The higher education management systems first identified and realized the trap of pitting innovation against privacy while first addressing COVID-19 social isolation challenges in 2020. In the age of data sprawl, we observe the situation has been exacerbating since then. Integrating blockchain technology has the potential to address the recent and emerging challenges in the higher education management system. This paper unravels the Good (scopes and benefits), Bad (limitations), and Ugly (challenges and trade-offs) of blockchain technology integration in the higher education management paradigm in the existing landscape. Our study adopts both qualitative and quantitative approaches to explore the experiences of educators, researchers, students, and other stakeholders and fully understand the blockchain's potential and contextual challenges. Our findings will envision an efficient, secure, and transparent higher education management system and help shape the debate (and trade-offs) pertaining to the recent shift in relevant business and management climate and regulatory sentiment.
As the significance of blockchain innovation grows and the focus on scalability intensifies, rollup technology has emerged as a promising approach to tackle these scalability concerns. Nonetheless, rollups encounter restrictions when interacting with other rollups, leading to diminished throughput, increased latency, higher fees, and a complex user experience in transactions between rollups. In this paper, we put forth a novel system that employs batch settlement techniques to augment the efficiency of transfers between rollups. Our proposed system comprises a settlement rollup responsible for batch settling transfers among rollups and a smart contract structure that carries out the settlements. Notably, we utilize a zero-knowledge proof algorithm to guarantee the computational integrity of the settlement rollup while ensuring security through Ethereum smart contracts for proof verification and settlement execution. By implementing this approach, the proposed system can effectively and securely execute asset transfers between rollups, ultimately improving their scalability and usability. Consequently, our research provides a fresh perspective on resolving the challenges of throughput, latency, and fees associated with transfer systems.
Joonyoung Lee, Myeonghyun Kim, Kisung Park, Sungkee Noh · 7 authors
Recently, with the increasing application of the Internet of Things (IoT), various IoT environments such as smart factories, smart homes, and smart grids are being generated. In the IoT environment, a lot of data are generated in real time, and the generated IoT data can be used as source data for various services such as artificial intelligence, remote medical care, and finance, and can also be used for purposes such as electricity bill generation. Therefore, data access control is required to grant access rights to various data users in the IoT environment who need such IoT data. In addition, IoT data contain sensitive information such as personal information, so privacy protection is also essential. Ciphertext-policy attribute-based encryption (CP-ABE) technology has been utilized to address these requirements. Furthermore, system structures applying blockchains with CP-ABE are being studied to prevent bottlenecks and single failures of cloud servers, as well as to support data auditing. However, these systems do not stipulate authentication and key agreement to ensure the security of the data transmission process and data outsourcing. Accordingly, we propose a data access control and key agreement scheme using CP-ABE to ensure data security in a blockchain-based system. In addition, we propose a system that can provide data nonrepudiation, data accountability, and data verification functions by utilizing blockchains. Both formal and informal security verifications are performed to demonstrate the security of the proposed system. We also compare the security, functional aspects, and computational and communication costs of previous systems. Furthermore, we perform cryptographic calculations to analyze the system in practical terms. As a result, our proposed protocol is safer against attacks such as guessing attacks and tracing attacks than other protocols, and can provide mutual authentication and key agreement functions. In addition, the proposed protocol is more efficient than other protocols, so it can be applied to practical IoT environments.
The privacy and security of patients' health records have been an ongoing issue, and researchers are in a race against technology to design a system that can help stop the compromising of patient data. Many researchers have proposed solutions; however, most solutions have not incorporated potential parameters that can ensure private and secure personal health records management, which is the focus of this study. To design and develop a solution, this research thoroughly investigated existing solutions and identified potential key contexts. These include IOTA Tangle, Distributed Ledger Technology (DLT), IPFS protocols, Application Programming Interface (API), Proxy Re-encryption (PRE), and access control, which are analysed and integrated to secure patient medical records, and Internet of Things (IoT) medical devices, to develop a patient-based access management system that gives patients full control of their health records. This research developed four prototype applications to demonstrate the proposed solution: the web appointment application, the patient application, the doctor application, and the remote medical IoT device application. The results indicate that the proposed framework can improve healthcare services by providing immutable, secure, scalable, trusted, self-managed, and traceable patient health records while giving patients full control of their own medical records.
