For Nakamoto's longest-chain consensus protocol, whose proof-of-work (PoW) and proof-of-stake (PoS) variants power major blockchains such as Bitcoin and Cardano, we revisit the classic problem of the security--performance tradeoff: Given a network of nodes with finite communication- and computation-resources, against what fraction of adversary power is Nakamoto consensus (NC) secure for a given block production rate? State-of-the-art analyses of NC fail to answer this question, because their bounded-delay model does not capture the rate limits to nodes' processing of blocks, which cause congestion when blocks are released in quick succession. We develop a new analysis technique to prove a refined security--performance tradeoff for PoW NC in a bounded-capacity model. In this model, we show that, in contrast to the classic bounded-delay model, Nakamoto's private attack is no longer the worst attack, and a new attack we call the teasing strategy, that exploits congestion, is strictly worse. In PoS, equivocating blocks can exacerbate congestion, making traditional PoS NC insecure except at very low block production rates. To counter such equivocation spamming, we present a variant of PoS NC we call Blanking NC (BlaNC), which achieves the same resilience as PoW NC.
Welcome to the fifteenth Jubilee International Symposium on Autonomous Decentralized Systems (ISADS).As Lifetime Honorary Chair, I would like to thank you for coming to ISADS 2023. ISADS was founded in 1993 atKawasaki, Japan.Since then, ISADSs have been held world-wide every two years except in 2021 due to pandemic.They were successful in their high quality and broad international participation from academia, government and industry.At the first ISADS, the concept of autonomous decentralized systems (ADS) was well recognized.During the last 30 years, fields of ADS have been substantially advanced to provide solutions for control, communication, computing, service systems and further to organization and finance management, such as FinTech along with rapid development of other related technologies and management.ISADS 2023 reflects not only such maturity but also innovation in ADS concept, technology and application as well as further integration with other heterogeneous fields.Now, structures of Society, Value, Business and Technology have been unpredictably and rapidly transformed under climate change, pandemic and economic turmoil.ADS, which behaves as a living system comprised of largely autonomous and decentralized subsystems, has been successfully contributing to fulfill adaptive, reliable and expandable properties under changing and transforming environment as consistent concept.The continuous growth of ISADS in size and diversity is reflected by the sponsoring society, the Computer Society of the Institute of Electrical and Electric Engineers (IEEE) together with the cooperating societies including the International Federation for Information Processing (IFIP), the International Federation of Automatic Control (IFAC), the Institute of Electronics, Information and Communication Engineers (IEICE), Japan and Object Management Group (OMG), as well as the strong supporting organization of Universidad Panamericana, Mexico.I hope that you will find the program stimulating and that you will take the opportunity to meet with your colleagues from around the world to engage in social as well as technical discussions.In addition, technical sessions and workshops on the hot topics of technologies and their advanced applications are jointly arranged.The success of the symposium depends on the dedication and contributions of many volunteers, committee members, authors, reviewers, speakers, workshop chairs, session chairs and supporting personnel, and the strong organizations.I would like to thank Honorary Chairs, Bojan Cukic and General Chair, Carlos Perez for their direction.
Lewis Golightly, Paolo Modesti, Rémi Garcia, Victor Chang
Access Control is a crucial defense mechanism organizations can deploy to meet modern cybersecurity needs and legal compliance with data privacy. The aim is to prevent unauthorized users and systems from accessing protected resources in a way that exceeds their permissions. The present survey aims to summarize state-of-the-art Access Control techniques, presenting recent research trends in this area. Moreover, as the cyber-attack landscape and zero-trust networking challenges require organizations to consider their Information Security management strategies carefully, in this study, we present a review of contemporary Access Control techniques and technologies being discussed in the literature and the various innovations and evolution of the technology. We also discuss adopting and applying different Access Control techniques and technologies in four upcoming and crucial domains: Cloud Computing, Blockchain, the Internet of Things, and Software-Defined Networking. Finally, we discuss the business adoption strategies for Access Control and how the technology can be integrated into a cybersecurity and network architecture strategy.
