Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

2,533 papersLast indexed Aug 31, 2026
Search papers

Paper index

2,533 results · page 37 of 106

Clear filters
Oct 31, 2023·Internet of Things
54 cites
Cogni-Sec: A secure cognitive enabled distributed reinforcement learning model for medical cyber–physical system

Sushruta Mishra, Soham Chakraborty, Kshira Sagar Sahoo, Muhammad Bilal

The advent of the Internet of Things (IoT) has resulted in significant technical development in the healthcare sector, enabling the establishment of Medical Cyber-Physical Systems (MCPS). The increased number of MCPS generates a massive amount of privacy-sensitive data, hence it is important to enhance the security of devices and data transmission in MCPS. Earlier several research studies were undertaken in order to enhance security in healthcare, but none of them could adapt to changing behaviors of data attacks. Here the role of blockchain and Reinforcement Learning (RL) comes into play since it can adjust itself to the nature of changing attacks, thus preventing any kind of attacks. This work proposes a solution, named Cogni-Sec, which employs a decentralized cognitive blockchain and Reinforcement Learning architecture and addresses the security issue. Blockchain is incorporated in the approach for data storage and transmission to increase the degree of security in the MCPS modules. Hyperledger Fabric is applied as the blockchain base which shows transaction query results with nearly 10% increased throughput, 69% less memory consumption, and 15% lower CPU usage when compared to Ethereum. Further security risk at the block mining level within a blockchain network is reduced by introducing distributed Reinforcement Learning architecture in replacement for the miner nodes, which imitates the cognitive behavior of miners in a distributed environment. Different multi-agent learning systems have been evaluated for building the mining agent. Among these, the a3c agent in distributed learning setup yields the optimum cumulative reward with a median value of 54.5 and minimizes the maximum number of data threats.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 30, 2023·International Journal of Computers Communications & Control
14 cites
Optimizing Heterogeneity in IoT Infra Using Federated Learning and Blockchain-based Security Strategies

Venkatesan Muthukumar, R. Sivakami, Vinoth Kumar Venkatesan, J. Balajee · 7 authors

The Internet of Things (IoT) and associated capabilities are becoming indispensable in the planning, operation, and administration of intricate systems of all sizes. High-end learning solutions that go beyond the boundaries of the problem are necessary for addressing the variety of communication concerns (compatibility, secure communication, etc.) in IoT settings. Building machine learning (ML) networks from disparate data sources is a cutting-edge practice known as Federated Learning (FL). In this article, we implement FL between edge-based servers and devices in a sparsely populated cloud to facilitate cohesive learning and the storage of critical information in smart IoT systems. FL enables collaborative training from a common model by aggregating smaller unit models via regulated edge network participants. Further, all the susceptible device’s information and sensitive message transactions are addressed via blockchain technology. Thus, a blockchain-based security mechanism is integrated to secure user privacy and facilitate widespread practical adoption. Finally, a comparison is made between the proposed model and the three best free, open-source Federated Learning models already in use (FedPD, FedProx, and FedAvg). In terms of statistical, and data heterogeneity (>70% SDI, >97% accuracy), the experimental findings suggest that the proposed model performs better than the existing techniques.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Advanced Data and IoT Technologies
Original source
Oct 30, 2023·International Journal on Recent and Innovation Trends in Computing and Communication
0 cites
BlockGov: Blockchain-Based Data Governance in the Internet of Things using Smart Contracts

C. S. Anita K. Sudharson

The rapid growth and integration of the Internet of Things (IoT) emphasizes the crucial need for effective data governance. This research unveils a novel framework, capitalizing on blockchain and smart contracts, aimed at decentralizing data governance in the IoT sphere. Our approach allows stakeholders to formulate and enforce data governance collaboratively, ensuring a balance between transparency, adaptability, and flexibility. Using the Ethereum platform and Solidity as our smart contract language, we constructed a demonstrative proof-of-concept. Our comparative evaluations highlighted our system's superiority, outpacing previous works with a scalability score of 95%, flexibility at 90%, and an unmatched transparency score of 100%. This framework presents a transformative paradigm for organizations and individuals working with IoT data, offering an efficient, transparent, and robust data governance mechanism.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Oct 30, 2023·2023 19th International Conference on Network and Service Management (CNSM)
12 cites
Blockchain-Based Self-Sovereign Identity for Federated Learning in Vehicular Networks

Engin Zeydan, Luis Blanco, Josep Mangues, Şuayb S. Arslan · 5 authors

Self-Sovereign Identity (SSI) has emerged lately as an identity and access management framework that is based on Distributed Ledger Technology (DLT) and allows users to control their own data. Federate Learning (FL), on the other hand, provides a framework to update Machine Learning (ML) models without relying on explicit data exchange between the users. This paper investigates identity management and authentication for vehicle users, which are participating into FL. We propose a new approach to SSI, that is alternative to the conventional blockchain-based SSI, specifically for use in vehicular networks, which focuses on maintaining confidentiality, authenticity, and integrity of vehicle users' identities and data exchanged between the users and the aggregation server during the execution of the FL process. We also provide experimental results for distributed identity management (DIM) operations, which show that the performance of credential operations in the implemented system is generally efficient and the average times are within reasonable limits. However, there is a slight increase in presentation time, offer time, connection establishment time, and credential revocation time as the number of requests increases, indicating a slight degradation in performance for these operations.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Oct 30, 2023·arXiv (Cornell University)
0 cites
Incorporating Zero-Knowledge Succinct Non-interactive Argument of Knowledge for Blockchain-based Identity Management with off-chain computations

Pranay Kothari, Deepak Chopra, Manjot Singh, Shivam Bhardwaj · 5 authors

In today's world, secure and efficient biometric authentication is of keen importance. Traditional authentication methods are no longer considered reliable due to their susceptibility to cyber-attacks. Biometric authentication, particularly fingerprint authentication, has emerged as a promising alternative, but it raises concerns about the storage and use of biometric data, as well as centralized storage, which could make it vulnerable to cyber-attacks. In this paper, a novel blockchain-based fingerprint authentication system is proposed that integrates zk-SNARKs, which are zero-knowledge proofs that enable secure and efficient authentication without revealing sensitive biometric information. A KNN-based approach on the FVC2002, FVC2004 and FVC2006 datasets is used to generate a cancelable template for secure, faster, and robust biometric registration and authentication which is stored using the Interplanetary File System. The proposed approach provides an average accuracy of 99.01%, 98.97% and 98.52% over the FVC2002, FVC2004 and FVC2006 datasets respectively for fingerprint authentication. Incorporation of zk-SNARK facilitates smaller proof size. Overall, the proposed method has the potential to provide a secure and efficient solution for blockchain-based identity management.

