Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results · page 167 of 177

Clear filters
Jul 8, 2008·International Journal of Andrology
13 cites
Misanalysis gave false association of mtDNA mutations with infertility

Hans‐Jürgen Bandelt

Dear Sir, In science, it is not surprising to have exciting claims later refuted by hard evidence – although it may even be harder to have them corrected in the same journal where they originally appeared (Don't challenge a winning paper: Bär, 2006). One of the main reasons why false claims could pass through peer reviewing and eventually appear in print is (i) limited knowledge about certain genetic markers in a newly emerging field at the time of submission or (ii) insufficient screening of the published data for comparison and (iii) inadvertent documentation and analysis of the novel data underlying such claims. It may then take some years before the true causes for a particular finding would come to light. This apparently applies to the remarkable claim made by Holyoake et al. (2001) that the mitochondrial DNA (mtDNA) mutations G9055A and G11719A would compromise the semen quality of those men who possess any of these mutations in their mtDNAs (leading to reduced sperm motility and/or low sperm count). This study won the 2nd Prize of the European Academy of Andrology in 2001 – a winning paper, thus. The results of this study were aptly challenged by Montiel-Sosa et al. (2002), who (i) pointed to the fact that site 11719 determines a basal European mtDNA haplogroup (nowadays referred to R0), (ii) hinted at the peculiar frequency of the 11719 polymorphism as reported by Holyoake et al. (2001), and (iii) argued that ethnic origins of samples in a mixed population would matter and that 'the control and low sperm motility group could be non-homogenous'. Indeed, no reference to haplogroups, constituting the major branches of the mtDNA phylogeny, was made in the study by Holyoake et al. (2001), although it was submitted at a time (September 2000) where the role of the two particular (G9055A and G11719A) and other mutations was already quite well understood. Holyoake et al. (2002) in their reply to Montiel-Sosa et al. (2002) emphasized that they were only 'interested in single nucleotide substitutions in relationship to poor semen quality'. This popular 'allelic' approach gleaned from the analysis of the nuclear genome, however, is patently unsuitable for a deeply hierarchical genetic system such as mtDNA. First, the allelic view ignores the tight link between different mutations in the mtDNA phylogeny (as between G9055A and G11719A). Clusters of mutations would show up together and could then not serve as independent indicators of a disease phenotype. Second, disregard for the mtDNA phylogeny leaves out the option of phylogenetic proof-reading of obtained mtDNA results in regard to potential errors (Bandelt et al., 2005a). Not unexpectedly, the detailed haplogroup analysis of Pereira et al. (2005) for a large Portuguese sample did not support the notion that men carrying an mtDNA from a specific haplogroup overall had an increased or a reduced risk of infertility. These authors also warned that the observation by Ruiz-Pesini et al. (2000) that 'haplogroups H and K are significantly more abundant in nonasthenozoospermic and asthenozoospermic populations, respectively' may have been caused by population stratification. As long as patients and controls are not controlled for ethnic background, geographical matrilineal ancestry and social stratum (which certainly matters in countries with a considerable record of recent immigration), mere correlation of a mutation/haplogroup with a disease phenotype may be spurious and thus cannot provide sufficient evidence for an association. The complete mtDNA data of Ingman et al. (2000) as well as the RFLP-based analysis of West Eurasian mtDNAs of Macaulay et al. (1999) would have provided the necessary background information for the SSCP analysis aimed at by Holyoake et al. (2001). Curiously, the Ingman et al. (2000) study was referred to in a later article (Gemmell & Sin, 2002) by the same senior author (F. Y. T. Sin), but apparently without reappraising the findings of his former paper. If the data by Ingman et al. (2000) had been inspected at the time, then it would have become clear that the frequencies of the mutations observed by Holyoake et al. (2001) are mutually inconsistent and thus cannot realistically correspond to real-world data. To see this, take a preview of the worldwide mtDNA phylogeny as seen from the early Ingman et al. (2000) data, but now enriched with the up-to-date information about the nesting of the corresponding haplogroups, as displayed in Figure 1 of Bandelt et al. (2006). Nucleotide A at site 8860 is shared by virtually all mtDNAs worldwide that are not closest relatives of the revised Cambridge reference sequence (rCRS; Andrews et al., 1999). In Table 3 of Holyoake et al. (2001) the frequencies are recorded as 2/102 and 1/59 instead of the expected frequency of (nearly) 100%! The other frequencies in that table do not fare much better. Virtually all mtDNAs not belonging to the basal West Eurasian haplogroup R0 (which encompasses the sister haplogroups R0a and HV) bear the characteristic mutation G11719A. Assuming the frequency for this mutation in 'normozoospermic' men reported by Holyoake et al. (2001), one would be forced to conclude that all 80 control mtDNAs are members of haplogroup R0 (Table 1). Such a population sample has never been observed anywhere in the world. Moreover, this zero frequency is at odds with the other mutation frequencies recorded, as there is evidence that the other two basal West Eurasian haplogroups, JT and U (including K), were observed in both, the 'normozoospermic' and the 'subnormozoospermic' men (Table 1). The two frequencies of G11719A, on their own, are thus far apart from any realistic value, indicating that the recognition of G11719A via SSCP analysis must have been strongly hampered by technical problems. There is, by the way, little evidence that Polynesian mtDNAs played a noticeable role, because the vast majority of them would fall into a specific branch of haplogroup B. This haplogroup would be pinpointed by the 9 base-pair (bp) deletion, which, however, was found at a meagre 2.8% in the total sample. Note that the 9-bp deletion is also seen sporadically on many haplogroup backgrounds other than B. Furthermore, potential Sub-Saharan African mtDNA mutations (possibly C7789A) or (South-)East Asian mtDNA mutations (possibly G7853A) are present (if at all) at similarly minor frequencies; thus, in particular, the suggestion of considerable African mtDNA ancestry (Montiel-Sosa et al., 2002) receives no support from the data. Therefore, the vast majority (perhaps >95%) of mtDNAs analysed by Holyoake et al. (2001) must have been of European descent. Table 4 of Holyoake et al. (2001), which provides the full haplotype information, indicates further problems. Mutations that would be expected to be linked with other mutations in view of the above inequalities are not just absent but show up in unexpected combinations, almost random-like, which would rather suggest sample mix-up. Moreover, the haplogroup K mutation G9055A should always entail the mutation G11719A specific to non-R0 lineages, but according to that table, both mutations are rather unlinked. In the present Table 2, some haplotypes from Table 4 of Holyoake et al. (2001) are listed that combine at least two mutations. In three cases, all from the 'subnormozoospermic' group, one observes potentially mosaic patterns (Table 2). The best explanation for the odd frequency spectrum as well as the incomplete and mosaic haplotypes is, in the first place, massive failure of the SSCP analysis carried out by Holyoake et al. (2001). Such a mis-analysis is not an infrequent phenomenon in medical genetics (see e.g. Bandelt et al., 2005b). But why would have 'subnormozoospermia' triumphed over 'normozoospermia' e.g. in the screening of G11719A? And why would the 11719 polymorphism, if deemed crucial for 'subnormozoospermia', have only been analysed in a meagre 33 instead of, say, 131 patients? And what about G9055A? A normal mtDNA sample of predominantly mixed European descent would hardly show so few (<1%) haplogroup K members (Behar et al., 2006). The consistent trend in identifying mutations at frequencies that are far too low, especially for the 'normozoospermic' group, could suggest that the SSCP analysis was biased and effectively carried out only for a minority of the samples. It then seems that the number of fully screened mtDNAs was smaller for the 'normozoospermic' group than for the 'subnormozoospermic' group. In summary, there is no solid evidence that primary mtDNA substitutions other than recognized pathogenic mutations, mainly in heteroplasmic state, which usually cause complex disease phenotypes, influence sperm motility in any way. Therefore, it would be premature to accept all hypotheses and interpretations put forward by Gemmell & Sin (2002) and St. John et al. (2005), who took the results of Ruiz-Pesini et al. (2000) and Holyoake et al. (2001) at face value. Before far-reaching implications are discussed, the underlying data should come under scrutiny first. It would certainly be desirable to re-study the mtDNA samples employed by Holyoake et al. (2001) by performing highest quality sequencing. In any case, there is an urgent need for a new start of mtDNA analysis of samples from men with idiopathic infertility (or subfertility) by complete mtDNA sequencing in order to provide a solid database to which any subsequent case studies could get compared and evaluated. The most recent work of Pereira et al. (2007) is a promising first step in this direction.

