Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,621 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,621 results · page 15 of 68

Clear filters
Aug 31, 2024·International Journal of Applied Information Systems
6 cites
UTILIZING BLOCKCHAIN TECHNOLOGY FOR UNIVERSITY CERTIFICATE VERIFICATION SYSTEM

Olaiya Samuel Oluwaseyi, Raphael Olufemi Akinyede

In the contemporary digital age, the authentication and verification of academic certificates have become increasingly vital yet challenging due to issues such as fraud, forgery, and the inefficiencies of traditional paper-based systems.This paper explored the implementation of blockchain technology as a robust solution for university certificate verification systems.Blockchain's decentralized, immutable ledger offers unparalleled security, transparency, and trust, making it an ideal framework for certifying academic credentials.By leveraging blockchain, universities can issue tamper-proof digital certificates that are easily verifiable by employers and other stakeholders, eliminating the need for intermediaries.This system enhances the reliability of academic records, reduces administrative burdens, and accelerates the verification process.Moreover, the paper discusses the technical architecture of a blockchain-based certificate system, including smart contracts, cryptographic techniques, and distributed consensus mechanisms.The paper analyze case studies of existing implementations to highlight the practical benefits and challenges encountered.The findings suggest that blockchain technology not only fortifies the integrity of academic certifications but also paves the way for a more efficient, transparent, and globally accessible verification infrastructure.This transformative approach has the potential to set new standards in academic administration and significantly curb credential fraud on a global scale.

Open access
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Original source
Aug 31, 2024·Scientific Journal of Metaverse and Blockchain Technologies
3 cites
Blockchain-Based Vendor Management in IT: Challenges and Solutions

Srikanthudu Avancha, Prof. Arpit Jain, Er. Om Goel

The rapid evolution of the IT sector has led to increasingly complex vendor management systems, necessitating innovative solutions to handle the multifaceted challenges associated with these systems. Traditional vendor management practices often struggle with issues related to transparency, security, inefficiencies in communication, and trustworthiness among vendors. Blockchain technology, with its decentralized, immutable, and transparent characteristics, presents a compelling solution to these challenges. This research paper explores the application of blockchain technology in IT vendor management, focusing on its potential to address critical challenges and enhance the overall efficiency of vendor-related processes. The paper begins by outlining the inherent challenges in conventional vendor management systems, including difficulties in verifying vendor credentials, managing contracts, ensuring data security, and maintaining a reliable audit trail. These challenges often result in operational inefficiencies, increased costs, and potential risks related to vendor fraud or non-compliance. Blockchain technology, known for its secure, transparent, and decentralized nature, offers a transformative approach to these challenges. By providing a distributed ledger that records all transactions in a secure and immutable manner, blockchain can significantly enhance the transparency and security of vendor management processes. The paper examines how blockchain can be used to automate vendor verification, streamline contract management through smart contracts, and ensure data integrity across the vendor lifecycle.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cloud Data Security Solutions
Original source
Aug 31, 2024·Journal of Informatics Education and Research
1 cites
Integrating blockchain with federated learning for distributed cloud data security

A Rengarajan

The combination of blockchain technology with federated learning (FL) introduces an innovative method to improve security, privacy, and trust in decentralized machine learning systems. Federated learning allows for distributed model training while safeguarding data privacy by keeping original data on local devices. Nonetheless, it confronts issues such as ensuring data integrity, the reliability of model updates, and vulnerability to adversarial attacks. Blockchain technology creates an immutable, decentralized ledger that guarantees transparency, secure aggregation, and verifiable updates to models. By utilizing blockchain's consensus protocols, smart contracts, and cryptographic methods, FL can counteract threats like poisoning attacks and eliminate single points of failure. This paper examines the architectural framework, advantages, and challenges of merging blockchain with FL, in addition to potential enhancements to boost scalability and efficiency. We also emphasize practical applications and prospective research pathways in this evolving field.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Aug 30, 2024·Queue
3 cites
Confidential Computing Proofs

Mark Russinovich, Cédric Fournet, Greg Zaverucha, Josh Benaloh · 6 authors

Proofs are powerful tools for integrity and privacy, enabling the verifier to delegate a computation and still verify its correct execution, and enabling the prover to keep the details of the computation private. Both CCP and ZKP can achieve soundness and zero-knowledge but with important differences. CCP relies on hardware trust assumptions, which yield high performance and additional confidentiality protection for the prover but may be unacceptable for some applications. CCP is also often easier to use, notably with existing code, whereas ZKP comes with a large prover overhead that may be unpractical for some applications.

