Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

8,503 papersLast indexed Aug 31, 2026
Search papers

Paper index

8,503 results · page 249 of 355

Clear filters
May 22, 2019·arXiv (Cornell University)
1 cites
Zero-Knowledge Proof-of-Identity: Sybil-Resistant, Anonymous\n Authentication on Permissionless Blockchains and Incentive Compatible,\n Strictly Dominant Cryptocurrencies

David Cerezo Sánchez

Zero-Knowledge Proof-of-Identity from trusted public certificates (e.g.,\nnational identity cards and/or ePassports; eSIM) is introduced here to\npermissionless blockchains in order to remove the inefficiencies of\nSybil-resistant mechanisms such as Proof-of-Work (i.e., high energy and\nenvironmental costs) and Proof-of-Stake (i.e., capital hoarding and lower\ntransaction volume). The proposed solution effectively limits the number of\nmining nodes a single individual would be able to run while keeping membership\nopen to everyone, circumventing the impossibility of full decentralization and\nthe blockchain scalability trilemma when instantiated on a blockchain with a\nconsensus protocol based on the cryptographic random selection of nodes.\nResistance to collusion is also considered.\n Solving one of the most pressing problems in blockchains, a zk-PoI\ncryptocurrency is proved to have the following advantageous properties:\n - an incentive-compatible protocol for the issuing of cryptocurrency rewards\nbased on a unique Nash equilibrium\n - strict domination of mining over all other PoW/PoS cryptocurrencies, thus\nthe zk-PoI cryptocurrency becoming the preferred choice by miners is proved to\nbe a Nash equilibrium and the Evolutionarily Stable Strategy\n - PoW/PoS cryptocurrencies are condemned to pay the Price of Crypto-Anarchy,\nredeemed by the optimal efficiency of zk-PoI as it implements the social\noptimum\n - the circulation of a zk-PoI cryptocurrency Pareto dominates other PoW/PoS\ncryptocurrencies\n - the network effects arising from the social networks inherent to national\nidentity cards and ePassports dominate PoW/PoS cryptocurrencies\n - the lower costs of its infrastructure imply the existence of a unique\nequilibrium where it dominates other forms of payment\n

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
May 15, 2019·Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks
2 cites
On the overhead of using zero-knowledge proofs for electric vehicle authentication

David Gabay, Mumin Cebe, Kemal Akkaya

As Electric Vehicles (EVs) are becoming widely available, their secure management is crucial to fully enable their potential. For instance, for convenient charging, they may require quick authentication with the charging stations while they are on the go. As charging is frequently needed, exposing one's charging frequency to the stations may risk the exposure of privacy for the EV driver. Therefore, a mechanism is needed to hide EV information. In this paper, we propose using zero-knowledge proofs to achieve this goal. While zero-knowledge proofs can provide anonymous authentication, they require computation for generation of witnesses. Therefore, we assess the overhead of generating a witness and proof computation at the resource constrained on-board units (OBUs) which are deployed on EVs that utilize wireless communications for scheduling. The results indicate that computation overhead is minimal and can be delployed on resource contrained devices.

Open access
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
Cryptography and Data Security
Original source
May 13, 2019·The World Wide Web Conference
20 cites
PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity Assets.

Hasini Gunasinghe, Ashish Kundu, Elisa Bertino, Hugo Krawczyk · 7 authors

User's digital identity information has privacy and security requirements. Privacy requirements include confidentiality of the identity information itself, anonymity of those who verify and consume a user's identity information and unlinkability of online transactions which involve a user's identity. Security requirements include correctness, ownership assurance and prevention of counterfeits of a user's identity information. Such privacy and security requirements, although conflicting, are critical for identity management systems enabling the exchange of users' identity information between different parties during the execution of online transactions. Addressing all such requirements, without a centralized party managing the identity exchange transactions, raises several challenges. This paper presents a decentralized protocol for privacy preserving exchange of users' identity information addressing such challenges. The proposed protocol leverages advances in blockchain and zero knowledge proof technologies, as the main building blocks. We provide prototype implementations of the main building blocks of the protocol and assess its performance and security.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
May 9, 2019·Philosophy and Phenomenological Research
30 cites
Varieties of Risk

