In this paper we propose an end-to-end (E2E) verifiable online shareholder voting system. Our system allows different voters to have different weights associated with their votes. These weights are dependent upon the number of shares owned by voters in an organization. In our system, the voters cast their votes over the Internet using a personal computing device, say a smart-phone. The voting client interacts with an online voting server which generates encrypted ballots for the chosen candidates with a receipt. Every encrypted ballot comes with a non-interactive zero-knowledge proof to prove the well-formedness of the ciphertext. In addition, the voting system allows the voters to verify their votes are cast as intended through voter initiated auditing. All the encrypted ballots and non-interactive proofs are made available on a publicly readable bulletin board. By checking the receipt against the bulletin board, voters are assured that their votes as recorded as cast. Finally, this e-voting scheme allows everyone including third-party observers to verify all votes are tallied as recorded without involving any tallying authorities. Once the polling concludes, the tallying result is available immediately on the bulletin board with publicly verifiable audit data to allow everyone including third-party observers to verify the tallying integrity of the entire election.
Electronic voting (E-voting) protocol is that voters can vote according to their wishes, and then the voting authority is responsible for collecting the votes and counting the final voting result. With the development of Blockchain, we tend to combine it with E-voting and propose Blockchain-based complete self-tallying E-voting protocol. Its distributed network makes the protocol more available than E-voting protocol based on centralized servers. In our protocol, Blockchain acts as bulletin board, and âEfficient One-out-of-Tâ zero knowledge proof (ZKP) is proposed to support multi-candidate voting. Moreover, the issues of abortive and adaptive are solved. The security analysis shows that our protocol meets the security requirements of E-voting, and it can be applied to small-scale and anonymous private scenario such as Corporate Board Voting. The performance analysis demonstrates that the proposed ZKP has low time consumption.
In leakage resilient cryptography, there is a seemingly inherent restraint on the ability of the adversary that it cannot get access to the leakage oracle after the challenge. Recently, a series of works made a breakthrough to consider a postchallenge leakage. They presented achievable public key encryption (PKE) schemes which are semantically secure against after-the-fact leakage in the split-state model. This model puts a more acceptable constraint on adversaryâs ability that the adversary cannot query the leakage of secret states as a whole but the functions of several parts separately instead of prechallenge query only. To obtain security against chosen ciphertext attack (CCA) for PKE schemes against after-the-fact leakage attack (AFL), existing works followed the paradigm of âdouble encryptionâ which needs noninteractive zero knowledge (NIZK) proofs in the encryption algorithm. We present an alternative way to achieve AFL-CCA security via lossy trapdoor functions (LTFs) without NIZK proofs. First, we formalize the definition of LTFs secure against AFL (AFLR-LTFs) and all-but-one variants (ABO). Then, we show how to realize this primitive in the split-state model. This primitive can be used to construct AFLR-CCA secure PKE scheme in the same way as the method of âCCA from LTFsâ in traditional sense.
Protecting sensitive medical data, including prescription and pill data, during its handling and storage is critical in the digital era. Data vaults that protect privacy provide a strong way to protect this information, guaranteeing that patient information is kept private but yet available for authorised uses. Focussing on the safe preservation of pharmaceutical data, this project investigates the creation of sophisticated algorithms for privacy-preserving data vaults. We start by contrasting the suggested innovative technique, which combines elements of Zero-Knowledge Proofs with Enhanced Homomorphic Encryption, with other known cryptographic and data masking algorithms, such as Differential Privacy, Secure Multi-Party Computation, and Homomorphic Encryption. Data integrity, computational efficiency, and resistance to different attack vectors are some of the characteristics used in the comparison.As the results show, the suggested method offers aimproved performance against confidentiality compromises, especially in real-time data retrieval scenarios, while existing techniques offer varied degrees of efficiency and security. But this comes with more implementation complexity and processing overhead. Improved security characteristics, like less data leakage and strong user authentication systems, are benefits of the suggested approach. Large-scale applications may experience latency problems and require more powerful hardware, which are drawbacks.The trade-offs between various data privacy strategies are highlighted in this study, and it also highlights the necessity for on-going innovation in privacy-preserving technology, which makes a contribution to the region.