Open access
Metabolism and Genetic Disorders
Mitochondrial Function and Pathology
Forensic and Genetic Research
Original source
Jun 12, 2008·Mathematical and Computer Modelling
55 cites
Prêt à Voter with Paillier encryption

Peter Y. A. Ryan

No abstract is available for this record.

Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Original source
May 10, 2008·European Journal of Echocardiography
3 cites
Contrast agents for echocardiographic studies within 24 h after myocardial infarction

Harald Becher

In April 2008, the US Food and Drug Administration (FDA) performed a safety review of the US-approved perflutren microsphere contrast agents (Definity and Optison) and revised a previous black box warning. The new contraindications are much less restrictive than the previous contraindications and satisfy the needs of clinical echocardiography. These changes have come after an intensive debate with the American Society of Echocardiography but also with significant European support. The correction of the contraindication for contrast agents is a good example, how inadequate decisions by the health administration can be reversed by competent and decisive actions of scientific and professional bodies like the ASE and EAE. Before April 2008, the use of contrast agents was contraindicated in patients with unstable cardiopulmonary status, including patients with unstable angina, acute myocardial infarction, respiratory failure, or recent worsening congestive heart failure. The contraindications were established temporarily after the reports of 199 serious cardiopulmonary reactions including 11 deaths during and shortly after the administration of contrast agents in post-marketing use. Ten of the events were observed with Definity over 6 years with more than 2 million applications; one fatal event was reported with Optison for 1 million applications. At least six of these cases (five Definity and one Optison) occurred 1–12 h after dosing and were attributed to serous underlying conditions. The FDA revised the benefit/risk assessment for patients with unstable conditions and acknowledged that some of the fatal events may be coincidental and not related to the contrast media. Only four fatal events with Definity occurred within 30 min after the application of contrast agents. Within this time frame, a negative role of contrast agents appears to be possible, but this is difficult to prove or exclude. Indeed, two patients had severe heart failure and one patient was ventilated because of respiratory failure, sepsis, and multiple emboli. The FDA and European Medicines Agency (EMEA) usually are concerned about a temporal relation of an adverse event and administration of the drug. They assume a possible causal relation as long as there is no proof of another explanation. But even if we assume that all four cases are related to the ultrasound contrast agent, the fatal event rate would be only 1 in 500 000 for Definity and zero for Optison. This rate is far less than the fatal event rate in exercise and Dobutamine stress echocardiography. 1 Meanwhile, several studies demonstrate the safety of ultrasound contrast agents in more than 20 000 patients including stress echocardiography and myocardial perfusion imaging using the flash-replenishment technique. 2–5 In order to provide further safety data, external, independent safety monitoring boards for the agents will be established by the manufacturers. So, it is time to be less worried about the safety of contrast echocardiography and it is good news to have ultrasound contrast agents not contraindicated in unstable conditions. However, as good physicians we still have to be prepared for a serious adverse event, e.g. hypersensitivity reactions, even if they are very rare. Like in the angiography suite, there should always be appropriate equipment and skilled personnel for resuscitation available during administration of contrast agents. According to the FDA, the risk for severe adverse reactions may be increased among patients with pulmonary hypertension or unstable cardiopulmonary conditions (acute myocardial infarction, acute coronary artery syndromes, worsening or unstable congestive heart failure, serious ventricular arrhythmias, or respiratory failure, including patients receiving mechanical ventilation). In these patients, vital signs, electrocardiography, and cutaneous oxygen saturation have to be monitored during the contrast agents application and for at least 30 min after DEFINITY® and OPTISON® administration. Surprisingly, the manufacturer of LUMINITY® (name of Definity in Europe) announced a temporary cessation of the marketing and supply of LUMINITY in Europe. There may be purely commercial reasons for that decision. For clinical echocardiography, OPTISON is not yet available in Europe. Thus, the only available contrast agent is SonoVue®. However, SonoVue has not been included in the FDA review, because it is not licensed in the US. For SonoVue, the contraindications have not changed yet! SonoVue remains contraindicated in acute coronary syndromes, patients with heart failure III and IV, serious ventricular arrhythmias, and respiratory failure. In the setting of an acute myocardial infarct, urgent and repeated echocardiographic examinations may be necessary to evaluate LV function, intracardiac thrombi, and other complications of myocardial infarction. Contrast agents have been shown to be useful to improve the image quality (endocardial definition) in 2D and 3D echocardiography. 6 Therefore, it appears to be straightforward to use contrast echocardiography for better image quality in those with suboptimal image quality. Contrast echocardiography also provides important information about myocardial perfusion. Using the state-of-the-art ultrasound scanners, LV cavity opacification is usually associated with myocardial tissue opacification, if the tissue is viable. Thus, contrast echocardiography after a coronary intervention shows the amount of non-reflow and necrosis in the myocardium. The prognostic significance of myocardial contrast echocardiography has been demonstrated: The extent of microvascular damage during myocardial contrast echocardiography was superior to other known indexes of post-infarct reperfusion in predicting left ventricular remodelling. 7 , 8 But what is the real clinical benefit of a more accurate assessment of the LV early after acute myocardial infarction? The best way to address this question is to ask what would have been happened to the patients should they not have had a contrast echocardiography study. To my knowledge, there are no controlled clinical studies at all addressing the question, how the contrast agents applications changed the management of patients in acute myocardial infarction. Until such time that adjunctive therapies following primary percutaneous coronary intervention are shown conclusively to alter the outcome in relation to myocardial perfusion, the role of myocardial contrast echocardiography in this scenario will be limited. 7 At present, it is the approved indication for LV opacification and endocardial border delineation, which makes contrast agents valuable for patient management: by reviewing case studies, Grayburn 1 recently demonstrated the catastrophic sequences of inaccurate assessment of LV function and misdiagnosis of complications such as pseudoaneurysms and thrombi. Even if there would be a moderate risk by the contrast agent, the risk/benefit still would be very favourable for using contrast agents in acute myocardial infarction! Nucifora et al.9 provide further reassurance about the safety of LUMINITY in the acute phase of myocardial infarction: in 115 consecutive patients with ST-elevation, myocardial infarction contrast echocardiography was performed with LUMINITY. Administration of echo contrast did not induce any significant change in vital signs, physical examination, and ECG. There were no serous adverse events, and minor events occurred only in five patients. Of course, this study cannot rule out all concerns about the safety of ultrasound contrast agents in unstable patients. Firstly, only patients were included after coronary intervention. These patients are probably in a lower risk group compared with patients who would get a contrast agent before the intervention. Secondly, the number of patients is not large enough for a definite answer to our safety questions. However, I agree with the authors that the results of this pilot study should encourage studies in larger cohorts. In Europe, we need ultrasound contrast agents that can be used within the first 24 h after myocardial infarction. There are conditions, where there is no real alternative to the diagnostic value of bedside LV opacification. In the debate with the FDA, the clinical and scientific echocardiographic community has demonstrated their impact on the health administration. We should use this momentum in the discussions with the EMEA in order to achieve a revision of the contraindications of SonoVue. Multi-centre randomized studies are needed to demonstrate how myocardial contrast echocardiography can change patient management. Finally, we need a registry of patients who have got a contrast agent within 24 h after myocardial infarction or other conditions of clinical instability.

