Crowdsourcing has emerged as a prevalent method for mitigating the risks of correctness and security in outsourced cloud computing. This process involves an aggregator distributing tasks, collecting responses, and aggregating outcomes from multiple data sources. Such an approach harnesses the wisdom of crowds to accomplish complex tasks, enhancing the accuracy of task completion while diminishing the risks associated with the malicious actions of any single entity. However, a critical question arises: How can we ensure that the aggregator performs its role honestly and each contributor's input is fairly evaluated? In response to this challenge, we introduce a novel protocol termed $\mathsf{zkTI}. This scheme guarantees both the honest execution of the aggregation process by the aggregator and the fair evaluation of each data source. It innovatively integrates a cryptographic construct known as zero-knowledge proof with a category of truth inference algorithms for the first time. Under this protocol, the aggregation operates with both correctness and verifiability, while ensuring fair assessment of data source reliability. Experimental results demonstrate the protocol's efficiency and robustness, making it a viable and effective solution in crowdsourcing and cloud computing.
Blockchain has proven in sensor networks as a distributed solution for transparent and secure storage, which allows its application in mobile wireless sensor networks (MWSNs). The consensus mechanism, an essential aspect of blockchain technology, must concern the high mobility, resource-constrained nature, and weak physical defenses of sensor nodes in MWSNs. To secure MWSN data storage in clustered communication, we design a proof-of-information (PoI) variant for fair miner campaigning via the amount of valid data generated from environmental information, including a dynamic adjustment of the data volume threshold to detect malicious nodes and prevent them from misreporting information. Additionally, we introduce a filtering mechanism through the dynamic integrated trust (DIt) of nodes, which integrates the trust evaluation of peer nodes across the network combining objective performance to prevent malicious nodes from infiltrating the final consensus group. The multi-level filtering technique improves the campaign fairness while isolating malicious nodes, ensuring complexity-sensitive PBFT algorithm efficiency in large-scale networks. Simulation results show that the scheme isolates 90% of the malicious nodes and screens 20% of members to produce a smaller final consensus group. Further analysis of impacts on the performance considering network topology and mobility patterns and comparisons of the relevant solutions are presented.
Jiawen Kang, Jinbo Wen, Dongdong Ye, Bingkun Lai · 10 authors
Given the revolutionary role of metaverses, healthcare metaverses are emerging as a transformative force, creating intelligent healthcare systems that offer immersive and personalized services. The healthcare metaverses allow for effective decision-making and data analytics for users. However, there still exist critical challenges in building healthcare metaverses, such as the risk of sensitive data leakage and issues with sensing data security and freshness, as well as concerns around incentivizing data sharing. In this paper, we first design a user-centric privacy-preserving framework based on decentralized Federated Learning (FL) for healthcare metaverses. To further improve the privacy protection of healthcare metaverses, a cross-chain empowered FL framework is utilized to enhance sensing data security. This framework utilizes a hierarchical cross-chain architecture with a main chain and multiple subchains to perform decentralized, privacy-preserving, and secure data training in both virtual and physical spaces. Moreover, we utilize Age of Information (AoI) as an effective data-freshness metric and propose an AoI-based contract theory model under Prospect Theory (PT) to motivate sensing data sharing in a user-centric manner. This model exploits PT to better capture the subjective utility of the service provider. Finally, our numerical results demonstrate the effectiveness of the proposed schemes for healthcare metaverses.
As a promising paradigm of distributed learning, federated learning has garnered considerable attention since its emergence. However, traditional federated learning solutions based on a central server are not efficient and scalable. Moreover, the centralized design relies on a trustworthy party coordinating participants. This also leads to trust and reliability issues, such as a compromised central server or a single-point failure. To address this issue, blockchain-based federated learning has been proposed as a decentralized variant. Blockchain-based decentralized federated learning seems promising. However, a new attack surface appears. Because blockchain records each transaction on a public ledger, all peers can obtain a legal copy of the local model of each participant, severely violating the privacy and interests of the participants. Challenged by this dilemma, we provide an alternative design for secure federated learning in a decentralized way, addressing data confidentiality and fairness issues simultaneously. Unlike previous studies, we construct a produce-and-consume model for parameter aggregation on a blockchain, auditing the behavior of participants in case of free-riding and false-reporting attacks. Furthermore, we design a consensus protocol called APoS, which provides an incentive and review mechanism and enforces honest training of federated learning participants.
