Samuel Steffen, Benjamin Bichsel, Roger Baumgartner, Martin Vechev
Data privacy is a key concern for smart contracts handling sensitive data. The existing work zkay addresses this concern by allowing developers without cryptographic expertise to enforce data privacy. However, while zkay avoids fundamental limitations of other private smart contract systems, it cannot express key applications that involve operations on foreign data.We present ZeeStar, a language and compiler allowing non-experts to instantiate private smart contracts and supporting operations on foreign data. The ZeeStar language allows developers to ergonomically specify privacy constraints using zkay’s privacy annotations. The ZeeStar compiler then provably realizes these constraints by combining non-interactive zero-knowledge proofs and additively homomorphic encryption.We implemented ZeeStar for the public blockchain Ethereum. We demonstrated its expressiveness by encoding 12 example contracts, including oblivious transfer and a private payment system like Zether. ZeeStar is practical: it prepares transactions for our contracts in at most 54.7s, at an average cost of 339k gas.
In today's era, internet-connected things provide immense opportunities to the world for enhancing the quality of lives through better data processing and intelligent decision making. Since the last decade, IoT brought numerous changes in people's personal as well as professional lives. With the enhancement in quality of lives, IoT also comes up with challenges such as security and privacy of data and devices. Every day, the attacker generates new zero-day attacks for IoT devices and data, and it's important to detect and protect the IoT eco-system from this type of attacks. Numerous researchers have proposed security schemes and methods to protect the IoT eco-system through either cryptography way or learning technique based way. AI and ML learning techniques have got immense popularity in handling the IoT security challenges as they are automatic in nature and can outperform provided the sufficient quality and quantity of data. Moreover, the AI techniques, including ML, DL and FL helps in intelligent decision-making and can also generate knowledge through its learning techniques. AI needs data to process, and IoT supplies the necessary data to process. In this paper, we provide a state-of-the-art survey for IoT security solutions proposed based on learning techniques. We provide an in-depth review of available learning techniques to solve critical security challenges such as IoT authentication, access control, anomaly detection and malware analysis. At the end, we also highlighted various futuristic technologies that can invigorate IoT research and help in the design of full proof IoT eco-system.
The cloud computing technology has emerged, developed, and matured in recent years, consequently commercializing remote outsourcing storage services. An increasing number of companies and individuals have chosen the cloud to store their data. However, accidents, such as cloud server downtime, cloud data loss, and accidental deletion, are serious issues for some applications that need to run around the clock. For some mission and business-critical applications, the continuous availability of outsourcing storage services is also necessary to protect users' outsourced data during downtime. Nevertheless, ensuring the continuous availability of data in public cloud data integrity auditing protocols leads to data privacy issues because auditors can obtain the data content of users by a sufficient number of storage proofs. Therefore, protecting data privacy is a burning issue. In addition, existing data integrity auditing schemes that rely on semi-trusted third-party auditors have several security problems, including single points of failure and performance bottlenecks. To deal with these issues, we propose herein a blockchain-based continuous data integrity checking protocol with zero-knowledge privacy protection. We realize a concrete construction by using a verifiable delay function with high efficiency and proof of retrievability, and prove the security of the proposal in a random oracle model. The proposed construction supports dynamic updates for the outsourced data. We also design smart contracts to ensure fairness among the parties involved. Finally, we implement the protocols, and the experimental results demonstrate the efficiency of the proposed protocol.
Yeray Mezquita, Ana Belén Gil González, A. Martı́n del Rey, Javier Prieto · 5 authors
Blockchain technology is used as a distributed ledger to store and secure data and perform transactions between entities in smart grids. This paper proposes a platform based on blockchain technology and the multi-agent system paradigm to allow for the creation of an automated peer-to-peer electricity market in micro-grids. The use of a permissioned blockchain network has multiple benefits as it reduces transaction costs and enables micro-transactions. Moreover, an improvement in security is obtained, eliminating the single point of failure in the control and management of the platform along with creating the possibility to trace back the actions of the participants and a mechanism of identification. Furthermore, it provides the opportunity to create a decentralized and democratic energy market while complying with the current legislation and regulations on user privacy and data protection by incorporating Zero-Knowledge Proof protocols and ring signatures.
