A large number of raw data collected by satellites are processed by the production chain to obtain a large number of product data, of which the secure exchange and storage is of interest to researchers in the field of remote sensing information science. Authentic, secure data provide a critical foundation for data analysis and decision-making. Traditional centralized cloud computing systems are vulnerable to attack and, once the central server is successfully attacked, all data will be lost. Distributed ledger technology (DLT) is an innovative computer technology that can ensure information security and traceability, is tamper-proof, and can be applied to the field of remote sensing. Although there are many advantages to using DLT in remote sensing applications, there are some obstacles and limitations to its application. Remote sensing data have the characteristics of a large data volume, a spatiotemporal nature, global scale, and so on, and it is difficult to store and interconnect remote sensing data in the blockchain. To address these issues, this paper proposes a trustworthy and decentralized system using blockchain technology. The novelty of this paper is the proposal of a multi-level blockchain architecture in which the system collects remote sensing data and stores them in the Interplanetary File System (IPFS) network; after generating the IPFS hash, the network rehashes the value again and uploads it on the Ethereum chain for public query. The distributed data storage improves data security, supports the secure exchange of information, and improves the efficiency of data management.
<em>The intersection of cryptocurrencies and franchising is generating a wave of innovation and curiosity. While cryptocurrencies offer the potential for streamlined transactions, increased security, and global reach, they also bring a host of legal considerations that must be meticulously addressed in franchising contracts. In this article, we delve into key legal consequences that arise when utilizing cryptocurrencies in franchising agreements.</em>
Smart contracts, programs running on a blockchain, play a crucial role in driving Web 3.0 across a variety of domains, such as digital finance and future networks. However, they currently face significant security vulnerabilities that could result in potential risks and losses. This paper outlines the inherent vulnerabilities of smart contracts, both those typical of their applications and those unique to Web 3.0 applications. We then systematically classify the techniques based on their core approach to detecting vulnerabilities in smart contracts. Using these approaches, we conduct a comparative analysis of existing tools in terms of their vulnerability coverage, detection effectiveness, open-source availability, and integration capabilities. Finally, we present the Co-Governed Sovereignty Multi-Identifier Network (CoG-MIN) as a case study to demonstrate the significance of smart contract application security in establishing a community with a shared future in cyberspace during the Web 3.0 era and anticipate future research directions with challenges. To conclude, this study addresses the gap in integrating existing smart contract security research with the advancement of Web 3.0 development, while also providing recommendations for future research directions.
ANDREI BOGDAN STANESCU, CATALIN VAJAIALA, Dragoş Cocîrlea
Abstract In the current digital world, ensuring efficient storage capabilities and increased data privacy, as well as high data availability and redundancy, are critical key performance indicators for organizations striving for customer excellence. To achieve these, a modern two-layer technical architecture is proposed in this study. The core layer of the solution is an InterPlanetary File System (IPFS) Cluster that leverages the distributed storage concept, and the second is an Ethereum-based blockchain that leverages privacy and immutability mechanisms. Next, the two-layer architecture is implemented and deployed to enhance data protection, as well as optimize data storage and access for a mid-size organization. The results reveal the enhancement of IPFS to overcome its privacy concerns via role-based access and cryptographic techniques. Moreover, the benefits of utilizing IPFS for data redundancy, efficient storage, and transfer through its distributed nature were reported. Finally, the integration of the IPFS Cluster with the Ethereum-based blockchain, as well as the overall benefits, we described.
Andrea De Salve, Damiano Di Francesco Maesa, Paolo Mori, Laura Ricci · 5 authors
The recent interest for decentralised systems and decentralisation of the control over users’ data brings a shift in the way identities and their information are managed. Self Sovereign Identity (SSI) has been proposed as the next generation paradigm for decentralised identity management. Research on SSI is getting more and more traction, focusing mainly on the management of users’ identifiers and on providing a standard way to express and verify credentials. Instead, this paper focuses on the understanding of the role of trust in SSI and it provides new insight into the trust relationships existing between the different SSI actors. Indeed, the analysis of such roles and the relationships existing between SSI actors reveals that the current paradigm suffers from trust issues between the verifier and the issuer of a verifiable credential. In order to cope this problem, the paper proposes a new multi-layer framework that exploits trust relationships defined by the actors of the SSI standards (verifiers and issuers of verifiable credentials). An implementation of the framework through Solidity smart contracts has been proposed and deployed on both private and public blockchain networks in order to assess its capabilities. In addition, a dataset related to the spread of spam reviews has been exploited to test the benefits and performance of the proposed framework, demonstrating that it is able to improve the reliability of the SSI paradigm in real-world scenario.
