The dynamic landscape of the Internet of Things (IoT) is set to revolutionize the pace of interaction among entities, ushering in a proliferation of applications characterized by heightened quality and diversity. Among the pivotal applications within the realm of IoT, as a significant example, the Smart Grid (SG) evolves into intricate networks of energy deployment marked by data integration. This evolution concurrently entails data interchange with other IoT entities. However, there are also several challenges including data-sharing overheads and the intricate establishment of trusted centers in the IoT ecosystem. In this paper, we introduce a hierarchical secure data-sharing platform empowered by cloud-fog integration. Furthermore, we propose a novel non-interactive zero-knowledge proof-based group authentication and key agreement protocol that supports one-to-many sharing sets of IoT data, especially SG data. The security formal verification tool shows that the proposed scheme can achieve mutual authentication and secure data sharing while protecting the privacy of data providers. Compared with previous IoT data sharing schemes, the proposed scheme has advantages in both computational and transmission efficiency, and has more superiority with the increasing volume of shared data or increasing number of participants.
The increased internet usage after the pandemic led the UN Forum to improve cybersecurity measures, with zero-knowledge proofs (ZKP) being a viable solution for securing confidential information. ZKP protocols can be demonstrated through the binary puzzle, an NP-complete logic puzzle with four specific constraints. The key contribution of this paper is its successful implementation of the genetic algorithm as a new method to solve the binary puzzle. The optimized fitness function determined the solution at an average of 1.33-2.33 generations for populations ranging from 100 to 500. Its quadratic property calculated the solution faster than the ordinary linear fitness function.
Arthur Carvalho, Chad Anderson, Liudmila Zavolokina
Information systems (IS) conferences, as venues for the introduction of new knowledge to the IS community, require effective peer review systems to evaluate submitted research for quality, validity, and originality. We argue in this paper that questionable practices and degrading review quality may arise without direct incentives beyond reviewer altruism to engage in the peer review process. In particular, we highlight potential issues with arguably common practices in some IS conferences, such as peer review invitations sent to researchers who have also submitted papers for publication consideration and the increasing number of reviews performed by graduate students. To address these issues, we suggest three solutions: 1) quid pro quo rules; 2) the use of incentive-compatible methods whose scores are linked to relevant rewards; and 3) the use of blockchain-based tokens in tandem with smart contracts and zero-knowledge proofs. We conclude by offering directions the IS community can take to further study the highlighted issues and implement the proposed solutions.
Ganga Rama Koteswara Rao, Hayder M. A. Ghanimi, V. S. Ramachandran, Dokhyl Al-Qahtani · 6 authors
A significant novel approach in distributed ML, Federated Learning (FL), enables multiple parties to work simultaneously on developing models while securing the confidentiality of their unique datasets. There are issues regarding privacy with FL, particularly for models that are being trained, because private information can be accessed from shared gradients or updates to the model. This investigation proposes SecureHE-Fed, a novel system that improves FL’s defense against attacks on privacy through the use of Homomorphic Encryption (HE) and Zero-Knowledge Proofs (ZKP). Before data from clients becomes involved in the learning procedure, SecureHE-Fed encrypts it. The following lets us determine encrypted messages without revealing the data as it is. As an additional security test, ZKP is employed to verify if modifications to models are valid without sharing the true nature of the information. By evaluating SecureHE-Fed with different FL techniques, researchers demonstrate that it enhances confidentiality while maintaining the precision of the model. The results of this work obtained validate SecureHE-Fed as a secure and scalable FL approach, and we recommend its use in applications where user confidentiality is essential.
