For the modern world where data is becoming one of the most valuable assets,\nrobust data privacy policies rooted in the fundamental infrastructure of\nnetworks and applications are becoming an even bigger necessity to secure\nsensitive user data. In due course with the ever-evolving nature of newer\nstatistical techniques infringing user privacy, machine learning models with\nalgorithms built with respect for user privacy can offer a dynamically adaptive\nsolution to preserve user privacy against the exponentially increasing\nmultidimensional relationships that datasets create. Using these privacy aware\nML Models at the core of a Federated Learning Ecosystem can enable the entire\nnetwork to learn from data in a decentralized manner. By harnessing the\never-increasing computational power of mobile devices, increasing network\nreliability and IoT devices revolutionizing the smart devices industry, and\ncombining it with a secure and scalable, global learning session backed by a\nblockchain network with the ability to ensure on-device privacy, we allow any\nInternet enabled device to participate and contribute data to a global privacy\npreserving, data sharing network with blockchain technology even allowing the\nnetwork to reward quality work. This network architecture can also be built on\ntop of existing blockchain networks like Ethereum and Hyperledger, this lets\neven small startups build enterprise ready decentralized solutions allowing\nanyone to learn from data across different departments of a company, all the\nway to thousands of devices participating in a global synchronized learning\nnetwork.\n
Muqaddas Naz, Fahad Ahmed Al-Zahrani, Rabiya Khalid, Nadeem Javaid · 7 authors
In a research community, data sharing is an essential step to gain maximum knowledge from the prior work. Existing data sharing platforms depend on trusted third party (TTP). Due to the involvement of TTP, such systems lack trust, transparency, security, and immutability. To overcome these issues, this paper proposed a blockchain-based secure data sharing platform by leveraging the benefits of interplanetary file system (IPFS). A meta data is uploaded to IPFS server by owner and then divided into n secret shares. The proposed scheme achieves security and access control by executing the access roles written in smart contract by owner. Users are first authenticated through RSA signatures and then submit the requested amount as a price of digital content. After the successful delivery of data, the user is encouraged to register the reviews about data. These reviews are validated through Watson analyzer to filter out the fake reviews. The customers registering valid reviews are given incentives. In this way, maximum reviews are submitted against every file. In this scenario, decentralized storage, Ethereum blockchain, encryption, and incentive mechanism are combined. To implement the proposed scenario, smart contracts are written in solidity and deployed on local Ethereum test network. The proposed scheme achieves transparency, security, access control, authenticity of owner, and quality of data. In simulation results, an analysis is performed on gas consumption and actual cost required in terms of USD, so that a good price estimate can be done while deploying the implemented scenario in real set-up. Moreover, computational time for different encryption schemes are plotted to represent the performance of implemented scheme, which is shamir secret sharing (SSS). Results show that SSS shows the least computational time as compared to advanced encryption standard (AES) 128 and 256.
Smart contracts are appealing because they are self-executing business agreements between parties with the predefined and immutable obligations and rights. However, as with all software, smart contracts may contain vulnerabilities because of design flaws, which may be exploited by one of the parties to defraud the others. In this paper, we demonstrate a systematic approach to building secure design models for smart contracts using formal methods. To build the secure models, we first model the behaviors of participating parties as state machines, and then, we model the predefined obligations and rights of contracts, which specify the interactions among state machines for achieving the business goal. After that, we illustrate executable secure model design patterns in TLA+ (Temporal Logic of Actions) to against well-known smart contract vulnerabilities in terms of state machines and obligations and rights at the design level. These vulnerabilities are found in Ethereum contracts, including Call to the unknown, Gasless send, Reentrancy, Lost in the transfer, and Unpredictable state. The resultant TLA+ specifications are called secure models. We illustrate our approach to detect the vulnerabilities using a real-estate contract example at the design level.
