Cloud computing dynamically provides high quality cloudbased secure services and applications over the internet. The efficient sharing of secure cloud storage services (ESC) scheme which allows the upper-level user to share the secure cloud storage services with multiple lower-level users. In hierarchical identity-based architecture, the sender needs to encrypt a file only once and store only one copy of the corresponding ciphertext in a cloud. The lower-level user needs to decrypt a file which will increase the computational overhead, because the lower-level user does not perform any partial decipherment. In this paper, we propose a Trapdoor commitment scheme that enables a lower-level user to send a short trapdoor to the cloud service provider before retrieving files. This scheme allows the CSP to participate in the partial decipherment, so as to reduce computational overhead on the users without leaking any information about the plaintext. If a lower-level user wants to retrieve a file with limited bandwidth, CPU and memory, the trapdoor which will largely helps to reduce computational power.
Provable data possession (PDP) is a technique for ensuring the integrity of data in storage outsourcing. In this paper, we address the construction of an efficient PDP scheme for distributed cloud storage to support the scalability of service and data migration, in which we consider the existence of multiple cloud service providers to cooperatively store and maintain the clients' data. We present a cooperative PDP (CPDP) scheme based on homomorphic verifiable response and hash index hierarchy. We prove the security of our scheme based on multiprover zero-knowledge proof system, which can satisfy completeness, knowledge soundness, and zero-knowledge properties. In addition, we articulate performance optimization mechanisms for our scheme, and in particular present an efficient method for selecting optimal parameter values to minimize the computation costs of clients and storage service providers. Our experiments show that our solution introduces lower computation and communication overheads in comparison with noncooperative approaches.
It is our contention that the authors of many clinical trials in anesthesia are not fully considering the implications of the minimum effect size of interesta entered in their power calculations, and are therefore making conclusions that are not supported by their findings. In this paper we use hypothetical examples to explain how the choice of minimum effect size of interest in the design of clinical trials sets conditions on their interpretation, including the threshold for clinical relevance, the magnitude of effect sizes that can be confidently excluded, and the discrimination between primary and secondary outcomes. We then use examples from a sample of recent highly cited anesthesia trials to show that this is a problem, which as a specialty we should be addressing. THE MINIMUM EFFECT SIZE OF INTEREST IN THE DESIGN OF CLINICAL TRIALS Let us suppose that a group of researchers wishes to investigate whether a new short-acting antihypertensive drug has a clinically worthwhile treatment effect for the attenuation of the arterial blood pressure response to tracheal intubation. The first step in planning their study is to estimate the sample size required to detect a clinically worthwhile difference for their primary outcome (in this case the blood pressure response), with adequate power.1–4 The alternative, using a confidence interval (CI) approach, is to predefine an acceptable CI width for the primary outcome.b5,6 After careful consideration of all factors, including drug costs, they decide that the minimum clinically worthwhile difference or “threshold for clinical relevance” is 10 mm Hg. This is their minimum effect size of interest. They perform a t test with a null hypothesis that there is no difference between the new drug versus control. They accept a type I error rate of 5% (α = 0.05; i.e., P < 0.05 will be considered significant), and a type II error rate of 20% (β = 0.2, i.e., power = 80% [power = the probability of getting a statistically significant result if there is a true difference ≥ the specified minimum effect size of interest]).1–4 They anticipate that the SD in both groups will be about 10 mm Hg. With these variables they require n = 16 in each group.7 (If they had chosen a minimum effect size of interest = 5 mm Hg, they would have required n = 63 in each group; alternatively, with n = 16 in each group, their power would be reduced to around 29%.)7 THE ROLE OF THE MINIMUM EFFECT SIZE OF INTEREST IN THE INTERPRETATION OF CLINICAL TRIALS Scenario 1: No Significant Difference In a hypothetical scenario, the authors find that the mean difference is 6 mm Hg (95% CI −0.4 to 12.4 mm Hg), P = 0.06. They accept (or more correctly, fail to reject) their null hypothesis and conclude that there is “no difference” between the groups. This conclusion is not correct. A nonsignificant finding does not support a conclusion of no difference without qualification.2–4,6 Nonsignificant findings are qualified by the minimum effect size of interest entered in the power calculation, and the power. This is because the minimum effect size of interest entered in the power calculation is also the “minimum detectable difference” of the trial.1–4 The trial does not exclude or confirm a difference up to this value (in this case 10 mm Hg). Moreover, the power (1 – β, in this case 80%) defines the likelihood of a type II error (β, in this case 20%). In other words, in this scenario there is still a 20% chance that there is a true difference ≥10 mm Hg, even though the investigators failed to find a statistically significant difference. This is very different from an unqualified conclusion of “no difference”! Moreover, while the null hypothesis may not have been rejected, the actual P value continues to provide important information about the probability of observing the finding (or one more extreme) given that the null hypothesis is true. For example, in this case the probability is 6%; in contrast, if the P value were 0.6 rather than 0.06, it would be 60%. Furthermore, the observed point estimate and its 95% CI remain the best estimate of the difference between groups, whether or not statistical significance is reached. For example, an observed 95% CI of −5.4 to 7.4 mm Hg would likewise have been “not statistically significant,” but would have suggested that the true point estimate is closer to 1 mm Hg, which would be very different than the actual example, where the most likely point estimate is about 6 mm Hg. The importance of the minimum effect size of interest and power when interpreting nonsignificant findings becomes clearer when we consider the possibility of smaller true effect sizes. For example, let us say that the drug cost turns out to be lower than expected and that most clinicians would accept a 5 mm Hg difference as clinically worthwhile, rather than the 10 mm Hg used by the authors. How