Primavera De Filippi
International audience
Follow blockchain research across journals, conferences, and preprint repositories.
2,611 results · page 98 of 109
Primavera De Filippi
International audience
Ariel Ekblaw, Chelsea Barabas, Jonathan Harvey-Buschel, Andrew Lippman
Since 2009, the Bitcoin open-source software project has established a commanding presence in the digital currency space as a self-organizing, distributed system. The project stems from a long history of efforts to harness decentralization and progressive cryptography for social good, as espoused by the ethos of the Cypherpunks mailing list on which Bitcoin was first released. However, certain design choices in Bitcoin's core protocol have led to consolidation of the peer-to-peer nodes, rather than greater diversification, thus threatening system integrity. In this position paper, we explore the socio-technical limits that challenge Bitcoin's ability to remain fully decentralized and "self-contained" as an algorithmically governed system. The need to integrate into existing human systems and infrastructures complicates the project's original vision. We propose hardware, software and electricity management modifications to the broader Bitcoin ecosystem, recognizing the need for socio-inspired design strategies to revive network integrity. We then use Bitcoin as an example to discuss the fundamental limitations of "pure decentralization" and algorithmic self-governance.
Pedro Moreno-Sánchez, Muhammad Bilal Zafar, Aniket Kate
Abstract The decentralized I owe you (IOU) transaction network Ripple is gaining prominence as a fast, low-cost and efficient method for performing same and cross-currency payments. Ripple keeps track of IOU credit its users have granted to their business partners or friends, and settles transactions between two connected Ripple wallets by appropriately changing credit values on the connecting paths. Similar to cryptocurrencies such as Bitcoin, while the ownership of the wallets is implicitly pseudonymous in Ripple, IOU credit links and transaction flows between wallets are publicly available in an online ledger. In this paper, we present the first thorough study that analyzes this globally visible log and characterizes the privacy issues with the current Ripple network. In particular, we define two novel heuristics and perform heuristic clustering to group wallets based on observations on the Ripple network graph. We then propose reidentification mechanisms to deanonymize the operators of those clusters and show how to reconstruct the financial activities of deanonymized Ripple wallets. Our analysis motivates the need for better privacy-preserving payment mechanisms for Ripple and characterizes the privacy challenges faced by the emerging credit networks.
Till Neudecker, Philipp Andelfinger, Hannes Hartenstein
Flooding Peer-to-Peer (P2P) networks form the basis of services such as the electronic currency system Bitcoin. The decentralized architecture enables robustness against failure. However, knowledge of the network's topology can allow adversaries to attack specific peers in order to, e.g., isolate certain peers or even partition the network. Knowledge of the topology might be gained by observing the flooding process, which is inherently possible in such networks,, performing a timing analysis on the observations. In this paper we present a timing analysis method that targets flooding P2P networks, show its theoretical, practical feasibility. A validation in the real-world Bitcoin network proves the possibility of inferring network links of actively participating peers with substantial precision, recall (both ~ 40%), potentially enabling attacks on the network. Additionally, we analyze the countermeasure of trickling, quantify the tradeoff between the effectiveness of the countermeasure, the expected performance penalty. The analysis shows that inappropriate parametrization can actually facilitate inference attacks.
Maurice Herlihy, Mark Moir
Permisionless decentralized ledgers ("blockchains") such as the one underlying the cryptocurrency Bitcoin allow anonymous participants to maintain the ledger, while avoiding control or "censorship" by any single entity. In contrast, permissioned decentralized ledgers exploit real-world trust and accountability, allowing only explicitly authorized parties to maintain the ledger. Permissioned ledgers support more flexible governance and a wider choice of consensus mechanisms. Both kinds of decentralized ledgers may be susceptible to manipulation by participants who favor some transactions over others. The real-world accountability underlying permissioned ledgers provides an opportunity to impose fairness constraints that can be enforced by penalizing violators after-the- fact. To date, however, this opportunity has not been fully exploited, unnecessarily leaving participants latitude to manipulate outcomes undetectably. This paper draws attention to this issue, and proposes design principles to make such manipulation more difficult, as well as specific mechanisms to make it easier to detect when violations occur.
