Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,228 papersLast indexed Aug 16, 2026
Search papers

Paper index

4,228 results Ā· page 93 of 177

Clear filters
Jun 24, 2024Ā·Review of Law Sciences
0 cites
"Protecting digital assets: cybersecurity imperatives for uzbekistan’s crypto exchange ecosystem "

Said Gulyamov, Исламбек Š ŃƒŃŃ‚амбеков

Analyzing the complex cybersecurity landscape of Uzbekistan’s crypto exchanges, the article emphasizes the importance of developing and implementing cybersecurity policies and regulatory frameworks. The article identifies the most pressing and evolving digital threats and evaluates the effectiveness of advanced mitigation measures. Furthermore, it explores the transformative potential of innovative legal and technological tools, such as blockchain-based identity verification, zero-knowledge proofs, and secure multi-party computation. The article provides an in-depth analysis of the current legislation governing cybersecurity practices within Uzbekistan’s crypto ecosystem and offers insights into future development prospects. To provide a comprehensive analysis of the cybersecurity situation in the cryptocurrency exchange industry, an extensive review of academic publications, industry reports and official documents related to cybersecurity in the cryptocurrency market is used. In addition, the article includes case studies of known cybersecurity incidents related to cryptocurrency exchanges. By analyzing real-life examples, the researchers aim to provide a more detailed understanding of the cybersecurity challenges faced by cryptocurrency exchanges and the effectiveness of various mitigation measures. Ultimately, the article presents practical recommendations for creating a secure, trustworthy, and innovation-driven environment for cryptocurrency users in Uzbekistan.

Open access
Security, Politics, and Digital Transformation
Digital Transformation in Law
Cybercrime and Law Enforcement Studies
Original source
Jun 24, 2024
1 cites
Detection of Anomalous e2e Encrypted Function Invocation in FaaS using Zero-Knowledge Proofs

Davide Andreotti, Giacomo Verticale

Function-as-a-Service providers manage security devices that are shared among multiple tenants. It is undesirable to give them access to cleartext HTTP requests to perform tasks such as traffic inspection. The recent Zero-Knowledge Middlebox (ZKMB) can be used to enforce network policies on TLS traffic without revealing any information on the content to the policy verifier. In this paper, we describe a ZKMB implementation and a policy designed to check whether the HTTPS function invocations by the clients follow a legitimate pattern. We also present and compare two strategies to distribute allowed patterns, introducing a Moving-Target Defense approach for the function URI randomization, which shows a good tradeoff between detection effectiveness and confidentiality. Performance assessment in our prototype implementation shows that the ZK algorithms are not yet suitable for real-time execution, but current research interest in this technology is expected to narrow this gap.

Open access
Cryptographic Implementations and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Jun 23, 2024
7 cites
MSMAC: Accelerating Multi-Scalar Multiplication for Zero-Knowledge Proof

Pengcheng Qiu, Guiming Wu, Tingqiang Chu, Changzheng Wei Ā· 8 authors

Multi-scalar multiplication (MSM) is the most computation-intensive part in proof generation of Zero-knowledge proof (ZKP). In this paper, we propose MSMAC, an FPGA accelerator for large-scale MSM. MSMAC adopts a specially designed Instruction Set Architecture (ISA) for MSM and optimizes pipelined Point Addition Unit (PAU) with hybrid Karatsuba multiplier. Moreover, a runtime system is proposed to split MSM tasks with the optimal sub-task size and orchestrate execution of Processing Elements (PEs). Experimental results show that MSMAC achieves up to 328X and 1.96X speedups compared to the state-of-the-art implementation on CPU (one core) and GPU, respectively, outperforming the state-of-the-art ASIC accelerator by 1.79X. On 4 FPGAs, MSMAC performs 1,261X faster than a single CPU core.