Aitizaz Ali, Bander Ali Saleh Al‐rimy, Faisal S. Alsubaei, Abdulwahab Ali Almazroi · 5 authors
The swift advancement of the Internet of Things (IoT), coupled with the growing application of healthcare software in this area, has given rise to significant worries about the protection and confidentiality of critical health data. To address these challenges, blockchain technology has emerged as a promising solution, providing decentralized and immutable data storage and transparent transaction records. However, traditional blockchain systems still face limitations in terms of preserving data privacy. This paper proposes a novel approach to enhancing privacy preservation in IoT-based healthcare applications using homomorphic encryption techniques combined with blockchain technology. Homomorphic encryption facilitates the performance of calculations on encrypted data without requiring decryption, thus safeguarding the data's privacy throughout the computational process. The encrypted data can be processed and analyzed by authorized parties without revealing the actual contents, thereby protecting patient privacy. Furthermore, our approach incorporates smart contracts within the blockchain network to enforce access control and to define data-sharing policies. These smart contracts provide fine-grained permission settings, which ensure that only authorized entities can access and utilize the encrypted data. These settings protect the data from being viewed by unauthorized parties. In addition, our system generates an audit record of all data transactions, which improves both accountability and transparency. We have provided a comparative evaluation with the standard models, taking into account factors such as communication expense, transaction volume, and security. The findings of our experiments suggest that our strategy protects the confidentiality of the data while at the same time enabling effective data processing and analysis. In conclusion, the combination of homomorphic encryption and blockchain technology presents a solution that is both resilient and protective of users' privacy for healthcare applications integrated with IoT. This strategy offers a safe and open setting for the management and exchange of sensitive patient medical data, while simultaneously preserving the confidentiality of the patients involved.
Decentralized identity frameworks grant users full sovereignty over their digital assets in the Web3 ecosystem. However, allowing arbitrary creation of identifiers makes the system susceptible to Sybil attacks and puts assets at risk when keys are lost or compromised. Moreover, the lack of identification prevents anonymous credential schemes from deterring malicious transfers. While existing solutions attempt to address these issues by linking identifiers to entities through trusted intermediaries, these entities are not always accessible and require costly offline interactions. In this work, we introduce LinkDID, a decentralized identity scheme offering Sybil resistance, trustless key recovery, and nontransferable anonymous credentials. LinkDID creates blockchainbased bindings between identifiers and gradually combines identifiers belonging to the same holder into a unified associated identifier. As all identifiers within an association are presumed to belong to one individual, any fraudulent activity can be detected. The association grows larger as interactions increase, substantially reducing the likelihood of successful Sybil attacks. This mechanism allows holders to recover identifiers with lost or stolen keys by proving knowledge of specific association structures. Additionally, LinkDID prevents unauthorized transfers through blockchain-based identifier-key bindings and proofs of ownership for credentials. The evaluation shows that LinkDID effectively achieves progressive Sybil resistance while surpassing state-of-the-art anonymous credential schemes, achieving identifier association and credential presentation times of 2.41s and 3.31s on consumer-grade devices.
Antonio Yaghy, Nicole Rose I. Alberto, Isabelle Rose I. Alberto, Rene S. Bermea · 9 authors
Non-fungible tokens (NFTs) are cryptographic assets recorded on the blockchain that can certify authenticity and ownership, and they can be used to monetize health data, optimize the process of receiving a hematopoietic stem cell transplant, and improve the distribution of solid organs for transplantation. Blockchain technology, including NFTs, provides equitable access to wealth, increases transparency, eliminates personal or institutional biases of intermediaries, reduces inefficiencies, and ensures accountability. Blockchain architecture is ideal for ensuring security and privacy while granting individuals jurisdiction over their own information, making it a unique solution to the current limitations of existing health information systems. NFTs can be used to give patients the option to monetize their health data and provide valuable data to researchers. Wearable technology companies can also give their customers the option to monetize their data while providing data necessary to improve their products. Additionally, the process of receiving a hematopoietic stem cell transplant and the distribution of solid organs for transplantation could benefit from the integration of NFTs into the allocation process. However, there are limitations to the technology, including high energy consumption and the need for regulatory guidance. Further research is necessary to fully understand the potential of NFTs in healthcare and how it can be integrated with existing health information technology. Overall, NFTs have the potential to revolutionize the healthcare sector, providing benefits such as improved access to health information and increased efficiency in the distribution of organs for transplantation.
