Today, digital identity management for individuals is either inconvenient and error-prone or creates undesirable lock-in effects and violates privacy and security expectations. These shortcomings inhibit the digital transformation in general and seem particularly concerning in the context of novel applications such as access control for decentralized autonomous organizations and identification in the Metaverse. Decentralized or self-sovereign identity (SSI) aims to offer a solution to this dilemma by empowering individuals to manage their digital identity through machine-verifiable attestations stored in a "digital wallet" application on their edge devices. However, when presented to a relying party, these attestations typically reveal more attributes than required and allow tracking end users' activities. Several academic works and practical solutions exist to reduce or avoid such excessive information disclosure, from simple selective disclosure to data-minimizing anonymous credentials based on zero-knowledge proofs (ZKPs). We first demonstrate that the SSI solutions that are currently built with anonymous credentials still lack essential features such as scalable revocation, certificate chaining, and integration with secure elements. We then argue that general-purpose ZKPs in the form of zk-SNARKs can appropriately address these pressing challenges. We describe our implementation and conduct performance tests on different edge devices to illustrate that the performance of zk-SNARK-based anonymous credentials is already practical. We also discuss further advantages that general-purpose ZKPs can easily provide for digital wallets, for instance, to create "designated verifier presentations" that facilitate new design options for digital identity infrastructures that previously were not accessible because of the threat of man-in-the-middle attacks.
Cloud storage is widely used by large companies to store vast amounts of data and files, offering flexibility, financial savings, and security. However, information shoplifting poses significant threats, potentially leading to poor performance and privacy breaches. Blockchain-based cognitive computing can help protect and maintain information security and privacy in cloud platforms, ensuring businesses can focus on business development. To ensure data security in cloud platforms, this research proposed a blockchain-based Hybridized Data Driven Cognitive Computing (HD2C) model. However, the proposed HD2C framework addresses breaches of the privacy information of mixed participants of the Internet of Things (IoT) in the cloud. HD2C is developed by combining Federated Learning (FL) with a Blockchain consensus algorithm to connect smart contracts with Proof of Authority. The “Data Island” problem can be solved by FL’s emphasis on privacy and lightning-fast processing, while Blockchain provides a decentralized incentive structure that is impervious to poisoning. FL with Blockchain allows quick consensus through smart member selection and verification. The HD2C paradigm significantly improves the computational processing efficiency of intelligent manufacturing. Extensive analysis results derived from IIoT datasets confirm HD2C superiority. When compared to other consensus algorithms, the Blockchain PoA’s foundational cost is significant. The accuracy and memory utilization evaluation results predict the total benefits of the system. In comparison to the values 0.004 and 0.04, the value of 0.4 achieves good accuracy. According to the experiment results, the number of transactions per second has minimal impact on memory requirements. The findings of this study resulted in the development of a brand-new IIoT framework based on blockchain technology.
A. Ramachandran, Punyala Ramadevi, Ahmed Alkhayyat, Yousif Kerrar Yousif
Nowadays, numerous applications are associated with cloud and user data gets collected globally and stored in cloud units. In addition to shared data storage, cloud computing technique offers multiple advantages for the user through different distribution designs like hybrid cloud, public cloud, community cloud and private cloud. Though cloud-based computing solutions are highly convenient to the users, it also brings a challenge i.e., security of the data shared. Hence, in current research paper, blockchain with data integrity authentication technique is developed for an efficient and secure operation with user authentication process. Blockchain technology is utilized in this study to enable efficient and secure operation which not only empowers cloud security but also avoids threats and attacks. Additionally, the data integrity authentication technique is also utilized to limit the unwanted access of data in cloud storage unit. The major objective of the projected technique is to empower data security and user authentication in cloud computing environment. To improve the proposed authentication process, cuckoo filter and Merkle Hash Tree (MHT) are utilized. The proposed methodology was validated using few performance metrics such as processing time, uploading time, downloading time, authentication time, consensus time, waiting time, initialization time, in addition to storage overhead. The proposed method was compared with conventional cloud security techniques and the outcomes establish the supremacy of the proposed method.
