Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

449 papersLast indexed Aug 31, 2026
Search papers

Paper index

449 results · page 15 of 19

Clear filters
Jul 16, 2020·International Journal of Innovative Technology and Exploring Engineering
0 cites
Zero-Knowledge Proof Based Authentication Over Untrusted Networks

Cherukupalli Veda Vyasa Aditya, Rajesh Kannan Megalingam

Zero knowledge proof is a powerful cryptographic protocol that is utilized to establish data security whilst ensuring and maintaining user anonymity. ZKP has relatively less complex computational requirements as compared to the other protocols for authentication. Conventional authentication schemes are susceptible to attacks such as MiTM, IP spoofing, DoS, replay and other eavesdropping based attacks, when the data is shared across an untrusted network. This paper shows an approach to ensure authentication of a device over an untrusted network whilst maintaining and safeguarding user credentials, by using the concepts of ZKP protocol.

Open access
Advanced Authentication Protocols Security
Internet Traffic Analysis and Secure E-voting
User Authentication and Security Systems
Original source
Jun 8, 2020·International Journal of Computer Network and Information Security
13 cites
Privacy Protection in Smart Cities by a Personal Data Management Protocol in Blockchain

Hossein Mohammadinejad, Fateme Mohammadhoseini

Due to the increase of cybercrime and security risks in computer networks as well as violations of user privacy, it is essential to upgrade the existing protection models and provide practical solutions to meet these challenges. An example of these risks is the presence of a third party between users and various services, which leads to the collection and control of large amounts of users' personal information and the possibility of their databases being misused or hacked. Blockchain technology and encrypted currencies have so far shown that a decentralized network of peer-to-peer users, along with a general ledger, can do reliable computing. So, in this article, we are going to introduce a protocol that converts the blockchain network to an automated access control manager without the presence of a third party. To this end, we designed a mutual authentication protocol to create a secure channel between the user and the service and then demonstrate its accuracy and completeness using the Gong-Nidham-Yahalom belief logic The results of our evaluations show that our proposed protocol is secure enough to be used on the blockchain network and attackers are unable to penetrate, track, impersonate, inject, misrepresent or distort information using the common attacks.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Privacy, Security, and Data Protection
Original source
Jun 4, 2020·Symmetry
48 cites
Securing Fingerprint Template Using Blockchain and Distributed Storage System

Moses Arhinful Acquah, Na Chen, Jeng‐Shyang Pan, Hong-Mei Yang · 5 authors

Biometrics, with its uniqueness to every individual, has been adapted as a security authentication feature by many institutions. These biometric data are processed into templates that are saved on databases, and a central authority centralizes and controls these databases. This form of storing biometric data, or in our case fingerprint template, is asymmetric and prone to three main security attacks, such as fake template input, template modification or deletion, and channel interception by a malicious attacker. In this paper, we secure an encrypted fingerprint template by a symmetric peer-to-peer network and symmetric encryption. The fingerprint is encrypted by the symmetric key algorithm: Advanced Encryption Standard (AES) algorithm and then is uploaded to a symmetrically distributed storage system, the InterPlanetary File system (IPFS). The hash of the templated is stored in a decentralized blockchain. The slow transaction speed of the blockchain has limited its use in real-life applications, such as large file storage, hence, the merge with IPFS to store just the hashes of large files. The encrypted template is uploaded to the IPFS, and its returned digest is stored on the Ethereum network. The implementation of IPFS prevents storing the raw state of the fingerprint template on the Ethereum network in order to reduce cost and also prevent identity theft. This procedure is an improvement of previous systems. By adopting the method of template hashing, the proposed system is cost-effective and efficient. The experimental results depict that the proposed system secures the fingerprint template by encryption, hashing, and decentralization.