Managing and exchanging sensitive information securely is a paramount concern for the scientific and cybersecurity community. The increasing reliance on computing workflows and digital data transactions requires ensuring that sensitive information is protected from unauthorized access, tampering, or misuse. This research paper presents a comparative analysis of three novel approaches for authenticating and securing access to scientific data: SciTokens, Verifiable Credentials, and Smart Contracts. The aim of this study is to investigate the strengths and weaknesses of each approach from trust, revocation, privacy, and security perspectives. We examine the technical features and privacy and security mechanisms of each technology and provide a comparative synthesis with the proposed model. Through our analysis, we demonstrate that each technology offers unique advantages and limitations, and the integration of these technologies can lead to more secure and efficient solutions for authentication and access to scientific data.
Zero-knowledge proof is emerging to enable privacy. Among existing techniques, zk-SNARK (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) [1] supports the shortest verification time and the smallest proof size. However, using zk-SNARK requires the execution of trusted setup ceremony in advance. The trusted setup ceremony generates common reference string (CRS) which is shared with prover and verifier. Currently, an external trusted third party is assumed for trusted setup ceremony, which causes significant security vulnerability in zk-SNARK. In this paper, we propose a blockchain-based protocol of trusted setup ceremony without trusted third party. Three different types of protocols are classified in terms of where to store CRS and how to validate CRS through pairing check. We analyze the protocol complexity of CRS pairing check computations and on-chain storage space.
Multi-brain Federated Learning (MBFL) introduces an innovative approach to decentralized artificial intelligence, enabling joint model training across various fields while maintaining data privacy. This study clarifies the MBFL concept and explores its potential uses in industries such as healthcare, finance, and defense. It covers the core principles of MBFL such as data decentralization, model aggregation, and privacy-preserving techniques. The benefits of MBFL, including improved model performance and reduction of data silos, are examined along with possible challenges and limitations. A framework for implementing MBFL in different scenarios was provided, and its impact on the future direction of AI development was discussed. The paper concludes by highlighting the transformative potential of MBFL in advancing collaborative AI, while ensuring data security and privacy. Keywords — Multi-brain Federated Learning, Decentralized AI, Privacy-preserving, Collaborative models, Data security, Cross- domain learning, Model aggregation, Federated Learning, Healthcare, Finance, Defense.
Training and deploying the large language models requires a large mount of computational resource because the language models contain billions of parameters and the text has thousands of tokens. Another problem is that the large language models are static. They are fixed after the training process. To tackle these issues, in this paper, we propose to train and deploy the dynamic large language model on blockchains, which have high computation performance and are distributed across a network of computers. A blockchain is a secure, decentralized, and transparent system that allows for the creation of a tamper-proof ledger for transactions without the need for intermediaries. The dynamic large language models can continuously learn from the user input after the training process. Our method provides a new way to develop the large language models and also sheds a light on the next generation artificial intelligence systems.
