Federated learning (FL) has gained significant attention in distributed machine learning due to its ability to protect data privacy while enabling model training across decentralized data sources. However, traditional FL methods face challenges in ensuring trust, security, and efficiency, particularly in heterogeneous environments with varying computational capacities. To address these issues, we propose a blockchain-based trusted federated learning method that integrates FL with consortium blockchain technology. This method leverages computational power registration to group participants with similar resources into private chains and employs cross-chain communication with a central management chain to ensure efficient and secure model aggregation. Our approach enhances communication efficiency by optimizing the model update process across chains, and it improves security through blockchain’s inherent transparency and immutability. The use of smart contracts for participant verification, model updates, and auditing further strengthens the trustworthiness of the system. Experimental results show significant improvements in communication efficiency, model convergence speed, and security compared to traditional federated learning methods. This blockchain-based solution provides a robust framework for creating secure, efficient, and scalable federated learning environments, ensuring reliable data sharing and trustworthy model training.
Xin Wang, Li Jiaqian, Ding Xueshuang, H. Zhang · 5 authors
The problem of data privacy protection in the information age deserves people’s attention. As a distributed machine learning technology, federated learning can effectively solve the problem of privacy security and data silos. Differential privacy(DP) technology is applied in federated learning(FL). By adding noise to raw data and model parameters, it can further enhance the degree of data privacy protection. Over the years, differential privacy technology based on federated learning framework has been developed, which is divided into central differential privacy federated learning(CDPFL) and local differential privacy federated learning(LDPFL). Although differential privacy may reduce the accuracy and convergence of federated learning models while protecting data privacy, researchers have proposed a variety of optimization methods to balance privacy protection and model performance. This paper comprehensively expounds the research status of differential privacy techniques based on the federated learning framework, first providing detailed introductions to federated learning and differential privacy technologies, and then summarizing the development status of two types of federated learning differential privacy(DPFL) techniques respectively; for CDPFL, the paper divides the discussion into first proposal of CDP and typical application examples, the impact of Gaussian mechanisms on model accuracy, optimization based on asynchronous differential privacy, and insights from other scholars; for LDPFL, the paper divides the discussion into first proposal of LDP and typical application examples, processing multidimensional data and improving model accuracy, existing methods and optimization for reducing communication costs, balancing privacy protection and data usability, LDPFL based on the Shuffle model, and insights from other scholars; following this, the paper addresses and summarizes the unique challenges introduced by incorporating differential privacy into federated learning and proposes solutions; finally, based on a summary of existing optimization techniques, the paper outlines future directions and specifically discusses three research ideas for enhancing the optimization effects of federated differential privacy: advanced optimization strategies combining Bayesian methods and the Alternating Direction Method of Multipliers (ADMM), integrating lattice homomorphic encryption techniques from cryptography to achieve more efficient differential privacy protection in federated learning, and exploring the application of zero-knowledge proof techniques in federated learning for privacy protection.
This research proposes a Blockchain-driven solution for enhancing the integrity and security of clinical trials, introducing a specialized system called Blockchain for Securing Clinical Trials (BC-SCT). The system reimagines traditional clinical trial data management by offering a decentralized, tamper-resistant platform that ensures trust, transparency, and efficiency across stakeholders including researchers, sponsors, and regulatory bodies.BC-SCT employs modern consensus mechanisms such as Proof-of-Authority (PoA) and Delegated Proof of Stake (DPoS) to significantly reduce transaction processing delays—from 900 ms to 550 ms across 50 transactions—ensuring faster data validation without compromising reliability. It also demonstrates strong performance under simultaneous query loads, cutting response times from 70 ms to 40 ms, a 43% improvement in real-time data access. To handle the scale and complexity of clinical data, the system incorporates features like data sharding, in-memory caching, and off-chain storage. These enhancements reduce Blockchain ledger load by 20%, lowering storage requirements from 100 GB to 80 GB for 10,000 entries—while maintaining high-speed access and data fidelity. Through these innovations, BC-SCT offers a future-proof foundation for conducting and overseeing clinical trials, addressing long-standing issues related to data manipulation, inefficiency, and lack of transparency in research workflows.
