Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

8,503 papersLast indexed Aug 31, 2026
Search papers

Paper index

8,503 results · page 246 of 355

Clear filters
Nov 1, 2019·2019 IEEE Conference on Dependable and Secure Computing (DSC)
2 cites
E2E Verifiable Electronic Voting System for Shareholders

Samiran Bag, Feng Hao

In this paper we propose an end-to-end (E2E) verifiable online shareholder voting system. Our system allows different voters to have different weights associated with their votes. These weights are dependent upon the number of shares owned by voters in an organization. In our system, the voters cast their votes over the Internet using a personal computing device, say a smart-phone. The voting client interacts with an online voting server which generates encrypted ballots for the chosen candidates with a receipt. Every encrypted ballot comes with a non-interactive zero-knowledge proof to prove the well-formedness of the ciphertext. In addition, the voting system allows the voters to verify their votes are cast as intended through voter initiated auditing. All the encrypted ballots and non-interactive proofs are made available on a publicly readable bulletin board. By checking the receipt against the bulletin board, voters are assured that their votes as recorded as cast. Finally, this e-voting scheme allows everyone including third-party observers to verify all votes are tallied as recorded without involving any tallying authorities. Once the polling concludes, the tallying result is available immediately on the bulletin board with publicly verifiable audit data to allow everyone including third-party observers to verify the tallying integrity of the entire election.

Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Nov 1, 2019·2019 Asia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)
16 cites
Blockchain-based Complete Self-tallying E-voting Protocol

Yikang Lin, Peng Zhang

Electronic voting (E-voting) protocol is that voters can vote according to their wishes, and then the voting authority is responsible for collecting the votes and counting the final voting result. With the development of Blockchain, we tend to combine it with E-voting and propose Blockchain-based complete self-tallying E-voting protocol. Its distributed network makes the protocol more available than E-voting protocol based on centralized servers. In our protocol, Blockchain acts as bulletin board, and “Efficient One-out-of-T” zero knowledge proof (ZKP) is proposed to support multi-candidate voting. Moreover, the issues of abortive and adaptive are solved. The security analysis shows that our protocol meets the security requirements of E-voting, and it can be applied to small-scale and anonymous private scenario such as Corporate Board Voting. The performance analysis demonstrates that the proposed ZKP has low time consumption.

Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 31, 2019·Security and Communication Networks
1 cites
CCA Secure Public Key Encryption against After-the-Fact Leakage without NIZK Proofs

Yi Zhao, Kaitai Liang, Bo Yang, Liqun Chen

In leakage resilient cryptography, there is a seemingly inherent restraint on the ability of the adversary that it cannot get access to the leakage oracle after the challenge. Recently, a series of works made a breakthrough to consider a postchallenge leakage. They presented achievable public key encryption (PKE) schemes which are semantically secure against after-the-fact leakage in the split-state model. This model puts a more acceptable constraint on adversary’s ability that the adversary cannot query the leakage of secret states as a whole but the functions of several parts separately instead of prechallenge query only. To obtain security against chosen ciphertext attack (CCA) for PKE schemes against after-the-fact leakage attack (AFL), existing works followed the paradigm of “double encryption” which needs noninteractive zero knowledge (NIZK) proofs in the encryption algorithm. We present an alternative way to achieve AFL-CCA security via lossy trapdoor functions (LTFs) without NIZK proofs. First, we formalize the definition of LTFs secure against AFL (AFLR-LTFs) and all-but-one variants (ABO). Then, we show how to realize this primitive in the split-state model. This primitive can be used to construct AFLR-CCA secure PKE scheme in the same way as the method of “CCA from LTFs” in traditional sense.

