A. Gómez Ramírez, Loui Al Sardy, Francis Gomez Ramirez
Blockchain security is becoming increasingly relevant in today's cyberspace as it extends its influence in many industries. This paper focuses on protecting the lowest level layer in the blockchain, particularly the P2P network that allows the nodes to communicate and share information. The P2P network layer may be vulnerable to several families of attacks, such as Distributed Denial of Service (DDoS), eclipse attacks, or Sybil attacks. This layer is prone to threats inherited from traditional P2P networks, and it must be analyzed and understood by collecting data and extracting insights from the network behavior to reduce those risks. We introduce Tikuna, an open-source tool for monitoring and detecting potential attacks on the Ethereum blockchain P2P network, at an early stage. Tikuna employs an unsupervised Long Short-Term Memory (LSTM) method based on Recurrent Neural Network (RNN) to detect attacks and alert users. Empirical results indicate that the proposed approach significantly improves detection performance, with the ability to detect and classify attacks, including eclipse attacks, Covert Flash attacks, and others that target the Ethereum blockchain P2P network layer, with high accuracy. Our research findings demonstrate that Tikuna is a valuable security tool for assisting operators to efficiently monitor and safeguard the status of Ethereum validators and the wider P2P network
The utilization of electronic voting systems for the election of public offices is becoming widespread globally. This trend can be attributed to the benefits provided by these systems, including remote voting capabilities and accelerated vote counting. Furthermore, electronic voting systems offer improved privacy and enhanced protection against voting bias. Blockchain technology enhances the robustness of the voting process through its immutable vote storage mechanism, thereby reducing the threat of vote tampering and safeguarding the legitimacy of elections. This technology has been adopted by countries such as Germany, Russia, Estonia, and Switzerland for use in their e-voting systems. This study provides a comprehensive overview of the blockchain-based e-voting systems currently being implemented by various countries and companies and proposed for academic research. Additionally, this study analyzes the challenges faced by blockchain e-voting systems and identifies areas for future research to enhance the trustworthiness of such systems.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
The term ‘Web3’ refers to the practices of participating in digital infrastructures through the ability to read, write and coordinate digital assets. Web3 is hailed as an alternative to the failings of big tech, offering a participatory mode of digital self-organizing and shared ownership of digital infrastructure through software-encoded governance rules and participatory practices. Yet, very few analytical frameworks have been presented in academic literature by which to approach Web3. This piece draws on the theoretical lens of infrastructure studies to offer an analytical framework to approach the emergent field of Web3 as an exploration in ‘how to infrastructure’ through prefigurative self-infrastructuring. Drawing on qualitative examples from digital ethnographic methods, I demonstrate how the origins of Web3 reveal the intentions of its creators as a political tool of prefiguration, yet its practices reveal the inherent tension of expressing these ideals in coherent technical and institutional infrastructure. Thus, I argue that one of the fundamental challenges Web3 is negotiating through technical and governance experiments is ‘how to self-infrastructure?’.
The primary concerns with manual transactions include corruption, lack of transparency, fraud, and mismanagement of distribution operations, all of which are created by traditional centralized applications, necessitating the migration to blockchain technology. In this work, a system is presented to secure and monitor correspondence between several nodes and store it in a decentralized database in order to secure distributed ledger transactions and safeguard against fraud and tampering when transactions are shared by multiple parties. The hashing that blockchain technology delivers in each transaction ensures a high level of security. The hashing associated with each transaction confirms all sending and receiving transactions. When a transaction is sent from one node to another, the other node checks the hash accompanying the transaction to see if it came from a registered node or an external node. Within the blockchain system, the nodes will check transaction correspondences. The system has demonstrated its effectiveness by delivering a more secure messaging system with high credibility and tamper resistance. In addition, the time it takes to authenticate will be in real time. Index Terms— Blockchain, Consensus procedure, Hashing, Blockchain in Governance.
Digital voting is increasingly important in both established and emerging democracies. Some of the advantages of digital voting are faster vote count and tabulation; accurate results; increased voters’ participation and convenience; and effective handling of complex electoral system formats that require laborious counting procedures. However, transparency, credibility, and integrity concerns, as well as the limited possibility of recount, usually make traditional digital voting systems unpopular. Digital voting using blockchain technology, however, is safe, transparent, and immutable, which makes it a suitable choice for future decentralized voting systems. In particular, the Ethereum blockchain is proposed as an appropriate platform for the backbone of an e-voting system due to its widespread use, transparency, consistency and provision of smart contracts. Initial piloting on the implementation of a blockchain-based voting framework in Jordan shows promising results on its transparency and integrity by incorporating a space for representatives and observers to monitor the election procedure and results as an additional measure to ensure its efficiency and reliability. The uptake of the proposed system calls for further debate and dialogue amongst governments and people, especially in developing countries where democracy is still in its infancy.
