence. A that evidence that does not a beliefs is not has several that are models of by the National of is a for the in the medical and are frequently and either or by The claims of of all political are at by the of at the of the has to be a remarkably for from the of of is a of the scientific method. A is never has his or her how well may be based on or the of and at the of the of significant by in using of and story was the three at and told the American that their in methods and that the of and were with and that the were not the was that the were not the been would be to into with the thinking is by evidence. As we must always our beliefs to the evidence by a we adapt the evidence to with our As in his of the cannot be we to the evidence offered to a claim or The of is on the a told that his a through the followed by a during a in They to and extraterrestrial I believe He is your I can think of of were a joke on his were his were out It not the so it is not to to explain the I is that extraterrestrial visitation is the most of claims and is typically by completely insufficient evidence. As claims I to a of anesthesiologists in an that in his he twice the of by He wanted to I thought of Why should I think not the one a claim of However, I pointed out that his claim of was by the of evidence: from his decades with he was of his from my the evidence was for is a per year by insufficient example, claims to of with and to the the the fact that do not recent for in with a for (fig. the to about the the to the in the In I that the a in which such was does any such great in the of is in our is to never believe based on For example, I on the clinical of I also believe that is a to The of for this claim is on It is an so evidence should However, the fact that I claim that is a better than is not evidence of is that is the an on an that This is an and for evidence. The was that this could to patients after they received for cardiac surgery and they to be and were He his claim with live in a that is with of medical junk and people do not have the to whether people to their in at their and as the same can be by a the face of it to our our scientific and the society in which we live to use critical thinking as a of we are and how we our and and beliefs must be based on critical of because you the the will (fig.

Open access
Epistemology, Ethics, and Metaphysics
Airway Management and Intubation Techniques
Education and Critical Thinking Development
Original source
Mar 18, 2009·arXiv (Cornell University)
0 cites
Generation of a Common Reference String, secure against Quantum Adversaries, and Applications

Ivan Damgaard, Carolin Lunemann

In this paper, we prove classical coin-flipping secure in the presence of quantum adversaries. The proof uses a recent result of Watrous [Wat09] that allows quantum rewinding for protocols of a certain form. We then discuss two applications. First, the combination of coin-flipping with any non-interactive zero-knowledge protocol leads to an easy transformation from non-interactive zero-knowledge to interactive quantum zero-knowledge. Second, we discuss how our protocol can be applied to a recently proposed method for improving the security of quantum protocols [DFL+09], resulting in an implementation without set-up assumptions. Finally, we sketch how to achieve efficient simulation for an extended construction in the common-reference-string model.

Open access
Cryptography and Data Security
Quantum Computing Algorithms and Architecture
Quantum Information and Cryptography
Original source
Feb 4, 2009·Noûs
8 cites
Critical Study of John Hawthorne's Knowledge and Lotteries and Jason Stanley's Knowledge and Practical Interests

