Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

4,146 papersLast indexed Aug 31, 2026
Search papers

Paper index

4,146 results · page 50 of 173

Clear filters
Jun 3, 2024·Proceedings of the 22nd Annual International Conference on Mobile Systems, Applications and Services
0 cites
Poster: Privacy in Distributed Mobile Networks

信一 馬場, Xingjun Wang

In order to achieve zero-knowledge proof (ZKP) in distributed mobile scenarios, we propose a two-stage multi-prover ZKP framework. Our method utilizes secure multi-party computation (MPC), which has advantages such as flexible adaptation, stable performance, and fewer restrictions compared to existing solutions. In addition, based on the properties of cyclic groups, we optimize secure multi-party summation, improving the balance between security and efficiency, as well as transferability of the algorithm.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Jun 2, 2024·Cybersecurity
7 cites
Atomic cross-chain swap based on private key exchange

Zeshuo Zhu, Rui Zhang, Yang Tao

Abstract Atomic Cross-Chain Swap (ACCS) is one important topic in cryptocurrency, where users can securely and trustlessly exchange assets between two different blockchains. However, most known ACCS schemes assume specific scripting functionalities of the underlying blockchains, such as Hash Time Locked Contracts (HTLC). In addition, these schemes are typically only applicable to certain digital signature schemes, like Schnorr or Elliptic Curve Digital Signature Algorithm (ECDSA) signatures. In this paper, we propose a generic ACCS scheme, independent from the underlying blockchains. To the best of our knowledge, this is the first solution of this kind. Our results are as follows. First, we define a formal system model of ACCS. Next, we present a generic ACCS scheme meets our model. This scheme admits atomicity in cross-chain swaps without the need for a Trusted Third Party (TTP) and protects users’ privacy. Finally, by using the Non-Interactive Zero-Knowledge (NIZK) proof protocol as a tool, we instantiate our generic scheme for Elliptic Curve Discrete Logarithm Problem-based (ECDLP-based) signatures. In addition, we implement our scheme, and the experimental results show that our protocol outperforms the existing ACCS schemes, such as the HTLC-based schemes.

Open access
Security in Wireless Sensor Networks
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jun 1, 2024·Cybernetics and Information Technologies
10 cites
Securing Decentralized Storage in Blockchain: A Hybrid Cryptographic Framework

Jadhav Swati, Pise Nitin

Abstract The evolution of decentralized storage, propelled by blockchain advancements, has revolutionized data management. This paper focuses on content security in the InterPlanetary File System (IPFS), a leading decentralized storage network lacking inherent content encryption. To address this vulnerability, we propose a novel hybrid cryptographic algorithm, merging AES 128-bit encryption with Elliptic Curve Cryptography (ECC) key generation. The algorithm includes ECC key pairs, random IV generation, and content/AES key encryption using ECC public keys. Benchmarking against standard AES 256-bit methods shows a significant 20% acceleration in encryption speed and a 16% increase in decryption efficiency, affirming practicality for enhancing IPFS content security. This research contributes to securing decentralized storage and provides a performance-driven solution. The promising results highlight the viability of the proposed approach, advancing understanding and mitigating security concerns in IPFS and similar systems.

Open access
Cryptography and Data Security
Advanced Data Storage Technologies
Chaos-based Image/Signal Encryption
Original source
May 31, 2024·Complex & Intelligent Systems
24 cites
A blockchain-based hybrid encryption technique with anti-quantum signature for securing electronic health records

Shtwai Alsubai, Abdullah Alqahtani, Harish Garg, Mohemmed Sha · 5 authors

Abstract Electronic health records (EHRs) are important for the efficient management of healthcare data. However, Healthcare data travels across an open route, i.e., the Internet, making EHR security a difficult process to do. This puts healthcare data vulnerable to cyber assaults. A possible method for protecting EHRs is blockchain technology. In this work, we develop an EHR architecture based on blockchain, which ensures all stakeholder's safety and privacy. We analyze various security architectures used for EHRs and the standard encryption system is integrated with quantum computing (QC). To safeguard the conventional traditional encrypting system against quantum assaults, we provide a hybrid signature technique that combines the Elliptic Curve Digital Signature Algorithm (ECDSA) and Dilithium within the anti-quantum lattice-based blind signature. Based on the difficulty of lattice problems over finite fields, Dilithium is a lattice-based signature method that is substantially safe against selected message assaults. The developed technique creates high entropy secret keys using the lattice basis delegation mechanism. The combination of ECDSA and Dilithium provides an efficient and secure signature system that is resilient to quantum attacks. The proposed scheme ensures that only authorized users with a defined role can use the database to access the data. We evaluate the efficiency of our scheme by comparing its performance to other state-of-the-art solutions in terms of transaction throughput, resource utilization, and communication cost. Results demonstrate that the developed technique outperforms the existing techniques in terms of efficiency and security.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
May 23, 2024·Center for Open Science
2 cites
WITHDRAWN

