Medical big data holds significant value in promoting precision medicine, disease prediction, and public health management. However, issues such as sensitivity, decentralization, and privacy security limit its in-depth application. This study proposes a collaborative computing framework based on blockchain and Apache Spark, aiming to address the challenges of privacy protection, cross-institutional sharing, and efficient analysis of medical data. By designing an access control mechanism based on smart contracts and an anonymization scheme utilizing zero-knowledge proofs, combined with Spark's distributed memory computing advantages, a secure and trustworthy platform for medical data analysis is constructed. Experiments demonstrate that this framework improves data processing efficiency by 3.5 times compared to the traditional Hadoop architecture on the MIMIC-III dataset, while also meeting HIPAA privacy standards. This study provides theoretical support and practical pathways for the application of "blockchain + big data" technology in the medical field.
Blockchain technology, a decentralized and immutable ledger, has transformed identity and access management (IAM) by enhancing security, privacy, and trust in digital ecosystems. Ensuring safe authentication and data integrity is made possible by its integration with sophisticated cryptographic techniques like zero-knowledge proofs (ZKPs) and public- key infrastructure (PKI). Other methods include verifiable credentials (VCs) and decentralized identifiers (DIDs). This paper provides a comprehensive analysis of blockchain-based IAM systems, comparing leading blockchain platforms, including Ethereum, Hyperledger Indy, IOTA, and IoTeX, in identity management. The role of blockchain in mitigating identity-related threats, such as identity theft and unauthorized access, is explored through decentralization, immutability, and smart contract automation. Additionally, key security enhancements, including cryptographic mechanisms that strengthen decentralized identity solutions and privacy-preserving authentication, are examined. The potential of blockchain to establish a self-sovereign identity framework that fosters trust, scalability, and security in digital identity ecosystems is highlighted, paving the way for the next generation of identity management solutions.
With the growth of the Internet of Things (IoT), millions of users, devices, and applications compose a complex and heterogeneous network, which increases the complexity of digital identity management. Traditional centralized digital identity management systems (DIMS) confront single points of failure and privacy leakages. The emergence of blockchain technology presents an opportunity for DIMS to handle the single point of failure problem associated with centralized architectures. However, the transparency inherent in blockchain technology still exposes DIMS to privacy leakages. In this paper, we propose the privacy-protected IoT DIMS (PPID), a novel blockchain-based distributed identity system to protect the privacy of on-chain identity data. The PPID achieves the unlinkability of identity-credential-verification. Specifically, the PPID adopts the Zero Knowledge Proof (ZKP) algorithm and Shamir secret sharing (SSS) to safeguard privacy security, resist replay attacks, and ensure data integrity. Finally, we evaluate the performance of ZKP computation in PPID, as well as the transaction fees of smart contract on the Ethereum blockchain.
Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Steganography and Watermarking Techniques
This research investigates privacy protection mechanisms and data security policy optimization for blockchain-based digital rights management platforms to balance transparency with robust privacy protection. A comprehensive experimental framework was developed, integrating advanced cryptographic techniques with intelligent policy management systems. A multi-layered validation methodology employed formal verification, black-box/white-box testing, and stress tests to validate performance across security, efficiency, and usability dimensions. The implemented solution provided 99.99% security assurance while achieving a 47% improvement in processing efficiency through zero-knowledge proofs and homomorphic encryption. Transaction processing reached 3,750 TPS (peaking at 4,200 TPS), with 99.8% regulatory compliance and 99.9% automated policy conflict resolution. The research demonstrates significant advancements in blockchain-based privacy protection through novel cryptographic implementation and automated policy management, establishing a robust framework for secure digital rights management. This solution offers substantial value for content delivery networks, digital asset management systems, financial institutions, and government services where the balance between transparency and privacy is critical, while reducing compliance management costs.