Open access
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
User Authentication and Security Systems
Original source
Jun 3, 2020·Register Jurnal Ilmiah Teknologi Sistem Informasi
26 cites
Two factor authentication framework based on ethereum blockchain with dApp as token generation system instead of third-party on web application

Marsha Chikita Intania Putri, Parman Sukarno, Aulia Arif Wardana

Authentication is a method for securing an account by verifying the user identity by inputting email with a password. Two factor authentications is an authentication system that combines the first-factor authentication with the second factor. General two factor authentication by entering an email or username with a password are similar. However, two factor authentication requires additional information that must be inputted by the user. Additional information can be in the form of tokens or one-time passwords (OTP). Two factor authentications generally still uses third-party services to generate token or OTP still have vulnerable because can attacked from tokens steal through MITM and found that the generated tokens with the same value. Therefore, we propose a two-factor authentication framework based on ethereum blockchain with dApp as token generation system. Firstly, outcome from the analysis of the system, next succeeded in creating a two-factor authentication system without using third-parties. Second, token system generate up to 3164 different tokens in one second and has been collisions tested. Third, security method to protect token from MITM attack. The attacker unable to get access caused all the checking are done by dApp user authentication.

Open access
User Authentication and Security Systems
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
May 21, 2020·Sensors
101 cites
Design of Secure Protocol for Cloud-Assisted Electronic Health Record System Using Blockchain

Myeonghyun Kim, Sungjin Yu, Joonyoung Lee, Yohan Park · 5 authors

In the traditional electronic health record (EHR) management system, each medical service center manages their own health records, respectively, which are difficult to share on the different medical platforms. Recently, blockchain technology is one of the popular alternatives to enable medical service centers based on different platforms to share EHRs. However, it is hard to store whole EHR data in blockchain because of the size and the price of blockchain. To resolve this problem, cloud computing is considered as a promising solution. Cloud computing offers advantageous properties such as storage availability and scalability. Unfortunately, the EHR system with cloud computing can be vulnerable to various attacks because the sensitive data is sent over a public channel. We propose the secure protocol for cloud-assisted EHR system using blockchain. In the proposed scheme, blockchain technology is used to provide data integrity and access control using log transactions and the cloud server stores and manages the patient's EHRs to provide secure storage resources. We use an elliptic curve cryptosystems (ECC) to provide secure health data sharing with cloud computing. We demonstrate that the proposed EHR system can prevent various attacks by using informal security analysis and automated validation of internet security protocols and applications (AVISPA) simulation. Furthermore, we prove that the proposed EHR system provides secure mutual authentication using BAN logic analysis. We then compare the computation overhead, communication overhead, and security properties with existing schemes. Consequently, the proposed EHR system is suitable for the practical healthcare system considering security and efficiency.

Open access
Cloud Data Security Solutions
Advanced Authentication Protocols Security
User Authentication and Security Systems
Original source
Apr 16, 2020·IET Biometrics
43 cites
BMIAE: blockchain‐based multi‐instance Iris authentication using additive ElGamal homomorphic encryption

Morampudi Mahesh Kumar, Munaga V. N. K. Prasad, U. S. N. Raju

Multi‐biometric systems have been widely accepted in various applications due to its capability to solve the limitations of unimodal systems. Directly storing the biometric templates into a centralised server leads to privacy concerns. In the past few years, many biometric authentication systems based on homomorphic encryption have been introduced to provide security for the templates. Most of the existing solutions rely on an implication of the assumption that the server is ‘honest‐but‐curious’. Therefore, the compromise of server results into the entire system vulnerability and fails to provide the integrity. To address this, we propose a novel multi‐instance iris authentication system, BMIAE to deal with malicious attacks over the transmission channel and at the untrusted server. BMIAE encrypt the iris templates using ElGamal encryption to guarantee confidentiality and Smart contract running on a Blockchain helps to achieve the integrity of templates and matching result. BMIAE also addresses the limitations of using Blockchain for biometrics like privacy and expensive storage. To check the effectiveness and robustness, BMIAE has experimented on CASIA‐V3‐Interval, IITD and SDUMLA‐HMT iris databases. Experimental results show that BMIAE provides improved accuracy, and eliminates the need to trust the centralised server when compared to the state‐of‐the‐art approaches.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Original source
Apr 3, 2020·Sensors
42 cites
Securing MQTT by Blockchain-Based OTP Authentication