Identification, authentication, and authorization processes can be conducted in various ways. Particular attention is given to the processes implemented within the self-sovereign identity paradigm. This paper analyses the processes from a data leak perspective. A comparison is made between self-sovereign identity and a centralized identity provider scheme. An overview of the relevant implementations for these processes is provided: in both the self-sovereign and non-sovereign paradigms. It has been found that, from the data leaks perspective, the self-sovereign identity scheme could only provide superior security if zero-knowledge proof technology is applied.
Abstract With the continuous development of network technology, cryptographic protocols are facing diverse and complex security challenges. Blockchain technology, as a solution incorporating decentralization, traceability, programmability, and immutability, effectively enhances the security, trustworthiness, operational efficiency, and ensures the security and integrity of data storage in traditional cryptographic protocols. Consequently, it has gradually emerged as a focal point of research in cryptographic protocols. This manuscript delves into the ongoing research concerning the application of blockchain technology in cryptographic protocols. First, this manuscript introduces the background of blockchain research in cryptographic protocols and the corresponding basic knowledge. Secondly, we delve into the main concerns of traditional cryptographic protocols, with a particular focus on security and performance. Thirdly, according to the main classification of cryptographic protocols, the latest research results of blockchain in authentication protocols, authentication and key agreement protocols, and e-commerce protocols are presented. Finally, the research directions of blockchain technology in cryptographic protocols are summarized based on the existing research, and the future development trend is also prospected.
The massive data generated by the Internet of Things (IoT) is often outsourced to the cloud, leading to a separation between data ownership and management. Access control during the data’s validity period and assured deletion once that period expires are both crucial for protecting privacy. While recent research has primarily focused on access control, assured deletion has received less attention. Existing assured deletion schemes can be classified into key-control based and cryptographic policy based methods, but to varying degrees, they have limitations such as requiring a trusted third party, high encryption overhead, lack of support for deletion verification and fine-grained access control. To address these limitations, we propose BBAD, a blockchain-based assured deletion scheme that leverages smart contracts for fine-grained access control, employs Shamir secret sharing and re-encryption for assured key deletion, and utilizes Merkle Hash Tree (MHT) for public deletion verification. Notably, BBAD eliminates the need for a trusted third party, exhibits low computational overhead, supports customizable deletion time limit, and enables offline verification of deletion for users. Our experimental comparison with two prominent alternatives, Secure Electronic-Document Self-Destructing with Identity-Based Timed-Release Encryption (ESITE) and Key-Policy Attribute-Based Encryption for Assured Deletion (AD-KP-ABE), demonstrates that BBAD reduces data processing time by over 46.5%, data deletion time by 98.4%, and deletion verification time by 99.0%.
One revolutionary way to tackle privacy and security issues in federated learning (FL) is to include blockchain technology and zero-knowledge proofs (ZK) into machine learning frameworks. To strengthen FL's defences against threats such as model poisoning attacks, this work investigates the use of ZK proofs. This study presents a new technique that uses secure multi-party computation (MPC) to efficiently detect poisoned models, addressing the shortcomings of previous ZK systems. Data anonymization, encryption of sensitive information, and encoding of categorical data all contribute to the proposed model's privacy-preserving features. Adding a privacy-protecting layer is an integral part of ML model integration. ZK circuits employ ZK-SNARKs or Bulletproofs to generate proofs that the ML model may use to predict without disclosing the data. ZK-SNARKs are trusted, and request validation and data access rules control proof access.
