Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,621 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,621 results · page 20 of 68

Clear filters
Jan 1, 2024·International Journal of Advanced Computer Science and Applications
1 cites
Enhance the Security of the Cloud Using a Hybrid Optimization-Based Proxy Re-Encryption Technique Considered Blockchain

Ahmed I. Alutaibi

Every day, a vast amount of data with incalculable value will be generated by the IoT devices that are deployed in various types of applications. It is crucial to ensure the reliability and safety of IoT data exchange in a cloud context because this data frequently contains the user's private information. This study presents a novel encrypted data storage and security system using the blockchain method in conjunction with hybrid optimization-based proxy re-encryption (HO-PREB). Dependency on outside central service providers is eliminated by the HO-PREB-based consensus process. In the blockchain system, several consensus nodes serve as proxy service nodes to restore encrypted data and merge transformed ciphertext with private data. Hybrid owl and bat optimization is employed to select the optimal key for enhancing security. This removes the limitations associated with securely storing and distributing private encrypted data via a distributed network. Moreover, the blockchain's distributed ledger ensures the permanent storage of data-sharing records and outcomes, ensuring accuracy and dependability. The simulated experiments of the designed model are evaluated with existing cryptographic techniques and gain a lower latency of 3.2 s and a lower turnaround time of 45 ms. Furthermore, the developed technique enhances cloud system security and possesses the capability to detect and mitigate attacks in the cloud environment.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jan 1, 2024·Procedia Computer Science
1 cites
Utilization of Blockchain Technology in the Data Audit System of Power Grid Engineering

Chunsheng Wang, Xuecheng Yu, Gonghao Tan, Xiaoqiang Li

To ensure the safety of power grid operation and the accuracy of data, it is necessary to solve the problems of credibility and transparency in traditional data auditing systems. In this study, the use of blockchain was proposed to design the system. It is a distributed ledger technology that can definitely provide new solutions for power grid engineering data auditing. In this article, the basic principles and characteristics of blockchain were elaborated in detail, and the application scenarios and advantages of blockchain technology in power grid engineering data audit systems were discussed. The challenges and problems of this technology in the field of power grid were analyzed. The research results indicated that the audit efficiency of the method proposed in this article ranged from 89% to 98%. Blockchain technology can provide advantages such as data security, transparency, traceability, and decentralization for power grid engineering data audit systems.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Economic and Technological Systems Analysis
Original source
Jan 1, 2024·Pravni vjesnik
4 cites
A COMPARATIVE REVIEW OF THE LEGAL STATUS OF NATIONAL CRYPTOCURRENCIES AND CBDCs : A LEGAL TENDER OR JUST ANOTHER MEANS OF PAYMENT

Šime Jozipović, Marko Perkušić, Nina Mladinić

This paper analyses the legal framework of national virtual currencies and so-called Central Bank Digital Currencies (CBDCs) from a comparative law perspective. The authors define the meaning of the terms “means of payment” and “legal tender” and determine the legal consequences of classifying certain means of payment as legal tender. Building on this, the authors present new developments in the field of sovereign virtual currencies and shed light on their evolution through a comparative legal analysis of various national virtual currencies. In this context, the authors present developments in various African countries, Venezuela’s initiative to introduce the first state-backed crypto token, the first CBDC pilot projects in Uruguay and China, and considerations to introduce a CBDC in the EU. Based on the analyzed systems, problems regarding privacy, user protection and effective regulation of transactions are highlighted in order to present the legal challenges for the establishment of a fully functional (supra-)national euro CBDC.

Open access
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Advanced Data Storage Technologies
Original source
Jan 1, 2024·IEEE Open Journal of the Computer Society
13 cites
Scalability and Security of Blockchain-Empowered Metaverse: A Survey

