Haya R. Hasan, Khaled Salah, Raja Jayaraman, Junaid Arshad · 7 authors
COVID-19 has emerged as a highly contagious disease which has caused a devastating impact across the world with a very large number of infections and deaths. Timely and accurate testing is paramount to an effective response to this pandemic as it helps identify infections and therefore mitigate (isolate/cure) them. In this paper, we investigate this challenge and contribute by presenting a blockchain-based solution that incorporates self-sovereign identity, re-encryption proxies, and decentralized storage, such as the interplanetary file systems (IPFS). Our solution implements digital medical passports (DMP) and immunity certificates for COVID-19 test-takers. We present smart contracts based on the Ethereum blockchain written and tested successfully to maintain a digital medical identity for test-takers that help in a prompt trusted response directly by the relevant medical authorities. We reduce the response time of the medical facilities, alleviate the spread of false information by using immutable trusted blockchain, and curb the spread of the disease through DMP. We present a detailed description of the system design, development, and evaluation (cost and security analysis) for the proposed solution. Since our code leverages the use of the on-chain events, the cost of our design is almost negligible. We have made our smart contract codes publicly available on Github.
Bruno Rodrigues, Trendafilov Spasen, Eder J. Scheid, Burkhard Stiller
Distributed Denial-of-Service (DDoS) attacks remains as one of the major causes of concerns for service providers around the world. This paper introduces SC-FLARE, a Smart Contract (SC) based cooperative signaling protocol built on top of a Ethereum Proof-of-Authority Blockchain (BC) for the sharing of attack information, the exchange of incentives, and the tracking of reputation in a fully distributed and automated fashion. By making use of BC and SC, SC-FLARE provide the required collaborative platform without the burden to maintain, design, and develop special registries and gossip protocols for a cooperative defense.
Purpose Cryptocurrency markets are notoriously noisy, but not all markets might behave in the exact same way. Therefore, the aim of this paper is to investigate which one of the cryptocurrency markets contributes the most to the common volatility component inherent in the market. Design/methodology/approach The paper extracts each of the cryptocurrency's markets' latent volatility using a stochastic volatility model and, subsequently, models their dynamics in a fractionally cointegrated vector autoregressive model. The authors use the refinement of Lien and Shrestha (2009, J. Futures Mark) to come up with unique Hasbrouck (1995, J. Finance) information shares. Findings The authorsâ findings indicate that Bitfinex is the leading market for Bitcoin and Ripple, while Bitstamp dominates for Ethereum and Litecoin. Based on the dominant market for each cryptocurrency, the authors find that the volatility of Bitcoin explains most of the volatility among the different cryptocurrencies. Research limitations/implications The authorsâ findings are limited by the availability of the cryptocurrency data. Apart from Bitcoin, the data series for the other cryptocurrencies are not long enough to ensure the precision of the authorsâ estimates. Originality/value To date, only price discovery in cryptocurrencies has been studied and identified. This paper extends the current literature into the realm of volatility discovery. In addition, the authors propose a discrete version for the evolution of a markets fundamental volatility, extending the work of Dias et al. (2018).
Contracts are obligations that involve multiple parties and stakeholders. Road - Toll collection contracts have certain guidelines and rules for collection of toll tax from vehicles against the use of constructed roads. Representation of such rules for collection of toll taxes using a smart contract, which is a paradigm based on blockchain, will solve some of the drawbacks of current toll collection and management system. The proposed methodology uses the strengths of blockchain to propose a solution to the current toll tax collection system, by ensuring complete transparency between tax payers and collectors and also attempts to curb the malicious collection of taxes from commuters. Blockchain will enable a radical way of approaching transactions as compared to the traditional society approved method where trust is placed on a central third party to carry out transactions. The purpose of this paper is to provide a alternative method of processing toll tax transactions, using ethereum based smart contracts, written in solidity language, to transform traditional desktop applications into blockchain based web application, which perform better, consume lesser resources and are much more secure as compared to the current system.