Francesco Buccafurri, Vincenzo De Angelis, Roberto Nardone

The Internet of Things is constantly capturing interest from modern applications, changing our everyday life and empowering industrial applications. Interaction and the collaboration among smart devices offer new challenges to security since they conflict with economic and energy consumption requirement constraints. On the other hand, the lack of security measures could negatively impact the concrete adoption of this paradigm. This paper focuses on the Message Queuing Telemetry Transport (MQTT) protocol, widely adopted in the Internet of Things. This protocol does not implement natively secure authentication mechanisms, which are demanded to developers. Hence, this paper proposes a novel OTP (one-time password)-authentication schema for MQTT, which uses the Ethereum blockchain to implement a second-factor out-of-band channel. The proposal enables the authentication of both local and remote devices preserving user privacy and guaranteeing trust and accountability via Ethereum smart contracts.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Mar 31, 2020·KSII Transactions on Internet and Information Systems
4 cites
Private Key Recovery on Bitcoin with Duplicated Signatures

Ju-Seong Ko, Jin Kwak

In the modern financial sector, interest in providing financial services that employ blockchain technology has increased. Blockchain technology is efficient and can operate without a trusted party to store all transaction information; additionally, it provides transparency and prevents the tampering of transaction information. However, new security threats can occur because blockchain technology shares all the transaction information. Furthermore, studies have reported that the private keys of users who use the same signature value two or more times can be recovered. Because private keys of blockchain identify users, private key leaks can result in attackers stealing the ownership rights to users' property. Therefore, as more financial services use blockchain technology, actions to counteract the threat of private key recovery must be continually investigated. Private key recovery studies are presented here. Based on these studies, duplicated signatures generated by blockchain users are defined. Additionally, scenarios that generate and use duplicated signatures are applied in an actual bitcoin environment to demonstrate that actual bitcoin users' private keys can be recovered.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Mar 30, 2020·International Journal of Recent Technology and Engineering (IJRTE)
0 cites
A Zero-Proof Knowledge Based on NFC for Data Authentication/Protection using Blockchain for Mobile Edge Computing

Hanumantharaju R, K. N. Shreenath, K. G. Srinivasa, Swetha Namburu

Mobile edge computing is a recent trend to complement the Internet of Things (IoT) ecosystem in the computing sector. IoT is the internet connected communications related to physical devices and everyday objects. The emergence of intelligent living spaces has been due to the rapid development of IoT technologies. Blockchain is one such technology that expands the list of information also referred to like records that are saved as blocks in the Blockchain which are connected using cryptographic algorithms. Within a Blockchain IoT environment, when data or device authentication information is stored in a Blockchain, authentication information can be displayed when verifying Block chain’s transactions, which are also referred to as proof of work. A principle of Zero-knowledge proof (ZKF) is implemented in this paper which is a way of proving that knowledge is known without exposing any data to the user. The proposed model uses a Mobile application where users can prove without revealing users' passwords. Blockchain stores client information that can prevent data from being manipulated. The results of applying the ZKF theory for data security are shown through a web application and NFC.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
IoT and Edge/Fog Computing
Original source
Mar 19, 2020·arXiv (Cornell University)
11 cites
Blockchain meets Biometrics: Concepts, Application to Template Protection, and Trends

Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez

Blockchain technologies provide excellent architectures and practical tools for securing and managing the sensitive and private data stored in biometric templates, but at a cost. We discuss opportunities and challenges in the integration of blockchain and biometrics, with emphasis in biometric template storage and protection, a key problem in biometrics still largely unsolved. Key tradeoffs involved in that integration, namely, latency, processing time, economic cost, and biometric performance are experimentally studied through the implementation of a smart contract on the Ethereum blockchain platform, which is publicly available in github for research purposes.

Open access
2 source records
cs.CV
cs.CR
Blockchain Technology Applications and Security
Original source
Mar 1, 2020·2020 IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops)
20 cites
Trustworthy, Secure, and Privacy-aware Food Monitoring Enabled by Blockchains and the IoT

