Blockchain is a decentralized transaction and data management technology first developed for the Bitcoin cryptocurrency. Blockchain technology is gaining popularity due to its core attributes which provides security, anonymity and data integrity without any involvement of third party. Consensus mechanism is a procedure by which all peers in the blockchain network agrees to a common agreement on the current state of the distributed ledger. It plays vital role in increasing efficiency of any blockchain environment. Though we have many consensus mechanisms working currently in different areas but they still lack in parameters like status of validators, latency, node failure etc. In Our proposed algorithm Proof of credibility, we have tried to incorporate all above factors in it. We have also implemented two or more factors of proposed algorithm and have evaluated and compared with existing consensus algorithm. In future research we aim to implement RPoC in any blockchain network and then we will evaluate it in terms of different evaluation parameters such as performance, security, scalability.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Yuzhou Fang, Daoyuan Wu, Yi Xiao, Shuai Wang · 8 authors
A smart contract is a piece of application-layer code running on blockchain ledgers and it provides programmatic logic via transaction-based execution of pre-defined functions. Smart contract functions are by default invokable by any party. To safeguard them, the mainstream smart contract language, i.e., Solidity of the popular Ethereum blockchain, proposed a unique language-level keyword called “modifier,” which allows developers to define custom function access control policies beyond the traditional “protected” and “private” modifiers in classic programming languages.
The new power system is an energy interconnection network based on renewable energy generation. Information interconnection, data security, and reliability are the basis for the digital transformation of the power grid. Data sharing, lifecycle management, security, and user information privacy are issues that need to be addressed urgently. This paper analyzes the characteristics of the multi-combination of power grid data across services and introduces smart contract, cross-chain, and security encryption-related technologies. Based on the effective combination of smart contract and CP-ABE, data sharing schemes, including data sharing mechanism and data access control model are designed. Given this scheme, the blockchain system’s overall architecture is proposed, including the main chain, side chain, data sharing, and cross-chain information interaction. Finally, the underlying blockchain service platform is built using the Hyperledger open-source framework. We deploy the platform to verify the feasibility of the scheme according to the requirements of the data center, trust center, and blockchain-distributed nodes.
Secure data deletion enables data owners to have full control over the erasure of their data stored on local or cloud data centers, and it is essential for preventing data leakage, especially in cloud storage. However, traditional data deletion methods based on unlinking, overwriting, and cryptographic key management are either ineffective in cloud storage or rely on impractical assumptions. In this paper, we introduce SevDel, a secure and verifiable data deletion scheme that utilizes zero-knowledge proofs to achieve verification of the encryption of outsourced data without retrieving the ciphertexts. Meanwhile, the deletion of encryption keys is guaranteed based on Intel SGX. SevDel implements secure interfaces for performing data encryption and decryption in secure cloud storage. It also utilizes smart contracts to enforce the operations of the cloud service provider, ensuring compliance with service level agreements with data owners and imposing penalties on the service provider for disclosing cloud data on its servers. Evaluation using real-world workloads demonstrates that SevDel efficiently achieves data deletion verification and maintains high bandwidth savings.
Communication and information technologies have accelerated the implementation of electronic medical records, but at the same time, have put patient privacy, information security and health data at risk. An alternative to address the problem of security and privacy of medical data is the use of blockchain. Scalability has become one of the biggest challenges facing the development of blockchain-based electronic health records (EHRs). The purpose of this article is to implement and test a scalable blockchain-based EHR management system. For this reason, we present a scalable blockchain-based EHR management architecture. In this paper, we propose an EHR management model based on entities and user roles, adapt, and then implement with Hyperledger Fabric in a two-channel configuration. We develop a prototype in Fabric using a one-and two-channel configuration. We then designed and conducted an experiment to verify the performance of the proposed scheme in terms of scalability improvement. This scalable blockchain-based EHR management solution, such as the Hyperledger Fabric platform, offers a viable alternative to address scalability issues, as well as to protect patient’s privacy and the security of their medical data.