then does the information from this trial help them in their decision whether to use the drug? The answer is very little. The trial was designed to have sufficient probability of detecting a difference, given that the true difference is ≥10 mm Hg. It provides little information on the probability of detecting a difference, given a true difference <10 mm Hg. Scenario 2: Significant Difference and Observed Effect ≥ Minimum Effect Size of Interest In another hypothetical scenario, the authors find a mean difference of 12 mm Hg (95% CI 0.5 to 23.5 mm Hg), P = 0.04. They reject their null hypothesis (acknowledging a 5% chance that they are making a type I error) and correctly conclude that there is a statistically significant treatment effect. They also correctly conclude that this treatment effect is likely to be clinically worthwhile, because the point estimate is at least as large as their predefined minimum clinically worthwhile difference (= minimum effect size of interest stipulated in their power calculation). Scenario 3: Significant Difference and Observed Effect < Minimum Effect Size of Interest In yet another hypothetical scenario, the authors find a difference of 6 mm Hg (95% CI 0.3 to 11.7 mm Hg), P = 0.04. They correctly conclude that there is a statistically significant treatment effect. But what should they conclude about whether the effect is clinically worthwhile? The hypothesis they tested was that there was no difference between the groups (null). The P value <0.05 supports rejection of this hypothesis. However, it does not provide information on the likely magnitude of the effect or whether it is clinically worthwhile. To assess whether the observed effect size is worthwhile, it is necessary to refer to the minimum clinically worthwhile difference decided before the trial began, and which was entered as the minimum effect size of interest in the power calculation (in this case 10 mm Hg). Therefore, the correct conclusion is that while there is a statistically significant effect in this particular trial (i.e., P < 0.05), the observed effect (6 mm Hg) is too small to be clinically worthwhile (i.e., <10 mm Hg). The authors may not accept this conclusion. They may argue that the 95% CI around their point estimate of 6 mm Hg includes 10 mm Hg, so their finding is still compatible with a clinically worthwhile difference. However, they would have to concede that the same 95% CI would be compatible with a range of effect sizes as small as 0.3 mm Hg, and that the true effect size is most likely closer to the point estimate of 6 mm Hg (i.e., <10 mm Hg). The authors may also argue that their original 10 mm Hg was not a true minimum clinically worthwhile difference, and was chosen only for pragmatic reasons to limit the required sample size. They may argue that 5 mm Hg is a more realistic value in any case. However, their trial did not have adequate power (i.e., only around 29%) to detect a ≥5 mm Hg difference.7 The authors may argue that the power is now irrelevant, because they have observed a statistically significant difference. This is a misconception, because there is no guarantee that a repeat trial with the same sample sizes would provide another significant result.8,9 The likelihood of reproducing a significant result (assuming that a true difference ≥ the stipulated minimum effect size of interest exists) is equal to the power of the trial.8 For example, with 80% power, if the trial were repeated using different samples of the same size, there would be an 80% chance of again observing a significant difference.8 In contrast, with 29% power, the likelihood would be only around 29%.8 It would be difficult to be conclusive about any finding with this low level of replicability. For this reason, the power of a study is important for both negative and positive findings. Reducing the minimum effect size of interest after the fact reduces the power, thereby reducing the likelihood of replicating a finding. In effect, the authors are faced with a dilemma. Either they accept that the observed effect size is too small to be clinically worthwhile, or they accept that they cannot be confident that the finding has >80% chance of being repeated. Neither of these supports a conclusion of a reproducible clinically worthwhile effect. THE MINIMUM EFFECT SIZE OF INTEREST AND PRIMARY VERSUS SECONDARY OUTCOMES Let us say the authors also assessed the heart rate (HR) response, but because this was a secondary outcome, they did not perform a power calculation. They found that the mean difference in HR was 6 beats per minute (bpm) (95% CI −1 to 13 bpm), P = 0.10. How should they interpret this finding? To interpret it correctly they need to refer to the minimum effect size of interest (= minimum detectable difference) in the power calculation and the power. Clearly, if these values are not presented, it is not possible to make a meaningful interpretation. Similarly, it would be difficult to interpret a P value <0.05, because without knowing the power and the minimum effect size of interest, it would not be clear how likely the result could be replicated.8,9 Unfortunately, it is not possible to extrapolate power from other outcomes.8,9 Moreover, it is not appropriate to perform a power calculation once the results are already known.6 The authors may argue that a power calculation is not necessary, because the CI alone provides sufficient information. This is another misconception. The CI does not provide sufficient information on the adequacy of the sample size, a major determinant of the CI width.5,6 Perhaps a larger sample size for the HR outcome (with the same sample variability) would have reduced the CI width around the same point estimate sufficiently for the lower limit to be above zero? In fact, ensuring an adequate sample size is equally important using CI as it is using inferential tests, as is predefining a clinically worthwhile difference.5,6 For these reasons, it is not possible to make conclusions about secondary outcomes, unless they are accompanied by this information.9,10 They might still be important (depending on the point estimate and the actual P value or the 95% CI), but remain as “observations” until confirmed or excluded in future studies.9,10 Nevertheless, let us say that in this particular trial the authors made conclusions about both blood pressure and HR responses without specifying which was the primary outcome. A quick check of the minimum effect size of interest would identify the blood pressure response as the primary outcome (i.e., the outcome for which the power had been calculated, the sample size estimated, and the threshold for a clinically worthwhile difference set).9 In this way the minimum effect size of interest discriminates between primary and secondary outcomes. A SAMPLE OF HIGHLY CITED ANESTHESIA TRIALS We identified 20 highly cited prospective anesthesia trials by interrogating the ISI Web of knowledge (http://apps.isiknowledge.com/, accessed December 2010) using the following