Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

8,503 papersLast indexed Aug 31, 2026
Search papers

Paper index

8,503 results ¡ page 264 of 355

Clear filters
Oct 1, 2017¡Ad Hoc Networks
17 cites
BAN-GZKP: Optimal Zero Knowledge Proof based Scheme for Wireless Body Area Networks

Gewu Bu, Maria Potop-Butucaru

In this paper, we propose BAN-GZKP that optimizes the best to date secure lightweight and energy efficient authentication scheme, BANZKP, designed for WBAN networks. BANZKP is vulnerable to several security attacks such as the replay attack, DDoS attacks at sink and redundancy information crack. Also BANZKP needs an end-to-end authentication which is not compliant with the human body postural mobility. Our scheme, BAN-GZKP, improves both the security and postural mobility resilience of BANZKP. In order to fix the security vulnerabilities of BANZKP, BAN-GZKP uses a novel random key allocation. Moreover, BAN-GZKP uses a hop-by-hop authentication scheme which makes it tolerant to postural mobility. We further prove the reliability of our scheme to various attacks including those to which BANZKP is vulnerable. Furthermore, via extensive simulations we prove that our scheme, BAN-GZKP, outperforms BANZKP in terms of reliability to human body postural mobility for various network parameters (end-to-end delay, number of packets exchanged in the network, number of transmissions). We compared both schemes using representative convergecast strategies with various transmission rates and human postural mobility. When our BAN-GZKP scheme is used the percentage of packets received increases by 34.06%, the end-to-end-delay reduces by 36.02% and the number of transmissions reduces by 8.75% with respect to the case when BANZKP is used. Moreover, BAN-GZKP uses only a three-phase authentication which is optimal in the class of ZKP protocols. Finally, it is important to mention that BAN-GZKP has no additional cost in terms memory, computational complexity or energy consumption compared to BANZKP.

Open access
5 source records
Wireless Body Area Networks
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Sep 30, 2017¡International Journal for Research in Applied Science and Engineering Technology
0 cites
Authentication and Proofing Using Zero Knowledge Protocol

T. S Brinda

Wireless sensor network (WSN) have become a prominent solution for various interesting applications like security surveillance and monitoring of geographical areas. Various types of sensors are used and deployed in the network to collect useful physical parameters and some highly sensitive information is then been transmitted between the nodes and to the base station, without any human intervention. Hence, message authenticity and security are major requirements in WSN. Since the cryptographic schemes used for wired networks tend to exhaust wireless sensor network resources, they cannot be directly used in sensor networks. In this, the zero knowledge protocol (ZKP) is investigated that it is an under applied authentication mechanism used to identify compromised nodes from genuine ones. Here the Zero Knowledge Protocol (ZKP) is implemented in the network for the authentication and verification of sender sensor nodes before transmitting any sensitive information. The proposed scheme addresses the improvement in the security while maintaining the message confidentiality. In proposed scheme an optimal number of challenge questions are also used to maintain a balance between the added security and the increase in cost. Increase in the number of challenge question makes up to the reduced key size thus providing an improved security. The proposed scheme was assessed based on the mat lab simulation and an analysis was performed.

Open access
Algorithms and Data Compression
Original source
Sep 28, 2017¡Structural Health Monitoring 2017
0 cites
Sparsity-based Reconstruction Method for Simultaneous External Force Monitoring and Structural Damage Identification

Daniel Ginsberg, Claus‐Peter Fritzen

Load monitoring and damage identification are important tasks in the field of Structural Health Monitoring. Reconstructing unknown force inputs or system parameters usually involves the solution of an inverse problem which is mostly ill-posed. In the last decades a lot of effort has been spent in solving these problems separately. However, unknown loads and damage both have influence on the structural vibration pattern. The difficulty of simultaneous identification of external forces and structural damage is to distinguish these influences by using only the measured vibration effects. The use of prior knowledge of the unknown quantities is advisable for solving the combined inverse problem and to obtain meaningful solutions. In this contribution a sparsity-based reconstruction method in time domain is developed for identifying the unknown structural force excitation and damage parameter simultaneously by using output-only acceleration data. Sparsity means the majority of the solution vector is zero and only a very few elements are nonzero. Here damage is interpreted as additional load on the damaged structural element (virtual distortion). A numerical proof-of-concept experiment of a quadratic aluminum plate is presented. It shows that the proposed reconstruction method is able to identify the unknown external force and damage parameter by using a significant lower number of accelerometers than present methods.

Structural Health Monitoring Techniques
Ultrasonics and Acoustic Wave Propagation
Non-Destructive Testing Techniques
Original source
Sep 27, 2017¡Nature Communications
25 cites
Nuclear disarmament verification via resonant phenomena

Jake Hecla, Areg Danagoulian

Nuclear disarmament treaties are not sufficient in and of themselves to neutralize the existential threat of the nuclear weapons. Technologies are necessary for verifying the authenticity of the nuclear warheads undergoing dismantlement before counting them towards a treaty partner's obligation. This work presents a novel concept that leverages isotope-specific nuclear resonance phenomena to authenticate a warhead's fissile components by comparing them to a previously authenticated template. All information is encrypted in the physical domain in a manner that amounts to a physical zero-knowledge proof system. Using Monte Carlo simulations, the system is shown to reveal no isotopic or geometric information about the weapon, while readily detecting hoaxing attempts. This nuclear technique can dramatically increase the reach and trustworthiness of future nuclear disarmament treaties.

Open access
2 source records
Nuclear Physics and Applications
Radiation Detection and Scintillator Technologies
Ion-surface interactions and analysis
Original source
Sep 27, 2017¡arXiv (Cornell University)
2 cites
Quantum State Isomorphism

Joshua Lockhart, Carlos E. GonzĂĄlez-GuillĂŠn

We consider a problem we call StateIsomorphism: given two quantum states of n qubits, can one be obtained from the other by rearranging the qubit subsystems? Our main goal is to study the complexity of this problem, which is a natural quantum generalisation of the problem StringIsomorphism. We show that StateIsomorphism is at least as hard as GraphIsomorphism, and show that these problems have a similar structure by presenting evidence to suggest that StateIsomorphism is an intermediate problem for QCMA. In particular, we show that the complement of the problem, StateNonIsomorphism, has a two message quantum interactive proof system, and that this proof system can be made statistical zero-knowledge. We consider also StabilizerStateIsomorphism (SSI) and MixedStateIsomorphism (MSI), showing that the complement of SSI has a quantum interactive proof system that uses classical communication only, and that MSI is QSZK-hard.

Open access
Quantum Computing Algorithms and Architecture
Computability, Logic, AI Algorithms
Complexity and Algorithms in Graphs
Original source
Sep 19, 2017¡arXiv (Cornell University)
2 cites
An Optimality Proof for the PairDiff operator for Representing Relations between Words.

Huda Hakami, Kohei Hayashi, Danushka Bollegala

Representing the semantic relations that exist between two given words (or entities) is an important first step in a wide-range of NLP applications such as analogical reasoning, knowledge base completion and relational information retrieval. A simple, yet surprisingly accurate method for representing a relation between two words is to compute the vector offset (\PairDiff) between the corresponding word embeddings. Despite its empirical success, it remains unclear whether \PairDiff is the best operator for obtaining a relational representation from word embeddings. In this paper, we conduct a theoretical analysis of the \PairDiff operator. In particular, we show that for word embeddings where cross-dimensional correlations are zero, \PairDiff is the only bilinear operator that can minimise the $\ell_{2}$ loss between analogous word-pairs. We experimentally show that for word embedding created using a broad range of methods, the cross-dimensional correlations in word embeddings are approximately zero, demonstrating the general applicability of our theoretical result. Moreover, we empirically verify the implications of the proven theoretical result in a series of experiments where we repeatedly discover \PairDiff as the best bilinear operator for representing semantic relations between words in several benchmark datasets.