Huawei Huang, Zhaokang Yin, Qinglin Yang, Taotao Li · 7 authors

Metaverse brings unlimited space and tremendous potential since it is an integrated application of multiple fundamental technologies such as artificial intelligence, blockchain, networking, Internet of Things, and interactivity. During those building blocks of metaverse, blockchain is a type of technology operated by a group of individual participants and known for its immutability feature. The massive adoption of blockchain has been severely prevented by various security and scalability issues in blockchain-based applications due to the inherent characteristics of this technology. To accelerate the massive adoption of blockchain, many previous studies have been carried out to address the security and scalability issues. This article reviews blockchain-related publications collected from four major security conferences (i.e., NDSS, CCS, S&P, and USENIX Security) published in the past three years. Through this overview, we disclose the security and scalability issues of mainstream blockchains such as Bitcoin and Ethereum. Our study aims to help researchers better understand the bottleneck of blockchain-empowered metaverse, and how to address user requirements for security and scalability from the perspective of blockchains.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Jan 1, 2024·Facta universitatis - series Electronics and Energetics
2 cites
Revolutionising the document workflow using blockchain in banking sector

Ervin Domazet, Gunter Merdzan, Violeta Cvetkoska, Daniela Mechkaroska · 6 authors

Blockchain is a distributed ledger technology that can revolutionise the banking sector by increasing transparency, reducing costs, and enhancing security. However, the success of any banking service lies in the efficiency of serving it, which depends on the smoothness of internal documents and process flows. This paper proposes a novel method that uses blockchain infrastructure to address the efficiency, security, and privacy of workflow processes in the banking sector. Our approach combines Alfresco DMS and CMIS with the orchestration tool Camunda for workflow management and secures them with a notary using the Factom Blockchain. This method provides a secure, efficient, and reliable way for banks to process transactions, store documents, and manage their processes. It will enable banks to process transactions faster, reduce costs, minimise the risk of fraud, increase customer satisfaction, and fully consider blockchain technology's advantages.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cloud Data Security Solutions
Original source
Jan 1, 2024·IET Information Security
1 cites
An Efficient Multiparty Threshold ECDSA Protocol against Malicious Adversaries for Blockchain‐Based LLMs

Jing Wang, Xue Yuan, Yingjie Xu, Yudi Zhang

Large language models (LLMs) have brought significant advancements to artificial intelligence, particularly in understanding and generating human language. However, concerns over management burden and data security have grown alongside their capabilities. To solve the problem, we design a blockchain‐based distributed LLM framework, where LLM works in the distributed mode and its outputs can be stored and verified on a blockchain to ensure integrity, transparency, and traceability. In addition, a multiparty signature‐based authentication mechanism is necessary to ensure stakeholder consensus before publication. To address these requirements, we propose a threshold elliptic curve digital signature algorithm that counters malicious adversaries in environments with three or more participants. Our approach relies on discrete logarithmic zero‐knowledge proofs and Feldman verifiable secret sharing, reducing complexity by forgoing multiplication triple protocols. When compared with some related schemes, this optimization speeds up both the key generation and signing phases with constant rounds while maintaining security against malicious adversaries.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jan 1, 2024·Journal of Computer and Communications
5 cites
Futureproofing Blockchain & Cryptocurrencies against Growing Vulnerabilities & Q-Day Threat with Quantum-Safe Ledger Technology (QLT)

Fazal Raheman

With one billion users using 380 exchanges, the security of blockchains and cryptocurrencies remains a major concern as billions are lost to hackers every year. Cryptocurrency hacks negatively impact cryptocurrency markets introducing volatility. Each major scam/hack incident results in a significant price dip for most cryptocurrencies, decelerating the growth of the blockchain economy. Existing blockchain vulnerabilities are further amplified by the impending existential threat from quantum computers. While there’s no reprieve yet from the scam/hack prone blockchain economy, quantum resilience is being aggressively pursued by post quantum cryptography (PQC) researchers, despite 80 of 82 candidate PQCs failing. As PQC has no role in combating inherent vulnerabilities, securing over 1000 existing blockchains against scammers/hackers remains a top priority for this industry. This research proposes a novel Quantum-safe Ledger Technology (QLT) framework that not only secures DLTs/cryptocurrencies and exchanges from current vulnerabilities but protects them from the impending Q-day threats from future quantum computers. As blockchain-agnostic technology, the QLT framework can be easily adapted to secure any blockchain or crypto exchange.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jan 1, 2024·International Journal of Advanced Computer Science and Applications
10 cites
A Blockchain Framework for Academic Certificates Authentication

