This paper presents the design and evaluation of an unpredictable random number generator (URNG) utilizing cryptocurrency prices. A URNG operates using a deterministic algorithm, while utilizing external entropy sources to generate random numbers that are practically unpredictable. The proposed URNG employs a linear feedback shift register (LFSR), whose sampling period are fluctuated by the cryptocurrency price Ptor its logarithmic return Rt. Using Bitcoin (BTC) price data, we simulated the proposed URNG and evaluated its randomness with the Diehard test. Our findings suggest that a 40-bit or longer LFSR, with sampling period fluctuations determined by either the least significant bit of Ptor the comparison of Rtto its average value, achieves satisfactory randomness quality. Future work includes evaluating the URNG with other cryptocurrencies and exploring new methods for entropy extraction.
The deterministic nature of blockchains presents a significant challenge to pseudo-random number generation. Conventional seed-based random number generation methods may not be suitable for deterministic environments as they may be predictable and susceptible to attacks. To address this challenge, this paper proposes the integration of a pseudo-random number generation oracle for the nodes of an Ethereum network. Such an oracle acts as an external provider of pseudo-random numbers, generating random data by using the Fortuna algorithm, which can be used by smart contracts and decentralized applications on the blockchain. However, the integration of an oracle raises additional security and reliability concerns as it relies on a central node that impairs the decentralization of the blockchain and depends on the ability of the oracle to provide unpredictable and non-tampered pseudo-random numbers. The presented implementation can be used in different sectors, such as games of chance, random selection and other scenarios where randomness is essential to guarantee fairness and security. Thus, the integration of a pseudo-random number generation oracle into a Ethereum network can significantly improve the functionality and security of such decentralized applications. In order to show the performance of the proposed system, a comparison is presented that evaluates the security improvements with respect to traditional randomization methods within smart contracts.
Hardware security is the root of trust in all modern ICT (Information and Communications Technology) systems. However, hardware security means something different for different communities. It has also a very wide scope. It covers efficient, secure implementations of new generations of cryptography such as light-weight crypto, post-quantum crypto as well as advanced schemes such as zero-knowledge proofs, fully homomorphic encryption, and computing on encrypted data in general [1][2]. Yet, implementations also must resist a wide variety of side-channel, fault, and micro-architectural attacks. Post-quantum algorithms might resist the attacks developed for quantum computers. Yet, they also have to be resistant to these attacks on classic platforms, see e.g. [3]. Security protocols rely on more than only cryptographic algorithms. They require analog and digital circuit techniques to design quality true random number generators, physically unclonable functions, secure key storage, and many more [4]. A recent report on "Revitalizing the U.S. Semiconductor Ecosystem" (from Executive Office of the President, President's Council of Advisors on Science and Technology, September 2022) [5] describes a set of recommendations on semiconductors and system security. In this presentation, we will demonstrate how our research addresses these recommendations and we will illustrate this with recent results and ongoing projects.
Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Public Key Encryption with Keyword Search (PEKS) is a widely adopted cryptographic scheme for retrieving encrypted data outsourced to cloud servers based on keywords. However, PEKS is susceptible to both offline and online Keyword Guessing Attacks (KGA). In this paper, We use Auxiliary Server to perform blind signing of user keywords to resist offline KGA and limit online KGA, then we introduce Password-Authenticated Encryption (PHE) as a means of authenticating users performing keyword searches. By leveraging passwords for identity verification and encryption key management, the keyword ciphertexts stored on the Storage Server undergo a secondary encryption process, ensuring that unauthorized users are unable to perform legitimate searches. Current password-based searchable encryption schemes are predominantly symmetric, often resulting in a more complex encryption workflow. Additionally, to address the computational overhead associated with exponentiation and zero-knowledge proofs in PHE-based schemes, we harness the capabilities of Intel SGX, a trusted execution environment. By offloading sensitive computational tasks related to password verification to SGX, we eliminate the need for costly exponentiation and zero-knowledge proofs, thereby enhancing the scheme's performance. This approach also achieves cross-period anonymity and addresses the issue of potential malicious auxiliary servers correlating user requests, as highlighted in Lai et al scheme. Consequently, the novel Server-aided Keyword Search with Password-hardened Encryption (SAKSPHE) we propose provides robust defense against offline KGA, restricts the feasibility of online KGA, and enables password-based user authentication alongside additional encryption of keyword ciphertexts for secure storage.