search strategy: topic = anesthesia or anaesthesia; journal = Lancet, New England Journal of Medicine, Anesthesiology, Anesthesia and Analgesia, or British Journal of Anaesthesia; year of publication = 2001 to 2010, with ranking of trials by number of citations.11–30 Publications other than prospective clinical trials were excluded. We scrutinized the top 20 most cited trials for conclusions that were not supported by the minimum effect size of interest stipulated in their power calculations. We did not recheck any statistical analysis or assess any other aspect of the trials. Conclusions Based on Secondary Outcomes There were 10 trials that based 1 or more conclusions on secondary outcomes (for which no minimum effect size of interest or power was provided) (Table 1).15,17,18,21,22,24,27–30 Three trials even included the findings of a secondary outcome in their title (Table 1).15,17,27 In many cases, it was not possible to differentiate between primary and secondary outcomes without reference to the minimum effect size of interest in the power calculation.Table 1: Studies that Include Secondary Outcomes in Their ConclusionsConclusions Based on Statistically Significant Findings too Small to Be Clinically Worthwhile There were 5 trials with statistically significant findings for their primary outcome, but with an observed effect size less than their minimum effect size of interest (Table 2).13,17–19,30 For example, Myles et al. chose a minimum effect size of interest of 0.9% “because uptake into routine practice would require convincing proof of benefit.“13 Yet they observed a mean effect size of only 0.74%.13 Similarly, Carli et al. specifically chose a “minimum effect size of interest” of 36 m walked in 6 minutes, because this difference produced “a meaningful impact” on long-term exercise capacity.17 Yet they observed a mean difference of only 33.6 m at 3 weeks, and 18 m at 6 weeks.17 Neither Myles et al. nor Carli et al. concluded that their observed effect was too small to be clinically worthwhile. Similar considerations apply to the other 3 trials in this category (Table 2).18,19,30 Only Myles et al. presented the 95% CI for their observed effect size. The remainder either presented no CI for the observed effect size, or presented CI in a different metric to the minimum effect size of interest (Table 2).Table 2: Studies with a Statistically Significant Primary Outcome but an Observed Effect Size Less than the Minimum Effect Size of InterestConclusions Based on Nonsignificant Findings—Unable to Exclude All Clinically Worthwhile Effect Sizes Four trials had nonsignificant findings for their primary outcomes (Table 3).11,22,26,27 Scrutiny of their minimum effect size of interest indicated that none could confidently exclude all clinically worthwhile effect sizes. For example, they were powered to detect differences in the incidence of morbidity and mortality ≥10%, length of stay ≥2.5 days, awareness incidence ≥0.9%, and block success rate ≥23%, respectively. Yet effect sizes below these ranges might still be considered clinically worthwhile. (e.g., mortality and morbidity reduction of 9%, length of stay reduction of 2 days, incidence of awareness reduction of 0.8%, block success rate improvement of 22%). Only Rigg et al. explained that they could not confidently exclude the possibility of a worthwhile true effect size less than the minimum effect size of interest stipulated in their power calculation.11 Only Avidan et al. presented the 95% CI for their observed effect size (which was instead of a P value from an inferential test).26Table 3: Studies with Nonsignificant Findings for the Primary OutcomeConclusions Based on Findings with no Power Analysis or Stipulation of Minimum Effect Size of Interest There were 4 trials with no power calculation or minimum effect size of interest for any outcomes.12,16,23,25 None of these explained that their findings could not be fully interpreted without this information. CONCLUSION To fully interpret a clinical trial in which inferential statistics are used, it is necessary to go beyond effect size, and consider also the minimum effect size of interest stipulated in the power calculation. This is an important value, which not only has a major influence on the required sample size, but also defines the threshold for clinical relevance for positive findings, and the minimum detectable difference for negative findings (Fig. 1). Readers should also scrutinize the value chosen by the authors, to determine if it is appropriate. Failure to consider the minimum effect size of interest may result in erroneous conclusions, such as conclusions based on secondary outcomes, on outcomes that are statistically significant but not clinically worthwhile, or on nonsignificant findings that do not exclude the possibility of a smaller, but nevertheless true clinically worthwhile treatment effect. We have provided examples of such conclusions in a sample of highly cited anesthesia trials in a selection of high-impact-factor journals. Given their criteria for selection, it is unlikely that these trials represent a negatively biased sample in terms of quality of statistical reporting. We suspect that similar findings would be found in any sample of anesthesia trials. To address this situation, we recommend greater rigor in the design and interpretation of clinical trials, with closer scrutiny of the minimum effect size of interest (by both authors and readers), adequate power, and a focus on primary rather than secondary outcomes. For key secondary outcomes, we recommend that additional a priori power calculations be provided, along with their minimum effect sizes of interest. The use of CI for the observed effect size has advantages, because CI provide information on the most likely true effect size and the range of likely true effect sizes for both primary and secondary outcomes. Nevertheless, the same principle of defining the minimum clinically worthwhile effect size before the trial commences applies, as well as holding to this value when interpreting outcomes, and ensuring that an adequate sample size was used.Figure 1: The central role of the minimum effect size of interest in the design and interpretation of clinical trials. Once chosen, the minimum effect size of interest determines the sample size required (for any given level of power, α, and sd of the samples). The threshold for clinical relevance for the observed effect size and the minimum effect size detectable (given the power) are mathematically equal to this value. As sample size cannot be changed once the trial is completed, none of the values can be altered post hoc without affecting the trial's power.DISCLOSURES Name: Neville M. Gibbs, MD, FANZCA. Contribution: Study design, conduct of study, data analysis, and manuscript preparation. Name: William M. Weightman, MB, FANZCA. Contribution: Study design, conduct of study, data analysis, and manuscript preparation. This manuscript was handled by: Franklin Dexter, MD, PhD.
