In this paper, we present the exploration of algorithms for the hardware acceleration of multi-scalar multiplication (MSM) on field programmable gate arrays (FPGAs). We have aggregated Verilog and System Verilog implementations of popular algorithms for each component in the MSM processing stack, including large integer multiplication, modular reduction, and elliptic curve point addition, doubling, and scalar multiplication. Additionally, we have compared these algorithms in the context of MSM and evaluated their performance. Our results highlight the efficiency of application specific hardware over general purpose processors for computationally intensive operations. Our contribution provides a valuable resource for those interested in using hardware acceleration to improve the efficiency of zero knowledge proof systems.
Yathin Kethepalli, Rony Joseph, Sai Raja Vajrala, Jashwanth Vemula · 5 authors
Crypto-wallets or digital asset wallets are a crucial aspect of managing cryptocurrencies and other digital assets such as NFTs. However, these wallets are not immune to security threats, particularly from the growing risk of quantum computing. The use of traditional public-key cryptography systems in digital asset wallets makes them vulnerable to attacks from quantum computers, which may increase in the future. Moreover, current digital wallets require users to keep track of seed-phrases, which can be challenging and lead to additional security risks. To overcome these challenges, a new algorithm is proposed that uses post-quantum cryptography (PQC) and zero-knowledge proof (ZKP) to enhance the security of digital asset wallets. The research focuses on the use of the Lattice-based Threshold Secret Sharing Scheme (LTSSS), Kyber Algorithm for key generation and ZKP for wallet unlocking, providing a more secure and user-friendly alternative to seed-phrase, brain and multi-sig protocol wallets. This algorithm also includes several innovative security features such as recovery of wallets in case of downtime of the server, and the ability to rekey the private key associated with a specific username-password combination, offering improved security and usability. The incorporation of PQC and ZKP provides a robust and comprehensive framework for securing digital assets in the present and future. This research aims to address the security challenges faced by digital asset wallets and proposes practical solutions to ensure their safety in the era of quantum computing.
Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Abstract This note is just a modest contribution to prove several classical results in Combinatorics from notions of Duality in some Artinian K -algebras (mainly through the Trace Formula), where K is a perfect field of characteristics not equal to 2. We prove how several classic combinatorial results are particular instances of a Trace (Inversion) Formula in finite $$\mathbb {Q}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Q</mml:mi> </mml:math> -algebras. This is the case with the Exclusion-Inclusion Principle (in its general form, both with direct and reverse order associated to subsets inclusion). This approach also allows us to exhibit a basis of the space of null t -designs, which differs from the one described in Theorem 4 of Deza and Frankl (Combinatorica 2:341–345, 1982). Provoked by the elegant proof (which uses no induction) in Frankl and Pach (Eur J Comb 4:21–23, 1983) of the Sauer–Shelah–Perles Lemma, we produce a new one based only in duality in the $$\mathbb {Q}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>Q</mml:mi> </mml:math> -algebra $$\mathbb {Q}[V_n]$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Q</mml:mi> <mml:mo>[</mml:mo> <mml:msub> <mml:mi>V</mml:mi> <mml:mi>n</mml:mi> </mml:msub> <mml:mo>]</mml:mo> </mml:mrow> </mml:math> of polynomials functions defined on the zero-dimensional algebraic variety of subsets of the set $$[n]:=\{1,2,\ldots , n\}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo>[</mml:mo> <mml:mi>n</mml:mi> <mml:mo>]</mml:mo> <mml:mo>:</mml:mo> <mml:mo>=</mml:mo> <mml:mo>{</mml:mo> <mml:mn>1</mml:mn> <mml:mo>,</mml:mo> <mml:mn>2</mml:mn> <mml:mo>,</mml:mo> <mml:mo>…</mml:mo> <mml:mo>,</mml:mo> <mml:mi>n</mml:mi> <mml:mo>}</mml:mo> </mml:mrow> </mml:math> . All results are equally true if we replace $$\mathbb {Q}[V_n]$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Q</mml:mi> <mml:mo>[</mml:mo> <mml:msub> <mml:mi>V</mml:mi> <mml:mi>n</mml:mi> </mml:msub> <mml:mo>]</mml:mo> </mml:mrow> </mml:math> by $$K[V_n]$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>K</mml:mi> <mml:mo>[</mml:mo> <mml:msub> <mml:mi>V</mml:mi> <mml:mi>n</mml:mi> </mml:msub> <mml:mo>]</mml:mo> </mml:mrow> </mml:math> , where K is any perfect field of characteristics $$\not =2$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mo>≠</mml:mo> <mml:mn>2</mml:mn> </mml:mrow> </mml:math> . The article connects results from two fields of mathematical knowledge that are not usually connected, at least not in this form. Thus, we decided to write the manuscript in a self-contained survey-like style, although it is not a survey paper at all. Readers familiar with Commutative Algebra probably know most of the proofs of the statements described in section 2. We decided to include these proofs for those potential readers not so familiar with this framework.