Kelly Kelvin, Terry Tera, Bamigboye Tobiloba

In today's data-driven world, the convergence of advanced machine learning techniques with privacy concerns has prompted the development of innovative approaches to safeguard sensitive information while harnessing the power of data analytics.This research article delves into the realm of privacy-preserving machine learning algorithms, specifically focusing on methodologies that embrace the concept of local information privacy.The abstract provides a succinct overview of the key themes, methodologies, and implications elucidated within the paper.The abstract begins by contextualizing the contemporary landscape, emphasizing the proliferation of big data and the attendant privacy challenges it poses.It highlights the dichotomy between the utility of machine learning algorithms and the imperative of preserving individuals' privacy, setting the stage for exploring novel solutions.Central to the abstract is the conceptual framework of local information privacy, which forms the cornerstone of privacy-preserving machine learning algorithms discussed in the paper.The abstract delineates the theoretical foundations of this framework, elucidating how decentralized computation and differential privacy principles contribute to safeguarding sensitive data.Moving beyond theoretical underpinnings, the abstract provides insights into the methodologies employed in privacy-preserving machine learning.It outlines diverse approaches such as federated learning, secure multi-party computation, and homomorphic encryption, showcasing their utility in mitigating privacy risks while enabling collaborative model training and inference.Furthermore, the abstract underscores the practical implications of adopting privacy-preserving machine learning algorithms leveraging local information privacy.It cites examples across various sectors, including healthcare, finance, and IoT, where decentralized learning frameworks empower organizations to derive actionable insights from data while upholding privacy regulations and ethical standards.The abstract concludes by delineating potential avenues for future research and development in the field.It emphasizes the importance of scalability, efficiency, and robustness in privacy-preserving techniques, calling for interdisciplinary collaborations to address emerging challenges and navigate regulatory landscapes effectively.The abstract encapsulates the essence of the research article, providing a concise yet comprehensive overview of privacy-preserving machine learning algorithms using local information privacy.It serves as a gateway for readers to delve deeper into the nuances of the topic while highlighting its significance in addressing contemporary privacy challenges in the era of big data and advanced analytics.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Privacy, Security, and Data Protection
Original source
May 23, 2024·PLoS ONE
19 cites
Research on blockchain smart contract technology based on resistance to quantum computing attacks

Xinhao Zheng

In recent years, blockchain technology has developed rapidly and has been widely used in medical, financial, energy and other fields. However, in the process of practical application, each blockchain is a small independent ecosystem, with all transactions and operations limited to the chain, resulting in a large number of mutually heterogeneous to independent blockchains. It presents challenges for cross-chain interactions, cross-organization data sharing, and cross-blockchain expansion, and hinders the wider application of blockchain technology. In addition, the traditional digital signature method based on elliptic curve cipher faces the threat of being cracked by quantum computing attacks. To solve the aforementioned problems, this paper proposed a blockchain smart contract technique based on quantum computing attack resistance(BSCTQCAT). The technique first introduces the digital signature of the lattice cipher into the blockchain to resist the quantum search algorithm attack. Then, based on the smart contract authentication scheme, the nodes on multiple heterogeneous chains are organized into an identity agent layer P2P network, through which transactions on the chain will establish a credible identity management and message authentication mechanism between different chains, solving the current problem that each chain is difficult to communicate with each other. In this paper, the performance of the algorithm is evaluated by simulating the Bitcoin transaction scenario and analyzing the experimental data.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Quantum Computing Algorithms and Architecture
Original source
May 15, 2024·arXiv (Cornell University)
0 cites
Asynchronous BFT Asset Transfer: Quasi-Anonymous, Light, and Consensus-Free