Additive Manufacturing (AM) is a major advancement in the digitization of manufacturing and production operations. Additive manufacturing uses three dimensional digital design, software and hardware equipment to precisely deposit layered materials for on-demand product manufacturing. The distinct advantages in enabling additive manufacturing includes cost efficiency, reduced time-to-market, flexibility and precise customization. However, several challenges such as trusted traceability, certification for quality compliance, and protecting intellectual property need to be addressed. Blockchain-based distributed ledgers provide tremendous advantages for product traceability and ensure trust among participating stakeholders. In this paper, we propose a blockchain-based solution for product traceability produced using additive manufacturing, guaranteeing secure and trusted traceability, accessibility, and immutability of transactions, and data provenance among supply chain stakeholders. Our proposed solution utilizes Ethereum smart contracts to govern and trace transactions initiated by participants involved in the manufacturing process. Decentralized storage of Inter-Planetary File Systems is used to store and share design files, IoT device records, and additional product specifications. We provide the system architecture, implementation, and detailed algorithms that demonstrate the working principles of our proposed solution for secure AM. Furthermore, we present detailed security and cost analysis of the solution highlighting its efficiency with respect to key security and performance requirements.
Denna studie undersöker huruvida avsiktligt implementerad friktion inom interaktionsdesign kan minska antal anvÀndarfel vid insatsprocessen för blockkedjor med Proof-of-Stake teknik. Friktion som avsiktligt implementerats har tidigare visats kunna leda till fÀrre anvÀndarfel. Det spekuleras i att blockkedjor kan komma att anvÀndas i större utstrÀckning i framtiden. Eftersom fel i insatsprocessen för en blockkedja med Proof-of-Stake teknik kan leda till att pengar gÄr förlorade valdes det omrÄdet för att undersökas nÀrmare om friktion kan leda till fÀrre anvÀndarfel. Studien avgrÀnsas till en typ av avsiktlig friktion som kallas design for pauses som syftar till att fÄ anvÀndaren att tillfÀlligt stanna upp med sin interaktion. I studien skapades tvÄ versioner av en prototyp pÄ en insatsprocess till blockkedjan Ethereum som testades pÄ tvÄ olika testgrupper. Ena versionen av prototypen innehöll avsiktligt implementerad friktion och i den andra versionen adderades ingen friktion avsiktligt. Deltagarna i testet ombads utföra insatsprocessen i prototypen dÀr deras interaktioner granskades och statistik fördes pÄ antal anvÀndarfel. AnvÀndarfelen delades upp i tvÄ kategorier: slarvfel och misstag. Resultaten frÄn testerna visar pÄ att avsiktlig friktion av typen design for pauses minskar antal anvÀndarfel av typen misstag. Ytterligare forskning krÀvs för att besvara om design for pauses kan bidra till att minska antal anvÀndarfel av typen slarvfel.
Designed for commercial decentralized applications (DApps), EOSIO is a Delegated Proof-of-Stake (DPoS) based blockchain system. It has overcome some shortages of the traditional blockchain systems like Bitcoin and Ethereum with its outstanding features (e.g., free for usage, high throughput and eco-friendly), and thus becomes one of the mainstream blockchain systems. Though there exist billions of transactions in EOSIO, the ecosystem of EOSIO is still relatively unexplored. To fill this gap, we conduct a systematic graph analysis on the early EOSIO by investigating its four major activities, namely account creation, account vote, money transfer and contract authorization. We obtain some novel observations via graph metric analysis, and our results reveal some abnormal phenomenons like voting gangs and sham transactions.
