Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results · page 92 of 177

Clear filters
Jul 9, 2024·arXiv (Cornell University)
21 cites
Towards a Novel Privacy-Preserving Distributed Multiparty Data Outsourcing Scheme for Cloud Computing with Quantum Key Distribution

D. Dhinakaran, D. Selvaraj, N. Dharini, S. Edwin Raja · 5 authors

The intersection of cloud computing, blockchain technology, and the impending era of quantum computing presents a critical juncture for data security. This research addresses the escalating vulnerabilities by proposing a comprehensive framework that integrates Quantum Key Distribution (QKD), CRYSTALS Kyber, and Zero-Knowledge Proofs (ZKPs) for securing data in cloud-based blockchain systems. The primary objective is to fortify data against quantum threats through the implementation of QKD, a quantum-safe cryptographic protocol. We leverage the lattice-based cryptographic mechanism, CRYSTALS Kyber, known for its resilience against quantum attacks. Additionally, ZKPs are introduced to enhance data privacy and verification processes within the cloud and blockchain environment. A significant focus of this research is the performance evaluation of the proposed framework. Rigorous analyses encompass encryption and decryption processes, quantum key generation rates, and overall system efficiency. Practical implications are scrutinized, considering factors such as file size, response time, and computational overhead. The evaluation sheds light on the framework's viability in real-world cloud environments, emphasizing its efficiency in mitigating quantum threats. The findings contribute a robust quantum-safe and ZKP-integrated security framework tailored for cloud-based blockchain storage. By addressing critical gaps in theoretical advancements, this research offers practical insights for organizations seeking to secure their data against quantum threats. The framework's efficiency and scalability underscore its practical feasibility, serving as a guide for implementing enhanced data security in the evolving landscape of quantum computing and blockchain integration within cloud environments.

Open access
2 source records
cs.CR
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jul 8, 2024·IACR Communications in Cryptology
1 cites
PACIFIC

Scott Griffy, Anna Lysyanskaya

To be useful and widely accepted, automated contact tracing schemes (also called exposure notification) need to solve two seemingly contradictory problems at the same time: they need to protect the anonymity of honest users while also preventing malicious users from creating false alarms. In this paper, we provide, for the first time, an exposure notification construction that guarantees the same levels of privacy and integrity as existing schemes but with a fully malicious database (notably similar to Auerbach et al. CT-RSA 2021) without special restrictions on the adversary. We construct a new definition so that we can formally prove our construction secure. Our definition ensures the following integrity guarantees: no malicious user can cause exposure warnings in two locations at the same time and that any uploaded exposure notifications must be recent and not previously uploaded. Our construction is efficient, requiring only a single message to be broadcast at contact time no matter how many recipients are nearby. To notify contacts of potential infection, an infected user uploads data with size linear in the number of notifications, similar to other schemes. Linear upload complexity is not trivial with our assumptions and guarantees (a naive scheme would be quadratic). This linear complexity is achieved with a new primitive: zero knowledge subset proofs over commitments which is used by our "no cloning" proof protocol. We also introduce another new primitive: set commitments on equivalence classes, which makes each step of our construction more efficient. Both of these new primitives are of independent interest.

Open access
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Original source
Jul 8, 2024
5 cites
Share with Care: Breaking E2EE in Nextcloud

M. Albrecht, Matilda Backendal, Daniele Coppola, Kenneth G. Paterson

Nextcloud is a leading cloud storage platform with more than 20 million users. Nextcloud offers an end-to-end encryption (E2EE) feature that is claimed to be able “to keep extremely sensitive data fully secure even in case of a full server breach”. They also claim that the Nextcloud server “has Zero Knowledge, that is, never has access to any of the data or keys in unencrypted form”. This is achieved by having encryption and decryption operations that are done using file keys that are only available to Nextcloud clients, with those file keys being protected by a key hierarchy that ultimately relies on long passphrases known exclusively to the users. We provide the first detailed documentation and security analysis of Nextcloud's E2EE feature. Nextcloud's strong security claims motivate conducting the analysis in the setting where the server itself is considered malicious. We present three distinct attacks against the E2EE security guarantees in this setting. Each one enables the confidentiality and integrity of all user files to be compromised. All three attacks are fully practical and we have built proof-of-concept implementations for each. The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users' data. We have responsibly disclosed the three vulnerabilities to N extcloud. The second and third vulnerabilities have been remediated. The first was addressed by temporarily disabling file sharing from the E2EE feature until a redesign of the feature can be made. We reflect on broader lessons that can be learned for designers of E2EE systems.

