Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,621 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,621 results ¡ page 44 of 68

Clear filters
Jun 1, 2021¡Intelligent and Converged Networks
31 cites
Blockchain-enabled fog resource access and granting

Gang Liu, Jinsong Wu, Ting Wang

Fog computing is a new computing paradigm for meeting ubiquitous massive access and latency-critical applications by moving the processing capability closer to end users. The geographical distribution/floating features with potential autonomy requirements introduce new challenges to the traditional methodology of network access control. In this paper, a blockchain-enabled fog resource access and granting solution is proposed to tackle the unique requirements brought by fog computing. The smart contract concept is introduced to enable dynamic, and automatic credential generation and delivery for an independent offer of fog resources. A per-transaction negotiation mechanism supports the fog resource provider to dynamically publish an offer and facilitates the choice of the preferred resource by the end user. Decentralized authentication and authorization relieve the processing pressure brought by massive access and single-point failure. Our solution can be extended and used in multi-access and especially multi-carrier scenarios in which centralized authorities are absent.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Jun 1, 2021¡arXiv
29 cites
Towards a Scalable and Trustworthy Blockchain: IoT Use Case

Hajar Moudoud, Soumaya Cherkaoui, Lyes Khoukhi

Recently, blockchain has gained momentum as a novel technology that gives rise to a plethora of new decentralized applications (e.g., Internet of Things (IoT)). However, its integration with the IoT is still facing several problems (e.g., scalability, flexibility). Provisioning resources to enable a large number of connected IoT devices implies having a scalable and flexible blockchain. To address these issues, we propose a scalable and trustworthy blockchain (STB) architecture that is suitable for the IoT; which uses blockchain sharding and oracles to establish trust among unreliable IoT devices in a fully distributed and trustworthy manner. In particular, we design a Peer-To-Peer oracle network that ensures data reliability, scalability, flexibility, and trustworthiness. Furthermore, we introduce a new lightweight consensus algorithm that scales the blockchain dramatically while ensuring the interoperability among participants of the blockchain. The results show that our proposed STB architecture achieves flexibility, efficiency, and scalability making it a promising solution that is suitable for the IoT context.

Open access
2 source records
cs.CR
cs.NI
Blockchain Technology Applications and Security
Original source
May 29, 2021¡Future Internet
35 cites
EngraveChain: A Blockchain-Based Tamper-Proof Distributed Log System

Louis Shekhtman, Erez Waisbard

A reliable log system is a prerequisite for many applications. Financial systems need to have transactions logged in a precise manner, medical systems rely on having trusted medical records and security logs record system access requests in order to trace malicious attempts. Keeping multiple copies helps to achieve availability and reliability against such hackers. Unfortunately, maintaining redundant copies in a distributed manner in a byzantine setting has always been a challenging task, however it has recently become simpler given advances in blockchain technologies. In this work, we present a tamper-resistant log system through the use of a blockchain. We leverage the immutable write action and distributed storage provided by the blockchain as a basis to develop a secure log system, but we also add a privacy preserving layer that is essential for many applications. We detail the security and privacy aspects of our solution, as well as how they relate to performance needs in relevant settings. Finally, we implement our system over Hyperledger Fabric and demonstrate the system’s value for several use cases. In addition, we provide a scalability analysis for applying our solution in a large-scale system.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
May 28, 2021¡Sensors
70 cites
A Scoping Review of Integrated Blockchain-Cloud (BcC) Architecture for Healthcare: Applications, Challenges and Solutions