Philip A. Ebert, Martin Smith, Ian Durbach

The notion of risk plays a central role in economics, finance, health, psychology, law and elsewhere, and is prevalent in managing challenges and resources in day-to-day life. In recent work, Duncan Pritchard (2015, 2016) has argued against the orthodox probabilistic conception of risk on which the risk of a hypothetical scenario is determined by how probable it is, and in favour of a modal conception on which the risk of a hypothetical scenario is determined by how modally close it is. In this article, we use Pritchard's discussion as a springboard for a more wide-ranging discussion of the notion of risk. We introduce three different conceptions of risk: the standard probabilistic conception, Pritchard's modal conception, and a normalcy conception that is new (though it has some precursors in the psychological literature on risk perception). Ultimately, we argue that the modal conception is ill-suited to the roles that a notion of risk is required to play and explore the prospects for a form of pluralism about risk, embracing both the probabilistic and the normalcy conceptions. We take the view that a risk judgment always implicates a body of evidence, which we refer to as the background evidence. In cases where the background evidence is not made explicit, we take it to be supplied by the context of utterance and, in typical cases, to be the evidence possessed by the one making the judgment. That is, we are inclined towards a contextualist semantics for utterances such as 3 and 4, on which their truth conditions feature an evidence parameter, the value of which is fixed by the context. The semantics of such utterances is not, however, our primary concern here. As well as making categorical risk judgments such as the above, we often make comparisons. While we may judge that the risk of a plane crash is very low, we may also judge that there is a higher risk of a car crash on the way to the airport. As well as judging that there's a high risk of food poisoning at a particular restaurant, we might also judge that there is a lower risk of food poisoning at the restaurant next door. Moreover, while we often speak about the riskiness of feared events, such as plane crashes, food poisoning, etc., we can also assess the risk of states of affairs. For instance, before drilling into the wall of a 1970s West Australian house, one might assess the risk that the wall contains asbestos, or jurors in a criminal trial, when contemplating a guilty verdict, might consider the risk that the defendant is innocent, or a mountaineer may ponder the risk that the snow conditions are unfavourable for a climb. Here, we treat propositions as the primary bearers of risk, with the riskiness of an event or state of affairs corresponding to the riskiness of the proposition that the event occurs, or the state of affairs obtains. As well as making judgments about the risk of specific events and states of affairs, people also assess the risk of activities or decisions, saying things like ‘Drilling into this wall is risky’, ‘It would be risky to attempt a climb under these conditions’. These judgments are important to understanding the connections between risk and decision making but we put them to one side here. According to the probabilistic of risk, the risk of a proposition is determined by the of higher the the higher the risk. this the risk of is higher the risk of in is more probable is. The be as the background evidence. We Pritchard in the probabilistic as the orthodox of risk is important to however, that this is different to the of risk that has standard in risk and in some this risk is with the of an by a of how or it would is some evidence to that this is as a a recent which with our risk judgments In our be on risk made in cases where is and the of risk the is that the risk judgments that people are inclined to make always with the probabilistic would In to at the 1970s a of in which judgments the probabilistic would These not as evidence against the probabilistic as important and which our judgments about risk and For a of that risk such as the and which in cases to the probabilistic would to be for an about risk are to in take into As a about risk and risk often of the as a to risk judgments some risk judgments be the of a and determined by such as while judgments be by a more and by the or with which the can be and by with the That risk judgments can the probabilistic is to be on a has a which has in a the people is way of the before the it is to The however, a of specific between and on the next The of these is to is not to with this as above, the a of three events obtains. the in the at the the by at the in the the by at the of to speak a of next The of this of events are to According to is and, to we to to We there may be some to judge as Pritchard but would be in about the of the probabilistic this judgment is on this this would to put Pritchard's in the as in which risk judgments to the probabilistic Pritchard with an as on the probabilistic of risk, a or which can our of and that into play in the of cases Pritchard that we might is that the conditions for a in to the conditions in that the in the by at or that the in the the by at or that the to speak a of next the of a In to particular in the next particular In a of that there is a between the with which an event can be or and how probable we the event to as the or the one might that of may an on risk judgments when are made That is, one might that the with which one can the scenario as in might one to it a higher risk the are to be to the to when the are can on how and people take to be with to the in that to take on events on events, when judge the to be in the would be to and as to that is a scenario in which or is to to be about the conditions in may be to that In the event that a in that may to some is the the of about the in The of a can be the of the it is how to the of the conditions in Pritchard a value for the of an in but it is to take this as more and the corresponding value in and a of in which in an scenario are by in about the In a that is for the and that when to between under conditions a or is in some where the are to be a for a for some the might well that the in are The that the in the by at and the in the the by at and the to speak a of next might be to be lower the value of in a more of this the probabilistic that the risk in is lower in for the These are of Pritchard's judgment about the scenario in a way that is with the probabilistic of risk. In as Pritchard to the probabilistic as a of risk of this to be Moreover, as above, it is also in this that Pritchard's judgment is this we put a the Pritchard The of our can be in the which a more discussion of the to the while the that people to our the that people judge to be risky is not with the of judging that the risk of the in the is These on their that Pritchard's judgment about the cases is and against the probabilistic Pritchard that to be by We in a about more we that the is in the of cases to which Pritchard the probabilistic a as to how people judge to to work, there are in which be the car or in a The risk of the car is car is new and it the risk of in a is on the at this and there are of the risk of to is the is this an but in it may be that this is is for instance, in the of risk on which that are to be are for risk in of their risk and a low, but of risk to as the which the are while which are the are to a risk in to be to against may by the and in the and is in the of and and both the risk one the of and against and the of and against one has in the of and against is there is that the risk of is the the the risk of a car and of a are both to be the the both of these are and are against these are the in which be for the are against this the risk that be for the may well be the in which the that we take against or at consider the of the of it is that this to risk is in which to play a role is in the context of of the of criminal are to the risk of an The high standard of for criminal to that a defendant be the risk that or is innocent, the evidence, is very criminal a of and the is to the standard to for For instance, to be guilty of in a defendant defendant be of one of these conditions is not a defendant be of these conditions is this that there is a risk that the defendant not take the there is a risk that the defendant not to the of that and there is a risk that the defendant the this that there is a risk that the defendant is in of the the probabilistic of risk, however, is an The of can be higher both the of and the of a the that a is and the that a is The that a or a is According to the probabilistic of risk, the risk of is and the risk of is low, it that the risk of is are which are at with the probabilistic of risk. we to that such are we are to the that may to however, that the of these to consider of risk that may make different about We to such a notion in As above, Pritchard the not to put on the probabilistic of risk, but to an which the modal of risk. In of the against the event in is, to that that is is for a to in the way at the In the conditions in to be very that the in the by at or that the in the the by at or that the to speak a of next we would to way to the of is by to an of how are to the to The of of is determined by how would to about the in to it into with the in As Pritchard very would to in for a of to in the next that is required is that in a particular there is a very or close in which this obtains. it that as as the in which the is be in which which feature the In to a would to we might in for the in the to by at or the in the to the by at or the to to speak a of next As the in which these events are very or According to the modal of risk, the risk of a proposition is determined by the of the in which is the more these the higher the risk. this the risk of is higher the risk of in the in which is are more the in which is this be to in which the background evidence and which are with the background evidence. As a on the modal of risk and very different The in which the in are to the in which the in the risk of the is higher in the the in both While Pritchard make this it is to that the modal in which is is a in which is or a in which As the in which is be the in which is or the in which is or a of the that a The in which a or a be more the in which a and more the in which a in which a or a be a in which a or a in which a the modal the risk of be higher the risk of and the risk of in be to the higher of these on the modal the risk of is and the risk of is low, it that the risk of is as required by it has a of the modal of risk a which as to it can play one of the roles that we a notion of risk. we can is that as more to the it is to on the modal event which be at high risk of and state of affairs which be at high risk of put the is it that be is to is but be is there is a which is in which to the modal there is a risk of we can to a concern about the modal notion of risk. one is about to into a wall in a West Australian in the and is about the risk that the wall contains the modal the wall asbestos, the risk is In this there is a which the wall contains on the the wall not asbestos, to the modal the risk be in which this is be of the In on the modal it that one make a judgment about the risk that the wall contains a view as to it consider the of jurors in a criminal are contemplating a guilty and about the risk that the defendant is the to the to the defendant as the is the risk that the defendant is not the the the defendant the and the are and the modal that the risk is In this the in which the defendant is be very the of the be different in these but the be or on the the defendant is in innocent, and the are or In this on the modal the risk that the defendant is the is in this the in which the defendant is is the on the modal it that one assess the risk that the defendant is a on is or is the risk is and is the risk is to be of when it to making a decision discussion this also Pritchard's about the about these it for that the conditions in are not that the in the the by at and the in the the by at and the to speak a of next we in a in which the conditions in are the modal would that the risk in is at as high as the risk in or of the modal that there are some cases in which one can judge a proposition to be high risk the to take a view on is In for instance, the modal to judge that there is a high risk be the while on be the of these in the we that there is a very in which While this be it the that the modal is one judge that there is a risk of that is is one on the modal be in an in which it is to judge that there is a risk of That is, a of the modal the wall or the defendant is innocent, one judge these propositions to be risk. however, on the modal these judgments be this is in to the probabilistic the probabilistic the risk that the wall contains or the risk that the defendant is innocent, is a of the evidence, and not on the wall contains asbestos, or the defendant is while the is on the modal can with this in a we there is an notion of risk that can some of the of the modal this particular a one we can consider is how probable it is that the proposition is we might consider is how or it would be for that proposition to be As the discussion our to the is not determined by our to the We might judge that the more in the of an are that we might consider is how or it would be for a proposition to be is to judge that it would be more for the to in in the are it might be for a particular of in the next there is a in which there would be about this some of has to and it may as well be this as In it would be for the in the to the by at and the in the to the by at and the to to speak a of next is this notion of normalcy which is to when we an event as we that it is or In this of it would as for to be the that in the would as when we a as we are not making a about the in to or car to when in the and not not that this is of is that there to be some specific for is there's a with the or the in house, the car is or has the there has to be more to the this is we in these events as may be for to be the that in the but this a of the are on an the to that the conditions in the by at the in the the by at and the to speak a of next are events that would As well as with to how we may also with to how with the normalcy of a proposition to the normalcy of the in which it is the in which the be in which of that an in In the in which the conditions of are are According to the of risk, the risk of a proposition is determined by the normalcy of the in which is more these the higher the risk. this the risk of is higher the risk of in the in which is are more the in which is this be to in which the background evidence and which are with the background evidence. According to the the risk of the is higher in the the in both The in which the in are more the in which the in While the and the modal may make the about the there are a of between the and while the be in a the is not of a normalcy While the as to it not as the is to of events and states of affairs. truth not normalcy and there is in saying is but be As a like the probabilistic the of risk it to assess the risk of a proposition a view on the probabilistic however, the in which is is a in which is or a in which As the in which is be the in which is or the in which is or a of the The in which a or a be more the in which a and more the in which a in which a or a be a in which a or a in which a the the risk of be to the of the risk of and the risk of on the the risk of is and the risk of is low, it that the risk of is The of is a of the risk of a proposition to the in an of in which is the in this is for this we to the as a for a might judge the risk in to be that in a to use the the or by the with which or to The of this has and is often to of as a for judging that has one of as a way of making risk judgments might be to to In to a in which one a in which or a in which The with which one can would in be to the with which one can or the with which one can one one that is risk, on the that it is to and that is risk, on the that it is to one would be to make the very judgment about is that there is a between the of that an event or state of affairs would and the with which it can be it to the in the by at and the in the the by at and the to speak a of next is that these some and, as there is to a in to make them In is in for particular to in the next and is to our of this Pritchard might we a in a particular some an between the with which a hypothetical event or state of affairs can be and the with which it can be In there is some evidence to that to a hypothetical event or state of affairs and to for a hypothetical event or state of affairs a their judgments about or risk the of the role of the with to risk it as an but for probabilistic risk, of be as the for risk of a different risk. We to this in the next has a which has in a the people is way of the before the it is to The however, specific between and on the next The of these is one to is not to with this In the are very against the in As the probabilistic that is the is however, the modal or the can this in risk. Pritchard's about would to to that is required for the to is for to in a particular as as the in which the is be in which which feature the According to the modal the risk of an in be to the risk of an in The the For particular to in a of the are on an the in which the is be in which which feature the the modal and that and are also that is the of the in is In this it the made by the modal and is the we might take to we it is that the is of that we a notion of risk. We three of modal and three of these we might conceptions of risk. That is, three that there is one notion of risk and on how to or that the a of the probabilistic is to to a of and in to judgments can that the to be of as a way of making a risk this is as a of which is it under the as a to risk, this to risk judgments that are at with the probabilistic this is to that the can with the of a of the probabilistic of risk a that the be and the or attempt to the of the probabilistic the use of such may be or for of the may the that it and is to the that may be to for some in risk that be a probabilistic as in the the is also to in risk, such as that between and which can be by the probabilistic to the and of of risk, an is to a view on which there are of risk. While we attempt a or of risk in we the of such a view and for the of view that we to the probabilistic and of our notion of risk, or on different of that While we to the of of risk, it is not our that such In our the of the modal notion of risk for instance, that it as a of our view of this a of the of and in making risk a we different for making risk we are to that one of these a which is a while it is for risk judgments to be by and we that are at play we for making such it may be that the are different of risk, of which can be our the the to use of as a way of judging risk is to an but for a however, this can be as an for is in our notion of risk. also a new on the which to an on risk For the of a has as a of in risk on the that it can people to or probabilistic the which our about risk, to or of the notion of risk. there are a of about on the view we we about the notion of risk and to the probabilistic and is to the notion of risk as a in the of by which to and In this the probabilistic and of risk be as which can be the and which it for a of be not as at but as the of also As more be required to our form of risk We by three our for and psychological discussion the notion of risk and the of risk our Pritchard's While a judge the as with the probabilistic is that one in three and judge to be risky as by the For a one in three a judgment which would to be and For the on the it might be that some of these are by the very of the to the by a notion of risk. the important of how and when such for of this to be an Ultimately, such may to more when a or probabilistic notion a of risk the be with the to judgment about risk. the by that there to be in our risk an which is a probabilistic is to risk pluralism with a by risk and probabilistic risk as the by the and may in a of the as one of the prospects for such a it is that in the role of such as and when making risk judgments be by the role that normalcy plays in judgment about risk. our discussion a new take on the in In a of and and of and as or judgment on them In that the of judgment against the of an probabilistic is often it to take into the of judgment and We not to into the of this but it is important to that it with one of our primary of a probabilistic the for risk The conception of risk a different on about the of risk According to the there are different of our notion of risk, of which their which in some cases but in judge in a way that against the the probabilistic this their judgment may be judging in with the for the notion of risk. may be a in which this the one we that there are with the different of risk, we might these are always or there are in which one of them be as the of and judgment. a we the of of that are to the about the of risk the of to the of a and the of to the standard in a context. the of which standard to be in in a to be to We for our which is to be to in an of and well in the the specific of the we to and for In we and we one background in We the of for this We the which is to the in Pritchard has a which has in a the people is way of the before the it is to The a of in a The of these is in is not to with this The a of three events obtains. the in the at the the by at the in the the by at the of to speak a of next The of this of events are in is not to with the of of the events in this We about their are the by the We them about their risk judgment to the judge The of our are as with to the While both the of scenario is scenario or the a for scenario more the when it to risk judgments to judge both to be judgment more the We with to both their and risk judgments In our we the and the risk on the and, while the before the risk both to the while to a risk judgment in of their judgment some for scenario to with the risk and judge the as risky of we not this for a for one of the and of a for and the to be challenges the in Pritchard's in these cases risk judgments are determined or by a on the a for scenario in one would this to a between the of people made the risk judgment that scenario is more and the the to be however, is not the to a for scenario in of evidence not the of an with is required when these is that these made by that with judge to be may a for a is to judgments and risk judgments in some cases but not in and there are for risk and