Currently, smart homes rely heavily on wireless sensor networks (WSNs), which typically consist of wireless sensor nodes with limited resources and are scattered throughout the network. This topology makes them vulnerable to packet sniffing, spoofing, and other malicious attacks, which can result in the leakage of private data collected by devices. Additionally, managing the device key for the entire system becomes difficult as more devices are added. Moreover, the centralization of current cloud service management in smart home systems poses a serious single-point-of-failure problem, and the private data of cloud outsourcing cannot receive strict privacy supervision, ultimately relying entirely on the trust of enterprises. To address these issues, this paper proposes using a consortium blockchain and InterPlanetary File System (IPFS) instead of the existing centralized structure. An improved pairing-free certificateless aggregated signature(CLAS) scheme ensures the security of message authentication and solves the device key management problem. Our scheme reduces the computational and communication overheads at the device side by 50% and 25%, respectively, compared with existing schemes in WSNs. The overall computational overhead is also reduced by 28.6%, making it more suitable for smart home scenarios. Additionally, we use an auditing method based on Merkle root hash verification to ensure the reliability of data storage in IPFS.
Blockchain technology is taking centre stage in major industries, ushering in a new era of decentralisation and digitalisation. While blockchain has garnered widespread traction in various sectors, there remain many technological, operational, societal, and legal challenges in deploying blockchain, mainly attributable to its sheer novelty. With ensuing ruminations about data protection concerns and given the real threats posed by the increasing usage of blockchain, scholars have examined these underlying challenges faced by blockchain users and regulators globally. Trust-building issues, such as data protection breaches, warrant our attention due to the negative consequences that may manifest and concretise in any measurable manner, triggering fragmentation of blockchain-based applications and socio-technical assemblages. This paper proposes eight data protection indicators (DPIs) to assess the maturity levels of countries in addressing data protection challenges in the blockchain landscape. The DPIs can contribute to developing institutional and governance frameworks to spur the global diffusion of hard and soft law instruments and establish broader safeguards of blockchain users’ data.
The growth of information technology has resulted in a massive escalation of data and the demand for data exploration, particularly in the machine learning sector. However, machine learning raises concerns about data privacy because algorithms require large amounts of data to learn and make accurate predictions. Such data often contain personal information about individuals, and there is a risk that this information could be accessed or misused by unauthorized parties. It is crucial for organizations that use machine learning to prioritize personal data protection and ensure that appropriate safeguards are in place to prevent privacy breaches. Federated learning (FL) and blockchain technology are two increasingly popular approaches to distributed computing. Federated learning is a distributed machine-learning approach that trains machine-learning models on decentralized datasets without centralizing the data. Federated learning offers several benefits, including improved data privacy. Ensuring the benefit of clients in federated learning is vital for the success of this distributed machine learning approach, especially when combined with blockchain technology, as it offers a secure and transparent way to store and verify data. In this study, we propose a combination of federated learning and blockchain as a solution to some of the challenges faced by both approaches. By leveraging the decentralized nature of federated learning and the security and transparency of blockchain, our approach tends to overcome issues such as data privacy and trustworthiness of results. The evaluation results demonstrated that the proposed approach has many potential applications in various domains.
Aysha Alnuaimi, Diana Hawashin, Raja Jayaraman, Khaled Salah · 5 authors
Healthcare credentialing plays a vital role in ensuring the competence and integrity of healthcare professionals. However, the current credentials verification process suffers from time-consuming procedures due to the large number of intermediaries, limited information access, data fragmentation and the persistent risk of fraudulent credentials, leading to delayed hiring, increased administrative burden, and loss of trust and reputation in the healthcare system. In this paper, we utilize blockchain technology to enhance the credentialing process by streamlining the verification steps, improving data security, and providing stakeholders with confidence through secure storage of credentials. In addition, we utilize advanced security techniques, such as proxy re-encryption and cryptographic algorithms, to ensure the protection of sensitive data, facilitate secure communication, and prevent unauthorized access. We develop smart contracts which eliminate the need for intermediaries, automate the verification process, and enhance transparency and data integrity. We present system architecture, sequence diagrams, entity relationship diagrams, and the underlying algorithms of our blockchain-based solution. We discuss how our proposed solution attains the objectives outlined in the paper. We conduct cost evaluation and security analysis to validate the effectiveness of our solution. Additionally, we compare our proposed system with existing blockchain-based solutions, highlighting its novelty. The code of our smart contracts is made publicly available on GitHub.
