Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

8,503 papersLast indexed Aug 31, 2026
Search papers

Paper index

8,503 results · page 259 of 355

Clear filters
Mar 26, 2018·IEEE Transactions on Services Computing
0 cites
Efficient and Adaptive Procurement Protocol with Purchasing Privacy

Peng Jiang, Fuchun Guo, Willy Susilo, Man Ho Au · 6 authors

A procurement protocol is a protocol for a buyer to purchase digital goods at their prices from a vendor. A procurement protocol with privacy preservation can be achieved by priced oblivious transfer (POT). POT allows the buyer to obliviously procure items one by one. An adaptive POT protocol only consumes O(1) communication cost in each transaction, where all items are committed and encrypted before transactions. However, we found that the state-of-the-art adaptive POT protocol proposed by Rial et al. is less practical and does not meet real-world needs. It has to restrict to the one-buyer setting where all items are encrypted associated with one buyer's public key. For multiple buyers, the vendor must respectively encrypt all the same items for each buyer. Besides, it has to employ computationally expensive primitives such as zero-knowledge proof which imply inefficient computation operations. It is therefore unscalable and unsuitable in large-scale applications. In this paper, we propose an efficient adaptive priced oblivious transfer protocol to address the aforementioned problems. The proposed adaptive POT is built on top of a new cryptographic primitive, namely, adaptive set membership encryption (ASME). In our proposed protocol, all items are encrypted without the use of buyers' public keys and hence they can be used for universal buyers. Our protocol significantly reduces the transaction cost compared to existing schemes. For example, the communication in each transaction costs only 6 group elements compared to at least 141 group elements in Rial et al.'s protocol. The implementation shows that our protocol is efficient in terms of bandwidth and computational cost.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Mar 5, 2018·Journal of the ACM
11 cites
Spatial Isolation Implies Zero Knowledge Even in a Quantum World

Alessandro Chiesa, Michael A. Forbes, Tom Gur, Nicholas Spooner

Zero knowledge plays a central role in cryptography and complexity. The seminal work of Ben-Or et al. (STOC 1988) shows that zero knowledge can be achieved unconditionally for any language in NEXP , as long as one is willing to make a suitable physical assumption : if the provers are spatially isolated, then they can be assumed to be playing independent strategies. Quantum mechanics, however, tells us that this assumption is unrealistic, because spatially-isolated provers could share a quantum entangled state and realize a non-local correlated strategy. The MIP * model captures this setting. In this work, we study the following question: Does spatial isolation still suffice to unconditionally achieve zero knowledge even in the presence of quantum entanglement? We answer this question in the affirmative: we prove that every language in NEXP has a 2-prover zero knowledge interactive proof that is sound against entangled provers; that is, NEXP ⊆ ZK-MIP * . Our proof consists of constructing a zero knowledge interactive probabilistically checkable proof with a strong algebraic structure, and then lifting it to the MIP * model. This lifting relies on a new framework that builds on recent advances in low-degree testing against entangled strategies, and clearly separates classical and quantum tools. Our main technical contribution is the development of new algebraic techniques for obtaining unconditional zero knowledge; this includes a zero knowledge variant of the celebrated sumcheck protocol, a key building block in many probabilistic proof systems. A core component of our sumcheck protocol is a new algebraic commitment scheme, whose analysis relies on algebraic complexity theory.

Open access
3 source records
Cryptography and Data Security
Complexity and Algorithms in Graphs
Blockchain Technology Applications and Security
Original source
Mar 1, 2018·Internal Medicine Journal
1 cites
P ‐value. What value?