Leila Ismail, Huned Materwala, Alain Hennebelle

Blockchain is a disruptive technology for shaping the next era of a healthcare system striving for efficient and effective patient care. This is thanks to its peer-to-peer, secure, and transparent characteristics. On the other hand, cloud computing made its way into the healthcare system thanks to its elasticity and cost-efficiency nature. However, cloud-based systems fail to provide a secured and private patient-centric cohesive view to multiple healthcare stakeholders. In this situation, blockchain provides solutions to address security and privacy concerns of the cloud because of its decentralization feature combined with data security and privacy, while cloud provides solutions to the blockchain scalability and efficiency challenges. Therefore a novel paradigm of blockchain-cloud integration (BcC) emerges for the domain of healthcare. In this paper, we provide an in-depth analysis of the BcC integration for the healthcare system to give the readers the motivations behind the emergence of this new paradigm, introduce a classification of existing architectures and their applications for better healthcare. We then review the development platforms and services and highlight the research challenges for the integrated BcC architecture, possible solutions, and future research directions. The results of this paper will be useful for the healthcare industry to design and develop a data management system for better patient care.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 27, 2021¡Studies in health technology and informatics
19 cites
A Blockchain-Based Healthcare Platform for Secure Personalised Data Sharing

Juliana Bowles, Thais Webber, Euan Blackledge, Andreas François Vermeulen

To facilitate personalised healthcare provision across Europe, we envision solutions that enable the secure integration and sharing of medical health records. These solutions should address privacy concerns, such as granular access control to personal data, establishing what should be accessible when and by whom, whilst complying with collective regulatory frameworks such as the European General Data Protection Regulation (GDPR) and adhering to international standards on how to manage information security. The proposed healthcare system design integrates technologies such as blockchain and scalable data lakes with adequate system routines to guarantee the secure access of confidential data. In this paper, we present the essential architectural components for the secure integration of medical records in a blockchain-based platform. We present a patient-centric data retrieval approach which incorporates a structured format to compose access rules.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
May 27, 2021¡Future Generation Computer Systems
63 cites
Achieving cybersecurity in blockchain-based systems: A survey

Mar Gimenez-Aguilar, José M. de Fuentes, Lorena González‐Manzano, David Arroyo

With the increase in connectivity, the popularization of cloud services, and the rise of the Internet of Things (IoT), decentralized approaches for trust management are gaining momentum. Since blockchain technologies provide a distributed ledger, they are receiving massive attention from the research community in different application fields. However, this technology does not provide with cybersecurity by itself. Thus, this survey aims to provide with a comprehensive review of techniques and elements that have been proposed to achieve cybersecurity in blockchain-based systems. The analysis is intended to target area researchers, cybersecurity specialists and blockchain developers. For this purpose, we analyze 272 papers from 2013 to 2020 and 128 industrial applications. We summarize the lessons learned and identify several matters to foster further research in this area.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 16, 2021¡Applied Sciences
38 cites
Application of Blockchain in Education: GDPR-Compliant and Scalable Certification and Verification of Academic Information

Christian Delgado‐von‐Eitzen, Luis Anido, Manuel J. Fernández Iglesias

Blockchain technologies are awakening in recent years the interest of different actors in various sectors and, among them, the education field, which is studying the application of these technologies to improve information traceability, accountability, and integrity, while guaranteeing its privacy, transparency, robustness, trustworthiness, and authenticity. Different interesting proposals and projects were launched and are currently being developed. Nevertheless, there are still issues not adequately addressed, such as scalability, privacy, and compliance with international regulations such as the General Data Protection Regulation in Europe. This paper analyzes the application of blockchain technologies and related challenges to issue and verify educational data and proposes an innovative solution to tackle them. The proposed model supports the issuance, storage, and verification of different types of academic information, both formal and informal, and complies with applicable regulations, protecting the privacy of users’ personal data. This proposal also addresses the scalability challenges and paves the way for a global academic certification system.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
May 16, 2021¡arXiv (Cornell University)
594 cites
Non-Fungible Token (NFT): Overview, Evaluation, Opportunities and Challenges

