Proof of retrievability (POR) is a technique for ensuring the integrity of data in outsourced storage services.In this paper, we address the construction of POR protocol on the standard model of interactive proof systems.We propose the first interactive POR scheme to prevent the fraudulence of prover and the leakage of verified data.We also give full proofs of soundness and zero-knowledge properties by constructing a polynomialtime rewindable knowledge extractor under the computational Diffie-Hellman assumption.In particular, the verification process of this scheme requires a low, constant amount of overhead, which minimizes communication complexity.
This paper presents a new zero-knowledge protocol for SDH pair,which based on TOO/BB-E encryption from DBDH as-sumption.This protocal's security is stronger than reference[1].
A proxy signature scheme enables a proxy signer to sign messages on behalf of the original signer. In this paper we propose an efficient proxy signature scheme based on RSA signature scheme, which divides the document M into m blocks and adds some redundant bits to each message block. We also give a kind of algorithm of the zero-knowledge proof of proposed digital signature. This algorithm has characteristics which has little computation, high reliability, and easy to be realized. The proposed signature scheme satisfies the secure requirements and is efficient.
Traditionally, the definition of zero-knowledge states that an interactive proof of x ∈ L provides zero (additional) knowledge if the view of any polynomial-time verifier can be reconstructed by a polynomial-time simulator. Since this definition only requires that the worst-case running-time of the verifier and simulator are polynomials, zero-knowledge becomes a worst-case notion. In STOC’06, Micali and Pass proposed a new notion of precise zero-knowledge, which captures the idea that the view of any verifier in every interaction can be reconstructed in (almost) the same time (i.e., the view can be “indistinguishably reconstructed”). This is the strongest notion among the known works towards precislization of the definition of zero-knowledge. However, as we know, there are two kinds of computational resources (i.e. time and space) that every algorithm consumes in computation. Although the view of a verifier in the interaction of a precise zero-knowledge protocol can be reconstructed in almost the same time, the simulator may run in very large space while at the same time the verifier only runs in very small space. In this case it is still doubtful to take indifference for the verifier to take part in the interaction or
The prevalence of digital information management in an open network has driven\nthe need to maintain balance between anonymity, authenticity and accountability (AAA).\nAnonymity allows a principal to hide its identity from strangers before trust relationship\nis established. Authenticity ensures the correct identity is engaged in the transaction even\nthough it is hidden. Accountability uncovers the hidden identity when misbehavior of the\nprincipal is detected. The objective of this research is to develop an AAA management\nframework for secure resource allocations. Most existing resource management schemes\nare designed to manage one or two of the AAA attributes. How to provide high strength\nprotection to all attributes is an extremely challenging undertaking. Our study shows that\nthe electronic cash (E-cash) paradigm provides some important knowledge bases for this\npurpose. Based on Chaum-Pederson’s general transferable E-cash model, we propose a\ntimed-zero-knowledge proof (TZKP) protocol, which greatly reduces storage spaces and\ncommunication overheads for resource transfers, without compromising anonymity and\naccountability. Based on Eng-Okamoto’s general divisible E-cash model, we propose a hypercube-based divisibility framework, which provides a sophisticated and flexible way\nto partition a chunk of resources, with different trade-offs in anonymity protection and\ncomputational costs, when it is integrated with different sub-cube allocation schemes.\nBased on the E-cash based resource management framework, we propose a privacy\npreserving service oriented architecture (SOA), which allows the service providers and\nconsumers to exchange services without leaking their sensitive data. Simulation results\nshow that the secure resource management framework is highly practical for missioncritical\napplications in large scale distributed information systems.
① Based on technologies of binary tree,bit commitment and zero knowledge proof,a fair and unlinkable divisible electronic cash scheme is which do not need the trusted third party was proposed.The complexity both of open account and withdraw protocol is O(N+K).The complexity of spending any node is proportional to poly(K) polylog(N).And the complexity of deposit protocol is the same with the payment protocol.The security of the scheme is based on the assumptions of strong RSA problems,the hardness of calculating discrete logarithm and the existence of the one-way hash function.
Divisibility of e-cash helps expend digital coin exactly.Most divisible e-cash schemes are based on binary tree,but few e-cash schemes offer fairness and divisibility at the same time.Based on binary tree,blind signature and zero-knowledge proof,a new fair indivisible electronic coins scheme was proposed.
Computational grids enable the sharing, aggregation, and selection of (geographically distributed) computational resources and can be used for solving large scale and data intensive computing applications. Computational grids are an appealing target application for market-based resource allocation especially given the attention in recent years to “virtual organizations ” and policy requirements. In this paper, we present a framework for truthful, decentralized, dynamic auctions in computational grids. Rather than a fullyspecified auction, we propose an open, extensible framework that is sufficient to promote simple, truthful bidding by endusers while supporting distributed and autonomous control by resource owners. Our auction framework incorporates resource prediction in enabling an expressive language for end-users, and highlights the role of infrastructure in enforcing rules that balance the goal of simplicity for end users with autonomy for resource owners. The technical analysis leverages simplifying assumptions of “uniform failure” and “threshold-reliability” beliefs.
