Zero-knowledge proofs (ZKP) are used to prove the correctness of computations without revealing any other information. Zero-knowledge proofs have origins in Interactive proof systems which were introduced in the 1980’s. Last decade has seen a big leap from theory to practice, thanks to applications such as blockchains, anonymous credentials etc. Initially used for privacy preserving transactions in Zcash, these have been used in various ways in blockchain designs like Monero, ensuring anonymity of users, designing scalable Layer-2 solutions, verifiable computation in decentralised blockchain oracles and many more. These are being increasingly used in blockchain applications.The aims of this tutorial are as follows: (1) Provide background, history, evolution and theoretical foundations, (2) Discuss desirable properties of ZKP for blockchains and its applications, (3) Present some well known ZKP systems and show how they are used in blockchains, and (4) Introduce the audience to a myriad of open problems in this space.The tutorial will be self contained, no knowledge of cryptography or blockchain will be assumed.
Multi-Scalar Multiplication (MSM) is a fundamental cryptographic primitive, which plays a crucial role in Zero-knowledge proof systems. In this paper, we optimize the single MSM Process Element (PE) utilizing buckets with fewer conflicts, enhanced by Greedy-based scheduling, to achieve higher efficiency. The evaluation results show our optimized single MSM PE achieving a speedup of over two times on average, peaking at 3.63 times compared to previous works. Furthermore, we introduce Gypsophila, a scalable and bandwidth-optimized architecture for implementing multiple MSM PEs. Leveraging the characteristics of the bucket method, we optimize the data flow by balancing the throughput of bucket classification, bucket aggregation, and result aggregation in MSM. Simultaneously, multiple PEs with different data access patterns share a universal point input channel and post-processing unit, which improves the module utilization and mitigates the bandwidth pressure. Gypsophila with 16 PEs, accomplishes 16 MSM tasks in a mere 1.01% additional time, showcasing an approximate 7.8% reduction in area, with only about 116 of the bandwidth requirement, compared with 16 PEs without input channel and post-process unit sharing.
Multi-scalar multiplication (MSM) is the most computation-intensive part in proof generation of Zero-knowledge proof (ZKP). In this paper, we propose MSMAC, an FPGA accelerator for large-scale MSM. MSMAC adopts a specially designed Instruction Set Architecture (ISA) for MSM and optimizes pipelined Point Addition Unit (PAU) with hybrid Karatsuba multiplier. Moreover, a runtime system is proposed to split MSM tasks with the optimal sub-task size and orchestrate execution of Processing Elements (PEs). Experimental results show that MSMAC achieves up to 328X and 1.96X speedups compared to the state-of-the-art implementation on CPU (one core) and GPU, respectively, outperforming the state-of-the-art ASIC accelerator by 1.79X. On 4 FPGAs, MSMAC performs 1,261X faster than a single CPU core.
In global grid-based cloud computing settings, performance optimization depends on effective data scheduling. The usefulness of the absolute distributed data scheduling function in controlling resource allocation, load balancing, and data dissemination across heterogeneous cloud infrastructures is assessed in this study. By taking into account variables including data locality, processing capacity, and network latency, we evaluate the function's capacity to increase system throughput while reducing scheduling overhead. Simulations that compare to current scheduling models show gains in fault tolerance, scalability, and efficiency. High-performance cloud computing is advanced by the findings, which offer insights on optimizing distributed scheduling systems. Cloud security is crucial for attracting customers and protecting data privacy. Online attackers disrupt cloud services, leading to financial growth for cloud-based organizations. Various methodologies are reviewed to develop strong security mechanisms for cloud computing, but machine learning is not enough. This research focuses on high-level technologies like Block chain and Quantum computing with Machine Learning (ML) concepts and algorithm conceptions like deep neural networks and quantum neural networks. These models reduce attacks and increase user trust, benefiting cloud service providers. The research aims to eradicate issues and promote end-to-end protection and secrecy in the cloud environment. Cloud computing is an on-demand technology that provides various services like vast computing power, unlimited storage, and on-demand web services over the internet without the need for internal infrastructure. This research focuses on data security and privacy of cloud customers using various experiments. Cyber-attacks can be Denial of Services (DoS), Distributed Denial of Services (DDoS), Man In The Middle (MITM), and malware attacks. To protect the cloud system from cyber-attacks, deep learning is used to train an intelligent honeynet system that not only protects the system from DDoS attacks but also redirects attacks towards another direction. Another approach is the Quantum Neural Network (QNN) approach, which helps identify attack patterns and categorizes them into different classes of DoS/DDoS attacks. The QNN training process addresses slowing down of the cloud system and allows valid cloud customers to access their private data in cloud storage. Another approach is Zero Knowledge Proof (ZKP) technology, which verifies the authenticity of cloud users by polarizing photons at a specific angle. This verifier model allows cloud customers to access sensitive data and only cloud services provided by the cloud service provider. Blockchain, a powerful security framework, is used to address increasing security vulnerabilities. The Quantum-Blockchain framework incorporates the quantum superimposition principle to prevent data tampering, ensuring data privacy and data security. This research aims to address intrusion detection and data storage security challenges in the cloud computing environment using collaborative efforts from Machine Learning and advanced technologies like Quantum Computing and Blockchain. The cloud manifesto and security alliance need to be standardized to ensure privacy and security. Current research is limited due to lack of security and privacy standards between cloud vendors and users. Future studies should focus on advanced technologies like hybrid cloud, artificial intelligence, quantum computing, data mining, machine learning, big data, and cryptography to enhance security and prevent cyber-attacks.
