Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

733 papersLast indexed Aug 31, 2026
Search papers

Paper index

733 results · page 22 of 31

Clear filters
Oct 26, 2020·Security and Communication Networks
64 cites
An Improved Blockchain-Based Authentication Protocol for IoT Network Management

Mostafa Yavari, Masoumeh Safkhani, Saru Kumari, Sachin Kumar · 5 authors

Communication security between IoT devices is a major concern in this area, and the blockchain has raised hopes that this concern will be addressed. In the blockchain concept, the majority or even all network nodes check the validity and accuracy of exchanged data before accepting and recording them, whether this data is related to financial transactions or measurements of a sensor or an authentication message. In evaluating the validity of an exchanged data, nodes must reach a consensus in order to perform a special action, in which case the opportunity to enter and record transactions and unreliable interactions with the system is significantly reduced. Recently, in order to share and access management of IoT devices information with distributed attitude a new authentication protocol based on blockchain is proposed and it is claimed that this protocol satisfies user privacy preserving and security. However, in this paper, we show that this protocol has security vulnerabilities against secret disclosure, replay, traceability, and <a:math xmlns:a="http://www.w3.org/1998/Math/MathML" id="M1"> <a:mtext>Token</a:mtext> </a:math> reuse attacks with the success probability of 1 and constant complexity of also 1. We also proposed an improved blockchain-based authentication protocol (IBCbAP) that has security properties such as secure access management and anonymity. We implemented IBCbAP using JavaScript programming language and Ethereum local blockchain. We also proved IBCbAP’s security both informally and formally through the Scyther tool. Our comparisons showed that IBCbAP could provide suitable security along with reasonable cost.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Privacy, Security, and Data Protection
Original source
Oct 23, 2020·IEEE Transactions on Network Science and Engineering
50 cites
Towards Large-Scale and Privacy-Preserving Contact Tracing in COVID-19 Pandemic: A Blockchain Perspective

Wenzhe Lv, Sheng Wu, Chunxiao Jiang, Yuanhao Cui · 6 authors

Activity-tracking applications and location-based services using short-range communication (SRC) techniques have been abruptly demanded in the COVID-19 pandemic, especially for automated contact tracing. The attention from both public and policy keeps raising on related practical problems, including1) how to protect data security and location privacy? 2) how to efficiently and dynamically deploy SRC Internet of Thing (IoT) witnesses to monitor large areas?To answer these questions, in this paper, we propose a decentralized and permissionless blockchain protocol, namedBychain. Specifically, 1) a privacy-preserving SRC protocol for activity-tracking and corresponding generalized block structure is developed, by connecting an interactive zero-knowledge proof protocol and the key escrow mechanism. As a result, connections between personal identity and the ownership of on-chain location information are decoupled. Meanwhile, the owner of the on-chain location data can still claim its ownership without revealing the private key to anyone else. 2) An artificial potential field-based incentive allocation mechanism is proposed to incentivize IoT witnesses to pursue the maximum monitoring coverage deployment. We implemented and evaluated the proposed blockchain protocol in the real-world using the Bluetooth 5.0. The storage, CPU utilization, power consumption, time delay, and security of each procedure and performance of activities are analyzed. The experiment and security analysis is shown to provide a real-world performance evaluation.

Open access
COVID-19 Digital Contact Tracing
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Oct 21, 2020·Electronics
42 cites
Blockchain Use in IoT for Privacy-Preserving Anti-Pandemic Home Quarantine

Jinxin Zhang, Meng Wu

The outbreak of the respiratory disease caused by the new coronavirus (COVID-19) has caused the world to face an existential health crisis. To contain the infectious disease, many countries have quarantined their citizens for several weeks to months and even suspended most economic activities. To track the movements of residents, the governments of many states have adopted various novel technologies. Connecting billions of sensors and devices over the Internet, the so-called Internet of Things (IoT), has been used for outbreak control. However, these technologies also pose serious privacy risks and security concerns with regards to data transmission and storage. In this paper, we propose a blockchain-based system to provide the secure management of home quarantine. The privacy and security attributes for various events are based on advanced cryptographic primitives. To demonstrate the application of the system, we provide a case study in an IoT system with a desktop computer, laptop, Raspberry Pi single-board computer, and the Ethereum smart contract platform. The obtained results prove its ability to satisfy security, efficiency, and low-cost requirements.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
Oct 14, 2020·Technological Forecasting and Social Change
104 cites
Peace engineering: The contribution of blockchain systems to the e-voting process

