Proof of retrievability (POR) is a technique for ensuring the integrity of data in outsourced storage services.In this paper, we address the construction of POR protocol on the standard model of interactive proof systems.We propose the first interactive POR scheme to prevent the fraudulence of prover and the leakage of verified data.We also give full proofs of soundness and zero-knowledge properties by constructing a polynomialtime rewindable knowledge extractor under the computational Diffie-Hellman assumption.In particular, the verification process of this scheme requires a low, constant amount of overhead, which minimizes communication complexity.
In this paper we present a new 5-pass identification scheme with asymptotic cheating probability 1/2 based on the syndrome decoding problem. Our protocol is related to the Stern identification scheme but has a reduced communication cost compared to previous code-based zero-knowledge schemes, moreover our scheme permits to obtain a very low size of public key and secret key. The contribution of this paper is twofold, first we propose a variation on the Stern authentication scheme which permits to decrease asymptotically the cheating probability to 1/2 rather than 2/3 (and very close to 1/2 in practice) but with less communication. Our solution is based on deriving new challenges from the secret key through cyclic shifts of the initial public key syndrome; a new proof of soundness for this case is given Secondly we propose a new way to deal with hashed commitments in zero-knowledge schemes based on Stern's scheme, so that in terms of communication, on the average, only one hash value is sent rather than two or three. Overall our new scheme has the good features of having a zero-knowledge security proof based on well known hard problem of coding theory, a small size of secret and public key (a few hundred bits), a small calculation complexity, for an overall communication cost of 19kb for authentication (for a $2^{16}$ security) and a signature of size of 93kb (11.5kB) (for security $2^{80}$), an improvement of 40% compared to previous schemes based on coding theory.
Vote validity proof and verification is an efficiency bottleneck and privacy drawback in homomorphic e-voting. The existing vote validity proof technique is inefficient and only achieves honest-verifier zero knowledge. In this paper, an efficient proof and verification technique is proposed to guarantee vote validity in homomorphic e-voting. The new proof technique is mainly based on hash function operations that only need a very small number of costly public key cryptographic operations. It can handle untrusted verifiers and achieve stronger zero knowledge privacy. As a result, the efficiency and privacy of homomorphic e-voting applications will be significantly improved.
For anyone interested in the philosophy of riskābenefit analysis, a two-part paper in this issue makes stimulating reading [1, 2]. The authors describe an effect of antidepressants on fetal neuronal development. Maternal exposure to both tricyclic antidepressants and selective serotonin reuptake inhibitors (SSRIs) during pregnancy was associated with a 10-fold increase in laxative use in children. The findings illustrate how safety issues can remain undetected late in the life cycle of a drug, despite millions of patients being exposed for decades. Clinical pharmacology research, as with any science, needs to define questions that summarize the hypotheses to be tested. The efficacy of medicines can be defined by questions that are easy to formulate and are addressed by clinical trials. Even so, the efficacy of antidepressant medication is contentious, given the high placebo response, failure to prevent suicide and selective reporting of results [3, 4]. For safety issues, the key questions are usually not known until the data are collected. With myriad potential safety questions, it is important that all the available basic pharmacology is reviewed and that this knowledge is used to direct a search for specific clinical safety signals. The Groningen group have adopted this approach with a detailed literature review to form a hypothesis that maternal antidepressant use might influence fetal enteric nervous system development [1]. In a second study, they use epidemiology to assess paediatric laxative use as a potential marker of a specific teratogenic signal associated with the maternal use of antidepressants [2]. The starting point for this work was the linking of a small signal of infantile hypertrophic pyloric stenosis cases to the maternal use of fluoxetine in a northern Netherlands birth defect registry. This association is rational, because fluoxetine crosses the bloodābrain barrier and serotonin contributes to the development of enteric neurons. A serotonin-based mechanism could also explain an increased use of laxatives by the children of mothers who