Linh Thủy Nguyễn, Lam Duc Nguyen, Thong Hoang, H. M. N. Dilum Bandara · 10 authors
The rise of data-sharing platforms, driven by public demand for open data and legislative mandates, has raised several pertinent issues. These encompass uncertainties over data accuracy, provenance and lineage, privacy concerns, consent management, and the lack of equitable incentives for data providers. The advanced nature of blockchain makes it well suited to address these concerns. Yet, the limitations of blockchains, particularly their restricted performance, scalability, and high cost, make them less adept at managing the four “Vs” of big data—volume, variety, velocity, and veracity. As the body of work proposing blockchain-based data-sharing solutions grows, so does the confusion in selecting between these platforms, particularly in terms of sharing mechanisms, services, quality of services, and applications. In this article, we aim to fill this knowledge gap through an in-depth survey of blockchain-based data-sharing architectures and applications. We first identify the key challenges of existing data-sharing techniques and lay out the foundations of blockchains. Our focus then shifts to the intersection of blockchain and data sharing, wherein we aim to clarify the existing landscape and propose a reference architecture for blockchain-based data sharing. Subsequently, we explore various industrial applications of blockchain-based data sharing, spanning healthcare, smart grids, transportation, and decarbonization. For each application, we draw from real-world deployments to present key lessons learned in the implementation of blockchain-based data sharing. Lastly, we shed light on current research challenges and open avenues for further study in this space. This article aims to serve as a comprehensive resource for researchers/practitioners looking to navigate the complex terrain of blockchain-based data-sharing solutions.
In recent years, edge-related smart computing is the way to process and store data via outsourcing environments. Security is the main progressive concept in smart-related Internet of Things (IoT) software denied networks to share and increase the scalability and efficiency in data storage. Because of the rapid growth of different smart services, different security-related problems may appear in resource processing and sharing data in real-time computing systems. To increase the reliability in secure data storage and satisfy the basic requirements related to IoT-related smart computing networks. So propose and implement a Novel Artificial Intelligence based Blockchain Secure Model (NAIBSM) to provide efficient secure data storage in IoT-related smart computing systems. This model flexibly captures each user authentication for the detection of different user-related attacks (i.e. distributed denial-of-service (DDOS)) in the storage of data via applying Artificial Intelligence (AI) calculation method i.e. Leverage Bat algorithm to explore complex features. Build a blockchain at the server side to provide secure communication and reliability of storing data on the terminal of IoT. This approach provides random hash values to each data to ensure blockchain for the integrity of data and uses a weight-based data storage procedure to arrange/store and classify data to each user with secure and unsecured storage in smart computing networks. The experimental results of the proposed model are to explore complex security features and ensure the performance of secure authentication to each user and better security, accuracy, and low communication overhead in IoT-related smart computing data storage and sharing systems.
Cybersecurity information sharing (CIS) is important in different business processes to secure data transmission, because it comprises Internet of Things (IoT) connectivity, workflow automation, collaboration, and communication. The shared information is influenced by intermediate users and alters the originality of the information. Although risk factors such as confidentiality and privacy of the data are reduced when using a cyber defense system, existing techniques rely on a centralized system that may be damaged during an accident. In addition, private information sharing faces rights issues when accessing sensitive information. The research issues influence trust, privacy, and security in a third-party environment. Therefore, this work uses the Access Control Enabled Blockchain (ACE-BC) framework to enhance overall data security in CIS. The ACE-BC framework uses attribute encryption techniques to manage data security, while the access control mechanism limits unauthorized user access. The effective utilization of blockchain techniques ensures overall data privacy and security. The efficiency of the introduced framework was evaluated using experimental results, and the experimental outcome indicated that the recommended ACE-BC framework enhanced the data confidentiality ratio (98.9%), the throughput ratio (98.2%), the efficiency ratio (97.4%), and the latency rate (10.9%) when compared to other popular models.
