Lakshmi Rama Kiran Pasumarthy, Hisham Ali, William J. Buchanan, Jawad Ahmad · 7 authors
There is an increasing need to share threat information for the prevention of widespread cyber-attacks. While threat-related information sharing can be conducted through traditional information exchange methods, such as email communications etc., these methods are often weak in terms of their trustworthiness and privacy. Additionally, the absence of a trust infrastructure between different information-sharing domains also poses significant challenges. These challenges include redactment of information, the Right-to-be-forgotten, and access control to the information-sharing elements. These access issues could be related to time bounds, the trusted deletion of data, and the location of accesses. This paper presents an abstraction of a trusted information-sharing process which integrates Attribute-Based Encryption (ABE), Homomorphic Encryption (HE) and Zero Knowledge Proof (ZKP) integrated into a permissioned ledger, specifically Hyperledger Fabric (HLF). It then provides a protocol exchange between two threat-sharing agents that share encrypted messages through a trusted channel. This trusted channel can only be accessed by those trusted in the sharing and could be enabled for each data-sharing element or set up for long-term sharing.
Bo Zhang, Tao Zhang, Zesheng Xi, Ping Chen · 6 authors
With the rapid development of the Internet of Things (IoT), ensuring secure communication between devices has become a crucial challenge. This paper proposes a novel secure communication solution by extracting wireless channel state information (CSI) features from IoT devices to generate a device identity. Due to the instability of the wireless channel, the CSI features are fuzzy and time-varying; thus, we a employ locally sensitive hashing (LSH) algorithm to ensure the stability of the generated identity in a dynamically changing wireless channel environment. Furthermore, zero-knowledge proofs are utilized to guarantee the authenticity and effectiveness of the generated identity. Finally, the identity generated using the aforementioned approach is integrated into an IBE communication scheme, which involves the fuzzy extraction of channel state information from IoT devices, stable identity extraction for fuzzy IoT devices using LSH, and the use of zero-knowledge proofs to ensure the authenticity of the generated identity. This identity is then employed as the identity information in identity-based encryption (IBE), constructing the device’s public key for achieving confidential communication between devices.
Sana Hafeez, Runze Cheng, Lina Mohjazi, Yao Sun · 5 authors
Unmanned Aerial Vehicles (UAVs) have significant potential for agile communication and relief coordination in post-disaster scenarios, especially when conventional ground infrastructure is compromised. However, effectively coordinating and securing swarms of heterogeneous UAVs from multiple service providers presents critical challenges related to privacy, scalability, lightweight consensus protocols, and cybersecurity resilience. This study proposes a blockchain-enabled UAV coordination framework that leverages consensus mechanisms, smart contracts, and cryptographic techniques to address these challenges. First, a consortium blockchain architecture is introduced, integrating Zero-Knowledge Proofs (ZKPs) to enable privacy-preserving, multi-agency coordination while ensuring access control and data security. Second, a hybrid Delegated Proof-of-Stake–Practical Byzantine Fault Tolerance (DPoS-PBFT) consensus protocol is developed to optimise security, efficiency, and resilience against node failures in resource-constrained UAV networks. Third, a decentralized flocking algorithm is proposed to enable adaptive and autonomous UAV cluster operations under dynamically changing connectivity conditions, ensuring seamless disaster relief functions. Comprehensive simulations show that the proposed system scales efficiently to 500 UAV nodes while maintaining high throughput and low latency, with only a 50-ms increase in latency from 10 to 500 nodes. The framework demonstrates strong cyber resilience, remaining robust under denial-of-service (DoS), spoofing, and tampering attacks. Furthermore, communication latencies remain under 10 milliseconds, with median values of approximately 2–3 ms, achieved through self-optimizing network intelligence. The results validate the proposed system as a secure, scalable, and high-performance solution for UAV-enabled disaster response, ensuring reliable emergency communication and efficient resource allocation in critical environments.
Статья посвящена актуальной проблеме обеспечения конфиденциальности в системах распределенного реестра. Рассматривается прикладная задача обеспечения конфиденциальности данных при операциях с цифровыми финансовыми активами. Представлено сравнение различных методов обеспечения конфиденциальности, включая перемешивающие сети, кольцевые подписи и оффчейн-протоколы. Отмечено, что эти методы не достигают достаточного уровня децентрализации, что является важным аспектом для систем распределенного реестра. Для одновременного обеспечения свойств децентрализации и конфиденциальности информации используются методы доказательства с нулевым разглашением, включая методы компактных неинтерактивных доказательств знания (SNARK). В статье приводится математическая модель систем доказательства SNARK, а также описаны подходы к их программной реализации. Приведены результаты экспериментов, направленные на сравнение производительности методов SNARK для решения прикладной задачи проведения операций с цифровыми финансовыми активами. Результаты эксперимента позволяют выделить дальнейшие возможности снижения времени генерации доказательства и сокращения его объема посредством использования пакетной верификации. Полученные результаты имеют практическую значимость для разработки систем распределенного реестра, требующих высокого уровня конфиденциальности и децентрализации.
Data provenance is critical for establishing the origin, authenticity, and integrity of data in distributed environments. Traditional provenance systems often face challenges such as tampering, lack of transparency, and centralized trust issues. Blockchain technology, with its immutable ledger and decentralized consensus mechanisms, provides a promising solution to these challenges. This article explores blockchain-based cryptographic methods that enhance the security and reliability of data provenance systems. We discuss key cryptographic primitives such as digital signatures, hash chains, and zero-knowledge proofs integrated within blockchain frameworks to guarantee secure and verifiable provenance records. The study also highlights practical implementations and identifies open challenges for future research
Nowadays, the integration of blockchain technology with Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has drawn the researcher attention because it can provide key security auditing and transaction traceability in the context of data sharing. However, in a majority of existing blockchain-based CP-ABE schemes, private keys were still issued by one central authority that would lead to heavy computation, higher transaction costs, and restricted scalability within the decentralized system. To address these challenges, we present an enhancement approach towards utilizing distributed key management service (KMS) and zero-knowledge paradigms. In our improved novel blockchain system model, we define two types of blockchain nodes for the CP-ABE scheme through staking mechanism. Firstly, the proxy re-encryption nodes are introduced to offer secure multi-party management and distribution of the CP-ABE's master secret key, eliminating dependence on a central authority and producing proofs of re-encryption correctness. Secondly, the operator nodes can collect all transactional information in blockchain-based CP-ABE scheme and then send the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARKs) proofs to verify the batch’s integrity via smart contract. Subsequently, we employ the staking economic incentive model with reward determination and slashing in the decentralized blockchain system to ensure network security. Finally, simulation results validate the effectiveness of our proposed scheme in achieving secure and efficient data sharing. Even amidst the pressure of 100 simultaneous transactions, the average response time for a single node remains at an approximate 28 s. Additionally, there is a notable decrease in on-chain gas consumption, with a gas reduction exceeding 61%. Comparative analyses further indicate that our blockchain-based CP-ABE scheme, in conjunction with a decentralized KMS, offers a superior balance between computational efficiency and functional capability.