Patricia Baudier, Galina Kondrateva, Chantal Ammi, Éric Seulliet

In recent decades, several countries have faced political tensions due to citizens' perceptions that their elections are fraudulent; some electors have even chosen not to vote because they believe that the results may be falsified. Thus, electoral fraud is a major issue. E-governance and e-voting are now being used in many countries, some of which are investigating blockchain solutions. The aim of this study is to investigate the potential contributions of blockchain technology to peace on a worldwide level by securing voting systems. Unfortunately, this technology is complex and could potentially generate conflict between actors in elections. Taking an exploratory approach, the authors chose a qualitative method to address this specific topic. Election observers and blockchain experts were interviewed to identify the technology's strengths and weaknesses. Our results emphasize the importance of trust and human factors in the voting process.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Original source
Sep 27, 2020·arXiv
6 cites
GDPR Compliance for Blockchain Applications in Healthcare

Anton Hasselgren, Paul Kengfai Wan, Margareth Horn, Katina Kralevska · 5 authors

The transparent and decentralized characteristics associated with blockchain can be both appealing and problematic when applied to a healthcare use-case. As health data is highly sensitive, it is therefore, highly regulated to ensure the privacy of patients. At the same time, access to health data and interoperability are in high demand. Regulatory frameworks such as GDPR and HIPAA are, amongst other objectives, meant to contribute to mitigating the risk of privacy violations of health data. Blockchain features can likely improve interoperability and access control to health data, and at the same time, preserve or even increase, the privacy of patients. Blockchain applications should address compliance with the current regulatory framework to increase real-world feasibility. This exploratory work indicates that published proof-of-concepts in the healthcare domain comply with GDPR, to an extent. Blockchain developers need to make design choices to be compliant with GDPR since currently, none available blockchain platform can show compliance out of the box.

Open access
2 source records
cs.CR
cs.CY
cs.SI
Original source
Sep 16, 2020·IEEE Transactions on Engineering Management
39 cites
Designing for Trust in Blockchain Platforms

Liudmila Zavolokina, Noah Zani, Gerhard Schwabe

Trust is a crucial component for successful transactions regardless of whether they are executed in physical or virtual spaces. Blockchain technology is often discussed in the context of trust and referred to as a trust-free, trustless, or trustworthy technology. However, the question of how the trustworthiness of blockchain platforms should be demonstrated and proven to end users still remains open. While there may be some genuine trust in the blockchain technology itself, on an application level trust in an IT artifact needs to be established. In this article, we examine how trust-supporting design elements may be implemented to foster an end user's trust in a blockchain platform. We follow the design science paradigm and suggest a practically useful set of design elements that can help designers of blockchain platforms to build more trustworthy systems.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
Sep 4, 2020·Journal of Digital Social Research
10 cites
‘Blockchain Good, Bitcoin Bad’: The Social Construction of Blockchain in Mainstream and Specialized Media

Peter A. Chow-White, Alberto Lusoli, Vu Thuy Anh Phan, Sandy Edward Green

Blockchain is one of the most widely debated technologies in recent years. Pundits and scholars have described it as a disruptive technology that will impact many sectors of society. Skeptics argue blockchain’s popularity is fuelled by the media’s obsession for the ‘next big thing’ rather than the intrinsic potential of the technology. In this paper, we follow a social constructivist approach with the aim of explaining how different discourses are creating new meanings about this technology. As Communication scholars, we focus on the role media play in framing debates about blockchain. Our analysis relies on a human coding of the most popular news about blockchain circulating on Twitter from October 2014 to July 2018. The findings show the general attitude about blockchain is predominantly positive. The discourses developing around crypto technologies are complex and multifaceted and indicate a general transition in the rhetorical definition of blockchain.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Misinformation and Its Impacts
Original source
Sep 1, 2020·IEEE Internet Computing
25 cites
COM-PACE: Compliance-Aware Cloud Application Engineering Using Blockchain

Gagangeet Singh Aujla, Masoud Barati, Omer Rana, Schahram Dustdar · 10 authors

The COVID19 Pandemic has highlighted our dependence on online services (from government, e-commerce/retail, and entertainment), often hosted over external cloud computing infrastructure. The users of these services interact with a web interface rather than the larger distributed service provisioning chain that can involve an interlinked group of providers. The data and identity of users are often provided to service provider who may share it (or have automatic sharing agreement) with backend services (such as advertising and analytics). We propose the development of compliance-aware cloud application engineering, which is able to improve transparency of personal data use -- particularly with reference to the European GDPR regulation. Key compliance operations and the perceived implementation challenges for the realization of these operations in current cloud infrastructure are outlined.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cloud Data Security Solutions
Original source
Sep 1, 2020·2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
15 cites
Cash, Cards or Cryptocurrencies? A Study of Payment Culture in Four Countries