Electronic Health Records (EHRs) are now a necessary component of contemporary healthcare, but managing them presents a number of security, privacy, and interoperability issues. In order to solve these issues, this study introduces a unique framework for EHR management that combines four cutting-edge technologies: blockchain, Zero-Knowledge Proofs (ZKP), Ciphertext-Policy Attribute-Based Encryption (CP-ABE), and InterPlanetary File System (IPFS). Our solution makes use of the Ethereum blockchain for transparent and safe record-keeping, IPFS for efficient and decentralized data storage, CP-ABE for fine-grained access control, and ZKP for private authentication. We offer computational proofs for important components together with a thorough security analysis utilizing formal verification tools like ProVerif and Tamarin Prover. Comparing our framework to other alternatives, the findings show that it provides stronger security guarantees, better privacy protection, and increased scalability. Our approach also defends against a broader variety of possible threats, such as man-inthe-middle attack, repudiation attacks, and side-channel attacks. This work opens the door for more effective and patient-cantered healthcare information systems by advancing secure and privacy-preserving EHR management.
This paper is concerned with a natural variant of the contact process modeling the spread of knowledge on the integer lattice. Each site is characterized by its knowledge, measured by a real number ranging from 0 = ignorant to 1 = omniscient. Neighbors interact at rate $λ$, which results in both neighbors attempting to teach each other a fraction $μ$ of their knowledge, and individuals die at rate one, which results in a new individual with no knowledge. Starting with a single omniscient site, our objective is to study whether the total amount of knowledge on the lattice converges to zero (extinction) or remains bounded away from zero (survival). The process dies out when $λ\leq λ_c$ and/or $μ= 0$, where $λ_c$ denotes the critical value of the contact process. In contrast, we prove that, for all $λ> λ_c$, there is a unique phase transition in the direction of $μ$, and for all $μ> 0$, there is a unique phase transition in the direction of $λ$. Our proof of survival relies on block constructions showing more generally convergence of the knowledge to infinity, while our proof of extinction relies on martingale techniques showing more generally an exponential decay of the knowledge.
Blockchain technology is rapidly evolving, with scalability remaining one of its most significant challenges. While various solutions have been proposed and continue to be developed, it is essential to consider the blockchain trilemma -- balancing scalability, security, and decentralization -- when designing new approaches. One promising solution is the zero-knowledge proof (ZKP)-based rollup, implemented on top of Ethereum. However, the performance of these systems is often limited by the efficiency of the ZKP mechanism. This paper explores the performance of ZKP-based rollups, focusing on a solution built using the Hardhat Ethereum development environment. Through detailed analysis, the paper identifies and examines key bottlenecks within the ZKP system, providing insight into potential areas for optimization to enhance scalability and overall system performance.
Abstract: Automated smart contracts represent a paradigm shift in decentralized governance by integrating artificial intelligence (AI) with blockchain technologies to enhance security, scalability, and adaptability. Traditional smart contracts, while enabling trustless and automated transactions, often lack the flexibility to adapt to dynamic regulatory frameworks, evolving economic conditions, and real-time security threats. AI-powered smart contracts leverage machine learning, reinforcement learning, and predictive analytics to optimize contract execution, detect fraudulent transactions, and enable self-adjusting governance mechanisms in Decentralized Autonomous Organizations (DAOs). Additionally, AI enhances blockchain consensus mechanisms, fraud detection, and risk assessment in Decentralized Finance (DeFi) applications. Privacy-preserving technologies such as zero-knowledge proofs (ZKPs) and quantum-resistant cryptography strengthen the security and confidentiality of AI-driven smart contracts. This research explores the convergence of AI and blockchain, examining how intelligent smart contracts can automate legal compliance, enforce dynamic contract logic, and optimize transaction fees while maintaining transparency and decentralization. By integrating AI-driven decision-making, automated dispute resolution, and scalable execution models, this study provides a comprehensive framework for secure, efficient, and intelligent decentralized governance. Keywords: AI-powered smart contracts, blockchain automation, decentralized governance, reinforcement learning, fraud detection, decentralized finance (DeFi), zero-knowledge proofs, quantum-resistant cryptography, DAO optimization, legal compliance automation.
