Christian Badertscher, Sandro Coretti, Chen-Da Liu-Zhang, Ueli Maurer
Commitment schemes that admit zero-knowledge proofs for relations among committed values are known as commit-and-prove functionalities or notarized envelopes. An important role in this context play equality proofs among commitments. They appear in various contexts of multi-party computation, circuit satisfiability or inclusion proofs. Using commit- and-prove functionalities admitting equality, we investigate blackbox constructions of commit-and-prove functionalities admitting more complex relations. Typically, these constructions have to create commitments to additional values to achieve a certain level of soundness. An important efficiency measure is the number of such additional commitments. We prove that, for the natural and quite general class of 3-round public-coin zero-knowledge protocols, implementing the inequality relation, or any of the relations NAND, NOR, or XOR, essentially requires at least 2n additional commitments in order to achieve a soundness of 2-n. A folklore protocol shows that this bound is tight for inequality.
Olivier Blazy, Philippe Gaborit, Julien Schrek, Nicolas Sendrier
In this paper we give the first blind signature protocol for code-based cryptography. Our approach is different from the classical original RSA based blind signature scheme, it is done in the spirit of the Fischlin approach [9] which is based on proofs of knowledge. To achieve our goal we consider a new tool for zero-knowledge (ZK) proofs, the Concatenated Stern ZK protocol, which permits to obtain an authentication protocol for concatenated matrices. A signature is then obtained from the usual Fiat-Shamir heuristic. We describe our blind signature protocol for cryptography based on Hamming metric and show how it can be extended to rank based cryptography. The security of our blind protocol is based on the security of a trapdoor function for the syndrome decoding problem: the CFS signature scheme for Hamming distance and on the more recent RankSign protocol for rank metric. We give proofs in the random oracle model (ROM) for our blind signature scheme, which rely on the Syndrome Decoding problem. The parameters we obtain for our protocol are practical for rank metric (200kBytes) for the signature length and 15kBytes for public key size) and a little less practical for Hamming distance.
5G mobile communication is being designed as heterogeneous network where different platforms, several technologies, and various cell sizes are deployed to fit specific requirements in terms of data rates and latency. The heterogeneity nature of this network will lead to new security issues and threats, especially when the number of deployed mobile devices become very important. In this paper, we propose a simple PKI certificate based access control scheme that is implemented on a multi-layer communication architecture designed for 5G networks. In addition, we establish a scalable authentication and handover schemes that can ensure security within the network. To this purpose, we define various types of certificates with different features and utilization. The authentication scheme is based on zero knowledge proof (ZKP) and is used to achieve secure device registration procedure before generating authorization certificates that will be used to enable secure device-to-device communication. We use simulation work to assess the efficiency of our scheme in terms of total overhead and average latency. Performance evaluation results show that our scheme is more scalable than existing authentication and handover schemes.
Dev P. Chakraborty, Robert M. Nishikawa, Colin G. Orton
One of the major roles of regulatory bodies is to enforce rules and thus maintain standards. They also often do research related to their missions, some of which might be used to establish the standards they are regulating and how they should be evaluated. This has led some to believe that, due to potential concerns of bias and conflicts of interest, regulatory bodies should not do evaluation methodology research related to their regulatory missions. This is the claim that is debated in this month's Point/Counterpoint. Arguing for the Proposition is Dev P. Chakraborty, Ph.D. Dr. Chakraborty earned his Ph.D. in solid state physics from the University of Rochester, New York in 1977 then, in 1979, began his career in medical physics working with Ivan Brezovich in the Department of Radiology, University of Alabama at Birmingham, AL, where he worked until 1988 before moving to the Department of Radiology, University of Pennsylvania, Philadelphia. He subsequently moved to the University of Pittsburgh, Pittsburgh, PA, in 1997, where he was Professor in the Department of Bioengineering before assuming his current position at ExpertCAD Analytics, LLC in 2016. He has published over 75 papers in peer-reviewed journals, many in the field of observer performance analysis. Arguing against the Proposition is Robert M. Nishikawa, Ph.D. Dr. Nishikawa received his B.Sc. in physics in 1981 and his M.Sc. and Ph.D. in Medical Biophysics in 1984 and 1990, respectively, all from the University of Toronto. While at the University of Chicago, he developed computer-aided diagnosis systems for classifying and detecting clustered calcifications in mammograms. He has seven patents on CAD-related technologies and has over 200 publications in breast imaging. He is currently a Professor and Director of the Clinical Translational Medical Physics Laboratory in the Department of Radiology at the University of Pittsburgh. He has won 24 awards including two for âbestâ paper, two innovation awards, and one teaching award. He is a fellow of the American Association of Physicists in Medicine, the Society of Breast Imaging, the College of American Institute for Medical and Biological Engineering, and a Distinguished Investigator, Academy of Radiology Research. His research interests are in computer-aided diagnosis, breast imaging, image quality assessment, and evaluation of medical technologies. The Food and Drug Administration (FDA) and the Center for Devices and Radiological Health (CDRH) both regulate imaging devices and claim leadership roles in how they are evaluated. To demonstrate that the CDRH leadership in imaging device evaluation research biases research in this area and results in