The proliferation of unreliable and biased information is a significant\nproblem on the Internet. To assess the credibility of the information retrieved\nfrom news websites and other sources, users often resort to social platforms\nlooking for confirmation with trustworthy parties. However, users may be faced\nwith considerable obstacles posed by the platform provider, who can prevent\naccess to certain content. This paper presents DClaims, a system that provides\na censorship-resistant distributed service for the exchange of information over\nthe Internet using web annotations. DClaims' fully decentralized architecture\nrelies on Inter-Planetary File System (IPFS) and Ethereum blockchain, both of\nwhich offer desirable censorship resistant properties. DClaims is implemented\nas a web annotations browser extension which allows for the classification of\nnews articles, on news websites. From our evaluation of the system, we conclude\nthat a large scale implementation of the system is practical and economically\nviable.\n
Vero Estrada-Galiñanes, Racin Nygaard, Viktor Trón, Rodrigo Q. Saramago · 6 authors
Blockchain is the driving force behind a myriad of decentralized applications (dapps) that promise to transform the Internet. The next generation Internet, or web3, introduces a "universal state layer" to store data in p2p networks. Swarm, a native layer of the Ethereum web3 stack, aims at providing redundant storage for dapp code, data, as well as, blockchain and state data. Based on a diploma verification dapp use case, we share insights on the role of redundancy strategies in designing a reliable storage layer. Our proof-of-concept improves Swarm's resilience to failures by balancing repairs and storage, with a slightly added latency.
Charlie Hou, Mingxun Zhou, Yan Ji, Phil Daian · 7 authors
Incentive mechanisms are central to the functionality of permissionless blockchains: they incentivize participants to run and secure the underlying consensus protocol. Designing incentive-compatible incentive mechanisms is notoriously challenging, however. As a result, most public blockchains today use incentive mechanisms whose security properties are poorly understood and largely untested. In this work, we propose SquirRL, a framework for using deep reinforcement learning to analyze attacks on blockchain incentive mechanisms. We demonstrate SquirRL's power by first recovering known attacks: (1) the optimal selfish mining attack in Bitcoin [52], and (2) the Nash equilibrium in block withholding attacks [16]. We also use SquirRL to obtain several novel empirical results. First, we discover a counterintuitive flaw in the widely used rushing adversary model when applied to multi-agent Markov games with incomplete information. Second, we demonstrate that the optimal selfish mining strategy identified in [52] is actually not a Nash equilibrium in the multi-agent selfish mining setting. In fact, our results suggest (but do not prove) that when more than two competing agents engage in selfish mining, there is no profitable Nash equilibrium. This is consistent with the lack of observed selfish mining in the wild. Third, we find a novel attack on a simplified version of Ethereum's finalization mechanism, Casper the Friendly Finality Gadget (FFG) that allows a strategic agent to amplify her rewards by up to 30%. Notably, [10] show that honest voting is a Nash equilibrium in Casper FFG: our attack shows that when Casper FFG is composed with selfish mining, this is no longer the case. Altogether, our experiments demonstrate SquirRL's flexibility and promise as a framework for studying attack settings that have thus far eluded theoretical and empirical understanding.
The integration of Internet of Things (IoT) and cloud services with edge technologies has enabled the development of many new types of edge services, which leverage blockchain features for cross-organizational, traceable and verifiable records. However, developing such edge services with blockchain features requires not only knowledge about complex blockchain technologies but also how blockchain technologies coexist with edge computing service models and architectures and deployments. In the context of edge service development, coupling edge systems, software models for edge services and blockchain technologies is complex. Thus, a strong collaboration and knowledge sharing for edge systems and blockchain technologies will help addressing many concerns of the developer. However, there is a lack of frameworks for sharing knowledge about blockchain software artefacts and deployments for edge services. In this paper, we present various types of information linking blockchain performance with service deployments at different levels. We represent and associate benchmarked performance information of blockchain operation and blockchain infrastructural services with common edge service interactions and resource deployments. Based on that, we develop a service offering blockchain knowledge to the developer seeking relevant blockchain operation information for their development decisions. We will present a prototype of our framework with benchmarked information obtained from experiments with Ethereum and Hyperledger.
Solidity is an object-oriented and high-level language for writing smart contracts that are used to execute, verify and enforce credible transactions on permissionless blockchains. In the last few years, analysis of smart contracts has raised considerable interest and numerous techniques have been proposed to check the presence of vulnerabilities in them. Current techniques lack traceability in source code and have widely differing work flows. There is no single unifying framework for analysis, instrumentation, optimisation and code generation of Solidity contracts at the source code level. In this paper, we present SIF, a comprehensive framework for Solidity contract analysis, query, instrumentation, and code generation. SIF provides support for Solidity contract developers and testers to build source level techniques for analysis, understanding, diagnostics, optimisations and code generation. We show feasibility and applicability of the framework by building practical tools on top of it and running them on 1838 real smart contracts deployed on the Ethereum network.
