Nicolas Buchmann, Christian Rathgeb, Harald Baier, Christoph Busch ยท 5 authors
In contrast to electronic travel documents (e.g. ePassports), the standardisation of breeder documents (e.g. birth certificates), regarding harmonisation of content and contained security features is in statu nascendi. Due to the fact that breeder documents can be used as an evidence of identity and enable the application for electronic travel documents, they pose the weakest link in the identity life cycle and represent a security gap for identity management. In this work, we present a cost efficient way to enhance the long-term security of breeder documents by utilizing blockchain technology. A conceptual architecture to enhance breeder document long-term security and an introduction of the concept's constituting system components is presented. Our investigations provide evidence that the Bitcoin blockchain is most suitable for breeder document long-term security.
Advanced Steganography and Watermarking Techniques
Mauro Conti, E. Sandeep Kumar, Chhagan Lal, Sushmita Ruj
Bitcoin is a popular cryptocurrency that records all transactions in a distributed append-only public ledger called blockchain. The security of Bitcoin heavily relies on the incentive-compatible proof-of-work (PoW) based distributed consensus protocol, which is run by the network nodes called miners. In exchange for the incentive, the miners are expected to maintain the blockchain honestly. Since its launch in 2009, Bitcoin economy has grown at an enormous rate, and it is now worth about 150 billions of dollars. This exponential growth in the market value of bitcoins motivate adversaries to exploit weaknesses for profit, and researchers to discover new vulnerabilities in the system, propose countermeasures, and predict upcoming trends. In this paper, we present a systematic survey that covers the security and privacy aspects of Bitcoin. We start by giving an overview of the Bitcoin system and its major components along with their functionality and interactions within the system. We review the existing vulnerabilities in Bitcoin and its major underlying technologies such as blockchain and PoW-based consensus protocol. These vulnerabilities lead to the execution of various security threats to the standard functionality of Bitcoin. We then investigate the feasibility and robustness of the state-of-the-art security solutions. Additionally, we discuss the current anonymity considerations in Bitcoin and the privacy-related threats to Bitcoin users along with the analysis of the existing privacy-preserving solutions. Finally, we summarize the critical open challenges, and we suggest directions for future research towards provisioning stringent security and privacy solutions for Bitcoin.
Open access
3 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Blockchain, which is the backbone of Bitcoin, has recently received a lot of attention. Blockchain functions as an immutable ledger that enables decentralized transactions. Numerous fields, such as the Internet of Things (IoT), reputation systems, and financial services, are being covered by blockchain-based applications. However, blockchain technology still faces numerous difficulties, such as scalability and security issues, that need to be resolved. A comprehensive overview of blockchain technology is provided in this paper. First, we compare some common consensus algorithms utilized by various blockchains and provide an overview of the architecture of blockchains. In addition, a brief list of recent advancements and technical difficulties is provided. In addition, we outline potential blockchain trends for the future.
Blockchain is offering new opportunities to develop new types of digital services. While research on the topic is still emerging, it has mostly focused on the technical and legal issues instead of taking advantage of this novel concept and creating advanced digital services. In this paper, we are going to leverage the open source Blockchain technology to propose a design for a new electronic voting system that could be used in local or national elections. The Blockchain-based system will be secure, reliable, and anonymous, and will help increase the number of voters as well as the trust of people in their governments.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Sean Rowan, Michael Clear, Mรกrio Gerla, Meriel Huggard ยท 5 authors
Autonomous and self-driving vehicles are appearing on the public highways.\nThese vehicles commonly use wireless communication techniques for both\nvehicle-to-vehicle and vehicle-to-infrastructure communications. Manufacturers,\nregulators and the public are understandably concerned about large-scale\nsystems failure or malicious attack via these wireless vehicular networks. This\npaper explores the use of sensing and signalling devices that are commonly\nintegrated into modern vehicles for side-channel communication purposes.\nVisible light (using a CMOS camera) and acoustic (ultrasonic audio)\nside-channel encoding techniques are proposed, developed and evaluated in this\ncontext. The side-channels are examined both theoretically and experimentally\nand an upper bound on the line code modulation rate that is achievable with\nthese side channel schemes in the vehicular networking context is established.\nA novel inter-vehicle session key establishment protocol, leveraging both\nside-channels and a blockchain public key infrastructure, is then presented. In\nlight of the limited channel capacity and the interoperability/security\nrequirements for vehicular communications, techniques for constraining the\nthroughput requirement, providing device independence and validating the\nlocation of the intended recipient vehicle, are presented. These reduce the\nnecessary device handshake throughput to 176 bits for creating symmetric\nencryption and message authentication keys and in verifying a vehicle's\ncertificate with a recognised certification authority.\n
