The hardness of lattice problems offers one of the most promising security foundations for quantum-safe cryptography. Basic schemes for public key encryption and digital signatures are already close to standardization at NIST and several other standardization bodies, and the research frontier has moved on to building primitives with more advanced privacy features. At the core of many such primitives are zero-knowledge proofs. In recent years, zero-knowledge proofs for (and using) lattice relations have seen a dramatic jump in efficiency and they currently provide arguably the shortest, and most computationally efficient, quantum-safe proofs for many scenarios. The main difficulty in using these proofs by non-experts (and experts!) is that they have a lot of moving parts and a lot of internal parameters depend on the particular instance that one is trying to prove.
Daniel Escudero, Antigoni Polychroniadou, Yifan Song, Chenkai Weng
In this work we study the efficiency of Zero-Knowledge (ZK) arguments of knowledge, particularly exploring Multi-Verifier ZK (MVZK) protocols as a midway point between Non-Interactive ZK and Designated-Verifier ZK, offering versatile applications across various domains. We introduce a new MVZK protocol designed for the preprocessing model, allowing any constant fraction of verifiers to be corrupted, potentially colluding with the prover. Our contributions include the first MVZK over rings. Unlike recent prior works on fields in the dishonest majority case, our protocol demonstrates communication complexity independent of the number of verifiers, contrasting the linear complexity of previous approaches. This key advancement ensures improved scalability and efficiency. We provide an end-to-end implementation of our protocol. The benchmark shows that it achieves a throughput of 1.47 million gates per second for 64 verifiers with 50% corruption, and 0.88 million gates per second with 75% corruption.
In the realm of healthcare analytics, preserving the privacy of sensitive data while enabling valuable insights poses a significant challenge, particularly given the increasing prevalence of data breaches and the sensitivity of personal health information. This paper presents a secure framework that addresses these concerns by integrating privacy-preserving parameters, zero-knowledge proofs (zk-SNARKs), blockchain technology, and a multi-tenant cloud environment. Through advanced cryptographic techniques, specifically zk-SNARKs, the framework ensures that healthcare records remain protected during analytics computations, without exposing raw data. The privacy-preserving analytics engine utilizes anonymized healthcare records and generates zk-SNARKs to validate computations. These proofs, integrated into a blockchain network, create a tamper-proof, transparent ledger that ensures secure healthcare transactions. This approach is critical in scenarios such as telemedicine, where secure data sharing and computation are paramount. By demonstrating its application in a telemedicine app, the framework highlights its practical significance in balancing data utility and privacy in healthcare analytics, providing a scalable and secure solution to a pressing problem.
Burhan Ul Islam Khan, Khang Wen Goh, Megat F. Zuhairi, Rusnardi Rahmat Putra · 6 authors
Amidst the rising demands for data security across expansive networks, blockchain technology is witnessing an upsurge in its adoption, particularly within Internet of Things (IoT) applications, services, and smart cities. Blockchains offer an immutable property that bolsters security and aids in the structured management of distributed ledgers. Nevertheless, ensuring scalability remains a formidable challenge, especially within decentralized Ethereum systems. Current methods often fall short of offering tangible solutions, and the scrutiny of Ethereum-based cases reveals persistent deficiencies in addressing scalability issues due to inherent system complexities, dependency on resource-intensive consensus algorithms, lack of optimized storage solutions, and challenges in ensuring synchronous transaction validation across a decentralized network. This paper proposes a foundational scheme underpinned by a unique graph-based topology and hash bindings for nodes that join the system. The proposed scheme establishes an innovative indexing mechanism for all transactions and blocks within the IoT framework, ensuring optimal node accessibility. Transaction and block replications occur over the joining nodes' graphical structure, ensuring efficient subsequent retrieval. A standout feature of the proposed scheme is its ability to enable participating nodes to forgo retaining a complete ledger, making it non-reliant on individual node capabilities. Consequently, this facilitates a broader spectrum of nodes to participate in the consensus system, irrespective of their operational prowess. This study also offers a novel empirical model for Proof-of-Validation (PoV), which reduces computational intricacy and expedites the validation process in stark contrast to prevailing blockchain systems.
