Federated learning has emerged as a promising paradigm for large-scale collaborative training tasks, harnessing diverse local datasets from different clients to jointly train global models. In real-world implementations, client data could have label noise, causing the quality of the global model to be influenced. Existing label-correction solutions assume all the clients are discreet and fail to consider detecting the malicious clients, thus are not practical or privacy-preserving. In this paper, we present zkCor, an efficient and reliable label noise correction scheme with zero-knowledge confidentiality. Our method is designed upon FedCorr [1], but with more relaxed security assumptions. zkCor is established from the ingenious synergy of the label noise correction protocol and the zero-knowledge proof (ZKP), requiring each client to provide a computation integrity proof to the aggregator in each iteration. Thus, clients are forced to jointly guarantee label-correction reliability. We further devise a batch ZKP that is efficient and more suitable for federated learning settings. We rigorously illustrate the building blocks of zkCor and complete the prototype implementation. The extensive experiments demonstrate that zkCor can gain at least 2 to 30 times better performance than the baseline approach on verification workloads with nearly no extra proof time cost from clients.
Jesús García-Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio Skármeta
The increasing user awareness and regulatory framework (e.g., GDPR, eIDAS2) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems. Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data. Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by developing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations.
When a user wants to access certain services offered by a service provider, typically the user must first authenticate herself with the service provider, such that the service provider may grant authorization to access the services. Authentication is the process through which the user provides confirmation of her identity to the service provider (and, in parallel, the user should receive confirmation that the service provider is legitimate). Several types (or factors) of authenticators can be utilized in this process. Namely, things the user know (e.g.: passwords, PINs); things the user possesses (e.g., token authenticators in the smartphone, key fobs, cards); characteristics or physical traits of the user (e.g., fingerprint, iris pattern); and, as proposed in this dissertation, the user’s location. Each authentication factor has, in terms of security and user experience when compared to other factors, strong and weak aspects, (or pros and cons). For instance, passwords must be long and random, but then remembering them can be taxing; fingerprints are (believed to be) unique and thus form a good authenticator, but they are immutable and hardly confidential; token authenticators and out-of-band tokens (such as SMS tokens) provide an ephemeral value that is valuable for security, but the user might lose possession of the respective token device. Combining two or more of those authenticators results in a potential increased security as compared to utilizing only one authenticator, which is known as multi-factor authentication. ☐ This dissertation focuses on multi-factor authentication. I present a cryptographic method to enable location as an authentication factor, using the flexibility of Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and its access policies, together with location beacons. Such that this location authenticator can be realized, I develop a technique to request and control the presentation of multi-factor authenticators, through which scores are assigned to each authenticator type and both the user and the authentication service are aware of a minimum score needed for full authentication. To address the necessity of a secure scheme through which a user presents the authenticators, I construct a method for conveying the authentication factors in a Zero-Knowledge Password Proof (ZKPP) scheme and through an ephemeral, confidential session. The method also provides a secure joint authenticator that is the cryptographic composite (built within ZKPP) of the individual authenticators. To embody and realize these techniques, I devise a multi-factor authentication protocol named LOCATHE, through which a user device or user can authenticate herself to an authentication service using the device’s or user’s location and other authentication factors, with guarantees of forward secrecy. Moreover, I design a Location-Enhanced Multi-Factor Authentication Service (Loc-Auth), abstracting hardware (such as the location beacons) and control into a layered structure, to provide the authentication services and support for the components of this dissertation. Finally, I develop a Proof-of-Concept system, and perform an extensive security evaluation and analysis of the work herein.
The rapid expansion of Internet of Things (IoT) devices has revolutionized data generation and sharing but simultaneously introduced profound privacy concerns for both individuals and organizations. To mitigate these risks, this paper evaluates cutting-edge privacy-preserving techniques specifically designed for data exchange within the IoT framework. These techniques are categorized into cryptographic, anonymization, and differential privacy approaches, with each offering distinct advantages and limitations across diverse IoT scenarios. Cryptographic techniques, including homomorphic encryption, attribute-based encryption, secure multiparty computation, and zero-knowledge proofs, offer robust privacy protection by encrypting data during transmission and computation. However, they may incur considerable computational overhead and require sophisticated key management mechanisms. Anonymization techniques such as k-anonymity, l-diversity, t-closeness, and differential privacy-based anonymization aim to conceal sensitive information by aggregating or perturbing data. While effective in safeguarding privacy, these methods may struggle to balance privacy and data utility, leading to potential information loss or re-identification risks.