Qin Wang, Rujia Li, Qi Wang, Shiping Chen

The Non-Fungible Token (NFT) market is mushrooming in recent years. The concept of NFT originally comes from a token standard of Ethereum, aiming to distinguish each token with distinguishable signs. This type of token can be bound with virtual/digital properties as their unique identifications. With NFTs, all marked properties can be freely traded with customized values according to their ages, rarity, liquidity, etc. It has greatly stimulated the prosperity of the decentralized application (DApp) market. At the time of writing (May 2021), the total money used on completed NFT sales has reached $34,530,649.86$ USD. The thousandfold return on its increasing market draws huge attention worldwide. However, the development of the NFT ecosystem is still in its early stage, and the technologies of NFTs are pre-mature. Newcomers may get lost in their frenetic evolution due to the lack of systematic summaries. In this technical report, we explore the NFT ecosystems in several aspects. We start with an overview of state-of-the-art NFT solutions, then provide their technical components, protocols, standards, and desired proprieties. Afterward, we give a security evolution, with discussions on the perspectives of their design models, opportunities, and challenges. To the best of our knowledge, this is the first systematic study on the current NFT ecosystems.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Cloud Data Security Solutions
Original source
May 12, 2021¡PeerJ Computer Science
5 cites
VisTAS: blockchain-based visible and trusted remote authentication system

Ahmad Ali, Mansoor Ahmed, Abid Khan, Adeel Anjum ¡ 6 authors

The information security domain focuses on security needs at all levels in a computing environment in either the Internet of Things, Cloud Computing, Cloud of Things, or any other implementation. Data, devices, services, or applications and communication are required to be protected and provided by information security shields at all levels and in all working states. Remote authentication is required to perform different administrative operations in an information system, and Administrators have full access to the system and may pose insider threats. Superusers and administrators are the most trusted persons in an organisation. "Trust but verify" is an approach to have an eye on the superusers and administrators. Distributed ledger technology (Blockchain-based data storage) is an immutable data storage scheme and provides a built-in facility to share statistics among peers. Distributed ledgers are proposed to provide visible security and non-repudiation, which securely records administrators' authentications requests. The presence of security, privacy, and accountability measures establish trust among its stakeholders. Securing information in an electronic data processing system is challenging, i.e., providing services and access control for the resources to only legitimate users. Authentication plays a vital role in systems' security; therefore, authentication and identity management are the key subjects to provide information security services. The leading cause of information security breaches is the failure of identity management/authentication systems and insider threats. In this regard, visible security measures have more deterrence than other schemes. In this paper, an authentication scheme, "VisTAS," has been introduced, which provides visible security and trusted authentication services to the tenants and keeps the records in the blockchain.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 11, 2021¡Symmetry
8 cites
Revisited—The Subliminal Channel in Blockchain and Its Application to IoT Security

Tzung‐Her Chen, Wei‐Bin Lee, Hsing‐Bai Chen, Chien-Lung Wang

Although digital signature has been a fundamental technology for cryptosystems, it still draws considerable attention from both academia and industry due to the recent raising interest in blockchains. This article revisits the subliminal channel existing digital signature and reviews its abuse risk of the constructor’s private key. From a different perspective on the subliminal channel, we find the new concept named the chamber of secrets in blockchains. The found concept, whereby the secret is hidden and later recovered by the constructor from the common transactions in a blockchain, highlights a new way to encourage implementing various applications to benefit efficiency and security. Thus, the proposed scheme benefits from the following advantages: (1) avoiding the high maintenance cost of certificate chain of certificate authority, or public key infrastructure, and (2) seamlessly integrating with blockchains using the property of chamber of secrets. In order to easily understand the superiority of this new concept, a remote authentication scenario is taken as a paradigm of IoT to demonstrate that the further advantages are achieved: (1) avoiding high demand for storage space in IoT devices, and (2) avoiding maintaining a sensitive table in IoT server.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
May 11, 2021¡Current Issues in Auditing
12 cites
Preparing Auditors for the Blockchain Oracle Problem