Blockchain technology has emerged as a transformative solution in the realm of cybersecurity, addressing critical challenges of data integrity and transparency.The ever-increasing sophistication of cyber threats necessitates robust mechanisms to secure sensitive data and ensure accountability in digital systems.Traditional methods, while effective to some extent, often fail to prevent data tampering and lack comprehensive traceability, leaving organizations vulnerable to breaches.Blockchain's decentralized, immutable ledger offers an innovative approach to overcoming these limitations by ensuring secure data integrity and creating transparent audit trails.This paper explores the application of blockchain technology in enhancing cybersecurity frameworks, emphasizing its role in preventing unauthorized data modification and enabling traceability.By employing cryptographic hashing and consensus mechanisms, blockchain ensures data authenticity while eliminating single points of failure.Its capabilities are particularly relevant for industries with stringent regulatory requirements, such as finance, healthcare, and supply chain management, where data accuracy and accountability are paramount.Moreover, we investigate advanced blockchain models, including private and consortium blockchains, to balance scalability, efficiency, and confidentiality.Integration with complementary technologies like smart contracts and artificial intelligence further extends its utility, enabling automated security protocols and anomaly detection.Despite its promise, blockchain adoption faces challenges, including high energy consumption, scalability issues, and the need for standardization.This study provides a comprehensive analysis of blockchain's potential and limitations in cybersecurity, proposing future directions to optimize its effectiveness.By bridging gaps in technology and implementation, blockchain holds the potential to redefine secure digital interactions, ensuring trust and resilience in increasingly interconnected systems.
This article provides an extensive review of the challenges and opportunities at the intersection of federated learning (FL) and data privacy.Federated learning is a distributed machine learning paradigm enabling collaborative model training across decentralized devices without transferring raw data to a central repository.This method reduces privacy risks and aligns with regulatory compliance while unlocking potential in sensitive domains such as healthcare, finance, and IoT.Despite these advantages, FL faces critical challenges, including susceptibility to adversarial attacks, communication bottlenecks, heterogeneity in devices and data distributions, and limited privacy guarantees.Promising research directions include the integration of differential privacy, secure multi-party computation, and blockchain for enhanced security.This paper underscores the importance of interdisciplinary efforts to overcome these challenges and explores potential applications across domains like personalized medicine, smart grid optimization, and decentralized AI in edge computing environments.It concludes by outlining pathways for future research, emphasizing the need for scalable, efficient, and privacy-preserving FL architectures.
Artificial intelligence has significantly advanced recently, penetrating various sectors such as healthcare, finance, and smart technology. A key factor driving this progress is federated learning (FL), an innovative decentralized machine learning approach. FL facilitates training models on diverse datasets without exchanging raw data, promoting collaboration while addressing privacy concerns associated with centralized data repositories. The framework utilizes a global deep-learning model from the central server. This study analyzes recent advancements and identifies several unanswered questions stemming from the expansion of FL research. It delves into privacy issues in the FL landscape, including secure multi-party computation, homomorphic encryption, differential privacy, and stochastic gradient descent. Additionally, it explores the application of artificial intelligence in public education, encompassing adaptive technologies, predictive analytics, and edge computing. Furthermore, it investigates the potential of FL in training models with low-power constraints, such as those in the Internet of Things (IoT). Nevertheless, challenges like communication overhead, interoperability standards, and data security concerns persist. This study underscores the transformative potential of federated learning in shaping the future of AI and emphasizes its crucial role in preserving privacy, enabling collaborative learning, and efficient learning mechanisms. Federated learning has been deployed in various domains, including wireless communications, service delivery, smart personal systems, and healthcare. This chapter charts a course forward by examining current FL challenges such as privacy preservation, communication overhead, low performance, and efforts to establish robust models. Federated learning represents a promising paradigm that aims to revolutionize artificial intelligence by facilitating privacy-preserving collaboration and enabling decentralized learning systems. While it holds significant potential, it also confronts challenges that require attention.