J O'donnell

Although the problems identified in the statement have been known for several decades, previous expressions of concern and calls for action have not fostered broad improvements in practice.2 A P value of 0.05 carries a 5% risk of a false positive result (i.e. there is no true difference between treatments). If a trial is meant to provide proof of a genuine treatment difference beyond reasonable doubt, a much smaller P value – say p < 0. 001 – is required.5 We disagree ….that our statement… is erroneous. According to the null hypothesis, P < 0.05 will occur 5% of the time.6 No editorial corrigendum has appeared. A P-value is the area under the curve of a probability distribution defined by a mathematical model. The model, usually presented graphically, describes the expected distribution of a sample statistic around a central measure, the parameter or theoretical ‘true’ value, for example the population mean, μ. Under the central limit theorem, this would be the standard normal distribution of sample means generated by repeat sampling of a population variable of interest. The mean of the sample means would equal the ‘true’ population mean, μ. In medicine, it is rare for us ever to know the true value of the variable of interest. However, we can usefully assign a value in the special case of a difference statistic, for example the difference in mean outcome variables in a placebo-controlled drug trial. In this case, the sampling distribution would represent that of the difference statistic. In this case, if the value we assign μ is zero then the mathematical model becomes the null hypothesis used in NHST. By way of contrast, non-inferiority drug trials require a non-zero value to be assigned. The cumulative AUC of the sampling distribution of a continuous variable is represented by a mathematical function called the cumulative density function. In medical science, most study variables are continuous or, if categorical, are transformed using the logit model. As the P-value is a mathematical integral, that is the cumulative AUC, it cannot take on a precise value as there is no AUC defined by a single point on the curve, for example the P-value ≤ 0.05, but not P = 0.05. While this may seem pedantic, the semantics of statistical inference are influential in thinking and decision-making yet misinterpretation and misuse of terminology are commonplace. Under the null hypothesis, one sample mean that happens to fall within an extreme region of the standard normal distribution may be expected to occur with a low frequency, say P ≤ 0.05 meaning such a sample mean or one more extreme would be expected to occur with a frequency of 5% or less. To be valid, the assumptions of independence and random selection of each sample mean selected from the normal distribution of sample means must be assumed. Another way of stating this is as a conditional probability: . Note: | means ‘given’. It is important to understand that the P-value is a measure conditional on the assumption that the mathematical model describes the distribution of sample means and is not a measure of the probability of the ‘truth’ of the mathematical model. To make this claim would invert the conditional probability statement and commit an error of reasoning called transposing the conditional7 aka the prosecutor's fallacy: . In reasoning from NHST, the commonly used definition of the P-value as ‘a measure of evidence against the null hypothesis’ is potentially misleading in that it seems to legitimise transposing the conditional as if it were a mathematically valid function rather than a matter of intuition. It was the intuitive interpretation that Fisher used in his a posteriori model of NHST.8, 9 His aim was to use the P-value as an aid in deciding which experiments to repeat. If on several repetitions, a consistent extreme P-value for the sample statistic was obtained then that would accumulate evidence for a true experimental effect. If no such effect was present, regression to the mean parameter (μ) would be expected (P ≥ 0.05). In real-life scenarios, many factors inhibit repetition and replication of experiments; however, modelling can give us insight into the precision and reproducibility of extreme P-values10, 11 and hence the intuitive weight we place on the P-value ‘as a measure of evidence against the null hypothesis’. Table 2 is a reproduction.10 It describes the results of simulating repeat experimentation and the probability of producing a P-value ≤ 0.05 under the prescribed conditions of the simulated experiment. It may be surprising to many how poorly reproducible the P-value is as a bright line test (a bright line test is a clearly defined rule or standard, the purpose of which is to produce consistent and predictable results). For example, if in the first experiment P ≤ 0.05 was produced there would be a 50% probability of reproducing P ≤ 0.05 in a repeat experiment; if P ≤ 0.01was produced in the first experiment the probability of producing P ≤ 0.05 in a repeat experiment, would be 73%; and if P ≤ 0.001 was produced in the first experiment the probability of P ≤ 0.05 in a repeat experiment would be 91%. The magnitudes of a number of these first experiment P-values are those commonly used in pharmaceutical trials and other medical analyses. The P-value is also sensitive to sample size. Irrespective of the effect size, with increasing sample size (n) the P-value can be made as small as you wish12 because the standard error is proportional to the inverse of n. If statistical significance is substituted for ‘clinical significance’ even small irrelevant differences may be regarded as worthy of investment. Large sample sizes are often a feature of pharmaceutical trials of secondary and primary prevention interventions such as preventive therapies in atherosclerotic diseases and osteoporosis. The quoted extract from the article on clinical trials mistakenly promotes the P-value as a measure of error and further states that the error rate can legitimately be adjusted depending on the magnitude of the P-value thus providing ‘proof of a genuine treatment difference beyond reasonable doubt’. This erroneous interpretation has arisen from the illusion of coherence resulting from the conflation of the dominant models of hypothesis testing.8, 9 The setting of theoretical type 1 (α) and type 2 (β) error rates in the Neyman and Pearson model envisions the frequency of error ‘in the long run of experience’ (experimental repetition) given randomness and independence of sample means from two juxtaposed probability distributions. A priori two identical populations are imagined except that they differ in mean parameters, null μ0 and alternative μA. This model is valuable in providing a rationality to sample size selection. However, the conflation has resulted in confusion between Fisher's P-value and Neyman's α giving the P-value an apparent legitimacy as an a posteriori ‘sliding’ type 1 error rate. Even if this were logical, decreasing α would increase β, resulting in a decrease in power (1-β). Also the dichotomous approach of pitting null hypothesis against alternative hypothesis carries the risk of blinding the researcher or the consumer to other explanatory hypotheses. For those who think the use of confidence intervals (CI) overcomes the problems described, think again. Although it has greater intuitive value especially with respect to estimating effect size, the CI relies on the same premises as the P-value. For example the CI of juxtaposed probability distributions can be made as large or as small as can be paid for by increasing the sample size such that for any small difference the CI can be made not to overlap. Statistical analyses are very valuable tools for extracting information from data. However, the reliability of the knowledge generated is dependent on many more important factors inter alia, evidential justification of the experimental hypothesis, study design, study conduct and data collection and cleansing, competence in choice of statistical model, valid reasoning, reviewer bias, publication bias and replication. Much of the criticism of medical science centres on its overemphasis on the importance of the P-value, NHST and statistically defined effect sizes. A better understanding of how sound statistical inferences are made and how they influence decision making will be key elements to improving all aspects of healthcare. This is critically important in acknowledgement of individuals as complex adaptive systems with characteristics of emergence, adaptability, non-linearity and unpredictability13 rather than as static population averages. Surveys suggest statistical literacy amongst doctors is low.14, 15 Teaching and assessing knowledge and application of statistical inference, critical appraisal and decision-making skills should be a primary focus of medical schools and specialist colleges. Difficult concepts underpinning statistical inference may be more effectively and efficiently taught using computer simulation whereby the learner can manipulate effect sizes, sample sizes and other statistics in order to see how parameter estimates, P-values and CI change with reproduction and replication.16 This will foster a more in-depth understanding of the limits of statistical inference, making clinicians better able to choose wisely amongst the myriad of investigations and treatment options on offer. Subsequent to article submission and review the author attended the referenced ASA conference.2 A special issue of the ASA journal reporting the conference proceedings is planned for 2018. In the opening addresses, the 400 participants were encouraged to devote their energies to developing proposals and goals to address the long standing yet stubbornly persistent errors in statistical inference described in this article. While concrete proposals are yet to be endorsed by the ASA, many speakers emphasised the need to place greater emphasis on teaching the conceptual framework of the different philosophical approaches to science (mastering the concepts as a priority rather than the mechanics of statistical inference). The need for better understanding of statistical semantics on the part of non-statistician scientists was also highlighted. Further that the best way to achieve understanding would be to develop context-specific learning modules. An aspect of the conference that resonated with the author with respect to prediction in medical science was the idea that science defines degrees of uncertainty (not certainty) apropos caution must be applied to the use of prediction models in medical practice lest they be over-extended.