suboptimal evaluation of new imaging devices, I will present a single extended example. CDRH scientists are leading proponents of FROC/ROC1, 2 methods for analyzing observer outcome studies. An alternative and often more efficacious approach is the JAFROC method3 pioneered in my laboratory. Does a computer-aided detection (CAD) manufacturer adopt evaluation methods developed by Chakraborty3 or does the manufacturer feel pressure to adopt the FDA's methods?1, 2 Chakraborty's methods/software (JAFROC) have been used in over 104 publications, but only 24 are from the US and none from the FDA. The chances that this low number is a fluke are astronomically small, especially given the much larger total numbers of published US studies relative to non-US studies. This is strong evidence the FDA has influenced US-researchers against using JAFROC. Most clinical trials, including the American College of Radiology Imaging Network (ACRIN) Digital Mammographic Imaging Screening Trial (DMIST),4 have used the lower power ROC paradigm for localization tasks, which is inappropriate and unethical:5 lower power means the study is either of dubious value or it is overly expensive. The location-specific method favored by the FDA1, 2 is based on the FROC curve: one can hardly do worse. FROC data consist of mark-rating pairs; marks are locations of suspicious regions and the rating is the associated confidence level. Based on a proximity criterion, a mark close to a lesion is scored as lesion localization (LL) and otherwise, it is non-lesion localization (NL). Lesion localization fraction (LLF) is defined as the number of LLs ⼠threshold divided by the total number of lesions. The non-lesion localization fraction (NLF) is the number of NLs ⼠threshold rating divided by the total number of images. The FROC curve (plot of LLF (ordinate) vs. NLF) rises with infinite slope from (0,0). The slope then decreases monotonically and the curve ends abruptly at an unpredictable point. The FROC is not contained within the unit square. This makes it impossible to define a meaningful area measure. The FROC is defined by marks: unmarked nondiseased cases, which represent perfect decisions, do not contribute to the area under the curve (AUC) under the FROC. In screening mammography, about 995 cases out of 1000 are nondiseased. The perfect radiologist, who marks all lesions and does not mark any nondiseased case, yields zero FROC AUC, receiving no credit for the 995 correct decisions. JAFROC is based on the AFROC (alternative-FROC) curve. The y-axis is similar to LLF, but the x-axis is the ROC false-positive fraction defined by the highest ratings on nondiseased cases, and the AFROC plot includes a connection from the uppermost operating point to (1,1). Unlike the FROC AUC, the AFROC AUC for the perfect observer is unity, not zero. JAFROC is ignored in FDA's Guidance Document,2 as are positive statements about JAFROC from the late Drs. Wagner and Metz,6 and there is not one reference to Chakraborty's work. The FDA's bias has doomed progress in breast cancer CAD (40,000 deaths/yr). Besides using incorrect FROC methodology, it has set a low (second reader) bar for CAD to be considered a âsuccessâ. The end result: massive clinical trials7 have shown that CAD is actually detrimental to the outcome and there has been a call to end CAD Medicare reimbursement.8 Regulation is necessary to balance the costs and benefits of implementing a product or activity. This raises two important issues. First, it is important to quantify costs and benefits accurately. Second, it is equally important for impartiality to acquire correct balances. The proposition directly addresses the second issue, but the first issue is necessary to discuss also. I will restrict my discussion to medical imaging devices for clarity. There are many well-established methods to determine the benefits of medical imaging devices.9 There are, however, situations where researchers need new evaluation methods, either for a new technology or to simplify tests for an existing type of technology. This requires research to develop and validate the new methodologies. The regulatory agencies need to understand the strengths and weaknesses of any tests presented to them as evidence for the effectiveness of a product. This would require regulatory agencies to either develop the expertise in-house or to rely on the scientific literature. That latter is insufficient for two reasons. First, regulatory science is not a well-funded branch of science. Therefore, unless the regulatory bodies perform the research, a disconnect may occur between developing the technologies and measuring their benefits and costs. This will either slow down approval of new technologies or lead to unbalanced regulations, or both. Second, reviewing the literature may be effective in understanding the basics of the evaluation methodology, but it is usually insufficient to understand the limitations of the method. Understanding the limitations is best done by applying the method, using simulations to a variety of situations, and evaluating the results. That is basically research and regulatory bodies benefit from conducting the studies themselves. While we can quantify benefits and costs, it is often difficult to decide on the proper balance of the two, particularly in an unbiased manner. Part of the difficulty arises from benefit and cost estimates not having the same units. A prime example of this, while not exactly in the regulatory domain, is the United States Preventative Services Task Force (USPSTF) recommendations on mammographic screening.10 We can evaluate the benefits of screening as lower mortality from breast cancer and costs as false-positive screens â recalling a woman for further imaging when, in fact, she does not have a breast cancer. It is not clear how to balance lives saved against more imaging and potentially an unnecessary biopsy. The USPSTF placed more weight on false-positive screens and chose not to recommend periodic screening for all women under the age of 50, compared to, for example, the American College of Radiology which supports annual screening of women 40 and older.11 Some proponents of screening argue that the USPSTF was biased in making their recommendations.12 There is no clear solution for this potential bias, but I do not believe that researching evaluation