Open access
Cryptography and Residue Arithmetic
Cryptography and Data Security
Numerical Methods and Algorithms
Original source
Jun 22, 2024Ā·Revista Electronica de Veterinaria
0 cites
Assessing Absolute Distributed Data Scheduling Functions in Global Grid-Based Cloud Computing

Preeta Rajiv Sivaraman

In global grid-based cloud computing settings, performance optimization depends on effective data scheduling. The usefulness of the absolute distributed data scheduling function in controlling resource allocation, load balancing, and data dissemination across heterogeneous cloud infrastructures is assessed in this study. By taking into account variables including data locality, processing capacity, and network latency, we evaluate the function's capacity to increase system throughput while reducing scheduling overhead. Simulations that compare to current scheduling models show gains in fault tolerance, scalability, and efficiency. High-performance cloud computing is advanced by the findings, which offer insights on optimizing distributed scheduling systems. Cloud security is crucial for attracting customers and protecting data privacy. Online attackers disrupt cloud services, leading to financial growth for cloud-based organizations. Various methodologies are reviewed to develop strong security mechanisms for cloud computing, but machine learning is not enough. This research focuses on high-level technologies like Block chain and Quantum computing with Machine Learning (ML) concepts and algorithm conceptions like deep neural networks and quantum neural networks. These models reduce attacks and increase user trust, benefiting cloud service providers. The research aims to eradicate issues and promote end-to-end protection and secrecy in the cloud environment. Cloud computing is an on-demand technology that provides various services like vast computing power, unlimited storage, and on-demand web services over the internet without the need for internal infrastructure. This research focuses on data security and privacy of cloud customers using various experiments. Cyber-attacks can be Denial of Services (DoS), Distributed Denial of Services (DDoS), Man In The Middle (MITM), and malware attacks. To protect the cloud system from cyber-attacks, deep learning is used to train an intelligent honeynet system that not only protects the system from DDoS attacks but also redirects attacks towards another direction. Another approach is the Quantum Neural Network (QNN) approach, which helps identify attack patterns and categorizes them into different classes of DoS/DDoS attacks. The QNN training process addresses slowing down of the cloud system and allows valid cloud customers to access their private data in cloud storage. Another approach is Zero Knowledge Proof (ZKP) technology, which verifies the authenticity of cloud users by polarizing photons at a specific angle. This verifier model allows cloud customers to access sensitive data and only cloud services provided by the cloud service provider. Blockchain, a powerful security framework, is used to address increasing security vulnerabilities. The Quantum-Blockchain framework incorporates the quantum superimposition principle to prevent data tampering, ensuring data privacy and data security. This research aims to address intrusion detection and data storage security challenges in the cloud computing environment using collaborative efforts from Machine Learning and advanced technologies like Quantum Computing and Blockchain. The cloud manifesto and security alliance need to be standardized to ensure privacy and security. Current research is limited due to lack of security and privacy standards between cloud vendors and users. Future studies should focus on advanced technologies like hybrid cloud, artificial intelligence, quantum computing, data mining, machine learning, big data, and cryptography to enhance security and prevent cyber-attacks.

Open access
Distributed and Parallel Computing Systems
Cloud Computing and Resource Management
Original source
Jun 22, 2024Ā·Journal of Network and Computer Applications
6 cites
An agnostic and secure interoperability protocol for seamless asset movement

El-hacen Diallo, Mohameden Dieye, Omar Dib, Pierre Valiorgue

As blockchain technology continues to evolve, it has fostered an extensive ecosystem of applications and platforms. This dynamic landscape is characterized by a myriad of innovative solutions, ranging from decentralized finance and supply chain management to digital identity and voting systems, each contributing to the ongoing advancement and adoption of blockchain technology across various sectors. Achieving interoperability among these applications and platforms poses a significant challenge due to their use of distinct protocols, and remains a bottleneck hindering the widespread adoption of blockchain technologies. Addressing this challenge requires designing a universal interoperability protocol while ensuring compliance with the security and privacy constraints specific to each blockchain, thus adding complexity. We propose an agnostic interoperability protocol designed for seamless asset movement across independent private blockchain networks, regardless of their individual protocols. This protocol leverages incentive-driven smart contract and Zero-Knowledge Proofs to establish a decentralized, secure, and privacy-focused framework for interoperability. We conduct a security analysis using game theory and provide both theoretical and empirical evaluations of the protocol end-to-end delay. Through a comprehensive use case, we demonstrate the secure deployment of the proposed protocol for asset movement between two private blockchains. We also discuss the trade-offs between cost and delay in cross-blockchain transactions. Furthermore, a comparative analysis with existing interoperability schemes showcases the proposed interoperability scheme superiority in terms of robustness, privacy preservation, and verifiability.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Auction Theory and Applications
Original source
Jun 21, 2024Ā·IEEE Transactions on Services Computing
17 cites
EDCOMA: Enabling Efficient Double Compressed Auditing for Blockchain-Based Decentralized Storage