This thesis is the culmination of research conducted between 2019 and 2023. It is divided into three parts. Inthe first part, we explore algorithms related to the Covid-19 pandemic, such as Pool Testing, a well-establishedtechnique where samples from multiple patients are pooled for collective testing, allowing for cost reduction and time savings. We propose algorithms taking into account the a priori probabilities that individual tests are positive, which can be evaluated during a prior clinical examination of the patient. We also examine Pool Testingin emergency situations, where certain samples need to be analyzed according to some prescribed priority order. In both cases, we propose new algorithms and analyze them in detail. This section also deals with DNA privacy preservation in Covid-19 tests. In the second part, we present our results in experimental mathematics, where we have discovered several new conjectures on continued fractions through automated exploration. All those conjectures have been numerically tested to assess their plausibility. Finally, the third part of this thesis is devoted to various results in the field of computer security, such as a previously unknown attack on the Mathematica software, a new protection mechanism against counterfeit medication, and new observations on zero-knowledge proofs.
CBDCs are a digital form of fiat money. CBDCs raise a number of challenges in terms of payments’ privacy. CBDCs may be implemented in two models (wholesale and retail). CBDCs may be used on a cross-border basis, subject to the connectivity of the technology. Cross-border use of some countries’ CBDCs could even bring about, under certain conditions, a shift in geopolitical power, especially if challenger currencies were to eventually lead to a replacement of the USD as the global reserve currency. As regards the key question about the interoperability of CBDC systems with private payment networks, the answer relies on the choice of technology and the location of the CBDC’s ledger, that is within or outside of existing Central Bank clearing and payment systems. CBDCs could transform the way modern societies conduct payments and handle money. Possible challenges that CBDCs raise in connection to monetary policy and financial stability will likely be manageable. Any financial stability issues that remunerated CBDCs might raise, in the sense that they might be in competition with bank deposits, could arguably be dealt with by setting the interest rate that remunerated CBDCs might attract at a level that is not competitive with bank deposits. Similarly, CBDCs are not expected to raise issues with respect to monetary policy and money circulation since essentially CBDCs will act as a replacement of fiat money, albeit in a digital rather than physical form. CBDCs are going to be a completely different form of digital currency than cryptocurrencies, both in terms of technology and in the fact that there will be a centralized state issuer rather than a private one. They will not be volatile as cryptocurrencies, but whether they would be a stable store of value will depend on the state of foreign exchange (FX) markets and exchange rates set by those markets. Cybersecurity safeguards will prove indispensable to building the public’s trust in CBDCs; if money goes missing from the system due to a cyber-heist, then that would undermine consumer confidence in the CBDC system. Thus, strong cybersecurity safeguards will prove indispensable to building the public’s trust in CBDCs. CBDCs will have to be handled through a system that is not excessively energy hungry in contrast with cryptocurrency operations. CBDCs are meant to be inclusive, and not exclude the digitally handicapped part of the population. Cross-border use of CBDCs could herald a new era of seamless, faster, and cheaper cross-border payments. English property law has accommodated crypto assets as a distinct form of personal property; thus the right approach is that CBDCs is that CBDCs will readily be accommodated in English law as a digital version of fiat currency. Several major Central Banks around the world have announced plans to develop a Central Bank Digital Currency (CBDC). The development of CBDCs may be seen as an assertion of monetary sovereignty—perhaps the last chance to do so in the face of technological change—but also raises several socio-economic challenges. This article critically explores these issues, including the configuration of a CBDC system, depending on the level of involvement allowed for the commercial banking sector, with reference to the policy papers issued by global regulatory bodies (eg, the Bank for International Settlements (BIS) and International Monetary Fund (IMF)). It also touches on the utility of different technologies mooted by central banks and their impact on the preservation of consumer privacy. This article postulates that CBDCs, rather than merely heralding the return of the state in the realm of money and payments, constitute a final frontier in the field of digital money and digital payments.1 It is also arguable that any monetary policy and financial stability challenges that CBDCs might pose would be manageable through the appropriate use of interest rates and internally imposed caps on deposits and withdrawals. The digitization of international payments opens the window for uniformity of the means of exchange that may be used for international payments. The use of CBDCs on a cross-border basis is mostly an issue of technological connectivity, which is yet an unresolved, and difficult to resolve, matter. If connectivity is ensured, leading to widespread cross-border use of CBDCs, this could give rise to strong competition between countries to promote their own CBDCs and will signal a new era of faster and seamless cross-border payments. This could possibly lead to lower transaction costs for cross-border payments, which in turn would make migrant labour remittances to their home country much cheaper, adding serious social value to the cross-border use of CBDCs. Given that CBDCs will have an exchange rate of one equals one, vis-à-vis the underlying currencies adopting a foreign CBDC would be tantamount to currency substitution; in fact, several countries around the world have experimented with dollarization, namely the replacement of their local currency with the USD. The experiment was mostly carried out in countries with weak national currencies with mixed results, for example, in Zimbabwe and Venezuela the experiment resulted in relative price stability and ensuring control of rampant inflation, especially with regard to food. On the other hand, in other cases,2 the adoption of a foreign currency has led to further weakening of the exchange parity of the national currency reinforcing the cycle of instability for the local economy, since local savers rushed to turn their savings in local currency to the newly adopted foreign currency. At the same time, the use of national CBDCs on a cross-border basis opens a window of opportunity for emerging economies such as China to promote the use of their CBDCs in international payments. Such a development would arguably, in the long run, enable the currencies of those countries to challenge the USD or edge away the USD from its long-entrenched position as the global reserve currency, thus enabling countries issuing CBDCs that are used on a cross-border basis to mount a gradual assault on the USA’s global financial hegemony. Here it should be mentioned that China has expressed the ambition to replace the USD as a global reserve currency through the cross-border use of the digital Renminbi (RMB); an obstacle is that the currency is not freely convertible; either way, such a development could possibly lead to the radical transformation of current global monetary arrangements.3 The main part of this article is structured into four sections, in addition to this introduction and the conclusion. Section 2 provides a critical evaluation of the rationales for the development of CBDCs. Section 3 addresses the requirements and implications of