Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

2,611 papersLast indexed Aug 31, 2026
Search papers

Paper index

2,611 results · page 22 of 109

Clear filters
Aug 24, 2024·Jurnal Online Informatika
3 cites
Strengthening the Authentication Mechanism of Blockchain-Based E-Voting System Using Post-Quantum Cryptography

Sonitema Laia, Ari Moesriami Barmawi

Election systems often face severe challenges regarding security and trust. Threats such as vote falsification and lack of transparency in vote counting have shaken the integrity of elections in various countries. The use of blockchain technology in e-voting has been proposed as an attractive solution to overcome this problem. Several studies use blockchain for the security of electronic voting systems. The existing methods are not resistant against impersonation attacks and man-in-the-middle attacks. This research proposes a new scheme to strengthen a blockchain-based e-voting system. The blockchain used in the proposed method is Ethereum. The proposed scheme uses the modified framework and The Goldreich-Goldwasser-Halevi (GGH) signature scheme. Digital signatures generated using Goldreich-Goldwasser-Halevi (GGH) can strengthen the identity of the message sender so that enemies cannot imitate someone. In this research, the Voter's public key and anonymous ID are used by the Voter to maintain the Voter's anonymity. Based on the experimental results, it can be concluded that the proposed scheme is stronger than the previous scheme because the probability of success in impersonating the sender with the proposed scheme using an impersonation attack and man-in-the-middle attack is small.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Original source
Aug 20, 2024·IEEE Transactions on Dependable and Secure Computing
12 cites
S3Voting: A Blockchain Sharding Based E-Voting Approach With Security and Scalability

Meiqi Li, Kaiping Xue, Xinyi Luo, Wentuo Sun · 7 authors

Electronic voting plays a crucial role in facilitating democratic and convenient decision-making in people’s lives. However, implementing an electronic voting system poses challenges, such as meeting the stringent security requirements for anonymity, fairness, and verifiability. Another concern is the performance degradation when dealing with a large number of voters. In this paper, we propose$S^{3}$Voting, a blockchain sharding-based e-voting scheme that addresses these challenges. By combining robust security and scalability,$S^{3}$Voting provides reliable technical support for conducting large-scale elections. Utilizing advanced technologies such asHomomorphic Time-Lock Puzzle (HTLP)andone-time ring signature, the system safeguards voters’ privacy and ballot confidentiality. The approach involves dividing voters and miners into smaller shards, and implementing shard managing mechanisms to ensure security and enhance system efficiency. Through thorough security analysis, we demonstrate that$S^{3}$Voting not only meets the fundamental security requirements of e-voting but also offers verifiability and strong robustness-essential elements for successful large-scale elections. Moreover, experimental results indicate that$S^{3}$Voting significantly reduces the computational burden on individual miners and minimizes system processing time compared to existing blockchain-based e-voting solutions.

Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Original source
Aug 19, 2024·2024 IEEE International Conference on Blockchain (Blockchain)
6 cites
Enhancing Security and Scalability in Electronic Voting Through Privacy-Preserving Cryptography and Efficient Data Structures

George Misiakoulis, Harris Niavis, Stéphane Kündig, Konstantinos Loupos

E-voting systems often face risks such as data breaches, vote manipulation, and lack of voter confidence. Balancing security and anonymity has posed significant obstacles that obscured the immense potential of electronic voting systems. This paper addresses critical challenges in e-voting, including security vulnerabilities, lack of transparency, scalability and user accessibility issues. We propose a privacy-preserving framework to tackle these challenges, enhancing the security, transparency and scalability of e-voting systems. Our framework leverages blockchain to provide a tamper-evident ledger, zero-knowledge proofs to ensure ballot secrecy and data integrity and Merkle Trees to facilitate data storage in a scalable manner. Furthermore, we present findings of the framework's performance that was conducted under an e-voting use case, while we suggest improvements towards an even more secure and transparent framework.

Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Cryptography and Data Security
Original source
Aug 19, 2024·arXiv
3 cites
The On-Chain and Off-Chain Mechanisms of DAO-to-DAO Voting

Thomas Lloyd, Daire O’Broin, Martin Harrigan

Voting is the primary mechanism through which DAOs, or Decentralised Autonomous Organisations, reach decisions. Although transparent, the voting process can be complex: it can involve many interacting smart contracts. The nexus of the decision-making process can be relocated and the true voter demographic obfuscated. Furthermore, DAOs can govern other DAOs - metagovernance. We present a method for identifying DAO-to-DAO metagovernance on the Ethereum blockchain. We focus on the links between DAOs and token contracts. We employ a signature-matching algorithm to flexibly handle a variety of DAO frameworks and voting schemes. Once we establish token-to-DAO relationships, we gather and process voting data to produce a list of metagovernance relationships. We apply this algorithm to an initial set of sixteen DAOs and we extend the dataset as more DAOs are identified. We produce a metagovernance network with 61 DAOs and 72 metagovernance relationships. We examine three case studies that show metagovernance of various forms: strategic, decisive, and centralised where a DAO becomes a nexus for metagovernance. We demonstrate that metagovernance obscures voting context and introduces entities driven by self-interest that can significantly influence governance. We highlight instances of metagovernance between DAOs operating on the Ethereum blockchain where current governance tools inadequately reveal such dynamics. To preserve the transparency-centric ethos of DAOs and mitigate risks associated with metagovernance, there is a pressing need for enhanced tools to address such issues.

Open access
2 source records
cs.CR
cs.CY
Internet Traffic Analysis and Secure E-voting
Original source
Aug 19, 2024·2024 IEEE International Conference on Blockchain (Blockchain)
0 cites
PRFX: A Privacy-Preserving Prefix Summation Protocol on Blockchain with Zero-Knowledge Proof

Goshgar Ismayilov, Can Özturan

Prefix summation has found its applications over the years in various important domains from sorting to geographical terrain analysis. In our work, we address the privacy-preserving prefix summation problem on blockchain where multiple parties aim to aggregate their secret values through a secure multi-party computation. For the given problem, we propose a novel crypto-graphic protocol (i.e. PRFX) by integrating zero-knowledge proof and hypercube network topology. In addition, we theoretically show the applicability of the proposed protocol on the privacy-preserving delegation using Euler Tour Technique. We analyze the protocol with respect to the scalability perspectives including the communication, computation and storage overheads. The proposed protocol is also exposed to the experimental study where its performance is measured through the blockchain gas cost, the zero-knowledge proof generation time and lastly the zero-knowledge proof size.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Aug 15, 2024·2024 International Conference on Multimedia Analysis and Pattern Recognition (MAPR)
1 cites
Towards Transparent Spam Detection: Sentinel Call - A Distributed Ledger Solution for Call Filtering

Tuan-Dung Tran, Nguyen Anh Tai, Tran The Anh, Phan The Duy · 5 authors

The proliferation of connectivity through modern telecommunications has led to increased unwanted and disruptive calls. Such communications negatively impact user experience and trust in platforms. Currently, call filtering relies on centralized architectures that aggregate vast troves of sensitive user data within single entities, compromising privacy and ownership. Users have limited visibility into how inputs inform labeling, challenging autonomy and oversight. We present the Sentinel Call Platform, a novel blockchain-powered decentralized framework to mitigate unsolicited calls. It establishes a permissionless blockchain tailored for immutable storage of call logs and community rules, and employs a Proof-of-Spam consensus, facilitating transparent flagging of suspicious numbers through democratic participation. An initial prototype demonstrates authenticating calls while preserving anonymity. By removing centralized data flow and governance models, the solution aims to restore transparency, autonomy and trust. The modular framework integrates applications and consensus optimization. Evaluations indicate ability to handle throughput loads. This decentralized alternative enhances user protection against disruptive communications through distributed, open solutions with implications for blockchain application across data sovereignty domains.

