PGP is built upon a Distributed Web of Trust in which the trustworthiness of a user is established by others who can vouch through a digital signature for that particular identity. Preventing its wholesale adoption are a number of inherent weaknesses to include (but not limited to) the following: 1) Trust Relationships are built on a subjective honor system, 2) Only first degree relationships can be fully trusted, 3) Levels of trust are difficult to quantify with actual values, and 4) Issues with the Web of Trust itself (Certification and Endorsement). Although the security that PGP provides is proven to be reliable, it has largely failed to garner large scale adoption. In this paper, we propose several novel contributions to address the aforementioned issues with PGP and associated Web of Trust. To address the subjectivity of the Web of Trust, we provide a new certificate format based on Bitcoin which allows a user to verify a PGP certificate using Bitcoin identity-verification transactions - forming first degree trust relationships that are tied to actual values (i.e., number of Bitcoins transferred during transaction). Secondly, we present the design of a novel Distributed PGP key server that leverages the Bitcoin transaction blockchain to store and retrieve Bitcoin-Based PGP certificates. Lastly, we provide a web prototype application that demonstrates several of these capabilities in an actual environment.
In this paper, I propose a new concept for understanding the role of algorithms in daily life: algorithmic authority. Algorithmic authority is the legitimate power of algorithms to direct human action and to impact which information is considered true. I use this concept to examine the culture of users of Bitcoin, a crypto-currency and payment platform. Through Bitcoin, I explore what it means to trust in algorithmic authority. My study of the Bitcoin community utilizes interview and survey data. I found that Bitcoin users prefer algorithmic authority to the authority of conventional institutions which they see as untrustworthy. However, I argue that Bitcoin users do not have blind faith in algorithms; rather, they acknowledge the need for mediating algorithmic authority with human judgment. I examine the tension between members of the Bitcoin community who would prefer to integrate Bitcoin with existing institutions and those who would prefer to resist integration.
Autor w pionierskiej dla nauki prawa polskiego publikacji poświęconej bitcoinowi (oraz innym tzw. walutom wirtualnym) sformułował wiązkę podstawowych tez na temat tego przedmiotu stosunków prywatnoprawnych. Podstawowe znaczenie ma postawienie i wnikliwe uargumentowanie tezy, która głosi, że bitcoin (oraz inne tzw. waluty wirtualne) jest innym niż pieniądz miernikiem wartości. Jest więc legalny jako taki, w zakresie wszystkich wyobrażalnych sfer jego faktycznego i potencjalnego zastosowania. Zobowiązania przewidujące świadczenie wyrażone w bitcoinie są - ponad wszelką wątpliwość - zaskarżalne, możliwe do zasądzenia przez sąd i wyegzekwowania. Wykorzystanie bitcoina na płaszczyźnie stosunków prywatnoprawnych opiera się na znanych konstrukcjach prawa cywilnego, przewidzianych przez kodeks cywilny. Ponieważ bitcoin nie jest rzeczą, przechodzi ze zbywcy na nabywcę po spełnieniu przesłanek przewidzianych dla rozporządzenia wierzytelnością. Może być przedmiotem sprzedaży i zamiany, a także innych zobowiązań przewidujących świadczenie typu dare, a więc np. przedmiotem pożyczki, zastrzeżenia zadatku, czy też kary umownej. Konstrukcja prawna bitcoina wpisuje się w wyartykułowaną i wnikliwie uzasadnianą na łamach innych publikacji Autora koncepcję środków symbolizujących prawo podmiotowe. Na tej zasadzie bitcoin jest po prostu prawem podmiotowym związanym z nośnikiem, co tłumaczy jednocześnie charakter prawny oraz dopuszczalne płaszczyzny praktycznego zastosowania. Dlatego bitcoin zasadniczo należy zakwalifikować do tej samej kategorii, co znaki legitymacyjne stwierdzające obowiązek świadczenia, dokumentowe papiery wartościowe oraz zdematerializowane instrumenty finansowe. Niniejsza publikacja stanowi pierwszą z dwóch poświęconych przez Autora bitcoinowi. W drugiej Autor podejmuje więcej kwestii szczegółowych (zob. Monitor Prawniczy 2015, nr 4).
