Jiajing Wu, Qi Yuan, Dan Lin, Wei You · 7 authors
Recently, blockchain technology has become a topic in the spotlight but also a hotbed of various cybercrimes. Among them, phishing scams on blockchain have been found making a notable amount of money, thus emerging as a serious threat to the trading security of the blockchain ecosystem. In order to create a favorable environment for investment, an effective method for detecting phishing scams is urgently needed in the blockchain ecosystem. To this end, this paper proposes an approach to detect phishing scams on Ethereum by mining its transaction records. Specifically, we first crawl the labeled phishing addresses from two authorized websites and reconstruct the transaction network according to the collected transaction records. Then, by taking the transaction amount and timestamp into consideration, we propose a novel network embedding algorithm called trans2vec to extract the features of the addresses for subsequent phishing identification. Finally, we adopt the oneclass support vector machine (SVM) to classify the nodes into normal and phishing ones. Experimental results demonstrate that the phishing detection method works effectively on Ethereum, and indicate the efficacy of trans2vec over existing state-of-the-art algorithms on feature extraction for transaction networks. This work is the first investigation on phishing detection on Ethereum via network embedding and provides insights into how features of large-scale transaction networks can be embedded.
We study the liquid democracy problem, where each voter can either directly vote to a candidate or delegate his voting power to a proxy. We consider the implementation of liquid democracy on the blockchain through Ethereum smart contract and to be compatible with the realtime self-tallying property, where the contract itself can record ballots and update voting status upon receiving each voting massage. A challenge comes due to the gas fee limitation of Ethereum mainnet, that the number of instruction for processing a voting massage can not exceed a certain amount, which restrict the application scenario with respect to algorithms whose time complexity is linear to the number of voters. We propose a fast algorithm to overcome the challenge, such that i) shifts the on-chain initialization to off-chain and ii) the on-chain complexity for processing each voting massage is O(\log n), where n is the number of voters.
David Allessie, Martijn Janssen, Jolien Ubacht, Scott W. Cunningham · 5 authors
Blockchain technology has the potential to provide public services directly to the public. This challenges the need for public organizations, who traditionally provided these services. Much of the current work is focused on the technology, whereas the influence on public administration structure has gained less attention. The goal of this paper is to investigate the impact of blockchain technology on the governance of public service provision. For this, we performed a case study of an EU-wide system that monitors the movement of excise goods under duty suspension. We developed two scenarios for blockchain technology’s use based on a permissionless blockchain architecture on the one hand and a permissioned one on the other. The scenarios were evaluated based on their impact on transaction validation, data quality and governance. The findings show that blockchain technology alone cannot be an alternative for the current data quality controls, equal access assurances and adaptations to legislation conducted by public administrations. As such, governments will remain playing a key role in registration of documents and assets, however, the governance will likely change depending on the type of blockchain architecture.
Organized surveillance, especially by governments poses a major challenge to individual privacy, due to the resources governments have at their disposal, and the possibility of overreach. Given the impact of invasive monitoring, in most democratic countries, government surveillance is, in theory, monitored and subject to public oversight to guard against violations. In practice, there is a difficult fine balance between safeguarding individual's privacy rights and not diluting the efficacy of national security investigations, as exemplified by reports on government surveillance programs that have caused public controversy, and have been challenged by civil and privacy rights organizations. Surveillance is generally conducted through a mechanism where federal agencies obtain a warrant from a federal or state judge (e.g., the US FISA court, Supreme Court in Canada) to subpoena a company or service-provider (e.g., Google, Microsoft) for their customers' data. The courts provide annual statistics on the requests (accepted, rejected), while the companies provide annual transparency reports for public auditing. However, in practice, the statistical information provided by the courts and companies is at a very high level, generic, is released after-the-fact, and is inadequate for auditing the operations. Often this is attributed to the lack of scalable mechanisms for reporting and transparent auditing. In this paper, we present SAMPL, a novel auditing framework which leverages cryptographic mechanisms, such as zero knowledge proofs, Pedersen commitments, Merkle trees, and public ledgers to create a scalable mechanism for auditing electronic surveillance processes involving multiple actors. SAMPL is the first framework that can identify the actors (e.g., agencies and companies) that violate the purview of the court orders. We experimentally demonstrate the scalability for SAMPL for handling concurrent monitoring processes without undermining their secrecy and auditability.