Open access
Ultrasound and Hyperthermia Applications
Ultrasound in Clinical Applications
Cardiac Arrest and Resuscitation
Original source
May 7, 2008·eCommons (Cornell University)
10 cites
Concurrent Zero Knowledge: Simplifications and Generalizations

Rafael Pass, Wei-Lung Dustin Tseng, Muthuramakrishnan Venkitasubramaniam

Few techniques for obtaining concurrent zero-knowledge exist; all require a complex and subtle analysis. We provide an arguably simpler and more general analysis of the oblivious simulation technique of Kilian and Petrank (STOC’01) while achieving the same bounds as Prabhakaran, Rosen and Sahai (FOCS’02). Using this analysis, and relying on tools recently developed by Ong and Vadhan (Eurocrypt’07, TCC’08) we are able to establish the following unconditional results: • every language inNP which has a ZK proof (resp. ZK argument, statistical ZK argument) also has a black-box concurrent ZK proof (resp. ZK argument, statistical ZK argument). • every languge which has a statistical ZK proof also has an ω(log n)-round black-box con-current statistical ZK proof.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Complexity and Algorithms in Graphs
Original source
May 1, 2008
6 cites
Zero-Knowledge in the Applied Pi-calculus and Automated Verification of the Direct Anonymous Attestation Protocol

Michael Backes, Matteo Maffei, Dominique Unruh

We devise an abstraction of zero-knowledge protocols that is accessible to a fully mechanized analysis. The abstraction is formalized within the applied pi-calculus using a novel equational theory that abstractly characterizes the cryptographic semantics of zero-knowledge proofs. We present an encoding from the equational theory into a convergent rewriting system that is suitable for the automated protocol verifier ProVerif. The encoding is sound and fully automated. We successfully used ProVerif to obtain the first mechanized analysis of (a simplified variant of) the Direct Anonymous Attestation (DAA) protocol. This required us to devise novel abstractions of sophisticated cryptographic security definitions based on interactive games. The analysis reported a novel attack on DAA that was overlooked in its existing cryptographic security proof. We propose a revised variant of DAA that we successfully prove secure using ProVerif.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
May 1, 2008·Journal of Computer Science
5 cites
Fractal (Mandelbrot and Julia) Zero-Knowledge Proof of Identity

Mohammad Alia, Azman Bin S amsudin

We proposed a new zero-knowledge proof of identity protocol based on Mandelbrot and Julia Fractal sets. The Fractal based zero-knowledge protocol was possible because of the intrinsic connection between the Mandelbrot and Julia Fractal sets. In the proposed protocol, the private key was used as an input parameter for Mandelbrot Fractal function to generate the corresponding public key. Julia Fractal function was then used to calculate the verified value based on the existing private key and the received public key. The proposed protocol was designed to be resistant against attacks. Fractal based zero-knowledge protocol was an attractive alternative to the traditional number theory zero-knowledge protocol.