This paper presents an overview of the basic concepts of cryptography and encryption. The work aims at presenting the main concepts and concerns of encryption on a high-level of abstraction, allowing non-domain expert readers to navigate through these topics. Less traditional arguments are also shown, from the relevance of Key Management Services with its usage in Envelope Encryption, to Zero Knowledge proofs and their innovative applications. The crucial importance of securing communications between IoT devices and widely used algorithms to do so, are also discussed.
Abstract Autonomous vehicles (AV) can not only improve traffic safety and congestion, but also have strategic significance for the development of the transportation industry. With the continuous updating of core technologies such as artificial intelligence, sensor detection, synchronous positioning, and high‐precision mapping, the development of AV has been promoted. When 5G network is combined with Internet of Vehicles, the problems of AV can be solved by taking advantage of 5G ultra‐large bandwidth, low latency and high reliability. However, when the user controls the vehicle remotely, a real‐time and reliable authentication process is needed, while minimizing the overhead of security protocols. Therefore, this article proposes a practical and secure multifactor user authentication protocol for AV in 5G network. By introducing non‐interactive zero‐knowledge proof technology and physical uncloning function, the protocol completes mutual authentication and key agreement without revealing any sensitive information. The article proves the security of the protocol through BAN logic and the simulation of Scyther. And it can resist malicious attacks and provide more security features. The informal security analysis shows that the protocol can meet the proposed security requirements. Finally, we evaluate the efficiency of the protocol, and the results show that the protocol can provide better performance.
Path validation assures operational integrity in 5G networks with various network infrastructures where nodes en route are operated by multiple untrusted network slicing authorities. However, in order to correctly validate a path, traditional solutions require the entire path to be revealed to all parties involved, which may potentially expose the network structure to malicious attackers. In this work, we propose a decentralized privacy-preserving path validation protocol utilizing XOR, hashing and Non-interactive zero-knowledge proof (NIZK) that guarantees security and privacy but circumvents performance compromise. We tested our protocols in a simulated multi-authority network to show how the privacy-preserving path validation can protect node privacy without significantly degrading performance.
Xiaoyan Hu, Jun Yin, Guang Cheng, Jian Gong · 7 authors
Due to its efficiency, low overhead, and high scalability, consortium blockchain has been deeply applied in various fields of society. Order financing is one of the scenarios of applying consortium blockchain. Since data on the consortium blockchain is available to the blockchain members, information of a financing order written directly to the blockchain will leak the commercial privacy of the purchaser and supplier. Therefore, the financing order data should be encrypted when published as a transaction on the consortium blockchain. However, the investor needs to verify the financing order data on a consortium blockchain before loaning money to the supplier. It is tricky to efficiently satisfy the verifiability of encrypted financing order data on the consortium blockchain. This work proposes VmppOrder, a verifiable model for privacy-preserving financing orders on a consortium blockchain based on zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARKs). By the supplier publishing zero-knowledge proofs generated from the financing order, the investor can verify the encrypted financing order published on the consortium blockchain without decrypting it. We elaborate on the specific construction of VmppOrder and analyze the security of the constructed circuit with zero-knowledge proof. We implement a prototype of the model on Hyperledger Fabric based on Libsnark and conduct comprehensive experiments to evaluate its performance. Our experimental results validate the efficiency of the proposed model. Its order proof generation takes about 6.31 seconds, the order verification takes only 2.58 milliseconds, and the transaction processing speed is about 660 transactions per second on a moderately equipped machine.
Large-scale applications of electronic medical records (EHRs) based on blockchain technology have prompted us to find an intelligent way to realize insurance compensation, which brings convenience for both insurance companies and patients. However, due to the public verifiability of blockchains, straightforward utilizing a blockchain to construct an insurance compensation scheme would cause leakage of patients’ privacy. In this paper, we propose an agent compensation model based on smart contract to guarantee the credibility of EHRs and to enable automatical insurance compensation without requiring interactions between insurance companies and patients. A hybrid smart contract privacy-preserving insurance compensation scheme is put forward based on the agent compensation model. The "private" and "public" smart contracts are deployed on the private and public blockchain respectively. By designing private smart contracts, we limit the visitors of private data and prevent third parties from accessing patient private data. By deploying public smart contract that introduces zero-knowledge proof and blockchain oracles, we realize compensations information verification and agent payment without privacy data leakage. Security analysis and performance evaluations are conducted to prove that our scheme is secure against various attacks while achieving high efficiency.