The rise of modern cryptographic protocols such as Zero-Knowledge proofs and secure Multi-party Computation has led to an increased demand for a new class of symmetric primitives. Unlike traditional platforms such as servers, microcontrollers, and desktop computers, these primitives are designed to be implemented in arithmetical circuits. In terms of security evaluation, arithmetization-oriented primitives are more complex compared to traditional symmetric cryptographic primitives. The arithmetization-oriented permutation Grendel employs the Legendre Symbol to increase the growth of algebraic degrees in its nonlinear layer. To analyze the security of Grendel thoroughly, it is crucial to investigate its resilience against algebraic attacks. This paper presents a preimage attack on the sponge hash function instantiated with the complete rounds of the Grendel permutation, employing algebraic methods. A technique is introduced that enables the elimination of two complete rounds of substitution permutation networks (SPN) in the sponge hash function without significant additional cost. This method can be combined with univariate root-finding techniques and Gröbner basis attacks to break the number of rounds claimed by the designers. By employing this strategy, our attack achieves a gain of two additional rounds compared to the previous state-of-the-art attack. With no compromise to its security margin, this approach deepens our understanding of the design and analysis of such cryptographic primitives.
Double auctions are procedures to trade commodities such as electricity or parts of the wireless spectrum at optimal prices. Buyers and sellers inform the auctioneer what quantity they want to buy or sell at specific prices. The auctioneer aggregates these offers into demand and supply curves and finds the intersection representing the optimal price. In this way, commodities exchange owners in an economically-efficient manner. Ideally, the auctioneer is a trusted third party that does not abuse the information they gain. However, the offers reveal sensitive information about the traders, which the auctioneer may use for economic gain as insider information. These concerns are not theoretical; investigations against auctioneers in electricity and advertisement auctions for manipulating auctions are ongoing. These concerns call for solutions that conduct double auctions in a privacy-preserving and verifiable way. However, current solutions are impractical: To the best of our knowledge, the only solutions satisfying these properties require full interaction of all participants. In this work, we design a more practical solution. We propose the first privacy-preserving and verifiable double auction scheme that does not require traders to interact actively, tailored to electricity trading on (inter)national exchanges. Our solution relies on homomorphic encryption, commitments, and zero-knowledge proofs. In a simulated auction with 256 traders, we observe that traders take up to 10 seconds to generate their order, the auctioneer takes 10 seconds to verify an order, and the auction result is computed and verified in 30 seconds. We extrapolate these results to larger auctions to show the practical potential.
Yuancheng Cai, Shitong Xiang, Min Zhu, Wei Luo · 12 authors
This Letter demonstrates a novel, to the best of knowledge, overlapping single-sideband (OSSB) transmission scheme for spectrally efficient multi-service fiber-wireless (FiWi) access in a low-cost direct-detection (DD) THz system. Utilizing the proposed OSSB scheme, user data from different services can share the same spectrum resource yet can be successfully demodulated via one cost-effective DD THz receiver in conjunction with the Kramers-Kronig (KK) based SSB field reconstruction and look-up table (LUT) enabled signal separation algorithms. A proof-of-principle experiment is conducted. Based on an IQ modulator and a single THz zero-bias diode (ZBD), two independent 10-GBd quadrature phase shift keying (QPSK) signals with an overlapped spectrum are successfully demodulated after 20-km fiber and up to 3-m wireless transmission at the 300-GHz band. To the best of our knowledge, this is the first demonstration of multi-service FiWi access with an OSSB format in a 300-GHz DD THz system.