Christoph Stach, Clémentine Gritti, Dennis Przytarski, Bernhard Mitschang

A large number of food scandals (e. g., falsely declared meat or non-compliance with hygiene regulations) are causing considerable concern to consumers. Although Internet of Things (IoT) technologies are used in the food industry to monitor production (e. g., for tracing the origin of meat or monitoring cold chains), the gathered data are not used to provide full transparency to the consumer. To achieve this, however, three aspects must be considered: a) The origin of the data must be verifiable, i. e., it must be ensured that the data originate from calibrated sensors. b) The data must be stored tamper-resistant, immutable, and open to all consumers. c) Despite this openness, the privacy of affected data subjects (e. g., the carriers) must still be protected. To this end, we introduce the SHEEPDOG architecture that “shepherds” products from production to purchase to enable a trustworthy, secure, and privacy-aware food monitoring. In SHEEPDOG, attribute-based credentials ensure trustworthy data acquisition, blockchain technologies provide secure data storage, and fine-grained access control enables privacy-aware data provision.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Food Supply Chain Traceability
Original source
Jan 11, 2020·Future Internet
50 cites
An Architecture for Biometric Electronic Identification Document System Based on Blockchain †

Rafael Páez, Manuel Pérez, Gustavo Ramirez Espinosa, Juan Montes · 5 authors

This paper proposes an architecture for biometric electronic identification document (e-ID) system based on Blockchain for citizens identity verification in transactions corresponding to the notary, registration, tax declaration and payment, basic health services and registration of economic activities, among others. To validate the user authentication, a biometric e-ID system is used to avoid spoofing and related attacks. Also, to validate the document a digital certificate is used with the corresponding public and private key for each citizen by using a user’s PIN. The proposed transaction validation process was implemented on a Blockchain system in order to record and verify the transactions made by all citizens registered in the electoral census, which guarantees security, integrity, scalability, traceability, and no-ambiguity. Additionally, a Blockchain network architecture is presented in a distributed and decentralized way including all the nodes of the network, database and government entities such as national register and notary offices. The results of the application of a new consensus algorithm to our Blockchain network are also presented showing mining time, memory and CPU usage when the number of transactions scales up.

Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
User Authentication and Security Systems
Original source
Jan 1, 2020·Procedia Computer Science
16 cites
Protect Your Pacemaker: Blockchain based Authentication and Consented Authorization for Implanted Medical Devices

Allison Gibson, Geethapriya Thamilarasu

Existing implanted medical devices often do not use any form of authentication due to resource constraints, resulting in unauthorized access or programming of devices. In this paper, we introduce Medical Implant Consent (MedIC), a non-embedded, blockchain-based solution that provides authentication and authorization according to patient consent. We design protocols for doctors to obtain digital medical licenses and for patients to obtain and verify digital patient consent. We evaluate the performance and cost of our solution, using time measurements and memory footprint of relevant operations. We also enumerate our cryptographic operations and compute the energy with benchmarked measurements. Our results demonstrate a memory footprint of 4436 MB and timing delay of 200 ms to authenticate according to our patient’s consent.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
IoT and Edge/Fog Computing
Original source
Jan 1, 2020·Computers, materials & continua/Computers, materials & continua (Print)
19 cites
A Key Recovery System Based on Password-protected Secret Sharing in a Permissioned Blockchain

Gyeong-Jin Ra, Chang-Hyun Roh, Im-Yeong Lee

In today’s fourth industrial revolution, various blockchain technologies are being actively researched. A blockchain is a peer-to-peer data-sharing structure lacking central control. If a user wishes to access stored data, she/he must employ a private key to prove ownership of the data and create a transaction. If the private key is lost, blockchain data cannot be accessed. To solve such a problem, public blockchain users can recover the key using a wallet program. However, key recovery in a permissioned blockchain (PBC) has been but little studied. The PBC server is Honest-but-Curious (HBC), and should not be able to learn anything of the user; the server should simply recover and store the key. The server must also be resistant to malicious attacks. Therefore, key recovery in a PBC must satisfy various security requirements. Here, we present a password-protected secret sharing (PPSS) key recovery system, protected by a secure password from a malicious key storage server of a PBC. We describe existing key recovery schemes and our PPSS scheme.