Open access
Statistical Methods in Clinical Trials
Meta-analysis and systematic reviews
Hemodynamic Monitoring and Therapy
Original source
Feb 23, 2018·IEEE Transactions on Information Theory
10 cites
Unlabeled Sensing With Random Linear Measurements

Jayakrishnan Unnikrishnan, Saeid Haghighatshoar, Martin Vetterli

We study the problem of solving a linear sensing system when the observations are unlabeled. Specifically we seek a solution to a linear system of equations y = Ax when the order of the observations in the vector y is unknown. Focusing on the setting in which A is a random matrix with i.i.d. entries, we show that if the sensing matrix A admits an oversampling ratio of 2 or higher, then, with probability 1, it is possible to recover x exactly without the knowledge of the order of the observations in y. Furthermore, if x is of dimension K, then any 2K entries of y are sufficient to recover x. This result implies the existence of deterministic unlabeled sensing matrices with an oversampling factor of 2 that admit perfect reconstruction. The result is universal in that conditioned on the realization of matrix A, recovery is guaranteed for all possible choices of x. While the proof is constructive, it uses a combinatorial algorithm which is not practical, leaving the question of complexity open. We also analyze a noisy version of the problem and show that local stability is guaranteed by the solution. In particular, for every x, the recovery error tends to zero as the signal-to-noise ratio tends to infinity. The question of universal stability is unclear. In addition, we obtain a converse of the result in the noiseless case: If the number of observations in y is less than 2K, then with probability 1, universal recovery fails, i.e., with probability 1, there exist distinct choices of x which lead to the same unordered list of observations in y. We also present extensions of the result of the noiseless case to special cases with non-i.i.d. entries in A, and to a different setting in which the labels of a portion of the observations y are known. In terms of applications, the unlabeled sensing problem is related to data association problems encountered in different domains including robotics where it is appears in a method called “simultaneous localization and mapping”, multi-target tracking applications, and in sampling signals in the presence of jitter.