had taken an SSRI. When a drug first comes to market, the assessment of the risk-to-benefit ratio is an educated guess. Efficacy can be defined by objective clinical trials, where predefined end-points are quantified. That the efficacy data are invariably adequate at the time of marketing is supported by the rarity of withdrawals of medicines because of later proof of a lack of efficacy. But safety cannot usually be quantified objectively; thus, many parameters might show a signal which can neither be confirmed or ignored [5]. To define fully the safety profile of a medicine at the time of marketing would be so expensive that new drug development would halt if this were a requirement. As a compromise, the subjective assessment of safety data is based on international guidance on minimal requirements, summarized by the International Conference on Harmonisation's guideline, ICHE1 [6]. This sets a reasonable minimal exposure for medicines for non-life-threatening diseases of about 1500 people, of whom some 300ā600 should be exposed for 6 months and at least 100 are exposed for 1 year. Though a reasonable requirement for drug development, the limitations of ICHE1 and the importance of postmarketing data are highlighted by the number of drugs that are withdrawn from the market for previously undetected safety problems. The ICHE1 safety population may prove inadequate to detect major concerns. Sometimes major safety concerns are only evident with larger and longer population exposure, for example, clofibrate. Here an early data set, considerably larger than the ICHE1 requirement, initially showed a favourable riskābenefit ratio [7]. But eventually, a clinical trial of some 200 000 patient-years showed a significant increase in mortality [8]. But not all important safety signals require large numbers of patients treated for many years. A safety signal might occur in only a small subpopulation, which at the time of licensing has either not been studied or has been studied in limited numbers. Ever since the thalidomide disaster revolutionized medicines regulation, the prime subpopulation of concern has been the fetus. The number of pregnancies exposed to a new drug at the time of licensing is invariably small or zero. When the drug is likely to be worth the risk of prescribing in pregnancy, it may take decades before the risks are quantified, for example, with anti-epileptic therapy [9]. With the increasing use of antidepressants during pregnancy in recent years, now about 2% of all pregnant women in some countries, it is time to consider how safe such prescribing might be. The labelling information of antidepressants has numerous safety warnings and always recommends caution in pregnancy, but statements that āneonates should be observedā raises the question of what form this observation should take. Without control groups, it is often impossible to separate the risk of the disease, the risk of the therapy and the background incidence of developmental abnormality. Some adverse events only become apparent indirectly through the presence of a cofactor, a proxy or a challenge test. Supressing eosinophils may seem safe until a parasitic infection is encountered; grapefruit juice seems innocuous until a drug solely metabolized by CYP3A4 is co-administered. In the present study, the group used a pharmacy prescription database to detect the use of diarrhoea and constipation medication as a marker of enteric nervous system development. What is commendable in this approach is that basic pharmacology has been reviewed to develop a hypothesis that is then tested with epidemiology. Antidepressants can modify monoamine synaptic transmission of serotonin, noradrenaline or dopamine. The pharmacology of noradrenaline and dopamine is well established. Serotonin may affect anger, aggression, arousal, body temperature, mood, sleep, vomiting, sexuality and appetite and may even modify social decision making [10]. The pharmacology of serotonin has been sufficiently studied that it is possible to define safety questions that need to be answered in clinical studies of a new molecule that affects serotoninergic pathways. These include whether there is an effect on the following parameters: pulmonary hypertension; pulmonary hypertension in the fetus; heart valve abnormalities; chronotropic/inotropic effects via receptors in atria or ventricles; mood changes or suicidality; platelet aggregation; vasoconstriction; QT effects similar to cisapride; the incidence of serotonin syndrome alone or in combination; and bone resorption [11]. But there is more to the monoamines than neurotransmission. Knockout mouse models show the importance of the serotonin re-uptake transporter (SERT) and the noradrenaline transporter (NET) in neuronal development. SERT-deficient mice are susceptible to both diarrhoea and constipation in adult life. A careful review of the literature by