Open access
Risk Perception and Management
Decision-Making and Behavioral Economics
Psychology of Moral and Emotional Judgment
Original source
May 9, 2019·Security and Communication Networks
34 cites
New Authentication Scheme to Secure against the Phishing Attack in the Mobile Cloud Computing

E. Munivel, A. Kannammal

A phishing attack is one of the severe threats to the smartphone users. As per the recent lookout report, mobile phishing attack is increasing 85% year to year and going to become a significant threat to the smartphone users. This social engineering attack attempts to get the user’s password by disguising as trusted service provider. Most of the smartphone users are using the Internet services outside of the traditional firewall. Cloud-based documents are one of the primary targets of this phishing attack in mobile cloud computing. Also, most smartphone users are using the cloud storage in their device. To secure against this password attack in a mobile cloud environment, we propose a new authentication scheme to provide novel security to the mobile cloud services. This scheme will verify the user and service provider without transmitting the password using the Zero-knowledge proof based authentication protocol. Moreover, the proposed scheme will provide mutual authentication between the communication entities. The effectiveness of proposed scheme would be verified using protocol verification tool called Scyther.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Cryptography and Data Security
Original source
May 1, 2019·2019 IEEE Symposium on Security and Privacy (SP)
11 cites
Blind Certificate Authorities

Liang Wang, Gilad Asharov, Rafael Pass, Thomas Ristenpart · 5 authors

We explore how to build a blind certificate authority (CA). Unlike conventional CAs, which learn the exact identity of those registering a public key, a blind CA can simultaneously validate an identity and provide a certificate binding a public key to it, without ever learning the identity. Blind CAs would therefore allow bootstrapping truly anonymous systems in which no party ever learns who participates. In this work we focus on constructing blind CAs that can bind an email address to a public key. To do so, we first introduce secure channel injection (SCI) protocols. These allow one party (in our setting, the blind CA) to insert a private message into another party's encrypted communications. We construct an efficient SCI protocol for communications delivered over TLS, and use it to realize anonymous proofs of account ownership for SMTP servers. Combined with a zero-knowledge certificate signing protocol, we build the first blind CA that allows Alice to obtain a X.509 certificate binding her email address alice@domain.com to a public key of her choosing without ever revealing ``alice'' to the CA. We show experimentally that our system works with standard email server implementations as well as Gmail.

Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
May 1, 2019·ICC 2019 - 2019 IEEE International Conference on Communications (ICC)
2 cites
Online Advertising with Verifiable Fairness

Cheng Huang, Jianbing Ni, Rongxing Lu, Xuemin Shen

Online advertising is a popular business model where advertisers can deliver promotional marketing messages to their potential consumers via Ad brokers. However, as the proxy between advertisers and customers, a malicious Ad broker could arbitrarily fabricate the advertising rates to overcharge advertisers, which causes unnecessary financial loss. To deal with this issue, we propose a publicly verifiable and fair online advertising scheme. Specifically, a proof-of-downloading (PoD) protocol is first designed based on the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK), to help the customer generate a unique acknowledgment for downloading the Ad; the acknowledgment will then be published to both the advertiser and the Ad broker such that anyone can verify the acknowledgment to guarantee the fairness and transparency of online advertising. Moreover, as long as the customer's private key is not leaked, our scheme can resist the collusion attack, i.e., the Ad broker and the customer collude with each other to deceive the advertiser, which has not been addressed in previous works. Finally, we evaluate the performance of the proposed scheme to demonstrate its computational efficiency.

Cryptography and Data Security
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
May 1, 2019·2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
12 cites
CaIV: Cast-as-Intended Verifiability in Blockchain-based Voting

Raphael Matile, Bruno Rodrigues, Eder J. Scheid, Burkhard Stiller

Democracy in the digital age has attracted a lot of public attention in recent years. However, bringing the human right of secrecy in voting to electronic systems is difficult. Properties, such as the possibility of verifying universally that any vote counted was indeed carrying the decision made by a voter, are often conflicting and a trade-off must be found. This paper proposes a blockchain-based electronic voting system providing explicitly cast-as-intended verifiability. By using a non-interactive zero-knowledge proof of knowledge any voter can verify that his or her encrypted vote represents the decision voted for while maintaining at the same time the secrecy of the ballot. In addition, any required cryptographic material can be generated in linear time with respect to the number of voters, making the system suitable for large scale elections, thus scalable.

Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Apr 30, 2019·IET Information Security
2 cites
Witness indistinguishability and witness hiding against quantum attacks

Huiqin Xie, Li Yang

The development of quantum computers has urged the cryptographic community to prepare cryptographic primitives for the eventual arrival of the post‐quantum world. To this end, the authors study the witness indistinguishability (WI) and witness hiding (WH) of proof systems against quantum adversaries. They give formal definitions of quantum WI (QWI) and quantum WH (QWH), present proof systems satisfying these definitions, and specify a condition under which QWI implies QWH. Regarding the non‐interactive proof systems, they prove that, even if a common reference string is used to generate polynomially many non‐interactive proofs, the QWI is still preserved, while quantum zero‐knowledge has no such beneficial property. To show the strength of QWI, they present two applications of them. First, they prove that the construction proposed by Feige et al . that transforms any non‐interactive bounded zero‐knowledge proof system to a general one is also feasible against quantum adversaries. Second, they construct a quantum‐secure signature scheme in the CRS model, which is existentially unforgeable against quantum adversaries and remains secure even if a common random string is used to sign polynomially many messages.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Complexity and Algorithms in Graphs
Original source
Apr 17, 2019·Cryptography
0 cites
I2PA : An Efficient ABC for IoT

Ibou Sene, Abdoul Aziz Ciss, Oumar Niang

The Internet of Things (IoT) is very attractive because of its promises. However, it brings many challenges, mainly issues about privacy preservation and lightweight cryptography. Many schemes have been designed so far but none of them simultaneously takes into account these aspects. In this paper, we propose an efficient attribute-based credential scheme for IoT devices. We use elliptic curve cryptography without pairing, blind signing, and zero-knowledge proof. Our scheme supports block signing, selective disclosure, and randomization. It provides data minimization and transaction unlinkability. Our construction is efficient since smaller key size can be used, and computing time can be reduced. As a result, it is a suitable solution for IoT devices characterized by three major constraints, namely low-energy power, small storage capacity, and low computing power.

Open access
2 source records
cs.CR
Cryptography and Data Security
Cryptography and Residue Arithmetic
Original source
Apr 4, 2019·Journal of King Abdulaziz University-Computing and Information Technology Sciences
2 cites
Privacy-aware Decentralized and Scalable Access Control Management for IoTEnvironment

Abrar O. Alkhamisi and Fathy Alboraei Abrar O. Alkhamisi and Fathy Alboraei

In recent years, the Internet of Things (IoT) plays a vital role in our daily activities .Owing to the increased number of vulnerabilities on the IoT devices, security becomes critical in the untrustworthy IoT environment. Access control is one of the top security concerns, however, implementing the traditional access control mechanisms in the resource-constrained nature of the IoT devices is a challenging task. With the emergence of blockchain technology, several recent research works have focused on the adoption of blockchain in IoT to resolve the security concerns. Despite, integrating the blockchain in the resource-constrained IoT context is difficult. To overcome these obstacles, the proposed work presents a privacy-aware IoT security architecture to ensure the access control based on Smart contract for resource-constrained and distributed IoT devices. The design of the proposed architecture incorporates three main components such as the contextual blockchain gateway, decentralized revocation manager, and non-interactive zero-knowledge proof based validation. By modeling the contextual blockchain gateway, the proposed architecture ensures the dynamic authentication and authorization based on the contextual information and access policies. Instead of integrating the blockchain technology into resource-constrained IoT devices, the smart contract-based distributed access control system with the contextual blockchain gateway provides the scalable solution. With the association of decentralized revocation manager in the smart contract, it prevents the resource access from the unauthorized users by dynamically generating and updating the revoked user list of all the nodes in the smart contract. Moreover, the proposed architecture employs the non-interactive zeroknowledge proof cryptographic protocol to ensure the transaction privacy within the smart contract. Consequently, it maintains the trade-off between the transparency and privacy while ensuring the security for the distributed IoT environment.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Apr 2, 2019·Journal of Immunotherapy and Precision Oncology
0 cites
5th Annual Immuno-Oncology 360° Conference: Spanning Science and Business to Bring New Therapies to Patients