methodology is the right place to start. On the contrary, I believe there is less potential for bias when people are more knowledgeable â unless they are predisposed to a bias to begin with. Which is to say a bias can exist whether knowledge is obtained first hand or from reviewing the literature. I agree with my colleague that the FDA/CDRH needs to be current on the science. If regulatory science is not a well-funded branch of science, that makes it even more important to be current on the existing science, both from a revered in-house predecessor6 and from academia.3 I also agree that there is need for developing new evaluation methods, but then why is the new FDA/CRDH still wedded to the 1940s ROC paradigm; what is new about it? The âmechanisticâ approach13 that they are enamored with does not advance the state-of-the-art in general-paradigm multireader multicase (MRMC) analysis, rather it explains and generalizes the variance-component decomposition used in Dorfman/Berbaum/Metz analysis14 in a mathematically appealing way. But, and this is the serious limitation, it applies only to the Wilcoxon ROC statistic; it is not even applicable to fitted ROC curves, let alone FROC methodology. In my Opening Statement, I cited the âpowerâ imbalance when it comes to reviewing/vetting the work of the FDA/CDRH, and examples of questionable work. I could go on, especially how they validate methodologies. It is a brave and knowledgeable researcher who can properly review a paper15 listing as institution of origin: âNIBIB/CDRH Laboratory for the Assessment of Medical Imaging Systemsâ. Any applicant for an NIH grant in methodology development, and I see there is a recent funding opportunity announcement (PAR-17-125), would be well advised to cite this paper, never mind that it is about ROC analysis, while CAD provides FROC data, so at the very least the title of the paper is misleading. The cited work remains true to model observer philosophy, which assumes the lesion location is known, ignoring the fact that if location were known, there would be no need for a radiologist to find it. This entire debate would be of academic interest, but it was not for the implications for patient care: lives literally depend on the selection of proper imaging technology. Conducting ROC studies for search tasks is not only bad science but it is also unethical and a disservice to patients and taxpayers. My colleague Dev Chakraborty argues, I believe because it is not explicitly stated that the FDA, but principally the CDRH, is biased because it âforcesâ companies to use ROC analysis instead of JAFROC analysis, which Dev developed; and that this bias exists because members of the CDRH have done ROC research, but not FROC research. That is an interesting premise. Dev supports his assertion with statistics that are consistent with his view, but it does not constitute proof. Here is my prospective on Dev's claim of bias. First, I know many of the people at the CDRH. In my view, they are among the leaders in the field, both in terms of their scientific rigor and in their vision. The CDRH has a long history of significant and cutting edge research and establishing methodology for evaluating screen-film systems, digital systems, computer-aided diagnosis systems, ultrasound, and others. I have not seen signs of bias in my interactions with members of the CDRH. Certainly, the members have preferences, but they remain open-minded and fair. It is important to note that just as there are differences in approach between scientists in academia and industry, there are differences between scientists in the public service sector and academia (and industry). Scientists in the public are much more open to sharing data and ideas. Second, companies applying for FDA approval are, in my experience working with them, very conservative in their approach, and they basically follow any FDA precedent or previous approved applications. This is because the approval process can be time-consuming and expensive. Companies usually overpower their observer studies to include more readers and cases than what is required by an 80% power calculation. They do not want to risk having a null result because the observer study was underpowered. Furthermore, and more importantly, it is much easier and less risky just to copy a previously approved application. This will result in the same methods being perpetuated over time. So, when a company develops a new method, even if there are some benefits to it over existing techniques, they are less likely to use the new method in FDA submissions. This is the company's choice, not an FDA edict. So, while Dr. Chakraborty has presented evidence, it is all circumstantial and, until he produces a âsmoking gunâ, I believe that his assertion of bias at the CDRH is false. The authors have no relevant conflicts of interest to disclose.
I-Hsun Chuang, Bing-Jie Guo, Jen-Sheng Tsai, Yau-Hwang Kuo
Internet of Things (IoT) is an emerging network technology applied to provide various services in our daily life. Generally, IoT environments are composed of numerous heterogeneous devices with constrained resource. The limited capability of IoT devices makes it impractical to perform traditional security mechanisms, and thus IoT services are usually vulnerable to all kinds of security threats, such as impersonation and forgery attacks. Moreover, the inflexible protection provided by these security mechanisms leads to inefficiency because different services haves diverse requirements. To provide IoT services suitable security protection, Multi-graph Zero-knowledge-based Authentication System (M-ZAS), which is not only light-weight but also high-adaptive, is proposed. Compared to traditional authentication mechanisms as well as other Zero-knowledge-proof (ZKP) methods such as GMW-ZKP, M-ZAS provides higher performance and better security protection. In addition, M-ZAS has lower transmission overheads than GMW-ZKP does. Considering relevant contexts as parameters, M-ZAS provides adaptive protection to fulfill what users actually need. Experiment results show that M-ZAS is 3 times faster than GMW-ZKP and even 7 times than traditional authentication mechanisms in IoT devices. Also, M-ZAS reduces 3 times network traffic than GMW-ZKP. Thus, the proposed M-ZAS is the most practical authentication system in IoT environments.