Haiyang Yu, Yurun Chen, Zhen Yang, Yuwen Chen Ā· 5 authors

Blockchain technology, known for its decentralized and immutable nature, serves as the foundation for various applications. As a prominent application of blockchain, decentralized storage is powered by blockchain technology and is expected to provide a reliable and cost-effective alternative to traditional centralized storage. A major challenge in blockchain-powered decentralized storage is how to guarantee the quality of storage services in decentralized storage nodes (DSNs). Storage auditing can ensure the integrity and security of the stored data. Unfortunately, it incurs additional computational costs for data owners and extra storage overheads for DSNs, which thereby cannot be directly applied to decentralized storage networks consisting of nodes with various computation and storage capacity. In this article, we overcome these problems and minimize additional burdens in storage auditing. We propose EDCOMA, a computation and storage efficient auditing scheme for blockchain-based decentralized storage, in which a double compression method is designed to compress data authenticators using both data and polynomial commitment. To prevent replay attacks on double compression launched by DSNs, we introduce zero knowledge proof and design a compression arithmetic circuit to guarantee the execution of compression operations in DSNs. We analyze the security of EDCOMA under the random oracle model and conduct extensive experiments to evaluate the performance of EDCOMA. Experimental results affirm that EDCOMA outperforms state-of-the-art approaches in both computational and storage efficiency.

Open access
Blockchain Technology Applications and Security
Caching and Content Delivery
Cloud Computing and Resource Management
Original source
Jun 20, 2024Ā·Tsinghua Science & Technology
7 cites
ZKP Protocols for Usowan, Herugolf, and Five Cells

Daiki Miyahara, LƩo Robert, Pascal Lafourcade, Takaaki Mizuki

A Zero-Knowledge Proof (ZKP) protocol allows a participant to prove the knowledge of some secret without revealing any information about it. While such protocols are typically executed by computers, there exists a line of research proposing physical instances of ZKP protocols. Up to now, many card-based ZKP protocols for pen-and-pencil puzzles, like Sudoku, have been designed. Those games, mostly edited by Nikoli, have simple rules, yet designing them in card-based ZKP protocols is non-trivial. In this work, we propose a card-based ZKP protocol for Usowan, a Nikoli game. In Usowan, for each room of a puzzle instance, there is exactly one piece of false information. The goal of the game is to detect this wrong data amongst the correct data and also to satisfy the other rules. Designing a card-based ZKP protocol to deal with the property of detecting a liar has never been done. In some sense, we propose a physical ZKP for hiding of a liar. This work extends a previous paper appearing in Ref. [1]. In this extension, we propose two other protocols, for Herugolf and Five Cells. The puzzles are specifically chosen because each of those three puzzles shares a common constraint, connectivity. However, showing the connected configuration cannot be done with generic approach and brings new construction to the existing connectivity ZKP protocol. Indeed, in Herugolf, the connectivity is handled with a given length of cell which is decremental (i.e., the length of each connected cell decreases by one at each step). For Five Cells, there is an additional step in the setup allowing to encode all the information needed to ensure a valid ZKP protocol.

Open access
graph theory and CDMA systems
Graph Labeling and Dimension Problems
Advanced Steganography and Watermarking Techniques
Original source
Jun 20, 2024Ā·Future Generation Computer Systems
12 cites
SeCTIS: A framework to Secure CTI Sharing

Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A. Ā· 7 authors

The rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof.