The metaverse gradually evolves into a virtual world containing a series of interconnected sub-metaverses. Diverse digital resources, including identities, contents, services, and supporting data, are key components of the sub-metaverse. Therefore, a Domain Name System (DNS)-like system is necessary for efficient management and resolution. However, the legacy DNS was designed with security vulnerabilities and trust risks due to centralized issues. Blockchain is used to mitigate these concerns due to its decentralized features. Additionally, it supports identity management as a default feature, making it a natural fit for the metaverse. While there are several DNS alternatives based on the blockchain, they either manage only a single type of identifiers or isolate identities from other sorts of identifiers, making it difficult for sub-metaverses to coexist and connect with each other. This article proposes a M ulti- I dentifier management and resolution S ystem (MIS) in the metaverse, supporting the registration, resolution, and inter-translation functions. The basic MIS is portrayed as a four-tier architecture on a consortium blockchain due to its manageability, enhanced security, and efficiency properties. On-chain data is lightweight and compressed to save on storage while accelerating reading and writing operations. The resource data is encrypted based on the attributes of the sub-metaverse in the storage tier for privacy protection and access control. For users with decentralization priorities, a modification named EMIS is built on top of Ethereum. Finally, MIS is implemented on two testbeds and is available online as the open-source system. The first testbed consists of 4 physical servers located in the UK and Malaysia while the second is made up of 200 virtual machines (VMs) spread over 26 countries across all 5 continents on Google Cloud. Experiments indicate that MIS provides efficient reading and writing performance than the legacy DNS and other public blockchain-based workarounds including EMIS and Ethereum Name Service (ENS).
Blockchain proposes many innovative technologies to establish credible mechanisms in an open environment and therefore, it becomes a promising solution to the problem of credibility in educational development. To better understand the role of the blockchain, we aim to provide an extensive survey focusing on its key technology, application potential, and performance evaluation. First, from the perspective of blockchain characteristics, we summarize its application architecture in educational credibility. Next, we extensively discuss application potential of the blockchain, such as data storage, data sharing, achievement certification, and activity evaluation. Moreover, we investigate the performance evaluation, including basic performance metrics and specialized metrics for credibility. Finally, we analyze the challenges and research trends of blockchain in educational credibility and provide useful insights for future research.
Jonathan Heiss, Tahir Oegel, Mehran Shakeri, Stefan Tai
<p>In face of the ongoing climate change, both reduction and offsetting of carbon emissions are critical. To this end, accurate, reliable emission data, and service-oriented architectures for processing the data are needed. Current carbon accounting practices, however, are often error-prone, costly, and time-consuming. Even in digital monitoring, reporting and verification (MRV) systems, the employment of single, trusted verification bodies inhibits transparent, fine-granular, and verifiable accounting on product instance-level in high-throughput supply chains. We propose Verifiable Carbon Accounting (VCA) as a novel accounting approach that leverages authenticity and zero-knowledge proofs in service-oriented architectures for creating non-disclosing emission reports that are peer-to-peer verifiable on blockchains. VCA builds upon and extends both conventional and digital MRV systems but ensures the confidentiality of business emission data and calculations while allowing for peer-to-peer transparency and verifiability. We introduce the concept and demonstrate VCA application for accounting product carbon footprints (PCFs) in supply chains. We present a proof-of-concept technical system design and implementation and discuss experimental findings, deriving both insights on VCA practicability and next steps. Overall, we show how VCA advances the state of art in carbon accounting in and beyond supply chains, and how VCA can serve as the basis for next-generation, accurate carbon accounting.</p>
Muhammad Zalkifal Khan, Maham Nadeem, Mohammad Kaleem, Sajid Nazir
Blockchain technology is poised to transform the data storage and data interchange models. A blockchain is a distributed ledger of transactions stored across a network of nodes. This decentralized model provides immutability and traceability of the records and is known as Distributed Ledger Technology (DLT). In the implemented healthcare system, we used a decentralized blockchain based peer to peer architecture ensuring data security, availability, and reliability. We leverage the Substrate framework, part of Polkadot ecosystem for building blockchains. Once the patient logs into their profile, they are able to view their medical history along with any doctor’s prescriptions and laboratory reports. When the doctor accesses a patient’s profile, they can make new entries to the medical records and prescriptions. In addition, we show that a tamper-proof record of the healthcare assets can be securely maintained, and accessible to the authorized entities.
