The group signature with designated traceability (GSdT) is a kind of group signatures (GS) which aim to restrict the opening authority of the group manager; by setting an access structure over openersâ attributes at the signing, a signer is able to control openers who can open the signature. A generic construction of GSdT was given when the notion was introduced, then a pairing-based construction and a symmetric-key-based one were presented. Nonetheless, it remains open whether or not a post-quantum GSdT that has full anonymity can be really constructed.In this paper, we give a lattice-based GSdT scheme that has full anonymity for the first time. In our construction, the lattice-based ciphertext-policy attribute-based encryption (CP-ABE) by Tsabary and the lattice-based group signatures (GS) by Libert et al. are employed. The CP-ABE is based on the Regev public-key encryption, while the GS uses a non-interactive zero-knowledge proof to prove the correctness of the encryption in the signing process. Based on the compatibility, we combine and modify them to build up a GSdT scheme.
The rise of Vehicle-to-Everything (V2X) communication in Intelligent Transportation Systems (ITS) enhances road safety and traffic management but introduces security vulnerabilities like impersonation and data tampering. Traditional identity management systems such as Public Key Infrastructure (PKI) are limited by their reliance on centralized authorities. This paper proposes a decentralized framework using Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and Distributed Ledger Technology (DLT), integrating Zero-Knowledge Proofs (ZKPs) to secure identity management in V2X systems. The proposed framework achieves robust authentication, mitigates centralization risks, and enables privacy-preserving mechanisms, demonstrating enhanced scalability and resilience against attacks in V2X communication.
Jie Yang, Yuta Kodera, Samsul Huda, Yasuyuki Nogami
In the distributed medical information management system, blockchain technology has more obvious advantages in terms of data tampering data traceability. However, considering the scalability issues of current Layer-1 blockchain, uploading massive medical information data onto the blockchain will add non-negligible space storage pressure. Patients are also unable to have a comprehensive grasp of their personal privacy information retained in these data, which can lead to concern about the systemâs privacy and security. To cope with these challenges, this paper introduced Layer-2 network to reduce the data space occupation in a single block. By storing unnecessary information in the off-chain channel, the transaction speed and throughput of the system would be improved. In addition, to strengthen the security within the process of data communication and storage, this paper also deployed the system based on consortium blockchain utilizing AWS cloud service. And the system integrated with the zero-knowledge proof algorithm zk-SNARKs to protect personal information privacy. According to the experimental simulation and analysis, the proposed scheme can reduce data storage space in the Lay-1 blockchain. Whatâs more, it also allows quick verification of on-chain data without disclosing personal privacy information.
Mpyana Mwamba Merlec, Nday Kabulo Sinai, Seng-Phil Hong, Hoh Peter In
The proliferation of digital technologies has led to an exponential growth in personal data generation, raising significant privacy, security, and ownership control challenges. However, existing centralized identity and data management models present concerns leading to data breaches, unauthorized data sharing, and loss of user ownership control. To address these issues, this article proposes a novel Personal Data-as-a-Service (PDaaS) platform, which leverages the robustness of a permissioned blockchain to ensure data integrity and access control, while using IPFS for decentralized and resilient data storage. It enables a secure and decentralized user-centric framework for managing personal data while preserving user privacy and data sovereignty. Leveraging a suite of advanced technologies including decentralized identifiers, verifiable credentials, enhanced encryption techniques (i.e., quantum-resistant encryption), zero-knowledge proofs, and dynamic consent management, the PDaaS platform enables individuals to retain ownership and control over their data while facilitating secure and privacy-preserving data processing, sharing, exchange, and monetization. This paper presents the design considerations and framework architecture of the proposed platform, which was built using the Hyperledger Besu to assess its feasibility and performance. It also discusses the implications, use cases, and challenges of deploying the PDaaS platform.