Blockchain has the potential to reconfigure the contemporary economic, legal, political and cultural landscape, causing a flood of research on this topic. However, limited efforts have been made to conduct retrospective research to appraise the blockchain studies in the recent period, easily leading to a neglect of new technological trends. Consequently, the present research designs a quantitative- and qualitative-analysis procedure to review the latest research status. Adopting a four-step workflow, six research hotspots (i.e., the specific application areas of blockchain technology, the integration of blockchain and other technologies, the driving factors of blockchain, the values of blockchain technology, the types of blockchain and the core technologies of blockchain) and five research frontiers (i.e., entrepreneurship, contract, industrial internet, data management and distributed ledger technology) were detected using quantitative analysis. Furthermore, three other topics (i.e., the Internet of things, access control and trust) and two research gaps (i.e., the true effect of blockchain technology on firms’ operational efficiency and the regulation of the “dark sides” of blockchain technology) were also identified, using qualitative analysis. Finally, the evolutionary paths were qualitatively analyzed, and then three phases of blockchain research were summarized. The conclusions are able to provide a more comprehensive enlightenment regarding blockchain’s research hotspots, research frontiers, evolutionary paths and research gaps in the recent period, from 2015 to 2021, and to provide a reference for future research.
Xianhui Deng, Binyong Li, Shaowei Zhang, Liangming Deng
The blockchain-based access control mechanism (BACM) is gradually becoming an essential paradigm for solving dynamic and trusted access control problems in the open network environment. However, since the current open network environment has such features as dynamic variability and the uncertainty of user identity, most of the existing BACM cannot solve the access control problems in the current open network environment in a dynamic, flexible, proactive, efficient, and fine-grained approach. In this paper, we propose a novel BACM scheme to address such problems. Specifically, we first design a new, proactive, and fine-grained access control model, by utilizing the dynamicity and fine-grain of the attribute-based access control model, flexibility shown by the trust evaluation mechanism in evaluating the trust level of users, and proactivity shown by the game evaluation mechanism in curbing malicious users who suddenly launch malicious access requests. Second, based on the above access control model, we propose a dynamic, flexible, and proactive BACM for the current open network environment, exploiting the trustworthiness and transparency that the smart contract and the transaction mechanism in blockchain technology show during program execution. Further, a double sliding storage window is built, guaranteeing accurate data acquisition by BACM while efficiently allowing it to acquire time-sensitive data during the permission management process. Meanwhile, a pre-authorization concept is introduced to improve the efficiency and flexibility of BACM in processing access control problems. Security analysis demonstrates that our proposed BACM scheme satisfies the simple security issue and the simple availability issue. Experiments on a real user trust record dataset demonstrate the high effectiveness of the proposed BACM scheme in evaluating and deciding on access requests and the superiorities over most existing schemes in dynamicity, fine granularity, flexibility, and proactivity.
Davide Basile, Claudio Di Ciccio, Valerio Goretti, Sabrina Kirrane
Decentralization initiatives such as Solid, Digi.me, and ActivityPub aim to give data owners more control over their data and to level the playing field by enabling small companies and individuals to gain access to data, thus stimulating innovation. However, these initiatives typically use access control mechanisms that cannot verify compliance with usage conditions after access has been granted to others. In this paper, we extend the state of the art by proposing a resource governance conceptual framework, entitled ReGov, that facilitates usage control in decentralized web environments. We subsequently demonstrate how our framework can be instantiated by combining blockchain and trusted execution environments. Through blockchain technologies, we record policies expressing the usage conditions associated with resources and monitor their compliance. Our instantiation employs trusted execution environments to enforce said policies, inside data consumers’ devices. We evaluate the framework instantiation through a detailed analysis of requirments derived from a data market motivating scenario, as well as an assessment of the security, privacy, and affordability aspects of our proposal.