António Pesqueira, Maria José Sousa, Andréia de Bem Machado
Blockchain technology (BT), originally developed to facilitate secure digital monetary transactions, has recently gained significant traction in various healthcare sectors. Characterized by the exponential growth of sensitive data, the healthcare sector is poised to witness the emergence of BT. This emergence is primarily driven by the pressing need to globally expose, protect against threats, ensure confidentiality, and establish traceability for the plethora of sensitive data continuously generated by the healthcare industry. The healthcare supply chain focuses on traceability due to the prevalence of counterfeit and recalled drugs. Managing operational constraints such as temperature, humidity, and air quality within specified parameters is paramount. The various processes involved in international trade transactions contribute to the creation of numerous records, each of which is meticulously entered into the systems of the companies involved. Therefore, the problem set for this study was: What are the challenges and prospects for BT in the healthcare sector? To answer this question, the following objective was set: describe and examine the challenges and prospects of BT in the healthcare sector. In addition, a key research objective was to identify specific applications and use cases that can benefit the most from this technological advancement. In line with the research objective, a systematic review of all studies BT for traceability, anti-counterfeiting, and fraud detection was conducted from January 2023 to September 2023. Using robust tools such as VosViewer, we used bibliometric metrics from the renowned medical repository PubMed to construct and visually represent data analysis networks. BT shows remarkable potential to improve traceability and optimize supply chain management within healthcare organizations. The study includes a deep analysis of blockchain capabilities, including smart contracts, identity management, access control, and zero-knowledge proofing.
Edge computing provides higher computational power and lower transmission latency by offloading tasks to nearby edge nodes with available computational resources to meet the requirements of time-sensitive tasks and computationally complex tasks. Resource allocation schemes are essential to this process. To allocate resources effectively, it is necessary to attach metadata to a task to indicate what kind of resources are needed and how many computation resources are required. However, these metadata are sensitive and can be exposed to eavesdroppers, which can lead to privacy breaches. In addition, edge nodes are vulnerable to corruption because of their limited cybersecurity defenses. Attackers can easily obtain end-device privacy through unprotected metadata or corrupted edge nodes. To address this problem, we propose a metadata privacy resource allocation scheme that uses searchable encryption to protect metadata privacy and zero-knowledge proofs to resist semi-malicious edge nodes. We have formally proven that our proposed scheme satisfies the required security concepts and experimentally demonstrated the effectiveness of the scheme.
In the backdrop of advancing communication technology and the adoption of decarbonization initiatives, peer-to-peer (P2P) electricity trading has evolved into a consequential avenue for the reliable utilization of clean energy resources. Most efforts have focused on the design of P2P distributed mechanisms to ensure that the security constraints of the grid can be adhered to. However, ensuring the assurance of the correct operation of the distributed mechanisms is also essential but has received less attention. A common assumption is that all participants in the P2P market are honest and make reasonable bids at market prices. Such an assumption could be risky because the P2P market clearing process relies on a coordination process of market participants and the clearing outcome of the P2P market is susceptible to manipulation by dishonest participants. In this work, we propose a new architecture for the P2P market by adding a verification layer based on zero-knowledge proof technology to identify dishonest bidding information of market participants without collecting their private cost information. In addition, we introduce an asynchronous market mechanism, which can greatly guide the P2P market clearing results in a dishonest environment to be close to the theoretical optimal results. Case studies demonstrate the advantages of our approach in resisting dishonesty, preserving privacy, and enhancing market robustness, which can help build a more credible and resilient P2P market environment.
Xiao Zhao, Suzhen Cao, Zheng Wang, D. Y. Xing · 5 authors
A traceable anonymous authentication ring signature scheme with privacy protection is proposed to solve the problem of tracking the identity of malicious signers in ring signatures and protecting the identity privacy of receiver. When the decrypted plaintext contains illegal words, the receiver can request to trusted third party (TTP) to trace the signer, the trusted third party (TTP) interaction with the ring member to find the signer. In avoid leaking the privacy information of receiver, and receiver’s privacy information or input data. Before identify tracing, scheme adopts zero-knowledge proof (ZKP) technology verify the legitimacy of receiver and protect the privacy of the receiver. At last, trusted third party (TTP) returns the public key of the traced signer to the receiver. Based on the computational Diffie-Hellman difficult problem, the scheme is proved to satisfy the security of signature unforgeability under the random oracle model. Compared with the existing schemes, the experimental results show that the scheme reduces the time of signature by 47.521%, the time of verification by 45.915%, and the time of traceability by 16.630%, which proves that the scheme is more effective.