the possible use of CBDCs on a cross-border basis, as well as the formidable obstacles that these would face. Section 4 covers some of the legal and economic aspects of CBDCs (including the impact of CBDCs on both financial stability and monetary policy) as well as the possible impact of remunerated (interest-bearing) CBDCs. Section 5 examines the key properties of different configurations of CBDC systems and discusses the ramifications of the different CBDC architectures and technology models that may be employed by central banks. Section 6 brings the different strands of the analysis contained within this article to a conclusion. This raises a question that seemed to have been settled by the fact that central banks normally exercise monetary policy through the balances of commercial banks, allowing thus the multiplication of private money in the economy. The idea of CBDCs constitutes a response to the recent trend of the increasing digitization of money and privatization of payments. Among the discussed benefits of CBDCs is better financial inclusion,4 especially in countries where it is expensive to have access to a commercial bank branch network, for example island states like The Bahamas5 and other states facing similar challenges in terms of logistics. It has to be noted here that some commentators are not convinced about the benefits of CBDCs, for example, the House of Lords issued a report on the Bank of England’s plans for a CBDC with the title CBDCs: A Solution in Search of a Problem?6 However, this may be unduly negative. Depending on the type of technology, central banks are likely to proceed with the development and/or the issuance and circulation of CBDCs, and technical solutions that can help with the preservation of privacy of citizens’ payment information.7 Notwithstanding, in a number of countries including Singapore,8 CBDCs have not progressed as fast as expected. The advent of digitization of money and payments has mostly been dominated by private sector operators and has given rise to a number of challenges for public policymakers, including identifying ways to secure universal and affordable access to private payment networks, and the protection of consumers from cryptocurrency scams. To these challenges, states have not reacted in expected ways, namely through the introduction of a heavier form of regulation of cryptocurrency markets and private payment system providers, but rather through the introduction of a competing form of digital currency and payment system. The key rationales for the introduction of CBDCs have been summarized by the Bank of International Settlements.9 These are payments finality, countering the market power of private providers of payment systems; making innovation work for all citizens and also to secure uninterrupted consumer access to payment systems.10 A number of other rationales are included in the European Central Bank’s paper on a digital Euro.11 These include the provision of a further boost for the digitization of the economy and to safeguard financial inclusion and to lower transaction costs, for example to access private payment systems.12 A final rationale includes the ambition to provide a stable digital currency to act as an anchor for the placement of citizens’ savings (eg, without having to pay access fees to use a digital payment system). The physical handling of money and the conduct of payments have drastically changed in the current era. Payments on the one hand have been fully digitized and dominated by private sector payment system providers like the Visa and MasterCard networks. These developments alongside the emerging challenge of cryptocurrencies and the distinct shortcomings of cryptocurrency markets (including grossly excessive volatility) have mounted a massive challenge with respect to citizens’ payments and money circulation, namely the tight control of monetary policy by the state. Another major challenge has been citizens’ access to digital payment systems. The weaknesses of cryptocurrency markets and obstacles (eg, transaction costs) to access to the wider public and obstacles placed on the access of wider public to private payment systems have amounted to a form of market failure. These market failures have necessitated the introduction of public regulation, and in the of such regulation, several states and central banks around the world have for the development of competing digital currencies and payment this by the state. The introduction of CBDCs will the about whether money is a public in the sense that a number of in the economy such as payments and financial should be in the public The and of international payments, for example, migrant remittances and international a window of opportunity for the possible cross-border use of CBDCs. Cross-border use of CBDCs could lead to a new era of seamless international payments. The in which and handle money and conduct payments has changed in The of the digitization of money and payments has a window of opportunity for the development of CBDCs for cross-border use in countries with a strong economy. China is the country that has so expressed an ambition for different countries to use its CBDC as a means of exchange in international payments, the to in international through the possible replacement of the USD as a global reserve currency by the digital in the or The for the development of cross-border CBDCs is connectivity in terms of technology between payments systems in different A further and challenge to energy and which also around system and of the adoption of a digital currency by a country other than the issuing countries adopting CBDC are the issuing interest rates and exchange rates exchange rates normally a in terms of international and thus have an impact on the issuing of payments, that is of and the use of CBDC with respect to the adopting international payments would lead to the by the adopting country of the interest and exchange rates policy by the issuing country given that exchange rates can the of and might in the adopting economic that is to the of their economy. On the other hand, the of a CBDC can benefits to the issuing country including increasing the of its national currency and leading to the of title between the issuing and adopting on the question of whether CBDCs will make cross-border payments and cheaper, much will depend on the central so that they the connectivity of their systems and of cross-border legal question in this would be whether both the issuing and the adopting and on would to cross-border of CBDCs. This question could be by at the of in private international law (eg, the with cross-border of digital and with reference to cross-border of digital The of the in this may depend on where the CBDC or where the central bank that the are CBDCs will a form of money, if they the of money, which to the The as a means of The as a store of The as a of The are the properties to money by central banks and international financial regulatory Given that CBDCs are likely to be as fiat money, albeit in a digital it is within the of the issuing state to CBDCs as legal CBDCs used by the public will the for the of money by the to money. CBDCs can as money which cryptocurrencies do if CBDCs are also as legal by certain this way they will also the requirements set out by the approach to the of state money. It should be noted here that cryptocurrencies do not into either CBDCs, will both the and of money. The idea of Central CBDC to be the answer of and central banks to the recent around money, payments and in CBDCs are digital form of fiat money. has been a of about CBDCs around the and papers by major central banks such as the the European Central the Bank of as well as those in and but there is the of CBDCs. The way to approach CBDCs is to as digital fiat money distinct from and thus states can CBDCs as their legal The main in this is that CBDCs may or a on commercial banks on the of of bank deposits in for savers to their money into CBDC that are central banks can a on the of CBDC that an can and banks in could the that an may at a