When wireless body area network (WBAN) is playing an increasing role in modern medical systems, smart electronic health record (SEHR) system is heralded primarily as an economical and efficient way to optimize personal information or electronic health records (EHR) flowing through the inter-connected hierarchical network. Large scale, diversity and high sensitivity on EHR data collected from the personal intelligent medical sensors intrigue strong security and privacy preservation. As an authentication protocol can effectively identify the legality of the access entities, many authentication approaches for SEHR system have been proposed. However, few of them are suitable for such situation where an authentication message need to be generated by two parties, for example, doctors need to gain authenticaion from patients when accessing to EHRs. A limitation of using secret sharing scheme is the requirement of a trusted third party to recover the original private key. Therefore, we focus on the specific case of two participants (i.e., no trusted majority) and present a collaborative authentication protocol for SEHR system. Our protocol is provable secure under the hard problem assumptions and meets all the security requirements, especially private key protection. Furthermore, contract to an existing secure two-party authentication protocol that relies on heavy homomorphic encryptions and zero-knowledge proofs, our proposed protocol is tremendously faster than the previous ones shown by the performance analysis.
With the increasing interest in connected vehicles along with electrification opportunities, there is an ongoing effort to automate the charging process of electric vehicles (EVs) through their capabilities to communicate with the infrastructure and each other. However, charging EVs takes time and thus in-advance scheduling is needed. As this process is done frequently due to limited mileage of EVs, it may expose the locations and charging pattern of the EV to the service providers, raising privacy concerns for their users. Nevertheless, the EV still needs to be authenticated to charging providers, which means some information will need to be provided anyway. While there have been many studies to address the problem of privacy-preserving authentication for vehicular networks, such solutions will be void if charging payments are made through traditional means. In this thesis, we tackle this problem by utilizing distributed applications enabled by Blockchain and smart contracts. We adapt zero-knowledge proofs to Blockchain for enabling privacy-preserving authentication while removing the need for a central authority. We introduce two approaches, one using a token-based mechanism and another utilizing the Pederson Commitment scheme to realize anonymous authentication. We also describe a protocol for the whole process which includes scheduling and charging operations. The evaluation of the proposed approaches indicates that the overhead of this process is affordable to enable real-time charging operations for connected EVs.
This paper presents a system architecture to promote the development of smart transportation systems. Thanks to the use of distributed ledgers and related technologies, it is possible to create, store and share data generated by users through their sensors, while moving. In particular, IOTA and IPFS are used to store and certify data (and their related metadata) coming from sensors or by the users themselves. Ethereum is exploited as the smart contract platform that coordinates the data sharing and provisioning. The necessary privacy guarantees are provided by the usage of Zero Knowledge Proof. We show some results obtained from some use case scenarios that demonstrate how such technologies can be integrated to build novel smart services and to promote social good in user mobility.
Sina Rafati Niya, Sebastian Allemann, Arik Gabay, Burkhard Stiller
Data leaks and privacy scandals have been a growing concern of the last decade. While most traditional, i.e., centralized, online platforms require users to register with their personal data, they potentially expose the user's identity and data to be used for unintended purposes. This work proposes TradeMap as an integrated architecture, designing and enabling an online end-to-end (e2e) trading market place, while supporting anonymous management features. TradeMap addresses the Swiss Financial Market Supervisory Authority (FINMA) regulations by designing a FINMA-complaint Know Your Customer (KYC) platform. Additionally, TradeMap is based on blockchains and employs Ethereum Smart Contracts (SC). Thus, trust and anonymity between the market place and the KYC system relies on zero knowledge proof-based SCs used for user identification processes. With this management approach proposed, the user authentication is only verified within the KYC platform, providing a legally valid and fully anonymous online trading platform.
A key challenge of the embedded era is to ensure trust in reuse of intellectual properties (IPs), which facilitates reduction of design cost and meeting of stringent marketing deadlines. Determining source of the IPs or their authenticity is a key metric to facilitate safe reuse of IPs. Though physical unclonable functions solves this problem for application specific integrated circuit (ASIC) IPs, authentication strategies for reconfigurable IPs (RIPs) or IPs of reconfigurable hardware platforms like field programmable gate arrays (FPGAs) are still in their infancy. Existing authentication techniques for RIPs that relies on verification of proof of authentication (PoA) mark embedded in the RIP by the RIP producers, leak useful clues about the PoA mark. This results in replication and implantation of the PoA mark in fake RIPs. This not only causes loss to authorized second hand RIP users, but also poses risk to the reputation of the RIP producers. We propose a zero knowledge authentication strategy for safe reusing of RIPs. The PoA of an RIP producer is kept secret and verification is carried out based on traversal times from the initial point to several intermediate points of the embedded PoA when the RIPs configure an FPGA. Such delays are user specific and cannot be replicated as these depend on intrinsic properties of the base semiconductor material of the FPGA, which is unique and never same as that of another FPGA. Experimental results validate our proposed mechanism. High strength even for low overhead ISCAS benchmarks, considered as PoA for experimentation depict the prospects of our proposed methodology.