Open access
Sparse and Compressive Sensing Techniques
Distributed Sensor Networks and Detection Algorithms
Microwave Imaging and Scattering Analysis
Original source
Feb 20, 2018·Proceedings on Privacy Enhancing Technologies
18 cites
Functional Credentials

Dominic Deuber, Matteo Maffei, Giulio Malavolta, Max Rabkin · 6 authors

Abstract A functional credential allows a user to anonymously prove possession of a set of attributes that fulfills a certain policy. The policies are arbitrary polynomially computable predicates that are evaluated over arbitrary attributes. The key feature of this primitive is the delegation of verification to third parties, called designated verifiers. The delegation protects the privacy of the policy : A designated verifier can verify that a user satisfies a certain policy without learning anything about the policy itself. We illustrate the usefulness of this property in different applications, including outsourced databases with access control. We present a new framework to construct functional credentials that does not require (non-interactive) zero-knowledge proofs. This is important in settings where the statements are complex and thus the resulting zero-knowledge proofs are not efficient. Our construction is based on any predicate encryption scheme and the security relies on standard assumptions. A complexity analysis and an experimental evaluation confirm the practicality of our approach.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Jan 26, 2018·arXiv (Cornell University)
6 cites
Oracle Separations for Quantum Statistical Zero-Knowledge

Sanketh Menda, John Watrous

This paper investigates the power of quantum statistical zero knowledge interactive proof systems in the relativized setting. We prove the existence of an oracle relative to which quantum statistical zero-knowledge does not contain UP intersect coUP, and we prove that quantum statistical zero knowledge does not contain UP relative to a random oracle with probability 1. Our proofs of these statements rely on a bound on output state discrimination for relativized quantum circuits based on the quantum adversary method of Ambainis, following a technique similar to one used by Ben-David and Kothari to prove limitations on a query complexity variant of quantum statistical zero-knowledge.

Open access
Cryptography and Data Security
Quantum Computing Algorithms and Architecture
Complexity and Algorithms in Graphs
Original source
Jan 25, 2018·D-Scholarship@Pitt (University of Pittsburgh)
0 cites
Model-based Decision Support for Sepsis Endotypes

Li Ang Zhang

Sepsis is a high mortality syndrome characterized by organ dysfunction due to a severe and dysregulated acute inflammatory response to infection. Research into therapies for this syndrome has historically ended in failure, which has largely been attributed to the elevated levels of subject heterogeneity. What may have been previously attributed to variability in sepsis may be due to mechanistic differences between patients. Endotypes are distinct subtypes of disease, where underlying causes such as mechanistic or pathway related differences manifest into phenotypes of disease. The lack of mechanistic understanding of immune mediator dynamics and the responses they trigger necessitates a mathematical modeling approach to analyze its complexities. A transfer function model is proposed to describe and cluster the dynamics of key inflammatory mediators. Five sepsis endotypes were discovered and revealed motifs of overwhelming inflammation, various levels of immunosuppression, sustained inflammation, and immunodeficiency. An accurate clinical tool was proposed to classify subjects into endotypes using six-hour trajectories of clinical data. A physiological ordinary differential equation model of sepsis is proposed that characterizes the interactions of inflammatory signaling molecules, neutrophils, and macrophages across the bone, blood, and tissue compartments of the body. This model used to generate individual subject fits against human sepsis data. Population-level parameter analysis implicated macrophage cell death and cytokine half- dynamics in endotype-level differences. Several proof-of-concept statistical models were introduced to demonstrate that it is possible to estimate the pre-hospital time of sepsis subjects and to quantify their sepsis-induced systemic tissue damage. A nearest-neighbor-based method was verified against animal and human data and revealed that identifying infection time-zero of sepsis patients can be quickly estimated with high accuracy using commonly measured clinical features. A logistic regression ensemble model demonstrated revealed early organ dysfunction were significant contributors to systemic damage and mortality. Knowledge of time-zero and systemic damage levels, in combination with an endotype classifier, provides clinicians with a clear depiction of where a subject is located on their sepsis trajectory. Such a decision support system enables therapy timing, early organ support, and targeted therapies to guide personalized treatment and shift patients towards better outcomes in sepsis.

Open access
Sepsis Diagnosis and Treatment
Original source
Jan 17, 2018·International Journal of Computer Applications
0 cites
Interactive Zero Knowledge Password Authentication Scheme for Commercial Web Sites

Mega Satish, Indranil Sengupta, K. Pratap

This paper presents the implementation of an interactive Zero Knowledge Password authentication scheme for commercial Web sites. In this scheme, a legitimate prover (client) can exchange a secret code (password) with a remote skeptic (server), in order to reveal his/her identification. Based on the validity of the secret code the skeptic then allows the prover to login to the site and access the web services. This paper introduces a protocol that integrates the concepts of Discrete Logarithm Problem (DLP) and Zero-Knowledge Proofs (ZKP). The protocol consists of three entities, namely, the prover, the skeptic, and the facilitator who interact with one another to generate the secret code. When tested, the time to carry out various operations related to this protocol was reasonably small (under 4 seconds). Our scheme is resistant to man-in-the-middle attack and discourages replaying previously intercepted secret codes. We also propose two modifications to our basic scheme to make it resistant against the attack on Integrity and Denial of Service attack (DOS).