Artificial Intelligence (AI) is profoundly transforming cryptography by significantly enhancing cryptanalysis techniques and informing innovative cryptographic design approaches. This survey reviews recent advancements in applying deep learning methods to side-channel and differential fault analyses, demonstrating substantial improvements over traditional methods in attack efficiency, accuracy, and resilience. Additionally, it highlights breakthroughs such as neural differential cryptanalysis, which expand classical cryptanalytic boundaries. In cryptographic design, Generative Adversarial Networks (GANs) have successfully automated the creation of high-quality cryptographic primitives, particularly S-boxes. Furthermore, AI shows promise in post-quantum cryptography (PQC) by uncovering potential vulnerabilities and optimizing cryptographic parameters. Despite these advancements, challenges persist regarding data dependency, model generalization, and interpretability. Future research directions emphasize enhancing AI model explainability, creating standardized benchmarks, and integrating AI with emerging technologies such as quantum computing and zero-knowledge proofs.
Open access
Cryptographic Implementations and Security
Chaos-based Image/Signal Encryption
Physical Unclonable Functions (PUFs) and Hardware Security
Modular arithmetic, particularly modular reduction, is widely used in cryptographic applications such as homomorphic encryption (HE) and zero-knowledge proofs (ZKP). High-bit-width operations are crucial for enhancing security; however, they are computationally intensive due to the large number of modular operations required. The lookup-table-based (LUT-based) approach, a ``space-for-time'' technique, reduces computational load by segmenting the input number into smaller bit groups, pre-computing modular reduction results for each segment, and storing these results in LUTs. While effective, this method incurs significant hardware overhead due to extensive LUT usage. In this paper, we introduce ALLMod, a novel approach that improves the area efficiency of LUT-based large-number modular reduction by employing hybrid workloads. Inspired by the iterative method, ALLMod splits the bit groups into two distinct workloads, achieving lower area costs without compromising throughput. We first develop a template to facilitate workload splitting and ensure balanced distribution. Then, we conduct design space exploration to evaluate the optimal timing for fusing workload results, enabling us to identify the most efficient design under specific constraints. Extensive evaluations show that ALLMod achieves up to $1.65\times$ and $3\times$ improvements in area efficiency over conventional LUT-based methods for bit-widths of $128$ and $8,192$, respectively.
Popular technologies such as blockchain and zero-knowledge proof, which have already entered the enterprise space, heavily use cryptography as the core of their protocol stack. One of the most used systems in this regard is Elliptic Curve Cryptography, precisely the point multiplication operation, which provides the security assumption for all applications that use this system. As this operation is computationally intensive, one solution is to offload it to specialized accelerators to provide better throughput and increased efficiency. In this paper, we explore the use of Field Programmable Gate Arrays (FPGAs) and the High-Level Synthesis framework of AMD Vitis in designing an elliptic curve point arithmetic unit (point adder) for the secp256k1 curve. We show how task-level parallel programming and data streaming are used in designing a RISC processor-like architecture to provide pipeline parallelism and increase the throughput of the point adder unit. We also show how to efficiently use the proposed processor architecture by designing a point multiplication scheduler capable of scheduling multiple batches of elliptic curve points to utilize the point adder unit efficiently. Finally, we evaluate our design on an AMD-Xilinx Alveo-family FPGA and show that our point arithmetic processor has better throughput and frequency than related work.
Federated Learning (FL) has emerged as a promising paradigm in distributed machine learning, enabling collaborative model training while preserving data privacy. However, despite its many advantages, FL still contends with significant challenges -- most notably regarding security and trust. Zero-Knowledge Proofs (ZKPs) offer a potential solution by establishing trust and enhancing system integrity throughout the FL process. Although several studies have explored ZKP-based FL (ZK-FL), a systematic framework and comprehensive analysis are still lacking. This article makes two key contributions. First, we propose a structured ZK-FL framework that categorizes and analyzes the technical roles of ZKPs across various FL stages and tasks. Second, we introduce a novel algorithm, Verifiable Client Selection FL (Veri-CS-FL), which employs ZKPs to refine the client selection process. In Veri-CS-FL, participating clients generate verifiable proofs for the performance metrics of their local models and submit these concise proofs to the server for efficient verification. The server then selects clients with high-quality local models for uploading, subsequently aggregating the contributions from these selected clients. By integrating ZKPs, Veri-CS-FL not only ensures the accuracy of performance metrics but also fortifies trust among participants while enhancing the overall efficiency and security of FL systems.