Distributed consensus mechanisms have been widely researched and made popular with a number of blockchain-based token applications, such as Bitcoin, and Ethereum. Although these general-purpose platforms have matured for scale and security, they are designed for human incentive and continue to require currency reward and contract functions that are not requisite in machine communications. Redes Chain is a custom designed blockchain, built to support fully decentralized self-organization in wireless networks-without a cryptocurrency or contract dependency.
Gaganjeet Singh Reen, Manasi Mohandas, S. Venkatesan
Electronic Health Records(EHR) are gaining a lot of popularity all over the world. The current EHR systems however have their fair share of problems related to privacy and security. We have proposed a mechanism which provides a solution to most of these problems. Using a permissioned Ethereum blockchain allows the hospitals and patients across the world to be connected to each other. Our mechanism uses a combination of symmetric and asymmetric key cryptography to ensure the secure storage and selective access of records. It gives patients full control over their health records and also allows them to grant or revoke a hospital's access to his/her records. We have used IPFS(inter planetary file system) to store records which has the advantage of being distributed and ensures immutability of records. The proposed model also maintains the statistics of diseases without violating the privacy of any patient.
Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Subject of Research. The paper considers the process of generating reports in electronic learning systems. The aim is to optimize learning process management in generating reports using blockchain technologies. The paper analyzes existing learning management systems and their tools for generating and analyzing reports. Blockchain technology is reviewed in terms of educational opportunities. Method. The process of generating reports in the learning management system is presented as a mathematical model. It has been proven that the use of blockchain technology simplifies this process, since blockchain tools automatically register network events. A model for generating reports in the learning system using blockchain transactions has been developed. The model is implemented in a test version of the Ethereum blockchain using the smart contract mechanism. A smart contract records heterogeneous data of learning events to the blockchain without using special data structures. The blockchain stores data in a unified registry and registers event timestamp and event author’s address by itself. Event data is available through the geth console oriented for the Ethereum blockchain. Main Results. A method of learning process documenting using blockchain technology has been developed. The method does not require any special data model for storing learning events data, as well as special mechanism for recording event timestamp and event author’s address. Practical Relevance. Research results show that blockchain application provides for optimization of the learning process management.
Blockchain technology and, in particular, blockchain-based cryptocurrencies offer us information that has never been seen before in the financial world. In contrast to fiat currencies, all transactions of crypto-currencies and crypto-tokens are permanently recorded on distributed ledgers and are publicly available. As a result, this allows us to construct a transaction graph and to assess not only its organization but to glean relationships between transaction graph properties and crypto price dynamics. The ultimate goal of this paper is to facilitate our understanding on horizons and limitations of what can be learned on crypto-tokens from local topology and geometry of the Ethereum transaction network whose even global network properties remain scarcely explored. By introducing novel tools based on topological data analysis and functional data depth into Blockchain Data Analytics, we show that Ethereum network (one of the most popular blockchains for creating new crypto-tokens) can provide critical insights on price strikes of crypto-tokens that are otherwise largely inaccessible with conventional data sources and traditional analytic methods.
Election is a significant job in our Elective Government. As technology progress with upcoming days, its impact becomes more optimistic. One such outcome is the Blockchain. It is possible to transform the process of voting system due to its decentralized property of immutability. Voting in most places are non-transparent and common with the corruption. In this paper we proposed the technology, is Blockchain technology. The concept of this paper is to develop a decentralized application for voting system. From there, the transaction votes are stored in the blockchain could be illustrated by the examining the block hashes. The outcome of the project shows the transaction of tokens from voter’s wallet into the candidate’s wallet. This application can deploy on a test platform using the Ethereum Virtual Machine (EVM) it provides the network to test the application. From there, the integrity of the blockchain technology is illustrated.
Ministry of Electronics and Information Technology, Govt. of India., Om Pal, Surendra Singh, Ministry of Electronics and Information Technology, Govt. of India.
