For electronic voting (e-voting) with a trusted authority, the ballots may be discarded or tampered, so it is attractive to eliminate the dependence on the trusted party. An e-voting protocol, where the final voting result can be calculated by any entity, is known as self-tallying e-voting protocol. To the best of our knowledge, addressing both abortive issue and adaptive issue simultaneously is still an open problem in self-tallying e-voting protocols. Combining Ethereum blockchain with cryptographic technologies, we present a decentralized self-tallying e-voting protocol. We solve the above problem efficiently by utilizing optimized Group Encryption Scheme and standard Exponential ElGamal Cryptosystem. We use zero-knowledge proof and homomorphic encryption to protect votes' secrecy and achieve self-tallying. All ballots can be verified by anyone and the final voting result can be calculated by any entity. In addition, using the paradigm of score voting and โ1-out-of-$k$โ proof, our e-voting system is suitable for a wide range of application scenarios. Experiments show that our protocol is more competitive and more suitable for large-scale voting.
Mwaffaq Abu AlHija, Osama Al-Baik, Abdelrahman H. Hussein, Hikmat A. M. Abdeljaber
The adoption of blockchain technology provides significant disruptive benefits to internet-of-things (IoT) applications in healthcare in vital aspects like security, integrity, transparency, and efficiency. Nevertheless, in order to fully realize the potential of blockchain-driven solutions, healthcare organizations have to address intricate compromises between essential factors including scalability, privacy and resource utilization considering that the data sensitivity alongside strict regulatory compliance requirements characterize this sector. This research discusses the fundamental aspects of these trade-offs, including the range of consensus protocols (e.g. proof-of-work, proof-of-stake) and cryptographic techniques (e.g. zero-knowledge proofs, homomorphic encryption). A systematic choice matrix is created, which relates specific use cases of the healthcare IoT to the optimal tailored blockchain structures on such critical metrics as transaction volume, frequency, privacy level and resource restrictions. The suggested framework provides solid, actionable recommendations to healthcare organizations in order to help them benefit from the enormous promise of the blockchain for connected IoT healthcare by finding a balance between decentralization advantages and performance, security and compliance requirements.
In each issue of Communications , we publish selected posts or excerpts from the many blogs on our website. The views expressed by bloggers are their own and not necessarily held by Communications or the Association for Computing Machinery. Read more blogs and join the discussion at https://cacm.acm.org/blog. https://cacm.acm.org/blog An examination of the intricate world of zero-knowledge proofs and how they may be used to enhance blockchain security and privacy.
Gigi Yong, Sherene Tyng Xin Saw, Jhen Nee Tang, Teng Li ยท 6 authors
In the domain of Industrial Internet of Things (IIoT), the demand for robust and secure methods for goods tracking and management has become growingly critical. Conventional methods face significant challenges, including authentication, computational overhead, cyber security, and data integrity. To address these issues, this paper proposes a block-chain based system for goods management and tracking with enhanced authentication mechanism by leveraging the decentralized nature of block-chain technology and integrating Elliptic Curve Digital Signature Algorithm (ECDSA) with Elliptic Curve Cryptography-Zero Knowledge Proof (ECC-ZKP). The proposed solution aims to ensure the authenticity and the integrity for all the transaction while providing high level privacy-preserving verification without revealing information. The research in this paper demonstrates that the proposed block-chain-based system significantly enhances security performance, key management and operational efficiency, addressing the existing challenges in IIoT goods tracking and management, providing a resilient framework for more secure industrial operations in managing goods.
This research evaluates how blockchain technology transforms data security functions, especially regarding privacy protection. The rise of decentralized systems led to Blockchain emerging as an answer for resolving traditional data security problems from breaches to centralization risks. This research investigates blockchain technology, which advanced from its initial cryptocurrency framework into an all-encompassing data protection solution. Research shows that Blockchain improves privacy through encryption methods and distributed operations. A qualitative research approach enables examination of blockchain solutions with privacy components alongside analysis of zero-knowledge proofs and decentralized storage facilities. Technology solutions provide users with comprehensive data visibility and reduce exposure to unauthorized intruders and free them from central control systems. The adaptive security structure of blockchain technology functions as the industry-leading answer to privacy breaches by establishing strengthened data protection protocols for all operational activities.