Gheith A. Abandah, Khalid A. Darabkh, Tawfiq Ammari, Omar Qunsul
Electronic voting provides accuracy and efficiency to the electoral processes. World democracies would benefit from a secure e-voting system not only to improve voter participation and trust but also to prevent electoral fraud. However, current e-voting systems are complex and have security weaknesses. In this paper, we describe a secure e-voting system for national and local elections (S-Vote). This system satisfies the important requirements of an e-voting system through state-of-the-art technologies and secure processes. S-Vote relies on homomorphic cryptography, zero-knowledge proofs, biometrics, smartcards, open-source software, and secure computers for securely and efficiently implementing the system processes over the various stages of the electoral process, without relying on online network connections. We outline the main conclusions of the pilot implementations of S-Vote that tested the main technologies and processes used. We also explain how the used technologies and processes achieve the system requirement. In conclusion, we recommend adopting S-Vote for its security, flexibility, economic, and scalability features.
Door het internet kan de burger rechtstreeks contact krijgen met zijn publiek zonder hulp van derden als omroepen, kranten, uitgevers, muziekindustrie, etc. Bij al deze communicaties is prominent (Youtube) of minder prominent (Wordpress) een derde partij betrokken die de communicatie faciliteert. Deze derde ontbreekt bij Bitcoin. Je kunt snel, betrouwbaar, met iedereen waar ook ter wereld bitcoins uitwisselen. Dus geen exorbitante bonussen, hoge transactiekosten, of ander ingrijpen of sturing van bovenaf. Internet in de meeste zuivere vorm: technologie van eindgebruiker naar eindgebruiker, zonder tussenkomst van derden.
This paper introduces a new information technology: ma3tch (autonomous anonymous analysis). Ma3tch enables virtual information integration to build a `dynamic networked collective intelligence' without infringing upon security, confidentiality, privacy and/or data protection regulations. It provides organizations with information and knowledge advantages. The ma3tch technology is empowered by a decentralized information oriented architecture: a `privacy by design' framework that uses distributed agents to facilitate decentralized but integrated information access, processing and analysis. It shapes a `virtual information cloud' between autonomous organizations that enables secure, integral and intelligent real time information analysis. Relevant information and knowledge distributed between autonomous organizations is automatically detected and applied throughout the network as soon as it emerges. The dynamic design principles allow practically any type of (cross domain) information to be virtually integrated: government, commercial, intelligence, law enforcement, financial, telecom, biomedical, compliance, etc., without infringing privacy, confidentiality, security or data protection rules and regulations. It advances both privacy AND knowledge beyond conventional limitations.