Mark D. Sheldon

SUMMARY This article summarizes “Auditing the Blockchain Oracle Problem” (Sheldon 2021), which introduces auditors to the risks of having an irreversible business agreement codified on a blockchain using a short software program called a smart contract that relies on an oracle to provide information from outside the blockchain in order to execute correctly. The article begins with an explanation of the role that oracles play in the blockchain ecosystem and proposes a working definition of oracles. Next, the article highlights how the auditing standards from both the AICPA and PCAOB can be interpreted to classify an oracle as part of smart contract users' information systems, and that the oracle provides a robust set of services that qualify it as a service organization. Finally, the article describes the process used by an oracle to collect, store, transform, and transmit data, and highlights relevant risks and illustrative control objectives related to this process.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
May 10, 2021¡Data Intelligence
26 cites
OpenKG Chain: A Blockchain Infrastructure for Open Knowledge Graphs

Huajun Chen, Ning Hu, Guilin Qi, Haofen Wang ¡ 7 authors

Abstract The early concept of knowledge graph originates from the idea of the Semantic Web, which aims at using structured graphs to model the knowledge of the world and record the relationships that exist between things. Currently publishing knowledge bases as open data on the Web has gained significant attention. In China, CIPS(Chinese Information Processing Society) launched the OpenKG in 2015 to foster the development of Chinese Open Knowledge Graphs. Unlike existing open knowledge-based programs, OpenKG chain is envisioned as a blockchain-based open knowledge infrastructure. This article introduces the first attempt at the implementation of sharing knowledge graphs on OpenKG chain, a blockchain-based trust network. We have completed the test of the underlying blockchain platform, as well as the on-chain test of OpenKG's dataset and toolset sharing as well as fine-grained knowledge crowdsourcing at the triple level. We have also proposed novel definitions: K-Point and OpenKG Token, which can be considered as a measurement of knowledge value and user value. 1033 knowledge contributors have been involved in two months of testing on the blockchain, and the cumulative number of on-chain recordings triggered by real knowledge consumers has reached 550,000 with an average daily peak value of more than 10,000. For the first time, We have tested and realized on-chain sharing of knowledge at entity/triple granularity level. At present, all operations on the datasets and toolset in OpenKG.CN, as well as the triplets in OpenBase, are recorded on the chain, and corresponding value will also be generated and assigned in a trusted mode. Via this effort, OpenKG chain looks to provide a more credible and traceable knowledge-sharing platform for the knowledge graph community.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Mobile Crowdsensing and Crowdsourcing
Original source
May 4, 2021¡Aptisi Transactions on Management (ATM)
44 cites
Blockchain For Education Purpose: Essential Topology

Qurotul Aini, Ninda Lutfiani, Nuke Puji Lestari Santoso, Sulistiawati Sulistiawati ¡ 5 authors

Blockchain technology is known for its large-scale digitisation trends that play an important role in various organisations. Because it is distributed and decentralized from blockchain, this feature makes the role of blockchain technologies based on products and services significantly different from previous technology offerings. The value proposition offered by this blockchain is very suitable to be applied in education. After a few years this caused disruption from various industry circles, current educational areas including those that are very perceived by the Indonesian people there is no progress and road in place. It is possible that in the next ten years, the educational actors who are less sensitive will one by one fall because of the storm-cast disruption technology. The educational institution is one of which is aware of the advantages and extraordinary potential of blockchain technology. Among other things, a digital signature certificate is important in the context of digital archiving to verify the authenticity of a document in an educational institution. But the lack of education from the community makes ignorance about the point of the advantage of blockchain technology that can be applied in the field of education. Therefore, a public understanding of the blockchain is packaged in the form of ontology on the education shutter. This research in particular is exploring the ontology approach of using root merkle methods in providing solutions to the application of blockchain, including slow process and small storage space. This issue causes it to be very difficult for educational institutions to store processes and stages of learning into the blockchain. This research can be the cornerstone of identifying solutions from certificates of digital signatures in terms of archiving, authentication and digital verification on the design of a new breakthrough framework with an ontology approach to blockchain educational design.