Open access
Topic Modeling
Natural Language Processing Techniques
Biomedical Text Mining and Ontologies
Original source
Sep 18, 2017¡IET Information Security
16 cites
Outsourcing secret sharing scheme based on homomorphism encryption

En Zhang, Jie Peng, Ming Li

Secret sharing is an important component of cryptography protocols and has a wide range of practical applications. However, the existing secret sharing schemes cannot apply to computationally weak devices and cannot efficiently guarantee fairness. In this study, a novel outsourcing secret sharing scheme is proposed. In the setting of outsourcing secret sharing, clients only need a small amount of decryption and verification operations, while the expensive reconstruction computation and verifiable computation can be outsourced to cloud service providers (CSP). The scheme does not require complex interactive argument or zero‐knowledge proof. The malicious behaviour of clients and CSP can be detected in time. Moreover, the CSP cannot get any useful information about the secret, and it is fair for every client to obtain the secret. At the end of this study, the authors prove the security of the proposed scheme and compare it with other secret sharing schemes.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Sep 1, 2017¡RFC Editor
60 cites
Schnorr Non-interactive Zero-Knowledge Proof

Authors unavailable

This document describes the Schnorr non-interactive zero-knowledge (NIZK) proof, a non-interactive variant of the three-pass Schnorr identification scheme. The Schnorr NIZK proof allows one to prove the knowledge of a discrete logarithm without leaking any information about its value. It can serve as a useful building block for many cryptographic protocols to ensure that participants follow the protocol specification honestly. This document specifies the Schnorr NIZK proof in both the finite field and the elliptic curve settings.

2 source records
Cryptography and Data Security
Cryptographic Implementations and Security
Cryptography and Residue Arithmetic
Original source
Aug 19, 2017¡IEEE Security & Privacy
8 cites
NIZKCTF: A Noninteractive Zero-Knowledge Capture-the-Flag Platform

Paulo Matias, Pedro Barbosa, Thiago N.C. Cardoso, Diego M. Campos ¡ 5 authors

Capture-the-flag (CTF) competitions are increasingly important for the Brazilian cybersecurity community as educational and professional tools. Unfortunately, CTF platforms may suffer from security issues, giving an unfair advantage to competitors. To mitigate this, we propose NIZKCTF, the first open-audit CTF platform based on noninteractive zero-knowledge proofs.

Open access
2 source records
Cryptography and Data Security
Web Application Security Vulnerabilities
Security and Verification in Computing
Original source
Aug 18, 2017¡Symmetry
323 cites
Blockchain Security in Cloud Computing: Use Cases, Challenges, and Solutions

Anand Kumar Mishra, Shrikant Tiwari, Kanchan Naithani, Amit Kumar Tyagi

Blockchain has drawn attention as the next-generation financial technology due to its security that suits the informatization era. In particular, it provides security through the authentication of peers that share virtual cash, encryption, and the generation of hash value. According to the global financial industry, the market for security-based blockchain technology is expected to grow to about USD 20 billion by 2020. In addition, blockchain can be applied beyond the Internet of Things (IoT) environment; its applications are expected to expand. Cloud computing has been dramatically adopted in all IT environments for its efficiency and availability. In this paper, we discuss the concept of blockchain technology and its hot research trends. In addition, we will study how to adapt blockchain security to cloud computing and its secure solutions in detail.

Open access
2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
Original source
Aug 10, 2017¡Journal of European Competition Law & Practice
21 cites
Economic Analysis in Damages Actions—Insights from Recent Proceedings in the UK

