The project aims to develop a decentralized file-sharing platform that harnesses the power of blockchain technology, Ethereum smart contracts, and InterPlanetary File System (IPFS) to create a secure, censorship-resistant, and user-centric file-sharing ecosystem, eliminating reliance on centralized intermediaries, enhancing data privacy, and reducing the risk of censorship or data loss for a future of decentralized and secure data management.
Ethereum 2.0 is a major upgrade to improve its scalability, throughput, and security. In this version, RANDAO is the scheme to randomly select the users who propose, confirm blocks, and get rewards. However, a vulnerability, referred to as the `Last Revealer Attack' (LRA), compromises the randomness of this scheme by introducing bias to the Random Number Generator (RNG) process. This vulnerability is first clarified again in this study. After that, we propose a Shamir's Secret Sharing (SSS)-based RANDAO scheme to mitigate the LRA. Through our analysis, the proposed method can prevent the LRA under favorable network conditions.
Abstract To meet the demand for high‐quality healthcare services, data trading can effectively promote the circulation of medical data and improve the level of healthcare services. To address the existing problems of data regulation difficulties and data privacy leakage in medical data trading, a trusted and regulated data trading scheme based on blockchain and zero‐knowledge proof is proposed. In this scheme, a regulatory institution is introduced to control the issuance of authorized tokens and ensure the controllability of data sharing activities. The blockchain takes over the task of generating public parameters to reduce the computational overhead of the system. Based on homomorphic proxy re‐encryption technology, users can perform data analysis in the cloud to ensure data security. Smart contracts and zero‐knowledge proof technology can automatically verify the validity of data to protect the rights and interests of data users; at the same time, efficient consensus algorithms can also increase the rate of transactions processed by the blockchain system. Finally, as the security and performance analysis shows, the scheme in this paper has better security, higher efficiency and more comprehensive functions.
Lakshmi Rama Kiran Pasumarthy, Hisham Ali, William J. Buchanan, Jawad Ahmad · 7 authors
There is an increasing need to share threat information for the prevention of widespread cyber-attacks. While threat-related information sharing can be conducted through traditional information exchange methods, such as email communications etc., these methods are often weak in terms of their trustworthiness and privacy. Additionally, the absence of a trust infrastructure between different information-sharing domains also poses significant challenges. These challenges include redactment of information, the Right-to-be-forgotten, and access control to the information-sharing elements. These access issues could be related to time bounds, the trusted deletion of data, and the location of accesses. This paper presents an abstraction of a trusted information-sharing process which integrates Attribute-Based Encryption (ABE), Homomorphic Encryption (HE) and Zero Knowledge Proof (ZKP) integrated into a permissioned ledger, specifically Hyperledger Fabric (HLF). It then provides a protocol exchange between two threat-sharing agents that share encrypted messages through a trusted channel. This trusted channel can only be accessed by those trusted in the sharing and could be enabled for each data-sharing element or set up for long-term sharing.
To solve the problem of climate warming, countries around the world have paid special attention to the construction of carbon governance. Carbon emission accounting is an important policy tool to control the vented CO2. But at present, there are third-party agencies in carbon emission accounting that cannot ensure the fairness and impartiality of accounting, and there may be risks such as illegal use and leakage of sensitive information in the process of carbon emission data transmission. Therefore, We design the blockchain-based carbon emission security accounting scheme (BCESAS) and propose cross-chain verification contract to ensure the efficiency of cross-chain information accounting. In addition, bilinear pairing is used to ensure data integrity, and we encrypt private data using an improved and more secure homomorphic encryption algorithm to ensure that privacy is not leaked during the transfer of carbon emission data, which is more efficent than other homomorphic encryption algorithms. We also use reputation mechanism to regulate the behavior of carbon emission auditors. The theoretical and experimental analysis demonstrates that BCESAS can verify the integrity, correctness and privacy of cross-chain data calculation result effectively, realizing secure and reliable expansion of blockchain.
Michalis Pingos, Panayiotis Christodoulou, Andreas S. Andreou
Data meshes are an approach to data architecture and organization that treats data as a product and focuses on decentralizing data ownership and access. It has recently emerged as a field that presents quite a few challenges related to data ownership, governance, security, monitoring, and observability. To address these challenges, this paper introduces an innovative algorithmic framework leveraging data blueprints to enable the dynamic creation of data meshes and data products in response to user requests, ensuring that stakeholders have access to specific portions of the data mesh as needed. Ownership and governance concerns are addressed through a unique mechanism involving Blockchain and Non-Fungible Tokens (NFTs). This facilitates the secure and transparent transfer of data ownership, with the ability to mint time-based NFTs. By combining these advancements with the fundamental tenets of data meshes, this research offers a comprehensive solution to the challenges surrounding data ownership and governance. It empowers stakeholders to navigate the complexities of data management within a decentralized architecture, ensuring a secure, efficient, and user-centric approach to data utilization. The proposed framework is demonstrated using real-world data from a poultry meat production factory.