In the growing field of artificial intelligence, training models often involve collecting large datasets in a centralized way. This raises concerns about data privacy and security. This chapter explores a novel approach called federated learning (FL). It proposes a shift towards decentralized and collaborative training. Instead of centralizing data, federated learning allows individual devices like smartphones, laptops, or private servers to act as training nodes. Using local data, each node helps improve the model without directly sharing sensitive information. FL has demonstrably enhanced many applications. This chapter presents a comprehensive classification and clustering analysis of the ongoing advancements in FL, encompassing its application to a diverse array of technologies and real-world use cases. Specifically, the analysis delves into the integration of FL with various applications and technologies, such as artificial intelligence (AI) and the Internet of Things (IoT), healthcare (patient data analysis for disease prediction and personalized medicine), mobile devices (on-device personalization of AI features), voice assistants (enhanced speech recognition while safeguarding privacy), finance (collaborative fraud detection and personalized recommendations), autonomous vehicles (safer and more efficient driving through decentralized learning), and cross-domain learning (gaining broader insights while respecting data privacy boundaries). By analyzing the theoretical foundations, practical applications, and ongoing advancements of FL in these areas, this chapter illuminates its potential as a cornerstone for decentralized, privacy-preserving AI development.
The scaled Web 3.0 digital economy, represented by decentralized finance (DeFi), has sparked increasing interest in the past few years, which usually relies on blockchain for token transfer and diverse transaction logic. However, illegal behaviors, such as financial fraud, hacker attacks, and money laundering, are rampant in the blockchain ecosystem and seriously threaten its integrity and security. In this paper, we propose a novel double graph-based Ethereum account de-anonymization inference method, dubbed DBG4ETH, which aims to capture the behavioral patterns of accounts comprehensively and has more robust analytical and judgment capabilities for current complex and continuously generated transaction behaviors. Specifically, we first construct a global static graph to build complex interactions between the various account nodes for all transaction data. Then, we also construct a local dynamic graph to learn about the gradual evolution of transactions over different periods. Different graphs focus on information from different perspectives, and features of global and local, static and dynamic transaction graphs are available through DBG4ETH. In addition, we propose an adaptive confidence calibration method to predict the results by feeding the calibrated weighted prediction values into the classifier. Experimental results show that DBG4ETH achieves state-of-the-art results in the account identification task, improving the F1-score by at least 3.75% and up to 40.52% compared to processing each graph type individually and outperforming similar account identity inference methods by 5.23 % to 12.91 %.
Blockchain technology, known for its immutable distributed ledger, which greatly improves the credibility of data management in various applications. However, the immutability may result in erroneous data being permanently stored in the blockchain, affecting the security of the blockchain system. To address this issue, redactable blockchain is proposed to allow flexibly modifications of erroneous data in blockchain. Despite their promise, current redactable blockchain solutions often fall short in balancing two critical aspects: decentralization and data accountability. In this paper, we propose a Decentralized, Accountable and Redactable Blockchain solution (DARB). Our solution aims to mitigate the risks associated with central authority while ensuring secure accountability in data modification processes. Decentralization is achieved by using authorized authorities instead of the central authority, utilizing decentralized ciphertext policy attribute-based encryption. Additionally, it incorporates traceable ring signatures, which enable the authorized authorities to collaborate effectively in holding edited data accountable and tracing the identity of malicious modifiers. The security analysis and experimental results demonstrate that the DARB scheme successfully facilitates secure data rewriting and ensures accountability, all while maintaining an acceptable level of additional time overhead.
Janak Dhokrat, Namita Pulgam, Tabassum Maktum, Vanita Mane
In digital landscape of today’s ongoing world, the imperative for enhanced security in cloud-based data processing is paramount. This paper introduces an innovative framework that seamlessly integrates Homomorphic Encryption and Zero-Knowledge Proofs (ZKPs) to bolster data privacy and confidentiality. This paper explores the technical intricacies, real-world applications, and potential implications of this fusion framework. Homomorphic Encryption empowers computations on encrypted data without compromising privacy, while Zero-Knowledge Proofs offer a mechanism to verify computations without exposing sensitive details. The effectiveness and adaptability of the proposed framework is demonstrated through meticulous analysis and practical deployment in safeguarding cloud-based data processing. The proposed framework marks a significant stride towards creating an environment where data security is unequivocally prioritized.