Open access
Advanced Authentication Protocols Security
Digital Rights Management and Security
Privacy, Security, and Data Protection
Original source
Jul 8, 2024
4 cites
Blockchain and Trustworthy Reputation for Federated Learning: Opportunities and Challenges

Farhana Javed, Josep Mangues‐Bafalluy, Engin Zeydan, Luis Blanco

In the domain of Collaborative Artificial Intelligence, Federated Learning ($\mathbf{F L}$) is a technique that enables multiple entities to collaboratively refine AI models while adhering to stringent data privacy standards, without the need for direct data sharing. This paper explores the integration of blockchain technology with FL to establish reliable trust mechanisms within this collaborative framework. We highlight and review current blockchain-enabled reputation mechanisms that evaluate the reliability and quality of contributions from participants, which are crucial for maintaining trust and operational integrity in distributed settings. Through our review, we address the concept and implementation challenges. Additionally, we discuss recent technological advances and explore the emerging opportunities that blockchain presents to address trust-related challenges in FL, emphasizing significant prospects for future research directions, such as decentralized identities, zero trust, and zero-knowledge proofs to enhance trust in these environments.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jul 8, 2024·IACR Communications in Cryptology
8 cites
Optimizing and Implementing Fischlin's Transform for UC-Secure Zero Knowledge

Yi-Hsiu Chen, Yehuda Lindell

Fischlin's transform (CRYPTO 2005) is an alternative to the Fiat-Shamir transform that enables straight-line extraction when proving knowledge. In this work we focus on the problem of using the Fischlin transform to construct UC-secure zero-knowledge from Sigma protocols, since UC security – that guarantees security under general concurrent composition – requires straight-line (non-rewinding) simulators. We provide a slightly simplified transform that is much easier to understand, and present algorithmic and implementation optimizations that significantly improve the running time. It appears that the main obstacles to the use of Fischlin in practice is its computational cost and implementation complexity (with multiple parameters that need to be chosen). We provide clear guidelines and a simple methodology for choosing parameters, and show that with our optimizations the running-time is far lower than expected. For just one example, on a 2023 MacBook, the cost of proving the knowledge of discrete log with Fischlin is only 0.41ms (on a single core). This is 15 times slower than plain Fiat-Shamir on the same machine, which is a significant multiple but objectively not significant in many applications. We also extend the transform so that it can be applied to batch proofs, and show how this can be much more efficient than individually proving each statement. We hope that this paper will both encourage and help practitioners implement the Fischlin transform where relevant.

Open access
Cryptography and Data Security
Cryptographic Implementations and Security
Security and Verification in Computing
Original source
Jul 7, 2024·Scientific Journal of Artificial Intelligence and Blockchain Technologies
0 cites
GDPR Compliance Challenges in Blockchain-Based Systems

Dr Sandeep Kumar

Blockchain’s decentralization, transparency, and tamper‐resistance are celebrated properties for auditability and trust, yet they collide with core data protection duties under the EU General Data Protection Regulation (GDPR). This manuscript analyzes the principal compliance challenges that arise when blockchain processes personal data and proposes a practical, design-oriented framework to address them. First, we synthesize legal and regulatory positions on what counts as “personal data,” the difference between anonymization and pseudonymization, and the implications of the right to erasure, data protection by design and by default, allocation of controller/processor roles, and international data transfers. We then map these requirements to blockchain architectures (public permissionless, public permissioned, and private permissioned) and data patterns (on-chain, off-chain, hybrid). Building on recent guidance from the European Data Protection Board (EDPB) and national authorities, we outline concrete technical and governance controls—off-chain storage and on-chain commitments, keyed hashing, encryption/key-revocation strategies, chameleon-hash/redactable-ledger designs, selective-disclosure credentials/zero-knowledge proofs, and robust consortium governance—to reduce risk and improve demonstrable compliance. Applying a six-step assessment methodology to three realistic use cases (NFT profile registry, supply-chain provenance, and consortium KYC), we show that while no single pattern fully reconciles immutability with erasure, practicable combinations can align processing with GDPR’s principles of minimization, purpose limitation, storage limitation, and accountability. The paper concludes with a prioritized checklist for engineering “compliance-by-design” blockchains, and delineates scope and limitations for practitioners and researchers.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Jul 6, 2024·Proceedings on Privacy Enhancing Technologies
1 cites
Divisible E-Cash for Billing in Private Ad Retargeting

