As global financial ecosystems become increasingly digitized, the need for secure, resilient, and interoperable frameworks to protect cross-border transactions and digital financial identities has grown exponentially.Traditional perimeter-based security models have proven insufficient in addressing the sophisticated cyber threats targeting financial networks, especially in decentralized and multi-jurisdictional environments.This has spurred the adoption of Zero Trust Architectures (ZTA)-a paradigm that assumes no implicit trust across networks, devices, or users-and mandates continuous verification at every interaction point.While ZTA enhances access control and minimizes attack surfaces, it faces implementation challenges in distributed financial infrastructures due to trust management, data integrity, and auditability concerns.Simultaneously, blockchain protocols-with their decentralized consensus, immutability, and cryptographic assurance-have emerged as powerful enablers of secure, transparent, and tamperresistant financial systems.This article explores the convergence of ZTA and blockchain technologies as a transformative strategy for enhancing the confidentiality, integrity, and availability of cross-border payment systems and digital identity frameworks.It examines how smart contracts, decentralized identifiers (DIDs), and distributed ledgers can reinforce ZTA principles such as least-privilege access, continuous authentication, and micro-segmentation in a decentralized context.Drawing on real-world use cases and regulatory insights, the study proposes a layered security model integrating ZTA with permissioned blockchain infrastructures, highlighting architectural synergies, potential threats, and scalability considerations.It also addresses the interoperability challenges and governance frameworks necessary for adoption in multi-stakeholder financial environments.By bridging trustless identity verification with cryptographic consensus, this integrated approach offers a future-ready blueprint for securing global digital finance in the era of open banking, fintech innovation, and evolving cyber threats.
In trans-border data (data transferred or accessed across national jurisdictions) exchange scenarios, identity authentication mechanisms serve as critical components for ensuring data security and privacy protection, with their effectiveness directly impacting the compliance and reliability of transnational operations. However, existing identity authentication systems face multiple challenges in trans-border contexts. Firstly, the transnational transfer of identity data struggles to meet the varying data-compliance requirements across different jurisdictions. Secondly, centralized authentication architectures exhibit vulnerabilities in trust chains, where single points of failure may lead to systemic risks. Thirdly, the inefficiency of certificate verification in traditional Public Key Infrastructure (PKI) systems fails to meet the real-time response demands of globalized business operations. These limitations severely constrain real-time identity verification in international business scenarios. To address these issues, this study proposes a trans-border distributed certificate-free identity authentication framework (STALE). The methodology adopts three key innovations. Firstly, it utilizes email addresses as unique user identifiers combined with a Certificateless Public Key Cryptography (CL-PKC) system for key distribution, eliminating both single-point dependency on traditional Certificate Authorities (CAs) and the key escrow issues inherent in Identity-Based Cryptography (IBC). Secondly, an enhanced Elliptic Curve Diffie–Hellman (ECDH) key-exchange protocol is introduced, employing forward-secure session key negotiation to significantly improve communication security in trans-border network environments. Finally, a distributed identity ledger is implemented, using the FISCO BCOS blockchain, enabling decentralized storage and verification of identity information while ensuring data immutability, full traceability, and General Data Protection Regulation (GDPR) compliance. Our experimental results demonstrate that the proposed method exhibits significant advantages in authentication efficiency, communication overhead, and computational cost compared to existing solutions.
Buy Now Pay Later (BNPL) is a rapidly proliferating e-commerce model, offering consumers to get the product immediately and defer payments. Meanwhile, emerging blockchain technologies endow BNPL platforms with digital currency transactions, allowing BNPL platforms to integrate with digital wallets. However, the transparency of transactions causes critical privacy concerns because malicious participants may derive consumers' financial statuses from on-chain asynchronous payments. Furthermore, the newly created transactions for deferred payments introduce additional time overheads, which weaken the scalability of BNPL services. To address these issues, we propose an efficient and privacy-preserving blockchain-based asynchronous payment scheme (Epass), which has promising scalability while protecting the privacy of on-chain consumer transactions. Specifically, Epass leverages locally verifiable signatures to guarantee the privacy of consumer transactions against malicious acts. Then, a privacy-preserving asynchronous payment scheme can be further constructed by leveraging time-release encryption to control trapdoors of redactable blockchain, reducing time overheads by modifying transactions for deferred payment. We give formal definitions and security models, generic structures, and formal proofs for Epass. Extensive comparisons and experimental analysis show that \textsf{Epass} achieves KB-level communication costs, and reduces time overhead by more than four times in comparisons with locally verifiable signatures and Go-Ethereum private test networks.