Tahiry Rabehaja, Shantanu Pal, Ambrose Hill, Michael Hitchens
The use of parametric insurance is promising as its payouts can be directly tied to hazard indicators and thus provide a fast-tracked claim-to-payout process, which improves liquidity in times of disaster. In parametric insurance, policies are determined by a loss threshold (modelled or sustained) or physical hazard severity (e.g., rainfall or wind speed). In the latter, when the severity of the hazard exceeds a threshold, a payout is automatically triggered according to the insurance contract terms to compensate the policyholder without needing a loss assessment. Recently, blockchains have been proposed to improve the efficiency of insurance product offerings (e.g., to cut administrative costs associated with the premium collection and claim processing) and to efficiently store and maintain information (e.g., immutable distributed storage for audits). While parametric insurance would certainly benefit from these blockchain implementations, existing proposals mostly depend on a single source of truth for payout calculations. In this paper, we present a novel trust-based framework to handle multiple sources of truth in parametric insurance products which use blockchain technology. This framework alleviates the reliance on a single point of failure (either through accidents or malicious abuses) and outperforms its statistical counterparts. We discuss how parametric insurance would work under such a framework using real-world use-case scenarios, show the use of subjective logic to reason about multiple sources of truth, present the architecture of the framework, and examine a detailed blockchain-based implementation using an Ethereum private blockchain. Our results show the feasibility of the proposed system in practice.
Due to the significance of trust in Social Internet of Things (SIoT)-based smart marketplaces, several research have focused on trust-related challenges. Trust is necessary for a smooth connection, secure systems, and dependable services during trade operations. Recent SIoT-based trust assessment approaches attempt to solve smart marketplace trust evaluation difficulties by using a variety of direct and indirect trust evaluation techniques and other local trust rating procedures. Nevertheless, these methodologies render trust assessment very sensitive to seller dishonesty, and a dishonest seller may influence local trust scores and at the same time pose a significant trust related threats in the system. In this article, a MarketTrust model is introduced, which is a blockchain-based method for assessing trust in an IoT-based smart marketplace. It has three parts: familiarity, personal interactions, and public perception. A conceptual model, assessment technique, and a global trust evaluation system for merging the three components of a trust value are presented and discussed. Several experiments were conducted to assess the model's security, viability, and efficacy. According to results, the MarketTrust model scored a 21.99% higher trust score and a 47.698% lower average latency than both benchmark models. Therefore, this illustrates that using the proposed framework, a potential buyer can efficiently choose a competent and trustworthy resource seller in a smart marketplace and significantly reduce malicious behavior.
Spectrum distribution is a classical licensed spectrum accessing method in mobile communication networks. The licensed idle spectrum resources are authorized and distributed from spectrum owners to mobile users. However, the exponential growth of user capacity brings excessive load pressure on the traditional centralized network architecture. With a lack of sufficient supervision and penalty measures, dishonest behaviors of spectrum owners and spectrum users will lead to an unfair status in the distribution process. As a result, the honest participants’ interest will be harmed. As an important supporting infrastructure of Internet of Things technology, 6G cannot completely follow the existing spectrum distribution method. Towards 6G network spectrum distribution, a blockchain-based licensed spectrum fair distribution method is proposed. A lightweight consensus mechanism named proof of trust (PoT) is applied to reduce computational power consumption and consensus time overhead. We deploy the method on the Ethereum test chain; a theoretical analysis and experimental results demonstrate the fairness, effectiveness and security of the method.
A well-known use of the blockchain technology is Decentralized Finance (DeFi). DeFi makes financial information accessible to the public but raises potential privacy and security issues. In this study, we implemented a DeFi protocol that protects privacy, which is based on the Mystiko.Network protocol. As a proxy between the user and DeFi platforms, the Mystiko.Network protocol offers an auditable confidentiality mechanism for blockchain transactions. Via the new system, users may submit anonymous DeFi transactions and get income back into a shielded tokens pool. Moreover, we implemented a rollup approach to handle anonymous DeFi transactions in groups. The evaluation results suggest that the protocol is both practical and affordable, in fact it is able to save around 90% of the cost for DeFi transactions.
This study presents an architectural framework for the blockchain-based usage-based insurance (UBI) policy auction mechanism in the internet of vehicles (IoV) applications. The main objective of this study is to analyze and design the specific blockchain architecture and management considerations for the UBI environment. An auction mechanism is developed for the UBI blockchain platform to enhance consumer trust. The study identifies correlations between driving behaviors and associated risks to determine a driver's score. A decentralized bidding algorithm is proposed and implemented on a blockchain platform using elliptic curve cryptography and first-price sealed-bid auctions. Additionally, the model incorporates intelligent contract functionality to prevent unauthorized modifications and ensure that insurance prices align with the prevailing market value. An experimental study evaluates the system's efficacy by expanding the participant pool in the bidding process to identify the winning bidder and is investigated under scenarios where varying numbers of insurance companies submit bids. The experimental results demonstrate that as the number of insurance companies increases exponentially, the temporal overhead incurred by the system exhibits only marginal growth. Moreover, the allocation of bids is accomplished within a significantly abbreviated timeframe. These findings provide evidence that supports the efficiency of the proposed algorithm.