Kevin Liao, Henry Corrigan-Gibbs, Dan Boneh

This paper presents new techniques for private billing in systems for privacy-preserving online advertising. In particular, we show how an ad exchange can use an e-cash scheme to bill advertisers for ad impressions without learning which client saw which ad: The exchange issues electronic coins to advertisers, advertisers pay publishers (via clients) for ad impressions, and publishers unlinkably redeem coins with the exchange. To implement this proposal, we design a new divisible e-cash scheme that uses modern zero-knowledge proofs to reduce the ad exchange's computational costs by roughly 250x compared to the previous state-of-the-art. With our new e-cash scheme, our private-billing infrastructure adds little overhead to existing private ad-retargeting systems: less than 63 ms of latency, negligible client computation, less than 3.2 KB of client communication, and a combined server operating cost (advertisers, publishers, and exchange) of less than 1% of ad spend, an over 5x savings compared to the previous state-of-the-art.

Open access
Banking stability, regulation, efficiency
Original source
Jul 4, 2024·Scientific Journal of Artificial Intelligence and Blockchain Technologies
0 cites
Ethical AI Design in Blockchain-Powered Surveillance Systems

Dr Munish Kumar

Artificial intelligence (AI) and distributed ledger technologies are increasingly integrated into public and private surveillance infrastructures—from city-wide camera networks to critical-infrastructure monitoring and access control. This integration promises higher integrity and accountability through immutable logs, faster incident response via on-device inference, and interoperable audit trails across organizations. Yet it also amplifies ethical risks: mass data collection, opacity in model decisions, function creep, demographic harms, cross-border data governance conflicts, and accountability gaps when immutable records meet “right to erasure” regimes. This manuscript proposes an ethics-by-design reference architecture for blockchain-powered surveillance that embeds privacy, proportionality, and fairness controls into each lifecycle stage (purpose definition → data capture → model training → inference → access → audit → decommissioning). Technically, it composes privacy-enhancing technologies (PETs)—including differential privacy, federated learning, zero-knowledge proofs, verifiable credentials (VCs), and content-provenance standards (C2PA)—with permissioned blockchain ledgers, model cards, and risk management aligned to the NIST AI RMF, ISO/IEC 23894, ISO/IEC 42001, UNESCO, and ACM guidance. A simulated evaluation illustrates how the architecture can reduce false-positive disparities and unauthorized access, while preserving evidentiary integrity. We discuss tensions with GDPR (e.g., Article 17 erasure; DPIA obligations), constraints introduced by the EU AI Act (e.g., prohibitions and high-risk biometric uses), and strategies to reconcile immutability with privacy (e.g., off-chain storage with revocation, redaction-friendly commitments). The paper closes with limitations and a future research agenda for measurable, auditable ethical guarantees in real-time surveillance.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Jul 4, 2024·Information
19 cites
Evaluating the Efficiency of zk-SNARK, zk-STARK, and Bulletproof in Real-World Scenarios: A Benchmark Study

Mohammed El‐Hajj, Bjorn Oude Roelink

This study builds on our previous systematic literature review (SLR) that assessed the applications and performance of zk-SNARK, zk-STARK, and Bulletproof non-interactive zero-knowledge proof (NIZKP) protocols. To address the identified research gaps, we designed and implemented a benchmark comparing these three protocols using a dynamic minimized multiplicative complexity (MiMC) hash application. We evaluated performance across four general-purpose programming libraries and two programming languages. Our results show that zk-SNARK produced the smallest proofs, while zk-STARK generated the largest. In terms of proof generation and verification times, zk-STARK was the fastest, and Bulletproof was the slowest. Interestingly, zk-SNARK proofs verified marginally faster than zk-STARK, contrary to other findings. These insights enhance our understanding of the functionality, security, and performance of NIZKP protocols, providing valuable guidance for selecting the most suitable protocol for specific applications.