Open access
Chaos-based Image/Signal Encryption
User Authentication and Security Systems
DNA and Biological Computing
Original source
Apr 1, 2008·Scientia Iranica
3 cites
A NEW, PUBLICLY VERIFIABLE, SECRET SHARING SCHEME

Aydin Behnad, Taraneh Eghlidos

A Publicly Veri able Secret Sharing (PVSS) scheme, as introduced by Stadler, has a feature where anyone, besides the participants, can verify the validity of the shares distributed by the dealer. Schoenmakers added a new feature, by providing a proof of correctness of the shares released by the players in the reconstruction process. This protocol is claimed to be an improvement on Stadler's and Fujisaki-Okamoto's, both in eciency and in the type of intractability assumptions. However, Young-Yung improved Schoenmakers' PVSS, using a Discrete-Log instead of a Decision Die-Hellman. In this paper, a new PVSS is presented, having an intrinsic di erence with its predecessors, that is, the participants can prove the validity of their given shares, implicitly, proving their membership by a zero-knowledge protocol. This feature prevents cheaters from participating in the reconstruction process to gain valid shares. Hence, the new proposed PVSS is more secure than previous ones. Besides, the dealer only sends the amount of commitments limited to the threshold value, regardless of the number of shareholders; this leads to a more dynamic protocol.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Auction Theory and Applications
Original source
Mar 19, 2008·Astronomy & Geophysics
3 cites
Defending the multiverse