Omar Ahmed, Charles Gouert, Nektarios Georgios Tsoutsos
Cloud computing has been a prominent technology that allows users to store their data and outsource intensive computations. However, users of cloud services are also concerned about protecting the confidentiality of their data against attacks that can leak sensitive information. Although traditional cryptography can be used to protect static data or data being transmitted over a network, it does not support processing of encrypted data. Homomorphic encryption can be used to allow processing directly on encrypted data, but a dishonest cloud provider can alter the computations performed, thus violating the integrity of the results. To overcome these issues, we propose PEEV (Parse, Encrypt, Execute, Verify), a framework that allows a developer with no background in cryptography to write programs operating on encrypted data, outsource computations to a remote server, and verify the correctness of the computations. The proposed framework relies on homomorphic encryption techniques as well as zero-knowledge proofs to achieve verifiable privacy-preserving computation. It supports practical deployments with low performance overheads and allows developers to express their encrypted programs in a high-level language, abstracting away the complexities of encryption and verification.
Cross-chain systems provide a way for isolated blockchains to communicate and exchange assets and data with each other. Sidechain-based cross-chain systems support more scenarios with more complicated functionalities. However, the correlation of transactions in two underlying blockchains makes the linkability for the sidechain and exposes the identity of transaction parties and transaction amounts. This incurs the cross-chain privacy leakage. Traditional privacy-preserving mechanisms conversely compromise the regulation of transactions, which limits the identification and punishment to malicious transaction parties. To balance privacy and regulation of cross-chain systems, in this paper, we propose PCP, a privacy-preserving policy-enforcement cross-chain protocol between Monero and Bitcoin. It leverages the signature of knowledge to guarantee the correctness and privacy, while sets a trapdoor for tracing authority to revoke the anonymity when the investigation is required. We instantiate a scheme with formal security proof. We conduct a series of experiments by using Fiat-Shamir paradigm with zero-knowledge and the results show that the proposed PCP is cost-reasonable with constant 150 ms for Swap Monero phase, 40 ms for proof generation and 24 ms for proof verification.
C. Wang, Wei Wu, Fulong Chen, Hong Shu · 9 authors
Blockchain is commonly employed in access control to provide safe medical data exchange because of the characteristics of decentralization, nontamperability, and traceability. Patients share personal health data by granting access rights to users or medical institutions. The major purpose of the existing access control techniques is to identify users who are permitted to access medical data. They hardly ever recognize internal assailants from legitimate entities. Medical data will involve multilayer access within the authorized organizations. Considering the cost of permissions management and the problem of insider malicious node attacks, users hope to implement authorization constraints within the authorized institutions. It can prevent their data from being maliciously disclosed by end‐users from different authorized healthcare domains. For the purpose to achieve the fine‐grained permissions propagation control of medical data in sharing institutions, a trust‐based authorization access control mechanism is suggested in this study. Trust thresholds are assigned to different privileges based on their sensitivity and used to generate zero‐knowledge proof to be broadcasted among blockchain nodes. This method evaluates the trust of each user through the dynamic trust calculation model. And meanwhile, smart contract is employed to verify whether the user’s trust can activate some permissions and ensure the privacy of the user’s trust in the process of authorization verification. In addition, the authorization transaction between users and institutions is recorded on the blockchain for patient traceability and accountability. The feasibility and effectiveness of the scheme are demonstrated through comprehensive comparisons and extensive experiments.
Verification of a deep neural network is required as large DNN models are used in machine learning as a service procedure where the server providing a classification service may be insecure and provide invalid classifications. A verification of deep neural networks in a machine learning as a service paradigm requires verification of function evaluation for all functions of a DNN model given a specific input where the service provider and the server do not want to reveal the DNN model to the client. In this paper, we investigate the privacy-preserving verification problem of the DNN model with zero-knowledge proofs. We have developed a KGZ polynomial commitment scheme based on zero-knowledge proof for such DNN verification. We present an efficient DNN verification using KGZ zero-knowledge proof. We have developed a batch-processing algorithm that can significantly reduce the number of function evaluation verifications. We also prove that a malicious server may not manipulate the proposed verification protocol.