Timothé Albouy, Emmanuelle Anceaume, Davide Frey, Mathieu Gestin · 7 authors

This article introduces a new asynchronous Byzantine-tolerant asset transfer system (cryptocurrency) with three noteworthy properties: quasi-anonymity, lightness, and consensus-freedom. Quasi-anonymity means no information is leaked regarding the receivers and amounts of the asset transfers. Lightness means that the underlying cryptographic schemes are \textit{succinct}, and each process only stores data polylogarithmic in the number of its own transfers.Consensus-freedom means the system does not rely on a total order of asset transfers. The proposed algorithm is the first asset transfer system that simultaneously fulfills all these properties in the presence of asynchrony and Byzantine processes. To obtain them, the paper adopts a modular approach combining a new distributed object called agreement proofs and well-known techniques such as vector commitments, universal accumulators, and zero-knowledge proofs. The paper also presents a new non-trivial universal accumulator implementation that does not need knowledge of the underlying accumulated set to generate (non-)membership proofs, which could benefit other crypto-based applications.

Open access
2 source records
cs.DC
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
May 14, 2024·Distributed Ledger Technologies Research and Practice
13 cites
Cross-Blockchain Communication Using Oracles With an Off-Chain Aggregation Mechanism Based on zk-SNARKs

Michael Sober, Giulia Scaffino, Stefan Schulte

The closed architecture of prevailing blockchain systems renders the usage of this technology mostly infeasible for a wide range of real-world problems. Most blockchains trap users and applications in their isolated space without the possibility of cooperating or switching to other blockchains. Therefore, blockchains need additional mechanisms for seamless communication and arbitrary data exchange between each other and external systems. Unfortunately, current approaches for cross-blockchain communication are resource-intensive or require additional blockchains or tailored solutions depending on the applied consensus mechanisms of the connected blockchains. Therefore, we propose an oracle with an off-chain aggregation mechanism based on Zero-Knowledge Succinct Non-interactive Arguments of Knowledge (zk-SNARKs) to facilitate cross-blockchain communication. The oracle queries data from another blockchain and applies a rollup-like mechanism to move state and computation off-chain. The zkOracle contract only expects the transferred data, an updated state root, and proof of the correct execution of the aggregation mechanism. The proposed solution only requires constant 378 kgas to submit data on the Ethereum blockchain and is primarily independent of the underlying technology of the queried blockchains.

Open access
4 source records
cs.CR
cs.DC
Blockchain Technology Applications and Security
Original source
May 13, 2024·2024 21st Annual International Conference on Privacy, Security and Trust (PST), 2024, pp. 1-11
5 cites
DID Link: Authentication in TLS with Decentralized Identifiers and Verifiable Credentials

Sandro Rodriguez Garzon, Dennis Natusch, Artur Philipp, Axel Küpper · 6 authors

Authentication in TLS is predominately carried out with X.509 digital certificates issued by certificate au-thorities (CA). The centralized nature of current public key infrastructures, however, comes along with severe risks, such as single points of failure and susceptibility to cyber-attacks, potentially undermining the security and trustworthiness of the entire system. With Decentralized Identifiers (DID) alongside distributed ledger technology, it becomes technically feasible to prove ownership of a unique identifier without requiring an attestation of the proof's public key by a centralized and therefore vulnerable CA. This article presents DID Link, a novel authentication scheme for TLS 1.3 that empowers entities to authenticate in a TLS-compliant way with self-issued X.509 certificates that are equipped with ledger-anchored DIDs instead of CA-issued identifiers. It facilitates the exchange of tamper-proof and 3rd-party attested claims in the form of DID-bound Verifiable Credentials after the TLS handshake to complete the authentication with a full identification of the communication partner. A prototypical implementation shows comparable TLS handshake durations of DID Link if verification material is cached and reasonable prolongations if it is obtained from a ledger. The significant speed improvement of the resulting TLS channel over a widely used, DID-based alternative transport protocol on the application layer demonstrates the potential of DID Link to become a viable solution for the establishment of secure and trustful end-to-end communication links with decentrally managed digital identities.