In recent years a new class of symmetric-key primitives over $\mathbb{F}_p$ that are essential to Multi-Party Computation and Zero-Knowledge Proofs based protocols have emerged. Towards improving the efficiency of such primitives, a number of new block ciphers and hash functions over $\mathbb{F}_p$ were proposed. These new primitives also showed that following alternative design strategies to the classical Substitution-Permutation Network (SPN) and Feistel Networks leads to more efficient cipher and hash function designs over $\mathbb{F}_p$ specifically for large odd primes $p$. In view of these efforts, in this work we build an \emph{algebraic framework} that allows the systematic exploration of viable and efficient design strategies for constructing symmetric-key (iterative) permutations over $\mathbb{F}_p$. We first identify iterative polynomial dynamical systems over finite fields as the central building block of almost all block cipher design strategies. We propose a generalized triangular polynomial dynamical system (GTDS), and based on the GTDS we provide a generic definition of an iterative (keyed) permutation over $\mathbb{F}_p^n$. Our GTDS-based generic definition is able to describe the three most well-known design strategies, namely SPNs, Feistel networks and Lai--Massey. Consequently, the block ciphers that are constructed following these design strategies can also be instantiated from our generic definition. Moreover, we find that the recently proposed \texttt{Griffin} design, which neither follows the Feistel nor the SPN design, can be described using the generic GTDS-based definition. We also show that a new generalized Lai--Massey construction can be instantiated from the GTDS-based definition. We further provide generic analysis of the GTDS including an upper bound on the differential uniformity and the correlation.
We prove that for every 3-player (3-prover) game $\mathcal G$ with value less than one, whose query distribution has the support $\mathcal S = \{(1,0,0), (0,1,0), (0,0,1)\}$ of hamming weight one vectors, the value of the $n$-fold parallel repetition $\mathcal G^{\otimes n}$ decays polynomially fast to zero; that is, there is a constant $c = c(\mathcal G)>0$ such that the value of the game $\mathcal G^{\otimes n}$ is at most $n^{-c}$. Following the recent work of Girish, Holmgren, Mittal, Raz and Zhan (STOC 2022), our result is the missing piece that implies a similar bound for a much more general class of multiplayer games: For $\textbf{every}$ 3-player game $\mathcal G$ over $\textit{binary questions}$ and $\textit{arbitrary answer lengths}$, with value less than 1, there is a constant $c = c(\mathcal G)>0$ such that the value of the game $\mathcal G^{\otimes n}$ is at most $n^{-c}$. Our proof technique is new and requires many new ideas. For example, we make use of the Level-$k$ inequalities from Boolean Fourier Analysis, which, to the best of our knowledge, have not been explored in this context prior to our work.
Non-interactive zero-knowledge proof or argument (NIZK) systems are widely used in many security sensitive applications to enhance computation integrity, privacy and scalability. In such systems, a prover wants to convince one or more verifiers that the result of a public function is correctly computed without revealing the (potential) private input, such as the witness. In this work, we introduce a new notion, called scriptable SNARK, where the prover and verifier(s) can specify the function (or language instance) to be proven via a script. We formalize this notion in UC framework and provide a generic trusted hardware based solution. We then instantiate our solution in both SGX and Trustzone with Lua script engine. The system can be easily used by typical programmers without any cryptographic background. The benchmark result shows that our solution is better than all the known SNARK proof systems w.r.t. prover’s running time (1000 times faster), verifier’s running time, and the proof size. In addition, we also give a lightweight scriptable SNARK protocol for hardware with limited state, e.g., Θ ( λ ) bits. Finally, we show how the proposed scriptable SNARK can be readily deployed to solve many well-known problems in the blockchain context, e.g. verifier’s dilemma, fast joining for new players, etc.
Elliptic curve pairings are a powerful tool and a popular way to construct zero-knowledge proofs, which are beginning to be used in blockchains as a way to provide privacy in the transaction ledger.