Since the dawn of human civilization, trust has been the core challenge of social organization. Trust functions to reduce the effort spent in constantly monitoring others' actions in order to verify their assertions, thus facilitating cooperation by allowing groups to function with reduced complexity. To date, in modern societies, large scale trust is almost exclusively provided by large centralized institutions. Specifically in the case of the Internet, Big Tech companies maintain the largest Internet platforms where users can interact, transact and share information. Thus, they control who can interact and conduct transactions through their monopoly of online trust. However, as recent events have shown, allowing for-profit corporations to act as gatekeepers to the online world comes with a litany of problems. While so far ecosystems of trust on the Internet could only be feasibly created by large institutions, Web3 proponents have a vision of the Internet where trust is generated without centralised actors. They attempt to do so by creating an ecosystem of trust constructed using decentralised technology. This survey explores this elusive goal of Web3 to create a "Universal Trust Machine", which in a true decentralised paradigm would be owned by both nobody and everybody. In order to do so, we first motivate the decades-old problem of generating trust without an intermediary by discussing Robert Axelrod's research on the evolution of cooperation. Next, we present the challenges that would have to be overcome in order to enable long term cooperation. We proceed to present various reputation systems, all of which present promising techniques for encouraging trustworthy behaviour. Then, we discuss Distributed Ledger technologies whose secure transaction facilitating and privacy preserving techniques promise to be a good complement to the current limitations of vanilla reputation systems.
Santiago Cuéllar Gempeler, Bill Harris, James Parker, Stuart Pernsteiner · 6 authors
Currently, when a security analyst discovers a vulnerability in critical software system, they must navigate a fraught dilemma: immediately disclosing the vulnerability to the public could harm the system’s users; whereas disclosing the vulnerability only to the software’s vendor lets the vendor disregard or deprioritize the security risk, to the detriment of unwittingly-affected users. A compelling recent line of work aims to resolve this by using Zero Knowledge (ZK) protocols that let analysts prove that they know a vulnerability in a program, without revealing the details of the vulnerability or the inputs that exploit it. In principle, this could be achieved by generic ZK techniques. In practice, ZK vulnerability proofs to date have been restricted in scope and expressibility, due to challenges related to generating proof statements that model real-world software at scale and to directly formulating violated properties. This article presents Cheesecloth , a novel proof-statement compiler, which proves practical vulnerabilities in ZK by soundly-but-aggressively preprocessing programs on public inputs, selectively revealing information about executed control segments, and formalizing information leakage using a novel storage-labeling scheme. Cheesecloth ’s practicality is demonstrated by generating ZK proofs of well-known vulnerabilities in (previous versions of) critical software, including the Heartbleed information leakage in OpenSSL, a memory vulnerability in the FFmpeg multimedia encoding framework, a cryptographic implementation bug in the Secure Scuttlebutt decentralised social network, and a denial of service vulnerability in OpenSSL.
Access control is widely used technology for securing sensitive resources of information systems, such as personal data managed by cloud-based data store and sensitive data stream collected by smart devices. Existing access control systems mainly adopt centralized architecture and static access control models, including Access Control List, Role-based Access Control and Attribute-based Access Control. However, these systems fail to meet the increasing requirements of behavior based dynamic access control or requirements of owner initiated autonomous access control without relying on trustworthy third parties and suffer inherent drawbacks of single point of failure or dishonesty. To this end, a novel blockchain-based and provenance enabled dynamic access control scheme called BPDAC is proposed. Specifically, it collects and stores data provenance on blockchain to enable behavior-based dynamic access control; in particular, the quick lookup table structure is designed to speed up access control evaluation based on provenance with increasing complexity. It also provides specifications for formulating access control policies based on provenance. It utilizes a set of smart contracts on blockchain to enable decentralized and reliable autonomous access control. A prototype system is implemented on the Hyperledger Fabric and experiments are conducted to show that the proposed scheme is practically feasible and scalable in terms of the performance metrics of throughput and latency.