The WiFi fingerprint-based localization method is considered one of the most popular techniques for indoor localization. In INFOCOM'14, Li et al. proposed a wireless fidelity (WiFi) fingerprint localization system based on Paillier encryption, which is claimed to protect both client$C{{}^{\prime}\mathrm{s}}$location privacy and service provider$S{{}^{\prime}\mathrm{s}}$database privacy. However, Yang et al. presented a practical data privacy attack in INFOCOM'18, which allows a polynomial time attacker to obtain$S{{}^{\prime}\mathrm{s}}$database. We propose a novel WiFi fingerprint localization system based on Castagnos-Laguillaumie (CL) encryption, which has a trustless setup and is efficient due to the excellent properties of CL encryption. To prevent Yang et al.'s attack, the system requires that$S$selects only the locations from its database that can receive the nonzero signals from all the available access points in$C{{}^{\prime}\mathrm{s}}$nonzero fingerprint in order to determine$C{{}^{\prime}\mathrm{s}}$location. Security analysis shows that our scheme is secure under Li et al.'s threat model. Furthermore, to enhance the security level of privacy-preserving WiFi fingerprint localization scheme based on CL encryption, we propose a secure and efficient zero-knowledge proof protocol for the discrete logarithm relations in$C{{}^{\prime}\mathrm{s}}$encrypted localization queries.
This paper introduces a novel Distributed Key Generation (DKG) protocol based on the Commutative Supersingular Isogeny Diffie-Hellman (CSIDH) framework for secure multi-party cryptography. Our proposed protocol is designed to address scalability and security concerns, particularly in post-quantum cryptographic systems. The main contributions include the introduction of Piecewise Verifiable Proofs (PVPs) for non-interactive zero-knowledge verification of secret shares, and the provision of rigorous security analysis, including resistance to quantum adversaries via Shorâs and Groverâs algorithms. We analyze the protocolâs efficiency, ensuring low computational overhead even in large-scale systems, and compare it with other distributed cryptographic protocols such as RSA-based and lattice-based schemes. Through mathematical proofs and complexity analysis, we demonstrate that our protocol offers enhanced security, efficiency, and scalability in a post-quantum environment. The results presented in this paper provide a strong foundation for implementing secure multi-party computations in quantum-resistant systems.
Marlene Koelbing, Klaus Kieseberg, Ceren Ăulha, Bernhard Garn · 5 authors
Abstract In this paper, we propose the modelling of patterns of financial transactions â with a focus on the domain of cryptocurrencies â as splittings and present a method for generating such splittings utilizing integer partitions. We study current money laundering regulations and directives concerning thresholds for monitoring of financial transactions. We further exemplify that, by having the partitions respect these threshold criteria, the splittings generated from them can be used for modelling illicit transactional behavior such as is shown by smurfing. In addition, we conduct an analysis of the splittings occurring in money laundering efforts that took place in the aftermath of the Upbit hack. Based on the potential weaknesses identified by our research, we finally provide suggestions on how to improve current AML techniques and initiatives towards more effective AML efforts.
Privacy computing involves the extensive exchange and processing of encrypted data. For the parties involved in these interactions, how to determine the consistency of exchanged data without accessing the original data, ensuring tamper resistance, non-repudiation, quality traceability, indexing, and retrieval during the use of encrypted data, which is a key topic of achieving "Data Availability versus Visibility". This paper proposes a new type of homomorphism: Feature Homomorphism, and based on this feature, introduces a cryptographic scheme for data verification under ciphertext-only conditions. The proposed scheme involves designing a group of algorithms that meet the requirements outlined in this paper, including encryption/decryption algorithms and Feature Homomorphic Algorithm. This group of algorithms not only allows for the encryption and decryption of data but also ensures that the plaintext and its corresponding ciphertext, encrypted using the specified encryption algorithm, satisfy the following property: the eigenvalue of the plaintext obtained using the Feature Homomorphic Algorithm is equal to the eigenvalue of the ciphertext obtained using the same algorithm. With this group of algorithms, it is possible to verify data consistency directly by comparing the eigenvalues of the plaintext and ciphertext without accessing the original data (i.e., under ciphertext-only conditions). This can be used for tamper resistance, non-repudiation, and quality traceability. Additionally, the eigenvalue can serve as a ciphertext index, enabling searchable encryption. This scheme completes a piece of the puzzle in homomorphic encryption. Keywords: Privacy Computing, Data Consistency, Searchable Encryption, Zero-Knowledge Proof, Feature Homomorphism
Random numbers play a vital role in many decentralized applications (dApps), such as gaming and decentralized finance (DeFi) applications. Existing random number provision mechanisms can be roughly divided into two categories, on-chain, and off-chain. On-chain approaches usually rely on the blockchain as the major input and all computations are done by blockchain nodes. The major risk for this type of method is that the input itself is susceptible to the adversary's influence. Off-chain approaches, as the name suggested, complete the generation without the involvement of blockchain nodes and share the result directly with a dApp. These mechanisms usually have a strong security assumption and high complexity. To mitigate these limitations and provide a framework that allows a dApp to balance different factors involved in random number generation, we propose a hybrid random number generation solution that leverages IoT devices equipped with trusted execution environment (TEE) as the randomness sources, and then utilizes a set of cryptographic tools to aggregate the multiple sources and obtain the final random number that can be consumed by the dApp. The new approach only needs one honest random source to guarantee the unbiasedness of the final random number and a user can configure the system to tolerate malicious participants who can refuse to respond to avoid unfavored results. We also provide a concrete construction that can further reduce the on-chain computation complexity to lower the cost of the solution in practice. We evaluate the computation and gas costs to demonstrate the effectiveness of the improvement.