Ăkos Hajdu, Naghmeh Ivaki, Imre Kocsis, Attila Klenik · 8 authors
Blockchain has become particularly popular due to its promise to support business-critical services in very different domains (e.g., retail, supply chains, healthcare). Blockchain systems rely on complex middleware, like Ethereum or Hyperledger Fabric, that allow running smart contracts, which specify business logic in cooperative applications. The presence of software defects or faults in these contracts has notably been the cause of failures, including severe security problems. In this paper, we use a software implemented fault injection (SWIFI) technique to assess the behavior of permissioned blockchain systems in the presence of faulty smart contracts. We emulate the occurrence of general software faults (e.g., missing variable initialization) and also blockchain-specific software faults (e.g., missing require statement on transaction sender) in smart contracts code to observe the impact on the overall system dependability (i.e., reliability and integrity). We also study the effectiveness of formal verification (i.e., done by solc-verify) and runtime protections (e.g., using the assert statement) mechanisms in detection of injected faults. Results indicate that formal verification as well as additional runtime protections have to complement built-in platform checks to guarantee the proper dependability of blockchain systems and applications. The work presented in this paper allows smart contract developers to become aware of possible faults in smart contracts and to understand the impact of their presence. It also provides valuable information for middleware developers to improve the behavior (e.g., overall fault tolerance) of their systems.
Aufgrund des Hypes um Bitcoin und Cryptocurrencys haben Blockchains in den letzten Jahren viel Aufmerksamkeit erhalten. Aber Cryptocurrencys sind bei weitem nicht die einzige Anwendung der Blockchaintechnologie. Smart Contract, also Applikationen die nach vordefinierten und unverĂ€nderbaren Regeln agieren, stellen eine weitere Anwendung dar. Solche Smart Contracts benötigen jedoch spezielle Platformen um ausgefĂŒhrt werden zu können: so gennante Smart Contract Platforms. Die momentan meistverwendete Plattform is Ethereum, aber es gibt weitere Plattformen die interessante Alternativen darstellen. Eine vielversprechende dieser möglichen Alternativen is NEO. NEO ist in vielen Belangen Ă€hnlich zu Ethereum, aber verspricht gleichzeitig einige Probleme zu lösen, mit denen sich Ethereum momentan konfroniert sieht wie zum Beispiel die schlechte Skalierbarkeit. Literatur, die sich mit den Unterschieden zwischen Ethereum and NEO befasst, ist spĂ€rlich. Vor allem NEO wird in der Literatur selten berĂŒcksichtigt, und falls NEO behandelt wird, dann passiert dies in der Regel nur oberflĂ€chlich. AuĂerdem haben die meisten Vergleiche und Evaluierungen von Smart Contract Plattformen beziehungsweise von Blockchains keine strukturierte Herangehensweise, sondern verwenden unterschiedliche Kriterien fĂŒr unterschiedliche Plattformen. Das bedeutet, dass die meiste Literatur zu diesem Thema eine Ăbersicht der Plattformen darstellt, aber wenig Hilfe bei der Auswahl von Smart Contract Plattformen liefert. Diese Arbeit schlieĂt diese LĂŒcke, indem sie einen detalierten Vergleich von Ethereum und NEO durchfĂŒhrt. Um eine strukturierte Herangehensweise zu gewĂ€hrleiten, wird in dieser Arbeit ein Kriterienkatalog basierend auf Kritierien in wissenschaftlicher Literatur abgeleitet. Dieser Kriterienkatalog wird anschlieĂend auf die beiden Plattformen Ethereum und NEO angewandt um die fĂŒr den Vergleich notwendigen Daten zu erhalten, die dazu dienen, die relevanten Gemeinsamkeiten und Unterschiede zwischen Ethereum und NEO zu identifieren. Des weiteren ermöglicht dies eine Diskussion ĂŒber die Auswirkungen dieser Unterschiede. Die Ergebnisse der Arbeit zeigen, dass obwohl Ethereum und NEO auf den ersten Blick sehr Ă€hnlich zu sein scheinen, diese doch markante Unterschiede aufweisen. Die Unterschiede reichen vom allgemeinen Ziel der Plattform ĂŒber die Reife der Dokumentation und Plattformfeatures bis hin zu praktischen Kritierien wie den Kosten fĂŒr die Erstellung von Smart Contracts.