César Sabater, Florian Hahn, Peter Andreas, Jan Ramon
In this paper we study verifiable sampling from probability distributions in the context of multi-party computation. This has various applications in randomized algorithms performed collaboratively by parties not trusting each other. One example is differentially private machine learning where noise should be drawn, typically from a Laplace or Gaussian distribution, and it is desirable that no party can bias this process. In particular, we propose algorithms to draw random numbers from uniform, Laplace, Gaussian and arbitrary probability distributions, and to verify honest execution of the protocols through zero-knowledge proofs. We propose protocols that result in one party knowing the drawn number and protocols that deliver the drawn random number as a shared secret.
With the Internet of Things' (IoTs) rapid expansion, effect, and potential, the healthcare industry is shifting to a new paradigm that permits wearable devices to collect patient medical data and use it for monitoring and diagnosis. Tamper-proof data and avoidance of the centralized record-keeping mechanism are crucial requirements in any wellness system due to its exigent and precise necessity of data requests. Along with the same, transactions’ auditability and revocation of access rights upon certain records for specific stakeholders are also a few of the other prerequisites in the medical segment. Blockchain, as a distributed ledger, offers a solution for securely storing data while providing transparency in transactions and interactions among stakeholders. Synchronous interaction among patient, doctor, pharmacy, consultant, hospital, etc. with all possible data security is another concern that could be resolved through the usage of Blockchain’s smart contracts wherein interaction among these stakeholders is permitted in a traceable and irreversible mode. The purpose of this paper is to discuss the potential use of Blockchain technology in the healthcare sector to achieve data security, transparency, and reliability without the involvement of a trusted third party. In terms of security and privacy, we survey and provide an exhaustive review of Blockchain-based access control systems for the healthcare system. In addition, for the healthcare system, we propose and implemented a decentralized role-based access control model based on Ethereum smart contract.
Within the context of the big data age, data sharing is gradually rising with the embodiment of data value. Data value can increase through sharing, but there are security problems during the period of data sharing such as centralized deployment, malicious theft, and tampering, which greatly affect the security of data. Aiming at the common privacy leakage problem during data sharing, this research builds a data sharing platform on the chain based on blockchain technology, and combines the function encryption technology and zero-knowledge proof technology to realize the sharing of verifiable computing results, and proposes a sharing model. The purpose of this model is to enable the data owner to control the data sharing, so as to guarantee the security and privacy of the data while sharing, ensure that the original data is not leaked, and realize the availability and invisibility of the data. In addition, it is necessary to ensure the reliability of data processing results, eliminate the risk of unreliable data processing caused by original data encryption, and protect the legal right of data users.
Yinqiu Liu, Hongyang Du, Dusit Niyato, Jiawen Kang · 8 authors
The rapid development of Artificial Intelligence-Generated Content (AIGC) has brought daunting challenges regarding service latency, security, and trustworthiness. Recently, researchers presented the edge AIGC paradigm, effectively optimize the service latency by distributing AIGC services to edge devices. However, AIGC products are still unprotected and vulnerable to tampering and plagiarization. Moreover, as a kind of online non-fungible digital property, the free circulation of AIGC products is hindered by the lack of trustworthiness in open networks. In this article, for the first time, we present a blockchain-empowered framework to manage the lifecycle of edge AIGC products. Specifically, leveraging fraud proof, we first propose a protocol to protect the ownership and copyright of AIGC, called Proof-of-AIGC. Then, we design an incentive mechanism to guarantee the legitimate and timely executions of the funds-AIGC ownership exchanges among anonymous users. Furthermore, we build a multi-weight subjective logic-based reputation scheme, with which AIGC producers can determine which edge service provider is trustworthy and reliable to handle their services. Through numerical results, the superiority of the proposed approach is demonstrated. Last but not least, we discuss important open directions for further research.