Marie Recine

The atmosphere at the 5th Annual Immuno-Oncology 360° (IO360°) Conference, which took place on February 6–8 at the Crowne Plaza Times Square in New York City, was truly collaborative. Co-chaired by Axel Hoos, MD, PhD (GSK), James Gulley, MD, PhD (National Cancer Institute [NCI]), and Andrew Baum, MD (Citi), the conference featured almost 100 speakers and 10 plenary sessions, including 4 keynote talks and 7 panel discussions. More than 400 attendees representing the pharma, biotech, academic, regulatory, and private investment communities gathered to discuss the rapid advancement in scientific, clinical, and business developments in IO, with the goal of accelerating the development of new therapeutics for patients. Over 350 partnering meetings took place over the 3-day conference.“360 degrees means we really want to speak to all stakeholders,” stated Dr. Hoos. The meeting is structured for the scientists to bring their most promising next-generation mechanisms that will help address these challenges. However, it is also important to look at therapies that haven't worked, so we don't repeat the same challenges of the past, he noted. “But IO360° is not just the science, it's about the entire ecosystem in which the science exists, and that includes the patients and those that provide the funding to make the science happen.”Michel Sadelain, MD, PhD, of Memorial Sloan Kettering Cancer Center, opened the meeting with a keynote, Chimeric Antigen Receptor (CAR) - T Cell Therapy and the CD19 Paradigm. With two CD19 CAR-T cells (CAR Ts) approved in 2017, Dr. Sadelain identified three new directions being taken to optimize CAR T therapy and develop next-generation CAR Ts. The first is addressing exhaustion (loss of functionality) using genome engineering at a carefully select locus (TRAC) to create more potent CAR Ts and incorporating new designs that modify the activating portion of the CAR and balance rapid expansion and retained memory (1XX CAR). The second is gaining insight into the pathophysiology of cytokine release syndrome, including CAR T–macrophage interactions, to try and reduce toxicity. The third is employing new strategies for circumventing antigen escape, such as use of radiosensitization and combinatorial targeting.The Discovery and Preclinical Science plenary focused on strategies being investigated to modify the tumor microenvironment and address limitations of patient-sourced therapies. According to the plenary chair, Ronald Herbst, PhD, “we are all excited about the potential for immunotherapy for patients with cancer, but many patients don't respond to checkpoint inhibitors.” Part of the problem is explained by the fact that “immune contexture varies within and across tumor types, and so-called ‘hot’ versus ‘cold’ tumors,” he noted. In order to increase the efficacy of immunotherapy, a number of areas are actively being targeted, including antigen presentation, innate mechanisms of activation, the tumor microenvironment, and overcoming immunosuppression.A variety of cells, growth factors, and cytokines in the tumor microenvironment play a pivotal role in whether or not immunotherapy is effective. Various strategies are being employed that attempt to modify the tumor microenvironment to overcome immunosuppressive mechanisms, such as blocking adenosine with an anti-CD73 monoclonal antibody (oleclumab, Medimmune) or an A2A receptor antagonist (CPI-144, Corvus), or inhibiting the IDO (indoleamine 2,3-dioxygenase) pathway (indoximod, NewLink Genetics). Other strategies are being employed to enhance the efficacy of cytokines to augment the expansion and activation of T cells, such as engineering enhanced versions of growth factors such as interleukin-2 (IL-2; NKTR-214, Nektar, and MDNA109, Medicenna) and IL-10 (pegilodecakin, ARMO). For example, pegilodecakin, a long-acting pegylated form of IL-10, induces hallmarks of CD8+ T cell immunity in cancer patients. According to Aung Naing, MD, and Martin Oft, MD, pegilodecakin demonstrated clinical benefit in studies as a single agent and in combination with both chemotherapy and checkpoint inhibitors across several tumor types. The agent is currently being investigated in a Phase 3 trial in metastatic pancreatic cancer.Off-the-shelf hematopoietic cell products are being developed to address some of the limitations of patient-sourced cell therapies, such as heterogeneity, single-patient manufacturing, need for sufficient cells, extended production time, and cost. For example, engineered CAR natural killer cells, derived from induced pluripotent stem cells, are being developed that incorporate several individual components that together help to enhance persistence and antitumor efficacy (FT596, Fate Therapeutics). Multicombinatorial strategies such as this may be key in reigniting the endogenous immune system and improving efficacy in solid tumor space.Genentech's Priti Hegde, PhD, opened the Translational Science and Emerging Biomarkers plenary, part 1, with a keynote, Biomarker Signaling: Turning Cold Tumors Hot. Individual cancer types can be characterized along the tumor immunity continuum based on immune phenotype (i.e. inflamed or noninflamed) and tumor mutational burden (TMB). How can we generate an immune response signal in noninflamed tumors when most do not achieve the TMB threshold that selects for benefit? Dr. Hedge highlighted two approaches: adaptive immunity, which has the potential to drive memory response, and synthetic immunity, which has the potential to sustain efficacy and drive log kill. An example of an adaptive immunity approach is neoantigen-specific T-cell therapy, in which there are limited but encouraging data demonstrating its ability to promote adaptive immunity in noninflamed tumors. Synthetic immunity approaches include engineered T cells (e.g. NY-ESO SPEAR T cells [GSK/Adaptimmune], BMCA CAR Ts) and bi-specific biologics (e.g. antibodies, BITEs® [Amgen], ImmTAC® [Immunocore]), in which there is a proof of concept that these approaches are feasible in solid tumors and checkpoint inhibitor-refractory hematologic malignancies.One may also need to address the underlying biology to turn cold tumors hot. According to Dr. Hegde, the future of immunotherapy may be highly personalized, and one will need to look at a variety of markers in biopsy specimens using a variety of techniques. This will only be possible if we have: (1) a tissue-conserving, regulatory-grade decentralized platform to be able to run all of these assays in trials and (2) trial designs and statistical analysis plans that enable diagnostic signal-seeking validation and a path for registration.The remainder of the plenary reported on translational data and evolving biomarkers and applications to help support decision-making for IO drug development.Negative results from the Phase 3 study of the therapeutic prostate cancer vaccine PROSTVAC (Bavarian Nordic) show that a combinatorial approach may be needed with vaccines. Similarly, oncolytic viruses may need multiple transgenes and mechanisms to reverse complex immunosuppressive microenvironments. To address this issue, T-Stealth™ oncolytic viruses (BeneVir) can incorporate multiple genes, evade clearance by the innate and adaptive immune systems, and be combined with other drugs and IO agents.With the increasing need for biomarker support, the clinical trial laboratory reality in the IO space is complex. Patrice Hugo, PhD (Q2 Solutions), summarized important features to consider when selecting a lab partner for drug development. Key strategies to successfully introduce innovation in the clinical trial lab space include joint review of pros and cons of technologies, consideration of joint investments, performing Phase 1 specialized testing in niche labs/academic settings with transfer to a central lab, and discussion and planning for regulatory requirements.Advances in positron emission tomography (PET) imaging and radiomics provide a quantitative, noninvasive way to assess the dynamic changes of the immune system. For example, CD8 PET (Imaging Endpoints) may help distinguish between hot and cold tumors and address fundamental questions regarding the role of CD8 cells in the tumor microenvironment.Other unique biomarkers and applications under investigation include MultiOmyx™ (NeoGenomics), a proprietary multi “omic” technology that enables detection and visualization of up to 60 biomarkers on a single slide; immunosequencing (immunoSEQ, Adaptive Biotechnologies), a clinical diagnostic for monitoring clonal expansion and predicting/evaluating response to therapy that can also be used in combination with cellular immunology and computational biology (Multiplexed Identification of T cell Receptor Antigen [MIRA] assay, Adaptive Biotechnologies) to map T-cell receptors; and CANscript™ (Mitra), a personalized ex vivo histoculture approach that can be used to evaluate drug-induced modulation of the tumor microenvironment and predict clinical performance.The IO Novel Technologies and Innovative Solutions plenary showcased companies that have technologies and solutions that will help stakeholders in the IO field advance developments for cancer therapeutics. Presenters included Advaxis, Bioxcel Therapeutics, IAG, Provecs Medical, Rgenix, and Sensei Bio.Andrew Baum, MD (Citi), opened the Financial and Commercial Implications plenary with a keynote, Evaluation and Forecast of the IO Space. He started off by discussing key questions on health-care investors' minds. According to Dr. Baum, “what investors don't like very much about IO is that the technology cycles are short, so you can go from here to zero very quickly very easily.” He cited ipilimumab and the fact that it was quickly eclipsed by anti-PD (L)-1 agents. Another issue is the “paradox of choice,” as there are so many different modalities. “It's almost overwhelming,” he noted, “especially for someone that doesn't have a deep scientific background to interpret a Phase one trial.” Other questions involve primary and secondary resistance, cell therapy manufacturing constraints, minimizing/managing toxicity, and