A novel fair and efficient divisible E-Cash system based on the schnorr blind signature and non-interactive zero-knowledge proofs is proposed in this paper.In this system,both discrete logarithm and collision-resistance Hash function are used in the computation of divisible E-Cash.It contains the C value which defines the security.C can only be C1or be obtained by associated by C1and C2,where C1 is able to disclose the users' ID when over-spending happened.Moreover,the combination of and can realized owner tracing and coin tracing through the cooperation of B and T more easily.The scheme can also realize overspending tracing and over-deposit user,furthermore,it can limit the power of T,avoid the possibility of the association guilt between B and T.
For most present threshold signature schemes,sub-sign member can not sign a message anonymously or theirs anonymity is very weak.To improve their anonymity,a strong anonymity (n,t) threshold signature scheme based on DAA (Direct Anonymous Attestation),which is adopted by Trusted Computing Group v1.2 specifications,is proposed.Compared with the others,the scheme colligates DAA,zero-knowledge proof and Feldman verifiable secret sharing technique to achieve untraceable sub-sign and insure strong anonymity of signers,even the verifier and the dealer are colluded.Besides strong anonymity,analysis shows the scheme also has the property of unforgeable share,verifiable sub-sign,and robustness etc.It can be used in the situations which desire high-level anonymity such as anonymous voting.
This paper presents a property attestation protocol for the security chip TCM (trusted cryptographic module) via analyzing the problems of the current property attestation, which is built on the property attestation model with the online trust third party. In the protocol the prover utilizes the zero-knowledge proof by the attribute certificates, configuration commitment and TCM signature, and attests its configuration and status which are compliant with the declarative security property. The protocol is characterized by shorter signature length and lower computations. The security of the protocol is proved at the random oracle model. The protocol can help extend application and improve standard for security chip TCM, and it also has practical value and immediate significance.
A trusted small world Peer-to-Peer (P2P) model with role and reputation based access control policies (SW-R2P) was designed to combine the network topology and trust evaluation in P2P network.The model utilizes the zero knowledge interactive proof (ZKIP) scheme to authenticate the group information between peers without transferring any related data.The group information is used to cluster the peers to construct a small world topology.The Bayesian trust network is involved into the SW-R2P model to evaluate the multi-faceted trust of the peer and the group,which supporting the action protocols of peers and the long links between groups.Simulation shows that the SW-R2P model performs much better than the Chord and R2P models in the resources lookup,clustering coefficient and peer reputation error.The SW-R2P model integrates the advantages of small world topology,ZKIP scheme and Bayesian trust network,therefore implements a trustworthy,secure and efficient P2P network.
In order to solve the issue that existing direct anonymous attestation (DAA) scheme can not operate effectively in different domains,based on the original DAA scheme,a novel direct anonymous attestation protocol used in multi domains environment is proposed and designed,in which,the certificate issuer located in outside of domain can be considered as a proxy server to issue the DAA certificate for valid member nodes directly.Our designed mechanism accords with present trusted computing group (TCG) international specification,and can solve the problems of practical authentication and privacy information protection between different trusted domains efficiently.Compared with present DAA scheme,in our protocol,the anonymity,unforgeability can be guaranteed,and the replay-attack also can be avoided.It has important referenced and practical application value in trusted computing field.
The similarity of E-cash and E-lottery was taken into account to have designed a secure E-cash-lottery scheme by using zero-knowledge proof and blind signature on the basis of applications of the traditional lottery. This E-cash-lottery is characterized with anonymity, double stake resisting, forgery resisting, traceableness and off-line. For lottery players, banks, and lottery delivery to infer the identity of the winners by E-lottery is as difficult as for them to solve discrete logarithm. For lottery players to forge the E-cash or the E-cash-lottery is as difficult as for them to attack the RSA public key signature system. If there exists any repeated spending by using this E-cash- lottery, the bank can certainly determine the identity of the spender. Compared with the traditional lottery, the anonymity and privacy of the E-cash-lottery were preferable.
Advanced Steganography and Watermarking Techniques
This paper proposes a new undeniable signature scheme which uses one-way function and partition-selection method to proof its zero-knowledge respectively. The main idea is to protect the signer of a document against the document being digitally distributed without knowledge of signer. And we show that our scheme is so effective that message exchange only needs much fewer times during the confirmation protocol and disavowal protocol respectively. which is very useful for poor network environment keeping the communication times with both sides as few as possible. And our scheme allows verifier to verify that the signature is valid, while the signer doesn't know the original message and the signature, to preserve the privacy of the verifier.
The WS-BPEL specification focuses on business processes the activities of which are assumed to be interactions with Web services. However, WS-BPEL processes go beyond the orchestration of activities exposed as Web services. There are cases in which people must be considered as additional participants to the execution of a process. The inclusion of humans, in turn, requires solutions to support the specification and enforcement of authorizations to users for the execution of human activities while enforcing authorization constraints. In this paper, we extend RBAC-WS-BPEL, a role-based authorization framework for WS-BPEL processes with an identity attribute-based role provisioning approach that preserves the privacy of the users who claim the execution of human activities. Such approach is based on the notion of identity records and role provisioning policies, and uses Pedersen commitments, aggregated zero knowledge proof of knowledge, and Oblivious Commitment-Based Envelope protocols to achieve privacy of user identity information.