Karoline Busse, Mohammad Tahaei, Katharina Krombholz, Emanuel von Zezschwitz · 7 authors

Payment cultures around the globe are diverse and have significant implications on security, privacy and trust. We study usable security aspects of payment cultures in four culturally distinct societies. Based on a qualitative study in Germany and Iran, we developed an online survey and deployed it in Germany, Iran, China, and the United States. The results reveal significant differences between the studied countries. For example, we found that participants from Iran and China are more comfortable with credential sharing and German participants were most accepting towards cryptocurrencies. We suggest these kinds of differences in payment culture need to be considered in the context of HCI research when evaluating current payment mechanisms or designing new ones.

Open access
Technology Adoption and User Behaviour
Privacy, Security, and Data Protection
Digital Platforms and Economics
Original source
Aug 27, 2020·Information Systems and e-Business Management
42 cites
Generating design knowledge for blockchain-based access control to personal health records

Pascal Meier, Jan Heinrich Beinke, Christian Fitte, Jan Schulte to Brinke · 5 authors

Abstract In the course of digitization in healthcare, personal health records (PHRs) are handled as a key solution. Despite the indisputable benefits, the adoption of PHRs is hampered by data security and data privacy concerns. Blockchain technology offers promising potential to address these issues by enabling secure transactions of sensitive data. With regards to PHRs, the blockchain can be used to manage the access to health-related data. Besides existing generic PHR architectures, we systematically identified issues for the healthcare sector that need to be considered for the development of a PHR. We subsequently derived eight meta-requirements that were consolidated into three design principles. Within a 1-year design science research project, we developed the blockchain-secured PHR prototype, OSHealthRec, and evaluated the system in four evaluation cycles. The findings of our research are twofold. On the one hand, we contribute to the design knowledge base by presenting three design principles. On the other hand, we present the development of a real, operational blockchain-secured PHR and the findings from its continuous evaluation, which may serve as useful advice for further solutions.

Open access
Blockchain Technology Applications and Security
Digital Mental Health Interventions
Privacy, Security, and Data Protection
Original source
Aug 24, 2020·Journal of Network and Computer Applications
12 cites
Privacy-preserving targeted mobile advertising: A Blockchain-based framework for mobile ads

Imdad Ullah, Salil S. Kanhere, Roksana Boreli

The targeted advertising is based on preference profiles inferred via relationships among individuals, their monitored responses to previous advertising and temporal activity over the Internet, which has raised critical privacy concerns. In this paper, we present a novel proposal for a Blockchain-based advertising platform that provides: a system for privacy preserving user profiling, privately requesting ads from the advertising system, the billing mechanisms for presented and clicked ads, the advertising system that uploads ads to the cloud according to profiling interests, various types of transactions to enable advertising operations in Blockchain-based network, and the method that allows a cloud system to privately compute the access policies for various resources (such as ads, mobile user profiles). Our main goal is to design a decentralized framework for targeted ads, which enables private delivery of ads to users whose behavioral profiles accurately match the presented ads, defined by the ad system. We implement a POC of our proposed framework i.e. a Bespoke Miner and experimentally evaluate various components of Blockchain-based in-app advertising system, implementing various critical components; such as, evaluating user profiles, implementing access policies, encryption and decryption of users' profiles. We observe that the processing delay for traversing policies of various tree sizes, the encryption/decryption time of user profiling with various key-sizes and user profiles of various interests evaluates to an acceptable amount of processing time as that of the currently implemented ad systems.

