Smart cities represent a promising paradigm aimed at enhancing citizens’ quality of life through cutting-edge infrastructure and technological advancements. Collaborative services serve as a cornerstone for any smart city, fostering seamless cooperation among diverse entities, including government agencies, businesses, and individuals, thereby enhancing community outcomes. These services are pivotal, promoting seamless communication and collaboration among various smart applications, and facilitating data exchange, resource sharing, and functional interactions within smart city environments to optimize efficiency, effectiveness, and user experiences. However, the development and deployment of secure, interoperable services in smart cities present significant challenges. These issues encompass, ensuring data security compliance during interoperation, effective management of interconnected services, securely handling sensitive data across services, and addressing issues related to confidentiality, integrity, and availability (CIA) traits. To tackle these challenges, this research proposes an innovative adaptive security governance framework tailored for smart cities. This framework relies on dynamic security policies implemented through smart contracts to guarantee data security and privacy during smart service interoperation. Real-world use cases in collaborative smart city environments validate the framework, integrating multi-chain blockchain technology, smart services APIs, and Software-Defined Networking (SDN), showcasing its ability to enhance security and efficiency in collaborative services. This study contributes to the development of safe and efficient collaborative services inside smart cities, tackling administrative issues while emphasizing data security and privacy. Smart cities may improve citizens’ living conditions while successfully addressing crucial security problems in an ever-changing environment by using this architecture.
With the wide adoption of cryptocurrency, blockchain technologies have become the foundation of such digital currencies. However, this adoption has been accompanied by a surge in cryptocurrency fraud, causing significant losses to financial organizations and individuals. One way to mitigate these losses is to use Federated Learning (FL) techniques to detect fraudulent cryptocurrency transactions. This paper provides an overview of secure, privacy-preserving, and scalable Blockchain-based Federated Learning (BCFL) as a promising solution for slowing the exponential growth of cryptocurrency fraud. BCFL enables multiple entities to collaboratively train machine learning models for detecting fraudulent cryptocurrency transactions without sharing their private data, thus preserving privacy. However, Integrating differential privacy and Secure Multi-party computation (SMPC) models in BCFL presents an additional scalability challenge. This study provides an overview of BCFL, evaluating existing research on its security, privacy, and scalability challenges in detecting cryptocurrency fraud. The review explores existing research and various methodologies, highlighting advancements and challenges in creating effective, privacy-conscious fraud detection solutions for cryptocurrency transactions. We first discuss the current state of BCFL in fraud detection, along with its potential advantages and limitations, and then discuss the existing research gaps. In particular, this paper examines various BCFL frameworks, consensus algorithms, and block architectures, emphasizing their strengths and limitations in the context of cryptocurrency fraud detection to develop scalable and privacy-preserving solutions. We compare various solutions that address scalability and privacy challenges in BCFL, including adopting a geographically distributed cloud computing model that utilizes SMPC and lightweight consensus algorithms and protocols to manage computational overheads.
Privacy and auditability have been conflicting design requirements for blockchainbased distributed ledgers since the inception of the field.As purpose-built blockchains with permissioned consensus and client access are developing in a broad and diverse range of industries, a specific form of this dichotomy is emerging: the need to audit the handling of regulated on-ledger financial assets, such as central bank digital currencies, while preserving the privacy and confidentiality of transactions as much as possible.This paper proposes a novel, privacy-preserving, noninteractive-zero-knowledge-proof-based protocol for a blockchain-based distributed ledger, to prove conformance with fundamental compliance requirements to external auditing parties.We present an extendable implementation and demonstrate the practicality of the approach.
Abstract Building trust in modern business and in social interactions is a critical need as our networks continue to grow and as we engage deeply with unknown people and companies from various parts of the planet. Zero-Knowledge (ZK) technology is a powerful enabler of this trust. It allows a person to demonstrate they know something, have something, or can do something without revealing the actual information or process. We describe the fundamental concepts of cryptography and ZK, their use and limitations, and discuss how ZK technology can be used from a personal as well as a business perspective.