Aditya Pathak, Irfan Al‐Anbagi, Howard J. Hamilton
Recent research has focused on applying blockchain technology to solve security-related problems in Internet of Things (IoT) networks. However, implementing blockchain technology directly on IoT networks is prone to high overheads and energy-expensive operations. Therefore, in this paper, we use edge computing technology to avoid these problems. We also propose a novel Trust-based Access Control Mechanism for Edge-IoT Networks using Blockchain technology (named TABI) to implement end-to-end security in resource-constrained IoT networks. The TABI mechanism utilizes both access control and trust evaluation mechanisms to mitigate the impact of malicious IoT users and devices. Additionally, it incorporates permissioned Hyperledger blockchain technology to provide an added layer of security through authentication. The trust evaluation mechanism is implemented as a trust calculation contract (TCC) on the edge devices using Hyperledger Composer. The access control mechanism employs an Attribute-based Access Control (ABAC) mechanism, which is implemented on the Hyperledger blockchain using two smart contracts: the attribute contract (AC) and the access control contract (ACC). We implement a proof-of-concept (PoC) implementation using Hyperledger Caliper (a benchmark testing tool) and Docker images. Our evaluation includes five analyses: Trust Evaluation Mechanism, Access Control Mechanism, Security, Blockchain, and IoT Applications. Through this evaluation, we highlight the effectiveness of TABI in terms of throughput, latency, detection of malicious IoT devices, and resource consumption of the IoT devices. Our analyses demonstrate that TABI is particularly useful in IoT applications that require low latency and resource efficiency.
Different from “read” based Web1 and “read-write” based Web2, “read-write-own” based Web3 is proposed as a typical user-centric internet to open the new generation of World Wide Web, which is expected to not allow the power to rest with a few big internet companies. Generally, Web3 is decentralized and semantic depending on user behavior, and thus the zero-trust architecture should be created initially. To hasten its arrival, a comprehensive discussion on its architecture and enabling technologies is inspired. Specifically, to access Web3, it is essential to study how to establish an identity management system. Meanwhile, for resource description and data verification, it is necessary to set up decentralized identifiers (DID), and link the data to identifiers in the form of DID document. In particular, a decentralized network operating system is an indispensable underlying technology for Web3, incorporating concepts such as decentralization and user-driven philosophy. Therefore, the corresponding technologies for the operating system such as blockchain and distributed ledger technology should be further studied and developed. Moreover, in order to reduce the consensus cost, a large-scale incentive mechanism is also the basis of long-term sustainability, which can attract and motivate distributed players to participate in the maintenance of Web3. Last but not the least, Web3 is built on a physical infrastructure relying on communication, networking, storage and computing, which is crucial to establishing an effective and secure Web3. This encourages us to study communication, networking, storage and computing in Web3, as well as the specific requirements of running Web3.
Tariq Alsboui, Muhammad Hussain, Hussain Al-Aqrabi, Richard Hill · 5 authors
With the vast development of Internet-of-Things (IoT) ecosystem, various types of information, such as healthcare records and physical resources, are integrated for different types of applications. Due to the sheer number of connected IoT devices, which generate a large amount of data, Distributed Ledger Technology, such as Blockchain and IOTA have been recently applied in developing access control models, yet they involve significant energy due to mining, low throughput, non-scalable, and computational overhead that is not acceptable for IoT resource-constrained devices. In this paper, we propose a Scalable Decentralized and Lightweight Access Control framework (SDAC) by using the IOTA platform. IOTA is an emerging distributed ledger technology that has significant features for IoT, such as zero fees transactions, scalability, security and energy efficiency. The proposed SDAC aims to improve security, authorize, and authenticate users when accessing data by using the IOTA Masked Authenticated Messaging (MAM) protocol. MAM ensures access control by encrypting and granting permission to only authorized users. The experimental results indicate that IOTA MAM is a feasible solution that can be used for managing authorization in the IoT domain.
Feifei Guo, Guohua Shen, Zhiqiu Huang, Yang Yang · 6 authors
With the advent of IoT technology, the dynamic nature of IoT devices has introduced new obstacles to access control. It is essential to consider the security requirements of the actual physical environment, rendering the traditional access control approach centered on the information space. In the IoT ecosystem, there are several issues such as the dynamics of devices frequently entering and leaving, the lack of computing and storage capacity, and distributed deployment. To address these challenges, this paper proposes the Domain Attribute Based Access Control(DABAC) that incorporates domain elements to implement the physical location limitation of dynamic devices. Moreover, an intelligent gateway is utilized to divide the physical area and act as a proxy to achieve regional device management, automatic networking of devices in the domain, and the dynamic expansion of the sensor network resulting from device entry or exit. Then, given the distributed deployment of devices, smart contracts are employed to deploy access control mechanisms and construct a trusted environment to mitigate threats such as single points of failure. Finally, the DABAC is implemented on the Ethereum platform, simulating a smart medical situation. The experimental results demonstrate that the proposed solution effectively addresses the problem of access control of device dynamics in an untrusted IoT environment while maintaining system security.