This research proposes a new method of data synchronization between public blockchain networks and local machines. We discussed the proposed algorithm, and the mathematical model which achieves the shortest delay required for data synchronization. Tests were conducted to verify the correctness of the proposed model. Then a comparison is made with the current available classical synchronization methods. Suggested method may be useful for future DApps applications on Ethereum network.
Seit der EinfĂŒhrung der Peer-to-Peer WĂ€hrung Bitcoin sind viele Ă€hnliche Projekte vorgestellt worden. Ein beliebtes Projekt heiĂt Ethereum, welches erlaubt, Smart Contracts in seinem Netzwerk einzusetzen. Diese Contracts können von NutzerInnen entwickelt werden, um die FĂ€higkeit von Ethereum zu erweitern. Um mit diesem System interagieren zu können, wird eine Client-Software benötigt, die Blockchain-Daten herunterlĂ€dt und anschlieĂend validiert. Als Blockchain wird die Datenstruktur bezeichnet, welche alle getĂ€tigten Transaktionen im Netzwerk speichert. Da eine groĂe Menge an Daten kontinuierlich generiert werden, ist Ethereum auf schwĂ€cheren Computern nicht mehr einsetzbar. Aus diesem Grund vertraut man sich einer Drittpartei an, dass die heruntergeladenen Daten valide sind, um den zeitaufwendigen Validierungschritt zu umgehen. Eine Alternative, die nicht die Validierung aller Daten benötigt, wird Simplified Payment Verification (SPV) genannt, welche nur ein Teil der Blockchain verarbeiten muss. Software dieser Art nennt man auch Light Clients. Allerdings ist auch dieses Verfahren zu rechenintensiv fĂŒr Ethereum. Erst vor Kurzem wurde ein kryptografisches Verfahren namens FlyClient vorgestellt, welches eine schnellere Validierung verspricht. Jedoch existiert bislang noch keine praktische Implementierung. Es stellt sich also die Frage, wie man die Validierung der Ethereum Blockchain auf schwĂ€cheren Computern wieder ermöglichen kann. Eine Motivation liegt in der praktischen Anwendung, wie beispielsweise Zahlungen per Smartphone tĂ€tigen zu können. Bei sicherheitsrelevanten Anwendungen ist es von Vorteil, nicht von einer Drittpartei abhĂ€ngig zu sein. Das Ziel dieser Arbeit ist daher die systematische Untersuchung von existierenden Verfahren, um Light Clients zu entwickeln. Der Fokus liegt besonders auf einer Schonung von Systemressourcen und die Vermeidung einer Drittpartei. Es werden existierende Ethereum Anwendungen und deren inbegriffenen Sicherheitsannahmen untersucht. Ein Ethereum Light Client Prototyp wird entwickelt, welcher den FlyClient-Ansatz verwendet. Es wird gezeigt, dass mit einer einfachen Modifikation der Ethereum Blockchain Light Clients entwickelt werden können, die: (1) Payment Channels unterstĂŒtzen, (2) eine effiziente Verifikation der Blockchain ermöglichen, (3) in einer dezentralen Art und Weise arbeiten, (4) hohe Sicherheitsgarantien bieten, und (5) auf schwĂ€cheren Computern, wie Smartphones oder IoT-GerĂ€ten, eingesetzt werden können.
In this research, the evolution of Distributed Ledger Technology (DLT) in supply chains has been mapped from the inception of the technology until June 2020, utilising primarily public data sources. Two hundred seventy-one blockchain projects operating in the supply chain have been analysed on parameters such as their inception dates, types of blockchain, stages reached, sectors applied to and type of organisation that founded the project. We confirm generally understood trends in the blockchain market with the creation of projects following the general hype and funding levels in the industry. We observe most activity in the Agriculture/Grocery sector and the Freight/Logistics sector. We see the shift of market interest from primarily private companies (startups) to public companies and consortia and the change in blockchain adoption from Ethereum to Hyperledger. Finally, we observe higher success and lower failure rates for Hyperledger-based projects in comparison to Ethereum-based projects.