In the era of decentralized identity management within blockchain ecosystems, ensuring user privacy during authentication processes is a critical concern. This dissertation addresses the challenge of privacypreserving authentication within decentralized identity management systems, specifically on the Algorand blockchain platform. As digital identity solutions become critical in today’s interconnected world, traditional centralized models expose user data to substantial privacy and security risks, such as data breaches, identity theft, and unauthorized access. The research leverages Algorand’s pure proof of stake (PPoS) consensus mechanism, recognized for its scalability and energy efficiency, along with cryptographic techniques such as zero-knowledge proofs (ZKPs) and the Pedersen commitment scheme. The primary contribution of this dissertation is the development of a proof of concept decentralized application (DApp) designed for secure and anonymous voting, designed to balance data protection with usability within the context of Dharma Teams, a decentralized application of Yari Labs. By incorporating cryptographic primitives such as anonymous credentials and secure, decentralized authentication protocols, the DApp demonstrates how user privacy can be maintained even in open blockchain environments. The framework developed within this research not only ensures user anonymity, but also upholds the integrity and transparency of the authentication process. Furthermore, this dissertation explores the applicability of these privacy-preserving methods in various use cases, including decentralized finance, supply chain management, and verification of digital identity. Through a blend of theoretical insights and practical implementation, this work lays a pathway toward more secure and use centric digital ecosystems on Algorand and similar platforms.
Frequent user data breaches and misuse incidents highlight the flaws in current identity management systems. This study proposes a blockchain-based, peer-supervised self-sovereign identity (SSI) generation and privacy protection technology. Our approach creates unique digital identities on the blockchain, enabling secure cross-domain recognition and data sharing and satisfying the essential users' requirements for SSI. Compared to existing SSI solutions, our approach has the practical advantages of less implementation cost, ease of users' understanding and agreement, and better possibility of being soon adopted by current society and legal systems. The key innovative technical features include (1) using a zero-knowledge proof technology to ensure data remain "usable but invisible", mitigating data breach risks; (2) introducing a peer review mechanism among service providers to prevent excessive data requests and misuse; and (3) implementing a comprehensive multi-party supervision system to audit all involved parties and prevent misconduct.
Jianping Yu, Hang Yao, Kai Ouyang, Xiaojun Cao · 5 authors
Federated Learning (FL) enables clients to securely share gradients computed on their local data with the server, thereby eliminating the necessity to directly expose their sensitive local datasets. In traditional FL, the server might take advantage of its dominant position during the model aggregation process to infer sensitive information from the shared gradients of the clients. At the same time, malicious clients may submit forged and malicious gradients during model training. Such behavior not only compromises the integrity of the global model, but also diminishes the usability and reliability of trained models. To effectively address such privacy and security attack issues, this work proposes a Blockchain-based Privacy-preserving and Secure Federated Learning (BPS-FL) scheme, which employs the threshold homomorphic encryption to protect the local gradients of clients. To resist malicious gradient attacks, we design a Byzantine-robust aggregation protocol for BPS-FL to realize the cipher-text level secure model aggregation. Moreover, we use a blockchain as the underlying distributed architecture to record all learning processes, which ensures the immutability and traceability of the data. Our extensive security analysis and numerical evaluation demonstrate that BPS-FL satisfies the privacy requirements and can effectively defend against poisoning attacks.
Yalan Wang, Liqun Chen, Long Meng, Christopher J. P. Newton
Concerns about how third parties manage personal information have led to the development of decentralized identities (DIDs) and verifiable credentials (VCs). The World Wide Web Consortium (W3C) working group has been developing standards for DIDs and VCs. In the W3C standards, a DID identifies an entity (a DID holder) and a VC confirms that this DID holder has some associated attributes. A DID holder can obtain many VCs and confirm any number of these VCs to others (verifiers) in verifiable presentations (VPs). In order to keep a holder’s identity and attributes private, it is necessary to achieve anonymous VPs that allows this information to be kept confidential. The W3C working group recommends using randomizable signatures to create VCs with zero-knowledge proofs for this purpose. However, the anonymous VPs provided by the this method are limited that in the real world, credentials in cross domains cannot be universally verified. To overcome this limitation, in this paper, we propose a new scheme, called Verifiable Credentials with anonymous DIDs (VCaDID), which aims to achieve anonymous VPs in cross-domain settings. The main technique in our VCaDID scheme is a ring signature with multiple attributes by hiding a holder’s public key among a ring of holders. In our scheme, we set private keys associated with the holder’s DID and attributes, which allow the holder to anonymously present these credentials in a verifiable way. We also prove that the proposed VCaDID scheme satisfies correctness, anonymity and unforgeability under security assumptions of discrete log and random oracle model. Finally, we implement our scheme to demonstrate its feasibility.