Open access
Cryptography and Data Security
Security and Verification in Computing
Cloud Data Security Solutions
Original source
Aug 30, 2024·International Journal of Advanced Research in Science Communication and Technology
0 cites
Designing Trustless Identity: A Multi-Layered Framework for Decentralized Verification in Web3 Ecosystems

Venkata Baladari

As digital interactions continue to shift toward decentralized platforms, the limitations of centralized identity systems such as data silos, lack of user control, and reliance on intermediaries have become increasingly apparent. This research introduces a structured, multi-layered framework to support the design and implementation of trustless digital identity systems aligned with the principles of Web3. The proposed model integrates five core components: standardized identity protocols, regulatory alignment, user-centric design, trusted institutional participation, and enterprise integration through middleware. Each layer addresses critical challenges such as legal recognition, interoperability, usability, and system scalability. By combining decentralized technologies with practical governance and user experience strategies, the framework aims to enable secure, verifiable, and portable identities that function across jurisdictions and platforms. This paper offers a foundational approach to advancing digital identity infrastructure in a way that is technically robust and socially inclusive

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Aug 29, 2024·Future Internet
30 cites
A Survey on Data Availability in Layer 2 Blockchain Rollups: Open Challenges and Future Improvements

Muhammad Bin Saif, Sara Migliorini, Fausto Spoto

Layer 2 solutions have emerged in recent years as a valuable alternative to increase the throughput and scalability of blockchain-based architectures. The three primary types of Layer 2 solutions are state channels, sidechains, and rollups. The rollups are particularly promising, allowing significant improvements in transaction throughput, security, and efficiency, and have been adopted by many real-world projects, such as Polygon and Optimistic. However, the adoption of Layer 2 solutions has led to other challenges, such as the data availability problem, where transaction data processed off-chain must be posted back on the main chain. This is crucial to prevent data withholding attacks and ensure all participants can independently verify the blockchain state. This paper provides a comprehensive survey of existing rollup-based Layer 2 solutions with a focus on the data availability problem and discusses the major advantages and disadvantages of them. Finally, an analysis of open challenges and future research directions is provided.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cloud Computing and Resource Management
Original source
Aug 24, 2024·arXiv (Cornell University)
0 cites
Tatami Printer: Physical ZKPs for Tatami Puzzles

Suthee Ruangwises

Tatami puzzles are pencil puzzles with an objective to partition a rectangular grid into rectangular regions such that no four regions share a corner point, as well as satisfying other constraints. In this paper, we develop a physical card-based protocol called Tatami printer that can help verify solutions of Tatami puzzles. We then use the Tatami printer to construct zero-knowledge proof protocols for two such puzzles: Tatamibari and Square Jam. These protocols enable a prover to show a verifier the existence of the puzzles' solutions without revealing them.

Open access
3 source records
cs.CR
cs.LO
Interactive and Immersive Displays
Original source
Aug 22, 2024·Distributed Ledger Technologies Research and Practice
2 cites
Empirical Study of Impact of Solidity Compiler Updates on Vulnerabilities in Ethereum Smart Contracts

Chihiro Kado, Naoto Yanai, Jason Paul Cruz, Kyosuke Yamashita · 5 authors

Vulnerabilities in Ethereum smart contracts often cause significant financial damage. Whereas the Solidity compiler has been updated to mitigate vulnerabilities, the effectiveness of these updates remains undisclosed to the best of our knowledge. In this paper, we aim to shed light on the impact of compiler versions on reducing vulnerabilities in Ethereum smart contracts. To achieve this, we collected 497,344 contracts with Solidity source codes from the Ethereum blockchain and analyzed their vulnerabilities. For three vulnerabilities of high severity, i.e., Locked Money , Using tx.origin , and Unchecked Call , we illustrate their appearance rate changes, showing decreases attributed to major updates of the Solidity compiler. Subsequently, we found the following four key insights. Firstly, updates to version 0.6 and version 0.8 led to decreased appearance rates for Locked Money . Secondly, regardless of compiler updates, the appearance rate for Using tx.origin was significantly low. Thirdly, the appearance rate for Unchecked Call significantly decreased from version 0.5 to version 0.8. Lastly, as an incidental discovery from our empirical study, we identified implications for code clones, which merit attention from subsequent researchers and developers.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
FinTech, Crowdfunding, Digital Finance
Original source
Aug 11, 2024·International Journal For Multidisciplinary Research
0 cites
Automated Medical Record Authentication and Verification with Blockchain Technology: A Study