the Groningen authors discusses evidence that modification of 5-HT2B receptors, SERT and NET may each adversely affect enteric nervous system development [1]. The safety analysis of medicines is more complex than the assessment of efficacy. Though antidepressants are taken by about 10% of Americans (they are the most commonly used prescription drug class in the USA), they continue to come up with surprises. If proved, the current findings are a major concern. Antidepressants have to cross the bloodābrain barrier and affect neuronal function in order to work. This makes them likely to cross the placenta and access the neural crest and neural tube. If these commonly used drugs affect enteric nervous system development, then it is difficult to guarantee the safe development of other tissues. We cannot yet be reassured about potential central nervous system effects on children who have been exposed in utero, nor is there much certainty about long-term effects on the increasing number of children and adolescents exposed to antidepressants during their youth [12, 13]. The approach by the Groningen group, of using pharmacology to define an appropriate safety question, is exemplary. Only when such questions are formulated can sense be made of much of the mass of postmarketing pharmacovigilance data. Finding signals in these huge databases is like searching for a needle in a haystack. Defining a question based on the pharmacology to probe the data and using co-medication usage as a marker is analogous to using a magnet to search for such a valuable needle. The author is a pharmaceutical industry consultant and advises a range of companies on pharmaceutical development. The content of this article does not promote a particular commercial interest.
Open access
Pharmacological Effects and Toxicity Studies
Intestinal Malrotation and Obstruction Disorders
Maternal Mental Health During Pregnancy and Postpartum
Abstract Distributed applications are difficult to program reliably and securely. Dependently typed functional languages promise to prevent broad classes of errors and vulnerabilities, and to enable program verification to proceed side-by-side with development. However, as recursion, effects, and rich libraries are added, using types to reason about programs, specifications, and proofs becomes challenging. We present F*, a full-fledged design and implementation of a new dependently typed language for secure distributed programming. Our language provides arbitrary recursion while maintaining a logically consistent core; it enables modular reasoning about state and other effects using affine types; and it supports proofs of refinement properties using a mixture of cryptographic evidence and logical proof terms. The key mechanism is a new kind system that tracks several sub-languages within F* and controls their interaction. F* subsumes two previous languages, F7 and Fine. We prove type soundness (with proofs mechanized in Coq) and logical consistency for F*. We have implemented a compiler that translates F* to .NET bytecode, based on a prototype for Fine. F* provides access to libraries for concurrency, networking, cryptography, and interoperability with C#, F#, and the other .NET languages. The compiler produces verifiable binaries with 60% code size overhead for proofs and types, as much as a 45x improvement over the Fine compiler, while still enabling efficient bytecode verification. We have programmed and verified nearly 50,000 lines of F* including new schemes for multi-party sessions; a zero-knowledge privacy-preserving payment protocol; a provenance-aware curated database; a suite of web-browser extensions verified for authorization properties; a cloud-hosted multi-tier web application with a verified reference monitor; the core F* typechecker itself; and programs translated to F* from other languages such as F7 and JavaScript.
For the problem of the original direct anonymous attestation (DAA) schemeās complexity and great time consumption, a new DAA scheme based on symmetric bilinear pairings is presented, which gives a practical solution to ECC-based TPM in protecting the privacy of the TPM. The scheme still includes five procedures or algorithms: Setup, Join, Sign, Verify and Rogue tagging, but gets rid of zero-knowledge proof and takes on a new process and framework, of which the main operations are addition, scalar multiplication and bilinear maps on supersingular elliptic curve systems. Moreover, the scheme adequately utilizes the properties of bilinear maps as well as the signature and verification of the ecliptic curve system itself. Compared with other schemes, the new DAA scheme not only satisfies the same properties, and shows better simplicity and high efficiency. This paper gives not only a detailed security proof of the proposed scheme, but also a careful performance analysis by comparing with the existing DAA schemes.