Open access
2 source records
Security and Verification in Computing
Forensic Toxicology and Drug Analysis
Distributed systems and fault tolerance
Original source
Jul 2, 2024·arXiv (Cornell University)
2 cites
RollupTheCrowd: Leveraging ZkRollups for a Scalable and Privacy-Preserving Reputation-based Crowdsourcing Platform

A. Bendada, Mouhamed Amine Bouchiha, Mourad Rabah, Yacine Ghamri-Doudane

Current blockchain-based reputation solutions for crowdsourcing fail to tackle the challenge of ensuring both efficiency and privacy without compromising the scalability of the block chain. Developing an effective, transparent, and privacy-preserving reputation model necessitates on-chain implementation using smart contracts. However, managing task evaluation and reputation updates alongside crowdsourcing transactions on-chain substantially strains system scalability and performance. This paper introduces RollupTheCrowd, a novel blockchain-powered crowdsourcing framework that leverages zkRollups to enhance system scalability while protecting user privacy. Our framework includes an effective and privacy-preserving reputation model that gauges workers' trustworthiness by assessing their crowdsourcing interactions. To alleviate the load on our blockchain, we employ an off-chain storage scheme, optimizing RollupTheCrowd's performance. Utilizing smart contracts and zero-knowledge proofs, our Rollup layer achieves a significant 20x reduction in gas consumption. To prove the feasibility of the proposed framework, we developed a proof-of-concept implementation using cutting-edge tools. The experimental results presented in this paper demonstrate the effectiveness and scalability of RollupTheCrowd, validating its potential for real-world application scenarios.

Open access
3 source records
cs.CR
cs.DC
Blockchain Technology Applications and Security
Original source
Jul 2, 2024·Distributed Ledger Technologies Research and Practice
5 cites
Scalable Anonymous Authentication Scheme Based on Zero-Knowledge Set-Membership Proof

Christopher Wiraatmaja, Shoji Kasahara

In this article, we propose zero-knowledge named proof, a stateless replay attack prevention strategy that ensures the user’s anonymity against malicious administrators. We begin with adopting the zero-knowledge set-membership proof into an authentication setting in which users would delegate their requests to an agent that obstructs the user’s identity from the administrator. This anonymous agent carries the guarantee of authenticity, which the administrator through the set-membership proof can confirm. Next, we prevent replay attacks from other parties by binding the agent’s identity to the authentication proof verifiable by the administrators. By leveraging these properties, a scalable blockchain-based authentication scheme is then built. We quantitatively evaluate the security and measure the time and monetary cost of our scheme under both ideal and realistic environments. On top of it, we provide a third-party authorization scheme derived from our authentication framework to demonstrate its real-world applicability.

Open access
2 source records
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
Jul 1, 2024·UPCommons institutional repository (Universitat Politècnica de Catalunya)
0 cites
Implementació de primitives criptogràfiques algebraiques en la estructura de Plonk

Mitjans Llorach, Àlex

As cryptographic technologies evolve, the need for specialized hash functions to operate efficiently over different computational environments becomes necessary. Traditional symmetric algorithms like AES and SHA-3 have been optimized for traditional hardware and software implementations, which are designed over binary fields. However, protocols like zero-knowledge proofs require hash functions that are optimised over large prime fields. This thesis addresses the growing demand for Arithmetization-Oriented (AO) cryptographic hash functions for zero-knowledge applications. The performance and efficiency of many zero-knowledge applications often depends on the efficiency of the hash function used. In response to this need, this work explores a selection of these hash functions and implements them within two zero-knowledge proving systems: Dusk Network?s Plonk and Polygon?s Plonky2, with a focus on assessing the different performance tradeoffs that these hash functions offer within these sytems.