Απόδειξη είναι η επικύρωση συμπερασμάτων με την εφαρμογή λογικών επιχειρημάτων και κανόνων σε υποθέσεις. Στα μαθηματικά, ένας ισχυρισμός για να γίνει δεκτός ως αληθής ή έγκυρος πρέπει να συνοδεύεται από απόδειξη. Ωστόσο, αποδεικτικές διαδικασίες δεν υπάρχουν μόνο στα μαθηματικά, αλλά σχεδόν παντού – στις φυσικές επιστήμες, στην επιστήμη των υπολογιστών, στη νομική και ηθική επιχειρηματολογία, στη φιλοσοφία και ούτω καθεξής. Κατά τη διάρκεια της αποδεικτικής διαδικασίας, απαιτείται διάλογος μεταξύ των δρώντων (agents) για να διευκρινιστούν τα ασαφή βήματα, να καλυφθούν κενά ή να αποδειχθούν έμμεσες υποθέσεις σε μια μη ολοκληρωμένη απόδειξη. Κατά συνέπεια, η επιχειρηματολογία είναι αναπόσπαστο συστατικό της διαδικασίας ανακάλυψης των αποδείξεων γενικότερα αλλά και –πιο συγκεκριμένα– στις μαθηματικές αποδείξεις. Το πρώτο σκέλος της εργασίας παρουσιάζει πώς οι θεωρίες επιχειρηματολογίας που βασίζονται στη λογική μπορούν να εφαρμοστούν για να περιγράψουν συγκεκριμένα χαρακτηριστικά στην ανάπτυξη των αποδεικτικών συμβάντων (proof-event), τονίζοντας τη σχέση μεταξύ επίσημης απόδειξης, άτυπου ανθρώπινου συλλογισμού, γνωστικών διαδικασιών και κοινωνικών αλληλεπιδράσεων. Η έννοια του αποδεικτικού συμβάντος επινοήθηκε από τον Goguen, ο οποίος περιέγραψε τη μαθηματική απόδειξη ως ένα κοινωνικό γεγονός που λαμβάνει χώρα σε συγκεκριμένο χώρο και χρόνο, σχεδιασμένο να καλύπτει όχι μόνο τις «παραδοσιακές» τυπικές αποδείξεις αλλά όλα τα είδη αποδείξεων, συμπεριλαμβανομένων των ελλιπών ή υποθετικών αποδείξεων. Στις πραγματικές γνωστικές διαδικασίες, ο άτυπος ανθρώπινος συλλογισμός και οι κοινωνικές πτυχές παίζουν σημαντικό ρόλο. Η προσέγγισή μας επιχειρεί να κάνει τα αποδεικτικά συμβάντα πιο περιεκτικά για να εκφράσει την πλήρη τροχιά μιας μαθηματικής διαδικασίας, συμπεριλαμβανομένων τόσο των τυπικών όσο και των άτυπων βημάτων απόδειξης, μέχρι την τελική επικύρωση του αποτελέσματος της απόδειξης. ΄Ετσι, παρουσιάζουμε μια εκτεταμένη εκδοχή του λογισμού αποδεικτικών συμβάντων με το όνομα Argumentation-based ProofEvent Calculus (APEC), η οποία βασίζεται σε θεωρίες επιχειρηματολογίας των Pollock, Toulmin και Kakas που έχουν σχεδιαστεί για να μπορούν να καταγράφουν την εσωτερική και εξωτερική δομή μιας συνεργατικής μαθηματικής πρακτικής. Στο δεύτερο σκέλος της εργασίας παρουσιάζονται δύο πεδία εφαρμογής για να τονιστεί η αποτελεσματικότητα και η εκφραστικότητα των βασισμένων στη λογική προσεγγίσεων σε πραγματικά σενάρια αποδεικτικών διαδικασιών. Το πρώτο πεδίο αφορά άμεσες πρακτικές μαθηματικής απόδειξης που μπορούν να εφαρμοστούν είτε για μια εις βάθος ανάλυση των εσωτερικών βημάτων σε μια μαθηματική απόδειξη, όπως υποδεικνύεται στο παράδειγμα των Zero Knowledge Proofs, είτε για τη μοντελοποίηση μιας πιο εξωτερικής προοπτικής για την ανάδειξη των κοινωνικών αλληλεπιδράσεων και της εξέλιξης κατά τη διάρκεια μιας διαδικασίας απόδειξης πολλών δρώντων, όπως απεικονίζεται στα παραδείγματα του Mini-Polymath 4 πρότζεκτ και του Τελευταίου Θεωρήματος του Φερμά. Το δεύτερο πεδίο αφορά έμμεσες διαδικασίες απόδειξης που αναφέρονται σε ηθικές και νομικές πτυχές των ιατρικών συσκευών και των φορητών ρομπότ (wearable robots). Τα νομικά μοντέλα τεχνητής νοημοσύνης στον ιατρικό τομέα μπορούν να εκφραστούν αποτελεσματικά μέσω συστημάτων που βασίζονται στη λογική, όπου ένα νομικό κείμενο περιγράφεται από κανόνες που μπορούν να εκφράσουν νομικά επιχειρήματα και εξαιρέ- σεις και μπορούν να ελεγχθούν και να παράσχουν επεξηγήσεις για το πώς αποδείχθηκε ένα συγκεκριμένο συμπέρασμα. Τα συστήματα με βάση τη λογική που παρουσιάζονται σε αυτήν την εργασία είναι: το WeaRED, ένα σύστημα ηθικής λήψης αποφάσεων σχετικά με το απόρρητο των προσωπικών δεδομένων των Wearable Robots, τα συστήματα AMeDC και Medical Devices Rules σχετικά με τη νομοθεσία για τα ιατροτεχνολογικά προϊόντα, και το σύστημα ExosCE σχετικά με το νομικό καθεστώς των εξωσκελετών.