Ayodeji Ibitoye, Halleluyah Oluwatobi Aworinde, Esther T. Adekunle
Originally, manual voting systems are surrounded with issues like results manipulation, errors and long result computation time, ineligible voters, void votes among others. Electronic voting system helped in overcoming the challenges with manual voting system, to engendered other problems of phishing, men in the middle attack alongside voter’s impersonation. By these challenges, the integrity of an election results in a distributed system has become another top concern for e-voting system based on reliability. To achieve an improved voters’ authentication and result validation with excellent user experience, here, a Facial Recognition Electronic Voting System that is power-driven by Blockchain Technology was developed. The entire election engineering activities are decentralised with improved security features to enhance transparency, verifiability, and accountability for each vote count. The self-service voting system was built by smart contract and implemented on the Ethereum network. The obtained reports and evaluations reflected a non-editable and self-sufficiently certifiable system for voting. It also has a competitive edge over fingerprint enabled e-voting system. Aside it’s excellent usability and general acceptance, the developed method discarded to a larger extend, intended fraudulent actions from election activities by eliminating the involvement of a middleman while facilitating privacy, convenience, eligibility and satisfactory voters’ right.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Bithin Alangot, Paweł Szałachowski, Tien Tuan Anh Dinh, Souhail Meftah · 7 authors
Decentralized identity (DID) systems aim to give users full control over their identities by using completely decentralized technologies, such as blockchain or distributed ledgers, as identity providers. However, when user credentials are compromised, it is impossible in existing DID systems for the users to detect credential misuse. In this paper, we propose new DID authentication protocols with two properties: auditability and privacy. The former enables the detection of malicious authentication events, while the latter prevents an adversary from linking an authentication event to the corresponding user and service provider. We present two protocols that achieve auditability with varying privacy and performance guarantees. The first protocol has high performance, but it reveals information about the user. The second protocol achieves full privacy, but it incurs a higher performance overhead. We present a formal security analysis of our privacy-preserving protocols by using the Tamarin prover. We implemented them and evaluated their performance with a permissioned blockchain deployed over the Amazon AWS and a local cloud infrastructure. The results demonstrate that the first protocol is able to support realistic authentication workloads, while the second is nearly practical.
Pekka Koskela, Anni Karinsalo, Jori Paananen, Laura Salmela
Since the mid-2000s, the digitalisation of border checks has often referred to the increased adoption of automated border control (ABC) solutions at border crossing points in all border environments from air- ports and seaports to land border crossings. Key prerequisites for the operational implementations of the so-called eGates have been the electronic machine-readable travel document together with biometric technologies that have facilitated the automation of much of the tasks performed by border guards at manual control booths for selected groups of nationalities. Now, the next wave of major changes is emerging with the development of electronic identification (eID), with certain implementations particularly designed for crossborder use cases supplementing and possibly replacing the traditional physical identity document in a long-term future. The evolution of eID strongly aligns with the increased demands for data privacy to ensure that individuals can better control how much information is shared about themselves, with whom and for what purpose. One possible technology to provide the so-called data self-sovereignty is distributed ledger technology (DLT), including blockchains. DLT is being developed for instance by the Linux foundation, dispensing several distributed ledger projects and associated solutions for digital and self-sovereign identity. One of these projects is Hyperledger Indy. In this study, we present a distributed ledger implementation based on Hyperledger Indy applied as a border check use case. Our aim is to investigate the suitability of DLT in providing data self-sovereign facility in border checks, and to discuss the benefits and disadvantages the technology might entail for this security domain.