Open access
Blockchain Technology in Education and Learning
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Original source
May 3, 2021¡2021 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
14 cites
HSM-based Key Management Solution for Ethereum Blockchain

Wazen M. Shbair, E. Gavrilov, Radu State

The security of distributed applications backed by blockchain technology relies mainly on keeping the associated cryptographic keys (i.e. private keys) in well-protected storage. Since they are the unique proof of ownership of the underlying digital assets. If the keys are stolen or lost, there is no way to recover the assets. The cold wallet is a good candidate for basic use cases, but it has a substantial challenge for more complex applications as it does not scale. Warm and hot wallets are more convenient options for blockchain-based solutions that aim to transact in a cloud environment. In this work, we focus on Hardware Security Module (HSM) based wallet. The HSM is the de-facto standard device designed to manage high-value cryptographic keys and to protect them against hacks. In this demonstration, we present an HSM-based working prototype that secures the entire life cycle of Ethereum public and private keys.

Open access
2 source records
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Security and Verification in Computing
Original source
May 1, 2021¡reposiTUm (TU Wien)
0 cites
Foundations for the Security Analysis of Distributed Blockchain Applications

Clara Schneidewind

Cryptocurrencies do not only allow for money transfers in the absence of a trusted third party but also enable the execution of distributed applications. Due to the rapid pace of development of cryptocurrencies, the foundations of such applications have not been rigorously studied. This is particularly problematic since in these applications, real money is at stake, and security breaches regularly cause severe financial losses.In this thesis, we present two systematic approaches to reliably verify the security of distributed blockchain applications based on formal foundations. To this end, we focus on the cryptocurrencies with the highest market capitalization, Bitcoin and Ethereum. In Ethereum, distributed applications are realized as smart contracts, reactive programs written in Ethereum’s expressive scripting language. In contrast, Bitcoin supports only a basic scripting language, and advanced applications are realized as peer-to-peer cryptographic protocols that resort to the execution of simple smart contracts in case of disputes among peers. As a result, the challenge in verifying distributed applications on the Ethereum blockchain lies in the study and abstraction of the semantics of Ethereum’s evolved scripting language, whereas Bitcoin, the study of distributed applications, requires a systematic analysis of the cryptographic protocols.In the thesis, we first formalize the formerly under-specified semantics of Ethereum’s native smart contract language EVM bytecode and implement the semantics in the proof assistant F*. In this context, we formally characterize relevant generic properties for smart contract security, which capture real-world attack scenarios.We then survey existing automated static analyzers for Ethereum smart contracts unveiling the weaknesses in the semantic foundations of these tools and the practical impact of these weaknesses on the analysis results. Based on these findings, we propose our own automatic static analysis tool for Ethereum smart contracts, which comes with a rigorous soundness proof while still showing competitive performance. In this course, we also propose a general framework for the modular and semantic-driven development of automatic static analyzers. Finally, we study the security of payment channel networks for Bitcoin. Payment channel networks are distributed protocols that allow for efficient and cheap payments between Bitcoin users and offer a promising solution to Bitcoin’s scalability problems. We unveil a security issue in Bitcoin’s existing payment channel network implementation and formally characterize the relevant security and privacy notions in this context. We further develop a cryptographic primitive for the construction of payment channel networks with formal security guarantees

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Network Security and Intrusion Detection
Original source
Apr 29, 2021¡Security and Communication Networks
39 cites
Blockchain-Based Cloud Data Integrity Verification Scheme with High Efficiency

Gaopeng Xie, Yuling Liu, Guojiang Xin, Qiuwei Yang

With the large-scale application of cloud storage, how to ensure cloud data integrity has become an important issue. Although many methods have been proposed, they still have their limitations. This paper improves some defects of the previous methods and proposes an efficient cloud data integrity verification scheme based on blockchain. In this paper, we proposed a lattice signature algorithm to resist quantum computing and introduced cuckoo filter to simplify the computational overhead of the user verification phase. Finally, the decentralized blockchain network is introduced to replace traditional centralized audit to publicize and authenticate the verification results, which improves the transparency and the security of this scheme. Security analysis shows that our scheme can resist malicious attacks and experimental results show that our scheme has high efficiency, especially in the user verification phase.

