In this paper, we present a solution to the problem of e–contract validation in a supply chain with chain contracting topology. In chain contracting, there are multiple bi–lateral contracts that are related, for example one original contract between two partners is modified by subsequent negotiations to form other bi–lateral contracts between other parties in the supply chain. We study how to validate these contracts and ensure appropriate relationship between these contracts. We first identify key technical requirements for such a solution and then present our models that address these requirements. The models are based on the concepts of commitment scheme and zero–knowledge proof. It can be implemented in a contract engine that supports both the contract formation and contract execution phases of the contract life cycle. Also proposed is a cryptographic scheme to facilitate the electronic transfer of payments.
In WS-BPEL process, Extensible Access Control Markup Language (XACML) is used as an authenticated tool to provide several services for an employee in an organization. There are several policies (XACML) used as an access control in Web Services. XACML policy as RBAC profile to support role based access controls policies. In an organization, there are several roles assigned to an employee based on their attributes. The attributes are used as an authenticating tool to assign the role and perform the task. The identity attributes are used for role provisioning policies to a particular employee i.e. social security number, date of birth, etc. are assigned as an identity attributes. In this aggregate zero knowledge proof knowledge (AgZKPK) and Oblivious commitment based envelope (OCBE) protocols are used during service (information) sharing between employees and to make it more flexible. This process may provide privacy to the user information and support multi-domain environment.
Abstract—Many cryptographic primitives, such as pseudorandom generators, encryption schemes, and zero-knowledge proofs, center around the notion of approximability. For instance, a pseudorandom generator is an expanding function which on a random seed, approximates the uniform distribution. In this paper, we classify different notions of computational approximability in the literature, and provide several new types of approximability. More specifically, we identify two hierarchies of computational approximability: The first hierarchy ranges from strong approximability—which is the most common type in the cryptography—to the weak approximability—as defined by Dwork et al. (FOCS 1999). We define semi-strong, mild, and semi-weak types as well. The second hierarchy, termed K-approximability, is inspired by the ε-approximability of Dwork et al. (STOC 1998). K-approximability has the same levels as the first hierarchy, ranging from strong K-approximability to weak K-approximability. While both hierarchies are general and can be used to define various cryptographic constructs with different levels of security, they are best illustrated in the context of zero-knowledge protocols. Assuming the existence of (trapdoor) one-way permutations, and exploiting the random oracle model, we present a separation between two definitions of zero knowledge: one based on strong K-approximability, and the other based on semi-strong K-approximability. Especially, we present a protocol which is zero knowledge only in the latter sense. The protocol is interesting in its own right, and can be used for efficient identification. Next, we show that our model for zero knowledge was not closed under sequential composition, and change the model to resolve this issue. After proving a composition theorem, we finally provide a version of the identification protocol which satisfies the requirements of the new model. Some techniques provided in this paper are of independent interest, such as proving a composition theorem in the presence of both simulator and knowledge extractor.
A zero-knowledge protocol allows a prover to convince a verifier of the correctness of a statement without disclosing any other information to the verifier. It is a basic tool and widely used in many other cryptographic applications. However, when stand-alone zero-knowledge protocols are used in complex environments, e.g., the Internet, the basic properties may not be sufficient. This is why researchers considered security of zero-knowledge protocols under concurrent composition and manin-the-middle attacks. Moreover, it is very likely that an adversary might break computers that run the protocol and get internal information of the parties. It is thus necessary to take account of the security of zero-knowledge protocols when adaptive corruptions are allowed. Previous adaptively secure zero-knowledge protocols work either in a stand-alone setting, or in a concurrent setting with trusted setup assumptions. In this paper, we study adaptive security of zero-knowledge protocols under both concurrent self composition and man-in-the-middle attacks in the plain model (i.e., without any set-up assumptions). We provide a construction of adaptively secure concurrent non-malleable zero-knowledge proof/argument for every language in NP.
The main idea is to protect the signer of a document against the document being digitally distributed without the cooperation of signer. This paper proposes a new scheme of undeniable signature, which is so effective and improved D. Chaum's scheme. And our scheme which is zero-knowledge proved by using one-way function and partition - selection method, shows that its communication(challenge-response) only needs much fewer times during the confirmation protocol and disavowal protocol respectively, being very useful for wireless network environment. In the meantime our scheme allows the verifier to verify that the signature is valid, while the signer doesn't know the original message and the signature, to preserve the privacy of the verifier.