Ruqaya Abdelmagid, Mohamed Abdelsalam, Fahad Kamal Alsheref

This paper proposes a framework to solve academic certificate fraud by implementing a blockchain network. A permission Hyperledger Fabric network is deployed to store students’ information and allows the proper access to guarantee the system's security. The paper discusses several studies that introduce variants of solutions for the academic certification tampering problem by using blockchain technology. It finds Hyperledger Fabric secure, and performant with higher TPS than Bitcoin and Ethereum; latency increases with participant number.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Jan 1, 2024·IEEE Open Journal of the Communications Society
2 cites
Eisdspa: An Efficient and Secure Blockchain-Based Donation Scheme With Privacy Protection and Auditability

Yong Zhou, Hong Lei, Zijian Bao

Charity donations are a critical mechanism for social resource distribution. However, traditional donation systems, typically centralized, are prone to issues such as data redundancy, vulnerability to single-point failures, and a deficiency in transparency and traceability. Although blockchain-based donation programs have emerged to address trust issues inherent in centralized models, they often neglect critical security concerns like privacy protection and identity authentication. This paper introduces Eisdspa, a blockchain-based donation system designed to offer identity authentication, auditability, and privacy protection. Specifically, we introduce an identity credential system that facilitates anonymous donations, shielding the identities of both donors and donees through the use of BBS+ signatures and zero-knowledge proofs of knowledge (ZKPoKs). Additionally, we ensure the integrity of goods donations by offering robust auditability and protecting user privacy with Pedersen commitments and ZKPoKs. We formally define the privacy aspects of Eisdspa and conduct a security analysis of the system under the random oracle model. A prototype implementation of the scheme, along with a comparative analysis with existing solutions, highlights the benefits of Eisdspa. Moreover, we assess the computational efficiency of Eisdspa, with experimental results indicating its high performance in computational overhead.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jan 1, 2024·AIMS Mathematics
5 cites
Ensuring data integrity in deep learning-assisted IoT-Cloud environments: Blockchain-assisted data edge verification with consensus algorithms

Fahad F. Alruwaili

<abstract> <p>Ensuring the reliability and trustworthiness of massive IoT-generated data processed in cloud-based systems is paramount for data integrity in IoT-Cloud platforms. The integration of Blockchain (BC) technology, particularly through BC-assisted data Edge Verification combined with a consensus system, utilizes BC's decentralized and immutable nature to secure data at the IoT network's edge. BC has garnered attention across diverse domains like smart agriculture, intellectual property, and finance, where its security features complement technologies such as SDN, AI, and IoT. The choice of a consensus algorithm in BC plays a crucial role and significantly impacts the overall effectiveness of BC solutions, with considerations including PBFT, PoW, PoS, and Ripple in recent years. In this study, I developed a Football Game Algorithm with Deep learning-based Data Edge Verification with a Consensus Approach (FGADL-DEVCA) for BC assisted IoT-cloud platforms. The major drive of the FGADL-DEVCA algorithm was to incorporate BC technology to enable security in the IoT cloud environment, and the DL model could be applied for fault detection efficiently. In the FGADL-DEVCA technique, the IoT devices encompassed considerable decentralized decision-making abilities for reaching an agreement based on the performance of the intrablock transactions. Besides, the FGADL-DEVCA technique exploited deep autoencoder (DAE) for the recognition and classification of faults in the IoT-cloud platform. To boost the fault detection performance of the DAE approach, the FGADL-DEVCA technique applied FGA-based hyperparameter tuning. The experimental result analysis of the FGADL-DEVCA technique was performed concerning distinct metrics. The experimental values demonstrated the betterment of the FGADL-DEVCA approach with other existing methods concerning various aspects.</p> </abstract>

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
Jan 1, 2024·IET Information Security
9 cites
A Blockchain‐Based Trustworthy Access Control Scheme for Medical Data Sharing