Evaluating1 the popularity of content, developing personalized recommendation algorithms, and optimizing advertising revenue are crucial aspects of Over-the-Top (OTT) media content services. In order to achieve these goals, accurate viewership measurement of OTT content is essential. However, due to the stringent security policies of mobile platforms, it has been challenging to propose an easy and reliable method for measuring viewership. In this paper, we propose an efficient and secure viewership measurement technique for OTT content on the iOS platforms. The proposed technique utilizes audio filtering and zero-knowledge proof techniques to address the challenges. By leveraging audio filtering, the content can be quickly identified, enabling accurate viewership measurement. Additionally, the use of zero-knowledge proof ensures the protection of users' personal information, preventing indiscriminate acquisition of user data in OTT services.
Aydin Abadi, Dan Ristea, Artem Grigor, Steven J. Murdoch
Time-Lock Puzzles (TLPs) enable a client to lock a message such that a server can unlock it only after a specified time. They have diverse applications, such as scheduled payments, secret sharing, and zero-knowledge proofs. In this work, we present a scalable TLP designed for real-world scenarios involving a large number of puzzles, where clients or servers may lack the computational resources to handle high workloads. Our contributions are both theoretical and practical. From a theoretical standpoint, we formally define the concept of a “Delegated Time-Lock Puzzle (D-TLP)”, establish its fundamental properties, and introduce an upper bound for TLPs, addressing a previously overlooked aspect. From a practical standpoint, we introduce the “Efficient Delegated Time-Lock Puzzle” (ED-TLP) protocol, which implements the D-TLP concept. This protocol enables both the client and server to securely outsource their resource-intensive tasks to third-party helpers. It enables realtime verification of solutions and guarantees their delivery within predefined time limits by integrating an upper bound and a fair payment algorithm. ED-TLP allows combining puzzles from different clients, enabling a solver to process them sequentially, significantly reducing computational resources, especially for a large number of puzzles or clients. ED-TLP is the first protocol of its kind. We have implemented ED-TLP and conducted a comprehensive analysis of its performance for up to 10,000 puzzles. The results highlight its significant efficiency in TLP applications, demonstrating that EDTLP securely delegates 99% of the client’s workload and 100% of the server’s workload with minimal overhead.
Crowdsourcing has emerged as a prevalent method for mitigating the risks of correctness and security in outsourced cloud computing. This process involves an aggregator distributing tasks, collecting responses, and aggregating outcomes from multiple data sources. Such an approach harnesses the wisdom of crowds to accomplish complex tasks, enhancing the accuracy of task completion while diminishing the risks associated with the malicious actions of any single entity. However, a critical question arises: How can we ensure that the aggregator performs its role honestly and each contributor's input is fairly evaluated? In response to this challenge, we introduce a novel protocol termed $\mathsf{zkTI}. This scheme guarantees both the honest execution of the aggregation process by the aggregator and the fair evaluation of each data source. It innovatively integrates a cryptographic construct known as zero-knowledge proof with a category of truth inference algorithms for the first time. Under this protocol, the aggregation operates with both correctness and verifiability, while ensuring fair assessment of data source reliability. Experimental results demonstrate the protocol's efficiency and robustness, making it a viable and effective solution in crowdsourcing and cloud computing.
Recently, the intellectual property protection methods based on deep learning have achieved great success, but there are still serious infringement issues that the network topology or hyper parameters of the trained model are stolen by third parties. In this paper, we construct a deep learning model based on the autoencoder to remove the bone from the medical images containing chest x-ray, and the specific trigger set is trained and predicted to get the effect of the backdoor watermark. The scheme of zero-knowledge proof is applied to transform the backdoor watermark of the model into the fixed-length string, which is published in the block chain to verify the ownership of the model. Through the non-interactive verification between the model owner and the third party, the ownership of the model can be confirmed by the third party and the verification process will not disclose any information of the model itself. The method proposed in this paper can support infinite times of verification and does not reveal any information about the model, so as to achieve the protection of intellectual property rights of the model.