Aditya Pribadi Kalapaaking, Ibrahim Khalil, Mohammed Atiquzzaman
The widespread adoption of Internet of Things (IoT) devices in smart cities, intelligent healthcare systems, and various real-world applications have resulted in the generation of vast amounts of data, often analyzed using different Machine Learning (ML) models. Federated learning (FL) has been acknowledged as a privacy-preserving machine learning technology, where multiple parties cooperatively train ML models without exchanging raw data. However, the current FL architecture does not allow for an audit of the training process due to the various data-protection policies implemented by each FL participant. Furthermore, there is no global model verifiability available in the current architecture. This paper proposes a smart contract-based policy control for securing the Federated Learning (FL) management system. First, we develop and deploy a smart contract-based local training policy control on the FL participants' side. This policy control is used to verify the training process, ensuring that the evaluation process follows the same rules for all FL participants. We then enforce a smart contract-based aggregation policy to manage the global model aggregation process. Upon completion, the aggregated model and policy are stored on blockchain-based storage. Subsequently, we distribute the aggregated global model and the smart contract to all FL participants. Our proposed method uses smart policy control to manage access and verify the integrity of machine learning models. We conducted multiple experiments with various machine learning architectures and datasets to evaluate our proposed framework, such as MNIST and CIFAR-10.
Flavio Corradini, Alessandro Marcelletti, Andrea Morichetta, Andrea Polini · 6 authors
In modern business scenarios, more and more organisations have to deal with the critical requirements of trustworthiness and flexibility, when collaborating in multi-party business processes. This calls for new kinds of systems able to manage collaborative processes in untrusted and dynamic environments. Concerning the collaborative perspective, the Business Process Management discipline has provided effective and standardised solutions for a long time, now. Regarding the trustworthiness perspective, blockchain is advocated as one of the most prominent technologies to guarantee trust in a multi-party setting. However, while the immutability of blockchain provides transparent and secure proof of past business interactions, it hinders the flexibility of the business process execution, as the business logic regulating the process execution is immutably stored in the blockchain. On the other hand, flexibility is a property that is becoming crucial in such a setting due to the high dynamism of the business scenarios. In fact, it permits to modify a process at run-time to deal with internal or external changes. In this paper, we face this issue by proposing an architecture for the flexible blockchain-based execution of multi-party business processes. In our approach, business processes are modelled by BPMN choreography diagrams translated into code, whose execution state is then stored in the blockchain. Flexibility is achieved by decoupling the business process’s logic from its execution state, thus allowing run-time changes to the process execution without losing the fundamental properties of trust provided by the blockchain. To show the effectiveness of our approach, we provide a prototypical implementation, called FlexChain, and we use it on a case study from the healthcare application domain. The results obtained by the analysis of cost for the reported case study show the feasibility of the approach. In particular, major costs to sustain relate to one-time operations, such as the deployment and the run-time update of the model, while the most frequent actions are quite efficient.