Open access
3 source records
cs.CR
Biometric Identification and Security
User Authentication and Security Systems
Original source
Oct 30, 2023·Sci
68 cites
Privacy and Security of Blockchain in Healthcare: Applications, Challenges, and Future Perspectives

Hamed Taherdoost

Blockchain offers a cutting-edge solution for storing medical data, carrying out medical transactions, and establishing trust for medical data integration and exchange in a decentralized open healthcare network setting. While blockchain in healthcare has garnered considerable attention, privacy and security concerns remain at the center of the debate when adopting blockchain for information exchange in healthcare. This paper presents research on the subject of blockchain’s privacy and security in healthcare from 2017 to 2022. In light of the existing literature, this critical evaluation assesses the current state of affairs, with a particular emphasis on papers that deal with practical applications and difficulties. By providing a critical evaluation, this review provides insight into prospective future study directions and advances.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 25, 2023·Future Generation Computer Systems
19 cites
Enabling Federated Learning at the Edge through the IOTA Tangle

Carlo Mazzocca, Nicolò Romandini, Rebecca Montanari, Paolo Bellavista

The proliferation of Internet of Things (IoT) devices, generating massive amounts of heterogeneous distributed data, has pushed toward edge cloud computing as a promising paradigm to bring cloud capabilities closer to data sources. In many cases of practical interest, centralized Machine Learning (ML) approaches can hardly be employed due to high communication costs, low reliability, legal restrictions, and scalability issues. Therefore, Federated Learning (FL) is emerging as a promising distributed ML approach that enables models to be trained on remote devices using their local data. However, “traditional” FL solutions still present open technical challenges, such as single points of failure and lack of trustworthiness among participants. To address these open challenges, some researchers have started to propose leveraging blockchain technologies. However, the adoption of blockchain for FL at the edge is limited by several factors nowadays, such as long waiting times for transaction confirmation and high energy consumption. In this work, we conduct an original and comprehensive analysis of the key design challenges to address towards an efficient implementation of FL at the edge, and analyze how Distributed Ledger Technologies (DLTs) can be employed to overcome them. Then, we present a novel architecture that enables FL at the edge by leveraging the IOTA Tangle, a next-generation DLT whose data structure is a directed acyclic graph (DAG), and the InterPlanetary File System (IPFS) to store and share partial models. Experimental results demonstrate the feasibility and efficiency of our proposed solution in real-world deployment scenarios.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Oct 24, 2023·2023 Fifth International Conference on Blockchain Computing and Applications (BCCA)
8 cites
Verifiable Credentials with Privacy-Preserving Tamper-Evident Revocation Mechanism

Xu Li, Tianyu Li, Zekeriya Erkin

Verifiable Credential (VC) is a new standard proposed by the W3C association to facilitate the expression and verification of third-party-verified credentials on the Internet, such as passports or diplomas. However, the current VC data model lacks an explicit revocation design that guarantees the secure operations of the system, which limits its application. In this paper, we specify the requirements for a tamper-evident and privacy-preserving revocation mechanism, based on which we compare existing solutions and propose our revocation mechanism that satisfies all the requirements. Our design combines a cryptographic accumulator and a role-based blockchain. With zero-knowledge proof, the verifier can operate off-chain computation of the revocation status while ensuring the correctness of revocation information published on the blockchain. Our analysis shows that the proposed revocation mechanism can prevent fraud using forged and revoked credentials and relieve privacy concerns caused by the correlation of digital data. Our proof-of-concept implementation demonstrates that our revocation mechanism adds only 42.86 ms overhead in the presentation and 31.36 ms overhead in the verification of verifiable credentials. We also provide scalability analysis, which illustrates that the throughput of our blockchain can meet real-world needs.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Oct 24, 2023·arXiv (Cornell University)
0 cites
Redactable Signature Schemes and Zero-knowledge Proofs: A comparative examination for applications in Decentralized Digital Identity Systems

Bryan Kumara, Mark Hooper, Carsten Maple, Timothy Hobson · 5 authors

Redactable Signature Schemes and Zero-Knowledge Proofs are two radically different approaches to enable privacy. This paper analyses their merits and drawbacks when applied to decentralized identity system. Redactable Signatures, though competitively quick and compact, are not as expressive as zero-knowledge proofs and do not provide the same level of privacy. On the other hand, zero-knowledge proofs can be much faster but some protocols require a trusted set-up. We conclude that given the benefits and drawbacks, redactable signatures are more appropriate at an earlier stage and zero-knowledge proofs are more appropriate at a later stage for decentralized identity systems

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Oct 23, 2023·arXiv (Cornell University)
0 cites
NFT formalised

Martha N. Kamkuemah, J. W. Sanders

Non-fungible tokens, NFT, have been used to record ownership of real estate, art, digital assets, and more recently to serve legal notice. They provide an important and accessible non-financial use of cryptocurrency's blockchain but are peculiar because ownership by NFT confers no rights over the asset. This work shows that it is possible to specify that peculiar property by combining functional and epistemic properties. Suitability of the specification is evaluated by proof that the blockchain implementation conforms to it, and by its use in an analysis of serving legal notice.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
cs.LO
Original source
Oct 21, 2023·IET Blockchain
6 cites
Security and privacy issues in blockchain and its applications