Kyle Richardson, Danny Bobrow, Cleo Condoravdi, Richard Waldinger Ā· 5 authors
We present work on using a domain model to guide text interpretation, in the context of a project that aims to interpret English questions as a sequence of queries to be answered from structured databases. We adapt a broad-coverage and ambiguity-enabled natural language processing (NLP) system to produce domain-specific logical forms, using knowledge of the domain to zero in on the appropriate interpretation. The vocabulary of the logical forms is drawn from a domain theory that constitutes a higher-level abstraction of the contents of a set of related databases. The meanings of the terms are encoded in an axiomatic domain theory. To retrieve information from the databases, the logical forms must be instantiated by values constructed from fields in the database. The axiomatic domain theory is interpreted by the first-order theorem prover SNARK to identify the groundings, and then retrieve the values through procedural attachments semantically linked to the database. SNARK attempts to prove the logical form as a theorem by reasoning over the theory that is linked to the database and returns the exemplars of the proof(s) back to the user as answers to the query. The focus of this paper is more on the language task, however, we discuss the interaction that must occur between linguistic analysis and reasoning for an end-to-end natural language interface to databases. We illustrate the process using examples drawn from an HIV treatment domain, where the underlying databases are records of temporally bound treatments of individual patients.
SÅawomir Grzonkowski, Peter Corcoran, Thomas Coughlin
A number of well-known authentication protocols are considered in the context of next-generation mobile and CE network services. The potential weaknesses of current protocols can be overcome using Zero Knowledge Proof (ZKP) techniques to protect user passwords so an alternative ZKP protocol, SeDiCi 2.0, is described. This offers mutual and also two-factor authentication that is considered more secure against various phishing attempts than existing trusted third party protocols. The suitability of such a ZKP protocol for various CE-based cloud computing applications is demonstrated.
In nanometer technology regime, design components mandate their reuse to meet the complex design challenges and hence comprise Intellectual Property (IP). Unauthorized reuse raises major security issues. IP mark(s) is embedded into a design for establishing the veracity of a legal IP owner/buyer. However, methods for trustworthy public verification of IP marks are not secure. For field-programmable gate-array (FPGA) designs, marks become prone to tampering, and even being overridden by an attacker's signature after public verification. In order to ensure trustworthy yet leakage-proof public verification based on the marks hidden in a FPGA design, we propose a zero-knowledge protocol Verify_ZKP. It is an interactive two-person game between the prover and the verifier. This protocol is fast, incurs no additional design overhead, and needs no centralized signature database. We establish that Verify_ZKP satisfies zero-knowledge property, and introduce statistical metrics to measure its robustness. We have simulated our protocol for IWLS'05 FPGA benchmarks. Experimental results on robustness and overhead are very encouraging.
Physical Unclonable Functions (PUFs) and Hardware Security
For the general problem of minimizing a convex function over a compact convex domain, we will investigate a simple iterative approximation algorithm based on the method by Frank & Wolfe 1956, that does not need projection steps in order to stay inside the optimization domain. Instead of a projection step, the linearized problem defined by a current subgradient is solved, which gives a step direction that will naturally stay in the domain. Our framework generalizes the sparse greedy algorithm of Frank & Wolfe and its primal-dual analysis by Clarkson 2010 (and the low-rank SDP approach by Hazan 2008) to arbitrary convex domains. We give a convergence proof guaranteeing ε-small duality gap after O(1/ε) iterations. The method allows us to understand the sparsity of approximate solutions for any l1-regularized convex optimization problem (and for optimization over the simplex), expressed as a function of the approximation quality. We obtain matching upper and lower bounds of Ī(1/ε) for the sparsity for l1-problems. The same bounds apply to low-rank semidefinite optimization with bounded trace, showing that rank O(1/ε) is best possible here as well. As another application, we obtain sparse matrices of O(1/ε) non-zero entries as ε-approximate solutions when optimizing any convex function over a class of diagonally dominant symmetric matrices. We show that our proposed first-order method also applies to nuclear norm and max-norm matrix optimization problems. For nuclear norm regularized optimization, such as matrix completion and low-rank recovery, we demonstrate the practical efficiency and scalability of our algorithm for large matrix problems, as e.g. the Netflix dataset. For general convex optimization over bounded matrix max-norm, our algorithm is the first with a convergence guarantee, to the best of our knowledge.