Open access
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Apr 28, 2021¡IEEE Transactions on Information Forensics and Security
17 cites
Accountable Fine-grained Blockchain Rewriting in the Permissionless Setting

Yangguang Tian, Bowen Liu, Yingjiu Li, Paweł Szałachowski · 5 authors

Blockchain rewriting with fine-grained access control allows a user to create a transaction associated with a set of attributes, while another user (or modifier) who possesses enough rewriting privileges from a trusted authority satisfying the attribute set can rewrite the transaction. However, it lacks accountability and is not designed for open blockchains that require no trust assumptions. In this work, we introduce accountable fine-grained blockchain rewriting in a permissionless setting. The property of accountability allows the modifier's identity and her rewriting privileges to be held accountable for the modified transactions in case of malicious rewriting (e.g., modify the registered content from good to bad). We first present a generic framework to secure blockchain rewriting in the permissionless setting. Second, we present an instantiation of our approach and show its practicality through evaluation analysis. Last, we demonstrate that our proof-of-concept implementation can be effectively integrated into open blockchains.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Apr 28, 2021¡Turkish Journal of Computer and Mathematics Education (TURCOMAT)
10 cites
Leveraging Blockchain technology in the Education Sector

Devaki Kulkarni

The act of maintaining educational records both online and on paper have become a norm. With the enforcement of lockdowns due to the Covid-19 pandemic, the education sector attempted to move their entire operations online.  However with this move, various operations such as Verification of Documents, Approval of LORs have become harder to deal with in a legitimate manner. In this paper, we have compared various existing methods to deal with the problem at hand and proposed our system for the same.

Open access
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Cloud Computing and Resource Management
Original source
Apr 28, 2021¡National Science Review
5 cites
Lattice-based digital signatures