Nowadays, Internet of Things platforms are being deployed in a wide range of application domains. Some of these include use cases with security requirements, where the data generated by an IoT node is the basis for making safety-critical or liability-critical decisions at system level. The challenge is to develop a solution for data exchange while proving and verifying the authenticity of the data from end-to-end. In line with this objective, this paper proposes a novel solution with the proper protocols to provide Trust in Data, making use of two Roots of Trust that are the IOTA Distributed Ledger Technology and the Trusted Platform Module. The paper presents the design of the proposed solution and discusses the key design aspects and relevant trade-offs. The paper concludes with a Proof-of-Concept implementation and an experimental evaluation to confirm its feasibility and to assess the achievable performance.
Engin Zeydan, Josep Mangues‐Bafalluy, Şuayb S. Arslan, Yekta Türk
Identity and access management frameworks address user access rights and data governance for organizations, vendors and users. In response to the problems associated with centralized authorities (e.g. single point of failure , limited scalability, lack of user control), new identity management models have emerged, such as Self-Sovereign Identity (SSI), which relies on verifiable data registers to validate Decentralized Identifier (DIDs) and can be achieved in many different ways, e.g. through Distributed Ledger Technology (DLT), distributed databases or other decentralized systems. The main goal of SSI is to enable users to take control of managing their data shared with different services. In this paper, we examine a possible application of the SSI concept to aerial base station (ABS)- integrated networks. The paper presents the effective use of DID implementation to provide a secure and decentralized way to create, associate and verify credentials and identities of ABSs, ensuring secure communication between Ground Base stations (GBSs) and other nodes in the network in a multi-operator scenario. In the numerical results, the average values of various metrics (namely, the average credential presentation time, the average credential offer time, the average DIDcomm connection creation time, the average DIDcomm signing time, and the average DIDcomm revoke credential time) related to credential operations in a DID management system are given for three different number of requests (50 K, 75 K, and 100 K). We have also provided the values of the different status codes that occurred in 100 K operations in the same DID management system. Towards the end of the paper, a comparison is made between SSI-based and Non-fungible token (NFT)-based blockchain solutions, also discussing the challenges and future directions of SSI solutions in the context of ABS-integrated networks.
A banking or identity provider can set up a customer identification data verification process between reliant parties with the use of the electronic know your customer (e-KYC) system. Due to its high degree of accessibility and availability and its efficient resource usage, the majority of banks choose to implement their e-KYC system on the cloud. All of the KYC procedures used by banks rely on encryption, which is a cumbersome process that may cause consumer data to be disclosed to unaffiliated financial institutions. Blockchain technology can be used to increase the efficiency of this system because it can automate a lot of human labor and is impervious to attacks of all kinds. The distributed ledger and immutable blockchain block make the perfect addition to the KYC process. The use of smart contacts can automate the identification of fraud. Any kind of KYC can be used to store information related to KYC identity. Consequently, financial institutions can establish a shared private blockchain on their premises for the purpose of document validation. This allows the user to maintain control over their private documents while also simplifying the process for banks to obtain the records needed for compliance
Battula Venkata Satish Babu, Kare Suresh Babu, Durga Prasad Kare
The secure access and reliable access revocation methods of modern digital systems are based on access control mechanisms.Access policies, which are used in access control mechanisms, are very important in safeguarding security and ensuring data protection.It is evident that the protection and tamper-proofing of such policies are very important.In addition, efficient access revocation schemes are required to promptly remove access privileges when users are no longer needed or authorized.The shortcomings of existing systems in ensuring efficient, streamlined access revocation and tamper-proof protection of access control policies underscore the need for innovative solutions.In this paper, we have introduced the novel Blockchain Attribute-Based Secure Data Management Model (BAB-SDMM).Our model is the first to integrate attribute-based encryption (ABE), Attribute-Based Access Control (ABAC), and blockchain to achieve multiple security features as well as provide partial and complete revocation at the same time.The experimental results and analysis, performed using the Ethereum blockchain network, demonstrated the enhanced performance of the proposed BAB-SDMM compared to existing research works.
