In the public mind, Bitcoin has often been associated with censorship circumvention and evasion of surveillance measures, specifically in the context of monetary transactions. However, this perceived anonymity is a false sense of security as both on-chain transactions and the underlying message exchange in the peer-to-peer network are attack vectors for deanonymisation and monitoring, as shown in other research. Nonetheless, there has been an increase in Bitcoin usage not only for end-users but also in the context of cybercrime in the form of cryptojacking and ransomware. So there are a number of reasons why proxies might be used in the Bitcoin network, either as a privacy-preserving measure of end-users or as obfuscation in cybercrime.
In blockchain-based anonymous cryptocurrencies, due to their tamper-resistance and transparency characteristics, transaction data are initially required to be anonymous, with the help of various cryptographic techniques, e.g., commitment schemes and zero-knowledge proofs. Also, cryptocurrencies are different from existing anonymous messaging protocols regarding the software architecture and the underlying security model. Due to these differences, the sense of anonymity must be specifically defined for anonymous cryptocurrencies, and the anonymity in each anonymous cryptocurrency must be analyzed and evaluated based on the specific architecture model. In this paper, we first propose a specific architecture model with three software layers to anonymous cryptocurrencies. Next, we introduce definitions of fundamental privacy properties (Pfitzmann's anonymity, unlinkability, and pseudonymity) and comprehensively analyze each privacy property for each architecture layer of anonymous cryptocurrencies to establish a privacy evaluation policy for anonymous cryptocurrencies. Finally, we fairly compare the privacy of current leading anonymous cryptocurrencies (e.g., Zerocash, CryptoNote, and Mimblewimble) using the privacy evaluation policy.
The purpose of the research is to use blockchain technology in the electoral process. The study was conducted on the example of blockchain technologies used in elections in the United States, Canada, Australia, Sierra Leone, Switzerland, Spain, Russia and other countries. The methodological basis of the research is based on the methods of comparative analysis and component analysis of definitions. Empirical methods of expert assessment and interviewing were used. The pros and cons of blockchain technologies and the possibility of using this innovative technology in elections of different levels are revealed. The advantages of inclusive blockchain technology include the mobility and accessibility of voting; minimizing the costs of organizing and conducting elections; de-bureaucratization by reducing the staff of election commissions; the possibility of excluding the impact on voters from participants in the electoral process; reducing the time for processing ballots and determining the results of voting; increasing the level of trust in electoral procedures on the part of citizens who usually do not participate in voting. Among the disadvantages of blockchain technologies, we can highlight: technical failures and hacker cyber-attacks; the possibility of hackers using data about voters, in case of hacking electronic databases; violation of the secrecy of voting.
Recognition of foreign qualifications for authorising the exercise of a regulated profession gains importance in globalised economies and in international organisations such as the UNESCO. However, national procedures for such recognition have not yet experienced the transformative changes that occurred in other sectors of public administration. The study of “transborder digitisation” is still in its infancy. While governments consider the adoption of blockchain applications for the e-administration of trade-related procedures, for example customs procedures, it is timely to give some thoughts to recognition as well. After explaining the role of recognition in international relations this article explores the features of recognition procedures that are relevant for the choice of a technology. It then aims to identify recognition authorities’ needs in terms of administrative tools and to find out the options and potential benefits of blockchain technology in view of those needs. It aims to find whether there are reasons to select that particular technology rather than conventional methods. This is highlighted in a concrete description of what could be a possible configuration of a blockchain solution for recognition procedures. Since opportunities are always balanced by limitations, the article also inquires into ithe expected challenges in adopting a blockchain system between different countries’ recognition authorities. The article’s overall aim is to offer an assessment of blockchain technologies’ potential in that field and to highlight developments in technology that could ease their adoption. The article finds that the advantages brought by DLT technologies and the needed features of recognition processes coincide in several respects. However, some critical challenges and limitations for the application of blockchain in this field also exist. An adoption of that technology for that particular branch of public administration could occur provided that the technology continues to improve. Such improvements include interoperability, interface with other protocols and legacy databases, portability, and a higher degree of safety regarding privacy.