Open access
Cryptographic Implementations and Security
Coding theory and cryptography
Cryptography and Residue Arithmetic
Original source
Jul 1, 2024·arXiv (Cornell University)
0 cites
Offline Digital Euro: a Minimum Viable CBDC using Groth-Sahai proofs

Leon Kempen, Johan Pouwelse

Current digital payment solutions are fragile and offer less privacy than traditional cash. Their critical dependency on an online service used to perform and validate transactions makes them void if this service is unreachable. Moreover, no transaction can be executed during server malfunctions or power outages. Due to climate change, the likelihood of extreme weather increases. As extreme weather is a major cause of power outages, the frequency of power outages is expected to increase. The lack of privacy is an inherent result of their account-based design or the use of a public ledger. The critical dependency and lack of privacy can be resolved with a Central Bank Digital Currency that can be used offline. This thesis proposes a design and a first implementation for an offline-first digital euro. The protocol offers complete privacy during transactions using zero-knowledge proofs. Furthermore, transactions can be executed offline without third parties and retroactive double-spending detection is facilitated. To protect the users' privacy, but also guard against money laundering, we have added the following privacy-guarding mechanism. The bank and trusted third parties for law enforcement must collaborate to decrypt transactions, revealing the digital pseudonym used in the transaction. Importantly, the transaction can be decrypted without decrypting prior transactions attached to the digital euro. The protocol has a working initial implementation showcasing its usability and demonstrating functionality.

Open access
2 source records
cs.CR
q-fin.TR
Stochastic processes and financial applications
Original source
Jul 1, 2024·Indonesian Journal of Electrical Engineering and Computer Science
79 cites
Optimizing blockchain for healthcare IoT: a practical guide to navigating scalability, privacy, and efficiency trade-offs

Mwaffaq Abu AlHija, Osama Al-Baik, Abdelrahman H. Hussein, Hikmat A. M. Abdeljaber

The adoption of blockchain technology provides significant disruptive benefits to internet-of-things (IoT) applications in healthcare in vital aspects like security, integrity, transparency, and efficiency. Nevertheless, in order to fully realize the potential of blockchain-driven solutions, healthcare organizations have to address intricate compromises between essential factors including scalability, privacy and resource utilization considering that the data sensitivity alongside strict regulatory compliance requirements characterize this sector. This research discusses the fundamental aspects of these trade-offs, including the range of consensus protocols (e.g. proof-of-work, proof-of-stake) and cryptographic techniques (e.g. zero-knowledge proofs, homomorphic encryption). A systematic choice matrix is created, which relates specific use cases of the healthcare IoT to the optimal tailored blockchain structures on such critical metrics as transaction volume, frequency, privacy level and resource restrictions. The suggested framework provides solid, actionable recommendations to healthcare organizations in order to help them benefit from the enormous promise of the blockchain for connected IoT healthcare by finding a balance between decentralization advantages and performance, security and compliance requirements.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Original source
Jun 30, 2024·Digital management sciences journal
0 cites
The impact of Block chain-Based System on Goods Tracking and management in Industrial Environment

Gigi Yong, Sherene Tyng Xin Saw, Jhen Nee Tang, Teng Li · 6 authors

In the domain of Industrial Internet of Things (IIoT), the demand for robust and secure methods for goods tracking and management has become growingly critical. Conventional methods face significant challenges, including authentication, computational overhead, cyber security, and data integrity. To address these issues, this paper proposes a block-chain based system for goods management and tracking with enhanced authentication mechanism by leveraging the decentralized nature of block-chain technology and integrating Elliptic Curve Digital Signature Algorithm (ECDSA) with Elliptic Curve Cryptography-Zero Knowledge Proof (ECC-ZKP). The proposed solution aims to ensure the authenticity and the integrity for all the transaction while providing high level privacy-preserving verification without revealing information. The research in this paper demonstrates that the proposed block-chain-based system significantly enhances security performance, key management and operational efficiency, addressing the existing challenges in IIoT goods tracking and management, providing a resilient framework for more secure industrial operations in managing goods.