Eric Appiah Mantey, Conghua Zhou, Joseph Henry Anajemba, Yasir Hamid · 5 authors
With the proliferation of privacy issues surrounding the Internet of Medical (IoMT) recommender system data, this study presents a Secure Recommendation and Training Technique (SERTT) which is contingent on a combination of both federated learning and blockchain approaches. Firstly, the study presents a new framework for recording, sorting, and transmission of IoMT data while incorporating blockchain to ensure that the IoMT data transmitted to cloud servers is not made vulnerable by the sharing of the original data. Secondly, by utilizing medical data, the study designs a Recommender Data Management Neural Architecture (REDMANA) which is based on federated learning and model searching training framework. The proposed technique guarantees that the model gradients which are trained by each node are not disclosed all through the universal training and modeling procedure. This makes the raw data inaccessible to either the IoMT data provider or the user. Considering that the model ensures that users can only obtain their necessary inquiries, neither medical data suppliers nor users can obtain access to raw data. Thus, it reduces the issues of safeguarding medical data sets to the issues of securing data processing. Using numerical analysis and experiments the proposed technique is compared with other existing techniques, the result shows that the proposed SERTT system is efficient and secures recommender data management training and modeling technique and that it performs previously designed techniques as compared.
Abhishek Bisht, Ashok Kumar Das, Dusit Niyato, Youngho Park
Secure storage and sharing of Personal Health Records (PHRs) in Internet of Medical Things (IoMT) is one of the significant challenges in the healthcare ecosystem. Due to the high value of personal health information, PHRs are one of the favourite targets of cyber attackers worldwide. Over the years, many solutions have been proposed; however, most solutions are inefficient for practical applications. For instance, several existing schemes rely on the bilinear pairings, which incur high computational costs. To mitigate these issues, we propose a novel PHR-sharing scheme that is dynamic, efficient, and practical. Specifically, we combine searchable symmetric encryption, blockchain technology and a decentralized storage system, known as Inter-Planetary File System (IPFS) to guarantee confidentiality of PHRs, verifiability of search results, and forward security. Moreover, we provide formal security proofs for the proposed scheme. Finally, we have conducted extensive test-bed experiments and the results demonstrate that the proposed scheme can be used in practical scenarios related to IoMT environment.
Gabriel Solomon, Peng Zhang, Rachael Brooks, Yuhong Liu
As resource-constrained Internet-of-Things (IoT) devices become popular targets of various malicious attacks, frequent updates to keep their software up to date are essential to their security. However, state-of-the-art software delivery and payment systems incorporate multiple services in a client-server structure requiring multiple transits of information between client and server, while also creating a wide attack surface. We propose a blockchain-based end-to-end secure software update delivery framework for Internet of Things (IoT) devices, which aims to ensure confidentiality, integrity, availability, efficiency, and audit-ability for verified software delivery, while offloading the cryptographic computation from resource-constrained IoT devices to a decentralized blockchain system. In particular, we leverage Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and design a customized authorization policy to not only ensure that software updates can only be decrypted and installed on authorized IoT devices but also significantly reduce the computational overhead for key generation and key delivery on the manufacturer side. Furthermore, secure and atomic software delivery and payments between IoT devices and the manufacturer are assured through smart contracts. The authenticity of the delivered software is guaranteed by offloading the computation-based signature validation to smart contracts. Compliance audits are satisfied through immutable records on the blockchain’s public ledger, and the smart contracts efficiently guarantee the delivery of software updates in exchange for payment. Security analysis and experiments are performed to compare the proposed framework with state-of-the-art studies and validate its effectiveness.