Open access
3 source records
cs.CR
cs.NI
DNA and Biological Computing
Original source
May 11, 2024·Computer Networks
5 cites
Beyond selective disclosure: Extending distributed p-ABC implementations by commit-and-prove techniques

Jesús García-Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio Skármeta

The increasing user awareness and regulatory framework (e.g., GDPR, eIDAS2) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems. Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data. Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by developing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
May 8, 2024·Sensors
0 cites
Metadata-Private Resource Allocation in Edge Computing Withstands Semi-Malicious Edge Nodes

Zihou Zhang, Jiangtao Li, Yufeng Li, Yuanhang He

Edge computing provides higher computational power and lower transmission latency by offloading tasks to nearby edge nodes with available computational resources to meet the requirements of time-sensitive tasks and computationally complex tasks. Resource allocation schemes are essential to this process. To allocate resources effectively, it is necessary to attach metadata to a task to indicate what kind of resources are needed and how many computation resources are required. However, these metadata are sensitive and can be exposed to eavesdroppers, which can lead to privacy breaches. In addition, edge nodes are vulnerable to corruption because of their limited cybersecurity defenses. Attackers can easily obtain end-device privacy through unprotected metadata or corrupted edge nodes. To address this problem, we propose a metadata privacy resource allocation scheme that uses searchable encryption to protect metadata privacy and zero-knowledge proofs to resist semi-malicious edge nodes. We have formally proven that our proposed scheme satisfies the required security concepts and experimentally demonstrated the effectiveness of the scheme.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
May 7, 2024·Proceedings of the 21st ACM International Conference on Computing Frontiers: Workshops and Special Sessions
2 cites
HAGAR: Hashgraph-based Aggregated Communication and Remote Attestation

Jo Vliegen, Md Masoom Rabbani, Wouter Hellemans, Nele Mentens

Over the past decade, an exponential rise in the deployment of Internet-of-Things (IoT) devices engulfed our surroundings. IoT devices have spread into domains like personal smart devices, industrial applications, military applications, and medical applications, to name a few. Brittle security features and large deployment in safety-critical systems make IoT devices an attractive target for cyberattacks. Large collections of data, ranging from personal, and oversensitive to financial data, make it crucial to safeguard IoT applications and data communication from cybercriminals. One key technique to deal with these cyberattacks is Remote Attestation (RA), in which a verifier remotely checks the sanity of an IoT device's firmware. However, implementing RA over large IoT networks can be challenging due to the dynamic nature of the network and the real-time aggregation of attestation results. We propose 'HAGAR: Hashgraph-based Aggregated Communication and Remote Attestation' to address the aforesaid challenges. HAGAR is a distributed ledger based on a hashgraph architecture that not only provides decentralized security guarantees like traditional blockchain technology, but also makes communication fast and thus offers continuous attestation aggregation in large IoT networks. We use the features of Hashgraphs for data aggregation in remote attestation mechanisms for large dynamic IoT networks.

Open access
User Authentication and Security Systems
Cryptography and Data Security
Advanced Authentication Protocols Security
Original source
May 1, 2024·IEEE Transactions on Services Computing
1 cites
T-Watch: Towards Timed Execution of Private Transaction in Blockchains

Chao Li, Balaji Palanisamy

In blockchains such as Bitcoin and Ethereum, transactions represent the primary mechanism that the external world can use to trigger a change of blockchain state. Transactions serve as key sources of evidence and play a vital role in forensic analysis. Timed transaction refers to a specific class of service that enables a user to schedule a transaction to change the blockchain state during a chosen future time-frame. This paper proposes T-Watch, a decentralized and cost-efficient approach for users to schedule timed execution of any type of transaction in Ethereum with privacy guarantees. T-Watch employs a novel combination of threshold secret sharing and decentralized smart contracts. To protect the private elements of a scheduled transaction from getting disclosed before the future time-frame, T-Watch maintains shares of the decryption key of the scheduled transaction using a group of executors recruited in a blockchain network before the specified future time-frame and restores the scheduled transaction at a proxy smart contract to trigger the change of blockchain state at the required time-frame. To reduce the cost of smart contract execution in T-Watch, we carefully design the proposed protocol to run in an optimistic mode by default and then switch to a pessimistic mode once misbehaviors occur. Furthermore, the protocol supports users to form service request pooling to further reduce the gas cost. We rigorously analyze the security of T-Watch and implement the protocol over the Ethereum official test network. The results demonstrate that T-Watch is more scalable compared to the state of the art and could reduce the cost by over 90% through pooling.