Endre Bangerter, Stephan Krenn, Martial Seifriz, Ulrich UltesāNitsche
Cryptographic two-party protocols are used ubiquitously in everyday life. While some of these protocols are easy to understand and implement (e.g., key exchange or transmission of encrypted data), many of them are much more complex (e.g., e-banking and e-voting applications, or anonymous authentication and credential systems). For a software engineer without appropriate cryptographic skills the implementation of such protocols is often difficult, time consuming and error-prone. For this reason, a number of compilers supporting programmers have been published in recent years. However, they are either designed for very specific cryptographic primitives (e.g., zero-knowledge proofs of knowledge), or they only offer a very low level of abstraction and thus again demand substantial mathematical and cryptographic skills from the programmer. Finally, some of the existing compilers do not produce executable code, but only metacode which has to be instantiated with mathematical libraries, encryption routines, etc. before it can actually be used. In this paper we present a cryptographically aware compiler which is equally useful to cryptographers who want to benchmark protocols designed on paper, and to programmers who want to implement complex security sensitive protocols without having to understand all subtleties. Our tool offers a high level of abstraction and outputs well-structured and documented Java code. We believe that our compiler can contribute to shortening the development cycles of cryptographic applications and to reducing their error-proneness.
With the development of wireless communication technology, the applications of Mobile ad hoc network (MANET) have been constantly expanded. However, MANET faces many security threats because of their own properties. Authentication is the fundamental service to protect the security of MANET, and in many applications users typically want personal information kept confidential, so that it required the anonymity in the process of authentication. In this paper, we present a distributed anonymous authentication scheme for MANET from the bilinear maps, based on the technique of secret share and zero-knowledge proof, solves the authentication and key management problems of MANET which is lack of fixed infrastructure, achieves the anonymity in the process of authentication and key transfer. Meanwhile the scheme shortens the signature length, thus reduces the computational cost of nodes that is important to the MANET which are often composed of weak or resource-limited devices.
A user centric approach to authentication for home networks is proposed. A zero-knowledge-proof (ZKP) authentication is used to leverage the emerging cloud infrastructure allowing users to temporarily transfer their service and content rights within a trusted environment such as a friend's home. This approach enables the sharing of personalized content and more sophisticated network-based services over a conventional TCP/IP infrastructure. Experimental results derived from a reference prototype are presented. These demonstrate the practicality of the underlying approach. The potential to develop new cloud services for "social" home networks is also discussed.
The canonical model of primary visual cortex (V1) is that it forms a linear generative model of the image stimulus presented to the eyes. Thus, for a given image with pixel values Xj, the representation Xj*=āibiĻij is formed by multiplying the activity of each neuron (bi) by the feature that neuron encodes (Ļij), and summing over all neurons. We call this a cooperative representation, since it involves all of the neurons collectively forming a single representation. Over time, the network is thought to adapt so as to minimize, on average, the mean-squared error between the representation X* and the input X, ||X-X*||2. Performing gradient descent on this error function yields the usual learning rule ĪĻij= α bi(Xj- āibiĻij ), where α is some small positive constant called the learning rate. Typically, the features Ļij are interpreted as the receptive fields (RFās; features to which a neuron responds) of the neurons; indeed, there is strong evidence [1] that the feature encoded by a neuron is very similar to its RF. In that case, the value Ļij can be thought of as the strength of the synaptic connection between input pixel value Xj, and neuron i. With that interpretation in mind, it is clear that the canonical learning rule ĪĻij= α bi(Xj- āibiĻij ), used by most previous work in this field [1,2], fails to be biologically realistic because the rule for updating one synaptic strength Ļij requires knowledge of the strengths of many synaptic connections, all on different neurons (with indices i), and it is not clear that such information is available to each individual synapse in the brain.