The integration of Terrestrial and Non-Terrestrial Networks (TNTNs) with the sixth-generation (6G) wireless ecosystem will revolutionize the futuristic communication networks by enabling comprehensive interconnection and quality of service. However, such an integrated network will raise serious security and privacy issues due to the insecure communication among untrusted participating entities over an open unsecured public channel. As a result, the entire ecosystem can be accessed by both legitimate users and adversaries. Distributed AI when integrated with blockchain has a great potential to provide a feasible alternative to solve the security and privacy issues of 6G-assisted TNTNs. As a case study, a distributed AI is first adopted to cooperatively participate in the training process of a global model directly on devices. This approach ensures privacy and security of user data, and also confirms that only valid data is used by smart contracts to execute consensus mechanism. The multiple parallel blockchain are employed to securely and efficiently manage, and share data at each layer of 6G-assisted TNTNs. The efficiency of the proposed framework is demonstrated by numerical findings. Finally, prospective open research issues in employing distributed AI and blockchain for 6G-assisted TNTNs are highlighted.
We present a new dispute resolution protocol that can be built on the Ethereum blockchain. Unlike existing applications like Kleros, privacy is ensured by design through the use of the zero-knowledge protocols Semaphore and MACI (Minimal Anti-Collusion Infrastructure), which provide, among other things, resistance to Sybil-like attacks and corruption. Differently from Kleros, dispute resolution is guaranteed despite the users having the final say. Moreover, the proposed model does not use a native token on the platform, but aims to reward stakeholders through a social incentive mechanism based on soulbound tokens, introduced by Weyl, Ohlhaver, and Buterin in 2022. Users with these tokens will be considered trustworthy and will have the ability to govern the platform. As far as we know, this is one of the first blockchain projects that seeks to introduce social governance rather than one based on economic incentives.
Edge computing brings computational ability to network edges to enable low latency based on deploying devices close to the environment where the data is generated. Nevertheless, the limitation of size and energy consumption constrain the scalability and performance of edge device applications such as deep learning, although, cloud computing can be adopted to support high-performance tasks with centralized data collection. However, frequently communicating with a central cloud server brings potential risks to security and privacy issues by exposing data on the Internet. In this paper, we propose a secure continuous knowledge transfer approach to improve knowledge by collaborating with multiple edge devices in the decentralized edge computing architecture without a central server. Using blockchain, the knowledge integrity is maintained in the transfer process by recording the transaction information of each knowledge improvement and synchronizing the blockchain in each edge device. The knowledge is a trained deep-learning model that is derived by learning the local data. Using the local data of each edge device, the model is continuously trained to improve performance. Therefore, each improvement is recorded as the contribution of each edge device immutably in the decentralized edge computing architecture.
We consider a project (model) owner that would like to train a model by utilizing the local private data and compute power of interested data owners, i.e., trainers. Our goal is to design a data marketplace for such decentralized collaborative/federated learning applications that simultaneously provides i) proof-of-contribution based reward allocation so that the trainers are compensated based on their contributions to the trained model; ii) privacy-preserving decentralized model training by avoiding any data movement from data owners; iii) robustness against malicious parties (e.g., trainers aiming to poison the model); iv) verifiability in the sense that the integrity, i.e., correctness, of all computations in the data market protocol including contribution assessment and outlier detection are verifiable through zero-knowledge proofs; and v) efficient and universal design. We propose a blockchain-based marketplace design to achieve all five objectives mentioned above. In our design, we utilize a distributed storage infrastructure and an aggregator aside from the project owner and the trainers. The aggregator is a processing node that performs certain computations, including assessing trainer contributions, removing outliers, and updating hyper-parameters. We execute the proposed data market through a blockchain smart contract. The deployed smart contract ensures that the project owner cannot evade payment, and honest trainers are rewarded based on their contributions at the end of training. Finally, we implement the building blocks of the proposed data market and demonstrate their applicability in practical scenarios through extensive experiments.