Dongliang Cai, Liang Zhang, Borui Chen, Haibin Kan
Decentralized data sovereignty and secure data exchange are regarded as foundational pillars of the new era. Attribute-based encryption (ABE) is a promising solution that enables fine-grained access control in data sharing. Recently, Hohenberger et al. (Eurocrypt 2023) introduced registered ABE (RABE) to eliminate trusted authority and gain decentralization. Users generate their own public and secret keys and then register their keys and attributes with a transparent key curator. However, RABE still suffers from heavy decryption overhead. A natural approach to address this issue is to outsource decryption to a decryption cloud server (DCS). In this work, we propose the first auditable RABE scheme with reliable outsourced decryption (ORABE) based on blockchain. First, we achieve verifiability of transform ciphertext via a verifiable tag mechanism. Then, the exemptibility, which ensures that the DCS escapes false accusations, is guaranteed by zero knowledge fraud proof under the optimistic assumption. Additionally, our system achieves fairness and auditability to protect the interests of all parties through blockchain. Finally, we give concrete security and theoretical analysis and evaluate our scheme on Ethereum to demonstrate feasibility and efficiency.
Cai, Dongliang, Borui Chen, Liang Zhang, Haibin Kan
Attribute-based encryption (ABE) is a generalization of public-key encryption that enables fine-grained access control in cloud services. Recently, Hohenberger et al. (Eurocrypt 2023) introduced the notion of registered ABE, which is an ABE scheme without a trusted central authority. Instead, users generate their own public/secret keys and then register their keys and attributes with a key curator. The key curator is a transparent and untrusted entity and its behavior needs to be audited for malicious registration. In addition, pairing-based registered ABE still suffers the heavy decryption overhead like ABE. A general approach to address this issue is to outsource decryption to a decryption cloud service (DCS).In this work, we propose BA-ORABE, the first fully auditable registered ABE with reliable outsourced decryption scheme based on blockchain. First, we utilize a verifiable tag mechanism to achieve verifiability of ciphertext transformation, and the exemptibility which enables the honest DCS to escape from wrong claims is guaranteed by zero knowledge fraud proof under optimistic assumption. Additionally, our system achieves fairness and decentralized outsourcing to protect the interests of all parties and the registration and outsourcing process are transparent and fully auditable through blockchain. Finally, we give security analysis, implement and evaluate our scheme on Ethereum to demonstrate its feasibility and efficiency, and show its advantages in real application of decentralized finance.
State-of-the-art blockchain sharding solutions, such as Monoxide, can cause severely imbalanced distribution of transaction (TX) workloads across all blockchain shards due to the deployment policy of their accounts. Imbalanced TX distributions then producehot shards, in which the cross-shard TXs may experience an unlimited confirmation latency. Thus, how to address the hot-shard issue and how to reduce cross-shard TXs become significant challenges of blockchain sharding. Through reviewing the related studies, we find that a cross-shard TX protocol that can achieve workload balance among all shards and simultaneously reduce the quantity of cross-shard TXs is still absent from the literature. To this end, we propose BrokerChain, which is a cross-shard blockchain protocol dedicated to account-based state sharding. Essentially, BrokerChain exploits fine-grained state partition and account segmentation. We also elaborate on how BrokerChain handles cross-shard TXs through broker accounts. The security issues and other properties of BrokerChain are analyzed rigorously. Finally, we conduct comprehensive evaluations using an open-source blockchain sharding prototype namedBlockEmulator. The evaluation results show that BrokerChain outperforms other baselines in terms of transaction throughput, transaction confirmation latency, the queue size of the transaction pool, and workload balance.