Open access
Big Data and Business Intelligence
Blockchain Technology Applications and Security
Original source
Jun 30, 2024·International Journal of Science and Research Archive
0 cites
Blockchain and privacy: How decentralized systems reshaped data security

Arfi Siddik Mollashaik

This research evaluates how blockchain technology transforms data security functions, especially regarding privacy protection. The rise of decentralized systems led to Blockchain emerging as an answer for resolving traditional data security problems from breaches to centralization risks. This research investigates blockchain technology, which advanced from its initial cryptocurrency framework into an all-encompassing data protection solution. Research shows that Blockchain improves privacy through encryption methods and distributed operations. A qualitative research approach enables examination of blockchain solutions with privacy components alongside analysis of zero-knowledge proofs and decentralized storage facilities. Technology solutions provide users with comprehensive data visibility and reduce exposure to unauthorized intruders and free them from central control systems. The adaptive security structure of blockchain technology functions as the industry-leading answer to privacy breaches by establishing strengthened data protection protocols for all operational activities.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Jun 28, 2024·Advances in Economics Management and Political Sciences
0 cites
Service and Technology Transaction Framework and Confidentially Mechanism Based on Blockchain

Junxue Zhou, Donglin Chen, Min Fu

The science and technology service industry is an indispensable part of the innovation system. Since the science and technology service transaction is platform dependent, they have the drawbacks of centralized transactions. As these services involve intellectual property, it is critical to preserve the confidentiality of transaction information. To address this issue, this study builds a science and technology service framework, which includes a provider and a demander, data temporary storage, timestamp and confidentiality verification, followed by the construction of a confidentiality mechanism for science and technology service transactions based on zero-knowledge proof technology. This mechanism can decentralize science and technology service transactions and keep the information of both parties confidential, which can promote the effective circulation of science and technology information. Finally, from the perspectives of economic value, industrial value, and commercial value, this study analyzes the value of combining blockchain with technology service transactions, considering the practical significance in promoting the development of scientific and technological services.

Open access
Blockchain Technology Applications and Security
Original source
Jun 28, 2024
3 cites
Camel: E2E Verifiable Instant Runoff Voting without Tallying Authorities

Luke Harrison, Samiran Bag, Feng Hao

Instant Runoff Voting (IRV) is one example of ranked-choice voting. It provides many known benefits when used in elections, such as minimising vote splitting, ensuring few votes are wasted, and providing resistance to strategic voting. However, the voting and tallying procedures for IRV are much more complicated than those of plurality and are both error-prone and tedious. Many automated systems have been proposed to simplify these procedures in IRV. Some of these also employ cryptographic techniques to protect the secrecy of ballots and enable verification of the tally. Nearly all of these cryptographic systems require a set of trustworthy tallying authorities (TAs) to perform the decryption of votes and/or running of mix servers, which adds significant complexity to the implementation and election management. We address this issue by proposing Camel: an E2E verifiable solution for IRV that requires no TAs. Camel employs a novel representation and a universally verifiable shifting procedure for ballots that facilitate the elimination of candidates as required in an IRV election. We combine these with a homomorphic encryption scheme and zero-knowledge proofs to protect the secrecy of the ballots and enable any party to verify the well-formedness of the ballots and the correctness of the tally in an IRV election. We examine the security of Camel and prove it maintains ballot secrecy by limiting the learned information (namely the tally) against a set of colluding voters.

Open access
Game Theory and Voting Systems
Complexity and Algorithms in Graphs
Internet Traffic Analysis and Secure E-voting
Original source
Jun 28, 2024
7 cites
Card-Based Zero-Knowledge Proof Protocols for the 15-Puzzle and the Token Swapping Problem

Y. TAMURA, Akira Suzuki, Takaaki Mizuki

The 15-puzzle is a puzzle game played with 15 square tiles numbered from 1 to 15 on a 4 × 4 board. It has been popular for generations because of its simplicity and challenge. The (w × h)-puzzle is a generalization of the 15-puzzle, which is played with wh − 1 square tiles numbered from 1 to wh − 1 on a w × h board. Solving the (w × h)-puzzle is NP-hard, and hence it is valuable to know its solution. In this paper, we apply the concept of zero-knowledge proof to the (w × h)-puzzle. We propose a physical zero-knowledge proof protocol, in which a prover who knows a solution to the (w × h)-puzzle can convince a verifier that the prover knows the solution without revealing any information about it. We also design physical zero-knowledge proof protocols of two token swapping problems closely related to the (w × h)-puzzle.