Liangmin Wang, Victor S. Sheng, Boris Düdder, Haiqin Wu · 5 authors

Blockchain technology has emerged and evolved as a disruptive technology with the potential to be applied in various fields, including digital finance, healthcare, and the Internet of Things (IoT). Besides being a distributed ledger, blockchain enables decentralized and trusted storage/computation without relying on a central trusted party. However, the growing heterogeneity of blockchain platforms and the expanding range of applications have resulted in escalating security and privacy concerns. These concerns encompass persistent privacy breaches, vulnerabilities in smart contracts, and the “impossible triangle” problem. These challenges have emerged as the primary obstacles to the development and seamless integration of blockchain technology with industry applications. To address the security and privacy challenges in blockchain platforms and its applications, numerous researchers have conducted extensive studies in this field by leveraging advanced technologies, including new cryptographic protocols and deep learning techniques. This special issue aims to highlight research perspectives, articles, and experimental studies pertaining to “Security and Privacy Issues in Blockchain and Its Applications”. In this special issue, we received a total of nineteen papers, out of which seventeen underwent a rigorous peer-review process. However, two papers were excluded from the peer-reviewed selection because one was submitted in a draft form and the other was voluntarily withdrawn by the authors. Out of the seventeen papers submitted for review, ten were accepted for publication, six were rejected without being transferred, and one was rejected and referred to a transfer service. The exceptional quality of all the submissions played a crucial role in ensuring the success of this special issue. These accepted papers can be classified into two categories, namely blockchain application security and cross-chain interaction security. The papers in the first category focus on analyzing and providing insights into the security of blockchain applications. Their objective is to keep readers informed about the latest trends, developments, challenges, and opportunities in blockchain application security. Moreover, significant research efforts have been dedicated to security analysis and detection in typical blockchain applications. The papers in this category are of Zhou et al., Grybniak et al., Lv et al., Li et al., Gong et al., Xiao et al. and Videira et al. These contributions further enhance our understanding and capability to safeguard blockchain applications from potential security threats. The second category of papers presents novel solutions that target the enhancement of security in cross-system interactions. These papers are of Feng et al., Xu et al. and Yu et al. By addressing the specific challenges associated with cross-system communication, these solutions contribute to the development of robust and secure blockchain networks. A brief presentation of each of the papers in the special issue is as follows. Zhou et al. present WASMOD, a prototype system designed to detect vulnerabilities in WebAssembly (Wasm) smart contracts. WASMOD utilizes a combination of bytecode instrumentation, run-time validation, and grey-box fuzzing techniques to identify integer overflow and stack overflow vulnerabilities. The tool was effectively applied to the EOSIO blockchain, successfully detecting vulnerable smart contracts. Grybniak et al. propose “Waterfall: Gozalandia”, a distributed protocol based on the Proof of Stake approach. This protocol enables fast finality, proven safety, and liveness in a network utilizing BlockDAG structures. By employing cross-voting for block ordering, the protocol ensures swift consensus and the ability to detect dishonest behaviors. The protocol assumes the presence of a Coordinating network that holds information about the approved ordering. This Coordinating network serves to significantly enhance security and improve network synchronization in a qualitative manner. Through load testing, the protocol has demonstrated its ability to handle a throughput of 3200–3600 transactions per second, with an average confirmation waiting time of 20 s. Lv et al. propose a graph-based embedding classification method for phishing detection on the Ethereum blockchain. The method involves constructing multiple subgraphs using the transaction records collected from Ethereum and introduces a modified version of Graph2Vec called imgraph2vec. This modified approach aims to learn more meaningful information from the subgraphs. To identify phishing attempts, the Extreme Gradient Boosting (XGBoost) algorithm is utilized. Li et al. introduce BlockDetective, an innovative framework based on GCN that employs a student-teacher architecture to identify fraudulent cryptocurrency transactions. The framework incorporates pre-training and fine-tuning, enabling the pre-trained model (teacher) to effectively adapt to the new data distribution and improve prediction performance. Meanwhile, a lightweight model (student) is trained to provide abstract and high-level information. Experimental results demonstrate that BlockDetective outperforms state-of-the-art methods. Gong et al. propose a novel method called SCGformer, which aims to detect vulnerabilities in smart contracts. This novel method combines the power of a control flow graph (CFG) and a transformer model to enhance the accuracy and effectiveness of vulnerability detection. SCGformer involves constructing the CFGs using the operation codes (opcodes) of smart contracts. By focusing on the opcodes, SCGformer provides a language-agnostic solution, ensuring consistent vulnerability detection regardless of specific language versions. The authors conduct experiments to assess the efficacy of SCGformer, yielding an accuracy rate of 94.36%. Xiao et al. introduce a blockchain-based image copyright protection system named BB-RICP. By leveraging the distributed storage technique of blockchain, BB-RICP aims to solve the vulnerabilities of centralized storage, such as data loss and tampering. The system provides a novel solution for managing the entire lifecycle of copyright. It utilizes spread spectrum watermarking to enable traceability and incorporates GM algorithms and the PBFT consensus algorithm to enhance its functionality and effectiveness. Lastly, to enhance the practicality of the system, they implement a copyright blockchain framework called ICP-Chain and conduct evaluations to assess its security and reliability. Videira et al. propose a solution to tackle the offline puzzle in the implementation of central bank digital currencies (CBDC). This solution involves minting coins with unique serial numbers, which are then stored on a local blockchain within a smartphone or EMV card. The local blockchain is fortified by a two-stage approval architecture that effectively mitigates