financial toxicity. However, despite these questions, “the good news is the amount of capital, the enthusiasm, and the scientific advancement all mean that we're going to make huge strides in IO, I have no doubt.”Dr. Baum stressed the importance of learning from historic disappointments and noted that we need better biomarkers, better trials, and patience so that the benefits can be extended to more patients. He ended his presentation with a slide showing Citi's top 10 novel IO targets for 2020, in which IL-2/IL-15 took the top spot.Khalil Barrage (Invus) agreed that the IO revolution has led to unprecedented investor enthusiasm for oncology, unlocking massive commercial opportunities. However, the discovery of checkpoints and their curative potential has led to hype in IO drug discovery, resulting in risky behavior. In addition, the flood of capital has lowered potential returns and there are a lot of IO agents in development with poorly validated rationale. As a result, Invus' approach to investing incorporates strategies such as diversification, selectivity, exploring synergistic opportunities, investing where innovation is happening, paying a premium for validated approaches when warranted, and assessing reimbursement.The plenary concluded with a panel discussion on monetizing science: the preparation of an IPO, straight licensing with the transition to a public company, and decision-making on prioritization within portfolios. Key takeaways included strategies for building out scientific and executive talent, the importance of having a scientific advisory board to test out the research, and being prepared to be a public company.The Trends and Collaborations plenary featured presentations by three major industry media companies in the IO field, which discussed new trends and their effect on the investment landscape.BioCentury analyzes IO trends at recent medical meetings using machine learning, began Simone Fishburn, PhD, VP, and Executive Editor. Despite the huge focus on PD (L)-1, academics and companies are aggressively looking for, and finding new targets, with LAG3 topping the list in company oncology pipelines in 2019. CAR T activity is moving into solid tumors, with new constructs and multiple tumor antigens targeted. Immunometabolism and tumor mutation burden are hot topics. Funding for IO start-ups is outstripping other areas, both inside and outside oncology, drawing traditional and corporate investors.According to John D. Carroll (Endpoints News), these trends are supported by global data published by the Cancer Research Institute, which show that there were 3394 IO agents representing 417 targets in the pipeline in 2018, representing a 67% increase over 2017.How are these trends affecting the investment landscape? According to Jeff Bockman, PhD (Cello Health BioConsulting), IO dominates oncology growth, but not sales. Moreover, although IO deals have shown evidence of slowing, whether due to maturation, saturation, or fatigue, and oncology and IO investments remain robust.The Business Development plenary, hosted by Solebury Trout, included panel discussions on partnering, fundraising, and rational investing. The first panel discussed IO partnering strategies from the viewpoint of pharma and academia. According to Dr. Hoos, who the partnering in this space have but there has much and is only that companies have started their unique which will a partnering the for is tumor and the and the companies on the panel and there to be both and with some moving from and on those that can IO and agents are being by most in the and are to play which was for and discussed in the IO space and a number of For example, the panel stressed the importance of at and and on key and as a private on their ecosystem their investors with in the past, key to their than at with the top at the with key the of and companies introduce than need to so that can panel focused on IO investment investors this an time, with a future for many modalities. However, the massive of data is it to to to from a The investors on the panel on a variety of such as the of and whether the data support a or whether an agent has a or has a niche in the IO important is a in their and their to plenary ended with a with of by Solebury Trout, the discussion focused on in the company, with a an For companies looking for highlighted the fact that as a and stressed the need to and where are are some very so both and in to a with a can try and to more like in As industry are companies can be quickly with limited capital, like companies have in the began with a keynote, to led by and MD, of of According to Dr. we are at an in it has from one to has the and of tumor types, agents and trials are and there is an to use to enable to of trials are the way new therapies are developed for cancer, make better and more personalized The of are testing drugs where most (i.e. the order of therapy to about response in the of building an to evaluate drugs and using imaging and biomarker and being by is a platform trial for of biopsy is used to assess and imaging and adaptive The and the are structured to enable and release of agents the The primary is response which is a highly of and and is in biomarker The from biomarker and is to drug to Dr. we want innovation to we have to The focus of new drug development be a a from of metastatic to is a huge is also a huge goal of is to of patients to with and of therapy based on Dr. ended with one of for drug from finding out which drug be to the with two The first Science and Emerging Biomarkers Part was led by PhD, of and to focus on biology and to help predict to Technologies discussed included to enhance antibody therapeutics mechanisms of to immune the for biomarker discovery a and a receptor in second for IO was led by of and was for clinical trial who to it to an IO clinical discussed included an clinical trial study a complex Phase 1 trial in IO and clinical trial for The ended in a panel discussion on the challenges with IO data and to advance to PhD, at the and (i.e. may not the clinical benefit of IO agents. As a result, trends include the use of immune response machine learning to the of imaging and new techniques. The IO plenary up the with a discussion of novel imaging are unique challenges with the use of response at IO clinical as a of complex According to some of these challenges can be by the and of response and including a of in the can be by the use of and and analysis and PhD are being used in with to more from to as as better between and such as the CD8 PET discussed is also an evolving Similarly, imaging using PET an to assess all of a tumors for with a single PET and assess use of a novel three opened with the of with cancer, cancer 10 as metastatic chemotherapy and therapies, and of an immunotherapy trial at the The the that cancer, and those cells in the an of the cells and the cancer has the of being the first to be of metastatic cancer a of to to from in the concluded with some to patients who be in the same the same to with cancer or out as much as you can about to a cancer to to not just one of therapy but several of out about clinical trials and whether you can in The is out there and you as try and on the was a panel discussion on to IO in a The are to but be and and the of a tumor to be want to if the tumor has by the adaptive immune is it by T cells if do have an immunosuppressive factors are in the tumor However, are an important the is the of the cell types are but also and able to look in the is but it doesn't provide all the can all these be with a new plenary for Cell According to Dr. Gulley, therapy has the to on the of cancer there is activity in hematologic but it's is needed to achieve the same effect in solid tumors, so this is where there is much The is to was in studies but the benefit to a of patients. The new technologies and targets discussed in this plenary to do just technology to a T cells their However, in the of approved CAR are According to MD of this as a of of and of He cited a where CD19 in a single cell led to by the CD19 which may have important for manufacturing and other cell therapies. For and the can be with a CAR T or it can be with a new of CAR that the SPEAR are an engineered T-cell of cells that are to a that a antigen in many technology an over CAR T therapy in that it to both and results have in a cancer for which there are no therapies the of noted products a number of over CAR Ts. CAR Ts Chimeric Antigen Receptor developed using the platform are being investigated in and multiple The is to multiple to create T cells with such as the ability to or overcome may an over other therapies in solid tumors in that multiple tumor antigens and there is a of or The technology used to develop the that has and of efficacy have in and the for the has from to to and the is a therapies have the potential to enhance CAR T activity in solid tumors. combination strategies consider both and can be used to enhance cell and and factors in the tumor microenvironment, or and plenary ended with a panel discussion on and clinical to IO therapeutics that will to more and therapies. of the strategies discussed were including a to and products and addressing antigen with or combination In order to we need to address like the when moving from in to the clinical as as cell and the used to create the may the cells, manufacturing and we need to cell therapies so that more patients will have conference concluded with the IO Development plenary, which discussed recent IO clinical The plenary began with an of data for the activity has demonstrated in more than cancer types. The agent has across more than including in is moving into the of therapy, and next-generation biomarkers are to help promising were also for a a and combination immunotherapy and the tumor receptor has to more benefit in Dr. Hoos. However, there is a lot of As a result, “we need to new to the benefit PD Cell therapy has really to the of engineered and we are to the benefit from to solid tumors and overcoming the such as T-cell that in the for patients is