In recent years decentralized currencies developed through Blockchains are increasingly becoming popular because of their transparent nature and absence of a central controlling authority. Though a lot of computation power, disk space, and energy are being used to run this system, most of these resources are dedicated to just keeping the bad actors away by using Proof of Work, Proof of Stake, Proof of Space, etc., consensus. In this paper, we discuss a way to combine those consensus mechanism and modify the defense system to create actual values for the end-users by providing a solution for securely storing their data in a decentralized manner without compromising the integrity of the blockchain.
Danda Prudhvi Krishna, R. Ramaguru, K. Praveen, M. Sethumadhavan · 7 authors
OAuth2.0 is a Single Sign-On approach that helps to authorize users to log into multiple applications without re-entering the credentials. Here, the OAuth service provider controls the central repository where data is stored, which may lead to third-party fraud and identity theft. To circumvent this problem, we need a distributed framework to authenticate and authorize the user without third-party involvement. This paper proposes a distributed authentication and authorization framework using a secret-sharing mechanism that comprises a blockchain-based decentralized identifier and a private distributed storage via an interplanetary file system. We implemented our proposed framework in Hyperledger Fabric (permissioned blockchain) and Ethereum TestNet (permissionless blockchain). Our performance analysis indicates that secret sharing-based authentication takes negligible time for generation and a combination of shares for verification. Moreover, security analysis shows that our model is robust, end-to-end secure, and compliant with the Universal Composability Framework.
Remote Health Monitoring (RHM) is going to reinvent the future healthcare industry and bring about abundant value to hospitals, doctors, and patients by overcoming the many challenges currently being faced in monitoring patient's well-being, promoting preventive care, and managing the quality of drugs and equipment. Despite the many benefits of RHM, it is yet to be widely deployed due to the healthcare data security and privacy challenges. Healthcare data are highly sensitive and require fail-safe measures against unauthorized data access, leakages, and manipulations, and as such, there are stringent regulations governing how healthcare data can be secured, communicated, and stored, such as General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA). The challenges and regulatory demands in RHM applications can be addressed using blockchain technology due to its distinguishing features of decentralization, immutability, and transparency to address the challenges of data security and privacy. This article will provide a systematic review on the use of blockchain in RHM, focusing primarily on data security and privacy.
Kelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen Sollins
Software repositories, used for wide-scale open software distribution, are a significant vector for security attacks. Software signing provides authenticity, mitigating many such attacks. Developer-managed signing keys pose usability challenges, but certificate-based systems introduce privacy problems. This work, Speranza, uses certificates to verify software authenticity but still provides anonymity to signers using zero-knowledge identity co-commitments. In Speranza, a signer uses an automated certificate authority (CA) to create a private identity-bound signature and proof of authorization. Verifiers check that a signer was authorized to publish a package without learning the signer's identity. The package repository privately records each package's authorized signers, but publishes only commitments to identities in a public map. Then, when issuing certificates, the CA issues the certificate to a distinct commitment to the same identity. The signer then creates a zero-knowledge proof that these are identity co-commitments. We implemented a proof-of-concept for Speranza. We find that costs to maintainers (signing) and end users (verifying) are small (< 1 ms), even for a repository with millions of packages. Techniques inspired by recent key transparency systems reduce the bandwidth for serving authorization policies to 2 KiB. Server costs in this system are negligible. Our evaluation finds that Speranza is practical on the scale of the largest software repositories. We also emphasize practicality and deployability in this project. By building on existing technology and employing relatively simple and well-established cryptographic techniques, Speranza can be deployed for wide-scale use with only a few hundred lines of code and minimal changes to existing infrastructure. Speranza is a practical way to bring privacy and authenticity together for more trustworthy open-source software.