Dec 16, 2020·CPP'2021: Proceedings of the 10th ACM SIGPLAN International Conference on Certified Programs and Proofs, January 18--19, 2021, Virtual, Denmark
Danil Annenkov, Mikkel Milo, Jakob Botsch Nielsen, Bas Spitters
We implement extraction of Coq programs to functional languages based on MetaCoq's certified erasure. As part of this, we implement an optimisation pass removing unused arguments. We prove the pass correct wrt. a conventional call-by-value operational semantics of functional languages. We apply this to two functional smart contract languages, Liquidity and Midlang, and to the functional language Elm. Our development is done in the context of the ConCert framework that enables smart contract verification. We contribute a verified boardroom voting smart contract featuring maximum voter privacy such that each vote is kept private except under collusion of all other parties. We also integrate property-based testing into ConCert using QuickChick and our development is the first to support testing properties of interacting smart contracts. We test several complex contracts such as a DAO-like contract, an escrow contract, an implementation of a Decentralized Finance (DeFi) contract which includes a custom token standard (Tezos FA2), and more. In total, this gives us a way to write dependent programs in Coq, test them semi-automatically, verify, and then extract to functional smart contract languages, while retaining a small trusted computing base of only MetaCoq and the pretty-printers into these languages.
Learning from data owned by several parties, as in federated learning, raises challenges regarding the privacy guarantees provided to participants and the correctness of the computation in the presence of malicious parties. We tackle these challenges in the context of distributed averaging, an essential building block of distributed and federated learning. Our first contribution is a novel distributed differentially private protocol which naturally scales with the number of parties. The key idea underlying our protocol is to exchange correlated Gaussian noise along the edges of a network graph, complemented by independent noise added by each party. We analyze the differential privacy guarantees of our protocol and the impact of the graph topology, showing that we can match the accuracy of the trusted curator model even when each party communicates with only a logarithmic number of other parties chosen at random. This is in contrast with protocols in the local model of privacy (with lower accuracy) or based on secure aggregation (where all pairs of users need to exchange messages). Our second contribution is to enable users to prove the correctness of their computations without compromising the efficiency and privacy guarantees of the protocol. Our construction relies on standard cryptographic primitives like commitment schemes and zero knowledge proofs.
Blockchain as a distributed system that confirms security and reliability have started a new era of a solid and consensus system.Blockchains focus on cryptocurrency is encouraging many other processes to follow the same reliable approach of security.Almost all procedures and operations are now invited to be electronically performed in the digital Ethereum network that has been presented. Moreover, this study proposed the use of an Ethereum network on a blockchain platform in the study when it was moved to a blockchain network to confirm transparency.An E-voting system sample has been tested by using an Ethereum network smart contracts inwhich solidity language and wallets were used. In the voting test, the Ethereum blockchain will be able to collect records in which voters can use their Ethereum wallets or android devices to submit their votes in a consensus node.The researchers studied the voting system taking Jordan as a case study.This study recommended the adaptation of e-voting to support transparency and voters trust to reduce corruption and unreliability in the voting processes. Moreover, the use of this system will allow a voter to vote from home in the time of the pandemic.\n\n
José Eduardo de Azevedo Sousa, Vinícius Cunha Oliveira, Júlia Almeida Valadares, Alex Borges Vieira · 7 authors
O crescimento do interesse em Ethereum leva a preocupações relacionadas à sua segurança, dado que já houveram ataques que exploraram o seu mecanismo de tarifação ou Penny Attack. Esses ataques afetaram a rede ocasionando lentidão nas transações e há indícios que Ethereum continua susceptível a esse tipo de ataque. Analisamos o comportamento da rede Ethereum durante um Penny Attack, buscando técnicas de aprendizado de máquina para detectá-lo previamente, utilizando atributos das transações. Nossas técnicas tiveram AUC, Fb e recall superior a 94%, 82% e 98% respectivamente.
Pedro Ivo de Castro Oyama, Jó Ueyama, Paulo Matias
Social media has become part of our daily lives. It brought significant developments in the way we communicate, but it also raised some concerns, including privacy and censorship. In this context, this work presents a social media platform -- EtherYou -- that makes use of cryptographic primitives and an Ethereum smart contract to overcome these issues. Experiments were conducted to evaluate the operating costs involved. The results showed considerable values for senders, zero for receivers, and zero maintenance costs, indicating its potential in scenarios with a reduced number of content producers and a large number of consumers. The proposal offers users privacy over their data, transparency on the system behaviour and censorship resistance.
S. Sowmiyasree Dr.L.Aruna, M. Maheswari, A. Saranya
Abstract Over the course of time, electronic voting has evolved as a substitute for paper ballot voting to decrease redundancies and inconsistencies. Due to the many security and privacy vulnerabilities experienced over time, the past results of e-voting in the last three decades indicate that it has not been very successful. All cryptocurrencies are actually based on block chain. Block chain is based on the principle of distribution and decentralization. It is a continuous and continuously growing ledger that holds, in a secure, chronological and immutable way, a permanent record of all the transactions that have taken place. Value in a block chain can be anything. In the case of cryptocurrencies, it takes the meaning of money or currency. While in a game it takes the form of points or score. The value can take the form of a vote or a ballot while e-voting. The blockchain can be used in this article to pass votes between two parties. In our case, the electorate is one party and the candidate who earns the vote is the other. Without having a controlling central authority body, the block chain can be implemented in a more stable manner in mass electoral voting practise. A voting system that uses a more stable, tamper-proof block chain (immutable to voting modifications either by other voters or by any third party) and is cost-effective.