Many existing searchable encryption schemes are inflexible in retrieval patterns. The data usage authorization is almost permanent valid as long as the user is not revoked. This “all-or-nothing” authorization mode is not compatible with the “pay-as-you-use” commercial billing model. In this article, we propose a new notion called time controlled expressive predicate query with accountable anonymity. It realizes time controlled data query, where a time server issues time token to authorize search privilege in designated time period. The data users can anonymously query on encrypted data and the anonymity is accountable in a way that the trusted authority is able to deanonymize data users if they misbehave in the system. The underlying techniques are anonymous credential, Pederson commitment and non-interactive zero-knowledge proof. We firstly design an efficient expressive predicate query (EPQ) scheme, which is proved secure to protect the privacy of expressive search predicate. Based on EPQ, we present a concrete system instantiation, which realizes key-escrow free and time token nontransferability. The formal definition and security models are given out. The system is formally proved indistinguishable against chosen keyword-set attacks, unforgeable of time tokens and accountable of anonymous users. The comparison and experiment results demonstrate its scalability and efficiency.
Remote voting has become more critical in recent years, especially since the COVID-19 outbreak. Blockchain technology and its benefits such as decentralization, security, and transparency have given rise to proposals for blockchain-based voting systems. However, the traceability of blockchain transactions violates voter anonymity in existing proposals. Besides, transaction costs also need to be considered. Solutions that may cause repeated elections should be avoided for a low-cost scalable voting system. In this work, we propose ElectAnon, a blockchain-based, self-tallying, and ranked-choice voting protocol focusing on anonymity, robustness, and scalability. ElectAnon achieves anonymity by enabling voters to register with identity commitments and cast their votes via zero-knowledge proofs. Robustness is realized by removing the direct control of the authorities in the voting process by using timed-state machines. Each voter encodes the ballot into a single integer and blinds the vote off-chain while making the verification on-chain. This makes the protocol infinitely scalable in the number of voters. ElectAnon is also a solution for governance in Decentralized Autonomous Organizations (DAO): It includes a candidate proposal module and an algorithm-agnostic mechanism to plug-in different tallying methods easily. The Merkle forest extension is proposed for conducting even more trustless elections. ElectAnon is implemented with smart contracts based on Ethereum Virtual Machine (EVM) and a zero-knowledge gadget, Semaphore. The implementation also includes two different sophisticated tallying methods, Borda Count and Tideman. Experimental results show that a 40-voter and 10-candidate election can be implemented with the gas consumption reduced up to 89% compared to previous works. While other studies could not exceed a 25,000-voter setup, ElectAnon has been observed to run safely for 1,000,000 voters. The implementation can be found at https://github.com/ceyonur/electanon .
Counterfeiting drugs has been a global concern for years. Considering the lack of transparency within the current pharmaceutical distribution system, research has shown that blockchain technology is a promising solution for an improved supply chain system. This study aims to explore the current solution proposals for distribution systems using blockchain technology. Based on a literature review on currently proposed solutions, it is identified that the secrecy of the data within the system and nodes' reputation in decision making has not been considered. The proposed prototype uses a zero-knowledge proof protocol to ensure the integrity of the distributed data. It uses the Markov model to track each node's 'reputation score' based on their interactions to predict the reliability of the nodes in consensus decision making. Analysis of the prototype demonstrates a reliable method in decision making, which concludes with overall improvements in the system's confidentiality, integrity, and availability. The result indicates that the decision protocol must be significantly considered in a reliable distribution system. It is recommended that the pharmaceutical distribution systems adopt a relevant protocol to design their blockchain solution. Continuous research is required further to increase performance and reliability within blockchain distribution systems.