Recently we have observed a growing demand for secure technologies for e-commerce that do not put customers at risk of identity theft. We have also experienced the advent of Web 2.0 which has led to new business models and which has changed the way users interact with the Web. This thesis proposes a set of strategies and enhancements towards providing improved security and privacy in such new settings. We introduce a novel concept: Fair Rights Management (FRM). It can be classified as a usage control solution. FRM enables a flexible way of managing digital content. There was a need to provide additional security extensions to keep such a flexible model applicable. Thus, in our approach we take advantage of trust obtained from social networks. This is also the reason why we created an efficient zero-knowledge proof protocol that is lightweight enough to be deployed within existing web-applications. The proposed protocol is also successfully integrated with Semantic Web architecture and associated components. It enables practical Web and mobile applications which employ trust-based transactions as part of their workflow. This core contribution overcomes various disadvantages of prior art and enables a range of new applications and potentially new business models. We show that compared to existing Usage Control Models (UCON) (i) FRM is a step towards fair use in the digital world and we also argue that our approach is enforced by law; (ii) the participants of the proposed solution do not put their privacy at risk. Our research shows that existing infrastructure is sufficient to support ZKP-based solutions; and thus, it is feasible to offer the users enhanced privacy within existing deployed solutions.
In ESS2008, Yang et al. suggested a key-exposure-free chameleon hashing scheme, and it can be used to design signature and some other cryptography mechanism. In this paper, we construct a new timeliness optimistic fair exchange protocol based on this key-exposure-free chameleon hashing scheme. The new scheme does not require the use of interactive zero-knowledge proofs in the exchange phase. In our scheme, both parties can contact the trusted third party and settle the argument before the deadline. Moreover, the new scheme achieves fairness and timeliness.
DAA scheme in the TCG specification is based on CL signature,which is also combined by group signature and zero knowledge proof techniques to prove the direct anonymous attestation,and its security is based on the decomposition of large numbers.With the increasement of computer performance and the development of cryptography,the problem based on integer factorization problem is likely to be attacked,the corresponding DAA scheme has become no longer safety.But the algorithm based on the elliptic curve discrete logarithm and the prime on the discrete logarithm (double discrete logarithm) can use a shorter key,achieve higher security.Based on double discrete logarithm algorithm,this article designed a new DAA scheme.Demonstrated by analyzing solution,this new DAA scheme could not only meet the requirements of direct anonymous attestation,but also could make the implementation efficiency of the scheme consistent with the original one,while improved its security greatly.
To address the problem that the common authentication mechanism is not applicable to the P2P network system model with anonymous communication requirements.This paper,based on the improvement of the Diffle-Hellman key agreement protocol and the combination of the RSA digital signatures agreements and zero-knowledge proof GQ agreement,proposes a new token-based services authentication mechanism to identify the nodes in P2P anonymous communication systems.This mechanism,with the premise of guaranteeing various general characteristics of P2P anonymous communication system and introduction of the trusted third party node into P2P anonymous communication system,implements anonymous control and behavior management of various communication nodes in P2P anonymous communication system.It could resist the threat of various common networks attack and realize effective authentication of P2P anonymous communication system,thus improving the security management ability of P2P anonymous communication system.
A novel fair and efficient divisible E-Cash system based on the schnorr blind signature and non-interactive zero-knowledge proofs is proposed in this paper.In this system,both discrete logarithm and collision-resistance Hash function are used in the computation of divisible E-Cash.It contains the C value which defines the security.C can only be C1or be obtained by associated by C1and C2,where C1 is able to disclose the users' ID when over-spending happened.Moreover,the combination of and can realized owner tracing and coin tracing through the cooperation of B and T more easily.The scheme can also realize overspending tracing and over-deposit user,furthermore,it can limit the power of T,avoid the possibility of the association guilt between B and T.