El-hacen Diallo, Mohameden Dieye, Omar Dib, Pierre Valiorgue
As blockchain technology continues to evolve, it has fostered an extensive ecosystem of applications and platforms. This dynamic landscape is characterized by a myriad of innovative solutions, ranging from decentralized finance and supply chain management to digital identity and voting systems, each contributing to the ongoing advancement and adoption of blockchain technology across various sectors. Achieving interoperability among these applications and platforms poses a significant challenge due to their use of distinct protocols, and remains a bottleneck hindering the widespread adoption of blockchain technologies. Addressing this challenge requires designing a universal interoperability protocol while ensuring compliance with the security and privacy constraints specific to each blockchain, thus adding complexity. We propose an agnostic interoperability protocol designed for seamless asset movement across independent private blockchain networks, regardless of their individual protocols. This protocol leverages incentive-driven smart contract and Zero-Knowledge Proofs to establish a decentralized, secure, and privacy-focused framework for interoperability. We conduct a security analysis using game theory and provide both theoretical and empirical evaluations of the protocol end-to-end delay. Through a comprehensive use case, we demonstrate the secure deployment of the proposed protocol for asset movement between two private blockchains. We also discuss the trade-offs between cost and delay in cross-blockchain transactions. Furthermore, a comparative analysis with existing interoperability schemes showcases the proposed interoperability scheme superiority in terms of robustness, privacy preservation, and verifiability.
U. Archana, M Jeyalaxmi, A. Vijayaprabhu, K. Dhanalakshmi · 6 authors
Homomorphic encryption stands as a transformative cryptographic technique, enabling computations on encrypted data sans decryption, a critical feature within privacy-preserving blockchain frameworks. Its integration mitigates the inherent security vulnerabilities of traditional blockchains, safeguarding sensitive data from exposure. Through identity-based encryption (IBE), key generation becomes not only secure but also user-friendly, streamlining access control. Smart contracts automate key distribution, bolstering security while dynamic key generation ensures resilience against potential attacks. Storing encrypted data on the blockchain guarantees confidentiality, with selective data sharing mechanisms offering granular control over information dissemination for collaborative purposes. Privacy-preserving transactions, facilitated by homomorphic operations and zero-knowledge proofs, maintain transactional confidentiality. Effective revocation and key renewal mechanisms further enhance the system’s security posture. Scalability and efficiency are significantly bolstered through the adoption of off-chain computations and batch processing strategies.
In the ever-expanding landscape of cloud computing, concerns over the privacy of sensitive data have become paramount. This chapter delves into the intricate realm of privacy-preserving data storage and processing in the cloud. It addresses the challenges posed by data ownership, control, and the ever-looming threat of data breaches in cloud environments. Focusing on innovative techniques, the chapter explores encryption mechanisms, secure multi-party computation, and trusted execution environments for privacy-preserving data storage. Additionally, it delves into cutting-edge methods such as privacy-preserving machine learning, secure query processing, and tokenization for safeguarding privacy during data processing in the cloud. Real-world case studies exemplify successful implementations, providing insights into practical applications. The chapter concludes by envisioning future trends, including the integration of blockchain and zero-knowledge proofs, and highlights the challenges and opportunities that lie ahead in the pursuit of privacy preservation in cloud computing.