Mariia Bakhtina, K. Leung, Raimundas Matulevičius, Ahmed Awad · 5 authors
X-Road is an open-source solution that acts as a data exchange layer and enables secure data exchange between organisations. X-Road serves as the backbone of digital infrastructure in the public sector (e.g., enabling Estonia’s digital public services) and private sector (e.g., enabling clients’ data exchange in the Japanese energy sector). An approach and architecture were recently proposed for the X-Road data exchange systems to move from public key infrastructure (PKI) with centralised certification authorities to decentralised PKI (DPKI). In this paper, we develop a proof of concept for the designed DPKI-based architecture that leverages distributed ledger-based identifiers and verifiable credentials to establish trust between information systems using Hyperledger Indy and Hyperledger Aries. We evaluate the proof of concept implementation against the design and functional requirements. The results show that the proposed system architecture is technically feasible and satisfies the identified design goals and functional requirements. To the best of our knowledge, this paper presents the first open-access system prototype for an organisation’s identity management following self-sovereign identity principles. The presented proof of concept proves that DPKI helps to address some of the scalability issues of PKI, improve control over identity and mitigate replay attacks and a single point of failure in the X-Road system.
Tayeb Kenaza, Sami Messai, Islam Debicha, Mehdi Sehaki
Abstract Electronic Health Records (EHRs) store sensitive and critical patient information, necessitating stringent access control and sharing mechanisms to uphold data security and comply with privacy regulations such as the General Data Protection Regulation (GDPR). In this paper, we propose a comprehensive architecture and a suite of efficient protocols that leverage the synergistic capabilities of blockchain and Interplanetary File System (IPFS) technologies to enable secure access control and sharing of EHRs. Our approach is based on a private blockchain, wherein smart contracts are deployed to enforce control exclusively by patients. By granting patients exclusive control over their EHRs, our solution ensures compliance with personal data protection laws and empowers individuals to manage their health information autonomously. Notably, our proposed architecture seamlessly integrates with existing health provider information systems, facilitating interoperability and effectively addressing security and data heterogeneity challenges. To exhibit the effectiveness of our approach, we developed a prototype implementation utilizing the Ethereum platform, enabling the simulation of diverse scenarios involving access control and health data sharing among healthcare practitioners. Our experimental results demonstrate the scalability, recovery mechanisms, and revocation procedures embedded within our solution, thereby substantiating its efficacy and robustness in real-world healthcare settings. Overall, our study provides a significant contribution towards a secure and interoperable framework for EHR access control and sharing, leveraging patient-centric control mechanisms.
This paper analyzes the current status of the engineering supervision process in construction and infrastructure projects in China. It discusses the existing problems, such as low efficiency of supervision, distorted monitoring data, resource waste, and environmental damage. Based on extensive literature research and combining the consensus mechanism, ECDSA encryption algorithm and so on, the paper proposes the idea of integrating blockchain technology with the engineering supervision process. This includes the decision of blockchain type, the use of digital signature technology to implement responsibility, and the construction of a hybrid blockchain system using the blockchain's consensus mechanism. The paper presents the general design, the design of the system structures, and the design of modules of the system. Through this system, project participants can verify their identities and share sensitive information confidentially, thereby improving the efficiency of supervision work and preventing data forgery, reducing resource waste, decreasing carbon emissions, and minimizing environmental damage.
A promising approach to building a distributed platform for shared data that is unchangeable, trustworthy, dependable, and accessible is blockchainbased drug traceability. The Hyperledger fabric and Hyperledger Besu methodologies are used in this article to provide a complete study and summary of the present state of drug traceability distribution research on the blockchain technology in enterprise platform. The Hyperledger Fabric and Besu blockchainbased platforms satisfy critical requirements for medication traceability, including privacy, reliability, transparency, security, authorisation, authentication, and scalability. Drug supply chain transactions are carried out skill fully and securely by the Hyperledger Fabric blockchain platform among a dispersed network of stakeholders. Various pharmaceutical stakeholder groups comprise this fabricenabled private, permissioned distributed network, which supports the efficient and secure execution of medication in supply chain transactions in enterprise system. This study also explains how blockchain technology is benefiting the healthcare industry while showcasing some of its disruptive aspects that have the potential to alter current enterprise application in drug tracking procedures.