In a digital world, users’ Personally Identifiable Information (PII) is normally managed with a system called an Identity Management System (IMS). There are many types of IMSs. There are situations when two or more IMSs need to communicate with each other (such as when a service provider needs to obtain some identity information about a user from a trusted identity provider). There could be interoperability issues when communicating parties use different types of IMS. To facilitate interoperability between different IMSs, an Identity Meta System (IMetS) is normally used. An IMetS can, at least theoretically, join various types of IMSs to make them interoperable and give users the illusion that they are interacting with just one IMS. However, due to the complexity of an IMS, attempting to join various types of IMSs is a technically challenging task, let alone assessing how well an IMetS manages to integrate these IMSs. The first contribution of this thesis is the development of a generic IMS model called the Layered Identity Infrastructure Model (LIIM). Using this model, we develop a set of properties that an ideal IMetS should provide. This idealized form is then used as a benchmark to evaluate existing IMetSs. Different types of IMS provide varying levels of privacy protection support. Unfortunately, as observed by Josang et al (2007), there is insufficient privacy protection in many of the existing IMSs. In this thesis, we study and extend a type of privacy enhancing technology known as an Anonymous Credential System (ACS). In particular, we extend the ACS which is built on the cryptographic primitives proposed by Camenisch, Lysyanskaya, and Shoup. We call this system the Camenisch, Lysyanskaya, Shoup - Anonymous Credential System (CLS-ACS). The goal of CLS-ACS is to let users be as anonymous as possible. Unfortunately, CLS-ACS has problems, including (1) the concentration of power to a single entity - known as the Anonymity Revocation Manager (ARM) - who, if malicious, can trivially reveal a user’s PII (resulting in an illegal revocation of the user’s anonymity), and (2) poor performance due to the resource-intensive cryptographic operations required. The second and third contributions of this thesis are the proposal of two protocols that reduce the trust dependencies on the ARM during users’ anonymity revocation. Both protocols distribute trust from the ARM to a set of n referees (n > 1), resulting in a significant reduction of the probability of an anonymity revocation being performed illegally. The first protocol, called the User Centric Anonymity Revocation Protocol (UCARP), allows a user’s anonymity to be revoked in a user-centric manner (that is, the user is aware that his/her anonymity is about to be revoked). The second protocol, called the Anonymity Revocation Protocol with Re-encryption (ARPR), allows a user’s anonymity to be revoked by a service provider in an accountable manner (that is, there is a clear mechanism to determine which entity who can eventually learn - and possibly misuse - the identity of the user). The fourth contribution of this thesis is the proposal of a protocol called the Private Information Escrow bound to Multiple Conditions Protocol (PIEMCP). This protocol is designed to address the performance issue of CLS-ACS by applying the CLS-ACS in a federated single sign-on (FSSO) environment. Our analysis shows that PIEMCP can both reduce the amount of expensive modular exponentiation operations required and lower the risk of illegal revocation of users’ anonymity. Finally, the protocols proposed in this thesis are complex and need to be formally evaluated to ensure that their required security properties are satisfied. In this thesis, we use Coloured Petri nets (CPNs) and its corresponding state space analysis techniques. All of the protocols proposed in this thesis have been formally modeled and verified using these formal techniques. Therefore, the fifth contribution of this thesis is a demonstration of the applicability of CPN and its corresponding analysis techniques in modeling and verifying privacy enhancing protocols. To our knowledge, this is the first time that CPN has been comprehensively applied to model and verify privacy enhancing protocols. From our experience, we also propose several CPN modeling approaches, including complex cryptographic primitives (such as zero-knowledge proof protocol) modeling, attack parameterization, and others. The proposed approaches can be applied to other security protocols, not just privacy enhancing protocols.
IKE protocol,with its complexity,is vulnerable to multiple attacks.This paper first analyzes its flaws,and then based on the idea of zero knowledge proof,proposes a new protocol,which can resist MITM attack efficiently as well as reduce system consumption.This protocol fits the users who need more strong security protect for their data.
A trusted small world Peer-to-Peer (P2P) model with role and reputation based access control policies (SW-R2P) was designed to combine the network topology and trust evaluation in P2P network.The model utilizes the zero knowledge interactive proof (ZKIP) scheme to authenticate the group information between peers without transferring any related data.The group information is used to cluster the peers to construct a small world topology.The Bayesian trust network is involved into the SW-R2P model to evaluate the multi-faceted trust of the peer and the group,which supporting the action protocols of peers and the long links between groups.Simulation shows that the SW-R2P model performs much better than the Chord and R2P models in the resources lookup,clustering coefficient and peer reputation error.The SW-R2P model integrates the advantages of small world topology,ZKIP scheme and Bayesian trust network,therefore implements a trustworthy,secure and efficient P2P network.
In order to solve the issue that existing direct anonymous attestation (DAA) scheme can not operate effectively in different domains,based on the original DAA scheme,a novel direct anonymous attestation protocol used in multi domains environment is proposed and designed,in which,the certificate issuer located in outside of domain can be considered as a proxy server to issue the DAA certificate for valid member nodes directly.Our designed mechanism accords with present trusted computing group (TCG) international specification,and can solve the problems of practical authentication and privacy information protection between different trusted domains efficiently.Compared with present DAA scheme,in our protocol,the anonymity,unforgeability can be guaranteed,and the replay-attack also can be avoided.It has important referenced and practical application value in trusted computing field.