The paper presents a model for decentralizing building information modelling, through implementing its infrastructure using the decentralized web. We discuss the shortcomings of BIM in terms of its infrastructure, with a focus on tracing identities of design authorship in this collective design tool. In parallel we examine the issues with BIM in the cloud and propose a decentralized infrastructure based on the Ethereum blockchain and the Interplanetary filesystem (IPFS). A series of computing nodes, that act as nodes on the Ethereum Blockchain, host disk storage with which they participate in a larger storage pool on the Interplanetary Filesystem. This storage is made available through an API is used by architects and designers creating and editing a building information model that resides on the IPFS decentralised storage. Through this infrastructure central servers are eliminated, and BIM libraries and models can be shared with others in an immutable and transparent manner. As such Architecture practices are able to exploit their intellectual property in novel ways, by making it public on the internet. The infrastructure also allows the decentralised creation of a resilient global pool of data that allows the participation of computation agents in the creation and simulation of BIM models.
OAuth 2.0 is the industry-standard protocol for authorization. It facilitates secure service provisioning, as well as secure interoperability among diverse stakeholders. All OAuth 2.0 protocol flows result in the creation of an access token, which is then used by a user to request access to a protected resource. Nevertheless, the definition of access tokens is transparent to the OAuth 2.0 protocol, which does not specify any particular token format, how tokens are generated, or how they are used. Instead, the OAuth 2.0 specification leaves all these as design choices for integrators. In this paper, we propose a new type of OAuth 2.0 token backed by a distributed ledger. Our construction is secure, and it supports proof-of-possession, auditing, and accountability. Furthermore, we provide added-value token management services, including revocation, delegation, and fair exchange by leveraging smart contracts. We realized a proof-of-concept implementation of our solution using Ethereum smart contracts and the ERC-721 token specification.
Chunmiao Li, Shijie Nie, Yang Cao, Yijun Yu · 5 authors
Smart contracts on Ethereum can be used to encode business logic and have been applied to many different areas, such as token exchanges and games. Unlike general programs, the computations of contracts on Ethereum are restricted by the gas limit. If a transaction runs out of the gas limit before an execution finishes, the Ethereum virtual machine throws an out-of-gas exception, and the entire transaction fails, which reverts to the state before the transaction started, although the transaction fee is still deducted. It is therefore, essential to conduct a gas estimation before sending a transaction. Existing studies have mostly failed in estimating the gas for a loop function because the number of iterations of the loops cannot be statically determined. However, we found that a quarter of all contracts have loop functions, and the gas cost for the loops is higher than for the other functions. Therefore, it is necessary to apply a gas estimation for the loop functions. In this study, we propose a gas estimation approach based on the transaction trace to dynamically estimate the gas for the loop functions. Our belief is that we can learn the relationship between the historical transaction traces and their gas costs to estimate the gas for new transactions. We considered three different abstractions of the original transaction trace and fed them to different machine learning models. The results show that our approach is effective in gas estimation and that a random forest can achieve the most accurate estimation.
Ethereum is a decentralized blockchain technology equipped with so-called Smart Contracts. A contract is a program whose code is public, which can be triggered by any user, and whose actual execution is performed by miners participating in Ethereum. Miners execute the contract on the Ethereum Virtual Machine (EVM) and apply its effect by adding new blocks to the blockchain. A contract that takes too much time to be processed by the miners of the network may result into delays or a denial of service in the Ethereum system. To prevent this scenario, termination of Ethereum's Smart Contracts is ensured using a gas mechanism. Roughly, the EVM consumes gas to process each instruction of a contract and the gas provided to run a contract is limited. This technique could make termination of contracts easy to prove but the way the official definition of the EVM specifies gas usage makes the proof of this property non-trivial. EVM implementations and formal analysis techniques of EVM's Smart Contracts use termination of contracts as an assumption, so having a formal proof of termination of contracts is crucial. This paper presents a mechanized, formal, and general proof of termination of Smart Contracts based on a measure of EVM call stacks.