José L. Muñoz, Marta Bellés, Miguel Isabel, Albert Rubio · 5 authors
A zero-knowledge (ZK) proof guarantees that the result of a computation is correct while keeping part of the computation details private. Some ZK proofs are tiny and can be verified in short time, which makes them one of the most promising technologies for solving two key aspects: the challenge of enabling privacy to public and transparent distributed ledgers and, enhancing the scalability limitations of distributed ledgers. Most practical ZK systems require the computation to be expressed as an arithmetic circuit that is encoded as a set of equations called rank-1 constraint system (R1CS). In this paper, we present \circom, a programming language and a compiler for designing arithmetic circuits that are compiled to R1CS. More precisely, with \circom, programmers can design arithmetic circuits, and the compiler outputs (i) a file with the R1CS description, (ii) \wasm and \cpp programs to efficiently compute all values of the circuit. We also provide an open-source library called \circomlib, with multiple circuit templates. Moreover, \circom can be complemented with \snarkjs, a tool for generating and validating ZK proofs from R1CS. Altogether, our software tools abstract the complexity of the proving mechanisms and provide a friendly interface to model low-level descriptions of arithmetic circuits.
Christopher R. Carpenter, Lucas Oliveira J. e Silva, Suneel Upadhye, Joshua Broder · 5 authors
Emergency medicine is often a specialty defined by diagnostic uncertainty when worried patients present with constellations of symptoms seeking explanation and relief. Abdominal pain is a common chief complaint among adult emergency department (ED) patients, with recurrent symptoms in the subsequent days, weeks, months, and even years, sometimes prompting repeat evaluations.1 The differential diagnosis is broad and diverse, including multiple organs and systems and extraabdominal causes. Ideally, clinical practice guidelines (CPGs) synthesize the entirety of evidence for questions relevant to an explicitly defined patient population and outcomes, but until now no CPG existed for the scenario of recurrent abdominal pain. Consequently, significant practice variation exists in the diagnostic and therapeutic approach to this clinical condition.2 The Society for Academic Emergency Medicine (SAEM) second "Guidelines for Reasonable and Appropriate Care in the Emergency Department 2 (GRACE-2)" article provides that CPG with adherence to Grading of Recommendations, Assessment, Development and Evaluations (GRADE) methodology including incorporation of patient priorities and external stakeholders.3 Through adherence to the GRADE methodology we aimed to create rigorous and trustworthy guidelines. The GRACE-2 writing team deliberated to select topics and questions and to explicitly define a clinically meaningful population, ultimately settling on definitions of recurrence within 30 days and adults with "low-risk" abdominal pain. Identifying no well-accepted or validated definition of "low risk" (as opposed to a risk model like the HEART score for chest pain4), the GRACE-2 writing team devised a definition of "low risk" that resonated with our clinical intuition and excluded populations that emergency physicians would routinely identify as moderate or high risk. Subsequently, the GRACE-2 writing team worked with medical librarians to focus searches based on the patient-intervention-control-outcome-time (PICOT) template5 and completed systematic reviews for each question before developing the recommendations.6, 7 The PICOT-oriented literature search revealed no studies that aligned with our definition of low risk and few that defined recurrence within our predefined time frame. However, that does not mean that our search rendered zero published evidence around which GRACE-2 could contemplate actionable recommendations via the GRADE Evidence to Decision (EtD) framework.8, 9 We had to make a decision about how to classify and incorporate the published research that we did identify. GRADE provides a framework for evidence synthesis and development of clinical guidelines and recommends inclusion of both direct and indirect evidence into CPGs, while providing guidance around the distinction between the two.8-12 Therefore, we decided to classify evidence as "direct" if each element of the PICOT question matched the study's inclusion criteria and outcomes assessed. "Indirect" evidence was defined by deviation from any component of the PICOT question (Table 1). These definitions are necessary for guideline developers who need to evaluate the domain of indirectness when rating the certainty of evidence.10, 12 Since the overall value of CPGs rests upon the rigor and transparency of the evidentiary search, quality assessment, and synthesis in conjunction with an explicit and representative assessment of anticipated benefits or potential harms of the subsequent recommendations, weighing the pros and cons of including indirect evidence is merited while considering if and how to incorporate the GRACE-2 recommendations into ED practice. Not emergency department Not adult Not recurrent Not undifferentiated abdominal pain Not low risk Initial CT identified explanatory pathology like kidney stone