Nicollas R. de Oliveira, Yago de R. dos Santos, Guilherme Nunes Nasseh Barbosa, Lúcio Henrik A. Reis · 8 authors
The expansion of Digital Health brings increasing data privacy and security challenges, mainly due to data collection by service providers and third parties. The decentralized approach of Self-Sovereign Identity emerges as a solution, offering users direct control over their data. This paper proposes the SmartMed system for controlling access to private medical data by attribute-based access control implemented on smart contracts. The paper investigates the performance limitations of the Ethereum and Besu blockchain platforms in controlling access to medical data. The proposal develops smart contracts to perform attribute-based access control and to store log records in the blockchain, highlighting the detailed performance analysis on both tested platforms. The results reveal the superiority of the Besu platform over Ethereum, indicating a lower computational cost per transaction. Our proposal innovates by proposing a system based on smart contracts to guarantee the authenticity of medical data, complemented by the use of Keycloak in managing access to healthcare systems.
Mpyana Mwamba Merlec, Nday Kabulo Sinai, Seng-Phil Hong, Hoh Peter In
The proliferation of digital technologies has led to an exponential growth in personal data generation, raising significant privacy, security, and ownership control challenges. However, existing centralized identity and data management models present concerns leading to data breaches, unauthorized data sharing, and loss of user ownership control. To address these issues, this article proposes a novel Personal Data-as-a-Service (PDaaS) platform, which leverages the robustness of a permissioned blockchain to ensure data integrity and access control, while using IPFS for decentralized and resilient data storage. It enables a secure and decentralized user-centric framework for managing personal data while preserving user privacy and data sovereignty. Leveraging a suite of advanced technologies including decentralized identifiers, verifiable credentials, enhanced encryption techniques (i.e., quantum-resistant encryption), zero-knowledge proofs, and dynamic consent management, the PDaaS platform enables individuals to retain ownership and control over their data while facilitating secure and privacy-preserving data processing, sharing, exchange, and monetization. This paper presents the design considerations and framework architecture of the proposed platform, which was built using the Hyperledger Besu to assess its feasibility and performance. It also discusses the implications, use cases, and challenges of deploying the PDaaS platform.
Privacy problems in blockchain smart contracts arise from the inherent transparency of the technology. While blockchain ensures data integrity, it also exposes sensitive information to all participants. This lack of privacy can be a concern in industries requiring confidentiality, like finance or healthcare, prompting the need for privacy solutions in smart contracts. The existing smart contracts face the problems of over-utilization or under-utilization of privacy parameters due to the unavailability of online or offline privacy classification; smart contracts fall behind in solving privacy issues.In this paper, we introduce the first privacy classification framework for smart contracts. We call our framework oFfloaded privAcy-classified Smart contrAct for bLocKchAins (FASALKA). To be specific, FASALKA runs a novel privacy-ensured smart contract that includes a novel hybrid learning mechanism. This hybrid learning mechanism combines the potential of federated learning and reinforcement learning. We deploy Ethereum on Azure and run a set of experiments to measure the performance of our proposed FASALKA. We compare a general Ethereum framework with an Ethereum framework using our proposed FASALKA. We observe that the Ethereum framework shows 1.1% more latency than the general Ethereum; however, our proposed framework has a similar throughput of 21 TPS. Besides, FASALKA has the 100% accuracy of privacy classification, which is not present in general Ethereum. Thus, our proposed FASALKA is efficient and beneficial for the privacy-ensured blockchains.
Ensuring secure and reliable urban metaverse cyberspaces requires addressing two critical challenges, namely, cybersecurity and privacy protection. In the upcoming years, it is anticipated that cybercrime activities will be widespread in this ecosystem, which has trillions of dollars in economic value. This report explores a Blockchain-Facilitated Federated Security-Preserving Deep Learning (BF-FSPDL) authentication and verification method using immersive metaverse devices. Blockchain technology and Federated Learning (FL) are merged not only to eliminate the requirement of a trusted third party for the verification of the authenticity of transactions and immersive actions, but also, to avoid Single Point of Failure (SPoF) and Generative Adversarial Networks (GAN) attacks by detecting the malicious nodes using the majority voting mechanism. The developed approaches in this research have been tested using Motion Capture Suits (MoCaps) in a co-simulation environment with the Proof of Work (PoW) consensus mechanism. The preliminary results prove the viability of employing the proposed approaches in realising the objectives presented in this report. The results suggest that the approaches can prevent impersonation, identity theft, and theft of credentials or avatars promptly before any transactions have been executed. The proposed system will be tested with a larger number of nodes involving the Proof of Stake (PoS) consensus mechanism using several other metaverse immersive devices as future work.