The robustness of critical infrastructure systems is contingent upon the integrity and transparency of their software supply chains. A Software Bill of Materials (SBOM) is pivotal in this regard, offering an exhaustive inventory of components and dependencies crucial to software development. However, prevalent challenges in SBOM sharing, such as data tampering risks and vendors' reluctance to fully disclose sensitive information, significantly hinder its effective implementation. These challenges pose a notable threat to the security of critical infrastructure and systems where transparency and trust are paramount, underscoring the need for a more secure and flexible mechanism for SBOM sharing. To bridge the gap, this study introduces a blockchain-empowered architecture for SBOM sharing, leveraging verifiable credentials to allow for selective disclosure. This strategy not only heightens security but also offers flexibility. Furthermore, this paper broadens the remit of SBOM to encompass AI systems, thereby coining the term AI Bill of Materials (AIBOM). The advent of AI and its application in critical infrastructure necessitates a nuanced understanding of AI software components, including their origins and interdependencies. The evaluation of our solution indicates the feasibility and flexibility of the proposed SBOM sharing mechanism, positing a solution for safeguarding (AI) software supply chains, which is essential for the resilience and reliability of modern critical infrastructure systems.
The integration of cloud computing and big data has revolutionized data storage, processing, and analytics. However, this convergence also presents significant challenges regarding data privacy, security breaches, and compliance with regulatory standards. This paper examines privacy and security concerns in cloud-integrated big data systems through a case study approach, identifying vulnerabilities, mitigation strategies, and best practices. By analyzing real-world implementations across healthcare, finance, and government sectors, this study provides actionable insights for designing more secure cloud-based big data infrastructures. Findings suggest that a combination of cryptographic techniques, decentralized architectures, and adaptive security models significantly enhances system resilience.
The maturation of wireless connectivity, blockchain (distributed ledger technologies), and intelligent systems has fostered a comprehensive ecosystem for the Internet of Things (IoT). However, the growing volume of data generated by IoT devices creates substantial pressure on blockchain storage and computation capabilities, impeding the further development of the IoT ecosystem. Decentralizing data storage across multiple chains and utilizing cross-chain technology for data exchange eliminates the need for expensive centralized infrastructure, lowers data transfer costs, and improves accessibility. Hence, the issue of computational and storage pressure in blockchain can be improved. Nonetheless, the data of IoT devices are constantly updating, and ensuring consistency for dynamic data across heterogeneous chains remains a significant challenge. To address the aforementioned challenge, we propose a blockchain-based distributed and lightweight data consistency verification model (BDCA), which leverages a batch verification dynamic Merkle hash tree (BV-MHT) and an advanced gamma multi-signature scheme (AGMS) to enable consistent verification of dynamic data while ensuring secure and private data transmission. The AGMS scheme is reliable and robust based on security analysis while the dependability and consistency of BDCA are verified through inductive reasoning. Experimental results indicate that BDCA outperforms CPVPA and Fortress in communication and computation overhead for data preprocessing and auditing in a similar condition, and the AGMS scheme exhibits superior performance when compared to other widely adopted multi-signature schemes such as Cosi, BLS, and RSA. Furthermore, BDCA provides up to 99% data consistency guarantees, demonstrating its practicality.
The benefit of using blockchain technology for information system security in the field of education is that all entered data cannot be easily faked, lost, or damaged. With blockchain, one can also communicate data and information instantly and be decentralized without depending on third parties. Blockchain is a distributed ledger that effectively and efficiently records transactions between two parties in a verifiable and everlasting way. Yet, even though blockchain technology has not yet been applied extensively in the field of education Yet, to meet the goals of this study and produce results that apply to the field of education, researchers attempt to assess the security of information systems in education using fingerprints by integrating cryptographic hash security sensors. These topics and the SWOT analysis used in this research approach will be explored.
Bitcoin is an electronic cryptocurrency developed based on Blockchain technology. With its decentralized feature, it has become incredibly popular since its invention. However, the Bitcoin network suffers from 51% attacks, where if malicious attackers’ control over half of the computing power, they are able to rewrite the network. The attackers are capable of doing so by initiating the Eclipse attack first, which aims to monopolize all communications from and to a controlled Bitcoin node. In this paper, we model and analyze the dependability of the Bitcoin network subject to the Eclipse and 51% attacks. We propose a hierarchical model that encompasses a continuous-time Markov chain method for the node-level dependability analysis and a multi-valued decision diagram method for the system-level dependability analysis. Detailed case studies on Bitcoin systems with homogeneous and heterogeneous nodes are conducted to demonstrate the proposed model and investigate the impacts of several critical parameters on Bitcoin network dependability.