Open access
3 source records
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jun 17, 2024Ā·arXiv (Cornell University)
0 cites
Blockchain for Academic Integrity: Developing the Blockchain Academic Credential Interoperability Protocol (BACIP)

Juan Alamrio Berrios Moya

This research introduces the Blockchain Academic Credential Interoperability Protocol (BACIP), designed to significantly enhance the security, privacy, and interoperability of verifying academic credentials globally, addressing the widespread issue of academic fraud. BACIP integrates dual blockchain architecture, smart contracts, and zero-knowledge proofs to offer a scalable and transparent framework aimed at reducing fraud and improving the mobility and opportunities for students and professionals worldwide. The research methodology adopts a mixed-methods approach, involving a rigorous review of pertinent literature and systematic integration of advanced technological components. This includes both qualitative and quantitative analyses that underpin the development of a universally compatible system. Preliminary evaluations suggest that BACIP could enhance verification efficiency and bolster security against tampering and unauthorized access. While the theoretical framework and practical implementations have laid a solid foundation, the protocol's real-world efficacy awaits empirical validation in a production environment. Future research will focus on deploying a prototype, establishing robust validation policies, and defining precise testing parameters. This critical phase is indispensable for a thorough assessment of BACIP's operational robustness and its compliance with international educational standards. This work contributes significantly to the academic field by proposing a robust model for managing and safeguarding academic credentials, thus laying a strong foundation for further innovation in credential verification using blockchain technology.

Open access
2 source records
cs.CR
cs.CY
Cloud Data Security Solutions
Original source
Jun 11, 2024Ā·arXiv (Cornell University)
0 cites
Pseudo-Entanglement is Necessary for EFI Pairs

Manuel Goulão, David Elkouss

Regarding minimal assumptions, most of classical cryptography is known to depend on the existence of One-Way Functions (OWFs). However, recent evidence has shown that this is not the case when considering quantum resources. Besides the well known unconditional security of Quantum Key Distribution, it is now known that computational cryptography may be built on weaker primitives than OWFs, e.g., pseudo-random states [JLS18], one-way state generators [MY23], or EFI pairs of states [BCQ23]. We consider a new quantum resource, pseudo-entanglement, and show that the existence of EFI pairs, one of the current main candidates for the weakest computational assumption for cryptography (necessary for commitments, oblivious transfer, secure multi-party computation, computational zero-knowledge proofs), implies the existence of pseudo-entanglement, as defined by [ABF+24, ABV23] under some reasonable adaptations. We prove this by constructing a new family of pseudo-entangled quantum states given only EFI pairs. Our result has important implications for the field of computational cryptography. It shows that if pseudo-entanglement does not exist, then most of cryptography cannot exist either. Moreover, it establishes pseudo-entanglement as a new minimal assumption for most of computational cryptography, which may pave the way for the unification of other assumptions into a single primitive. Finally, pseudo-entanglement connects physical phenomena and efficient computation, thus, our result strengthens the connection between cryptography and the physical world.

Open access
2 source records
quant-ph
cs.CR
Magnetic Properties and Applications
Original source
Jun 10, 2024Ā·Elmi ʏsərlər
0 cites
ÜSTÜN MʏXFİLİYİN QORUNMASI TEXNİKALARI İLʏ AĞILLI MÜQAVİLʏLʏRDʏ MʏLUMAT MʏXFİLİYİNİN TʏKMİLLĘÅžDİRİLMʏSİ

Abdulhüseyn Vəfadar Ağayev

This research paper delves into the imperative domain of bolstering data confidentiality within smart contracts through the integration of advanced privacy-preserving methodologies. Smart contracts, pivotal components of blockchain technology, execute self-executing contracts with predefined conditions and are increasingly utilized across various sectors, necessitating stringent data protection measures. The paper addresses the pressing need for fortified data privacy within smart contracts and investigates cutting-edge approaches to mitigate privacy challenges. Two focal techniques under scrutiny are zero-knowledge proofs (SBƇs) and homomorphic encryption. SBƇs facilitate the validation of computations without revealing sensitive data, enabling parties to verify transaction authenticity without disclosing the underlying information. Meanwhile, homomorphic encryption permits computations on encrypted data, preserving confidentiality by allowing operations on encrypted information without the need for decryption. By analyzing these advanced privacy-preserving techniques, this study aims to address the vulnerabilities in data confidentiality present in smart contracts. Its findings hold significant promise in fortifying the security and confidentiality of transactions, thus contributing substantially to the evolution of secure blockchain technology. This research underscores the pivotal role of innovative privacy-enhancing mechanisms in safeguarding sensitive data within smart contracts, ensuring the trust and integrity essential for their widespread adoption.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Jun 10, 2024Ā·Proceedings of the 56th Annual ACM Symposium on Theory of Computing
8 cites
One-Way Functions and Zero Knowledge