Online advertising is at the core of today’s Web: it is the main business model, generating large annual revenues expressed in tens of billions of dollars that sponsor most of the online content and services. Online advertising consists of delivering marketing messages, embedded into Web content, to a targeted audience. In this model, entities attract Web traffic by offering the content and services for free and charge advertisers for including advertisements in this traffic (i.e., advertisers pay for users’ attention and interests). Online advertising is a very successful form of advertising as it allows for advertisements (ads) to be targeted to individual users’ interests; especially when advertisements are served on users’ mobile devices, as ads can be targeted to users’ locations and the corresponding context. However, online advertising also introduces a number of problems. Given the high ad revenue at stake, fraudsters have economic incentives to exploit the ad system and generate profit from it. Unfortunately, to achieve this goal, they often compromise users’ online security (e.g., via malware, phishing, etc.). For the purpose of maximizing the revenue by matching ads to users’ interests, a number of techniques are deployed, aimed at tracking and profiling users’ digital footprints, i.e., their behavior in the digital world. These techniques introduce new threats to users’ privacy. Consequently, some users adopt ad-avoidance tools that prevent the download of advertisements and partially thwart user profiling. Such user behavior, as well as exploits of ad systems, have economic implications as they undermine the online advertising business model. Meddling with advertising revenue disrupts the current economic model of the Web, the consequences of which are unclear. Given that today’s Web model relies on online advertising revenue in order for users to have access and consume content and services for “free”, coupled with the fact that there are many threats that could jeopardize this model, in this thesis we address the security, privacy and economic issues stemming from this fundamental element of the Web. In the first part of the thesis, we investigate the vulnerabilities of online advertising systems. We identify how an adversary can exploit the ad system to generate profit for itself, notably by performing inflight modification of ad traffic. We provide a proof-of-concept implementation of the identified threat on Wi-Fi routers. We propose a collaborative approach for securing online advertising and Web browsing against such threats. By investigating how a certificate-based authentication is deployed in practice, we assess the potential of relying on certificate-based authentication as a building block of a solution to protect the ad revenue. We propose a multidisciplinary approach for improving the current state of certificate-based authentication on the Web. In the second part of the thesis, we study the economics of ad systems’ exploits and certain potential countermeasures. We evaluate the potential of different solutions aimed at protecting ad revenue being implemented by the stakeholders (e.g., Internet Service Providers or ad networks) and the conditions under which this is likely to happen. We also study the economic ramifications of ad-avoidance technologies on the monetization of online content. We use game-theory to model the strategic behavior of involved entities and their interactions. In the third part of the thesis, we focus on privacy implications of online advertising. We identify a novel threat to users’ location privacy that enables service providers to geolocate users with high accuracy, which is needed to serve location-targeted ads for local businesses. We draw attention to the large scale of the threat and the potential impact on users’ location privacy.
The increasing trend of embedding positioning capabilities (e.g., GPS) in mobile devices facilitates the widespread use of Location Based Services. For such applications to succeed, privacy and confidentiality are key issues. Over all privacy will have to be managed through a combination of technology, legislation, corporate policy, and social norms. There are many data privacy schemes including Zero Knowledge Proof (ZKP) those can be used for location privacy. ZKP is also useful for removing the bottleneck problem introduced by use of trusted third party. In the earlier work, authors proposed the concept of middleware architecture in which, request and response are not routed through middleware for every transaction. This has reduced the dependency on middleware. This paper presents correspondence between the authentication techniques used in above said architecture and zero knowledge proof technique. Use of the concept of zero knowledge proof for authentication and authorization in the domain of location based services is also explored.
Abstract. Bitcoin is quickly emerging as a popular digital payment system. However, in spite of its reliance on pseudonyms, Bitcoin raises a number of privacy concerns due to the fact that all of the transactions that take place are publicly announced in the system. In this paper, we investigate the privacy guarantees of Bitcoin in the setting where Bitcoin is used as a primary currency for the daily transactions of individuals. More specifically, we evaluate the privacy that is provided by Bitcoin (i) by analyzing the genuine Bitcoin system and (ii) through a simulator that faithfully mimics the operation of Bitcoin in the context where Bitcoin is used for all transactions within a university. In this setting, our results show that the profiles of almost 40 % of the users can be, to a large extent, recovered even when users adopt privacy measures recommended by Bitcoin. To the best of our knowledge, this is the first work that comprehensively analyzes, and evaluates the privacy implications of Bitcoin. As a by-product, we have designed and implemented the first simulator of Bitcoin; our simulator can be used to model the interaction between Bitcoin users in generic settings. 1
Anonymity in Bitcoin, a peer-to-peer electronic currency system, is a complicated issue. Within the system, users are identified by public-keys only. An attacker wishing to de-anonymize its users will attempt to construct the one-to-many mapping between users and public-keys and associate information external to the system with the users. Bitcoin tries to prevent this attack by storing the mapping of a user to his or her public-keys on that user's node only and by allowing each user to generate as many public-keys as required. In this chapter we consider the topological structure of two networks derived from Bitcoin's public transaction history. We show that the two networks have a non-trivial topological structure, provide complementary views of the Bitcoin system and have implications for anonymity. We combine these structures with external information and techniques such as context discovery and flow analysis to investigate an alleged theft of Bitcoins, which, at the time of the theft, had a market value of approximately half a million U.S. dollars.