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Spam and Phishing Detection
Original source
Jan 14, 2018·arXiv (Cornell University)
0 cites
Non-Locality in Interactive Proofs

Claude Crépeau, Nan Yang

In multi-prover interactive proofs (MIPs), the verifier is usually non-adaptive. This stems from an implicit problem which we call ``contamination'' by the verifier. We make explicit the verifier contamination problem, and identify a solution by constructing a generalization of the MIP model. This new model quantifies non-locality as a new dimension in the characterization of MIPs. A new property of zero-knowledge emerges naturally as a result by also quantifying the non-locality of the simulator.

Open access
Artificial Intelligence in Games
Original source
Jan 14, 2018·arXiv (Cornell University)
1 cites
New Perspectives on Zero-Knowledge Multi-Prover Interactive Proofs

Claude Crépeau, Nan Yang

In multi-prover interactive proofs (MIPs), the verifier can provide non-local resources for the provers intrinsically. In most cases, this is undesirable. Existing proofs of soundness do not account for the verifier's non-local potential. We show that this may be a problem for many MIPs. We provide a solution by constructing a generalization of the MIP model, of which standard MIPs are a special case. This new model accounts for both the prover and the verifier's non-local correlations. A new property of multi-prover zero-knowledge naturally emerges as a result.

Open access
Cryptography and Data Security
Logic, Reasoning, and Knowledge
Logic, programming, and type systems
Original source
Jan 8, 2018·International Journal of Computer Network and Information Security
18 cites
Using Homomorphic Cryptographic Solutions on E-voting Systems

Ahmed Aziz, Hasan N. Qunoo, Aiman A. Abu Samra

Homomorphic Cryptography raised as a new solution used in electronic voting systems. In this research, Fully Homomorphic encryption used to design and implement an e-voting system. The purpose of the study is to examine the applicability of Fully Homomorphic encryption in real systems and to evaluate the performance of fully homomorphic encryption in evoting systems. Most of homomorphic cryptography evoting systems based on additive or multiplicative homomorphic encryption. In this research, fully homomorphic encryption used to provide both operations additive and multiplication, which ease the demonstration of none interactive zero-knowledge proof NIZKP. The proposed e-voting system achieved most of the important security issues of the internet-voting systems such as eligibility, privacy, accuracy, verifiability, fairness, and others. One of the most important properties of the implemented internet voting system its applicability to work on cloud infrastructure, while preserving its security characteristics. The implementation is done using homomorphic encryption library HELib. Addition and multiplication properties of fully homomorphic encryption were used to verify the correctness of vote structure as a NIZKP, and for calculating the results of the voting process in an encrypted way. The results show that the implemented internet voting system is secure and applicable for a large number of voters up to 10 million voters.

Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Privacy, Security, and Data Protection
Original source
Jan 1, 2018·Lincoln (University of Nebraska)
0 cites
Theoretical and Experimental Gas Phase Nuclear Magnetic Resonance

Seth B. Blackwell

Gas phase nuclear magnetic resonance (NMR) spectroscopy is a powerful method, determining physical and chemical properties of molecules and giving insight into internal spin dynamics. Work has been done to significantly expand the known database of gas phase proton and carbon chemical shieldings obtained in the zero-pressure limit, which provide a comparison to computational NMR methods performed in vacuo. The combination of new knowledge of gas phase shieldings and high-resolution capabilities are demonstrated on analysis of natural gas and volatile fractions of crude oil, which gives new applications of gas phase NMR towards the petroleum industry. Furthermore, more insight has been obtained in regards to gas spin-relaxation, particularly in multiple-quantum relaxation through comprehensive pulse sequences to filter double- and zero-quantum coherences. Finally, results will be given of efforts in 13C hyperpolarization via the Haupt effect, as most notably observed in γ-picoline. New enhancements in γ-picoline were obtained through careful sample preparation and more understanding has been achieved though examining the time periods of liquid helium immersion required to generate the hyperpolarization. The hyperpolarization in γ-picoline served as a proof of concept for the application of this paradigm to smaller molecules. Results are given of matrix-isolation techniques in gas phase methyl-rotors with intention to create hyperpolarization through A/E state rotor imbalance of methyl groups at 4.2 Kelvin.