Saeed Ranjbar Alvar, Mohammad Akbari, David Yue, Yong Zhang
In today's digital world, enterprises and individuals are generating massive data that is potentially useful for many data consumers with data driven applications. The emergence of data marketplaces is a step toward helping the data owners to monetize their digital assets and get connected to the potential buyers. The current data marketplaces cannot handle the challenges related to data ownership claims, illegal redistribution, and data ownership traceability. To overcome these problems in a general-purpose market, we propose a marketplace based on watermarking and Non-Fungible Token (NFT) technologies. In the proposed NFT-based marketplace, the owner's data is stored as an NFT where the underlying content of the NFT holds the watermarked data. The watermarked data is obtained by embedding some information about the owners and the buyers into the original data. The embedded information can later be extracted to identify the owner and the buyer of the traded data. Furthermore, the transactions corresponding to the NFT provide verifiable ownership proof and traceable ownership history. A Proof-Of-Concept (POC) implementation of the proposed marketplace that will be integrated within AI-Gallery Data Marketplace service in Huawei Cloud is presented for trading image data. An extensive set of experiments to measure the gas consumption on the blockchain and evaluate the robustness of the watermarked assets against 51 attacks are performed. Finally, a method based on error correction codes is proposed for improving the watermarking robustness in the implemented marketplace. The link for the codes and the POC demo is provided in the appendix.
Stealth addresses are a privacy-enhancing technology that provides recipient anonymity on blockchains. In this work, we investigate the recipient anonymity and unlinkability guarantees of Umbra, the most widely used implementation of the stealth address scheme on Ethereum, and its three off-chain scalability solutions, i.e., Arbitrum, Optimism, and Polygon. Specifically, we define and evaluate four heuristics to uncover the real recipients of stealth payments. We find that for the majority of Umbra payments, it is straightforward to establish the recipient, hence nullifying the benefits of using Umbra. In particular, we identify the real recipient of 48.5%, 25.8%, 65.7%, and 52.6% of all Umbra transactions on the Ethereum main net, Polygon, Arbitrum, and Optimism networks, respectively. Finally, we suggest easily implementable countermeasures to evade our deanonymization and linking attacks.
A large amount of raw data collected by satellites is processed by the production chain to obtain a large amount of product data, of which the secure exchange and storage is of interest to researchers in the field of remote sensing information science. Authentic, secure data is a critical foundation for data analysis and decision-making. And traditional centralized cloud computing systems are vulnerable to attacks, and once the central server is successfully attacked, all data will be lost. Distributed Ledger Technology (DLT) is an innovative computer technology that can ensure information security, traceability and tamper-proof, and can be applied to the field of remote sensing. Although there are many advantages to using DLT in remote sensing applications, there are some obstacles and limitations to its application. Remote sensing data has the characteristics of large data volume, spatiotemporal nature, global and so on, and it is difficult to store and interconnect remote sensing data in the blockchain. To address these issues, this paper proposes a trustworthy and decentralized system using blockchain. The novelty of this paper is to propose a multi-level blockchain architecture in which the system collects remote sensing data and stores it in the Interplanetary File System (IPFS) network, after generating the IPFS hash, the network rehashes the value again and uploads it on the Ethereum chain for public query. Distributed data storage improves data security, supports the secure exchange of information, and improves the efficiency of data management.
Vyacheslav Petrenko, Фариза Тебуева, Igor Struchkov, Sergey Ryabtsev
Objective . The purpose of the work is to increase the efficiency of the functioning of agents of a cyber-physical system in the presence of agents with incorrect or malicious behavior. The goal is achieved by establishing a trusted interaction between agents and quick detection of malicious impact. Method . Trusted interaction is carried out using distributed ledger technology and agent confidence indicators. The novelty of the proposed solution lies in the fact that information about the actions of agents is stored and aggregated using smart contracts at specified time intervals. Each agent keeps a local copy of the agent interaction chain. If several agents interact with each other, then they exchange information stored in their copies of the ledger. Result . To test the proposed method, we implemented it in C++. For the experiments, the scenario of collective perception by agents of a decentralized cyber-physical environment in a specialized simulation program Contiki Cooja was used. Conclusion . The method implemented using the solutions proposed in this work showed higher efficiency than the method based on the dynamic calculation of the confidence index. The proposed solutions can be applied not only in cyber-physical systems, but also in any other systems with decentralized control.