Adversarial Robustness in Machine Learning
Generative Adversarial Networks and Image Synthesis
Zero-knowledge Proof (ZKP) allows active image authentication to prove image integrity after editing without revealing its source. However, existing ZKP solutions require impractical execution time, leaving a considerable gap between theory and practice. To tackle this, we present a Region-Aware Photo Assurance System based on the nature of image editing with privacy: sensitive information is usually local and relatively small, and thus by cropping and/or adding mosaic to these small regions suffices to protect privacy. Using ZKP for the locally edited region and digital signature for the others can still ensure the integrity of an image, with significantly better efficiency. We comprehensively analyzed the system's performance and showed the advantage of our system compared with the state-of-the-art ZKP-based method, PhotoProof, with 15x/60xfaster on the KeyGen/Proof operations and 25x lower in the Proof size. Furthermore, we protect several real-world images selected in the Redaction dataset with our system. Our system achieves up to 2,700x faster than PhotoProof for a proof generation. We expect the system can become a practical system for real-world applications.
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
Electronic voting systems have the potential to improve the efficiency and accessibility of elections, but they also introduce unique challenges in terms of security, privacy, and voter anonymity. In this paper, we propose a secure and privacy-preserving voting system based on zero-knowledge proofs and homomorphic encryption. Our system ensures the integrity, confidentiality, and authenticity of votes while preserving the anonymity of voters. We present the system architecture, design, and implementation, along with a detailed analysis of the cryptographic techniques employed. The evaluation of our proposed system demonstrates its effectiveness, efficiency, and scalability, making it suitable for use in large-scale elections. This work contributes to the ongoing efforts to develop more secure, transparent, and accessible electronic voting systems for the future.
Blockchain-based decentralized identity management provides a promising solution to improve the security and privacy of healthcare systems and make them scalable. Traditional Identity Management Systems are centralized, which makes them single-point-of-failure, vulnerable to attacks and data breaches, and non-scalable. In contrast, decentralized identity management based on the blockchain can ensure secure and transparent access to patient data while preserving privacy. This approach enables patients to control their personal health data while granting permission for medical personnel to access specific information as needed. We propose a decentralized identity management system for healthcare systems named BDIMHS based on a permissioned blockchain with Hyperledger Indy and Hyperledger Aries. We develop further descriptions of required functionalities and provide high-level procedures for network initialization, enrollment, registration, issuance, verification and revocation functionalities. The proposed solution improves data security, privacy, immutability, interoperability, and patient autonomy by using selective disclosure, zero-knowledge proofs, Decentralized Identifiers, and Verifiable Credentials. Furthermore, we discuss the potential challenges associated with implementing this technology in healthcare and evaluate the performance and security of the proposed solution.
Haochen Sun, Tonghe Bai, J. Li, Change Institutions to: University of Waterloo
The recent advancements in deep learning have brought about significant changes in various aspects of people’s lives. Meanwhile, these rapid developments have raised concerns about the legitimacy of the training process of deep neural networks. To protect the intellectual properties of AI developers, directly examining the training process by accessing the model parameters and training data is often prohibited for verifiers. In response to this challenge, we present zero-knowledge deep learning (zkDL), an efficient zero-knowledge proof for deep learning training. To address the long-standing challenge of verifiable computations of non-linearities in deep learning training, we introduce zkReLU, a specialized proof for the ReLU activation and its backpropagation. zkReLU turns the disadvantage of non-arithmetic relations into an advantage, leading to the creation of FAC4DNN, our specialized arithmetic circuit design for modelling neural networks. This design aggregates the proofs over different layers and training steps, without being constrained by their sequential order in the training process. With our new CUDA implementation that achieves full compatibility with the tensor structures and the aggregated proof design, zkDL enables the generation of complete and sound proofs in less than a second per batch update for an 8-layer neural network with 10M parameters and a batch size of 64, while provably ensuring the privacy of data and model parameters. To our best knowledge, we are not aware of any existing work on zero-knowledge proof of deep learning training that is scalable to million-size networks.