Abstract This chapter has two purposes. First, we describe how information system (IS) scholars approach privacy research and summarize major findings. IS scholars are concerned with information privacy and have discovered that individuals have serious information privacy concerns. These concerns, however, do not prevent individuals from disclosing personal identifiable information (PII) with centralized platform providers, a phenomenon called the privacy paradox . We highlight four common explanations for the privacy paradox: privacy calculus, privacy fatigue, trust, and lack of choice. Most IS research investigated Web2 applications. Web2 is the foundation for today’s global economy. With Web2, users rely on centralized platforms for online searching, shopping, banking, data storage, social media, and other services. Second, we introduce readers to the new paradigm of Web3. Privacy protection has been the paramount logic behind the grand design of Web3 applications. Web3 is the era of the Internet that is based on decentralized infrastructures and applications, like Bitcoin and Ethereum. Web3 applications enhance information privacy compared to Web2 because individuals can access services without disclosing PII to a central authority. The privacy objective is achieved technically through a combination of digital wallets, cryptography, and distributed ledgers (a.k.a blockchain). While Web3 is still in its early days, education is an important driver of adoption.
The surge in interest and application of large language models (LLMs) has sparked a drive to fine-tune these models to suit specific applications, such as finance and medical science. However, concerns regarding data privacy have emerged, especially when multiple stakeholders aim to collaboratively enhance LLMs using sensitive data. In this scenario, federated learning becomes a natural choice, allowing decentralized fine-tuning without exposing raw data to central servers. Motivated by this, we investigate how data privacy can be ensured in LLM fine-tuning through practical federated learning approaches, enabling secure contributions from multiple parties to enhance LLMs. Yet, challenges arise: (1) despite avoiding raw data exposure, there is a risk of inferring sensitive information from model outputs, and (2) federated learning for LLMs incurs notable communication overhead. To address these challenges, this article introduces DP-LoRA, a novel federated learning algorithm tailored for LLMs. DP-LoRA preserves data privacy by employing a Gaussian mechanism that adds noise in weight updates, maintaining individual data privacy while facilitating collaborative model training. Moreover, DP-LoRA optimizes communication efficiency via low-rank adaptation, minimizing the transmission of updated weights during distributed training. The experimental results across medical, financial, and general datasets using various LLMs demonstrate that DP-LoRA effectively ensures strict privacy constraints while minimizing communication overhead.
Open access
2 source records
Privacy-Preserving Technologies in Data
Artificial Intelligence in Healthcare and Education
In this paper, we present a novel blockchain-enabled approach to opportunistic federated learning (OppCL) for intelligent transportation systems (ITS). Our approach integrates blockchain with OppCL to streamline the learning of autonomous vehicle models while addressing data privacy and trust challenges. We deploy resilient countermeasures, incentivized mechanisms, and a secure gradient distribution to combat single-point failure verification attacks. Additionally, we integrate the Byzantine fault-tolerant algorithm (BFT) into the node verification component of the delegated proof of stake (DPoS) to minimize verification delays. We validate our approach through experiments on the MNIST, SVHN, and CIFAR-10 datasets, showing convergence rates and prediction accuracy comparable to traditional OppCL approaches.
In an era dominated by rapid digitalization of sensed data, the secure exchange of sensitive information poses a critical challenge across various sectors. Established techniques, particularly in emerging technologies like the Internet of Things (IoT), grapple with inherent risks in ensuring data confidentiality, integrity, and vulnerabilities to evolving cyber threats. Blockchain technology, known for its decentralized and tamper-resistant characteristics, stands as a reliable solution for secure data exchange. However, the persistent challenge lies in protecting sensitive information amidst evolving digital landscapes. Among the burgeoning applications of blockchain technology, non-fungible tokens (NFTs) have emerged as digital certificates of ownership, securely recording various types of data on a distributed ledger. Unlike traditional data storage methods, NFTs offer several advantages for secure information exchange. Firstly, their tamperproof nature guarantees the authenticity and integrity of the data. Secondly, NFTs can hold both immutable and mutable data within the same token, simplifying management and access control. Moving beyond their conventional association with art and collectibles, this paper presents a novel approach that utilizes NFTs as dynamic carriers for sensitive information. Our solution leverages the immutable NFT data to serve as a secure data pointer, while the mutable NFT data holds sensitive information protected by steganography. Steganography embeds the data within the NFT, making them invisible to unauthorized eyes, while facilitating portability. This dual approach ensures both data integrity and authorized access, even in the face of evolving digital threats. A performance analysis confirms the approach's effectiveness, demonstrating its reliability, robustness, and resilience against attacks on hidden data. This paves the way for secure data transmission across diverse industries.
Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
Federated learning (FL) has emerged as an alternative to traditional machine learning in scenarios where training data is sensitive. In federated learning, training is held at end devices, and thus data does not need to leave users devices. However, most approaches to federated learning rely on a central server to coordinate the learning process which, in turn, introduces its own security and privacy problems. We propose Federify, a decentralized federated learning framework based on blockchain which employs homomorphic encryption and zero knowledge proofs to provide security, privacy, and transparency. The scheme preserves the confidentiality of both the data used for training and the local models using homomorphic encryption. zkSNARKs are used to provide security by verifying the contributions from the different agents, and transparency of both the learning process and the incentive mechanism is achieved by delegating coordination into a smart contract in a public blockchain. We have also implemented, deployed, and evaluated a proof of concept of our framework, to demonstrate its viability both in terms of computational resources needed and cost to train in a public generic blockchain such as Ethereum.
Massive amounts of data drive the performance of deep learning models, but in practice, data resources are often highly dispersed and bound by data privacy and security concerns, making it difficult for multiple data sources to share their local data directly. Data resources are difficult to aggregate effectively, resulting in a lack of support for model training. How to collaborate between data sources in order to aggregate the value of data resources is therefore an important research question. However, existing distributed-collaborative-learning architectures still face serious challenges in collaborating between nodes that lack mutual trust, with security and trust issues seriously affecting the confidence and willingness of data sources to participate in collaboration. Blockchain technology provides trusted distributed storage and computing, and combining it with collaboration between data sources to build trusted distributed-collaborative-learning architectures is an extremely valuable research direction for application. We propose a trusted distributed-collaborative-learning mechanism based on blockchain smart contracts. Firstly, the mechanism uses blockchain smart contracts to define and encapsulate collaborative behaviours, relationships and norms between distributed collaborative nodes. Secondly, we propose a model-fusion method based on feature fusion, which replaces the direct sharing of local data resources with distributed-model collaborative training and organises distributed data resources for distributed collaboration to improve model performance. Finally, in order to verify the trustworthiness and usability of the proposed mechanism, on the one hand, we implement formal modelling and verification of the smart contract by using Coloured Petri Net and prove that the mechanism satisfies the expected trustworthiness properties by verifying the formal model of the smart contract associated with the mechanism. On the other hand, the model-fusion method based on feature fusion is evaluated in different datasets and collaboration scenarios, while a typical collaborative-learning case is implemented for a comprehensive analysis and validation of the mechanism. The experimental results show that the proposed mechanism can provide a trusted and fair collaboration infrastructure for distributed-collaboration nodes that lack mutual trust and organise decentralised data resources for collaborative model training to develop effective global models.
Federated learning is a privacy-preserving machine learning framework where multiple data owners collaborate to train a global model under the orchestra of a central server. The local training results from trainers should be submitted to the central server for model aggregation and update. Busy central server and malicious trainers can introduce the issues of a single point of failure and model poisoning attacks. To address the above issues, the trusty decentralized federated learning (called TrustDFL) framework has been proposed in this paper based on the zero-knowledge proof scheme, blockchain, and smart contracts, which provides enhanced security and higher efficiency for model aggregation. Specifically, Groth 16 is applied to generate the proof for the local model training, including the forward and backward propagation processes. The proofs are attached as the payloads to the transactions, which are broadcast into the blockchain network and executed by the miners. With the support of smart contracts, the contributions of the trainers could be verified automatically under the economic incentive, where the blockchain records all exchanged data as the trust anchor in multi-party scenarios. In addition, IPFS (InterPlanetary File System) is introduced to alleviate the storage and communication overhead brought by local and global models. The theoretical analysis and estimation results show that the TrustDFL efficiently avoids model poisoning attacks without leaking the local secrets, ensuring the global model’s accuracy to be trained.