The security proof of a protocol, though formally rigorous within a given model, is entirely contingent on the model's assumptions. If the adversary's capabilities are underspecified, the cryptographic primitives are idealized, or the security properties are incompletely formalized, the proof may not hold in practice.The first contribution advances prior work on refining symbolic models for crypto- graphic primitives to better capture their behaviors. Specifically, we propose more precise equational theories for the ElGamal cryptosystem, DSA signatures, and Zero-Knowledge Proofs. Standard symbolic modeling of these primitives disregards their algebraic prop- erties, which may lead to missed attacks in larger protocols. Additionally, we introduce a formal model of exponentiation and re-encryption Mix-Networks. By combining these models with our equational theories, we can automatically find attacks based on the incorrect use of the Mix-Networks missed by previous symbolic models.The second contribution involves analyzing the WireGuard protocol. We examine the protocol's claimed security properties under an adversary capable of compromising any possible key combinations. To systematize this analysis, we introduce the concepts of minimal defensive model and minimal offensive adversary model. The defensive models ensures that violating a security property requires possessing specific atomic capabilities. Minimal offensive models define the smallest sets of adversarial capabilities that break security. Theses derivations helped to identify an implementation optimization that introduces new attack vectors.The third contribution presents a hybrid protocol combining WireGuard and Post- Quantum WireGuard, aligning with recommendations for a secure transition to post- quantum cryptography. Although a symbolic analysis of PQ-WireGuard existed, we uncover discrepancies between the model and the protocol's specifications, including pre- viously missed Unknown Key-Share attacks. We propose fixes and ensure the hybrid protocol's security relies on both the corrected post-quantum and classical WireGuard protocols. We formally defined a hybrid protocol's security as when there exists both minimal defensive models dependent on post-quantum keys and defensive models depen- dent on classical keys. Our work underscores the importance of iterative analysis during design, as achieving hybrid security required repeated refinement between modeling and verification.
Abdullah Ayub Khan, Asif Ali Laghari, Roobaea Alroobaea, Abdullah M. Baqasah · 7 authors
The Internet of Things (IoMT) has revolutionized the global landscape by enabling the hierarchy of interconnectivity between medical devices, sensors, and healthcare applications. Significant limitations in terms of scalability, privacy, and security are associated with this connection. This study presents a scalable, lightweight hybrid authentication system that integrates blockchain and edge computing within a Hyperledger Consortium network to address such real-time problems, particularly the use of Hyperledger Indy. For secure authentication, Hyperledger ensures a permissioned, decentralized, and impenetrable environment, while edge computing lowers latency by processing data closer to IoMT devices. The proposed framework balances security and computing performance by utilizing a hybrid cryptographic technique, like NuCypher Threshold Proxy Re-Encryption. Applicational activities are now appropriate for IoMT devices with limited resources thanks to this integration. By facilitating cooperation between numerous stakeholders with restricted access, the consortium network improves scalability and data governance. Comparing the proposed framework to the state-of-the-art techniques, experimental evaluation shows that it reduces latency by 2.93% and increases authentication efficiency by 98.33%. Therefore, in contrast to current solutions, guarantee data integrity and transparency between patients, consultants, and hospitals. The development of dependable, scalable, and secure IoMT applications is facilitated by this work, enabling next-generation medical applications.
Web-based credit card payments require complete disclosure of all payment card details for transaction authorization. The card’s CVV (Card Verification Value) is the secret code that authorizes card not presented transactions. Currently, all payment card details must be shared among various intermediaries involved in processing the transaction. To mitigate the risks associated with fraudulent transactions, industries have adopted security standards such as the PCI DSS. Credit card data confidentiality rests on all involved stakeholders adhering to best security practices, including data communication encryption, and do not misuse the payment information. However, this security posture does not prevent potential credit card data leaks. We propose an alternative method for conducting remote card payments that does not require disclosing the authorization code while ensuring high interoperability with existing payment networks. Our approach demonstrates how designated verifier Zero-Knowledge Proofs (ZKP) enable minimal disclosure of card details, particularly protecting the confidentiality of authorization codes.