Open access
2 source records
cs.CR
cs.DC
Blockchain Technology Applications and Security
Original source
Apr 30, 2024·American Journal Of Cryptography And Network Security
0 cites
Data Integrity and Cryptography in Blockchain Networks

Ayesha Khan

Blockchain technology has emerged as a transformative approach for decentralized data management, ensuring transparency, security, and trustworthiness in digital transactions. Central to blockchain’s robustness are data integrity and cryptographic mechanisms, which collectively maintain the immutability and confidentiality of data. This article examines the critical role of cryptography in safeguarding blockchain networks, highlighting techniques such as hash functions, digital signatures, and public-key cryptography. Further, it discusses how these cryptographic tools enable data integrity, prevent tampering, and secure distributed ledger systems. Challenges and future prospects of cryptographic methods in evolving blockchain applications are also explored.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Apr 29, 2024·Mathematics
2 cites
Adaptive Parallel Scheduling Scheme for Smart Contract

Wenjin Yang, Meng Ao, Jing Sun, Guoan Wang · 7 authors

With the increasing demand for decentralized systems and the widespread usage of blockchain, low throughput and high latency have become the biggest stumbling blocks in the development of blockchain systems. This problem seriously hinders the expansion of blockchain and its application in production. Most existing smart contract scheduling solutions use static feature analysis to prevent contract conflicts during parallel execution. However, the conflicts between transactions are complex; static feature analysis is not accurate enough. In this paper, we first build the dependency between smart contracts by analyzing the features. After numerous experiments, we propose a conflict model to adjust the relationship between threads and conflict to achieve high throughput and low latency. Based on these works, we propose adaptive parallel scheduling for smart contracts on the blockchain. Our adaptive parallel scheduling can distinguish conflicts between smart contracts and dynamically adjust the execution strategy of smart contracts based on the conflict factors we define. We implement our scheme on ChainMaker, one of the most popular open-source permissioned blockchains, and build experiments to verify our solution. Regarding latency, our solution demonstrates remarkable efficiency compared with the fully parallel scheme, particularly in high-conflict transaction scenarios, where our solution achieves latency levels just one-twentieth of the fully parallel scheme. Regarding throughput, our solution significantly outperforms the fully parallel scheme, achieving 30 times higher throughput in high-conflict transaction scenarios. These results highlight the superior performance and effectiveness of our solution in addressing latency and throughput challenges, particularly in environments with high transaction conflicts.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Auction Theory and Applications
Original source
Apr 28, 2024·INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
2 cites
Immutable Identity Validation Using Soul bound Token Abhishek Sharma,

Aditi Singh

The "Immutable Identity Validation System: A Blockchain and Soulbound Token Approach" paper introduces an innovative method for verifying digital identities. By combining blockchain technology and Soulbound Tokens (SBTs), it enhances security and privacy in identity verification processes. SBTs, designed as non-transferable and tamper-proof digital assets, play a crucial role in bolstering the security and reliability of the system. Their unique properties ensure that user privacy is prioritized while also facilitating swift verification through blockchain transparency. This approach addresses the growing demand for robust identity verification solutions, particularly in sectors like education and corporations, where fraud prevention and streamlined processes are critical. The methodology involves various steps, including SBT generation, blockchain integration, user control mechanisms, and stringent security measures. Both frontend and backend development, along with the integration of blockchain using tools like Ganache and decentralized data storage through IPFS, contribute to building a secure and user-friendly system. Thorough testing, documentation, and knowledge transfer are essential to ensuring the system's reliability, security, and compliance with legal standards. Ultimately, the goal is to establish a globally accepted framework for identity verification in today's interconnected digital landscape. Keywords:; privacy; security; Blockchain; Cryptography; Decentralization; Soul Bound Token (SBT), distributed ledger.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Original source
Apr 26, 2024·INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
0 cites
The Paradox of Power: Securing User Data in the Cloud's Shadow

Ajay Ahuja

Whilst the blessing of the cloud, which provides for adaptability and easy data sharing as well as storage, comes with some security doubts. We place a major responsibility on our backs of protecting the data provided by our users from any evil attempts to sneak in and also risks of being accidentally exposed and the ones that exist through shared infrastructure. This paper traverses this complex terrain by noting the need for targeted security solutions which are aimed towards dealing with the compounded nature of the fast-growing problem. By exploring such threats as data breaches, the possible encryption breaks and the nature of server sharing we will analyze the safety of cloud-based services. We position that the existing security methods, though very necessary, are not exclusive in responding to the ones posed by the new threats. This means we will therefore be rather flexible in our design of the data security in the cloud. By the way, we will employ innovative strategies, maybe, by replacing a word for words such as homomorphic encryption, zero-knowledge proofs, and federated learning, presenting how it holds promise for private and confidential assets. Furthermore, we investigate the exploding influence of blockchain technology, regarding the wages it might deserve in providing manipulated data authentication and creating trust. The work in this paper creates a path towards a future when database users' virtual information in the cloud is safe and certified. Through proposing a wide-ranged approach, which equates realized ideas with well-established security frameworks, we shall lead a cloud infrastructure where stability and power would prevail. Keywords – Cloud Computing, Security Issues, Security Challenges