The disadvantage of previous multi-coupon schemes is the lack of efficient protocol in which users can decide the maximal number of redemption according to their demands.And another deficiency is that they cannot remain secure in the concurrent case.This article remedied these obstacles by providing two improved systems with concurrent security.The first scheme was obtained by extending the underlying scheme of Blanton with the proof of two committed values and the Sigma-compiler for two round concurrent zero-knowledge argument.The second scheme(i.e.,the strengthened version of the first one) achieved more efficient security reduction by incorporating the straight-line extraction paradigm and removed random oracles by using the non-interactive zero-knowledge argument from homomorphic encryption.Compared with the other strongly unsplittable schemes,the first scheme has better communicational efficiency and the second one does not rely on the random oracle model.
Climate change—fears of it; predictions about it; proposed reactions to it; and in some cases, denials of it—is a momentous issue for humanity, and it promises to become even more important. However, despite its importance—and mountains of scientific research on the topic—real progress by those with the means to address climate change has been slow in coming. The warming climate, with its accompanying intense weather, rising seas, and wrenching changes in agriculture, human health, and ecosystems in general, is not a recent discovery. Scientists and policymakers have been talking about it for decades. Climate scientists have produced reams of information about the change that is upon us—some showing that the shift is well under way, some offering ideas about how to cope with it by mitigating its effects or by adapting to it. Scientists are starting to develop the tools necessary to discover links between global change and specific local events, such as floods and droughts. Much of the US-based research is directed at people who make political decisions: members of Congress, the president, state legislators, municipal officials. But whereas the flow of information from scientists has been copious, the response from policymakers, including those at the topmost positions in government, has been minuscule. Interest in preparing for climate change seems to have been superseded by concerns about the economy. But the problems of a changed climate march on (see National Research Council definitions box), and at some point, policymakers will have to deal with them. As far back as 1978, Congress passed the National Climate Program Act in response to a need “to assist in the understanding and response to natural and man-induced climate processes and their implications.” The legislation stated that “Congress finds and declares” that “an ability to anticipate natural and man-induced changes in climate would contribute to the soundness of policy decisions in the public and private sectors,” and that “the United States lacks a well-defined and coordinated program in climate-related research, monitoring, assessment of effects, and information utilization.” Today, after dozens of data-heavy reports on climate change, bolstered by the work of the Intergovernmental Panel on Climate Change (IPCC), the crisis remains unaddressed, in large part because the issue has become a partisan arguing point—increasingly so as a presidential election looms. In April 2011, the House of Representatives considered action stating that “Congress accepts the scientific findings… that climate change is occurring, is caused largely by human activities, and poses significant risks for public health and welfare.” The national legislators voted the proposition down 240 to 184, largely along party lines. Scientists who study climate change, then, are left with the following question: How do we communicate in a meaningful way with policymakers? Climate change, in the United States and elsewhere, covers most areas of the human experience. A report from the US National Research Council lists the following areas of concern: changes in the climate system; sea-level rise and its effects on the coastal environment; freshwater resources; ecosystems, ecosystem services, and biodiversity; agriculture and aquaculture; public health; cities and the “built environment”; transportation systems; energy systems; solar radiation management; national and human security; and climate policy. First of all, says Pamela A. Matson, an interdisciplinary earth scientist at Stanford University, scientists should not tell policymakers what to do. Matson chaired one of four expert panels charged by the US National Academies in 2009 with studying climate change and recommending responses to it. The panels—Limiting the Magnitude of Future Climate Change, Adapting to the Impacts of Climate Change, Informing an Effective Response to Climate Change, and Advancing the Science of Climate Change—each produced extensive reports. Together, these reports and a summary volume form a solid tutorial on the challenges facing the nation (see For more information). Matson headed the Advancing the Science of Climate Change panel. “We can't do much about politics,” said Matson in an interview, “other than to keep reminding people that there is a huge amount of evidence about climate change, its causes, and the risks associated with it. Decisionmakers of all sorts will need to decide if they want to take the risks and expose future generations to even greater risks, but scientists can do our best to provide the best and most clear information about those risks and uncertainties. We can also help by providing viable options for reducing those risks—options that make sense from social, economic, technical, and environmental perspectives. The Advancing report calls for more research designed to develop such options and thus support decisionmakers who want to respond to the risks of climate change by limiting it and adapting to it.” In practically all of the heavyweight studies of climate change, including those in the National Academies quartet, the panelists assumed that the federal government is the logical leader in climate policymaking, if only because climate does not respect local boundaries (or international ones either). But there are scant signs of leadership from federal officials, and there is active opposition to any climate action (or even the notion that climate change exists) among some national legislators. Progress at the federal level, says Peter Raven, cochair of the National Academies panel Informing Decisions and Actions, is missing. His panel recommended that the federal government create “comprehensive, robust, and credible information systems to inform climate choices and evaluate their effectiveness.” “My impression,” said Raven recently, “is that it hasn't happened. The United States is the only nation in the world where serious doubt is expressed about the scientific conclusion that the climate is warming rapidly and that human beings are the principal underlying factor. That kind of anti-intellectualism can only hurt as we try to maintain our standing in science and technology against some very stiff competition internationally.” Robert Fri, visiting scholar at Resources for the Future, chaired the Limiting the Magnitude of Future Climate Change panel, which recommended “a framework of national goals and policies” to limit greenhouse gases. Asked about the report's reception, he replied, “Policy attention has been focused on the economy recently. Not much has happened on the climate front as a result.” So the search for leadership has turned elsewhere—to local, state, and regional governments and private organizations. Several states have