Nai‐Wei Lo, Chi-Ying Chuang, Jheng-Jia Huang, Yuxuan Luo
With the rise of the Internet of Vehicles (IoV), secure and efficient authentication is essential to prevent cyber threats. This paper proposes a session key establishment protocol using Zero-Knowledge Proofs (zk-SNARKs) and Elliptic Curve Cryptography (ECC), including the Elliptic Curve Diffie–Hellman (ECDH) key exchange, to ensure privacy and efficiency. While zk-SNARK computations introduce additional verification overhead, our optimizations, such as precomputed proof parameters and lightweight session re-authentication, mitigate delays. Performance evaluation shows a 20% reduction in computation overhead and a 75% faster re-authentication time compared to existing methods, making it a secure and practical solution for real-world IoV applications.
Decentralized applications are often composed of multiple interconnected smart contracts. This is especially evident in DeFi, where protocols are heavily intertwined and rely on a variety of basic building blocks such as tokens, decentralized exchanges and lending protocols. A crucial security challenge in this setting arises when adversaries target individual components to cause systemic economic losses. Existing security notions focus on determining the existence of these attacks, but fail to quantify the effect of manipulating individual components on the overall economic security of the system. In this paper, we introduce a quantitative security notion that measures how an attack on a single component can amplify economic losses of the overall system. We study the fundamental properties of this notion and apply it to assess the security of key compositions. In particular, we analyse under-collateralized loan attacks in systems made of lending protocols and decentralized exchanges.
Munir Hussain, Amjad Mehmood, Muhammad Altaf Khan, Jaime Lloret · 5 authors
The recent developments in telecommunication technologies and monitoring devices have brought many changes in modern electronic healthcare systems (EHSs) by improving quality and decreasing healthcare expenses. Despite the benefits, they have privacy and security issues because the communication between patients and service providers takes place generally over public channels. Several user authentication protocols using distributed ledger technology (DLT) have recently been proposed to address these issues in EHSs. However, many are still vulnerable to a single point of failure (SPoF), privacy, and security attacks. Besides, they suffered from high communication and computational costs. Therefore, in this paper, we proposed a user authentication protocol using DLT to avoid these issues. A Burrows-Abadi-Needham (BAN) logic proof method has been used to check the security of the proposed protocol and ensure it achieves the desired security goals. In addition, an informal security analysis has been conducted to verify its important security requirements. A formal security analysis has been performed via the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool and Real-or-Random (ROR) model for further security strength. The results demonstrate that the proposed user authentication protocol is SAFE against all types of Man-in-the-Middle (MitM) attacks, impersonation, replay, and forgery attacks . Finally, performance analysis has been performed and results show that it achieves better performance by consuming 29.63 % and 13.21 % less communication and computational overheads as compared to existing related user authentication protocols. The security and performance analysis make it a more appropriate choice for the EHSs.
Electronic voting (e-voting) has emerged as a transformative technology in the modern digital era. Many countries across the world are using e-voting systems in different types of elections, from political to non-political. One of the primary goals of e-voting is ensuring both verifiability and privacy simultaneously, which we refer to as security. Verifiability is a security feature that guarantees voters can confirm their vote is reflected in the final election result, while privacy guarantees that no one is able to link a vote to the voter who cast it. Verifiability needs to hold only for the duration of the election, whereas privacy needs to extend beyond the election period, even decades after the election. This property, known as everlasting privacy in the literature, ensures that even computationally unbounded adversaries cannot compromise voter privacy, securing elections against future advances in computing, including quantum computing. Researchers have proposed a wide variety of protocols to achieve this ambitious goal in secure e-voting, however, these protocols differ significantly, making the analysis and state-of-the-art complicated. In this thesis, we first address this fragmentation by systematically analyzing all existing e-voting protocols designed to ensure everlasting privacy. We map out the relationships and dependencies among these protocols, evaluate their security and efficiency under realistic assumptions, and identify unresolved challenges in the field. Our work