Peter Davis

Mobility Scooters highlights that collective actions must raise common issues, thus placing a focus on the variation in damages across claimants. The MasterCard consumer action highlights the challenge in taking a ‘top-down’ approach (estimating aggregate damages and only subsequently considering how to distribute that amount across individuals) and also the role of individual issues in collective actions. Retailers’ claims in MasterCard make clear the need for courts to pay careful attention to economic analysis, notably in the context of complex settings such as two-sided markets and in deriving counterfactual scenarios. The Consumer Rights Act 2015 (CRA) introduced a new collective action regime to the competition law landscape in the UK, including the ability to bring opt-out actions.1 The defining feature of a collective action is that the Competition Appeal Tribunal (CAT) can consider a collection of individual claims together rather than considering all aspects of every individual claim separately. The UK’s collective action regime aims to facilitate redress for claims that might not otherwise be brought, while avoiding aspects of the US class-action regime. The fact that it can accommodate both opt-in and opt-out claims means it represents a potentially dramatic change in the competition law landscape. Opt-out claims introduce new opportunities for redress for potential claimants and may markedly change the risks and exposure of defendants in cases taken in the UK. Moreover, other member states are likely to draw lessons from the experience and, while the European Commission recommended that member states have collective redress systems by 2015, its recommendation was that they should, as a general rule, be based on the ‘opt-in’ principle.2 The development of the UK’s new regime has therefore potentially very significant ramifications for the approach across Europe. Two cases have so far reached the stage where the CAT has been asked to certify whether the matter can proceed to trial on a collective basis, Mobility Scooters3 and the MasterCard4 consumer case. This article first reviews the core legal test described by the CAT for class certification and then considers the key economic issues at the heart of these cases. The cases relate to two very different types of infringement. Mobility Scooters was a claim following an OFT5 infringement decision that manufacturer Pride had entered into vertical arrangements with eight of its UK-wide online retailers which had as their object the prevention, restriction or distortion of competition in the market for mobility scooters by6 ‘prohibiting the advertising of below RRP prices online in respect of certain Pride mobility scooters between February 2010 and February 2012.’ In the MasterCard consumer case, the claim relates to a finding by the European Commission that the defendant acted unlawfully and in breach of Article 101 TFEU in establishing and implementing certain fees known as Multilateral Interchange Fees (MIFs), which retailers were required to pay on credit and debit card transactions. In addition to the consumer claim, the CAT considered whether an individual retailer suffered damages in Sainsbury’s v. MasterCard, and in the judgement by Justice Popplewell, the High Court addressed at least 12 other claims brought by retailers.7 The consumer claim argues that the MIF was passed on by businesses to all 46.2 million individuals who purchased goods and/or services from UK businesses that accepted MasterCard. To issue a Collective Proceedings Order (CPO),8 the CAT must be satisfied that there is some basis in fact9 which establishes that three individual certification requirements are met, namely:10 The claims must be brought on behalf of an identifiable class of persons The claims must raise ‘common issues’ The claims must be ‘suitable’ to be brought in collective proceedings The CAT describes the first requirement thus: (i) it must be possible to say for any particular person, using an objective definition of the class, whether that person falls within the class; and (ii) that the class should be defined as narrowly as possible without arbitrarily excluding some people entitled to claim.11 Common issues are defined as the same, similar or related issues of fact or law.12 In other words, claims can be efficiently collected together when the issues the court must decide are common to each of the claims. Although the claims must raise common issues, that does not require that all the significant issues in the claims should be common issues13 and the final resolution of the claims will often require the assessment of individual issues.14 It is notable that this aspect of the UK threshold for certification is potentially less restrictive to certification than the US class-action system where common issues must also predominate.15 The CAT Rules describe that assessing whether claims are ‘suitable’ to be brought in collective proceedings can depend on a wide range of factors.16 One aspect is whether the claims are suitable for an aggregate award of damages,17 including whether such an award can be distributed between members of definable subclasses.18 Using language familiar to US class certification discussions,19 the CAT has described that its approach to certification ‘should be rigorous.’20 In practice, the question is how much rigorous analysis can really be undertaken at the CPO stage when ‘[t]he approach under the UK regime of collective proceedings is intended to be very different [from the US], with either no or only very limited disclosure and shorter hearings held within months of the claim form being served.’21 There will clearly be tensions between the desire for a rigorous analysis at the CPO stage and the desire to limit pre-CPO disclosure. More generally, the UK courts have accepted that the quantification of an overcharge always involves estimation,22 and that difficulties in quantifying compensation are to be dealt with ‘by the exercise of a sound imagination and the practice of the broad axe.’23 That said, as Mr Alan Bates vividly described during the Mobility Scooters case, ‘a broad axe is very different from a sort of crazed axeman swinging out all over the place because you do not have the…proper parameters for the exercise.’24 Moreover, Justice Popplewell (while replacing a broad axe with a broad brush) drew an explicit link between the quality of evidence and the appropriate size of a damages award:25 ‘[W]here the court is compelled to use a broad brush in the absence of precision in the evidence of the harm suffered by a claimant, it should err on the side of under-compensation so as (a) to reflect the uncertainty in the actual loss suffered and (b) to give the defendant the benefit of any doubts in the calculation.’ In Mobility Scooters the consumer claim followed an OFT decision that certain vertical agreements infringed Chapter 1 of the Competition Act (1998) since they involved a prohibition on ‘below RRP advertising of online prices’ (BROPA). Claimants argued26 they were harmed by the infringing agreements because price competition was less intense since retailers did not advertise the lower prices they might have absent the infringement, and that retailers either advertised higher prices or they advertised no prices and directed online purchasers towards telephone sales channels—advising them to ‘call for better prices.’ The claimants proposed estimating the overcharge by calculating a weighted average price during the infringement period (February 2010–February 2012) and comparing it to a calculated weighted average price from the post-infringement period (March 2012–December 2014). Claimants argued that prices in physical stores fell on average after the infringement period by 16.2 per cent and attributed that fall to the removal of the infringement. They further asserted that the differential between the two distribution channels (physical stores and online) was the same during and after the infringements so that the overcharge to online customers could also be estimated (see Fig. 1). The competitive benchmark in Mobility Scooters.Note: Author's estimates based on information available in the Mobility Scooters judgement. However, the CAT judgement in Mobility Scooters makes clear that evidence of declining prices alone is insufficient. Instead, the claimant must establish that there is a basis for demonstrating that an observed fall in prices is attributable to the end of the infringements and not to other factors, that is, provide evidence of causality.27 The CAT considered whether any overcharge in Mobility Scooters was a common issue among purchasers. The defendant argued that (i) the loss suffered by each customer would depend on that individual’s purchasing and search behaviour and so the damage caused would not be common; and (ii) that any methodology which allowed damages to be estimated on a common basis would require knowledge of whether a given individual did search the market and/or would have searched the market in the counterfactual. The claimant accepted there was marked price variation across individuals since prices were individually negotiated, but argued that overcharge was nonetheless a common issue. The claimant asserted the extra amount customers paid as a result of the infringing agreements was sufficiently similar to mean overcharge was a common issue, whether or not a given individual paid, say, £1,000 or £750 for the scooter.28 The most significant element of the quantification argumentation during the CPO application in Mobility Scooters related to quantity not price. The relevant quantity depended on whether any overcharge resulting from the conduct was market-wide, or whether it was limited to at most the customers of the eight retailers with whom infringing agreements were signed.29 The claimants submitted that the BROPA prohibition made it harder for consumers to shop around for the best price, and that the infringing agreements meant the competitive pressure on other retailers was absent while the eight retailers (with collective market share of around 15 per cent of sales) were not insignificant.30 the sales an overcharge was thus a issue for This issue also a role in the CPO application since the CAT was required to the relevant claimant in the CPO and subsequently would be required to award any aggregate damages for each The to of customers by (i) sales online per cent of sales) physical stores per cent of and (ii) whether or not customers purchased a that was by an infringing The CAT did these alone could an aggregate damages award since it and is within them sufficiently The CAT was that a different of damage may be to who purchased from the eight retailers and sales from other The application for a CPO was thus with the that a CPO application could be made by the claimants. the claimants their application for a The CAT its judgement for the CPO application in the MasterCard consumer claim in considering the consumer claim for it is to first consider the related claims by retailers MasterCard. This first considers the economic issues in these cases to the particular for economic analysis in the MasterCard consumer damages were for the breach of Chapter 1 of and/or Article 101 TFEU by of the at which the UK Multilateral Interchange or was for MasterCard The CAT and Sainsbury’s million in damages The in below how in card the MIF is per cent and the is per the an for the will and the and the in a card card MasterCard the UK the CAT that to the of than to the of and that would a higher UK MIF have no to in in the can from any such and to the In the would no have a UK MIF and Interchange Fees would have to be between and UK MIF means would have a than in the However, in other the analysis of is In the analysis that (i) have they do not have to issue MasterCard to their have the to between MasterCard, and and (ii) have their must all rather than the sales for no This in should the resulting counterfactual price. It is that the CAT a benchmark from a of in to the on the other that a an would in price in to its only when the other side of the the had all of the In there is marked between the of the analysis of and its to an as the benchmark for counterfactual competitive prices absent the of 12 further claims MasterCard were brought Justice Popplewell in the High Justice Popplewell that the that the counterfactual was not Instead, the there were two potentially relevant the MIF (i) being to or (ii) being to the MIF less than actual MIF and to the court is under Article Justice Popplewell considered whether MIF should be held at its actual in the counterfactual. That might not be the case, for it were on the basis of the infringement decision MasterCard that actual were also that the claimants would need to establish that and were In MIF was then its actual should form of the counterfactual since for the counterfactual is the and the court conduct as and it is to be Justice Popplewell thus that there would be a differential between and MasterCard in the counterfactual. Moreover, counterfactual MIF were while MIF at its actual would have both the ability and to their of from towards and so card would competition from would the It was then a to with MasterCard that its MIF was since it was to the of the MasterCard as a The question of whether prices should be in the counterfactual is a general to consider that the prices by may be it will not always make to price counterfactual and when finding that price would lower in the counterfactual than it was in the The challenge is to how prices would have in a new counterfactual this case, a new in a two-sided market The economic of card prices is best considered within the of two-sided In two-sided the there are on the the is to the other Justice of the economic on two-sided markets is both and In two-sided competitive prices reflect the between they do not reflect the or from side of the competition between can to or no for and fees for This feature was by Justice Popplewell, who described with the benchmark in based approach is not in any of the as any sound and 2015 describe it as by any and as with the whether the judgement the analysis of the of two-sided markets into a the judgement argues that to so competition between card systems to higher that must to and would thus need to The challenge in a competition under Article 101 is to decide the of MIF in of the under and also Justice Popplewell a benchmark price and to it using the best available The analysis that both and of MIF were higher than actual MIF and Justice Popplewell that there was therefore no In the CAT described that the is in not a at the need to that a claimant is sufficiently and not by a the key question relates to the of the actual of the damages suffered by the In the actual of the damages in the CAT consider that the legal definition of a from that of the in two an might to and the is only with identifiable in prices by a to its customers the in price must be with the and The CAT to the tensions between the legal and economic of In the that (i) the or can relate only to identifiable price by a to its and (ii) the price should be each to in for the the definition of with that approach since is defined to which a given change in a given change in is defined The shop was considered by the CAT to whether there were between legal and economic The CAT that a shop at price them to at price and that there was a which the price of say, per of on the higher price to the in the form of the shop to its its The CAT the question of whether the are considered by an since they would not to its definition of In respect of this whether an it or this conduct to the harm suffered from the shop In the shop actions to damage to the damages suffered from the the damage to the actions damage the customers quality of being and there is an potential claimant the conduct the of the CAT a on such in and it would no be to establish in practice, the to to be potentially of such an the of in fact the actual of damage In the CAT the of in to on the its approach to as by a of under-compensation to it considers at least as as the of In the CAT only to on the of the defendant has that there class of claimant, of the in the to whom the overcharge has been passed the defendant that the is on the the of such a class, consider that a of the overcharge by it should not be or on this that under a of definition of which allowed for or this approach would need to be but only to the that the defendant would need to that there other of claimant, and of the in the to whom damage was the the would on the defendant to to the court that the to but not means the damage award should be The CAT and evidence on whether would have in to an overcharge on It that MasterCard had to its of in to the the range of by and the of by Sainsbury’s in it would be to say of the price of any given was attributable to the UK in its the CAT also that there was in respect of In following the claimant should be allowed to actual including a loss of the claim is and The CAT the UK MIF was a common to Sainsbury’s and its consider that a amount of the UK MIF would have been not in a which would have to a of the CAT that Sainsbury’s per cent of the overcharge and so it suffered damage from lower in the and than it would have had absent the infringement. In it on damages based on the of Sainsbury’s that Sainsbury’s did not raise any during the claim and that it was appropriate to award on per cent of Sainsbury’s damages the that were not passed The approach in these two aspects to but the in by defendant and The by Justice Popplewell and the CAT in Sainsbury’s provide context for the decision on whether the requirements for class certification were in the MasterCard consumer In the CAT had to decide whether all of the 46.2 million individual claims ‘common issues’ and were ‘suitable’ to be brought in collective the of the consumer claim, the a methodology which to at a of the aggregate damages award calculated The then proposed a for the aggregate damages across individuals in the aspect of the proposed methodology is in The submitted that the aggregate damages could be calculated by a methodology which involved (i) the of (ii) the and or In of the the proposed using to the of made by consumers using MasterCard credit and debit to businesses in the UK each during the claims the and the across each of of and debit and and the CAT it would be to for each of and the in to Popplewell, in the MasterCard consumer claim the overcharge was to be the between the MasterCard UK MIF and the counterfactual that would have been had there been no infringement, either no MIF at all or a lower of MIF which for under Article The of the relevant counterfactual the CAT be a significant issue in the the application were to In each the economic followed the approach accepted and by the CAT in Sainsbury’s by calculating a weighted average MIF and counterfactual in to the overcharge for each of the of the claim and for each of the of in the There was no that passed on the MIF to in the form of a the question was how much of the was passed on to individual customers The argued that as a matter it was appropriate to a but not over weighted average across the UK That said, the accepted under that will be by such as of and and of regime. The further accepted within broad there was a wide of businesses which may have different of so that for may not be the same as for and that some of the may also across the UK. a weighted average for the of the UK would clearly be the it should be possible on the basis of (a) information from the retailer claims actions (b) disclosure from and available The CAT it (a) the difficulties of from evidence on cases claims made by (b) the and that would disclosure from and the difficulties of and a weighted average were calculated based on the limited amount of available In the CAT that the proposed across the UK over a period of would be a complex exercise to a wide range of It also that a would have had to be made to whether such a is by are the test from the CAT was on the basis of the in of it that there were available for the proposed methodology to be on a sufficiently sound basis, so it was not satisfied that the claims were suitable for an aggregate award of 1 describes aspects of the application which the CAT described would be relevant for an individual claim and, in whether each issue is common across individual claimants. The CAT that the did raise common issues, but that it also issues which were individual in Common and individual issues in the MasterCard consumer claim between different of goods and services between different of in the of sales made by that paid for by card to since the lower the actual overcharge which it has to over the prices of its goods or services between different of goods and services between different of in the of sales made by that paid for by card to since the lower the actual overcharge which it has to over the prices of its goods or services Common and individual issues in the MasterCard consumer claim between different of goods and services between different of in the of sales made by that paid for by card to since the lower the actual overcharge which it has to over the prices of its goods or services between different of goods and services between different of in the of sales made by that paid for by card to since the lower the actual overcharge which it has to over the prices of its goods or services The methodology is not from the of individual claimants but rather is to be ‘top-down’ to the issues by to to of a for all claims. The CAT that this of approach can be but only there is a and means of to the of individual aggregate damage award would need to be distributed across The proposed calculating the aggregate loss on an basis for each of the in the claims period and it on an per basis among all the class members for that of who were in the UK and over the of in that However, when the were asked this by the they that the proposed no to the individual They for that individual would depend on much a given individual on as as across a range of other and so The CAT considered how a loss would be estimated in an individual action for It that since no individual can be to or the of would be on the basis of an assessment of and then a broad of how that was between and and between of It on to say in the is that there is no of a very of the loss suffered by each individual claimant from the aggregate loss calculated to the proposed The CAT that the of the individual issues of the from whom they and the of which they made it to how the to individuals could be on any The application for a CPO was the UK courts have considered the first two collective Mobility Scooters and the MasterCard consumer claim, as as significant related actions for The courts have been asked to consider such as overcharge and in agreements in Mobility Scooters and a two-sided market in MasterCard. In at the CPO application these collective actions have a focus on the and of the variation in damage across claimants. the CAT has the CPO in both of these first two opt-out it does not mean that other cases will not the CAT will need to to consider how a it should place on the claimant a CPO when such must be made on the basis of limited disclosure.