undertaken serious studies of climate change problems, many of them as a result of gubernatorial executive orders issued a few years ago, when climate change was considered less controversial. Some went a step further and set up commissions to recommend legislative action. The results of those efforts have been mixed; the economic crisis has sapped much of the climate change energy of local, as well as national, politicians. Arizona's Policy on Climate Change, instituted on 2 February 2010, under Governor Jan Brewer, seeks to reduce greenhouse gas emissions “while maintaining Arizona's economic growth and competitiveness.” Yet in the same executive order that established the policy, Brewer pulled her state out of a promising regional effort, the Western Climate Initiative, to limit the gases. The 15-member commission created by Brewer's executive order included representatives of electric power, manufacturing, and mining companies, but no scientists. Arctic sea ice reaches its annual minimum in September. The satellite images above show September Arctic sea ice in 1979 (upper panel), the first year these data were available, and in 2007 (lower panel). Source: US Global Change Research Program (www.globalchange.gov). For a free download of the National Academies 2009 expert panel reports and a summary volume, among other reports on climate, go to www.nap.edu. A 1990 law created the National Climate Assessment, which evaluates federal global research programs. The most recent assessment was in 2009; to see an outline of the forthcoming 2013 report, visit http://globalchange.gov/what-we-do/assessment. Information on climate research may be found through the US Global Change Research Program Web site, at http://globalchange.gov/. The Pew Center on Global Climate Change publishes the “Climate Change 101” series, available at www.pewclimate.org/globalwarming-basics/climate_change_101. For detailed state reports on plans and recommendations for adaptation, see Massachusetts's at www.mass.gov/eea/docs/eea/energy/cca/eea-climate-adaptation-report.pdf. For a critical look at America's willingness to adapt to climate change, see Robert Repetto's 2008 report for the Yale School of Forestry and Environmental Studies at http://environment.yale.edu/publication-series/climate_change/5790. The Colorado Climate Project created a blue-ribbon action panel in 2007 that, a year later, produced 70 recommendations for reducing greenhouse gas emissions and preparing for the coming changes. The panel's efforts appear to have been received favorably by policymakers. Texas, beset by wildfires in 2011 that some experts linked to climate change, has no state adaptation plan, according to a survey by the Pew Center on Global Climate Change. Texas leads the states in carbon dioxide emissions. In Connecticut, the Governor's Steering Committee on Climate Change says that it is “working with stakeholders” and “assessing the impacts of climate change.” However, the committee's Web site devotes approximately half of its space to thanking the company that designed its logo. Massachusetts has made a more strenuous effort. In September 2011, the state sent a report to its legislature in which the expected impacts were analyzed and suggestions were made for reactions to them. The proof of the pudding in Massachusetts, as in the nation as a whole, lies in what happens after the recommendations go to the policymakers. In the Bay State, that would include the office of Frank I. Smizik, the chair of the House Committee on Climate Change. Smizik believes that climate change is going to affect “every corner of our lives,” is already creating problems, and is “one of the most complex and interrelated problems we face. And that makes it even more of a challenge to confront.” In an interview, the legislator praised the state's framework report both for its “long-term and far-reaching strategies” and for the “small, incremental improvements we can make at little or no cost. This aspect of the report makes the necessary task of climate adaptation seem more feasible.” Does this mean that Massachusetts's policymakers will rush to enact laws to deal with the well-documented menace? “Ideally, the need to adapt to climate change will be taken seriously, and these strategies will be swiftly transformed into reality in Massachusetts,” said Smizik. “Realistically, it won't be that easy. My job as the Chair of the House Committee on Global Warming and Climate Change is to advocate for the strategies that I think are not only most effective but also the most politically feasible at this time. I could see some of the more short-term, cost-effective strategies making progress in the State House as legislative packages. Meanwhile, some strategies will be directly implemented by state agencies. “I feel these issues are very pressing and they warrant our immediate attention. But… the legislating and governing process takes time, with good reason. The release of this adaptation report is an important step for our state, but it's hard to say how quickly or slowly these adaptation measures will become law. The economic climate is such that legislators are very focused on job creation and the like, and environmental issues are often pushed to the back burner in this situation.” The state of Washington is another place where policymakers take climate change seriously. Hedia Adelsman is the director of the state's Department of Ecology. Her predecessor in that job was Christine Gregoire, who went on to become the state's attorney general and then governor. Adelsman credits Gregoire with helping move climate awareness into action. Also, the University of Washington produced an exhaustive examination of climate change and ways to react to it that has served as a vital resource for legislators and other policymakers. Within 50–100 years, 2400 miles of major roadway are projected to be inundated by sea-level rise in the Gulf Coast region. The map shows roadways at risk in the event of a sea-level rise of about 4 feet, which is within the range of projections for this region in this century under medium- and high-emissions scenarios. In total, 24 percent of interstate highway miles and 28 percent of secondary road miles in the Gulf Coast region are at elevations below 4 feet. Source: US Global Change Research Program (www.globalchange.gov). Even though Washington is more environmentally conscious than most other states, economic troubles have hampered action on the climate front. “The conversation is not as active as it used to be,” said Adelsman in an interview, “[for] a couple of reasons: One of them—no surprise—is all the budget problems that the state is facing. And when you talk about the impact of climate change, people really see it as in the future. And right now we have all these urgent problems facing us. Some of the impacts that would be due to climate change… people don't see as something that's happening now. They see it as happening a little bit more in the future. So they feel like they can get back to it later… But the communication continues. “It all depends on how you describe it,” she said. “If you are describing the problem as a water-availability issue—if we are going to face a major issue with water available for irrigation; for municipal, for our fish, the salmon—you get people to listen. If you talk about it as global warming, it's immediately, ‘go away.’ “It's kind of sad to not call it by what it is, but it's much easier to communicate with the public and with the policymaker if you put it in these terms.” Some, including the authors of the National Research Council's panel Advancing the Science of Climate Change, think that a likely source of federal leadership can come, with a few modifications, from an existing organization: the US Global Change Research Program (USGCRP), which was created in 1989 as a presidential initiative by George H. W. Bush. USGCRP coordinates and integrates the global change work of 13 agencies, from the US Department of Agriculture to the US Department of Defense to the US Environmental Protection Agency and the Smithsonian Institution. Thomas Armstrong, of the White House Office of Science and Technology Policy, is USGCRP's executive director. In an interview, he said that he certainly agreed with the panels' findings. “But the real challenge comes not when you recommend strategic changes but when you get down to the nuts and bolts of implementing programs.” One potential obstacle, he said, could come if 13 agencies, which together receive $2.8 billion in global change research funds, are asked not only to funnel their work through a single office—his—but are made to redirect their agencies' funding as well. “If we were to take this level of enterprise and now say that it is no longer just coordinated but actually run out of my office, with all the resources coming to my office, that would be a big change in our collective way of doing to say the said is the 13 agencies, and the 13 are The of 13 them and a of leadership of this I would be that in their we would be the and of 13 federal who their research and to 13 agencies' In we would be the USGCRP out of what makes this program so the Science in climate information to policymakers. one is the climate change who can of all science in the of some is the of of scientific which scientists by their as does the in of such as very out of out of very than out of and so deal with communication such as these and many there has a of or for a can be government agencies, such as the that produced the state action or state such as Hedia in and federal such as the USGCRP they can be such as the regional Climate Science that were established in 2009 by the US Department of the The are by the US and by one or more significant of communication is by private and the Pew Center on Global Climate Change, which has been to and information on climate Climate an of and a for natural systems in the face of climate change.” The which a large of for for adaptation, dozens of studies from The appear to be some in scientific information into the of those who already want to it in their program director at the Climate for the part of a regional program run by the National and says that it that are more with decisionmakers much to the in of decisions that may be to scientific for something more to We certainly people who are out scientific information to make decisions that help them deal with of these decisions to the that has the region for years and are vital to policymakers who deal with water does a of its when public and private including a to a are also for scientific about adaptation and a then, is on the that climate change is important. are who for one or climate or climate change as something they really need to more about into their it's because a to attention to of the US Department of the have been under orders now to make climate change part of their it's because an like their is to the impacts of climate, and they want to more so they can to address this it's because an or government has a climate impact that them into The is an of as is in the United States and for how are projected to become more A so that it is years would other year or more by the of the century under the Source: US Global Change Research Program (www.globalchange.gov). But on many other the science of climate change has a much was one of states that active in the issue of climate change State and a the on Global Climate Change and it with the problems of global warming, as well as with into ways to the and with the potential of carbon The commission for years and up with the of that time, the legislature to the commission to its State who was cochair of the now says that the effort. in the way of the scientific evidence and any for doing about a she said in an “We a from the with the of so They all up and to recommend of We a very large and it was so it was to Even with she said, that make it out of her at the As the climate that are to Source: US Global Change Research Program (www.globalchange.gov). says that opposition to progress from and such as the and who of the US are major of and “It was she said. “I could get an passed that that our state the impact of climate change and make recommendations as to policy changes and other even any to deal with I that we would be that climate change is an issue in will see little to no to address climate change the leadership is in This is we are the most in the to sea-level she said. In the state is for and has also and said, “We are one of the of greenhouse at in the than many that the state has to a of and has its carbon The for those measures was For climate change legislation to on its she said, “I we will need federal
利用Cha-Cheon 的基于身份的签名方案提出了一个可证安全的基于身份的可验证加密签名(verifiablyencrypted signature,简称VES)方案,并利用该方案和基于身份的代理可验证加密签名(proxy verifiably encryptedsignature,简称PVES)方案提出了一个新颖的多元合同签署协议.信息交换过程中,原始签名者或代理签名者分别利用VES 或PVES 实现承诺消息的交换与认证,并未使用复杂的零知识证明系统,从而有效避免了大量运算.当争议发生时,可信第三方从VES 或PVES 中恢复出有效的合同签名,以保证签署者的公平性.安全性分析结果表明,协议满足不可否认性、时效性以及公平性.;Utilizing the Cha-Cheon’s identity-based signature scheme, a provably secure identity-based verifiably encrypted signature (VES) scheme is proposed. Utilizing the proposed scheme and identity-based proxy verifiably encrypted signature (PVES) scheme, a novel multiplex contract signing protocol is also proposed. The original signer or proxy signer uses VES or PVES to realize the interaction and certification of the commitment message in the information exchange process. The proposed scheme does not need the zero-knowledge proof and excessive computation. An optimized trusted third party who participates in the protocol extracts the formal signature from the VES or PVES only when problem occurs. The performance analysis results show that the scheme satisfies non-repudiation, timeliness and fairness.
A new ID-based group signature scheme,whose group managers and group members are all ID-based,is presented.Because the scheme does not require zero knowledge proof and the group signature is generated by a group member in collaboration with the group manager,the scheme has the advantages of simple structure,short signature length,concurrent join of users,immediate revocation of group members,easy tracing of group signatures.
Abstract. In this study, a novel pairing based strong designated verifier signature scheme based on non-interactive zero knowledge proofs is proposed. The security of the proposal is presented by sequences of games without random oracles; furthermore, this scheme has a security proof for the property of privacy of the signer’s identity in comparison with the scheme proposed by Zhang et al. in 2007. In addition, this proposal compared to the scheme presented by Huang et al. in 2011 supports non-delegatability. The non-delegatability of our proposal is achieved since we do not use the common secret key shared between the signer and the designated verifier in our construction. Furthermore, if a signer delegates her signing capability which is derived from her secret key on a specific message to a third party, then, the third party cannot generate a valid designated verifier signature due to the relaxed special soundness of the non-interactive zero knowledge proof. To the best of our knowledge, this construction is the first attempt to generate a designated verifier signature scheme with non-delegatability in the standard model, while satisfying of non-delegatability property is loose.