provides a foundational reference for researchers aiming to design secure e-voting systems with everlasting privacy, paving the way for privacypreserving elections in the post-quantum era. Building on these insights, we propose a novel e-voting system that integrates the best practices from prior research while addressing their limitations. Leveraging the Hyperion scheme as a foundation, we develop an enhanced protocol that not only guarantees everlasting privacy but also introduces everlasting receipt-freeness and coercion mitigation. Unlike existing systems like Selene and Hyperion, which rely on computational assumptions for privacy, our protocol offers privacy even against adversaries with unlimited computational power. In secure electronic voting systems with everlasting privacy, the focus is on futureproofing privacy, while sometimes election verifiability relies on the computational soundness of zero-knowledge proofs (ZKP), which are vulnerable to quantum adversaries. Therefore, a key technical challenge is designing e-voting systems with efficient post-quantum cryptographic primitives to secure both privacy and verifiability against quantum attacks. In this thesis, we advance the state of post-quantum ZKPs by focusing on the ZKPs proposed by Jain et al., which are based on the conservative Learning Parity with Noise (LPN) assumption. We optimize the efficiency of these ZKPs, achieve formal security verification using EasyCrypt, and uncover flaws in existing implementations, demonstrating their vulnerability to malicious provers. Additionally, we construct the first code-based ZKP of shuffle, enabling a verifiable and privacy-preserving e-voting protocol with mixing-based tallying. Our e-voting system ensures both verifiability and vote privacy through the computational difficulty of decoding random linear codes, marking it as the first verifiable code-based e-voting system.
Junhui Zhao, Yingxuan Guo, Longxia Liao, Dongming Wang
Vehicular Ad-hoc Network (VANET) is a platform that facilitates Vehicle-to-Everything (V2X) interconnection. However, its open communication channels and high-speed mobility introduce security and privacy vulnerabilities. Anonymous authentication is crucial in ensuring secure communication and privacy protection in VANET. However, existing anonymous authentication schemes are prone to single points of failure and often overlook the efficient tracking of the true identities of malicious vehicles after pseudonym changes. To address these challenges, we propose an efficient anonymous authentication scheme for blockchain-based VANET. By leveraging blockchain technology, our approach addresses the challenges of single points of failure and high latency, thereby enhancing the service stability and scalability of VANET. The scheme integrates homomorphic encryption and elliptic curve cryptography, allowing vehicles to independently generate new pseudonyms when entering a new domain without third-party assistance. Security analyses and simulation results demonstrate that our scheme achieves effective anonymous authentication in VANET. Moreover, the roadside unit can process 500 messages per 19 ms. As the number of vehicles in the communication domain grows, our scheme exhibits superior message-processing capabilities.
Vehicular Ad Hoc Networks (VANETs) are essential to intelligent transportation systems (ITS), enabling secure, real-time communication among vehicles and infrastructure. However, their decentralized and dynamic nature makes them vulnerable to threats such as Sybil attacks, message forgery, replay attacks, and Denial-of-Service (DoS). This paper presents VANETGuard, a lightweight scalable trust management system that enhances security and scalability in 5G-enabled smart vehicular networks. The proposed system integrates entropy-based anomaly detection, Bayesian inference for adaptive trust scoring, and a lightweight distributed ledger for decentralized, tamper-resistant trust storage. Large-scale simulations under realistic traffic and attack conditions demonstrate that VANETGuard achieves 99.97% detection accuracy, significantly reduces false positives, and maintains low latency and computational overhead while supporting over 300 vehicles. These results highlight VANETGuard’s potential to enable secure, efficient, and scalable trust mechanisms in next-generation ITS and urban mobility systems.
The rapid growth of digital technologies has intensified concerns about data privacy and security. Blockchain technology, combined with advanced cryptographic methods, presents a promising solution to enhance digital privacy by enabling decentralized, transparent, and tamper-resistant systems. This article explores the foundational principles of blockchain and cryptography, evaluates their interplay in preserving digital privacy, and examines current challenges and future directions. Through comprehensive analysis, the study highlights how cryptographic protocols such as zero-knowledge proofs and homomorphic encryption can significantly augment privacy on blockchain platforms, while addressing inherent scalability and usability challenges.