Everyone should have the right to expression and opinion without interference. Nevertheless, Internet censorship is often misused to block freedom of speech. The distributed ledger technology provides a globally shared database that is geographically distributed and that cannot be controlled by a central authority. Blockchain is an emerging technology that enabled distributed ledgers and has recently been employed for building various types of applications. This paper demonstrates a unique application of blockchain technologies to create a platform that supports the freedom of expression. The paper adapts permissionless and public blockchains in order to leverage their advantages of providing an immutable and tamper-proof digital ledger. The study shows the blockchain potential for providing censorship-resistant publication platform. The paper presents and evaluates possible methods for building such system using the Bitcoin and Ethereum blockchain networks. Our results demonstrate that the Ethereum blockchain is much more beneficial for our system as it requires much lower cost than Bitcoin. to use as a platform to allow freedom of speech.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Yousif Abuidris, Rajesh Kumar, Ting Yang, Joseph Ochieng Onginjo
The evolution of blockchain-based systems has enabled researchers to develop next-generation e-voting systems. However, the classical consensus method of blockchain, that is, Proof-of-Work, as implemented in Bitcoin, has a significant impact on energy consumption and compromises the scalability, efficiency, and latency of the system. In this paper, we propose a hybrid consensus model (PSC-Bchain) composed of Proof of Credibility and Proof of Stake that work mutually to address the aforementioned problems to secure e-voting systems. Smart contracts are used to provide a trustworthy public bulletin board and a secure computing environment to ensure the accuracy of the ballot outcome. We combine a sharding mechanism with the PSC-Bchain hybrid approach to emphasize security, thus enhancing the scalability and performance of the blockchain-based e-voting system. Furthermore, we compare and discuss the execution of attacks on the classical blockchain and our proposed hybrid blockchain, and analyze the security. Our experiments yielded new observations on the overall security, performance, and scalability of blockchain-based e-voting systems.
This paper presents Adamastor, a new low latency and scalable decentralized anonymous payment system, which is an extension of Ring Confidential Transactions (RingCT) that is compatible with consensus algorithms that use Delegated Proof of Stake (DPoS) as a defense mechanism against Sybil attacks. Adamastor also includes a new Decoy Selection Algorithm (DSA) that can be of independent interest, called SimpleDSA, a crucial aspect of protocols that use ring signatures to anonymize the sender. SimpleDSA offers security against homogeneity attacks and chain analysis. Moreover, it enables the pruning of spent outputs, addressing the issue of perpetual output growth commonly associated with such schemes. Adamastor is implemented and evaluated using the Narwhal consensus algorithm, demonstrating significantly lower latency compared to Proof of Work based cryptocurrencies. Adamastor also exhibits ample scalability, making it suitable for a decentralized and anonymous payment network.
Xiaoyu Ma, Jiting Zhou, Xiumei Yang, Guangyuan Liu
A blockchain voting system based on the feedback mechanism and Wilson score is proposed to solve the problem of the malicious votes behavior. Firstly, the relatively accurate supporting rate and ranking for candidates are obtained using the Wilson score. Secondly, different feedback coefficients are calculated according to the above parameters. Finally, the account points are adjusted according to the feedback coefficients. The feedback mechanism is designed in the voting smart contract, and the smart contract is deployed on the blockchain to ensure the enforcement of the feedback mechanism. A fully functional smart contract is designed and briefly verified in this paper. The experiment is conducted under the K-out-of-L type of weighted voting. Experimental results show that the Wilson score can accurately modify the candidates’ supporting rates, and the feedback mechanism can effectively suppress malicious votes.