Willy Sudiarto Raharjo, Ignatia Dhian Estu Karisma Ratri, Henry Susilo
Abstract â This paper describes a login system utilizing Two Factor Authentication and Zero Knowledge Proof using Schnorr NIZK. The proposed system is designed to prevent password leak when being sent over insecure network or when used in an untrusted devices. Zero Knowledge Proof is used for maintaining the confidentiality of the password and Two Factor Authentication is used to secure login process on untrusted devices. The proposed system has been tested and initial results indicates that such system is able to secure the login process without leaking the userâs password. Keywordsâ Authentication, Security, Two Factor Authentication, Password, Zero Knowledge Proof
Alessandro Chiesa, Michael A. Forbes, Nicholas Spooner
Many seminal results in Interactive Proofs (IPs) use algebraic techniques based on low-degree polynomials, the study of which is pervasive in theoretical computer science. Unfortunately, known methods for endowing such proofs with zero knowledge guarantees do not retain this rich algebraic structure. In this work, we develop algebraic techniques for obtaining zero knowledge variants of proof protocols in a way that leverages and preserves their algebraic structure. Our constructions achieve unconditional (perfect) zero knowledge in the Interactive Probabilistically Checkable Proof (IPCP) model of Kalai and Raz [KR08] (the prover first sends a PCP oracle, then the prover and verifier engage in an Interactive Proof in which the verifier may query the PCP). Our main result is a zero knowledge variant of the sumcheck protocol [LFKN92] in the IPCP model. The sumcheck protocol is a key building block in many IPs, including the protocol for polynomial-space computation due to Shamir [Sha92], and the protocol for parallel computation due to Goldwasser, Kalai, and Rothblum [GKR15]. A core component of our result is an algebraic commitment scheme, whose hiding property is guaranteed by algebraic query complexity lower bounds [AW09,JKRS09]. This commitment scheme can then be used to considerably strengthen our previous work [BCFGRS16] that gives a sumcheck protocol with much weaker zero knowledge guarantees, itself using algebraic techniques based on algorithms for polynomial identity testing [RS05,BW04]. We demonstrate the applicability of our techniques by deriving zero knowledge variants of well-known protocols based on algebraic techniques, including the protocols of Shamir and of Goldwasser, Kalai, and Rothblum, as well as the protocol of Babai, Fortnow, and Lund [BFL91].
Anwar Kh. Faraj, Areej M. Abduldaim, Shatha A. Salman, Nadia M. G. Al-Saidi
Algebra is one of the important fields of mathematics. It concerns in the study and manipulates of mathematical symbols. It also concerns with study of abstractions such as groups, rings and fields. Ring theory is the most attractive category of algebra in the area of cryptography. Recently, many algebraic cryptosystem protocols based on non-commutative algebraic structures such as; authentication, key exchange, and encryption-decryption processes are adopted. In this paper, we employ the algebraic structure called nil Armendariz (NA) rings to design a neoteric algorithm for zero knowledge proof. The proposed protocol is implemented and illustrated through numerical example, and its soundness and completeness are proved.
Ken Naganuma, Masayuki Yoshino, Hisayoshi SATO, Takayuki Suzuki
Bitcoin is the first widely adopted decentralized digitale-cash system. All Bitcoin transactions that include addresses of senders and receivers are stored in the public blockchain which could cause privacy problems. The Zerocoin protocol hides the link between individual Bitcoin transactions without adding trusted third parties. However such an untraceable remittance system could cause illegal transfers such as money laundering. In this paper we address this problem and propose an auditable decentralized e-cash scheme based on the Zerocoin protocol. Our scheme allows designated auditors to extract link information from Zerocoin transactions while preventing other users including miners from obtaining it. Respecting the mind of the decentralized system, the auditor doesn't have other authorities such as stopping transfers, confiscating funds, and deactivating accounts. A technical contribution of our scheme is that a coin sender embeds audit information with a non-interactive zeroknowledge proof of knowledge (NIZKP). This zero-knowledge prevents malicious senders from embedding indiscriminate audit information, and we construct it simply using only the standard Schnorr protocol for discrete logarithm without zk-SNARKs or other recent techniques for zero-knowledge proof.
Yupeng Zhang, Jonathan Katz, Charalampos Papamanthou
We present a new construction of an expressive set accumulator. Unlike existing cryptographic accumulators, ours provides succinct proofs for a large collection of operations over accumulated sets, including intersection, union, set difference, SUM, COUNT, MIN, MAX, and RANGE, as well as arbitrary nestings of the above. We also show how to extend our accumulator to be zero-knowledge. The security of our accumulator is based on extractability assumptions and other assumptions that hold in the generic group model. Our construction has asymptotically optimal verification complexity and proof size, constant update complexity, and public verifiability/updatability-namely, any client who knows the public key and the last accumulator value can verify the supported operations and update the accumulator. The expressiveness of our accumulator comes at the cost of quadratic prover time. However, we show that the cryptographic operations involved are cheap compared to those incurred by generic approaches (e.g., SNARKs) that are equally expressive: our prover runs faster for sets of up to 5 million items. Our accumulator serves as a powerful cryptographic tool with many applications. For example, it can be applied to efficiently support verification of a rich collection of SQL queries when used as a drop-in replacement in existing verifiable database systems (e.g., IntegriDB, CCS 2015).