Blockchains are being recently used as a supporting technology framework for decentralized applications requiring functionalities such as exchange of value through tokens, cryptocurrency and smart contracts. In this paper, we have developed a decentralized application model in Python, where blockchain data are stored in a Neo4j graph database. Following the basic principles of Ethereum blockchain network, we implemented a Casper-like consensus mechanism and tested its effectiveness in achieving finality. For block proposing, we employed both Proof of Work and Proof of Stake protocols and examined how participants' incentives and consensus criteria differ according to each one. A major part of this work is to incorporate the graph model in the functionality of the blockchain and its components, while also exploiting its benefits in data analysis by finding relationships between data and extracting their true value. Through this approach, we were able to monitor and visualize changes in blockchain data in various use case scenarios. Lastly, we ran a series of simulated experiments to test the efficiency of the implemented technologies and mechanisms in preventing the most common blockchain attacks such as the 51% Attack, Catastrophic Crashes and Attack from dynamic validator sets. We show how the modelling of the blockchain data as a distributed graph can assist protocols operations, enhance their security, and facilitate the application of analytical methods to the stored information through path-dependent queries.
In modern healthcare systems, the ability to share electronic health records is crucial for providing quality care and for enabling a larger spectrum of health services. Health data sharing is dependent on obtaining individual consent which, in turn, is hindered by a lack of resources. To this extent, blockchain-based platforms facilitate data sharing by creating a trusted distributed network of users. These users are enabled to share their data without depending on the time and resources of specific actors (such as the health services). In blockchain-based platforms, data governance mechanisms become very important due to the need to specify and monitor data sharing and data use conditions. In this article, we present a blockchain-based data-sharing consent model for access control over individual health data. We use smart contracts to dynamically represent the individualâs consent over health data and to enable data requesters to search and access those data. The dynamic consent model extends to two ontologies: the Data Use Ontology (DUO) which models the individual consent of users and the Automatable Discovery and Access Matrix (ADA-M), which describes queries from data requesters. We deploy the model on Ethereum blockchain and evaluate different data sharing scenarios. The contribution of this article consists of the creation of an individual consent model for health data sharing platforms. Such a model guarantees that individual consent is respected and that all the participants in the data sharing platform are accountable. The evaluation of our solution indicates that such a data sharing model provides a flexible decision-making approach over data usage by data requesters. Our experimental evaluation shows that the proposed model is efficient and adapts to personalized access control policies in different data-sharing scenarios.
Recently, researchers around the world in medical institutions and pharmaceutical companies are demanding a wider access to healthcare data for secondary use in order to provide enhanced and personalized medical services. For this purpose, healthcare information exchange between health authorities can be leveraged as a fundamental concept to meet these demands and enable the discovery of new insights and cures. However, health data are highly sensitive and private information that requires strong authentication and authorization procedures to manage the access to them. In this regard, the cloud paradigm has been used in these e-healthcare solutions, but they remain inefficient due to their inability to adapt to the expanding volume of data generated from body sensors and their vulnerability against cyberattacks. Hence, collaborative and distributed data governance supported by edge computing and blockchain promises enormous potentials in improving the performance and security of the whole system. In this paper, we present a secure and efficient data management framework, named âEdgeMediChainâ, for sharing health data. The proposed architecture leverages both edge computing and blockchain to facilitate and provide the necessary requirements for a healthcare ecosystem in terms of scalability, security, as well as privacy. The Ethereum-based testbed evaluations show the effectiveness of EdgeMediChain in terms of execution time with a reduction of nearly 84.75% for 2000 concurrent transactions, higher throughput compared to a traditional blockchain, and scalable ledger storage with a linear growth rate.