Jeremy Fantl, Matthew McGrath

In two important recent books, John Hawthorne and Jason Stanley each argue that non-evidential factors, such as the cost of being wrong and salience of possible error, have a place in epistemological theorizing. This point is familiar from the work of epistemological contextualists, who emphasize non-evidential speaker factors: factors which, when present in a speaker's conversational context, affect the semantic content of her knowledge attributions. According to Hawthorne and Stanley, the appropriate focus is on the subject, rather than the speaker: when the relevant non-evidential factors are present in a subject they can affect whether the subject knows. This suggests a reorientation for epistemology, away from the standard “intellectualist” (Stanley's term) model, endorsed even by contextualists, according to which only evidential or more broadly truth-related factors (evidence, safety, sensitivity, reliability, etc.) bear on whether a subject knows. If Hawthorne and Stanley are right, then the contextualist program should give way to a program of anti-intellectualist invariantism, or to use a more common label, subject-sensitive invariantism (SSI).1 The books explore in insightful and original fashion a range of important issues in epistemology, all focused on the concept of knowledge: the lottery puzzle, skepticism, the knowledge rule of assertion, the relation of knowledge to objective chance, epistemic closure, etc. Here, we limit ourselves to the relative merits of SSI. Stanley claims that the only plausible argument for contextualism is based on intuitions about certain stakes-shifting cases (like Keith DeRose's bank cases and Stewart Cohen's airport case). (84) This is because he takes the contextualist about knowledge attributions to be positing a sort of context-sensitivity which departs significantly from the familiar sorts. He painstakingly backs up this claim in chapters 2 and 3. In chapter 2, ‘know’ is shown not to be a gradable expression (it doesn't admit modifiers and has no associated comparative), and so the assumption that gradable expressions are context-sensitive is no evidence that ‘know’ is. Chapter 3 argues for two general points: first, our use of propositional anaphora (‘what I said’) and speech reports (‘I said that I knew’) doesn't follow the pattern displayed by familiar context-sensitive expressions (like modals, demonstratives, quantifiers, gradable expressions); second, we do not find the sorts of intra-discourse context-shifts that we find with the uncontroversial examples and which we would expect to find given the plausible assumption that context-sensitivity has its source in particular occurrences of elements in logical form.2 Stanley's conclusion is that if the intuitions in the stakes-shifting cases can be explained away adequately without resorting to contextualism, we would have little reason to accept contextualism.3 If Stanley is right about the dialectical situation, the ramifications for epistemology are significant. Contextualists have wanted to argue that, because these cases force us to acknowledge dramatic shifts in epistemic standards across contexts of use, we have good reason to think that even more dramatic shifts could be the source of the appeal of skeptical arguments. Without an independent reason to think that dramatic shifts occur, contextualists have no good answer to the charge that their response of skepticism is ad hoc, the sort of easy response available to solve almost any philosophical puzzle. With all this in mind, here are DeRose's original (1992) bank cases: Bank Case A (Low Stakes). My wife and I are driving home on a Friday afternoon. We plan to stop at the bank on the way home to deposit our paychecks. But as we drive past the bank, we notice that the lines inside are very long, as they often are on Friday afternoons. Although we generally like to deposit our paychecks as soon as possible, it is not especially important in this case that they be deposited right away, so I suggest that we drive straight home and deposit our paychecks on Saturday morning. My wife says, “Maybe the bank won't be open tomorrow. Lots of banks are closed on Saturdays.” I reply, “No, I know it'll be open. I was just there two weeks ago on Saturday. It's open until noon.” Bank Case B (High Stakes). My wife and I drive past the bank on a Friday afternoon, as in Case A, and notice the long lines. I again suggest that we deposit our paychecks on Saturday morning, explaining that I was at the bank on Saturday morning only two weeks ago and discovered that it was open until noon. But in this case, we have just written a very large and important check. If our paychecks are not deposited into our checking account before Monday morning, the important check we wrote will bounce, leaving us in a very bad situation. And, of course, the bank is not open on Sunday. My wife reminds me of these facts. She then says, “Banks do change their hours. Do you know the bank will be open tomorrow?” Remaining as confident as I was before that the bank will be open then, still, I reply, “Well, no. I'd better go in and make sure.” (913) How do these cases support contextualism?4 It seems (premise 1), you speak the truth in both cases. But (premise 2) you have the same evidence and generally the same truth-related factors regarding the proposition in question. Therefore, (conclusion) the sentence ‘I know that the bank will be open on Saturday’ must differ in semantic content in these two contexts of use, due to a difference in content associated with ‘know’: contextualism is true.5 Stanley grants both premises but denies the conclusion. The conclusion follows only on the assumption of intellectualism—only on the assumption that, if the content of ‘I know that the bank is open on Saturday’ is the same in the two cases, a difference in the sentence's truth-value across the cases requires a difference in the evidence for the bank is open on Saturday. But perhaps intellectualism is false: even if ‘I know that the bank will be open on Saturday’ has the same content across the cases, it could be true in one case but false in the other because the practical facts differ. SSI can handle the bank cases just as well as contextualism. DeRose's bank cases are cases of first-person present-tense knowledge attributions in which the attributor