Open access
2 source records
Peer-to-Peer Network Technologies
Advanced Steganography and Watermarking Techniques
With the widespread use of cryptocurrencies and the development of anonymity network technology, how to effectively identify cryptocurrency transactions through anonymity networks such as Tor has become a major challenge in cybersecurity. We introduce a new traffic correlation technique, TSMCorr, aimed at identifying cryptocurrency transactions through anonymous networks like Tor. Traditional traffic correlation methods struggle with the high cost of deployment, while we leverage advanced feature engineering and deep learning, including a Traffic Volume Matrix (TSM), to develop a more accurate and efficient flow correlation model. TSMCorr not only improves upon existing methods in terms of F1 score by $15.5 \%$ on DeepCoFFEA dataset, but also lowers the computational time by $89 \%$, RAM consumption by $77.4 \%$, and model parameters by $11.5 \%$.
Internet Traffic Analysis and Secure E-voting
Chaos-based Image/Signal Encryption
Advanced Steganography and Watermarking Techniques
In the digital age, cryptographic systems are the most important part of safe communication. To protect data security, confidentiality, and validity, they need strong design frameworks. The math methods used in this paper are very important for designing and analyzing secure systems. As basic ideas, it looks at number theory, math, and complexity theory, with an emphasis on both old and new methods. Some important topics are the creation of prime numbers, modular arithmetic, elliptic curves, and finite fields, which are the basis for many encryption methods. The paper also talks about how complexity theory can be used to measure the strength of cryptography. It specifically talks about issues with discrete logarithms and integer factorization, which are at the heart of popular protocols like RSA and ECC. It also looks into lattice-based cryptography, which is seen as a strong option to quantum threats, and shows how hard it is to solve lattice issues. The study also looks at the design principles of symmetric cryptography, mainly block ciphers and stream ciphers, and how they use permutation groups and linear algebra to make sure that key plans and spread methods are safe. The paper also looks at secure hash functions, focusing on collision resistance, pre-image resistance, and how they are made using mathematics concepts such as Merkle-DamgÄrd and sponge functions. Advanced topics like homomorphic encryption and zero-knowledge proofs show how mathematics and cryptography are increasingly coming together. They show how they can be used to make operations safe on protected data and privacy-preserving protocols. This paper gives a full picture of how mathematical theories and methods are used to build strong cryptographic systems by combining strict mathematical models with real-world cryptographic needs. The discussion stresses that the field is always changing because of new threats and improvements in computers. It also calls for constant scientific progress to make cryptography stronger against future problems.
A niche corner of the Web3 world is increasingly making use of hardware-based Trusted Execution Environments (TEEs) to build decentralized infrastructure. One of the motivations to use TEEs is to go beyond the current performance limitations of cryptography-based alternatives such as zero-knowledge proofs (ZKP), fully homomorphic encryption (FHE), and multi-party computation (MPC). Despite their appealing advantages, current TEEs suffer from serious limitations as they are not secure against physical attacks, and their attestation mechanism is rooted in the chip manufacturer's trust. As a result, Web3 applications have to rely on cloud infrastruture to act as trusted guardians of hardware-based TEEs and have to accept to trust chip manufacturers. This work aims at exploring how we could potentially architect and implement chips that would be secure against physical attacks and would not require putting trust in chip manufacturers. One goal of this work is to motivate the Web3 movement to acknowledge and leverage the substantial amount of relevant hardware research that already exists. In brief, a combination of: (1) physical unclonable functions (PUFs) to secure the root-of-trust; (2) masking and redundancy techniques to secure computations; (3) open source hardware and imaging techniques to verify that a chip matches its expected design; can help move towards attesting that a given TEE can be trusted without the need to trust a cloud provider and a chip manufacturer.
