To address the complexities, inflexibility, and security concerns in traditional data sharing models of the Industrial Internet of Things (IIoT), we propose a blockchain-based data sharing and privacy protection (BBDSPP) scheme for IIoT. Initially, we characterize and assign values to attributes, and employ a weighted threshold secret sharing scheme to refine the data sharing approach. This enables flexible combinations of permissions, ensuring the adaptability of data sharing. Subsequently, based on non-interactive zero-knowledge proof technology, we design a lightweight identity proof protocol using attribute values. This protocol pre-verifies the identity of data accessors, ensuring that only legitimate terminal members can access data within the system, while also protecting the privacy of the members. Finally, we utilize the InterPlanetary File System (IPFS) to store encrypted shared resources, effectively addressing the issue of low storage efficiency in traditional blockchain systems. Theoretical analysis and testing of the computational overhead of our scheme demonstrate that, while ensuring performance, our scheme has the smallest total computational load compared to the other five schemes. Experimental results indicate that our scheme effectively addresses the shortcomings of existing solutions in areas such as identity authentication, privacy protection, and flexible combination of permissions, demonstrating a good performance and strong feasibility.
Payment channels serve as an effective solution to the scalability problem of cryptocurrencies, which significantly increase transaction rates by allowing users to conduct large-scale offline transactions off-chain without posting everything to the blockchain. However, the existing payment channels lack privacy protection for the transaction amount and the linking relationship between the two parties to the transaction. Therefore, in order to address the scalability and privacy issues of cryptocurrencies such as Bitcoin, this paper proposes a zk-SNARKs-based anonymous payment channel (zk-APC), which supports an unlimited number of off-chain payments between the payer and the payee and protects the privacy of the participants. Specifically, the proposed scheme achieves relational anonymity and amount privacy for both on-chain and off-chain transactions in the payment channel through utilizing zero-knowledge proof (zk-SNARKs) and commitment schemes. This paper proves that the proposed method is more effective than similar schemes through a performance evaluation.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
A paradox of compliance and privacy exists among an increasing number of users of Decentralized Finance (DeFi). While the Financial Action Task Force (FATF) has established Travel Rules to improve transparency for financial institutions to prevent money laundering, data protection regulations like GDPR require financial institutions to maintain secrecy about customer information. The existing DeFi architecture currently solves this problem via two approaches; it either sacrifices user anonymity in order to meet the regulatory standards set forth by government entities, or creates non-transparent environments that do not hold users accountable for their actions. This paper introduces a novel DLT architecture that balances the user’s requirement for anonymity with the regulatory requirements of the financial services sector through the application of Zero-Knowledge Proofs in combination with a Permissioned DLT. By utilizing a cryptographic pipeline that allows for shielded transactions, yet provides evidence that the transaction was valid and met all relevant regulatory requirements, the architecture enables compliance with regulatory standards and maintains anonymity. Furthermore, this architecture includes protocols for selective disclosure that will enable authorized third-party auditors to audit a user’s regulatory compliance automatically without exposing PII. Experimental results demonstrate that this architecture can be deployed and tested using Hyperledger Fabric and will support both consistent performance and scalability. Specifically, experimental results demonstrate that this architecture can operate commercially at a throughput rate of 1,200 TPS, which represents less than a 35 percent increase in the consumption of computing resources compared to the corresponding rates of fully transparent architectures. Finally, the security analysis proves mathematically that this architecture fulfills the compliance requirements for preventing fraudulent activities and prevents unauthorized de-anonymization of users.
Recently, Oblivious Storage has been proposed to prevent privacy leakage from user access patterns, which obfuscates and makes it computationally indistinguishable from the random sequences by fake accesses and probabilistic encryption. The same data exhibits distinct ciphertexts. Thus, it seriously impedes cloud providers’ efforts to improve storage utilization to remove user redundancy, which has been widely used in the existing cloud storage scenario. Inspired by the successful adoption of removing duplicate data in cloud storage, we attempt to integrate obliviousness, remove redundancy, and propose a practical oblivious storage, PEO-Store. Instead of fake accesses, introducing delegates breaks the mapping link between a valid access pattern and a specific client. The cloud interacts only with randomly authorized delegates. This design leverages non-interactive zero-knowledge-based redundancy detection, discrete logarithm problem-based key sharing, and secure time-based delivery proof. These components collectively protect access pattern privacy, accurately eliminate redundancy, and prove the data delivery among delegates and the cloud. Theoretical proof demonstrates that, in our design, the probability of identifying the valid access pattern with a specific client is negligible. Experimental results show that PEO-Store outperforms state-of-the-art methods, achieving an average throughput of up to 3 times faster and saving 74% of storage space.