Darshana M Chigari, Dashvath R, Chandrakanth K J, Bhavya Das D · 5 authors
The evolution of Blockchain has given way to a Smart World where there is improved security and integration of devices, systems, and processes with humans through all-pervasive connectivity. There are numerous secure applications using Blockchain like smart cities, Cloud Computing, Smart Management of the Environment and Healthcare, etc.A decentralized voting system is an option for the paper ballot system and EVM (Electronic Voting Machines). Democracies need a decentralized voting system that offers security, integrity, immutability, transparency, and privacy to voters. Blockchain is an emerging technology that offers integrity, immutability, and decentralization of data. Moving our traditional voting system to Blockchain technology can increase voter confidence. This paper describes an attempt to influence the advantages of Blockchain, such as cryptography and transparency, to accomplish an efficient scheme for a decentralized voting system using the Ethereum network. Smart contracts are profound chunks of codes, which are included in the Blockchain and then execute written code as planned in each stage of Blockchain updates. Decentralized voting is one of the trending topics, but is yet to be significant, compared to the other e-services.
In recent years, the internet of things (IoT) growth has brought about many technological changes, including the emergence of the notion of the smart city. The development of a smart city requires the integration of IoT devices and information and communication technologies to improve the quality of lives of citizens in many areas such as health, economy, business, agriculture, and transport. However, with this evolution, many cybersecurity risks and challenges have been raised, so it is necessary to develop these technologies in a protected way to avoid being compromised by attackers. Blockchain, being a new technology based on cryptographic principles, can play an important role in securing smart cities. In this survey, we discussed different applications of blockchain technology in smart cities and also studied how blockchain features (transparency, democracy, decentralization, and security) can help in the improvement of smart city services. This analysis will help us to implement an electronic voting model using a smart contract based on the Ethereum blockchain to highlight how blockchain technology can be implemented in smart cities to promote security.
Abstract: Voting is a primary right of every citizen living ina country. Traditional methods used for voting includes paper ballot system, EVMs (Electronic Voting Machines), etc. which are still followed and trusted by every voter or citizen blindly. These voting systems can have ambiguity as the data is maintainedunder a centralized environment whether it is counting the paper ballots or storing the vote caste on a computer server. Thisuse of a centralized database for the voting system has some security issues such as Data modification through the third party in the network due to the use of the central database systemas well as the result of the voting is not shown in real-time, or manipulation with the data which can hamper the result and thus have an impact on not only system integrity but also lose faith in democracy, government, nation, etc. The voting methods used in an election should be legal, accurate, safe, and convenient.
Блокчейн - це тип технології розподіленого реєстру (Distributed Ledger Technology або DLT), який складається зі зростаючого списку записів, які називаються блоками, що надійно пов'язані між собою за допомогою криптографії [1]. В першу чергу, метою блокчейну є надати здатність користувачам записувати та розповсюджувати цифрову інформацію без змоги редагування.
V. Anitha, Orlando Juan Márquez, R. Sudharsan, S. Yoganandan · 5 authors
The aim of this paper is to create a decentralized transparent voting and analysis system that can be implemented with blockchain to provide an efficient and highly secure justifiable method of election systems in countries where traditional physical voting with gameable securities is used, increasing the chances of rigged elections. This system is designed to focus on a secure voting system, lower costs, faster wait times, no disparities due to various erroneous proxies, high scalability, and geographic independence. Overall, an effective election mechanism to strengthen the democratic process. The proposed dApp allows voters to vote from the comfort of their own homes, saving time and reducing the number of false votes registered.
Stefan More, Sebastian Ramacher, Lukas Alber, Marco Herzl
Authentication, authorization, and trust verification are central parts of an access control system. The conditions for granting access in such a system are collected in access policies. Since access conditions are often complex, dedicated languages -- policy languages -- for defining policies are in use. However, current policy languages are unable to express such conditions having privacy of users in mind. With privacy-preserving technologies, users are enabled to prove information to the access system without revealing it. In this work, we present a generic design for supporting privacy-preserving technologies in policy languages. Our design prevents unnecessary disclosure of sensitive information while still allowing the formulation of expressive rules for access control. For that we make use of zero-knowledge proofs (NIZKs). We demonstrate our design by applying it to the TPL policy language, while using SNARKs. Also, we evaluate the resulting ZK-TPL language and its associated toolchain. Our evaluation shows that for regular-sized credentials communication and verification overhead is negligible.
Normal cash has developed and appears numerous downsides such as inaccessibility. It is inclined to burglary and is intensely directed by government offices. Cryptocurrencies have risen as a egotistic money related framework. They depend upon secure disseminated ledger data structure. Mining plays a critical portion in this framework [1]. Basically, our cryptocurrency could be a conveyed database that keeps up tamper-proof information structure pieces containing his bunches of person exchanges. Blockchain innovation can be a widely emerging approach to data innovations. Bitcoin as a cryptocurrency has made several considerations since it was one of its earliest implementations. They discuss the key elements driving the development of sophisticated cryptocurrencies alongside Ethereum, a blockchain implementation with a focus on informed contracts [1]. In its most basic form, our cryptocurrency may be thought of as a distributed database that keeps track of tamper-proof data structure blocks comprising batchesof individual transactions [1].