Open access
semigroups and automata theory
Cryptography and Data Security
DNA and Biological Computing
Original source
Jun 27, 2024·arXiv (Cornell University)
4 cites
Towards Credential-based Device Registration in DApps for DePINs with ZKPs

Jonathan Heiss, Fernando Castillo, Xinxin Fan

Decentralized Physical Infrastructure Networks (De-PINS) are secured and governed by blockchains but beyond crypto-economic incentives, they lack measures to establish trust in participating devices and their services. The verification of relevant device credentials during device registration helps to overcome this problem. However, on-chain verification in decentralized applications (dApp) discloses potentially confidential device attributes whereas off-chain verification introduces undesirable trust assumptions. In this paper, we propose a credential-based device registration (CDR) mechanism that verifies device credentials on the blockchain and leverages zero-knowledge proofs (ZKP) to protect confidential device attributes from being disclosed. We characterize CDR for DePINs, present a general system model, and technically evaluate CDR using zkSNARKs with Groth16 [1] and Marlin [2]. Our experiments give first insights into performance impacts and reveal a tradeoff between the applied proof systems.

Open access
3 source records
cs.CR
cs.DC
Scientific Computing and Data Management
Original source
Jun 26, 2024·Heliyon
4 cites
BRON: A blockchained framework for privacy information retrieval in human resource management

Gulshan Kumar, Rahul Saha, Manish Gupta, Tai-hoon Kim

The correctness and the true validated data in Human Resource Management (HRM) are important for organizations as the data plays an impactful role in recruiting, developing, and retaining a skilled workforce. On one hand, the validated data in an organization helps in recruiting legitimate skillful employees; on the other hand, keeping the employee's data safe and maintaining privacy laws such as compliance with the General Data Protection Regulation (GDPR) is also an organization's responsibility. Besides, transparency in human resource management operations is crucial because it promotes trust and fairness within an organization. The present HRM systems are centralized in nature and their verifiable credential system is ineffective; this leads to the intentions of internal data sabotage or internal threats. Besides, the organizations' biases also become more prominent. In this paper, we address the above-mentioned problems with a blockchain framework for HRM to utilize the privacy of data access through a Privacy Information Retrieval (PIR) process. To be specific, our proposed framework called Blockchained piR of resOurces as humaN (BRON) , is the first blockchain framework to show an effective mechanism to access data from organizations globally without hampering privacy. BRON uses a generalized user registration process to use the services of data access and in the background, it uses Zero-Knowledge Proofs (ZKPs) for global verification and PIR for privacy-based data retrieval. More specifically, credential verification and ZKP-based PIR are the highlights of our proposed BRON. Another interesting aspect of BRON is the use of Proof-of-Authority (PoA) to validate the anonymity and unlinkability of any HR operation. Finally, BRON has also contributed with a smart contract to incentivize the employees. BRON is very generic and easily be customizable as per the HR requirements. We run a set of experiments on BRON and observe that it is successful in providing privacy-assured data access and decentralized human resource data management. Overall, BRON provides 30% reduced latency and 35% better throughput as compared to the existing blockchain solutions in the direction of HRM.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jun 26, 2024·arXiv (Cornell University)
0 cites
A Communication Satellite Servises Based Decentralized Network Protocol

Xiao Ying Yan, Bernie Gao

In this paper, we present a decentralized network protocol, Space Network Protocol, based on Communication Satellite Services. The protocol outlines a method for distributing information about the status of satellite communication services across the entire blockchain network, facilitating fairness and transparency in all communication services. Our primary objective is to standardize the services delivered by all satellite networks under the communication satellite protocol. This standard remains intact regardless of potential unreliability associated with the satellites or the terminal hardware. We proposed PoD (Proof of Distribution) to verify if the communication satellites are online and PoF (Proof of Flow) to authenticate the actual data flow provided by the communication satellites. In addition, we also proposed PoM (Proof of Mesh) to verify if the communication satellites have successfully meshed together. Utilizing zero-knowledge proof and multi-party cryptographic computations, we can evaluate the service provisioning parameters of each satellite, even in the presence of potential terminal or network node fraud. This method offers technical support for the modeling of distributed network services.