<p>To solve the problems of existing e-auction protocols such as semi-trustworthiness of outsourced third parties, collusive attacks among participants, unsatisfactory decentralized structure, and inability of public verification, we propose an efficient first-price sealed e-auction protocol under a secure multi-party computational malicious model. First, the protocol combines the additive homomorphism of the ElGamal cryptographic algorithm to achieve a decentralized structure and eliminate the problem of semi-trustworthiness of outsourced third parties; it uses (n, n) threshold encryption and decryption techniques to solve the problem of collusion attacks among participants and uses Hash-based Message Authentication Code (HMAC) technology to achieve public verifiability of auction results. Additionally, the protocol proposes a method to quickly find the maximum value of the data encoding, which can avoid multiple processing of confidential data and thus effectively reduce the number of communication rounds. The combination of zero-knowledge proof and ideal/realistic simulation paradigm proves that the protocol in this paper is resistant to up to n-1 party collusion attacks and satisfies the security of the secure multi-party computational malicious model. Finally, after theoretical analysis and simulation experiments, the protocol not only satisfies higher security performance but also has greater overall operational efficiency.</p> <p>&nbsp;</p>
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The metaverse has dramatically transformed the traditional online realm and garnered significant interest from researchers and industry experts. By integrating with consumer electronics such as wearables and smart devices, it presents an immersive virtual world where individuals can engage in diverse activities. As this integration accelerates, there is an increasing need for robust and efficient methods to secure digital communications and transactions. The distributed Identity-Based Digital Signature (IBS) scheme has emerged as a promising solution to address the challenges of authenticity and integrity. However, most distributed IBS schemes are designed to rely on a trusted Key Generation Center (KGC), which introduces security risks of key escrow and a single point of failure. Meanwhile, the extensive use of cryptographic primitives such as homomorphic encryption and zero-knowledge proofs leads to the inefficiency of most schemes. Therefore, this paper proposes a blockchain-assisted fully distributed IBS scheme for integrating consumer electronics in the metaverse that complies with the IEEE P1363 Standard. In detail, our proposal completely eliminates the need for the trusted KGC and the signing key generation process is distributed among multiple users. In addition, we utilize oblivious transfer instead of homomorphic encryption to construct the signature’s additive share, making our scheme more efficient. Under the discrete logarithm assumption, it has been demonstrated that our scheme possesses existential unforgeability. Finally, based on the theoretical and experimental simulation analyses, our work shows outstanding effectiveness and practicality.
In the next generation of consumer electronics, bitcoin mixing scheme is an essential part to realize decentralized anonymous payment. However, there are still some challenges in existing decentralized schemes. First, existing schemes necessitate broadcast of sensitive information for group construction and lack of machine learning models to make assisted decisions. Second, these schemes fall short in verification of consumers’ integrity prior to their admission. Last but not least, the decentralized protocols tend to lack robust mechanisms for protecting the details of transactions during negotiations. To address the above challenges, this paper proposes a machine learning and zero knowledge empowered trustworthy bitcoin mixing for next-G consumer electronics payment to enhance consumer privacy and transaction details protection. Specifically, we design a mechanism based on zk-SNARKs for verifiable proofs to preserve privacy. Moreover, we construct a model based on machine learning to assist in decision making and verify the integrity by Pedersen commitments. Finally, proposed scheme refines an approach to guard transaction details during negotiations. The experiment demonstrates our approach offers enhanced efficiency and anonymity assurances without sacrificing performance.