Quantum cryptography represents a revolutionary paradigm shift in Smart contracts enable decentralized automation of agreements on blockchain platforms, enhancing transparency and trust. However, their immutable and public nature exposes them to various security vulnerabilities, including data leakage, unauthorized access, and execution flaws. This article explores advanced cryptographic solutions to secure blockchain smart contracts, focusing on zero-knowledge proofs, homomorphic encryption, multi-signature schemes, and secure multi-party computation. Through an in-depth analysis, the paper evaluates these cryptographic methods for their effectiveness in safeguarding confidentiality, integrity, and privacy of smart contract operations. Two comparative graphs illustrate the trade-offs between security strength, computational overhead, and privacy enhancement. The study concludes by highlighting future directions for optimizing cryptographic implementations to balance security and scalability.
Gautam Mandoliya, Geet Kiran Kaur, Anmol Tyagi, Sanjay Singla
This paper introduces a novel approach to revolutionize public transport ticketing systems through the integration of decentralized technologies, namely cryptocurrency and NFTs utilizing a decentralized wallet storing both cryptocurrency for payments and NFT-based digital identities containing user credentials. This system empowers users with granular control over data privacy through on-device verification requests and zero-knowledge proofs, promoting standardization, decentralization, and enhanced user privacy in public transportation ticketing system.
The science and technology service industry is an indispensable part of the innovation system. Since the science and technology service transaction is platform dependent, they have the drawbacks of centralized transactions. As these services involve intellectual property, it is critical to preserve the confidentiality of transaction information. To address this issue, this study builds a science and technology service framework, which includes a provider and a demander, data temporary storage, timestamp and confidentiality verification, followed by the construction of a confidentiality mechanism for science and technology service transactions based on zero-knowledge proof technology. This mechanism can decentralize science and technology service transactions and keep the information of both parties confidential, which can promote the effective circulation of science and technology information. Finally, from the perspectives of economic value, industrial value, and commercial value, this study analyzes the value of combining blockchain with technology service transactions, considering the practical significance in promoting the development of scientific and technological services.
Instant Runoff Voting (IRV) is one example of ranked-choice voting. It provides many known benefits when used in elections, such as minimising vote splitting, ensuring few votes are wasted, and providing resistance to strategic voting. However, the voting and tallying procedures for IRV are much more complicated than those of plurality and are both error-prone and tedious. Many automated systems have been proposed to simplify these procedures in IRV. Some of these also employ cryptographic techniques to protect the secrecy of ballots and enable verification of the tally. Nearly all of these cryptographic systems require a set of trustworthy tallying authorities (TAs) to perform the decryption of votes and/or running of mix servers, which adds significant complexity to the implementation and election management. We address this issue by proposing Camel: an E2E verifiable solution for IRV that requires no TAs. Camel employs a novel representation and a universally verifiable shifting procedure for ballots that facilitate the elimination of candidates as required in an IRV election. We combine these with a homomorphic encryption scheme and zero-knowledge proofs to protect the secrecy of the ballots and enable any party to verify the well-formedness of the ballots and the correctness of the tally in an IRV election. We examine the security of Camel and prove it maintains ballot secrecy by limiting the learned information (namely the tally) against a set of colluding voters.
Today's digital revolution is built on the fusion of blockchain technology and cryptography. This paper examines how cryptographic algorithms support blockchain network security, integrity, and decentralization by delving into the complex interactions between these fields. We explore the landscape of cryptographic techniques that guarantee transactions and block authenticity through a thorough discussion. We also delve into the creation and administration of cryptographic keys within blockchain ecosystems and reveal the cryptographic underpinnings of consensus mechanisms. This paper also covered zero-knowledge proofs, multi-party computation, scalable solutions, secure cooperation, and the effective development of post-quantum cryptography. The findings shed light on a secure, inclusive, and radically transformational future powered by blockchain technology.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The widespread developments of blockchain bring about diverse blockchain networks, where each stands as an isolated data island and operates independently. The need of interoperability and interconnection among kinds of blockchains inspires the emergence of the cross-chain technology. It enables the asset transfer and information interaction via crosschain transactions. The previous cross-chain transaction systems are almost implemented over the plain data, fully exposing the transaction-associated information. Cryptographic techniques such as non-interactive zero-knowledge proof can be used to protect the transaction privacy, while its high complexity incurs heavy running cost. The privacy of cross-chain transactions is still a challenging issue. In this paper, we propose a lightweight crosschain transaction privacy-preserving method named PTCross. It embeds Bulletproofs and Pedersen commitment to hide crosschain transaction information, meanwhile combining off-chain computation and on-chain contract verification. We instantiate and implement PTCross between ChainMaker and Bitcoin. The experimental results show that the proposed PTCross achieves both lightweight performance and strong privacy.