Blockchain is the technology that has attracted enormous interest recently as it provides security and privacy through immutable distributed ledger. It is the backbone of the most popular cryptocurrency, bitcoin. Due to its robust consensus mechanism and tamper proof data storage, it is widely adopted in the applications where trust is given utmost importance.Homomorphic Encryption algorithms can be used to operate on the data that is encrypted without the knowledge of private key. Operations can be performed on encrypted data without decrypting the data. Only client knows about the private key. These two technologies can be used to securely transfer and store data in the cloud systems.In this paper we propose how this blockchain technology and homomorphic encryption can be used to build reliable, tamper-proof and efficient electronic voting system. An electronic voting system should be secure, and itshould not allow duplicate votes and be fully tamper proof, while protecting the privacy of the voters. In this work, we have designed, implemented and tested an electronic voting application and providing hashing for votes and stored in blockchaincloud.If data in database is lost, then it can be retrieved from blockchain cloud.
Recently, crowd sensing has been intensively researched, due to the rapid growth of sensor-integrated mobile devices. Crowd sensing is a participatory sensing service where a server gathers and analyzes sensing data submitted from mobile devices of lots of users. In crowd sensing, the user's anonymity is desired, since the server gathers sensitive data from the participants including their GPS locations and moving path. However, the anonymous data submission may compromise the trust of the sensing data, because anonymous users may submit inappropriate sensing data, but they cannot be traced. Therefore, as the system to achieve both anonymity and trust in crowd sensing, ARTSense has been proposed. In the system, the trust of the sensing data is assessed on the sensed environment, other users' sensing, and the reputation of the user, and furthermore the reputation of the user is anonymously managed on the feedback from the trust assessment for the data. However, the anonymous reputation system of ARTSense has the efficiency problem, i.e., the user needs to wait a random time after the data submission phase before requesting the reputation update, which causes the communication delay. In this paper, we propose an efficient anonymous reputation system for crowd sensing, which can be integrated to the trust assessment in ARTSense. In the proposed system, during the data submission, the reputation update is anonymously completed. This is because the server does not manage the reputation of each user, but each user manages his/her reputation in the user side, where the the validity of the reputation is ensured by a certificate and anonymously checked by zero-knowledge proofs. Therefore, the proposed system achieves the better efficiency with no delay.
Blockchain and cryptocurrencies have been widely deployed and used in our daily life. Although there are numerous works in the literature surveying technical challenges and security issues in blockchains, very few works focused on the anonymity guarantees provided in cryptocurrencies. In this work, we conduct a systematic survey on anonymity in cryptocurrencies with a clear categorization for the different tiers of anonymity offered in the various cryptocurrencies as well as their known weaknesses and vulnerabilities. We also study the techniques that have been used to achieve each tier of anonymity. Finally, we asses the current techniques, and present a forecast for the technological trends in this field.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
There is no uncertainty that the chroma currency is very popular for the transaction information stored in the block of blocks. To initiate the importance of blocking, there is only one distributed ledger in which data is stored, since many of the centers in the blockchain network limit enough records for these records. This document proposes a decision-making framework based on innovation to create a secure, unjustifiable, accurate and transparent framework for voter privacy. In addition, it is voted and declared in this context that the race has a short period of time, since it is automatically registered in the table. This framework also gives society confidence in its legislation when applying this technique. In this framework, an administrator can add a candidate and a voter to the block. In different hands, a voter can log into the framework and then decide in favor of a candidate that the details of the vote should be stored in the block. In addition, each square in the blockchain innovation that relates to the previous square contains the hash of the previous square, and each square contains explicit data based on the square footage. The hub is connected by a peer network in this framework, with all the hubs in the block site network that have a complete duplicate block.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Kazi Sadia, Md Masuduzzaman, Rajib Kumar Paul, Anik Islam
Voting is a very important issue which can be beneficial in term of choosing the right leader in an election. A good leader can bring prosperity to a country and also can lead the country in the right direction every time. However, elections are surrounds with ballot forgery, coercion and multiple voting issues. Moreover, while giving votes, a person has to wait in a long queue and it is a very time consuming process. Blockchain is a distributed database in which data are shared with the participant of the node and each participant holds the same copy of the data. Blockchain has properties like distributed, pseudonymous, data integrity etc. In the paper, a fully decentralized evoting system based on blockchain technology is proposed. This protocol utilizes smart contract into the evoting system to deal with security issues, accuracy and voters privacy during the vote. The protocol results in a transparent, non editable and independently verifiable procedure that discards all the intended fraudulent activities occurring during the election process by removing the least participation of the third party and enabling voters right during the election. Both transparency and coercion are obtained at the same time.
Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
This paper describes a decentralized electronic voting system using blockchain technology with peer-to-peer network rather than the centralized voting system of server-client structure. In the proposed system, an Ethereum-based private blockchain network is configured and decentralized applications are implemented to store and distribute voting data to all nodes participating in the network to create secure and reliable electronic voting system. Smart contracts for electronic voting are implemented using the Solidity language and distributed to a configured network so that all users can view and vote on elections, and voting data are shared and contrasted by all users in the network, which makes it possible to build a safer and more reliable electronic voting system without third party involvement.
Maurantonio Caprolu, Simone Raponi, Gabriele Oligeri, Roberto Di Pietro
Cryptojacking occurs when an adversary illicitly runs crypto-mining software over the devices of unaware users. This novel cybersecurity attack, that is emerging in both the literature and in the wild, has proved to be very effective given the simplicity of running a crypto-client into a target device. Several countermeasures have recently been proposed, with different features and performance, but all characterized by a host-based architecture. The cited solutions, designed to protect the individual user, are not suitable for efficiently protecting a corporate network, especially against insiders. In this paper, we propose a network-based approach to detect and identify crypto-clients activities by solely relying on the network traffic, even when encrypted and mixed with non-malicious traces. First, we provide a detailed analysis of the real network traces generated by three major cryptocurrencies, Bitcoin, Monero, and Bytecoin, considering both the normal traffic and the one shaped by a VPN. Then, we propose Crypto-Aegis, a Machine Learning (ML) based framework built over the results of our investigation, aimed at detecting cryptocurrencies related activities, e.g., pool mining, solo mining, and active full nodes. Our solution achieves a striking 0.96 of F1-score and 0.99 of AUC for the ROC, while enjoying a few other properties, such as device and infrastructure independence. Given the extent and novelty of the addressed threat we believe that our approach, supported by its excellent results, pave the way for further research in this area.
This research explores Law Enforcement Agency (LEA) applications for digital watermarking performed on the camera in real time, combining this with Distributed Ledger Technology (DLT) to suggest workable systems for data cataloguing and image integrity. Reference implementations of both technologies are developed and evaluated for their effectiveness and suitability for these purposes.
Open access
Advanced Steganography and Watermarking Techniques
The modernization of democratic institutions has been greatly influenced by the intensive development of technology. Various innovations in the field of digital communications have affected a rather traditional sphere of popular votings. The widespread introduction of the distributed ledger technology has enormously changed approaches to organizing them. Distributed registers gained the widest popularity after the technology of the chain of blocks (blockchain) was introduced. Despite the fact that initially this technology was considered exclusively as an element of the development of information, and later financial technologies, at the present stage it is gradually becoming increasingly common in other areas of human activity due to a high degree of security and confidentiality. The paper deals in detail with the world practice concerning using this technology in popular voting. Also, the author analizes the technical solutions applied in the most actively developing projects aimed at developing a software used to conduct electronic voting with the use of blockchain technology. The article investigates some problems of voting with the use of blockchain technology, such as identification and secrecy of the vote.
Chinnapong Angsuchotmetee, Pisal Setthawong, Sapjarern Udomviriyalanon
Voting is an essential activity in the modern democracy. To facilitate the voting process, there are several attempts on proposing an electronic voting system such that, the voting and tallying processes can be done efficiently and the results would be accountable to the public. To date, however, an online electronic voting system has been rarely adopted in practice due to the possibility of having the voting result tampered through vote-rigging or cyber-attacking. In 2009, the blockchain algorithm was proposed by Satoshi Nakamoto. Blockchain is a technique for recording transactions between self-auditing ledgers in an open, distributed, permanent, and verifiable manner. Even though blockchain was originally designed for a financial applications, it is possible to apply blockchain to other domains, including in the implementation of an online decentralized-based electronic voting system. In this study, the architecture of a blockchain-based electronic voting system, named \textit{BlockVOTE}, is proposed. The architecture design and all related formal definitions are given. To validate the proposal, two BlockVOTE prototypes were implemented using two different blockchain application frameworks. The performance analysis of both versions of the prototypes are given. The analysis of both technical and management aspects on the possibility of adopting the proposed decentralized voting system in an actual voting scenario is also given at the end of this study.