Data integrity and tamper-proofing are of paramount importance in legal documents. To mitigate these issues of data tampering and data corruption in a centralized system, blockchain technology and Non-fungible tokens can be used. Blockchain is used to establish a trust-less system, eliminating the need for a facilitator or a centralized body to validate the correctness of data. Non Fungible Tokens can be used for their properties of immutability. The limitations of traditional NFTs such as data security and data corruption in a centralized and decentralized storage services are also discussed and a new method for data storage is proposed, i.e. On-Chain NFTs and their possible advantages and disadvantages, and how they provide an additional layer of security, making it more reliable than our current Off-Chain Non Fungible Token standards. Three novel approaches have been proposed, along with their respective pros and cons.
Federated learning (FL) has been widely used in both academia and industry all around the world. FL has advantages from the perspective of data security, data diversity, real-time continual learning, hardware efficiency, etc. However, it brings new privacy challenges, such as membership inference attacks and data poisoning attacks, when parts of participants are not assumed to be fully honest. Moreover, selfish participants can obtain others’ collaborative data but do not contribute their real local data or even provide fake data. This violates the fairness of FL schemes. Therefore, advanced privacy and fairness techniques have been integrated into FL schemes including blockchain, differential privacy, zero-knowledge proof, etc. However, most of the existing works still have room to enhance the practicality due to our exploration. In this paper, we propose a Blockchain-based Pseudorandom Number Generation (BPNG) protocol based on Verifiable Random Functions (VRFs) to guarantee the fairness for FL schemes. Next, we further propose a Gradient Random Noise Addition (GRNA) protocol based on differential privacy and zero-knowledge proofs to protect data privacy for FL schemes. Finally, we implement both two protocols on Hyperledger Fabric and analyze their performance. Simulation experiments show that the average time that proof generation takes is 18.993 s and the average time of on-chain verification is 2.27 s under our experimental environment settings, which means the scheme is practical in reality.
Resource management is a key issue that needs to be addressed in the future smart Internet of Things (IoT). This paper focuses on a Federated Learning (FL)-based resource management mechanism in IoT. It incorporates blockchain technology to guarantee the security of the FL model parameters exchange. We propose an IoT resource management framework incorporating blockchain and federated learning technologies; then, a specific FL-based resource management with a blockchain trust assurance algorithm is given. We use a Support Vector Machine (SVM) classifier to detect malicious nodes in order to avoid the impact on the performance of the FL-based algorithm. Finally, we perform simulation to verify the SVM classification effect and the proposed algorithm performance. The results show that the SVM-based malicious node identification accuracy can be acceptable. Moreover, the proposed algorithm obtains better performance when malicious nodes are excluded from the FL selected participant.
In this paper, we propose a practically efficient model for securely computing rank-based statistics, e.g., median, percentiles and quartiles, over distributed datasets in the malicious setting without leaking individual data privacy. Based on the binary search technique of Aggarwal et al. (EUROCRYPT \textquotesingle 04), we respectively present an interactive protocol and a non-interactive protocol, involving at most $\log ||R||$ rounds, where $||R||$ is the range size of the dataset elements. Besides, we introduce a series of optimisation techniques to reduce the round complexity. Our computing model is modular and can be instantiated with either homomorphic encryption or secret-sharing schemes. Compared to the state-of-the-art solutions, it provides stronger security and privacy while maintaining high efficiency and accuracy. Unlike differential-privacy-based solutions, it does not suffer a trade-off between accuracy and privacy. On the other hand, it only involves $O(N \log ||R||)$ time complexity, which is far more efficient than those bitwise-comparison-based solutions with $O(N^2\log ||R||)$ time complexity, where $N$ is the dataset size. Finally, we provide a UC-secure instantiation with the threshold Paillier cryptosystem and $Σ$-protocol zero-knowledge proofs of knowledge.