Open access
Cryptography and Data Security
Cryptographic Implementations and Security
Cryptography and Residue Arithmetic
Original source
Oct 30, 2019·International Journal of Innovative Research in Advanced Engineering
0 cites
PRIVACY –PRESERVING DATA VAULTS: SAFE GUARDING PILL INFORMATION IN THE DIGITAL AGE

Bhuman Vyas

Protecting sensitive medical data, including prescription and pill data, during its handling and storage is critical in the digital era. Data vaults that protect privacy provide a strong way to protect this information, guaranteeing that patient information is kept private but yet available for authorised uses. Focussing on the safe preservation of pharmaceutical data, this project investigates the creation of sophisticated algorithms for privacy-preserving data vaults. We start by contrasting the suggested innovative technique, which combines elements of Zero-Knowledge Proofs with Enhanced Homomorphic Encryption, with other known cryptographic and data masking algorithms, such as Differential Privacy, Secure Multi-Party Computation, and Homomorphic Encryption. Data integrity, computational efficiency, and resistance to different attack vectors are some of the characteristics used in the comparison.As the results show, the suggested method offers aimproved performance against confidentiality compromises, especially in real-time data retrieval scenarios, while existing techniques offer varied degrees of efficiency and security. But this comes with more implementation complexity and processing overhead. Improved security characteristics, like less data leakage and strong user authentication systems, are benefits of the suggested approach. Large-scale applications may experience latency problems and require more powerful hardware, which are drawbacks.The trade-offs between various data privacy strategies are highlighted in this study, and it also highlights the necessity for on-going innovation in privacy-preserving technology, which makes a contribution to the region.

Open access
Privacy, Security, and Data Protection
Digital and Cyber Forensics
Cybercrime and Law Enforcement Studies
Original source
Oct 25, 2019·IEEE Sensors Journal
37 cites
Lightweight Collaborative Authentication With Key Protection for Smart Electronic Health Record System

Qi Feng, Debiao He, Huaqun Wang, Lu Zhou · 5 authors

When wireless body area network (WBAN) is playing an increasing role in modern medical systems, smart electronic health record (SEHR) system is heralded primarily as an economical and efficient way to optimize personal information or electronic health records (EHR) flowing through the inter-connected hierarchical network. Large scale, diversity and high sensitivity on EHR data collected from the personal intelligent medical sensors intrigue strong security and privacy preservation. As an authentication protocol can effectively identify the legality of the access entities, many authentication approaches for SEHR system have been proposed. However, few of them are suitable for such situation where an authentication message need to be generated by two parties, for example, doctors need to gain authenticaion from patients when accessing to EHRs. A limitation of using secret sharing scheme is the requirement of a trusted third party to recover the original private key. Therefore, we focus on the specific case of two participants (i.e., no trusted majority) and present a collaborative authentication protocol for SEHR system. Our protocol is provable secure under the hard problem assumptions and meets all the security requirements, especially private key protection. Furthermore, contract to an existing secure two-party authentication protocol that relies on heavy homomorphic encryptions and zero-knowledge proofs, our proposed protocol is tremendously faster than the previous ones shown by the performance analysis.

Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
Oct 24, 2019·Florida International University
1 cites
A Privacy Framework for Decentralized Applications using Blockchains and Zero Knowledge Proofs

David Gabay

With the increasing interest in connected vehicles along with electrification opportunities, there is an ongoing effort to automate the charging process of electric vehicles (EVs) through their capabilities to communicate with the infrastructure and each other. However, charging EVs takes time and thus in-advance scheduling is needed. As this process is done frequently due to limited mileage of EVs, it may expose the locations and charging pattern of the EV to the service providers, raising privacy concerns for their users. Nevertheless, the EV still needs to be authenticated to charging providers, which means some information will need to be provided anyway. While there have been many studies to address the problem of privacy-preserving authentication for vehicular networks, such solutions will be void if charging payments are made through traditional means. In this thesis, we tackle this problem by utilizing distributed applications enabled by Blockchain and smart contracts. We adapt zero-knowledge proofs to Blockchain for enabling privacy-preserving authentication while removing the need for a central authority. We introduce two approaches, one using a token-based mechanism and another utilizing the Pederson Commitment scheme to realize anonymous authentication. We also describe a protocol for the whole process which includes scheduling and charging operations. The evaluation of the proposed approaches indicates that the overhead of this process is affordable to enable real-time charging operations for connected EVs.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Vehicular Ad Hoc Networks (VANETs)
Original source
Oct 8, 2019·2020 IEEE 17th Annual Consumer Communications & Networking Conference (CCNC)
45 cites
A Distributed Ledger Based Infrastructure for Smart Transportation System and Social Good

Mirko Zichichi, Stefano Ferretti, Gabriele D'Angelo

This paper presents a system architecture to promote the development of smart transportation systems. Thanks to the use of distributed ledgers and related technologies, it is possible to create, store and share data generated by users through their sensors, while moving. In particular, IOTA and IPFS are used to store and certify data (and their related metadata) coming from sensors or by the users themselves. Ethereum is exploited as the smart contract platform that coordinates the data sharing and provisioning. The necessary privacy guarantees are provided by the usage of Zero Knowledge Proof. We show some results obtained from some use case scenarios that demonstrate how such technologies can be integrated to build novel smart services and to promote social good in user mobility.