Distributed Ledger Technologies (DLTs) and blockchain systems are used in various higher-level departments, government sectors and commercial industries. This article reviews how DLTs and blockchain systems work with IOT devices and how it provides security and scalability. The metaverse sets a new standard for social media sites and 3D virtual spaces. Moreover, the key aim of the virtual world is to safeguard the metadata of IOT customers. Additionally, crypto is an effective solution due to its openness, data integrity, and accountability characteristics. So, we review the two new burning technologies of crypto and the virtual world from a methodological perspective, i.e. data collection, saving data, allocation, integration, and data confidentiality are all aspects of data management. By each strategy, in this article, we discuss the methodological techniques of the meta chain and then investigate the potential benefits of blockchain technology. Further, we analyze how blockchain will influence other critical enabling technologies in the metaverse's service world, such as the IOT.
Tao Huang, Renchao Xie, Yuzheng Ren, F. Richard Yu · 10 authors
In recent years, the Industrial Internet and Industry 4.0 came into being. With the development of modern industrial intelligent manufacturing technology, digital twins, Web3 and many other digital entity applications are also proposed. These applications apply architectures such as distributed learning, resource sharing, and arithmetic trading, which make high demands on identity authentication, asset authentication, resource addressing, and service location. Therefore, an efficient, secure, and trustworthy Industrial Internet identity resolution system is needed. However, most of the traditional identity resolution systems follow DNS architecture or tree structure, which has the risk of a single point of failure and DDoS attack. And they cannot guarantee the security and privacy of digital identity, personal assets, and device information. So we consider a decentralized approach for identity management, identity authentication, and asset verification. In this paper, we propose a distributed trusted active identity resolution system based on the inter-planetary file system (IPFS) and non-fungible token (NFT), which can provide distributed identity resolution services. And we have designed the system architecture, identity service process, load balancing strategy and smart contract service. In addition, we use Jmeter to verify the performance of the system, and the results show that the system has good high concurrent performance and robustness.
Lattice-based cryptography is one of the most promising candidates for designing post-quantum cryptographic algorithms that resist emerging quantum computing attacks. The recent NIST PQC standardization process is nearing its completion, with practical lattice-based algorithms for basic cryptographic functionalities (namely digital signature and public-key encryption) selected for standardization in the near future. However, practical lattice-based solutions for more advanced privacy-preserving protocols, in particular, Zero-Knowledge Proofs (ZKPs), have only emerged recently and are an active area of research. We discuss some recent developments in design and analysis of practical lattice-based post-quantum ZKPs and their applications. In particular, we review some challenges that arise in designing ZKPs in the lattice setting and some recent progress on efficient lattice-based Schnorr-like proofs for important relations, such as binary/range proofs, one-out-of-many proofs and rounding proofs [1, 2, 4]. We discuss applications and optimization of such proof systems as building blocks for practical advanced cryptographic protocols such as ring signatures and balance proofs for privacy-preserving cryptocurrency payment protocols [2, 3]. We also discuss our recent work on succinct designated-verifier ZKPs (DV-ZKSNARKS) for verifying correctness of general delegated computations [5].
Saeed Banaeian Far, Azadeh Imani Rad, Maryam Rajabzadeh Asaar
Without a doubt, the blockchain is one of the most valuable technological advancements to have been introduced over the past decade and has played a significant role in the industrial revolution. The emergence of technologies derived from blockchain, such as decentralized finance (DeFi) and the Metaverse, has fundamentally transformed people's daily lives and profoundly impacted future versions of digital businesses. This study explored the evolution of digital businesses in the near future, with a specific focus on the two primary technologies mentioned above. First, we reviewed DeFi-based technologies, including GameFi, SciFi, SocialFi, and others, which serve as foundational building blocks for future jobs and businesses. Second, we examined Metaverse-based jobs, such as Metaverse-based academies and markets, which are expected to be launched as commonly used businesses. Ultimately, this study provides several guidelines, such as how to use DeFi 2.0 and apply centralized decentralized finance (CeDeFi)-based platforms. Additionally, it offers future directions for launching these businesses, including controlling the progress of artificial intelligence (AI) in practical applications, utilizing cloud-assisted models for the Metaverse, and providing conditional privacy for future Metaverse-based businesses.