Open access
User Authentication and Security Systems
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jan 1, 2020·Procedia Computer Science
23 cites
Feasibility of Identity Authentication for IoT Based on Blockchain

Zongqing Tian, Biwei Yan, Qiang Guo, Jianyun Huang · 5 authors

With the rapid development of the Internet of Things (IoT), more and more devices are connected to the Internet. As IoT devices are resource-constrained in terms of processing, storage and network capacity, it becomes a challenging task to ensure the access of IoT devices. Identity authentication is a key technology to prevent illegal users from access resources and permissions. Based on the principle of blockchain technology, combining blockchain technology with IoT, this paper proposes a blockchain system framework for IoT identity authentication, which implements the authentication between devices and cloud servers, IoT base stations as well as devices, and then analyzes its feasibility.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Malware Detection Techniques
Original source
Jan 1, 2020·Euroasia Journal of Mathematics Engineering Natural and Medical Sciences
3 cites
BLOCKCHAIN BASED DIGITAL IDENTITY MANAGEMENT

* *

Identity is a tool that identifies a person or group and ensures that they are recognized by others. Personalidentification cards issued by the states to people contain specific information about the person given.Identity systems used for centuries are now digitalized, ID cards with chips and passports with chipshave entered our lives. In the past, only information such as name, surname and place of birth wereincluded in ID cards with chips and passports. But today, in addition to our personal information, itincludes our biometric information such as fingerprints, iris, digital signatures. Blockchain technology,which has entered our lives with the financial sector, offers application areas in different sectors andsubjects. Some of these are IoT (internet of things), security and reliability systems, copyrights, publicand health sectors. In this study, it has been mentioned about the advantages and the features obtainedby using blockchain technology in identity management. The purpose of this study; It is to ensure thesafe use of identity information thanks to the features provided by the block chain such as distributeddatabase called DLT (distributed ledger technology), peer-to-peer transmission, transparency andirreversible records. Also in this study, a software that can simulate blockchain technology was createdand an Android application that reads data with NFC (Near Field Communication) technology wasdeveloped. Thus, the process of adding the data in the ID card or passport to the block chain by readingthe data from NFC with the Android application can be performed.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Internet Traffic Analysis and Secure E-voting
Original source
Jan 1, 2020·IEEE Access
41 cites
A Secure Framework for Data Sharing in Private Blockchain-Based WBANs

Lijun Xiao, Dezhi Han, Xiangwei Meng, Wei Liang · 5 authors

With the development of sensor devices, wireless sensor networks have been widely used, and Wireless Body Area Networks (WBANs) are relatively common application scenarios in wireless sensor networks. The wearable device is used to collect physiological data of the human body, and the server device is adopted to store physiological data of the human body. The openness of the network environment and network devices’ dynamic nature make WBANs vulnerable to security threats from attackers. The centralized two-hop architecture contains only one hub node, and the data stored in the hub node may be tampered with by attackers. Once attackers occupy the node, the entire network will be paralyzed. To tackle such an issue, it is proposed in this article a model in WBANs architecture based on Blockchain technology, where the authentication protocol and blind signature protocol between nodes are designed in the new WBANs model, making the Blockchain data transmission system in a wireless network environment secure and reliable. Experimental results show that the proposed method is promising and shows higher levels of safety and stability than other methods.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Jan 1, 2020·IEEE Access
76 cites
A Tutorial and Future Research for Building a Blockchain-Based Secure Communication Scheme for Internet of Intelligent Things

Mohammad Wazid, Ashok Kumar Das, Sachin Shetty, Minho Jo

The Internet of Intelligent Things (IoIT) communication environment can be utilized in various types of applications (for example, intelligent battlefields, smart healthcare systems, the industrial internet, home automation, and many more). Communications that happen in such environments can have different types of security and privacy issues, which can be resolved through the utilization of blockchain. In this paper, we propose a tutorial that aims in desiging a generalized blockchain-based secure authentication key management scheme for the IoIT environment. Moreover, some issues with using blockchain for a communication environment are discussed as future research directions. The details of different types of blockchain are also provided. Some of the widely-accepted consensus algorithms are then discussed. Next, we discuss different types of applications in blockchain-based IoIT communication environments. The details of the associated system models are provided, such as, the network and attack models for the blockchain-based IoIT communication environment, which are helpful in designing a security protocol for such an environment. A practical demonstration of the proposed generalized scheme is provided in order to measure the impact of the scheme on the performance of the essential parameters. Finally, some of the future research challenges in the blockchain-based IoIT communication environment are highlighted, which will also be helpful to the researchers.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Jan 1, 2020·Electronics
57 cites
Distributed Blockchain-Based Message Authentication Scheme for Connected Vehicles