Atomic and Subatomic Physics Research
Advanced NMR Techniques and Applications
Quantum, superfluid, helium dynamics
Original source
Jan 1, 2018·Proceedings of the 5th ACM on ASIA Public-Key Cryptography Workshop
0 cites
Towards Ideal Self-bilinear Map

Takashi Yamakawa

Bilinear maps (also called pairings) have been used for constructing various kinds of cryptographic primitives including (but not limited to) short signatures, identity-based encryption, attribute-based encryption, and non-interactive zero-knowledge proof systems. In known instantiations of cryptographic bilinear maps based on eliptic curves, source and target groups are different groups, which may restrict applications of bilinear maps. Cheon and Lee studied self-bilinear maps, which are bilinear maps whose source and target groups are identical. They showed huge potential of self-bilinear maps by showing that self-bilinear maps can be transformed into multilinear maps, which give further more cryptographic applications including (but not limited to) multiparty non-interactive key exchange, broadcast encryption, attribute-based encryption, homomorphic signatures, and obfuscation. However, they also showed a strong negative result on the existence of cryptographic self-bilinear maps. Namely, they showed that if there exists an efficiently computable self-bilinear map on a known order group, then the computational Diffie-Hellman (CDH) assumption does not hold on the group. This means that cryptographically useful self-bilinear maps do not exist on groups of known order. On the other hand, there is no negative result for self-bilinear maps on groups of unknown order. Indeed, Yamakawa et al. gave a partial positive result for self-bilinear maps on unknown order groups. Namely, they constructed self-bilinear maps with auxiliary information, which is a weaker variant of self-bilinear maps based on indistinguishability obfuscation. Though they showed that they are sufficient for some applications of self-bilinear maps, they are not as useful as "ideal" self-bilinear maps, which do not need auxiliary information. In this talk, we first review the construction of self-bilinear maps with auxiliary information given by Yamakawa et al. Then we consider the possibility of constructing ideal self-bilinear maps.

2 source records
Cryptography and Data Security
Cryptography and Residue Arithmetic
Complexity and Algorithms in Graphs
Original source
Jan 1, 2018·Research Repository (Delft University of Technology)
0 cites
Consecutive Delegatable Signing Rights for the Issuance of Anonymous Attribute-Based Credentials

Victor C. Li

Digital identities and credentials are gradually replacing physical documents, as they can be verified with more accuracy and efficiency. Since online privacy is becoming more crucial than ever, it is essential to preserve the privacy of individuals whenever possible. Therefore, anonymous attestation of digital credentials should be feasible, where provers can selectively disclose attributes and create abstractions over attributes in their credential, in order to solely disclose the minimum amount of information required to complete the goal of verification.&lt;br/&gt;&lt;br/&gt;Many schemes in the field of attribute-based credentials consider a single root authority issuing credentials to provers. This is coherent to the traditional way of the issuance of credentials since the process of producing physical documents is costly to distribute to multiple issuers. Digital identities provide the opportunity for authorities to distribute credential issuance rights (consecutively) to smaller entrusted entities.&lt;br/&gt;&lt;br/&gt;To the best of our knowledge, we propose the first protocol which combines both anonymous attestation with attribute-based credentials and the delegation of selective signing rights for the issuance of these credentials. Root authorities could delegate signing rights for selective attributes consecutively to trustees, which are able to create anonymous attribute-based credentials with the acquired attributes for provers. Verifiers are able to verify presentation tokens with solely the public key of the root authority, without gaining knowledge about the identities of the prover and intermediate delegators. We introduce three adapted signature schemes based on existing work in order to realize a concrete instantiation of the protocol. Anonymity is achieved by incorporating Schnorr's zero-knowledge proof of knowledge with bilinear pairings to efficiently prove the correctness of presentation tokens.&lt;br/&gt;&lt;br/&gt;We realized a prototype of our concrete instantiation and optimized the verification algorithm in order to achieve optimal pairing performance. Complexity analysis of the protocol shows improvement in efficiency by aggregating attribute signatures throughout signing right delegation. Experimental results demonstrate a degree of practical feasibility for the verification of presentation tokens on commodity hardware within the challenging public transportation access control time bound of 300 ms.&lt;br/&gt;

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Jan 1, 2018·eScholarship (California Digital Library)
0 cites
How to Rewind with Minimal Interaction

Dakshita Khurana

The notion of simulation is central to cryptography: often, to demonstrate that an adversary did not recover any information about private inputs of other participants, we exhibit the existence of a simulator that generates the adversary's view without access to inputs of honest participants. The primary method used to build simulators is rewinding, where a simulator resets the adversary to a previous point in the protocol and tries to complete the protocol tree multiple times until it achieves a favorable outcome.First introduced in the context of zero-knowledge proof systems and secure computation, today the rewinding technique is synonymous with protocol security and polynomial simulation. Prior to this work, all known rewinding techniques in the plain model required multiple rounds of back-and-forth interaction between participants.In this thesis, we demonstrate the first rewinding techniques that require only a single message from each participant. Using these techniques, we overcome several barriers from literature to construct for the first time, based on standard sub-exponential cryptographic assumptions, the following core protocols, and several subsequent applications:- Two message commitments satisfying non-malleability (with respect to commitment).- Two-message delayed-input weak zero-knowledge arguments for NP. These imply arguments for NP satisfying witness hiding and strong witness indistinguishability.