The Internet of Things (IoT) has revolutionized industries by enabling the interconnection of devices, creating opportunities for enhanced automation and real-time data analysis. However, the rapid proliferation of IoT devices has introduced significant security vulnerabilities, such as unauthorized access, data manipulation, and privacy breaches. These challenges stem from the inherent limitations of IoT devices, such as low computational power, and the reliance on centralized security models that are susceptible to single points of failure. To address these issues, this paper proposes a Blockchain-Based Secure Framework for IoT devices. Blockchain, a decentralized, immutable, and transparent distributed ledger technology, offers an effective solution for securing IoT networks. By leveraging blockchain's cryptographic features and consensus mechanisms, this framework ensures secure device authentication, data integrity, and transparent communication between IoT devices. Devices can securely authenticate themselves through blockchain-based digital identities, eliminating the need for centralized servers, thus reducing the risk of unauthorized access.Moreover, the framework guarantees data integrity by recording all IoT transactions on the blockchain, making them tamper-proof and verifiable. Blockchain's decentralized nature also mitigates the risk of Distributed Denial of Service (DDoS) attacks by removing central points of vulnerability. Privacy is enhanced through techniques such as zero-knowledge proofs, allowing users to control access to their personal data. This proposed framework not only enhances IoT security but also provides scalability, transparency, and resilience. By combining the strengths of blockchain with IoT, it offers a robust solution for secure, reliable, and privacy-preserving communication in the ever-growing IoT ecosystem. The integration of blockchain technology is poised to transform IoT security, facilitating the secure deployment and management of IoT devices across various industries.
The integration of machine learning with blockchain technology has witnessed increasing interest, driven by the vision of decentralized, secure, and transparent AI services. In this context, we introduce opML (Optimistic Machine Learning on chain), an innovative approach that empowers blockchain systems to conduct AI model inference. opML lies a interactive fraud proof protocol, reminiscent of the optimistic rollup systems. This mechanism ensures decentralized and verifiable consensus for ML services, enhancing trust and transparency. Unlike zkML (Zero-Knowledge Machine Learning), opML offers cost-efficient and highly efficient ML services, with minimal participation requirements. Remarkably, opML enables the execution of extensive language models, such as 7B-LLaMA, on standard PCs without GPUs, significantly expanding accessibility. By combining the capabilities of blockchain and AI through opML, we embark on a transformative journey toward accessible, secure, and efficient on-chain machine learning.
Bjorn Oude Roelink, Mohammed El‐Hajj, Dipti Kapoor Sarmah
Abstract This systematic literature review examines the implementation and analysis of zk‐SNARK, zk‐STARK, and bulletproof non‐interactive zero‐knowledge proof (NIZKP) protocols in privacy‐preserving applications across diverse sectors. Examining 41 research works obtained through the systematic search queries and filtering criteria published from 2015 to April 2023, we categorized findings into financial, medical, business, general, and other domains. Our analysis highlights significant variations of up to several orders of magnitude in real‐world performance across implementations utilizing NIZKP protocols. However, divergent methodologies in security analyses hindered conclusive comparisons. Addressing research gaps, our future endeavors aim to establish a real‐world benchmark for these protocols.
As a distributed ledger, blockchain technology is used to store, secure, and execute interactions in smart grids between entities. This study suggests an automated peer-to-peer electricity market development platform for micro-grids, based on blockchain technology and the multi-agent system paradigm. There are several benefits to using a permissioned blockchain network. Advantages because it makes microtransactions possible and lowers transaction costs. Additionally, a development. After security is achieved, the single point of failure in the administration and control of the platform in addition to making it possible to track back participants' behaviour and a identifying mechanism Additionally, by utilizing ring signatures and Zero-Knowledge Proof protocols, it offers the chance to establish a decentralized and democratic energy market while adhering to the laws and regulations now in place regarding user privacy and data protection.
This paper presents an in-depth examination of privacy-enhancing methodologies in machine learning. It highlights the integration of federated learning with cutting-edge encryption techniques and explores how blockchain architectures contribute to data privacy. A major focus is on federated learning, a decentralized model training strategy, and its combination with privacy-protecting technologies like Homomorphic Encryption, Differential Privacy, and Secure Multi-Party Computation. We emphasize that federated learning naturally improves data privacy and, when paired with cryptographic methods, increases resilience against data breaches and cyber-attacks. Additionally, this study explores the potential of blockchain in enhancing data privacy. Blockchain's immutable and transparent characteristics, supplemented with shuffling technology, zero-knowledge proofs, and ring signatures, improve the confidentiality and integrity of data transactions. The paper also emphasizes the critical need for transparency and explainability in machine learning, advocating for methods that demystify the decision-making processes of ML models. This transparency is crucial for building trust and is becoming a regulatory requirement in many industries. Furthermore, the paper discusses the importance of auditing in machine learning, highlighting the need for comprehensive model validation and ethical considerations. In conclusion, the paper argues that achieving a balance 1 between functionality and privacy in ML applications is essential. It suggests that a combination of federated learning, advanced cryptographic techniques, and explainable AI principles can create effective and privacy-respecting systems.