C. Wang, Wei Wu, Fulong Chen, Hong Shu · 9 authors

Blockchain is commonly employed in access control to provide safe medical data exchange because of the characteristics of decentralization, nontamperability, and traceability. Patients share personal health data by granting access rights to users or medical institutions. The major purpose of the existing access control techniques is to identify users who are permitted to access medical data. They hardly ever recognize internal assailants from legitimate entities. Medical data will involve multilayer access within the authorized organizations. Considering the cost of permissions management and the problem of insider malicious node attacks, users hope to implement authorization constraints within the authorized institutions. It can prevent their data from being maliciously disclosed by end‐users from different authorized healthcare domains. For the purpose to achieve the fine‐grained permissions propagation control of medical data in sharing institutions, a trust‐based authorization access control mechanism is suggested in this study. Trust thresholds are assigned to different privileges based on their sensitivity and used to generate zero‐knowledge proof to be broadcasted among blockchain nodes. This method evaluates the trust of each user through the dynamic trust calculation model. And meanwhile, smart contract is employed to verify whether the user’s trust can activate some permissions and ensure the privacy of the user’s trust in the process of authorization verification. In addition, the authorization transaction between users and institutions is recorded on the blockchain for patient traceability and accountability. The feasibility and effectiveness of the scheme are demonstrated through comprehensive comparisons and extensive experiments.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Jan 1, 2024·JOIV International Journal on Informatics Visualization
0 cites
Optimizing Linked List-based Smart Contract on Ethereum with IPFS for E-book Management System

Maznun Arifa Mohammadan Makhtar, Novia Admodisastro, Mohd Anuar Mat Isa, Daniel Hafiz Abdullah · 5 authors

People are now widely adopting digital assets in various applications, integrating them into almost every aspect of their lives. Electronic books, or e-books, are one of the digital assets that result from the transformation of physical reading material into the digital world. Nowadays, blockchain is used in many industries because it provides immutable and transparent records. E-book publishers may take this opportunity to adopt blockchain technology for e-book data management. However, blockchain storage is limited; thus, storing the e-book files in blockchain is not recommended. A decentralized storage system, such as InterPlanetary Files Systems (IPFS), is an alternative way to store large files like e-books. IPFS can facilitate the storage of e-book files while the metadata is stored in the blockchain. The e-book metadata should be stored in a structured way for effective search and retrieval. E-book metadata could be added, deleted, and updated occasionally. Nevertheless, some data structures often struggle with dynamic collections of records. This paper proposes a linked list-based smart contract on Ethereum that integrates with IPFS for the e-book management system. We demonstrate the implementation of a linked list smart contract for insertion, deletion, update, retrieval, and traversal of the e-book’s metadata. The result shows that a linked list-based smart contract with IPFS could offer a robust solution for e-book data management. This solution provides more opportunities to explore further security and cryptography approaches toward a secure e-book management system.

Open access
2 source records
FinTech, Crowdfunding, Digital Finance
Digital Rights Management and Security
Blockchain Technology Applications and Security
Original source
Jan 1, 2024·IEEE Access
26 cites
A Blockchain Oracle Interoperability Technique for Permissioned Blockchain

Asma A. Alhussayen, Kamal Jambi, Maher Khemakhem, Fathy Eassa

Blockchain interoperability has become an essential requirement for the advancement of blockchain technology in numerous fields. Enterprise organizations are increasingly utilizing permissioned blockchains to manage and store their organizations’ data and transactions in a private immutable ledger. Interoperability enables permissioned blockchain platforms to communicate and exchange information which is paramount for fully exploiting permissioned blockchains as facilitators for B2B applications. Additionally, the cross-network invocation of smart contracts under agreed conditions enhances business operations. Blockchain oracles can enable permissioned blockchain interoperability and cross-network transactions in a seamless and private manner. However, they have not been studied in the literature as interoperability techniques between permission blockchains. This study proposes a blockchain oracle interoperability technique designed specifically for permissioned blockchain platforms. We presented the architecture of the blockchain oracle interoperability technique and a prototypical implementation to demonstrate the practicality of the proposed technique. In addition, we obtained cross-network transaction latency measurements and analyzed the results.