Spam and Phishing Detection
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Original source
Aug 15, 2024·Journal of Computational Innovation and Analytics (JCIA)
4 cites
DECENTRALIZED ELECTRONIC VOTING WITH ETHEREUM BLOCKCHAIN IN DEMOCRATIC AND POLITICAL ELECTIONS

Stephanie Kew Yen Nee, Kang Eng Thye

The Ethereum blockchain-based electronic voting (e-voting) systems can emerge as a viable strategy in this era of contemporary democracies to revolutionize political elections and augment the efficacy of the electoral process. There are myriad advantages that the Ethereum blockchain has to offer, from fairness to increased voting rates. Unlike traditional voting protocols, the Ethereum blockchain can assure substantial cost savings and eliminate the necessity for electoral intermediaries. The use of the Ethereum blockchain in political contexts also ensures that elections are held with integrity while preserving the voters’ privacy. Due to its popularity, provision of smart contracts logic, and various promising advantages, this systematic review aims to examine the potential deployment of decentralized e-voting systems integrated with Ethereum blockchain technology for democratic political elections. A systematic literature review (SLR) and the PICO approach, which stands for population, intervention, control, and outcomes, were adopted in this study to systematically analyze the existing literature. Key technological approaches identified in the voting system include the hybrid blockchain and privacy-preserving score voting. Among the noteworthy findings are the following: while adoption and complexity remain challenges across numerous e-voting frameworks, scalability, end-to-end security, enhanced efficiency, and effectiveness are key benefits. An exploration into the prospective future innovations, such as the integration of artificial intelligence and big data analytics into the Ethereum blockchain, was also included to further improve the reliability of the e-voting systems. It is believed that the Ethereum blockchain has a promising transformative impact on electoral politics and democratic processes, presenting a ray of hope for future elections.

Open access
Internet Traffic Analysis and Secure E-voting
Original source
Aug 14, 2024·Research Advances in Network Technologies
0 cites
Design and analysis of a Diffie–Hellman-based network security and cryptography approach

Praneeth Kanagala

Multiple internet services rely on the Diffie–Hellman (DH) algorithm for security. In spite of this, a study from October 2015 reveals that many DH-based internet applications are not protected adequately from highly resourced attackers, including the security services of some nations. To improve the security of data while it is in transit over an unsecured network, a novel method for encrypting and decrypting voice signals is presented in this research. The Diffie–Hellman algorithm, a specific form of asymmetric key cryptography, is the basis of the presented technique. This method&s;s primary value is that it lets users encrypt and decode their conversations using an encrypted session key. To begin, the dispatcher uses the agreed-upon secret key to encrypt the incoming speech signal using this technique. Second, the encrypted voice signal is transmitted through a public network to reach its final destination. To begin, we implemented a client-side encryption system to better protect sensitive information while still allowing for secure communication between client and server. Key exchange is protected from man-in-the-middle and discrete logarithm attacks with the help of the modified Diffie–Hellman method and from unauthorized access with the help of the modified Zero Knowledge Proof (ZKP) method. Criteria for evaluation include file size, time to generate keys, time to encrypt and decode data, and time to execute the algorithm.

Chaos-based Image/Signal Encryption
Cryptographic Implementations and Security
Internet Traffic Analysis and Secure E-voting
Original source
Aug 13, 2024·2024 19th Asia Joint Conference on Information Security (AsiaJCIS)
0 cites
Secure and Portable Anonymous Credentials without Tamper-Resistant Hardware

Tianshu Yu, Kunpeng Bai

Authentication is a key technology that provides trusts in cyberspace. Anonymous credentials are aimed at providing user authentication and protecting users' privacy meanwhile. Existing anonymous credential protocols mostly rely on specific hardware to protect their credential secrets, the inconvenience of which and the fact that losses or damages of the hardware can make their identities unavailable significantly hamper large-scale deployments of these schemes. In this paper, based on Zhang et al.'s password-based credential techniques (NDSS'20), combined with cryptographic primitives such as non-interactive zero knowledge proofs and homomorphic encryption, we propose a secure and portable anonymous credential protocol which does not need tamper-resistant hardware. Our anonymous credentials are designed to be encrypted using passwords which can be implemented and deployed in software only in the user terminal. The structure of our (encrypted) credentials and the design of our verifier-designated authentication tokens ensure the resistance of our protocol against serious offline dictionary attacks. We further balance security and user privacy, and propose a concept of maximum authentication failure time limit combined with hash computation and zero-knowledge proofs against online dictionary attacks, which are more difficult to defend against in the anonymous authentication setting. Our protocol supports not only blind issuance of anonymous credentials but also anonymous authentication of users. From the perspective of the dominating exponentiation computations in anonymous credential protocols, our anonymous authentication protocol outperforms most existing schemes except the ones that do not provide blind issuance.