I. Román, Jorge Calvillo‐Arbizu, Vicente Mayor, German Madinabeitia-Luque · 6 authors
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual’s will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
Background: The rapid development of modern technologies renders a convenient and efficient solution to implement Electronic Health Records (EHRs) systems. The rapid growth of healthcare data has a distinctive attribute of digital transformations. The big datasets of healthcare, their complexity and their dynamic nature have posed severe challenges associated with the analysis, pre-processing, privacy, security, storage, usability and data exchange. Material and Methods: We have performed the Systematic Literature Review (SLR) and followed the Reporting Items for Systematic Reviews and Meta-Analysis (PRISMA) methodology. SLR refers to the methodology that discovers, analyses and accesses recent research literature related to the subject field. The research papers were searched from academic repositories like IEEE, WOS, Scopus and PubMed for the previous five years on March 2023. Results: The designed search string provides 199 research articles in total. We filter the research articles based on inclusion-exclusion strategies and quality assessment metrics. Six main criteria for research inclusion-exclusion for SLR are formulated. These works of literature insight into 1) the issues associated with interoperability and security of EHRs by using the Blockchain (BC) technology, 2) different frameworks and tools to improve privacy and security in the healthcare domain, 3) the open issues of using BC technology in the electronic healthcare domain, 4) the standardized ways to store EHRs, 5) various ways to handle the big data using the BC systems and 6) the usage of Federated Learning (FL) to preserve the privacy of EHRs in the healthcare domain. We acquired 46 research articles based on the criteria (inclusion-exclusion) that investigate the above-mentioned issues. Conclusion: The SLR will serve as the state-of-the-art (SOTA) for future researchers in the field of BC in healthcare. Additionally, the paper provides insights to the new researchers to revolutionize the healthcare domain by adopting the latest digitalized technologies. The proposed study identified various reflections. It analyzed the architectural mechanism that supports the security and interoperability of EHRs. Secondly, the study described different tools and frameworks to improve the privacy and security of EHRs using the BC. Thirdly, the open issues of storing and preserving the EHRs using BC in the healthcare system were determined. Fourth, it analyzed and provided a detailed view of using standardized ways for storing and handling big data by using the BC system. Lastly, the usage of FL to preserve the privacy of EHRs was analyzed.
The convergence of blockchain and Machine Learning (ML) promises to reshape technological innovation by enhancing security, efficiency, and transparency in ML systems. This survey explores the transformative potential of integrating these two technologies. We outline the foundational principles of blockchain and ML, clarifying their capabilities and synergies. We examine how blockchain strengthens ML as a secure, immutable platform for data sharing, model validation, and executing tasks. We emphasize the opportunities for heightened data security, improved model validation, and decentralized, privacy-preserving systems. However, challenges exist like scalability, energy-wise, and the need for new tailored consensus mechanisms. We provide insights based on recent research at this intersection. Additionally, we explore emerging trends and future directions, like blockchain’s application in federated learning for secure, transparent data sharing and model validation. We also investigate privacy-preserving systems such as Proof of Learning, where blockchain enables secure execution while maintaining data privacy. Moreover, we examine the potential for decentralized AI systems leveraging blockchain to deploy and execute models. This survey offers a comprehensive overview of the evolving landscape at the intersection of blockchain and ML, highlighting opportunities and challenges while suggesting future research directions.
Hussain Ahmad Madni, Rao Muhammad Umer, Gian Luca Foresti
Federated Learning (FL) is a machine learning technique, where collaborative and distributed learning is performed, while the private data reside locally on the client. Rather than the data, only gradients are shared among all collaborative nodes with the help of a central server. To ensure the data privacy, the gradients are prone to the deformation, or the representation is perturbed before sharing, ultimately reducing the performance of the model. Recent studies show that the original data can still be recovered using latent space (i.e., gradient leakage problem) by Generative Adversarial Network and different optimization algorithms such as Bayesian and Covariance Matrix Adaptation Evolution Strategy. To address the issues of data privacy and gradient leakage, in this paper, we train deep neural networks by exploiting the blockchain-based Swarm Learning (SL) framework. In the SL scheme, instead of sharing perturbed or noisy gradients to the central server, we share the gradients among authenticated (i.e., blockchain-based smart contract) training nodes. To demonstrate the effectiveness of the SL approach, we evaluate the proposed approach using the standard CIFAR10 and MNIST benchmark datasets and compare it with the other existing methods.