The first cryptocurrency was invested in 2008/09, but the Blockchain-Web3 concept is still in its infancy, and the cyber risk is constantly changing. Our cybersecurity should also be adapting to these changes to ensure security of personal data and continuation of business for organisations. This review paper starts with a comparison of existing cybersecurity standards and regulations from the National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) - ISO27001, followed by a discussion on more specific and recent standards and regulations, such as the Markets in Crypto-Assets Regulation (MiCA), Committee on Payments and Market Infrastructures and the International Organisation of Securities Commissions (CPMI-IOSCO), and more general cryptography and post-quantum cryptography, in the context of cybersecurity. These topics are followed up by a review of recent technical reports on cyber risk/security and a discussion on cloud security questions. Comparison of Blockchain cyber risk is also performed on the recent EU standards on cyber security, including European Cybersecurity Certification Scheme (EUCS) – cloud, and additional US standards – The National Vulnerability Database (NVD) Common Vulnerability Scoring System (CVSS). The study includes a review of Blockchain endpoint security, and new technologies e.g., IoT. The research methodology applied is a review and case study analysing secondary data on cybersecurity. The research significance is the integration of knowledge from the United States (US), the European Union (EU), the United Kingdom (UK), and international standards and frameworks on cybersecurity that can be alighted to new Blockchain projects. The results show that cybersecurity standards are not designed in close cooperation between the two major western blocks - US and EU. In addition, while the US is still leading in this area, the security standards for cryptocurrencies, internet-of-things, and blockchain technologies have not evolved as fast as the technologies have. The key finding from this study is that although the crypto market has grown into a multi-trillion industry, the crypto market has also lost over 70% since its peak, causing significant financial loss for individuals and cooperation’s. Despite this significant impact to individuals and society, cybersecurity standards and financial governance regulations are still in their infancy.
A smart contract is a special form of computer program that runs on a blockchain and provides a new way to implement financial and business transactions in a conflict-free and transparent environment. In blockchain systems such as Ethereum, smart contracts can handle and autonomously transfer assets of considerable value to other parties. Hence, it is particularly important to ensure that smart contracts function as intended since bugs or vulnerabilities may lead, and indeed have led, to substantial economic losses and erosion of trust for blockchain. While a number of approaches and tools have been developed to find vulnerabilities, formal methods present the highest level of confidence in the security of smart contracts. In this paper, we propose a formal solution to model a smart contract based on colored Petri nets (CPNs). Herein, we focus on the most common type of security bugs in smart contract, i.e., reentrancy bugs, which led to a serious financial loss of around USD 34 million for the Cream Finance project in 2021. We present a hierarchical CPN modelling method to analyze potential security vulnerabilities at the contract’s source code level. Then, modeling analysis methods such as correlation matrix, state space report and state space graph generated via CPN Tools simulation are exploited for formal analysis of smart contracts. The example shows the full state space and wrong path in accordance with our expected results. Finally, the conclusion was verified on the Ethereum network based on the Remix platform.
Zhiqiang Du, W. Jiang, Chenguang Tian, Xiaofeng Rong · 5 authors
Cloud computing is a disruptive technology that has transformed the way people access and utilize computing resources. Due to the diversity of services and complexity of environments, there is widespread interest in how to securely and efficiently authenticate users under the same domain. However, many traditional authentication methods involve untrusted third parties or overly centralized central authorities, which can compromise the security of the system. Therefore, it is crucial to establish secure authentication channels within trusted domains. In this context, we propose a secure and efficient authentication protocol, HIDA (Hyperledger Fabric Identity Authentication), for the cloud computing environment. Specifically, by introducing federated chain technology to securely isolate entities in the trust domain, and combining it with zero-knowledge proof technology, users’ data are further secured. In addition, Subsequent Access Management allows users to prove their identity by revealing only brief credentials, greatly improving the efficiency of access. To ensure the security of the protocol, we performed a formal semantic analysis and proved that it can effectively protect against various attacks. At the same time, we conducted ten simulations to prove that the protocol is efficient and reliable in practical applications. The research results in this paper can provide new ideas and technical support for identity authentication in a cloud environment and provide a useful reference for realizing the authentication problem in cloud computing application scenarios.