Open access
Insurance and Financial Risk Management
Original source
Aug 5, 2017¡Zenodo (CERN European Organization for Nuclear Research)
0 cites
Generalized Π-Armendariz Authentication Cryptosystem

Areej M. Abduldaim, Nadia M. G. Al-Saidi

Algebra is one of the important fields of mathematics. It concerns with the study and manipulation of mathematical symbols. It also concerns with the study of abstractions such as groups, rings, and fields. Due to the development of these abstractions, it is extended to consider other structures, such as vectors, matrices, and polynomials, which are non-numerical objects. Computer algebra is the implementation of algebraic methods as algorithms and computer programs. Recently, many algebraic cryptosystem protocols are based on non-commutative algebraic structures, such as authentication, key exchange, and encryption-decryption processes are adopted. Cryptography is the science that aimed at sending the information through public channels in such a way that only an authorized recipient can read it. Ring theory is the most attractive category of algebra in the area of cryptography. In this paper, we employ the algebraic structure called skew -Armendariz rings to design a neoteric algorithm for zero knowledge proof. The proposed protocol is established and illustrated through numerical example, and its soundness and completeness are proved.

Open access
Cryptographic Implementations and Security
Coding theory and cryptography
Chaos-based Image/Signal Encryption
Original source
Aug 1, 2017¡Neurosurgery
7 cites
Strategies for Autonomous Sensor–Brain Interfaces for Closed-Loop Sensory Reanimation of Paralyzed Limbs