Abstract—This paper investigates the integration of Zero-Knowledge Proofs (ZKP) and OAuth 2.0 to enhance anonymity and security in multi-agent distributed systems. We propose an approach that allows agents to authenticate and prove possession of specific data without revealing the underlying details. Additionally, we outline a potential access control strategy using ZKP for anonymity, allowing agents to validate their access rights without identity exposure. When combined with OAuth 2.0, this mechanism provides a framework for secure data access. While the proposed methods offer promising solutions to security, privacy, and anonymity challenges in multi-agent systems, they also highlight the need for further research and validation to confirm their effectiveness.
Carmit Hazay, Muthuramakrishnan Venkitasubramaniam, Mor Weiss
Abstract Distributed zero-knowledge (dZK) proofs, recently introduced by Boneh et al. (CRYPTO‘19), allow a prover $$\mathcal{P}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>P</mml:mi> </mml:math> to prove NP statements on an input x , which is distributed between k verifiers $$\mathcal{V}_1,\ldots ,\mathcal{V}_k$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:msub> <mml:mi>V</mml:mi> <mml:mn>1</mml:mn> </mml:msub> <mml:mo>,</mml:mo> <mml:mo>…</mml:mo> <mml:mo>,</mml:mo> <mml:msub> <mml:mi>V</mml:mi> <mml:mi>k</mml:mi> </mml:msub> </mml:mrow> </mml:math> , where each $$\mathcal{V}_i$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:msub> <mml:mi>V</mml:mi> <mml:mi>i</mml:mi> </mml:msub> </mml:math> holds only a piece of x . As in standard ZK proofs, dZK proofs guarantee Completeness when all parties are honest; Soundness against a malicious prover colluding with t verifiers; and Zero Knowledge against a subset of t malicious verifiers, in the sense that they learn nothing about the NP witness and the input pieces of the honest verifiers. Unfortunately, dZK proofs provide no correctness guarantee for an honest prover against a subset of maliciously corrupted verifiers. In particular, such verifiers might be able to “frame” the prover, causing honest verifiers to reject a true claim. This is a significant limitation, since such scenarios arise naturally in dZK applications, e.g., for proving honest behavior, and such attacks are indeed possible in existing dZKs (Boneh et al., CRYPTO‘19). We put forth and study the notion of strong completeness for dZKs, guaranteeing that true claims are accepted even when t verifiers are maliciously corrupted. We then design strongly-complete dZK proofs in the honest-majority setting using the “MPC-in-the-head” paradigm of Ishai et al. (STOC‘07), providing a novel analysis that exploits the unique properties of the distributed setting. To demonstrate the usefulness of strong completeness, we present several applications in which it is instrumental in obtaining security. First, we construct a certifiable version of Verifiable Secret Sharing (VSS), which is a VSS in which the dealer additionally proves that the shared secret satisfies a given NP relation. Our construction withstands a constant fraction of corruptions, whereas a previous construction of Ishai et al. (TCC‘14) required $$k={\textsf{poly}}\left( t\right) $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>k</mml:mi> <mml:mo>=</mml:mo> <mml:mi>poly</mml:mi> <mml:mfenced> <mml:mi>t</mml:mi> </mml:mfenced> </mml:mrow> </mml:math> . We also design a reusable version of certifiable VSS that we introduce, in which the dealer can prove an unlimited number of predicates on the same shared secret. Finally, we extend a compiler of Boneh et al. (CRYPTO‘19), who used dZKs to transform a class of “natural” semi-honest protocols in the honest-majority setting into maliciously secure ones with abort. Our compiler uses strongly-complete dZKs to obtain identifiable abort.