Blockchain Technology is one of the most popular technologies of present days. This technology has the capability to eliminate the requirement of third party to validate the transactions over the Peer-to-Peer network. Due to various features of Blockchain like smart contract, consensus mechanism, network transactions are completed securely, efficiently and timely. This technology is very useful in many areas including medical, IoT, e-Governance services, smart cities, taxation, supply chain, banking etc. In this paper, we discuss the Blockchain Technology in detail, its data structure, open source platform like Ethereum and Hyperledger, technical aspects of this technology, possible applications of this technology, challenges and limitations in adaptation of this technology.
The booming Internet of Things (IoT) market has drawn tremendous interest from cyber attackers. The centralized cloud-based IoT service architecture has serious limitations in terms of security, availability, and scalability, and is subject to single points of failure (SPOF). Recently, accommodating IoT services on blockchains has become a trend for better security, privacy, and reliability. However, blockchain's shortcomings of high cost, low throughput, and long latency make it unsuitable for IoT applications. In this paper, we take a retrospection of existing blockchain-based IoT solutions and propose a framework for efficient blockchain and IoT integration. Following the framework, we design a novel blockchain-assisted decentralized IoT remote accessing system, RS-IoT, which has the advantage of defending IoT devices against zero-day attacks without relying on any trusted third-party. By introducing incentives and penalties enforced by smart contracts, our work enables "an economic approach" to thwarting the majority of attackers who aim to achieve monetary gains. Our work presents an example of how blockchain can be used to ensure the fairness of service trading in a decentralized environment and punish misbehaviors objectively. We show the security of RS-IoT via detailed security analyses. Finally, we demonstrate its scalability, efficiency, and usability through a proof-of-concept implementation on the Ethereum testnet blockchain.
Yongjie Ye, Jingjing Zhang, Weigang Wu, Xiapu Luo · 5 authors
The payment channel, which allows two parties to perform micropayments without involving the blockchain, has become a promising proposal to improve the scalability of decentralized ledgers such as Bitcoin and Ethereum. Payment channels have been extended to the payment network, through which users can utilize existing channels as intermediary links to route coins to others. However, routing payments through multiple channels bears nontrivial overheads. It requires every intermediary channel to lock a portion of its available capacity until the payment is settled. This may lead to deadlock in a concurrent situation. The intermediary nodes in a payment path may also charge fees for routing a payment. The longer the routing path, the more serious the above problems. In this paper, we design and develop a novel off-chain system to shorten the routing path for the payment network. In particular, we propose the channel hub, which is an extension of the payment hub, to allows transferring coins directly from one payment channel to another within the same hub. That is, the channel hub can be viewed as a shortcut device for the underlying payment network. We design a new protocol named Boros to perform secure off-chain cross-channel transfers through the channel hub. We not only present the security definition of the Boros protocol formally but also prove its security using the UC-framework. To demonstrate the feasibility of the Boros protocol, we develop a proof-of-concept prototype running on the Ethereum. Our evaluation shows that our system can effectively shorten the off-chain routing path.
We present Solythesis, a source to source Solidity compiler which takes a smart contract code and a user specified invariant as the input and produces an instrumented contract that rejects all transactions that violate the invariant. The design of Solythesis is driven by our observation that the consensus protocol and the storage layer are the primary and the secondary performance bottlenecks of Ethereum, respectively. Solythesis operates with our novel delta update and delta check techniques to minimize the overhead caused by the instrumented storage access statements. Our experimental results validate our hypothesis that the overhead of runtime validation, which is often too expensive for other domains, is in fact negligible for smart contracts. The CPU overhead of Solythesis is only 0.12% on average for our 23 benchmark contracts.
Digital ledger teknologi kan enkelt automatisera Sverige som en jurisdiktion, inklusive automatisering av beskattning, och möjliggöra digitala regeringsval, säkra digitala nationella IDn, och en Svensk e-krona. Exakt vad som behövs för en Svensk digital ledger är en konsensus algoritm som ordnar ledgern under Svenska folkets kontroll, proof-of-vote, digitala motsvarigheten av representativ demokrati. Under proof-of-vote röstar Svenska medborgare fram validatorer, som sen följer motsvarande protokoll som i Bitcoin och Ethereum, e.g., konkurrerar om auktoritet utifrån konsensus algoritmen, Nakamoto konsensus, i proof-of-vote med dom folk-röster dom fått, motsvarande stake i proof-of-stake.