Background: The immense increase of data due to web services, social media, Health care data, and mobile data results in the massive quantity of organized and unorganized data known as big data, which is utilized by various data miners as it contains some sensitive information. Method: In this research, a privacy mechanism in the decentralized cloud through the smart contract approach is developed to ensure the privacy of the data and ensure a fair trading strategy. Findings: The comparative analysis is revealed in the proposed SABPP model, which shows that the responsiveness attained by the proposed SABPP method is found to be 26.9759sec, 85.2969sec, and 158.6968sec for 20, 60 and 100 nodes respectively. Novelty: In this research, the smart contract approach named SABPP is proposed that ensures the smart agreement trading in the Blockchain and overcomes the privacy challenge associated with the trusted third party thereby, ensuring the data availability for the data consumer and privacy for the data provider. Keywords: Blockchain, smart contract, privacy preservation, authentication, access control, data trading strategy
Protecting private data in smart homes, a popular Internet-of-Things (IoT) application, remains a significant data security and privacy challenge due to the large-scale development and distributed nature of IoT networks. Recently, smart healthcare has leveraged smart home systems, thereby compounding security concerns in terms of the confidentiality of sensitive and private data and by extension the privacy of the data owner. However, PoA-based Blockchain DLT has emerged as a promising solution for protecting private data from indiscriminate use and thereby preserving the privacy of individuals residing in IoT-enabled smart homes. This review elicits some concerns, issues, and problems that have hindered the adoption of blockchain and IoT (BCoT) in some domains and suggests requisite solutions using the aging-in-place scenario. Implementation issues with BCoT were examined as well as the combined challenges BCoT can pose when utilised for security gains. The study discusses recent findings, opportunities, and barriers, and provide recommendations that could facilitate the continuous growth of blockchain application in healthcare. Lastly, the study then explored the potential of using a PoA-based permission blockchain with an applicable consent-based privacy model for decision-making in the information disclosure process, including the use of publisher-subscriber contracts for fine-grained access control to ensure secure data processing and sharing, as well as ethical trust in personal information disclosure, as a solution direction. The proposed authorisation framework could guarantee data ownership, conditional access management, scalable and tamper-proof data storage, and a more resilient system against threat models such as interception and insider attacks.
Aleksandr Kormiltsyn, Vimal Dwivedi, Chibuzor Udokwu, Alex Norta
Integrating personal health records (PHRs) and electronic health records (EHRs) facilitates the provision of novel services to individuals, researchers, and healthcare practitioners. Simultaneously, integrating healthcare data leads to complexities arising from the structural and semantic heterogeneity within the data. The subject of healthcare data evokes strong emotions due to concerns surrounding privacy breaches. Blockchain technology is employed to address the issue of patient data privacy in inter-organizational processes, as it facilitates patient data ownership and promotes transparency in its usage. At the same time, blockchain technology creates new challenges for e-healthcare systems, such as data privacy, observability, and online enforceability. This article proposes designing and formalizing automatic conflict resolution techniques in decentralized e-healthcare systems. The present study expounds upon our concepts by employing a running case study centered around preventive and personalized healthcare domains. Plain Language Summary: This paper suggests using blockchain technology for privacy concerns in integrating personal health records and electronic health records in decentralized e-healthcare systems. This report focuses on designing automatic conflict resolution techniques to ensure patient data ownership, transparency, and privacy in inter-organizational processes. This paper proposes designing automatic conflict resolution techniques in decentralized e-healthcare systems, which can improve inter-organizational processes in healthcare. Using blockchain technology to integrate personal and electronic health records can ensure patient data ownership and promote transparency in data usage, addressing privacy concerns in healthcare systems. This paper emphasizes the importance of data privacy and protection in healthcare systems, highlighting the need for compliance with laws and regulations. The research results, including the proof-of-concept prototype, can provide practical insights into implementing conflict resolution techniques in decentralized e-healthcare systems.
The industrial internet of things (IIoT) necessitates robust cross-domain authentication to secure sensitive on-site equipment data. This paper presents a refined reputation-based lightweight consensus mechanism (LRBCM) tailored for IIoT's distributed network structures. Leveraging node reputation values, LRBCM streamlines ledger consensus, minimizing communication overhead and complexity. Comparative experiments show LRBCM outperforms competing mechanisms. It maintains higher throughput as the number of participating nodes increases and achieves a throughput approximately 10.78% higher than ReCon. Moreover, runtime analysis demonstrates LRBCM's scalability, surpassing ReCon by approximately 12.79% with equivalent nodes and transactions. In addition, as a combination of LRBCM, the proposed distributed lightweight authentication mechanism (ELAM) is rigorously evaluated against the security of various attacks, and its resilience is confirmed. Experiments show that ELAM has good efficiency while maintaining high security.
Nan Xiao, Zhaoshun Wang, Xiaoxue Sun, Junfeng Miao
To address challenges in digital evidence collection and responsibility determination for industrial safety accidents involving industrial Internet of Things (IIoT) device nodes, this paper proposes a blockchain-based digital forensic scheme within the IIoT communication architecture. The scheme utilizes a decentralized blockchain storage mechanism to enable remote storage of digital forensic data. Additionally, it leverages smart contract mechanisms to facilitate efficient retrieval and tracing of related evidence chains. To enhance data security of IIoT device nodes, a token mechanism is implemented for access control. Moreover, to meet real-time evidence acquisition requirements in IIoT, an efficient batch consensus mechanism is proposed. Experimental simulations demonstrate the superiority of the novel consensus algorithm compared to the traditional Delegated Proof-of-Stake (DPOS) consensus in the proposed scheme for the IIoT environment. It meets speed requirements for evidence collection, ensuring tamper-proof, non-repudiable, and permanent storage of digital forensic data. Consequently, the application of blockchain technology for judicial access and evidence storage has made significant contributions to digital forensics within the IIoT context.