Blockchain technology, known for its decentralized and immutable nature, serves as the foundation for various applications. As a prominent application of blockchain, decentralized storage is powered by blockchain technology and is expected to provide a reliable and cost-effective alternative to traditional centralized storage. A major challenge in blockchain-powered decentralized storage is how to guarantee the quality of storage services in decentralized storage nodes (DSNs). Storage auditing can ensure the integrity and security of the stored data. Unfortunately, it incurs additional computational costs for data owners and extra storage overheads for DSNs, which thereby cannot be directly applied to decentralized storage networks consisting of nodes with various computation and storage capacity. In this article, we overcome these problems and minimize additional burdens in storage auditing. We propose EDCOMA, a computation and storage efficient auditing scheme for blockchain-based decentralized storage, in which a double compression method is designed to compress data authenticators using both data and polynomial commitment. To prevent replay attacks on double compression launched by DSNs, we introduce zero knowledge proof and design a compression arithmetic circuit to guarantee the execution of compression operations in DSNs. We analyze the security of EDCOMA under the random oracle model and conduct extensive experiments to evaluate the performance of EDCOMA. Experimental results affirm that EDCOMA outperforms state-of-the-art approaches in both computational and storage efficiency.
A Zero-Knowledge Proof (ZKP) protocol allows a participant to prove the knowledge of some secret without revealing any information about it. While such protocols are typically executed by computers, there exists a line of research proposing physical instances of ZKP protocols. Up to now, many card-based ZKP protocols for pen-and-pencil puzzles, like Sudoku, have been designed. Those games, mostly edited by Nikoli, have simple rules, yet designing them in card-based ZKP protocols is non-trivial. In this work, we propose a card-based ZKP protocol for Usowan, a Nikoli game. In Usowan, for each room of a puzzle instance, there is exactly one piece of false information. The goal of the game is to detect this wrong data amongst the correct data and also to satisfy the other rules. Designing a card-based ZKP protocol to deal with the property of detecting a liar has never been done. In some sense, we propose a physical ZKP for hiding of a liar. This work extends a previous paper appearing in Ref. [1]. In this extension, we propose two other protocols, for Herugolf and Five Cells. The puzzles are specifically chosen because each of those three puzzles shares a common constraint, connectivity. However, showing the connected configuration cannot be done with generic approach and brings new construction to the existing connectivity ZKP protocol. Indeed, in Herugolf, the connectivity is handled with a given length of cell which is decremental (i.e., the length of each connected cell decreases by one at each step). For Five Cells, there is an additional step in the setup allowing to encode all the information needed to ensure a valid ZKP protocol.
Open access
graph theory and CDMA systems
Graph Labeling and Dimension Problems
Advanced Steganography and Watermarking Techniques
Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A. · 7 authors
The rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof.
This research introduces the Blockchain Academic Credential Interoperability Protocol (BACIP), designed to significantly enhance the security, privacy, and interoperability of verifying academic credentials globally, addressing the widespread issue of academic fraud. BACIP integrates dual blockchain architecture, smart contracts, and zero-knowledge proofs to offer a scalable and transparent framework aimed at reducing fraud and improving the mobility and opportunities for students and professionals worldwide. The research methodology adopts a mixed-methods approach, involving a rigorous review of pertinent literature and systematic integration of advanced technological components. This includes both qualitative and quantitative analyses that underpin the development of a universally compatible system. Preliminary evaluations suggest that BACIP could enhance verification efficiency and bolster security against tampering and unauthorized access. While the theoretical framework and practical implementations have laid a solid foundation, the protocol's real-world efficacy awaits empirical validation in a production environment. Future research will focus on deploying a prototype, establishing robust validation policies, and defining precise testing parameters. This critical phase is indispensable for a thorough assessment of BACIP's operational robustness and its compliance with international educational standards. This work contributes significantly to the academic field by proposing a robust model for managing and safeguarding academic credentials, thus laying a strong foundation for further innovation in credential verification using blockchain technology.
This chapter provides an overview of the crucial role played by blockchain technology in securing healthcare metaverse by ensuring the privacy and integrity of sensitive medical data. Techniques like zero-knowledge proofs and commitment schemes empower patients to control their data while enabling secure data sharing. Secure multi-party computation further enhances security by facilitating joint computations without revealing individual data fragments. However, challenges remain in implementing these technologies effectively. Scalability issues arise from the vast amount of data generated in the metaverse, requiring efficient processing and storage solutions. Existing cryptographic techniques, while robust, might not be future-proof against advancements like quantum computing. By prioritizing data security and privacy, the metaverse can evolve into a reliable and accessible digital environment for healthcare delivery. By embracing innovation, fostering collaboration, and upholding patient autonomy, we can create a future where healthcare is personalized and accessible, for all.