Open access
2 source records
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Cloud Data Security Solutions
Original source
Jan 1, 2024·Lecture notes in business information processing
2 cites
The Cost of Executing Business Processes on Next-Generation Blockchains: The Case of Algorand

Fabian Stiehle, Ingo Weber

Process (or workflow) execution on blockchain suffers from limited scalability; specifically, costs in the form of transactions fees are a major limitation for employing traditional public blockchain platforms in practice. Research, so far, has mainly focused on exploring first (Bitcoin) and second-generation (e.g., Ethereum) blockchains for business process enactment. However, since then, novel blockchain systems have been introduced - aimed at tackling many of the problems of previous-generation blockchains. We study such a system, Algorand, from a process execution perspective. Algorand promises low transaction fees and fast finality. However, Algorand's cost structure differs greatly from previous generation blockchains, rendering earlier cost models for blockchain-based process execution non-applicable. We discuss and contrast Algorand's novel cost structure with Ethereum's well-known cost model. To study the impact for process execution, we present a compiler for BPMN Choreographies, with an intermediary layer, which can support multi-platform output, and provide a translation to TEAL contracts, the smart contract language of Algorand. We compare the cost of executing processes on Algorand to previous work as well as traditional cloud computing. In short: they allow vast cost benefits. However, we note a multitude of future research challenges that remain in investigating and comparing such results.

Open access
2 source records
cs.SE
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Original source
Jan 1, 2024·IEEE Access
5 cites
BLS-MT-ZKP: A novel approach to selective disclosure of claims from digital credentials

Šeila Bećirović, Irfan Prazina, Damir Pozderac, Razija Turčinhodžić Mulahasanović · 5 authors

Digital credentials represent crucial elements of digital identity on the Internet. Credentials should have specific properties that allow them to achieve privacy-preserving capabilities. One of these properties is selective disclosure, which allows users to disclose only the claims or attributes they must. This paper presents a novel approach to selective disclosure BLS-MT-ZKP that combines existing cryptographic primitives: Boneh-Lynn-Shacham (BLS) signatures, Merkle hash trees (MT) and zero-knowledge proof (ZKP) method called Bulletproofs. Combining these methods, we achieve selective disclosure of claims while conforming to selective disclosure requirements. New requirements are defined based on the definition of selective disclosure and privacy spectrum. Besides selective disclosure, specific use cases for equating digital credentials with paper credentials are achieved. The proposed approach was compared to the existing solutions, and its security, threat, performance and limitation analysis was done. For validation, a proof-of-concept was implemented, and the execution time was measured to demonstrate the practicality and efficiency of the approach.

Open access
3 source records
cs.CR
Digital Rights Management and Security
Blockchain Technology Applications and Security
Original source
Jan 1, 2024·McGill-DEV
0 cites
Blockchain Tokens as Universal Encrypted Access: A Comprehensive System for Healthcare Information Networks

Ghassan Al-Sumaidaee

The digitization of healthcare presents both opportunities and challenges in managing medical data securely and efficiently. Centralized systems often raise concerns about data security, privacy, and accessibility. Blockchain technology, with its decentralized and transparent framework, offers a potential solution for data exchange and management. However, interoperability limitations between independent blockchain networks restrict their widespread adoption in healthcare. Fragmented data across these systems can lead to duplication, inconsistencies, and compromised patient privacy.This thesis proposes a novel approach using blockchain tokens, specifically non-fungible tokens (NFTs), which are unique digital certificates of ownership recorded on a blockchain, as a universal encrypted access system. These tokens facilitate the seamless transfer of patients' medical data across various blockchain-based healthcare networks. Assigning a unique token to each patient addresses the issues of data fragmentation and lack of interoperability that currently impede healthcare blockchain adoption.To achieve universal access with tokens, our solution leverages distributed storage systems (DSS), a decentralized network approach for data storage, employs steganography, a technique for hiding information within a digital carrier, and integrates cryptographic techniques. DSS eliminates centralized storage of sensitive medical data, thus preventing a single point of failure. To mitigate the inherent vulnerability of public DSS and NFTs metadata, steganography is employed to protect sensitive data, unique identifiers, and critical metadata, thus limiting access to authorized parties. Data is further secured with a password when embedded within images, serving later as NFTs images for simplified data retrieval. Cryptographic methods ensure secure password transfer during patient mobility across networks. Our model leverages the unique properties of NFTs. We use the mutability of NFT data to introduce patient updatable NFTs that can accommodate dynamic medical data. Conversely, the immutability of NFT data establishes an ownership mechanism for patients, ensuring data privacy, uniqueness, and a trusted, sharable protocol. This approach facilitates the seamless integration of new patient records in real-time on the public blockchain. A scoping study on a medical test network assessed the feasibility of using a private blockchain for healthcare records management (HRM). Insights gained led to expanding the scope to two blockchain medical networks. Multiple institutions implemented and tested medical record integration on IPFS within the private network using updatable NFTs on a public blockchain. Performance analysis confirmed the solution's feasibility, effectiveness, and potential for practical application