is aware of his practical interests. SSI delivers the same results as contextualism for these cases. The same goes for first-person versions of the lottery puzzle. The contextualist says that the sentence ‘I don't know my ticket is a loser’ is true in a context in which the possibility that one wins is salient, even though it wasn't true in a previous context when that possibility wasn't salient (e.g., because, as in Hawthorne's example, one is thinking about whether one will have enough money to go on Safari next year). For the contextualist, the change in truth-value is due to the association of a higher epistemic standard in the later context than in the former, and this association is made possible by the content-shifting power of salience. The SSIist, piggybacking off the contextualist, may say that salience destroys knowledge. When the possibility of your winning wasn't salient, you knew you would lose. Now that it is, you don't know. And the same case could be made for skeptical arguments. The SSIist might say that the salience of the possibility that one is a brain in a vat strips one of much of one's empirical knowledge. These anti-intellectualist manoeuvres incur an explanatory burden, for it is unclear how salience of possible error, or raised practical stakes, could destroy knowledge. But the view does at least match contextualism in its claims about the truth-values of first-person present-tense knowledge attributions and denials. Moreover, the SSIist doesn't make the vindication of our intuitions about cases dependent on delicate use/mention issues, such as the distinction between the question of whether what is said in uttering ‘I know that p’ is true and the question of whether the subject knows that p. It appears, then, that we have a prima facie case for thinking that either contextualism or SSI is true. But which? One consideration that might seem to favor contextualism is the fact that SSI predicts the truth of odd-sounding temporal and modal embeddings. It sounds wrong to say “I don't know that p, but, assuming p is true, I used to know that p,” or “If I didn't have so much at stake, then if p were true, I'd know it was.” But SSIists seem committed to the potential truth of both of these utterances. Is this a reason to favor contextualism over SSI? Stanley suggests (pp. 107–13) that contextualists might find themselves committed to similarly peculiar temporal and modal embeddings, depending on how they explain the source of context-sensitivity. If so, these oddities would be no reason to favor contextualism over SSI. He considers in particular David Lewis's (1996) contextualism, according to which knowledge-ascribing sentences contain a context-sensitive quantifier under semantic analysis. Under Lewis's account, ‘S knows that p’ is true in a context iff ‘S has evidence which rules out all possibilities in which not-p’ is true in the context, with ‘all possibilities’ contextually restricted to those that are not being properly ignored in the context, where attention to a possibility is one way of not being properly ignored. Because the best semantic account of quantifiers holds that they express properties, it would seem that Lewis is committed to thinking that the relevant property is not being properly ignored by A, where A is the attributor. But then we should expect that a sentence such as ‘If A were properly ignoring more possibilities than he is, S would know that p, if p were true’ to be acceptable, which of course it isn't. We have a reservation about Stanley's argument. Consider his example of ‘every bottle’. In a context of use, this expresses a property, e.g., being a bottle on such and such shelf. Which property it expresses depends on what is salient to the attributor or conversational participants, but the property expressed itself is not about salience to a certain attributor. Thus, ‘John bought every bottle but wouldn't have if I had been thinking about a different grocery store’ won't come out true. Similarly, it seemed to us that one could revamp Lewis's view by proposing that which property ‘all possibilities’ expresses in a context of use depends on what the attributor is properly ignoring but the property expressed isn't itself about the attributor and his ignorings. So, perhaps SSI is committed to the peculiar sounding embeddings in a way that contextualism isn't. Nonetheless, there are ways to soften the blow. As Hawthorne (177n.40) remarks, anyone who thinks barn façade cases are Gettier cases must say that in many cases in which you look at a barn it is true to say, “I know that's a barn, but if unbeknownst to me there were a lot of barn facades around then even if this one was a barn I wouldn't know it was.” The defeasibility of knowledge, too, generates odd-sounding predictions like this: “I don't know that Mary is sick, now that her boyfriend told me she was faking it, but if he is misleading me, then if he hadn't told me anything, I would know (having seen her coughing earlier today).” If we can live with these embeddings, perhaps we can live with SSI's temporal and modal embeddings as well. SSIists, however, must further part company with contextualists on third person knowledge attributions. When Mary and John, whose evidence is the same as Smith's, utter not only ‘We don't know’ but also ‘And neither does Smith,’ the intellectualist contextualist will say that Mary and John speak the truth about Smith if they speak the truth about themselves. The SSIist will of course have to insist that this move is in general illicit, because, e.g., less might be at stake for Smith than for Mary and John or fewer counterpossibilities of error salient to him. Yet we seem to make this move on a regular basis. It would be very odd for Mary and John to wonder, “We don't know whether the plane stops in Chicago, but if it does, then Smith knows it does.” The SSIist has to explain away mistakes about third-person knowledge attributions and denials. Keith DeRose (2004) has called this the problem with SSI. Hawthorne and Stanley are well aware of it, and propose their own solutions. The core idea behind both proposals, spelled out most clearly in Stanley (who is trying to improve upon Hawthorne's account (see pp. 162–66)), is that we treat others as if they were in our situation, having our stakes (or finding salient possibilities we find salient). Stanley puts it this way: our real aim is to deny that if they were in our situation they'd know. Indeed, they wouldn't. But what is strictly said, that they don't know, is false. (101–4) This proposal is committed to an error theory about some of our knowledge attributions. But, as Hawthorne and Stanley would be quick to point out, contextualism has a similar problem because as we noted above, contextualists place heavy weight on the use/mention distinction. Mary and John are happy to assert not only ‘Smith doesn't know’ but ‘What Smith said is false. He doesn't know any more than we do.’ Equally worrisome, Stanley notes that contextualists have to strain, more than SSIists, to accommodate intuitions about other third person cases—cases in which the attributor has lower stakes than the subject. Stanley calls such cases Low Attributor-High Stakes and claims that contextualism delivers the wrong result about them. Intuitively, Stanley claims, the speaker's attribution of knowledge to the subject is false, whereas contextualism predicts its truth. Contextualism in his view also than SSI in certain person cases, such as Stakes which a subject thinks her stakes are but they are He that the weight of the versions of the stakes-shifting SSI over contextualism. does not that contextualism is false. Therefore, there is a way to accommodate without Stanley's intuitions about all the versions of the stakes cases, by for a contextualist of it is part of the for knowledge attributions that that p’ only when the subject is to as if p in of the So, when a attributor says of a subject knows that p,” the attributor that intellectualist contextualism, it will have to to This takes of all but the subject has stakes, but we have the the attributor when she says, doesn't know that handle this case, we the contextualist when one's stakes that one a certain standard to know, in one's speech context associated with having an epistemic that at least that so that if a subject doesn't it with to p, the subject doesn't with to p in one's speech possibility for all the stakes-shifting cases is to with a view which would also have the over contextualism that it doesn't different intuitions depending on whether the say or he said is rather than doesn't The possibility of these of up the to the epistemological question of whether intellectualism is true from both the semantic question of whether knowledge-ascribing sentences in content across contexts of use and the question of whether knowledge-ascribing can only be true relative to an (e.g., a or an epistemic Stanley is right that intellectualism is a for contextualism for in the of stakes-shifting cases. As Stewart in contextualist from his case of Smith and Mary and John, what is in the is a good enough reason for Smith to know, then it is a good enough reason for John and Mary to But there is no reason an anti-intellectualist to semantic or are to accommodate intuitions such as those in the cases. the are as as we know no one is on as they do the cases. these we are with intellectualist contextualism and each of which is committed to error about our to some of the cases at has to to accommodate those It will seem to some that all this and in the is an Consider what Hawthorne calls This is intellectualist invariantism with the claim that the standards for knowledge are enough so that a many of our knowledge claims are in fact true. it is that contextualism and SSI are committed to error of their own about the versions of the bank cases, there is now no from consideration of those cases, to invariantism just because it requires its own error theory to handle we to the invariantism, is a reason to that knowledge, or even is to salience or practical in the such factors are not truth-related or the used in standard Gettier misleading into the at we little in salience of possible error as a subject seems to us to be no other than the to the cases, to a between knowledge and salience of possible The situation is more for knowledge and This is the of our Hawthorne us to the are a for a lottery ticket that cost a in a ticket lottery with a and reason as I will the If I the ticket I will If I the I will a I to the This he claims, is The is that you don't know the is true. this lottery case to Hawthorne's A or so you bought a lottery ticket in a ticket the in a at I won't have enough money to go on Safari next the less as to the This is In Hawthorne's because you know the is true. like these are used to support Hawthorne's one is to use p as a in practical if and only if one knows that Hawthorne that it is to give the the difference between the and the other the lottery is that in the case the for the subject that he will is enough so as to be to the practical issues at he can the epistemic that is This knowledge out in favor of a about you can use p in practical just in case the that p is false is just in case it can be in your practical this the If this is so we give in and accept Hawthorne's is to appeal to the according to which that p is and for having epistemic or for being or for there being no epistemic for the subject that the epistemic of is the same in both cases or If it is the then by the you don't know that you will in the you don't know, in the lottery case, that you will the But if you don't that, then by you don't know that you won't have enough money to go on But the seems to be a of knowledge. Thus, Hawthorne that if the epistemic of is the same in the two cases, then skepticism So, skepticism the for you of winning between the cases, and so by the the two cases differ with to your knowledge that your ticket will lose. It follows that practical can affect knowledge in the way We can think of two ways to to Hawthorne's argument. one might argue that you know in the case isn't to in the case you do have a lottery and might be have a reason to think you might have enough money to go on Safari next In response Hawthorne (pp. argues that lottery cases can be at will for just about any of our claims to knowledge. If so, then there is about the case, because there is about the of that is a lottery one might question the We with this are the relevant to between If your epistemic for p is then, it should follow that you would be to accept a on p at any But you wouldn't be to do this for very many doesn't think he would on the of at any Thus, the seems