Open access
3 source records
cs.CR
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Aug 24, 2020·IEEE Internet of Things Journal
50 cites
Anonymous Authentication on Trust in Blockchain-Based Mobile Crowdsourcing

Wei Feng, Zheng Yan, Laurence T. Yang, Qinghua Zheng

Mobile crowdsourcing (MCS) has become an effective data collection method due to its mobility, low cost, and flexibility. However, since centralized MCS confronts severe security and privacy risks in reality, many researchers are devoted to building a decentralized MCS system based on blockchain. Despite the effectiveness of these schemes, they fail to offer anonymous authentication on the trust of MCS nodes, although privacy is a main concern in MCS and trust plays an important role in a series of MCS activities, such as worker selection and truth discovery. Nevertheless, anonymous authentication on trust is not a trivial issue since trust evaluation usually conflicts with anonymity, which is a necessary privacy requirement in an open MCS environment. To tackle this problem, we leverage Intel software guard extension (SGX) and propose a scheme to anonymously authenticate trust with trustworthy trust evaluation in a blockchain-based MCS system. The scheme employs an SGX-enabled cloud server to periodically alter user public/private key pairs and mix newly altered keys among a number of faked keys in order to ensure unlinkability. Besides, we consider the unique features of MCS and work out a novel trust evaluation method by aggregating both subjective feedback and objective behaviors. Finally, we conduct several analyses and experiments to illustrate its security and efficiency.

Open access
User Authentication and Security Systems
Privacy, Security, and Data Protection
Mobile Crowdsensing and Crowdsourcing
Original source
Aug 7, 2020·Figshare
21 cites
User Mental Models of Cryptocurrency Systems - A Grounded Theory Approach

Alexandra Mai, Katharina Pfeffer, Matthias Gusenbauer, Edgar Weippl · 5 authors

Frequent reports of monetary loss, fraud, and user-caused security incidents in the context of cryptocurrencies emphasize the need for human-centered research in this domain. We contribute the first qualitative user study (N=29) on user mental models of cryptocurrency systems and the associated threat landscape. Using Grounded Theory, we reveal misconceptions affecting users' security and privacy. Our results suggest that current cryptocurrency tools (e.g., wallets and exchanges) are not capable of counteracting threats caused by these misconceptions. Hence, users frequently fail to securely manage their private keys or assume to be anonymous when they are not. Based on our findings, we contribute actionable advice, grounded in the mental models of users, to improve the usability and secure usage of cryptocurrency systems.

Open access
Privacy, Security, and Data Protection
Information and Cyber Security
Spam and Phishing Detection
Original source
Aug 4, 2020·Frontiers in Blockchain
22 cites
What Happens in Blockchain Stays in Blockchain. A Legal Solution to Conflicts Between Digital Ledgers and Privacy Rights

Gianluigi M. Riva

Blockchain is a disruptive technology presented in 2008 that allows both scarcity and timestamps to be introduced to the digital world. Whereas many technological applications may benefit from this architecture, it involves direct conflict with both Privacy rights and Data Protection rules, as introduced by the General Data Protection Regulation (GDPR). This study first provides an overview of what blockchain is, how it works, and how it can affect privacy. It describes how this technology functions, thanks to binary ledgers distributed amongst the system nodes, and what role they play in validating the succession of blocks. The work analyses how blockchain can be applied to innovative fields and investigates related Privacy issues. Indeed, the chain can certify the time, the parties and the object included in a ‘block’ but cannot guarantee the legal validity, the veracity or correctness of the content. Furthermore, its immutability is in direct conflict with the right to be forgotten. In addition, due to the distributed nature of the system, it does not allow identification of data controllers and, consequentially, the accountable subject for the personal data processed within the digital ledger. The aim of the study is to highlight the characteristics of the proposed solution, i.e. supporting centralised governance of blockchain infrastructures to ensure control over the distributed nodes, as well as having the capability to intervene in modifying the chain when the law requires it. This set of interventions would also render publicly available the personal information within the blockchain with different levels of accessibility (‘Privacy by Layers’ (PbL)) and, therefore, provide log control that can ensure compliance with the Data Protection regulatory framework. To provide complete analysis on the matter, the study also addresses how Intelligent Systems running on a blockchain-based infrastructure that holds pieces of personal information can clash with Article 22 of the GDPR on automated decisions when it affects the fundamental rights of individuals. Finally, the conclusions crystallise the legal remarks by stressing the essential elements of the analysis that emerged during the study and framing them within the bigger picture of how the Law addresses social or technological phenomena.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jul 25, 2020·10th International Conference on Computer Science, Engineering and Applications (CCSEA 2020), July 25~26, 2020, London, United Kingdom
7 cites
Data Confidentiality in P2P Communication and Smart Contracts of Blockchain in Industry 4.0