Shuichi Hirahara, Mikito Nanashima

The fundamental theorem of Goldreich, Micali, and Wigderson (J. ACM 1991) shows that the existence of a one-way function is sufficient for constructing computational zero knowledge (CZK) proofs for all languages in NP. We prove its converse, thereby establishing characterizations of one-way functions based on the worst-case complexities of zero knowledge. Specifically, we prove that the following are equivalent: - A one-way function exists. - NP āŠ† CZK and NP is hard in the worst case. - CZK is hard in the worst case and the problem GapMCSP of approximating circuit complexity is in CZK. The characterization above also holds for statistical and computational zero-knowledge argument systems. We further extend this characterization to a proof system with knowledge complexity O(logn). In particular, we show that the existence of a one-way function is characterized by the worst-case hardness of CZK if GapMCSP has a proof system with knowledge complexity O(logn). We complement this result by showing that NP admits an interactive proof system with knowledge complexity ω(logn) under the existence of an exponentially hard auxiliary-input one-way function (which is a weaker primitive than an exponentially hard one-way function). We also characterize the existence of a robustly-often nonuniformly computable one-way function by the nondeterministic hardness of CZK under the weak assumption that PSPACE ⊈AM. We present two applications of our results. First, we simplify the proof of the recent characterization of a one-way function by NP-hardness of a meta-computational problem and the worst-case hardness of NP given by Hirahara (STOC’23). Second, we show that if NP has a laconic zero-knowledge argument system, then there exists a public-key encryption scheme whose security can be based on the worst-case hardness of NP. This improves previous results which assume the existence of an indistinguishable obfuscation.

Open access
2 source records
Cryptography and Data Security
Complexity and Algorithms in Graphs
Privacy-Preserving Technologies in Data
Original source
Jun 10, 2024·Dipòsit Digital de la Universitat de Barcelona (Universitat de Barcelona)
0 cites
A formal introduction to zero-knowledge proofs

Peso Vilella, Antonio

Treballs Finals de Grau de MatemĆ tiques, Facultat de MatemĆ tiques, Universitat de Barcelona, Any: 2024, Director: Bruno Mazorra i Luis Victor Dieulefait

Open access
Logic, programming, and type systems
Computability, Logic, AI Algorithms
Advanced Algebra and Logic
Original source
Jun 10, 2024
11 cites
Batch Proofs Are Statistically Hiding