Open access
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Apr 25, 2024·BMC Medical Informatics and Decision Making
2 cites
INNBC DApp, a decentralized application to permanently store biomedical data on a modern, proof-of-stake (POS), blockchain such as BNB Smart Chain

Jonathan Fior

BACKGROUND: A blockchain can be described as a distributed ledger database where, under a consensus mechanism, data are permanently stored in records, called blocks, linked together with cryptography. Each block contains a cryptographic hash function of the previous block, a timestamp, and transaction data, which are permanently stored in thousands of nodes and never altered. This provides a potential real-world application for generating a permanent, decentralized record of scientific data, taking advantage of blockchain features such as timestamping and immutability. IMPLEMENTATION: Here, we propose INNBC DApp, a Web3 decentralized application providing a simple front-end user interface connected with a smart contract for recording scientific data on a modern, proof-of-stake (POS) blockchain such as BNB Smart Chain. Unlike previously proposed blockchain tools that only store a hash of the data on-chain, here the data are stored fully on-chain within the transaction itself as "transaction input data", with a true decentralized storage solution. In addition to plain text, the DApp can record various types of files, such as documents, images, audio, and video, by using Base64 encoding. In this study, we describe how to use the DApp and perform real-world transactions storing different kinds of data from previously published research articles, describing the advantages and limitations of using such a technology, analyzing the cost in terms of transaction fees, and discussing possible use cases. RESULTS: We have been able to store several different types of data on the BNB Smart Chain: raw text, documents, images, audio, and video. Notably, we stored several complete research articles at a reasonable cost. We found a limit of 95KB for each single file upload. Considering that Base64 encoding increases file size by approximately 33%, this provides us with a theoretical limit of 126KB. We successfully overcome this limitation by splitting larger files into smaller chunks and uploading them as multi-volume archives. Additionally, we propose AES encryption to protect sensitive data. Accordingly, we show that it is possible to include enough data to be useful for storing and sharing scientific documents and images on the blockchain at a reasonable cost for the users. CONCLUSION: INNBC DApp represents a real use case for blockchain technology in decentralizing biomedical data storage and sharing, providing us with features such as immutability, timestamp, and identity that can be used to ensure permanent availability of the data and to provide proof-of-existence as well as to protect authorship, a freely available decentralized science (DeSci) tool aiming to help bring mass adoption of blockchain technology among the scientific community.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
Original source
Apr 23, 2024·Applied Sciences
13 cites
Decentralized Identity Authentication Mechanism: Integrating FIDO and Blockchain for Enhanced Security

Hsia‐Hung Ou, C. C. Pan, Yang-Ming Tseng, Iuon‐Chang Lin

FIDO (Fast Identity Online) is a set of network identity standards established by the FIDO Alliance. It employs a framework based on public key cryptography to facilitate multi-factor authentication (MFA) and biometric login, ensuring the robust protection of personal data associated with cloud accounts and ensuring the security of server-to-terminal device protocols during the login process. The FIDO Alliance has established three standards: FIDO Universal Second Factor (FIDO U2F), FIDO Universal Authentication Framework (FIDO UAF), and the Client to Authenticator Protocols (CTAP). The newer CTAP, also known as FIDO2, integrates passwordless login and two-factor authentication. Importantly, FIDO2’s support for major browsers enables users to authenticate their identities via FIDO2 across a broader range of platforms and devices, ushering in the era of passwordless authentication. In the FIDO2 framework, if a user’s device is stolen or compromised, then the private key may be compromised, and the public key stored on the FIDO2 server may be tampered with by attackers attempting to impersonate the user for identity authentication, posing a high risk to information security. Recognizing this, this study aims to propose a solution based on the FIDO2 framework, combined with blockchain technology and access control, called the FIDO2 blockchain architecture, to address existing security vulnerabilities in FIDO2. By leveraging the decentralized nature of the blockchain, the study addresses potential single points of failure in FIDO2 server centralized identity management systems, thereby enhancing system security and availability. Furthermore, the immutability of the blockchain ensures the integrity of public keys once securely stored on the chain, effectively reducing the risk of attackers impersonating user identities. Additionally, the study implements an access control mechanism to manage user permissions effectively, ensuring that only authorized users can access corresponding permissions and preventing unauthorized modifications and abuse. In addition to proposing practical solutions and steps, the study explains and addresses security concerns and conducts performance evaluations. Overall, this study brings higher levels of security and trustworthiness to FIDO2, providing a robust identity authentication solution.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Apr 23, 2024·arXiv (Cornell University)
7 cites
Zero-Knowledge Location Privacy via Accurate Floating-Point SNARKs