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Cryptocurrencies, such as Bitcoin and Ethereum, are becoming increasingly prevalent mainly due to their anonymity, decentralization, transparency, and security. However, the completely public ledger makes the trace and analysis of each account possible as long as the identity behind the public address is revealed. Theoretically, social networks could make that happen when addresses are posted on social network platforms using accounts containing personal information. To verify such a possibility, we have collected public data from two major platforms, i.e. Twitter and Reddit, aiming to find potential privacy leakage behind the ETH public address. In the end, an easy-to-use retrieval application is also built for a better illustration.
The data in the blockchain cannot be tampered with and the users are anonymous, which enables the blockchain to be a natural carrier for covert communication. However, the existing methods of covert communication in blockchain suffer from the predefined channel structure, the capacity of a single transaction is not high, and the fixed transaction behaviors will lower the concealment of the communication channel. Therefore, this paper proposes a derivation matrix-based covert communication method in blockchain. It uses dual-key to derive two types of blockchain addresses and then constructs an address matrix by dividing addresses into multiple layers to make full use of the redundancy of addresses. Subsequently, to solve the problem of the lack of concealment caused by the fixed transaction behaviors, divide the rectangular matrix into square blocks with overlapping regions and then encrypt different blocks sequentially to make the transaction behaviors of the channel addresses match better with those of the real addresses. Further, the linear congruence algorithm is used to generate random sequence, which provides a random order for blocks encryption, and thus enhances the security of the encryption algorithm. Experimental results show that this method can effectively reduce the abnormal transaction behaviors of addresses while ensuring the channel transmission efficiency.
Open access
Advanced Steganography and Watermarking Techniques
Yukun Niu, Lingbo Wei, Chi Zhang, Jianqing Liu · 5 authors
Anonymous yet accountable authentication can protect users' privacy and security and prevent users from misbehaving when they access public Wi-Fi hotspots. However, most existing privacy-enhanced authentication schemes either do not meet the accountability requirements in public Wi-Fi hotspot access or they are inherently dependent on trusted third parties, and therefore are undeployable in practical settings. In this paper, we design and implement an access authentication scheme to simultaneously and efficiently provide anonymity and accountability without relying on any trusted third party by utilizing a permissionless blockchain (e.g., Bitcoin or Ethereum) and Intel SGX. Inspired by the recent progress on Bitcoin techniques such as Colored Coins, we utilize the unmodified Bitcoin blockchain as the powerful platform to manage access credentials without introducing any trusted third party. We leverage SGX-based mixer to allow users to anonymously exchange their access credentials and design the verification path of access credentials to support blacklisting misbehaving access credentials without compromising users' anonymity. By integrating with the anti-double-spending property of the Bitcoin blockchain, our scheme can simultaneously provide users' accountability and anonymity without involving any trusted third party. Finally, we demonstrate that our proposed scheme is compatible with the current Bitcoin system or other permissionless blockchains, and is highly effective and practical for public Wi-Fi hotspot access control systems.
In order to analyze real-time power data without revealing users’ privacy, privacy-preserving data aggregation schemes have been extensively researched in smart grid. However, most of the existing schemes either can only allow stationary users, or require a trusted center. In this paper, we propose an efficient and robust multidimensional data aggregation scheme based on blockchain. In our scheme, a leader election algorithm in Raft protocol is used to select a mining node from all smart meters to aggregate data. A dynamically verifiable secret sharing homomorphism scheme is adopted to realize flexible dynamic user management. In addition, our scheme can not only resist internal and external attacks but also support multidimensional data aggregation and fault tolerance. The security analysis shows that our proposed scheme is IND-CPA secure and can meet stronger security features. The experimental results show that compared with other schemes, our scheme can be implemented with lower computation and communication overhead.