K P - BINDUSHREE, C. Rashmi, C P - SHANTHALA

A health record is a crucial component of patient follow-up, encompassing healthcare professionals' observations, prescriptions, diagnoses, and all relevant data about the patient. Multiple stakeholders—including the patient, doctor, and pharmacist—are involved in the management and sharing of this record. Electronic Medical Records (EMRs) can be accessed by authorized individuals from anywhere, facilitating the sharing of information among various healthcare providers. However, this sharing process requires strict security and confidentiality measures. Current medical systems face challenges such as potential system failures and malicious attacks, which can undermine service reliability. Additionally, managing centralized access control can be difficult. This paper introduces SEMRAchain, a system integrating role-based access control (RBAC), attribute-based access control (ABAC), and smart contracts. This combination enables decentralized, fine-grained, and dynamic access management for EMR systems. By leveraging blockchain technology as a secure distributed ledger, SEMRAchain offers stakeholders not only visibility but also trustworthiness, credibility, and immutability.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Aug 8, 2024·CLEI electronic journal
1 cites
A Formal Analysis of the Mimblewimble Cryptocurrency Protocol with a Security Approach

Adrián Silveira, Gustavo Betarte, Carlos Luna

A cryptocurrency is a digital currency that enables online transactions for various products and services. Cryptocurrencies are deployed over public blockchains which have the transactions duplicated and dispersed across multiple nodes within a computer network. This decentralized mechanism is devised in order to achieve reliability in a network consisting of unreliable nodes. Privacy, anonymity and security have become crucial in this context. For that reason, formal and mathematical approaches are gaining popularity in order to guarantee the correctness of the cryptocurrency implementations. Mimblewimble is a privacy-oriented cryptocurrency technology which provides security and scalability properties that distinguish it from other protocols of its kind. Mimblewimble combines confidential transactions, CoinJoin and cut-through to achieve a higher level of privacy and security, as well as, scalability. In this work, we present and discuss these security properties and outline the basis of a model-driven verification approach to address the certification of the correctness of the protocol implementations. In particular, we propose an idealized model that is key in the described verification process. Then, we identify and precisely state the conditions for our model to ensure the verification of relevant security properties of Mimblewimble. In addition, we analyze the Grin and Beam implementations of Mimblewimble in their current state of development. We present detailed connections between our model and their implementations regarding the Mimblewimble structure and its security properties. Finally, we analyze the Litecoin soft-fork that enhances privacy over the blockchain based on Mimblewimble features.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Aug 8, 2024·Applied Sciences
11 cites
A Security-Oriented Data-Sharing Scheme Based on Blockchain

Wei Ma, Xibei Wei, Longlong Wang

Data sharing serves to maximize the efficiency of data resources by facilitating their full utilization and reducing associated costs. However, existing data-sharing schemes are confronted with issues such as data loss, data tampering, difficulties in privacy protection, and high sharing costs. To address these issues, this paper proposes a blockchain-based security-oriented data-sharing scheme. Firstly, an architecture that separates data from data ownership is employed to enhance the security of the scheme and reduce storage overhead. Secondly, a lightweight on-chain and off-chain collaborative data security algorithm based on ECC and ECDHE is designed to ensure confidentiality during data sharing. Finally, a mechanism for tracking the circulation of shared data is proposed, which records the data flow in non-fungible tokens (NFTs), thereby improving the traceability of the proposed scheme. We designed relevant experiments to evaluate the proposed solution, and the results demonstrate that the data-sharing scheme devised in this paper performs well in terms of both security and usability, effectively achieving secure data sharing.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
Aug 6, 2024·Future Generation Computer Systems
25 cites
Decentralised Identity Management solution for zero-trust multi-domain Computing Continuum frameworks

José Manuel Bernabé Murcia, Eduardo Cánovas, Jesús García-Rodríguez, Alejandro Molina Zarca · 5 authors