Recently, distributed databases have achieved tremendous realistic performances and developed one of the most essentially utilized tools in society communication applications. However, the existing distributed databases often contain users’ sensitive information and are vulnerable to web attackers, which may cause severe privacy issues and economic loss. In this paper, we first attempt to propose a novel protocol to dispose of the potential verification risks in distributed databases. Compared with currently distributed databases, the requester can steal important data without any payment. Therefore, our model faces two primary challenges including guaranteeing the efficiency and security of the distributed databases, the data verification procedure may lead to data leakage. To address the above problems, we utilize zero-knowledge proof to dispose of the data verification issue for the requester. Moreover, a secure and effective proof protocol is established to achieve database responses the privacy data access. From our extensive experimental results, we can conclude that our developed framework can achieve an effective performance with reasonable communication costs.
Abstract The focus of this review article is on the societal problems and end user acceptance of blockchain technology. The paper begins by outlining the importance of blockchain in modernizing trust and data management systems and highlighting its rapid spread across numerous industries. In‐depth analysis of the adoption‐influencing aspects is done, which also lists the advantages and typical end‐user problems. It examines the privacy implications, restrictions on pseudonymity, and function of technologies that improve privacy, such as zero‐knowledge proofs, while also exploring the legal and regulatory environment around blockchain, putting a focus on digital identity, intellectual property, and data ownership. It also evaluates blockchain security features, such as flaws and risks associated with smart contracts, discusses best practices for boosting security, discusses the societal effects of blockchain, and makes suggestions for legislators, companies, and scholars. The use of blockchain technology and its effects on privacy, rights, and security are discussed in real‐world case studies as well.
Recent booming development of Generative Artificial Intelligence (GenAI) has facilitated model commercialization to reinforce the model performance, including licensing or trading Deep Neural Network (DNN) models. However, DNN model trading may violate the benefit of the model owner due to unauthorized replications or misuse of the model. Model identity auditing is a challenging issue in protecting DNN model ownership, and verifying the integrity and ownership of models is one of the critical obstacles. In this paper, we focus on the above issue and propose an \underline{A}ccumulator-enabled \underline{A}uditing for \underline{D}ecentralized \underline{Id}entity of DNN \underline{M}odel (A2-DIDM) that utilizes blockchain and zero-knowledge techniques to protect data and function privacy while ensuring the lightweight on-chain ownership verification. The proposed model presents a scheme of identity records via configuring model weight checkpoints with zero-knowledge proofs, which incorporates predicates to capture incremental state changes in model weight checkpoints. Our scheme ensures both computational integrity and programmability in DNN training process so that the uniqueness of the weight checkpoint sequence in a DNN model is preserved. %to ensure the correctness of model identity auditing, so that the uniqueness of the weight checkpoint sequence in a DNN model is preserved. A2-DIDM also addresses privacy protections in decentralized identity. We systematically analyze the security and robustness of our proposed model and further evaluate the effectiveness and usability of auditing DNN model identities. The code is available at https://github.com/xtx123456/A2-DIDM.git.
Federated learning (FL) has emerged as a viable paradigm for decentralized machine learning (DML) across multiple platforms while safeguarding data privacy.This study covers a thorough analysis of FL strategies intended to protect the privacy of data.It investigates the techniques and tactics FL uses to secure data privacy and explores the benefits and constraints of FL privacy protection.Using a methodical approach to the literature review, the study distinguishes FL approaches, explores the nuances of the FL transfer process, assesses current techniques, and identifies inherent vulnerabilities and shortcomings.These outcomes emphasize the vitality FL has for alleviating concerns about privacy while fostering collaborative learning.A variety of FL techniques are identified in the review, each of which contributes a distinct mechanism for maintaining privacy.These include differential privacy, homomorphic encryption, pruning, secure aggregation, secure multiparty computation, and zero-knowledge proofs, among others.This study provides scholars and practitioners with significant perspectives on existing procedures and prospective areas for advancement by integrating ideas from multiple sources to provide an overview of the current FL landscape concerning data privacy protection.The findings are more credible and reliable because of the systematic study, which also provides a strong basis for further research on FL and data privacy protection.At the end of the study, the implications of FL approaches for improving data privacy are covered.The significance of continuing research endeavors to tackle new problems and refine FL techniques for resilient and expandable privacy protection in the distributed machine learning age is underlined.