Jan Stodt, Christoph Reich

Increased collaborative production and dynamic selection of production partners within industry 4.0 manufacturing leads to ever-increasing automatic data exchange between companies. Automatic and unsupervised data exchange creates new attack vectors, which could be used by a malicious insider to leak secrets via an otherwise considered secure channel without anyone noticing. In this paper we reflect upon approaches to prevent the exposure of secret data via blockchain technology, while also providing auditable proof of data exchange. We show that previous blockchain based privacy protection approaches offer protection, but give the control of the data to (potentially not trustworthy) third parties, which also can be considered a privacy violation. The approach taken in this paper is not utilize centralized data storage for data. It realizes data confidentiality of P2P communication and data processing in smart contracts of blockchains.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jul 2, 2020·arXiv (Cornell University)
19 cites
Decentralized Blockchain for Privacy-Preserving Large-Scale Contact Tracing

Wenzhe Lv, Sheng Wu, Chunxiao Jiang, Yuanhao Cui · 6 authors

Activity-tracking applications and location-based services using short-range communication (SRC) techniques have been abruptly demanded in the COVID-19 pandemic, especially for automated contact tracing. The attention from both public and policy keeps raising on related practical problems, including \textit{1) how to protect data security and location privacy? 2) how to efficiently and dynamically deploy SRC Internet of Thing (IoT) witnesses to monitor large areas?} To answer these questions, in this paper, we propose a decentralized and permissionless blockchain protocol, named \textit{Bychain}. Specifically, 1) a privacy-preserving SRC protocol for activity-tracking and corresponding generalized block structure is developed, by connecting an interactive zero-knowledge proof protocol and the key escrow mechanism. As a result, connections between personal identity and the ownership of on-chain location information are decoupled. Meanwhile, the owner of the on-chain location data can still claim its ownership without revealing the private key to anyone else. 2) An artificial potential field-based incentive allocation mechanism is proposed to incentivize IoT witnesses to pursue the maximum monitoring coverage deployment. We implemented and evaluated the proposed blockchain protocol in the real-world using the Bluetooth 5.0. The storage, CPU utilization, power consumption, time delay, and security of each procedure and performance of activities are analyzed. The experiment and security analysis is shown to provide a real-world performance evaluation.

Open access
2 source records
cs.CR
cs.NI
eess.SP
Original source
Jul 1, 2020·arXiv
0 cites
The Bisq DAO: On the Privacy Cost of Participation

Liam Hickey, Martin Harrigan

The Bisq DAO is a core component of Bisq, a decentralized cryptocurrency exchange. The purpose of the Bisq DAO is to decentralize the governance and finance functions of the exchange. However, by interacting with the Bisq DAO, participants necessarily publish data to the Bitcoin blockchain and broadcast additional data to the Bisq peer-to-peer network. We examine the privacy cost to participants in sharing this data. Specifically, we use a novel address clustering heuristic to construct the one-to-many mappings from participants to addresses on the Bitcoin blockchain and augment the address clusters with data stored within the Bisq peer-to-peer network. We show that this technique aggregates activity performed by each participant: trading, voting, transfers, etc. We identify instances where participants are operating under multiple aliases, some of which are real-world names. We identify the dominant transactors and their role in a two-sided market. We conclude with suggestions to better protect the privacy of participants in the future.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Jun 29, 2020·SSRN Electronic Journal
5 cites
The Puzzle of Squaring Blockchain with the General Data Protection Regulation

Raffi Teperdjian

Blockchain is a revolutionary technology that enables the secure recording and storage of transactions without the need for a trusted third-party intermediary. This distributed ledger technology has the potential to mainstream entirely new, decentralized business models where determining the operation of a blockchain-based product or service is decided democratically among the systems users. Because of the way that it works, blockchain presents a significant challenge for the European Union’s General Data Protection Regulation (GDPR). The GDPR is the leading privacy law in the world, serving as a template for privacy laws in many countries and affecting a vast number of multinational organizations. Blockchain, unfortunately, fits rather poorly in the GDPR’s regulatory framework. This is primarily because the legislation makes the assumption that the entities that define the means and purpose of processing users’ personal data, that is, the Data Controllers, are readily identifiable and remain constant. In blockchains with decentralized data governance, where a user’s role can vary over time, this assumption is often false. Several commissions in the European Union have tried to tackle the conundrum of how to fit blockchain into the GDPR’s framework, but the analysis and recommendations of these bodies has failed to adequately resolve the conflicts. This Article is the first to provide an overview of blockchain technology that distinguishes between the variety of centralized and decentralized data governance models. To bring about the truly revolutionary applications of blockchain while ensuring adequate individual personal data protections, this Article proposes that the European Union eliminate untenable GDPR data controller obligations for blockchains with decentralized data governance models.