The paper contains main concepts of the interactive proof theory and suggests zero-knowledge proof of Diffie–Hellman problem solution with bilinear maps.
Silicon as a mono-crystalline bulk semiconductor is today the predominant material in many integrated electronic and photovoltaic applications. This has not been the case in lighting technology, since due to its indirect bandgap nature bulk silicon is an inherently poor light emitter.With the discovery of efficient light emission from silicon nanostructures, great new interest arose and research in this area increased dramatically.However, despite more than two decades of research on silicon nanocrystals and nanowires, not all aspects of their light emission mechanisms and optical properties are well understood, yet.There is great potential for a range of applications, such as light conversion (phosphor substitute), emission (LEDs) and harvesting (solar cells), but for efficient implementation the underlying mechanisms have to be unveiled and understood.Investigation of single quantum emitters enable proper understanding and modeling of the nature and correlation of different optical, electrical and geometric properties.In large numbers, such sets of experiments ensure statistical significance. These two objectives can best be met when a large number of luminescing nanostructures are placed in a pattern that can easily be navigated with different measurement methods.This thesis presents a method for the (optional) simultaneous fabrication of luminescent zero- and one-dimensional silicon nanostructuresand deals with their structural and optical characterization.Nanometer-sized silicon walls are defined by electron beam lithography and plasma etching. Subsequent oxidation in the self-limiting regime reduces the size of the silicon core unevenly and passivates it with a thermal oxide layer.Depending on the oxidation time, nanowires, quantum dots or a mixture of both types of structures can be created.While electron microscopy yields structural information, different photoluminescence measurements, such as time-integrated and time-resolved imaging, spectral imaging, lifetime measurements and absorption and emission polarization measurements, are used to gain knowledge about optical properties and light emission mechanisms in single silicon nanocrystals.The fabrication method used in this thesis yields a large number of spatially separated luminescing quantum dots randomly distributed along a line, or a slightly smaller number that can be placed at well-defined coordinates. Single dot measurements can be performed even with an optical microscope and the pattern, in which the nanostructures are arranged, enables the experimenter to easily find the same individual dot in different measurements.Spectral measurements on the single dot level reveal information about processes that are involved in the photoluminescence of silicon nanoparticles and yield proof for the atomic-like quantized nature of energy levels in the conduction and valence band, as evidenced by narrow luminescence lines (~500 µeV) at low temperature. Analysis of the blinking sheds light on the charging mechanisms of oxide-capped Si-QDs and, by exposing exponential on- and off-time distributions instead of the frequently observed power law distributions, argues in favor of the absence of statistical aging. Experiments probing the emission intensity as a function of excitation power suggest that saturation is not achieved. Both absorption and emission of silicon nanocrystals contained in a one-dimensional silicon dioxide matrix are polarized to a high degree. Many of the results obtained in this work seem to strengthen the arguments that oxide-capped silicon quantum dots have universal properties, independently of the fabrication method, and that the greatest differences between individual nanocrystals are indeed caused by individual factors like local environment, shape and size (among others).
This paper focuses on the robustness of concurrent non-malleable zero-knowledge.Existing concurrent non-malleable zero-knowledge protocols either apply non-black-box techniques,or employ black-box but incorporate a zero-knowledge sub-protocol.Hence when concurrently composed with other protocols,security of these protocols is not preserved or hard to argue.Following the well-known Feige-Shamir style,this paper presents a new construction for concurrent non-malleable zero-knowledge argument system,which is easily composed.This protocol takes the robust non-malleable commitment scheme introduced by Lin and Pass in STOC 2009 and specially designed witness indistinguishable proofs as basic components to achieve non-malleability and robustness.Moreover,this paper applies the oblivious simulation strategy to simulate the view of the adversary,and the proof technique introduced by Lin et al.in Crypto 2010 to analyze the indistinguishability of simulation.Since witness indistinguishability is closed under concurrent composition,the commitment sub-protocol is robust and the is oblivious,when concurrently composed with other protocols,this protocol is easier to work with and analyze.Based on the one-way function assumption,the round complexity of this protocol is super-logarithmic.
We present a general framework for constructing non-interactive universally composable (UC) commitment schemes that are secure against adaptive adversaries in the non-erasure setting under a single re-usable common reference string. Previously, such “fully-equipped ” UC commitment schemes are only known in [8, 9], with an unavoidable overhead of O(κ) in the sense of communication and computational complexities; meaning that to commit λ bits, the communication and computational costs require O(λκ), where κ denotes the security parameter. Efficient construction of a fully-equipped UC commitment scheme was a long-standing open problem. We introduce a cryptographic primitive, called all-but-many encryptions (ABMEs), and prove that it is a translation of fully-equipped UC commitment in the primitive level. We then construct ABMEs from cryptographic primitives that we call a probabilistic pseudo random function family and extractable sigma protocols – the former is a probabilistic version of a pseudo random function family and the latter is a special kind of sigma (i.e., canonical 3-round public-coin HVSZK) protocols with some extractability. We provide fully-equipped UC commitment schemes from ABMEs under DDH and DCR-based assumptions, respectively. In particular, the DCR-based scheme is the first fully-equipped UC commitment scheme with optimal expansion factor Ω(1); to commit κ bits, the communication and computational costs are Ω(κ). We further construct a fully-equipped UC commitment scheme from a general assumption (in which trap-door permutations exist), which is far more efficient than the previous construction [9], because, unlike [9], our construction does not require non-interactive zero-knowledge proof systems. 1
Pascal Weibel, Miriam Ender, Jerzy Madon, Annelies S. Zinkernagel · 5 authors
Introducing PCR products into plasmids vectors is key for molecular techniques. Ideally cloning vectors are easy to construct, modify and propagate, neither require advanced techniques nor special equipment or reagents and efficiently incorporate PCR products at close to zero empty vector background. We provide an easy to engineer self-made cloning vector, neither requiring sophisticated tools or techniques nor advanced cloning knowledge. Through recombination we obtained the pUC18ccdB vector, carrying the ccdB suicide gene within the pUC18 backbone. When SmaI cleaved (within the ccdB) vector was T4 ligated with small (0.2 kbp) and intermediate (1.3 to 2.2 kbp) blunt end PCR-products and transformed into E. coli, the amount of clones with incorporated PCR product was comparable to commercial PCR-cloning kits and at a close to zero PCR product negative background. In conclusion we present a simple, versatile and cheap approach to an efficient “home made ” PCR-cloning vector that allows integration of crude blunt end PCR products at close to zero background.