Open access
3 source records
Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Transportation and Mobility Innovations
Original source
Oct 4, 2019·HAL (Le Centre pour la Communication Scientifique Directe)
0 cites
Lossy trapdoor primitives, zero-knowledge proofs and applications

Chen Qian

Les primitives lossy trapdoor, preuve Ă  divulgation nulle de connaissance et applications Dans cette thĂšse, nous Ă©tudions deux primitives diffĂ©rentes : les lossy trapdoor functions (LTF) et les systĂšmes de preuve Ă  divulgation nulle de connaissance. Les LTFs sont des familles de fonctions dans lesquelles les fonctions injectives et les fonctions lossy sont calculatoirement indistinguables. Depuis leur introduction, elles se sont avĂ©rĂ©es utiles pour la construction de diverses primitives cryptographiques. Nous donnons dans cette thĂšse des constructions efficaces d’une variante de la LTF : le filtre algĂ©brique lossy. Avec cette variante, nous pouvons amĂ©liorer l’efficacitĂ© du schĂ©ma de chiffrement KDM-CCA et extracteur flous. Dans la deuxiĂšme partie de cette thĂšse, nous Ă©tudions les constructions de systĂšmes de preuve Ă  divulgation nullle de connaissance. Nous donnons la premiĂšre signature d’anneau de taille logarithmique avec la sĂ©curitĂ© Ă©troite en utilisant une variante de Groth-Kolhweiz ÎŁ-protocole dans le modĂšle de l’oracle alĂ©atoire. Nous proposons Ă©galement une nouvelle construction d’arguments Ă  divulgation nulle de connaissance non-intĂ©ractive et Ă  vĂ©rifieur dĂ©signĂ© (DVNIZK) sous l’hypothĂšse de rĂ©seaux Euclidiens. En utilisant cette nouvelle construction, nous construisons un systĂšme de vote basĂ© sur les rĂ©seaux Euclidiens dans le modĂšle standard.

Open access
2 source records
Cryptography and Data Security
Cryptographic Implementations and Security
Internet Traffic Analysis and Secure E-voting
Original source
Oct 1, 2019·Open MIND
13 cites
TradeMap: A FINMA-compliant Anonymous Management of an End-2-end Trading Market Place

Sina Rafati Niya, Sebastian Allemann, Arik Gabay, Burkhard Stiller

Data leaks and privacy scandals have been a growing concern of the last decade. While most traditional, i.e., centralized, online platforms require users to register with their personal data, they potentially expose the user's identity and data to be used for unintended purposes. This work proposes TradeMap as an integrated architecture, designing and enabling an online end-to-end (e2e) trading market place, while supporting anonymous management features. TradeMap addresses the Swiss Financial Market Supervisory Authority (FINMA) regulations by designing a FINMA-complaint Know Your Customer (KYC) platform. Additionally, TradeMap is based on blockchains and employs Ethereum Smart Contracts (SC). Thus, trust and anonymity between the market place and the KYC system relies on zero knowledge proof-based SCs used for user identification processes. With this management approach proposed, the user authentication is only verified within the KYC platform, providing a legally valid and fully anonymous online trading platform.