attacks and facilitates non-repudiation handling. To enhance security, the coins are safeguarded by hardware keys embedded in the microchip and can be continuously mined by the wallet. Feng et al. introduce a novel federated learning framework that leverages a Directed Acyclic Graph (DAG) to enhance interoperability among different blockchains. The framework comprises a shard chain and a main chain, featuring replaceable consensus mechanisms and a weighted context graph to enhance efficiency. The experimental results unequivocally demonstrate the efficacy of the proposed federated framework. Specifically, the framework significantly reduces the global computation requirements while simultaneously increasing the blockchain throughput. Xu et al. introduce ChainKeeper, a cross-chain scheme for governing the chain by chain. ChainKeeper incorporates several key components, including a modular node proxy program, a verifiable node random selection method (VNRS), and a verifiable identity threshold signature method (VITS). These components work together to ensure universality, efficiency, and security throughout the cross-chain process. The scheme is resilient against malicious behaviors and collaborative attacks from both business nodes and supervision nodes. The experimental results demonstrate the effectiveness of ChainKeeper in cross-chain supervision scenarios. Yu et al. present SPRA, a policy-based regulatory architecture designed to regulate blockchain transactions. The architecture comprises four layers: permission layer, regulation layer, bridge layer, and business layer. To facilitate interoperability between these layers, they introduce XRPL, a regulatory policy description language. The regulation layer incorporates JuryBC, a decentralized jury mechanism based on the Shamir threshold secret sharing algorithm and Pedersen commitment. At the business layer, they implement RDShare, a secure and efficient regulatory data sharing mechanism that utilizes attribute-based encryption. All the selected papers in this special issue showcase the continuous advancements in the field of blockchain and its application security. However, it is important to recognize that security and privacy issues in blockchain and its applications continue to pose significant challenges. These challenges serve as a driving force for further research and exploration of new technologies. They highlight the need for ongoing efforts to enhance the security and privacy aspects of blockchain, fostering a more resilient and trustworthy blockchain ecosystem. This work is supported by the National Key R&D Program of China (2020YFB1005500) and the National Natural Science Foundation of China (62372105). The authors would like to express their sincere appreciation to all the contributors who have submitted their scientific findings to this special issue and the anonymous reviewers whose expertise and meticulous work have made this endeavor possible. The authors sincerely hope that this collaborative effort will make a meaningful contribution to the advancement of the field. Lastly, the authors would like to express their utmost appreciation to the editors-in-chief and the editorial office for their unwavering support and guidance throughout this venture. Liangmin Wang received his B.S. degree in computational mathematics in Jilin University, Changchun, China in 1999, and his PhD degree in cryptology from Xidian University, Xi'an, China in 2007. He is a full professor in the School of Cyber Science and Engineering, Southeast University, Nanjing, China. He has been honored as a “Wan-Jiang Scholar” of Anhui Province since November 2013. Now his research interests include data security and privacy. He has published over 70 technical papers at premium international journals and conferences, for example, IEEE/ACM Transactions on Networking and IEEE International Conference on Computer Communications. He has severed as a TPC member of many IEEE conferences, such as IEEE ICC, IEEE HPCC, IEEE Trust-COM. Victor S. Sheng received the master's degree in computer science from the University of New Brunswick, Canada, in 2003, and the PhD degree in computer science from Western University, Ontario, Canada, in 2007. He is an associate professor of computer science, Texas Tech University, and the founding director of the Data Analytics Lab (DAL). His research interests include data mining, machine learning, and related applications. He was an associate research scientist and NSERC postdoctoral fellow in information systems at Stern Business School, New York University, after he obtained his PhD. He is a senior member of the IEEE and a lifetime member of the ACM. He received the test-of-time award for research from KDD’20, the best paper award runner-up from KDD’08, and the best paper award from ICDM’11. He is an area chair and SPC/PC member for several international top conferences and an associate editor for several international journals. Boris Düdder is an associate professor at the department of computer science (DIKU) at the University of Copenhagen (UCPH), Denmark. He is head of the research group Software Engineering & Formal Methods at DIKU. His primary research interests are formal methods and programming languages in software engineering of trustworthy distributed systems, where he is studying automated program generation for adaptive systems with high-reliability guarantees. He is working on the computational foundations of reliable and secure Big Data ecosystems. His research is bridging the formal foundations of computer science and complex industrial applications. Haiqin Wu received her B.E. degree in computer science and Ph.D. degree in computer application technology from Jiangsu University in 2014 and 2019, respectively. She is an associate professor at the Shanghai Key Laboratory of Trustworthy Computing (Software Engineering Institute), East China Normal University, China. Before joining ECNU, she was a postdoctoral researcher in the Department of Computer Science, University of Copenhagen, Denmark. She was also a visiting student in the School of Computing, Informatics, and Decision Systems Engineering at Arizona State University, USA. Her research interests include data security and privacy protection, mobile crowdsensing/crowdsourcing, and blockchain-based applications. Huijuan Zhu received her master's degree at School of Computer Science and Communication Engineering in Jiangsu University, Zhenjiang, China in 2010 and her Ph.D. degree at School of Computer and Control Engineering in University of Chinese Academy of Sciences, Beijing, China in 2017. Her research interests include malware detection and machine learning. She is an associate professor in the School of Computer Science and Communication Engineering at Jiangsu University.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 18, 2023·2023 IEEE Secure Development Conference (SecDev)
4 cites
Security and Privacy Threat Analysis for Solid