The Internet of Medical Things (IoMT) builds a bridge between patients and doctors, facilitating patients’ being diagnosed and monitored by uploading physiological indicators without visiting the hospital. However, physiological indicators are sensitive data of patients, making it a challenge to achieve verifiability of data sources while ensuring data privacy during data transmission of IoMT. Due to its ease of deployment and the ability to provide both encryption and signature, certificateless signcryption (CLSC) is suitable for designing secure data-transfer protocol in IoMT. Nevertheless, internal adversaries “malicious users” and “malicious KGC,” capable of launching Type I and Type II attacks, threaten the security of present CLSC schemes, making most of them insecure. In this work, after giving an example of a recent CLCS scheme suffering Type I attack, we propose an efficient pairing-free CLCS scheme suitable for secure data transmission in IoMT based on the idea of zero-knowledge proof. It not only provides confidentiality and unforgeability of transmitted data under the Type I and Type II attacks but also achieves lower computational and communication overhead, and public verifiability. Finally, compared with the five recent CLSC schemes, theoretical analysis and experimental testing results show that the proposed scheme outperforms the other five schemes in terms of computation and communication costs as well as security. Therefore, our scheme is better suited for constructing secure data transmission in IoMT scenarios.
Electron energy-loss spectroscopy (EELS) and cathodoluminescence (CL) are both powerful tools for the optical characterization of materials such as plasmonic and resonant dielectric nano-structures, probing electronic transitions and the local photonic density of states with nanometric spatial resolution [1]. Up to now, the correlations between electron energy-loss and photon generation have only scarcely been considered, which however has huge potential of increasing measurements sensitivity as recently demonstrated for x-ray & core-loss EELS [2]. In this work, we demonstrate two-order of magnitude contrast enhanced cavity mode imaging enabled by the generation and coincident detection of energy-shifted electrons and intracavity photons, produced in a spontaneous scattering process [3]. We combine a transmission electron microscope (TEM) with a fibre-coupled high-Q silicon nitride (Si3N4) resonator with top air cladding, enabling access to the optical near field for free electrons. The continuous electron beam at 120keV with 25nm focal diameter is passed by the ring resonator in an aloof geometry visualized in Fig. 1a. The stream of single electrons interacts with the vacuum fields of the waveguide, resulting in the generation of single photons by inelastic electron-light scattering [4,5]. In this spontaneous process the electron will lose the corresponding photon quanta of energy. We achieve coincidence detection of generated photons and energy-shifted electrons by employing a single-photon avalanche diode and an event-based electron detector behind an imaging spectrometer (cf. Fig 1a). Analysing the correlation data in time delay to the next photon event and electron energy, we observe a time-independent uncorrelated background around zero energy-loss and a strong coincidence peak at zero time-delay and an electron energy-loss of 0.8 eV, corresponding to a generated photon wavelength around 1550 nm (cf. Fig. 1b). The latter demonstrates the measurement of correlated electron-photon pairs on a single particle level. These pairs can be harnessed for correlation-enhanced imaging by enabling the separation of physical scattering events from independent noise at the detectors. In a proof of concept experiment we demonstrate correlation-enhanced mapping of an optical mode's exponential decay in vacuum. To this end, we scan the focused electron beam across the area in front of the resonator's waveguide and perform an electron-photon correlation measurement for every beam position. When analysing the electron and photon data separately, we observe the known behaviour of tracing the exponential decay up to a point where the detector counts level off at a constant background value, thereby limiting the dynamic range of the measurement (cf. Fig. 1c, blue and orange data). In contrast, the correlated events resolve the evanescent decay of the cavity field over longer distances, due to the strongly reduced background (cf. Fig. 1c, purple). Including the slight decrease in signal intensity, this corresponds to a two-order of magnitude improved dynamic range. In conclusion, we demonstrate contrast-enhanced optical cavity mode imaging, by harnessing the generation and detection of electron-photon pairs. This quantum enhanced imaging allows background-suppression in optical field measurements