Trusted hardware systems, such as Intel's new SGX instruction set architecture extension, aim to provide strong confidentiality and integrity assurances for applications. Recent work, however, raises serious concerns about the vulnerability of such systems to side-channel attacks. We propose, formalize, and explore a cryptographic primitive called a Sealed-Glass Proof (SGP) that models computation possible in an isolated execution environment with unbounded leakage, and thus in the face of arbitrary side-channels. A SGP specifically models the capabilities of trusted hardware that can attest to correct execution of a piece of code, but whose execution is transparent, meaning that an application's secrets and state are visible to other processes on the same host. Despite this strong threat model, we show that SGPs enable a range of practical applications. Our key observation is that SGPs permit safe verifiable computing in zero-knowledge, as data leakage results only in the prover learning her own secrets. Among other applications, we describe the implementation of an end-to-end bug bounty (or zero-day solicitation) platform that couples a SGX-based SGP with a smart contract. Our platform enables a marketplace that achieves fair exchange, protects against unfair bounty withdrawals, and resists denial-of-service attacks by dishonest sellers. We also consider a slight relaxation of the SGP model that permits black-box modules instantiating minimal, side-channel resistant primitives, yielding a still broader range of applications. Our work shows how trusted hardware systems such as SGX can support trustworthy applications even in the presence of side channels.
Security and Verification in Computing
Cloud Data Security Solutions
Physical Unclonable Functions (PUFs) and Hardware Security
An ultra-long distance distributed intrusion detecting system assisted with power amplification and sensitivity enhancement is proposed and demonstrated. First, through introducing multiple bidirectional amplifiers into the unbalanced Mach-Zehnder/Sagnac interferometer-based fiber sensing link, the sensing distance is remarkably extended, and second, the signal-to-noise ratio of this sensing system is significantly improved from less than 2 to 6-8 dB by coating the sensing fiber with organic silicone polymer. Furthermore, the high-order downtrend fitting function is adopted to implement the intrusion locating of ultralong distance sensing; the zero-padding fast Fourier transform algorithm and multiple-averaging method are jointly utilized for the improvement of the locating accuracy. Experimentally, a proof-of-concept distributed intrusion detecting system is constructed with the employment of bidirectional amplification. In particular, the ultra-long sensing distance up to 226.337 km is implemented, which is the reported longest distributed sensing system to the best of our knowledge.
Melissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi ¡ 8 authors
We propose a new class of post-quantum digital signature schemes that: (a) derive their security entirely from the security of symmetric-key primitives, believed to be quantum-secure, and (b) have extremely small keypairs, and, (c) are highly parametrizable. In our signature constructions, the public key is an image y=f(x) of a one-way function f and secret key x. A signature is a non-interactive zero-knowledge proof of x, that incorporates a message to be signed. For this proof, we leverage recent progress of Giacomelli et al. (USENIXâ16) in constructing an efficient sigma protocol for statements over general circuits. We improve this sigma protocol to reduce proof sizes by a factor of two, at no additional computational cost. While this is of independent interest as it yields more compact proofs for any circuit, it also decreases our signature sizes. We consider two possibilities for making the proof non-interactive, the Fiat-Shamir transform, and Unruhâs transform (EUROCRYPTâ12,â15,â16). The former has smaller signatures, while the latter has a security analysis in the quantum-accessible random oracle model. By customizing Unruhâs transform to our application, the overhead is reduced to 1.6x when compared to the Fiat-Shamir transform, which does not have a rigorous post-quantum security analysis. We implement and benchmark both approaches and explore the possible choice of f, taking advantage of the recent trend to strive for practical symmetric ciphers with a particularly low number of multiplications and end up using LowMC.
This paper presents Prio, a privacy-preserving system for the collection of aggregate statistics. Each Prio client holds a private data value (e.g., its current location), and a small set of servers compute statistical functions over the values of all clients (e.g., the most popular location). As long as at least one server is honest, the Prio servers learn nearly nothing about the clients' private data, except what they can infer from the aggregate statistics that the system computes. To protect functionality in the face of faulty or malicious clients, Prio uses secret-shared non-interactive proofs (SNIPs), a new cryptographic technique that yields a hundred-fold performance improvement over conventional zero-knowledge approaches. Prio extends classic private aggregation techniques to enable the collection of a large class of useful statistics. For example, Prio can perform a least-squares regression on high-dimensional client-provided data without ever seeing the data in the clear.
The latest Eurobarometer published in December 2016, reflecting the perceptions of the European citizens on privacy and security in telecommunications shows that, although people are not always informed on the privacy regulations or the implications of privacy breaches, they demand specific privacy protection. In particular, citizens want their data, their communications and the data that they give or outsource to online services to be well protected and not shared with unwanted parties. The demands of the public can be partly covered by the application of the privacy-by-design principle and the use of Privacy Enhancing Techniques (PETs) in commercial applications.
The privacy-by-design principle requires application designers to gather only the personal data that are essential to the correct operation of their applications. That is, applications following this principle should only ask the users to input those personal data that the specific application explicitly needs. Most applications in the market (and especially smartphone applications) clearly disregard this principle ---a look at the permissions they request is conclusive---: they collect contextual information too, even if it is not needed. The privacy policies of major service providers explain that all data may be used for commercial purposes.
Although major service providers collect more data than strictly necessary, the privacy-by-design principle demands that users be empowered with the decision about when to grant access to their data, when to modify them and when to delete them. While this is more or less being taken into account by service providers, sometimes the procedures to modify or delete personal data are not transparent enough or too cumbersome.