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jan 1, 2024·IEEE Access
3 cites
MECAT: Memory-Safe Smart Contracts in ARM TrustZone

Seonghwan Park, Hayoung Kang, Shangze Han, Jonghee M. Youn · 5 authors

A smart contract is a program executed on a blockchain. However, once the smart contract is deployed on the blockchain, it becomes visible to all participants and remains immutable. Thus, any sensitive information or vulnerabilities in smart contracts can be exposed to potential attackers. To protect the confidentiality of smart contracts, existing studies execute smart contracts in a trusted execution environment (TEE). However, they still suffer from vulnerabilities in smart contracts and potential memory-vulnerability problems. If an attack such as privilege escalation occurs by exploiting this vulnerability, the TEE can have a detrimental effect on the entire system as it has the most privileges in the system. To mitigate the memory vulnerability of the smart contracts in TEE, we propose MECAT, a prototype for memory-safe confidential smart contracts. In essence, MECAT runs smart contracts written in Rust, a memory-safe language, in ARM TrustZone. And MECAT is developed as a software library, allowing developers to easily apply MECAT to their smart contracts. According to our evaluation, MECAT only incurs a 1.36x performance overhead and 0.3% power overhead in single-node environments and can process the 16 clients concurrently in the network made with 8 peer nodes.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Security and Verification in Computing
Original source
Jan 1, 2024·IEEE Access
0 cites
AIAS: Ensuring Application Integrity Through Ethereum Blockchain

Ho-Won Lee, Yoon-Young Park, Sungchul Lee, Yoon-Jae Chae

In today’s rapidly evolving digital landscape, ensuring data integrity is paramount for maintaining the security and reliability of applications. This paper introduces the Application Integrity Assurance System (AIAS), a novel solution designed to enhance data integrity through the integration of Ethereum blockchain technology. AIAS leverages smart contracts and the Interplanetary File System (IPFS) to securely store and verify application manifests. By decentralizing the integrity assurance process, AIAS mitigates the risks associated with tampering and unauthorized modifications, providing a robust framework for maintaining data integrity in various application environments. The system has been prototyped and tested on an augmented reality platform, demonstrating its practical application and efficiency. The AIAS framework offers a cost-effective, infrastructure-free solution for safeguarding application integrity, making it an essential tool for platforms that demand high standards of data integrity and security.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Advanced Malware Detection Techniques
Original source
Jan 1, 2024·Institutional Repositories DataBase (IRDB)
0 cites
A Security Study in Decentralized Applications of Ethereum Blockchain

Zhanwen Chen

The proposal of the first cryptocurrency Bitcoin brings about the new technology called blockchain that massively expands the concept of financial system.Tamper-resistance, decentralization and traceability are three essential properties of a blockchain.In the following years, the original idea of blockchain also inspired the development and research of other cryptocurrency implementations.And the development of blockchain has extended beyond its fundamental transactional attributes.As blockchain can be regarded as an immutable ledger, it can also be exploited in other application scenarios.Ethereum, based on the principles of blockchain, further introduced smart contract technology, allowing any blockchain user to deploy programs on the chain for others to invoke.This has given rise to decentralized applications.Due to the distinct network model of decentralized applications, existing studies regarding the security of centralized models are difficult to directly adapt to decentralized blockchain applications.Therefore, safeguarding information security and user privacy in the blockchain environment has become a focal point of security study.The thesis contains three studies regarding security of decentralized applications.They are primarily categorized into two types according to the scenarios.One type involves using blockchain to enhance existing applications, while the other focuses on native applications based on blockchain.In the first scenario, I utilize blockchain to provide a verifiable endorsement solution for identity authentication in social networking service (SNS) scenarios.Previous identity authentication research in this area rarely incorporated blockchain.I significantly enhance the reliability and efficiency of identity authentication while preventing impersonation using blockchain.In the second scenario, our focus is on NFT trading within the blockchain.Existing research has only addressed NFT privacy issues to a limited extent due to conflicts with Ethereum's transparency principle.To tackle this problem, I proposed two solutions: first, I make the marketplace a semi-trusted entity to achieve anonymous NFT trading.Then, based on previous research, I further propose a solution for anonymous NFT transactions in a trustless environment.Through security analysis and performance evaluation, our solutions meet security requirements with acceptable expenses, making them suitable for practical applications.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jan 1, 2024·arXiv (Cornell University)
34 cites
A Holistic Approach for Trustworthy Distributed Systems with WebAssembly and TEEs

