Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,146 papersLast indexed Aug 31, 2026
Search papers

Paper index

4,146 results · page 85 of 173

Clear filters
Jul 8, 2022·Expert Systems with Applications
4 cites
HyperNet: A conditional k-anonymous and censorship resistant decentralized hypermedia architecture

Carlos Núñez‐Gómez, Víctor Garcia-Font

Nowadays, the vast majority of Internet services used to distribute hypermedia content follow a centralized model, which is highly dependent on servers and raises several quality and security concerns. Among other issues, this centralized model creates single points of failure, requires trust on providers to avoid censorship and personal data misuse, and results in a scenario where digital content tends to disappear or be inaccessible over time, for example, when a content creator stops maintaining a site or when the content is moved to another location. To improve this, it is necessary to replicate data and follow more distributed models. Nevertheless, current platforms to distribute content in this way, either do not offer an effective mechanism to maintain the privacy of their users or they offer full-anonymity, which contributes to the dissemination of content that goes beyond the law and moral standards of many users. This paper proposes a novel distributed architecture that enables hypermedia resource distribution ensuring censorship resistance and conditional k-anonymity. In the proposed system, users form groups to share hypermedia content where the anonymity of the publisher is preserved only if the publication follows a set of rules defined by the group. To this end, the proposed system uses threshold discernible ring signatures to enable conditional k-anonymity, the Ethereum blockchain platform to manage groups and user identities, and the InterPlanetary File System to store and share hypermedia resources in a distributed way. This document provides the design for the proposed architecture and protocols, it evaluates system risks and its security properties, and it discusses the proposal in general terms.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Jul 5, 2022·arXiv (Cornell University)
2 cites
Can We Effectively Use Smart Contracts to Stipulate Time Constraints?

Tobias Eichinger, Marcel Ebermann

Smart contracts provide the means to stipulate rules of interaction between mutually distrustful organizations. They encode contractual agreements on the basis of source code, which else need to be contractualized in natural language. While the mediation of contractual agreements via smart contracts is seamless in theory, it requires that the conditions of an interaction are accurately made available in the blockchain. Time is a prominent such condition. In the paper at hand, we empirically measure the consistency of a smart contract to yield equal results on the basis of the time of an interaction and its potentially inaccurate representation in the blockchain. We propose a novel metric called execution accuracy to measure this consistency. We specifically measure the execution accuracy of a time intervalconstrained smart contract that executes distinct logic within and without some constraint interval. We run experiments for the local Ganache and Quorum and the public Görli and Rinkeby Ethereum blockchains. Our experiments confirm our intuition that execution accuracy decreases near interval bounds. The novelty of our proposed metric resides in its capacity to quantify this decrease. We demonstrate how time constraints can be effectively stipulated on the basis of execution accuracy measurements.

Open access
3 source records
cs.DC
eess.SY
Blockchain Technology Applications and Security
Original source
Jul 5, 2022·Lecture notes in computer science
23 cites
Cryptography with Certified Deletion

James Bartusek, Dakshita Khurana

We propose a new, unifying framework that yields an array of cryptographic primitives with certified deletion. These primitives enable a party in possession of a quantum ciphertext to generate a classical certificate that the encrypted plaintext has been information-theoretically deleted, and cannot be recovered even given unbounded computational resources. - For X \in {public-key, attribute-based, fully-homomorphic, witness, timed-release}, our compiler converts any (post-quantum) X encryption to X encryption with certified deletion. In addition, we compile statistically-binding commitments to statistically-binding commitments with certified everlasting hiding. As a corollary, we also obtain statistically-sound zero-knowledge proofs for QMA with certified everlasting zero-knowledge assuming statistically-binding commitments. - We also obtain a strong form of everlasting security for two-party and multi-party computation in the dishonest majority setting. While simultaneously achieving everlasting security against all parties in this setting is known to be impossible, we introduce everlasting security transfer (EST). This enables any one party (or a subset of parties) to dynamically and certifiably information-theoretically delete other participants' data after protocol execution. We construct general-purpose secure computation with EST assuming statistically-binding commitments, which can be based on one-way functions or pseudorandom quantum states. We obtain our results by developing a novel proof technique to argue that a bit b has been information-theoretically deleted from an adversary's view once they output a valid deletion certificate, despite having been previously information-theoretically determined by the ciphertext they held in their view. This technique may be of independent interest.