Privacy Enhancing Techniques (PET) are cryptographic and non-cryptographic tools that, when used appropriately, minimize the amount of personal data being handled by applications, and therefore help developers to more easily comply with regulations on personal data processing. Therefore, research on privacy enhancing techniques and on the practical deployment of the privacy-by-design principle is backed by the demands of the general population.
In this work we aim at demonstrating that, if appropriate techniques are used, privacy does not necessarily work against security and/or utility. We focus on three specific application cases described below:
- Group discounts are offered by vendors and public authorities to encourage a more sustainable (or profitable) way to access their services or use public resources. An example of this are high-occupancy vehicle (HOV) tolls in highways, which offer discounts for vehicles carrying more than a given number of passengers (2 or more, 3 or more, etc). There are several ways to ascertain the number of members of a group: employees at access points that count them, cameras that take photos and analyze them in toll booths, or registration procedures that require the names of all members of groups, among others.
We argue that automated mechanisms, such as cameras and registration procedures, take more information from the participants that is actually needed (thus violating the privacy-by-design principle), and that the only really necessary information is the size of the groups.
- Loyalty programs are marketing efforts implemented by vendors, especially retailers, that are aimed at establishing a lasting relationship with consumers. In a loyalty program, the vendor pursues two main goals: i) to encourage the consumer to make more purchases in the future (returning customer); ii) to allow the vendor to profile the consumer in view of conducting market research and segmentation (profiled customer). In order to lure consumers into a loyalty program, the vendor offers them rewards, typically loyalty points that consumers can later exchange for discounts, gifts or other benefits offered by the vendor.
Normally, enrollment to loyalty programs involves some kind of registration procedure, in which customers fill out a form with their personal information and are granted a loyalty card, be it a physical card (magnetic stripe or smartcard) or a smartphone application. Although loyalty programs have become widespread, they are experiencing a loss of active participants and they have been criticized by business experts and consumer associations. Criticism is mainly due to privacy issues, because it is not always clear whether the benefits offered by vendors in their loyalty programs are worth the loss of consumer privacy caused by profiling.
- Implicit authentication refers to a software system authenticating individuals based on the way they interact with their device, i.e. their behavior. In this context, the user's behavior can be determined by collecting a variety of features, such as keystroke patterns, browser history and configuration, IP addresses, location, visible antennas, etc. Implicit authentication can be viewed as a complement of the usual explicit authentication based on identifiers and credentials.
Note that a common trait in these three application cases is that users need to prove something about themselves or their context without revealing more than what is strictly necessary. We believe these cases can be used as an example for other applications in which the goal is similar.
The main contributions of this thesis are: 1. A group size accreditation method that preserves anonymity of the members of the groups. The anonymity provided by the scheme is congurable.
The method rests on two building blocks: (a) A new parameterized key management scheme for identity-based signatures that allows setting the anonymity level of users by providing them with multiple keys that are shared by many other users, but that are extracted from a unique identity.
(b) A novel IBDT signature scheme based on asymmetric bilinear pairings, that combines the properties of identity-based and threshold signature schemes. Signatures produced with this scheme reveal only the public keys of the group members, which are called identities, and the size of the signing group. The signature scheme is efficient, and the sizes of the signatures are constant.
2. A privacy-preserving loyalty program protocol suite, whereby vendors can issue and verify loyalty points, and customers can maintain their anonymity and con gure the level of generalization for their purchase receipts before submitting them for additional loyalty points. This allows vendors to still carry out client profiling in a privacy-aware way. This protocol suite combines the following techniques: (a) A new construction for anonymous (untransferable) tokens with controlled linkability based on partially blind signatures and zero-knowledge proofs. The construction allows issuing and verifying tokens, while the verifier cannot link tokens to a specific user or between concrete executions of the issuance and verification procedures, unless such a linkage is authorized by the user. Moreover, if a hardware based keystore is available, the tokens can be made untransferable, so that only users who originally received the tokens can submit them.
(b) Generalization techniques to select the level of anonymization of purchase receipts.
3. A mechanism to compute the distance between user profiles (expressed as feature sets of different data types) based on the size of the intersectionof the feature sets.
4. A privacy-preserving implicit authentication mechanism using the homomorphic properties of the Paillier cryptosystem, that protects the privacy of the sensitive data in the user's profile and ensures that the server does not learn anything about the user's behavior.
5. A second privacy-preserving implicit authentication with similar functionalities and higher speed compared to the previous one, based on the intersection of Bloom filters. While this mechanism provides slightly less protection than the previous one, its substantially better performance makes it ideal for implementation in existing authentication suites.
