Garima Misra, Bramah Hazela, Brijesh Kumar Chaurasia
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,104 results · page 14 of 46
Garima Misra, Bramah Hazela, Brijesh Kumar Chaurasia
No abstract is available for this record.
Riaz Ahmed Khan, Saba Mushtaq, Sajaad Ahmed Lone, Rajesh Gupta · 5 authors
No abstract is available for this record.
Indukuri Mani Varma, Neetesh Kumar, Novella Bartolini
The Internet of Vehicles facilitates seamless Vehicle-to-Everything (V2X) communication, offering a myriad of services ranging from traffic management to data exchange and route scheduling. However, the existence of malicious Autonomous Vehicles (AVs) poses significant security and privacy threats to data communications and vehicle users, respectively. Therefore, it is crucial to verify the identity and preserve the privacy of AVs before offering V2X services within each vehicular broadcast domain. To address the aforementioned issues, a novel privacy-preserving lightweight Fast Reed-Solomon Interactive Oracle Proof of Proximity using polynomial commitment-based authentication protocol is presented. The AVs are initially registered with a trusted authority in this protocol. After that, they are authenticated by roadside units in their respective broadcast domains using a zero-knowledge proof-based challenge-response mechanism. As per the performance analysis, the proposed protocol surpasses state-of-the-art authentication protocols and achieves notable improvements of 19.43% in registration computation time, 50.96% in registration latency, 89.75% in authentication computation time, 14.97% in authentication latency, 97.42% in handover computation time, and 95.84% in handover latency, compared to other protocols. A qualitative security analysis is also carried out to prove that the proposed protocol provides anonymity, privacy, user verifiability, and untraceability features.
Qiuli Wang, Zhiyu Ren, Cao Yajun
The advancement of Industrial Internet of Things (IIoT) has enabled cross-domain collaboration among enterprises, facilitating data exchange and coordinated operations for complex manufacturing tasks. As the primary security mechanism, cross-domain continuous authentication periodically verifies external devices to prevent unauthorized access and session hijacking, thereby mitigating system vulnerabilities. However, existing solutions face limitations: some rely on device-specific features incompatible with heterogeneous environments, while others neglect cross-domain scenarios, offering insufficient privacy protection and irreversible identity management. To address these gaps, we propose a cross-domain authentication framework leveraging zero-knowledge proofs and blockchain technology. Devices are assigned anonymous identities, with revocation managed via a distributed ledger. Initial authentication employs zero-knowledge proofs to generate valid tokens, while continuous authentication refreshes these tokens periodically. Security analysis confirms robustness against common threats, and performance evaluations demonstrate that periodic token renewal reduces computational and communication costs compared to repeated initial authentication processes.
Ru Li, Jie Cui, Jing Zhang, Lu Wei · 6 authors
With the rapid development of vehicular ad-hoc networks (VANETs) and the increasing diversification of user demands, interactions between different management domains have become more frequent. Identity authentication is an effective way to establish cross-domain trust and secure communication. However, the existing cross-domain authentication schemes of VANETs are limited to the same management or authentication technology for each domain and rely on centralized cross-domain identity management. Even distributed management solutions encounter latency sensitivity, security and privacy challenges. To address these challenges, we propose a blockchain-assisted revocable cross-domain authentication scheme for VANETs. The proposed scheme can establish trust between domain entities by deploying different authentication methods and using distributed management to avoid single-point failures. In addition, the scheme can revoke the identity of malicious vehicles by updating the group public key, thereby ensuring the security and privacy of cross-domain Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. This design avoids the additional impacts of blockchain technology constraints on the high mobility and real-time requirements of VANETs. Security analysis and performance evaluation show that our scheme can resist more attacks and has better security than other related schemes while also achieving a better balance between communication and computational cost.
Mohsen Minaei, Pedro Moreno-Sánchez, Zhiyong Fang, Srinivasan Raghuraman · 8 authors
We propose Data Tumbling Layer (DTL), a cryptographic scheme for non-interactive data tumbling. The core concept is to enable users to commit to specific data and subsequently re-use to the encrypted version of these data across different applications while removing the link to the previous data commit action. We define the following security and privacy notions for DTL: (i) no one-more redemption: a malicious user cannot redeem and use the same data more than the number of times they have committed the data; (ii) theft prevention: a malicious user cannot use data that has not been committed by them; (iii) non-slanderabilty: a malicious user cannot prevent an honest user from using their previously committed data; and (iv) unlinkability: a malicious user cannot link tainted data from an honest user to the corresponding data after it has been tumbled. To showcase the practicality of DTL, we use DTL to realize applications for (a) unlinkable fixed-amount payments; (b) unlinkable and confidential payments for variable amounts; (c) unlinkable weighted voting protocol. Finally, we implemented and evaluated all the proposed applications. For the unlinkable and confidential payment application, a user can initiate such a transaction in less than $1.5$s on a personal laptop. In terms of on-chain verification, the gas cost is less than $1.8$ million.