B. J. Carr

From a historical perspective, the multiverse is just one more step in our progress from geocentric to heliocentric to galactocentric to cosmocentric worldview. Indeed, several lessons of relevance to the multiverse debate can be gleaned from considering the history of this progression. To the ancient Greeks, the heavenly spheres were the unchanging domain of the divine and therefore outside science by definition. It required Tycho de Brahe's observation of a supernova in 1572 and the realization that its apparent position did not change as the Earth moved around the Sun to dash that view. Because this contradicted the Aristotelian view that the heavens cannot change, the claim was at first received sceptically. Frustrated by those who had eyes but would not see, Brahe wrote: “O crassa ingenia. O coecos coeli spectators.” (Oh thick wits. Oh blind watchers of the sky.) Lesson 1: Theoretical prejudice should not blind one to the evidence. Of course, we will never see the other universes themselves — in that sense we are necessarily blind, so this point might seem irrelevant to the multiverse. However, I would claim that the analogue of Tycho's supernova is the fine-tunings. Long after Galileo had speculated that the Milky Way consists of stars like the Sun and Newton had shown the laws of Nature could be extended beyond the solar system, there was still a prejudice that the investigation of this region was beyond the domain of science. In 1842 August Comte said of the study of stars: “Never, by any means, will we be able to study their chemical compositions. The field of positive philosophy lies entirely within the Solar System, the study of the universe being inaccessible in any possible science.” Comte had not foreseen the advent of spectroscopy, which identified absorption features in stellar spectra with chemical elements. Lesson 2: New observational developments are hard to anticipate. Perhaps we will find extra dimensions at the Large Hadron Collider or even create baby universes in the laboratory one day. Cosmology attained the status of a proper science in 1915, when the advent of general relativity gave it a secure mathematical basis. Nevertheless, for a further decade there was resistance to the idea that science could be extended beyond our galaxy. Indeed many astronomers refused to believe that there was anything beyond. Although Kant had speculated as early as 1755 that some nebulae are “island universes” similar to the Milky Way, most astronomers continued to adopt a galactocentric view until the 1920s. Indeed, the most popular model of the galaxy at the start of the 20th century — Kapteyn's Universe — even had the Sun at its centre! The controversy came to a head in 1920 when Heber Curtis defended the island universe theory in a famous debate with Harlow Shapley. The issue was finally resolved in 1924, when Edwin Hubble measured the distance to M31 using Cepheid variable stars. In many ways this parallels the current debate about whether anything exists beyond our horizon. Lesson 3: More conservative cosmologists might prefer to maintain the cosmocentric view but perhaps the tide of history is against them. The evidence for other universes can never be as decisive as that for extragalactic nebulae but the transformation of worldview required may be just as necessary. A few years later Hubble obtained radial velocities and distance estimates for several dozen nearby galaxies, thereby discovering that all galaxies are moving away from us with a speed proportional to their distance. The most natural interpretation of this is that space itself is expanding, as indeed had been predicted by Alexander Friedmann in 1920 on the basis of general relativity. Einstein rejected this model at the time because he believed the universe (i.e. the Milky Way) was static and he even introduced an extra repulsive term into his equations — the cosmological constant — to allow this possibility. After Hubble's discovery, he described this as his “biggest blunder”. Lesson 4: One should not necessarily reject theoretical predictions because they have no observational support. In fact, Einstein continued to uphold the static model even after the evidence was against it — he only accepted the Friedmann model in 1931, several years after Hubble published his data — so knowing how much weight to attach to theory and observation can be tricky. Let me now address George's specific issues. There are plausibly galaxies just beyond the visual horizon, where we cannot see them, so we can extend this argument, step by step, to way beyond the horizon and infer there are many different universes that we cannot see. Even though we can never prove what happens outside our visual horizon, the standard FRW model has been well tested within it, so there is surely some probabilistic sense in which one can extrapolate models at least some way beyond it. Also the smooth dependence of the CMB fluctuations on angular separation (whatever the source of those fluctuations) gives no reason to suppose that anything strange happens just beyond the horizon. George himself seems to accept this, which illustrates the problem of regarding speculations as non-scientific just because they involve the unobservable. Admittedly one's confidence in any proposed model must decrease as one extrapolates ever further beyond the horizon, but one should beware of using Rees's slippery slope argument in reverse: we cannot extrapolate to scales much larger than the horizon, so we should not extrapolate to scales only slightly outside it. The problem comes when one makes the jump from the Level I to Level II multiverse (which is where George's argument that the FRW solution extends everywhere must fail). In fact, the inflationary scenario does provide an answer to this. For if the amplitude of the density fluctuations increases slightly with scale (as appears to be the case), one can predict the scale at which the FRW approximation breaks down. Current data suggest that this happens at around 10100 horizon scales. The existence of a multiverse is implied by inflation, which is verified by the CMB anisotropy observations. In particular, known physics leads to chaotic inflation and this implies a multiverse. There are two distinct issues here: does one believe in inflation and does inflation lead to a multiverse? Inflation is attractive because it resolves several cosmological conundra. Quantum fluctuations of the scalar field can also generate the small density perturbations that eventually give rise to galaxies and large-scale structure and it is impressive that the predicted dependence of the CMB fluctuations on angular separation is almost exactly as observed by the WMAP satellite (Spergel et al. 2003). Of course, the evidence for inflation is not conclusive — there is still no evidence for any scalar field in Nature!— but the Level I multiverse is still a good bet. As regards the second issue, I agree with George that the evidence for the sort of chaotic inflation that leads to a Level II multiverse is more equivocal, and certainly one cannot infer this from the form of the CMB anisotropies. There are now around 100 models of inflation and, while Linde (1990) claims that the existence of other domains with different coupling constants is generic, this is debatable. The multiverse idea is testable, because it can be disproved if we determine there are closed spatial sections in the universe (for example, if the curvature is positive). This is really a straw man argument because we have seen that inflation is only one of several multiverse proposals — for example, quantum cosmology models give closed spatial sections — and not all inflationary models require that the spatial sections be open anyway. However, George is surely right to stress the importance of looking for circles in the CMB. The idea of small universes is not mainstream but it has the advantage that it can be tested. The existence of a multiverse is the only physical explanation for the fine-tuning of parameters that leads to our existence. In the absence of direct evidence for other universes, I regard the anthropic fine-tunings as the best indirect evidence. (A multiverse in which the constants were the same everywhere would have no explanatory value.) I agree with George that the fine-tunings do not constitute proof, but they still carry weight. One can argue about how impressive the fine-tunings are (could we really exclude life if the constants changed a lot?), but I still think the number and precision of the tunings is remarkable. Nearly 30 years ago I wrote a review with Martin Rees about these fine-tunings (Carr and Rees 1979). In the intervening period a few of them have gone away (e.g. inflation may explain the value of the cosmological density parameter) but most of them have got stronger. Without a multiverse one may be forced to adopt a non-physical explanation like a fine-tuner, which is why Neil Manson (2003) claims that “the multiverse is the last resort of the desperate atheist”. This is not necessarily true — Paul Davies (2006) advocates a “third way” in which the laws of Nature evolve in a single universe in such a way that life can arise — but if you reject the multiverse, you certainly lower the scientific status of the anthropic arguments. I agree with George's argument against physical infinities. However, we do not need an infinity to validate the anthropic principle — just a large number. The existence of a multiverse is implied by a probability argument: the universe is no more special than it need be to create life. In particular, the small value of the cosmological constant shows that other universes exist. George argues that multiverse theories are not useful because they cannot be disproved: if all possibilities exist somewhere, then they can explain all conceivable observations. However, the fact that we only observe one sample of the multiverse still allows the proposal to be refuted at a given confidence level. Statistical predictions still qualify as science and that is why Rees has stressed the importance of calculating the probability distribution for various parameters across the universes. Indeed, a core difference between the Bayesian and frequentist views is the former's willingness to make inferences from single, and possibly unrepeatable, pieces of data. George rejects the Λ argument but there is no doubt that this has been very influential in attracting many physicists to the multiverse cause. It used to be thought that Λ was exactly zero and it was then plausible that there might be some physical (non-anthropic) explanation for this. However, the fact that Λ is non-zero but very tiny is a profound mystery that completely changes the situation. Critics say that we cannot know what distribution for Λ is predicted across the multiverse and that is correct. It may be simplistic to assume that the distribution is uniform, but postulating that there is a spike in precisely the observed region is just as improbable as what we are trying to explain. Even if one does not accept inflation, multi-verses are predicted by many theories of particle physics. It is still legitimate to invoke the existence of other universes for which there can be no direct evidence if one has a theory (like M-theory) that predicts this. It is not necessary to check all predictions of the theory for it to be considered scientific (e.g. we cannot probe inside black holes and we cannot see quarks but we still regard these as subjects for scientific discourse); it is only necessary to test some of them. Does M-theory qualify in this respect? George claims no; it does not come under the purview of science because our confidence in it is based on faith and aesthetic considerations (mathematical beauty etc) rather than experimental data. Certainly he is not alone in this attitude. For example, Woit (2006) and Smolin (2007) dismiss M-theory as mathematics rather than physics because it has not made contact with observations after 20 years. However, I feel this rejection is premature. It may take 200 years to solve the equations of M-theory and test them, but the definition of what constitutes a scientific question should not depend on how difficult it is. The nature of science changes, so what is illegitimate science today may be legitimate tomorrow. The fundamental issue in the dispute between myself and George concerns which features of science are to be regarded as sacrosanct. Experimentation used to be regarded as sacrosanct but by that criterion all of astronomy would be excluded since one cannot experiment with stars and galaxies. Fortunately, one can still make observations and — since there are billions of these objects — Nature effectively performs experiments for us. Cosmologists are in worse shape because there is only one universe to observe and speculations about processes at very early and very late times have to be viewed as ultra-speculative. For this reason, more conservative physicists regard even relatively standard cosmological speculations as trespassing into metaphysics. George places a lot of emphasis on falsifiability, but not everybody in the philosophy of science agrees with Popper on this and it is surely dangerous to impose a philosophical prescription that prevents scientists changing the border of their field. As Susskind cautions, it would be a pity to miss out on some fundamental truth because of an over-restrictive definition of science. Of course, one needs some degree of falsifiability, but the question is, how much? It is certainly not fair to put M-theory in the same class as astrology. On the other hand, I share George's scepticism of the Level IV multiverse, which corresponds to universes governed by different mathematical structures. The view that any mathematically possible universe must exist somewhere seems untestable in a deeper sense than Levels I to III. The notion of a multiverse entails a new perspective of the nature of science and it is not surprising that this causes intellectual discomfort. But this situation has often occurred before and one should not be surprised if it happens again. The Cosmic Uroborus in figure 2 shows that the history of physics might be regarded as the extension of knowledge into ever smaller and ever larger scales. The ideas encountered at the two frontiers have often been viewed as part of philosophy rather than science, so in a sense the debate is nothing new. However, there is another sense in which the current situation is very special. This is because — for the first time — the boundaries at the largest and smallest scales have connected, as indicated by the top of the Cosmic Uroborus, so the two science/philosophy frontiers have merged. Does this merging represent the completion of science or merely the sort of transformation in the perceived nature of science that accompanies every paradigm shift? This is a contentious issue and clearly we do not yet know the answer. I accept that there may eventually be a limit to the sort of questions that science can address; George and I merely disagree on whether we have reached that limit with the multiverse. In any case, we are surely behoven to try to take science as far as possible. I will end with a comment by Steven Weinberg (2007) in his contribution to Universe or Multiverse?: “We usually mark advances in the history of science by what we learn about Nature, but at certain critical moments the most important thing is what we discover about science itself. These discoveries lead to changes in how we score our work, in what we consider to be an acceptable theory.”