The privacy-preserving data aggregation is a challenging task in decentralized networks (e.g. blockchain) where multiple distinct contributors need to collaborate in order to perform a shared task (e.g. arithmetic operations) by preserving the privacy of each individual data. The existing protocols for the privacy-preserving data aggregation in the literature may require the fully-complete hypercubes over the Ethereum blockchain where it supports limited number of contributors at a certain time (i.e. exactly 2knodes in k-dimension). Therefore, we theoretically analyze the security of such protocols from the perspective of underdetermined systems and identify the potential root problem so that any arbitrary number of nodes could be supported. For this problem, we propose three novel decentralized techniques (i.e. node multiplexing, topological recursing and data splitting) by comparing their relative advantages and disadvantages.
Internet of Things (IoT) technology is increasingly prevalent across various sectors, including the military and healthcare. IoT devices play a pivotal role in collecting and analyzing crucial data while executing assigned tasks. Given the sensitive nature of this data, access control in IoT is crucial for data protection, and regulating the accessibility of data, applications, and resources. Yet, conventional centralized access control mechanisms are not well-suited to the dynamic IoT environment. The decentralized and distributed nature of Distributed Ledger Technology (DLT) presents a promising solution due to its high degree of transparency. This paper investigates various DLT-based access control models, presenting their distribution levels based on access control functional points and evaluating their capabilities using a predefined set of criteria. Upon defining a set of criteria for assessing DLT-based access control models within the IoT, it was observed that only two publications can be classified as highly distributed based on functional points. Furthermore, the assessment revealed that no model possesses both a highly distributed architecture and a highly distributed functional point distribution level simultaneously. This highlights the need for further development of distributed, scalable, and flexible access control models that align with the characteristics of the Internet of Things. This may involve integrating additional functional points into the chain and implementing smart contracts.
G Ananya, Bindu Madhavi, Monisha Krishna Murthy, N. Guruprasad
In today’s world, Artificial Intelligence and Machine Learning are transforming many industries, but they rely on huge amounts of data leading to privacy issues. A better alternative is Federated learning. Federated Learning involves training the model from multiple sources using the decentralization technique, meaning each device trains the model on its local data thereby reducing the strain on the single server. This is useful in cases where the data is too large to be sent and maintained on a central server or in handling privacy and security concerns. Cybersecurity is a prime domain where vulnerable attacks and breaches can be prevented using this technique. Other domains like finance, healthcare, IoT etc. have transformed the idea of data-driven decisions. This paper gives an insight into the concept of Federated learning and why it is a better choice. It includes the various algorithms that can be implemented in multiple applications depicted through a comparative analysis. The choice of algorithm depends upon its efficiency and the desired cybersecurity application.
Sujit Biswas, Kashif Sharif, Zohaib Latif, Mohammed J. F. Alenazi · 6 authors
Abstract Smart device manufacturers rely on insights from smart home (SH) data to update their devices, and similarly, service providers use it for predictive maintenance. In terms of data security and privacy, combining distributed federated learning (FL) with blockchain technology is being considered to prevent single point failure and model poising attacks. However, adding blockchain to a FL environment can worsen blockchain's scaling issues and create regular service interruptions at SH. This article presents a scalable Blockchain‐based Privacy‐preserving Federated Learning (BPFL) architecture for an SH ecosystem that integrates blockchain and FL. BPFL can automate SHs' services and distribute machine learning (ML) operations to update IoT manufacturer models and scale service provider services. The architecture uses a local peer as a gateway to connect SHs to the blockchain network and safeguard user data, transactions, and ML operations. Blockchain facilitates ecosystem access management and learning. The Stanford Cars and an IoT dataset have been used as test bed experiments, taking into account the nature of data (i.e. images and numeric). The experiments show that ledger optimisation can boost scalability by 40–60% in BCN by reducing transaction overhead by 60%. Simultaneously, it increases learning capacity by 10% compared to baseline FL techniques.