The adoption of the Computing Continuum is characterised by the seamless integration of diverse computing environments and devices. In this dynamic landscape, sharing resources across the continuum is becoming a reality and security must move an step forward, specially in terms of authentication and authorisation for such a distributed and heterogeneous environments. The need for robust identity management is paramount and, in this regard, Decentralised Identity Management (DIM) emerges as a promising solution. It leverages decentralised technologies to secure and facilitate identity interactions across the Computing Continuum. Particularly, to enhance security and privacy, it would be desirable to apply the principles of Self-Sovereign Identity (SSI). In this paradigm, users have full ownership and control of their digital identities that empowers individuals to manage and share their identity data on a need-to-know basis. These mechanisms could contribute to improve security properties during continuum resource management operations. In this context, this paper presents the design, workflows and implementation of a solution that provides authentication/authorisation features to distributed zero-trust based infrastructures across the continuum, enhancing security in resource sharing and resource acquisition stages. To this aim, the solution relies on key aspects like decentralisation, interoperability, trust management and privacy-enhancing capabilities. The decentralisation leverages distributed ledger technologies, such as blockchain, to establish a decentralised identity ecosystem. The solution prioritises interoperability, enabling nodes to seamlessly access and share their identities across different domains and environments. Trustworthiness is at the core of DIM, and privacy is also considered, incorporating privacy-preserving techniques that individuals to selectively disclose identity attributes while safeguarding sensitive information. The implementation includes different operations for allowing continuum frameworks to be enhanced with decentralised authentication and authorisation features. The performance has been evaluated measuring the impact for the adoption of the solution. The most expensive task, the self-identity generation, takes only a few seconds (in our deployment) and it is only executed once. Authorisation tasks operate in the millisecond range, which is a totally invaluable time if incorporated into resource acquisition processes in frameworks such as Liqo, used in the scope of FLUIDOS project.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Aug 1, 2024·Heliyon
34 cites
Blockchain-enabled EHR access auditing: Enhancing healthcare data security

Faheem Ullah, Jingsha He, Nafei Zhu, Ahsan Wajahat · 8 authors

In the realm of modern healthcare, Electronic Health Records EHR serve as invaluable assets, yet they also pose significant security challenges. The absence of EHR access auditing mechanisms, which includes the EHR audit trails, results in accountability gaps and magnifies security vulnerabilities. This situation effectively paves the way for unauthorized data alterations to occur without detection or consequences. Inadequate EHR compliance auditing procedures, particularly in verifying and validating access control policies, expose healthcare organizations to risks such as data breaches, and unauthorized data usage. These vulnerabilities result from unchecked unauthorized access activities. Additionally, the absence of EHR audit logs complicates investigations, weakens proactive security measures, and raises concerns to put healthcare institutions at risk. This study addresses the pressing need for robust EHR auditing systems designed to scrutinize access to EHR data, encompassing who accesses it, when, and for what purpose. Our research delves into the complex field of EHR auditing, which includes establishing an immutable audit trail to enhance data security through blockchain technology. We also integrate Purpose-Based Access Control (PBAC) alongside smart contracts to strengthen compliance auditing by validating access legitimacy and reducing unauthorized entries. Our contributions encompass the creation of audit trail of EHR access, compliance auditing via PBAC policy verification, the generation of audit logs, and the derivation of data-driven insights, fortifying EHR access security.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Big Data and Digital Economy
Original source
Jul 31, 2024·Cryptography
3 cites
A Novel Method of Secured Data Distribution Using Sharding Zkp and Zero Trust Architecture in Blockchain Multi Cloud Environment

Komala Rangappa, Arun Kumar Banavara Ramaswamy, Mahadeshwara Prasad, Shreyas Arun Kumar

In the era of cloud computing, guaranteeing the safety and effectiveness of data management is of utmost importance. This investigation presents a novel approach that amalgamates the sharding concept, encryption, zero-knowledge proofs (zkp), and blockchain technology for secure data retrieval and data access control to improve data security, efficiency in cloud storage and migration. Further, we utilize user-specific digital wallets for secure encryption keys in order to encrypt the file before storing into the cloud. As Large files (greater than 50 MB) or Big data files (greater than 1 TB) require greater computational complexity, we leverage the sharding concept to enhance both space and time complexity in cloud storage. Hence, the large files are divided into shards and stored in different database servers. We also employ a blockchain smart contract to enhance secure retrieval of the file and also a secure access method, which ensures the privacy of the user. The zk-snark protocol is utilized to ensure the safe transfer of data between different cloud services. By utilizing this approach, data privacy is preserved, as only the proof of the data’s authenticity is shared with the verifier at the destination cloud, rather than the actual data themselves. The suggested method tackles important concerns related to data protection, privacy, and efficient resource utilization in cloud computing settings by ensuring it meets all the cloud policies required to store data. Since the environment maintains the privacy of the user data and the raw data of the user is not stored anywhere, the entire environment is set up as a Zero trust model.