Student, CSE, Sir MVIT, B Sumangala, Aman Raj, Amritanshu Bhardwaj · 6 authors
Abstract - CrypticReport is a decentralized crime reporting system designed to make public reporting safer, more transparent, and free from identity risks. Citizens often avoid reporting crimes due to fear of exposure, harassment, or data misuse. CrypticReport overcomes these challenges by combining blockchain technology, decentralized IPFS storage, artificial intelligence or zero-knowledge–based authentication. Using Anon Aadhaar, users can verify their identity without revealing any personal information. AI models classify reports to block spam and detect duplicate submissions. All verified reports and evidence are stored in IPFS, and their hashes are recorded on the blockchain for tamper-proof storage. The platform uses a React interface for reporting, a Flask backend for AI processing, Ethereum smart contracts for record immutability, and the Waku protocol for real-time updates between citizens and authorities. Testing shows that the system improves trust, preserves anonymity, and ensures that no data can be altered once submitted. CrypticReport proves that decentralized systems can make crime reporting more secure, reliable, and citizen-friendly. Key Words: Blockchain, IPFS, Anonymous Reporting, AI Classification, Zero-Knowledge Proof, Decentralized Systems
Secure multiparty computation is a major field of research in modern cryptography. It allows for the creation of a protocol that maintains the privacy of the inputs and ensures that violation of the protocol results in no undue benefit to the violator or detriment to an honest party. These protocols can be used in many fields. In this dissertation, we explore the application of the mechanisms of secure party computation in the context of peer-to-peer lending, fair exchange with cryptocurrencies, consensus, and electronic voting. In all these areas, honesty of execution and fairness in the outcome should be assured or verifiable, especially if the other parties are not trusted. In this dissertation, we designed protocols to solve the above-mentioned problems, analyzed their efficiency and scalability, and proved their security. First, we present a platform called ZeroLender for peer-to-peer lending in Bitcoin. Our protocol utilizes zero-knowledge proofs to achieve unlinkability between lenders and borrowers while securing payments in both directions against potential malicious behavior of the ZeroLender as well as the lenders and covert action by the borrowers. We prove by simulation that our protocol is privacy-preserving. Based on our experiments, we show that the runtime and transcript size of our protocol scale linearly with respect to the number of lenders and repayments. Second, we propose a generic framework for atomic swap, called PolySwap, that enables fair exchange of assets between two {heterogeneous sets of blockchains}. Our construction preserves the anonymity of the swap by preventing transactions from being linked to each other or be distinguishable from other transactions on the blockchain and does not require any scripting capability in the blockchain, all without requiring a third party. We provide construction details of secret sharing signatures for ECDSA, Schnorr, and CryptoNote-style Ring signatures. Additionally, we provide an alternative contingency protocol, allowing parties to exchange to and from blockchains that do not support any form of time-locked escape transactions. We prove that PolySwap is secure against malicious adversaries, and is privacy-preserving against passive observers. We conducted experiments to demonstrate the efficiency of the protocol. Third, we propose ACCORD, a consensus protocol consisting of three distinct components: an asynchronous quorum selection procedure to designate the creators of future blocks, a block creation protocol run by the quorum to prevent omissions in the presence of honest quorum members, and a decentralized arbitration protocol to ensure consensus by voting. We implemented the protocol and conducted experiments to demonstrate scalability, robustness, and fairness. Finally, we introduce ORBIT, a cryptographic voting protocol that uses hidden credentials and mutable identities through ciphertext manipulation to prevent coercion. This enables voters to submit dummy ballots that are indistinguishable from genuine ones, thus enabling them to evade potential coercers, as well as preventing a fully compromised government from determining their voting preferences. ORBIT is blockchain-based, allowing government verifiers to process incoming ballots as they are submitted. We implemented ORBIT and performed experiments that illustrate its linear scaling in relation to three key variables: election size, the number of ring members within the anonymity set, and the number of ballots.