D. Rosy Salomi Victoria, S. Roselin Mary, K. Somasundaram
Evident Guard is the best way to add credibility to the evidence in the court. It includes the First Information Report (FIR) system, SHA-1 algorithm, and secure attachment of evidence. This system revolutionizes the current mode of an investigation that is based on trustworthiness, and positive law such as transparency and honesty. After linking FIR with a safe evidence app; users will be able to upload their own proof directly thus enhancing the transparency of the investigation process. Pivotal contents will be in an instant glance for endurance by case involved groups. In the SHA-1 cryptographic algorithm, the alteration of the original program will be detected as a result of the hash changing its value along an iteration number. The program hashes each piece of evidence and delivers them as well-defined hash values hence the data getting unique fingerprints. Cryptography used the representations of the encoding technique to verify that original version data had no definite hash values. The system stores the hashed data instead of the centralized databases. The proof of the FIR-report evidence became real-time and tamper resistant with the blockchain, which is a technology which has made it possible to guarantee their unbreakable nature. The use of Non-Fungible Tokens (NFT) as part of blockchain technology is a proof for safeguarding the whole process. NFTs digitize evidence into unique digital goods that certify the ownership and truthfulness of the evidence.
In crowd-sourced data aggregation over the Internet, participants share their data points with curators. However, a lack of strong privacy guarantees may discourage participation, which motivates the need for privacy-preserving aggregation protocols. Moreover, existing solutions remain limited with respect to public auditing without revealing the participants’ data. In realistic applications, however, there is an increasing need for public verifiability (i.e., verifying the protocol correctness) while preserving the privacy of the participants’ inputs, since the participants do not always trust the data curators. At the same time, while publicly distributed ledgers may provide public auditing, these schemes are not designed to protect sensitive information. In this work, we introduce two protocols, dubbed Masquerade and zk-Masquerade, for computing private statistics, such as sum, average, and histograms, without revealing anything about participants’ data. We propose a tailored multiplicative commitment scheme to ensure the integrity of data aggregations and publish all the participants’ commitments on a ledger to provide public verifiability. zk-Masquerade detects malicious participants who attempt to poison the aggregation results by adopting two zero-knowledge proof protocols that ensure the validity of shared data points before being aggregated and enable a broad range of numerical and categorical studies. In our experiments, we use homomorphic ciphertexts and commitments for a variable number of participants and evaluate the runtime and the communication cost of our protocols.
Decentralized Federated Learning improves data privacy and eliminates single points of failure by removing reliance on centralized storage and model aggregation in distributed computing systems. Ensuring the integrity of computations during local model training is a significant challenge, especially before sharing gradient updates from each local client. Current methods for ensuring computation integrity often involve patching local models to implement cryptographic techniques, such as Zero-Knowledge Proofs. However, this approach becomes highly complex and sometimes impractical for large-scale models that use techniques such as random dropouts to improve training convergence. These random dropouts create non-deterministic behavior, making it challenging to verify model updates under deterministic protocols. We propose ProxyZKP, a novel framework combining Zero-Knowledge Proofs with polynomial proxy models to provide computation integrity in local training to address this issue. Each local node combines a private model for online deep learning applications and a proxy model that mediates decentralized model training by exchanging gradient updates. The multivariate polynomial nature of proxy models facilitates the application of Zero-Knowledge Proofs. These proofs verify the computation integrity of updates from each node without disclosing private data. Experimental results indicate that ProxyZKP significantly reduces computational load. Specifically, ProxyZKP achieves proof generation times that are 30-50% faster compared to established methods like zk-SNARKs and Bulletproofs. This improvement is largely due to the high parallelization potential of the univariate polynomial decomposition approach. Additionally, integrating Differential Privacy into the ProxyZKP framework reduces the risk of Gradient Inversion attacks by adding calibrated noise to the gradients, while maintaining competitive model accuracy. The results demonstrate that ProxyZKP is a scalable and efficient solution for ensuring training integrity in decentralized federated learning environments, particularly in scenarios with frequent model updates and the need for strong model scalability.