Smart city is one of the major Internet of Things (IoT) applications and has become an emerging paradigm with the recent advancements of IoT devices and sensors. But the heterogenous nature of a smart city IoT environment makes it vulnerable to many privacy and security concerns and introduces significant challenges for access control of IoT resources especially where access needs to be provided to third parties and external organizations. This paper proposes a new structural relationships-based access control (SRBAC) model that can be used to delegate resource access rights to users in a large scale IoT scenario like smart city while keeping the resource owner in full control. The proposed architecture uses smart contracts and public blockchain for managing access control for external users and a local off-block chain storage for managing access control for organization’s internal users and enforcing fine-grained access control for the resources.
Sina Rafati Niya, Sebastian Allemann, Arik Gabay, Burkhard Stiller
Data leaks and privacy scandals have been a growing concern of the last decade. While most traditional, i.e., centralized, online platforms require users to register with their personal data, they potentially expose the user's identity and data to be used for unintended purposes. This work proposes TradeMap as an integrated architecture, designing and enabling an online end-to-end (e2e) trading market place, while supporting anonymous management features. TradeMap addresses the Swiss Financial Market Supervisory Authority (FINMA) regulations by designing a FINMA-complaint Know Your Customer (KYC) platform. Additionally, TradeMap is based on blockchains and employs Ethereum Smart Contracts (SC). Thus, trust and anonymity between the market place and the KYC system relies on zero knowledge proof-based SCs used for user identification processes. With this management approach proposed, the user authentication is only verified within the KYC platform, providing a legally valid and fully anonymous online trading platform.
Matteo Varvello, Iñigo Querejeta Azurmendi, Antonio Nappa, Panagiotis N. Papadopoulos · 6 authors
Distributed Virtual Private Networks (dVPNs) are new VPN solutions aiming to solve the trust-privacy concern of a VPN's central authority by leveraging a distributed architecture. In this paper, we first review the existing dVPN ecosystem and debate on its privacy requirements. Then, we present VPN0, a dVPN with strong privacy guarantees and minimal performance impact on its users. VPN0 guarantees that a dVPN node only carries traffic it has "whitelisted", without revealing its whitelist or knowing the traffic it tunnels. This is achieved via three main innovations. First, an attestation mechanism which leverages TLS to certify a user visit to a specific domain. Second, a zero knowledge proof to certify that some incoming traffic is authorized, e.g., falls in a node's whitelist, without disclosing the target domain. Third, a dynamic chain of VPN tunnels to both increase privacy and guarantee service continuation while traffic certification is in place. The paper demonstrates VPN0 functioning when integrated with several production systems, namely BitTorrent DHT and ProtonVPN.