Nir Bitansky, Chethan Kamath, Omer Paneth, Ron D. Rothblum Ā· 5 authors

Batch proofs are proof systems that convince a verifier that x1,…,xt ∈ L, for some NP language L, with communication that is much shorter than sending the t witnesses. In the case of statistical soundness (where the cheating prover is unbounded but the honest prover is efficient given the witnesses), interactive batch proofs are known for UP, the class of unique-witness NP languages. In the case of computational soundness (where both honest and dishonest provers are efficient), non-interactive solutions are now known for all of NP, assuming standard lattice or group assumptions. We exhibit the first negative results regarding the existence of batch proofs and arguments: - Statistically sound batch proofs for L imply that L has a statistically witness indistinguishable (SWI) proof, with inverse polynomial SWI error, and a non-uniform honest prover. The implication is unconditional for obtaining honest-verifier SWI or for obtaining full-fledged SWI from public-coin protocols, whereas for private-coin protocols full-fledged SWI is obtained assuming one-way functions. This poses a barrier for achieving batch proofs beyond UP (where witness indistinguishability is trivial). In particular, assuming that NP does not have SWI proofs, batch proofs for all of NP do not exist. - Computationally sound batch proofs (a.k.a batch arguments or BARGs) for NP, together with one-way functions, imply statistical zero-knowledge (SZK) arguments for NP with roughly the same number of rounds, an inverse polynomial zero-knowledge error, and non-uniform honest prover. Thus, constant-round interactive BARGs from one-way functions would yield constant-round SZK arguments from one-way functions. This would be surprising as SZK arguments are currently only known assuming constant-round statistically-hiding commitments. We further prove new positive implications of non-interactive batch arguments to non-interactive zero knowledge arguments (with explicit uniform prover and verifier): - Non-interactive BARGs for NP, together with one-way functions, imply non-interactive computational zero-knowledge arguments for NP. Assuming also dual-mode commitments, the zero knowledge can be made statistical. Both our negative and positive results stem from a new framework showing how to transform a batch protocol for a language L into an SWI protocol for L.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Privacy-Preserving Technologies in Data
Original source
Jun 10, 2024Ā·Proceedings of the 56th Annual ACM Symposium on Theory of Computing
15 cites
A New Approach for Non-Interactive Zero-Knowledge from Learning with Errors

Brent Waters

We put forward a new approach for achieving non-interactive zero-knowledge proofs (NIKZs) from the learning with errors (LWE) assumption (with subexponential modulus to noise ratio). We provide a LWE-based construction of a hidden bits generator that gives rise to a NIZK via the celebrated hidden bits paradigm. A notable feature of our construction is its simplicity. Our construction employs lattice trapdoors, but beyond that uses only simple operations. Unlike prior solutions, we do not rely on a correlation intractability argument nor do we utilize fully homomorphic encryption techniques. Our solution provides a new methodology that adds to the diversity of techniques for solving this fundamental problem.

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Complexity and Algorithms in Graphs
Original source
Jun 8, 2024Ā·Applied Sciences
11 cites
Efficient and Secure EMR Storage and Sharing Scheme Based on Hyperledger Fabric and IPFS

Jinxi Guo, Kui Zhao, Zhiwei Liang, Kai Min

This study examines the issues of privacy protection, data security, and query efficiency in blockchain-based electronic medical record (EMR) sharing. It proposes a secure storage and sharing scheme for EMR based on Hyperledger Fabric and the InterPlanetary File System (IPFS). To mitigate the privacy risks of data mining that could reveal patient identities, we establish an attribution channel in Hyperledger Fabric to store EMR ownership information and a data channel to store the storage location, digest, and usage records of medical data. Encrypted medical data are stored in the IPFS. To improve query efficiency in the blockchain, we integrate queryable medical data attributes into a composite key for conditional queries, avoiding complex data filtering processes. Additionally, we use a zero-knowledge proof combined with smart contracts for decentralized identity verification, eliminating reliance on third-party centralized verification services and enhancing system security. We also integrate AES and proxy re-encryption techniques to ensure data security during sharing. This scheme provides a more secure, efficient, and privacy-preserving approach for EMR systems, with significant practical implications and broad application potential.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Jun 3, 2024
0 cites
Poster: Privacy in Distributed Mobile Networks

俔一 馬堓, Xingjun Wang

In order to achieve zero-knowledge proof (ZKP) in distributed mobile scenarios, we propose a two-stage multi-prover ZKP framework. Our method utilizes secure multi-party computation (MPC), which has advantages such as flexible adaptation, stable performance, and fewer restrictions compared to existing solutions. In addition, based on the properties of cyclic groups, we optimize secure multi-party summation, improving the balance between security and efficiency, as well as transferability of the algorithm.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Jun 3, 2024Ā·arXiv (Cornell University)
2 cites
No Vandalism: Privacy-Preserving and Byzantine-Robust Federated Learning

