SearcharxivSearch

arXiv subjects

Murat Cenk

Publications and source records attributed to Murat Cenk.

2 recordsLinked to original sources

Quantum Disruption: An SOK of How Post-Quantum Attackers Reshape Blockchain Security and Performance

As quantum computing advances, classical cryptographic systems - signature schemes, key exchange protocols, public-key encryption, and certain hash constructions - that secure most blockchain platforms come under threat, raising serious concerns about their long-term security and integrity. Transitioning to post-quantum primitives is rarely straightforward: their larger sizes and higher computation costs can have unintended consequences, and in some cases make such a transition impractical. We examine the impact of post-quantum migration on blockchain systems across three dimensions. First, we dissect the cryptographic primitives most vulnerable to quantum attacks within the consensus, identity, and transaction-validation layers. Next, we survey proposed post-quantum adaptations and evaluate their practical feasibility. Finally, we assess how substituting classical primitives with post-quantum alternatives affects system performance, protocol behavior, and the underlying incentive and trust structures. Our findings show that PQ adoption is far from a drop-in replacement: it demands careful architectural reconsideration, as naive substitution risks destabilizing core protocol operations and weakening the security and efficiency guarantees blockchains rely upon.

cs.CR

Estonian Voting Verification Mechanism Revisited

After the Estonian Parliamentary Elections held in 2011, an additional verification mechanism was integrated into the i-voting system in order to resist corrupted voting devices, including the so called Student's Attack where a student practically showed that the voting system is indeed not verifiable by developing several versions of malware capable of blocking or even changing the vote. This mechanism gives voters the opportunity to verify whether the vote they cast is stored in the central system correctly. However, the verification phase ends by displaying the cast vote in plain form on the verification device. In other words, the device on which the verification is done learns the voter's choice. In this work, our aim is to investigate this verification phase in detail and to point out that leaking the voter's choice to the verification application may harm the voter privacy. Additionally, when applied in a wide range, this would even compromise the fairness and the overall secrecy of the elections. In this respect, we propose an alternative verification mechanism for the Estonian i-voting system to overcome this vulnerability. Not only is the proposed mechanism secure and resistant against corrupted verification devices, so does it successfully verify whether the vote is correctly stored in the system. We also highlight that our proposed mechanism brings only symmetric encryptions and hash functions on the verification device, thereby mitigating these weaknesses in an efficient way with a negligible cost. More concretely, it brings only $m$ additional symmetric key decryptions to the verification device, where $m$ denoting the number of candidates. Finally, we prove the security of the proposed verification mechanism and compare the cost complexity of the proposed method with that of the current mechanism.

cs.CR