After successful completion of graduation, students receive the credits of the courses in the form of certificate issued by the respective University. A Student have to produce his/her documents to the employers or the authorities for employment or higher education. Today ,as the system is centralized all the data resides on the server which can be hacked or the data can be lost if the system crushes down. However, verifying a certificate by authorities, is a time-consuming process as there is an involvement of human resources ,for validating the details of the candidate from its University. Today , with the advancement in technologies and due to the easy availability of many efficient soft wares that have led to the forgery of credentials/certificates. The lack of anti-tampering mechanisms resulted in incidents where the forged graduation certificates are often found. Also ,in case certificates are out of place , applying for duplicate certificates and its issuance by the University consumes a lot of time. Use of blockchain technology in this process will make the system decentralized as blocks as cryptographically connected and all the nodes in the network shares the entire chain .Hence the proposed decentralized certificate verification system, uses blockchain technology incorporating all the essential features in developing a DAPP. This system is proposed to address the issue of certificate counterfeiting, faster certificate verification and issuance. Putting across all the issues, the system aims at addressing the problems and provide solutions to the current Certificate Issuance, verification and Validation Process.
The beacon chain is the backbone of the Ethereum's evolution towards a proof-of-stake-based scalable network. Beacon clients are the applications implementing the services required to operate the beacon chain, namely validators, beacon nodes, and slashers. Security defects in beacon clients could lead to loss of funds, consensus rules violation, network congestion, and other inconveniences. We reported more than 35 issues to the beacon client developers, including various security improvements, specification inconsistencies, missing security checks, exposure to known vulnerabilities. None of our findings appears to be high-severity. We covered the four main beacon clients, namely Lighthouse (Rust), Nimbus (Nim), Prysm (Go), and Teku (Java). We looked for bugs in the logic and implementation of the new security-critical components (BLS signatures, slashing, networking protocols, and API) over a 3-month project that followed a preliminary analysis of BLS signatures code. We focused on Lighthouse and Prysm, the most popular clients, and thus the highest-value targets. Furthermore, we identify protocol-level issues, including replay attacks and incomplete forward secrecy. In addition, we reviewed the network fingerprints of beacon clients, discussing the information obtainable from passive and active searches, and we analyzed the supply chain risk related to third-party dependencies, providing indicators and recommendations to reduce the risk of backdoors and unpatchable vulnerabilities. Our results suggest that despite intense scrutiny by security auditors and independent researchers, the complexity and constant evolution of a platform like Ethereum requires regular expert review and thorough SSDLC practices.
Despite increasingly emerging applications, a primary concern for blockchain to be fully practical is the inefficiency of data query. Direct queries on the blockchain take much time by searching every block, while indirect queries on a blockchain database greatly degrade the authenticity of query results. To conquer the authenticity problem, we propose a Verifiable Query Layer (VQL) that can be deployed in the cloud to provide both efficient and verifiable data query services for blockchain systems. The middleware layer extracts data from the underlying blockchain system and efficiently reorganizes them in databases. To prevent falsified data from being stored in the middleware, a cryptographic fingerprint is calculated based on each constructed database. The database fingerprint will be first verified by miners and then written into the blockchain. Moreover, public users can verify the entire databases or several databases that interest them in the middleware layer. We implement VQL together with the verification schemes and conduct extensive experiments based on a practical blockchain system. The evaluation results demonstrate that VQL can efficiently support various data query services and guarantee the authenticity of query results for blockchain systems.
Christos Chrysoulas, A. M. Thomson, Nikolaos Pitropakis, Pavlos Papadopoulos · 10 authors
The continuously advancing digitization has provided answers to the bureaucratic problems faced by eGovernance services. This innovation led them to an era of automation it has broadened the attack surface and made them a popular target for cyber attacks. eGovernance services utilize internet, which is currently a location addressed system where whoever controls the location controls not only the content itself, but the integrity of that content, and the access to that content. We propose GLASS, a decentralised solution which combines the InterPlanetary File System (IPFS) with Distributed Ledger technology and Smart Contracts to secure EGovernance services. We also create a testbed environment where we measure the IPFS performance.