We consider instead a Hebbian learning rule that respects synaptic locality, ĪĻij= α bi(Xj- biĻij ) [3]. In this case, the information required to change the strength of synapse Ļij consists solely of the pre-synaptic activity Xj, the post-synaptic activity bi, and the current strength of the synaptic connection Ļij. While this rule respects the locality of synaptic information, it does not appear to perform gradient descent on the desired error function ||Xj- āibiĻij||2. Instead, our local rule can be seen as gradient descent on the error function āi||Xj- biĻij ||2, which is the sum over all neurons of the error between each neuronās own internal representation of the input, biĻij, and the input image. In other words, a network that follows Ojaās [3] local learning rule is a solipsistic one: each neuron makes its own individual representation of the input, and learning optimizes each of those representations individually.
We have proven that, if neuronal activities {bi} are uncorrelated, and sufficiently sparse (the majority of the biās are zero for any given image), the local and non-local learning rules are approximately equal, when averaged over many image presentations: = α ā α . This suggests a previously undiscovered role for independence and sparseness in visual cortex: these properties allow the neuronal network to (approximately) form the optimal cooperative representation, despite the locality of its learning rules. The same proof applies other neuronal networks that form linear generative models.
We will present the details of our proof, and an example network (similar to that of [4]) of leaky integrate-and-fire neurons that learns a sparse image code using the local learning rule ĪĻij= α bi(Xj- biĻij ). In our network, inhibitory inter-neuronal connections and variable firing thresholds keep the neuronal activities uncorrelated and sparse throughout the learning process. When trained on natural scenes, this network learns the same diversity of receptive fields as do previous non-local algorithms [1,2].
We study repeated games in which players have imperfect execution skill and one playerās true skill is not common knowledge. In these settings the possibility arises of a player āhustlingā, or pretending to have lower execution skill than they actually have. Focusing on repeated zero-sum games, we provide a hustle-proof strategy; this strategy maximizes a playerās payoff, regardless of the true skill level of the other player. 1
Ioannis Chatzigiannakis, Apostolos Pyrgelis, Paul G. Spirakis, Yannis C. Stamatiou
Elliptic Curve Cryptography (ECC) is an attractive alternative to\nconventional public key cryptography, such as RSA. ECC is an ideal candidate\nfor implementation on constrained devices where the major computational\nresources i.e. speed, memory are limited and low-power wireless communication\nprotocols are employed. That is because it attains the same security levels\nwith traditional cryptosystems using smaller parameter sizes. Moreover, in\nseveral application areas such as person identification and eVoting, it is\nfrequently required of entities to prove knowledge of some fact without\nrevealing this knowledge. Such proofs of knowledge are called Zero Knowledge\nInteractive Proofs (ZKIP) and involve interactions between two communicating\nparties, the Prover and the Verifier. In a ZKIP, the Prover demonstrates the\npossesion of some information (e.g. authentication information) to the Verifier\nwithout disclosing it. In this paper, we focus on the application of ZKIP\nprotocols on resource constrained devices. We study well-established ZKIP\nprotocols based on the discrete logarithm problem and we transform them under\nthe ECC setting. Then, we implement the proposed protocols on Wiselib, a\ngeneric and open source algorithmic library. Finally, we present a thorough\nevaluation of the protocols on two popular hardware platforms equipped with low\nend microcontrollers (Jennic JN5139, TI MSP430) and 802.15.4 RF transceivers,\nin terms of code size, execution time, message size and energy requirements. To\nthe best of our knowledge, this is the first attempt of implementing and\nevaluating ZKIP protocols with emphasis on low-end devices. This work's results\ncan be used from developers who wish to achieve certain levels of security and\nprivacy in their applications.\n
Ioannis Chatzigiannakis, Apostolos Pyrgelis, Paul G. Spirakis, Yannis C. Stamatiou