Timothy H. Lucas, Xilin Liu, Milin Zhang, Sri Sritharan ¡ 10 authors

BCI: brain–computer interface DCN: dorsal column nuclei ICMS: intracortical microstimulation LED: light-emitting diode PDMS: polydimethylsiloxane RF: radiofrequency The dexterous hand is a defining feature of human existence. Evolved over tens of millions of years, modern humans are able to perform remarkable tasks with their hands. From typing hundreds of words per minute to playing Rachmaninoff's Piano Concerto No. 2, the dexterous hand defines us. Unfortunately, a number of maladies rob us of this defining human characteristic. In the most extreme case, paralyzed individuals lose communication between the brain and the periphery. This condition affects an estimated 5.4 million people, or 2% of the US population.1 At present, no effective treatment restores function to these individuals. Regaining hand function is a principal concern for paralyzed patients. Toward this aim, significant advances in motor—or efferent—brain–computer interface (BCI) systems have occurred in recent years. Efferent BCI systems extract movement-relevant information from electrocorticography (ECoG) or electroencephalography (EEG). These analogue signals are transformed into control commands to drive robotic arms2 or evoke muscle contractions in paralyzed limbs.3-8 In the later example, compound wrist flexion may be evoked by brain-controlled functional electrical stimulation of forearm flexors. Planned clinical trials aim to capitalize upon these scientific advances to test efferent BCI across a range of conditions and control routines. While these proof-of-principal systems are encouraging, a number of substantial hurdles remain. Perhaps the most pressing barrier to restoring dexterous hand movements is the lack of systems to restore somatosensory feedback. Even in the presence of intact descending motor systems, precise hand movements are abolished when somatosensation is missing.9-16 Indeed, the majority of efferent BCI systems currently in testing rely solely upon visual guidance. This constraint is unnatural and unlikely to be useful if deployed clinically. Visual guidance requires constant vigilance and introduces substantial time-lags to error correct each movement. To restore naturalistic movements, bi-directional BCI systems that link movements and real-time sensory feedback must be developed. The feedback loop of bi-directional BCI is closed with sensory feedback. Unfortunately, the field of sensory—or afferent—brain–computer interface has not kept pace with the maturation of efferent systems. This is due, in part, to the challenges concerning sensory research in animals. Sensory perception is a uniquely subjective experience that does not lend itself readily to the quantitative metrics. For decades, experimentalists have attempted to characterize the perceptual experiences associated with stimulation of the sensory cortices, including primary somatosensory cortex (S1), secondary somatosensory cortex (S2), and parietal association areas in animal models. From this body of literature, we know that intracortical microstimulation (ICMS) of S1 yields sufficient percepts to permit limited binary decisions, such as differentiating between 2 stimulation frequencies or amplitudes.17-21 Despite exhaustive investigation, no study has convincingly reproduced the complex sensory phenomena that are fundamental to our routine encounters with the physical world. Compounding the problem, very limited human data are available to assess the efficacy of S1 stimulation. Animal studies do not answer the question of how stimulation feels. To answer these qualitative questions, we need human data. Most human data have been obtained during brief testing sessions in awake craniotomies or during stimulation in patients with implanted ECoG electrodes.22-24 Invariably, these patients reported that S1 stimulation yielded only vague ‘tingling’ sensations with modest regional localization. Flesher and colleagues recently reported the first human data using ICMS encoding in S1 with chronic penetrating arrays.25 In this experiment, a 28-yr-old male with a spinal cord injury underwent implantation of 2 32-channel multi-electrode arrays into primary somatosensory cortex (S1). Over the course of several months, the investigators mapped perceptual responses to ICMS up to 100 μA. The majority of responses (93%) were categorized as ‘possibly natural,’ ‘pressure’ sensations. The perceptual intensity was modulated by stimulation amplitude with increased pressure corresponding to increase stimulus amplitude. This finding mirrors that of ICMS in primary visual cortex where phosphine brightness is modulated by stimulus amplitude.26 These data constitute a substantial step toward clinical sensory BCI. However, there were a number of findings that tempered enthusiasm for immediately clinical implementation. For instance, none of the S1 electrodes activated sensory representations of the distal fingers where feedback is most needed. Instead, the majority of responses were localized to the palmar crease region of the hand proximal to the fingers. Also, the detection thresholds of a many electrode sites rose significantly over the short course of the study, raising the concern that the effect of S1 encoding will fade over time. Finally, few of the stimuli evoked properly ‘naturalistic’ percepts. These limitations and the disappointing results from similar work in visual cortex raise the question of whether cortical ICMS encoding is the optimal solution for sensory restoration. These unanswered questions motivate our research program. Our work aims to bridge the divide between current state-of-the-art and the clinical needs of our patients. Our overarching strategy is to develop closed-loop, autonomous bidirectional brain–machine interface systems. These systems, as conceived, provide real-time communication between the brain and body. Because the field of efferent BCI has vastly outpaced that of afferent BCI, our work primarily focuses on developing sensory-brain interfaces to couple with existing BCIs (see Bouton et al27 for example). Our strategy focuses on 3 critical intersections of engineering and neuroscience. The first is development of a suite of sensors that serve as mechanoreceptors for the paralyzed, insensate hand. The second is development of a chronic neural interface for artificial sensory encoding. The third is a body area network that links peripheral sensors with novel neural interfaces. The integration of these components is illustrated in Figure 1.FIGURE 1: Body area network. Fully integrated system with implantable force and flex sensors (1, 2), wearable analyzer (3), electrogoniometer (4), and neural interface (5).In this brief overview, we outline our approach, preliminary data, and future directions. This work collectively represents a fruitful collaboration between neurosurgery and electrical engineering. We are grateful to the National Science Foundation for funding our work. RESEARCH APPROACH Our research strategy follows 3 central aims: development of novel sensors, characterization of novel neural interfaces, and development of an autonomous body-area network. Novel Sensors Hand somatosensation can be characterized by a multidimensional space with axes defined by sensory modality (eg, light touch, proprioception), somatotopy, temporal dynamics, the influence of descending central inputs, and brain state. Restoring native somatosensation is perhaps too lofty a goal for a first-generation sensor–brain interface. Instead, we reduce the dimensionality of the problem to a single sensory modality at a single somatotopic location. We have developed a number of force sensors and a proprioceptive sensor as our first aim. The design of our force sensors is constrained by the form and function of the human hand. Relevant design features include: sensor sensitivity, range, power, form-factor, and complexity. Sensitivity is defined as a sensor's accuracy to convert mechanical force into voltage changes on the sensor. Dynamic range captures the extremes of mechanical force spanning interactions between the hand and the physical environment. The feature of power concerns both the requirements of the sensor (active or passive) as well as the sensor's efficiency to convert physical energy into electrical energy. For wireless sensors, the power feature also includes power harvesting and wireless transmission of data. Form-factor is defined as the mechanical properties of the sensor (size, shape) as well as the flexibility and elasticity of the substrate. Finally, the complexity of the sensor constrains fabrication and durability. These competing design constraints inevitably require engineering trade-offs. In the interest of brevity, we focus on 2 prototype force sensors and a proprioceptive sensor to illustrate these engineering trade-offs in the context of sensor–brain interface. First we consider scattering force sensors and optical force sensors before moving toward proprioceptive electrogoniometers. Scattering force sensors operate under the principle of radiofrequency (RF) back scatter. RF identification is a common technique used to track tags, like those attached to garments at a department store to prevent theft or those implanted subdermally in house pets to identify them when they are lost. The central concept is that RF energy polarizes conductive elements, such as the linear segments of an antenna, and scatter energy back in a measurable way. Deformations of the segment length or shape cause a shift in the back-scatter pattern as the polarization of each segment is related to its orientation in a pulsed electromagnetic field. By calibrating the back-scatter patterns induced by force-induced deformations of RF antenna segments, one may indirectly measure forces applied to a flexible antenna implanted under the skin. In the first series of experiments, our group characterized the back-scatter signatures of a number of antenna designs serving as passive sensor nodes. An advantage of passive sensors is that they do not require active power supplies. Therefore, flexible antennas can be implanted under the skin without the need of wires or batteries. Initial antennas were made with copper tape for rapid prototyping. Antenna shapes were constructed into space filling curves (eg, Hilbert, Peano curves) that varied in the number and length of conductive segments (Figure 2). Changes in size and shape of copper RF antennas were associated with reproducible batter scatter properties.FIGURE 2: Passive scattering force sensor design. A, Antenna shapes with different linear segments in second order Hilbert and Peano curves. B and C, Polarization of antenna segments within electromagnetic field. D, Radiofrequency response curves as a function of area of RF tag (left), and shifts in curves with ±2% change in area (right). E, Prototype indium–gallium tags in PDMS substrate. Central reservoir visible in series with antenna segments. F, RF tuning curve of indium–gallium tags in response to forces applied to central reservoir. Rapid shift noted in low end of force axes indicates appropriate sensitivity for precise finger grip.To build force sensitivity, our second series of experiments examined the flexibility of antennas across a range of forces routinely encountered by the human hand. Liquid metal indium–gallium antennas were designed within a flexible, skin-like polydimethylsiloxane (PDMS) substrate. Indium–gallium is a highly conductive eutectic alloy whose melting point is sufficiently low (∼ –2°F) to allow the alloy to remain in liquid phase at room temperature. Channels were laser-etched into the PDMS in the shape of space filling curves to house the alloy (Figure 2). Force sensitivity was amplified by creating a central compressible metal reservoir in series with the channels. When force was applied, the liquid metal filled the channel segments proportionally. As each successful segment of the antenna was filled with conductive metal, the RF back-scatter properties shifted (Figure 2). As can be seen in the RF response curve, the antenna was sufficiently sensitive to capture force changes within 5 N of fingertip pressure, appropriate for precision grip activities. These experiments verified the feasibility of force sensing RF tags. However, limitations to this technique include the need for sensitive detecting antennas to measure back scatter. For this reason, we examined force sensor designs that were independent of RF signal. Optical force sensing is a method to detect fingertip pressure without electromagnetic interference. An optical force sensor layers PDMS membrane on SiO2 within an implantable chip (Figure 3) that could be implanted subdermally. At one end of the floor of the sensor, an internal 80 μm2 light-emitting diode (LED) emits light. The light is reflected by the internal ceiling of the chip that is constructed of PDMS in an inverse lenticular structure. Reflected light is detected by a photodiode at the opposite end of the sensor. The intervening SiO2 acts as an optical waveguide. In the absence of force (or compressing pressure), the waveguide allows reflected light to excite the photodiode with an efficient electric-to-optical conversion, a high sensitivity (0.02 kPa−1) and a pressure sensing resolution (38 mPa). When force is applied, the PDMS ceiling bows downward, opening light channels in the membrane. This allows light to escape, which in turn decreases the voltage at the photodiode monotonically, and yields a scaled readout.FIGURE 3: Optical force sensor design. A, Side view of optical sensor in absence of load. Directional path of light shown in yellow reflected from internal surface of PDMS ceiling. LED emitter located in lower left of sensor; photodiode (PD) located in lower right. B, Applied forces reduce light received by photodiode end. C, Diagram of optical force sensor circuit. D, Idealized relationship between applied force and photodiode voltageBoth scatter sensors and optical sensors achieved their desired engineering goals of converting force into measurable data. Neither system represented optimal solutions. In the case of scatter sensors, environmental noise may obscure the back-scatter energy detected by a horn antenna. In the case of optical sensors, an active circuit is required. On-going experiments aim to address these limitations by increasing the signal-to-noise ratio (RF sensors) and integrating rechargeable power (optical sensors). Beyond touch sensation, proprioception is a fundamental sensory modality that informs us about limb position. To restore proprioception across large joints, we developed a wireless electrogoniometer.28 Unlike other electrogoniometers that require strain gauges or power-hungry potentiometers, our system was designed to have very low power requirements (∼20 μW) both in terms of sensing and wireless data transmission. This was achieved using a pair of impulse-radio ultrawide band wireless smart sensor nodes interfacing with low-power 3-axis accelerometers through event-driven analog-to-digital converters. Electrogoniometers are designed to operate across large joints, such as the elbow, which are too large for strain sensors or other position sensors. On-going experiments aim to combine multiple sensor modalities in the same organism. Novel Central Nervous System Targets Our second aim is to identify optimal sensory encoding nodes along the neuraxis. Cortical encoding has been attempted for decades in animals, and recently in humans, with mixed results. It remains to be seen how well S1 ICMS will faithfully reproduce naturalistic perception. ICMS in other sensory areas, like primary visual cortex, generates phosphenes but not complex visual images.26 This may be due to the fact that cortical representations are distributed. Complex experiential phenomena, like rich somatosensory percepts, are therefore unlikely to be reproduced with focal stimulation without activation of a larger network. Upstream sensory circuits have To to this we developed the first chronic neural interface of the dorsal column nuclei to and stimulation in awake The a for sensory encoding. These nuclei on the dorsal surface of the and proprioceptive signals from primary (Figure from the high information to the for sensory the descending from that may sensory column nuclei interface. A, between and nuclei and in are readily with of the B, implanted in the of a at of in for several C, of of electrode in to studies of the were limited to or In our first of in were implanted with multi-electrode arrays to the feasibility of a chronic interface. Over several months, we that these arrays are and well in without data from implanted yielded a number of Over were The most was that over that are frequencies occurred with a in the we that could be over multiple in with chronic by the results of we designed a series of stimulation In experiments, we the at sensory encoding through at in a highly precise stimulation of the evoked responses in primary sensory stimulation evoked and field in the S1 (Figure which is to from sensory The induced for up to This finding may the of perceptual experiences primary that circuits between and S1 have a function for sensory To test perceptual thresholds of were on a detection and When stimuli were with to detect the electrical stimuli over rose to thresholds for are to cortical thresholds This that encoding experiments to characterize the efficacy of evoked Cortical responses to encoding. A, evoked responses to stimulation. to the which B, of frequencies stimulation. the stimulus at a well the stimulus feasibility of and encoding testing not from these experiments have for somatosensory currently will characterize responses and their to nodes including the and sensory Novel BCI Novel systems are to link peripheral sensor nodes and sensory encoding We developed a bidirectional brain–machine the as our third aim. This when links a suite of implantable and wearable peripheral sensor nodes with neural and electrodes (Figure the system and its nodes are to as a body area network. At the of the are wireless including a neural a neural a sensor and a The of a neural neural feature neural and associated The neural feature are for or field the system includes an neural energy and a detection with control is in the form of a that sensor data from peripheral sensors to desired patterns related to somatosensory cortex (Figure of brain–computer interface A, intersections between BCI systems and in the case of paralyzed or feedback control from nodes within in B, control loop integrating neural and stimulation in the flexibility to paralyzed or neural may be to or or stimulation with a voltage of Our the to current the that that neural and current current stimulation with a to a phase that neural However, changes due to during the Over millions of develop and in that the interface and To properly for this we a feedback that the phase when a point is detected (Figure The of this circuit is an error that error by the during stimulus the are the range, stimulation are as error that this method over that the system will have in experiments are to test this principle A, and of between phase and phase shown Idealized shown in shown in B, the on of point body area network requires real-time communication between the is with an impulse-radio band The and components to and between For clinical communication between nodes must be and operate within an of data The features an data of 2 in The error was over a of 3 of these are well within the desired for human moving toward human a number of must be of the system must be in must also be to To whether of the system was and effective at percepts, we designed in experiments on the the were to a to the by visual a pattern the is were to ICMS by the as a on the (Figure As the animal the stimulation As significantly in the presence of perception. When the was during was are able to systems to perception in a and effective In feasibility testing of novel systems. A, B, design is to in by ICMS as Idealized illustrated from with and optimal in presence of In our strategy to develop a sensor–brain interface system focuses on 3 aims: development of novel sensors, characterization of novel neural and development of autonomous body-area network. We have made in each of these areas, but substantial work We to our systems up to channel peripheral sensors and our In we our systems to animal models. It is our goal to this sensor brain interface with existing efferent systems to a bidirectional BCI to paralyzed This work was in by the National Science The have no or interest in of the or in this