Serge Abiteboul, Bogdan Cautis, Amos Fiat, T. Milo
The common assumption about digital signatures is that they disallow any kind of modification on signed data. However, a more flexible approach is often needed and has been advocated lately, one in which some restricted modifications may still occur, without invalidating the data. This is made possible by offering signatures which are homomorphic with respect to some operation on the message domain. Starting from the signature(s) of some data instance(s), computed by the data owner, anybody else can derive the signature corresponding to a new data instance, if obtained only via some accepted operation from the previous one(s). More, updated signatures should be indistinguishable from the ones computed by the data owner and this updating step should be applicable as many times as needed. This paper deals with the signing of insert-only collections, in which element insertions are accepted but no removals should occur. Newly inserted elements do not have to be signed or known by the initial signer. We propose two techniques: one which transposes the insert-only problem into a delete-only one (which is already solved), and another technique based on zero-knowledge proofs. We also give performance measures and discuss applications.
Arshad Ali, A. Anjum, Tahir Azim, M. Thomas · 9 authors
In this paper we describe JClarens; a Java based implementation of the Clarens remote data server. JClarens provides Web services for an interactive analysis environment to dynamically access and analyze the tremendous amount of data scattered across various locations. Additionally this research is aimed to develop a service oriented grid enabled portal (GEP) that provides interface and access to several grid services to give a homogeneous and optimized view of the distributed and heterogeneous environment. Other than showing platform independent behavior provided by Java, the use of XML-RPC based Web services enabled JClarens to be a language neutral server and demonstrated interoperability with its Python variant. Extreme care has been taken in the usage and manipulation of various Java libraries to cater the needs of high performance computing. The overall exercise has yielded in a prototype with strong emphasis on security and virtual organization management (VOM). This shall provide a common platform to support development of larger, more flexible framework with future aims to integrate it with a loosely coupled, decentralized, and autonomous framework for grid enabled analysis environment (GAE).
Wanzong Peng, Tongliang Lu, Wenju Peng, Zhongpan Wang
File sharing, being the foundation of the Internet, has traditionally relied on a centralized service architecture resulting in significant maintenance costs. Moreover, due to the lack of an effective file management system, instances of sensitive information going out of control and loss of confidentiality in file sharing have occurred frequently. In order to address the difficulty of tamper detection and the lack of supervision in the entire process of file transfer in the current Internet environment, this paper designs a blockchain-based system architecture for secure sharing of electronic documents. An efficient blockchain model is used in our framework, and with the help of distributed storage system and asymmetric encryption technology, file sharing can be controlled, reliable and traceable in the transfer process. Referring to existing consensus mechanisms, e.g., Delegated Proof of Stake (DPoS) and Practical Byzantine Fault Tolerance (PBFT), we propose a new consensus for efficient and secure file sharing. Our experimental results show that our framework can maintain a higher throughput than existing schemes.
Grids enable users to share and access large collections and various types of resources in wide areas, and how to locate resources in such dynamic, heterogeneous and autonomous distributed environments is a key and challenging issue. In this paper, a three-level decentralized and dynamic VEGA Infrastructure for Resource Discovery (VIRD) is proposed. In this architecture, every Border Grid Resource Name Server (BGRNS) or Grid Resource Name Server (GRNS)has its own local policies, governing information organization, management and searching. Changes in resource information are propagated dynamically among GRNS servers according to a link-statelike algorithm. A client can query its designated GRNS either recursively or iteratively. Optimizing techniques, such as shortcut, are adopted to make the dynamic framework more flexible and efficient. A simulator called SimVIRD is developed to verify the proposed architecture and algorithms.Experiment results indicate that this architecture could deliver good scalability and performance for grid resource discovery.
We present a protocol for controlling a shared ATM multicast tree supporting many-to-many communication. The protocol supports one or several ATM virtual channel connections (VCCs) of the many-to-many type. The number of VCCs is independent of the number of endpoints. The protocol guarantees that there is no interleaving on any VCC of the tree. The protocol also guarantees that the traffic contract associated with the VCCs is respected, thus making it possible to use ordinary VCCs of the constant bit rate (CBR), variable bit rate (VBR), or unspecified bit rate (UBR) class. No resequencing server or cell buffering inside the network is required, and all cell forwarding is performed at the ATM layer. We describe the protocol both informally and formally.
The extraordinarily rapid advance of microelectronics is causing a rapid drop in both the cost and economy of scale of computing equipment. In less than a decade, the powerful economic incentive for centralizing the production of computing cycles has reversed. Simultaneously, the productivity of computing professionals has not kept pace with inflation, and it appears that staff productivity gains will be difficult to achieve in a decentralized environment.Distribution of computing equipment is making support for the individual computer user more difficult in the following ways:-- There is a need for support of multiple types of small computer hardware.-- There is a need to maintain multiple operating systems and versions of applications software.-- There is little knowledge and experience in providing documentation, user training, and consulting support in a highly distributed multi-architecture computing environment.This paper outlines Cornell's response to the challenge of decentralized computing. The paper details the rationale, planning, organization, financing, and staffing for the new Decentralized Academic Computer Support group in Cornell Computing Services. In addition, the responsibilities of that group and its interaction with the other groups in Computing Services is described. Finally, attention is given to the relationship between Computing Services and the Cornell community regarding small computers.The accelerating trend of decentralizing the production of computing cycles presents user support groups with both a challenge and an opportunity. Failure to respond will result in more expensive and lower quality computing for the university community as well as declining utilization of user support services.