Jaewon Noh, Sangil Jeon, Sunghyun Cho

Vehicular ad-hoc networks (VANETs) have several security issues such as privacy preservation, secure authentication, and system reliability. In the VANET, a vehicle communicates with other vehicles or infrastructures using broadcasting messages. These messages contain not only normal traffic information, but also identification information of sender. In general, the identification information remains encrypted to ensure privacy. However, the conventional centralized system can decrypt the identification information using private information of the sender vehicle. As a result, the central server can often be targeted by adversaries. We propose a message authentication scheme for anonymity and decentralization of information using blockchain technology. Here, we introduce public-private key and message authentication code (MAC) for secure authentication. In this paper, we adopt consensus algorithms for composing blockchain system such as the proof of work (PoW) and Practical Byzantine Fault Tolerance (PBFT) into the proposed authentication process. Finally, we demonstrate that the proposed method is secure from the attacks which include impersonation from internal attacker as well as typical attacks.

Open access
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
User Authentication and Security Systems
Original source
Jan 1, 2020·IEEE Access
72 cites
A Blockchain Based Data Aggregation and Group Authentication Scheme for Electronic Medical System

Chun‐Ta Li, Dong‐Her Shih, Chun-Cheng Wang, Chin‐Ling Chen · 5 authors

In recent years, due to the rapid development of information techniques and network technologies, more and more medical documents have been replaced by electronic files for sharing and transmitting in real time. However, medical data transmitted over public communication channels may suffer from security attacks and privacy threats. Blockchain technology has been gotten many attentions in different areas due to its unique properties such as anonymity, verifiability, immutability and decentralization. In order to secure patient privacy and provide more personal healthcare services, in this paper, we propose a data aggregation scheme based on Blockchain technology for medical environments. Moreover, in order to implement remote medical monitoring, we design a group authentication mechanism for multiple authorized users (such as patient, doctors, caregivers, family and friends) to freely access patient's personal health records. The authorized group members in a group will agree on a group session key and use it to protect patient's sensitive information. In case of a new member joins the medical group or an old member leaves the medical group, the group session key needs to be updated at any time. Finally, the electronic medical system will become more secure, reliable and useful by our proposed scheme.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Biometric Identification and Security
Original source
Jan 1, 2020·IEEE Access
50 cites
A Blockchain-Based Authentication and Key Agreement (AKA) Protocol for 5G Networks

Maede Hojjati, Alireza Shafieinejad, Halim Yanıkömeroğlu

Subscriber authentication is a primitive operation in mobile networks required by each operator prior to offering any service to end users. In this paper, we propose a novel blockchain-based Authentication and Key Agreement (AKA) protocol for roaming services in 5G networks. Each Home Network (HN) creates its own smart contract and publishes its address to inform other operators who want to offer roaming services to HN subscribers. All subsequent communication between the HN and Serving Network (SN) is done by calling the function of this smart contract. The proposed protocol eliminates the need for a secure channel between the HN and SN, which is a primary requirement of current 5G AKA protocols. In practice, a secure channel requires the HN and SN to establish a secure session before running the AKA protocol. Further, the proposed protocol leverages the benefits of blockchain, such as auditable log, decentralized architecture, and the prevention of Denial of Service (DoS) attacks. Furthermore, we provide a security proof of the protocol through formal verification using ProVerif. The results show that our scheme tends to preserve user privacy and at the same time provides mutual authentication of the participants. Finally, our evaluation of the Ethereum blockchain shows that the protocol is efficient in terms of both transaction and execution costs.