David Bernhard, Véronique Cortier, Olivier Pereira, Ben Smyth · 5 authors
Abstract. Recent results show that the current implementation of He-lios, a practical e-voting protocol, does not ensure independence of the cast votes, and demonstrate the impact of this lack of independence on vote privacy. Some simple fixes seem to be available and security of the revised scheme has been studied with respect to symbolic models. In this paper we study the security of Helios using computational models. Our first contribution is a model for the property known as ballot privacy that generalizes and extends several existing ones. Using this model, we investigate an abstract voting scheme (of which the revised Helios is an instantiation) built from an arbitrary encryp-tion scheme with certain functional properties. We prove, generically, that whenever this encryption scheme falls in the class of voting-friendly schemes that we define, the resulting voting scheme provably satisfies ballot privacy. We explain how our general result yields cryptographic security guaran-tees for the revised version of Helios (albeit from non-standard assump-tions). Furthermore, we show (by giving two distinct constructions) that it is possible to construct voting-friendly encryption, and therefore voting schemes, using only standard cryptographic tools. We detail an instan-tiation based on ElGamal encryption and Fiat-Shamir non-interactive zero-knowledge proofs that closely resembles Helios and which provably satisfies ballot privacy. 1
Recently we have observed a growing demand for secure technologies for e-commerce that do not put customers at risk of identity theft. We have also experienced the advent of Web 2.0 which has led to new business models and which has changed the way users interact with the Web. This thesis proposes a set of strategies and enhancements towards providing improved security and privacy in such new settings. We introduce a novel concept: Fair Rights Management (FRM). It can be classified as a usage control solution. FRM enables a flexible way of managing digital content. There was a need to provide additional security extensions to keep such a flexible model applicable. Thus, in our approach we take advantage of trust obtained from social networks. This is also the reason why we created an efficient zero-knowledge proof protocol that is lightweight enough to be deployed within existing web-applications. The proposed protocol is also successfully integrated with Semantic Web architecture and associated components. It enables practical Web and mobile applications which employ trust-based transactions as part of their workflow. This core contribution overcomes various disadvantages of prior art and enables a range of new applications and potentially new business models. We show that compared to existing Usage Control Models (UCON) (i) FRM is a step towards fair use in the digital world and we also argue that our approach is enforced by law; (ii) the participants of the proposed solution do not put their privacy at risk. Our research shows that existing infrastructure is sufficient to support ZKP-based solutions; and thus, it is feasible to offer the users enhanced privacy within existing deployed solutions.
Kazi Md. Rokibul Alam, Shinsuke Tamura, Shuji Taniguchi, Tatsuro Yanase
This paper proposes a new electronic voting (e-voting) scheme that fulfills all the security requirements of e-voting i.e. privacy, accuracy, universal verifiability, fairness, receipt-freeness, incoercibility, dispute-freeness, robustness, practicality and scalability; usually some of which are found to be traded. When compared with other existing schemes, this scheme requires much more simple computations and weaker assumptions about trustworthiness of individual election authorities. The key mechanism is the one that uses confirmation numbers involved in individual votes to make votes verifiable while disabling all entities including voters themselves to know the linkages between voters and their votes. Many existing e-voting schemes extensively deploy zero-knowledge proof (ZKP) to achieve verifiability. However, ZKP is expensive and complicated. The confirmation numbers attain the verifiability requirement in a much more simple and intuitive way, then the scheme becomes scalable and practical.