Saeed Shokrollahi, Mahtab Dehghan
No abstract is available for this record.
Yeming Yang, Shuaichao Song, Songhui Guo
Currently, PAKE (Password Authenticated Key Exchange) protocols on lattice using a single-server architecture are widely applied. However, such protocols are vulnerable to server leakage attacks, dictionary attacks, and other threats. To address these issues, researchers have proposed multi-server and two-server architecture-based PAKE protocols. However, PAKE protocols in a multi-server architecture require the use of complex cryptographic primitives such as signatures, and zero-knowledge proofs to ensure security, which reduces the execution efficiency of the protocol. To tackle these challenges, we propose two new multi-server password authentication key exchange protocols based on the MLWE (Module learning with errors) problem. Both protocols rely on MLWE instances, using Peikert's error coordination technique to enable two parties with similar values to compute the same result. Furthermore, we introduce the error pairing assumption and proves its security within random oracle model. The proposed protocol divides the password information into different shares and stores them on separate servers. In protocol 1, all servers and user collaboratively generate session keys, making it suitable for high-security application scenarios. In protocol 2, both user and servers generate session keys individually, which is ideal for high-efficiency application scenarios. Compared to similar protocols, both protocols lower computation and communication costs, better addressing practical application needs while providing protection against quantum computing attacks and server leakage threats.
Phuc-Hung Pham Le, Trung-Tin Tran, Toan Q. Dinh, Quy N.
As end-to-end encryption (E2EE) becomes the standard for secure communication, ensuring message authenticity while maintaining user privacy poses significant challenges.This paper introduces the BL0K-ME protocol, a novel cryptographic solution that combines Zero-Knowledge Proofs (ZKP), RSA encryption, and Bloom filters to authenticate individual messages within E2EE conversations.RSA encryption is employed to secure the transmission of messages between users, ensuring that only the intended recipient can decrypt the content, while ZKP enables third-party verification of specific message content without exposing the entire conversation.By leveraging Bloom filters, the protocol provides efficient logging and verification of message existence, balancing privacy protection with legal and regulatory requirements for digital evidence.BL0K-ME addresses a critical gap in current messaging systems by allowing service providers to verify message authenticity for legal investigations without compromising the confidentiality of unrelated communications.This research demonstrates the potential of integrating RSA encryption, ZKP, and Bloom filters to offer a scalable, secure solution for message authentication in E2EE systems, safeguarding both user privacy and the integrity of digital evidence.
Chao Geng, Yang Zhang, Xin Xu, Yingbiao Yao · 6 authors
No abstract is available for this record.
Deepika Gautam, Garima Thakur, Sunil Prajapat, Pankaj Kumar
No abstract is available for this record.
Yeming Yang, Shuaichao Song, Songhui Guo
Currently, PAKE (Password Authenticated Key Exchange) protocols on lattice using a single-server architecture are widely applied. However, such protocols are vulnerable to server leakage attacks, dictionary attacks, and other threats. To address these issues, researchers have proposed multi-server and two-server architecture-based PAKE protocols. However, PAKE protocols in a multi-server architecture require the use of complex cryptographic primitives such as signatures, and zero-knowledge proofs to ensure security, which reduces the execution efficiency of the protocol. To solve these problems, we propose a two-server PAKE protocol on the lattice based on the MLWE (Module learning with errors) problem. The protocol is built using instances of the MLWE problem and utilizes the Peikert error coordination technique, which ensures both parties with similar values arrive at the same result through computation. Additionally, we introduce the error pairing hypothesis and demonstrates its security within the random oracle model. The protocol securely stores different shares of password information across various servers. This approach protects user password data, even if one of the servers is compromised. Compared to similar protocols, we avoid the use of numerous cryptographic primitives, and can better resist quantum computing attacks and server leakage. And we reduce computational and communication costs, and can better meet practical application needs.