With the rapid advancement of blockchain technology, smart contracts have enabled the implementation of increasingly complex functionalities. However, ensuring the security of smart contracts remains a persistent challenge across the stages of development, compilation, and execution. Vulnerabilities within smart contracts not only undermine the security of individual applications but also pose significant risks to the broader blockchain ecosystem, as demonstrated by the growing frequency of attacks since 2016, resulting in substantial financial losses. This paper provides a comprehensive analysis of key security risks in Ethereum smart contracts, specifically those written in Solidity and executed on the Ethereum Virtual Machine (EVM). We focus on two prevalent and critical vulnerability types (reentrancy and integer overflow) by examining their underlying mechanisms, replicating attack scenarios, and assessing effective countermeasures.
TetraUnified v2.0 presents a fully revised, academically aligned research framework integrating three experimental components: Tetrahedral Key Exchange (TKE):Exploratory key exchange mechanism based on recursive geometric projections. Recursive Tesseract Hashing (RTH):Hyperdimensional hashing model using 16-axis Clifford projections and recursive entropy mixing. Quantum Isoca-Dodecahedral Lattice Encryption (QIDL):Conceptual encoding model for representing plaintext within dynamic polyhedral phase lattices. This version restructures the system into a coherent research-grade framework, emphasizing mathematical clarity, reproducibility, consistent notation, and proper cryptographic disclaimers.No security guarantees are claimed and no component should be used in production systems.All structures are intended strictly for experimental simulation, prototyping, and conceptual evaluation. Purpose of This Release Version 2.0 was developed to achieve three objectives: Remove speculative, metaphorical, or narrative content from earlier drafts and establish a formal academic tone. Strengthen mathematical structure and notation, including explicit operator definitions and theorem–proof formulations. Position the system as a technical R&D testbed, rather than a security product or operational cryptographic protocol. This release supersedes all previous versions.Earlier manuscripts are preserved only as historical development notes. Key Improvements in v2.0 1. Formal Mathematical Structures Includes new theorem–proof style sections addressing: TKE reconstruction consistency RTH entropy evolution under recursion QIDL transformation intractability (as a conceptual model) Defined core operators: Projection (𝒯) Modulation (f) Reconstruction () Polyhedral rotation (_{I,D}) Sealing (𝒮) Geometric embeddings now use clearly stated synthetic Clifford bases. 2. Cryptographic Positioning TKE, RTH, and QIDL are explicitly described as experimental, unverified, not secure, and not production-ready. No hardness assumptions are claimed. All constructs are positioned as alternative simulation models inspired by geometric/topological methods. 3. Distributed Systems & Navigation Concepts Introduces a conceptual framework for: phase-based synchronization inertial alignment without external timing sources distributed state coordination under high latency resilience to environmental drift or partial network partitions 4. Comparison with Existing Quantum Programming Includes a revised comparison table contrasting: NISQ-era quantum programming TetraUnified’s hyperdimensional simulation models Highlights key architectural differences without implying superiority. 5. Expanded Application Sections Updated application discussions for TKE, RTH, and QIDL covering: distributed identity experiments mesh communication models ledger integrity prototyping inertial navigation research off-world / high-latency environments multi-agent swarm coordination recursive lineage tracking for AI pods All applications are strictly conceptual research pathways, not operational deployments. Version Philosophy TetraUnified v2.0 establishes the framework as: an academic-style experimental cryptography model a research environment for hyperdimensional and geometric transformations an R&D prototype for studying non-linear distributed coordination a computational sandbox for exploring alternative post-quantum architectures No practical security, correctness, or adversarial resistance should be inferred.Formal verification and cryptanalysis remain open areas for future work. Included Artifacts This release includes: the revised LaTeX manuscript (PDF) updated mathematical definitions for TKE, RTH, QIDL reference diagrams and basis definitions example code structures (if present in repository) reproducibility metadata and version history Notes on Previous Versions Earlier versions contained exploratory and speculative material.Version 2.0 replaces these with a rigorous mathematical and systems-engineering structure. Per Zenodo policies, earlier versions remain visible but represent developmental prototypes only.The DOI series now resolves to v2.0 as the authoritative technical edition. Intended Use TetraUnified v2.0 is intended for: researchers exploring geometric or topological cryptography models distributed systems experimentation verifiable computation and XR/digital-twin state modeling conceptual post-quantum architecture studies academic and peer review simulation, prototyping, and reproducibility analysis This work is not intended for operational cryptography, production deployment, or security-critical environments. Citation MacDonald, M. (2025).TetraUnified v2.0 — Experimental Framework for Hyperdimensional Cryptography, Recursive Hashing, and Distributed State Models.Zenodo. https://doi.org/10.5281/zenodo.17759222
Smart contracts are a secure and trustworthy application that plays a vital role in decentralized applications in various fields such as insurance,the internet, and gaming. However, in recent years, smart contract security breaches have occurred frequently, and due to their financial properties, they have caused huge economic losses, such as the most famous security incident "The DAO" which caused a loss of over $60 million in Ethereum. This has drawn a lot of attention from all sides. Writing a secure smart contract is now a critical issue. This paper focuses on Ether smart contracts and explains the main components of Ether, smart contract architecture and mechanism. The environment used in this paper is the Ethernet environment, using remix online compilation platform and Solidity language, according to the four security events of American Chain, The DAO, Parity and KotET, the principles of integer overflow attack, reentrant attack, access control attack and denial of service attack are studied and analyzed accordingly, and the scenarios of these vulnerabilities are reproduced, and the measures to prevent them are given. Finally, preventive measures are given. In addition, the principles of short address attack, early transaction attack and privileged function exposure attack are also introduced in detail, and security measures are proposed. As vulnerabilities continue to emerge, their classification will also evolve. The analysis and research of the current vulnerabilities are also to lay a solid foundation for avoiding more vulnerabilities.