Kealan Dunnett, Shantanu Pal, Zahra Jadidi, Raja Jurdak
CTI sharing is increasingly used by organisations to strengthen security. The sensitivity of CTI has led to research on trust-based sharing, yet most existing CTI sharing approaches only support static trust-based decisions or centralised trust evaluation, limiting their scalability and lead to centralised risk. This paper proposes a blockchain-based CTI sharing framework that relies on trustless delegates for dynamic trust-based decision-making and decentralised trust evaluation. To facilitate trustless delegation, our proposal allows CTI producers to intentionally inject false data on a periodic basis into the system to audit the behaviour of delegates. Moreover, unlike existing approaches, delegates within our framework facilitate sharing of CTI directly with consumers such that scalable CTI sharing occurs. The results of a qualitative evaluation of the proposed framework's security show that it is resilient to common privacy and trust concerns. Moreover, a quantitative evaluation of a proof-of-concept prototype using Ethereum show that the proposed framework is scalable and cost-effective.
Marco Di Francesco, Lodovica Marchesi, Raffaele Porcu
Trading data sets is not easy. The owner of valuable data, once they are sold the first time, cannot be sure that they will not be copied and resold. On the other hand, the buyer, cannot be sure that the seller will not sell the same data to a competitor. The advent of blockchain technology, or DLT, can mitigate, or event solve these issues, because it can certify the data ownership, and act as a broker between seller and buyer. In this paper we present Kryptosafe, a system developed following sound software engineering practices, aimed to manage the trade of data sets taking advantage of the unique features of immutability and trustfulness of Ethereum blockchain, and of IPFS distributed DBMS. Kryptosafe allows data sellers to sell a whole encrypted data set or to show potential buyers a subset of it, allowing full access only after the sale is finalized. Using ERC721 and ERC1155 tokens, it also manages one-time sales, when the data set ownership is simply transferred to the buyer, or multiple sales of the same data set to different buyers.
To prevent DoS attacks, Ethereum assigns a fixed gas cost to every atomic operation in the EVM and the party who creates a transaction has to pay for its overall gas usage. While the gas model is successful in preventing DoS attacks, it causes significant costs in transaction fees. For example, in June-September 2022, the average daily gas usage of Ethereum was almost four million dollars. We propose a solution to minimize these fees by moving most of the execution of a contract off-chain and storing only the bare minimum on-chain. We then trigger an on-chain execution only if there is a disagreement between the parties to the contract, which is in turn only possible if at least one party is acting dishonestly. In such cases, our approach can identify and penalize the dishonest party by making them pay not only for the gas usage of their own function calls, but also calls made by other parties. Thus, it is game-theoretically irrational to behave dishonestly in this protocol. If all parties are rational, the total gas usage goes down significantly. Notably, our approach does not require a sidechain and works directly on the main Ethereum blockchain. We also provide extensive experiments over real-world Ethereum smart contracts, demonstrating that our protocol reduces their gas usage by 40.09%.
saving the patient medical record electronically is done via electronic medical records (EMRs) where all the patient-related information that consider private and sensitive is usually related to the treatment process, as well as the diagnoses process of a specific patient usually this information needs to be shared and re-submit by many peers doctors with each, In this paper, propose a novel approach for electronic medical records system using a non-fungible token (NFT) based on a customized permission blockchain built with secret sharing technology to reduce the key management overhead as well as provide a readable extension of the ledger to ensure it is easy to read and easy access from any type of computer. The system that uses NFT for electronic medical records (NFT-EMR) ensures easy access and guarantees availability, privacy, and security providing authority to the patient over his data as well as proof of ownership which is done using proof of secret shares and consistency this system can be used in real-world between hospitals and medical centers and within metaverse world. The NFT-ERM system was evaluated using the main evaluation factors used to evaluate blockchain and compared to the standard ERM system.