Enhancing privacy on smart contract-enabled blockchains has garnered much attention in recent research. Zero-knowledge proofs (ZKPs) is one of the most popular approaches, however, they fail to provide full expressiveness and fine-grained privacy. To illustrate this, we underscore an underexplored type of Miner Extractable Value (MEV), called Residual Bids Extractable Value (RBEV). Residual bids highlight the vulnerability where unfulfilled bids inadvertently reveal traders' unmet demands and prospective trading strategies, thus exposing them to exploitation. ZKP-based approaches failed to address RBEV as they cannot provide post-execution privacy without some level of information disclosure. Other MEV mitigations like fair-ordering protocols also failed to address RBEV. We introduce Ratel, an innovative framework bridging a multi-party computation (MPC) prototyping framework (MP-SPDZ) and a smart contract language (Solidity), harmonizing the privacy with full expressiveness of MPC with Solidity 's on-chain programmability. This synergy empowers developers to effortlessly craft privacy-preserving decentralized applications (DApps). We demonstrate Ratel's efficacy through two distinguished decentralized finance (DeFi) applications: a decentralized exchange and a collateral auction, effectively mitigating the potential RBEV issue. Furthermore, Ratel is equipped with a lightweight crash-reset mechanism, enabling the seamless recovery of transiently benign faulty nodes. To prevent the crash-reset mechanism abused by malicious entities and ward off DoS attacks, we incorporate a cost-utility analysis anchored in the Bayesian approach. Our performance evaluation of the applications developed under the Ratel framework underscores their competency in managing real-world peak-time workloads.
Matrix multiplication is a common operation in applications like machine learning and data analytics. To demonstrate the correctness of such an operation in a privacy-preserving manner, we propose zkMatrix, a zero-knowledge proof for the multiplication of committed matrices. Among the succinct non-interactive zero-knowledge protocols that have an O(log n) transcript size and O(log n) verifier time, zkMatrix stands out as the first to achieve O(n2) prover time and O(n2) RAM usage for multiplying two n X n matrices. Significantly, zkMatrix distinguishes itself as the first zk-SNARK protocol specifically designed for matrix multiplication. By batching multiple proofs together, each additional matrix multiplication only necessitates O(n) group operations in prover time.
The 15-puzzle is a puzzle game played with 15 square tiles numbered from 1 to 15 on a 4 ร 4 board. It has been popular for generations because of its simplicity and challenge. The (w ร h)-puzzle is a generalization of the 15-puzzle, which is played with wh โ 1 square tiles numbered from 1 to wh โ 1 on a w ร h board. Solving the (w ร h)-puzzle is NP-hard, and hence it is valuable to know its solution. In this paper, we apply the concept of zero-knowledge proof to the (w ร h)-puzzle. We propose a physical zero-knowledge proof protocol, in which a prover who knows a solution to the (w ร h)-puzzle can convince a verifier that the prover knows the solution without revealing any information about it. We also design physical zero-knowledge proof protocols of two token swapping problems closely related to the (w ร h)-puzzle.
Decentralized Physical Infrastructure Networks (De-PINS) are secured and governed by blockchains but beyond crypto-economic incentives, they lack measures to establish trust in participating devices and their services. The verification of relevant device credentials during device registration helps to overcome this problem. However, on-chain verification in decentralized applications (dApp) discloses potentially confidential device attributes whereas off-chain verification introduces undesirable trust assumptions. In this paper, we propose a credential-based device registration (CDR) mechanism that verifies device credentials on the blockchain and leverages zero-knowledge proofs (ZKP) to protect confidential device attributes from being disclosed. We characterize CDR for DePINs, present a general system model, and technically evaluate CDR using zkSNARKs with Groth16 [1] and Marlin [2]. Our experiments give first insights into performance impacts and reveal a tradeoff between the applied proof systems.