Data sharing is ubiquitous in the metaverse, which adopts blockchain as its foundation. Blockchain is employed because it enables data transparency, achieves tamper resistance, and supports smart contracts. However, securely sharing data based on blockchain necessitates further consideration. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising primitive to provide confidentiality and fine-grained access control. Nonetheless, authority accountability and key abuse are critical issues that practical applications must address. Few studies have considered CP-ABE key confidentiality and authority accountability simultaneously. To our knowledge, we are the first to fill this gap by integrating non-interactive zero-knowledge (NIZK) proofs into CP-ABE keys and outsourcing the verification process to a smart contract. To meet the decentralization requirement, we incorporate a decentralized CP-ABE scheme into the proposed data sharing system. Additionally, we provide an implementation based on smart contract to determine whether an access control policy is satisfied by a set of CP-ABE keys. We also introduce an open incentive mechanism to encourage honest participation in data sharing. Hence, the key abuse issue is resolved through the NIZK proof and the incentive mechanism. We provide a theoretical analysis and conduct comprehensive experiments to demonstrate the feasibility and efficiency of the data sharing system. Based on the proposed accountable approach, we further illustrate an application in GameFi, where players can play to earn or contribute to an accountable DAO, fostering a thriving metaverse ecosystem.
Ensuring security for highly dynamic peer-to-peer (P2P) networks has always been a challenge, especially for services like online transactions and smart devices. These networks experience high churn rates, making it difficult to maintain appropriate access control. Traditional systems, particularly Role-Based Access Control (RBAC), often fail to meet the needs of a P2P environment. This paper presents a blockchain-based access control framework that uses Ethereum smart contracts to address these challenges. Our framework aims to close the gaps in existing access control systems by providing flexible, transparent, and decentralized security solutions. The proposed framework includes access control contracts (ACC) that manage access based on static and dynamic policies, a Judge Contract (JC) to handle misbehavior, and a Register Contract (RC) to record and manage the interactions between ACCs and JC. The security model combines impact and severity-based threat assessments using the CIA (Confidentiality, Integrity, Availability) and STRIDE principles, ensuring responses are tailored to different threat levels. This system not only stabilizes the fundamental issues of peer membership but also offers a scalable solution, particularly valuable in areas such as the Internet of Things (IoT) and Web 3.0 technologies.
Covid19 pandemic has affected many sectors including education. All types of schools (public and private) have started to provide online education systems to their students to prevent spreading the disease. The online education system has brought many advantages besides stopping the spread of the disease. The students have more time since the lectures are not in class, it reduces the cost for the students since they physically do not go to school, and it provides flexibility in the lectures that students decide their schedule to attend the classes. However, there are some challenges in the online education system. The system needs to be available for the students when they take exams, view their exam results, and upload their exams for assessment. Since the lectures and exams are taken online, the data is very crucial. The data contains sensitive information such as exams, answers, scores, name, date of birth, address, phone number, government identification number, etc. A traditional online education system has a centralized infrastructure governed and managed by a single entity. This results in the system having single-point-of-failure attacks. This paper proposes an online examination system based on a smart contract and a blockchain. The blockchain eliminates single-point-of-failure attacks. The teachers write questions and store them in the blockchain. Only authorized students retrieve the exams from the blockchain by using smart contracts. The students submit their completed exams at predefined times. Then, the teachers evaluate the students’ exams and put the results into the blockchain. Their exam scores are protected from any unauthorized entities by encryption. Students can freely see and view their scores at any time. Then, the students can show their results to any other third parties (once they apply for an internship or job) that they have completed the courses successfully. The system also uses a decentralized storage (off-chain) system to eliminate scalability problems. Off-chain storage (InterPlanetary File System) stores students’ exams, answers, and exam results while the corresponding content identifiers of the files are stored in the blockchain. The proposed system is resilient to malicious teachers who can manipulate the exam results. In addition, the proposed system also provides a method for dishonest students who can complain about their exam results. In other words, the proposed system solves any conflicts between entities.