Open access
2 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jul 31, 2024·Electronics
1 cites
Secure Processing and Distribution of Data Managed on Private InterPlanetary File System Using Zero-Knowledge Proofs

Kyohei Shibano, Kensuke Ito, Changhee Han, Tsz Tat Chu · 6 authors

In this study, a new data-sharing method is proposed that uses a private InterPlanetary File System—a decentralized storage system operated within a closed network—to distribute data to external entities while making its authenticity verifiable. Among the two operational modes of IPFS, public and private, this study focuses on the method for using private IPFS. Private IPFS is not open to the general public; although it poses a risk of data tampering when distributing data to external parties, the proposed method ensures the authenticity of the received data. In particular, this method applies a type of zero-knowledge proof, namely, the Groth16 protocol of zk-SNARKs, to ensure that the data corresponds to the content identifier in a private IPFS. Moreover, the recipient’s name is embedded into the distributed data to prevent unauthorized secondary distribution. Experiments confirmed the effectiveness of the proposed method for an image data size of up to 120 × 120 pixels. In future studies, the proposed method will be applied to larger and more diverse data types.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Advanced Data Storage Technologies
Original source
Jul 26, 2024·ACM SIGKDD Explorations Newsletter
13 cites
Blockchain for Large Language Model Security and Safety: A Holistic Survey

Caleb Geren, Amanda Board, Gaby G. Dagher, Tim Andersen · 5 authors

With the growing development and deployment of large language models (LLMs) in both industrial and academic fields, their security and safety concerns have become increasingly critical. However, recent studies indicate that LLMs face numerous vulnerabilities, including data poisoning, prompt injections, and unauthorized data exposure, which conventional methods have struggled to address fully. In parallel, blockchain technology, known for its data immutability and decentralized structure, offers a promising foundation for safeguarding LLMs. In this survey, we aim to comprehensively assess how to leverage blockchain technology to enhance LLMs' security and safety. Besides, we propose a new taxonomy of blockchain for large language models (BC4LLMs) to systematically categorize related works in this emerging field. Our analysis includes novel frameworks and definitions to delineate security and safety in the context of BC4LLMs, highlighting potential research directions and challenges at this intersection. Through this study, we aim to stimulate targeted advancements in blockchain-integrated LLM security.

Open access
2 source records
cs.CR
cs.AI
cs.DC
Original source
Jul 26, 2024·Computer Communications
23 cites
Tethering Layer 2 solutions to the blockchain: A survey on proving schemes

Domenico Tortola, Andrea Lisi, Paolo Mori, Laura Ricci

A blockchain is a data structure consisting of a list of blocks containing transactions and maintained by a network of nodes in a decentralized manner. In permissionless blockchains, anyone can contribute to the decentralization and security of the transactions. With the advent of smart contracts, programs whose execution is replicated by all the nodes of the network, the blockchain can be deemed not only a reliable and auditable data repository, but also a secure and verifiable computational infrastructure. However, due to the aforementioned features, the throughput of most permissionless blockchains is low, and executing a smart contract can be expensive, depending on its computational complexity. To mitigate these issues, a popular research line studies the implementation of Layer 2 solutions, which consists of nodes that operate off-chain yet remaining tethered to the blockchain. Our literature analysis revealed that a majority of the research articles surveying Layer 2 technologies and solutions typically classify them on the basis of the Layer 2 operations they perform, as well as their ability to improve the processing capacity of the blockchain. In this paper, instead, we survey the methodologies that provide a secure binding between Layer 2 and the blockchain. We refer to these binding techniques as “proving schemes” which we classify as: data integrity proofs, validity proofs, and fraud proofs. For each proving scheme, we describe its intended purpose, the advantages it offers, the methodologies commonly used to connect the operations performed at Layer 2 with the blockchain, and the applications that benefit from such scheme. Finally, we discuss and compare them to give a general comprehension about how schemes can satisfy general requirements common to most Decentralized Applications.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jul 25, 2024·ACM Transactions on Architecture and Code Optimization
1 cites
Data Deduplication Based on Content Locality of Transactions to Enhance Blockchain Scalability