Elliptic Curve Cryptography (ECC) is an attractive alternative to conventional public key cryptography, such as RSA. ECC is an ideal candidate for implementation on constrained devices where the major computational resources i.e. speed, memory are limited and low-power wireless communication protocols are employed. That is because it attains the same security levels with traditional cryptosystems using smaller parameter sizes. Moreover, in several application areas such as person identification and eVoting, it is frequently required of entities to prove knowledge of some fact without revealing this knowledge. Such proofs of knowledge are called Zero Knowledge Interactive Proofs (ZKIP) and involve interactions between two communicating parties, the Prover and the Verifier. In a ZKIP, the Prover demonstrates the possesion of some information (e.g. authentication information) to the Verifier without disclosing it. In this paper, we focus on the application of ZKIP protocols on resource constrained devices. We study well-established ZKIP protocols based on the discrete logarithm problem and we transform them under the ECC setting. Then, we implement the proposed protocols on Wiselib, a generic and open source algorithmic library. Finally, we present a thorough evaluation of the protocols on two popular hardware platforms equipped with low end microcontrollers (Jennic JN5139, TI MSP430) and 802.15.4 RF transceivers, in terms of code size, execution time, message size and energy requirements. To the best of our knowledge, this is the first attempt of implementing and evaluating ZKIP protocols with emphasis on low-end devices. This work's results can be used from developers who wish to achieve certain levels of security and privacy in their applications.
Nan Guo, Tianhan Gao, Bin Zhang, Ruchith Fernando Ā· 5 authors
An aggregated privacy-preserving identity verification scheme is proposed for composite Web services. It aggregates multiple component providers' interactions of identity verification to a single one involving the user. Besides, it protects users from privacy disclosure through the adoption of zero-knowledge of proof of knowledge. This approach can dramatically reduce the computation time, independently on the number of identity attributes and component providers.
PURPOSE: Knowledge of the complete axial dose profile f(z), including its long scatter tails, provides the most complete (and flexible) description of the accumulated dose in CT scanning. The CTDI paradigm (including CTDIvol) requires shift-invariance along z (identical dose profiles spaced Sat equal intervals), and is therefore inapplicable to many of the new and complex shift-variant scan protocols, e.g., high dose perfusion studies using variable (or zero) pitch. In this work, a convolustion-based beam model developed by Dixon et al. [Med. Phys. 32, 3712-3728, (2005)] updated with a scatter LSF kernel (or DSF) derived from a Monte Carlo simulation by Boone [Med. Phys. 36, 4547-4554 (2009)] is used to create an analytical equation for the axial dose profile f(z) in a cylindrical phantom. Using f(z), equations are derived which provide the analytical description of Sconventional (axial and helical) dose, demonstrating its physical underpinnings; and likewise for the peak axial dose f(0) appropriate to stationary phantom cone beam CT, (SCBCT). The methodology can also be applied to dose calculations in shift-variant scan protocols. This paper is an extension of our recent work Dixon and Boone [Med. Phys. 37, 2703-2718 (2010)], which dealt only with the properties of the peak dose f(0), its relationship to CTDI, and its appropriateness to SCBCT. METHODS: The experimental beam profile data f(z) of Mori et al. [Med. Phys. 32, 1061-1069 (2005)] from a 256 channel prototype cone beam scanner for beam widths (apertures) ranging from a = 28 to 138 mm are used to corroborate the theoretical axial profiles in a 32 cm PMMA body phantom. RESULTS: The theoretical functions f(z) closely-matched the central axis experimental profile data for all apertures (a = 28 -138 mm). Integration of f(z) likewise yields analytical equations for all the (CTDI-based) dosimetric quantities of conventional CT (including CTDIL itself) in addition to the peak dose f(0) relevant to SCBCT (allowing direct cross-comparison between CT scan modes and mathematical proofs of several hypotheses of practical utility in CT dosimetry). A fast, analytical dose simulator6 is also demonstrated-successfully matching complex dose distributions measured using OSL and film dosimetry. CONCLUSIONS: The model described allows one to obtain analytical functions describing both the primary and scatter components of the axial dose profile. This model (using no empirical functions or adjustable fit parameters) provides a good match to the experimental data, as well as a complete analytical description of dose for both conventional (axial and helical) CT and cone beam CT. An efficient method whereby the complete data set for both modalities can be obtained from a single measurement of either CTDI100 or f(0) is illustrated. This method is also flexible--allowing calculation of heretofore unattainable doses for recently-introduced shift-variant protocols [e.g., variable pitch (irregular scan spacing), variable aperture, shuttle mode acquisition, and mA modulation schemes].
