Anonymity in Bitcoin, a peer-to-peer electronic currency system, is a complicated issue. Within the system, users are identified by public-keys only. An attacker wishing to de-anonymize its users will attempt to construct the one-to-many mapping between users and public-keys and associate information external to the system with the users. Bitcoin tries to prevent this attack by storing the mapping of a user to his or her public-keys on that user's node only and by allowing each user to generate as many public-keys as required. In this chapter we consider the topological structure of two networks derived from Bitcoin's public transaction history. We show that the two networks have a non-trivial topological structure, provide complementary views of the Bitcoin system and have implications for anonymity. We combine these structures with external information and techniques such as context discovery and flow analysis to investigate an alleged theft of Bitcoins, which, at the time of the theft, had a market value of approximately half a million U.S. dollars.
Concepts for future energy networks envision the distribution of measurement and control infrastructures to the customers to allow for improved reactions to certain events in the energy grid and to ease the measurement process. Such a distribution of control functionalities requires a corresponding device on the customer side that performs or mediates between the energy grid requirements and the customer infrastructure. These Smart Energy Gateways (SEGs) are owned by the energy network operator and but enforce the contracts between network operator and customer for both parties. They can also support additional value-added services. Due to the different uses, SEGs will be exposed to more and other attacks than current end-user devices such as DSL or WLAN routers. The impact of attacks to SEGs is also a peril to the overall operation of the energy grid. This paper provides an approach to the reliable identification of SEGs based on already established industry standards, namely Trusted Computing and Trusted Network Connect.
We introduce WORM-ORAM, a first mechanism that combines Oblivious RAM (ORAM) access privacy and data confidentiality with Write-Once Read-Many (WORM) regulatory data retention guarantees. Clients can outsource their database to a server with full confidentiality and data access privacy, and, for data retention, the server ensures client access WORM semantics. In general simple confidentiality and WORM assurances are easily achievable, e.g., via an encrypted outsourced data repository with server-enforced read-only access to existing records (albeit encrypted). However, this becomes hard when also access privacy is to be ensured-when client access patterns are necessarily hidden and the server cannot enforce access control directly. WORM-ORAM overcomes this by deploying a set of zero-knowledge proofs to convince the server that all stages of the protocol are WORM-compliant.
We present a cryptographic framework to achieve access control, privacy of social relations, secrecy of resources, and anonymity of users in social networks. The main idea is to use pseudonyms to hide user identities, signatures on pseudonyms to establish social relations, and zero-knowledge proofs on these signatures to demonstrate the existence of the corresponding social relations without sacrificing user anonymity. Our framework is generally applicable and, in particular, constitutes an ideal plug-in for decentralized social networks.
A public watermark detection scheme based on secure multiparty computation is proposed. It removes the expensive zero-knowledge interactive proofs and replaces the traditional trusted third party with a group of proxies. Then, the proposed scheme is robust against "single point failure", and efficient in terms of computation cost, the number of rounds and bandwidth required in the communications. Because of using integer comparison technique, the scheme achieves the provable security against sensitivity attacks without leaking any information about the secret watermark.
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
A public watermark detection scheme using verifiable secret sharing is proposed. It removes the expensive zero-knowledge interactive proofs and replaces the traditional trusted third party with a group of proxies. Moreover, the scheme is secure against sensitivity attacks and very efficient in terms of computation cost, the number of rounds and bandwidth required in the communications.
Open access
Advanced Steganography and Watermarking Techniques
A new watermark embedding and detection method in Microsoft Word 2007-2010 files which use Office Open XML (OOXML) format is proposed in this paper. Watermark information can be imperceptibly embedded into OOXML documents by replacing or adding the values of Revision Identifiers (RIs), which are specific attributes in the main document body of the OOXML document. In the detection process, a secure watermark detection scheme based on zero-knowledge proof is proposed without revealing any watermarking-related information to improve the security of watermarking detection. Experiments show that 4.43 bit is embedded into each word and 0.07 bit is embedded into each bit of the document on average, which is higher than contemporary linguistic watermarking approaches. The method can resist “Format”, “Impersonation”, “Save As”, “Copy” and other active attacks and all these changes will not be shown on the MS Office screen display. Therefore, the proposed method can apply to the field of security protection for OOXML format documents.