in These would the of a of bank deposits. much will depend on whether CBDCs with interest rates at or at a level to with savings If interest is at the rate to remunerated CBDCs could be so that it not with commercial savings other this is CBDCs could lead to a of monetary that not that they would lead to an in interest The of digital has mounted a challenge to control of the money CBDCs raise the question of whether they would the of money in circulation, thus leading to inflation, this mostly to CBDCs, which could CBDCs will be than a or replacement of fiat money in circulation, it that they will lead to leading to inflation, or have an impact on the existing of money in circulation in the question is as to the of commercial banks and private payment systems in the use of CBDCs. As regards the question of whether the CBDC will be in the form of a or in the form of an of the central banks that they will be and will be used in a way, not on a technology like terms of the choice between an and a there is in of but it has been by an of that central banks can issue or CBDCs in if they have the to issue and in the of CBDCs, it should be that it would be difficult to payment and finality, in the of CBDCs in the of a centralized payment and even if the CBDC system is not on technology payment and are much in the of CBDCs. The of in this is to payment but that with serious in a market with payment it is to the of CBDCs will be for payments in the from the fact that they may be an for and central banks to their way into control of money and payments in an economy, and in the exercise of monetary CBDC systems could in be as or systems. A system would the involvement of the commercial banking sector with CBDC payments and the of CBDC A CBDC on the other hand would that CBDCs will be used for payments by and (eg, The involvement of the private banking sector would a number of with respect to regulatory especially as regards the question of which in the system is and the of such the CBDC system, which banks on their as a of it which is going to conduct these if CBDCs are in and by the it is to be to they the to the CBDC system, to out these the Bank of has plans for the development of a digital which will work as a Similarly, the European Central Bank to the development of the digital as a It should be noted that some CBDC systems may work under both that is by the central the Bank of has announced plans to develop a payments will be through a system on the basis of carried out through the the Bank of plans the possible use of the digital as a CBDC without the that it could be used as a Similarly, the not the of its digital this The choice of the CBDC will also the issue of with regulatory and they will impact the of the CBDCs. If commercial banks are part of the system, then it would be commercial banks which will out the and the and with regulatory to the different requirements to money and payments. On the other hand, if the is through a of private then it will be to to out regulatory if a a payment through their systems. if the CBDC is there have been that the could be by the public with the central However, such a development could impact commercial banking where the public their savings with commercial banks. since the is that CBDCs will be a central bank this approach be it would make central banks a of failure. terms of this would the and of on central banks CBDC of the challenges to CBDCs the protection of the privacy of citizens’ payments and connectivity with private sector systems. as to the question of the form of CBDCs, namely whether they are in the form of an or this on whether CBDCs will be through the of the private banking in which CBDCs will be used for the payments of private and the of an the same system would also the of systems payments and payment finality, making for CBDC Such a system should also a for the secure of payment from the different possibly by the use of digital The use of CBDCs in the form of a sense if they are as CBDCs. Another major challenge to the interoperability with private payment networks, for example, commercial bank The answer to this challenge may be in the form of an between the CBDC and the where central banks the balances with commercial banks. on it could be that CBDCs can be a way for the state to in terms of payments and money and payment systems to all as CBDCs can access to payment systems and financial to without bank as systems are not to use for CBDC and payments even systems can safeguard their and level of would make to to the privacy of citizens’ payments. The preservation of privacy on the type of technology which will be used for the and of CBDCs, for example use of central systems would all about citizens’ payments to the central bank and any state are technical solutions to secure the privacy of on systems such as at this it be noted that major central banks have that they will not use a system for their CBDCs. Another technical that would provide a for the preservation of payments privacy could be the system on digital used and by citizens and The on this is that could with the central a to also enable or to the to be to handle their payments in CBDCs on a fact, it would be difficult for a CBDC system to work without a system of On the question of whether CBDC systems will be or central banks to have the question that the system will be by the of technology for CBDCs. Given that CBDCs will be a digital form of the national currency, to the that systems on CBDC systems to may be a way to to for the national currency which could boost exchange CBDCs could be a possible for the use of in markets the market of the and is to be in an where private sector innovation the to will depend on the CBDCs will prove with the public at other will they be CBDCs may prove to be an public control to money and with possible benefits for national contrast to cryptocurrency the possible of on CBDC the that CBDCs can be used to the same to the of certain to use CBDCs for the of CBDCs will depend on citizens’ If CBDCs prove to be and a stable store of and through a payments system which is from it will not be difficult for to citizens’ especially if they are also used as legal The of to control the use of CBDCs in CBDCs into an form of state could that the introduction of CBDCs would lead to in for both the at and for the would use CBDCs. The of the CBDC the answer to the question whether the CBDC will be with the of the banking sector or will also prove critical in terms of citizens’ and To citizens’ this will that the CBDC system would have a and that for such a and other issues, do not have an on is also mentioned as one of the in for the development of a digital and some other cryptocurrencies have in this respect which should and are not is which to the global economy should be allowed to to global CBDCs are the final frontier in increasing digitization of money and payments and the gradual of in the physical and in reinforcing the use of fiat money by the wider They also to be the last chance for state to monetary as of money and payments in national it would be in the for CBDCs to fully currency in a physical form. The is that money in a physical form has a distinct in terms of of for example, in that it not exclude the digitally The is that in of an such as a of technology, or an act of such as a physical or such as currency in the physical form can as a and possibly critical the development of CBDCs challenges which to some have been in this which has also to possible to the key CBDCs of the challenges that these raise like cross-border connectivity is certain is that the of CBDC systems will have a impact on payments and the provision of money in the economy and may have an impact on the of banking systems. of the challenges with CBDCs can through the type of technology that will be Given the challenges vis-à-vis the adoption of CBDCs, an international such as the should further on these challenges could be the adoption of CBDCs the including a form of technology to cross-border connectivity between different national central bank CBDC systems. However, it if a CBDCs to and the digital in money and payments would be Given competition from the private sector, the return of the state in the realm of money and of payment systems may prove to be with To in the the of money was the of central banks, and CBDCs may be a way to that in CBDCs may prove to be the last frontier for money and payments in the of the and have the not the bring about a radical transformation in the way that payments are and money is handled in This article is an and version of a paper to a on the of and at at the for of on this have several in to of the of the of of the and at the European Central for their and