Open access
EEG and Brain-Computer Interfaces
Neuroscience and Neural Engineering
Muscle activation and electromyography studies
Original source
Aug 1, 2017¡arXiv
39 cites
Transforming face-to-face identity proofing into anonymous digital identity using the Bitcoin blockchain

Daniel Augot, HervĂŠ Chabanne, Olivier ClĂŠmot, William R. George

The most fundamental purpose of blockchain technology is to enable persistent, consistent, distributed storage of information. Increasingly common are authentication systems that leverage this property to allow users to carry their personal data on a device while a hash of this data is signed by a trusted authority and then put on a blockchain to be compared against. For instance, in 2015, MIT introduced a schema for the publication of their academic certificates based on this principle. In this work, we propose a way for users to obtain assured identities based on face-to-face proofing that can then be validated against a record on a blockchain. Moreover, in order to provide anonymity, instead of storing a hash, we make use of a scheme of Brands to store a commitment against which one can perform zero-knowledge proofs of identity. We also enforce the confidentiality of the underlying data by letting users control a secret of their own. We show how our schema can be implemented on Bitcoin's blockchain and how to save bandwidth by grouping commitments using Merkle trees to minimize the number of Bitcoin transactions that need to be sent. Finally, we describe a system in which users can gain access to services thanks to the identity records of our proposal.

Open access
2 source records
cs.CR
cs.IT
Blockchain Technology Applications and Security
Original source
Jul 21, 2017¡Universitat Politècnica de Catalunya
0 cites
Advanced cryptographic techniques for building verifiable and transparent electronic voting protocols

Alex Escala Ribas

Electronic voting presents many challenges due to its multiple security requirements. Some of the challenges are related to guaranteeing voters' privacy and system's transparency, which are hard to satisfy simultaneously. Electronic voting also presents other challenges such as usability, particularly from the voter's side. We study two particular problems of electronic voting. Cast-as-intended verifiability comprises those mechanisms which assure the voter that her cast ballot corresponds to her chosen voting options. Current proposals put the verification burden on the voter, something which is undesirable in real-world elections, where both technically skilled and non-skilled voters participate. In this thesis, we introduce the concept of universal cast-as-intended verifiability, which provides mechanisms which allow any entity to check that any ballot corresponds to the voter's selections - without revealing them. We formally define what universal cast-as-intended verifiability is and we give an electronic voting protocol satisfying this property. The other problem we have studied is the problem of invalid votes in electronic elections. Since a common selling point of electronic voting is that it avoids voters inadvertently spoiling their votes, deliberately spoiled ballots appearing in the tallying phase of an electronic election can cause mistrust on the system. Indeed, election stakeholders might think that the system is flawed or that it was exploited somehow. To avoid this situation, we define the concept of vote validatability, which states the electronic voting system should be able to detect spoiled ballots before they are successfully cast. In addition to formally defining this notion, we design an electronic voting protocol satisfying this property. All these security requirements of electronic voting systems are implemented with cryptographic tools. In addition to encryption and signature schemes, another essential primitive for building electronic voting protocols is zero-knowledge proofs. Zero-knowledge proofs allow a prover to convince a verifier that a statement is true without leaking any other information. These zero-knowledge proofs can be used to, for example, prove that the tally of the election was done properly. Recently, Groth and Sahai constructed efficient non-interactive zero-knowledge proofs for a wide range of statements including, among others, statements appearing in electronic voting. In this thesis we give two contributions on Groth-Sahai proofs. On the one hand, we give a framework for deriving cryptographic assumptions from which to build secure cryptographic protocols. In particular, we build new Groth-Sahai proofs improving the efficiency of currently known constructions. Independently, we show how the original Groth-Sahai proofs can be extended to be compatible with even more statements, how to improve their out-of-the-box efficiency for many of these statements and how to improve their re-usability efficiency among multiple statements. Els sistemes de vot electrònic presenten molts reptes a causa dels seus múltiples requeriments. Alguns d'aquests reptes estan relacionats amb garantir la privacitat del votant i la transparència del sistema, requisits que són difícils de satisfer al mateix temps. D'altra banda, els sistemes de vot electrònic presenten altres reptes com la usabilitat, sobretot de cara als votants. En aquesta tesi estudiem dos problemes del vot electrònic. La verificabilitat "cast-as-intended" tracta d'obtenir mecanismes que garanteixin al votant que el seu vot correspon a les seves preferències. Les propostes actuals posen la càrrega de la verificació en el votant, cosa que no Ês desitjable en eleccions del món real, on participen votants amb diferents graus de coneixements tècnics. Nosaltres introduïm el concepte de "universal cast-as-intended verifiability", que proporciona mecanismes per a que qualsevol entitat de l'elecció pugui comprovar que qualsevol vot contÊ les preferències del votant que l'ha emès - sense revelar el contingut del vot. A banda de definir formalment el concepte de "universal cast-as-intended verifiability" tambÊ proposem un protocol de vot electrònic que satisfà aquesta propietat. L'altre problema que hem estudiat Ês el problema dels vots invàlids en eleccions electròniques. Un dels avantatges del vot electrònic Ês que permet evitar que els votants emetin vots nuls sense voler. Per això, si durant el recompte de l'elecció apareixen vots nuls construïts intencionadament es pot crear desconfiança en el sistema de vot. Els usuaris del sistema de vot poden pensar que el sistema tÊ forats de seguretat o que ha estat atacat. Per evitar aquesta situació, definim el concepte de "vote validatability", una propietat dels sistemes de vot electrònic que garanteix que els vots nuls es poden identificar en el moment que s'emeten. En aquesta tesi hem definit formalment aquesta propietat i hem dissenyat un protocol que la satisfà. Tots aquests requisits de seguretat dels protocols de vot electrònic s'implementen amb eines criptogràfiques. Les principals eines que s'utilitzen són esquemes de xifrat, esquemes de firma i proves de coneixement zero. Una prova de coneixement zero permet a una entitat convèncer una altra entitat que una sentència Ês certa sense donar cap altra informació que la certesa de la sentència. Aquestes proves de coneixement zero es poden fer servir, per exemple, per demostrar que el recompte de l'elecció s'ha fet correctament. Recentment, Groth i Sahai han construït proves de coneixement zero que es poden fer servir per un ampli ventall de sentències com per exemple sentències que apareixen en protocols de vot electrònic. En aquesta tesi hem fet dos contribucions sobre les proves de Groth i Sahai. Per una banda donem un marc teòric que permet derivar hipòtesis criptogràfiques per construir protocols criptogràfics. En particular, construïm noves proves de Groth i Sahai millorant l'eficiència de les construccions existents. De manera independent, indiquem com les proves de Groth i Sahai es poden estendre per fer-les compatibles amb un ventall mÊs ampli de sentències, millorem l'eficiència de les proves de Groth i Sahai per moltes d'aquestes sentències i, en particular, quan es fan servir per demostrar múltiples sentències.