Muhammad Jawad, Mahmood A. Al-Shareeda, Omar Yawez Mustafa Mustafa, Mohammed Amin Almaiah · 5 authors
Analysis of repeated attack signatures is important because of the rapid evolution of the Social Internet of Vehicles (SIoV). However, threats such as replay attacks, session hijacking, and key reuse make secure communication between vehicles, roadside units (RSUs), and the fog node difficult. Traditional models for authentication are limited by computational overhead and lack quick key revocation. In response to these challenges, we propose a hybrid cryptographic authentication scheme that combines a Zero-Knowledge Proof (ZKP) with AES-GCM encryption. Our protocol implements a dynamic key revocation mechanism to avoid rogue and session key migration, minimizing re-authentication delay. Security analysis in the Real-Oracle Random (ROR) model shows that it is not vulnerable to impersonation or replay attacks. Evaluations demonstrate decreases of 58% in authentication latency while achieving 45% and 72% improvements in communication and computation efficiency, respectively. Our approach is also scalable and secure, providing SIoV with higher reliability for automotive applications in the vehicular networks of the future.
The advancement of Industrial Internet of Things (IIoT) has enabled cross-domain collaboration among enterprises, facilitating data exchange and coordinated operations for complex manufacturing tasks. As the primary security mechanism, cross-domain continuous authentication periodically verifies external devices to prevent unauthorized access and session hijacking, thereby mitigating system vulnerabilities. However, existing solutions face limitations: some rely on device-specific features incompatible with heterogeneous environments, while others neglect cross-domain scenarios, offering insufficient privacy protection and irreversible identity management. To address these gaps, we propose a cross-domain authentication framework leveraging zero-knowledge proofs and blockchain technology. Devices are assigned anonymous identities, with revocation managed via a distributed ledger. Initial authentication employs zero-knowledge proofs to generate valid tokens, while continuous authentication refreshes these tokens periodically. Security analysis confirms robustness against common threats, and performance evaluations demonstrate that periodic token renewal reduces computational and communication costs compared to repeated initial authentication processes.
We propose Data Tumbling Layer (DTL), a cryptographic scheme for non-interactive data tumbling. The core concept is to enable users to commit to specific data and subsequently re-use to the encrypted version of these data across different applications while removing the link to the previous data commit action. We define the following security and privacy notions for DTL: (i) no one-more redemption: a malicious user cannot redeem and use the same data more than the number of times they have committed the data; (ii) theft prevention: a malicious user cannot use data that has not been committed by them; (iii) non-slanderabilty: a malicious user cannot prevent an honest user from using their previously committed data; and (iv) unlinkability: a malicious user cannot link tainted data from an honest user to the corresponding data after it has been tumbled. To showcase the practicality of DTL, we use DTL to realize applications for (a) unlinkable fixed-amount payments; (b) unlinkable and confidential payments for variable amounts; (c) unlinkable weighted voting protocol. Finally, we implemented and evaluated all the proposed applications. For the unlinkable and confidential payment application, a user can initiate such a transaction in less than $1.5$s on a personal laptop. In terms of on-chain verification, the gas cost is less than $1.8$ million.