Cryptography and Data Security
Security and Verification in Computing
Internet Traffic Analysis and Secure E-voting
Original source
Aug 8, 2024·2024 7th International Conference on Circuit Power and Computing Technologies (ICCPCT)
3 cites
Blockchain-Enabled Decentralized Trust Management and Secure Voting system

R. I. Minu, G. Nagarajan

In the era of digital transformation, trust and security are paramount in ensuring the integrity of various online transactions and processes, including voting systems. Traditional centralized trust management and voting systems have faced challenges related to security, transparency, and accountability. To address these issues, this research introduces a novel Blockchain-Enabled Decentralized Trust Management and Secure Voting System . It leverages blockchain technology, a decentralized and immutable ledger, to enhance trust, transparency, and security in trust management and voting processes. This system combines several key components, including smart contracts, cryptographic techniques, and distributed ledger technology, to create a robust and tamper-resistant infrastructure. In the trust management aspect, the proposed system employs a decentralized reputation system where individuals and entities can build trust through transparent and verifiable interactions. Smart contracts automate trust-building processes and provide a reliable mechanism for dispute resolution. This system allows for trust to be quantified and established in a trustless environment. The secure voting component introduces a tamper-proof and transparent voting system. Through the use of cryptographic keys and digital signatures, voters can securely cast their votes while ensuring anonymity and integrity. All voting transactions are recorded on the blockchain, providing a permanent and auditable record of the election process. Verification of election results becomes accessible to all stakeholders, enhancing transparency and trust in the electoral process. The Blockchain-Enabled Decentralized Trust Management and Secure Voting System represents a significant step towards enhancing trust and security in critical online processes, such as voting. By combining blockchain technology, cryptography, and decentralized trust mechanisms, it offers a promising solution to address the challenges associated with centralized trust management and voting systems. This research paves the way for a more transparent, secure, and accountable future in the realm of digital trust and elections.

Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Original source
Aug 6, 2024·arXiv (Cornell University)
2 cites
Simple Perturbations Subvert Ethereum Phishing Transactions Detection: An Empirical Analysis

Ahod Alghureid, Aziz Mohaisen

This paper explores the vulnerability of machine learning models, specifically Random Forest, Decision Tree, and K-Nearest Neighbors, to very simple single-feature adversarial attacks in the context of Ethereum fraudulent transaction detection. Through comprehensive experimentation, we investigate the impact of various adversarial attack strategies on model performance metrics, such as accuracy, precision, recall, and F1-score. Our findings, highlighting how prone those techniques are to simple attacks, are alarming, and the inconsistency in the attacks' effect on different algorithms promises ways for attack mitigation. We examine the effectiveness of different mitigation strategies, including adversarial training and enhanced feature selection, in enhancing model robustness.

Open access
4 source records
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Imbalanced Data Classification Techniques
Original source
Jul 24, 2024·2024 IEEE Annual Congress on Artificial Intelligence of Things (AIoT)
0 cites
Decentralized Anonymous Crowdsourcing with Blockchain and Anonymous Payments

Hanwei Zhu, Chi-Kin Chau

Decentralizing crowdsourcing through blockchain technology eliminates the need for trusted third-party intermediaries that may introduce social biases in data aggregation, thereby enhancing transparency and ensuring appropriate rewards for workers. However, open permissionless blockchain platforms typically disclose all transaction data on public ledgers, which compromises the privacy and anonymity of workers and encourages free-riding. Blockchain-based anonymous crowdsourcing systems have recently emerged, offering anonymity but requiring identity registration for workers and a trusted setup for key generation. These systems in general, fail to support anonymous payments, potentially compromising worker identities. In this paper, we integrate anonymous payments into crowdsourcing, eliminating the need for identity registration and trusted setup, thus fostering open and anonymous participation from any worker. Our solution utilizes the decentralized anonymous payment system framework, such as Zerocoin, and includes staking mechanisms for participation in crowdsourcing as well as efficient one-out-of-many zero-knowledge proofs. Additionally, our empirical evaluations reveal that the system incurs moderate and practical gas costs.