In this paper, we first trace the evolution of cryptography from symmetric- and public-key primitives to the emerging paradigm of privacy computing. We systematically examine three pillars, namely, zero-knowledge proofs, fully homomorphic encryption, and secure multi-party computation, by highlighting their models, algorithms, and performance frontiers. The second half narrows the lens to recent deployed systems. In particular, we introduce the Plonk zk-SNARK powering Ethereum layer-2 roll-ups, and present a state-of-the-art privacy-preserving Vickrey auction algorithm. These case studies illustrate how privacy-computing techniques are transitioning from theory to production-grade blockchain applications.
Most recent research on healthcare systems has focused on integrating the Internet of Things (IoT), Blockchain technology, and cloud computing to enhance the performance of IoT devices with limited resource availability, create smart healthcare platforms, and offer patients the best possible healthcare service. Modern healthcare systems use large-scale sensor devices to address many challenges brought on by the conventional delivery of healthcare services. Most studies have lately identified data collection, massive data processing, geolocating, access management, device prioritization, and storing as primary issues in most IoT healthcare systems. Decentralization, privacy, security, scalability, trust, anonymity, and building geospatial-based intelligent healthcare systems for patient care are significant difficulties that most healthcare systems today must overcome. Blockchain technology in healthcare platforms is noteworthy and innovative since it opens platforms for data privacy, anonymity, and validity through the consensus process. In this work, we proposed a novel decentralized Blockchain-enabled geospatial service architecture for smart healthcare systems calledBCGeo. The proposed framework offers an online geospatial healthcare service for residents of Bhubaneswar, a city in India, who are newcomers to the city and are less familiar with its local healthcare organizations. An analytical queueing method prioritizes serving Critical patients more than other patients. In contrast to previously proposed frameworks, the proposed framework includes immutability, scalability, geospatial mapping, patient prioritizing, and decentralized privacy protection policies for addressing the technical challenges in most of the current healthcare systems. Additionally, it explains the performance analysis ofBCGeo. It includes graphs showing the various possible outcomes of arithmetic operations, performance measurement, and experimental results on the proposed architecture.
A secured platform is a critical component of digital governance, as it helps to ensure the privacy, security, and reliability of the electronic platforms and systems used to manage and deliver public services. Interoperability and data exchange are essential for digital governance, as they enable different government agencies and departments to share data, information, and resources seamlessly, regardless of the platforms and technologies they use. In this paper, we build a secure platform to enhance the trustworthiness of digital governance interoperability and data exchange using blockchain and deep learning-based frameworks. Initially, an optimal blockchain leveraging approach is designed using the bonobo optimization algorithm to authenticate data generated from smart city environments. Furthermore, we introduce the integration of a lightweight Feistel structure with optimal operations to enhance privacy preservation. This integration provides two levels of security and ensures interoperability and double-secured data exchange in digital governance systems. In addition, we utilize a deep reinforcement learning (DRL) model to detect and prevent intrusions such as fraud/corruption in the smart city data. This approach enhances transparency and accountability in accessing the data and shows its predominance over other cutting-edge techniques on two benchmark datasets, BoT-IoT and ToN-IoT. Furthermore, the effectiveness of the framework in real-time scenarios has been demonstrated through two case studies. Overall, our proposed framework provides a trustworthy platform for digital governance, interoperability, and data exchange, addressing the challenges of privacy, security, and reliability in managing and delivering public services.