to One can to this as Hawthorne does, by intellectualism about epistemic and so that how a proposition is for a person can with practical This seems to us If you me a on the proposition this will come up that doesn't seem to lower its and not to the that it will come up us the Is there any other reason to knowledge into the of certain of practical are and others not just on the If you an when a for his lottery he isn't to it, he will you that he doesn't know that the ticket will lose. If you the same in the he the rather than the given that he of on he will answer that he knows he won't have enough money to go on seem to knowledge its to their As Stanley A standard use of knowledge attributions is to When I I to the on the rather than the on the right, I will by that I knew that the on the had the I but I not know whether the on the right When my wife me I rather than I that I knew that it was the to go to the If we could have a view that knowledge relevant but doesn't us to the this might seem to just the right And it such a view is We can claim that knowledge is with a epistemic of error but only an This view at least the of Hawthorne's will of course to the Stanley as having rather than semantic The idea would be that there are cases in which one knows but isn't to on it, that one knows often or at least in some way that one is to on it Stanley is well aware of this and a to come up with a We that it is not easy to give such a (see our but we that he shifts the of As we above, many in our view will insist that intellectualism is a cost than positing or intellectualism us to the claim that you can or knowledge, not by or by but by or up a large check. And that seems Is there a more argument available for a When it to would deny that when can be to other It does not follow from the fact that your is even from the fact that you that you have a reason to that your won't But you know that your is you have an reason to that your won't that your is So, when it to we do to say that, when you know that p, p can be your your for course, when you know that p, p can to be your for some for the very reason that p has to do with if you know that your is that it is is not a reason you have for that is from the than But its to be a reason you in this case, is not the result of the for you that your is not the result of any other epistemic you have with to the proposition that your is When you know that p, in the for you that doesn't in the way of p being a reason you have for We can say very similar about the very there are facts such that, when you know to be true, they can be you have to do The fact that your will be by a which is the you and in the next seems to be such a that the of this fact would not that you have any reason to your (having no idea of the situation, you would be it in on the with your would your in it if be enough if that itself were not But if you know this then you do have a reason to your This is a of the situation. As with the situation, when you know that p, p might to be a reason you have for but not because of any epistemic of with to because for example, the for you that might know that your is But this is not a reason you have to your out of the way of an its to be a reason you have is not due to any epistemic with to the proposition that your is seems little to the practical and the cases in the way by the If the that doesn't in the way of p being a reason you have for for any then the that doesn't in the way of p being a reason you have for A, for any This other of the fact that, when we that p in the course of about what to we don't then p off from our about what to When we p, we can use p. But, noted that, when you know that p, then the that doesn't in the way of p being a reason you have for in with the a general not those by and more in a by Hawthorne and Stanley If you know that p, then the that doesn't in the way of p being a reason you have for or a problem for intellectualism if there are of for the that is the but are such that the that in the way of p being a reason one has but not the Consider again the airport Smith and Mary and John are with to the that the plane stops in According to the Smith and Mary and John all know that the plane stops in the that the plane doesn't stop in doesn't in the way of it being a reason they have say, In case, at For Mary and John, there is. and the assumption that Mary and John have knowledge, Mary and John have an reason not to checking with the a of the case is so that they should check with the given all that is at So, the had better not Mary and reason to just go and to Mary and John in just and How might the that the plane stops in is a reason that Mary and John have to the that, even if they have a very good reason to in their reason is by some other reason they The A proposition about the of error with the of the relevant or to use the a proposition to the that checking further A general intellectualist then, for is to make a first, having to do with of error can with about what is in fact the case and second, when the stakes are about of error can out about what is in fact the This is For this would seem to the sort of the one the plane stops the other it might And if it doesn't it the are I'd better check further to it stops in it This is not what we do when we we we do when we is the at and which is more the one the other Which is more the good or the that both that we don't facts the that those facts don't if we were facts would the one the plane is to the other it might not Which is more the fact that it is, or the that it In the intellectualist what seems to be a about having When you have a reason to or about when you have a reason to to that reason for in whether to This is not to say that, you have a reason to you should But it is to say that, when you have that you to it into with other you have without the relative of those In this you have are might not have as that it will that you will have to for the If you do then when whether to your you might have to the that it will how long you think have to for the if you have both as then you can use both in your without their to and have to So, to if I don't the Because this off the intellectualist there is us from on the of that if knowledge is with a of error, then knowledge can come and go with in the practical If Hawthorne's is false, so is