Federica Paci, Ning Shang, Sam Kerr, Kevin Steuer · 6 authors
Users increasingly use their mobile devices for electronic transactions to store related information, such as digital receipts. However, such information can be target of several attacks. There are some security issues related to M-commerce: the loss or theft of mobile devices results in a exposure of transaction information; transaction receipts that are send over WI-FI or 3G networks can be easily intercepted; transaction receipts can also be captured via Bluetooth connections without the user's consent; and mobile viruses, worms and Trojan horses can access the transaction information stored on mobile devices if this information is not protected by passwords or PIN numbers. Therefore, assuring privacy and security of transactions' information, as well as of any sensitive information stored on mobile devices is crucial. In this paper, we propose a privacy-preserving approach to manage electronic transaction receipts on mobile devices. The approach is based on the notion of transaction receipts issued by service providers upon a successful transaction and combines Pedersen commitment and Zero Knowledge Proof of Knowledge (ZKPK) techniques and Oblivious Commitment-Based Envelope (OCBE) protocols. We have developed a version of such protocol for Near Field Communication (NFC) enabled cellular phones.
A publicly verifiable multi-secret sharing scheme is proposed, using non-interactive zero-knowledge proof protocol and Shamir’s sharing system. The security of the scheme is based on the intractability of integer factorization problem and discrete logarithm problem. The validity of the sharing distributed by the dealer can be verified by anyone. Recovering the secret, participants only need to provide a shadow of the sharing. It is difficult to get the sharing from the shadow. So the sharing can be reused to share the multi-secret. Moreover, the validity of the shadow can also be verified by anyone. So the scheme is secure, efficient, and can prevent both dealer and participant from cheating.
A practical publicly verifiable secret sharing (PVSS) is constructed based on the bilinear pairing on elliptic curves, which has all advantages of B. Schoenmakerspsila PVSS and its secret is not the form of discrete logarithm, thus this PVSS is extremely practical. Moreover, in the schemepsilas distribution of shares phase, only using bilinearity of bilinear pairing, anybody can verify whether the participants received correct shares without implementing zero-knowledge proofs, without implementing the non-interactive protocol and without construction so called witness of shares applying Fiat-Shamirpsilas technique. Subsequently, in the schemepsilas reconstruction of secret phase, the released shares may be verified by anybody with the same method. Since the PVSS need not to implement non-interactive protocol to prevent malicious players. Therefore this scheme is simpler, more efficient and practical suitable for some especially case.
The main objective of this project was to design, develop and validate a digital signature in a security device for telemedicine applications. Medical domain requires high security conditions for archiving since the information to be protected contains images, diagnosis, personal information of the patients and physicians involved in the telemedicine process. The developed strategy consists in a USB device which allows proper authentication in the information system using a conventional public-private key scheme, through a zero knowledge proof algorithm that guarantees the privacy of the personal password. Once the user is accepted, the device also makes possible the generation of the digital signature required for generated documents.
Remote attestation is an important attribute in trusted computing. One of the purpose of remote attestation is to attest the remote platform is trusty but not revealing the actual identity of the platform. Direct anonymous attestation (DAA) is a kind of scheme which is adopted by Trusted Computing Group in the specification 1.2 to hide the privacy of the platform. But DAA involves various of zero-knowledge proofs and is not efficient to implement. To guarantee the trustworthiness and privacy, we propose a remote anonymous attestation protocol based on ring signature in this paper. We also show that our protocol is secure under the RSA assumption in random oracle model. Furthermore, the attestation protocol does not need the third party and extra zero-knowledge proof, which makes it very efficient in realization.
Tianjie Cao, Shi Ming Huang, Hui Cui, Yipeng Wu · 5 authors
How to leak authoritative secrets in an elegant way? The paper aims to solve this problem. The desired security properties i.e. Semantic-Security; Recipient-Designation; Verification-Dependence; Designated-Verifier Signature-Verifiability; Public Signature-Verifiability; Recipient-Ambiguity; Designated-Verifier Recipient-Verifiability; Public Recipient-Verifiability; Signer-Ambiguity; Signer- Verifiability are specified in secret leakage. Based on Chow-Yiu-Hui's ID-based ring signature scheme and techniques of zero-knowledge proof, an ID-based controlled secret leakage scheme is proposed. The proposed scheme satisfies all specified security properties and can be used in trust negotiation.
Zero knowledge sets is a new cryptographic primary in- troduced by Micali, Rabin, and Kilian in FOCS 2003. It is intensively investigated recently. However all schemes follow the basic frame by Micali et al. That is, the schemes employ Merkle tree as basic frame and mercurial com- mitments as commitment units to nodes of the tree. The proof for any query constitutes of an authentication chain. We propose in this paper a new algebraic scheme that is completely different from all existing schemes. The new scheme is computationally secure under standard assump- tion: Strong RSA assumption. It employs neither mercurial commitments nor tree frame as all previous schemes did. In fact, the prover (also as the committer) in our construc- tion commits the desired set without trapdoor information, which is another important difference from the previous ap- proaches.