As for the advancement of IoT and cloud computing in healthcare, outsourcing encrypted Electronic medical records (EMRs) created by the aggregation of medical treatment applications and health data collected from IoT devices enables high accessibility, effective collaboration, and zero computational operation cost. Current applications and research works generally concern the privacy of the finest EMRs that are encrypted with secure and lightweight cryptographic protocols before they are outsourced to the cloud. However, this process does not consider the security and privacy of the data collected by IoT devices, where the data being transferred can be leaked before they are aggregated. Furthermore, existing IoT-cloud based access control solutions have not addressed the outsourced encryption, privacy of IoT data transmission and aggregation, and the policy update of the EMRs in an integrated manner. In this paper, we propose an access control scheme called LightMED which provides secure, fine-grained, and scalable EMR sharing in a cloud-based environment integrated with fog computing, CP-ABE, and blockchain technology. We propose a secure IoT data transmission and aggregation method based on lightweight encryption and digital signing. At the core, we introduce outsourced encryption with a privacy-preserving access policy scheme and an outsourced encryption and decryption algorithm leveraged by the collaboration between fog nodes and blockchain. In addition, we introduce a novel lightweight policy update algorithm to enable the data owners of EMRs to effectively manage their policies in a secure and effective manner. Finally, we performed the comparative analysis to illustrate the computation cost and conducted experiments to evaluate the performance of our scheme and related works. The experimental results showed that our scheme outperformed existing works since it yielded least processing cost of both encryption and decryption at end-users’ devices, which demonstrates the higher efficiency and practicality of our scheme.
The emerging combination of Internet of Things (IoT) and aerospace integration aided by satellite and 6G communication techniques has stimulated the Internet of Unmanned Aerial Vehicles (UAVs), i.e., Internet of Drones (IoD). To accommodate and share the enormous real-time UAV data, cloud-based IoD is an inevitable choice to lower the heavy burden of mobile UAVs. Nevertheless, how to protect highly sensitive UAV data in such a honest-but-curious, open and distributed environment with resource-limited UAVs is a significant challenge. Although our previous work (PATLDAC) in SPNCE’21 devises a cloud-based UAV data access control scheme with policy privacy protection, limited access time and user traceability, it incurs inflexible and centralized cloud data storage and access as well as untrustworthy metadata in untrusted cloud environment for data access and user tracing. To this end, we further propose a blockchain-based privacy-aware data access control (BPADAC) scheme for distributed and secure UAV data sharing in cloud-based IoD. Based on fine-grained, traceable and privacy-preserving UAV data access characteristic of our previous work, we extend it by leveraging blockchain and Distributed Hash Table (DHT) for distributed and trustful UAV data access and storage, together with reliable and limited access mechanism to guarantee cloud UAV data sharing service provision. We also design public and undeniable user tracing mechanism to prevent user key abuse with traitor denial. Finally, we present formal security analysis and prototype the system leveraging the smart contracts of Ethereum blockchain for performance evaluation to show the feasibility of BPADAC.
Normaizeerah Mohd Noor, Noor Afiza Mat Razali, Sharifah Nabila S Azli Sham, Khairul Khalil Ishak · 6 authors
The convergence of farming with cutting-edge technologies, like the Internet of Things (IoT), has led to the emergence of a smart farming revolution. IoT facilitates the interconnection of numerous devices across different agricultural ecosystems, enabling automation and ultimately enhancing the efficiency and quality of production. However, the implementation of IoT entails an array of potential risks. The accelerated adoption of IoT in the domain of smart farming has amplified the existing cybersecurity concerns, specifically those pertaining to access control. In extensive IoT environments that require scalability, the conventional centralized access control system is insufficient. Therefore, to address these gaps, we propose a novel decentralized access control framework. The framework applies blockchain technology as the decentralization approach with smart contract application focuses on the application scenario in smart farming to protect and secure IoT devices from unauthorised access by anomalous entities. The proposed framework adopted attribute-based access control (ABAC) and role-based access control (RBAC) to establish access rules and access permissions for IoT. The framework is validated via simulation to determine the price of gas consumption when executing smart contracts to retrieve attributes, roles and access rules between three smart contracts and provide the baseline value for future research references. Thus, this paper offers valuable insight into ongoing research on decentralized access control for IoT security to protect and secure IoT resources in the smart farming environment.