Cheng-Long Yi, Jintong Liu, Shenggang Wan, Juntao Fang · 6 authors

Blockchain is a promising infrastructure for the internet and digital economy, but it has serious scalability problems, that is, long block synchronization time and high storage cost. Conventional coarse-grained data deduplication schemes (block or file level) are proved to be ineffective on improving the scalability of blockchains. Based on comprehensive analysis on typical blockchain workloads, we propose two new locality concepts (economic and argument locality) and a novel fine-grained data deduplication scheme (transaction level) named Alias-Chain. Specifically, Alias-Chain replaces frequently used data, for example, smart contract arguments, with much shorter aliases to reduce the block sizes, which results in both shorter synchronization time and lower storage cost. Furthermore, to solve the potential consistency issue in Alias-Chain, we propose two complementary techniques: one is generating aliases from history blocks with high consistency, and the other is speeding up the generation of aliases via a specific algorithm. Our simulation results show: (1) the average transfer and SC-call transaction (a transaction used to call the smart contracts in the blockchain) sizes can be significantly reduced by up to 11.03% and 79.44% in native Ethereum, and up to 39.29% and 81.84% in Ethereum optimized by state-of-the-art techniques; and (2) the two complementary techniques well address the inconsistency risk with very limited impact on the benefit of Alias-Chain. Prototyping-based experiments are further conducted on a testbed consisting of up to 3200 miners. The results demonstrate the effectiveness and efficiency of Alias-Chain on reducing block synchronization time and storage cost under typical real-world workloads.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
Jul 24, 2024·International Journal of e-Collaboration
1 cites
Research on ZKP Algorithm of Data Asset Security and Privacy Protection Based on Blockchain Technology

Fei Lan, Junjia Yang, Hao Feng, Wendi Xu · 7 authors

Zero Knowledge Proof (ZKP) is a very effective method of preserving privacy as it hides the most confidential information throughout the transaction. In this paper, we present a security and privacy-preserving approach for blockchain that relies on account and multi-data asset models using the Zero Knowledge Proof (ZKP) mechanism. We provide options for transferring data assets and detecting duplicate expenditures, and we also develop transaction structures, anonymised addresses and anonymised metadata for the data assets. To create and validate the ZKP, we use the zk-SNARKs algorithm and specify validation criteria for masked transactions, and finally conduct experimental tests to validate it. Creating better algorithms for ZKP will be the focus of our future efforts.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
Jul 20, 2024·Blockchain Research and Applications
2 cites
nPPoS: Non-interactive practical proof-of-storage for blockchain

Jun Wook Heo, Gowri Ramachandran, Raja Jurdak

Blockchain full nodes are pivotal for transaction availability, as they store the entire ledger, but verifying their storage integrity faces challenges from malicious remote storage attacks such as Sybil, outsourcing, and generation attacks. However, there is no suitable proof-of-storage solution for blockchain full nodes to ensure a healthy number of replicas of the ledger. Existing proof-of-storage solutions are designed for general-purpose settings where a data owner uses secret information to verify storage, rendering them unsuitable for blockchain where proof-of-storage must be fast, publicly verifiable, and data owner-agnostic. This paper introduces a decentralised and quantum-resistant solution named Non-interactive Practical Proof of Storage (nPPoS) with an asymmetric encoding and decoding scheme, for fast and secure PoStorage, and Zero-Knowledge Scalable Transparent Arguments of Knowledge (zk-STARKs), for public variability in blockchain full nodes. The algorithm with asymmetric times for encoding and decoding creates unique block replicas and corresponding proofs for each storage node to mitigate malicious remote attacks and minimise performance degradation. The intentional resource-intensive encoding deters attacks, while faster decoding minimises performance overhead. Through zk-STARKs, nPPoS achieves public verifiability enabling one-to-many verification for scalability, quantum resistance and decentralisation. It also introduces a two-phase randomisation technique and a time-weighted trustworthiness measurement for scalability and adaptability.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jul 17, 2024·arXiv (Cornell University)
0 cites
LSKV: A Confidential Distributed Datastore to Protect Critical Data in the Cloud