Jan Henrik Ziegeldorf, Roman Matzutt, Martin Henze, Fred Grossmann · 5 authors
No abstract is available for this record.
Maria Apostolaki, Aviv Zohar, Laurent Vanbever
Bitcoin is without a doubt the most successful cryptocurrency in circulation today, making it an extremely valuable target for attackers. Indeed, many studies have highlighted ways to compromise one or several Bitcoin nodes. In this paper, we take a different perspective and study the effect of large-scale network-level attacks such as the ones that may be launched by Autonomous Systems (ASes). We show that attacks that are commonly believed to be hard, such as isolating 50% of the mining power, are actually within the reach of anyone with access to a BGP-enabled network and hijacking less than 900 prefixes. Once on path, AS-level adversaries can then partition the Bitcoin network or delay block propagation significantly. The key factors that enable these attacks are the extreme centralization of Bitcoin, both from a routing and a mining perspective, along with the fact that Bitcoin messages are sent unencrypted, without integrity guarantees. We demonstrate the feasibility of large-scale attacks in practice against the deployed Bitcoin software and quantify their disruptive network-wide impact. The potential damage to Bitcoin is severe. By isolating a part of the network or delaying the propagation of blocks, network-level attackers can cause a significant amount of mining power to be wasted, leading to revenue losses and enabling a wide range of attacks such as double spending. We provide several suggestions on approaches to mitigate such attacks employing both short-term and long-term measures.
Maria Apostolaki, Aviv Zohar, Laurent Vanbever
As the most successful cryptocurrency to date, Bitcoin constitutes a target of choice for attackers. While many attack vectors have already been uncovered, one important vector has been left out though: attacking the currency via the Internet routing infrastructure itself. Indeed, by manipulating routing advertisements (BGP hijacks) or by naturally intercepting traffic, Autonomous Systems (ASes) can intercept and manipulate a large fraction of Bitcoin traffic. This paper presents the first taxonomy of routing attacks and their impact on Bitcoin, considering both small-scale attacks, targeting individual nodes, and large-scale attacks, targeting the network as a whole. While challenging, we show that two key properties make routing attacks practical: (i) the efficiency of routing manipulation; and (ii) the significant centralization of Bitcoin in terms of mining and routing. Specifically, we find that any network attacker can hijack few (<100) BGP prefixes to isolate ~50% of the mining power---even when considering that mining pools are heavily multi-homed. We also show that on-path network attackers can considerably slow down block propagation by interfering with few key Bitcoin messages. We demonstrate the feasibility of each attack against the deployed Bitcoin software. We also quantify their effectiveness on the current Bitcoin topology using data collected from a Bitcoin supernode combined with BGP routing data. The potential damage to Bitcoin is worrying. By isolating parts of the network or delaying block propagation, attackers can cause a significant amount of mining power to be wasted, leading to revenue losses and enabling a wide range of exploits such as double spending. To prevent such effects in practice, we provide both short and long-term countermeasures, some of which can be deployed immediately.
Philipp Locher, Rolf Haenni
No abstract is available for this record.
Roger Piqueras Jover, Joshua Lackey
The Home Subscriber Server (HSS) within the packet core of the Long Term Evolution (LTE) is a key node leveraged for essential operations, such as mutual authentication and access control. This centralized node is essential for the overall network operation as it is the cornerstone of the cryptographic functions executed in a mobile network. It stores several parameters for each subscriber, including a copy of the secret key ki that is securely stored in the Subscriber Identity Module (SIM). The advent of the Internet of Things (IoT) has sparked the concern in the industry on the potential risk of control plane signaling overloads. Due to the traffic characteristics of IoT devices and the potential risk of malfunctioning or compromised devices, there is a potential risk for floods of signaling traffic overwhelming the mobile core network and, in particular, the HSS. Moreover, recent security research has theorized potential attacks against this central core network node that could be launched from a botnet of compromised smartphones. In this paper we theoretically introduce a novel distributed and secure Peer-to-Peer (P2P) implementation of the HSS. Based on the Bitcoin/Namecoin framework, this new architecture drifts away from the symmetric key model of the standard HSS and proposes a robust public key infrastructure. Moreover, it does not rely in central points of failure, it is resilient to signaling overload threats and allows to re-authenticate and re-generate mobile session keys frequently with zero control plane signaling load at the mobile core.
Antoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Bryan Parno
Despite advances in security engineering, authentication in applications such as email and the Web still primarily relies on the X.509 public key infrastructure introduced in 1988. This PKI has many issues but is nearly impossible to replace. Leveraging recent progress in verifiable computation, we propose a novel use of existing X.509 certificates and infrastructure. Instead of receiving and validating chains of certificates, our applications receive and verify proofs of their knowledge, their validity, and their compliance with application policies. This yields smaller messages (by omitting certificates), stronger privacy (by hiding certificate contents), and stronger integrity (by embedding additional checks, e.g. for revocation). X.509 certificate validation is famously complex and error-prone, as it involves parsing ASN.1 data structures and interpreting them against diverse application policies. To manage this diversity, we propose a new format for writing application policies by composing X.509 templates, and we provide a template compiler that generates C code for validating certificates within a given policy. We then use the Geppetto cryptographic compiler to produce a zero-knowledge verifiable computation scheme for that policy. To optimize the resulting scheme, we develop new C libraries for RSA-PKCS#1 signatures and ASN.1 parsing, carefully tailored for cryptographic verifiability. We evaluate our approach by providing two real-world applications of verifiable computation: a drop-in replacement for certificates within TLS, and access control for the Helios voting protocol. For TLS, we support fine-grained validation policies, with revocation checking and selective disclosure of certificate contents, effectively turning X.509 certificates into anonymous credentials. For Helios, we obtain additional privacy and verifiability guarantees for voters equipped with X.509 certificates, such as those readily available from some national ID cards.
Maria Fueyo, Javier Herranz
The problem of revocation in anonymous authentication systems is subtle and has motivated a lot of work. One of the preferable solutions consists in maintaining either a whitelist LWof non-revoked users or a blacklist LBof revoked users, and then requiring users to additionally prove, when authenticating themselves, that they are in LW(membership proof) or that they are not in LB(non-membership proof). Of course, these additional proofs must not break the anonymity properties of the system, so they must be zero-knowledge proofs, revealing nothing about the identity of the users. In this paper, we focus on the RSA-based setting, and we consider the case of non-membership proofs to blacklists L = LB. The existing solutions for this setting rely on the use of universal dynamic accumulators; the underlying zero-knowledge proofs are bit complicated, and thus their efficiency; although being independent from the size of the blacklist L, seems to be improvable. Peng and Bao already tried to propose simpler and more efficient zero-knowledge proofs for this setting, but we prove in this paper that their protocol is not secure. We fix the problem by designing a new protocol, and formally proving its security properties. We then compare the efficiency of the new zero-knowledge non-membership protocol with that of the protocol, when they are integrated with anonymous authentication systems based on RSA (notably, the IBM product Idemix for anonymous credentials). We discuss for which values of the size k of the blacklist L, one protocol is preferable to the other one, and we propose different ways to combine and implement the two protocols.
Juan A. Garay, Aggelos Kiayias, Nikos Leonardos, Giorgos Panagiotakos
No abstract is available for this record.