Yustus Eko Oktian, Thi-Thu-Huong Le, Uk Jo, Agus Mahardika Ari Laksmono · 5 authors
With the increasing number of Internet of Things devices, it is crucial to keep them up-to-date to prevent cyber attacks. Traditional centralized delivery is not suitable for scaling and also can be too expensive to run for small vendors. Thus, finding a fully secure, scalable, yet cost-efficient firmware update distribution strategy is always an open research problem. This paper tries to answer those problems by proposing Patchman, a secure decentralized firmware update delivery service for the Internet of Things ecosystem leveraging blockchain. When a new firmware patch is available, vendors make a bid in the smart contract for anyone to join as firmware distributors. For each successful delivery to targeted devices, distributors are rewarded with tokens. Meanwhile, devices gain a reputation score every time they successfully install an update. To ensure robustness and fairness, we develop secure fair exchange protocols using verifiable proof-of-delivery and proof-of-installation. Those proofs can be traded in the blockchain for rewards and reputation scores increase, proving that the proof-holders have successfully processed a firmware delivery and firmware installation task. This way, the firmware update delivery can be executed safely without centralized third-party control. Our evaluation results show that our implementation complies with the five security goals that we envision. We also have successfully punished malicious actions by confiscating their deposits and requiring them to pay up to four times of base deposit value when they join the next update task, ensuring the fairness of our protocol. Furthermore, we generate low processing delay overhead compared to existing works that rely on Zero-Knowledge Proofs. The gas usage consumption from our approach also produced a competitive result despite our works supporting more features than existing works, ensuring the efficiency of our proposal.
This comprehensive technical paper presents a novel multi-modal trust architecture for AI-driven HR systems, focusing on the critical aspects of user acceptance in enterprise-scale people analytics platforms. Through the implementation of advanced zero-knowledge proof protocols, explainable AI frameworks, blockchain-based audit trails, and federated learning approaches, the architecture achieved an 85% improvement in user confidence metrics. The system demonstrates remarkable performance across resistance prediction, technical integration, and trust analytics, processing over 9.5 million daily interactions with 99.999% reliability. Our implementation across 1,850 organizations showed an 82% enhancement in system trustworthiness and a 2.8x improvement in operational efficiency, while reducing algorithmic bias by 89%. The architecture's event-driven design and microservices implementation resulted in a 76% improvement in system responsiveness and a 92% reduction in data processing latency, establishing a new benchmark for trust-centric AI-HR systems.
Taprootized Atomic Swaps is an extension for Atomic Swaps that enables the untraceability of transactions in a particular swap. Based on Schnorr signatures, Taproot technology, and zero-knowledge proofs, the taprootized atomic swaps hide swap transactions between regular payments. We propose several implementation options: single-transaction protocol, multiple-transaction protocol that splits the receiving amount in an untraceable way, and multichain swap protocol. Our proposed approach works with any smart-contract-compatible chain and multiple Taproot-compatible chains. We describe the concrete implementation of the protocol and release the source code publically.
In this article we show that all cyclic branched covers of a Seifert link have left-orderable fundamental groups, and therefore admit co-oriented taut foliations and are not $L$-spaces, if and only if it is not an $ADE$ link up to orientation. This leads to a proof of the $ADE$ link conjecture for Seifert links. When $L$ is an $ADE$ link up to orientation, we determine which of its canonical $n$-fold cyclic branched covers $Σ_n(L)$ have non-left-orderable fundamental groups. In addition, we give a topological proof of Ishikawa's classification of strongly quasipositive Seifert links and we determine the Seifert links that are definite, resp. have genus zero, resp. have genus equal to its smooth $4$-ball genus, among others. In the last section, we provide a comprehensive survey of the current knowledge and results concerning the $ADE$ link conjecture.
Open access
Geometric and Algebraic Topology
Geometric Analysis and Curvature Flows
Organometallic Compounds Synthesis and Characterization
In a democratic regime, voting is crucial to making collective decisions. Unfortunately, although this activity has great significance and value, little effort has been made to improve the way we vote. Paper ballots are still the most used method, although this method is relatively simple, brings many inconveniences, and represents a contradiction to the modern world and its advances. This paper mostly focuses on a review study of blockchain-based voting systems. It aims at identifying the strategies and the guidelines as well as provides a comprehensive end-to-end electronic voting system based on blockchain, with the help of cryptographic techniques such as zero-knowledge proofs to improve privacy. The novelty of this paper is that we tackle the limitations of electronic voting systems found in the literature, including cost, identity management, and scalability problems. Our purpose is to provide key elements for organizations on how to design their proper electronic voting system based on blockchain technology.
Open access
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
ABSTRACT Voting has always been a crucial topic of public attention for democratic reasons. The ease of use and low cost are the result of e‐voting being frequently used for such important decision outcomes. However, the tremendous authority and intervening data in current e‐voting systems make it risky and difficult to achieve correct equity and clarity in e‐voting. So, by combining e‐voting with blockchain technology, these issues can be resolved while providing reorganization and intervention‐resistant characteristics. A voter's improper manipulation, frequent voting, or non‐party voting, may also undermine fairness. A verifier is therefore required to check the e‐voting mechanism in order to ensure its effectiveness and control the process equality and fairness. In this paper, a Blockchain‐based e‐Voting Mechanism (BVM) is developed for providing the end to end security and fairness for transparent voting. This mechanism also provides a zero‐knowledge proof (ZP) based verifier to inspect the voting procedure against voter's mis‐operations and uses a novel Improved Master‐key Administration (IMA) based public key cryptography to attack prevention. The utilization of blockchain technology ensures transparency, anonymity, confidentiality, authentication, tamper resistance, and a high level of data integrity, making it a promising choice for modernizing and enhancing the electoral process. Also, the performance of BVM has been compared with similar voting mechanisms and analyzed based on time complexity, security analysis, performance factors like delay and throughput, and anti‐attack examination.