Anne Broadbent, Alex B. Grilo, Nagisa Hara, Arthur Mehta
In a proof of knowledge (PoK), a verifier becomes convinced that a prover possesses privileged information. In combination with zero-knowledge proof systems, PoKs play an important role in security protocols such as in digital signatures and authentication schemes, as they enable a prover to demonstrate possession of certain information (such as a private key or a credential), without revealing it. A PoK is formally defined via the existence of an extractor, which is capable of reconstructing the key information that makes a verifier accept, given oracle access to any accepting prover. We extend this concept to the setting of a single classical verifier and multiple quantum provers and present the first statistical zero-knowledge (ZK) PoK proof system for problems in QMA. To achieve this, we establish the PoK property for the ZK protocol of Broadbent, Mehta, and Zhao (TQC 2024), which applies to the local Hamiltonian problem. More specifically, we construct an extractor which, given oracle access to a provers' strategy that leads to high acceptance probability, is able to reconstruct the ground state of a local Hamiltonian. Our result can be seen as a new form of self-testing, where, in addition to certifying a pre-shared entangled state, the verifier also certifies that a prover has access to a quantum system, in particular, a ground state; this indicates a new level of verification for a proof of quantumness.
Federated learning (FL) enables multiple participants to collaboratively train machine learning models while ensuring their data remains private and secure. Blockchain technology further enhances FL by providing stronger security, a transparent audit trail, and protection against data tampering and model manipulation. Most blockchain-secured FL systems rely on conventional consensus mechanisms: Proof-of-Work (PoW) is computationally expensive, while Proof-of-Stake (PoS) improves energy efficiency but risks centralization as it inherently favors participants with larger stakes. Recently, learning-based consensus has emerged as an alternative by replacing cryptographic tasks with model training to save energy. However, this approach introduces potential privacy vulnerabilities, as the training process may inadvertently expose sensitive information through gradient sharing and model updates. To address these challenges, we propose a novel Zero-Knowledge Proof of Training (ZKPoT) consensus mechanism. This method leverages the zero-knowledge succinct non-interactive argument of knowledge proof (zk-SNARK) protocol to validate participants' contributions based on their model performance, effectively eliminating the inefficiencies of traditional consensus methods and mitigating the privacy risks posed by learning-based consensus. We analyze our system's security, demonstrating its capacity to prevent the disclosure of sensitive information about local models or training data to untrusted parties during the entire FL process. Extensive experiments demonstrate that our system is robust against privacy and Byzantine attacks while maintaining accuracy and utility without trade-offs, scalable across various blockchain settings, and efficient in both computation and communication.
The integration of Zero-Trust Architecture (ZTA) and Blockchain-based Security Models in IoT-driven industrial power electronics systems has emerged as a transformative approach to mitigating cyber threats and ensuring robust access control. Traditional security mechanisms, which rely on perimeter-based defenses, are increasingly ineffective against advanced persistent threats (APTs), insider attacks, and lateral movement techniques within industrial IoT (IIoT) environments. Zero-Trust security enforces continuous verification, least-privilege access, and micro-segmentation, ensuring that no device or user was inherently trusted. Implementing ZTA in resource-constrained IoT ecosystems presents significant challenges related to computational overhead, authentication latency, and secure data transmission. To address these limitations, blockchain technology enhances decentralized identity management, immutable access logs, and tamper-resistant security frameworks, fortifying Zero-Trust-based access control. Privacy-preserving cryptographic techniques, including zero-knowledge proofs (ZKPs) and homomorphic encryption, safeguard sensitive industrial data while maintaining compliance with evolving regulatory frameworks. AI-driven anomaly detection models reinforce continuous authentication and behavior-based threat monitoring, enabling proactive defense mechanisms against zero-day exploits and sophisticated cyber intrusions. This chapter presents a comprehensive analysis of Zero-Trust implementation models for IIoT systems, highlighting the role of secure communication protocols, distributed ledger-based identity verification, and adaptive security automation. The integration of blockchain-enabled access control and AI-powered real-time security analytics ensures a resilient security posture for industrial power electronics networks, mitigating risks associated with unauthorized access, data breaches, and operational disruptions. The proposed framework enhances scalability, privacy, and computational efficiency, paving the way for next-generation cybersecure industrial ecosystems.