Singh Toor Gurbakshish
The evolution of the traditional electricity infrastructure into smart grids promises more reliable and efficient power management, more energy aware consumers and inclusion of renewable sources for power generation. These fruitful promises are attracting initiatives by various nations all over the globe in various fields of academia. However, this evolution relies on the advances in the information technologies and communication technologies and thus is inevitably prone to various risks and threats. Even though many solutions have been proposed in the recent literature to overcome the security threats in smart grid networks, many issues still need to be addressed to make smart grids a reliable and efficient innovation. In this thesis, we first introduce the background, network architecture, security threats and the security requirements of smart grid networks. Our work focuses on the security aspects of Neighborhood Area Network (NAN) subsystems of smart grid. We present some of the prominent threats and attacks, specific to this subsystem, which violate the specific security goals requisite for its reliable operation. The proposed solutions and countermeasures for these security issues presented in the recent literature have been deeply reviewed to identify the promising solutions with respect to the specific security goals. Then we propose an improved VI dynamic key refreshment strategy for mesh security in the NAN and an authentication scheme based on software defined network (SDN) using dynamic one-way accumulators. The proposed dynamic key refreshment scheme can protect the mesh network system based on IEEE 802.11s standard from DoS attacks during the key refreshment whereby the intruder could launch the attack using the information from previous key refreshment cycle as proposed in the original key refreshment scheme. The use of simple hash based operation makes the scheme cost effective for the resource limited network devices. The proposed scheme also adds an enhancement to the sub-protocol of the original key refreshment scheme for enhanced security and reliability. The proposed SDN based authentication scheme employs one-way dynamic accumulators combined with zero-knowledge proofs for easy and cost efficient authentication process. The availability of the cross authentication among different NAN devices enables us to replicate the mesh network architecture. Using SDN as the backbone of the scheme helps us accommodate the advances of the upcoming wireless technologies where we can update the changes in the scheme conveniently. Our analysis shows that the proposed schemes can achieve the requisite authentication while withstanding multiple attacks and the balance between security and system performance is also achieved.
Kibin Lee, Joshua I. James, Tekachew Gobena Ejeta, Hyoung Rae Kim
Cryptocurrency, and its underlying technologies, has been gaining popularity for transaction management beyond financial transactions. Transaction information is maintained in the block-chain, which can be used to audit the integrity of the transaction. The focus on this paper is the potential availability of block-chain technology of other transactional uses. Block-chain is one of the most stable open ledgers that preserves transaction information, and is difficult to forge. Since the information stored in block-chain is not related to personally identify information, it has the characteristics of anonymity. Also, the block-chain allows for transparent transaction verification since all information in the block-chain is open to the public. These characteristics are the same as the requirements for a voting system. That is, strong robustness, anonymity, and transparency. In this paper, we propose an electronic voting system as an application of block-chain, and describe block-chain based voting at a national level through examples.
Judyta Przyłuska-Schmitt
No abstract is available for this record.
Angela Upreti
Addition of automated components such as smart meters, embedded microprocessors, and the two-ways communication systems from customers to operators to the power grid makes the power grid “smart”. One enhancement that requires the power grid to be “smart” is dynamic pricing. Implementation of dynamic pricing in the smart grid will require frequent transfer of energy consumption data from the consumers to the utilities. Privacy and security issues in transferring this energy consumption data is a widely studied topic. However, almost all of the studies done so far rely on a trusted third party, such as an electrical utilities or a load aggregator, that will have access to all of consumer data. This thesis proposes a Bitcoin-like decentralized model as a solution for secure information transfer within the smart grid, eliminating the presence of a central entity. Hence, a significant portion of this thesis is describes working principles of the Bitcoin network. This thesis specifically focuses on securing bidirectional data transfer between the gateway devices and the electrical utilities. How the information contained in the data is used is left upto the discretion of the consumers. Along with a proposal for a decentralized model, a broad discussion on security and privacy issues in the smart grid as well as cryptographic protocols required for a decentralized smart grid is also presented; a semi-detailed discussion on cryptographic protocols elliptic curve cryptography (ECC) and zero knowledge proof is included. Code for some of the useful cryptographic tools for a decentralized smart grid can be found in the appendix. A novel Bitcoin-like model developed to address security and privacy concerns of consumer data in the smart grid is the contribution of this thesis
