Tianlong Fei, Yuan Chang, Jiaqi Wang, Ning Lu · 5 authors
As Bitcoin users grow, the protection of the Bitcoin privacy protection becomes an important issue. Bitcoin mixing technology can cut off the connection between buyers and sellers. Now, a more effective method is used to carry out a coin mixing operation. The existing flat structure and two-layer structure have their own deficiencies. Therefore, anonymous Bitcoin mixing scheme is proposed. In order to increase the anonymity of coin mixing, group blind signature technology is used to expand the anonymous set of users. Moreover, a Supervisor for supervising Mixes is introduced to ensure the security of the system and the threshold signature is also used to ensure the security of the Mix's Bitcoin to prevent the Supervisor from stealing Bitcoin. Finally, the security analysis and experiment are given to conclude that our scheme is secure and efficient.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
We consider a new class of business-to-business (B2B) blockchain applications that require the execution of specific subroutines to simultaneously satisfy authenticity, compliance, and anonymity. Existing blockchain smart contract protocols do not, either directly or with minor modifications, ensure all the three properties. We present the ACAn smart contract protocol guaranteeing authenticity and compliance over a set of anonymous (unlinkable) subroutine executions. ACAn achieves this through a novel combination of zero-knowledge proofs and multiple Merkle-Tree commitments. We specifically focus on implementing ACAn on Hyperledger Fabric, a popular platform for B2B blockchain applications, which processes transactions in the execute-order-commit framework. The latter, however, leads to performance degradation due to read-write conflicts arising out of multiple clients independently executing the ACAn protocol. We propose enhancements to Hyperledger Fabric's smart contract API to support deferred changes to the shared ledger, allowing us to adapt ACAn so that such conflicts are effectively resolved. Our work provides evidence of significant performance gains due to the proposed enhancements, as well as experimental evaluation of the protocol's privacy preserving components.
Darknet websites, the warm beds for money laundry, child pornography, and illicit drug trafficking, are built on hidden services and anonymous communication protocols. Cryptocurrencies, such as Bitcoin, is the major payment method used on Darknet. In this paper, we summarize and introduce the latest development on de-anonymization techniques used to reveal the hidden information that are helpful for crime investigation, which is a key step for the future research work.
Nasir D. Khan, Chrysostomos Chrysostomou, Babar Nazir
Electronic First Information Report (e-FIR) is a basic document filed to the police stations by a victim or someone on his/her behalf when a cognizable offense such as murder, kidnapping, rape, theft, etc. is committed. In the e-FIR database, the offense's record can be compromised due to its centralized nature, and further the intentional registration of false e-FIR can occur. Thus, data integrity and transparency are key concerns in e-FIR database. In this paper, e-FIR data integrity and false registration appended with police stations in a centralized database are addressed via a consensus-based distributed blockchain solution, as an integral part of a smart city environment. Specifically, a smart contract based intelligent framework has been utilized to explore the potential of Ethereum blockchain in providing integrity to e-FIR data stored in a police station's database. Local database is interfaced with Ethereum blockchain using Web3 Remote Procedure Call (RPC) protocol. Multiple simulations have been performed to evaluate the performance of the proposed framework. Our results show a trade-off between different hashing algorithm security level for the offenses data and number of transactions stored in a single block on blockchain ledger.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Cryptocurrencies like Bitcoin have the potential advantages to break traditional financial barriers, which have attracted great interests from civilian users, financial and online commercial industry, and researchers. However, a recent study [1] reported that approximately one-quarter of Bitcoin users and one-half of Bitcoin transactions are associated with illicit activity. Around US$72 billion of unlawful activity per year involves Bitcoin, which is close to the scale of the U.S. and European markets for illegal drugs. We have made an effort to understand and try our best to exhaustively discover Bitcoin mixing or tumbling services (essentially money laundering mechanisms) which exist or had existed. In our study, 69 services were identified, and evaluation of the public discussion around these services reveals certain trends in Bitcoin user understanding of privacy issues and enforcement of anti-money laundering regulation. So far, Law enforcement interference with Bitcoin laundering services is uncommon, while our study showed that most services failed due to lack of user trust. Trust is perhaps the greatest challenge amongst Bitcoin anonymization services, as many services that have existed appear to be outright scams, and even legitimate services sometimes disappear with user funds. We will report other observations and discussions at the end of the paper.
the paper reveals the prospects of using electronic trust services, in particular electronic signature services, for building electronic (remote) voting systems. The advantages of such systems are described, as well as problematic issues related to the implementation of remote voting systems in practice. The most well-known existing electronic voting protocols based on classical principles are analyzed. Their shortcomings and difficulties in implementation are highlighted. We offer a new principle for building an electronic voting system. Unlike the analyzed protocols, the new approach is based on a decentralized public key infrastructure. The paper shows how, with the help of DLT technology, it is possible to ensure the fulfillment of the necessary requirements for system security without introducing significant redundancy into the interaction process of all stakeholders. The electronic voting algorithm is a modification of the Nurmi-Salom-Santin protocol which avoids the need to organize special bodies for the formation of voter lists. It also allows maintaining the anonymity of voters without the use of blind signatures.