Alisa Solomonâs Wonder of Wonders opens with two brief stories that, in the hands of another writer, might be mere anecdotes: Fiddler on the Roofâs near-simultaneous invocation in 2011 by political radio talk show host Glenn Beck and Jewish protestors involved with Occupy Wall Street. Indeed, the entire introduction, aptly named âA little bit of this, a little bit of that,â seems at first to dwell on the anecdotal. Before we come to the evolution of the musical Fiddler on the Roof, we are first introduced to kids singing âSabbath Prayerâ at summer camps, interfaith holiday greeting cards featuring Tevye, Augusto Pinochetâs banning of Fiddler in Chile in the mid-1970s, and references to Fiddler in The Simpsons. But, like the modest yet treasured possessions of the residents of Anatevka, thereâs a lot more to these little bits then meets the eye. By page 2, Solomon has already essentially proven her central argumentâthat âFiddler, like no other musical before or since, has seeped into the culture more widely, functioning in sometimes contradictory waysâ (2) as a signifier of various kinds and degrees of Jewishness, a measure of political affiliation, and a mode of Jewish ritual practice, among others. Indeed, Wonder of Wonders tells the story of Fiddler on the Roofâs evolution and cultural impact with an astonishing breadth that is itself proof positive for her argument.The juxtaposition of Glenn Beck and Occupy at the start of the book is no mere anecdote, but a hint of whatâs to come. For this book is not only about how Fiddler on the Roof came into being and its reception, though Solomon does provide a fresh take on that subject. But more than anything else, this is a book about the musicalâs âradiant afterlifeâ as a global cultural phenomenon with âsurprising, enduring, shape-shifting utilityâ (4). It is this shape-shifting quality that Solomon traces most closely, following the trail of each new permutation of Sholem-Aleichemâs original Tevye stories like a magician demonstrating how a simple scarf can change color and texture, become a bird, vanish into thin air, and then suddenly reappear. In Wonder of Wonders, we catch a glimpse of how this beloved, shape-shifting Broadway musical has become part of the worldâs cultural ether, ever ready to meet the changing needs of its audiences.Time and time again, as Solomon demonstrates, Fiddler has morphed anew across a wide range of cultural contexts and locales. From the readers who first loved Tevye in Eastern Europe to the middle schoolers in a controversial Brownsville student production of Fiddler in 1968, from young Polesâ attempts to understand their countryâs past via musical theater to Jewish parents hiring bottle dancers for bar and bat mitzvahs, from Sholem-Aleichemâs years of struggle to bring his work to the Yiddish stage to the Fiddler-themed Judaica and dishware that can be found in synagogue gift shops across the country, Solomon examines it all. In the hands of another writer, these might have been rendered picayune episodes, nothing more than footnotes to the ârealâ story of the Broadway musical. Not so in Wonder of Wonders. Instead, these examples illuminate Fiddlerâs remarkable staying power as something more than just a play with many productions: a cultural touchstone.In Solomonâs capable hands, we readers are thus presented with dozens of incarnations of Tevyeâs story as it is told and retold, deconstructed, reconfigured, and revived over the course of more than a century. Many fine books and articles have been written about Fiddler on the Roof, of course, but no one before Solomon has ever examined Fiddler as a cultural phenomenon with such comprehensive scope. Encompassing not only the expected topics (Sholem Aleichemâs stories, Jerome Robbinsâs feud with Zero Mostel, the casting for the film) but also subjects that have never before been considered vis-Ă -vis their relationship to Fiddler (Hebrew theater in the forties, black-Jewish relations in the sixties, Fiddlerâs impact on contemporary Jewish rituals), this is cultural history at its finest.Like the writers and artists who are her subjects, Solomon knows how to create dramatic tension. The single word that readers are most likely to automatically associate with Fiddler on the Roof (and the title of the showâs signature opening number, âTradition!â), doesnât appear in Wonder of Wonders until well over a hundred pages in, when Jerome Robbins finally realizes what his show is actually about. Solomon thus enables her readers to develop a fresh view of Fiddler on the Roof, one that builds and grows over the course of the book. When Jerome Robbins has his âahaâ moment and realizes that tradition is the heart of the show, we experience the rush of enthusiasm and recognition that must have filled the room along with the creative team. Indeed, a full half of the book covers events that happened before Fiddler even opened on Broadway. By the time we arrive at opening night, the reader has the sense of only just understanding this iconic musical for the first time.Wonder of Wonders is structured in three parts, arranged chronologically. The first set of chapters considers the Yiddish writer Sholem-Aleichem and his authorship of the Tevye stories, his failure to break into the Yiddish theater, and the subsequent work of translators, writers, and artists who garnered visibility for this work among English speakers (Maurice Samuel, Arnold Perl, Frances Butwin, and others). Part 2, âTevye Strikes It Rich,â examines the long process via which Fiddler came to Broadway and its initial reception. But it is part 3, âTevyeâs Travels,â that represents the most significant contribution of this book: Solomonâs careful tracing of how Fiddler on the Roof has, to an extent unique among Broadway musicals, thoroughly permeated the cultural landscape with a broad global audience that includes Jews and non-Jews, and theatergoers and non-theatergoers, within its reach.Solomon displays many talents in these pages: careful researcher, astute scholar, skilled cultural critic. But above all, it is Solomonâs power as a storyteller that is on fullest display. In clever, witty, memorable prose, Solomon introduces us to a vivid cast of characters who at times seem to almost burst forth from the page. On Jerome Robbinsâs goals for Fiddler: â[he] labored mightily to burn away the schmaltz that for two decades had encased the world of the shtetl like amber.â (119) Or on Zero Mostelâs relationship to his mother tongue: âYiddish never stopped gurgling within him; often it spilled out.