Xiaowan Wang, Huiyin Xie, Shan Ji, Liang Liu · 5 authors
The rapid development of the Internet and Internet of Things has rapidly introduced human society into the information age, and the way of fake news production has been updated, which has greatly affected the normal life of human beings. In order to identify worthless fake news and trace massive fake news data from unknown sources, and share valuable news data to fully disseminate effective real news, news owners usually store news data in cloud. Users of IoT terminals can access news data on demand without storing it locally. However, the authenticity of the fictive newspaper numbers source, which is easy to destroy, and the social media platform. Besides, when massive news data is saved on cloud server, the news owners have to at the risk of lose physical control over news data and it will face the risk of fake news being disseminated and real news being falsified. Thus, this paper proposes a novel mechanism for secure storage of news data using blockchain technology. Firstly, traceability and verification of fake news data is improved by the cooperative storage model on and off the chain. Secondly due to the inability of past polynomial commitment to update the commitment, we will be a hindrance to use polynomial commitment to build a secure authentication protocol. Therefore, in this paper, we design the update algorithm for polynomial commitment in order to be able to guarantee the consistency of on-chain and blockchain database news data.
Tal Derei, Benjamin Aulenbach, Victor Carolino, Caleb Geren · 8 authors
Zero-Knowledge proofs are a cryptographic technique to reveal knowledge of information without revealing the information itself, thus enabling systems optimally to mix privacy and transparency, and, where needed, regulatability. Application domains include health and other enterprise data, financial systems such as central-bank digital currencies, and performance enhancement in blockchain systems. The challenge of zero-knowledge proofs is that, although they are computationally easy to verify, they are computationally hard to produce. This paper examines the scalability limits of leading zero-knowledge algorithms and addresses the use of parallel architectures to meet performance demands of applications.
Blockchain is also known as Distributed Ledger Technology (DLT) and real transparencies of the history of digital assets by decentralization and encryption. It guarantees that the user's data never be erased, making it impossible to alter or falsify. Some people know that the "Blockchain revolution" can be compared with the internet and the web in their early days. As a result, all software development around blockchain is growing incredibly. Most software engineers are interested in blockchain technologies as they rush to develop unregulated software. Although some research has been performed on blockchain security and privacy concerns, a thorough analysis state of blockchain security is lacking. This article explores current problems and new principles for blockchain-oriented software engineering (BOSE) and discusses the need for new software engineering practices in the blockchain industry. Also, examine the solutions to improve blockchain protection, which might have been used to develop different blockchain applications, and suggest a few potential directions for moving research into this area.
Summary Every transaction is made public and verified by a third party, and the transparency of blockchain applications leads to privacy leaks. Everyone can access the transaction, making it easier for network analysis to identify the user's identity, which is a major problem with the blockchain. Financial institutions have become hesitant to adopt blockchain technology; as a result, preventing its spread. To confirm that encryption and security are maintained for transactions in the blockchain, this research introduces a zero‐knowledge proof (ZKP) based transaction validation scheme. To increase the security of blockchain applications, the proposed lattice‐based blind ring signature (LBRS) scheme integrates blind and ring signatures and is applied to sensitive data. The data are encrypted using this encryption scheme before being stored with the transactional information in the blocks. The encrypted data is then stored in the blocks, which users can retrieve after verification. The encrypted data is then stored in blocks, which users can retrieve after verification. A verification scheme based on the ZKP is used to prevent unauthorized access and changes to the data. The proposed LBRS scheme meets the security analysis requirement. The performance of an LBRS scheme is compared to other relevant models in terms of execution time, encryption time, and decryption time. Overall, the results are more encouraging and reassuring than other relevant works of interest. Finally, this model provides better computational security and satisfies the requirements like correctness and security analysis.