Auditability, privacy, transparency, and resiliency are four essential properties of a central bank digital currency (CBDC) system. However, it is difficult to satisfy these properties at once. This issue has become a crucial challenge to ongoing CBDC projects worldwide. In this article, we propose a novel unspent transaction output (UTXO) model, which offers auditable, privacy-preserving, transparent CBDC payments in a consortium blockchain network. The proposed model adopts a high-speed, non-interactive zero-knowledge proof scheme named zero-knowledge Lightweight Transparent ARgument of Knowledge (zk-LTARK) scheme to verify the ownership of UTXOs. The scheme provides low-latency proof generation and verification while maintaining 128-bit security with a smaller proof size. It also provides memory-efficient, privacy-preserving multi-party computation and multi-signature protocols. By using zk-LTARKs, users do not require numerous private–public key pairs to preserve privacy, which reduces risks in key management. Decentralized identifiers are used to authenticate users without interacting with any centralized server and avoid a single point of failure. The model was implemented in a customized consortium blockchain network with the proof-of-authority consensus algorithm.
The requirements for large amounts of data have promoted the rapid emergence of an industry for trading data. However, the current one-to-one trading constraints in the existing data trading schemes lead to low security and low efficiency. To tackle the challenges, a novel one-to-many distributed data trading scheme is proposed based on blockchain, which enables a data seller to sell one piece of data to multiple data buyers simultaneously, saving storage resources and computing resources significantly. Firstly, some new smart contracts are devised for two decentralized applications. Then, attribute-based searchable encryption technology is proposed to establish a data circulation scheme that realizes end-to-end encryption of data and ensures data security and highly efficient access. Finally, an inspection mechanism based on zero-knowledge proof and a pricing strategy based on the Stackelberg game are designed to guarantee fairness in trading and maximize revenue. The experiment results show that, in comparison to one-to-one trading, the high efficiency of this data trading scheme gradually emerges as the number of buyers (n) is greater than 2, and the run time is less than 1/10 of the former when n =35. Furthermore, the pricing strategy can enable buyers and sellers to obtain more revenue when$\text {n} \gt 4$.
This paper considers introducing asymmetric privacy in the design of central bank digital currencies (CBDC) and digital currencies more generally to preserve the privacy of money spent while keeping the benefits of digital records for money received. It is shown that this feature would help minimize real distortions between consumers, firms, and financiers while enabling tax optimization and better access to external financing. Protecting the privacy of consumers is desirable from a welfare and efficiency standpoint as long as there exist noticeable privacy concerns. Implementing asymmetric privacy is technologically feasible, using, for instance, zero-knowledge proofs or other privacy tools. This paper has been accepted by Lin William Cong for the Virtual Special Issue on Digital Finance. Supplemental Material: The online appendix is available at https://doi.org/10.1287/mnsc.2024.06830 .
This article explores the ethical dilemmas propelled by a significant shift in the allocation of trust and intelligence due to blockchain technology and AI, resulting in a notable decrease in transaction costs. The ethical and political implications of democratizing the resulting productivity gains are noteworthy, and while the pie is expanding, how its slices are distributed remains an open question. Enter Worldcoin, an innovative worldwide initiative that creates an identity system based on proof of personhood and zero-knowledge proofs (ZKP) to provide everyone with a distinct and anonymous "World ID. Using the author's “cyberethics-mix" framework, this paper examines the possible implications of such a system concerning data's protection, ownership, accuracy, and accessibility, underscoring the ethical significance of a political approach emphasizing inclusivity and sustainability through digital decentralization.
Apurva K. Vangujar, Buvana Ganesh, Alia Umrani, Paolo Palmieri
This article presents a novel e-voting scheme that combines Group Identity-based Identification (GIBI) with Homomorphic Encryption (HE) based on the discrete logarithmic assumption. The proposed scheme uses the Schnorr-like GIBI scheme for voter identification and authorization using zero-knowledge proofs to ensure the anonymity and eligibility of voters. The voter$\textsf {v}_{i,j}$is granted the authorization to cast a valid vote for a single candidate$\textsf {C}_{k}$. The use of distributed ElGamal provides fairness while the use of partial shares for decryption enables individual and universal verifiability without the need for a central authority. The proposed scheme is secure under various scenarios and robust in the random oracle model. The GIBI-HE scheme offers a promising solution for e-voting, providing a sustainable and accessible environment for voters while supporting the unreusability of votes and protecting the privacy of voters.