Zhibo Xing, Zijian Zhang, Ziang Zhang, Jiamou Liu Ā· 6 authors

Federated learning allows several clients to train one machine learning model jointly without sharing private data, providing privacy protection. However, traditional federated learning is vulnerable to poisoning attacks, which can not only decrease the model performance, but also implant malicious backdoors. In addition, direct submission of local model parameters can also lead to the privacy leakage of the training dataset. In this paper, we aim to build a privacy-preserving and Byzantine-robust federated learning scheme to provide an environment with no vandalism (NoV) against attacks from malicious participants. Specifically, we construct a model filter for poisoned local models, protecting the global model from data and model poisoning attacks. This model filter combines zero-knowledge proofs to provide further privacy protection. Then, we adopt secret sharing to provide verifiable secure aggregation, removing malicious clients that disrupting the aggregation process. Our formal analysis proves that NoV can protect data privacy and weed out Byzantine attackers. Our experiments illustrate that NoV can effectively address data and model poisoning attacks, including PGD, and outperforms other related schemes.

Open access
2 source records
cs.CR
cs.DC
cs.LG
Original source
Jun 2, 2024Ā·Cybersecurity
7 cites
Atomic cross-chain swap based on private key exchange

Zeshuo Zhu, Rui Zhang, Yang Tao

Abstract Atomic Cross-Chain Swap (ACCS) is one important topic in cryptocurrency, where users can securely and trustlessly exchange assets between two different blockchains. However, most known ACCS schemes assume specific scripting functionalities of the underlying blockchains, such as Hash Time Locked Contracts (HTLC). In addition, these schemes are typically only applicable to certain digital signature schemes, like Schnorr or Elliptic Curve Digital Signature Algorithm (ECDSA) signatures. In this paper, we propose a generic ACCS scheme, independent from the underlying blockchains. To the best of our knowledge, this is the first solution of this kind. Our results are as follows. First, we define a formal system model of ACCS. Next, we present a generic ACCS scheme meets our model. This scheme admits atomicity in cross-chain swaps without the need for a Trusted Third Party (TTP) and protects users’ privacy. Finally, by using the Non-Interactive Zero-Knowledge (NIZK) proof protocol as a tool, we instantiate our generic scheme for Elliptic Curve Discrete Logarithm Problem-based (ECDLP-based) signatures. In addition, we implement our scheme, and the experimental results show that our protocol outperforms the existing ACCS schemes, such as the HTLC-based schemes.

Open access
Security in Wireless Sensor Networks
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jun 1, 2024Ā·Bezopasnost informacionnyh tehnology
0 cites
GOST 34.11-2018 Analysis in The Context of Zero-Knowledge Proofs

Vladlen D. Afonin, Sergey Zapechnikov, Igor A. Prostov

Zero-knowledge proofs are being increasingly applied to a wide range of tasks in modern distributed information systems. Of particular interest are such areas of activity as digital asset management systems, anonymous electronic voting systems, and anonymous credentials. Nevertheless, within the framework of the desire of Russian developers to localize the developed products, there is a question of compliance of the used algorithms with the legislative framework of the Russian Federation, which obliges developers to use local cryptographic standards. As our analysis shows, insufficient attention has been paid in the literature to the applicability of these standards to the scenario of use in zero-knowledge proof systems. In particular, the complexity of proof generation, parameters of arithmetic schemes are not analyzed, there is no comparison of computational complexity and cryptographic properties with foreign alternatives. In this paper we consider in detail the peculiarities of implementation of the arithmetic scheme for the function of GOST 34.11-2018 in the most widespread language for arithmetic circuit programming Circom. The developed program code is open and available for use and modification. The characteristics of the scheme, compilation and generation times are analyzed. The obtained results were compared with other popular hash functions: the cryptographic hash function SHA256 included in the standard language library, and the hash function Poseidon, specialized and optimized for use in zero-knowledge proof systems. The results show that while the use of the Russian hash function is possible, it is not desirable in applications that do not require the use of local cryptographic standards, due to the greater time complexity of witness generation and consequently proof generation. Recommendations on usage scenarios are given and further research directions are suggested.