Open access
Epistemology, Ethics, and Metaphysics
Philosophy and Theoretical Science
Philosophy and History of Science
Original source
Jan 1, 2009·Duo Research Archive (University of Oslo)
0 cites
A Comparison of Observers for Estimation of the Bottomhole Pressure.

Eirik Nyland Opsanger

New offshore oil recourses that are developed are more difficult to drill and increase the requirements to the technology in the offshore industry. A relatively new technology is Managed Pressure Drilling where a choke topside is used to control the bottom hole pressure. The bottom hole pressure measurement is unreliable, which motivates the need for an observer. Different methods for estimation will be presented and compared in this thesis. Proofs of convergence are outlined for the Stamnes observer, derived for the Grip observer and some stepping stones for further work are presented for the Optimal Polynomial Filter. Each observer is simulated with a simple step in the mud pump to verify the estimation laws. The results show that all observes estimated the bottom hole pressure correctly for this simple case. A more realistic case, a pipe connection, is also simulated for each observer. The case includes zero flow from the mud pump, which reveals that all observers miss the estimation convergence in this case, but that the estimate converges when there is flow from the mud pump. One of the states that affects the bottom hole pressure is the pressure loss due to friction in drill string and annulus. Earlier work modeled these losses as quadratic with respect to the flow through the bit, which are simplifications. To improve the estimate of the bottom hole pressure, new and better friction models are needed. Measurement data from Gullfaks C are analyzed to get new knowledge of friction loss in the drilling string and annulus. For the drill string the quadratic friction model is found to be good enough, catching the main behavior. On the other hand, the friction loss in the annulus is a more complicated function of flow. The annulus friction is approximated with sets of basis functions and the weighted sum of these functions gives an approximation to the friction curve. Each weight is estimated to get the friction loss estimate. The use of the weighted sum of four 1st-order b-spline functions give a good approximation to the real friction curve, and the weight for each basis function is estimated. This is tested in simulations both with a simple case and the pipe connection case. The simulations show that the annulus friction loss and the bit pressure are estimated correctly.

Open access
Hydraulic and Pneumatic Systems
Oil and Gas Production Techniques
Drilling and Well Engineering
Original source
Jan 1, 2009
0 cites
Sound and Fine-grain Specification of Ideal Functionalities

Juan A. Garay, Aggelos Kiayias, Hong-Sheng Zhou

Nowadays it is widely accepted to formulate the security of a protocol carrying out a given task via the "trusted-party paradigm," where the protocol execution is compared with an ideal process where the outputs are computed by a trusted party that sees all the inputs. A protocol is said to securely carry out a given task if running the protocol with a realistic adversary amounts to "emulating" the ideal process with the appropriate trusted party. In the Universal Composability (UC) framework the program run by the trusted party is called an ideal functionality. While this simulation-based security formulation provides strong security guarantees, its usefulness is contingent on the properties and correct specification of the ideal functionality, which, as demonstrated in recent years by the coexistence of complex, multiple functionalities for the same task as well as by their "unstable" nature, does not seem to be an easy task. In this paper we address this problem, by introducing a general methodology for the sound specification of ideal functionalities. First, we introduce the class of canonical ideal functionalities for a cryptographic task, which unifies the syntactic specification of a large class of cryptographic tasks under the same basic template functionality. Furthermore, this representation enables the isolation of the individual properties of a cryptographic task as separate members of the corresponding class. By endowing the class of canonical functionalities with an algebraic structure we are able to combine basic functionalities to a single final canonical functionality for a given task. Effectively, this puts forth a bottom-up approach for the specification of ideal functionalities: first one defines a set of basic constituent functionalities for the task at hand, and then combines them into a single ideal functionality taking advantage of the algebraic structure. In our framework, the constituent functionalities of a task can be derived either directly or, following a translation strategy we introduce, from existing game-based definitions; such definitions have in many cases captured desired individual properties of cryptographic tasks, albeit in less adversarial settings than universal composition. Our translation methodology entails a sequence of steps that derive a corresponding canonical functionality given a game-based definition. In this way, we obtain a well-defined mapping of game-based security properties to their corresponding UC counterparts. Finally, we demonstrate the power of our approach by applying our methodology to a variety of basic cryptographic tasks, including commitments, digital signatures, zero-knowledge proofs, and oblivious transfer. While in some cases our derived canonical functionalities are equivalent to existing formulations, thus attesting to the validity of our approach, in others they differ, enabling us to "debug" previous definitions and pinpoint their shortcomings.