David Zhao, Alessandro Rinaldo, Christopher Brookins
Few assets in financial history have been as notoriously volatile as cryptocurrencies. While the long term outlook for this asset class remains unclear, we are successful in making short term price predictions for several major crypto assets. Using historical data from July 2015 to November 2019, we develop a large number of technical indicators to capture patterns in the cryptocurrency market. We then test various classification methods to forecast short-term future price movements based on these indicators. On both PPV and NPV metrics, our classifiers do well in identifying up and down market moves over the next 1 hour. Beyond evaluating classification accuracy, we also develop a strategy for translating 1-hour-ahead class predictions into trading decisions, along with a backtester that simulates trading in a realistic environment. We find that support vector machines yield the most profitable trading strategies, which outperform the market on average for Bitcoin, Ethereum and Litecoin over the past 22 months, since January 2018.
Smart contracts on a blockchain behave precisely as specified by their code. A vulnerability in this code can lead to unexpected behaviour, which is hard to fix because a blockchain does not allow to change smart contract code after its deployment. Such vulnerabilities have led to several incidents. In the aftermath of such an event, a hard-fork between Ethereum and Ethereum classic was the result. This thesis proposes to develop a new smart contract programming language with the primary focus on safety, auditability, and the intention to prevent as many of the known categories of vulnerabilities by design as possible. The programming language's code is validated during deployment and afterwards isolated from other smart contracts running on the same blockchain to enforce compile-time guarantees during runtime. The designed programming language does evaluate new concepts and paradigms rarely used in non-smart contract environments for their potential benefit in a smart contract environment.
Blockchain offers a decentralized, immutable, transparent system of records. It offers a peer-to-peer network of nodes with no centralised governing entity making it unhackable and therefore, more secure than the traditional paper-based or centralised system of records like banks etc. While there are certain advantages to the paper-based recording approach, it does not work well with digital relationships where the data is in constant flux. Unlike traditional channels, governed by centralized entities, blockchain offers its users a certain level of anonymity by providing capabilities to interact without disclosing their personal identities and allows them to build trust without a third-party governing entity. Due to the aforementioned characteristics of blockchain, more and more users around the globe are inclined towards making a digital transaction via blockchain than via rudimentary channels. Therefore, there is a dire need for us to gain insight on how these transactions are processed by the blockchain and how much time it may take for a peer to confirm a transaction and add it to the blockchain network. This paper presents a novel approach that would allow one to estimate the time, in block time or otherwise, it would take for a mining node to accept and confirm a transaction to a block using machine learning. The paper also aims to compare the predictive accuracy of two machine learning regression models- Random Forest Regressor and Multilayer Perceptron against previously proposed statistical regression model under a set evaluation criterion. The objective is to determine whether machine learning offers a more accurate predictive model than conventional statistical models. The proposed model results in improved accuracy in prediction.
Cryptomonnaies et efficience des marchés Les innovations apportées par les cryptomonnaies et leur technologie sous-jacente, la blockchain, ouvrent de nouvelles voies de recherches en finance. Cette thèse de doctorat est composée de trois essais portant sur les cryptomonnaies et est centrée autour de la notion d’efficience informationnelle des marchés. La première étude vise à expliquer comment la blockchain, développée au sein de communautés informelles, est adoptée et intégrée par les organisations. Cette étude apporte un cadre théorique à la technologie blockchain, cadre qui s’appuie sur les approches contractuelle et cognitive de la théorie des organisations. Grâce à une revue de la littérature illustrée, une analyse à deux dimensions présente les possibles utilisations de la blockchain fondées sur l’accès à l’information pour les participants. L’objectif de la seconde étude est double. Premièrement, elle soulève la problématique de la réelle nature du Bitcoin. Après avoir comparé le Bitcoin aux monnaies, à l’or et aux actions, nous basons notre analyse sur l’hypothèse que les cryptomonnaies peuvent être assimilées aux actions. Deuxièmement, la performance financière (la rentabilité ajustée au risque) du Bitcoin est mesurée en utilisant des modèles traditionnels tels que le MEDAF et le model de Fama-French à trois facteurs. Nous trouvons que l’intégration du Bitcoin dans un portefeuille améliore considérablement sa diversification, tout en apportant des rentabilités ajustées au risque positives et significatives dans le monde, l’Europe et l’Asie-Pacifique. La forte volatilité du Bitcoin ainsi que sa haute performance nous conduisent à analyser le caractère de bulle spéculative des cryptomonnaies, ce qui est l'objet de la troisième étude. Nous analysons cet aspect en utilisant le modèle PSY de Phillips and Shi, 2018. Deuxièmement, nous analysons le plus important pic/éclatement du marché des cryptomonnaies à la fin des années 2017 à l’aide du modèle LPPL (Log Periodic Power Law). Les résultats suggèrent des périodes de bulles avec effet de contagion entre les cryptomonnaies. Les analyses théoriques et empiriques de cette thèse contribuent à la littérature académique sur les cryptomonnaies. Nos résultats sont également importants pour les entreprises et pour les investisseurs qui s’intéressent au potentiel des cryptomonnaies et de la blockchain, ainsi que pour les décideurs politiques responsables de leur régulation.