Open access
2 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Digital Platforms and Economics
Original source
Oct 1, 2019·TENCON 2019 - 2019 IEEE Region 10 Conference (TENCON)
1 cites
Zero Knowledge Authentication for Reuse of IPs in Reconfigurable Platforms

Krishnendu Guha, Debasri Saha, Amlan Chakrabarti

A key challenge of the embedded era is to ensure trust in reuse of intellectual properties (IPs), which facilitates reduction of design cost and meeting of stringent marketing deadlines. Determining source of the IPs or their authenticity is a key metric to facilitate safe reuse of IPs. Though physical unclonable functions solves this problem for application specific integrated circuit (ASIC) IPs, authentication strategies for reconfigurable IPs (RIPs) or IPs of reconfigurable hardware platforms like field programmable gate arrays (FPGAs) are still in their infancy. Existing authentication techniques for RIPs that relies on verification of proof of authentication (PoA) mark embedded in the RIP by the RIP producers, leak useful clues about the PoA mark. This results in replication and implantation of the PoA mark in fake RIPs. This not only causes loss to authorized second hand RIP users, but also poses risk to the reputation of the RIP producers. We propose a zero knowledge authentication strategy for safe reusing of RIPs. The PoA of an RIP producer is kept secret and verification is carried out based on traversal times from the initial point to several intermediate points of the embedded PoA when the RIPs configure an FPGA. Such delays are user specific and cannot be replicated as these depend on intrinsic properties of the base semiconductor material of the FPGA, which is unique and never same as that of another FPGA. Experimental results validate our proposed mechanism. High strength even for low overhead ISCAS benchmarks, considered as PoA for experimentation depict the prospects of our proposed methodology.

Physical Unclonable Functions (PUFs) and Hardware Security
Neuroscience and Neural Engineering
Integrated Circuits and Semiconductor Failure Analysis
Original source
Oct 1, 2019·arXiv (Cornell University)
4 cites
VPN0: A Privacy-Preserving Decentralized Virtual Private Network

Matteo Varvello, Iñigo Querejeta Azurmendi, Antonio Nappa, Panagiotis N. Papadopoulos · 6 authors

Distributed Virtual Private Networks (dVPNs) are new VPN solutions aiming to solve the trust-privacy concern of a VPN's central authority by leveraging a distributed architecture. In this paper, we first review the existing dVPN ecosystem and debate on its privacy requirements. Then, we present VPN0, a dVPN with strong privacy guarantees and minimal performance impact on its users. VPN0 guarantees that a dVPN node only carries traffic it has "whitelisted", without revealing its whitelist or knowing the traffic it tunnels. This is achieved via three main innovations. First, an attestation mechanism which leverages TLS to certify a user visit to a specific domain. Second, a zero knowledge proof to certify that some incoming traffic is authorized, e.g., falls in a node's whitelist, without disclosing the target domain. Third, a dynamic chain of VPN tunnels to both increase privacy and guarantee service continuation while traffic certification is in place. The paper demonstrates VPN0 functioning when integrated with several production systems, namely BitTorrent DHT and ProtonVPN.

Open access
2 source records
cs.NI
cs.CR
Caching and Content Delivery
Original source
Oct 1, 2019·2019 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC)
5 cites
A Survey on Range Proof and Its Applications on Blockchain

Chunhua Deng, Jia Fan, Zhen Wang, Yili Luo · 7 authors

Blockchain is one of the hot research technologies recently. Blockchain-based distributed ledger requires that all the transactions are public and transparent such that the transactions information is recorded on the chain, which may easily cause the privacy disclosure and other problems. Therefore, in order to preserve users' privacy, the transaction amount should be hidden. The common method is homomorphic commitment. When verifying the legitimacy of a transaction, using the range proof protocol to verify that the transaction amount is non-negative. This paper studied and summarized the range proof protocol based on zero-knowledge proof. We discussed the definition of range proof, the research results, the classification of algorithm, the security and efficiency for each algorithm. This paper discussed further directions for the future research.

Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Oct 1, 2019·2019 International Workshop on Big Data and Information Security (IWBIS)
7 cites
Consensus-Based Secret Sharing in Blockchain Smart Contracts

Christopher G. Harris

Smart contracts on a blockchain permit the performance of credible transactions without the involvement or oversight of a third party. In some industries such as finance, confidentiality is paramount to protect business-critical information from becoming public; however, in a smart contract, information needs to be known and independently verified. A zero-knowledge proof (ZKP) can be used to obscure this information when there are only two parties in the contract; however, ZKPs do not have a mechanism to handle situations in which multiple parties are involved. We introduce, discuss, and simulate a consensus-based secret sharing protocol which provides zero knowledge of personal information, only allows members to participate if they have a key, and only works when a specified number of members “vote.” This enhances the ability for smart contracts to work in situations where majority votes are needed, but the confidentiality of members needs to be preserved.

Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Oct 1, 2019·2019 International Conference on Networking and Network Applications (NaNA)
3 cites
Enhanced BAN-GZKP: Optimal Zero Knowledge Proof Based Scheme in Body Area Networks

Mubarak Umar, Xuening Liao, Jiawang Chen

A network of embedded sensors on the human body called Wireless Body Area Network (WBAN) has recently emerged as a healthcare monitoring framework, to provide better medical services. The data collected by these sensors is transmitted via a wireless medium and contains sensitive information of the patients. Therefore, how to provide security schemes for WBAN with resource constraints devices remains a big challenge. Recently, BAN-GZKP, an authentication scheme based on Zero-Knowledge Proof (ZKP) was designed for WBAN as an optimal solution to several attacks suffered by another ZKP based protocol called BANZKP. However, BAN-GZKP is found to be vulnerable to Node Compromise Attack, Node Impersonation, and Denial-of-Service Attacks. To fix the vulnerabilities of BANGZKP, this paper proposes an enhanced BAN-GZKP which exploits a unique physical layer characteristic coming from the surrounding WBAN, i.e., the distinct received signal strength variation among on-body channels and between on-body and off-body channels, to ensure robust authentication. To prove the reliability of our proposal, we conducted real-world experiments on 3 subjects in indoor and outdoor areas. The results showed that our scheme improves the security of the previous scheme with even lesser cost.

Wireless Body Area Networks
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Oct 1, 2019·2019 IEEE International Conference on Systems, Man and Cybernetics (SMC)
7 cites
Lightweight Protection of User Identity Privacy Based on Zero-knowledge Proof

Zhengwei Ren, Xianye Zha, Kai Zhang, Jing Liu · 5 authors

A number of solutions have been proposed to tackle the user privacy-preserving issue. Most of existing schemes, however, focus on methodology and techniques from the perspective of data processing. In this paper, we propose a lightweight privacy-preserving scheme for user identity from the perspective of data user and applied cryptography. The basic idea is to break the association relationships between User identity and his behaviors and ensure that User can access data or services as usual while the real identity will not be revealed. To this end, an interactive zero-knowledge proof protocol of identity is executed between CSP and User. Besides, a trusted third-party is introduced to manage user information, help CSP to validate User identity and establish secure channel between CSP and User via random shared key. After passing identity validation, User can log into cloud platform as usual without changing existing business process using random temporary account and password generated by CSP and sent to User by the secure channel which can further obscure the association relationships between identity and behaviors. Formal security analysis and theoretic and experimental evaluations are conducted, showing that the proposal is efficient and practical.

Privacy-Preserving Technologies in Data
Cryptography and Data Security
Privacy, Security, and Data Protection
Original source
Oct 1, 2019·2019 IEEE 44th LCN Symposium on Emerging Topics in Networking (LCN Symposium)
15 cites
A Privacy Framework for Charging Connected Electric Vehicles Using Blockchain and Zero Knowledge Proofs

David Gabay, Kemal Akkaya, Mumin Cebe

With the increasing interest in connected vehicles along with electrification opportunities, there is an ongoing effort to automate the charging process of electric vehicles (EVs). However, charging EVs takes time and thus in-advance scheduling is needed. This, however, raises privacy concerns since frequent scheduling will expose the charging pattern of the EV to the service providers. Nevertheless, the EV needs to be authenticated which means some information will need to be provided anyway. While there have been many studies to address the problem of privacy-preserving authentication, such solutions will be void if charging payments are made through traditional means. In this paper, we tackle this problem by utilizing distributed applications enabled by Blockchain and smart contracts. We adapt zero-knowledge proofs to Blockchain for enabling privacy-preserving authentication while removing the need for a central authority. The evaluation indicates that the overhead of this process is affordable to enable real-time charging operations for connected EVs.