â (154). Or, about the rivalry between the two men: âIf a time machine could put a story about them on the Yiddish stage of earlier decades, charismatic, outsize Thomashefsky would have to play Mostel and haughty, blazing Jacob Adler would embody Robbinsâ (151). Solomonâs description of the Yiddish theater rivals in chapter 1 is so vivid that she can continue to reference them throughout the book.Indeed, Wonder of Wonders offers the reader a refreshingly rich and nuanced overview of Yiddish literature and the history of the Yiddish stage interwoven with a century of Tevyeâs journeys. The triumph of this book lies in Solomonâs exacting insistence on telling the whole story of Fiddler on the Roof, leaving no stone unturned. To entice the wary reader who may not consider him- or herself interested in such details as the state of Yiddish publishing in the nineteenth century or the history of translations of Sholem-Aleichem, Wonder of Wonders explains the significance of these contextual pieces through superb historical storytelling that makes the fluid and multifaceted relationship between the turn-of-the-century explosion of modern Yiddish culture and Fiddler transparent. Fiddler, in other words, didnât emerge in a vacuum; and Solomon wants to make sure that the reader understands the cultural landscape that birthed Tevyeâs story. Not only does Wonder of Wonders provide a rich mini-history of Yiddish literature, but Solomon also leverages Yiddish sources to demonstrate how Yiddish culture influenced the production itself. For instance, she explores Boris Aronson and Jerome Robbinsâs involvement with Yiddish theater prior to their Broadway careers, and analyzes how their experiences might have influenced particular production choices (like Robbins drawing upon his experience acting in Di brider ashkenazi at Maurice Schwartzâs Yiddish Art Theater for Fiddlerâs wedding scene). Solomon also examines the response to Fiddler in the Yiddish press, which has never before been examined, when considering the Jewish communityâs reaction to the musical. This is, to my knowledge, the first time in musical theater scholarship that a direct, continuous relationship between the Yiddish theater and Fiddler has been suggested, and it is a significant contribution. Solomon is implicitly proposingâquite rightly, I believeâthat Fiddler represents a moment of sharp continuity between the Yiddish stage and Broadway, in which American Jewish theater artists drew directly upon what they had learned early in their careers in the Yiddish theater. This perspective is far too often overlooked, and is a much needed corrective to scholarship that assumes that Yiddish culture was already long gone in postwar America.In sum, Alisa Solomon has written a brilliant, eminently readable, remarkable gem of a book that is so delightful to read that one has the sense of guzzling down her prose, all 448 pages of it. Upon finishing the introduction, my first thought was, âI canât wait to read the rest of this book.â My second thought was, âI canât wait to have my students read this book.â This is no small feat for a hefty, meticulously researched scholarly book, steeped in years of archival research. And yetâwonder of wonders, miracle of miraclesâSolomon pulls it off, this fusion of sophisticated academic argumentation with all of the literary qualities of a page-turner in a manner so seamless that it is nothing short of miraculous.
M. Suguna, R. Anusia, S. Mercy Shalinie, S. Renu Deepti
Mobile cloud computing (MCC) is a platform that allows mobile users to offload the computationally rigorous and storage demanding tasks on available cloud resources using wireless access. The major concern with MCC is the privacy of data. Mobile users give confidential information through the network, that if not safeguarded may lead to security issues. Identity Management (IDM) is the management of user identities, their authentication, and authorization in the cloud environment. The existing Consolidated Identity Management (CIDM) overcomes the network traffic interception in the traditional IDM but is prone to Identity theft in case of Identity Management Server (IDMS) compromise. This work is focused on the development of a Secure Identity Management (SIDM) that alleviates the attacks in the CIDM by using techniques that strengthens the authentication process and identity privacy. A secure IDM is developed using two-step authentication process which involves Zero Knowledge Proof (ZKP) and token verification. The proposed SIDM model reduces the consequences of Identity server compromise attack. There is a marginal increase in the communication overhead of SIDM compared to that of CIDM but it can be compromised to realize the benefits of identity privacy. The analysis of the experimental results shows that there is an overall increase of thirty percent in communication overhead when compared to CIDM.
Xavier Bultel, Jannik Dreier, Pascal Lafourcade, Malika More
At the main cryptography conference, CRYPTO, in 1989, Quisquater and colleagues published a paper showing how to explain the complex notion of zero-knowledge proof in a simpler way that children can understand. In the same line of work, this article presents simple and intuitive explanations of various modern security concepts and technologies, including symmetric encryption, public key encryption, homomorphic encryption, intruder models (CPA, CCA1, CCA2), and security properties (OW, IND, NM). The explanations given in this article may also serve in demystifying such complex security notions for non-expert adults.
Authentication is a process by whichaparty (could be a person or intended computer) establishes its identity to another party. In private and public communication channels including the Internet, authentication is usually done via the use of login passwords. Knowing of the password is supposed to guarantee that the user is authentic. Online business and many other deals need a stricter authentication procedure. With this type of protocols, many cryptographic operations, such as; authentication, identification, key exchange, etc. are implemented without presenting any secret information through the commination process. In this article, a novel approach for zero knowledge protocol is proposed using different perspective. The category of ring theory is adopted to design a new algorithm for zero knowledge proof using the Ď-Armendariz rings. The key idea of our algebraic zero knowledge protocol is the condition in the definition of this ring, in addition to its the properties. The proposed approach used a secret polynomial whose coefficients are in a Ď-Armendariz ring, this polynomial is kept by the prover and the algebraic zero knowledge protocol does not reveal any information about the polynomial.