Advanced Steganography and Watermarking Techniques
Web service demand is heterogeneous and it is expanding day by day. Malicious web attacks particularly at application layer, are also increasing significantly. It is estimated eighty percent (80%) malicious attacks are web application layer attacks such as Cross Site Scripting and SQL injection. Such attacks have affected financial organizations, government institutes, hospitals and enterprise companies and so on. It is required to detect such attacks instantly to maintain the safe operations. Existing Web Application Firewalls (WAF) aim at protection of web application attacks using Black and White list based approach. Black list based WAFs operate at security operation center (SOC) to protect known attacks and it is easy to maintain same black list by other WAF nodes. However, white list independent signature from each Web service and it is generated by each web site policy. When the event of WAF fails, other WAF doesn't have same level of White list at that time. Black list is common type of signature and it can be keep the assurance by multiple WAF nodes or proxy node but White list is individual type of signature and can't maintain assurance by same policy of node. Therefore, to maintain high detection rate, dynamic adaptability of White list is required. It also requires online property and timeliness response. To solve these issues, an integrated Autonomous Decentralized Multi Layer Cache (ADMLC) system with Web Application Firewall is proposed. Evaluation shows that proposed architecture detection rate is much better than other traditional WAF based systems.
In this paper, we study methods for improving the utility and privacy of\nreputation scores for online auctions, such as used in eBay, so as to reduce\nthe effectiveness of feedback extortion. The main ideas behind our techniques\nare to use randomization and various schemes to escrow reputations scores until\nappropriate external events occur. Depending on the degree of utility and\nprivacy needed, these external techniques could depend on the number and type\nof reputation scores collected. Moreover, if additional privacy protection is\nneeded, then random sampling can be used with respect reputation scores in such\na way that reputation aggregates remain useful, but individual reputation\nscores are probabilistically hidden from users. Finally, we show that if\nprivacy is also desired with respect to the the reputation aggregator, then we\ncan use zero-knowledge proofs for reputation comparisons.\n
We present a cryptographic framework to achieve access control, privacy of social relations, secrecy of resources, and anonymity of users in social networks. We illustrate our technique on a core API for social networking, which includes methods for establishing social relations and for sharing resources. The cryptographic protocols implementing these methods use pseudonyms to hide user identities, signatures on these pseudonyms to establish social relations, and zero-knowledge proofs of knowledge of such signatures to demonstrate the existence of social relations without sacrificing user anonymity. As we do not put any constraints on the underlying social network, our framework is generally applicable and, in particular, constitutes an ideal plug-in for decentralized social networks. We analyzed the security of our protocols by developing formal definitions of the aforementioned security properties and by verifying them using ProVerif, an automated theorem prover for cryptographic protocols. Finally, we built a prototypical implementation and conducted an experimental evaluation to demonstrate the efficiency and the scalability of our framework.
Harry Kalodner, Miles Carlsten, Paul Ellenbogen, Joseph Bonneau · 5 authors
Secure decentralized namespaces have recently become possible due to cryptocurrency technology. They enable a censorship-resistant domainname system outside the control of any single entity, among other applications. Namecoin, a fork of Bitcoin, is the most prominent example. We initiate the study of decentralized namespaces and the market for names in such systems. Our extensive empirical analysis of Namecoin reveals a system in disrepair. Indeed, our methodology for detecting “squatted” and otherwise inactive domains reveals that among Namecoin’s roughly 120,000 registered domain names, a mere 28 are not squatted and have nontrivial content. Further, we develop techniques for detecting transfers of domains in the Namecoin block chain and provide evidence that the market for domains is thin-tononexistent. We argue that the state of the art in mechanism design for decentralized namespace markets is lacking. We propose a model of utility of different names to different participants, and articulate desiderata of a decentralized namespace in terms of this utility function. We use this model to explore the design space of mechanisms and analyze the trade-offs.
Jeff Naruchitparames, Mehmet Hadi Gunes, Cansın Yaman Evrenosoglu
This paper focuses on deployment of smart meters in the power distribution systems to enhance the operation infrastructure. An important challenge in establishing a communication paradigm between the utilities and the customers is that customers are susceptible to privacy concerns. In this paper, we present a model to ensure the privacy and integrity of communicating parties within the smart grid by using smart meters as a gateway between intra- and inter-network communications. In particular, we utilize the smart meter as a firewall to manage incoming and outgoing traffic and mediate household devices based on the instructions from the electric utility. Moreover, third parties are introduced in our model such as service providers so that they can monitor and manage the contracted customers by using the existing communication infrastructure.