Recent developments in Distributed Ledger Technology (DLT), including Blockchain offer new opportunities in the manufacturing domain, by providing mechanisms to automate trust services (digital identity, trusted interactions, and auditable transactions) and when combined with other advanced digital technologies (e.g. machine learning) can provide a secure backbone for trusted data flows between independent entities. This paper presents an DLT-based architectural pattern and technology solution known as SmartQC that aims to provide an extensible and flexible approach to integrating DLT technology into existing workflows and processes. SmartQC offers an opportunity to make processes more time efficient, reliable, and robust by providing two key features i) data integrity through immutable ledgers and ii) automation of business workflows leveraging smart contracts. The paper will present the system architecture, extensible data model and the application of SmartQC in the context of example smart manufacturing applications.
Since 2009 when the first cryptocurrency Bitcoin began to be inserted into the market of electronic currencies, today in 2023 there are more than 19,850 electronic cryptocurrencies [1]. According to information from the coinecko website, the cryptocurrency market has expanded dramatically from a market capitalization of $1 million in 2013 to $3 trillion in November 2021 [2]. Referring to the latest statistical data, 3 are the cryptocurrencies that rule the e-commerce market in November 2023, Bitcoin,Ethereum AND Tether USDt [3]. Robotic Process Automation (RPA) is a growing trend in the restructuring of business processes, combined with digital transformation. This technology can be applied in different areas of business processes and by organizations from any activity sector [4].With continuous advances in automated processes through RPA, mechanisms involving Artificial Intelligence (AI) were incorporated to influence real-life decision-making [5]. Artificial Intelligence (AI) allows improving the accuracy and execution of RPA processes in extracting information and recognizing, classifying, predicting and optimizing processes [6].Nowadays, artificial intelligence is affecting the way people process computer data, televisions have started to create avatars that they use for news reporting. In this paper we will study the impact that the use of automatic sale and purchase of electronic cryptocurrencies can have using IPA and RPA and the possibility of this process being realized through this process.
Abstract With the rapid development of the Internet of Medical Things (IoMT) and the increasing concern for personal health, sharing Electronic Medical Record (EMR) data is widely recognized as a crucial method for enhancing the quality of care and reducing healthcare expenses. EMRs are often shared to ensure accurate diagnosis, predict prognosis, and provide health advice. However, the process of sharing EMRs always raises significant concerns about potential security issues and breaches of privacy. Previous research has demonstrated that centralized cloud-based EMR systems are at high risk, e.g., single points of failure, denial of service (DoS) attacks, and insider attacks. With this motivation, we propose an EMR sharing scheme based on a consortium blockchain that is designed to prioritize both security and privacy. The interplanetary file system (IPFS) is used to store the encrypted EMR while the returned hash addresses are recorded on the blockchain. Then, the user can authorize other users to decrypt the EMR ciphertext via the proxy re-encryption algorithm, ensuring that only authorized personnel may access the files. Moreover, the scheme attains personalized access control and guarantees privacy protection by employing attribute-based access control. The safety analysis shows that the designed scheme meets the expected design goals. Security analysis and performance evaluation show that the scheme outperforms the comparison schemes in terms of computation and communication costs.
The adoption of cloud-based electronic health record (EHR) systems and blockchain technology in healthcare is gaining attention for enhancing data security and interoperability. This research focuses on designing and implementing a blockchain-based cloud EHR system. It explores selecting suitable blockchain technology, cloud infrastructure, and data management methods to ensure patient data confidentiality, integrity, and availability. The architecture and components of the system, including the blockchain network, cloud storage layer, and user interface, are thoroughly discussed. A pilot study evaluates the system’s feasibility and performance, showcasing improved data protection, sharing, and management compared to traditional EHR systems. The potential benefits, drawbacks, and barriers to adoption of a blockchain-based cloud EHR system are examined. This research provides valuable insights and recommendations for healthcare institutions considering the implementation of such systems, addressing the challenges, and offering guidance for successful adoption.
Iulian Aciobăniţei, Ştefan-Ciprian Arseni, Emil Bureacă, Mihai Togan
The current shift towards digital transactions emphasizes the need for robust Qualified Electronic Signature (QES) frameworks that safeguard integrity and privacy. Having the potential to become the leading type of adopted QES, the main challenge that Remote QESs present to end users is choosing between transmitting the entire document or only its digest to the Trust Service Provider (TSP). The first option compromises the document’s confidentiality, while the second one requires the development of signature applications compliant with advanced signature formats, a task that often needs additional time and resources. In this paper, we introduce a comprehensive strategy for remote QESs, designed for seamless integration with current client applications, while simultaneously maintaining user privacy. The main topics approached in this paper are the following: a comprehensive architecture for privacy-aware remote QES systems, relevant standards and legislation, integration scenarios for clients, and remote QES standard protocols to assure communication between client and TSP environments. Furthermore, we also explore the integration of our proposed solution with an enhanced long-term preservation service that uses Ethereum smart contracts and methodologies to implement signature applications with advanced electronic signatures via open-source libraries while ensuring document privacy. The main result of this work is a flexible on-premise module that provides the ability to sign, validate, and preserve documents, with a minimal integration effort.