In order to preserve privacy in a blockchain ecosystem, the main objective is to keep a transaction's data private, such as the sender, the receiver, and the amount transferred. The current work studies the cryptographic tools commonly used to achieve this type of privacy, primarily focusing on the Ethereum blockchain. Such tools usually require many computational and storage resources, leading to additional fees. An anonymous auction protocol was developed as a case study to explore these costs, where hiding the identity and the amount of the bids utilizes a variety of cryptographic primitives. The proposed implementation was compared against three sealed-bid auction protocols, which utilize similar cryptographic tools for preserving privacy throughout the auction process. The results show that providing an additional level of anonymity, such as hiding someone's identity, can increase the gas cost significantly, up to 2.5 times, depending on the choice of the cryptographic tools, which determine the usage of the blockchain's storage and computational resources. By adjusting the level of decentralization on the application level by moving some operations off-chain and maintaining the role of the auctioneer, we show that we can maintain anonymity while reducing the gas cost by 40%.
In today's medical field, an ever-increasing number of different medical institutions begin to share patients' cases. Although this provides convenience for patients to seek medical advice, it will also lead to the problem of data abuse, and the patient's medical records are also at risk of being leaked or tampered with. The decentralization, non-tampering, openness, transparency, and traceability of blockchain technology can effectively solve these problems. This paper mainly studies a kind of medical records electronic contract which can guarantee the authenticity, security, and security of medical data. Firstly, patients own their medical records, and their medical data can be stored on the blockchain. The certificates of doctors and patients will also be stored on the blockchain. Secondly, the identities of doctors and patients need to be double verified in the storage process to ensure the authenticity and reliability of the data on the chain. Finally, the performance of a smart contract is evaluated by experiments. The smart contract studied in this paper can assure that large-scale medical data can be effectively stored and ensure the security of electronic medical records. And it can realize the sharing and reading of medical information between different hospitals.
In crowdsourcing systems, requesters publish tasks, and interested workers provide answers to get rewards. Worker anonymity motivates participation since it protects their privacy. Anonymity with unlinkability is an enhanced version of anonymity because it makes it impossible to ``link'' workers across the tasks they participate in. Another core feature of crowdsourcing systems is worker quality which expresses a worker's trustworthiness and quantifies their historical performance. Notably, worker quality depends on the participation history, revealing information about it, while unlinkability aims to disassociate the workers' identities from their past activity. In this work, we present AVeCQ, the first crowdsourcing system that reconciles these properties, achieving enhanced anonymity and verifiable worker quality updates. AVeCQ relies on a suite of cryptographic tools, such as zero-knowledge proofs, to (i) guarantee workers' privacy, (ii) prove the correctness of worker quality scores and task answers, and (iii) commensurate payments. AVeCQ is developed modularly, where the requesters and workers communicate over a platform that supports pseudonymity, information logging, and payments. In order to compare AVeCQ with the state-of-the-art, we prototype it over Ethereum. AVeCQ outperforms the state-of-the-art in three popular crowdsourcing tasks (image annotation, average review, and Gallup polls). For instance, for an Average Review task with $5$ choices and $128$ participating workers AVeCQ is 40\% faster (including overhead to compute and verify the necessary proofs and blockchain transaction processing time) with the task's requester consuming 87\% fewer gas units.
In order to catch the express train of the digital age and seize the opportunities brought by the development of blockchain technology, many government departments have begun to build blockchain-based data sharing protocols. Most existing data sharing protocols are built on different blockchains with different specific features. The interaction between them is not trivial, leading to the phenomenon of “data islands.” Therefore, we consider building a data sharing protocol compatible with various blockchains. In this work, we propose a generalized blockchain-based data sharing protocol, which takes fairness, privacy, auditability, and generality into account simultaneously. With adaptor signature and zero-knowledge techniques, the proposed protocol ensures a secure and fair data sharing process and is compatible with various blockchains since it only requires the underlying blockchain to perform signature verification. Finally, we implement our construction on an Ethereum test network and conduct a series of experiments. The results demonstrate the practicality of our construction while remaining good functionalities.