Internet of Things (IoT) refers to a technology where computing devices are connected and form a network. IoT faces many security and privacy issues due to less computation power, heterogeneity, and limited resources available with its devices. Data is transferred among these devices with little or no human interaction. Data Confidentiality and Integrity are very critical parameters and can be achieved by securely sharing information in IoT scenarios. Managing and maintaining trust in exchanging information over IoT becomes very significant. Recent researches have focused on the applications of Blockchain technology for assuring trust management in IoT networks. Blockchain provides completely distinct and more secure approaches. This survey paper aims to illustrate the significance of integrating Blockchain technology in the IoT environment to ensure trust among IoT devices. Particularly, first we give an overview and security aspects of IoT and Blockchain technologies. Then we trace out some important challenges and issues of trusted IoT with potential solutions by Blockchain. Following this, we highlight some complications in the integration of Blockchain with IoT. Finally, we present a comparative analysis between traditional and Blockchain-based trust management techniques as proof of work to represent the significance of Blockchain in ensuring trust.
Zero-Knowledge proofs (ZKPs) enable proving of mathematical statements, revealing nothing but their validity. We design an authentication sys-tem with a ZKP as a password verification mech-anism within the Extensible Authentication Pro-tocol (EAP) framework. Designing a secure pass-word authentication system requires us to adopt security practices for protecting ourselves against the vulnerabilities of passwords. Integrating said practices is not trivial because of the tight cou-pling with the password verification method.
Vincent Schlatt, Johannes Sedlmeir, Janina Traue, Fabiane Völter
The digital transformation of the medical sector requires solutions that are convenient and efficient for all stakeholders while protecting patients' sensitive data. One example that has already attracted design-oriented research are medical prescriptions. However, current implementations of electronic prescription management systems typically create centralized data silos, leaving user data vulnerable to cybersecurity incidents and impeding interoperability. Research has also proposed decentralized solutions based on blockchain technology, but privacy-related challenges have often been ignored. We conduct design science research to develop and implement a system for the exchange of electronic prescriptions that builds on two blockchains and a digital wallet app. Our solution combines the bilateral, verifiable, and privacy-focused exchange of information between doctors, patients, and pharmacies through verifiable credentials with a token-based, anonymized double-spending check. Our qualitative and quantitative evaluations as well as a security analysis suggest that this architecture can improve existing approaches to electronic prescription management by offering patients control over their data by design, a high level of security, sufficient performance and scalability, and interoperability with emerging digital identity management solutions for users, businesses, and institutions. We also derive principles on how to design decentralized, privacy-oriented information systems that require both the exchange of sensitive information and double-usage protection.
The application of technology in various aspects of life has made it easy for many people. However, there are also shortcomings in the use of technology, one of which is security issues, both transactions and data. Given these issues in this paper, we propose blockchain technology for an authentication system that will protect data rights and interests and be safe from interference to store information in the form of confidential text, especially in the application of technology in education. From this writing, there are 2 benefits, the first is that all data stored in the education system is guaranteed and there will be increased trust from both parents, teachers and other parties due to the decentralized nature of blockchain.
Most of the existing identity management is the centralized architecture that has to validate, certify, and manage identity in a centralized approach by trusted authorities. Decentralized identity is causing widespread public concern because it enables to give back control of identity to clients, and the client then has the ability to control when, where, and with whom they share their credentials. A decentralized solution atop on blockchain will bypass the centralized architecture and address the single point of the failure problem. To our knowledge, blockchain is an inherited pseudonym but it cannot achieve anonymity and auditability directly. In this paper, we approach the problem of decentralized identity management starting from the designated-verifier anonymous credential (DVAC in short). DVAC would assist to build a new practical decentralized identity management with anonymity and auditability. Apart from the advantages of the conventional anonymous credential, the main advantage of the proposed DVAC atop blockchain is that the issued cryptographic token will be divided into shares at the issue phase and will be combined at the showing credential phase. Further, the smooth projective hash function ( <a:math xmlns:a="http://www.w3.org/1998/Math/MathML" id="M1"> <a:mi mathvariant="sans-serif">SPHF</a:mi> </a:math> in short) is regarded as a designated-verifier zero-knowledge proof system. Thus, we introduce the <d:math xmlns:d="http://www.w3.org/1998/Math/MathML" id="M2"> <d:mi mathvariant="sans-serif">SPHF</d:mi> </d:math> to achieve the designated verifiability without compromising the privacy of clients. Finally, the security of the proposed DVAC is proved along with theoretical and experimental evaluations.