This paper researches the latest advancements in Ethereum virtual machine wallet standards, with a particular focus on ERC4337 and Zero-Knowledge (ZK)-Based wallet proposals. With the continuous evolution of the Blockchain technology, there is an escalating demand for wallets that are not only more secure and efficient but also user-friendly. This study presents an in-depth analysis of ERC4337, a new wallet standard that introduces a novel account abstraction layer, enabling more flexible and user-centric experiences. Additionally, the paper explores ZK-Based wallet proposals, which leverage zero-knowledge proofs to enhance privacy and security in transactions. Through a summarized analysis, this research assesses the potential impacts of these emerging standards on user experience, security, and overall blockchain ecosystem integration. The findings aim to provide valuable insights for developers, users, and stakeholders in the cryptocurrency domain, highlighting the opportunities and challenges these new wallet standards present.
A.R Baku, Emmanuel Amadi, Udoka Felista Eze, G. A. Chukwudebe · 5 authors
The agri-food industry faces increasing demands for transparency and accountability due to concerns over product safety and sustainability. Current traceability systems often fall short due to fragmented data, potential inaccuracies, and limited scalability. This research proposes a novel blockchain-based framework to address these challenges. The proposed framework features a multi-layered architecture, dividing the system into distinct layers for data storage, consensus mechanisms, and user interactions. A comprehensive literature review was conducted using academic databases (e.g., Scopus, Web of Science) and industry reports to identify existing research on blockchain technology, agri-food supply chains, and traceability. Key search terms included "blockchain," "agri-food," "traceability," "transparency," and "privacy." The identified research was analyzed to identify the key challenges and opportunities in agri-food traceability. A detailed analysis of the existing systems was conducted to understand their limitations and potential improvements. Based on the analysis, a blockchain-based framework was designed. The framework incorporates a multi-layered architecture, including a data layer, consensus layer, and application layer. Parallel side chains and zero-knowledge proofs were integrated to enhance scalability and privacy. The proposed framework was modeled using the Unified Modeling Language (UML) to visualize the system's components, relationships, and interactions. Microsoft Visio was used as a modeling tool to create diagrams and visualize the system's architecture. Key Contributions includes a robust and scalable blockchain-based framework for agrifood traceability, a multi-layered architecture that addresses the specific needs of the agri-food industry, the use of zero-knowledge proofs to enhance privacy and trust and a comprehensive system design based on a rigorous methodology. Keywords: blockchain, agri-food supply chain, traceability, transparency, privacy, zero-knowledge proofs, OOAD, system design.
The privacy-preserving data aggregation is a challenging task in decentralized networks (e.g. blockchain) where multiple distinct contributors need to collaborate in order to perform a shared task (e.g. arithmetic operations) by preserving the privacy of each individual data. The existing protocols for the privacy-preserving data aggregation in the literature may require the fully-complete hypercubes over the Ethereum blockchain where it supports limited number of contributors at a certain time (i.e. exactly 2knodes in k-dimension). Therefore, we theoretically analyze the security of such protocols from the perspective of underdetermined systems and identify the potential root problem so that any arbitrary number of nodes could be supported. For this problem, we propose three novel decentralized techniques (i.e. node multiplexing, topological recursing and data splitting) by comparing their relative advantages and disadvantages.
Junyi Zhong, Thiago Abreu, Sami Souihi, Françoise S. Lucas
This paper introduces the G-TOK framework, which utilizes advanced zero-knowledge proofs (ZKPs) and dynamic verifiable credentials (VCs) to preserve data privacy in sensor data sharing on blockchain networks. As industries increasingly depend on accurate and confidential sensor data from IoT applications, maintaining privacy and data integrity becomes a significant challenge. Our framework specifically addresses this issue in the context of smart environment sensor networks. Typically, data access control in such networks is either fully permissioned or overly restrictive, lacking mechanisms for selective disclosure access control. Our approach aims to enhance encrypted decentralized data storage and improve data interoperability. It includes dynamic VCs, authenticated privacy-preserving tokenization of geolocation data, and a decentralized real-time location verification scheme. Additionally, we propose a proof-of-footprint (PoF) schema, showcasing the integration and practicality of cutting-edge technologies such as ZKPs, VCs, and self-sovereign identities. This schema aligns with international standards, including the Verifiable Credentials Data Model v2.01and selective disclosure of JSON Web Token (JWT) claims2.