Charlotte Hoffmann
Atoms and photons, two things so different but yet so alike. The former, the building block of matter, something we learn about in school and imagine it as some tiny marbles encircled by other tinier marbles. The latter, an electromagnetic wave, a light particle or an excitation of the electromagnetic field. Quantum mechanics tells us about the properties of these two entities. And even if it sounds, looks and writes counter-intuitive, it has proven right for over a century now. In this work, I elaborate on how we tested the laws of quantum mechanics and how we used them learn more about the tiny building blocks of nature and the fields they use to talk to each other. The atoms we use, are artificial. Superconducting qubits, small electrical circuits with quantized energy levels behave like electrons that transition between different orbitals in an atom. One of the qubits' advantages, is also a big disadvantage. We design the circuits' energy levels and fabricate them in a cleanroom. This allows for arbitrary spaced energy levels but in contrast to real atoms, prevents two superconducting qubits from being alike. Still, this qubit platform is one of the frontrunners for future quantum computing technology and testing fundamental physics due to their scalability. We interface superconducting qubits, which operate in the GHz regime, with microwave photons. We use 3D aluminum cavities as mediators between qubits and photons. The cavities allow for non-destructive readout of the qubit state, they shield the qubits from noise at the qubit frequency and they give us an easy way to frequency-tune these joint systems. We need to operate superconducting qubits and their cavities at millikelvin temperatures in dilution refrigerators. At higher temperatures, superconductivity suffers and even worse, the environment is filled with thermal noise photons. This poses a fundamental limitation on the scalability of superconducting qubit devices. Also connecting multiple devices in different fridges does not work over room temperature links because the microwave photons used for this purpose will be covered in noise and the quantum information they carry, will be unusable. Infrared photons do not suffer from this noise problem since there are close to zero thermal noise photons at their frequencies at room temperature. We cannot simply interface superconducting devices with optical photons due their frequency mismatch and the destructive effect of optical photons on superconductors. Therefore, we use microwave-to-optics transducers that allow to convert microwave photons into optical ones and vice-versa. The transducers that we use are macroscopic electro-optic transducers using the Pockels effect in a disk-shaped Lithium Niobate whispering gallery mode resonator. By using a strong optical pump, photons from the two frequency domains experience a beam-splitter interaction and get converted from one to the other. We measure the generated optical photons using elaborate optical setups, optical heterodyning and single photon detectors to gain knowledge about the qubit state or the converted microwave photons. Bridging the microwave and the optical world allows us to take advantage of both of their strengths but it also requires deep knowledge about both of their working principles. In this work, we describe two experiments that our group conducted to showcase the opportunities that arise from interfacing superconducting qubits with optical photons but also the pitfalls, one may encounter on the way. In the first experiment, we managed to all-optically read out a superconducting qubit. We show that the assignment fidelity, the probability that a measurement of the qubit state matches the prepared state, is close to equal for all-optical, microwave-to-optics and conventional microwave readout. We show T1 and T2 measurements for all three readout types and give an analysis of the noise caused by the optics. Finally, we show that the infrared light does not affect the qubit performance in a negative way but that the heating it causes does. This is an important insight that we used in the next experiment. The second experiment is the upconversion of itinerant single microwave photons to the optical domain. We show that we can generate single microwave photons from a qubit-cavity system. We upconvert these single photons, measure them with a single photon detector and reconstruct their shape. By conducting a single photon Rabi measurement, we show correlations between the microwave and the optical domain. And by thorough signal-to-noise measurements and noise analysis, we find that we can generate single infrared photons with high signal-to-noise ratio 5.1 and low transducer added noise (<0.012 quanta). We show that this measurement creates a path towards entanglement of a superconducting qubit and an optical photon and what parameters need to be improved to achieve it. Additionally, this experiment is a proof of principle for an on-demand infrared single photon source. More generally, it allows to link microwave quantum technology in general to the optical domain.
航 车
随着信息技术的快速发展,数据安全和用户的隐私越发受到重视。本文提出了一种匿名认证密钥交换(Anonymous Key Exchange, AKE)协议,旨在为医疗场景下的医疗数据共享和患者身份隐私提供安全和隐私的保护。该方案通过使用累加器、零知识证明和关联数据加密等技术,实现用户匿名的认证和安全的会话密钥协商,有效防止敌手对于用户和医用物联网设备的攻击,还能抵御诚实且好奇的医疗机构对患者身份的猜测。相较于现有的方案提供了更强的隐私安全保护,并且很好地平衡了性能和安全性,具有重要的理论价值和意义。With the rapid development of information technology, data security and user privacy have been paid more and more attention. This paper proposes an Anonymous authenticated Key Exchange (AKE) protocol to provide security and privacy protection for medical data sharing and patient identity privacy in medical scenarios. By using accumulator, zero-knowledge proof and associated data encryption technology, the scheme realizes anonymous user authentication and secure session key agreement, which effectively prevents adversaries from attacking users and medical IoT devices, and can resist honest and curious medical institutions from guessing the patient’s identity. Compared with the existing schemes, it provides stronger privacy security protection, and a good balance between performance and security, which has important theoretical value and significance.