Franck Cassez, Joanne Fuller, Milad K. Ghale, David J. Pearce · 5 authors
The Ethereum protocol implements a replicated state machine. The network participants keep track of the system state by: 1) agreeing on the sequence of transactions to be processed and 2) computing the state transitions that correspond to the sequence of transactions. Ethereum transactions are programs, called smart contracts, and computing a state transition requires executing some code. The Ethereum Virtual Machine (EVM) provides this capability and can execute programs written in EVM bytecode. We present a formal and executable semantics of the EVM written in the verification-friendly language Dafny: it provides (i) a readable, formal and verified specification of the semantics of the EVM; (ii) a framework to formally reason about bytecode.
Stefan More, Sebastian Ramacher, Lukas Alber, Marco Herzl
Authentication, authorization, and trust verification are central parts of an access control system. The conditions for granting access in such a system are collected in access policies. Since access conditions are often complex, dedicated languages -- policy languages -- for defining policies are in use. However, current policy languages are unable to express such conditions having privacy of users in mind. With privacy-preserving technologies, users are enabled to prove information to the access system without revealing it. In this work, we present a generic design for supporting privacy-preserving technologies in policy languages. Our design prevents unnecessary disclosure of sensitive information while still allowing the formulation of expressive rules for access control. For that we make use of zero-knowledge proofs (NIZKs). We demonstrate our design by applying it to the TPL policy language, while using SNARKs. Also, we evaluate the resulting ZK-TPL language and its associated toolchain. Our evaluation shows that for regular-sized credentials communication and verification overhead is negligible.
Scientific and commercial endeavors could benefit from cross-organizational, decentralized collaboration, which becomes the key to innovation. This work addresses one of its challenges, namely efficient access control to assets for distributed data processing among autonomous data centers. We propose a group membership management framework dedicated for realizing access control in decentralized environments. Its novelty lies in a synergy of two concepts: a decentralized knowledge base and an incremental indexing scheme, both assuming a P2P architecture, where each peer retains autonomy and has full control over the choice of peers it cooperates with. The extent of exchanged information is reduced to the minimum required for user collaboration and assumes limited trust between peers. The indexing scheme is optimized for read-intensive scenarios by offering fast queries -- look-ups in precomputed indices. The index precomputation increases the complexity of update operations, but their performance is arguably sufficient for large organizations, as shown by conducted tests. We believe that our framework is a major contribution towards decentralized, cross-organizational collaboration.
A medical record is an important part of a patient’s follow-up. It comprises healthcare professionals’ views, prescriptions, analyses, and all information about the patient. Several players, including the patient, the doctor, and the pharmacist, are involved in the process of sharing, and managing this file. Any authorized individual can access the electronic medical record (EMR) from anywhere, and the data are shared among various health service providers. Sharing the EMR requires various conditions, such as security and confidentiality. However, existing medical systems may be exposed to system failure and malicious intrusions, making it difficult to deliver dependable services. Additionally, the features of these systems represent a challenge for centralized access control methods. This paper presents SEMRAchain a system based on Access control (Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC)) and a smart contract approach. This fusion enables decentralized, fine-grained, and dynamic access control management for EMR management. Together, blockchain technology as a secure distributed ledger and access control provides such a solution, providing system stakeholders with not just visibility but also trustworthiness, credibility, and immutability.
Tobias Adrian, Federico Grinberg, Tommaso Mancini Griffoli, Robert M. Townsend · 5 authors
Cross-border payments can be slow, expensive, and risky. They are intermediated by counterparties in different jurisdictions which rely on costly trusted relationships to offset the lack of a common settlement asset as well as common rules and governance. In this paper, we present a vision for a multilateral platform that could improve cross-border payments, as well as related foreign exchange transactions, risk sharing, and more generally, financial contracting. The approach is to leverage technological innovations for public policy objectives. A common ledger, smart contracts, and encryption offer significant gains to market efficiency, completeness, and access, as well as to transparency, transaction and compliance costs, and safety. This paper is a first step aiming to stimulate further work in this space.