Valeh Farzaliyev, Calvin PĂ€rn, Heleen Saarse, Jan Willemson
Abstract This paper studies several building blocks needed for electronic voting in order to prepare for the post-quantum era. In particular, we present lattice-based constructions for a generic zero-knowledge (ZK) proof of ballot correctness, a ZK proof of ballot correctness applicable for the homomorphic tallying scenario, and a ZK proof to achieve cast-as-intended verification during the vote casting period. We implement and benchmark our ballot correctness proofs, giving concrete estimations comparing the performance of homomorphic tallying and mix-net based e-voting systems in case of our lattice-based constructions.
Cryptography plays a vital role in ensuring the security and privacy of blockchain networks, as well as Web3 dApps and wallets. This chapter describes some common cryptographic concepts and algorithms relevant to Web3, which include: Hash Functions : Hash functions transform data into fixed-length strings (hashes). In Web3, hashes are used to verify data integrity and create unique identifiers for transactions and blocks. Public and Private Key Pairs : Web3 relies on asymmetric encryption, where each user has a public key (used for encryption) and a corresponding private key (used for decryption). Public keys are openly shared, while private keys must remain confidential. Transactions and data integrity are secured using these key pairs. Symmetric Encryption : Symmetric encryption uses a single shared secret key for both encryption and decryption. While less common in Web3, it&s;s still relevant for certain use cases. Digital Signatures : Digital signatures provide proof of authenticity and integrity. When a user signs a transaction with their private key, others can verify it using the associated public key. Zero-Knowledge Proofs : Zero-Knowledge Proofs are cryptographic protocols that allow one party (the prover) to prove the truth of a statement to another party (the verifier) without revealing any additional information beyond the statement&s;s validity. In other words, ZKPs enable verification without disclosure.
Relevance: Starting with the invention of the Internet, the world began to change rapidly, and the pace of change is increasing, so the problem of data storage and processing is becoming more and more relevant. The ZK-STARK protocol is a new cryptographic zero-knowledge proof protocol that is not yet widely used in practice and allows you to check a message or a transaction on the blockchain network for authenticity without reproducing it completely. At the moment, gaps and problems related to this protocol are identified: computational complexity, possible poor compatibility with other protocols, and resistance to attacks from quantum computers. Therefore, the paper aims to supplement the coverage of the problem associated with computational complexity and to propose solutions to this problem. Purpose: on the basis of the theoretical implementation of the first stage named Arithmetization of the ZK-STARK protocol, to test its software implementation in order to provide recommendations on its most computationally efficient version. Research methods: mathematical statements on interpolation theory, group theory, number theory; information on Fibonacci numbers; information on the Euler function; generating element of a group; cyclic groups; Lagrange interpolation polynomial and the sequence of calculations of Arithmetization; Visual Studio 2022 programming environment, C++ programming language, NTL library, Microsoft Excel. Results of work: The result of the work is the theoretical implementation of the first stage of the ZK-STARK protocol and the effectiveness testing of the first stage, and providing recommendations for its most effective version. Conclusion: Testing has shown that the practical implementation of the Arithmetization based on the inverse fast Fourier transform has a time complexity , that is in times less than the time complexity of the Arithmetization based on inverse matrices method and Gaussian method for interpolation, that speeds up the work of Arithmetization of the ZK-STARK protocol.