Open access
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Advanced Authentication Protocols Security
Original source
Jul 14, 2017¡Studies in computational intelligence
0 cites
An Efficient Signature Scheme for Anonymous Credentials

Chien-Nan Wu, Chun‐I Fan, Jheng-Jia Huang, Yi‐Fan Tseng · 5 authors

No abstract is available for this record.

Cryptography and Data Security
Cryptography and Residue Arithmetic
Advanced Authentication Protocols Security
Original source
Jul 1, 2017¡The Philosophical Review
0 cites
Ideas, Evidence, and Method: Hume's Skepticism and Naturalism Concerning Knowledge and Causation

Jonathan Cottrell

This is a rich, ambitious, and original study. Graciela De Pierris aims to give a new account of the relationship between Hume's skepticism and his naturalism. Notoriously, Hume gives skeptical arguments targeting our best methods of inquiry, such as inductive reasoning. So, how can he—in good intellectual conscience—endorse and rely on those very methods, in his own naturalistic investigation of the human mind (his “science of man”)? Some scholars answer that, despite his skeptical arguments, Hume does not ultimately conclude that we lack justification for beliefs formed through induction or the other methods of inquiry that he employs as a scientist of man. Others answer that his skeptical arguments do not target his own preferred conception of these methods.De Pierris rejects both of these approaches. In her view, Hume argues for a form of skepticism that is “radical,” in that it targets his own preferred conception of our best methods of inquiry—the one that he endorses, as a practicing scientist of man. However, his “radical skepticism” and his “naturalism” can coexist because they constitute two different but mutually complementary “standpoints,” which must both “remain permanently available to all reflective thinkers” (22). In developing and defending this view, De Pierris offers an original interpretation not just of Hume but of early modern philosophy more broadly. She claims that Hume's views have been distorted by scholars who approach them from contemporary perspectives, such as cognitive psychology or naturalized epistemology. She therefore aims to understand Hume's skepticism and naturalism by placing them in the philosophical context of his own time. In doing so, she gives a novel account of the major intellectual fault lines in early modern philosophy.De Pierris divides early modern philosophers along two cross-cutting lines. First, she divides them based on their theories of mental content and “ultimate evidence.” Descartes and Locke accept what she calls “the presentational-phenomenological model of apprehension and ultimate evidence” (hereafter, PPM). According to PPM, we can be acquainted with an “ostensively given” particular content (for example, a particular sensory image) prior to grasping any general contents, such as formal rules of inference, and “ultimate evidence” derives from such acquaintance with particular contents. In opposition to these philosophers, Leibniz accepts the “logical-conceptual model,” according to which we must grasp a system of universal logical rules prior to any particular content, and “ultimate evidence” derives from this system of rules. (De Pierris's conception of “ultimate evidence” seems to have several components, including at least the following: ultimate evidence is the best possible evidence available to us; it confers certainty; and all other evidence derives from and depends on it.)With respect to this first division, De Pierris argues that Hume's theory of impressions and ideas is a version of PPM and is therefore a normative epistemological theory, not just a descriptive psychological one. Hume's version of PPM is the basis for his skeptical arguments, including his arguments for radical skepticism. Here, De Pierris assigns particular importance to Hume's distinction between natural and philosophical relations. As she interprets it, this distinction concerns two different kinds of mental activity: (i) unreflective, associative processes (natural relations) and (ii) reflective assessments of the evidence that particular contents are, or are not, related in certain ways (philosophical relations). Her view that Hume's notion of a philosophical relation is normative (insofar as it concerns the assessment of evidence) is original and informs her interpretation of his argument about induction in Treatise 1.3.6, discussed below.De Pierris's second division is between “mechanical philosophers,” who accept the “demonstrative ideal” of natural knowledge, and philosophers who accept Newton's rival, inductivist ideal. According to the former group, causal relationships are akin to geometric ones—an effect is a “necessary, quasi-geometric consequence” of its cause (164)—and science aims at a priori, demonstrative knowledge of them. Descartes and Leibniz accept this view. And, although Locke denies that we can attain a priori, demonstrative knowledge of nature, he accepts this as an unattainable ideal; this explains why he denies that we can have a genuine science of nature. In contrast, Newton rejects the demonstrative conception of natural knowledge, even as an unattainable ideal. According to his rival methodology, science ideally aims not at demonstration but at inductive “proof”—that is, inductive inference from a perfectly constant conjunction that we have experienced. De Pierris argues that Hume belongs in the Newtonian camp, based on several considerations, including a comparison of Hume's “rules by which to judge of causes and effects” with Newton's “rules for the study of natural philosophy” in the Principia. She sees this as “an important new argument against the skeptical realist interpretation of Hume” (187n258), which, she claims, wrongly assimilates his position to Locke's (14). However, she nowhere considers a striking passage from Hume's Dialogues Concerning Natural Religion, where Philo suggests that “the whole economy of the universe” may be conducted by a necessity like that of arithmetic, “though no human algebra can furnish a key, which solves the difficulty” (Hume 1947, 191). This passage presents a view like that which De Pierris attributes to Locke, and skeptical realist interpreters have made much of it, so it is disappointing that she neglects to discuss it.De Pierris interprets Hume's skepticism and naturalism in the context of these divisions among early modern philosophers. As she understands it, his naturalism consists chiefly in his endorsement of Newtonian inductive methodology. It is therefore a normative position, not just a descriptive one. Hume's naturalism also involves a distinctive conception of causal necessity, as a projection of “the normative force of our best inductive methods . . . onto nature itself” (176). If I understand this correctly, it means that, for Hume, our conception of causal necessity just is the conception of conformity to those regularities that our best inductive methods tell us that we should believe to obtain. This “epistemological notion” of causal necessity differs from both the mechanical philosophers’ quasi-geometrical notion and the regularity theory of causation that some scholars attribute to Hume, which are both “ontological” (176).Hume's skepticism, on the other hand, derives from his version of PPM. De Pierris finds two main lines of skeptical argument in Hume. One concerns mathematical knowledge; the other concerns natural knowledge and, relatedly, the nature of causation. Each argument has two stages. At the first stage, Hume targets his philosophical opponents’ conception of the knowledge in question. Numerous scholars think that his skeptical arguments end here. But De Pierris holds that these arguments have a second stage, at which Hume targets his own preferred conception of the knowledge in question—the conception that he endorses, as part of his naturalism. This is where his skepticism becomes “radical.”De Pierris's “skeptical inductivist” interpretation of Treatise 1.3.6 (and the corresponding passages of the “Abstract” and first Enquiry) is particularly interesting and original. She claims that this section gives a skeptical argument targeting “causation as a philosophical relation” (240)—that is, targeting the best evidence we can have, when reflectively comparing two phenomenologically given particulars, that they are causally related. For Hume, Newton's inductive methodology specifies what such evidence consists in: experience of a perfectly constant conjunction, which serves as the basis for an inductive “proof,” rather than a mere probability. According to Newton, an inductive proof relies, implicitly or explicitly, on the principle that nature is “ever consonant with itself” (as he puts it in the Principia). In Treatise 1.3.6, Hume argues that we have no good reason to accept this Newtonian uniformity principle. This is a normative, epistemological form of skepticism that targets Hume's own preferred conception of natural knowledge. Hence, De Pierris's interpretation differs from the “cognitive mechanisms” approach of Don Garrett and David Owen, who claim that Treatise 1.3.6 argues for a purely descriptive, nonnormative conclusion about the psychological processes that cause our beliefs about the unobserved. De Pierris's interpretation also differs from Peter Millican's (2002) skeptical interpretation of the corresponding section of the first Enquiry, according to which Hume's argument targets a conception of inductive reasoning that he himself does not endorse.For De Pierris, then, Hume gives skeptical arguments targeting what are, by his own lights, our best methods of scientific inquiry. So how can he continue to endorse and rely on those methods, as a practicing scientist of man? De Pierris claims that Hume's philosophy involves two different “standpoints,” each with its own normative standards. From the “standpoint of common life and science,” Hume endorses and employs Newtonian inductive methodology. From the “radical skeptical standpoint,” he argues that we lack justification for the uniformity principle that underwrites this very methodology. De Pierris claims that these two standpoints cannot be integrated but are nonetheless mutually complementary because those who occupy the standpoint of common life and science (including Newton and his followers) are frequently tempted into religion and superstition, and the radical skeptical standpoint serves to counter this temptation. She contrasts this interpretation with what she calls “the vehicle view,” on which Hume's skeptical arguments serve merely as a preliminary stage, clearing the way for his positive, naturalistic science of man. On her interpretation, by contrast, the radical skeptical standpoint must remain permanently available to the scientist of man, to serve as a check on our superstitious inclinations. She also contrasts her interpretation with Garrett's, which appeals to Hume's “Title Principle,” that “where reason is lively, and mixes itself with some propensity, it ought to be assented to. Where it does not, it can never have any title to operate on us” (Treatise 1.4.7.11/270).1 According to Garrett, this principle gives Hume epistemic permission to pursue his science of man, and to retain a significant degree of belief in its findings, despite the skeptical considerations that he raises. De Pierris gives some interesting objections to this proposal and claims that Hume recommends philosophy not because we have a “propensity” to it but because it is a safer guide than superstition.I am not convinced that De Pierris succeeds in removing the tension between Hume's skepticism and naturalism. For two reasons, it seems to me that the Humean scientist of man, as characterized by De Pierris, is irrational by his or her own lights.First, I can find only one argument in this book that supports Newtonian methodology. It proceeds by using Hume's version of PPM to eliminate the mechanical philosophers’ alternative methodology: Hume argues that a cause and its effect are always phenomenologically separable, and therefore lack an internal necessary connection that would allow us to demonstrate the existence of one from that of the other—contrary to the mechanical philosophers’ “demonstrative ideal” of natural knowledge. However, Hume's version of PPM is also the basis for his radical skeptical argument against Newtonian methodology (225, 237n297). So, someone who accepts Hume's version of PPM is rationally committed to rejecting both the mechanical philosophy and the Newtonian alternative. And so, it is irrational to accept Newtonian methodology on the strength of Hume's PPM-based argument against the mechanical philosophy.Second, according to De Pierris, Treatise 1.4.1 argues that Hume's own “rules by which to judge of causes and effects” epistemically require us to reduce our degree of belief in the conclusion of any piece of reasoning to zero. The Humean scientist of man endorses these rules. So, if he or she continues to believe any conclusions of reasoning, then this is irrational, by his or her own lights.It therefore seems to me that De Pierris's Hume cannot, in good intellectual conscience, pursue his science of man. In contrast, Garrett's Hume (who accepts the Title Principle) is epistemically permitted do so.There is much of value in this book beyond its main line of argument about Hume's skepticism and naturalism and their intellectual context. It contains interesting and original discussions of early modern theories of mathematical knowledge, Locke's relation to Newton, and Hume's view of space and geometry. Concerning this last view, De Pierris rejects, and develops an alternative to, two influential interpretations: the “discrete space” interpretation due to Donald Baxter, James Franklin, and others; and the “actual parts” interpretation due to Thomas Holden. De Pierris proposes that, contrary to the “discrete space” interpretation, Hume does not aim to replace Euclidean geometry with an alternative, finitist geometry. Instead, he accepts Euclidean geometry as a demonstrative science, albeit an inexact one that cannot achieve the same degree of certainty as algebra and arithmetic. And contrary to the “actual parts” interpretation, a given spatially extended whole is not composed of a determinate number of indivisible minima whose existence is metaphysically prior to that of the whole. Instead, extended wholes have a kind of priority over the minima that compose them: minima are defined in terms of processes of diminution or division performed upon such wholes.Ideas, Evidence, and Method is essential reading not just for Hume scholars, but for all philosophers interested in early modern epistemology, philosophy of mind, philosophy of mathematics, and philosophy of science.I thank Andrew Chignell and Don Garrett for helpful feedback on earlier drafts.