Open access
Cryptography and Data Security
Cryptographic Implementations and Security
Security and Verification in Computing
Original source
Jan 1, 2018·TUScholarShare (Temple University)
1 cites
Asynchronous Optimized Schwarz Methods for Partial Differential Equations in Rectangular Domains

José C. Garay

Asynchronous iterative algorithms are parallel iterative algorithms in which communications and iterations are not synchronized among processors. Thus, as soon as a processing unit finishes its own calculations, it starts the next cycle with the latest data received during a previous cycle, without waiting for any other processing unit to complete its own calculation. These algorithms increase the number of updates in some processors (as compared to the synchronous case) but suppress most idle times. This usually results in a reduction of the (execution) time to achieve convergence. Optimized Schwarz methods (OSM) are domain decomposition methods in which the transmission conditions between subdomains contain operators of the form \linebreak $\partial/\partial \nu +\Lambda$, where $\partial/\partial \nu$ is the outward normal derivative and $\Lambda$ is an optimized local approximation of the global Steklov-Poincar\'e operator. There is more than one family of transmission conditions that can be used for a given partial differential equation (e.g., the $OO0$ and $OO2$ families), each of these families containing a particular approximation of the Steklov-Poincar\'e operator. These transmission conditions have some parameters that are tuned to obtain a fast convergence rate. Optimized Schwarz methods are fast in terms of iteration count and can be implemented asynchronously. In this thesis we analyze the convergence behavior of the synchronous and asynchronous implementation of OSM applied to solve partial differential equations with a shifted Laplacian operator in bounded rectangular domains. We analyze two cases. In the first case we have a shift that can be either positive, negative or zero, a one-way domain decomposition and transmission conditions of the $OO2$ family. In the second case we have Poisson's equation, a domain decomposition with cross-points and $OO0$ transmission conditions. In both cases we reformulate the equations defining the problem into a fixed point iteration that is suitable for our analysis, then derive convergence proofs and analyze how the convergence rate varies with the number of subdomains, the amount of overlap, and the values of the parameters introduced in the transmission conditions. Additionally, we find the optimal values of the parameters and present some numerical experiments for the second case illustrating our theoretical results. To our knowledge this is the first time that a convergence analysis of optimized Schwarz is presented for bounded subdomains with multiple subdomains and arbitrary overlap. The analysis presented in this thesis also applies to problems with more general domains which can be decomposed as a union of rectangles.

Open access
Advanced Numerical Methods in Computational Mathematics
Matrix Theory and Algorithms
Differential Equations and Numerical Methods
Original source
Jan 1, 2018·Electronic Theses of LMU Munich (Ludwig-Maximilians-Universität München)
3 cites
Effective evolution equations from quantum mechanics

Nikolai Leopold

The goal of this thesis is to provide a mathematical rigorous derivation of the Schrödinger-Klein-Gordon equations, the Maxwell-Schrödinger equations and the defocusing cubic nonlinear Schrödinger equation in two dimensions. We study the time evolution of the Nelson model (with ultraviolet cutoff) in a limit where the number N of charged particles gets large while the coupling of each particle to the radiation field is of order N^{−1/2}. At time zero it is assumed that almost all charges are in the same one-body state (a Bose-Einstein condensate) and that the radiation field is close to a coherent state. We show the persistence of condensation over time and prove that the time evolution is approximately described by the Schrödinger-Klein-Gordon system of equations in the large N limit. Subsequently, we consider the spinless Pauli-Fierz Hamiltonian which models the interaction between charged bosons and the quantized electromagnetic field. We discuss the limit previously described and prove that the time evolution is approximated by the Maxwell-Schrödinger equations. To our knowledge, this is the first rigorous result concerning a mean-field limit of the Pauli-Fierz Hamiltonian. We then turn to the evolution of Bose-Einstein condensates in two dimensions and consider N bosons which interact by a repulsive two-body potential. The interaction is given either by N^{−1+2β}V(N^{β}x) with β∈R^{+}_{0} or by e^{2N}V(e^{N}x), for some spherical symmetric, positive and compactly supported V∈L_{∞}(R^{2},R). We prove that the dynamics is approximated by the defocusing two-dimensional cubic nonlinear Schrödinger equation in the large N limit. In case of the exponential scaling, we show that a short-scale correlation structure affects the dynamics of the condensate. This is the first rigorous derivation that considers an exponential scaling of the interaction. All derivations rely on a method developed by Pickl in [Lett. Math. Phys. 97(2), 151–164 (2011)]. The first two results are obtained by an extension of the method to systems which interact with quantized radiation fields. The latter is derived by an appropriate adaption of the proof in three space dimensions [Rev. Math. Phys., 27, 1550005 (2015)]. The crucial insight to derive the Maxwell-Schrödinger equations is to restrict the class of many-body wave functions to a subspace of states whose energy per particle only fluctuates little around the energy functional of the Maxwell-Schrödinger system. To derive the two-dimensional Gross-Pitaevskii equation it is essential to define a measure of condensation which properly incorporates the correlations that arise from the exponential scaling of the interaction. This thesis is based on the preprints [54, 47].