Open access
Cybersecurity and Information Systems
Advanced Computational Techniques in Science and Engineering
With the rapid development of Industrial Internet of Things (IIoT) technology, an increasing number of devices are connecting to the internet, generating vast amounts of sensitive data and creating data silos that hinder resource coordination. Current centralized storage systems for IIoT data are prone to single points of failure, privacy breaches, and security issues. To address these problems, this paper proposes an IIoT data storage and access solution based on Solana blockchain and InterPlanetary File System (IPFS) technology, aiming to achieve efficient, secure, and scalable data management. The Chainlink Verifiable Random Function (VRF) protocol generates verifiable and tamper-proof random numbers for data verification and consensus. Encryption algorithms and digital signatures implement data encryption, decryption, access control, and privacy protection, while zero-knowledge proof (ZKP) ensures data security and privacy during access. Leveraging IPFS, a high-bandwidth, distributed, peer-to-peer off-chain storage solution is constructed. Smart contracts define rules and automate data access and management operations, enhancing system security and automation. Simulation experiments demonstrate significant efficiency, security, and scalability advantages over traditional centralized solutions, making it suitable for IIoT applications with large data volumes. Future work will focus on optimizing node communication, expanding experiments, and real-world deployment to further enhance system performance.
This paper focuses on the implementation of decentralized identity authentication system and designs an innovative algorithm based on blockchain technology, aiming to improve the security, privacy and decentralization of the system. The algorithm proposed in this study implements encrypted storage and distributed authentication of identity data through distributed ledger and smart contracts of blockchain, ensuring the privacy and data security of users. The hash function and zero-knowledge proof method are introduced, so that the user's identity information does not need to be transmitted in plain text during the verification process, further improving the security of the authentication process. The model simulation part uses real data sets to test the system many times, covering key performance indicators such as response time, authentication success rate, throughput and system load. The experimental results show that while ensuring security, the system's response speed has improved by about 18%. The authentication success rate is more than 99%, and it still maintains high stability under high concurrency conditions. These results verify the effectiveness and practicality of the proposed algorithm, and provide theoretical and technical support for the application of decentralized identity authentication system in the future.
In database applications involving sensitive data, the dual imperatives of data confidentiality and provable (verifiable) query processing are important. This paper introduces PoneglyphDB, a database system that leverages non-interactive zero-knowledge proofs (ZKP) to support both confidentiality and provability. Unlike traditional databases, PoneglyphDB enhances confidentiality by ensuring that raw data remains exclusively with the host, while also enabling verifying the correctness of query responses by providing proofs to clients. The main innovation in this paper is proposing efficient ZKP designs (called circuits) for basic operations in SQL query processing. These basic operation circuits are then combined to form ZKP circuits for larger, more complex queries. PoneglyphDB's circuits are carefully designed to be efficient by utilizing advances in cryptography such as PLONKish-based circuits, recursive proof composition techniques, and designing with low-order polynomial constraints. We demonstrate the performance of PoneglyphDB with the standard TPC-H benchmark. Our experimental results show that PoneglyphDB can efficiently achieve both confidentiality and provability, outperforming existing state-of-the-art ZKP methods.
In this research paper, we introduce a Kotlin application that assesses different security features on the Android SDK and executes them. The objectives are:1.Improving security of mobile phonesâThe most commonly used for m-payments; High-value targets, because they store substantial amount of personal information (especially financial details);2.Some of the available features include data obfuscation and anti-screenshot which is meant to be obedient with security guidelines set by RBI for financial apps.3.Zero-Knowledge Proof â enables the parties to verify facts about each other without sharing personal data and removes risks associated with unauthorized access or data breaches, significantly enhancing security for end-users.It is important to have this kind of initiative for any financial application that you develop, otherwise how can an app user trust your code and be sure it met all possible regulations?!