of nano-structures without requiring prior knowledge of the noise causing processes. Additionally, it improves the differentiation between CL pathways [6]. Moreover, the generation and detection of electron-photon pairs constitutes a crucial step towards future experiments on the quantum nature of free electron-light interactions, investigating the entanglement between photons and electrons. Correlation-enhanced cavity mode imaging. a) Experimental setup: Free electrons in a continuous electron beam traverse a fibre-coupled high-Q Si3N4 microring resonator. In a spontaneous scattering process a photon is emitted into a resonator mode, while the electron experiences energy loss. The generated photons are detected with a single photon counter and the electron energy and arrival time are analysed with an event-based electron detector behind an imaging spectrometer. Both signals are considered in a coincidence scheme, with the photon arrival time used for time tagging. b) Correlation histogram over the electron energy and relative time delay to a photon event, showing a clear coincidence peak at an energy-loss of one photon energy and zero time-delay. c) Imaging of the distant dependent exponential decay of an optical resonator mode. Every data point is acquired by integrating over a line parallel to the resonator's surface. The correlated events show a much smaller background and, thus, a higher dynamic range (DR) compared to the sole electron data and the sole photon data.
Zero-knowledge proof is emerging to enable privacy. Among existing techniques, zk-SNARK (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) [1] supports the shortest verification time and the smallest proof size. However, using zk-SNARK requires the execution of trusted setup ceremony in advance. The trusted setup ceremony generates common reference string (CRS) which is shared with prover and verifier. Currently, an external trusted third party is assumed for trusted setup ceremony, which causes significant security vulnerability in zk-SNARK. In this paper, we propose a blockchain-based protocol of trusted setup ceremony without trusted third party. Three different types of protocols are classified in terms of where to store CRS and how to validate CRS through pairing check. We analyze the protocol complexity of CRS pairing check computations and on-chain storage space.
Wireless body area network (WBAN) is a new technology trend that uses wearable sensors linked to the Internet-of-Things (IoT) network to provide remote tracking and data collection for patient healthcare records. IoT technologies have the potential to change our everyday lives, but they also pose significant security concerns. However, in untrusted wireless environments, the majority of WBAN–IoT data is shared between computationally restricted devices. As a result, protecting sensitive data in WBAN–IoT becomes a crucial challenge. The algorithm had to be lightweight due to the limited computing resources in WBAN sensors or IoT devices. However, significant issues in cloud-based IoT systems must be resolved to recognize the authority of communicators during contact sessions over vulnerable networks like the Internet. To eliminate unauthorized access in IoT applications, a safe authentication, confidentiality, and integrity protocol are highly desirable. Under the hard problem assumptions, our protocol is provably reliable and meets all security criteria, including session key security. In addition, our proposed lightweight secure session key protection, mutual authentication, and access control IoT (LSSMAC-IoT) is considerably greater than the fastest ones shown by the performance evaluation, based on an already existing safe, mutual authentication (MA) process based on heavy homomorphic encryptions and zero-knowledge proof.
We exploit the idea of [Fen22] which proposes to build an efficient signature scheme based on a zero-knowledge proof of knowledge of a solution of a MinRank instance. The scheme uses the MPCitH paradigm, which is an efficient way to build ZK proofs. We combine this idea with another idea, the hypercube technique introduced in [AMGH+22], which leads to more efficient MPCitH-based scheme. This new approach is more efficient than classical MPCitH, as it allows to reduce the number of party computation. This gives us a first scheme called MIRA-Additive. We then present an other scheme, based on low-threshold secret sharings, called MIRA-Threshold, which is a faster scheme, at the price of larger signatures. The construction of MPCitH using threshold secret sharing is detailed in [FR22]. These two constructions allows us to be faster than classical MPCitH, with a size of signature around 5.6kB with MIRA-Additive, and 8.3kB with MIRA-Threshold. We detail here the constructions and optimizations of the schemes, as well as their security proofs.