Summary Today, the integrity and authenticity of digital documents and data are often hard to verify. Existing public key infrastructures (PKIs) are capable of certifying digital identities but do not provide solutions to store signatures immutably, and the process of certification is often not transparent. We propose Veritaa, a distributed public key infrastructure with an integrated signature store (DPKISS). The central part of Veritaa is the Graph of Trust that manages identity claims and singed declarations between identity claims and document identifiers. An application‐specific distributed ledger is used to store the transactions that form the Graph of Trust immutably. For the distributed certification of identity claims, a reputation system based on signed trust declarations and domain vetting is used. In this work, we have designed and implemented the proposed architecture of Veritaa, created a testbed, and performed several experiments. The experiments show the benefits and the high performance of Veritaa.
A verifiable random function (VRF in short) is a powerful pseudo-random function that provides a non-interactively public verifiable proof for the correctness of its output. Recently, VRFs have found essential applications in blockchain design, such as random beacons and proof-of-stake consensus protocols. To our knowledge, the first generation of blockchain systems used inherently inefficient proof-of-work consensuses, and the research community tried to achieve the same properties by proposing proof-of-stake schemes where resource-intensive proof-of-work is emulated by cryptographic constructions. Unfortunately, those most discussed proof-of-stake consensuses (e.g., Algorand and Ouroborous family) are not future-proof because the building blocks are secure only under the classical hard assumptions; in particular, their designs ignore the advent of quantum computing and its implications. In this paper, we propose a generic compiler to obtain the post-quantum VRF from the simple VRF solution using symmetric-key primitives (e.g., non-interactive zero-knowledge system) with an intrinsic property of quantum-secure. Our novel solution is realized via two efficient zero-knowledge systems ZKBoo and ZKB++, respectively, to validate the compiler correctness. Our proof-of-concept implementation indicates that even today, the overheads introduced by our solution are acceptable in real-world deployments. We also demonstrate potential applications of a quantum-secure VRF, such as quantum-secure decentralized random beacon and lottery-based proof of stake consensus blockchain protocol.
Hanlin Zhang, Peng Gao, Jia Yu, Jie Lin · 5 authors
Linear Regression (LR) is a classical machine learning algorithm which has many applications in the cyber physical social systems (CPSS) to shape and simplify the way we live, work, and communicate. This paper focuses on the data analysis for CPSS when the Linear Regression is applied. The training process of LR is time-consuming since it involves complex matrix operations, especially when it gets a large scale training dataset In the CPSS. Thus, how to enable devices to efficiently perform the training process of the Linear Regression is of significant importance. To address this issue, in this paper, we present a secure, verifiable and fair approach to outsource LR to an untrustworthy cloud-server. In the proposed scheme, computation inputs/outputs are obscured so that the privacy of sensitive information is protected against cloud-server. Meanwhile, computation result from cloud-server is verifiable. Also, fairness is guaranteed by the blockchain, which ensures that the cloud gets paid only if he correctly performed the outsourced workload. Based on the presented approach, we exploited the fair, secure outsourcing system on the Ethereum blockchain. We analysed our presented scheme on theoretical and experimental, all of which indicate that the presented scheme is valid, secure and efficient.
Blockchain is a reliable and innovative technology that harnesses education and training through digital technologies. Nonetheless, it has been still an issue keeping track of student/graduate academic achievement and blockchain access rights management. Detailed information about academic performance within a certain period (semester) is not present in the official education documents. Furthermore, academic achievement documents issued by institutions are not secured against unauthorized changes due to the involvement of intermediaries. Therefore, verification of official educational documents has become a pressing issue owing to the recent development of digital technologies. However, effective tools to accelerate the verification are rare as the process takes time. This study provides a prototype of the UniverCert platform based on a consortium version of the decentralized, open-source Ethereum blockchain technology. The proposed platform is based on a globally distributed peer-to-peer network that allows educational institutions to partner with the blockchain network, track student data, verify academic performance, and share documents with other stakeholders. The UniverCert platform was developed on a consortium blockchain architecture to address the problems universities face in storing and securing student data. The system provides a solution to facilitate students’ registration, verification, and authenticity of educational documents.