Andrew Jeffery, Julien Maffre, Heidi Howard, Richard Mortier

Software services are increasingly migrating to the cloud, requiring trust in actors with direct access to the hardware, software and data comprising the service. A distributed datastore storing critical data sits at the core of many services; a prime example being etcd in Kubernetes. Trusted execution environments can secure this data from cloud providers during execution, but it is complex to build trustworthy data storage systems using such mechanisms. We present the design and evaluation of the Ledger-backed Secure Key-Value datastore (LSKV), a distributed datastore that provides an etcd-like API but can use trusted execution mechanisms to keep cloud providers outside the trust boundary. LSKV provides a path to transition traditional systems towards confidential execution, provides competitive performance compared to etcd, and helps clients to gain trust in intermediary services. LSKV forms a foundational core, lowering the barriers to building more trustworthy systems.

Open access
Cloud Data Security Solutions
Network Security and Intrusion Detection
Privacy-Preserving Technologies in Data
Original source
Jul 9, 2024·arXiv (Cornell University)
21 cites
Towards a Novel Privacy-Preserving Distributed Multiparty Data Outsourcing Scheme for Cloud Computing with Quantum Key Distribution

D. Dhinakaran, D. Selvaraj, N. Dharini, S. Edwin Raja · 5 authors

The intersection of cloud computing, blockchain technology, and the impending era of quantum computing presents a critical juncture for data security. This research addresses the escalating vulnerabilities by proposing a comprehensive framework that integrates Quantum Key Distribution (QKD), CRYSTALS Kyber, and Zero-Knowledge Proofs (ZKPs) for securing data in cloud-based blockchain systems. The primary objective is to fortify data against quantum threats through the implementation of QKD, a quantum-safe cryptographic protocol. We leverage the lattice-based cryptographic mechanism, CRYSTALS Kyber, known for its resilience against quantum attacks. Additionally, ZKPs are introduced to enhance data privacy and verification processes within the cloud and blockchain environment. A significant focus of this research is the performance evaluation of the proposed framework. Rigorous analyses encompass encryption and decryption processes, quantum key generation rates, and overall system efficiency. Practical implications are scrutinized, considering factors such as file size, response time, and computational overhead. The evaluation sheds light on the framework's viability in real-world cloud environments, emphasizing its efficiency in mitigating quantum threats. The findings contribute a robust quantum-safe and ZKP-integrated security framework tailored for cloud-based blockchain storage. By addressing critical gaps in theoretical advancements, this research offers practical insights for organizations seeking to secure their data against quantum threats. The framework's efficiency and scalability underscore its practical feasibility, serving as a guide for implementing enhanced data security in the evolving landscape of quantum computing and blockchain integration within cloud environments.

Open access
2 source records
cs.CR
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jul 5, 2024·Computer Networks and Communications
1 cites
DeAuth: A Decentralized Authentication and Authorization Scheme for Secure Private Data Sharing

Phillipe Austria, Yoohwan Kim, Ju-Yeon Jo

The sharing of private information is a daunting, multifaceted, and expensive undertaking. Furthermore, identity management is an additional challenge that poses significant technological, operational, and legal obstacles. Present solutions and their accompanying infrastructures rely on centralized models that are susceptible to hacking and can hinder data control by the rightful owner. Consequently, blockchain technology has generated interest in the fields of identity and access control. This technology is viewed as a potential solution due to its ability to offer decentralization, transparency, provenance, security, and privacy benefits. Nevertheless, a completely decentralized and private solution that enables data owners to control their private data has yet to be presented. In this research, we introduce DeAuth, a novel decentralized, authentication and authorization scheme for secure private data transfer. DeAuth combines blockchain, smart-contracts, decentralized identity, and distributed peer-to-peer (P2P) storage to give users more control of their private data, and permissioning power to share without centralized services. For this scheme, identity is proven using decentralized identifiers and verifiable credentials, while authorization to share data is performed using the blockchain. A prototype was developed using the Ethereum Blockchain and the InterPlanetary Files System, a P2P file sharing protocol. We evaluated DeAuth through a use-case study and metrics such as security, performance, and cost. Our findings indicate DeAuth to be viable alternative to using centralized services; however, the underlying technologies are still in its infancies and require more testing before it can supplant traditional services.

Open access
Cryptography and Data Security
Access Control and Trust
Cloud Data Security Solutions
Original source