Rafael Pass, Elaine Shi
Nakamoto's famous blockchain protocol enables achieving consensus in a so-called permissionless setting---anyone can join (or leave) the protocol execution, and the protocol instructions do not depend on the identities of the players. His ingenious protocol prevents sybil attacks (where an adversary spawns any number of new players) by relying on computational puzzles (a.k.a. moderately hard functions) introduced by Dwork and Naor (Crypto'92). Recent work by Garay et al (EuroCrypt'15) and Pass et al (manuscript, 2016) demonstrate that this protocol provably achieves consistency and liveness assuming a) honest players control a majority of the computational power in the network, b) the puzzle-hardness is appropriately set as a function of the maximum network delay and the total computational power of the network, and c) the computational puzzle is modeled as a random oracle. Assuming honest participation, however, is a strong assumption, especially in a setting where honest players are expected to perform a lot of work (to solve the computational puzzles). In Nakamoto's Bitcoin application of the blockchain protocol, players are incentivized to solve these puzzles by receiving rewards for every block (of transactions) they contribute to the blockchain. An elegant work by Eyal and Sirer (FinancialCrypt'14), strengthening and formalizing an earlier attack discussed on the Bitcoin forum, demonstrates that a coalition controlling even a minority fraction of the computational power in the network can gain (close to) 2 times its share of the rewards (and transaction fees) by deviating from the protocol instructions. In contrast, in a fair protocol, one would expect that players controlling a φ fraction of the computational resources to reap a φ fraction of the rewards. We present a new blockchain protocol---the FruitChain protocol---which satisfies the same consistency and liveness properties as Nakamoto's protocol (assuming an honest majority of the computing power), and additionally is δ-approximately fair: with overwhelming probability, any honest set of players controlling a φ fraction of computational power is guaranteed to get at least a fraction (1-δ)φ of the blocks (and thus rewards) in any Ω(κ/δ) length segment of the chain (where κ is the security parameter). Consequently, if this blockchain protocol is used as the ledger underlying a cryptocurrency system, where rewards and transaction fees are evenly distributed among the miners of blocks in a length κ segment of the chain, no coalition controlling less than a majority of the computing power can gain more than a factor (1+3δ) by deviating from the protocol (i.e., honest participation is an n/2-coalition-safe 3δ-Nash equilibrium). Finally, the FruitChain protocol enables decreasing the variance of mining rewards and as such significantly lessens (or even obliterates) the need for mining pools.
Philipp Locher, Rolf Haenni, Reto E. Koenig
No abstract is available for this record.
Tuyet Duong, Lei Fan, Thomas Veale, Hong-Sheng Zhou
No abstract is available for this record.
Nils Fleischhacker, Johannes Krupp, Giulio Malavolta, Jonas Schneider · 6 authors
A sanitizable signature scheme is a malleable signature scheme where a designated third party has the permission to modify certain parts of the message and adapt the signature accordingly. This primitive was introduced by Ateniese et al . (ESORICS 2005) and Brzuska et al . (PKC 2009) formalized the initially suggested five security properties. In the subsequent year, Brzuska et al . (PKC 2010) introduced a notion called unlinkability where the basic idea is that linking message‐signature pairs of the same document should be infeasible. Brzuska et al . formalized this notion and suggested a generic instantiation based on group signatures with a special structure. Unfortunately, the most efficient instantiations of group signatures do not have this property. In this work, we present the first efficient construction of unlinkable sanitizable signatures based on a novel type of signature schemes with re‐randomizable keys. This property allows one to re‐randomize both the signing and the verification key separately but consistently. Given a signature scheme with re‐randomizable keys, we obtain a sanitizable signature scheme by signing the message with a re‐randomized key and proving in zero‐knowledge that the derived key originates from either the signer or the sanitizer. To obtain an efficient instantiation, we instantiate this generic idea with Schnorr signatures and efficient ‐protocols that we turn into a non‐interactive zero‐knowledge proof via the Fiat‐Shamir transformation. In this work, we present an optimized version that is more efficient than the construction we suggested in the extended abstract of this work at PKC 2016.
Shravanthi, R Pooja, Bhagya Shree J
Bitcoin is a crypto currency with several advantages over approaches. Transactions are confirmed and stored by a peer-to-peer network in a blockchain. Therefore, all transactions are public and soon solutions where designed to increase privacy in Bitcoin. Many come with downsides, like requiring a trusted third-party or requiring modifications to Bitcoin. In this paper, we compare these approaches according to several criteria. Based on survey, coin Join emerges as the best approach for anonymizing Bitcoins today.
Ilaria Chillotti, Nicolas Gama, Mariya Georgieva, Malika Izabachène
No abstract is available for this record.
Ethan Heilman, Foteini Baldimtsi, Leen Alshenibr, Alessandra Scafuro · 5 authors
No abstract is available for this record.