Alexander Djamali, Patrick Dossow, Michael Hinterstocker, Benjamin Schellinger · 7 authors
Abstract Due to a steeply growing number of energy assets, the increasingly decentralized and segmented energy sector fuels the potential for new digital use cases. In this paper, we focus our attention on the application field of asset logging, which addresses the collection, documentation, and usage of relevant asset data for direct or later verification. We identified a number of promising use cases that so far have not been implemented; supposedly due to the lack of a suitable technical infrastructure. Besides the high degree of complexity associated with various stakeholders and the diversity of assets involved, the main challenge we found in asset logging use cases is to guarantee the tamper-resistance and integrity of the stored data while meeting scalability, addressing cost requirements, and protecting sensitive data. Against this backdrop, we present a blockchain-based platform and argue that it can meet all identified requirements. Our proposed technical solution hierarchically aggregates data in Merkle trees and leverages Merkle proofs for the efficient and privacy-preserving verification of data integrity, thereby ensuring scalability even for highly frequent data logging. By connecting all stakeholders and assets involved on the platform through bilateral and authenticated communication channels and adding a blockchain as a shared foundation of trust, we implement a wide range of asset logging use cases and provide the basis for leveraging platform effects in future use cases that build on verifiable data. Along with the technical aspects of our solution, we discuss the challenges of its practical implementation in the energy sector and the next steps for testing in a regulatory sandbox approach.
Access control is a major factor in enhancing data security in the cloud storage system. However, the existing data sharing and the access control method have privacy data leakage and key abuse, which is a major challenge in the research community. Therefore, an effective method named Blockchain-based access control and data sharing approach is developed in the cloud storage system to increase data security. The proposed Blockchain-based access control and data sharing approach effectively solve single-point failure in the cloud system. It provides more benefits by increasing the throughput and reducing the cost. The Data user (DU) makes the registration request using the ID and password and forwards it to the Data Owner (DO), which processes the request and authenticates the Data user. The information of the data owner is embedded in the transactional blockchain using the encrypted master key. The Data owner achieves the data encryption process, and encrypted files are uploaded to the Interplanetary File System (IPFS). Based on the encrypted file location and encrypted key, the Data owner generates the ciphertext metadata and is embedded in the transactional blockchain. The proposed Blockchain-based access control and data sharing approach achieved better performance using the metrics, like a better genuine user detection rate of 95% and lower responsiveness of 25sec with the blockchain of 100 sizes.
The integrity of data stored in cloud environments is a critical concern as organizations increasingly rely on distributed cloud services for their data storage and processing needs. Traditional methods of data integrity assurance, such as cryptographic hashing and third-party audits, often fail to provide the required levels of security due to their centralized nature and reliance on trust in third-party entities. This paper proposes an AI augmented blockchain framework designed to provide a robust, decentralized solution for data integrity assurance in distributed cloud environments. By integrating Artificial Intelligence (AI) with blockchain technology, the proposed framework offers real-time anomaly detection, improved decision-making, and enhanced scalability for cloud data systems. The architecture utilizes a lightweight consensus mechanism, such as Delegated Proof of Stake (DPoS), to reduce latency and computational costs, while AI models are employed to identify anomalies in data transactions before they are permanently recorded on the blockchain. Experimental results show that the proposed system achieves a data integrity assurance rate of 98.5%, significantly outperforming traditional blockchain methods. Moreover, the framework reduces average transaction latency by 35% and increases transaction throughput by 43%. This results in a more efficient and sustainable approach to data integrity management, making it suitable for large-scale cloud deployments. The findings suggest that the AI-augmented blockchain framework can serve as a foundational solution for building trustworthy, tamper-proof data systems, with applications ranging from enterprise cloud services to secure Internet of Things (IoT) deployments. These advancements contribute to a more secure and resilient cloud computing environment, addressing the evolving challenges of data integrity and security.