Location-based services are at the heart of many applications that individuals use every day. However, there is often no guarantee of the truthfulness of users’ location data, since this information can be easily spoofed without a proof mechanism. In distributed system applications, preventing users from submitting counterfeit locations becomes even more challenging because of the lack of a central authority that monitors data provenance. In this work, we propose a decentralized architecture based on blockchains and decentralized technologies, offering a transparent solution for Proof of Location (PoL). We specifically address two main challenges, i.e., the issuing process of the PoL and the proof verification. We describe a smart contract based implementation in Reach, a blockchain-agnostic smart contract language, and the tests we conducted on different blockchains, i.e. Ethereum, Polygon, and Algorand, measuring latency and costs due to the payment of fees. Results confirm the viability of the proposal.
Prabhat Kumar, Randhir Kumar, Moayad Aloqaily, A.K.M. Najmul Islam
The next-generation digital revolution is anticipated to be the convergence of Consumer Internet of Things (CIoT) platforms and Metaverse. The use of Metaverse in CIoT can offer a hyper-spatiotemporal, self-sustaining 3D virtual shared space for people to interact, work, and play. Despite the hype around CIoT-inspired Metaverse, security and privacy concerns are seen as the two biggest obstacles in the communication infrastructure and information gathering procedures. The eXplainable Artificial Intelligence (XAI) and blockchain have the potential to reshape and transform the CIoT-inspired Metaverse by bringing significant enhancements in terms of explainability, interpretability, transparency, traceability, and immutability regarding data and communications. In this paper, we first discuss about the security and privacy issues in CIoT-inspired Metaverse. Second, we discuss the importance and properties of XAI and blockchain with a use case to demonstrate the benefits of our proposed architecture to tackle the aforementioned obstacles. Finally, we highlight the future research directions in building futuristic CIoT-inspired Metaverse.
Jesús García-Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio Skármeta
PREPRINT: The increasing user awareness and regulatory framework (e.g., GDPR) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems.<br> Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data.<br> Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by formalizing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations.
Machine learning has become increasingly popular in academic and industrial communities and has been widely implemented in various online applications due to its powerful ability to analyze and use data. Among all the machine learning models, decision tree models stand out due to their great interpretability and simplicity, and have been implemented in cloud computing services for various purposes. Despite its great success, the integrity issue of online decision tree prediction is a growing concern. The correctness and consistency of decision tree predictions in cloud computing systems need more security guarantees since verifying the correctness of the model prediction remains challenging. Meanwhile, blockchain has a promising prospect in two-party machine learning services as the immutable and traceable characteristics satisfy the verifiable settings in machine learning services. In this paper, we initiate the study of decision tree prediction services on blockchain systems and propose VDT, a Verifiable Decision Tree prediction scheme for decision tree prediction. Specifically, by leveraging the Merkle tree and hash function, the scheme allows the service provider to generate a verification proof to convince the client that the output of the decision tree prediction is correctly computed on a particular data sample. It is further extended to an update method for a verifiable decision tree to modify the decision tree model efficiently. We prove the security of the proposed VDT schemes and evaluate their performance using real datasets. Experimental evaluations show that our scheme requires less than one second to produce verifiable proof.