Open access
2 source records
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Stefanos Chaliasos, Jens Ernstberger, David Theodore, David A. Wong · 6 authors
Zero-knowledge proofs (ZKPs) have evolved from being a theoretical concept providing privacy and verifiability to having practical, real-world implementations, with SNARKs (Succinct Non-Interactive Argument of Knowledge) emerging as one of the most significant innovations. Prior work has mainly focused on designing more efficient SNARK systems and providing security proofs for them. Many think of SNARKs as "just math," implying that what is proven to be correct and secure is correct in practice. In contrast, this paper focuses on assessing end-to-end security properties of real-life SNARK implementations. We start by building foundations with a system model and by establishing threat models and defining adversarial roles for systems that use SNARKs. Our study encompasses an extensive analysis of 141 actual vulnerabilities in SNARK implementations, providing a detailed taxonomy to aid developers and security researchers in understanding the security threats in systems employing SNARKs. Finally, we evaluate existing defense mechanisms and offer recommendations for enhancing the security of SNARK-based systems, paving the way for more robust and reliable implementations in the future.
Secure aggregation enables federated learning (FL) to perform collaborative training of clients from local gradient updates without exposing raw data. However, existing secure aggregation schemes inevitably perform an expensive fresh setup per round because each client needs to establish fresh input-independent secrets over different rounds. The latest research, Flamingo (S&P 2023), designed a share-transfer-based reusable secret key to support the server continuously performing multiple rounds of aggregation. Nevertheless, the share transfer mechanism it proposed can only be achieved with P probability, which has limited reliability. To tackle the aforementioned problems, we propose a more reliable and anonymously authenticated scheme called Chu-ko-nu for multi-round secure aggregation. Specifically, in terms of share transfer, Chu-ko-nu breaks the probability P barrier by supplementing a redistribution process of secret key components (the sum of all components is the secret key), thus ensuring the reusability of the secret key. Based on this reusable secret key, Chu-ko-nu can efficiently perform consecutive aggregation in the following rounds. Furthermore, considering the client identity authentication and privacy protection issue most approaches ignore, Chu-ko-nu introduces a zero-knowledge proof-based authentication mechanism. It can support clients anonymously participating in FL training and enables the server to authenticate clients effectively in the presence of various attacks. Rigorous security proofs and extensive experiments demonstrated that Chu-ko-nu can provide reliable and anonymously authenticated aggregation for FL with low aggregation costs, at least a 21.02% reduction compared to the state-of-the-art schemes.
Jonathan Ku, Junyao Zhang, Haoxuan Shan, Saichand Samudrala · 9 authors
Elliptic curve cryptography (ECC) is widely used in security applications such as public key cryptography (PKC) and zero-knowledge proofs (ZKP). ECC is composed of modular arithmetic, where modular multiplication takes most of the processing time. Computational complexity and memory constraints of ECC limit the performance. Therefore, hardware acceleration on ECC is an active field of research. Processing-in-memory (PIM) is a promising approach to tackle this problem. In this work, we design ModSRAM, the first 8T SRAM PIM architecture to compute large-number modular multiplication efficiently. In addition, we propose R4CSA-LUT, a new algorithm that reduces the cycles for an interleaved algorithm and eliminates carry propagation for addition based on look-up tables (LUT). ModSRAM is co-designed with R4CSA-LUT to support modular multiplication and data reuse in memory with 52% cycle reduction compared to prior works with only 32% area overhead.
Chhavi Yadav, Amrita Roy Chowdhury, Dan Boneh, Kamalika Chaudhuri
Machine learning models are increasingly used in societal applications, yet legal and privacy concerns demand that they very often be kept confidential. Consequently, there is a growing distrust about the fairness properties of these models in the minds of consumers, who are often at the receiving end of model predictions. To this end, we propose \name -- a system that uses Zero-Knowledge Proofs (a cryptographic primitive) to publicly verify the fairness of a model, while maintaining confidentiality. We also propose a fairness certification algorithm for fully-connected neural networks which is befitting to ZKPs and is used in this system. We implement \name in Gnark and demonstrate empirically that our system is practically feasible. Code is available at https://github.com/infinite-pursuits/FairProof.