Physical Unclonable Functions (PUFs) and Hardware Security
Neuroscience and Neural Engineering
Integrated Circuits and Semiconductor Failure Analysis
Matteo Varvello, Iñigo Querejeta Azurmendi, Antonio Nappa, Panagiotis N. Papadopoulos · 6 authors
Distributed Virtual Private Networks (dVPNs) are new VPN solutions aiming to solve the trust-privacy concern of a VPN's central authority by leveraging a distributed architecture. In this paper, we first review the existing dVPN ecosystem and debate on its privacy requirements. Then, we present VPN0, a dVPN with strong privacy guarantees and minimal performance impact on its users. VPN0 guarantees that a dVPN node only carries traffic it has "whitelisted", without revealing its whitelist or knowing the traffic it tunnels. This is achieved via three main innovations. First, an attestation mechanism which leverages TLS to certify a user visit to a specific domain. Second, a zero knowledge proof to certify that some incoming traffic is authorized, e.g., falls in a node's whitelist, without disclosing the target domain. Third, a dynamic chain of VPN tunnels to both increase privacy and guarantee service continuation while traffic certification is in place. The paper demonstrates VPN0 functioning when integrated with several production systems, namely BitTorrent DHT and ProtonVPN.
Chunhua Deng, Jia Fan, Zhen Wang, Yili Luo · 7 authors
Blockchain is one of the hot research technologies recently. Blockchain-based distributed ledger requires that all the transactions are public and transparent such that the transactions information is recorded on the chain, which may easily cause the privacy disclosure and other problems. Therefore, in order to preserve users' privacy, the transaction amount should be hidden. The common method is homomorphic commitment. When verifying the legitimacy of a transaction, using the range proof protocol to verify that the transaction amount is non-negative. This paper studied and summarized the range proof protocol based on zero-knowledge proof. We discussed the definition of range proof, the research results, the classification of algorithm, the security and efficiency for each algorithm. This paper discussed further directions for the future research.
Smart contracts on a blockchain permit the performance of credible transactions without the involvement or oversight of a third party. In some industries such as finance, confidentiality is paramount to protect business-critical information from becoming public; however, in a smart contract, information needs to be known and independently verified. A zero-knowledge proof (ZKP) can be used to obscure this information when there are only two parties in the contract; however, ZKPs do not have a mechanism to handle situations in which multiple parties are involved. We introduce, discuss, and simulate a consensus-based secret sharing protocol which provides zero knowledge of personal information, only allows members to participate if they have a key, and only works when a specified number of members âvote.â This enhances the ability for smart contracts to work in situations where majority votes are needed, but the confidentiality of members needs to be preserved.
A network of embedded sensors on the human body called Wireless Body Area Network (WBAN) has recently emerged as a healthcare monitoring framework, to provide better medical services. The data collected by these sensors is transmitted via a wireless medium and contains sensitive information of the patients. Therefore, how to provide security schemes for WBAN with resource constraints devices remains a big challenge. Recently, BAN-GZKP, an authentication scheme based on Zero-Knowledge Proof (ZKP) was designed for WBAN as an optimal solution to several attacks suffered by another ZKP based protocol called BANZKP. However, BAN-GZKP is found to be vulnerable to Node Compromise Attack, Node Impersonation, and Denial-of-Service Attacks. To fix the vulnerabilities of BANGZKP, this paper proposes an enhanced BAN-GZKP which exploits a unique physical layer characteristic coming from the surrounding WBAN, i.e., the distinct received signal strength variation among on-body channels and between on-body and off-body channels, to ensure robust authentication. To prove the reliability of our proposal, we conducted real-world experiments on 3 subjects in indoor and outdoor areas. The results showed that our scheme improves the security of the previous scheme with even lesser cost.