Arusoaie, Andrei, Bărbieru, Claudiu-Nicu, Captarencu, Oana-Otilia, Felber, Pascal · 9 authors

Ethereum is the dominant blockchain ecosystem capable of executing Turing-complete smart contracts. Rollups gained significant traction as the primary layer 2 (L2) solution meant to bring horizontal scalability to the main Ethereum network (L1). A core component of any rollup is the sequencer, which creates new L2 blocks to be submitted in rollup batches to L1. In most of the current rollup architectures, this component is centralised. As a result, these designs are prone to inconspicuous censorship practices by the sequencer. Trusted execution environments (TEEs) can guarantee the integrity of various sequencer components, which is instrumental in addressing censorship. However, the reaction of the system design to censorship attempts depends on where a TEE is integrated and which components it protects. In particular, this reaction is limited in the case of a monolithic TEE-protected sequencer design. Proposer-Builder Separation (PBS) is a non-monolithic paradigm adopted on L1, which separates the production of blocks from proposing them for inclusion in the blockchain. Recently, PBS has been considered for integration with L2 sequencers, with an impact on alleviating censorship. In this paper, we explore the design space of TEE-integrating PBS and non-PBS sequencer variants. First, we introduce a formal framework for the censorship actions that captures the specificity of the L2 sequencer. Then, we analyse to what extent the different designs address these censorship actions. Our main contribution is a novel design variation that allows for a precise observation of censored transactions. In the presence of TEEs, in a PBS setting, we demonstrate this precise observability, which is necessary to enable resilience to censorship.

Open access
Security and Verification in Computing
Cloud Data Security Solutions
Advanced Malware Detection Techniques
Original source
Jan 1, 2024·IEEE Access
97 cites
Dynamic AES Encryption and Blockchain Key Management: A Novel Solution for Cloud Data Security

Mohammed Y. Shakor, Mustafa Ibrahim Khaleel, Mejdl Safran, Sultan Alfarhood · 5 authors

In the rapidly evolving realm of cloud computing security, this paper introduces an innovative solution to address persistent challenges. The proliferation of cloud technology has brought forth heightened concerns regarding data security, necessitating novel approaches to safeguarding sensitive information. The issue centers on the vulnerability of cloud-stored data, often necessitating enhanced encryption and key management strategies. Traditional methods often fall short in mitigating risks associated with compromised encryption keys and centralized key storage. To combat these challenges, our proposed solution encompasses a two-phase approach. In the first phase, dynamic Advanced Encryption Standard (AES) keys are generated, ensuring each file’s encryption with a unique and ever-changing key. This approach significantly enhances file-level security, curtailing an attacker’s ability to decrypt multiple files even if a key is compromised. The second phase introduces blockchain technology, where keys are securely stored with accompanying metadata, bolstering security and data integrity. Elliptic Curve Cryptography (ECC) public key encryption enhances security during transmission and storage, while also facilitating secure file sharing. In conclusion, this comprehensive approach enhances cloud security, providing robust encryption, decentralized key management, and protection against unauthorized access. Its scalability and adaptability make it a valuable asset in contemporary cloud security paradigms, assuring users of data security in the cloud.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Chaos-based Image/Signal Encryption
Original source