Khalid Mrabet, Faissal El Bouanani, Hussain Ben-Azza
Reputation management systems are essential for establishing trust among network users. They are tools for reinforcing cooperation and sanctioning malicious behavior. This importance becomes a requirement in decentralized environments such as mobile ad-hoc networks (MANETs), peer-to-peer systems (P2P), wireless sensor networks (WSNs), or decentralized social networks (DSNs) where there is no trusted third party to monitor and enforce good behavior among users. In this paper, we propose a dynamic decentralized reputation system that fits such network characteristics, namely decentralization, dynamism, and openness, without conceding on security. The novel system is a general-purpose system that uses blockchain to gather and supply global reputation information while remaining fully decentralized. Unlike previous works on decentralized reputation systems where reputation information is inconsistent and limited to users’ direct experience and recommendations from peers (neighbors), our system gathers feedback from all over the network and stores reputation information on a distributed ledger fully accessible to all users. In terms of security, the proposed method achieves privacy utilizing secure multiparty computation, a cryptographic primitive that preserves feedback privacy even with a dishonest majority reaching$n-2$malicious parties while requiring only$O(n)$messages. The employed techniques enable the system to achieve unique characteristics like consistency, conservation, and verifiability in addition to privacy. The security analysis we provide confirms these properties, and the performed simulation shows the protocol’s effectiveness.
Tariq Alsboui, Muhammad Hussain, Hussain Al-Aqrabi, Richard Hill · 5 authors
With the vast development of Internet-of-Things (IoT) ecosystem, various types of information, such as healthcare records and physical resources, are integrated for different types of applications. Due to the sheer number of connected IoT devices, which generate a large amount of data, Distributed Ledger Technology, such as Blockchain and IOTA have been recently applied in developing access control models, yet they involve significant energy due to mining, low throughput, non-scalable, and computational overhead that is not acceptable for IoT resource-constrained devices. In this paper, we propose a Scalable Decentralized and Lightweight Access Control framework (SDAC) by using the IOTA platform. IOTA is an emerging distributed ledger technology that has significant features for IoT, such as zero fees transactions, scalability, security and energy efficiency. The proposed SDAC aims to improve security, authorize, and authenticate users when accessing data by using the IOTA Masked Authenticated Messaging (MAM) protocol. MAM ensures access control by encrypting and granting permission to only authorized users. The experimental results indicate that IOTA MAM is a feasible solution that can be used for managing authorization in the IoT domain.
Distributed deep learning (DDL) within vehicular ad hoc networks (VANETs) holds profound significance in developing smart applications, such as intelligent transport systems and autonomous driving, where multiple parties are coordinated to leverage the training capability and acquisitive intelligence. Blockchain (BC) is a distribution technology promising for trustworthy DDL, holding the divide-and-conquer concept with decentralized management and consensus algorithms to reduce the exposure of sensitive controllers and thus the risks of malicious system-wide attacks. Moreover, zero trust architecture (ZTA) concepts are promoted as innovative cybersecurity solution which can be integrated with BC to address the resource-limited and infrastructure-less issues to augment the strength of DDL in VANETs. In this dissertation, the BC and ZTA potential is explored to construct reliable VANETs for trustworthy data sharing and thus to support significant within-VANET DDL and relevant applications. Firstly, virtualized distributed ledger technology (vDLT) is developed as the multimedia BC platform, followed by vDLT-based VANETs built to solve the unsteady communication; secondly, vDLT is improved to transmit and secure traffic events in VANETs; subsequently, a vDLT-based DDL system is proposed to enhance object detection (OD) inside VANETs; finally, ZTA and sharding scheme are enabled in vDLT-based VANETs for improved protection. Generally, vDLT runs with virtualized resource and sharding supports for scalability improvement, along with multi-layered consensus algorithm and an adaptable hierarchical and decentralized PBAC (hdPBAC) access control model to agilely protect the DDL procedures and relevant DDL-related applications. The proposed system has been developed, including the vDLT system, the multimedia streaming over vDLT in fixed networks and VANETs, a precursory vDLT-based DDL system for OD purpose, and the integration of ZTA into scalable-BC-based VANETs. The evaluation results show the feasibility of proposed design and demonstrate the significance of performance improvements.