Recently, blockchain technology has become a topic in the spotlight but also a hotbed of various cybercrimes. Among them, phishing scams on blockchain have been found making a notable amount of money, thus emerging as a serious threat to the trading security of the blockchain ecosystem. In order to create a favorable environment for investment, an effective method for detecting phishing scams is urgently needed in the blockchain ecosystem. To this end, this paper proposes an approach to detect phishing scams on Ethereum by mining its transaction records. Specifically, we first crawl the labeled phishing addresses from two authorized websites and reconstruct the transaction network according to the collected transaction records. Then, by taking the transaction amount and timestamp into consideration, we propose a novel network embedding algorithm called trans2vec to extract the features of the addresses for subsequent phishing identification. Finally, we adopt the oneclass support vector machine (SVM) to classify the nodes into normal and phishing ones. Experimental results demonstrate that the phishing detection method works effectively on Ethereum, and indicate the efficacy of trans2vec over existing state-of-the-art algorithms on feature extraction for transaction networks. This work is the first investigation on phishing detection on Ethereum via network embedding and provides insights into how features of large-scale transaction networks can be embedded.
PURPOSE The healthcare system in the United States is unique. From payor to provider, patients have many choices but they lack in the ability to manage or share their health information. This complicated care paradigm places patients at a distinct disadvantage. Legislation clearly defines government expectations of data availability but not how to achieve exchange. Because methods of sharing are left to the discretion of care providers and software vendors, non-interoperability is the standard. METHODS The OpenPharma Blockchain on Fast Healthcare Interoperability Resources (FHIR) (OBF) solution is interoperable by design. OBF empowers patients with data access through biometric identity authentication, blockchain, and machine-–to-machine secure data access. OBF provides authenticated users read-only, real-time access to patient records using the healthcare interoperability standard HL7 FHIR. OBF is built around a modern, browser-based user interface, blockchain technologies (leveraging either Ethereum or the Hedera protocols) and modular, modern software exposed as Application Programming Interfaces (APIs). This allows OBF to meet the Office of National Coordinator for Health Information (ONC) metrics, which include sending, receiving, and finding information from outside sources and using that information to make informed clinical decisions without additional burden on clinicians or patients. RESULTS Building on the HL7 FHIR application community practices, OBF is a SMART-on-FHIR plug-in for Electronic Medical Record (EMR) systems. Using OBF, patients can identify themselves and gain access to their medical records using their voice. This unique feature is accomplished through the Saavha voice print biometrics technology. Saavha returns a unique member ID that is passed directly to the OBF blockchain smart contract for storage and interoperable patient record access (the ID does not contain public health information [PHI]). To ensure complete privacy, all information is passed through multiple layers of encryption where no keys are stored locally. Additionally, no PHI is shared to the blockchain. To ensure privacy, OBF creates a new encrypted address for the FHIR patient record object, using the Saavha generated member ID as the unique identifier. This encrypted address is then published on chain, making it available to participating providers. Providers must register their relationships to patients before OBF will permit online viewing of patient records. Patient record access is accomplished through voice verification and real-time surfacing of encrypted patient data through the OBF FHIR Viewer. CONCLUSIONS OBF is a lightweight, flexible, secure, and stable interoperable solution that places data stewardship with patients. Using industry-wide data standards, biometrics, Smart contracts, Ethereum, and OpenPharma’s data viewer for the first-time patients can authorize read-only record exchange using their voice.