Open access
Privacy, Security, and Data Protection
Digitalization, Law, and Regulation
European Criminal Justice and Data Protection
Original source
Jun 21, 2020·Sensors
44 cites
A Novel Location Privacy-Preserving Approach Based on Blockchain

Ying Qiu, Yi Liu, Xuan Li, Jiahui Chen

Location-based services (LBS) bring convenience to people's lives but are also accompanied with privacy leakages. To protect the privacy of LBS users, many location privacy protection algorithms were proposed. However, these algorithms often have difficulty to maintain a balance between service quality and user privacy. In this paper, we first overview the shortcomings of the existing two privacy protection architectures and privacy protection technologies, then we propose a location privacy protection method based on blockchain. Our method satisfies the principle of k-anonymity privacy protection and does not need the help of trusted third-party anonymizing servers. The combination of multiple private blockchains can disperse the user's transaction records, which can provide users with stronger location privacy protection and will not reduce the quality of service. We also propose a reward mechanism to encourage user participation. Finally, we implement our approach in the Remix blockchain to show the efficiency, which further indicates the potential application prospect for the distributed network environment.

Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Mobile Crowdsensing and Crowdsourcing
Original source
Jun 8, 2020·International Journal of Computer Network and Information Security
13 cites
Privacy Protection in Smart Cities by a Personal Data Management Protocol in Blockchain

Hossein Mohammadinejad, Fateme Mohammadhoseini

Due to the increase of cybercrime and security risks in computer networks as well as violations of user privacy, it is essential to upgrade the existing protection models and provide practical solutions to meet these challenges. An example of these risks is the presence of a third party between users and various services, which leads to the collection and control of large amounts of users' personal information and the possibility of their databases being misused or hacked. Blockchain technology and encrypted currencies have so far shown that a decentralized network of peer-to-peer users, along with a general ledger, can do reliable computing. So, in this article, we are going to introduce a protocol that converts the blockchain network to an automated access control manager without the presence of a third party. To this end, we designed a mutual authentication protocol to create a secure channel between the user and the service and then demonstrate its accuracy and completeness using the Gong-Nidham-Yahalom belief logic The results of our evaluations show that our proposed protocol is secure enough to be used on the blockchain network and attackers are unable to penetrate, track, impersonate, inject, misrepresent or distort information using the common attacks.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Privacy, Security, and Data Protection
Original source
Jun 3, 2020·EAI Endorsed Transactions on Smart Cities
31 cites
Implementation of Decentralized Blockchain E-voting

Saad Khan, Aansa Arshad, Gazala Mushtaq, Aqeel Khalique · 5 authors

E-voting reduced the cost of election and provided convenience to some extent as compared to the traditional approach of pen and paper but it was considered to be unreliable as anyone having access to the machine physically can obstruct the machine and alter the votes. Also in order to control the e

Open access
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Advanced Steganography and Watermarking Techniques
Original source
May 28, 2020·arXiv (Cornell University)
21 cites
Blockchain is Watching You: Profiling and Deanonymizing Ethereum Users

Ferenc Béres, István András Seres, András A. Benczúr, Mikerah Quintyne-Collins

Ethereum is the largest public blockchain by usage. It applies an account-based model, which is inferior to Bitcoin's unspent transaction output model from a privacy perspective. Due to its privacy shortcomings, recently several privacy-enhancing overlays have been deployed on Ethereum, such as non-custodial, trustless coin mixers and confidential transactions. In our privacy analysis of Ethereum's account-based model, we describe several patterns that characterize only a limited set of users and successfully apply these quasi-identifiers in address deanonymization tasks. Using Ethereum Name Service identifiers as ground truth information, we quantitatively compare algorithms in recent branch of machine learning, the so-called graph representation learning, as well as time-of-day activity and transaction fee based user profiling techniques. As an application, we rigorously assess the privacy guarantees of the Tornado Cash coin mixer by discovering strong heuristics to link the mixing parties. To the best of our knowledge, we are the first to propose and implement Ethereum user profiling techniques based on quasi-identifiers. Finally, we describe a malicious value-fingerprinting attack, a variant of the Danaan-gift attack, applicable for the confidential transaction overlays on Ethereum. By incorporating user activity statistics from our data set, we estimate the success probability of such an attack.

Open access
3 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source