Mobile crowdsourcing aims to recruit enough workers holding mobile devices to collect data. Nevertheless, the platform will have cold start problems when the number of workers is limited. Existing studies have proposed solving this problem by propagating tasks to social networks for social recruitment. However, they neglect to verify workers’ propagation, leading to malicious workers reducing the platform's utility. Furthermore, during propagation verification, it is imperative to protect the privacy of social relationships among workers, as it can significantly influence the propagation. Therefore, this paper proposes Zero-knowledge Propagation Verification based on Social Relationship Encryption (ZPV-SRE) to improve the platform's utility. Specifically, we transform the propagation verification problem into a problem of computing the solution of the function. Then, the Zero-knowledge proof is used to prove the propagation, in which the worker's social relationship is protected through homomorphic encryption. Considering that ZPV-SRE will incur a significant time cost, we propose Trust-guided Zero-knowledge Propagation Verification based on Social Relationship Encryption (TZPV-SRE), which updates the worker's trust based on the verification results and selects suspicious workers for verification. The experimental results show ZPV-SRE improves the platform's utility as high as 104.05% over the state-of-the-art methods, while TZPV-SRE reduces time costs and ensures improvement.
Regarding minimal assumptions, most of classical cryptography is known to depend on the existence of One-Way Functions (OWFs). However, recent evidence has shown that this is not the case when considering quantum resources. Besides the well known unconditional security of Quantum Key Distribution, it is now known that computational cryptography may be built on weaker primitives than OWFs, e.g., pseudo-random states [JLS18], one-way state generators [MY23], or EFI pairs of states [BCQ23]. We consider a new quantum resource, pseudo-entanglement, and show that the existence of EFI pairs, one of the current main candidates for the weakest computational assumption for cryptography (necessary for commitments, oblivious transfer, secure multi-party computation, computational zero-knowledge proofs), implies the existence of pseudo-entanglement, as defined by [ABF+24, ABV23] under some reasonable adaptations. We prove this by constructing a new family of pseudo-entangled quantum states given only EFI pairs. Our result has important implications for the field of computational cryptography. It shows that if pseudo-entanglement does not exist, then most of cryptography cannot exist either. Moreover, it establishes pseudo-entanglement as a new minimal assumption for most of computational cryptography, which may pave the way for the unification of other assumptions into a single primitive. Finally, pseudo-entanglement connects physical phenomena and efficient computation, thus, our result strengthens the connection between cryptography and the physical world.
This research paper delves into the imperative domain of bolstering data confidentiality within smart contracts through the integration of advanced privacy-preserving methodologies. Smart contracts, pivotal components of blockchain technology, execute self-executing contracts with predefined conditions and are increasingly utilized across various sectors, necessitating stringent data protection measures. The paper addresses the pressing need for fortified data privacy within smart contracts and investigates cutting-edge approaches to mitigate privacy challenges. Two focal techniques under scrutiny are zero-knowledge proofs (SBÇs) and homomorphic encryption. SBÇs facilitate the validation of computations without revealing sensitive data, enabling parties to verify transaction authenticity without disclosing the underlying information. Meanwhile, homomorphic encryption permits computations on encrypted data, preserving confidentiality by allowing operations on encrypted information without the need for decryption. By analyzing these advanced privacy-preserving techniques, this study aims to address the vulnerabilities in data confidentiality present in smart contracts. Its findings hold significant promise in fortifying the security and confidentiality of transactions, thus contributing substantially to the evolution of secure blockchain technology. This research underscores the pivotal role of innovative privacy-enhancing mechanisms in safeguarding sensitive data within smart contracts, ensuring the trust and integrity essential for their widespread adoption.
The legal status of cryptoassets as property has been widely accepted, but it remains unclear who owns a cryptoasset. This article explores the determination of the owner of a cryptoasset. It argues that under the doctrine of deemed ownership, a person in possession of a thing is deemed or presumed to be its owner unless there is evidence to the contrary. The cryptographic control of cryptoassets is equivalent or analogous to the physical possession of tangible things. Thus, a private key holder who has cryptographic control of a cryptoasset is presumed to be the owner of the cryptoasset. A person without cryptographic control can prove ownership of the cryptoasset in the hands of a different person if they can follow or trace the cryptoasset into the hands of the controller and they are entitled to claim ownership over the followed or traced cryptoasset.