Open access
Security and Verification in Computing
Cryptography and Data Security
Cryptographic Implementations and Security
Original source
Jan 1, 2009·Communications in computer and information science
4 cites
Escrowed Deniable Identification Schemes

Pairat Thorncharoensri, Qiong Huang, Willy Susilo, Man Ho Au · 6 authors

No abstract is available for this record.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
Security in Wireless Sensor Networks
Original source
Jan 1, 2009·Lecture notes in computer science
22 cites
Quantum-Secure Coin-Flipping and Applications

Ivan DamgÄrd, Carolin Lunemann

In this paper, we prove classical coin-flipping secure in the presence of quantum adversaries. The proof uses a recent result of Watrous [Wat09] that allows quantum rewinding for protocols of a certain form. We then discuss two applications. First, the combination of coin-flipping with any non-interactive zero-knowledge protocol leads to an easy transformation from non-interactive zero-knowledge to interactive quantum zero-knowledge. Second, we discuss how our protocol can be applied to a recently proposed method for improving the security of quantum protocols [DFL+09], resulting in an implementation without set-up assumptions. Finally, we sketch how to achieve efficient simulation for an extended construction in the common-reference-string model.

Open access
2 source records
Quantum Information and Cryptography
Cryptography and Data Security
Quantum Computing Algorithms and Architecture
Original source
Jan 1, 2009·Research Online (University of Wollongong)
6 cites
Contribution to privacy-preserving cryptographic techniques

Man Ho Au

Digital signatures are fundamental cryptographic primitives. They are useful as a stand-alone application and building blocks of complex cryptographic systems. Accumulators are another useful cryptographic primitive which provide a way to combine a set of values into one short value. They are useful in improving efficiency of cryptographic systems. In particular, these two primitives are key components in privacy-preserving cryptographic systems. In this thesis, we study the use of digital signatures and accumulators in cryptographic applications. We design digital signature schemes and accumulators with different features that are suitable for a wide range of applications. We are interested in privacy-preserving cryptographic applications including anonymous electronic cash systems, anonymous authentication schemes and anonymous credential systems. We construct three different digital signature schemes, each with distinctive features. We also propose two novel constructions of accumulators. Based on our signature schemes and accumulators, we design two compact electronic cash schemes and a divisible electronic cash scheme. All our schemes are truly anonymous, meaning that privacy of the users is well-protected. We also explore other applications of our newly proposed signatures and accumulators. Specifically, we give a construction of k-times anonymous authentication schemes and attribute-based anonymous credential systems. During the course of the development of the thesis, we generalise existing techniques of zero-knowledge proof-of-knowledge protocol of double-discrete logarithms into zero-knowledge proof-of-knowledge protocol of representation of a committed value. Our protocol is compatible with existing zero-knowledge proof-of-knowledge protocols that demonstrate relationship amongst discrete logarithms. We believe that this protocol, together with the newly introduced primitives, are of independent interest.

Open access
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
Jan 1, 2009·Lecture notes in computer science
8 cites
Verifiable Rotation of Homomorphic Encryptions

Sebastiaan de Hoogh, Berry Schoenmakers, Boris Ć korić, JosĂ© Villegas

No abstract is available for this record.

Open access
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Chaos-based Image/Signal Encryption
Original source