Open access
3 source records
Cryptography and Data Security
Cryptographic Implementations and Security
Chaos-based Image/Signal Encryption
Original source
Jul 4, 2022·Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
3 cites
ID-based self-encryption via Hyperledger Fabric based smart contract

Ilya Grishkov, Roland Kromes, Thanassis Giannetsos, Kaitai Liang

This paper offers a prototype of a Hyperledger Fabric-IPFS based network architecture including a smart contract based encryption scheme that meant to improve the security of user's data that is being uploaded to the distributed ledger. A new extension to the self-encryption scheme was deployed by integrating data owner's identity into the encryption process. Such integration allows to permanently preserve ownership of the original file and link it to the person/entity who originally uploaded it. Moreover, self-encryption provides strong security guarantees that decryption of a file is computationally not feasible under the condition that the encrypted file and the key are safely stored.

Open access
4 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jul 3, 2022·Mathematics
26 cites
Delegated Proof of Accessibility (DPoAC): A Novel Consensus Protocol for Blockchain Systems

Manpreet Kaur, Shikha Gupta, Deepak Kumar, Chaman Verma · 6 authors

As the backbone of every blockchain application, the consensus protocol is impacted by numerous risks, namely resource requirements and energy consumption, which limit the usage of blockchain. Applications such as IoT/IIoT cannot use these high-cost consensus methods due to limited resources. Therefore, we introduce Delegated Proof of Accessibility (DPoAC), a new consensus technique that employs secret sharing, PoS with random selection, and an interplanetary file system (IPFS).DPoAC is decomposed into two stages. During the initial stage, a secret is generated by a randomly chosen super node and divided into n shares. These shares are encrypted and stored in different n nodes on the IPFS network. The nodes will compete to access these shareholders to reconstruct the secret. The winning node will be awarded block generation rights. PoS with random selection is used in the second stage to compute the appropriate hash value and construct a block with valid transactions. In this novel approach, a node with few computational resources and small stakes can still obtain block generation rights by providing access to secret shares and reconstructing the secret, making the system reasonably fair. We qualitatively analyze and compare our scheme based on performance parameters against existing mainstream consensus protocols in the context of IoT/IIoT networks.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
IoT and Edge/Fog Computing
Original source
Jul 1, 2022·IEEE Network
27 cites
BCTrustFrame: Enhancing Trust Management via Blockchain and IPFS in 6G Era

Wenjuan Li, Weizhi Meng

Beginning in 2030, sixth generation (6G) mobile communication is expected to play a key role by collecting billions of things, humans, and robots, resulting in zettabytes of digital information. The key features of 6G include inherent connected intelligence in the telecommunication networks with devices from different vendors. Hence, trust should be enforced among devices, sub-networks, and applications, especially for mission-critical services. Currently, trust-based intrusion detection can measure an entity's trustworthiness by collecting statistics or sending consultation messages, while it may become inefficient in the era of 6G due to the overloaded traffic and potential latency. In this article, we discuss the challenges of deploying trust-based intrusion detection in 6G, and design BCTrustFrame, a framework of blockchain-based trust management with IPFS, which aims to enhance the effectiveness of trust evaluation via the collaboration of blockchain and IPFS technology. We also perform a case study to demonstrate the viability and performance.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cryptography and Data Security
Original source
Jul 1, 2022·Proceedings/Proceedings of the ... International Conference on Software Engineering and Knowledge Engineering
0 cites
Smifier: A Smart Contract Verifier for Composite Transactions

Yu Dong, Yue Li, Dongqi Cui, Jianbo Gao · 6 authors

Ensuring functional correctness of smart contracts is a pressing security concern to blockchain-based systems. With the development of blockchain application, the trading scenarios and function implementation of smart contracts have become increasing complex, containing several interacted contracts or related functions. However, the existing contracts verifiers for proving functional correctness focus on verifying isolated contract or function but ignore the interactions between them, which makes it difficult to verify correctness of composite transactions, i.e., complex transaction scenarios that invoke multiple contracts or trigger a set of transactions. In this paper, we present SMIFIER, a formal verification tool for smart contracts to prove functional properties in composite transactions. SMIFIER defines a set of specifications for composite transactions and can automatically specify properties in these multiple complex transactions. Based on states extraction and mapping, SMIFIER translates annotated Solidity program into Boogie program and verifies relations between functions and properties for interacted contracts. Our experimental evaluation on 12 real-world projects and 65 properties, demonstrates that SMIFIER is practically effective in ensuring functional correctness of properties in composite transactions.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Auction Theory and Applications
Original source
Jul 1, 2022·2022 IEEE 42nd International Conference on Distributed Computing Systems Workshops (ICDCSW)
12 cites
Flash Freezing Flash Boys: Countering Blockchain Front-Running