Repeat CT >12 months after initial CT GRADE recognizes indirectness as a key domain in the assessment of certainty of evidence.10, 12 Whenever systematic review authors or guideline developers identify important indirectness issues from a body of evidence that deviates from the original PICOT question, the certainty of evidence must be downgraded by one or two levels.10, 12 Despite such guidance from GRADE, conceptualization of what type of indirect evidence could be synthesized and used by CPGs remains debatable, especially when there is insufficient direct evidence.13 Also, a second layer of complexity is added when guideline developers need to evaluate the directness of research evidence for all criteria of the GRADE EtD framework including values, resources, cost-effectiveness, equity, acceptability, and feasibility. This cognitive framework can quickly diffuse into uncertainties. Nonetheless, indirect evidence is not fundamentally or inevitably flawed. For example, a study might be rated as indirect because the age range of enrolled subjects does not perfectly match the intended population or because the time frame of follow-up slightly exceeds the desired target. Such evidence may provide a very reasonable estimate of the range of expected outcomes in the intended population. In addition, many randomized controlled trials employ so many exclusion criteria and carefully controlled experimental conditions that the results may not predict outcomes in a broader ED population. GRADE attempts to distill value from the broad range of available evidence, rather than taking a nihilistic attitude that rejects evidence on the basis of any imperfection. Nihilism suggests "we know nothing" and have no basis for any decision—but emergency medicine requires that physicians make the best decision possible based on the available, if imperfect, evidence in a more pragmatic approach. GRADE recommends that if a large body of indirect evidence that can be convincingly linked to the PICOT support the management strategy, recommendations should be made.14 Specifically, GRADE states that "clinicians will rarely explore the evidence as thoroughly as a guideline panel, nor devote as much thought to the trade-offs, or the possible underlying values and preferences in the population. We therefore encourage panels to deal with their discomfort and to make recommendations even when confidence in effect estimate is low and/or desirable and undesirable consequences are closely balanced."15 The ideal strategy to dealing with absent direct evidence for a certain question during CPG development is not fully established among guideline developers, and each panel along with their methodologists need to individualize such decisions according to resource availability (e.g., methodological expertise, funding) and feasibility. Murad et al.,13 for example, suggest five strategies for supplementing systematic review findings when evidence on benefits or harms is found to be insufficient, including: (1) reconsider eligible study designs, (2) summarize indirect evidence, (3) summarize contextual and implementation evidence, (4) consider modeling, and (5) incorporate unpublished health system data in the evidence synthesis. In GRACE-2, summary of indirect evidence was chosen as the main approach and different "bodies of indirect evidence" were systematically synthesized.6, 7 As three out of four questions in GRACE-2 were related to diagnostic tests, we also faced the reality that direct evidence evaluating the impact of different testing strategies on patient-important outcomes (i.e., diagnostic randomized trials) seldom exists, which ultimately leads to the use of different types of indirect evidence such as diagnostic accuracy.16-18 Even within the adaptive framework of GRADE, indirect evidence may leave the PICOT question unanswered, and subsequent recommendations are often necessarily weak or nonexistent. Strong and definitive recommendations necessitate multiple studies evaluating the identical patient population and diagnostic approach quantifying the same outcomes in similar time frames with minimal concerns about health inequities, resource consumption, imprecision, or feasibility. Indirect evidence alone is unlikely to justify strong recommendations, but does provide substantive proof of the scope of the problem relative to the paucity of evidence. If the indirect evidence was excluded, CPG stakeholders would not be cognizant that this research was identified and reviewed in developing the recommendations. Clinicians, educators, and researchers would remain unaware of how little empiric evidence exists around which to shape decision making or how future investigators could more directly address the knowledge void. GRACE-2 is not alone in identifying a painfully surprising gap between what emergency medicine thinks is common knowledge and high-quality research to justify those beliefs. One reflection of this is that the majority of American College of Emergency Physician Clinical Policy recommendations are not level A.19 Ultimately, concerns about the directness of evidence for CPGs represent an existential crisis for emergency medicine. As society's safety net for potentially life-threatening medical, surgical, or psychiatric illness, emergency