Omid Mirzamohammadi, Kristof Jannes, Laurens Sion, Dimitri Van Landuyt · 6 authors

This paper provides an in-depth security and privacy analysis of the Solid protocol. Solid is a specification that allows user data to be stored decentralized in a personal online datastore (pod) independent from the application. This allows users to easily migrate to a different service and have more control over who data is shared with. We provide a comprehensive overview of the authentication, identification, and authorization protocols within Solid. We make use of the SPARTA threat modeling tool to assess the security and privacy aspects of Solid by modeling a realistic finance analytics application envisioned by the Solid community. This concrete use case allowed us to prioritize the residual threats in Solid. We employ methodologies such as STRIDE and LINDDUN for robust security and privacy threat modeling. The findings highlight the existence of several critical threats in the Solid specification. This is especially the case for privacy threats, which although it is an essential aspect of Solid, has so far not yet received enough attention, as our results indicate. These findings can be employed in future work to prioritize which residual threats to address and mitigate first.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Oct 17, 2023·Big Data and Cognitive Computing
69 cites
ZeroTrustBlock: Enhancing Security, Privacy, and Interoperability of Sensitive Data through ZeroTrust Permissioned Blockchain

Pratik Thantharate, Anurag Thantharate

With the digitization of healthcare, an immense amount of sensitive medical data are generated and shared between various healthcare stakeholders—however, traditional health data management mechanisms present interoperability, security, and privacy challenges. The centralized nature of current health information systems leads to single points of failure, making the data vulnerable to cyberattacks. Patients also have little control over their medical records, raising privacy concerns. Blockchain technology presents a promising solution to these challenges through its decentralized, transparent, and immutable properties. This research proposes ZeroTrustBlock, a comprehensive blockchain framework for secure and private health information exchange. The decentralized ledger enhances integrity, while permissioned access and smart contracts enable patient-centric control over medical data sharing. A hybrid on-chain and off-chain storage model balances transparency with confidentiality. Integration gateways bridge ZeroTrustBlock protocols with existing systems like EHRs. Implemented on Hyperledger Fabric, ZeroTrustBlock demonstrates substantial security improvements over mainstream databases via cryptographic mechanisms, formal privacy-preserving protocols, and access policies enacting patient consent. Results validate the architecture’s effectiveness in achieving 14,200 TPS average throughput, 480 ms average latency for 100,000 concurrent transactions, and linear scalability up to 20 nodes. However, enhancements around performance, advanced cryptography, and real-world pilots are future work. Overall, ZeroTrustBlock provides a robust application of blockchain capabilities to transform security, privacy, interoperability, and patient agency in health data management.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Oct 13, 2023·Engineering Technology & Applied Science Research
8 cites
Efficient and Secure Access Control for IoT-based Environmental Monitoring

Asia Othman Aljahdali, Afnan Habibullah, Huda Aljohani

Environmental monitoring devices based on IoT collect a large amount of data about the environment and our surroundings. These data are collected and processed before being uploaded to third-party servers and accessed and viewed by ordinary or specialized users. However, they may hold sensitive information that should not be exposed to unauthorized users. Therefore, accessing this sensitive information must be strictly controlled and limited in order to prevent unauthorized access. This research intends to create an access control mechanism based on distributed ledger technologies. The idea is to use a hybrid of IOTA technology and Ciphertext-Policy Attribute-Based Signcryption (CP-ABSC) technology. The permissions to access these data are written in a token, and this token will be sent to the Tangle after being signcrypted with CP-ABSC. Consequently, the data will be safeguarded, their confidentiality and integrity will be maintained, and unauthorized individuals will be unable to access the information. The proposed system was evaluated in terms of performance and the results showed that the system is straightforward, rapid, and convenient to use. Furthermore, a security assessment was conducted by running several scenarios to evaluate its feasibility and protection.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Oct 13, 2023·IEEE Transactions on Parallel and Distributed Systems
7 cites
HybridChain: Fast, Accurate, and Secure Transaction Processing with Distributed Learning

Amirhossein Taherpour, Xiaodong Wang

In order to fully unlock the transformative power of distributed ledgers and blockchains, it is crucial to develop innovative consensus algorithms that can overcome the obstacles of security, scalability, and interoperability, which currently hinder their widespread adoption. This paper introduces HybridChain that combines the advantages of sharded blockchain and DAG distributed ledger, and a consensus algorithm that leverages decentralized learning. Our approach involves validators exchanging perceptions as votes to assess potential conflicts between transactions and the witness set, representing input transactions in the UTXO model. These perceptions collectively contribute to an intermediate belief regarding the validity of transactions. By integrating their beliefs with those of other validators, localized decisions are made to determine validity. Ultimately, a final consensus is achieved through a majority vote, ensuring precise and efficient validation of transactions. Our proposed approach is compared to the existing DAG-based scheme IOTA and the sharded blockchain Omniledger through extensive simulations. The results show that IOTA has high throughput and low latency but sacrifices accuracy and is vulnerable to orphanage attacks especially with low transaction rates. Omniledger achieves stable accuracy by increasing shards but has increased latency. In contrast, the proposed HybridChain exhibits fast, accurate, and secure transaction processing, and excellent scalability.

Open access
3 source records
cs.DC
Blockchain Technology Applications and Security
Advanced Memory and Neural Computing
Original source
Oct 8, 2023·Drones
11 cites
A Hierarchical Blockchain-Based Trust Measurement Method for Drone Cluster Nodes

Jinxin Zuo, Ruohan Cao, Jiahao Qi, Peng Gao · 8 authors

In response to the challenge of low accuracy in node trust evaluation due to the high dynamics of entry and exit of drone cluster nodes, we propose a hierarchical blockchain-based trust measurement method for drone cluster nodes. This method overcomes the difficulties related to trust inheritance for dynamic nodes, trust re-evaluation of dynamic clusters, and integrated trust calculation for drone nodes. By utilizing a multi-layer unmanned cluster blockchain for trusted historical data storage and verification, we achieve scalability in measuring intermittent trust across time intervals, ultimately improving the accuracy of trust measurement for drone cluster nodes. We design a resource-constrained multi-layer unmanned cluster blockchain architecture, optimize the computing power balance within the cluster, and establish a collaborative blockchain mechanism. Additionally, we construct a dynamic evaluation method for trust in drone nodes based on task perception, integrating and calculating the comprehensive trust of drone nodes. This approach addresses trusted sharing and circulation of task data and resolves the non-inheritability of historical data. Experimental simulations conducted using NS3 and MATLAB demonstrate the superior performance of our trust value measurement method for unmanned aerial vehicle cluster nodes in terms of accurate malicious node detection, resilience to trust value fluctuations, and low resource delay retention.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Security in Wireless Sensor Networks
Original source
Oct 7, 2023·Adjunct Proceedings of the 2023 ACM International Joint Conference on Pervasive and Ubiquitous Computing & the 2023 ACM International Symposium on Wearable Computing
0 cites
Smart Contracts for Ethical Mobile Data Collection and Usage