Open access
Numerical Methods and Algorithms
Historical Astronomy and Related Studies
Parallel Computing and Optimization Techniques
Original source
May 29, 2024Ā·International journal of Computer Networks & Communications
2 cites
Blockchain Enforced Attribute based Access Control with ZKP for Healthcare Service

Dongju Lee, Hyunsung Kim

The relationship between doctors and patients is reinforced through the expanded communication channels provided by remote healthcare services, resulting in heightened patient satisfaction and loyalty. Nonetheless, the growth of these services is hampered by security and privacy challenges they confront. Additionally, patient electronic health records (EHR) information is dispersed across multiple hospitals in different formats, undermining data sovereignty. It allows any service to assert authority over their EHR, effectively controlling its usage. This paper proposes a blockchain enforced attribute-based access control in healthcare service. To enhance the privacy and data-sovereignty, the proposed system employs attribute-based access control, zero-knowledge proof (ZKP) and blockchain. The role of data within our system is pivotal in defining attributes. These attributes, in turn, form the fundamental basis for access control criteria. Blockchain is used to keep hospital information in public chain but EHR related data in private chain. Furthermore, EHR provides access control by using the attributed based cryptosystem before they are stored in the blockchain. Analysis shows that the proposed system provides data sovereignty with privacy provision based on the attributed based access control.

Open access
Access Control and Trust
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
May 29, 2024Ā·Journal of Information Security and Applications
2 cites
ZeroMT: Towards Multi-Transfer transactions with privacy for account-based blockchain

Emanuele Scala, Changyu Dong, Flavio Corradini, Leonardo Mostarda

The public blockchain lacks data confidentiality. Although a level of anonymity seems guaranteed, it is still possible to link transactions and disclose related information. A solution to the privacy problem is to use cryptography in transactions, however this can lead to increased costs and slowdown in network throughput. Recent works experiment with advanced cryptography, in particular Zero-Knowledge proofs (ZK-proofs) can be supplied within a transaction to prove its validity, without revealing sensitive information. We analyze solutions that adopt ZK-proofs, such as Confidential Transactions (CTs). Several challenges emerge depending on both the zero-knowledge system and the balance model considered (UTXO, hybrid or account model). For ZK-proofs, systems that do not introduce additional trust are required. On the other hand, the account model is the most flexible for addressing security challenges. Moreover, CTs do not fully exploit the potential of ZK-proofs, since each transaction comes with one or more ZK-proof for a single transfer. Within this paper, we present ZeroMT, a novel multi-transfer private payment scheme for account-based blockchains. Drawing inspiration from Zether, our approach extends their work to develop a payment model that supports multiple payees within a single transaction. This also benefits scalability: ZeroMT enriches the CTs with the aggregation property, i.e., the batch verification of multiple transfers from a single and aggregate proof. We show that in our extended model the overdraft-safety and privacy security properties still hold. We provide an implementation and evaluation of ZeroMT, which shows the benefits of aggregating multiple transfers.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
May 23, 2024Ā·Scientific Reports
42 cites
Integrating blockchain and ZK-ROLLUP for efficient healthcare data privacy protection system via IPFS

Shengchen Ma, Xing Zhang

With the rapid development of modern medical technology and the dramatic increase in the amount of medical data, traditional centralized medical information management is facing many challenges. In recent years blockchain, which is a peer-to-peer distributed database, has been increasingly accepted and adopted by different industries and use cases. Key areas of healthcare blockchain applications include electronic medical record (EMR) management, medical device supply chain management, remote condition monitoring, insurance claims and personal health data (PHD) management, among others. Even so, there are a number of challenges in applying blockchain concepts to healthcare and its data, including interoperability, data security privacy, scalability, TPS and so on. While these challenges may hinder the development of blockchain in healthcare scenarios, they can be improved with existing technologies In this paper, we propose a blockchain-based healthcare operations management framework that is combined with the Interplanetary File System (IPFS) for managing EMRs, protects data privacy through a distributed approach while ensuring that this medical ledger is tamper-proof. Doctors act as full nodes, patients can participate in network maintenance either as light nodes or as full nodes, and the hospital acts as the endpoint database of data, i.e., the IPFS node, which saves the arithmetic power of nodes and allows the data stored in the hospitals and departments to be shared with the other organizations that have uploaded the data. Therefore, the integration of blockchain and zero-knowledge proof proposed in this paper helps to protect data privacy and is efficient, better scalable, and more throughput.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source