Christina Ovezik, Dimitris Karakostas, Aggelos Kiayias
Decentralization has been touted as the principal security advantage which propelled blockchain systems at the forefront of developments in the financial technology space. Its exact semantics nevertheless remain highly contested and ambiguous, with proponents and critics disagreeing widely on the level of decentralization offered by existing systems. To address this, we put forth a systematization of the current landscape with respect to decentralization and we derive a methodology that can help direct future research towards defining and measuring decentralization. Our approach dissects blockchain systems into multiple layers, or strata, each possibly encapsulating multiple categories, and it enables a unified method for measuring decentralization in each one. Our layers are (1) hardware, (2) software, (3) network, (4) consensus, (5) economics ("tokenomics"), (6) client API, (7) governance, and (8) geography. Armed with this stratification, we examine for each layer which pertinent properties of distributed ledgers (safety, liveness, privacy, stability) can be at risk due to centralization and in what way. We also introduce a practical test, the "Minimum Decentralization Test" which can provide quick insights about the decentralization state of a blockchain system. To demonstrate how our stratified methodology can be used in practice, we apply it fully (layer by layer) to Bitcoin, and we provide examples of systems which comprise one or more "problematic" layers that cause them to fail the MDT. Our work highlights the challenges in measuring and achieving decentralization, and suggests various potential directions where future research is needed.
With the development of the Internet of Things (IoT) and its applications, a large amount of data is generated regularly. If this information is used by malicious attackers, it will be a great disaster for the relevant users. In this regard, this article focuses on the user’s identity privacy issues involved in the IoT. By protecting the user’s identity privacy, the attacker cannot associate the obtained data with the user’s real identity, and so achieve the purpose of protecting the user. This article uses the features of blockchain that cannot be tampered with nor forged to strengthen the reliability of the system. The proposed scheme saves the transaction information of user information through the Hyperledger and uses the ring signature method to obscure the real identity. A key generator is used to generate system public parameters and ring membership information required for signature. Users can use this information to hide their identity in a ring group of n users so that other users can only guess the true identity of the user with a probability of 1/n. Additionally, the method of aggregated signature is used to shorten the time and space required for k signature verification to 1/k, which greatly improves the efficiency. Finally, this article also uses an accountability mechanism to punish some attackers who attempt to waste system resources by revealing the real identity of the attacker and refusing to serve him. In this paper, GO language is used to write chain code to realize the proposed algorithm, and a prototype system is built through HyperLeger Fabric blockchain network, and the prototype system is verified by experiment. The correctness and efficiency of the above scheme are also proved through theoretical analysis and experiments.
Saba Abdulbaqi Salman, Sufyan Al-Janabi, Ali Makki Sagheer
Improving the voting system has become a widely discussed issue. Paper-based elections are not safe because of the possibility of changing and adding ballots. Consequently, many countries use e-voting systems to ensure security, authenticity and time efficiency. Blockchain e-voting systems can be adopted to reduce fraud and increase voting access from home, especially in pandemics. This paper suggests a blockchain e-voting system that tackles two security and authentication issues. The security has been ensured using hybrid public-key cryptography; the voter information is encrypted using the regional election office elliptic public key, while the homomorphic public supreme election authority encrypts the vote. Using homomorphic encryption for voice enables the calculations of results as the authority encrypts it without revealing the vote itself. Authentication has been improved for home voting by a robust login system. This login system consists of two steps. In the first step, the voter enters the site using his unique QR code number scanned by webcam; in the second step, the system checks the voter's face using a face recognition system by web camera to be routed to the voting page. Voting public keys are also authenticated using a digital certificate schema. The system has been tested to show its efficiency and suitability in block establishment time and the encryption and key generator randomness using NIST tests.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Voting is one of the most fundamental components of a democratic society. In 2021 Iraq held the Council of Representatives (CoR) elections in 83 electoral constituencies in 19 governorates. Nonetheless, several significant issues arose during this election, including the problem of logistics distribution, the excessively long period of ballot counting, voters can't know if their votes were counted or if their ballots were tampered with, and the inconsistent regulation of vote counting. Blockchain technology, which was just invented, may offer a solution to these problems. This paper introduces an electronic voting system for the Iraq Council of Representatives elections that is based on a prototype of the permission hyperledger fabric blockchain. An immutable, distributed ledger maintained by all members of a network is what blockchain technology is all about. By authenticating each voter, the system can prevent voting fraud by making votes traceable and verifiable, hence decreasing the chance of unlawful activities and fraudulent ballots. This work investigates the influence of E-voting, specifically the voting phase workload, on the performance of the hyperledger fabric blockchain platform in terms of latency and throughput by altering transaction send rates (tps), block size, and block timeout.