Vadim Lyubashevsky

Digital signatures and key exchange protocols are the two most important public key cryptographic primitives used in the electronic transmission of data. The goal of key exchange is to preserve the secrecy of the communication, while the goal of digital signatures is to guarantee the authenticity of the exchanged messages. Constructions of digital signature schemes based on classical mathematical assumptions appeared shortly following the invention of public key cryptography in the late 1970s. And just like with key exchange, the most efficient variants are based on number-theoretic problems that are believed to be (sub)-exponentially hard for classical machines, but are solved in polynomial time by Shor’s algorithm on a powerful-enough quantum computer. Also, like for key exchange, the most efficient constructions that we believe to be quantum safe are based on the presumed hardness of lattice problems over polynomial rings. One interesting difference between key exchange and digital signatures is that key exchange appears to inherently require that some mathematical problem be computationally hard. Digital signatures, on the other hand, can be generically constructed from any one-way function [1,2]. So even though they certainly fall into the category of public key primitives based on their usage, their existence requires much weaker assumptions. Additionally, the transformation from a one-way function to a digital signature is not too inefficient. For example, the total parameter size (public key + signature) of the SPHINCS+ scheme [3] is around 40 kB. While these sizes are larger, and signing times considerably longer, than those of signatures based on factoring or discrete log, it is still a usable scheme for many applications. And being only based on symmetric assumptions (e.g. one wayness and collision resistance of cryptographic hash functions), its security is very attractive. In order to be considered an interesting alternative to the above-mentioned signature, a scheme based on a mathematical assumption would need to have significant performance advantages. Schemes based on factoring and the discrete logarithm problem were significantly shorter and faster, and so the generic approach lay dormant for over four decades. The new quantum-safe schemes will need to have similar performance advantages if they are to be used in lieu of this safe approach. Below, we describe two techniques for constructing lattice-based digital signatures with output sizes being just a few kilobytes. On a very high level, lattice-based signature constructions follow the two known approaches for constructing classical signatures. In the first approach, the signer outputs a function f and an image y = f(x) as his public key and keeps x as his secret key. To sign a message μ, he gives a non-interactive zero-knowledge proof that he knows an x satisfying y = f(x), using the message μ to create the ‘challenge’ H(μ) for the proof (where H is a public function that maps μ to something ‘random looking’). If the function f is one way then the verifier should be convinced that the proof could have only been created by the entity who knows x. A classic example of this type of scheme is the Schnorr signature scheme [4] based on the hardness of the discrete logarithm problem. The second approach is to create a function f together with a trapdoor f−1, output f as the public key and keep f−1 as the secret key. A message μ is signed by using the secret trapdoor to create a pre-image x such that f(x) = H(μ). Again, if the function f is one way then only someone in possession of a trapdoor should be able to invert it. An example of such a construction based on a ‘factoring-like’ assumption is the RSA signature scheme [5]. The high-level ideas for lattice-based signatures follow the above blueprints, but the technical details are significantly more involved. The main reason for the complications is the different algebraic structure of the hard one-way function underlying lattice cryptography. While the domain of the function in discrete log and RSA-based one-way functions are groups, the domains in lattice-based signatures are sets that are not closed under any operation—in particular, they are elements in a group that have small norms. This crucial small norm requirement precludes us from using uniformly random masking as in Schnorr signatures or having a trapdoor for a bijective one-way function as in RSA signatures. These barriers have, nevertheless, been overcome and the resulting digital signatures are quite practical. In 2017, the US National Institute of Standards and Technology (NIST) began a ‘competition’ for a quantum-safe key exchange and digital signatures standard. At the time of this writing, this process is in the third round and there are two lattice-based signatures remaining—each following one of the above high-level designs. The CRYSTALS-Dilithium [6] scheme follows the Schnorr framework, but adds a crucial rejection-sampling step to keep the size of the coefficients small. The FALCON scheme [7] utilizes a randomized trapdoor sampling technique that uses a secret trapdoor for f−1 to produce random pre-images from a particular distribution. Because there is no longer a bijection, it is crucial to also have the property that the distribution of the outputted pre-images does not leak information about the trapdoor. Both schemes are relatively fast and their parameters (public key + signature size) are the shortest of all quantum-safe signature schemes. While both schemes are based on lattices, they have rather different characteristics. FALCON has very short parameters (see Table 1), but entails a rather complicated procedure for signature generation. In particular, it uses (an optimized version of) the GPV sampler [8], which requires floating-point arithmetic with approximately 64 bits of precision. Requiring such high precision means that subtle implementation errors may not get detected even with rigorous testing. Dilithium, on the other hand, has larger parameters but a very simple implementation where all the sampling in the signing is done in a power-of-2 range; it is thus much less prone to implementation errors. It is quite possible that in the future both schemes will be used for different applications. Approximate parameter sizes (in bytes) for the CRYSTALS-Dilithium and FALCON digital signature schemes at approximately 128-bit security levels. Approximate parameter sizes (in bytes) for the CRYSTALS-Dilithium and FALCON digital signature schemes at approximately 128-bit security levels. Conflict of interest statement. None declared.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Digital Image Processing Techniques
Original source
Apr 28, 2021·Türk bilgisayar ve matematik eğitimi dergisi
48 cites
A Blockchain-based framework for secure Educational Credentials

Et. al. Shadab Alam

Blockchain provides a creative approach to storing information, executing transactions, conducting tasks, and building trust. Some see Blockchain as a revolutionary technology for cryptography and cybersecurity, with applications ranging from cryptocurrency to healthcare, smart contracts, Internet of Things, smart grids governance, supply-chain etc. This research work would offer a detailed analysis of blockchain Security, Privacy and Trust. It further studies the applications of blockchain technology in the domain of education and involved challenges. Finally, it proposes a blockchain-based framework for secure and reliable student's record management.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
Apr 27, 2021¡arXiv (Cornell University)
41 cites
PrivChain: Provenance and Privacy Preservation in Blockchain enabled Supply Chains