Xin Liu Xin Liu, Xiaomeng Liu Xin Liu, Dan Luo Xiaomeng Liu, Gang Xu Dan Luo · 5 authors
<p>Secure multi-party computation is a hotspot in the cryptography field, and it is also a significant means to realize privacy computation. The Millionaires&rsquo; problem is the most fundamental problem among them, which is the basic module of secure multi-party computation protocols. Although there are many solutions to this problem, there are few anti-malicious adversarial protocols besides protocols based on Yao&rsquo;s garbled circuit. Only a few solutions have low efficiency, and there is no protocol for rational numbers comparison under the malicious model, which restricts the solution of many secure multi-party computation problems. In this paper, the possible malicious behaviors are analyzed in the existing Millionaires&rsquo; problem protocols. These behaviors are discovered and taken precautions against through the triangle area formula, zero-knowledge proof, and cut-and-choose method, so the protocol of comparing confidentially rational numbers is proposed under the malicious model. And this paper adopts the real/ideal model paradigm to prove the security of the malicious model protocol. Efficiency analysis indicates that the proposed protocol is more effective than existing protocols. The protocol of rational numbers comparison under the malicious model is more suitable for the practical applications of secure multi-party computation, which has important theoretical and practical significance.</p> <p>&nbsp;</p>
The rapid development of modern cryptographic applications such as zero-knowledge, secure multi-party computation, fully homomorphic encryption has motivated the design of new so-called arithmetization-oriented symmetric primitives. As designing ciphers in this domain is relatively new and not well-understood, the security of these new ciphers remains to be completely assessed. In this paper, we revisit the security analysis of arithmetization-oriented cipher Grendel. Grendel uses the Legendre symbol as a component, which is tailored specifically for the use in zero-knowledge and efficiently-varifiable proof systems. At FSE 2022, the first preimage attack on some original full GrendelHash instances was proposed. As a countermeasure, the designer adds this attack into the security analysis and updates the formula to derive the secure number of rounds. In our work, we present new algebraic attacks on GrendelHash. For the preimage attack, we can reduce the complexity or attack one more round than previous attacks for some instances. In addition, we present the first collision attack on some round-reduced instances by solving the constrained input/constrained output problem for the underlying permutations.
This paper introduces the Proof of Sampling (PoSP) protocol, a Nash Equilibrium-based verification mechanism, and its application to decentralized machine learning inference through spML. Our protocol has a pure strategy Nash Equilibrium, compelling rational participants to act honestly. It economically disincentivizes dishonest behavior, making it costly for participants to compromise the network's integrity. In our spML protocol, we apply PoSP to decentralized inference for AI applications via a novel cryptographic protocol. The resulting protocol is much more efficient than zero knowledge proof based approaches. Moreover, we anticipate that the PoSP protocol could be effectively utilized for designing verification mechanisms within Actively Validated Services (AVS) in restaking solutions. We further expect that the PoSP protocol could be applied to a variety of other decentralized applications. Our approach enhances the reliability and efficiency of decentralized systems, paving the way for a new generation of decentralized applications.
In the era of increasing government surveillance driven by national security and law enforcement interests, maintaining individual privacy has become a critical challenge. Cryptographic privacy solutions offer powerful tools to protect communication confidentiality, data integrity, and user anonymity against intrusive surveillance mechanisms. This paper explores the contemporary cryptographic techniques employed to counter government surveillance efforts, including end-to-end encryption, anonymous communication networks, zero-knowledge proofs, and homomorphic encryption. We also analyze the legal and ethical landscape shaping the deployment of these technologies. Emphasis is placed on the balance between privacy preservation and regulatory oversight. Case studies illustrate practical implementations and limitations. The findings highlight the necessity of advancing cryptographic solutions while addressing usability and policy challenges for robust privacy protection.
Multiple sequence alignment (MSA) is a fundamental algorithm in bioinformatics. In a situation when the alignment might need to be protected while revealing the other information such the input sequences and the alignment score, zero knowledge proof can be used. In this paper, a validator checks the consistency between the input sequence and the alignment, and between the alignment and the alignment score. The validator is written in Circom language which will be compile into a circuit. Using a zero knowledge prove system called zkSNARK, a cryptographic proof is generates for the circuit and its input. This proof demonstrates that all inputs are consistent without revealing the actual alignment.