Akila Rekima, Lieke van den Elsen, Charlotte Isnard, Danielle J. Smyth · 19 authors
Colostrum is the physiological food for the first 72 h of a newborn.1 Its window of intake and high content in microbiota-shaping and growth factors1 suggest that colostrum is critical in guiding gut immune development. To address this hypothesis, we developed a mouse model of colostrum deprivation (Figure 1A). Like humans, mice have different lactation stages.2 We compared pups nursed immediately after birth by dams that no longer produced colostrum (Day 9 of lactation, a well-defined lactation stage in mice that is distinct from colostrum2) with control pups. This allowed us to assess the causal role of colostrum in the perinatal expansion of two cell types important in gut immune regulation, namely ILCs and CD4+ T cells. While we found a major increase in small intestine ILC2 frequency and numbers between Days 7 and 14 in control mice, ILC2 expansion was severely compromised when mice were deprived of colostrum (Figure 1B). Colostrum deprivation did not impact gut ILC, ILC1, ILC3, CD4+ T cells, Th1, Th2, Th17 and Treg cells representation in 2-week-old mice (Figure S1), suggesting a selective effect of colostrum on ILC2 ontogeny. The low numbers of Th1, Th2 and Th17 cells are consistent with the predominantly naïve T cell compartment at this time point of life.3 A more detailed analysis of CD4 T-cell phenotype including T-cell activation and their response to inflammatory signals remains to be performed to fully elucidate the role of colostrum in T-cell ontogeny. To verify that the decreased representation of ILC2 in 14-day-old mice was due to the imprinting of a different trajectory due to the absence of colostrum at birth, we performed two additional experiments. First, we investigated whether the impact of the intervention on ILC2 at Day 14 was due to changes in diet at birth versus at later time points. Therefore, pups were cross-fostered at Day 10, instead of Day 0, to dams that gave birth 9 days earlier than their biological mothers. As shown in Figure S2A, their percentage and number of ILC2 at Day 14 were similar to ctrl mice demonstrating that ILC2 ontogeny is not affected by exposure to ‘old’ milk at the time when ILC2 massively expands. We then investigated whether the reduced ILC2 expansion in mice nursed from birth by dams at Day 9 of lactation was due to colostrum deprivation versus exposure to mature milk at birth. We cross-fostered pups at birth to dams that had delivered only 3 days earlier. Similar to mice nursed by mothers at Day 9 of lactation, we found a major decrease in the representation of ILC2 compared to control mice (Figure S2B), supporting the hypothesis that colostrum at birth is required for ILC2 ontogeny. Given the importance of the microbiota in gut immune ontogeny, we next evaluated whether colostrum shaped the gut microbiota.3 Both the alpha and beta diversity of the gut microbiota significantly differed between control and colostrum-deprived 2-week-old mice (Figure S3A,B). To address whether this difference played a causal role in decreased ILC2 expansion in colostrum-deprived mice, experiments were repeated in germ-free mice. As observed in specific pathogen-free mice, we found that colostrum deprivation resulted in a 30% decrease in small intestine ILC2 compared to control germ-free mice (Figure S3C), indicating that the role of colostrum in ILC2 ontogeny is microbiota independent. The alarmins, IL-33, IL-25 and TSLP, play a major role in ILC2 proliferation and/or activation.4 During the first days of lung alveolarization, transient high levels of IL-33 were found to promote ILC2 accumulation.5 We also observed a transient increase in IL-33 secretion in the gut of 4-day-old control mice, which was two-fold lower in colostrum-deprived mice (Figure 1C). In addition to IL-33, IL-25, which is known to be important for gut ILC2 expansion/activation was significantly reduced in colostrum-deprived mice at Day 4 (Figure 1C). TSLP has a synergistic effect on the proliferation and Type 2 cytokine production of ILC2 and may be particularly important in early life where IL-33 alone is not sufficient to activate cytokine secretion.4 We also found a trend towards reduced TSLP secretion in colostrum-deprived mice (Figure 1C). Altogether, these data strongly suggest an important role for colostrum in alarmins-driven perinatal ILC2 expansion. Whereas we found that colostrum intake affected neither the circulating pool of ILC2 nor the expression of gut-homing molecules CCR9 and α4β7 on small intestine ILC2 nor their proliferation (Figure S4A–C), we found a threefold increase in apoptotic ILC2 in colostrum-deprived 2-week-old mice compared to controls (Figure 1D). The reduction in alarmins secretion in colostrum-deprived mice may contribute to their increased apoptotic death of ILC2.4 Finally, we evaluate the functional consequences of a decreased representation of small intestine ILC2 in colostrum-deprived mice by measuring their gut content in IL-13 and their ability to clear helminth infection, which is known to involve ILC2.5 IL-13 levels in gut tissues form colostrum-deprived mice were significantly reduced compared to control mice (Figure 1E). When 3-week-old colostrum-deprived mice were infected with Heligmosomoides polygyrus, twice as many worms in the intestine and threefold more eggs in the faeces were found 21 days later, compared to control mice (Figure 1F), showing the decreased ability of colostrum-deprived mice to efficiently control helminth infection later in life. Our data suggest that the reduced representation of ILC2 underlies this increased susceptibility to helminth infection. Future studies will establish whether other characteristics of colostrum-deprived mice may explain this observation. As a first step in translating our findings to humans, we analyzed the association between delayed initiation of breastfeeding (based on WHO guidelines recommending initiation within 1 h6), a practice that deprives the newborn of the full dose of colostrum, and the susceptibility to helminth infection in young children. Three-hundred mothers and their children (aged 1–3 years) were recruited in Uganda, and data on early feeding practices were collected retrospectively (Table 1). Among mothers who initiated breastfeeding after 1 h, 78% initiated breastfeeding on the first day of life, 17% on Day 2 and 5% after 1 week. Delayed initiation of breastfeeding was strongly associated with an increased risk for helminth infection [OR (95% CI): 5.3 (1.9–15.06, p = .009)] (Figure 1G). Data remained significant after adjustment for maternal and child age, which differed between the two groups [aOR (95% CI): 6.6 (2–22)]. A limitation of this proof-of-concept study is the recall bias on early feeding practice. To fully establish the importance of colostrum in the prevention of helminth infections, prospective studies specifically addressing the relationship between the amount of colostrum feeding and helminth infections will be required. Mouse and human data show there is a massive infiltration of ILC2 in the infant small intestine7, 8; however, factors involved in this process remained unknown. This work uncovers a critical role for colostrum in gut ILC2 ontogeny and reveals its importance for anti-helminth defence. Given the importance of ILC2 in the regulation of allergic responses,5 future research will need to address the impact of colostrum deprivation at birth on allergy risk. Despite WHO guidelines, more than half of newborns globally are non-optimally colostrum-fed,6 which deprives the newborn of colostrum bioactives at a time of both high vulnerability and critical developmental change. There is strong evidence that optimal colostrum feeding has a major impact on the prevention of neonatal mortality, especially in low-and middle-income countries.9 Our data provide evidence that colostrum may also be fundamental in imprinting healthy immune development. Expanding the knowledge on colostrum bioactives responsible for ILC2 expansion should lead to a major impact on child health. Project design and supervision: VV. Conceptualization: VV (whole project), AR (whole project), ML (GF exp), DL (GF exp), RL (ILC2 ontogeny), RM (helminth mice), TE (helminth human) and RB (microbiota). Mice experiments, data analysis and interpretation: AR, LvdE, CI, SM, ND, CT, ML, NS, TY and VV. Human data collection and analysis: MB, CR and TE. Microbiota data analysis: FS, RB and VV. Writing—original draft: AR and VV. Writing—review and editing: All. The authors would like to thank Simone Ross and Caitlin Murray at the Harry Perkins Institute for Medical Research, the Gnotobiotic facilities and the technical assistance of staff in the South Australian Health and Medical Research Institute (SAHMRI) Preclinical Imaging and Research Laboratories (PIRL) and Translational Research Institute (TRI). Flow cytometry analysis was performed with the help of Catherine Rinaldi from the Cytometry Centre of Microscopy Characterisation, and Analysis (CMCA, UWA) and at the ACRF Cellular Imaging and Cytometry Core Facility in SAHMRI. The ACRF Facility is generously supported by the Detmold Hoopman Group, Australian Cancer Research Foundation and Australian Government through the Zero Childhood Cancer Program. We also thank Benjamin Lelouvier from Vaiomer for the data analysis. VV, LE, AR, SM, MB and ND were supported by the Larsson-Rosenquist Foundation. AR and LE were supported by a Raine collaborative grant award. DJL was supported by an EMBL Australia Group Leader award. RMM thanks the Wellcome Trust for support through an Investigator Award (Ref 219530), and core-funded Wellcome Centre for Integrative Parasitology (Ref: 104111). Florence Servant declares she is an employee of the “Vaiomer SAS” company. All the other authors declare they have no conflict of interest related to this publication. The data that support the findings of this study are available on request from the corresponding author. The data are not publicly available due to privacy or ethical restrictions. Data S1. Please note: The publisher is not responsible for the content or functionality of any supporting information supplied by the authors. Any queries (other than missing content) should be directed to the corresponding author for the article.