Sidra Malik, Volkan Dedeoglu, Salil S. Kanhere, Raja Jurdak

Blockchain offers traceability and transparency to supply chain event data and hence can help overcome many challenges in supply chain management such as: data integrity, provenance and traceability. However, data privacy concerns such as the protection of trade secrets have hindered adoption of blockchain technology. Although consortium blockchains only allow authorised supply chain entities to read/write to the ledger, privacy preservation of trade secrets cannot be ascertained. In this work, we propose a privacy-preservation framework, PrivChain, to protect sensitive data on blockchain using zero knowledge proofs. PrivChain provides provenance and traceability without revealing any sensitive information to end-consumers or supply chain entities. Its novelty stems from: a) its ability to allow data owners to protect trade related information and instead provide proofs on the data, and b) an integrated incentive mechanism for entities providing valid proofs over provenance data. In particular, PrivChain uses Zero Knowledge Range Proofs (ZKRPs), an efficient variant of ZKPs, to provide origin information without disclosing the exact location of a supply chain product. Furthermore, the framework allows to compute proofs and commitments off-line, decoupling the computational overhead from blockchain. The proof verification process and incentive payment initiation are automated using blockchain transactions, smart contracts, and events. A proof of concept implementation on Hyperledger Fabric reveals a minimal overhead of using PrivChain for blockchain enabled supply chains.

Open access
3 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Apr 22, 2021¡Electronics
24 cites
Blockchain-Enabled Access Management System for Edge Computing

Yong Zhu, Chao Huang, Zhihui Hu, Abdullah Al‐Dhelaan · 5 authors

In the post-cloud era, edge computing is a new computing paradigm with data processed at the edge of the network, which can process the data close to the end-user in real time and offload the cloud task intelligently. Meanwhile, the decentralization, tamper-proof and anonymity of blockchain technology can provide a new trusted computing environment for edge computing. However, it does raise considerable concerns of security, privacy, fault-tolerance and so on. For example, identity authentication and access control rely on third parties, heterogeneous devices and different vendors in IoT, leading to security and privacy risks, etc. How to combine the advantages of the two has become the highlight of academic research, especially the issue of secure resource management. Comprehensive security and privacy involve all aspects of platform, data, application and access control. In. this paper, the architecture and behavior of an Access Management System (AMS) in a proof of concept (PoC) prototype are proposed with a Color Petri Net (CPN) model. The two domains of blockchain and edge computing are organically connected by interfaces and interactions. The simulation of operation, activity and role association proves the feasibility and effectiveness of the AMS. The instances of platform business access control, data access control, database services, IOT hub service are run on Advantech WISE-PaaS through User Account and Authentication (UAA). Finally, fine-grained and distributed access control can be realized with the help of a blockchain attribute. Namely, smart contracts are used to register, broadcast, and revoke access authorization, as well as to create specific transactions to define access control policies.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Apr 20, 2021¡Zenodo (CERN European Organization for Nuclear Research)
0 cites
A Dynamic Resource Management Algorithm for Improving Service Availability in Multi-Cloud Systems

Kushala M V, Dr. B S Shylaja

The increasing adoption of multi-cloud computing has created new opportunities for improving resource utilization, service reliability, and reducing dependence on a single cloud provider. However, the distributed nature of multi-cloud infrastructures introduces significant challenges in maintaining data security, privacy, and continuous service availability. This study presents a dynamic security framework designed for multi-cloud environments that integrates adaptive monitoring with a multi-layer encryption mechanism. The proposed approach intelligently selects suitable encryption techniques based on data sensitivity, file size, and available computing resources to achieve an optimal balance between security and performance. The framework Dynamic Resource Management Algorithm(DRMA) for secure key establishment, efficient symmetric encryption for protecting data, and zero-knowledge proof-based authentication to ensure secure user verification without revealing sensitive information. A comprehensive performance evaluation was conducted by comparing the proposed model with conventional RSA-based security approaches. Experimental results demonstrate improved computational efficiency, reduced encryption overhead, enhanced scalability, and stronger protection against unauthorized access. Furthermore, the framework provides resilience against both conventional cyberattacks and emerging quantum computing threats while maintaining efficient resource utilization. These findings indicate that the proposed solution offers a practical and secure approach for protecting data and improving the reliability of modern multi-cloud environments.

Open access
3 source records
Cloud Data Security Solutions
Big Data and Digital Economy
Cloud Computing and Resource Management
Original source