Abstract. We present a generic transformation that allows us to use a large class of pairing-based signatures to construct schemes for signing group elements in a structure preserving way. As a result of our transformation we obtain a new efficient signature scheme for signing a vector of group elements that is based only on the well established decisional linear assumption (DLIN). Moreover, the public keys and signatures of our scheme consist of group elements only, and a signature is verified by evaluating a set of pairing-product equations. In combination with the Groth-Sahai proof system, such a signature scheme is an ideal building block for many privacy-enhancing protocols. To do this, we start by proposing a new stateful signature scheme for signing vectors of exponents that is F-unforgeable under weak chosen message attacks. This signature scheme is of independent interest as it is compatible with Groth-Sahai proofs and secure under a computational assumption implied by DLIN. Then we give a general transformation for signing group elements based on signatures (for signing exponents) with efficient non-interactive zero-knowledge proofs. This transform also removes any dependence on state in the signature used to sign exponents. Finally, we obtain our result by instantiating this transformation with the above signature scheme and Groth-Sahai proofs. 1
Andrés Molina–Markham, George Danezis, Kevin Fu, Prashant Shenoy · 5 authors
Abstract. Smart meters that track fine-grained electricity usage and implement sophisticated usage-based billing policies, e.g., based on timeof-use, are a key component of recent smart grid initiatives that aim to increase the electric grid’s efficiency. A key impediment to widespread smart meter deployment is that fine-grained usage data indirectly reveals detailed information about consumer behavior, such as when occupants are home, when they have guests or their eating and sleeping patterns. Recent research proposes cryptographic solutions that enable sophisticated billing policies without leaking information. However, prior research does not measure the performance constraints of real-world smart meters, which use cheap ultra-low-power microcontrollers to lower deployment costs. In this paper, we explore the feasibility of designing privacy-preserving smart meters using low-cost microcontrollers and provide a general methodology for estimating design costs. We show that it is feasible to produce certified meter readings for use in billing protocols relying on Zero-Knowledge Proofs with microcontrollers such as those inside currently deployed smart meters. Our prototype meter is capable of producing these readings every 10 seconds using a $3.30USD MSP430 microcontroller, while less powerful microcontrollers deployed in today’s smart meters are capable of producing readings every 28 seconds. In addition to our results, our goal is to provide smart meter designers with a general methodology for selecting an appropriate balance between platform performance, power consumption, and monetary cost that accommodates privacy-preserving billing protocols. 1
David Bernhard, Véronique Cortier, Olivier Pereira, Ben Smyth · 5 authors
Abstract. Recent results show that the current implementation of He-lios, a practical e-voting protocol, does not ensure independence of the cast votes, and demonstrate the impact of this lack of independence on vote privacy. Some simple fixes seem to be available and security of the revised scheme has been studied with respect to symbolic models. In this paper we study the security of Helios using computational models. Our first contribution is a model for the property known as ballot privacy that generalizes and extends several existing ones. Using this model, we investigate an abstract voting scheme (of which the revised Helios is an instantiation) built from an arbitrary encryp-tion scheme with certain functional properties. We prove, generically, that whenever this encryption scheme falls in the class of voting-friendly schemes that we define, the resulting voting scheme provably satisfies ballot privacy. We explain how our general result yields cryptographic security guaran-tees for the revised version of Helios (albeit from non-standard assump-tions). Furthermore, we show (by giving two distinct constructions) that it is possible to construct voting-friendly encryption, and therefore voting schemes, using only standard cryptographic tools. We detail an instan-tiation based on ElGamal encryption and Fiat-Shamir non-interactive zero-knowledge proofs that closely resembles Helios and which provably satisfies ballot privacy. 1
Traditional electricity meters are replaced by Smart Meters in customers' households. Smart Meters collects fine-grained utility consumption profiles from customers, which in turn enables the introduction of dynamic, time-of-use tariffs. However, the fine-grained usage data that is compiled in this process also allows to infer the inhabitant's personal schedules and habits. We propose a privacy-preserving protocol that enables billing with time-of-use tariffs without disclosing the actual consumption profile to the supplier. Our approach relies on a zero-knowledge proof based on Pedersen Commitments performed by a plug-in privacy component that is put into the communication link between Smart Meter and supplier's back-end system. We require no changes to the Smart Meter hardware and only small changes to the software of Smart Meter and back-end system. In this paper we describe the functional and privacy requirements, the specification and security proof of our solution and give a performance evaluation of a prototypical implementation.