Anto Benedetti, Tiphaine Henry, Sara Tucci-Piergiovanni
Blockchain applications are witnessing rapid evolution, necessitating the integration of upgradeable smart contracts. Software patterns have been proposed to summarize upgradeable smart contract best practices. However, research is missing on the comparison of these upgradeable smart contract patterns, especially regarding gas costs related to deployment and execution. This study aims to provide an in-depth analysis of gas costs associated with two prevalent upgradeable smart contract patterns: the Proxy and diamond patterns. The Proxy pattern utilizes a Proxy pointing to a logic contract, while the diamond pattern enables a Proxy to point to multiple logic contracts. We conduct a comparative analysis of gas costs for both patterns in contrast to a traditional non-upgradeable smart contract. We derive from this analysis a theoretical contribution in the form of two consolidated blockchain patterns and a corresponding decision model. By so doing we hope to contribute to the broader understanding of upgradeable smart contract patterns.
Federated learning (FL) and blockchains exhibit significant commonality, complementarity, and alignment in various aspects, such as application domains, architectural features, and privacy protection mechanisms. In recent years, there have been notable advancements in combining these two technologies, particularly in data privacy protection, data sharing incentives, and computational performance. Although there are some surveys on blockchain-based federated learning (BFL), these surveys predominantly focus on the BFL framework and its classifications, yet lack in-depth analyses of the pivotal issues addressed by BFL. This work aims to assist researchers in understanding the latest research achievements and development directions in the integration of FL with blockchains. Firstly, we introduced the relevant research in FL and blockchain technology and highlighted the existing shortcomings of FL. Next, we conducted a comparative analysis of existing BFL frameworks, delving into the significant problems in the realm of FL that the combination of blockchain and FL addresses. Finally, we summarized the application prospects of BFL technology in various domains such as the Internet of Things, Industrial Internet of Things, Internet of Vehicles, and healthcare services, as well as the challenges that need to be addressed and future research directions.
Cross-border data privacy protection often involves personal privacy data from different regions, where cross-border vehicle identity authentication requires a large amount of sensitive data. The cross-border movement of this sensitive data poses a significant threat to privacy. A distributed identity management blockchain model for cross-border data privacy protection is proposed to avoid the cross-border transmission of sensitive data through identity authentication. The model combines the SM2 and SM9 algorithms and blockchain technology to guarantee the security of stored data while providing a method to avoid sensitive data crossing borders and realizing cross-border identity authentication. The model was originally designed for the Northbound Travel for Macao scenario but can still be applied to other cross-border authentications. The generation speed of a Non-Fungible Token is verified through experiments, and the generation time and efficiency of Non-Fungible Tokens satisfy the actual needs of Internet of Vehicles authentication.
The implementation of blockchain technology alongside Artificial Intelligence features that strengthen Internet of Things cloud-based systems through extended data protection, enhanced robotic trust, and decentralized intelligence capabilities.Both potential benefits and obstacles of building blockchain-empowered collaborative AI systems that perform secure computations across multiple parties and present architectural guidelines for privacy protection.Digital transformation now drives various industries forward because of the power combination between IoT and distributed ledger technology and their alignment with AI and edge-fog-cloud computing environments.Blockchain integration with IoT networks protects data integrity by remedying vital privacy and security problems, which creates a robust system that handles decentralized, secure data management.Blockchain technology makes financial operations secure and faster across all payment transactions, trade finance, and asset management operations to build complete trust with banking institutions.Through their mutual partnership, blockchain and robotic technologies develop advanced robotic systems that exhibit better operational performance and use strengthened security systems to address blockchain weaknesses.This leads to better dependability of AIdriven service operations.Multiple forces drive blockchain integration with AI applications because users need stronger data security basics to protect confidential data from unauthorized use or tampering, and they want more reliable robot decision authentication.