Open access
Advanced Mathematical Physics Problems
Numerical methods for differential equations
Nonlinear Photonic Systems
Original source
Jan 1, 2018·KTH Publication Database DiVA (KTH Royal Institute of Technology)
4 cites
Analysis of sustainable building materials, their possibilities and challenges

Erik Arnesson

Sweden has as the first welfare state signed the petition of having net zero GHG emissions 2045. The construction industry is a large contributor to Sweden’s current GHG emissions and an action plan signed by several construction companies, including Veidekke, has stated several partial goals and one end goal of a construction industry with net zero emissions 2045. At the same time the demand of new residential houses is high. The choice of material affects the GHG emissions during the entire lifetime, making it a key parameter when planning a construction. 80 % of the emissions during a construction origin from the production of the materials used. The R&amp;amp;D intensity in the construction industry is low and the sector is ruled by a high level of competition and low margins. This thesis aimed to investigate more sustainable building materials for bearing parts of multifamily houses, how they compare with conventional materials and challenges facing them. The materials investigated was compared to a reference wall with KPI:s from one construction made by Veidekke. The GHG emission from the reference wall was calculated to be 107 kg CO2-eq/m2wall. The materials were evaluated with the method of Industrial Dynamics to investigate salient and reverse salient properties, lock-ins and important stakeholders. The materials investigated were Cross-laminated timber (CLT) and different types of sustainable concretes. Creating timber concrete hybrids were also explored. CLT currently has a small market share but is a promising material with several beneficial properties. The current development of more sustainable concrete resulted in the investigation of Recycled Aggregates Concrete, Alkali Activated Concrete and the Eco-concrete with reduced amount of cement in favor for limestone powder. A second step was to explore the social and economic challenges for integrating new building materials into the construction industry. As the industry is heavily project based, the timeframe and lack of budget to explore new options acts as barrier. The processes also tend to be repetitive. As of now the industry has made itself path dependent to concrete in a large extent. However, the social acceptance towards CLT is rising and making sustainability a strategic business goal is becoming more important to appeal to the customers. Interviews at Veidekke showed the rising interest of mixing timber and concrete, but also the difficulties of pushing development forward in the industry. The materials and their KPI:s resulted in the further investigation of CLT and Eco-concrete. By stating the salient and reverse salient properties of the materials further analysis could be done. CLT showed the greatest reduction of GHG emissions due to the embodied carbon resulting in a negative GHG emission of -66.2 kg CO2-eq/m2wall. In addition to this the construction time and several other beneficial properties were found. The reduction of GHG emissions of the Eco-concrete is great too, about 50 % comparing with the concrete used in the reference wall. As a concrete the Eco-concrete should also face less barriers as the industry is familiar with the product. Further analysis with tools from industrial dynamics showed the importance of creating incitements for developing the knowledge of a sustainable construction industry. Results also showed that new networks between the manufactures and the building sector is of essence to find and use new materials. Timber and concrete industries have the main responsibility of developing new and more sustainable products. The building sector also have a responsibility of choosing sustainable options. Advocating a diversity of solutions will create a more robust and resilient industry with fewer lock-ins and path dependencies occurring today. The key stakeholders identified from stakeholder mapping was the business developers, the department of purchase, the timber and concrete industry and lastly the customers. Business developers need to pursue projects with clear and tough goals of sustainability. This will increase the chance of succeeding. The department of purchase need to have incitements for mapping sustainable materials and the ability to explore new subcontractors. The results of the analysis show that not a single innovation will solve the goal of having a construction industry with net zero emissions 2045. The key innovation opportunities for CLT is to develop a standardization and modularization comparable with the concrete industry. Improving the fire safety of CLT is also of essence and the development of fire proofing plasterboards and insulation could be a solution. Further research on modified design mixing and the usage of pozzolanic materials like limestone in concrete is also an important way forward. Constructing timber concrete hybrids have also raised great potential both in the literature, analysis and from the interviews to simplify the integration of timber into the market.

Open access
Sustainable Building Design and Assessment
Original source
Jan 1, 2018·Advanced textbooks in control and signal processing
12 cites
Robust Adaptive Control

Nhan T. Nguyen

No abstract is available for this record.

Advanced Control Systems Optimization
Adaptive Control of Nonlinear Systems
Control Systems and Identification
Original source