Data privacy and sharing has always been a critical issue when trying to\nbuild complex deep learning-based systems to model data. Facilitation of a\ndecentralized approach that could take benefit from data across multiple nodes\nwhile not needing to merge their data contents physically has been an area of\nactive research. In this paper, we present a solution to benefit from a\ndistributed data setup in the case of training deep learning architectures by\nmaking use of a smart contract system. Specifically, we propose a mechanism\nthat aggregates together the intermediate representations obtained from local\nANN models over a blockchain. Training of local models takes place on their\nrespective data. The intermediate representations derived from them, when\ncombined and trained together on the host node, helps to get a more accurate\nsystem. While federated learning primarily deals with the same features of data\nwhere the number of samples being distributed on multiple nodes, here we are\ndealing with the same number of samples but with their features being\ndistributed on multiple nodes. We consider the task of bank loan prediction\nwherein the personal details of an individual and their bank-specific details\nmay not be available at the same place. Our aggregation mechanism helps to\ntrain a model on such existing distributed data without having to share and\nconcatenate together the actual data values. The obtained performance, which is\nbetter than that of individual nodes, and is at par with that of a centralized\ndata setup makes a strong case for extending our technique across other\narchitectures and tasks. The solution finds its application in organizations\nthat want to train deep learning models on vertically partitioned data.\n
With the transformation in smart grids, power grid companies are becoming increasingly dependent on data networks. Data networks are used to transport information and commands for optimizing power grid operations: Planning, generation, transportation, and distribution. Performing periodic security audits is one of the required tasks for securing networks, and we proposed in a previous work autoauditor, a system to achieve automatic auditing. It was designed according to the specific requirements of power grid companies, such as scaling with the huge number of heterogeneous equipment in power grid companies. Though pentesting and security audits are required for continuous monitoring, collaboration is of utmost importance to fight cyber threats. In this paper we work on the accountability of audit results and explore how the list of audit result records can be included in a blockchain, since blockchains are by design resistant to data modification. Moreover, blockchains endowed with smart contracts functionality boost the automation of both digital evidence gathering, audit, and controlled information exchange. To our knowledge, no such system exists. We perform throughput evaluation to assess the feasibility of the system and show that the system is viable for adaptation to the inventory systems of electrical companies.
Digital watermarking can be used to implement mechanisms aimed at protecting the copyright of digital content distributed on the Internet. Such mechanisms support copyright identification and content tracking by enabling content providers to embed perceptually invisible watermarks into the distributed copies of content. They are employed in conjunction with watermarking protocols, which define the schemes of the web transactions by which buyers can securely purchase protected digital content distributed by content providers. In this regard, the “buyer friendly” and “mediated” watermarking protocols can ensure both a correct content protection and an easy participation of buyers in the transactions by which to purchase the distributed content. They represent a valid alternative to the classic “buyer and seller” watermarking protocols documented in the literature. However, their protection schemes could be further improved and simplified. This paper presents a new watermarking protocol able to combine the “buyer friendly” and “mediated” design approach with the blockchain technology. The result is a secure protocol that can support a limited and balanced participation of both buyers and content providers in the purchase transactions of protected digital content. Moreover, the protocol can avoid the direct involvement of trusted third parties in the purchase transactions. This can reduce the actual risk that buyers or sellers can violate the protocol by illicitly interacting with trusted third parties. In fact, such peculiarities make the proposed protocol suited for the current web context.
Open access
Advanced Steganography and Watermarking Techniques
Lei Wu, Yufeng Hu, Yajin Zhou, Haoyu Wang · 8 authors
One reason for the popularity of Bitcoin is due to its anonymity. Although several heuristics have been used to break the anonymity, new approaches are proposed to enhance its anonymity at the same time. One of them is the mixing service. Unfortunately, mixing services have been abused to facilitate criminal activities, e.g., money laundering. As such, there is an urgent need to systematically understand Bitcoin mixing services. In this paper, we take the first step to understand state-of-the-art Bitcoin mixing services. Specifically, we propose a generic abstraction model for mixing services and observe that there are two mixing mechanisms in the wild, i.e. {swapping} and {obfuscating}. Based on this model, we conduct a transaction-based analysis and successfully reveal the mixing mechanisms of four representative services. Besides, we propose a method to identify mixing transactions that leverage the obfuscating mechanism. The proposed approach is able to identify over $92$\% of the mixing transactions. Based on identified transactions, we then estimate the profit of mixing services and provide a case study of tracing the money flow of stolen Bitcoins.