Open access
Interdisciplinary Cultural and Social Studies
Gender, Feminism, and Media
Critical Realism in Sociology
Original source
Feb 25, 2008·Lecture notes in computer science
33 cites
On Constant-Round Concurrent Zero-Knowledge

Rafael Pass, Muthuramakrishnan Venkitasubramaniam

No abstract is available for this record.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Privacy-Preserving Technologies in Data
Original source
Feb 1, 2008
0 cites
Specifying and implementing privacy-preserving cryptographic protocols

Θεόδωρος Μπαλόπουλος

Η διατριβή αυτή ασχολείται με την προδιαγραφή και υλοποίηση πρωτοκόλλων ασφάλειας με απαιτήσεις διασφάλισης ιδιωτικότητας, όπως για παράδειγμα τα πρωτόκολλα ηλεκτρονικών μετρητών, ηλεκτρονικής ψηφοφορίας και επιλεκτικής αποκάλυψης δεδομένων. Ο στόχος, όσον αφορά την προδιαγραφή τους, είναι αυτή να γίνει με τυπική μέθοδο (formal method), και, όσον αφορά την υλοποίησή τους, να βασίζεται στην προδιαγραφή τους και να διασφαλίζει τις περί ιδιωτικότητας απαιτήσεις. Το υπάρχον ερευνητικό έργο στη διεθνή βιβλιογραφία σε τυπικές μεθόδους δεν καλύπτει επαρκώς τα πρωτόκολλα ασφάλειας με απαιτήσεις διασφάλισης ιδιωτικότητας όσο άλλων ειδών πρωτόκολλα ασφάλειας, όπως τα πρωτόκολλα αυθεντικοποίησης. Στην παρούσα διατριβή υποστηρίζεται ότι οι λόγοι για αυτή την ανεπάρκεια μελέτης είναι οι εξής: Πρώτον, ότι τα πρωτόκολλα με απαιτήσεις διασφάλισης ιδιωτικότητας βασίζονται σε πιο εξειδικευμένη κρυπτογραφία, όπως η δέσμευση (commitment), η τυφλή υπογραφή (blind signature), η απόδειξη μηδενικής γνώσης (zero-knowledge proof), η ομομορφική κρυπτογραφία (homomorphic encryption), το mix του Chaum και το onion routing. Δεύτερον, ότι είναι απαραίτητη η διαφοροποίηση στη μοντελοποίηση της κλασικής κρυπτογραφίας (συμμετρική και ασύμμετρη κρυπτογράφηση και ψηφιακές υπογραφές) που τα πρωτόκολλα αυτά χρησιμοποιούν από κοινού με τα υπόλοιπα πρωτόκολλα. Η διατριβή αυτή χρησιμοποιεί ως βάση τη γλώσσα προδιαγραφής πρωτοκόλλων Typed MSR [14, 15], καθώς και την προηγούμενη εργασία μας στην ίδια [10, 7, 9, 8, 6] ερευνητική κατεύθυνση και στοχεύει με τροποποιήσεις και προσθήκες να την μετατρέψει σε κατάλληλη, αφενός για την προδιαγραφή πρωτοκόλλων με απαιτήσεις διασφάλισης ιδιωτικότητας, αφετέρου για την προδιαγραφή ενός κατά Dolev-Yao επιτιθέμενου [19] σχεδιασμένου για επίθεση σε πρωτόκολλα τέτοιου είδους. Επιπλέον, χρησιμοποιεί ως βάση τη γλώσσα Jif [30, 31, 29], καθώς και την προηγούμενη εργασία μας [6] στην ίδια ερευνητική κατεύθυνση και στοχεύει να επιδείξει πως η γλώσσα αυτή, που διαθέτει σύστημα τύπων για απαιτήσεις ασφάλειας, μπορεί να χρησιμοποιηθεί με τέτοιον τρόπο ώστε οι αδυναμίες στην υλοποίηση πρωτοκόλλων ασφαλείας όσον αφορά τη συνδεσιμότητα (linkability) να μπορούν να ανιχνευτούν με ένα συνδυασμό στατικών και δυναμικών (runtime) ελέγχων. Τα βασικά συμπεράσματα της διατριβής αυτής είναι τα ακόλουθα: 1. Προκειμένου η Typed MSR να είναι κατάλληλη για την προδιαγραφή πρωτοκόλλων ασφάλειας με απαιτήσεις ιδιωτικότητας, δεν θα πρέπει να μοντελοποιεί τη συμμετρική και την ασύμμετρη κρυπτογράφηση ως αιτιοκρατική. Μια τέτοια απλούστευση μπορεί να μη δημιουργεί προβλήματα στη μοντελοποίηση άλλων πρωτοκόλλων, αλλά οδηγεί σε ανύπαρκτες αδυναμίες διασύνδεσης στα πρωτόκολλα που μελετούμε στην παρούσα διατριβή. 2. Μπορούμε να κατασκευάσουμε υψηλού επιπέδου μοντελοποιήσεις για κρυπτογραφία πιο σύνθετη από την κλασική, όπως είναι η δέσμευση, η τυφλή υπογραφή, η απόδειξη μηδενικής γνώσης και η ομομορφική κρυπτογραφία. 3. Η χρήση μη διαδραστικών μοντελοποιήσεων για τις αποδείξεις μηδενικής γνώσης οδηγεί στην απλοποίηση τόσο της προδιαγραφής των πρωτοκόλλων, όσο και της μετατροπής αυτής σε υλοποίησή τους. 4. Με βάση τις προαναφερθείσες αλλαγές και προσθήκες, η Typed MSR γίνεται κατάλληλη για την προδιαγραφή πρωτοκόλλων ασφάλειας με απαιτήσεις ιδιωτικότητας, όπως δείχνει η προδιαγραφή των δύο πρωτοκόλλων ηλεκτρονικής ψηφοφορίας που περιέχονται στην παρούσα διατριβή. 5. Ένα απλό σύστημα τύπων, που χρησιμοποιείται παράλληλα με το σύστημα τύπων της Typed MSR, αποτρέπει συγκεκριμένες εσφαλμένες χρήσεις της κρυπτογραφίας που μπορεί να οδηγήσουν σε αδυναμίες συνδεσιμότητας, καθώς και να παρακολουθήσει την απειλή συνδεσιμότητας που προκύπτει από κάθε πιθανή χρήση της κρυπτογραφίας. 6. Είναι απαραίτητη η ενημέρωση του εκφρασμένου σε Typed MSR μοντέλου του κατά Dolev-Yao επιτιθέμενου με βάση τα παραπάνω, ώστε να μπορεί πλέον να επιτεθεί στα πρωτόκολλα τα οποία μελετάμε. 7. Η ενημερωμένη αυτή έκδοση του κατά Dolev-Yao επιτιθέμενου δημιουργεί ένα τυπικό (formal) περιβάλλον, στο οποίο μπορούν να εκφραστούν αδυναμίες διασύνδεσης των πρωτοκόλλων. 8. Τα παραπάνω μπορούν να αποτελέσουν τη βάση για τη χρήση της γλώσσας Jif με τέτοιο τρόπο, ώστε οι αδυναμίες στην υλοποίηση πρωτοκόλλων ασφαλείας όσον αφορά τη συνδεσιμότητα να μπορούν να ανιχνευτούν με ένα συνδυασμό στατικών και δυναμικών ελέγχων. 9. Η συνδεσιμότητα δεν είναι δυνατό να ελεγχθεί στατικά στη γενική περίπτωση, αλλά μπορεί να ελέγχεται δυναμικά κατά την εκτέλεση των πρωτοκόλλων. 10. Οι κανόνες της Typed MSR με τους οποίους παράγονται τα καινούρια μηνύματα τα οποία μπορεί να σχηματίσει ο κατά Dolev-Yao επιτιθέμενος από ένα σύνολο γνωστών μηνυμάτων χωρίζονται σε δύο κατηγορίες, ανάλογα με το αν χρησιμοποιούνται στη φάση αποδόμησης των γνωστών μηνυμάτων ή στη φάση κατασκευής των καινούριων. Συγκεκριμένα μηνύματα που βασίζονται στην κρυπτογραφία της διατριβής αυτής δεν μπορούν όμως να χωριστούν σε μία από τις δύο κατηγορίες, καθώς είναι ωφέλιμη η χρήση τους και στις δύο αυτές φάσεις.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
User Authentication and Security Systems
Original source
Jan 31, 2008·Algebraic structures and their applications, pp. 351--363 (2002)
0 cites
On the Double Coset Membership Problem for Permutation Groups