Blockchain Technology Applications and Security
Recycling and Waste Management Techniques
Cryptography and Data Security
Original source
Sep 23, 2019·DergiPark (Istanbul University)
3 cites
Security of Smart-Meters against Side-Channel-Attacks (SCA)

İqra Mustafa, Adeel Anjum, Kouahla Zineddine

The smart meters become an important node for managing information about electric power system so, smart-meter drags cyber security attention in this regard.  In this paper, the protocol for smart meters named as “privacy preserving billing” is used which provides authentication, non-repudiation and integrity by digital signature scheme and zero-knowledge proof. This protocol ensures secrecy and reliability of end to end communication. However, vulnerability lies in integrated circuits of smart meters that can leak sensitive information and side channel attacks (SCA), derive this information from integrated circuits(IC) while it's operating. The most well-known SCA's against smart-meters are electromagnetic radiations, timing and power analysis attacks. Due to side channel attacks integrated circuit’s physical and electrical effects broadcast information related to secret key and have emerged as a major vulnerability to security applications. SCA does not temper IC security as their non-invasiveness observes device under normal conditions. Hence, our ultimate goal is to make circuit of smart-meter immune against side channel attacks, specifically differential power analysis (DPA) attack is main focus, as it is more aggressive than other SCA’s. For this reason, we present basis for SCA resistance and concept of CMOS library. Secondly, the other concept, we introduces is CMOS-based digital isolation that provides immunity to electrical noise and external fields compared to optocouplers for smart-meters.

Physical Unclonable Functions (PUFs) and Hardware Security
Cryptographic Implementations and Security
Smart Grid Security and Resilience
Original source
Sep 16, 2019·arXiv (Cornell University)
0 cites
Truthful and Faithful Monetary Policy for a Stablecoin Conducted by a\n Decentralised, Encrypted Artificial Intelligence

David Cerezo SĂĄnchez

The Holy Grail of a decentralised stablecoin is achieved on rigorous\nmathematical frameworks, obtaining multiple advantageous proofs: stability,\nconvergence, truthfulness, faithfulness, and malicious-security. These\nproperties could only be attained by the novel and interdisciplinary\ncombination of previously unrelated fields: model predictive control, deep\nlearning, alternating direction method of multipliers (consensus-ADMM),\nmechanism design, secure multi-party computation, and zero-knowledge proofs.\nFor the first time, this paper proves:\n - the feasibility of decentralising the central bank while securely\npreserving its independence in a decentralised computation setting\n - the benefits for price stability of combining mechanism design, provable\nsecurity, and control theory, unlike the heuristics of previous stablecoins\n - the implementation of complex monetary policies on a stablecoin, equivalent\nto the ones used by central banks and beyond the current fixed rules of\ncryptocurrencies that hinder their price stability\n - methods to circumvent the impossibilities of Guaranteed Output Delivery\n(G.O.D.) and fairness: standing on truthfulness and faithfulness, we reach\nG.O.D. and fairness under the assumption of rational parties\n As a corollary, a decentralised artificial intelligence is able to conduct\nthe monetary policy of a stablecoin, minimising human intervention.\n

Open access
Monetary Policy and Economic Impact
Original source
Sep 13, 2019·The Computer Journal
8 cites
A (Zero-Knowledge) Vector Commitment with Sum Binding and its Applications

Qiang Wang, Fucai Zhou, Jian Xu, Zifeng Xu

Abstract Vector commitment (VC) schemes allow committing to an ordered sequence of ${q}$ values ${(m_1,\cdots ,m_q)}$ in such a way that one can later open the commitment at specific positions. However, the existing VC schemes suffer from two substantial shortcomings that limit their use: (i) the commitments cannot be opened except at some specific positions, and (ii) their security only captures position-binding but offers no privacy: the client may learn additional information about the committed sequence through the proofs and the commitments. To resolve these problems, we first extend VC to a more expressive primitive called VC with sum binding (VCS), in which the commitment can also be opened to the sum of all elements in the committed sequence. VCS additionally satisfies the security of sum binding, which guarantees that the commitment cannot be opened to different sums. To enhance its privacy, we extend VCS to zero-knowledge VCS (ZKVCS), in which commitments and proofs constructed during the protocol execution leak nothing about the committed sequence. We formalize this new property by a standard real/ideal experiment. Meanwhile, the detailed performance analyses and simulations show that our proposed schemes are more practical. Finally, we introduce a novel notion of (zero-knowledge) verifiable database supporting sum and show how to construct it from our (ZK)VCS scheme.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Sep 10, 2019·IEEE Transactions on Vehicular Technology
84 cites
Toward Blockchain-Based Fair and Anonymous Ad Dissemination in Vehicular Networks