Open access
2 source records
cs.CR
cs.DC
cs.NI
Original source
Jun 25, 2024·Proceedings on Privacy Enhancing Technologies
5 cites
Compact Issuer-Hiding Authentication, Application to Anonymous Credential

Olivier Sanders, Jacques Traoré

Anonymous credentials are cryptographic mechanisms enabling users to authenticate themselves with a fine-grained control on the information they leak in the process. They have been the topic of countless papers which have improved the performance of such mechanisms or proposed new schemes able to prove ever-more complex statements about the attributes certified by those credentials. However, although these papers have studied in depth the problem of the information leaked by the credential and/or the attributes, almost all of them have surprisingly overlooked the information one may infer from the knowledge of the credential issuer. In this paper we address this problem by showing how one can efficiently hide the actual issuer of a credential within a set of potential issuers. The novelty of our work is that we do not resort to zero-knowledge proofs but instead we show how one can tweak Pointcheval-Sanders signatures to achieve this issuer-hiding property in a compact way. This results in an efficient anonymous credential system that indeed provides a complete control of the information leaked in the authentication process. Our construction is moreover modular and can then fit a wide spectrum of applications, notably for Self-Sovereign Identity (SSI) systems.

Open access
Cryptography and Data Security
Original source
Jun 25, 2024·Proceedings on Privacy Enhancing Technologies
1 cites
FlashSwift: A Configurable and More Efficient Range Proof With Transparent Setup

Nan Wang, Dongxi Liu

Bit-decomposition-based zero-knowledge range proofs in the discrete logarithm (DLOG) setting with a transparent setup, e.g., Bulletproof (IEEE S&P 18), Flashproof (ASIACRYPT 22), and SwiftRange (IEEE S&P 24), have garnered widespread popularity across various privacy-enhancing applications. These proofs aim to prove that a committed value falls within the non-negative range [0, 2^N-1] without revealing it, where N represents the bit length of the range. Despite their prevalence, the current implementations still suffer from suboptimal performance. Some exhibit reduced communication costs at the expense of increased computational costs while others experience the opposite. Presently, users are compelled to utilize these proofs in scenarios demanding stringent requirements for both communication and computation efficiency. In this paper, we introduce, FlashSwift, a stronger DLOG-based logarithmic-sized alternative. It stands out for its greater shortness and significantly enhanced computational efficiency compared with the cutting-edge logarithmic-sized ones for the most common ranges where N is no more than 64. It is developed by integrating the techniques from Flashproof and SwiftRange without using a trusted setup. The substantial efficiency gains stem from our dedicated efforts in overcoming the inherent incompatibility barrier between the two techniques. Specifically, when N=64, our proof achieves the same size as Bulletproof and exhibits 1.1 times communication efficiency of SwiftRange. More importantly, compared with the two, it achieves 2.3 times and 1.65 times proving efficiency, and 3.2 times and 1.7 times verification efficiency, respectively. At the time of writing, our proof also creates two new records of the smallest proof sizes, 289 bytes and 417 bytes, for 8-bit and 16-bit ranges among all the bit-decomposition-based ones without requiring trusted setups. Moreover, to the best of our knowledge, it is the first configurable range proof that is adaptable to various scenarios with different specifications, where the configurability allows to trade off communication efficiency for computational efficiency. In addition, we offer a bonus feature: FlashSwift supports the aggregation of multiple single proofs for efficiency improvement. Finally, we provide comprehensive performance benchmarks against the state-of-the-art ones to demonstrate its practicality.

Open access
Advanced Data Storage Technologies
Advanced Data Compression Techniques
Algorithms and Data Compression
Original source