Federated Learning is susceptible to various kinds of attacks like Data Poisoning, Model Poisoning and Man in the Middle attack. We perceive Federated Learning as a hierarchical structure, a federation of nodes with validators as the head. The process of validation is done through consensus by employing Novelty Detection and Snowball protocol, to identify valuable and relevant updates while filtering out potentially malicious or irrelevant updates, thus preventing Model Poisoning attacks. The opinion of the validators is recorded in blockchain and trust score is calculated. In case of lack of consensus, trust score is used to determine the impact of validators on the global model. A hyperparameter is introduced to guide the model generation process, either to rely on consensus or on trust score. This approach ensures transparency and reliability in the aggregation process and allows the global model to benefit from insights of most trusted nodes. In the training phase, the combination of IPFS , PGP encryption provides : a) secure and decentralized storage b) mitigates single point of failure making this system reliable and c) resilient against man in the middle attack. The system is realized by implementing in python and Foundry for smart contract development. Global Model is tested against data poisoning by flipping the labels and by introducing malicious nodes. Results found to be similar to that of Flower.
Blockchain technology is increasingly being used in personal data protection. Inspired by the importance of data security, this paper proposes a personal data protection mechanism based on blockchain, combined with distributed hash tables and cryptography, to enhance users' control over the data generated using web applications. This paper designs this mechanism's system model and describes the three aspects in detail: data storage mechanism, data encryption mechanism, and data trading mechanism. Among them, the data storage mechanism restricts user data to be stored only in the local storage space of the user terminal, the decentralized blockchain network, and the distributed hash table network to ensure that enterprises providing network applications cannot privately store user interaction data, the encryption mechanism is responsible for encrypting all user data recorded in the network and allows users to control the key of the data to ensure the security of the user data in the blockchain and distributed hash tables, the data transaction mechanism allows users to trade their data, and to incentivize enterprises to assist users in collecting personal data, data transaction contracts are built into the data transaction mechanism, allowing enterprises to receive a share of the revenue from user data transactions. Then, for data transactions, use the Stackelberg game to simulate the revenue sharing between users and service providers in data trading to incentivize enterprises providing web services to assist users in collecting their data. The simulation results show that when the number of users is 1000, the revenues of this scheme for service providers are 31%, 561%, and 19% higher than the existing scheme. Finally, the personal data protection platform is implemented by code to verify the feasibility of the theory proposed in this paper in personal data protection.
Mobile crowdsourcing (MCS) is an emerging paradigm that enables the outsourcing of a complex task to a group of mobile devices. The ability to utilize the collective power of mobile devices and human intelligence makes MCS a significant tool in various scenarios. Nevertheless, it faces practical challenge in protecting user privacy due to the sensitive nature of information collected by mobile devices. Additionally, the inherent openness of MSC and the heterogeneity of mobile devices raise reliability concerns among participants. To address these challenges, by integrating Federated Learning with the pairwise additive masking technique and the Chinese Remainder Theorem, we propose a Blockchain-based Privacy-preserving Federated Learning (BPFL) framework for mobile crowdsourcing, which allows mobile participants to collaboratively solve a crowdsourced machine learning task while preserving privacy. Besides, it employs blockchain technology to record the training process in a transparent and tamper-proof ledger. This ledger guarantees the verifiability of aggregation results and the fair distribution of training rewards, thereby enhancing trust and fairness. We prove that our BPFL supports privacy protection and trust mechanism simultaneously and resists inference and collusion attacks. Experimental results show that our BPFL can achieve high performance in terms of computation cost, communication cost and model accuracy, which is friendly for mobile users with resource-constrained devices in MCS ecosystems.
Minh-Quan Le, Hai‐Duong Le, Anh Vu Dinh-Duc, Thanh-Tung Tran
Recent blockchain-based systems for managing credentials show advantages over paper-based procedures. However, issuing credentials with blockchain could conflict with current management rules and policies. One of the possible conflicts is the auditability. Most blockchain-based systems for credentials focus on security, efficiency and privacy while ignoring the auditability of the system. In this paper, we propose a new system IU-TransCert for issuing, verifying, and auditing academic credentials. The system uses a new data structure named the Auditable Merkle Tree that enables credential issuance and built-in auditing capabilities. The auditable data fields can be customized to meet regulations. Credentials are published to the blockchain in the root node of the Auditable Merkle Tree, allowing access for auditors while preserving privacy. The system provides automated and transparent auditing processes for educational authorities to independently verify credentials without involving issuers. We also present a prototype to demonstrate feasibility, and a security analysis to examine protections against threats. The analysis and discussion shows that the proposed system could enhance credential privacy, efficiency, integrity, and auditability across the university ecosystem.