Ángel Jesús Varela‐Vaca, Rafael M. Gasca, David Iglesias, J.M. Gónzalez-Gutiérrez
Collaboration of business processes is essential for business-to-business (B2B) processes. Collaboration is interesting and important in connecting the digital context with the physical world (IoT) to feed processes with data or send data. However, it also presents multiple challenges, such as the lack of trust between participants with each other and additional privacy and security problems in the communicated data. Fraud detection is crucial for many type of organisations that deal with B2B transactions (banking, fintech, health, etc.) and are therefore exposed to a high risk of fraud. Fraud detection requires expensive professional investigations and intensive collaboration between processes of different organisations. This issue could be mitigated by effectively managing digital evidence, fostering trust and ensuring security for various stakeholders involved in the business processes. This paper proposes an approach to modelling and deploying any collaborative business process scenario, ensuring trust, security, and data privacy. Collaboration-level agreements are defined as a means to ensure trust, security, and data privacy. To accomplish this, our approach enables the automatic generation Smart Contract templates for the collaboration-level agreement specification involving different stakeholders in the collaboration. The Smart contracts are deployed in a Blockchain to ensure that the collaboration-level agreement conditions are signed by the parties. To validate the feasibility of our approach, a proof-of-concept for a fraud detection scenario is implemented, where different metrics are tested in relation to a set of threats and vulnerabilities.
Tácito Augusto Farias Júnior, Rafael Oliveira Vasconcelos, Admilson de Ribamar Lima Ribeiro
Privacy protection ensures that individuals have control over personal data, preventing abuse and preserving trust in the use of online services. In the “Digital Era”, where the collection, storage and processing of personal information have become ubiquitous, data privacy emerges as a relevant topic. In this sense, laws were created, such as the General Data Protection Law (LGPD) in Brazil and the General Data Protection Regulation (GDPR) in Europe, to control privacy and the processing of personal data. The article presents a comparative analysis of 2 (two) data privacy mechanisms, the Zero-Knowledge Proof (ZKP) and Ring Signatures, used in Blockchain, aiming at the legal and regulatory implications with the LGPD and GDPR. The comparative study between ZKP and Ring Signatures highlights the flexibility of ZKP in various contexts, including voting and secure authentication systems, while Ring Signatures offer significant advantages in terms of scalability and efficiency in systems where subscriber anonymity is considered fundamental. Furthermore, the legal and regulatory implications of the ZKP are discussed, mainly in relation to LGPD and GDPR. Finally, the article concludes that the comparative analysis offers insights into applications, challenges and legal and regulatory implications, particularly in relation to data privacy and compliance with regulations such as LGPD and GDPR.
This paper explores the relationship between the development of the internet and health care, highlighting their parallel growth and mutual influence. It delves into the transition from the early, static days of Web 1.0, akin to siloed physician expertise in health care, to the more interactive and patient-centric era of Web 2.0, which was accompanied by advancements in medical technologies and patient engagement. This paper then focuses on the emerging era of Web3-the decentralized web-which promises a transformative shift in health care, particularly in how patient data are managed, accessed, and used. This shift toward Web3 involves using blockchain technology for decentralized data storage to enhance patient data access, control, privacy, and value. This paper also examines current applications and pilot projects demonstrating Web3's practical use in health care and discusses key questions and considerations for its successful implementation.
The rapid expansion of the Internet of Things (IoT) has introduced significant challenges in data authentication, necessitating a balance between scalability and security. Traditional approaches often rely on third parties, while blockchain-based solutions face computational and storage bottlenecks. Our novel framework employs edge aggregating servers and Ethereum Layer 2 rollups, offering a scalable and secure IoT data authentication solution that reduces the need for continuous, direct interaction between IoT devices and the blockchain. We utilize and compare the Nova and Risc0 proving systems for authenticating batches of IoT data by verifying signatures, ensuring data integrity and privacy. Notably, the Nova prover significantly outperforms Risc0 in proving and verification times; for instance, with 10 signatures, Nova takes 3.62 s compared to Risc0's 369 s, with this performance gap widening as the number of signatures in a batch increases. Our framework further enhances data verifiability and trust by recording essential information on L2 rollups, creating an immutable and transparent record of authentication. The use of Layer 2 rollups atop a permissionless blockchain like Ethereum effectively reduces on-chain storage costs by approximately 48 to 57 times compared to direct Ethereum use, addressing cost bottlenecks efficiently.