Open access
CAR-T cell therapy research
Biomedical Ethics and Regulation
Biosimilars and Bioanalytical Methods
Original source
Apr 1, 2019·Journal of Physics Conference Series
7 cites
Blockchain-based Intelligent Hospital Security and Data Privacy Construction

Qiuzi Huang, Shuyu Chen, Hui Zhao, Junhao Wen

With the rapid development of medical information services, the construction of intelligent hospitals is opening up a new mode of medical treatment in the health care industry. Medical data is gradually becoming more and more important, while it also faces some challenges, among which the most urgent problem to be solved is data security and privacy protection. In the construction of intelligent hospitals, the safety issues among the basic information of patients, the protection of medical information and inter-institutional information sharing have become the focus at this stage. Blockchain technology, with highly security, reliable architecture and algorithm design have operated stably in the financial industry for more than seven years. The related innovative technologies such as distributed ledgers, smart contracts, symmetric encryptions and consensus mechanisms are used widely in many fields. This paper will take the demonstration construction of Chongqing Intelligent Hospital as an example, which tries to combine the blockchain, homomorphic encryption and zero-knowledge proof technology to carry out the research on the security construction and data privacy protection of intelligent hospitals.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare and Education
Original source
Apr 1, 2019·2019 IEEE International Conference on RFID (RFID)
15 cites
Configurable Anonymous Authentication Schemes For The Internet of Things (IoT)

Amar Rasheed, Ray R. Hashemi, Ayman Bagabas, Jeffrey A. Young · 6 authors

The Internet of Things (IoT) has revolutionized the way of how pervasive computing devices communicate and disseminate information over the global network. A plethora of user data is collected and logged daily into cloud-based servers. Such data can be analyzed by the IoT infrastructure to capture users' behaviors (e.g. users' location, tagging of smart home occupancy). This brings a new set of security challenges, specifically user anonymity. Existing access control and authentication technologies failed to support user anonymity. They relied on the surrendering of the device/user authentication parameters to the trusted server, which hence could be utilized by the IoT infrastructure to track users' behavioral patterns. This paper, presents two novel configurable privacy-preserving authentication schemes. User anonymity capabilities were incorporated into our proposed authentication schemes through the implementation of two crypto-based approaches (i) Zero Knowledge Proof (ZKP) and (ii) Verifiable Common Secret Encoding (VCSE). We consider a user-oriented approach when determining user anonymity. The proposed authentication schemes are dynamically capable of supporting various levels of user privacy based on the user preferences. To validate the two schemes, they were fully implemented and deployed on an IoT testbed. We have tested the performance of each proposed schemes in terms of power consumption and computation time. Based on our performance evaluation results, the proposed ZKP-based approach provides better performance compared to the VCSE-based approach.

User Authentication and Security Systems
Advanced Malware Detection Techniques
Advanced Authentication Protocols Security
Original source
Apr 1, 2019·2019 IEEE International Conference on Decentralized Applications and Infrastructures (DAPPCON)
19 cites
An Improved Non-Interactive Zero-Knowledge Range Proof for Decentralized Applications

Ya Che Tsai, Raylin Tso, Ziyuan Liu, Kung Chen

Blockchain is the core technology underlying the first decentralized cryptocurrency, Bitcoin, introduced by Nakamoto in 2008. Since then, blockchain technology has many more advancements that are being developed and experimented. In particular, recent blockchain platforms such as Ethereum offer general and executable scripts, namely smart contracts, that can be employed to develop decentralized applications (DApps) in many domains beyond payment. However, the transparency of blockchain data raises concerns for many applications that require high privacy level. Therefore, many privacy enhancing technologies have been applied to DApp development, including zero knowledge proof (ZKP). This paper focuses on a particular kind of ZKP, called zero knowledge range proof (ZKRP), that has been applied in blockchain-based payments for banks. ZKRP allows a user to convince other people that a secret value actually lies within an interval without revealing any information about the secret. Here we introduce a new ZKRP which has the following remarkable features: (1) Non-interactive: No communication is required between a user and a verifier during the proof. (2) Range-flexibility: There is no limitation on the lower bound and the upper bound of the range except that they are natural numbers. (3) Efficiency: Our scheme is modified from that of Pang et al. (2010), yet achieves better security and is more efficient than their scheme. We believe our new ZKRP can be beneficial to the development of DApps and can extend the application scope to more scenarios.

Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Original source
Apr 1, 2019·TELKOMNIKA (Telecommunication Computing Electronics and Control)
3 cites
Guillou-quisquater protocol for user authentication based on zero knowledge proof

Kevin Kusnardi, Dennis Gunawan

Authentication is the act of confirming the validity of someone’s personal data. In the traditional authentication system, username and password are sent to the server for verification. However, this scheme is not secure, because the password can be sniffed. In addition, the server will keep the user’s password for the authentication. This makes the system vulnerable when the database server is hacked. Zero knowledge authentication allows server to authenticate user without knowing the user’s password. In this research, this scheme was implemented with Guillou-Quisquater protocol. Two login mechanisms were used: file-based certificate with key and local storage. Testing phase was carried out based on the Open Web Application Security Project (OWASP) penetration testing scheme. Furthermore, penetration testing was also performed by an expert based on Acunetix report. Three potential vulnerabilities were found and risk estimation was calculated. According to OWASP risk rating, these vulnerabilities were at the medium level.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source
Mar 31, 2019·Advances in information security, privacy, and ethics book series
1 cites
How to Authenticate MQTT Sessions Without Channel- and Broker Security

Reto E. Koenig, Lukas Laederach, Cédric von Allmen

This paper describes a new but state-of-the-art approach to provide authenticity in mqtt sessions using the means of zero-knowledge-proofs. This approach completely voids session hijacking for the mqtt protocol and provides authenticity without the need for any network-security nor channel-security nor broker-based predefined ACLs. The presented approach does not require the broker to keep any secrets for session handling, what so ever. Moreover, it allows the clientID, which represents the identification for a session, to be publicly known. The presented approach allows completely anonymous but authentic sessions, hence the broker does not need any a priori knowledge of the client-party. As it is especially targeted for applications within the world of IoT, the presented approach is tuned to require only the minimum in extra power in terms of energy and space. The approach does not introduce any new concept, but simply fusions a state-of-the-art cryptographic zero knowledge proof of identity with the existing MQTT-5 specification. Thus no protocol extension is required in order to provide the targeted security properties. The described approach is completely agnostic to the application layer at the client side and is only required during mqtt-session establishment.