It is well-known that digital signatures can be constructed from one-way functions in a black-box way. While one-way functions are essentially the minimal assumption in classical cryptography, this is not the case in the quantum setting. A variety of qualitatively weaker and inherently quantum assumptions (e.g. EFI pairs, one-way state generators, and pseudorandom states) are known to be sufficient for non-trivial quantum cryptography. While it is known that commitments, zero-knowledge proofs, and even multiparty computation can be constructed from these assumptions, it has remained an open question whether the same is true for quantum digital signatures schemes (QDS). In this work, we show that there $\textit{does not}$ exist a black-box construction of a QDS scheme with classical signatures from pseudorandom states with linear, or greater, output length. Our result complements that of Morimae and Yamakawa (2022), who described a $\textit{one-time}$ secure QDS scheme with classical signatures, but left open the question of constructing a standard $\textit{multi-time}$ secure one.
This paper introduces the zk-IoT framework, a novel approach to enhancing the security of Internet of Things (IoT) ecosystems through the use of Zero-Knowledge Proofs (ZKPs) on blockchain platforms. Our framework ensures the integrity of firmware execution and data processing in potentially compromised IoT devices. By leveraging the concept of ZKP, we establish a trust layer that facilitates secure, autonomous communication between IoT devices in environments where devices may not inherently trust each other. The framework includes zk-Devices, which utilize functional commitment to generate proofs for executed programs, and service contracts for encoding interaction logic among devices. It also utilizes a blockchain layer and a relayer as a ZKP storage and data communication protocol, respectively. Our experiments demonstrate that proof generation, reading, and verification take approximately 694, 5078, and 19 milliseconds in our system setup, respectively. These timings meet the practical requirements for IoT device communication, demonstrating the feasibility and efficiency of our solution. The zk-IoT framework represents a significant advancement in the realm of IoT security, paving the way for reliable and scalable IoT networks across various applications, such as smart city infrastructures, healthcare systems, and industrial automation.
Shrabani Sutradhar, S. P. Majumder, Rajesh Bose, Haraprasad Mondal · 5 authors
The Internet of Medical Things (IoMT) has transformed healthcare, collecting and transmitting vast medical data. This study proposes an innovative solution, integrating blockchain into IoMT within a fog-cloud computing framework for secure medical data transmission. The blockchain-based zero-trust system ensures reliable data auditing and Electronic Health Repository (EHR) protection. New blockchain entries atop prior blocks deter tampering, with Quad Merkle tree and zero-knowledge proof encryption ensuring data integrity and privacy. The multi-critic deep deterministic policy gradient algorithm optimizes task-offloading decisions in the fog-cloud layer. Security analyses validate its effectiveness, improving computing efficiency and ensuring data fidelity and privacy. These findings position the system as a promising solution for enhancing medical data security and integrity in edge-fog cloud environments, aligning with evolving healthcare technology demands.
Bianca-Mihaela Ganescu, Jonathan Passerat‐Palmbach
Generative AI, exemplified by models like transformers, has opened up new possibilities in various domains but also raised concerns about fairness, transparency and reliability, especially in fields like medicine and law. This paper emphasizes the urgency of ensuring fairness and quality in these domains through generative AI. It explores using cryptographic techniques, particularly Zero-Knowledge Proofs (ZKPs), to address concerns regarding performance fairness and accuracy while protecting model privacy. Applying ZKPs to Machine Learning models, known as ZKML (Zero-Knowledge Machine Learning), enables independent validation of AI-generated content without revealing sensitive model information, promoting transparency and trust. ZKML enhances AI fairness by providing cryptographic audit trails for model predictions and ensuring uniform performance across users. We introduce snarkGPT, a practical ZKML implementation for transformers, to empower users to verify output accuracy and quality while preserving model privacy. We present a series of empirical results studying snarkGPT's scalability and performance to assess the feasibility and challenges of adopting a ZKML-powered approach to capture quality and performance fairness problems in generative AI models.
This article discusses the issues with traditional scientific publishing and the solutions offered by DeSci. It covers problems caused by oligopoly in scientific publishing, author-reviewer-editor triangulation, predatory journals, and funding and resource allocation. These issues result in gated publishing, peer review bias, publish or perish culture, centralized funding, poor publication quality, low accessibility, low transparency, and low reproducibility. This study discusses DeSci's solutions to the aforementioned problems through blockchain technologies, including DAO, DBDAO, NFT, Zero-Knowledge Proofs, IP-NFT, and IPFS. Sample applications and projects are provided to illustrate these solutions. DeSci's solutions represent a transition from oligopoly in scientific production to the true Open Science era.