Jianhong Zhang, Qing Ji, Chuming Shi
Multi-signatures have recently garnered considerable attention, particularly within the domain of smart contracts in blockchain ecosystems, as they enhance account security and mitigate single points of failure by requiring the approval of multiple key holders for transaction execution. However, most existing multi-signature schemes heavily rely on traditional Public Key Infrastructure (PKI), which requires a trusted authority and conflicts with the decentralized nature of blockchain technology. Certificateless multi-signature (CLMS) schemes, which eliminate the requirement for a trusted authority, represent promising solutions to address this issue. Nevertheless, existing CLMS schemes encounter challenges that limit their suitability for smart contract applications, including high communication overhead, expensive verification costs, and “loose" security reductions. To address these challenges, we propose two novel two-round certificateless multi-signature schemes. These schemes not only support key aggregation but also optimize the signing process with two-round communication, maintaining fixed computational overhead during verification. Furthermore, the security proofs for the proposed schemes are independent of the Forking lemma, resulting in tighter security reductions and strengthened security assurance. Finally, experimental results demonstrate that the proposed schemes significantly reduce both communication and computational overhead compared to existing CLMS schemes, making them more efficient and practical for blockchain-based smart contract applications.
Zibin Lin, Taotao Wang, Junhao Lai, Shengli Zhang · 6 authors
No abstract is available for this record.
Yashika Gaidhani
In this age of always-on connection, it is very important to keep data safe while also protecting user privacy. In today's networks, where data travels through many pathways, such as cloud services and IoT devices, cryptographic algorithms are very important for keeping private data safe. But it's still exceptionally difficult to create beyond any doubt that information is secure without putting people's protection at chance. This conversation goes into detail almost privacy-preserving security strategies, looking at their significance, issues, and other ways to solve them. The objective of privacy-preserving cryptographic strategies is to create beyond any doubt that private information is kept secure whereas still permitting secure contact and computation. To keep data secure from individuals who shouldn't have get to to it, these frameworks utilize diverse sorts of cryptography, like encryption, hashing, and secure multi-party computation (SMPC). Information spills and illicit observing are less likely to happen with these methods because they cover up information at diverse steps of exchange and handling. Indeed in spite of the fact that they may well be useful, privacy-preserving cryptographic strategies have a number of issues. Finding a great blend between client security and information security is one of the most issues. Extreme security measures may offer assistance keep information secure, but they frequently include collecting information in ways that are as well intrusive and abuse people's security. On the other hand, putting as well much accentuation on protection might make security weaker, taking off information open to being abused. Finding a cautious adjust between these competing objectives is key to making cryptographic frameworks that work well. A few potential methods that permit secure information taking care of whereas ensuring security are homomorphic encryption, differential protection, and zero-knowledge proofs. Improvements in hardware-accelerated cryptography and distributed computing tools also make it possible to speed up secure processes and make them more scalable.
Gaurav Kumawat, Tapan Kant, Vivek Bhardwaj, Mukesh Kumar · 6 authors
Password-based authentication systems are vulnerable to a variety of security risks, such as phishing, credential theft, and user fatigue due to complex password requirements. This paper introduces a novel passwordless authentication framework that leverages advanced cryptographic techniques, including Zero-Knowledge Proofs (ZKP), Secure Multi-Party Computation (SMPC), and Homomorphic Encryption to enhance security, privacy, and user experience. The proposed system eliminates the need for traditional passwords by utilizing biometric data to generate cryptographic keys, ensuring that sensitive information remains secure. The architecture is composed of three primary components: the client device, the authentication server, and the key management system (KMS). The client device captures biometric data and transforms it into cryptographic keys using SMPC, while the server verifies the authentication using ZKP and establishes secure communication channels via Diffie-Hellman key exchange. The KMS handles key generation, storage, and rotation to ensure secure communication. Evaluation results show that the system is highly resistant to common attack vectors such as replay and man-in-the-middle attacks, with a 0% attack success rate. Performance analysis reveals an average authentication time of 180 ms, which is 10% faster than WebAuthn.
