Homomorphic Cryptography raised as a new solution used in electronic voting systems. In this research, Fully Homomorphic encryption used to design and implement an e-voting system. The purpose of the study is to examine the applicability of Fully Homomorphic encryption in real systems and to evaluate the performance of fully homomorphic encryption in evoting systems. Most of homomorphic cryptography evoting systems based on additive or multiplicative homomorphic encryption. In this research, fully homomorphic encryption used to provide both operations additive and multiplication, which ease the demonstration of none interactive zero-knowledge proof NIZKP. The proposed e-voting system achieved most of the important security issues of the internet-voting systems such as eligibility, privacy, accuracy, verifiability, fairness, and others. One of the most important properties of the implemented internet voting system its applicability to work on cloud infrastructure, while preserving its security characteristics. The implementation is done using homomorphic encryption library HELib. Addition and multiplication properties of fully homomorphic encryption were used to verify the correctness of vote structure as a NIZKP, and for calculating the results of the voting process in an encrypted way. The results show that the implemented internet voting system is secure and applicable for a large number of voters up to 10 million voters.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Defending against distributed denial of service (DDoS) attacks in the Internet is a fundamental problem. One practical approach to addressing DDoS attacks is to redirect all destination (e.g., via DNS or BGP) to a third-party, DDoS protection-as-a-service provider (e.g., Cloudflare and Akamai), which is well provisioned and equipped with proprietary filtering mechanisms to remove attack traffic before passing the remaining traffic to the destination. Although such an approach is appealing, as it requires no modification to the existing Internet infrastructure and can scale to handle very large attacks, recent industrial interviews with more than 100 interviewees from over 10 industry segments reveal that this approach alone is not sufficient, especially for large organizations (e.g., Web hosting companies and government) that cannot afford to allow third-parity security-service providers to terminate their network connections. Instead, these organizations have to rely on their ISPs to filter attack traffic. In this paper, we discuss the challenges faced by the ISPs in order to disrupt the Internet security-service market and sketch our solutions, powered by smart contracts.
Digital identities and credentials are gradually replacing physical documents, as they can be verified with more accuracy and efficiency. Since online privacy is becoming more crucial than ever, it is essential to preserve the privacy of individuals whenever possible. Therefore, anonymous attestation of digital credentials should be feasible, where provers can selectively disclose attributes and create abstractions over attributes in their credential, in order to solely disclose the minimum amount of information required to complete the goal of verification.<br/><br/>Many schemes in the field of attribute-based credentials consider a single root authority issuing credentials to provers. This is coherent to the traditional way of the issuance of credentials since the process of producing physical documents is costly to distribute to multiple issuers. Digital identities provide the opportunity for authorities to distribute credential issuance rights (consecutively) to smaller entrusted entities.<br/><br/>To the best of our knowledge, we propose the first protocol which combines both anonymous attestation with attribute-based credentials and the delegation of selective signing rights for the issuance of these credentials. Root authorities could delegate signing rights for selective attributes consecutively to trustees, which are able to create anonymous attribute-based credentials with the acquired attributes for provers. Verifiers are able to verify presentation tokens with solely the public key of the root authority, without gaining knowledge about the identities of the prover and intermediate delegators. We introduce three adapted signature schemes based on existing work in order to realize a concrete instantiation of the protocol. Anonymity is achieved by incorporating Schnorr's zero-knowledge proof of knowledge with bilinear pairings to efficiently prove the correctness of presentation tokens.<br/><br/>We realized a prototype of our concrete instantiation and optimized the verification algorithm in order to achieve optimal pairing performance. Complexity analysis of the protocol shows improvement in efficiency by aggregating attribute signatures throughout signing right delegation. Experimental results demonstrate a degree of practical feasibility for the verification of presentation tokens on commodity hardware within the challenging public transportation access control time bound of 300 ms.<br/>
A fraudulent election is one of the biggest problems of the contemporaneity in most countries. Even the world’s largest democracies like India, United States, and Japan still suffer from a flawed electoral system. Vote rigging, hacking of the EVM (Electronic voting machine), election manipulation, and polling booth capturing are the major issues in the current voting system. This fallacious election process calls voting systems into question. With the current Cambridge Analytica scandal a hot topic around the world, it brings the validity of current voting systems into question. In this paper, we investigate the problems in the election voting systems and propose a novel voting model which can resolve these issues. We use a recently introduced blockchain based protocol called PHANTOM, which uses a directed acyclic graph of blocks, also known as blockDAG, to generalize the initial blockchain technology.