José Ricardo Cedeño-García, Jesús Favela, Carlos Eduardo Sánchez-Torres

The significant increase in data production resulting from the widespread adoption of mobile and IoT technologies has revolutionized healthcare but also presents significant privacy and ethical challenges. The field of medical data collection is no exception and has limitations in terms of the source, variety and quantity of records from studies on healthcare and wellness. One way to address this dilemma is the use of the Blockchain for patient data collection and use. The anonymity of a centralized network allows the patient’s identity to be protected. The structure formed by nodes allows the information to be always available and does not depend on a main server. The immutability of records in the chain ensures unambiguous traceability of information flow by the healthcare provider. Finally, the network’s consensus and reward mechanisms could motivate new users to participate in active sensing. In this article we will expose the architecture of an application that relies on the Blockchain to meet the above information needs by leveraging the potential of the Ethereum network. In addition, we present a use case where consciously collected data from our platform is used to train a machine learning model automatically, using a P2P Browser-Based Computational Notebook as execution and distribution environment.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Ethics and Social Impacts of AI
Original source
Oct 7, 2023·Cybersecurity
3 cites
Evicting and filling attack for linking multiple network addresses of Bitcoin nodes

Huashuang Yang, Jinqiao Shi, Yue Gao, Xuebin Wang · 7 authors

Abstract Bitcoin is a decentralized P2P cryptocurrency. It supports users to use pseudonyms instead of network addresses to send and receive transactions at the data layer, hiding users’ real network identities. Traditional transaction tracing attack cuts through the network layer to directly associate each transaction with the network address that issued it, thus revealing the sender’s network identity. But this attack can be mitigated by Bitcoin’s network layer privacy protections. Since Bitcoin protects the unlinkability of Bitcoin addresses and there may be a many-to-one relationship between addresses and nodes, transactions sent from the same node via different addresses are seen as coming from different nodes because attackers can only use addresses as node identifiers. In this paper, we proposed the evicting and filling attack to expose the correlations between addresses and cluster transactions sent from different addresses of the same node. The attack exploited the unisolation of Bitcoin’s incoming connection processing mechanism. In particular, an attacker can utilize the shared connection pool and deterministic connection eviction strategy to infer the correlation between incoming and evicting connections, as well as the correlation between releasing and filling connections. Based on inferred results, different addresses of the same node with these connections can be linked together, whether they are of the same or different network types. We designed a multi-step attack procedure, and set reasonable attack parameters through analyzing the factors that affect the attack efficiency and accuracy. We mounted this attack on both our self-run nodes and multi-address nodes in real Bitcoin network, achieving an average accuracy of 96.9% and 82%, respectively. Furthermore, we found that the attack is also applicable to Zcash, Litecoin, Dogecoin, Bitcoin Cash, and Dash. We analyzed the cost of network-wide attacks, the application scenario, and proposed countermeasures of this attack.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
Oct 6, 2023·IEEE Transactions on Network and Service Management
19 cites
Redactable Blockchain-Assisted Secure Data Aggregation Scheme for Fog-Enabled Internet-of-Farming-Things

Rahul Mishra, Dharavath Ramesh, Paolo Bellavista, Damodar Reddy Edla

Internet-of-Farming Things (IoFT)-enabled smart agriculture can collect data more reliably and frequently to track the crop’s status and other significant information. Considering that smart agriculture requires working with substantial amounts of sensitive data. In light of this, frequent data processing may threaten the confidentiality and integrity of data and IoFT device privacy. Although numerous privacy-preserving data aggregation methods have been implemented to address these issues, they also have certain security vulnerabilities, such as inadequate data confidentiality, collusion attacks, and malicious data mining attacks. Therefore, we introduce a three-tier architecture-assisted redactable blockchain-based secure data aggregation method with source authentication for the fog-enabled IoFT. This work provides an efficient and secure two-level data aggregation model. The proposed model supports resistance to collusion and malicious data mining threats launched by internal or external attackers. It can also achieve perfect data confidentiality and integrity against a malicious aggregator and an inquisitive control center for an authorized IoFT device. Specifically, the detailed performance analysis and theoretical concrete security proofs demonstrate the practicability and efficiency of the proposed model.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
IoT and Edge/Fog Computing
Original source
Oct 4, 2023·IEEE Transactions on Big Data
38 cites
zkFL: Zero-Knowledge Proof-Based Gradient Aggregation for Federated Learning

Zhipeng Wang, Nanqing Dong, Jiahao Sun, William J. Knottenbelt · 5 authors

Federated learning (FL) is a machine learning paradigm, which enables multiple and decentralized clients to collaboratively train a model under the orchestration of a central aggregator. FL can be a scalable machine learning solution in big data scenarios. Traditional FL relies on the trust assumption of the central aggregator, which forms cohorts of clients honestly. However, a malicious aggregator, in reality, could abandon and replace the client's training models, or insert fake clients, to manipulate the final training results. In this work, we introduce zkFL, which leverages zero-knowledge proofs to tackle the issue of a malicious aggregator during the training model aggregation process. To guarantee the correct aggregation results, the aggregator provides a proof per round, demonstrating to the clients that the aggregator executes the intended behavior faithfully. To further reduce the verification cost of clients, we use blockchain to handle the proof in a zero-knowledge way, where miners (i.e., the participants validating and maintaining the blockchain data) can verify the proof without knowing the clients' local and aggregated models. The theoretical analysis and empirical results show that zkFL achieves better security and privacy than traditional FL, without modifying the underlying FL network structure or heavily compromising the training speed.