Zhengwei Ren, Xianye Zha, Kai Zhang, Jing Liu · 5 authors
A number of solutions have been proposed to tackle the user privacy-preserving issue. Most of existing schemes, however, focus on methodology and techniques from the perspective of data processing. In this paper, we propose a lightweight privacy-preserving scheme for user identity from the perspective of data user and applied cryptography. The basic idea is to break the association relationships between User identity and his behaviors and ensure that User can access data or services as usual while the real identity will not be revealed. To this end, an interactive zero-knowledge proof protocol of identity is executed between CSP and User. Besides, a trusted third-party is introduced to manage user information, help CSP to validate User identity and establish secure channel between CSP and User via random shared key. After passing identity validation, User can log into cloud platform as usual without changing existing business process using random temporary account and password generated by CSP and sent to User by the secure channel which can further obscure the association relationships between identity and behaviors. Formal security analysis and theoretic and experimental evaluations are conducted, showing that the proposal is efficient and practical.
With the increasing interest in connected vehicles along with electrification opportunities, there is an ongoing effort to automate the charging process of electric vehicles (EVs). However, charging EVs takes time and thus in-advance scheduling is needed. This, however, raises privacy concerns since frequent scheduling will expose the charging pattern of the EV to the service providers. Nevertheless, the EV needs to be authenticated which means some information will need to be provided anyway. While there have been many studies to address the problem of privacy-preserving authentication, such solutions will be void if charging payments are made through traditional means. In this paper, we tackle this problem by utilizing distributed applications enabled by Blockchain and smart contracts. We adapt zero-knowledge proofs to Blockchain for enabling privacy-preserving authentication while removing the need for a central authority. The evaluation indicates that the overhead of this process is affordable to enable real-time charging operations for connected EVs.
The smart meters become an important node for managing information about electric power system so, smart-meter drags cyber security attention in this regard. In this paper, the protocol for smart meters named as âprivacy preserving billingâ is used which provides authentication, non-repudiation and integrity by digital signature scheme and zero-knowledge proof. This protocol ensures secrecy and reliability of end to end communication. However, vulnerability lies in integrated circuits of smart meters that can leak sensitive information and side channel attacks (SCA), derive this information from integrated circuits(IC) while it's operating. The most well-known SCA's against smart-meters are electromagnetic radiations, timing and power analysis attacks. Due to side channel attacks integrated circuitâs physical and electrical effects broadcast information related to secret key and have emerged as a major vulnerability to security applications. SCA does not temper IC security as their non-invasiveness observes device under normal conditions. Hence, our ultimate goal is to make circuit of smart-meter immune against side channel attacks, specifically differential power analysis (DPA) attack is main focus, as it is more aggressive than other SCAâs. For this reason, we present basis for SCA resistance and concept of CMOS library. Secondly, the other concept, we introduces is CMOS-based digital isolation that provides immunity to electrical noise and external fields compared to optocouplers for smart-meters.
Physical Unclonable Functions (PUFs) and Hardware Security
The Holy Grail of a decentralised stablecoin is achieved on rigorous\nmathematical frameworks, obtaining multiple advantageous proofs: stability,\nconvergence, truthfulness, faithfulness, and malicious-security. These\nproperties could only be attained by the novel and interdisciplinary\ncombination of previously unrelated fields: model predictive control, deep\nlearning, alternating direction method of multipliers (consensus-ADMM),\nmechanism design, secure multi-party computation, and zero-knowledge proofs.\nFor the first time, this paper proves:\n - the feasibility of decentralising the central bank while securely\npreserving its independence in a decentralised computation setting\n - the benefits for price stability of combining mechanism design, provable\nsecurity, and control theory, unlike the heuristics of previous stablecoins\n - the implementation of complex monetary policies on a stablecoin, equivalent\nto the ones used by central banks and beyond the current fixed rules of\ncryptocurrencies that hinder their price stability\n - methods to circumvent the impossibilities of Guaranteed Output Delivery\n(G.O.D.) and fairness: standing on truthfulness and faithfulness, we reach\nG.O.D. and fairness under the assumption of rational parties\n As a corollary, a decentralised artificial intelligence is able to conduct\nthe monetary policy of a stablecoin, minimising human intervention.\n
Abstract Vector commitment (VC) schemes allow committing to an ordered sequence of ${q}$ values ${(m_1,\cdots ,m_q)}$ in such a way that one can later open the commitment at specific positions. However, the existing VC schemes suffer from two substantial shortcomings that limit their use: (i) the commitments cannot be opened except at some specific positions, and (ii) their security only captures position-binding but offers no privacy: the client may learn additional information about the committed sequence through the proofs and the commitments. To resolve these problems, we first extend VC to a more expressive primitive called VC with sum binding (VCS), in which the commitment can also be opened to the sum of all elements in the committed sequence. VCS additionally satisfies the security of sum binding, which guarantees that the commitment cannot be opened to different sums. To enhance its privacy, we extend VCS to zero-knowledge VCS (ZKVCS), in which commitments and proofs constructed during the protocol execution leak nothing about the committed sequence. We formalize this new property by a standard real/ideal experiment. Meanwhile, the detailed performance analyses and simulations show that our proposed schemes are more practical. Finally, we introduce a novel notion of (zero-knowledge) verifiable database supporting sum and show how to construct it from our (ZK)VCS scheme.