Open access
3 source records
cs.CR
Advanced Steganography and Watermarking Techniques
Giuseppe Pappalardo, Tiziana Di Matteo, Guido Caldarelli, Tomaso Aste
We investigate Bitcoin network observing transactions broadcasted into the network during a week from 04/05/2016 and then monitoring their inclusion into the blockchain during the following seven months.We unveil that 42% of the transactions are still not included in the Blockchain after 1 h from their appearance and 20% of the transactions are still not included in the Blockchain after 30 days, therefore revealing a great inefficiency in the Bitcoin system. However, we observe that most of these โforgottenโ transactions have low values and in terms of transferred value the system is less inefficient with 93% of the transactions value being included into the Blockchain within 3 h and 98.8% within a day. The fact that a sizeable fraction of transactions is not processed timely casts serious doubts on the usability of the Bitcoin Blockchain for reliable time-stamping purposes. It also calls for a debate about the right systems of incentives which a peer-to-peer unintermediated system should introduce to promote efficient transaction recording
Open access
3 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Today it is common that people are users of more than one social networking site, so more and more people have multiple accounts on the web. It is challenging to identify the anonymous users on the web. A technique based on the friend relationship is used to identify the same user on multiple social networking sites. It is based on the concept that friend relationships cannot be faked by others. Based on that FRUI (Friend Relationship User Identification) algorithm is developed to match users on multiple sites. It calculates the matching degree for all users with similar screen names on multiple sites and users with the highest matching degree will be considered as the identical users. The proposed method is extended to find the fraud identities in social media sites including the bitcoin concept.
Spam and Phishing Detection
Authorship Attribution and Profiling
Advanced Steganography and Watermarking Techniques
Bitcoin seems to be the most successful cryptocurrency so far given the growing real life deployment and popularity. While Bitcoin requires clients to be online to perform transactions and a certain amount of time to verify them, there are many real life scenarios that demand for offline and immediate payments (e.g., mobile ticketing, vending machines, etc). However, offline payments in Bitcoin raise non-trivial security challenges, as the payee has no means to verify the received coins without having access to the Bitcoin network. Moreover, even online immediate payments are shown to be vulnerable to double-spending attacks. In this paper, we propose the first solution for Bitcoin payments, which enables secure payments with Bitcoin in offline settings and in scenarios where payments need to be immediately accepted. Our approach relies on an offline wallet and deploys several novel security mechanisms to prevent double-spending and to verify the coin validity in offline setting. These mechanisms achieve probabilistic security to guarantee that the attack probability is lower than the desired threshold. We provide a security and risk analysis as well as model security parameters for various adversaries. We further eliminate remaining risks by detection of misbehaving wallets and their revocation.
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Heretofore the concept of "blockchain" has not been precisely defined. Accordingly the potential useful applications of this technology have been largely inflated. This work sidesteps the question of what constitutes a blockchain as such and focuses on the architectural components of the Bitcoin cryptocurrency, insofar as possible, in isolation. We consider common problems inherent in the design of effective supply chain management systems. With each identified problem we propose a solution that utilizes one or more component aspects of Bitcoin. This culminates in five design principles for increased efficiency in supply chain management systems through the application of incentive mechanisms and data structures native to the Bitcoin cryptocurrency protocol.
With the emergence of Bitcoin, businesses are focusing on leveraging Bitcoin's blockchain technology to non-cryptocurrency based applications to improve efficiency of the operations. These business applications operate in environments where participants have verified identities; these are called permissioned environments. Blockchain is an immutable and append only distributed ledger that can be utilized for record keeping applications. We observe that when blockchain technology is adapted from permissionless environments to permissioned environments the immutability of blockchain becomes questionable as the end-users may not monitor or store a copy of the blockchain. We propose the use of Keyless Signatures' Infrastructure as an additional mechanism to ensure irreversible and irrefutable proof of block confirmations which acts as a global proof thus preserving long term immutability of blockchain in permissioned environments.