Haoqian Zhang, Louis-Henri Merino, Vero Estrada-Galiñanes, Bryan Ford

Front-running, the practice of benefiting from advanced knowledge of pending transactions, has proliferated in the cryptocurrency space with the emergence of decentralized finance. Front-running causes devastating losses to honest participants—estimated at $280M each month—and endangers the fairness of the ecosystem. We present Flash Freezing Flash Boys (F3B), an architecture to address front-running attacks by relying on a commit-and-reveal scheme where the contents of a transaction are encrypted and later revealed by a decentralized secret-management committee (SMC) when the transaction has been committed by the underlying consensus layer. To maintain legacy compatibility, we design F3B to be agnostic to the underlying consensus algorithm and compatible with existing smart contracts. A preliminary exploration of F3B shows that with a secret-management committee consisting of 8 and 128 members, F3B presents between 0.1 and 2.2 seconds of transaction-processing latency, respectively.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Distributed systems and fault tolerance
Original source
Jun 29, 2022·Cryptography
10 cites
Adaptable Cryptographic Primitives in Blockchains via Smart Contracts

Riccardo Longo, Carla Mascia, Alessio Meneghetti, Giordano Santilli · 5 authors

Blockchain-based platforms utilise cryptographic protocols to enforce the correct behaviour of users, as well as to guarantee a sufficient level of protection against malicious adversaries. Cryptography is, however, an ever-evolving discipline, and any breakthrough would have immediate consequences on the security of blockchain-based applications. A possible threat currently under investigation is given by the development of quantum computers, since several wide-adopted cryptographic protocols have been proved to be unsafe against quantum-capable adversaries. In this work, we propose a novel approach for the management of cryptographic primitives in smart-contract-based ledgers, discussing how it fits in both a (partially) permissioned and a fully permissionless setting. The cryptographic protocols are managed in a flexible manner via a set of smart-contracts defined on the ledger itself, in this way the choice of algorithms and parameters can change quickly. Among the advantages of this approach, we remark how it allows designing an adaptive post-quantum-based blockchain that keeps up with ongoing technological advances. In general, the introduction of new features and the application of fixes to a blockchain cause forks in the chain, which may cause major disruptions. The use of smart contracts in blockchain management allows to avoid this problem, dynamically introducing new protocols or deprecating old ones without compromising previous data. The Cryptographic Kernel approach has been adopted by Quadrans, an open-source, public, decentralised smart-contract-based blockchain with a specific focus on the needs of industry, complex supply chains, and IOT devices.

Open access
Blockchain Technology Applications and Security
Quantum Computing Algorithms and Architecture
Cryptography and Data Security
Original source
Jun 28, 2022·Computational Intelligence and Neuroscience
10 cites
Increasing Cyber Defense in the Music Education Sector Using Blockchain Zero-Knowledge Proof Identification

Ying Zhang

Music creation and its promotion are encouraged both in music education and through activities organized in the context of artistic creation as part of the education in question. Although copyright registration is the primary way authors protect their rights, this is not feasible in most cases, as the processes take a long time to complete and incur high costs. We utilize modern innovative technologies and their developments in copyright protection matters to increase security and trust in music education. In particular, an advanced model of ensuring the methods and innovation produced in music education processes is proposed, using blockchain technology and smart contracts. But given that, even in an advanced system like the proposed one, authentication evidence can be easily intercepted, this work proposes a single and robust identification scheme based on an innovative zero-knowledge proof (ZNP) system, which allows one side of communication to convince the other of its validity.

Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Cryptography and Data Security
Original source
Jun 24, 2022·IEEE Transactions on Network and Service Management
73 cites
A Hybrid Blockchain-Edge Architecture for Electronic Health Records Management with Attribute-based Cryptographic Mechanisms

Hao Guo, Wanxin Li, Mark Nejad, Chien‐Chung Shen

This paper presents a hybrid blockchain-edge architecture for managing Electronic Health Records (EHRs) with attribute-based cryptographic mechanisms. The architecture introduces a novel attribute-based signature aggregation (ABSA) scheme and multi-authority attribute-based encryption (MA-ABE) integrated with Paillier homomorphic encryption (HE) to protect patients' anonymity and safeguard their EHRs. All the EHR activities and access control events are recorded permanently as blockchain transactions. We develop the ABSA module on Hyperledger Ursa cryptography library, MA-ABE module on OpenABE toolset, and blockchain network on Hyperledger Fabric. We measure the execution time of ABSA's signing and verification functions, MA-ABE with different access policies and homomorphic encryption schemes, and compare the results with other existing blockchain-based EHR systems. We validate the access activities and authentication events recorded in blockchain transactions and evaluate the transaction throughput and latency using Hyperledger Caliper. The results show that the performance meets real-world scenarios' requirements while safeguarding EHR and is robust against unauthorized retrievals.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 24, 2022·arXiv (Cornell University)
18 cites
zPROBE: Zero Peek Robustness Checks for Federated Learning

Zahra Ghodsi, Mojan Javaheripi, Nojan Sheybani, Xinqiao Zhang · 6 authors

Privacy-preserving federated learning allows multiple users to jointly train a model with coordination of a central server. The server only learns the final aggregation result, thereby preventing leakage of the users’ (private) training data from the individual model updates. However, keeping the individual updates private allows malicious users to degrade the model accuracy without being detected, also known as Byzantine attacks. Best existing defenses against Byzantine workers rely on robust rank-based statistics, e.g., setting robust bounds via the median of updates, to find malicious updates. However, implementing privacy-preserving rank-based statistics, especially median-based, is nontrivial and unscalable in the secure domain, as it requires sorting of all individual updates. We establish the first private robustness check that uses high break point rank-based statistics on aggregated model updates. By exploiting randomized clustering, we significantly improve the scalability of our defense without compromising privacy. We leverage the derived statistical bounds in zero-knowledge proofs to detect and remove malicious updates without revealing the private user updates. Our novel framework, zPROBE, enables Byzantine resilient and secure federated learning. We show the effectiveness of zPROBE on several computer vision benchmarks. Empirical evaluations demonstrate that zPROBE provides a low overhead solution to defend against state-of-the-art Byzantine attacks while preserving privacy.

Open access
3 source records
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Adversarial Robustness in Machine Learning
Original source
Jun 23, 2022·International Journal for Research in Applied Science and Engineering Technology
4 cites
Blockchain-based Self-sovereign Identity Management System

Gauri Shetye, Nandini Sonar, Dhanamma Jagli

Abstract - The whole concept of self-sovereign identity (SSI) is gaining a lot of optimism, with the emerging Blockchain Technology in the current tech-scenario. It is a major change in how online interactions will take place in the future considering the identity of each user. The different aspects of SSI are examined by various works in the literature This paper surveys the origin of identity, various digital identity models and how it leads to self-sovereign identity. It then goes on to discuss related research, as well as the SSI's building blocks, which include decentralized IDs, verifiable credentials, a distributed ledger, and a variety of privacy mechanisms. Finally, it proposes a solution for self-sovereign identity by using the Ethereum platform for blockchain and other technologies

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy, Security, and Data Protection
Original source
Jun 23, 2022·arXiv (Cornell University)
41 cites
Advancing Blockchain-based Federated Learning through Verifiable Off-chain Computations

Jonathan Heiss, Elias Grünewald, Stefan Tai, Nikolas Haimerl · 5 authors

Federated learning may be subject to both global aggregation attacks and distributed poisoning attacks. Blockchain technology along with incentive and penalty mechanisms have been suggested to counter these. In this paper, we explore verifiable off-chain computations using zero-knowledge proofs as an alternative to incentive and penalty mechanisms in blockchain-based federated learning. In our solution, learning nodes, in addition to their computational duties, act as off-chain provers submitting proofs to attest computational correctness of param-eters that can be verified on the blockchain. We demonstrate and evaluate our solution through a health monitoring use case and proof-of-concept implementation leveraging the ZoKrates language and tools for smart contract-based on-chain model management. Our research introduces verifiability of correctness of learning processes, thus advancing blockchain-based federated learning.