This paper proposes a new undeniable signature scheme which uses one-way function and partition-selection method to proof its zero-knowledge respectively. The main idea is to protect the signer of a document against the document being digitally distributed without knowledge of signer. And we show that our scheme is so effective that message exchange only needs much fewer times during the confirmation protocol and disavowal protocol respectively. which is very useful for poor network environment keeping the communication times with both sides as few as possible. And our scheme allows verifier to verify that the signature is valid, while the signer doesn't know the original message and the signature, to preserve the privacy of the verifier.
The WS-BPEL specification focuses on business processes the activities of which are assumed to be interactions with Web services. However, WS-BPEL processes go beyond the orchestration of activities exposed as Web services. There are cases in which people must be considered as additional participants to the execution of a process. The inclusion of humans, in turn, requires solutions to support the specification and enforcement of authorizations to users for the execution of human activities while enforcing authorization constraints. In this paper, we extend RBAC-WS-BPEL, a role-based authorization framework for WS-BPEL processes with an identity attribute-based role provisioning approach that preserves the privacy of the users who claim the execution of human activities. Such approach is based on the notion of identity records and role provisioning policies, and uses Pedersen commitments, aggregated zero knowledge proof of knowledge, and Oblivious Commitment-Based Envelope protocols to achieve privacy of user identity information.
Apr 13, 2009·Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies
Trust is a fundamental concept that enables cooperation and collaboration among the nodes in any network. Formal trust models are necessary for sharing information in a collaborative environment. Trust assessment methods that are commonly used in network applications or in social networks passively gather information about other nodes and take significant amount of time for assessing trust. Such models are not convenient for applications such as tactical airborne networks which are typically deployed for short durations of time.
We address the problems of privacy-preserving duplicate tuple matching (PPDTM) and privacy-preserving threshold attributes matching (PPTAM) in the scenario of a horizontally partitioned database among N parties, where each party holds a private share of the database's tuples and all tuples have the same set of attributes. In PPDTM, each party determines whether its tuples have any duplicate on other parties' private databases. In PPTAM, each party determines whether all attribute values of each tuple appear at least a threshold number of times in the attribute unions. We propose protocols for the two problems using additive homomorphic cryptosystem based on the subgroup membership assumption, e.g., Paillier's and ElGamal's schemes. By analysis on the total numbers of modular exponentiations, modular multiplications and communication bits, with a reduced computation cost which dominates the total cost, by trading off communication cost, our PPDTM protocol for the semihonest model is superior to the solution derivable from existing techniques in total cost. Our PPTAM protocol is superior in both computation and communication costs. The efficiency improvements are achieved mainly by using random numbers instead of random polynomials as existing techniques for perturbation, without causing successful attacks by polynomial interpolations. We also give detailed constructions on the required zero-knowledge proofs and extend our two protocols to the malicious model, which were previously unknown.
In order to protect the private key of TTP(Trusted Third Party) in P2P network,an algorithm of synthesizing the private key of TTP was presented.Based on the fault tolerance technology,the shares of the private key of TTP were distributed to the synthesized key server and different share cards,and the private key of TTP was synthesized and protected through these shares.Moreover,the modified share cards were found by zero-knowledge proof technology.Then the digital certificates were effectively protected when they were signed by the private key of TTP.A security analysis proves that the algorithm makes the whole P2P networks have resilience and resistance against collusive attack.
The anonymous authentication schemes for Trusted Computing Platform(TCP) is studied in this paper, the advantages and disadvantages of the subsistent authentication schemes for TCP are analyzed. A new anonymous authentication scheme for TCP is proposed by using the method of zero-knowledge proof. The validity of a TPM platform is proved anonymously, and there is no trusted third party to participate in the authentication schemes. The new scheme has higher efficiency than others and satisfies forgery-resistance, anonymity and revocation under strong RSA assumption and Diffie-Hellman assumption in the random model.
This paper analyzes the development and properties of zero knowledge argument systems in Bare Public Key(BPK) model set, according to the researches and applications of recent years. The generic 4-round mode and 3-round mode are proposed for the constructions of zero knowledge protocols with optimal round complexity, following explorations on the proof techniques of (concurrent) soundness and (resettable) zero knowledge of the protocols. Possible focuses of the near future are discussed.
This paper first gives out definition of receipt-freeness,and prove necessary and sufficient condition of receipt-freeness. Then by employing homomorphic ElGamal encryption,threshold ElGamal encryption and zero-knowledge proof,this paper designs an efficient electronic voting scheme,which satisfies universal verifiability,receipt-freeness,also eligibility,privacy and so on. Different from the previous protocols,there needs less security requirement on trusted third party in the new scheme,which is more practical.