Cloud computing allows clients with limited computational resources to offload computations to more powerful remote servers. In this paradigm, homomorphic encryption (HE) schemes enable a server to run any computation on a client's encrypted data. These schemes are widely used in cloud computing protocols such as delegated computing, two-party secure computation, and zero-knowledge proofs. Quantum homomorphic encryption (QHE) aims to achieve the objectives of HE with quantum data and quantum circuits, enabling cloud quantum servers to compute on encrypted quantum data uploaded by clients. In this work, we consider a scenario where a client has access to a quantum âencryption/decryption deviceâ, which allows the encryption, transmission, reception, and decryption of quantum states, but not universal quantum computation. In this setting, we provide a proof-of-concept software simulation of quantum homomorphic encryption. Our code implements the âEPR schemeâ of Broadbent and Jeffery, which allows for the execution of universal quantum circuits by the server at the cost of requiring shared EPR pairs between the client and server. Our implementation explores the near-term viability of the EPR scheme. Perhaps unsurprisingly, our experiments indicate that the additional cost of homomorphic circuit evaluation is minor in comparison to the simulation cost of the quantum operations. Our simulation toolkit is implemented in Python and is open-source.
Non-fungible tokens (NFTs) offer a unique method for representing digital and physical assets on the blockchain. However, the NFT market has recently experienced a downturn in interest, mainly due to challenges related to high entry barriers and limited market liquidity. Fractionalization emerges as a promising solution, allowing multiple parties to hold a stake in a single NFT. By breaking down ownership into fractional shares, this approach lowers the entry barrier for investors, enhances market liquidity, and democratizes access to valuable digital assets. Despite these benefits, the current landscape of NFT fractionalization is fragmented, with no standardized framework to guide the secure and interoperable implementation of fractionalization mechanisms. This paper contributions are twofold: first, we provide a detailed analysis of the current NFT fractionalization landscape focusing on security challenges; second, we introduce a standardized approach that addresses these challenges, paving the way for more secure, interoperable, and accessible NFT fractionalization platforms.
This article proposes a new digital watermarking mechanism based on the Ethereum blockchain, Smart Contract, and Interplanetary File System (IPFS), with an enhanced Fast Walsh Hadamard Transform (FWHT) algorithm for watermark embedding and extraction. The proposed scheme aims to address the limitations of existing digital watermarking techniques, such as dependence on third-party platforms, by leveraging the decentralization feature of blockchain. The Smart Contract is used to manage the transaction between the parties involved in the watermarking process, while IPFS is used to store the watermark data. The enhanced FWHT algorithm is used to embed the watermark into the host image without affecting its visual quality. The results show that the proposed scheme outperforms the state-of-the-art algorithms in terms of both imperceptibility and robustness. Additionally, it demonstrates that our scheme can effectively resist various attacks. Therefore, our scheme can be a promising solution for image copyright protection, authentication applications, and image trading.
Open access
Advanced Steganography and Watermarking Techniques
The expansion of decentralized cryptocurrencies poses notable complexities for law enforcement in terms of detecting unlawful behaviors, as well as in the identification of individuals and the retrieval of transaction histories of perpetrators who take advantage of the pseudonymous nature inherent in the cryptocurrency system. This research paper puts forth a solution called Kavach. The designated user of Kavach will be an investigator. The tool leverages graph machine learning for the categorization of transactions as illicit or legitimate. It utilizes graph-based embeddings for the recognition of potentially suspicious addresses within the bitcoin network. The tool incorporates a predefined watch list for such suspicious addresses and will have the capability to trace the digital trail of these addresses using Open Source Intelligence (OSINT).
Smart contracts are a major tool in Ethereum transactions. Therefore hackers can exploit them by adding code vulnerabilities to their sources and using these vulnerabilities for performing malicious transactions. This paper presents two successful approaches for detecting malicious contracts: one uses opcode and relies on GPT2 and the other uses the Solidity source and a LORA fine-tuned CodeLlama. Finally, we present an XGBOOST model that combines gas properties and Hexa-decimal signatures for detecting malicious transactions. This approach relies on early assumptions that maliciousness is manifested by the uncommon usage of the contracts' functions and the effort to pursue the transaction.