We introduce the concept of identity-based encryption (IBE) with master key-dependent chosenplaintext (mKDM-sID-CPA) security. These are IBE schemes that remain secure even after the adversary sees encryptions, under some initially selected identities, of functions of the master secret key(s). We then propose a generic construction of chosen-ciphertext secure key-dependent encryption (KDM-CCA) schemes in the public key setting starting from mKDM-sID-CPA secure IBE schemes. This is reminiscent to the celebrated work by Canetti, Halevi and Katz (Eurocrypt 2004) on the traditional key-oblivious setting. Previously only one generic construction of KDM-CCA secure public key schemes was known, due to Camenisch, Chandran and Shoup (Eurocrypt 2009), and it required non-interactive zero knowledge proofs (NIZKs). Our transformation shows that NIZKs are not intrinsic to KDM-CCA public key encryption. Additionally, we are able to instantiate our new concept under the Rank assumption on pairing groups and for affine functions of the secret keys. The scheme builds on previous work by Boneh, Halevi, Hamburg and Ostrovsky (Crypto 2008). Our concrete schemes are only able to provide security against a bounded number of encryption queries, which is enough in some practical scenarios. As a corollary we obtain a KDM-CCA secure public key encryption scheme, in the standard model, whose security reduction to a static assumption is independent of the number of challenge queries. As an independent contribution, we give new and better reductions between the Rank problem (previously named as Matrix DDH problem) and the Decisional Linear and the Decisional 3-Party Diffie-Hellman problems.
Dana Dachman-Soled, Abhishek Jain, Yael Tauman Kalai, Adriana López-Alt
The Fiat-Shamir paradigm [CRYPTO’86] is a heuristic for converting 3-round identification schemes into signature schemes, and more generally, for collapsing rounds in public-coin interactive protocols. This heuristic is very popular both in theory and in practice, and many researchers have studied its security (and insecurity). In this work, we continue this study. As our main result, we show that for many well studied interactive proofs (and arguments) the soundness of the Fiat-Shamir heuristic cannot be proven via a black-box reduction to any falsifiable assumption. Previously, the insecurity of this paradigm was exemplified only when applied to interactive arguments (as opposed to proofs). Using similar techniques, we also show a black-box impossibility result for Micali’s CSproofs [FOCS’94]. Namely, we prove that there exist PCPs such that for “sufficiently hard” NP languages, Micali’s CS-proof cannot be proven sound via black-box reduction to any falsifiable assumption. These results are obtained by extending the impossibility of two-message zero knowledge protocols due to Goldreich and Oren [J. Cryptology’94].
Abstract. In TCC 2007, Adida and Wikström proposed a novel approach to shuffle, called a public shuffle, in which a shuffler can perform shuffle publicly without needing information kept secret. Their scheme uses an encrypted permutation matrix to shuffle ciphertexts publicly. This approach significantly reduces the cost of constructing a mix-net to verifiable joint decryption. Though their method is successful in making shuffle to be a public operation, their scheme still requires that some trusted parties should choose a permutation to be encrypted and construct zero-knowledge proofs on the well-formedness of this permutation. In this paper, we propose a method to construct a public shuffle without relying on permutations and randomizers generated privately: Given an n-tuple of ciphertext (c1,..., cn), our shuffle algorithm computes fi(c1,..., cn) for i = 1,..., ℓ where each fi(x1,..., xn) is a symmetric polynomial in x1,..., xn. Depending on the symmetric polynomials we use, we propose two concrete constructions. One is to use ring homomorphic encryption with constant ciphertext complexity and the other is to use simple ElGamal encryption with linear ciphertext complexity in the number of senders. Both constructions are free of zero-knowledge proofs and publicly verifiable.
In a traditional (t, n)-threshold secret sharing scheme, t or more honest participants can reconstruct the secret K. In the reconstruction process, the individual shares and the secret key K are revealed, hence K is shared once only. In this paper, we firstly give the definition of leakproof secret sharing scheme which is composed of a distribution protocol and a proof protocol, then propose two leakproof secret sharing protocols, a computationally secure protocol and an information-theoretically secure protocol. In our protocols, t or more participants can jointly prove that they hold the secret K by using a multi-prover zero-knowledge argument of knowledge. As a result, the secret K will be shared for as many times as desired. Furthermore, each participant can detect the dealer in the distribution protocol from cheating, and any verifier can prevent non-qualified set of participants in proof protocol from cheating. As an example of the practical impact of our work we use our techniques to construct group identification schemes with zero-knowledge.