Veri, Hans Kristjan
The rise of quantum computing threatens to break many of the cryptographic systems that secure today’s digital world. In response, researchers are developing new tools designed to remain secure in a post-quantum future. Most of the promising candidates for post-quantum digital signatures rely on security assumptions based on lattices or properties of hash functions. Another promising approach transforms secure multi-party computation protocols into zero-knowledge proofs, which are then turned into digital signatures. This technique, known as multi-party computation in-the-head (MPCitH), offers strong security properties and flexibility for distributed applications. This thesis investigates whether MPCitH digital signatures can be efficiently adapted for use by two cooperating parties to jointly produce a signature. Here we show how to construct two-party signatures based on syndrome decoding in-the-head (SDitH) signatures. We propose a provably secure scheme that achieves the smallest known communication overhead among two-party MPCitH signatures, while resulting in a signature size approximately double that of a single-prover variant. This result provides a new data point in the design space of multi-party MPCitH signatures and post-quantum digital signatures in general.
Jeremies Enmanuel Chinchay Camargo, Massiel Fiorella Parvina Huaman, Carmen Luz Cuba Cornejo, Cesar Augusto Cabrera Garcia
Digital electoral security has become fundamental to the development of reliable, integrated and available technological systems, driven by the growing demand for transparency and protection against threats. The purpose of this study is to analyze the impact of cryptographic protocols on the security of electoral processes, evaluating their effectiveness against traditional methods. For this purpose, a systematic review of the literature was carried out, considering 50 articles extracted from the Scopus database. The analysis focused on cryptographic techniques applied to blockchain-based environments, such as homomorphic encryption, zero-knowledge proofs and smart contracts, evaluating their contribution to design more secure, auditable and reliable voting systems. The results show that these protocols contribute to prevent recurring vulnerabilities, such as vote tampering, electoral fraud, impersonation and lack of validation, in addition to strengthening auditability and operational reliabilityFinally, the study concludes that the adoption and assessment of cryptographic protocols are essential to reduce risks in electronic voting, and promote more secure, transparent and efficient electoral processes.
Mohuya Chakraborty, Sudip Kumar Palit
No abstract is available for this record.
Hongguo Zhang, Yun-Ming Sun, Kaiqi Zhang, Zhibo Guan · 6 authors
With the rapid expansion of digital asset trading, the contradiction between data sharing and privacy protection has increasingly become a significant challenge in the Internet environment. To address this issue, this paper proposes a secure multi-party computation scheme based on blockchain technology. Firstly, in response to the risk of data leakage in distributed storage scenarios, a threshold-based encryption algorithm is designed, utilizing a distributed key protection mechanism to effectively prevent single-point failures and data breaches. Secondly, a smart contract system is developed: the ERC721 contract is used to confirm the ownership of data assets, the ERC20 contract facilitates the transfer of usage rights, and the threshold decryption contract ensures secure multi-party computation and compliant incentive distribution. The collaboration of these three types of contracts enables comprehensive on-chain management of data assets, covering the entire process from ownership confirmation and circulation to compliant usage. In addition, this paper integrates non-interactive zero-knowledge proofs into the multi-party interaction process, allowing public verification of data consistency and computational validity on the blockchain. Finally, experiments are conducted to evaluate the impact of computation latency, communication overhead, and encryption parameters on system performance. The proposed scheme demonstrates significant performance improvements over mainstream SMPC protocols, with a 95.4 % reduction in key generation time and a 19.5 % reduction in ciphertext decryption time. Meanwhile, the scheme effectively resists various semi-malicious attacks, ensuring data security and privacy. • A t-out-of-N threshold ElGamal-based MPC scheme is proposed for secure computation in synchronous environments. • A blockchain smart contract framework manages data assets' lifecycle by combining ERC721/ERC20 and threshold decryption. • A method verifies on-chain data consistency and computation validity using non-interactive zero-knowledge proofs.
Aditya Kapoor
No abstract is available for this record.
Carmen Wabartha
The end-to-end verifiable e-voting system Ordinos [26] is primarily characterized by its tally-hiding property, which ensures that only the actual election result, e. g., the winner of the election, is revealed while the full tally consisting of the aggregated votes stays hidden. Ordinos is an abstract model that guarantees tally-hiding, verifiability and vote privacy if the underlying cryptographic primitives satisfy certain requirements. It uses a multi-party-computation protocol over an additively homomorphic encryption scheme and guarantees active security with zero-knowledge proofs. Ordinos has already been instantiated for several election systems using the Paillier [35] encryption scheme, which can be broken by Shor’s algorithm [41]. The aim of this thesis is to instantiate Ordinos post-quantum secure using a variant of Regev’s LWE-based cryptosystem [39], which is adapted to realize an actively secure threshold encryption scheme over an arbitrary plaintext space. Then a noise analysis of the arithmetic and logical components used in the MPC-protocol of the Paillier instantiation is conducted, and the components are slightly adapted to restrict the noise growth. Additionally, valid zero-knowledge proofs are provided and a concrete instantiation achieving a security level of 128 bits is shown.