This paper designs a distributed multi-center identity authentication system based on blockchain technology. By supporting fine-grained declaration descriptions and privacy credentials related to zero-knowledge proof, the system achieves discretionary control of entities, privacy protection of user identities, and trusted data exchange. Since most blockchain-based identity authentication systems are based on public blockchain platforms, they are in essence traditional centralized identity management and verification methods. Therefore, this study establishes an open, transparent, trustworthy underlying identity architecture for users and upper-level applications, demonstrating the effectiveness and usability of the designed system through performance analyses and experiments.
This paper presents a cryptographic solution for establishing trust in peer-to-peer (P2P) networks, addressing issues of privacy, performance, and anonymity. Our protocol utilizes Zero-Knowledge Proofs (ZKP) for continuous trust validation during data transfers. This procedure compels each node to continually demonstrate its integrity, significantly decreasing the potential for network at- tacks. Upon evaluation, the protocol proved to be highly scalable and efficient, expanding network reach without requiring additional control messages. This result validates the protocol’s robustness, suggesting its potential use in larger and more intricate P2P network architectures.
Foteini Baldimtsi, Konstantinos Kryptos Chalkias, Yan Ji, Jonas Lindstrøm · 9 authors
For many users, a private key based wallet serves as the primary entry point to blockchains. Commonly recommended wallet authentication methods, such as mnemonics or hardware wallets, can be cumbersome. This difficulty in user onboarding has significantly hindered the adoption of blockchain-based applications. We develop zkLogin, a novel technique that leverages identity tokens issued by popular platforms (any OpenID Connect enabled platform e.g., Google, Facebook, etc.) to authenticate transactions. At the heart of zkLogin lies a signature scheme allowing the signer to sign using their existing OpenID accounts and nothing else. This improves the user experience significantly as users do not need to remember a new secret and can reuse their existing accounts. zkLogin provides strong security and privacy guarantees. Unlike prior works, zkLogin's security relies solely on the underlying platform's authentication mechanism without the need for any additional trusted parties (e.g., trusted hardware or oracles). As the name suggests, zkLogin leverages zero-knowledge proofs (ZKP) to ensure that the sensitive link between a user's off-chain and on-chain identities is hidden, even from the platform itself. zkLogin enables a number of important applications outside blockchains. It allows billions of users to produce \textit{verifiable digital content leveraging their existing digital identities}, e.g., email address. For example, a journalist can use zkLogin to sign a news article with their email address, allowing verification of the article's authorship by any party. We have implemented and deployed zkLogin on the Sui blockchain as an additional alternative to traditional digital signature-based addresses.
The increasing complexity of identity verification in U.S. banking and fintech ecosystems has highlighted thelimitations of traditional centralized Know Your Customer (KYC) processes, which often involve redundantdata collection, slow onboarding, and increased risk of data breaches. This study explores the design andimplementation of a Decentralized Identity (DID) architecture to enable secure, privacy-preserving, and usercentric KYC. By leveraging self-sovereign identity (SSI) principles, verifiable credentials (VCs), andcryptographic proofs, the proposed framework allows individuals to control their identity data while banks,fintechs, and regulatory authorities can authenticate users efficiently and compliantly. The architectureintegrates permissioned networks, identity wallets, credential issuers, and verifier nodes, supportinginteroperability with existing financial systems. Security, privacy, and regulatory compliance—including AML,FinCEN, and OFAC requirements—are embedded through robust cryptography, zero-knowledge proofs, andselective disclosure mechanisms. The study concludes that DID-enabled KYC can streamline onboarding,reduce operational costs, enhance user privacy, and strengthen overall financial ecosystem trust, providing aviable path for next-generation identity verification in U.S. banking and fintech.