Ming Li, Jian Weng, Anjia Yang, Jia-Nan Liu · 5 authors
Commercial advertisement (ad) dissemination has been proliferating on connected vehicles, allowing users to promote their products via vehicle-to-vehicle/-infrastructure communications. Despite the prospect of ad dissemination in vehicular networks, it faces challenges upon deployment especially on security and privacy. Particularly, vehicles may collude to defraud the advertiser to obtain rewards without disseminating ads, which may cause unfair âfree-ridingâ issue in these activities. Furthermore, concerns on possible privacy leakage may discourage vehicles to participate in the process of ad dissemination. In addition, external DDoS attacks and internal single point of failure may also affect service availability. To address these issues, we explore the potential of blockchain technology to construct a fair and anonymous scheme for advertising in vehicular networks. We first present the overview of the blockchain-based ad dissemination framework. Then, under the framework, we design a concrete, fair and anonymous scheme. To ensure fairness, we utilize the Merkle hash tree together with smart contracts to achieve the âproof-of-ad-receivingâ property (i.e., check whether a vehicle indeed receives an ad without deception or introducing significant storage cost) to mitigate the âfree-ridingâ attack. On the other hand, any ad receiver who acquires a dissemination reward per ad more than once can be effectively detected and will be punished which is achieved by using smart contracts. Additionally, the proposed scheme can protect vehicles' privacy in terms of anonymity and conditional linkability based on zero-knowledge proof techniques. Lastly, extensive security analysis and implementations demonstrate the feasibility and efficiency of the scheme.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Password-based authenticated key exchange($\mathsf {PAKE}$PAKE) protocol, a widely used authentication mechanism to realize secure communication, allows protocol participants to establish a high-entropy session key by pre-sharing a low-entropy password. An open challenge in$\mathsf {PAKE}$PAKEis how to design a quantum-resistant round-optimal$\mathsf {PAKE}$PAKE. To solve this challenge, lattice-based cryptography is a promising candidate for post-quantum cryptography. In addition, Katz and Vaikuntanathan (ASIACRYPT’09) design the firstthree-round$\mathsf {PAKE}$PAKEprotocol by leveraging the smooth projective hash function ($\mathsf {SPHF}$SPHF) over lattices. Subsequently, Zhang and Yu (AISACRYPT’17) optimized Katz-Vaikuntanathan’s approximate$\mathsf {SPHF}$SPHFvia a splittable public key encryption. They then constructed atwo-round$\mathsf {PAKE}$PAKEby using the simulation-sound non-interactive zero-knowledge (NIZK) proofs, but how to construct a lattice-based simulation-sound NIZK remains an open research question. In other words, how to design a one-round$\mathsf {PAKE}$PAKEvia an efficient lattice-based$\mathsf {SPHF}$SPHFstill remains a challenge. In this work, we attempt to fill this gap by proposing a lattice-based$\mathsf {SPHF}$SPHFwith adaptive smoothness. We then obtain aone-round$\mathsf {PAKE}$PAKEprotocol over lattices with rigorous security analysis by integrating the proposed$\mathsf {SPHF}$SPHFinto the one-round framework proposed by Katz and Vaikuntananthan (TCC’11). Furthermore, we explore the possibilities of achieving two-round$\mathsf {PAKE}$PAKEand universal composable (UC) security from our$\mathsf {SPHF}$SPHF, and show the potential application of our$\mathsf {PAKE}$PAKEin Internet of Things (IoTs) where communication cost is the main consideration.