Oleg Verbitsky

We show that the Double Coset Membership problem for permutation groups possesses perfect zero-knowledge proofs.

Open access
2 source records
cs.CC
Cryptography and Data Security
Complexity and Algorithms in Graphs
Original source
Jan 4, 2008·arXiv (Cornell University)
0 cites
Quantum Zero-Knowledge Protocol Using Quantum Bit Commitment without Quantum Memory

Rubens Viana Ramos, José Cláudio do Nascimento

Zero-knowledge proof system is an important protocol that can be used as a basic block for construction of other more complex cryptographic protocols. Quantum zero-knowledge protocols have been proposed but, since their implementation requires advanced quantum technology devices, experimental implementation of zero-knowledge protocols have not being reported. In this work, we present a quantum zero-knowledge protocol based on a quantum bit commitment protocol that can be implemented with today technology. Hence, our quantum zero-knowledge protocol can be readily implemented.

Open access
2 source records
quant-ph
Quantum Computing Algorithms and Architecture
Quantum Information and Cryptography
Original source
Jan 1, 2008·OpenGrey (Institut de l'Information Scientifique et Technique)
2 cites
The symmetric eigenvalue problem : stochastic perturbation theory and some network applications

Zhivko Stoyanov

This thesis is concerned with stochastic perturbation theory of the symmetric eigen-value problem. In particular, we provide results about the probability of interchanges in the ordering of the eigenvalues and changes in the eigenvectors of symmetric matrices subject to stochastic perturbations. In this analysis we use a novel combination of traditional Numerical Linear Algebra, Perturbation Theory and Probability Theory. The motivation for this study arises from reliability of spectral clustering of networks, when network data is subject to noise. As far as we are aware, there is nothing comparable in the literature. Further, we make conjectures from which we derive an asymptotic relation between the distributions of the largest eigenvalue and the 2-norm of random symmetric ma- trices, whose entries above the main diagonal are independent, identically distributed random variables with probability density functions being symmetric with respect to zero, including matrices from the Gaussian Orthogonal Ensemble (GOE). As far as we know, some of these conjectures are not new (possibly only as conjectures) but we are not aware of any proofs. Also, we consider networks of coupled oscillators. In their analysis we use both, knowledge of dynamical systems and spectral properties of non-negative matrices. As a result, we present an algorithm, which uncovers the \\master-slave" structure of the network. With its help, the analysis of the dynamics and the entrainment of the entire network can be reduced to considering only few of the oscillators, those whose dynamics determine the behaviour of the rest. This can be helpful in large networks exhibiting the \\master-slave" structure. Finally, we consider similarities of spectral clustering with respect to di®erent matrices which can be associated with a given network. In particular, we compare clustering of products of Path graphs with respect to two di®erent matrices: the Laplacian and the Normalised Laplacian matrices of the graph. We make the comparison by constructing a Homotopy between two eigenvalue problems and, using some Linear Algebra techniques, we show that the two matrices give similar spectral clusterings when applied to products of Path graphs.