Desire Ngabo, Dong Wang, Celestine Iwendi, Joseph Henry Anajemba · 6 authors
The recent developments in fog computing architecture and cloud of things (CoT) technology includes data mining management and artificial intelligence operations. However, one of the major challenges of this model is vulnerability to security threats and cyber-attacks against the fog computing layers. In such a scenario, each of the layers are susceptible to different intimidations, including the sensed data (edge layer), computing and processing of data (fog (layer), and storage and management for public users (cloud). The conventional data storage and security mechanisms that are currently in use appear to not be suitable for such a huge amount of generated data in the fog computing architecture. Thus, the major focus of this research is to provide security countermeasures against medical data mining threats, which are generated from the sensing layer (a human wearable device) and storage of data in the cloud database of internet of things (IoT). Therefore, we propose a public-permissioned blockchain security mechanism using elliptic curve crypto (ECC) digital signature that that supports a distributed ledger database (server) to provide an immutable security solution, transaction transparency and prevent the patient records tampering at the IoTs fog layer. The blockchain technology approach also helps to mitigate these issues of latency, centralization, and scalability in the fog model.
Supply chain applications operate in a multi-stakeholder setting, demanding trust, provenance, and transparency. Blockchain technology provides mechanisms to establish a decentralized infrastructure involving multiple stakeholders. Such mechanisms make the blockchain technology ideal for multi-stakeholder supply chain applications. This chapter introduces the characteristics and requirements of the supply chain and explains how blockchain technology can meet the demands of supply chain applications. In particular, this chapter discusses how data and trust management can be established using blockchain technology. The importance of scalability and interoperability in a blockchain-based supply chain is highlighted to help the stakeholders make an informed decision. The chapter concludes by underscoring the design challenges and open opportunities in the blockchain-based supply chain domain.
Eugenio Balistri, Francesco Casellato, Carlo Giannelli, Cesare Stefanelli
To identify health risks in working environments, it is crucial for companies to share personal health data demonstrating to clients and suppliers their employees are healthy, while being compliant with data protection legislation. Based on these considerations, our Blockchain-based BlockHealth solution allows personal health data sharing with tamper proofing and data protection. Traditionally, the Blockchain guarantees data immutability but not confidentiality. On the contrary, BlockHealth stores in the Blockchain only hash values of data. Health data is stored in private databases managed by companies, thus also allowing to delete data in compliance with the right to be forgotten.
Lattice-based non-interactive zero-knowledge proof has been widely used in one-way communication and can be effectively applied to resist quantum attacks. However, lattice-based non-interactive zero-knowledge proof schemes have long faced and paid more attention to some efficiency issues, such as proof size and verification time. In this paper, we propose the non-interactive zero-knowledge proof schemes from RLWE-based key exchange by making use of the Hash function and public-key encryption. We then show how to apply the proposed schemes to achieve the fixed proof size and rapid public verification. Compared with previous approaches, our schemes can realize better effectiveness in proof size and verification time. In addition, the proposed schemes are secure from completeness, soundness, and zero-knowledge.
The use of digital health records, stricter health laws and the growing need for health records exchange points towards the need for an efficient security and privacy preserving mechanism. For Health Insurance management systems, multiple entities exchange health information which is used for decision making. Since multiple authoritative entities are involved, a secure and efficient information sharing protocol is required as extremely sensitive health information is exchanged among the entities. Hence this paper aims to put forward a novel a decentralized authentication system based on Blockchain known as Insurance Claim Blockchain (ICBChain) system. The proposed system ensures privacy of patients, provides secure information exchange and authentication of entities. An implementation of the proposed system is provided using Ethereum Blockchain. The security and performance analysis of the system shows its potential to satisfy Healthcare security requirements and its efficiency respectively
Estruturas de dados tem sido um dos principais objetos de estudo da computação. Alguns cenários de aplicação dessas estruturas possuem requisitos relacionados à segurança e integridade dos dados nelas contidos. Deste modo, no decorrer da história da computação foram propostas estruturas de dados verificáveis, que apresentam características que visam atender a alguns requisitos de segurança como a garantia de imutabilidade e a verificação de um item de dado pertencente a estas estruturas. Este artigo analisa duas estruturas de dados verificáveis, a saber, a Mekle Tree e a Merkle PATRICIA Trie, descrevendo seus conceitos, características e cenários de aplicação no contexto das blockchains Ethereum e Neo.
Enrico Bacis, Dario Facchinetti, Marco Guarnieri, Marco Rosa · 6 authors
A Time-Lock enables the release of a secret at a future point in time. Many approaches implement Time-Locks as cryptographic puzzles, binding the recovery of the secret to the solution of the puzzle. Since the time required to find the puzzle’s solution may vary due to a multitude of factors, including the computational effort spent, these solutions may not suit all scenarios.