Federated learning (FL) is an emerging paradigm that enables multiple clients to collaboratively train a machine learning (ML) model without the need to exchange their raw data. However, it relies on a centralized authority to coordinate participants’ activities. This not only interrupts the entire training task in case of a single point of failure, but also lacks an effective regulatory mechanism to prevent malicious behavior. Although blockchain, with its decentralized architecture and data immutability, has significantly advanced the development of FL, it still struggles to withstand poisoning attacks and faces limitations in computational scalability. We propose Zkfhed, a verifiable and scalable FL system that overcomes the limitations of blockchain-based FL in poison attacks and computational scalability. First, we propose a two-stage audit scheme based on zero-knowledge proofs (ZKPs), which verifies that the training data are extracted from trusted organizations and that computations on the data exactly follow the specified training protocols. Second, we propose a homomorphic encryption delegation learning (HEDL), based on fully homomorphic encryption (FHE). It is capable of outsourcing complex computing to external computing resources without sacrificing the client's data privacy. Final, extensive experiments on real-world datasets demonstrate that Zkfhed can effectively identify malicious clients and is highly efficient and scalable in terms of online time and communication efficiency.
With the development of communication infrastructure and the popularity of smart devices, e-commerce is presenting in more diverse forms and attracting the attention of more and more users. Since e-commerce transactions usually involve sensitive information of a large number of users, privacy and security have become increasingly important issues. Despite certain advantages (e.g., trading security), the privacy protection capability and efficiency of blockchain is still limited by some key factors, especially of its architecture. In this paper, we propose a blockchain-based privacy protection system named PBTMS that integrates zero-knowledge proofs, hybrid encryption, and Pedersen commitments as foundational mechanisms to ensure robust privacy protection for transaction data and user information. To achieve secure, reliable, and efficient e-commerce transactions, the PBTMS employs blockchain technology and consensus mechanisms to enable distributed storage, thereby mitigating single points of failure and addressing the risks posed by malicious nodes. Moreover, by integrating on-chain storage with off-chain computation, the system substantially reduces blockchain-related overheads, including processing time, gas consumption, and storage costs. This design establishes the PBTMS as a highly adaptable and efficient system for the evolving requirements of secure and privacy-preserving e-commerce platforms. Theoretical analysis and experimental validation demonstrate that PBTMS reduces decryption and authentication times by 79.2% and 52.6%, respectively, while cutting encrypted data size by 52.5% and overall gas consumption by 55.4%, outperforming state-of-the-art solutions. These results indicate that PBTMS is a reliable and efficient system for secure e-commerce transaction platforms and provides a novel approach to enhancing privacy protection in e-commerce.
Property transactions in the UK are increasingly adopting blockchain technology to enhance efficiency, transparency, and security. However, the inherent transparency of blockchain raises significant data privacy risks and regulatory compliance challenges, particularly under the UK General Data Protection Regulation (UK GDPR). This study examines the role of Zero-Knowledge Proofs (ZKPs) in addressing these concerns by enabling transaction validation while preserving confidentiality. Using entropy measures, k-anonymity analysis, and logistic regression, this research quantitatively assesses the privacy risks, effectiveness of ZKPs, and regulatory acceptance in blockchain-based property transactions. The findings reveal that 65.5% of transactions remain highly or moderately identifiable, posing privacy vulnerabilities under UK data protection laws. ZKP-enabled transactions significantly enhance confidentiality, achieving a 92.5% transaction privacy score, compared to 48.3% for non-ZKP transactions. However, these privacy gains come at a 67.8% increase in transaction costs, highlighting a critical trade-off between security and efficiency. Regulatory approval rates for ZKP-based blockchain platforms stand at 72.5%, suggesting a strong potential for compliance advantages. While ZKPs improve privacy and regulatory alignment, challenges remain in terms of computational overhead, transaction costs, and adoption barriers. To facilitate large-scale implementation, this study recommends optimizing zk-Rollups for efficiency, developing clear policy frameworks, and enhancing collaboration between regulators, industry stakeholders, and blockchain developers. These steps are essential to ensuring a balance between privacy, scalability, and compliance, paving the way for secure and legally sound blockchain-based property transactions in the UK.