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
The increasing capabilities of todayโs smartphones enables users to live stream video directly from their mobile device. One increasing concern regarding videos found online is their authenticity a ...
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Nazmul Islam, Kazi Md. Rokibul Alam, Shinsuke Tamura, Yasuhiko Morimoto
This paper proposes a new electronic voting (e-voting) scheme that exploits confirmation numbers (CNs) and revised simplified verifiable re-encryption mixnet (R-SVRM). R-SVRM is a recently introduced mechanism of mixnet also used to develop an e-voting scheme where a vote is decomposed to protect its voter from being coerced to cast a particular vote. Though the scheme avoids complicated zero knowledge proof (ZKP), the verification procedures of its cryptographic operations are still cumbersome. Again, another e-voting scheme based on CNs comes with benefits of vote verifiability and unlinkability between the vote and its voter, lags behind in adopting public keys for encryption and signature verification. Also its exploited mixnet is not verifiable; therefore requires a pair of signatures on each encrypted vote to ensure the verifiability of mixnet. Hence, the computation and communication overhead of the scheme becomes weighty, though ZKP is avoided. In contrast, the proposed scheme deploys both CNs and R-SVRM to eliminate these limitations. Hence, any coercer cannot force the voter to cast a specific vote as well as cryptographic operations and their verifications become simpler. Also the computation and communication overheads for involved entities get decreased. Finally, the security requirements of e-voting are achieved more elegantly.
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Blockchain technology has the potential to disrupt how cryptography is done. In this work, we propose to view blockchains as an โenablerโ, much like indistinguishability obfuscation [5, 23, 46] or one-way functions, for building a variety of cryptographic systems. Our contributions in this work are as follows:
1.
A Framework for Proof-of-Stake based Blockchains: We provide an abstract framework for formally analyzing and defining useful security properties for Proof-of-Stake (POS) based blockchain protocols. Interestingly, for some of our applications, POS based protocols are more suitable. We believe our framework and assumptions would be useful in building applications on top of POS based blockchain protocols even in the future.
2.
Blockchains as an Alternative to Trusted Setup Assumptions in Cryptography: A trusted setup, such as a common reference string (CRS) has been used to realize numerous systems in cryptography. The paragon example of a primitive requiring trusted setup is a non-interactive zero-knowledge (NIZK) system. We show that already existing blockchains systems including Bitcoin, Ethereum etc. can be used as a foundation (instead of a CRS) to realize NIZK systems. The novel aspect of our work is that it allows for utilizing an already existing (and widely trusted) setup rather than proposing a new one. Our construction does not require any additional functionality from the miners over the already existing ones, nor do we need to modify the underlying blockchain protocol. If an adversary can violate the security of our NIZK, it could potentially also take over billions of dollars worth of coins in the Bitcoin, Ethereum or any such cryptocurrency!
We believe that such a โtrusted setupโ represents significant progress over using CRS published by a central trusted party. Indeed, NIZKs could further serve as a foundation for a variety of other cryptographic applications such as round efficient secure computation [33, 36].
3.
One-time programs and pay-per use programs: Goldwasser et al. [29] introduced the notion of one time program and presented a construction using tamper-proof hardware. As noted by Goldwasser et al. [29], clearly a one-time program cannot be solely software based, as software can always be copied and run again. While there have been a number of follow up works [4, 6, 30], there are indeed no known constructions of one-time programs which do not rely on self destructing tamper-proof hardware (even if one uses trusted setup or random oracles). Somewhat surprisingly, we show that it is possible to base one-time programs on POS based blockchain systems without relying on trusted hardware. Our ideas do not seem to translate over to Proof-of-Work (POW) based blockchains.
We also introduce the notion of pay-per-use programs which is simply a contract between two parties โ service provider and customer. A service provider supplies a program such that if the customer transfers a specific amount of coins to the provider, it can evaluate the program on any input of its choice once, even if the provider is offline. This is naturally useful in a subscription based model where your payment is based on your usage.