Blockchain-based decentralized identity management provides a promising solution to improve the security and privacy of healthcare systems and make them scalable. Traditional Identity Management Systems are centralized, which makes them single-point-of-failure, vulnerable to attacks and data breaches, and non-scalable. In contrast, decentralized identity management based on the blockchain can ensure secure and transparent access to patient data while preserving privacy. This approach enables patients to control their personal health data while granting permission for medical personnel to access specific information as needed. We propose a decentralized identity management system for healthcare systems named BDIMHS based on a permissioned blockchain with Hyperledger Indy and Hyperledger Aries. We develop further descriptions of required functionalities and provide high-level procedures for network initialization, enrollment, registration, issuance, verification and revocation functionalities. The proposed solution improves data security, privacy, immutability, interoperability, and patient autonomy by using selective disclosure, zero-knowledge proofs, Decentralized Identifiers, and Verifiable Credentials. Furthermore, we discuss the potential challenges associated with implementing this technology in healthcare and evaluate the performance and security of the proposed solution.
Esa Fauzi, Sy Yuliani, Yenie Syukriyah, Azizah Zakiah
Single Sign-On (SSO) is a mechanism that allows users to access various services using a single set of login credentials. However, in SSO implementations, there are still challenges related to security and authentication management, particularly attacks targeting the Identity Provider (IDP). To address this, the use of Non-Fungible Tokens (NFTs) as proof of IDP ownership has been proposed as a solution to enhance security in the authentication mechanism. The utilization of NFTs in SSO with OpenID Connect and OAuth 2.0 has the potential to improve security and convenience in the authentication process due to the unique and non-duplicable nature of NFTs. The results of this research present a model and design of SSO with NFTs on OpenID Connect and OAuth 2.0. An SSO application with login, register, and password recovery features was also developed to provide convenience to users during the login process. The findings conclude that the utilization of NFTs in SSO with OpenID Connect and OAuth 2.0 has the potential to enhance security and convenience in the authentication mechanism. Further research is needed to explore aspects such as scalability, in-depth security analysis, testing in real-world scenarios, improvement of integration and interoperability, as well as comparative analysis with other SSO technologies.
Zhijian Liu, Zihan Shen, Hongfei Wang, Qianjia Zou
With the increasing amount and trading volume, account security has become an issue that people have to consider. The security of Ethereum is discussed in four different aspects. This paper reviews the application of cryptography in Ethereum, including the importance of relevant hash algorithms and digital signature techniques for securing data. The basic structure of the Merkle Tree and the role of its modified data structure, performed in the security mechanism of Ethereum are also analyzed. This paper also analyzes the related Merkle Proof algorithm. Additionally, the definition and working mechanism of Gas in Ethereum are also provided, through which the operating mechanism and creation method of Gas can guarantee the security of Ethereum's processing power. Finally, this paper indicates the underlying vulnerabilities and possible attacks on Bitcoin and Ethereum, including double spending attacks under proof of work and further introduces the related solutions. This paper can provide researchers good references on Ethereum security problem.
Managing and exchanging sensitive information securely is a paramount concern for the scientific and cybersecurity community. The increasing reliance on computing workflows and digital data transactions requires ensuring that sensitive information is protected from unauthorized access, tampering, or misuse. This research paper presents a comparative analysis of three novel approaches for authenticating and securing access to scientific data: SciTokens, Verifiable Credentials, and Smart Contracts. The aim of this study is to investigate the strengths and weaknesses of each approach from trust, revocation, privacy, and security perspectives. We examine the technical features and privacy and security mechanisms of each technology and provide a comparative synthesis with the proposed model. Through our analysis, we demonstrate that each technology offers unique advantages and limitations, and the integration of these technologies can lead to more secure and efficient solutions for authentication and access to scientific data.
Javier Arcenegui, Rosario Arjona, Iluminada Baturone
Ethereum is a dynamic blockchain that grows every day thanks to a community that creates and decides on various of its issues. The community participates through Ethereum Improvement Proposals (EIPs) at many levels, from proposals that describe new standards for the creation of new tokens to proposals that define new ways for the Ethereum main network to generate new blocks. This paper describes how an Ethereum Request for Comments (ERC)-type EIP, the ERC-4519, was proposed last year to standardize the way to define non-fungible tokens (NFTs) representing assets that can generate their own Ethereum addresses and obey users and owners. Advantages provided by ERC-4519 in several use cases are illustrated. The examples show the facilities and the security improvements introduced in the management of both physical and digital assets by their owners and users. Particularly, use cases with physical assets such as IoT devices are illustrated.