Mobile Crowdsensing and Crowdsourcing
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Original source
Jul 17, 2024·2024 International Conference on Computer, Information and Telecommunication Systems (CITS)
8 cites
TGAT: Temporal Graph Attention Network for Blockchain Phishing Scams Detection

Chaofan Dai, Qideng Tang, Huahua Ding

In recent years, blockchain has emerged as a promising technology with extensive applications in various fields. One of its most notable applications is cryptocurrency. However, the prevalence of phishing scams in blockchain transaction networks has led to significant economic losses and poses a severe threat to transaction security within the cryptocurrency ecosystem. Existing methods for phishing scams detection often employ traditional machine learning techniques or graph embedding methods to extract key information that distinguishes phishing addresses. Nevertheless, these methods often overlook the temporal information within transaction networks, failing to fully capture the dynamic nature of the blockchain transaction network, resulting in suboptimal detection performance. In this paper, we propose a Temporal Graph Attention Network for blockchain phishing scams detection. Specifically, we use a Long Short-Term Memory (LSTM) network to obtain temporal transaction representations. Additionally, we utilize an attention mechanism to aggregate transaction features and features between neighboring nodes. Finally, by incorporating the obtained node representations and the topological characteristics of nodes, we identify phishing addresses using a Multilayer Perceptron (MLP). Experimental results on three real-world Ethereum phishing scams detection datasets indicate that our proposed method significantly outperforms competing approaches.

Spam and Phishing Detection
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Original source
Jul 15, 2024·IEEE Transactions on Services Computing
5 cites
ABDP: Accurate Billing on Differentially Private Data Reporting for Smart Grids

Jialing He, Ning Wang, Tao Xiang, Yiqiao Wei · 7 authors

While smart grid significantly facilitates energy efficiency by using users’ power consumption data, it poses privacy leakage risk for user personal behaviors. Differential privacy (DP) has emerged as a promising solution to address this issue. However, existing approaches suffer from severe data utility degradation due to the intensive noise introduced by DP. Additionally, some of these methods are vulnerable to security attacks. To bridge this gap, in this paper, we propose ABDP (accuratebilling-enableddifferentiallyprivate), a mechanism that achieves high-strength DP while ensuring accurate aggregation and billing operations without compromising security. In particular, we propose aggregated and individual noise cancellation algorithms to counteract the negative effects of noise on data utility. Specifically, our ABDP ensures precise aggregation and accurate billing calculations for the power grid and individual users, respectively Furthermore, we present a Blockchain smart contract exploiting the pseudo random function to enforce a fair and secure data reporting process. Theoretical analysis is provided to evaluate the privacy and security guarantees of ABDP. Experimental results on real-world datasets, namely NERL-DATA and REDD, demonstrate that ABDP achieves error-free aggregation and billing calculation, offers arbitrary intensity privacy protection against non-intrusive load monitoring and filtering attacks, and outperforms existing state-of-the-art approaches.

Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Jul 15, 2024·Sensors
79 cites
BFLIDS: Blockchain-Driven Federated Learning for Intrusion Detection in IoMT Networks

Khadija Begum, Md Ariful Islam Mozumder, Moon-Il Joo, Hee‐Cheol Kim

The Internet of Medical Things (IoMT) has significantly advanced healthcare, but it has also brought about critical security challenges. Traditional security solutions struggle to keep pace with the dynamic and interconnected nature of IoMT systems. Machine learning (ML)-based Intrusion Detection Systems (IDS) have been increasingly adopted to counter cyberattacks, but centralized ML approaches pose privacy risks due to the single points of failure (SPoFs). Federated Learning (FL) emerges as a promising solution, enabling model updates directly on end devices without sharing private data with a central server. This study introduces the BFLIDS, a Blockchain-empowered Federated Learning-based IDS designed to enhance security and intrusion detection in IoMT networks. Our approach leverages blockchain to secure transaction records, FL to maintain data privacy by training models locally, IPFS for decentralized storage, and MongoDB for efficient data management. Ethereum smart contracts (SCs) oversee and secure all interactions and transactions within the system. We modified the FedAvg algorithm with the Kullback-Leibler divergence estimation and adaptive weight calculation to boost model accuracy and robustness against adversarial attacks. For classification, we implemented an Adaptive Max Pooling-based Convolutional Neural Network (CNN) and a modified Bidirectional Long Short-Term Memory (BiLSTM) with attention and residual connections on Edge-IIoTSet and TON-IoT datasets. We achieved accuracies of 97.43% (for CNNs and Edge-IIoTSet), 96.02% (for BiLSTM and Edge-IIoTSet), 98.21% (for CNNs and TON-IoT), and 97.42% (for BiLSTM and TON-IoT) in FL scenarios, which are competitive with centralized methods. The proposed BFLIDS effectively detects intrusions, enhancing the security and privacy of IoMT networks.