Mohamed Abdel‐Basset, Ibrahim Alrashdi, Hossam Hawash, Karam M. Sallam · 5 authors
In the aftermath of the COVID-19 pandemic, the need for efficient and reliable disease diagnosis in smart cities has become increasingly serious. In this study, we introduce a novel blockchain-based federated learning framework tailored specifically for the diagnosis of pandemic diseases in smart cities, called BFLPD, with a focus on COVID-19 as a case study. The proposed BFLPD takes advantage of the decentralized nature of blockchain technology to design collaborative intelligence for automated diagnosis without violating trustworthiness metrics, such as privacy, security, and data sharing, which are encountered in healthcare systems of smart cities. Cheon–Kim–Kim–Song (CKKS) encryption is intelligently redesigned in BFLPD to ensure the secure sharing of learning updates during the training process. The proposed BFLPD presents a decentralized secure aggregation method that safeguards the integrity of the global model against adversarial attacks, thereby improving the overall efficiency and trustworthiness of our system. Extensive experiments and evaluations using a case study of COVID-19 ultrasound data demonstrate that BFLPD can reliably improve diagnostic accuracy while preserving data privacy, making it a promising tool with which smart cities can enhance their pandemic disease diagnosis capabilities.
The maturing blockchain technology has gradually promoted decentralized data storage from cryptocurrencies to other applications, such as trust management, resulting in new challenges based on specific scenarios. Taking the mobile trust blockchain within a vehicular network as an example, many users require the system to process massive traffic information for accurate trust assessment, preserve data reliably, and respond quickly. While existing vehicular blockchain systems ensure immutability, transparency, and traceability, they are limited in terms of scalability, performance, and security. To address these issues, this paper proposes a novel decentralized vehicle trust management solution and a well-matched blockchain framework that provides both security and performance. The paper primarily addresses two issues: i) To provide accurate trust evaluation, the trust model adopts a decentralized and peer-review-based trust computation method secured by trusted execution environments (TEEs). ii) To ensure reliable trust management, a multi-shard blockchain framework is developed with a novel hierarchical Byzantine consensus protocol, improving efficiency and security while providing high scalability and performance. The proposed scheme combines the decentralized trust model with a multi-shard blockchain, preserving trust information through a hierarchical consensus protocol. Finally, real-world experiments are conducted by developing a testbed deployed on both local and cloud servers for performance measurements.
Zero-knowledge proof (ZKP) frameworks have the potential to revolutionize the handling of sensitive data in various domains. However, deploying ZKP frameworks with real-world data presents several challenges, including scalability, usability, and interoperability. In this project, we present Fact Fortress, an end-to-end framework for designing and deploying zero-knowledge proofs of general statements. Our solution leverages proofs of data provenance and auditable data access policies to ensure the trustworthiness of how sensitive data is handled and provide assurance of the computations that have been performed on it. ZKP is mostly associated with blockchain technology, where it enhances transaction privacy and scalability through rollups, addressing the data inherent to the blockchain. Our approach focuses on safeguarding the privacy of data external to the blockchain, with the blockchain serving as publicly auditable infrastructure to verify the validity of ZK proofs and track how data access has been granted without revealing the data itself. Additionally, our framework provides high-level abstractions that enable developers to express complex computations without worrying about the underlying arithmetic circuits and facilitates the deployment of on-chain verifiers. Although our approach demonstrated fair scalability for large datasets, there is still room for improvement, and further work is needed to enhance its scalability. By enabling on-chain verification of computation and data provenance without revealing any information about the data itself, our solution ensures the integrity of the computations on the data while preserving its privacy.
Abstract While blockchain technology (BT) is considered secure, there are several vulnerabilities that can breach its security. The study in artificial intelligence (AI) and BT is widely popular due to its expanding importance in enhancing security and computational prowess. In this study, we present a comprehensive and meticulous comprehensive review of AI and BT‐based privacy‐preserving smart healthcare. The selection for this study was based on a holistic and integrated approach which involved examining not only individual studies but also their relationships, and trends. Through a systematic analysis of various phases, we identified 91 primary studies pertaining to information needed to stockpile directions called for retorting the research queries. We have undertaken a descriptive comparison of foundational manuscripts, taking into account an array of essential factors, including performance metrics, security protocols, and computational prowess. Our thorough discussions and debates have led to the identification of research gaps in the current manuscript, as well as the direction for future research. We also propose our constructive approach for the aforementioned integration, highlighting its potential benefits and implications.
Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Artificial Intelligence in Healthcare and Education