medicine's breadth of knowledge must remain broad and open-ended as clinical science continues to expand the horizons of possibility. The hierarchy of evidence-based medicine places CPGs at the top of the information pyramid, yet guidelines for common syndromic presentations like acute abdominal pain do not exist in emergency medicine. Certainly, our specialty could await others to create CPGs for these conditions, but those organizations are most likely to view patient encounters through the lens of an established or highly suspected diagnosis. In contrast, emergency physicians confront undifferentiated patients with constellations of signs and symptoms in a chaotic environment. We navigate the challenges of accurate and timely diagnosis, often with imperfect data. Paradoxically, we face expectations of constraint with testing—often without evidence-based guidance for when to safely limit workups—while avoiding critical misses. Experience with other organization's CPGs has shown that ED clinicians are often noncompliant with their recommendations, which commonly do not account for the real-life conditions of emergency care. The consequence is an unfair judgment that emergency physicians engage in inferior, non–evidence-based, and excessively costly health care by external stakeholders.20-23 The Association of Academic Chairs of Emergency Medicine's 2030 research goals focus on increasing the proportion of NIH R01-funded emergency medicine investigators, who will someday close the knowledge gap for prevalent conditions that currently remain underinvestigated.24 The absence of direct evidence and the imperfection of indirect evidence for high-priority emergency medicine CPGs illustrates the importance of forming a National Institute of Emergency Care. In addition to supporting the next generation of independent health-outcomes researchers, a central prioritizing body could ensure that the most pertinent questions affecting patient care on a daily basis are the focus of funding opportunities.19, 25 Until that day, GRACE-2 provides a synthesis of evidence and corresponding recommendations derived using GRADE methodology upon which to guide imaging and therapy decisions for adults with low-risk and recurrent abdominal pain. Medicine is equal parts science and art with clinical judgment based on hermeneutic thinking to generate a holistic understanding of an individual patient's current condition.26 Our vision is for the inclusion of direct and indirect evidence in this CPG to ground that decision making in a realistic understanding of our current state of knowledge, while catalyzing more pertinent research in the near future.
Dan Bogdanov, Joosep Jääger, Peeter Laud, Härmel Nestra · 10 authors
We present ZK-SECREC, a domain-specific language for zero-knowledge (ZK) proofs. We focus on its type system, making the point that this is the most appropriate mechanism for tracking information flows in a statement that is meant to be proved using a zero-knowledge protocol. The appropriateness stems from the necessary distinctions between the two involved parties and between the computations made locally or on top of the protocol. The appropriateness also stems from how the types match with the major steps of typical ZK protocols, including the generation of Common Reference Strings. We compare the type system of ZK-SECREC with those of the previously proposed languages for ZK proofs and privacy-preserving computations, and show how ZK-SECREC handles certain aspects better.
With the rapid development of blockchain, big data, cloud computing, and artificial intelligence, the security of multisource data collaborative computing has become increasingly prominent. Secure multiparty computing has become the core technology of privacy collaborative computing. Millionaires’ problem is the cornerstone of secure multiparty computation. Firstly, this paper proposes a 0-1 coding rule, which is used to solve the millionaires’ problem under the semihonest model. Aiming at the possible malicious behaviors of the protocol under the semihonest model, the millionaires’ problem protocol under the malicious model based on the elliptic curve cryptography is designed by using cryptographic tools such as the zero-knowledge proof and the cut-choose method. This protocol not only can effectively solve the millionaires’ problem but also can safely and effectively prevent malicious behaviors. Meanwhile, the security ordering designed by the protocol can be effectively applied to a quality evaluation in the blockchain.
The Robustness of any cryptographic technique gives us an idea about how that technique is asymptotically secure (asymptotic security), efficient, and can defeat different types of attacks on it. In this research, analysis and study have been done about how non-black-box technique called zero-knowledge proofs, can be used with RSA (Rivest, Shamir, Adleman) problem. One of the better algorithms for factoring needed by the RSA problem is general number field sieve factoring. The efficiency of general number field sieve factoring for RSA problem and discrete logarithm problem is analyzed and compared with each other; covariance between their asymptotic functions is calculated which clearly shows that they are strongly correlated with each other.