We introduce WORM-ORAM, a first mechanism that combines Oblivious RAM (ORAM) access privacy and data confidentiality with Write-Once Read-Many (WORM) regulatory data retention guarantees. Clients can outsource their database to a server with full confidentiality and data access privacy, and, for data retention, the server ensures client access WORM semantics. In general simple confidentiality and WORM assurances are easily achievable, e.g., via an encrypted outsourced data repository with server-enforced read-only access to existing records (albeit encrypted). However, this becomes hard when also access privacy is to be ensured-when client access patterns are necessarily hidden and the server cannot enforce access control directly. WORM-ORAM overcomes this by deploying a set of zero-knowledge proofs to convince the server that all stages of the protocol are WORM-compliant.
As radio frequency identification (RFID) applications become ubiquitous, security and privacy issues have been addressed with universal acceptances. This paper proposes a lightweight Zero-Knowledge Authentication Protocol (ZKAP) based on alternative mode to address such severe problems. In ZKAP, dual zero-knowledge proofs are randomly chosen to provide anonymity and mutual authentication without revealing any sensitive identifiers. Pseudo-random flags and access lists employed for quick search and check ensure high efficiency and scalability. Meanwhile, formal proof model based on reasonable mathematical assumptions is established to prove the adaptive completeness, soundness and zero-knowledgeness, and the attack models are adopted to analyze the resilience and resistance for malicious attacks. It indicates that ZKAP owns no obvious design defects theoretically and is robust enough to resist major attacks (e.g., forgery, replay, Man-in-the-Middle, and tracking). The protocol is attractive and appropriate for low-cost and resource-restricted RFID systems.
Shlomi Dolev, Panagiota N. Panagopoulou, Mikaël Rabie, Elad M. Schiller · 5 authors
Players in a game are assumed to be totally rational and absolutely smart. However, in reality all players may act in non-rational ways and may fail to understand and find their best actions. In particular, participants in social interactions, such as lotteries and auctions, cannot be expected to always find by themselves the "best-reply" to any situation. Indeed, agents may consult with others about the possible outcome of their actions. It is then up to the counselee to assure the rationality of the consultant's advice. We present a distributed computer system infrastructure, named rationality authority, that allows safe consultation among (possibly biased) parties. The parties' advices are adapted only after verifying their feasibility and optimality by standard formal proof checkers. The rationality authority design considers computational constraints, as well as privacy and security issues, such as verification methods that do not reveal private preferences. Some of the techniques resembles zero-knowledge proofs. A non-cooperative game is presented by the game inventor along with its (possibly intractable) equilibrium. The game inventor advises playing by this equilibrium and offers a checkable proof for the equilibrium feasibility and optimality. Standard verification procedures, provided by trusted (according to their reputation) verification procedures, are used to verify the proof. Thus, the proposed rationality authority infrastructure facilitates the applications of game theory in several important real-life scenarios by the use of computing systems.