Ming Li, Jian Weng, Anjia Yang, Jia-Nan Liu · 5 authors

Commercial advertisement (ad) dissemination has been proliferating on connected vehicles, allowing users to promote their products via vehicle-to-vehicle/-infrastructure communications. Despite the prospect of ad dissemination in vehicular networks, it faces challenges upon deployment especially on security and privacy. Particularly, vehicles may collude to defraud the advertiser to obtain rewards without disseminating ads, which may cause unfair “free-riding” issue in these activities. Furthermore, concerns on possible privacy leakage may discourage vehicles to participate in the process of ad dissemination. In addition, external DDoS attacks and internal single point of failure may also affect service availability. To address these issues, we explore the potential of blockchain technology to construct a fair and anonymous scheme for advertising in vehicular networks. We first present the overview of the blockchain-based ad dissemination framework. Then, under the framework, we design a concrete, fair and anonymous scheme. To ensure fairness, we utilize the Merkle hash tree together with smart contracts to achieve the “proof-of-ad-receiving” property (i.e., check whether a vehicle indeed receives an ad without deception or introducing significant storage cost) to mitigate the “free-riding” attack. On the other hand, any ad receiver who acquires a dissemination reward per ad more than once can be effectively detected and will be punished which is achieved by using smart contracts. Additionally, the proposed scheme can protect vehicles' privacy in terms of anonymity and conditional linkability based on zero-knowledge proof techniques. Lastly, extensive security analysis and implementations demonstrate the feasibility and efficiency of the scheme.

Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Vehicular Ad Hoc Networks (VANETs)
Original source
Sep 6, 2019·IEEE Transactions on Services Computing
48 cites
Achieving One-Round Password-Based Authenticated Key Exchange over Lattices

Zengpeng Li, Ding Wang

Password-based authenticated key exchange($\mathsf {PAKE}$PAKE) protocol, a widely used authentication mechanism to realize secure communication, allows protocol participants to establish a high-entropy session key by pre-sharing a low-entropy password. An open challenge in$\mathsf {PAKE}$PAKEis how to design a quantum-resistant round-optimal$\mathsf {PAKE}$PAKE. To solve this challenge, lattice-based cryptography is a promising candidate for post-quantum cryptography. In addition, Katz and Vaikuntanathan (ASIACRYPT’09) design the firstthree-round$\mathsf {PAKE}$PAKEprotocol by leveraging the smooth projective hash function ($\mathsf {SPHF}$SPHF) over lattices. Subsequently, Zhang and Yu (AISACRYPT’17) optimized Katz-Vaikuntanathan’s approximate$\mathsf {SPHF}$SPHFvia a splittable public key encryption. They then constructed atwo-round$\mathsf {PAKE}$PAKEby using the simulation-sound non-interactive zero-knowledge (NIZK) proofs, but how to construct a lattice-based simulation-sound NIZK remains an open research question. In other words, how to design a one-round$\mathsf {PAKE}$PAKEvia an efficient lattice-based$\mathsf {SPHF}$SPHFstill remains a challenge. In this work, we attempt to fill this gap by proposing a lattice-based$\mathsf {SPHF}$SPHFwith adaptive smoothness. We then obtain aone-round$\mathsf {PAKE}$PAKEprotocol over lattices with rigorous security analysis by integrating the proposed$\mathsf {SPHF}$SPHFinto the one-round framework proposed by Katz and Vaikuntananthan (TCC’11). Furthermore, we explore the possibilities of achieving two-round$\mathsf {PAKE}$PAKEand universal composable (UC) security from our$\mathsf {SPHF}$SPHF, and show the potential application of our$\mathsf {PAKE}$PAKEin Internet of Things (IoTs) where communication cost is the main consideration.

Cryptography and Data Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source