Open access
Advanced Authentication Protocols Security
Blockchain Technology Applications and Security
User Authentication and Security Systems
Original source
Jan 1, 2020·Future Internet
66 cites
Toward Blockchain-Enabled Supply Chain Anti-Counterfeiting and Traceability

Neo C. K. Yiu

Innovative solutions addressing product anti-counterfeiting and record provenance have been deployed across today's internationally spanning supply chain networks. These product anti-counterfeiting solutions are developed and implemented with centralized system architecture relying on centralized authorities or any form of intermediaries. Vulnerabilities of centralized product anti-counterfeiting solutions could possibly lead to system failure or susceptibility of malicious modifications performed on product records or various potential attacks to the system components by dishonest participant nodes traversing along the supply chain. Blockchain technology has progressed from merely with a use case of immutable ledger for cryptocurrency transactions to a programmable interactive environment of developing decentralized and reliable applications addressing different use cases globally. In this research, so as to facilitate trustworthy data provenance retrieval, verification and management, as well as strengthening capability of product anti-counterfeiting, key areas of decentralization and feasible mechanisms of developing decentralized and distributed product anti-counterfeiting and traceability ecosystems utilizing blockchain technology, are identified via a series of security and threat analyses performed mainly against NFC-Enabled Anti-Counterfeiting System (NAS) which is one of the solutions currently implemented in the industry with centralized architecture. A set of fundamental system requirements are set out for developing a blockchain-enabled autonomous and decentralized solution for supply chain anti-counterfeiting and traceability, as a secure and immutable scientific data provenance tracking and management platform in which provenance records, providing compelling properties on data integrity of luxurious goods, are recorded and verified automatically, for supply chain industry.

Open access
3 source records
Blockchain Technology Applications and Security
Food Supply Chain Traceability
Advanced Malware Detection Techniques
Original source
Jan 1, 2020·IEEE Access
94 cites
A Permissioned Blockchain-Based Identity Management and User Authentication Scheme for E-Health Systems

Xinyin Xiang, Mingyu Wang, Weiguo Fan

The growth of electronic healthcare (e-health) systems is promoted by the evolution of Internet of Things (IoT) technology, as this new environment provides a variety of alternatives for medical data collection. Traditional authentication models in e-health systems cannot be applied directly to scenarios requiring low-latency, real-time services. Providing a variety of means for data transmission is considered an important method to achieve effective control in e-health systems. However, this new approach also leads to security and privacy concerns as increasingly flexible communication services are introduced. Achieving effective authentication of medical data for different users while providing security guarantees in e-health systems is an interesting problem. In this paper, we present a permissioned blockchain-based identity management and user authentication (PBBIMUA) scheme for the e-health environment. Our scheme satisfies the extensive security requirements of medical data. An evaluation and security analysis show that performance, in terms of lightweight construction and lower network latency with high security standards, is improved in comparison to known methods. The experimental results show that the system has good efficiency.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Jan 1, 2020·IEEE Access
114 cites
Design of Secure Authentication Protocol for Cloud-Assisted Telecare Medical Information System Using Blockchain

Seunghwan Son, Joonyoung Lee, Myeonghyun Kim, Sungjin Yu · 6 authors

Telecare medical information system (TMIS) implemented in wireless body area network (WBAN) is convenient and time-saving for patients and doctors. TMIS is realized using wearable devices worn by a patient, and wearable devices generate patient health data and transmit them to a server through a public channel. Unfortunately, a malicious attacker can attempt performing various attacks through such a channel. Therefore, establishing a secure authentication process between a patient and a server is essential. Moreover, wearable devices have limited storage power. Cloud computing can be considered to resolve this problem by providing a storage service in the TMIS environment. In this environment, access control of the patient health data is essential for the quality of healthcare. Furthermore, the database of the cloud server is a major target for an attacker. The attacker can try to modify, forge, or delete the stored data. To resolve these problems, we propose a secure authentication protocol for a cloud-assisted TMIS with access control using blockchain. We employ ciphertext-policy attribute-based encryption (CP-ABE) to establish access control for health data stored in the cloud server, and apply blockchain to guarantee data integrity. To prove robustness of the proposed protocol, we conduct informal analysis and Burrows-Adabi-Needham (BAN) logic analysis, and we formally validate the proposed protocol using automated validation of internet security protocols and applications (AVISPA). Consequently, we show that the proposed protocol provides more security and has better efficiency compared to related protocols. Therefore, the proposed protocol is proper for a practical TMIS environment.

Open access
Advanced Authentication Protocols Security
Cryptography and Data Security
User Authentication and Security Systems
Original source