Matteo Maffei, Giulio Malavolta, Manuel Reinert, Dominique Schröder
The existing (election) voting systems, e.g., representative democracy, have many limitations and often fail to serve the best interest of the people in collective decision making. To address this issue, the concept of liquid democracy has been emerging as an alternative decision-making model to make better use of "the wisdom of crowds". Very recently, a few liquid democracy implementations, e.g. Google Votes and Decentralized Autonomous Organization (DAO), are released; however, those systems only focus on the functionality aspect, as no privacy/anonymity is considered. In this work, we, for the first time, provide a rigorous study of liquid democracy under the Universal Composability (UC) frame- work. In the literature, liquid democracy was achieved via two separate stages -- delegation and voting. We propose an efficient liquid democracy e-voting scheme that uni es these two stages. At the core of our design is a new voting concept called statement voting, which can be viewed as a natural extension of the conventional voting approaches. We remark that our statement voting can be extended to enable more complex voting and generic ledger-based non-interactive multi-party computation. We believe that the statement voting concept opens a door for constructing a new class of e-voting schemes.
Ein E- Voting System muss einerseits sicher sein andererseits muss es gewährleisten dass jede Wahl berücksichtigt und anonym ausgewertet wird. \nDieses Projekt befasst sich mit der Aufgabe, ein solch sicheres, stabiles und transparentes Wahlsystem anzubieten. Das Ziel der Arbeit ist es, einen Web Client zu entwickeln, der mit Hilfe einer Big- Integer Library und JavaScript Funktionen das für E- Voting geeignete Damgård- Jurik Kryptosystem zu implementiert. Weiter galt es, die Verfügbarkeit von echten Zufallszahlen in JavaScript abzuklären. Die generierten Datensätze sind in der JavaScript Object Notation (JSON) an den Server weiterzuleiten. In einem optionalen Teil der Arbeit sollte die Wohlgeformtheit der verschlüsselten Stimmzettel mittels eines Zero-Knowledge Proofs Protokoll nachgewiesen werden können. \nDer verwendete asymmetrische Damgård- Jurik Verschlüsselungsalgorithmus, hat die homomorphe Eigenschaft, dass die Multiplikation chiffrierter Werte gleich der verschlüsselten Summe der entsprechenden Klartexte entspricht. Da nur das aufkumulierte Schlussresultat der Abstimmung entschlüsselt wird, ist dadurch die Anonymität der einzelnen Stimmen gewährleistet. Um die Gültigkeit eines verschlüsselten Wahlzettels zu überprüfen, wird ein Zero-Knowledge Proofs Protokoll verwendet. Da JavaScript nur mit Zahlen bis 53 Bit rechnen kann, ist für die Berechnungen eine JavaScript Big- Integer Library notwendig. Es wurden verschiedene Bibliotheken getestet und im Detail ausgewertet. Ebenfalls wurde die Möglichkeit echte Zufallszahlen plattformunabhängig zu generieren abgeklärt. \nDie Wahl der Big-Integer Library ist auf jsbn.js der Stanford University gefallen und für die Generierung von Zufallszahlen auf jscrypto.js, welche durch die Auswertung von Mausbewegungen Entropie gewinnt. Der implementierte JavaScript Client verschlüsselt erfolgreich Stimmzettel mittels Damgård- Jurik Verschlüsselungsalgorithmus und leitet das Chiffrat mit zusätzlichen, für den Zero-Knowledge Proofs Protokoll notwendigen Parametern im JSON Format an den Server weiter, der die empfangenen Daten auf ihre Wohlgeformtheit prüft. Die Messungen haben ergeben, dass der Google Chrome Browser am optimalsten mit den angewendeten Libraries läuft. Bei der Verwendung eines 1024 Bit RSA Modulus benötigt der Google Chrome Browser 1.7 Sekunden für die Damgård- Jurik Verschlüsselung und zusätzlich 8.8 Sekunden für die Generierung der Zero-Knowledge Proofs Protokoll notwendigen Parametern.
To address the problem that the common authentication mechanism is not applicable to the P2P network system model with anonymous communication requirements.This paper,based on the improvement of the Diffle-Hellman key agreement protocol and the combination of the RSA digital signatures agreements and zero-knowledge proof GQ agreement,proposes a new token-based services authentication mechanism to identify the nodes in P2P anonymous communication systems.This mechanism,with the premise of guaranteeing various general characteristics of P2P anonymous communication system and introduction of the trusted third party node into P2P anonymous communication system,implements anonymous control and behavior management of various communication nodes in P2P anonymous communication system.It could resist the threat of various common networks attack and realize effective authentication of P2P anonymous communication system,thus improving the security management ability of P2P anonymous communication system.