Advances in monitoring, sensing, control, and communication allow the use of Smart Grid. It enables smart metering applications, substation event and alarm updates, vehicle-tovehicle (V2V), and vehicle-to-network (V2G) energy transactions, among others. However, the data used is sensitive and communication between entities must be reliable and secure. For this, the Internet uses the Public Key Infrastructure (ICP) in which the communicating parties must have a digital certificate issued by a certification authority (CA). However, it has a centralized architecture with a single point of failure. An alternative to this is the use of distributed technologies and one that stands out is Blockchain. It is a technology that allows trusted communication between untrusted entities without a centralized third party. Also, Blockchain is a chronological sequence of blocks linked through the hash of each one. This characteristic ensures data integrity and immutability. Therefore, Blockchain is a powerful technology for recording data like access control rules. This work utilizes Blockchain to provide a framework applying the Smart Contract concept for a Role-Based Access Control (RBAC) system. Also, it uses the framework Truffle to test the Smart Contract functionalities and presents a study case of the proposal (KIM et al., 2019) together with this work. In counterpart to the related works, this work does not have a single-point of failure.
Daniël Reijsbergen, Aung Htein Maw, Zheng Yang, Tien Tuan Anh Dinh · 5 authors
Users today expect more security from services that handle their data. In addition to traditional data privacy and integrity requirements, they expect transparency, i.e., that the service's processing of the data is verifiable by users and trusted auditors. Our goal is to build a multi-user system that provides data privacy, integrity, and transparency for a large number of operations, while achieving practical performance. To this end, we first identify the limitations of existing approaches that use authenticated data structures. We find that they fall into two categories: 1) those that hide each user's data from other users, but have a limited range of verifiable operations (e.g., CONIKS, Merkle2, and Proofs of Liabilities), and 2) those that support a wide range of verifiable operations, but make all data publicly visible (e.g., IntegriDB and FalconDB). We then present TAP to address the above limitations. The key component of TAP is a novel tree data structure that supports efficient result verification, and relies on independent audits that use zero-knowledge range proofs to show that the tree is constructed correctly without revealing user data. TAP supports a broad range of verifiable operations, including quantiles and sample standard deviations. We conduct a comprehensive evaluation of TAP, and compare it against two state-of-the-art baselines, namely IntegriDB and Merkle2, showing that the system is practical at scale.
Zhe Tu, Huachun Zhou, Kun Li, Haoxiang Song · 5 authors
The rapid development of the Internet of Things (IoT) has dramatically increased the number of distributed IoT devices and users. Trust and Reputation Model (TRM) is a well-known technique for improving the security of IoT, which detects malicious attacks by evaluating user behavior. Since traditional distributed TRMs lack secure and reliable data sharing mechanisms, some works have integrated the TRMs into the trusted blockchains. Nevertheless, they have not realized the security requirements of the comprehensive assessment of user behavior and dynamic evaluation of reputation. Therefore, this paper introduces a Blockchain-based Trust and Reputation Model (BTRM), which evaluates user reputation from many aspects and can resist multiple malicious attacks in the distributed network. Second, we propose a novel Dynamic Evaluation Mechanism (DEM), which reduces the number of reputation evaluations without degrading network security and builds a trusting foundation between long-term inactive users and the network. Eventually, we deploy the proposed model DEM-BTRM in a prototype system of Hyperledger Fabric and compare it with existing reputation evaluation methods. The results show that the DEM-BTRM can comprehensively evaluate user behavior and dynamically detect malicious attacks.
Self-Sovereign Identity (SSI) is projected to become part of every person's life in some form. The ability to verify and authenticate that an individual is the actual person they are purported to be along with securing the personal attributes could have wide spread implications when engaging with third party organizations. Utilizing blockchains and other decentralized technologies, SSI is a growing area of research. The aspect of securing personal information within a decentralized structure has possible benefits to the public and private sectors. In this paper, we describe the SSI framework architecture as well as possible use cases across domains like healthcare, finance, retail, and government. The paper also contrasts SSI and its decentralized architecture with the current widely adopted model of Public Key Infrastructure (PKI).