This paper proposes a new electronic voting (e-voting) scheme that fulfills all the security requirements of e-voting. The key mechanism is the one that uses confirmation numbers involved in individual votes to make votes verifiable while disabling all entities including voters themselves to know the linkages between voters and their votes. Unlike complicated zero knowledge proof involved in many e-voting schemes, the confirmation numbers attain the verifiability requirement in a much more simple and intuitive way, then the scheme becomes scalable and practical.
Many business models for smart products, like pay-per-use, require that the smart product can digitally verify whether the user has a contract with the smart product and should be granted access to privileged functionality. Traditional means to do so, e.g. password login, are very obtrusive and can thus not be applied for smart product scenarios. In this paper, we present the mechanism of association. Associations represent the abstract concept of a digitally checkable contract on the middleware level. Associations use a service for digitally representing the user that performs the tedious parts of creating a digitally checkable contract automatically. Thus, the interaction can be established unobtrusively. As this service acts on behalf of the user, the user must trust this service. We address this issue in two ways: the service is executed on the personal trusted device of the user and the user can control and inspect the actions of the service via a user interface.
In this paper we have formulated an online voting framework which ensures that the voter is able to vote in a public environment without his vote being eavesdropped on by a neighbor i.e. his vote becomes known to his neighbor or a third party when he marks his choice on a particular candidate. We also give a model for secure online voting system using zero knowledge proof and other cryptographic schemes encompassing the voting process of the user and the backend process of servers and the tallying and display of results and verification by the user of the vote cast by him at a later stage.
This paper proposes a new PKI-based public-key traitor tracing scheme. The length of the public-key and that of each users private-key are independent of the number of users. The scheme is built to be asymmetric so as to protect legal users from being framed . Previous traitor tracing schemes cannot protect against a legal user to divulge his/her private key to others , this scheme is a self-enforcement one, so no legal users will give out their private keys willingly. This scheme verifies a users secret-key with the method of zero-knowledge proof , so no user can get a private-key that does not include his/her secret-key in PKI .
The voting plays important roles in a democratic country. Due to the problems of the existed voting m ethod, the new voting methods, electronic voting system, have been developing using the computer net work and cryptographic techniques. Many electronic voting schemes have been introduced for secure electronic voting systems. In this paper, we propose the secure electronic voting for absentee e-voting system. The absentee voting plays the important percentage in the existing voting system. But, the abs entee vote can not look forward to the security because of transmit by mail. The absentee does not kno w whether one’s voting is exactly counted or not. In this paper, we propose the absentee e-voting syste m based on security, completeness and verifiability. We use r-th residue cryptography for homomorphi c encryption, ZKIP (Zero-Knowledge interactive proofs), RSA algorithm. Also, we propose the ne w method of tallying for multi-candidate. The goals of out voting system are the absentee vot ing based on privacy, universal verifiability, reuseability and multi-candidate.
Tim Bell, Harold Thimbleby, Michael R. Fellows, Ian H. Witten · 5 authors
Modern cryptography can achieve levels of security and authentication that non-specialists find literally incredible. Techniques include information-hiding protocols, zero-knowledge proofs and public key cryptosystems; they can be used to support applications like digital signatures, digital cash, on-line poker and secure voting in ways that are provably secure—far more secure than the traditional systems they replace. This paper describes simple versions of such applications that have been used to give school-children and the general public a broad understanding of what can be achieved, and how.
Smart contracts combine protocols with user interfaces to formalize and secure relationships over computer networks. Objectives and principles for the design of these systems are derived from legal principles, economic theory, and theories of reliable and secure protocols. Similarities and differences between smart contracts and traditional business procedures based on written contracts, controls, and static forms are discussed. By using cryptographic and other security mechanisms, we can secure many algorithmically specifiable relationships from breach by principals, and from eavesdropping or malicious interference by third parties, up to considerations of time, user interface, and completeness of the algorithmic specification. This article discusses protocols with application in important contracting areas, including credit, content rights management, payment systems, and contracts with bearer.