Open access
3 source records
cs.NI
cs.CR
Security and Verification in Computing
Original source
Mar 28, 2019·DROPS (Schloss Dagstuhl – Leibniz Center for Informatics)
6 cites
DEEP-FRI: Sampling Outside the Box Improves Soundness

Eli Ben‐Sasson, Lior Goldberg, Swastik Kopparty, Shubhangi Saraf

Motivated by the quest for scalable and succinct zero knowledge arguments, we revisit worst-case-to-average-case reductions for linear spaces, raised by [Rothblum, Vadhan, Wigderson, STOC 2013]. The previous state of the art by [Ben-Sasson, Kopparty, Saraf, CCC 2018] showed that if some member of an affine space U is δ-far in relative Hamming distance from a linear code V - this is the worst-case assumption - then most elements of U are almost-δ-far from V - this is the average case. However, this result was known to hold only below the "double Johnson" function of the relative distance δ_V of the code V, i.e., only when δ < 1-(1-δ_V)^(1/4). First, we increase the soundness-bound to the "one-and-a-half Johnson" function of δ_V and show that the average distance of U from V is nearly δ for any worst-case distance δ smaller than 1-(1-δ_V)^(1/3). This bound is tight, which is somewhat surprising because the one-and-a-half Johnson function is unfamiliar in the literature on error correcting codes. To improve soundness further for Reed Solomon codes we sample outside the box. We suggest a new protocol in which the verifier samples a single point z outside the box D on which codewords are evaluated, and asks the prover for the value at z of the interpolating polynomial of a random element of U. Intuitively, the answer provided by the prover "forces" it to choose one codeword from a list of "pretenders" that are close to U. We call this technique Domain Extending for Eliminating Pretenders (DEEP). The DEEP method improves the soundness of the worst-case-to-average-case reduction for RS codes up their list decoding radius. This radius is bounded from below by the Johnson bound, implying average distance is approximately δ for all δ < 1-(1-δ_V)^(1/2). Under a plausible conjecture about the list decoding radius of Reed-Solomon codes, average distance from V is approximately δ for all δ. The DEEP technique can be generalized to all linear codes, giving improved reductions for capacity-achieving list-decodable codes. Finally, we use the DEEP technique to devise two new protocols: - An Interactive Oracle Proof of Proximity (IOPP) for RS codes, called DEEP-FRI. The soundness of the protocol improves upon that of the FRI protocol of [Ben-Sasson et al., ICALP 2018] while retaining linear arithmetic proving complexity and logarithmic verifier arithmetic complexity. - An Interactive Oracle Proof (IOP) for the Algebraic Linking IOP (ALI) protocol used to construct zero knowledge scalable transparent arguments of knowledge (ZK-STARKs) in [Ben-Sasson et al., eprint 2018]. The new protocol, called DEEP-ALI, improves soundness of this crucial step from a small constant < 1/8 to a constant arbitrarily close to 1.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Coding theory and cryptography
Original source
Mar 18, 2019·arXiv (Cornell University)
883 cites
Security and Privacy on Blockchain

Rui Zhang, Rui Xue, Ling Liu

Blockchain offers an innovative approach to storing information, executing transactions, performing functions, and establishing trust in an open environment. Many consider blockchain as a technology breakthrough for cryptography and cybersecurity, with use cases ranging from globally deployed cryptocurrency systems like Bitcoin, to smart contracts, smart grids over the Internet of Things, and so forth. Although blockchain has received growing interests in both academia and industry in the recent years, the security and privacy of blockchains continue to be at the center of the debate when deploying blockchain in different applications. This article presents a comprehensive overview of the security and privacy of blockchain. To facilitate the discussion, we first introduce the notion of blockchains and its utility in the context of Bitcoin-like online transactions. Then, we describe the basic security properties that are supported as the essential requirements and building blocks for Bitcoin-like cryptocurrency systems, followed by presenting the additional security and privacy properties that are desired in many blockchain applications. Finally, we review the security and privacy techniques for achieving these security properties in blockchain-based systems, including representative consensus algorithms, hash chained storage, mixing protocols, anonymous signatures, non-interactive zero-knowledge proof, and so forth. We conjecture that this survey can help readers to gain an in-depth understanding of the security and privacy of blockchain with respect to concept, attributes, techniques, and systems.

Open access
3 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Mar 14, 2019·IEEE Transactions on Intelligent Transportation Systems
58 cites
Adaptive Group-Based Zero Knowledge Proof-Authentication Protocol in Vehicular Ad Hoc Networks

Amar Rasheed, Rabi Mahapatra, Felix G. Hamza-Lup

Vehicular Ad Hoc Networks (VANETs) are a particular subclass of mobile ad hoc networks that raise a number of security challenges, notably from the way users authenticate the network. Authentication technologies based on existing security policies and access control rules in such networks assume full trust on Roadside Unit (RSU) and authentication servers. The disclosure of authentication parameters enables user's trace-ability over the network. VANETs' trusted entities (e.g. RSU) can utilize such information to track a user traveling behavior, violating user privacy and anonymity. In this paper, we proposed a novel, light-weight, Adaptive Group-based Zero Knowledge Proof-Authentication Protocol (AGZKP-AP) for VANETs. The proposed authentication protocol is capable of offering various levels of users' privacy settings based on the type of services available on such networks. Our scheme is based on the Zero-Knowledge-Proof (ZKP) crypto approach with the support of trade-off options. Users have the option to make critical decisions on the level of privacy and the amount of resources usage they prefer such as short system response time versus the number of private information disclosures. Furthermore, AGZKP-AP is incorporated with a distributed privilege control and revoking mechanism that render user's private information to law enforcement in case of a traffic violation.

Open access
2 source records
Vehicular Ad Hoc Networks (VANETs)
Mobile Ad Hoc Networks
Advanced Authentication Protocols Security
Original source
Mar 9, 2019·arXiv (Cornell University)
1 cites
Post-Quantum Cryptographic Hardware Primitives

Lake Bu, Rashmi Agrawal, Hai Cheng, Michel A. Kinsy

The development and implementation of post-quantum cryptosystems have become a pressing issue in the design of secure computing systems, as general quantum computers have become more feasible in the last two years. In this work, we introduce a set of hardware post-quantum cryptographic primitives (PCPs) consisting of four frequently used security components, i.e., public-key cryptosystem (PKC), key exchange (KEX), oblivious transfer (OT), and zero-knowledge proof (ZKP). In addition, we design a high speed polynomial multiplier to accelerate these primitives. These primitives will aid researchers and designers in constructing quantum-proof secure computing systems in the post-quantum era.

Open access
2 source records
cs.CR
Quantum Computing Algorithms and Architecture
Cryptographic Implementations and Security
Original source