Xinyu Liu, Shan Ji, Xiaowan Wang, Liang Liu · 5 authors
Blockchain, with its characteristics of non-tamperability and decentralization, has had a profound impact on various fields of society and has set off a boom in the research and application of blockchain technology. However, blockchain technology faces the problem of data availability attacks during its application, which greatly limits the scope and domain of blockchain applications. One of the most advantageous researches to address this problem is the scalable data availability solution that integrates coding theory design into the Merkle tree promise. Based on this scheme, this paper combines a zero-knowledge accumulator with higher efficiency and security with local repair coding, and proposes a data availability scheme with strong dataset privacy protection. The scheme first encodes the data block information on the blockchain to ensure tamper-proof data, and then uses a zero-knowledge accumulator to store the encoded data block information. Its main purpose is to use zero-knowledge property to protect the accumulation set information stored in the accumulator from being leaked and to ensure that no other information about the accumulation set is revealed during the data transmission. It fundamentally reduces the possibility of attackers generating fraudulent information by imitating block data and further resists data availability attacks.
Mohamed Emish, Hari Kishore Chaparala, Zeyad Kelani, Sean D. Young
Machine learning advancements in healthcare have made data collected through smartphones and wearable devices a vital source of public health and medical insights. While wearable device data helps to monitor, detect, and predict diseases and health conditions, some data owners hesitate to share such sensitive data with companies or researchers due to privacy concerns. Moreover, wearable devices have been recently available as commercial products; thus large, diverse, and representative datasets are not available to most researchers. In this article, we propose an open marketplace where wearable device users securely monetize their wearable device records by sharing data with consumers (e.g., researchers) to make wearable device data more available to healthcare researchers. To secure the data transactions in a privacy-preserving manner, we use a decentralized approach using Blockchain and Non-Fungible Tokens (NFTs). To ensure data originality and integrity with secure validation, our marketplace uses Trusted Execution Environments (TEE) in wearable devices to verify the correctness of health data. The marketplace also allows researchers to train models using Federated Learning with a TEE-backed secure aggregation of data users may not be willing to share. To ensure user participation, we model incentive mechanisms for the Federated Learning-based and anonymized data-sharing approaches using NFTs. We also propose using payment channels and batching to reduce smart contact gas fees and optimize user profits. If widely adopted, we believe that TEE and Blockchain-based incentives will promote the ethical use of machine learning with validated wearable device data in healthcare and improve user participation due to incentives.
Gebrekiros Gebreyesus Gebremariam, Jeebananda Panda, S. Indu
Wireless sensor networks are the core of the Internet of Things and are used in healthcare, locations, the military, and security. Threats to the security of wireless sensor networks built on the Internet of Things (IoT-WSNs) can come from a variety of sources. This study proposes secure attack localization and detection in IoT-WSNs to improve security and service delivery. The technique used blockchain-based cascade encryption and trust evaluation in a hierarchical design to generate blockchain trust values before beacon nodes broadcast data to the base station. Simulation results reveal that cascading encryption and feature assessment measure the trust value of nodes by rewarding each other for service provisioning and trust by removing malicious nodes that reduce localization accuracy and quality of service in the network. Federated machine learning improves data security and transmission by merging raw device data and placing malicious threats in the blockchain. Malicious nodes are classified through federated learning. Federated learning combines hybrid random forest, gradient boost, ensemble learning, <a:math xmlns:a="http://www.w3.org/1998/Math/MathML" id="M1"> <a:mi>K</a:mi> </a:math> -means clustering, and support vector machine approaches to classify harmful nodes via a feature assessment process. Comparing the proposed system to current ones shows an average detection and classification accuracy of 100% for binary and 99.95% for multiclass. This demonstrates that the suggested approach works well for large-scale IoT-WSNs, both in terms of performance and security, when utilizing heterogeneous wireless senor networks for the providing of secure services.