Quratulain Arshad, Wazir Zada Khan, Faisal Azam, Muhammad Khurram Khan · 6 authors
Abstract Internet of Things (IoT) vision has astoundingly transcended environmental sensing with integrated computing systems and smart devices, providing seamless connectivity among humans, machines, and their environment to cooperate for convenience and economical benefits. Apart from all the tremendous benefits of IoT, this paradigm still suffers from challenges of security and privacy vulnerabilities and demands a secure system for effective utilization of services in real-world IoT scenarios relying on which the IoT consumers expect secure and trustworthy communications. Trust Management (TM), which is a crucial aspect of security, plays a vital role in ensuring the exchange of information in a secure manner and maintaining the reliability of a system by measuring the degree of trust on IoT devices, reducing the uncertainties and risks involved in the systems. Thus, in recent years, Blockchain technology has been utilized for developing security innovations in TM field for different classes of IoT applications. It can provide tamper-proof data by enabling more reliable trust information and integrity verification, ultimately enhancing its availability and privacy when storing and sharing information. This paper provides a comprehensive survey that aims at analyzing and assessing Blockchain-based decentralized trust management systems (BCDTMS) for IoT. The contributions of this study are threefold; first, we provide the comprehensive and comparative analysis of state-of-the-art BCDTMS devised for different IoT classes such as Internet of Medical of Things (IoMT), Internet of Vehicles (IoV), Industrial IoT (IIoT), and Social IoT (SIoT). To make it an extensive study, we perform a detailed assessment of the existing BCDTMS in the literature in the aspects of Blockchain and TM. Second, we present requirements for developing Blockchain-based TM systems for IoT, and third we have highlighted the challenges in the context of using Blockchain for TM in various IoT applications.
Abstract The audiovisual media content (AMC) industry, focused on film and television drama production, is confronted with a broken business model due to the dominance of centralized streaming platforms. The top platforms dominate global distribution but only offer slices of produced and heritage content. In addition, they compete with the AMC industry by producing a majority of content distributed. This leaves fewer gatekeepers deciding on the content to be distributed and less diverse content easily accessible to audiences Consequently, audiences are compelled to engage in pirating movies despite a willingness to pay. Recent blockchain innovations towards the so-called Web3 promise to restore this broken business model by re-establishing direct contact between the producers of films and their audiences. The benefits of networks (peer-to-peer or community based) in combination with Web3 follow the principle of decentralized disintermediation while comprising elements such as FIAT to crypto-payment mechanisms, self-sovereign identity authentication, blockchain oracles, decentralized autonomous organizations (DAO), and so on. A gap exists with regard to methodological designs of Web3 decentralized applications (DApp) and their ecosystems for restoring a viable AMC business model that not only eliminates the need for piracy activities but even the need for platforms. The DApp architecture designs for the film- and media industry ecosystem creation in this paper allow, on the one hand, for a legal compliance check ahead of a costly deployment. On the other hand, the DApp designs of this paper also allow for a tailored blockchain technology stack development. Ultimately, this research is a continuation of an earlier whitepaper to establish a participatory economy in the film industry from peer-to-peer streaming.
Abstract Blockchain and Decentralized Applications (DApps) are increasingly important for creating trust and transparency in data storage and computation. However, on-chain transactions are often costly and slow. To overcome this challenge, off-chain nodes can be used to store and compute data. Unfortunately, this introduces the risk of untrusted nodes. To address this, authenticated data structures have been proposed, however, this ignores the compute of data from the raw data. We tackle this challenge by introducing zk-Oracle, which provides an efficient and trusted compute and storage off-chain. There is a challenge in using zero-knowledge proofs (zk-proof for short), which is the large proof generation time. We aim to overcome it with novel designs in zk-Oracle. zk-Oracle builds on zk-proofs technologies to achieve two goals. First, the computation of data structures from raw data and the corresponding proof generation is improved in terms of performance. Second, the verification on-chain is inexpensive and fast. Our experiments show that we can speed up zk-proof generation by up to $$550 \times $$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mn>550</mml:mn> <mml:mo>×</mml:mo> </mml:mrow> </mml:math> faster than the baseline method.