This report describes two projects created by the author which are based on ideas which originate from the Bitcoin community. The first, bmd, is a re-implementation of the Bitmessage protocol in go. Bitmessage is an anonymous and secure messaging system invented by Jonathan Warren, who was inspired by the design of Bitcoin's p2p network. [WARR1] The second is Shufflepuff, an implementation of a protocol called CoinShuffle[RUFF1] which allows several people to construct a Bitcoin transaction with an input and an output for each participant without any participant knowing who owns which output. CoinShuffle was invented by Tim Ruffing et al, and it is an upgrade of a protocol called CoinJoin, invented by Gregory Maxwell. This paper discusses the background, properties, applications, and design of bmd and Shufflepuff. There is also a report of a performance analysis on bmd.
Casimer DeCusatis, Marcus Zimmermann, Anthony Sager
While blockchain services hold great promise to improve many different industries, there are significant cybersecurity concerns which must be addressed. In this paper, we present experimental test bed results for a novel method of user identity management for cloud-based blockchain applications. Using a BlackRidge Technology endpoint on a Windows host, we insert cryptographic identity tokens on the first packet to request a new session. A corresponding gateway appliance in the cloud enforces security policy, blocking unauthorized access at or below the transport layer. Results of penetration testing a sample Hyperledger 1.0 application are discussed. We also demonstrate network segmentation and traffic separation, which allows multiple organizations to share blockchain infrastructure and facilitates compliance auditing.
The smart terminal and grid protection devices play a very important role in the safe operation of the smart grid. Traditional maintenance and renewal of the center node wastes a lot of manpower and material resources and have huge safety implications. This paper proposes a safety equipment diagnosis mechanism based on consortium blockchain technology to realize more efficient, convenient, and secure device maintenance. When a device has problems or notices improper operation, it can make a device diagnosis request in the consortium blockchain network, and receive a diagnosis response from a vendor or non-original supplier nodes. This scheme designs a decentralized safety equipment diagnosis smart contract, combining response node bid price and credit, and applies a multi-dimensional reverse auction mechanism to determine bid node and transaction price. After a smart device diagnosed, the relevant message will be packaged and sent to a smartphone, which can use the client to set up the smart contract of equipment operation policy. Paillier encryption arithmetic can be used to ensure device diagnosis mechanism safety. The proposed scheme is guaranteed not to reveal sensitive information in the process of device interaction.
Lightweight clients are gaining increasing adoption in existing blockchain deployments, owing to their reduced resource consumption. There are currently a number of libraries that implement lightweight clients (e.g., BIP37, Electrum, LES, filter commitments). Notice that these libraries are intrinsically different and require significant effort to be integrated across blockchain platforms. Additionally, lightweight clients require the cooperation of full nodes, which are expected to invest in their computational (to run filters) and bandwidth resources in order to serve lightweight clients. Existing blockchains however offer no rewards for full nodes in exchange-which offers little incentives for full nodes to correctly serve lightweight clients.
Abstract This chapter considers the regulatory regime for cryptocurrencies and other value data (defined as assets which are both excludable and rivalrous, recorded by a trusted technology rather than booked by a qualified intermediary). It begins with a discussion of changes in selected monetary assets and manifestations — namely banknotes and central bank reserve balances — that have occurred over time. It then describes three modes of money creation and their effect on the substance of an asset: money created on a temporary basis; outright money created with no connected reversal event; and by issue of helicopter money. It also analyses the different forms in which cryptocurrencies manifest themselves and their consequences for the rules governing title, transfer and protection of commercial dealings. Finally, it explores the excludable and rivalrous nature of value data and the manifestation of such data by entry in a register kept by a trusted technology.
Privacy in online applications has drawn tremendous attention in recent years. With the development of cloud-based applications, protecting users' privacy while guaranteeing the expected service from the server has become a significant issue. This paper surveyed the most popular cryptographic algorithms in privacy-preserving online applications to provide a tutorial-like introduction to researchers in this area. Specifically, this paper focuses on introduction to homomorphic encryption, secret sharing, secure multi-party computation and zero-knowledge proof.