Open access
3 source records
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Stochastic Gradient Optimization Techniques
Original source
Oct 3, 2023·Annual Computer Security Applications Conference
9 cites
FLEDGE: Ledger-based Federated Learning Resilient to Inference and Backdoor Attacks

Jorge Castillo, Phillip Rieger, Hossein Fereidooni, Qian Chen · 5 authors

Federated learning (FL) is a distributed learning process that uses a trusted aggregation server to allow multiple parties (or clients) to collaboratively train a machine learning model without having them share their private data. Recent research, however, has demonstrated the effectiveness of inference and poisoning attacks on FL. Mitigating both attacks simultaneously is very challenging. State-of-the-art solutions have proposed the use of poisoning defenses with Secure Multi-Party Computation (SMPC) and/or Differential Privacy (DP). However, these techniques are not efficient and fail to address the malicious intent behind the attacks, i.e., adversaries (curious servers and/or compromised clients) seek to exploit a system for monetization purposes. To overcome these limitations, we present a ledger-based FL framework known as FLEDGE that allows making parties accountable for their behavior and achieve reasonable efficiency for mitigating inference and poisoning attacks. Our solution leverages crypto-currency to increase party accountability by penalizing malicious behavior and rewarding benign conduct. We conduct an extensive evaluation on four public datasets: Reddit, MNIST, Fashion-MNIST, and CIFAR-10. Our experimental results demonstrate that (1) FLEDGE provides strong privacy guarantees for model updates without sacrificing model utility; (2) FLEDGE can successfully mitigate different poisoning attacks without degrading the performance of the global model; and (3) FLEDGE offers unique reward mechanisms to promote benign behavior during model training and/or model aggregation.

Open access
2 source records
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Oct 2, 2023·Universitat Politècnica de Catalunya
0 cites
Coercion-resistant cast-as-intended verifiability in electronic voting systems

Tamara Finogina

(English) One of the most common fears regarding electronic voting is that a voting device will disregard the voter's intent and cast a different vote instead. An undetectable attack like that on a large scale will allow the adversary to control the election result completely. Therefore, the cast-as-intended verification, which ensures that the ballot contains the voter's choice and not something else, is crucial. Another common fear when introducing electronic voting is coercion, which captures a variety of ways the coercer can use to prevent voters from expressing their will. Hence, coercion resistance is a valuable property of electronic voting as well. One particularly challenging task is to find a trade-off between ensuring a voter cannot be coerced and, at the same time, preventing a malicious voting device from cheating. This thesis explores this trade-off to find how we can provide coercion-resistant cast-as-intended verification. The contributions can be roughly divided into three parts: (1) study in the standard settings, (2) exploration of post-quantum cryptography, and (3) practical constructions and search for the limitations of both properties. In the first part, we give an extensive overview of the current state of the art in electronic voting literature regarding those properties. Then, we put forward two formal definitions for achieving coercion-resistant cast-as-intended verification in settings without pre-exchanged data. After that, we present two practical constructions and prove their security under the proposed definitions. We also show the efficiency of our proposals by providing proof of the concept implementations. In the second part, we switch to post-quantum settings and identify the usability issues rooted in the lattice-based math affecting both proposed solutions. To address those issues, we present a generic transformation that departs from an interactive zero-knowledge system (that might require multiple re-runs to complete the protocol) and obtains a 3-move zero-knowledge system (without re-runs). The transformation combines the well-known Fiat-Shamir technique with several initially exchanged messages. The resulting 3-move system enjoys honest-verifier zero-knowledge and can be easily turned into a fully deniable proof using standard methods. In the final part, we focus on the practical aspects of the coercion-resistant cast-as-intended verification. First, we present the case of a computationally limited voter, which we consider the most realistic. We show that even a computationally limited voter can enjoy coercion-resistant cast-as-intended verification, but a help of a simple aid device for nonce generation is required. Also, we demonstrate that our generic definition easily adapts to the constraints of the limited voter. After that, we present ongoing work that focuses on the cases of extreme coercion based on new and unexplored mechanisms such as delay encryption and blockchain. We show an advanced coercive attack on our first construction and describe an improvement to the second solution that reduces the number of interactions to an optimal three rounds. To summarize, we start by studying coercion-resistant cast-as-intended verification in standard settings, which results in formal definitions and two practical solutions. Then we move into the post-quantum world, where we learn that an extra step is needed to preserve the usability of our previously proposed constructions, which results in the generic transformation to avoid protocol re-runs. After that, we concentrate on a computationally limited voter, which leads to another simple solution and shows the adaptability of our original definitions. Finally, we explore the extreme coercion threats, which result in a new coercion attack on the first construction and upgrade of the second solution. (Català) Una de les preocupacions més comunes pel que fa al vot electrònic és que el dispositiu de votació no tingui en compte la intenció del votant i emeti un vot diferent. Un atac com aquest, si no fos detectable, a gran escala permetria a l'adversari controlar completament el resultat electoral. Per tant, és crucial permetre la propietat de verificació de la intenció del vot emès, la qual garanteix que la papereta contingui la intenció del votant i no una altra cosa. Una altra preocupació és la coacció, que engloba una varietat de maneres que el coaccionador pot utilitzar per obligar que els votants expressin la seva voluntat. La prevenció de la coacció també és una propietat valuosa del vot electrònic .Una tasca especialment difícil és trobar un compromís entre assegurar que un votant no pot ser coaccionat i, al mateix temps, evitar que un dispositiu de vot compromès faci trampes. Aquesta tesi analitza aquesta problemàtica; les contribucions de la tesi es poden dividir en tres parts: (1) estudi de les configuracions d’escenaris de vot estàndards, (2) exploració de la criptografia post-quàntica i (3) construccions pràctiques i cerca de les limitacions d'ambdues propietats. A la primera part, donem una visió general de l'estat actual de la literatura sobre el vot electrònic relacionada a aquestes propietats. A continuació, proposem dues definicions formals per assolir una verificació resistent a la coacció de la intenció del vot emès, en escenaris on no existeix un intercanvi de dades previ. Després, presentem dues propostes pràctiques i demostrem la seva seguretat sota les definicions proposades. També mostrem l'eficàcia de les nostres propostes implementant proves de concepte A la segona part, canviem a l’escenari post-quàntic amb matemàtiques basades en reticles i identifiquem els problemes d'usabilitat que afectarien ambdues solucions proposades en aquest nou escenari. Per solucionar-los, presentem una transformació genèrica que parteix d'un sistema interactiu de coneixement nul (que podria requerir múltiples re-execucions per completar el protocol) i que obté un sistema de coneixement nul de 3 moviments (sense re-execucions). La transformació combina la coneguda tècnica Fiat-Shamir amb diversos missatges intercanviats inicialment. A la part final, ens centrem en els aspectes pràctics de la verificació resistent a la coacció de la intenció del vot emès. En primer lloc, presentem el cas d'un votant limitat computacionalment, que considerem el més realista. Mostrem que fins i tot un votant amb limitacions computacionals pot gaudir d'una verificació resistent a la coacció de la intenció del vot emès, però requereix l'ajuda d'un dispositiu senzill per a la generació d’una prova. A més, demostrem que la nostra definició genèrica s'adapta fàcilment a les limitacions del votant. Després d'això, presentem un treball recent que se centra en els casos de coacció extrema basats en mecanismes nous i poc explorats com ara el xifrat amb retard i la cadena de blocs. Mostrem un atac coercitiu avançat a la nostra primera proposta genèrica i descrivim una millora de la segona que redueix el nombre d'interaccions a tres rondes òptimes. Com a resum, comencem estudiant la verificació resistent a la coacció de la intenció del vot emès en entorns criptogràfics estàndard, que dóna lloc a definicions formals i dues solucions pràctiques. Aleshores ens movem al món de la criptografia post-quàntica, on cal un pas addicional per preservar la usabilitat de les dues solucions proposades anteriorment: una transformació genèrica per evitar repeticions del protocol. Després d'això, ens concentrem en un votant computacionalment limitat, que condueix a una altra solució senzilla i mostra l'adaptabilitat de les nostres definicions originals. Finalment, explorem les amenaces de coacció extremes, que donen lloc a un nou atac de coerció a la primera solució i a una actualització de la segona solució.