Open access
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Smart Grid Security and Resilience
Original source
Jul 12, 2024·2024 2nd World Conference on Communication & Computing (WCONF)
5 cites
Secured Electronic Voting Using Ethereum Blockchain Technology

A Balamanikandan, N Venkataramana, Thirumalesu Kudithi, Ankala Satya Prabha · 6 authors

This project aims to solve the problems of the existing centralized server-based voting system by implementing a blockchain-based e-voting system. The decentralized nature of the system ensures that the voting details are maintained by multiple nodes, and even if one node fails or crashes, the data can still be retrieved from other working nodes. The use of cryptography in this system ensures the security of the voting details. Each user's voting data is encrypted and stored in the blockchain, which is secured by a hash code. The hash code acts as a digital signature and helps to ensure the integrity of the data. This makes it very difficult for anyone to alter the data or hack into the system. The immutability of the blockchain is another important feature of this system. Once the data is stored in the blockchain, it cannot be altered or deleted. This ensures that the voting details are tamper-proof and cannot be manipulated by anyone. Overall, the use of decentralization, cryptography, and blockchain technology makes this e-voting system more secure, transparent, and reliable than the traditional centralized server-based voting systems. It eliminates the risk of data loss, hacking, or manipulation, and ensures that each vote is counted accurately

Internet Traffic Analysis and Secure E-voting
Original source
Jul 11, 2024·IEEE Transactions on Intelligent Transportation Systems
6 cites
BloomACS: Bloom Filter-Based Access Control Scheme in Blockchain-Enabled V2G Networks

Arzoo Miglani, Neeraj Kumar

Recent advancements in Vehicle-to-Grid (V2G) lead to efficient service provisions, such as eco-friendly environment, demand response management, charging, and discharging to the end-users. However, security and privacy preservation for the aforementioned services are key challenges keeping in view of the dependency on the existing centralized security architectures which are not resilient to fault tolerance due to a single point of failure. Hence, there is a need to design new efficient security solutions for the current V2G network, so as to provide seamless services to the end-users. Motivated by these, in this work, we proposed a bloom filter-enabled smart contract-based scheme for access control in V2G environment. In comparison to complex signature-based cryptographic techniques, we propose bloom filter-based authentication for the registered nodes for efficient storage and searching of stored data on the blockchain network. We also designed the Proof-of-Authority (PoA) consensus mechanism, which selects authority nodes dynamically to verify various transactions on the blockchain network. To validate the proposal, we implemented it on the Ethereum network on benchmark datasets using various evaluation parameters such as- latency, throughput, false positive probability, and gas cost.

Internet Traffic Analysis and Secure E-voting
Caching and Content Delivery
Software-Defined Networks and 5G
Original source
Jul 8, 2024·IACR Communications in Cryptology
1 cites
PACIFIC

Scott Griffy, Anna Lysyanskaya

To be useful and widely accepted, automated contact tracing schemes (also called exposure notification) need to solve two seemingly contradictory problems at the same time: they need to protect the anonymity of honest users while also preventing malicious users from creating false alarms. In this paper, we provide, for the first time, an exposure notification construction that guarantees the same levels of privacy and integrity as existing schemes but with a fully malicious database (notably similar to Auerbach et al. CT-RSA 2021) without special restrictions on the adversary. We construct a new definition so that we can formally prove our construction secure. Our definition ensures the following integrity guarantees: no malicious user can cause exposure warnings in two locations at the same time and that any uploaded exposure notifications must be recent and not previously uploaded. Our construction is efficient, requiring only a single message to be broadcast at contact time no matter how many recipients are nearby. To notify contacts of potential infection, an infected user uploads data with size linear in the number of notifications, similar to other schemes. Linear upload complexity is not trivial with our assumptions and guarantees (a naive scheme would be quadratic). This linear complexity is achieved with a new primitive: zero knowledge subset proofs over commitments which is used by our "no cloning" proof protocol. We also introduce another new primitive: set commitments on equivalence classes, which makes each step of our construction more efficient. Both of these new primitives are of independent interest.