Gulshan Kumar, Rahul Saha, Manish Gupta, Tai-hoon Kim
The correctness and the true validated data in Human Resource Management (HRM) are important for organizations as the data plays an impactful role in recruiting, developing, and retaining a skilled workforce. On one hand, the validated data in an organization helps in recruiting legitimate skillful employees; on the other hand, keeping the employee's data safe and maintaining privacy laws such as compliance with the General Data Protection Regulation (GDPR) is also an organization's responsibility. Besides, transparency in human resource management operations is crucial because it promotes trust and fairness within an organization. The present HRM systems are centralized in nature and their verifiable credential system is ineffective; this leads to the intentions of internal data sabotage or internal threats. Besides, the organizations' biases also become more prominent. In this paper, we address the above-mentioned problems with a blockchain framework for HRM to utilize the privacy of data access through a Privacy Information Retrieval (PIR) process. To be specific, our proposed framework called Blockchained piR of resOurces as humaN (BRON) , is the first blockchain framework to show an effective mechanism to access data from organizations globally without hampering privacy. BRON uses a generalized user registration process to use the services of data access and in the background, it uses Zero-Knowledge Proofs (ZKPs) for global verification and PIR for privacy-based data retrieval. More specifically, credential verification and ZKP-based PIR are the highlights of our proposed BRON. Another interesting aspect of BRON is the use of Proof-of-Authority (PoA) to validate the anonymity and unlinkability of any HR operation. Finally, BRON has also contributed with a smart contract to incentivize the employees. BRON is very generic and easily be customizable as per the HR requirements. We run a set of experiments on BRON and observe that it is successful in providing privacy-assured data access and decentralized human resource data management. Overall, BRON provides 30% reduced latency and 35% better throughput as compared to the existing blockchain solutions in the direction of HRM.
In this paper, we present a decentralized network protocol, Space Network Protocol, based on Communication Satellite Services. The protocol outlines a method for distributing information about the status of satellite communication services across the entire blockchain network, facilitating fairness and transparency in all communication services. Our primary objective is to standardize the services delivered by all satellite networks under the communication satellite protocol. This standard remains intact regardless of potential unreliability associated with the satellites or the terminal hardware. We proposed PoD (Proof of Distribution) to verify if the communication satellites are online and PoF (Proof of Flow) to authenticate the actual data flow provided by the communication satellites. In addition, we also proposed PoM (Proof of Mesh) to verify if the communication satellites have successfully meshed together. Utilizing zero-knowledge proof and multi-party cryptographic computations, we can evaluate the service provisioning parameters of each satellite, even in the presence of potential terminal or network node fraud. This method offers technical support for the modeling of distributed network services.
Anonymous credentials are cryptographic mechanisms enabling users to authenticate themselves with a fine-grained control on the information they leak in the process. They have been the topic of countless papers which have improved the performance of such mechanisms or proposed new schemes able to prove ever-more complex statements about the attributes certified by those credentials. However, although these papers have studied in depth the problem of the information leaked by the credential and/or the attributes, almost all of them have surprisingly overlooked the information one may infer from the knowledge of the credential issuer. In this paper we address this problem by showing how one can efficiently hide the actual issuer of a credential within a set of potential issuers. The novelty of our work is that we do not resort to zero-knowledge proofs but instead we show how one can tweak Pointcheval-Sanders signatures to achieve this issuer-hiding property in a compact way. This results in an efficient anonymous credential system that indeed provides a complete control of the information leaked in the authentication process. Our construction is moreover modular and can then fit a wide spectrum of applications, notably for Self-Sovereign Identity (SSI) systems.
Bit-decomposition-based zero-knowledge range proofs in the discrete logarithm (DLOG) setting with a transparent setup, e.g., Bulletproof (IEEE S&P 18), Flashproof (ASIACRYPT 22), and SwiftRange (IEEE S&P 24), have garnered widespread popularity across various privacy-enhancing applications. These proofs aim to prove that a committed value falls within the non-negative range [0, 2^N-1] without revealing it, where N represents the bit length of the range. Despite their prevalence, the current implementations still suffer from suboptimal performance. Some exhibit reduced communication costs at the expense of increased computational costs while others experience the opposite. Presently, users are compelled to utilize these proofs in scenarios demanding stringent requirements for both communication and computation efficiency. In this paper, we introduce, FlashSwift, a stronger DLOG-based logarithmic-sized alternative. It stands out for its greater shortness and significantly enhanced computational efficiency compared with the cutting-edge logarithmic-sized ones for the most common ranges where N is no more than 64. It is developed by integrating the techniques from Flashproof and SwiftRange without using a trusted setup. The substantial efficiency gains stem from our dedicated efforts in overcoming the inherent incompatibility barrier between the two techniques. Specifically, when N=64, our proof achieves the same size as Bulletproof and exhibits 1.1 times communication efficiency of SwiftRange. More importantly, compared with the two, it achieves 2.3 times and 1.65 times proving efficiency, and 3.2 times and 1.7 times verification efficiency, respectively. At the time of writing, our proof also creates two new records of the smallest proof sizes, 289 bytes and 417 bytes, for 8-bit and 16-bit ranges among all the bit-decomposition-based ones without requiring trusted setups. Moreover, to the best of our knowledge, it is the first configurable range proof that is adaptable to various scenarios with different specifications, where the configurability allows to trade off communication efficiency for computational efficiency. In addition, we offer a bonus feature: FlashSwift supports the aggregation of multiple single proofs for efficiency improvement. Finally, we provide comprehensive performance benchmarks against the state-of-the-art ones to demonstrate its practicality.