What will computer security look like in the year 2100? This talk will begin with a few predictions that aim to suggest a few research directions in the present. We will then transition to the exciting area of applied zero knowledge proofs, an area that has seen tremendous growth in recent years. We will describe some of the new ideas in the space and focus on a number of remarkable real-word applications of these techniques. The talk will be self contained and accessible to all.
Alex Berke, Tobin South, Robert Mahari, Kent Larson · 5 authors
Tax returns contain financial information of interest to third parties: public officials are asked to share financial data for transparency, companies seek to assess the financial status of business partners, and individuals need to prove their income to third-parties.Tax returns also contain sensitive data such that sharing them in their entirety undermines privacy.We outline how zero-knowledge cryptography may be applied to address this tension by allowing individuals and organizations to make provable claims about select information in their tax returns without revealing additional information, in a way that can be independently verified by third parties.We highlight key system goals and design specifications for this zero-knowledge tax disclosure system (zkTax) and present a prototype implementation.The prototype consists of three distinct services that can be distributed: a tax authority that provides signed tax documents; a Redact & Prove Service that enables users to redact tax documents and produce a zero-knowledge proof attesting the provenance of the redacted data; and a Verify Service to check the validity of claims.We demonstrate how zkTax could be implemented with minimal changes to existing tax infrastructure, allowing the system to be extensible to other contexts and jurisdictions.This work provides a practical example of how distributed tools leveraging cryptography can enhance existing government or financial infrastructures, providing immediate transparency alongside privacy without system overhauls.
The rise of Autonomous Vehicles (AVs) brings with it the need for secure and privacy-preserving machine learning models. Federated Learning (FL) allows AVs to collaboratively train models while keeping raw data localized. However, traditional FL systems are vulnerable to security threats, including adversarial attacks, data breaches, and dependency on a central aggregator, which can be a single point of failure. To address these concerns, this paper introduces a peer-to-peer decentralized federated learning system that integrates lightweight blockchain technology and Binius Zero- Knowledge Proofs (ZKPs) to enhance security and privacy. In this system, Binius ZKPs ensure that model updates are cryptographically verified without exposing sensitive information, guaranteeing data confidentiality and integrity during the learning process. The lightweight blockchain framework secures the network by creating an immutable, decentralized record of all model updates, thus preventing tampering, fraud, or unauthorized modifications. This decentralized approach eliminates the need for a central aggregator, significantly enhancing system resilience to attacks and making it suitable for dynamic environments like AV networks. Additionally, the system's design includes Byzantine resilience, providing protection against adversarial nodes and ensuring that the global model aggregation process remains robust even in the presence of malicious actors. Extensive performance evaluations demonstrate that the system achieves low-latency, scalability, and efficient resource usage while maintaining strong security and privacy guarantees, making it an ideal solution for real-time federated learning in autonomous vehicle networks. The proposed framework not only ensures privacy but also fosters trust among participants in a fully decentralized environment.
Ertem Nusret Tas, István András Seres, Yinuo Zhang, Márk Melczer · 7 authors
We introduce a blockchain Fair Data Exchange (FDE) protocol, enabling a storage server to transfer a data file to a client atomically: the client receives the file if and only if the server receives an agreed-upon payment. We put forth a new definition for a cryptographic scheme that we name verifiable encryption under committed key (VECK), and we propose two instantiations for this scheme. Our protocol relies on a blockchain to enforce the atomicity of the exchange and uses VECK to ensure that the client receives the correct data (matching an agreed-upon commitment) before releasing the payment for the decrypting key. Our protocol is trust-minimized and requires only constant-sized on-chain communication, concretely 3 signatures, 1 verification key, and 1 secret key, with most of the data stored and communicated off-chain. It also supports exchanging only a subset of the data, can amortize the server's work across multiple clients, and offers a general framework to design alternative FDE protocols using different commitment schemes. A prominent application of our protocol is the Danksharding data availability scheme on Ethereum, which commits to data via KZG polynomial commitments. We also provide an open-source implementation for our protocol with both instantiations for VECK, demonstrating our protocol's efficiency and practicality on Ethereum.