Open access
3 source records
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 23, 2022·arXiv (Cornell University)
5 cites
Homomorphic Sortition -- Secret Leader Election for PoS Blockchains

Luciano Freitas de Souza, Andrei Tonkikh, Adda-Akram Bendoukha, Sara Tucci-Piergiovanni · 7 authors

In a single secret leader election protocol (SSLE), one of the system participants is chosen and, unless it decides to reveal itself, no other participant can identify it. SSLE has a great potential in protecting blockchain consensus protocols against denial of service (DoS) attacks. However, all existing solutions either make strong synchrony assumptions or have expiring registration, meaning that they require elected processes to re-register themselves before they can be re-elected again. This, in turn, prohibits the use of these SSLE protocols to elect leaders in partially-synchronous consensus protocols as there may be long periods of network instability when no new blocks are decided and, thus, no new registrations (or re-registrations) are possible. In this paper, we propose Homomorphic Sortition -- the first asynchronous SSLE protocol with non-expiring registration, making it the first solution compatible with partially-synchronous leader-based consensus protocols. Homomorphic Sortition relies on Threshold Fully Homomorphic Encryption (ThFHE) and is tailored to proof-of-stake (PoS) blockchains, with several important optimizations with respect to prior proposals. In particular, unlike most existing SSLE protocols, it works with arbitrary stake distributions and does not require a user with multiple coins to be registered multiple times. Our protocol is highly parallelizable and can be run completely off-chain after setup. Some blockchains require a sequence of rounds to have non-repeating leaders. We define a generalization of SSLE, called Secret Leader Permutation (SLP) in which the application can choose how many non-repeating leaders should be output in a sequence of rounds and we show how Homomorphic Sortition also solves this problem.

Open access
2 source records
Distributed systems and fault tolerance
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jun 22, 2022·2022 IEEE Conference on Dependable and Secure Computing (DSC)
1 cites
A Novel Approach for Providing Client-Verifiable and Efficient Access to Private Smart Contracts

Alexander Koberl, Holger Bock, Christian Steger

Distributed Ledger Technology is a powerful tool to support direct collaboration between organisations, without requiring full trust into a centralised infrastructure. By defining a program logic and access policies with smart contracts, all interactions are verified in the distributed network and the history of the data is recorded on the ledger. Blockchain implementations targeting enterprise use cases also provide means for private transactions, where the content of the transaction is only readable by authorized participants. Direct access to the ledger requires a node with reliable connection to the network and sufficient computational resources, which usually cannot be fulfilled with lightweight Internet of Things devices and mobile applications. We present an advanced system for accessing an enterprise Blockchain through dedicated gateway nodes, while preserving the functionality of private transactions. A hybrid approach is used to allow computation- and storage restricted clients to send private transactions through a central gateway, and use Light Ethereum Subprotocol to verify the data integrity based on proofs from distributed nodes. To increase the client-side security level, we introduce a dedicated Hardware Security Module for key management and efficient execution of the cryptographic primitives. A proof-of-concept implementation, using the Quorum Blockchain client and an extension for the Tessera transaction manager, validates the feasibility of the approach and can be used for further research in this field.

Open access
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Cryptography and Data Security
Original source
Jun 21, 2022·Connection Science
16 cites
A secure and efficient data deduplication framework for the internet of things via edge computing and blockchain

Zeng Wu, Hui Huang, Yuping Zhou, Chenhuang Wu

Data deduplication can solve the problem of resource wastage caused by duplicated data. However, due to the limited resources of Internet of Things (IoT) devices, applying data deduplication to IoT scenarios is challenging. Existing data deduplication frameworks for the IoT are prone to inefficiency or trust crises due to the random allocation of edge computing nodes. Furthermore, side-channel attacks remain a risk. In addition, after IoT devices store data in the cloud through data deduplication, they cannot share their data efficiently. In this paper, we propose a secure and efficient data deduplication framework for the IoT based on edge computing and blockchain technologies. In this scheme, we propose a model based on parallel use of three-layer and two-layer architectures and introduce the RAndom REsponse (RARE) scheme to resist side-channel attacks. We also design a label tree to realise one-to-many data-sharing, which improves efficiency and meets the needs of the IoT. In addition, we use blockchain to resist collusion attacks. Experiments were conducted to demonstrate that our framework has advantages over similar schemes in terms of communication cost, security and efficiency.