Atsuki Koyama, Kentaroh Toyoda, Manato Fujimoto, Thi Hong Tran
The rapid advancement of deepfake technology poses serious risks, including financial fraud and political misinformation, demanding robust methods for verifying image content authenticity. While the C2PA standard and zero-knowledgeproof-based methods provide an image content authenticity proving mechanism, the existing solutions struggle to efficiently support privacy-preserving edits and iterative modifications. To address these challenges, we propose zk-REAL (Zero-Knowledge-Based Protocol for Repeated Image Edit Authenticity Proof with Lattice Hashing), a framework that leverages a lightweight lattice-based hashing scheme within a zero-knowledge proof system. Our approach significantly reduces computational overhead, enabling faster proof generation and smaller proof size even for high-resolution images. Additionally, the updatability of our hashing method supports iterative edits, such as mosaicking or partial modifications, by minimizing redundant computations. Finally, to ensure compatibility with the C2PA ecosystem and conventional signature verifications, we integrate SHA-256 outside of the zero-knowledge circuit. Our evaluation shows up to a 29% reduction in computational costs for proof generation, showcasing the potential of zk-REAL in practical content authenticity verification scenarios.
Open access
2 source records
Advanced Steganography and Watermarking Techniques
In many-task optimization scenarios, surrogate models are valuable for mitigating the computational burden of repeated fitness evaluations across tasks. This study proposes a novel meta-surrogate framework to assist many-task optimization, by leveraging the knowledge transfer strengths and emergent capabilities of large language models (LLMs). We formulate a unified framework for many-task fitness prediction, by defining a universal model with metadata to fit a group of problems. Fitness prediction is performed on metadata and decision variables, enabling efficient knowledge sharing across tasks and adaptability to new tasks. The LLM-based meta-surrogate treats fitness prediction as conditional probability estimation, employing a unified token sequence representation for task metadata, inputs, and outputs. This approach facilitates efficient inter-task knowledge sharing through shared token embeddings and captures complex task dependencies via multi-task model training. Experimental results demonstrate the model's emergent generalization ability, including zero-shot performance on problems with unseen dimensions. When integrated into evolutionary transfer optimization (ETO), our framework supports dual-level knowledge transfer -- at both the surrogate and individual levels -- enhancing optimization efficiency and robustness. This work establishes a novel foundation for applying LLMs in surrogate modeling, offering a versatile solution for many-task optimization.
In distributed computing, data trading mechanisms are essential for ensuring the sharing of data across multiple computing nodes. Nevertheless, they currently encounter considerable obstacles, including low accuracy in matching trading parties, ensuring fairness in transactions, and safeguarding data privacy throughout the trading process. To address these issues, we put forward a data trading security scheme based on zero-knowledge proofs and smart contracts. In the phase of preparing the security parameters, the objective is to reduce the complexity of generating non-interactive zero-knowledge proofs and to enhance the efficiency of data trading. In the pre-trading phase, we come up with attribute atomic matching smart contracts that are based on precise data property alignment. The goal is to get trading parties to match data attributes in a very specific way. During the trading execution phase, we use lightweight cryptographic algorithms based on Elliptic Curve Cryptography (ECC) and non-interactive zero-knowledge proofs to encrypt trading data twice and make attribute proof contracts. This keeps the data safe and private. The results of experiments conducted on the Ethereum platform in an industrial Internet of Things (IoT) scenario demonstrate that our scheme maintains stable and low-cost consumption while ensuring accuracy in matching and privacy protection. Especially in battery industrial manufacturing, the application of distributed computing is in huge demand and essential to maintaining a healthier technology integration among various systems and technological nodes to perform the better management of energy cells within the battery management system.