<strong>Blockchain technology is a distributed ledger system that is secured by cryptography. This makes it very difficult to tamper with or hack blockchain-based transactions. Additionally, blockchain can be used to automate transactions, which can save time and money. This paper explores the potential of blockchain technology to revolutionize the way we make transactions. We discuss the benefits of blockchain technology, such as its security, efficiency, and transparency. We also discuss the challenges of blockchain technology, such as its scalability and regulation. We conclude that blockchain technology has the potential to make transactions more secure, efficient, and transparent. However, there are still challenges to overcome before blockchain technology can be widely adopted.</strong>
Khaled Ahmed, Sabry F. Saraya, John F. Wanis, Hesham Ali
Open finance is evolving and extending open banking. This creates a large context that implies a financial and identity data exchange paradigm, which faces challenges to balance customer experience, security, and the self-control over personal identity information. We propose Self-Sovereign Banking Identity (SSBI), a Blockchain-based self-sovereign identity (SSI) to secure private data sharing by utilizing trusted customer’s banking cards as a key storage and identity transaction-signing enclave. The design and implementation of the SSI framework is based on the Veramo SDK and Ethereum to overcome the limitation of signing curve availability on the current banking Java Cards needed for Hyperledger Indy. SSBI uses the elliptic curve SECP256K1 for transaction signing, which exists for several payment cards in the market. SSBI enables automated financial services and trust in the service provider communication. This work analyzes the flow and framework components, and evaluates the usability, integration, and performance in terms of throughput, latency, security, and complexity. Furthermore, the proposed approach is compared with related solutions. The presented prototype implementation is based on a test Ethereum network and signing transactions on the banking card. The preliminary results show that SSBI provides an effective solution for integrating the customer’s banking cards to secure open banking identity exchange. Furthermore, it allows the integration of several scenarios to support trusted open banking. The Blockchain layer settings need to be scaled and improved before real-world implementation.
Chihiro Kado, Naoto Yanai, Jason Paul Cruz, Kyosuke Yamashita · 5 authors
Vulnerabilities of Ethereum smart contracts often cause serious financial damage. Whereas the Solidity compiler has been updated to prevent vulnerabilities, its effectiveness has not been revealed so far, to the best of our knowledge. In this paper, we shed light on the impact of compiler versions of vulnerabilities of Ethereum smart contracts. To this end, we collected 503,572 contracts with Solidity source codes in the Ethereum blockchain and then analyzed their vulnerabilities. For three vulnerabilities with high severity, i.e., Locked Money, Using tx.origin, and Unchecked Call, we show that their appearance rates are decreased by virtue of major updates of the Solidity compiler. We then found the following four key insights. First, after the release of version 0.6, the appearance rate for Locked Money has decreased. Second, regardless of compiler updates, the appearance rate for Using tx.origin is significantly low. Third, although the appearance rate for Unchecked Call has decreased in version 0.8, it still remains high due to various factors, including code clones. Fourth, through analysis of code clones, our promising results show that the appearance rate for Unchecked Call can be further decreased by removing the code clones.
With the development of cloud services and the Internet of Things, the integration of heterogeneous systems is becoming increasingly complex. Identity management is important in the coordination of various systems, and public key infrastructure (PKI) is widely known as an identity management methods. In PKI, a certificate authority (CA) acts as a trust point to guarantee the identity of entities such as users, devices, and services. However, traditional CAs that delegate the operations to a specific organization are not always suitable for heterogeneous services, and a new methodology is required to enable multiple stakeholders to securely and cooperatively operate a CA. In this study, we introduce the concept of a consortium CA and propose a distributed public key certificate-issuing infrastructure that realizes a consortium CA. The proposed infrastructure enables multiple organizations to cooperatively operate a CA suitable for services involving multiple stakeholders. We identify four requirements for the cooperative operation of a consortium CA and design the proposed infrastructure with distributed ledger technology. Furthermore, we present the implementation of smart contracts with Hyperledger Fabric and prove that the proposed infrastructure satisfies the four requirements. Finally, we confirm that certificate issuance and verification are stable at approximately 4 and 3 ms, respectively.
Matteo Loporchio, Anna Bernasconi, Damiano Di Francesco Maesa, Laura Ricci
Set accumulators are cryptographic primitives used to represent arbitrarily large sets of elements with a single constant-size value and to efficiently verify whether a value belongs to that set. Accumulators support the generation of membership proofs, meaning that they can certify the presence of a given value among the elements of a set. In this paper we present an overview of the theoretical concepts underlying set accumulators, we compare the most popular constructions from a complexity perspective, and we survey a number of their applications related to blockchain technology. In particular, we focus on four different use cases: query authentication, stateless transactions validation, anonymity enhancement, and identity management. For each of these scenarios, we examine the main problems they introduce and discuss the most relevant accumulator-based solutions proposed in the literature. Finally, we point out the common approaches between the proposals and highlight the currently open problems in each field.