Currently, PAKE (Password Authenticated Key Exchange) protocols on lattice using a single-server architecture are widely applied. However, such protocols are vulnerable to server leakage attacks, dictionary attacks, and other threats. To address these issues, researchers have proposed multi-server and two-server architecture-based PAKE protocols. However, PAKE protocols in a multi-server architecture require the use of complex cryptographic primitives such as signatures, and zero-knowledge proofs to ensure security, which reduces the execution efficiency of the protocol. To tackle these challenges, we propose two new multi-server password authentication key exchange protocols based on the MLWE (Module learning with errors) problem. Both protocols rely on MLWE instances, using Peikert's error coordination technique to enable two parties with similar values to compute the same result. Furthermore, we introduce the error pairing assumption and proves its security within random oracle model. The proposed protocol divides the password information into different shares and stores them on separate servers. In protocol 1, all servers and user collaboratively generate session keys, making it suitable for high-security application scenarios. In protocol 2, both user and servers generate session keys individually, which is ideal for high-efficiency application scenarios. Compared to similar protocols, both protocols lower computation and communication costs, better addressing practical application needs while providing protection against quantum computing attacks and server leakage threats.
Phuc-Hung Pham Le, Trung-Tin Tran, Toan Q. Dinh, Quy N.
As end-to-end encryption (E2EE) becomes the standard for secure communication, ensuring message authenticity while maintaining user privacy poses significant challenges.This paper introduces the BL0K-ME protocol, a novel cryptographic solution that combines Zero-Knowledge Proofs (ZKP), RSA encryption, and Bloom filters to authenticate individual messages within E2EE conversations.RSA encryption is employed to secure the transmission of messages between users, ensuring that only the intended recipient can decrypt the content, while ZKP enables third-party verification of specific message content without exposing the entire conversation.By leveraging Bloom filters, the protocol provides efficient logging and verification of message existence, balancing privacy protection with legal and regulatory requirements for digital evidence.BL0K-ME addresses a critical gap in current messaging systems by allowing service providers to verify message authenticity for legal investigations without compromising the confidentiality of unrelated communications.This research demonstrates the potential of integrating RSA encryption, ZKP, and Bloom filters to offer a scalable, secure solution for message authentication in E2EE systems, safeguarding both user privacy and the integrity of digital evidence.
Currently, PAKE (Password Authenticated Key Exchange) protocols on lattice using a single-server architecture are widely applied. However, such protocols are vulnerable to server leakage attacks, dictionary attacks, and other threats. To address these issues, researchers have proposed multi-server and two-server architecture-based PAKE protocols. However, PAKE protocols in a multi-server architecture require the use of complex cryptographic primitives such as signatures, and zero-knowledge proofs to ensure security, which reduces the execution efficiency of the protocol. To solve these problems, we propose a two-server PAKE protocol on the lattice based on the MLWE (Module learning with errors) problem. The protocol is built using instances of the MLWE problem and utilizes the Peikert error coordination technique, which ensures both parties with similar values arrive at the same result through computation. Additionally, we introduce the error pairing hypothesis and demonstrates its security within the random oracle model. The protocol securely stores different shares of password information across various servers. This approach protects user password data, even if one of the servers is compromised. Compared to similar protocols, we avoid the use of numerous cryptographic primitives, and can better resist quantum computing attacks and server leakage. And we reduce computational and communication costs, and can better meet practical application needs.