Open access
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jun 16, 2022·Electronics
23 cites
Secure and Anonymous Voting D-App with IoT Embedded Device Using Blockchain Technology

Cristian Toma, M. Popa, Cătălin Boja, Cristian Ciurea · 5 authors

The paper presents the construction of a proof-of-concept for a distributed and decentralized e-voting application in an IoT embedded device with the help of blockchain technology. A SoC board was used as an IoT embedded device for testing the PoC. This solution ensures complete voter anonymity and end-to-end security for all entities participating in the electronic voting process. The paper outlines the solution’s two layers. Implementation details are presented for the e-voting application, which was deployed inside of an IoT embedded device. The solution and presented protocols provide two major properties: privacy and verifiability. To ensure privacy, the proposed solution protects the secrecy of each electronic vote. As for implementing verifiability, the solution prevents a corrupt authority from faking in any way the process of counting the votes. Both properties are achieved in the presented solution e-VoteD-App.

Open access
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Cryptography and Data Security
Original source
Jun 16, 2022·YMER Digital
6 cites
BLOCKCHAIN-BASED ACCESS CONTROL SYSTEM FOR CLOUD STORAGE

Surarapu Sunitha, Nampalli Shirisha, Batchu Teja Sai Satish, Koyalakonda Vishnu · 5 authors

In this paper, we present a model of a multi-client framework for access control to datasets put away in an untrusted cloud climate. Distributed storage like some other untrusted climate needs the capacity to get share data. Our methodology gives an entrance command over the information put away in the cloud the supplier investment. The fundamental device of the access control instrument is a ciphertext-strategy trait-based encryption plot with dynamic credits. Utilizing a blockchain-based decentralized record, our framework gives a permanent log of all significant security occasions, for example, key age, access strategy task, change or repudiation, and access demand. We propose a bunch of cryptographic conventions guaranteeing the security of cryptographic tasks requiring mystery or private keys. Just ciphertexts of hash codes are moved through the blockchain record. The model of our framework is executed utilizing shrewd agreements and tried on the Ethereum blockchain stage. Keywords- cloud storage; attribute-based access control; ciphertext-policy attribute-based encryption; blockchain

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Jun 15, 2022·Proceedings of the 17th International Conference on Availability, Reliability and Security
7 cites
Towards Verifiable Differentially-Private Polling

Gonzalo Munilla Garrido, Johannes Sedlmeir, Matthias Babel

Analyses that fulfill differential privacy provide plausible deniability to individuals while allowing analysts to extract insights from data. However, beyond an often acceptable accuracy tradeoff, these statistical disclosure techniques generally inhibit the verifiability of the provided information, as one cannot check the correctness of the participants' truthful information, the differentially private mechanism, or the unbiased random number generation. While related work has already discussed this opportunity, an efficient implementation with a precise bound on errors and corresponding proofs of the differential privacy property is so far missing. In this paper, we follow an approach based on zero-knowledge proofs~(ZKPs), in specific succinct non-interactive arguments of knowledge, as a verifiable computation technique to prove the correctness of a differentially private query output. In particular, we ensure the guarantees of differential privacy hold despite the limitations of ZKPs that operate on finite fields and have limited branching capabilities. We demonstrate that our approach has practical performance and discuss how practitioners could employ our primitives to verifiably query individuals' age from their digitally signed ID card in a differentially private manner.