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
The paper deals with the concept of homomorphic encryption and the possibility of its use in the mechanism of electronic voting. One of the problematic requirements for electronic voting systems is voter anonymity. On the one hand, each voter must be identified, and on the other, the content of his or her vote must be unknown. Currently, the methods and mechanisms used in real voting systems do not provide real anonymity. Therefore, both theoretical and practical content is an urgent and necessary problem of developing mechanisms for anonymous counting of votes with the protection of their distortion. The paper also provides a general analysis of the security level of prospective homomorphic encryption schemes. The essence of homomorphic encryption is that there is some set of operations whose result of executing over ciphertexts (with subsequent decryption) coincides with similar actions over plaintexts. Homomorphic encryption allows you to perform some calculations on information without having access to the information itself. However, there are a number of problems when trying to apply such calculations. The main ones are the choice of the method of asymmetric encryption, which provides the necessary cryptographic stability from both classical and quantum attacks, the identification of possible candidates for asymmetric cryptotransformations in homomorphic encryption, their evaluation of comparison with each other, and, of course, the choice of the most rational for a given multiple restrictions. The asymmetric schemes of homomorphic encryption are compared using the hierarchy analysis process. The method of asymmetric encryption with zero knowledge is substantiated. The objective of this article is to substantiate the possibilities, conditions, and constraints on the use of standardized asymmetric cryptotransformations in the creation of modern homomorphic encryption-type transformations, when anonymity of electronic voting and practical implementation of anonymous voting based on proof of zero knowledge must be guaranteed.
Bitcoin paper gave birth to a new era; cryptocurrencies aiming distributed trust model. Almost all the cryptocurrencies require their users individually manage their own cryptographic keys, provide or recommend use of cryptocurrency wallets. A wallet, which at least stores public-private keys and addresses, is one of the key points for end-users' security. Since the authentication of a transaction strictly depends on private keys, any adversary who gains access to a wallet may seize all the coins within. Hence, cryptocurrency wallet solutions should be carefully analyzed and better to be certified if possible. In this study, we aim to define the security problems and objectives necessary for the development of a certified product that can stand against the known attacks within the Framework of Common Criteria (CC). We believe this would be a brief source for cryptocurrency wallet Protection Profile (PP) and Security Target (ST) documents.
Ralph Holz, Diego Perino, Matteo Varvello, Johanna Amann · 9 authors
In late 2017, a sudden proliferation of malicious JavaScript was reported on the Web: browser-based mining exploited the CPU time of website visitors to mine the cryptocurrency Monero. Several studies measured the deployment of such code and developed defenses. However, previous work did not establish how many users were really exposed to the identified mining sites and whether there was a real risk given common user browsing behavior. In this paper, we present a retroactive analysis to close this research gap. We pool large-scale, longitudinal data from several vantage points, gathered during the prime time of illicit cryptomining, to measure the impact on web users. We leverage data from passive traffic monitoring of university networks and a large European ISP, with suspected mining sites identified in previous active scans. We corroborate our results with data from a browser extension with a large user base that tracks site visits. We also monitor open HTTP proxies and the Tor network for malicious injection of code. We find that the risk for most Web users was always very low, much lower than what deployment scans suggested. Any exposure period was also very brief. However, we also identify a previously unknown and exploited attack vector on mobile devices.
In this article, we present DPTS, a data payment and transfer the scheme that uses bitcoin payments to reward users for detailed electricity measurements they submit to a utility provider (UP). DPTS emphasizes both privacy and fairness of transactions; not only it allows participants to earn bitcoins in a way that cannot be linked to their actions or identities but also ensures that data are delivered if and only if an appropriate payment is received. While DPTS is described in the smart grid setting, the protocol can also be applied in other areas where incentives are used to increase user participation. One such important area is participatory or crowdsensing, where individuals use their smartphones to report sensed data back to a campaign administrator and obtain a reward for it. DPTS allows users to enjoy the benefits of participation without compromising anonymity. The proposal is coupled with a security analysis showing the privacy-preserving character of the system along with an efficiency analysis demonstrating the feasibility of our approach.