Open access
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Original source
Jul 2, 2024·Distributed Ledger Technologies Research and Practice
5 cites
Scalable Anonymous Authentication Scheme Based on Zero-Knowledge Set-Membership Proof

Christopher Wiraatmaja, Shoji Kasahara

In this article, we propose zero-knowledge named proof, a stateless replay attack prevention strategy that ensures the user’s anonymity against malicious administrators. We begin with adopting the zero-knowledge set-membership proof into an authentication setting in which users would delegate their requests to an agent that obstructs the user’s identity from the administrator. This anonymous agent carries the guarantee of authenticity, which the administrator through the set-membership proof can confirm. Next, we prevent replay attacks from other parties by binding the agent’s identity to the authentication proof verifiable by the administrators. By leveraging these properties, a scalable blockchain-based authentication scheme is then built. We quantitatively evaluate the security and measure the time and monetary cost of our scheme under both ideal and realistic environments. On top of it, we provide a third-party authorization scheme derived from our authentication framework to demonstrate its real-world applicability.

Open access
2 source records
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
Jul 2, 2024·2024 IEEE 48th Annual Computers, Software, and Applications Conference (COMPSAC)
2 cites
EGAGN: Generative Adversarial Graph Networks for Ethereum Phishing Scams Detection

Bo Cui, Zhenyu Zhang, Wenhan Hou

In recent years, phishing scams have seriously threatened Ethereum's ecological security and caused massive economic losses. Moreover, the significant disparity between the number of normal addresses and phishing addresses on Ethereum poses a challenge for detecting phishing scams. Existing studies primarily employ methods such as oversampling, filtering rules, and traditional machine learning models to resolve the Ethereum data imbalance problem. However, these methods disregard topological structure features of the transaction network and the link relationship between nodes. In this paper, we propose an Ethereum phishing scams detection model based on Generative Adversarial Graph Networks called EGAGN to alleviate imbalanced data, enhance node representation, and then improve detection performance. Specifically, the graph generator and discriminator play with each other to generate synthetic nodes that satisfy the real nodes distribution to balance Ethereum data and extract effective network structural features. We further extract statistical features from the transaction network and aggregate transaction records based on time series to obtain trading features. The complete representation of nodes is composed of the above three types of features to detect phishing nodes. Experimental results on the real-world Ethereum dataset show that EGAGN outperforms existing models and is far ahead in recall, which indicates that our model can effectively detect Ethereum phishing scams.

Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Advanced Malware Detection Techniques
Original source
Jun 28, 2024·Proceedings of the 19th ACM Asia Conference on Computer and Communications Security
3 cites
Camel: E2E Verifiable Instant Runoff Voting without Tallying Authorities

Luke Harrison, Samiran Bag, Feng Hao

Instant Runoff Voting (IRV) is one example of ranked-choice voting. It provides many known benefits when used in elections, such as minimising vote splitting, ensuring few votes are wasted, and providing resistance to strategic voting. However, the voting and tallying procedures for IRV are much more complicated than those of plurality and are both error-prone and tedious. Many automated systems have been proposed to simplify these procedures in IRV. Some of these also employ cryptographic techniques to protect the secrecy of ballots and enable verification of the tally. Nearly all of these cryptographic systems require a set of trustworthy tallying authorities (TAs) to perform the decryption of votes and/or running of mix servers, which adds significant complexity to the implementation and election management. We address this issue by proposing Camel: an E2E verifiable solution for IRV that requires no TAs. Camel employs a novel representation and a universally verifiable shifting procedure for ballots that facilitate the elimination of candidates as required in an IRV election. We combine these with a homomorphic encryption scheme and zero-knowledge proofs to protect the secrecy of the ballots and enable any party to verify the well-formedness of the ballots and the correctness of the tally in an IRV election. We examine the security of Camel and prove it maintains ballot secrecy by limiting the learned information (namely the tally) against a set of colluding voters.

Open access
Game Theory and Voting Systems
Complexity and Algorithms in Graphs
Internet Traffic Analysis and Secure E-voting
Original source