Zero-knowledge proof is emerging to enable privacy. Among existing techniques, zk-SNARK (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) [1] supports the shortest verification time and the smallest proof size. However, using zk-SNARK requires the execution of trusted setup ceremony in advance. The trusted setup ceremony generates common reference string (CRS) which is shared with prover and verifier. Currently, an external trusted third party is assumed for trusted setup ceremony, which causes significant security vulnerability in zk-SNARK. In this paper, we propose a blockchain-based protocol of trusted setup ceremony without trusted third party. Three different types of protocols are classified in terms of where to store CRS and how to validate CRS through pairing check. We analyze the protocol complexity of CRS pairing check computations and on-chain storage space.
R Harsha, E Indra, Thirugnana Sambandham, K. Panimozhi
The growth of blockchain over the last ten years has been astounding: from bitcoin to over 2,000 altcoins, and from decentralized electronic payments to programmable transactions, by complicated tokens and smart contracts controlled by autonomous entities. The technological aspects of blockchain are developing at the same time as the new generation of blockchain applications are also developing. This paper considers one such sphere, to develop a decentralized solution for accessing Educational Resources which will alleviate the issues due to the single point of failure of centralized systems, democratize access to educational content and provide a facile experience for users who are not exposed to web3 technologies. This platform was developed by implementing Smart Contracts using Solidity and deploying them on the Ethereum blockchain to store educational resource metadata and files on the Inter Planetary File System (IPFS). Interfacing of blockchain and the frontend is done using the web3.js. The platform is more tenacious and fault-tolerant than systems using a centralized architecture and provides a better user experience by incorporating a search mechanism for the files uploaded to the platform. This paper proposes a decentralized platform that allows users to upload educational resources that can be accessed by others and implemented a file meta-data-based search feature to remove the need for users to remember the IPFS hash of a file.
The Metaverse is rapidly evolving, bringing us closer to its imminent reality. However, the widespread adoption of this new automated technology poses significant research challenges in terms of authenticity, integrity, interoperability, and efficiency. These challenges originate from the core technologies underlying the Metaverse and are exacerbated by its complex nature. As a solution to these challenges, this paper presents a novel framework based on Non-Fungible Tokens (NFTs). The framework employs the Proof-of-Stake consensus algorithm, a blockchain-based technology, for data transaction, validation, and resource management. PoS efficiently consume energy and provide a streamlined validation approach instead of resource-intensive mining. This ability makes PoS an ideal candidate for Metaverse applications. By combining NFTs for user authentication and PoS for data integrity, enhanced transaction throughput, and improved scalability, the proposed blockchain mechanism demonstrates noteworthy advantages. Through security analysis, experimental and simulation results, it is established that the NFT-based approach coupled with the PoS algorithm is secure and efficient for Metaverse applications.
Jesús García-Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio Skármeta
PREPRINT: The increasing user awareness and regulatory framework (e.g., GDPR) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems.<br> Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data.<br> Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by formalizing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations.
The maturing blockchain technology has gradually promoted decentralized data storage from cryptocurrencies to other applications, such as trust management, resulting in new challenges based on specific scenarios. Taking the mobile trust blockchain within a vehicular network as an example, many users require the system to process massive traffic information for accurate trust assessment, preserve data reliably, and respond quickly. While existing vehicular blockchain systems ensure immutability, transparency, and traceability, they are limited in terms of scalability, performance, and security. To address these issues, this paper proposes a novel decentralized vehicle trust management solution and a well-matched blockchain framework that provides both security and performance. The paper primarily addresses two issues: i) To provide accurate trust evaluation, the trust model adopts a decentralized and peer-review-based trust computation method secured by trusted execution environments (TEEs). ii) To ensure reliable trust management, a multi-shard blockchain framework is developed with a novel hierarchical Byzantine consensus protocol, improving efficiency and security while providing high scalability and performance. The proposed scheme combines the decentralized trust model with a multi-shard blockchain, preserving trust information through a hierarchical consensus protocol. Finally, real-world experiments are conducted by developing a testbed deployed on both local and cloud servers for performance measurements.