5G communications proposed significant improvements over 4G in terms of efficiency and security. Among these novelties, the 5G Network Slicing seems to have a prominent role: deploy multiple virtual network slices, each providing a different service with different needs and features. Like this, a Slice Operator (SO) ruling a specific slice may want to offer a service for users meeting some requirements. It is of paramount importance to provide a robust authentication protocol, able to ensure that users meet the requirements, but providing at the same time a privacy-by-design architecture. This makes even more sense having a growing density of Internet of Things (IoT) devices exchanging private information over the network. In this paper, we improve the 5G network slicing authentication using a Self-Sovereign Identity (SSI) scheme: granting users full control over their data. We introduce an approach to allow a user to prove his right to access a specific service without leaking any information about him. Such an approach is SANS, a protocol that provides non-linkable protection for any issued information, preventing an SO or an eavesdropper from tracking users' activity and relating it with their real identities. Furthermore, our protocol is scalable and can be taken as a framework for improving related technologies in similar scenarios, like authentication in the 5G Radio Access Network (RAN) or other wireless networks and services. Such features can be achieved using cryptographic primitives called Zero-Knowledge Proofs (ZKP). Upon implementing our solution using a state-of-the-art ZKP library and performing several experiments, we provide benchmarks demonstrating that our approach is affordable in speed and memory consumption.
The Bitcoin P2P network is at the core of all communications between clients.\nThe reachable part of this network has been explored and analyzed by numerous\nstudies. Unreachable nodes, however, are, in most part, overlooked.\nNonetheless, they are a relevant part of the network and play an essential role\nin the propagation of messages. In this paper, we focus on transaction\npropagation and show that increasing the participation of unreachable nodes can\npotentially improve the robustness and efficiency of the network. In order to\ndo that, we propose a few changes to the network protocol. Additionally, we\ndesign a novel transaction propagation protocol that explicitly involves\nunreachable nodes to provide better protection against deanonymization attacks.\nOur solutions are simple to implement and can effectively bring immediate\nbenefits to the Bitcoin network.\n
Stanisław Barański, Julian Szymański, Andrzej Sobecki, David Gil · 5 authors
In this paper, we propose a privacy-preserving i-voting system based on the public Stellar Blockchain network. We argue that the proposed system satisfies all requirements stated for a robust i-voting system including transparency, verifiability, and voter anonymity. The practical architecture of the system abstracts a voter from blockchain technology used underneath. To keep user privacy, we propose a privacy-first protocol that protects voter anonymity. Additionally, high throughput and low transaction fees allow handling large scale voting at low costs. As a result we built an open-source, cheap, and secure system for i-voting that uses public blockchain, where everyone can participate and verify the election process without the need to trust a central authority. The main contribution to the field is a method based on a blind signature used to construct reliable voting protocol. The proposed method fulfills all requirements defined for i-voting systems, which is challenging to achieve altogether.
In agreements among anonymous users, smart contracts eliminate the need for a trusted intermediary and enforce its terms when the conditions set by the parties are met. Although smart contracts are mostly used for positive purposes, they have also been used for illegal activities due to their appealing characteristics in the criminal context. More specifically, a smart contract stimulates new forms of trustless collaboration among cybercriminals and the trend toward criminal use of smart contract can be more dangerous in collaborative attacks in terms of attacks' destructive power and sophistication.
In this paper, we present an architecture for real-world collaborative attacks based on criminal smart contracts (CSCs). We propose a CSC for the case of a collaborative distributed denial of service attack. In order to explore the feasibility and capture the characteristic of the attack-result, we formulate the attackers' interaction as an incomplete information game and prove that it has a unique dominant strategy equilibrium. We also model the proposed CSC as an incentive mechanism and prove that it is a strategy-proof and budget-balanced mechanism. Our numerical simulations show that the proposed incentive mechanism provides individual rationality and fairness to the collaborating attackers in its equilibrium.
Internet of Things (IoT) devices facilitate intelligent service delivery in a broad range of settings, such as smart offices, homes and cities. However, the existing IoT access control solutions are mainly based on conventional identity management schemes and use centralized architectures. There are known security and privacy limitations with such schemes and architectures, such as the single-point failure or surveillance (e.g., device tracking). Hence, in this paper, we present an architecture for capability-based IoT access control utilizing the blockchain and decentralized identifiers to manage the identity and access control for IoT devices. Then, we propose a protocol to provide a systematic view of system interactions, to improve security. We also implement a proof-of-concept prototype of the proposed approach and evaluate the prototype using a real-world use case. Our evaluation results show that the proposed solution is feasible, secure, and scalable.
Dan Boneh, Saba Eskandarian, Lucjan Hanzlik, Nicola Greco
In a Single Secret Leader Election (SSLE), a group of participants aim to randomly choose exactly one leader from the group with the restriction that the identity of the leader will be known to the chosen leader and nobody else. At a later time, the elected leader should be able to publicly reveal her identity and prove that she has won the election. The election process itself should work properly even if many registered users are passive and do not send any messages. Among the many applications of SSLEs, their potential for enabling more efficient proof-of-stake based cryptocurrencies have recently received increased attention.