The fundamental theorem of Goldreich, Micali, and Wigderson (J. ACM 1991) shows that the existence of a one-way function is sufficient for constructing computational zero knowledge (CZK) proofs for all languages in NP. We prove its converse, thereby establishing characterizations of one-way functions based on the worst-case complexities of zero knowledge. Specifically, we prove that the following are equivalent: - A one-way function exists. - NP ⊆ CZK and NP is hard in the worst case. - CZK is hard in the worst case and the problem GapMCSP of approximating circuit complexity is in CZK. The characterization above also holds for statistical and computational zero-knowledge argument systems. We further extend this characterization to a proof system with knowledge complexity O(logn). In particular, we show that the existence of a one-way function is characterized by the worst-case hardness of CZK if GapMCSP has a proof system with knowledge complexity O(logn). We complement this result by showing that NP admits an interactive proof system with knowledge complexity ω(logn) under the existence of an exponentially hard auxiliary-input one-way function (which is a weaker primitive than an exponentially hard one-way function). We also characterize the existence of a robustly-often nonuniformly computable one-way function by the nondeterministic hardness of CZK under the weak assumption that PSPACE ⊈AM. We present two applications of our results. First, we simplify the proof of the recent characterization of a one-way function by NP-hardness of a meta-computational problem and the worst-case hardness of NP given by Hirahara (STOC’23). Second, we show that if NP has a laconic zero-knowledge argument system, then there exists a public-key encryption scheme whose security can be based on the worst-case hardness of NP. This improves previous results which assume the existence of an indistinguishable obfuscation.
Treballs Finals de Grau de Matemàtiques, Facultat de Matemàtiques, Universitat de Barcelona, Any: 2024, Director: Bruno Mazorra i Luis Victor Dieulefait
Nir Bitansky, Chethan Kamath, Omer Paneth, Ron D. Rothblum · 5 authors
Batch proofs are proof systems that convince a verifier that x1,…,xt ∈ L, for some NP language L, with communication that is much shorter than sending the t witnesses. In the case of statistical soundness (where the cheating prover is unbounded but the honest prover is efficient given the witnesses), interactive batch proofs are known for UP, the class of unique-witness NP languages. In the case of computational soundness (where both honest and dishonest provers are efficient), non-interactive solutions are now known for all of NP, assuming standard lattice or group assumptions. We exhibit the first negative results regarding the existence of batch proofs and arguments: - Statistically sound batch proofs for L imply that L has a statistically witness indistinguishable (SWI) proof, with inverse polynomial SWI error, and a non-uniform honest prover. The implication is unconditional for obtaining honest-verifier SWI or for obtaining full-fledged SWI from public-coin protocols, whereas for private-coin protocols full-fledged SWI is obtained assuming one-way functions. This poses a barrier for achieving batch proofs beyond UP (where witness indistinguishability is trivial). In particular, assuming that NP does not have SWI proofs, batch proofs for all of NP do not exist. - Computationally sound batch proofs (a.k.a batch arguments or BARGs) for NP, together with one-way functions, imply statistical zero-knowledge (SZK) arguments for NP with roughly the same number of rounds, an inverse polynomial zero-knowledge error, and non-uniform honest prover. Thus, constant-round interactive BARGs from one-way functions would yield constant-round SZK arguments from one-way functions. This would be surprising as SZK arguments are currently only known assuming constant-round statistically-hiding commitments. We further prove new positive implications of non-interactive batch arguments to non-interactive zero knowledge arguments (with explicit uniform prover and verifier): - Non-interactive BARGs for NP, together with one-way functions, imply non-interactive computational zero-knowledge arguments for NP. Assuming also dual-mode commitments, the zero knowledge can be made statistical. Both our negative and positive results stem from a new framework showing how to transform a batch protocol for a language L into an SWI protocol for L.
We put forward a new approach for achieving non-interactive zero-knowledge proofs (NIKZs) from the learning with errors (LWE) assumption (with subexponential modulus to noise ratio). We provide a LWE-based construction of a hidden bits generator that gives rise to a NIZK via the celebrated hidden bits paradigm. A notable feature of our construction is its simplicity. Our construction employs lattice trapdoors, but beyond that uses only simple operations. Unlike prior solutions, we do not rely on a correlation intractability argument nor do we utilize fully homomorphic encryption techniques. Our solution provides a new methodology that adds to the diversity of techniques for solving this fundamental problem.
Most trust models are identity based, which how-ever are not appropriate to the permissionless peer-to-peer (P2P) networking since anonymity is a built-in property in the cryptocurrency system (e.g., Bitcoin). Hence, there exists an inherent trade-off between anonymity and trust in the context of permissionless P2P networking system. This paper is motivated to propose a keyless authentication based on zero-knowledge proof. With this, peers can authenticate each other without disclosing any sensitive information. To this end, this approach leverages the software-defined networking (SDN) technique to facilitate the zero-knowledge proof so that the peer's link information can be identified while the proving process will never reveal any identity information. Therefore, the challenge-response exchange can prevent Man-in-the-Middle (MITM) attacks with minimal communication overhead. The experimental results built on the prototype show that this approach is efficient.