<em>In the second decade of the new millennium, with the development of Blockchain technology, the interest of many applications in the world has come to the attention of exciting applications. One of the challenging applications of Blockchain technology is in the area of electronic voting. The issue of preventing fraud and establishing democracy has always been a major challenge in all countries. Since 2015, various implementations of electronic voting with Blockchain have been introduced. Among these, some of the proposed methods have been implemented in small and medium scales in some countries. With respect to this fact that almost all of the above-mentioned methods use proof-of-work (PoW) consensus mechanism, the most significant shortcoming of such implementations is energy consumption. In the near future it is expected that this problem will be resolved through replacing PoW mechanism by new ones such as proof-of-stake (PoS) and its other variants. In this paper, we present security policy model parameters for e-voting, based on Blockchain technologies. The contribution of this paper is two-fold. First, this paper is the first to classify the requirements of e-voting according to confidentiality-integrity-availability, well-known as CIA principles in security terminology. Second, it provides a statistical analysis to extract hidden inter-dependencies among the requirements.</em>
With the current rise in the demand and usage of the blockchain technology for a variety of purposes, ranging from finance, medical, identification amongst others, major focus has been dedicated towards its legal implications rather than leveraging on the practical applications in administration. In this paper, we discuss the concepts of blockchain and how it can be implemented as an efficient solution towards public voting while aiming to destroy the disadvantages of the current voting system in India, at the same time providing a better, more reliable, secure and transparent means of public governance. We also aim to provide an exemplified voting solution for India with the integration of the current Aadhaar identification system as implemented by UIDAI.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Maximilian Schiedermeier, Omar M. Hassan, Lionel Brunie, Tobias Mayer · 5 authors
High voter turnout in elections and referendums is very desirable in order to ensure a robust democracy. Secure electronic voting is a vision for the future of elections and referendums. Such a system can counteract factors that hinder strong voter turnout such as the requirement of physical presence during limited hours at polling stations. However, this vision brings transparency and confidentiality requirements that render the design of such solutions challenging. Specifically, the counting must be implemented in a reproducible way and the ballots of individual voters must remain concealed. In this paper, we propose and evaluate a referendum protocol that ensures transparency, confidentiality, and integrity, in trustless networks. The protocol is built by combining Secure Multi-Party Computation (SMPC) and Distributed Ledger or Blockchain technology. The persistence and immutability of the protocol communication allows verifiability of the referendum outcome on the client side. Voters therefore do not need to trust in third parties. We provide a formal description and conduct a thorough security evaluation of our proposal.
High voter turnout in elections and referendums is very desirable in order to\nensure a robust democracy. Secure electronic voting is a vision for the future\nof elections and referendums. Such a system can counteract factors that hinder\nstrong voter turnout such as the requirement of physical presence during\nlimited hours at polling stations. However, this vision brings transparency and\nconfidentiality requirements that render the design of such solutions\nchallenging. Specifically, the counting must be implemented in a reproducible\nway and the ballots of individual voters must remain concealed. In this paper,\nwe propose and evaluate a referendum protocol that ensures transparency,\nconfidentiality, and integrity, in trustless networks. The protocol is built by\ncombining Secure Multi-Party Computation (SMPC) and Distributed Ledger or\nBlockchain technology. The persistence and immutability of the protocol\ncommunication allows verifiability of the referendum outcome on the client\nside. Voters therefore do not need to trust in third parties. We provide a\nformal description and conduct a thorough security evaluation of our proposal.\n
Payment channel networks (PCNs) are viewed as one of the most promising scalability solutions for cryptocurrencies today. Roughly, PCNs are networks where each node represents a user and each directed, weighted edge represents funds escrowed on a blockchain; these funds can be transacted only between the endpoints of the edge. Users efficiently transmit funds from node A to B by relaying them over a path connecting A to B, as long as each edge in the path contains enough balance (escrowed funds) to support the transaction. Whenever a transaction succeeds, the edge weights are updated accordingly. In deployed PCNs, channel balances (i.e., edge weights) are not revealed to users for privacy reasons; users know only the initial weights at time 0. Hence, when routing transactions, users typically first guess a path, then check if it supports the transaction. This guess-and-check process dramatically reduces the success rate of transactions. At the other extreme, knowing full channel balances can give substantial improvements in transaction success rate at the expense of privacy. In this work, we ask whether a network can reveal noisy channel balances to trade off privacy for utility. We show fundamental limits on such a tradeoff, and propose noise mechanisms that achieve the fundamental limit for a general class of graph topologies. Our results suggest that in practice, PCNs should operate either in the low-privacy or low-utility regime; it is not possible to get large gains in utility by giving up a little privacy, or large gains in privacy by sacrificing a little utility.
Traditional elections satisfy neither citizens nor political authorities in recent years. They are not fully secure since it is easy to attack votes. It threatens also privacy and transparency of voters. Additionally, it takes too much time to count the votes. This paper proposes a solution using Blockchain to eliminate all the disadvantages of conventional elections. Security and data integrity of votes are absolutely provided theoretically. Voter privacy is another requirement that is ensured in the system. Lastly, the waiting time for results decreased significantly in the proposed Blockchain voting system.