This article presents a novel framework for decentralized artificial intelligence model training that combines federated learning with blockchain technology in cloud environments. By integrating these cutting-edge technologies, the article addresses critical challenges in collaborative AI development, including data privacy, secure model sharing, and participant incentivization. The article framework leverages Zero Knowledge Proofs (ZKPs) for enhanced privacy guarantees while utilizing blockchain-based smart contracts to ensure transparent and automated governance of the training process. The implementation demonstrates significant improvements in data transfer efficiency, privacy preservation, system reliability, and participant diversity compared to traditional centralized approaches. The results validate the effectiveness of combining federated learning with blockchain technology for secure, scalable, and efficient distributed AI model training.
Jens Ernstberger, Jan Lauinger, Yulin Wu, Arthur Gervais · 5 authors
Transport Layer Security (TLS) is foundational for safeguarding client-server communication. However, it does not extend integrity guarantees to third-party verification of data authenticity. If a client wants to present data obtained from a server, it cannot convince any other party that the data has not been tampered with. TLS oracles ensure data authenticity beyond the client-server TLS connection, such that clients can obtain data from a server and ensure provenance to any third party, without server-side modifications. Generally, a TLS oracle involves a third party, the verifier, in a TLS session to verify that the data obtained by the client is accurate. Existing protocols for TLS oracles are communication-heavy, as they rely on interactive protocols. We present ORIGO, a TLS oracle with constant communication. Similar to prior work, ORIGO introduces a third party in a TLS session, and provides a protocol to ensure the authenticity of data transmitted in a TLS session, without forfeiting its confidentiality. Compared to prior work, we rely on intricate details specific to TLS 1.3, which allow us to prove correct key derivation, authentication and encryption within a Zero Knowledge Proof (ZKP). This, combined with optimizations for TLS 1.3, leads to an efficient protocol with constant communication in the online phase. Our work reduces online communication by 375× and online runtime by up to 4.6×, compared to prior work.
Stefan Dziembowski, Shahriar Ebrahimi, Parisa Hassanizadeh
Ensuring the authenticity and credibility of daily media on internet is an ongoing problem. Meanwhile, genuinely captured images often require refinements before publication. Zero-knowledge proofs (ZKPs) offer a solution by verifying edited image without disclosing the original source. However, ZKPs typically come with high costs, particularly in terms of prover complexity and proof size. This paper presents VIMz, a framework for efficiently proving the authenticity of high-resolution images using folding-based zkSNARKs; a type of proving system that minimizes computational overhead by recursively folding multiple evaluations of the same constraints into a compact proof. As a complete proof system, VIMz proves the integrity of both the original and edited images, as well as the correctness of the transformation without revealing intermediate images within a chain of edits--only the final result is disclosed. Moreover, VIMz maintains the anonymity of the original signer and all subsequent editors while proving the authenticity of the final image. We also compare VIMz with the system model in Coalition for Content Provenance and Authenticity (C2PA) from different perspectives and show that VIMz offers higher level of security guarantee by eliminating the need to trust the editing environment. Experimental results show that VIMz performs efficiently in both prover and verifier sides. It can prove the transformations on 8K (33MP,i.e., 100MB) images with up to 13%~25% faster than the competition, while reaching to a peak memory of only 10 GB. Moreover, VIMz has a verification time of under 1 second and achieves succinct proofs of less than 11 KB for all resolutions, which is more than 90% improvement compared to the competition. VIMz's low memory complexity allows for proving multiple transformations in parallel to achieve a 3.5x additional speedup on average.
Open access
Advanced Steganography and Watermarking Techniques
Digital Media Forensic Detection
Physical Unclonable Functions (PUFs) and Hardware Security