Jens Ernstberger, Chengru Zhang, Luca Ciprian, Philipp Jovanovic · 5 authors

We introduce Zero-Knowledge Location Privacy (ZKLP), enabling users to prove to third parties that they are within a specified geographical region while not disclosing their exact location. ZKLP supports varying levels of granularity, allowing for customization depending on the use case. To realize ZKLP, we introduce the first set of Zero-Knowledge Proof (ZKP) circuits that are fully compliant to the IEEE 754 standard for floating-point arithmetic. Our results demonstrate that our floating point circuits amortize efficiently, requiring only $64$ constraints per multiplication for $2^{15}$ single-precision floating-point multiplications. We utilize our floating point implementation to realize the ZKLP paradigm. In comparison to a baseline, we find that our optimized implementation has $15.9 \times$ less constraints utilizing single precision floating-point values, and $12.2 \times$ less constraints when utilizing double precision floating-point values. We demonstrate the practicability of ZKLP by building a protocol for privacy preserving peer-to-peer proximity testing - Alice can test if she is close to Bob by receiving a single message, without either party revealing any other information about their location. In such a configuration, Bob can create a proof of (non-)proximity in $0.26 s$, whereas Alice can verify her distance to about $470$ peers per second

Open access
4 source records
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Security in Wireless Sensor Networks
Original source
Apr 23, 2024·Annals of Telecommunications
8 cites
Digital credentials management system using rejectable soulbound tokens

Rosa Pericàs-Gornals, Macià Mut–Puigserver, M. Magdalena Payeras–Capellà, Miquel À. Cabot-Nadal · 5 authors

Abstract Digital credentials are being issued by authorized entities to facilitate the digital identification of their users. Blockchain offers some inherent features that are highly advantageous for the management of credentials. Non-fungible tokens, or NFTs, might seem to be a perfect fit for the implementation of digital credentials. However, some crucial requirements for credentials are the non-transferability of the credential and that the authorized entity should receive explicit acceptance from the user who will own the new credential, which are features lacking in the current NFTs. This paper introduces a management system focused on issuing digital access credentials, enhancing traditional features by enabling the association of terms and conditions (T &C) during issuance and providing users with non-repudiation of reception evidence upon acceptance. Leveraging an enhanced version of the soulbound tokens (SBTs), called RejSBTs, introduced in our previous work, the new system guarantees non-repudiation of reception and origin proofs. Furthermore, we provide a detailed implementation of the system, including solidity smart contracts, accompanied by a comprehensive cost and security analysis.

Open access
Cloud Data Security Solutions
Cryptography and Data Security
Security and Verification in Computing
Original source
Apr 19, 2024·2024 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
11 cites
End-to-End Verifiable Decentralized Federated Learning

Chaehyeon Lee, Jonathan Heiss, Stefan Tai, James Won‐Ki Hong

Verifiable decentralized federated learning (FL) systems combining blockchains and zero-knowledge proofs (ZKP) make the computational integrity of local learning and global aggregation verifiable across workers. However, they are not end-to-end: data can still be corrupted prior to the learning. In this paper, we propose a verifiable decentralized FL system for end-to-end integrity and authenticity of data and computation extending verifiability to the data source. Addressing an inherent conflict of confidentiality and transparency, we introduce a two-step proving and verification (2PV) method that we apply to central system procedures: a registration workflow that enables non-disclosing verification of device certificates and a learning workflow that extends existing blockchain and ZKP-based FL systems through non-disclosing data authenticity proofs. Our evaluation on a prototypical implementation demonstrates the technical feasibility with only marginal overheads to state-of-the-art solutions.

Open access
4 source records
cs.LG
cs.CR
cs.DC
Original source