To address the challenges of low credibility, difficult data sharing, and regulatory supervision issues involving electronic evidence storage in the judicial preservation process, this paper proposes a blockchain-based judicial evidence preservation scheme. The scheme utilizes the characteristics of blockchain's immutability to achieve credible forensics of electronic evidence on the chain and employs the decentralized storage of the interplanetary file system for secure and efficient off-chain storage. Simultaneously, it resolves the problem of declining throughput due to limited block capacity. Additionally, it leverages smart contract technology to encompass major aspects of the judicial process, including user case registration, authority management, judicial evidence uploading and downloading, case data sharing, partial disclosure of case information, and regulatory review. Simulation experiments demonstrate that the scheme significantly improves throughput and stability. Performance tests indicate that the transfer speed of the interplanetary file system can meet the data-sharing needs among judicial organizations.
Rafael Belchior, Limaris Torres, Jonas Pfannschmidt, André Vasconcelos · 5 authors
With the evolution of distributed ledger technology (DLT), several blockchains that provide enhanced privacy guarantees and features, including Corda, Hyperledger Fabric, and Canton, are being increasingly adopted. These distributed ledgers only provide partial consistency, meaning that participants can observe the same ledger differently, i.e., observe some transactions but not others, providing higher levels of privacy to the end-user. Choosing privacy instead of transparency leads to delicate trade-offs that are difficult to manage during runtime, hampering the development of applications that depend on reasoning about shared state, e.g., asset transfers across blockchains. We propose using the concept of blockchain view (view) – an abstraction of the state a participant can access at a certain point to address this problem. Views allow us to systematically reason about either state partitions within the same DLT or an integrated view spanning across several DLTs. We introduce BUNGEE (Blockchain UNifier view GEnErator), the first DLT view generator, to allow capturing snapshots, constructing views from these snapshots, and merging views according to a set of rules specified by the view stakeholders. Creating views and operating views allows new applications built on top of dependable blockchain interoperability, such as stakeholder-centric snapshots for audits, cross-chain analysis, blockchain migration, and combined on-chain-off-chain analytics.
The rapid digitization of various industries has underscored the critical need for secure and reliable document verification methods. Traditional verification techniques, including signature and stamp verification, image processing, and machine learning, often grapple with issues of scalability, accuracy, and security. Blockchain technology, renowned for its decentralization, immutability, and transparency, presents a transformative solution to these challenges. This research proposes a unified framework that integrates blockchain with traditional document verification methods, aiming to create a scalable, secure, and robust system for both electronic and printed documents. The framework is designed with several core components: a blockchain layer for immutable and transparent record-keeping, a traditional verification layer augmented by machine learning for accurate document analysis, and an integration layer that facilitates seamless interaction between these components. Smart contracts are employed to automate the verification process, enhancing efficiency and reducing human error. Key aspects of the framework include strategies to overcome technical challenges such as scalability using off-chain solutions and sharding and ensuring data privacy with advanced cryptographic techniques. The framework also incorporates regulatory and compliance considerations, ensuring that the system meets legal standards across different jurisdictions. Case studies from sectors such as finance, healthcare, and legal services illustrate the practical implementation and benefits of the proposed framework. These examples demonstrate the framework’s ability to enhance document security, streamline verification processes, and provide a reliable audit trail. This research offers a comprehensive approach to modernizing document verification, leveraging the strengths of both blockchain and traditional methods to meet the evolving needs of a digital world.
Iván Abellán Álvarez, Vincent Gramlich, Johannes Sedlmeir
With the increasing adoption of decentralized information systems based on a variety of permissionless blockchain networks, the choice of consensus mechanism is at the core of many controversial discussions. Ethereum's recent transition from proof-of-work (PoW) to proof-of-stake (PoS)-based consensus has further fueled the debate on which mechanism is more favorable. While the aspects of energy consumption and degree of (de-)centralization are often emphasized in the public discourse, seminal research has also shed light on the formal security aspects of both approaches individually. However, related work has not yet comprehensively structured the knowledge about the security properties of PoW and PoS. Rather, it has focused on in-depth analyses of specific protocols or high-level comparative reviews covering a broad range of consensus mechanisms. To fill this gap and unravel the commonalities and discrepancies between the formal security properties of PoW- and PoS-based consensus, we conduct a systematic literature review over 26 research articles. Our findings indicate that PoW-based consensus with the longest chain rule provides the strongest formal security guarantees. Nonetheless, PoS can achieve similar guarantees when addressing its more pronounced tradeoff between safety and liveness through hybrid approaches.