Atoms and photons, two things so different but yet so alike. The former, the building block of matter, something we learn about in school and imagine it as some tiny marbles encircled by other tinier marbles. The latter, an electromagnetic wave, a light particle or an excitation of the electromagnetic field. Quantum mechanics tells us about the properties of these two entities. And even if it sounds, looks and writes counter-intuitive, it has proven right for over a century now. In this work, I elaborate on how we tested the laws of quantum mechanics and how we used them learn more about the tiny building blocks of nature and the fields they use to talk to each other. The atoms we use, are artificial. Superconducting qubits, small electrical circuits with quantized energy levels behave like electrons that transition between different orbitals in an atom. One of the qubits' advantages, is also a big disadvantage. We design the circuits' energy levels and fabricate them in a cleanroom. This allows for arbitrary spaced energy levels but in contrast to real atoms, prevents two superconducting qubits from being alike. Still, this qubit platform is one of the frontrunners for future quantum computing technology and testing fundamental physics due to their scalability. We interface superconducting qubits, which operate in the GHz regime, with microwave photons. We use 3D aluminum cavities as mediators between qubits and photons. The cavities allow for non-destructive readout of the qubit state, they shield the qubits from noise at the qubit frequency and they give us an easy way to frequency-tune these joint systems. We need to operate superconducting qubits and their cavities at millikelvin temperatures in dilution refrigerators. At higher temperatures, superconductivity suffers and even worse, the environment is filled with thermal noise photons. This poses a fundamental limitation on the scalability of superconducting qubit devices. Also connecting multiple devices in different fridges does not work over room temperature links because the microwave photons used for this purpose will be covered in noise and the quantum information they carry, will be unusable. Infrared photons do not suffer from this noise problem since there are close to zero thermal noise photons at their frequencies at room temperature. We cannot simply interface superconducting devices with optical photons due their frequency mismatch and the destructive effect of optical photons on superconductors. Therefore, we use microwave-to-optics transducers that allow to convert microwave photons into optical ones and vice-versa. The transducers that we use are macroscopic electro-optic transducers using the Pockels effect in a disk-shaped Lithium Niobate whispering gallery mode resonator. By using a strong optical pump, photons from the two frequency domains experience a beam-splitter interaction and get converted from one to the other. We measure the generated optical photons using elaborate optical setups, optical heterodyning and single photon detectors to gain knowledge about the qubit state or the converted microwave photons. Bridging the microwave and the optical world allows us to take advantage of both of their strengths but it also requires deep knowledge about both of their working principles. In this work, we describe two experiments that our group conducted to showcase the opportunities that arise from interfacing superconducting qubits with optical photons but also the pitfalls, one may encounter on the way. In the first experiment, we managed to all-optically read out a superconducting qubit. We show that the assignment fidelity, the probability that a measurement of the qubit state matches the prepared state, is close to equal for all-optical, microwave-to-optics and conventional microwave readout. We show T1 and T2 measurements for all three readout types and give an analysis of the noise caused by the optics. Finally, we show that the infrared light does not affect the qubit performance in a negative way but that the heating it causes does. This is an important insight that we used in the next experiment. The second experiment is the upconversion of itinerant single microwave photons to the optical domain. We show that we can generate single microwave photons from a qubit-cavity system. We upconvert these single photons, measure them with a single photon detector and reconstruct their shape. By conducting a single photon Rabi measurement, we show correlations between the microwave and the optical domain. And by thorough signal-to-noise measurements and noise analysis, we find that we can generate single infrared photons with high signal-to-noise ratio 5.1 and low transducer added noise (<0.012 quanta). We show that this measurement creates a path towards entanglement of a superconducting qubit and an optical photon and what parameters need to be improved to achieve it. Additionally, this experiment is a proof of principle for an on-demand infrared single photon source. More generally, it allows to link microwave quantum technology in general to the optical domain.
随着信息技术的快速发展,数据安全和用户的隐私越发受到重视。本文提出了一种匿名认证密钥交换(Anonymous Key Exchange, AKE)协议,旨在为医疗场景下的医疗数据共享和患者身份隐私提供安全和隐私的保护。该方案通过使用累加器、零知识证明和关联数据加密等技术,实现用户匿名的认证和安全的会话密钥协商,有效防止敌手对于用户和医用物联网设备的攻击,还能抵御诚实且好奇的医疗机构对患者身份的猜测。相较于现有的方案提供了更强的隐私安全保护,并且很好地平衡了性能和安全性,具有重要的理论价值和意义。With the rapid development of information technology, data security and user privacy have been paid more and more attention. This paper proposes an Anonymous authenticated Key Exchange (AKE) protocol to provide security and privacy protection for medical data sharing and patient identity privacy in medical scenarios. By using accumulator, zero-knowledge proof and associated data encryption technology, the scheme realizes anonymous user authentication and secure session key agreement, which effectively prevents adversaries from attacking users and medical IoT devices, and can resist honest and curious medical institutions from guessing the patient’s identity. Compared with the existing schemes, it provides stronger privacy security protection, and a good balance between performance and security, which has important theoretical value and significance.