With the widespread application of blockchain technology, various range proof protocols based on zero-knowledge proofs have been proposed. However, existing range proof protocols suffer from issues such as high communication overhead and computational complexity. Therefore, this paper introduces an efficient and secure Zero-Knowledge Set Membership Proof Protocol (ZSMPP) to address these challenges. Building upon improvements to the proof structure of range proof protocols, the paper integrates the SM2 identity-based digital signature algorithm, effectively avoiding the time-consuming bilinear pairing operations and reducing computational costs. The proposed protocol offers an efficient and secure solution for the given problem. Experimental results demonstrate that, compared to protocols proposed by Bootle, Deng, Mao, and others, the protocol presented in this paper exhibits superior computational efficiency, providing an efficient and secure solution for data security and individual privacy protection in the digital age.
The sealed-bid auction enables bidders to secretly send their bids to the auctioneer, which compares all bids and publishes the winning one on the bid-opening day. This type of auction is friendly for protecting the bid privacy, and sufficiently fair for all bidders if the auctioneer acts faithfully. Unfortunately, the auctioneer may not always be trustworthy. The auctioneer has the ability to deliberately leak any bid information to a part of bidders for raising the final winning price based on the investigation. Meanwhile, the auctioneer can appoint any bidder as the winner, as long as the bidder accepts a higher winning price than the current highest bid. Since bidders cannot obtain any bid information from others, to the best of our knowledge, it is difficult to prevent bid leakage from the auctioneer, and support bidders to verify the bid comparison results without disclosing the winning bid, simultaneously. To alleviate these problems, we first construct a homomorphic encryption(HE)-based bid comparison circuit. All bidders can directly compute a cipher of the winning bid by using this circuit; hence, the winning bid does not need to be exposed to all bidders. Then, we propose a blockchain-based sealed-bid scheme (BSS) by integrating the circuit with commitment and zero-knowledge proof. The auctioneer only obtains the commitments of bids before the bid-opening day, and he has to prove that the winner's bid is the same as the plaintext of the bidders' computed cipher. Thus, the auctioneer can neither leak the bid information nor publish a higher winning price during in the auction. Detailed performance analysis shows that the computational complexity of BSS is linear with the binary length of bids.
Marta Irene García Cid, Dileepsai Bodanapu, Alberto Gatto, Paolo Martelli · 6 authors
A new interactive quantum zero-knowledge protocol for identity authentication implementable in currently available quantum cryptographic devices is proposed and demonstrated. The protocol design involves a verifier and a prover knowing a pre-shared secret, and the acceptance or rejection of the proof is determined by the quantum bit error rate. It has been implemented in modified Quantum Key Distribution devices executing two fundamental cases. In the first case, all players are honest, while in the second case, one of the users is a malicious player. We demonstrate an increase of the quantum bit error rate around 25% in the latter case compared to the case of honesty. The protocol has also been validated for distances from a back-to-back setup to more than 60 km between verifier and prover. The security and robustness of the protocol has been analysed, demonstrating its completeness, soundness and zero-knowledge properties.
Andrea Flamini, Giada Sciarretta, Mario Scuro, Amir Sharif · 6 authors
Verifiable credentials are a digital analogue of physical credentials. Their authenticity and integrity are protected by means of cryptographic techniques, and they can be presented to verifiers to reveal attributes or even predicates about the attributes included in the credential. One way to preserve privacy during presentation consists in selectively disclosing the attributes in a credential. In this paper we present the most widespread cryptographic mechanisms used to enable selective disclosure of attributes identifying two categories: the ones based on hiding commitments - e.g., mdl ISO/IEC 18013-5 - and the ones based on non-interactive zero-knowledge proofs - e.g., BBS signatures. We also include a description of the cryptographic primitives used to design such cryptographic mechanisms. We describe the design of the cryptographic mechanisms and compare them by performing an analysis on their standard maturity in terms of standardization, cryptographic agility and quantum safety, then we compare the features that they support with main focus on the unlinkability of presentations, the ability to create predicate proofs and support for threshold credential issuance. Finally we perform an experimental evaluation based on the Rust open source implementations that we have considered most relevant. In particular we evaluate the size of credentials and presentations built using different cryptographic mechanisms and the time needed to generate and verify them. We also highlight some trade-offs that must be considered in the instantiation of the cryptographic mechanisms.