Ken Huang, Youwei Yang, Fan Zhang, Xi Chen · 5 authors
Chapter 5 explores the interconnected ecosystem enabling feature-rich smart contracts. It first covers oracles, which provide external data to blockchains, outlining use cases, design considerations, and business decisions around oracle solutions. It then discusses interoperability, explaining atomic swaps and various cross-chain bridge designs such as lock/mint, liquidity pools, and zkBridge for trustless transfers. Next, it examines the ecosystem for mitigating Miner Extractable Value (MEV), categorizing solutions into auctions, time/content-based ordering, and application-specific designs. It also highlights other vital components such as user-friendly wallets, performant RPC nodes, governance mechanisms for collective decision-making, and privacy-preserving techniques such as zero-knowledge proofs. By delving into these key building blocks, this chapter offers readers a comprehensive understanding of the dynamic smart contract ecosystem. It emphasizes how components such as oracles, bridges, MEV mitigation, governance, and privacy-preservation enable richer functionality, interoperability, fairness, and user experience, shaping decentralized applicationsâ future.
In crowd-sourced data aggregation over the Internet, participants share their data points with curators. However, a lack of strong privacy guarantees may discourage participation, which motivates the need for privacy-preserving aggregation protocols. Moreover, existing solutions remain limited with respect to public auditing without revealing the participantsâ data. In realistic applications, however, there is an increasing need for public verifiability (i.e., verifying the protocol correctness) while preserving the privacy of the participantsâ inputs, since the participants do not always trust the data curators. At the same time, while publicly distributed ledgers may provide public auditing, these schemes are not designed to protect sensitive information. In this work, we introduce two protocols, dubbed Masquerade and zk-Masquerade, for computing private statistics, such as sum, average, and histograms, without revealing anything about participantsâ data. We propose a tailored multiplicative commitment scheme to ensure the integrity of data aggregations and publish all the participantsâ commitments on a ledger to provide public verifiability. zk-Masquerade detects malicious participants who attempt to poison the aggregation results by adopting two zero-knowledge proof protocols that ensure the validity of shared data points before being aggregated and enable a broad range of numerical and categorical studies. In our experiments, we use homomorphic ciphertexts and commitments for a variable number of participants and evaluate the runtime and the communication cost of our protocols.
We give a short proof of the well-known Knuthâs old sum and provide some general- izations. Our approach utilizes the binomial theorem and integration formulas derived using the Beta function. Several new polynomial identities and combinatorial identities are derived.
In the context of the new era, the financing needs of enterprises grow significantly with the continuous expansion of their scale. However, in the financing process, small and micro enterprises often encounter challenges such as insufficient credit ratings, lack of working capital, difficulty in accessing information, and lack of guarantee mechanisms, while medium and large enterprises are more concerned about the security of confidential data. To address these challenges, this paper innovatively proposes a credit model based on zero-knowledge proof, ZKPrivateLoan, which combines blockchain technology with distributed zk-SNARK technology to not only efficiently generate proof of credentials of confidential data to ensure the security of data privacy, but also enhance the trust of commercial banks in the credit credentials of micro- and small enterprises. In addition, this paper also realizes the batch verification mechanism based on the ZKPrivateLoan model, which effectively reduces the verification time and blockchain uploading cost and provides a more efficient and secure solution for enterprise financing.
Ken Huang, Youwei Yang, Fan Zhang, Xi Chen · 5 authors
Chapter 4 examines the scaling of Web3 to support widespread adoption. It first discusses why scalability is crucial for Web3, enabling it to handle high transaction volumes and users such as centralized systems. Scalability refers to the ability to sustain performance amid growth. Key factors are number of users, response time, storage, transaction costs, and throughput. Scalability is challenging due to the blockchain trilemma of decentralization, security, and scalability. Solutions involve optimizations at the network layer (layer 0), blockchain layer (layer 1), and Off-chain layer (layer 2). Layer 0 focuses on data transfer, using protocols such as BloXroute. Layer 1 aims to improve the blockchain itself via methods like sharding or new consensus algorithms. Layer 2 leverages Off-chain processing via rollups, sidechains, and state channels. Each layer has trade-offs. Rollups bundle transactions Off-chain using zero-knowledge proofs or fraud proofs before validating On-chain. Sidechains process transactions externally to relieve the main chainâs load. State channels allow Off-chain transfers between participants. No single scaling approach fits all cases. A combination of solutions across layers tailored to the application offers the most potential.