Open access
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
Sep 29, 2023·Journal of Knowledge Learning and Science Technology ISSN 2959-6386 (online)
29 cites
Data Guardianship: Safeguarding Compliance in AI/ML Cloud Ecosystems

Samir Vinayak Bayani, Sanjeev Prakash, Lavanya Shanmugam

AI has found widespread application across various sectors, including security, healthcare, finance, and national defense. However, alongside its transformative advancements, there has been an unfortunate trend of malicious exploitation of AI capabilities. Concurrently, the rapid evolution of cloud computing technology has introduced cloud-based AI systems. Regrettably, vulnerabilities inherent in cloud computing infrastructure also pose risks to the security of AI services. We observe that the integrity of training data is pivotal, as any compromise therein directly impacts the efficacy of AI systems. Against this backdrop, we assert the paramount importance of preserving data integrity within AI systems. To address this imperative, we propose a data integrity architecture guided by the National Institute of Standards and Technology (NIST) cyber security framework. Leveraging block chain technology and smart contracts emerges as a fitting solution to tackle integrity challenges, owing to their characteristics of shared and decentralized ledgers. Smart contracts facilitate automated policy enforcement, enable continuous monitoring of data integrity, and mitigate the risk of data tampering.

Open access
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Sep 26, 2023·Journal of Computer Security
7 cites
Securing blockchain-based timed data release against adversarial attacks1

Jingzhe Wang, Balaji Palanisamy

Timed data release refers to protecting sensitive data that can be accessed only after a pre-determined amount of time has passed. While blockchain-based solutions for timed data release provide a promising approach for decentralizing the process, designing an attack-resilient timed-release service that is resilient to malicious adversaries in a blockchain network is inherently challenging. A timed-release service on a blockchain network is inevitably exposed to the risk of post-facto attacks where adversaries may launch attacks after the data is released in the blockchain network. Existing incentive-based solutions for timed data release in Ethereum blockchains guarantee protection under the assumption of a fully rational adversarial environment in which every peer acts rationally. However, these schemes fail invariably when even a single participating peer node in the protocol starts acting maliciously and deviates from the rational behavior. In this paper, we propose a systematic solution for attack-resilient and practical blockchain-based timed data release in a mixed adversarial environment, where both malicious adversaries and rational adversaries exist. We first propose an effective uncertainty-aware reputation measure to capture the behaviors of the peer involved in timed data release activities in the network. In light of such a measure, we present the design of a basic protocol that consists of two critical ingredients, namely reputation-aware peer recruitment and verifiable enforcement protocols. The former, prior to the start of the enforcement protocols, performs peer recruitment based on the reputation measure to make the design probabilistically attack-resilient to the post-facto attacks. The latter is responsible for contractually guarding the recruited peers at runtime by transparently reporting observed adversarial behaviors. However, the basic recruitment design is only aware of the reputation of the peers and it does not consider the working time schedule of the participating peers and as a result, it results in lower attack-resilience. To enhance the attack resilience further without impacting the verifiable enforcement protocols, we propose a temporal graph-based reputation-aware peer recruitment algorithm that carefully determines the peer recruitment plan to make the service more attack-resilient. In our proposed approach, we formally capture the timed data release service as a temporal graph and we develop a novel maximal attack-resilient path-finding algorithm on the temporal graph for the participating peers. We implement a prototype of the proposed approach using Smart Contracts and deploy it on the Ethereum official test network, Rinkeby. For extensively evaluating the proposed techniques, we perform simulation experiments to validate the effectiveness of the reputation-aware timed data release protocols as well as our proposed temporal-graph-based improvements. The results demonstrate the effectiveness and strong attack resilience of the proposed mechanisms and our approach incurs only a modest gas cost.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source