Open access
Topological and Geometric Data Analysis
Complex Network Analysis Techniques
Random Matrices and Applications
Original source
Jan 1, 2008·Technischen Universität Darmstadt
1 cites
On the Theory and Practice of Quantum-Immune Cryptography

Martin Döring

Public-key cryptography is a key technology for making the Internet and other IT infrastructures secure. The security of the established public-key cryptosystems relies on the difficulty of factoring large composite integers or computing discrete logarithms. However, it is unclear whether these computational problems remain intractable in the future. For example, Shor showed in 1994 that quantum computers can be used to factor integers and to compute discrete logarithms in polynomial time. It is therefore necessary to develop alternative public-key cryptosystems which do not rely on the difficulty of factoring or computing discrete logarithms and which are secure even against quantum computer attacks. We call such cryptosystems quantum-immune. To prove the security of these quantum-immune cryptosystems, appropriate security models have to be used. Since quantum computers are able to solve problems in polynomial time which are supposed to be intractable for classical computers, the existing security models are inadequate in the presence of quantum adversaries. Therefore, new security models have to be developed to capture quantum adversaries. Properties of these new security models have to be investigated. On a more practical level, the quantum-immune cryptosystems have to be implemented in a way that they can seamlessly replace established cryptosystems. The implementations have to be efficient and suitable for resource-constrained devices. They must easily integrate into existing public-key infrastructures. This thesis contributes to both the theory and practice of quantum-immune cryptography, addressing the above-mentioned challenges. In the theoretical part, we concentrate on the quantum zero-knowledge property of interactive proof systems. We show for the first time that the quantum statistical, perfect, and computational zero-knowledge properties are preserved under sequential composition of interactive proof systems. In the practical part, we provide implementations of the most important quantum-immune cryptosystems. We present efficiency improvements of some of the alternative cryptosystems. The implementations are very efficient and easily integrate into existing public-key infrastructures. We present comprehensive timings that show that the alternative cryptosystems are competitive or even superior compared to established cryptosystems. Finally, we present a new cryptographic API that is particularly well-suited for resource-constrained devices like mobile phones and PDAs. With this API, the alternative cryptosystems can also be used with these devices.

Open access
Cryptography and Data Security
Cryptographic Implementations and Security
Quantum Computing Algorithms and Architecture
Original source
Jan 1, 2008·Lecture notes in computer science
3 cites
Efficient Simultaneous Broadcast

Sebastian Faust, Emilia Käsper, Stefan Lucks

We present an efficient simultaneous broadcast protocol ν-SimCast that allows n players to announce independently chosen values, even if up to t &amp;lt; n players are corrupt. Independence is guaranteed in the partially syn-2 chronous communication model, where communication is structured into rounds, while each round is asynchronous. The ν-SimCast protocol is more efficient than previous constructions. For repeated executions, we reduce the communication and computation complexity by a factor O(n). Combined with a deterministic extractor, ν-SimCast provides a particularly efficient solution for distributed coin-flipping. The protocol does not require any zero-knowledge proofs and is shown to be secure in the standard model under the Decisional Diffie Hellman assumption.

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Distributed systems and fault tolerance
Original source
Jan 1, 2008·Journal of Cryptology
41 cites
Possibility and Impossibility Results for Selective Decommitments

Dennis Hofheinz

The selective decommitment problem can be described as follows: assume an adversary receives a number of commitments and then may request openings of, say, half of them. Do the unopened commitments remain secure? Although this question arose more than twenty years ago, no satisfactory answer could be presented so far. We answer the question in several ways: 1. If simulation-based security is desired (i.e., if we demand that the adversary's output can be simulated by a machine that does not see the unopened commitments), then security is not achievable for non-interactive or perfectly binding commitment schemes via black-box reductions to standard cryptographic assumptions. However, we show how to achieve security in this sense with interaction and a non-black-box reduction to one-way permutations. 2. If only indistinguishability of the unopened commitments from random commitments is desired, then security is not achievable for (interactive or non-interactive) perfectly binding commitment schemes, via black-box reductions to standard cryptographic assumptions. However, any statistically hiding scheme does achieve security in this sense. Our results give an almost complete picture when and how security under selective openings can be achieved. Applications of our results include: • Essentially, an encryption scheme must be non-committing in order to achieve provable security against an adaptive adversary. • When implemented with our secure commitment scheme, the interactive proof for graph 3-coloring due to Goldreich et al. becomes zero-knowledge under parallel composition. On the technical side, we develop a technique to show very general impossibility results for black-box proofs.

Open access
2 source records
Cryptography and Data Security
Security and Verification in Computing
Digital and Cyber Forensics
Original source
Jan 1, 2008·Brown Digital Repository
11 cites
Efficient Non-Interactive Zero-Knowledge Proofs for Privacy Applications

Melissa Chase

Non-interactive zero-knowledge (NIZK) proofs can be an extremely powerful tool, allowing one to prove a statement in a single message without revealing any information besides the truth of the statement. Blum et al. showed that NIZK proof systems exist for all languages in NP. However, in practice, NIZK proofs are rarely used, because existing protocols are extremely inefficient. Here we examine some useful languages for which we can give efficient proof system. We define two useful building blocks: one for proving that a message has been signed, and a second for proving that a value has been chosen according to a pseudorandom function. We give applications of these building blocks to anonymous credential systems, to electronic cash, and to the design of other efficient NIZK proofs systems.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Dec 31, 2007
49 cites
Applications of the Quillen-Suslin theorem to multidimensional systems theory

Anna Fabiańska, Alban Quadrat

The purpose of this paper is to give four new applications of the Quillen-Suslin theorem to mathematical systems theory. Using a constructive version of the Quillen-Suslin theorem, also known as Serre's conjecture, we show how to effectively compute flat outputs and injective parametrizations of flat multidimensional linear systems. We prove that a flat multidimensional linear system is algebraically equivalent to the controllable 1-D dimensional linear systems obtained by setting all but one functional operator to zero in the polynomial matrix defining the system. In particular, we show that a flat ordinary differential time-delay linear system is algebraically equivalent to the corresponding ordinary differential system without delay, i.e., the controllable ordinary differential linear system obtained by setting all the delay amplitudes to zero. We also give a constructive proof of a generalization of Serre's conjecture known as Lin-Bose's conjecture. Moreover, we show how to constructively compute (weakly) left-/right-/doubly coprime factorizations of rational transfer matrices over a commutative polynomial ring. The Quillen-Suslin theorem also plays a central part in the so-called decomposition problem of linear functional systems studied in the literature of symbolic computation. In particular, we show how the basis computation of certain free modules, coming from projectors of the endomorphism ring of the module associated with the system, allows us to obtain unimodular matrices which transform the system matrix into an equivalent block-triangular or a block-diagonal form. Finally, we demonstrate the package QuillenSuslin which, to our knowledge, contains the first implementation of the Quillen-Suslin theorem in a computer algebra system as well as the different algorithms developed in the paper.

Open access
Advanced Differential Equations and Dynamical Systems
Formal Methods in Verification
Polynomial and algebraic computation
Original source