Gang Han, Yannan Li, Yong Yu, Kim‐Kwang Raymond Choo · 5 authors
IoT revolutionizes academia as well as industry. An increasing number of interconnected smart devices are gradually changing the urban lifestyle, among which, voting machines are one of the most widely used smart devices. However, the existing voting protocols for IoT are barely satisfactory, in the sense that most of them are centralized and subject to fairness issues. Moreover, the embedded softwares in voting machines are susceptible to internal vulnerabilities and external attacks. To address these issues, in this article, we propose a framework of a blockchain-based self-tallying voting system with software updates in decentralized IoT, which is fully decentralized and fair. In the proposed system, everyone can compute the final election results by collecting the ballots on the blockchain with equal privilege. Voting machines achieve self-tallying voting functionality in decentralized IoT systems and each entity in the system can obtain the voting results. Vendors deploy smart contracts to publish new patches securely and reliably. We implement a prototype of the proposed framework on laptops and mobile phones respectively to demonstrate its practicality.
Recent development of electronic voting (e-voting) systems has been focusing on blockchain-based design [4]. Despite blockchain’s advantages in public verifiability, existing blockchain-based voting systems are impractical due to the high block time and transaction costs of the underlying blockchain. To achieve verifiability and efficiency simultaneously, we propose Hybrid-Voting, a hybrid structured e-voting system that combines an untrusted centralized server with smart contracts on Ethereum blockchain. In addition, voter anonymity and privacy are guaranteed by using short linkable ring signature and ElGamal encryption. Our evaluation shows that Hybrid-Voting can support 10k voters by using one commodity computer, and the cost per voter is less than one US dollar, much lower than the cost per voter in today’s elections [1].
Monero provides a high level of anonymity for both users and their transactions. However, many criminal activities might be committed with the protection of anonymity in cryptocurrency transactions. Thus, user accountability (or traceability) is also important in Monero transactions, which is unfortunately lacking in the current literature. In this paper, we fill this gap by introducing a new cryptocurrency named Traceable Monero to balance the user anonymity and accountability. Our framework relies on a tracing authority, but is optimistic, in that it is only involved when investigations in certain transactions are required. We formalize the system model and security model of Traceable Monero. We present a detailed construction of Traceable Monero by overlaying Monero with two types of tracing mechanisms, tracing the one-time addresses with money flows and tracing the long-term addresses. We prove the security of Traceable Monero and implement a prototype of the system, which demonstrates that Traceable Monero incurs merely a very small overhead in generating and verifying a transaction compared to Monero transactions.
Kwame Omono Asamoah, Hu Xia, Sandro Amofa, Isaac Amankona Obiri · 9 authors
The challenges of population management as urban density increase globally have compelled researchers and developers to consider more efficient means of managing resources in cities. Consequently, the smart city concept has emerged as a response to addressing the challenge of optimal resource utilization in urban centers. However, with digital technologies proliferating as key components of the solution, it is necessary to develop a digital identity solution for all components of the smart city environment. For completeness, the solution must encompass all entities, including physical and intangible assets, processes, and most importantly, its residents. Consequently, a unified, distributed data integration and efficient analysis platform is required: the digital city operating system. In this article, we focus on a key component of digital city management in the form of secure identification of individual residents. We collect user attributes and securely transmit them to other system components for verification. Upon successful completion of the verification process, a digital identity is created for the applying resident and the set of transactions leading to the ID creation are stored in the blockchain. Our system is secure and can serve as the basis for the development of a digital infrastructure for smart city management.
Xun Yi, Russell Paulet, Elisa Bertino, Fang-Yu Rao
In this paper we consider the problem where a client wishes to subscribe to some product or service provided by a server, but maintain their anonymity. At the same time, the server must be able to authenticate the client as a genuine user and be able to discontinue (or revoke) the client's access if the subscription fees are not paid. Current solutions for this problem are typically constructed using some combination of blind signature or zero-knowledge proof techniques, which do not directly support client revocation (that is, revoking a user before expiry of their secret value). In this paper, we present a solution for this problem on the basis of the broadcast encryption scheme, suggested by Boneh et al., by which the server can broadcast a secret to a group of legitimate clients. Our solution allows the registered client to log into the server anonymously and also supports client revocation by the server. Our solution can be used in many applications, such as location-based queries. We formally define a model for our anonymous subscription protocol and prove the security of our solution under this model. In addition, we present experimental results from an implementation of our protocol. These experimental results demonstrate that our protocol is practical.
Blockchain and distributed ledger technologies have increasingly been gaining interest over the last few years. The promise of a completely secure environment for data to be stored has caught the attention of everyone, including individuals and institutions, who, in their turn, have started to invest generously in related research and development of such systems, especially those concerned with finance and crypto-currency. In this research, we focus on the applications beyond these topics, aiming to solve the problem of tampering with vote counting in elections around the world. By designing and constructing a system of a distributed ledger with a permissioned consensus algorithm, we are composing a tamper-proof method to provide a secure environment for voting.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The Transport Layer Security (TLS) protocol and its public-key infrastructure (PKI) are widely used in the Internet to achieve secure communication. Validating domain ownership by trusted certification authorities (CAs) is a critical step in issuing digital certificates, but unfortunately, this process provides a poor security level. In this work, we present SmartCert, a novel approach based on smart contracts to improve digital certificates. A certificate in SmartCert conveys detailed information about its validation state which is constantly changing but only with respect to the specified smart contract code and individual domain policies. CAs issuing and updating certificates are kept accountable and their actions are transparent and monitored by the code. We present the implementation and evaluation of SmartCert, and discuss its deployability.