Open access
3 source records
cs.CR
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Jun 13, 2022·arXiv
14 cites
SBvote: Scalable Self-Tallying Blockchain-Based Voting

Ivana Stančíková, Ivan Homoliak

Decentralized electronic voting solutions represent a promising advancement in electronic voting. One of the e-voting paradigms, the self-tallying scheme, offers strong protection of the voters' privacy while making the whole voting process verifiable. Decentralized smart contract platforms became interesting practical instantiation of the immutable bulletin board that this scheme requires to preserve its properties. Existing smart contract-based approaches employing the self-tallying scheme (such as OVN or BBB-Voting) are only suitable for a boardroom voting scenario due to their scalability limitation. The goal of our work is to build on existing solutions to achieve scalability without losing privacy guarantees and verifiability. We present SBvote, a blockchain-based self-tallying voting protocol that is scalable in the number of voters and therefore suitable for large-scale elections. The evaluation of our proof-of-concept implementation shows that the protocol's scalability is limited only by the underlying blockchain platform. We evaluated the scalability of SBvote on two public smart contract platforms -- Gnosis and Harmony. Despite the limitations imposed by the throughput of the blockchain platform, SBvote can accommodate elections with millions of voters.

Open access
2 source records
cs.CR
cs.DC
Internet Traffic Analysis and Secure E-voting
Original source
Jun 8, 2022·arXiv (Cornell University)
0 cites
Intractable Group-theoretic Problems Around Zero-knowledge Proofs

Cansu Betin Onur

While the amount of data produced and accumulated continues to advance at unprecedented rates, protection and concealment of data increase its prominence as a field of scientific study that requires more action. It is essential to protect privacy-sensitive data at every phase; at rest, at run, and while computations are executed on data. The zero-knowledge proof (ZKP) schemes are a cryptographic tool toward this aim. ZKP allows a party to securely ensure the data's authenticity and precision without revealing confidential or privacy-sensitive information during communication or computation. The power of zero-knowledge protocols is based on intractable problems. There is a requirement to design more secure and efficient zero-knowledge proofs. This demand raises the necessity of determining appropriate intractable problems to develop novel ZKP schemes. In this paper, we present a brief outline of ZKP schemes, the connection of these structures to group-theoretic intractable problems, and annotate a list of intractable problems in group theory that can be employed to devise new ZKP schemes.

Open access
2 source records
Cryptography and Data Security
Geometric and Algebraic Topology
Advanced Authentication Protocols Security
Original source
Jun 2, 2022·Applied Sciences
16 cites
Privacy-Preserving Data Mining on Blockchain-Based WSNs

Niki Hrovatin, Aleksandar Tošić, Michaël Mrissa, Branko Kavšek

Currently, the computational power present in the sensors forming a wireless sensor network (WSN) allows for implementing most of the data processing and analysis directly on the sensors in a decentralized way. This shift in paradigm introduces a shift in the privacy and security problems that need to be addressed. While a decentralized implementation avoids the single point of failure problem that typically applies to centralized approaches, it is subject to other threats, such as external monitoring, and new challenges, such as the complexity of providing decentralized implementations for data mining algorithms. In this paper, we present a solution for privacy-aware distributed data mining on wireless sensor networks. Our solution uses a permissioned blockchain to avoid a single point of failure in the system. Contracts are used to construct an onion-like structure encompassing the Hoeffding trees and a route. The onion-routed query conceals the network identity of the sensors from external adversaries, and obfuscates the actual computation to hide it from internally compromised nodes. We validate our solution on a use case related to an air quality-monitoring sensor network. We compare the quality of our model against traditional models to support the feasibility and viability of the solution.

Open access
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Jun 2, 2022·Security and Communication Networks
9 cites
Enabling Decentralized and Auditable Access Control for IoT through Blockchain and Smart Contracts

Hien Thi Thu Truong, José L. Hernández-Ramos, Juan A. Martínez, Jorge Bernal Bernabé · 7 authors

The increase in the interconnection of physical devices and the emergence of the 5 G paradigm foster the generation and distribution of massive amounts of data. The complexity associated with the management of these data requires a suitable access control approach that empowers citizens to control how their data are shared, so potential privacy issues can be mitigated. While well-known access control models are widely used in web and cloud scenarios, the IoT ecosystem needs to address the requirements of lightness, decentralization, and scalability to control the access to data generated by a huge number of heterogeneous devices. This work proposes CapBlock, a design that integrates a capability-based access control model and blockchain technology for a fully distributed evaluation of authorization policies and generation of access credentials using smart contracts. CapBlock is intended to manage the access to information in federated IoT environments where data need to be managed through access control policies defined by different data providers. The feasibility of CapBlock has been successfully evaluated in the scope of the EU research project IoTCrawler, which aims at building a secure search engine for IoT data in large-scale scenarios.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source