American Constitutional Law and Politics
Original source
Jul 1, 2017¡22017 IEEE International Conference on Computational Science and Engineering (CSE) and IEEE International Conference on Embedded and Ubiquitous Computing (EUC)
0 cites
An Efficient CPA-Secure Encryption Scheme with Equality Test

Han Jiang, Qiuliang Xu, Changyuan Liu, Zhe Liu

In this paper, we propose a CPA-Secure encryption scheme with equality test. Unlike other public key solutions, in our scheme, only the data owner can encrypt the message and get the comparable ciphertext, and only the tester with token who can perform the equality test. Our encryption scheme is based on multiplicative homomorphism of ElGamal Encryption and Non Interactive Zero Knowledge proof of Discrete Log. We proof that the proposed scheme is OW-CPA security under the attack of the adversary who has equality test token, and IND-CPA security under the attack of adversary who can not test the equality. The proposed scheme only suppose to compare two ciphertexts encrypted by same user, though it is less of flexibility, it is efficient and more suitable for data outsourcing scenario.

Cryptography and Data Security
Chaos-based Image/Signal Encryption
Cryptography and Residue Arithmetic
Original source
Jun 23, 2017¡International Journal of Advanced Research in Computer Science
1 cites
AN EFFICIENT AUTHENTICATION PROTOCOL USING ZERO KNOWLEDGE PROPERTY AND PAIRING ON ELLIPTIC CURVES

Manoj Kumar

The systematic introduction to zero knowledge proof protocol has important theoretical guidance and practical significance on attracting more scholars involved in research as well as expanding application fields. Zero-knowledge proofs were first conceived in 1985 by Shafi Golwasser, Silvio Micalli and Charles Rackoff in a draft of the knowledge complexity of interactive proof systems. The goal of the present paper is to introduce a new identity based scheme which is a combination of zero-knowledge interactive proof and weil pairing on elliptic curves. The concept of weil pairing was first introduced by Andre Weil in 1940. It plays an important role in the theoretical study of the arithmetic of elliptic curves and Abelian varieties. It has also recently become extremely useful in cryptologic constructions related to these objects.

Open access
Cryptography and Residue Arithmetic
Cryptography and Data Security
Polynomial and algebraic computation
Original source
Jun 20, 2017¡Journal of Zankoy Sulaimani - Part A
5 cites
Hollow and Semihollow Modules

Payman Ali, Basil Al-Hashimi

Let be an associative ring with identity and be a non-zero unitary left module over . is called a hollow (semihollow) module if every proper (finitely generated proper) submodule of is a small submodule of . The purpose of this work is, to give a comprehensive study of hollow modules and semihollow modules. Moreover, we study the class of modules with finite spanning dimension. We supply the details of the proofs for almost all the results and we illustrate the concepts by examples. Also, we add some results that seem to be new to the best of our knowledge.

Open access
Rings, Modules, and Algebras
Original source
Jun 1, 2017¡DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
Two-way Authentication Protocol Based on SM2 and Zero Knowledge for Radio Frequency Identification

LI Zichen,LIU Boya,WANG Peidong,YANG Yatao

To ensure the wireless communication security of the reader and tag in the Radio Frequency Identification(RFID) system,based on domestic public key cryptography algorithm SM2 and introducing zero knowledge proof idea,this paper proposes a two-way authentication protocol.Then security and efficiency analysis are given.The formal analysis is made by using BAN logic.Results show that the two-way authentication of the proposed protocol is completed in the case that reader and tag just interact twice,and has high safety and communication efficiency.

RFID technology advancements
Advanced Authentication Protocols Security
Cryptography and Data Security
Original source