Said Gulyamov, ะัะปะฐะผะฑะตะบ ะ ัััะฐะผะฑะตะบะพะฒ
Analyzing the complex cybersecurity landscape of Uzbekistanโs crypto exchanges, the article emphasizes the importance of developing and implementing cybersecurity policies and regulatory frameworks. The article identifies the most pressing and evolving digital threats and evaluates the effectiveness of advanced mitigation measures. Furthermore, it explores the transformative potential of innovative legal and technological tools, such as blockchain-based identity verification, zero-knowledge proofs, and secure multi-party computation. The article provides an in-depth analysis of the current legislation governing cybersecurity practices within Uzbekistanโs crypto ecosystem and offers insights into future development prospects. To provide a comprehensive analysis of the cybersecurity situation in the cryptocurrency exchange industry, an extensive review of academic publications, industry reports and official documents related to cybersecurity in the cryptocurrency market is used. In addition, the article includes case studies of known cybersecurity incidents related to cryptocurrency exchanges. By analyzing real-life examples, the researchers aim to provide a more detailed understanding of the cybersecurity challenges faced by cryptocurrency exchanges and the effectiveness of various mitigation measures. Ultimately, the article presents practical recommendations for creating a secure, trustworthy, and innovation-driven environment for cryptocurrency users in Uzbekistan.
Ardra Vinod, Malavika Vinodkumar, S Pranav, P Remyakrishnan
Vehicular Ad Hoc Network (VANET) is a particular subclass of the mobile ad-hoc network that raises several security challenges, notably how users authenticate the network. The work explores using zero-knowledge proofs for secure authentication while preserving user privacy and aims at encrypted information exchange between onboard units. Zero-knowledge proofs enhance security by protecting against impersonation attacks. We strive to reduce the dependence on roadside units for computational tasks by integrating the central authentication server and sub-authentication servers. We reduce modular exponentiation operations during authentication, enhancing efficiency without compromising security. We use the protocol verifier tool called Proverif to verify the security of our protocol. Simulation using the NS-2 simulator validates the protocol by varying the vehicle density. This paper advances VANET security by combining zero-knowledge authentication with encrypted information exchange, strengthening security, efficiency, and data confidentiality while reducing reliance on RSUs. Our protocol ensures secure communication in VANET with minimum computational and communication overhead.
The global transition towards Web3 is giving rise to many blockchain networks, each with its native cryptocurrency. Ethereum is used for decentralized applications, Bitcoin is used for investment, and Polygon is used for scalability solutions. Furthermore, a few well-known blockchain platforms have implemented interoperability features, meaning users can now send wrapped tokens around different blockchains. User assets are then distributed across multiple blockchain networks and wallets. This means user assets are already distributed across multiple tokens on different blockchain networks. This work presents a web application that allows you to visualize your assets distributed across different blockchain networks and wallets. Notably, this work supports the straightforward integration of secondary wallets with user accounts. In addition, this work supports tracking the historical user asset transfer requests, including incoming and outgoing ones, and storing the metadata associated with each asset transfer, including its corresponding proofโs Content Identifier (CID) after zkSNARKs proof generation by hosting it on the InterPlanetary File System (IPFS).
Function-as-a-Service providers manage security devices that are shared among multiple tenants. It is undesirable to give them access to cleartext HTTP requests to perform tasks such as traffic inspection. The recent Zero-Knowledge Middlebox (ZKMB) can be used to enforce network policies on TLS traffic without revealing any information on the content to the policy verifier. In this paper, we describe a ZKMB implementation and a policy designed to check whether the HTTPS function invocations by the clients follow a legitimate pattern. We also present and compare two strategies to distribute allowed patterns, introducing a Moving-Target Defense approach for the function URI randomization, which shows a good tradeoff between detection effectiveness and confidentiality. Performance assessment in our prototype implementation shows that the ZK algorithms are not yet suitable for real-time execution, but current research interest in this technology is expected to narrow this gap.