Pemilihan Suara Secara Elektronis Menggunakan Sistem Terdesentralisasi Berbasis Blockchain Ethereum merupakan suatu sistem yang dibuat dalam bentuk aplikasi yang dapat digunakan dalam pemilihan umum. Hal ini dilakukan untuk menyelesaikan masalah yang dimiliki oleh sistem pemilihan suara secara elektronis yang konvensional dimana integritas data belum terjamin dan data hasil suara kemungkinan dapat dirubah oleh pihak tertentu. Masalah ini dapat diselesaikan dengan membuat sistem pemilihan suara secara elektronik yang menyimpan data hasil suara pada blockchain agar integritas data dapat terjamin. Pembuatan sistem ini dilakukan menggunakan bahasa Solidity, bahasa pemrograman yang sudah Turing Complete pada Ethereum. Source code yang dijalankan akan di kompilasi menjadi Bytecode yang kemudian dijalankan pada Ethereum Virtual Machine. Program yang dibuat tersebut kemudian akan di desentralisasi kan menggunakan Blockchain. Hasil nya adalah sistem Electronic Voting yang terdesentralisasi. Sistem ini dapat diakses melalui website https://pemilurt.herokuapp.com/. Abstract Electronic Voting Using Decentralised System Based On Ethereum’s Blockchain is a system made in the form of application used for Electronic Voting. This is done to solve the current problem on conventional electronic voting system where the integrity of the data can’t be ascertain and the result of the vote can be tampered malicious actors. To solve this problem, an electronic voting system will be built that store the data of election results on blockchain to ensure the integrity of the data. The creation of the system involves using the Solidity language, a Turing Complete programming language used on Ethereum. Source code that will be run will first need to be compiled into Bytecode, which will then in turn run on Ethereum Virtual Machine. The finished program will then be decentralised using Blockchain. The result will be a decentralised Electronic Voting system that can be accessed from the website https://pemilurt.herokuapp.com/.
Christian Killer, Bruno Rodrigues, Raphael Matile, Eder J. Scheid · 5 authors
Digitization of electoral processes depends on confident systems that produce verifiable evidence. The design and implementation of voting systems has been widely studied in prior research, bringing together expertise in many fields. Switzerland is organized in a federal, decentralized structure of independent governmental entities. Thus, its decentralized structure is a real-world example for implementing an electronic voting system, where trust is distributed among multiple authorities.
Flooded by the propagation of false or biased news in the Web, people tend to resort to social networks to read posts from reliable sources, exchange commentaries with trustworthy parties, access first-hand content, or cross-check information that appears in news outlets. However, platform providers like Facebook or Twitter can ultimately decide about the contents exposed to each user. Anecdotal evidence suggests that such platform providers are prone to pressure by political or economical agents, and may be ideologically driven to hide messages or block certain users [2, 12] thereby impairing users' ability to freely access rightful information.
Payment channel networks, and the Lightning Network in particular, seem to offer a solution to the lack of scalability and privacy offered by Bitcoin and other blockchain-based cryptocurrencies. Previous research has focused on the scalability, availability, and crypto-economics of the Lightning Network, but relatively little attention has been paid to exploring the level of privacy it achieves in practice. This paper presents a thorough analysis of the privacy offered by the Lightning Network, by presenting several attacks that exploit publicly available information about the network in order to learn information that is designed to be kept secret, such as how many coins a node has available or who the sender and recipient are in a payment routed through the network.
With the rise of cloud computing, data centers, and big data, the current rigid network architecture has been found to be inadequate. The modern technological demands require a flexible and easily reconfigurable network architecture. Software Defined Networking is a revolutionary concept that separates the control plane of network devices from their data plane and centralizes the control plane of all devices, facilitating the controlling of the entire network through a single portal. This helps us create flexible network architectures that can be reconfigured quickly to fit different needs. However, centralizing control leads to a Single Point of Failure and makes the network vulnerable to Denial of Service attacks, which is one of the major reasons why industries are reluctant to adopt this technology. Blockchain provides us a with a distributed ledger and a decentralized state, allowing us to create decentralized applications that run over multiple computers. This research aims to distribute the control plane of Software Defined Networks across multiple devices using blockchain. This addresses the existing security vulnerabilities of the Software Defined Network architecture such as Single Point of Failure while continuing to keep the control plane logically centralized, thereby allowing the network to be configured through a single portal. The resulting architecture has a physically distributed control plane whose logic is centralized.