Maurizio Talamo, Franco Arcieri, Andrea Dimitri, Christian H. Schunck
Public key infrastructures (PKIs) are the cornerstone for the security of the communication layer of online services relying on certificate-based authentication, such as e-commerce, e-government, online banking, cloud services, and many others. A PKI is an infrastructure based on a hierarchical model, but the use of PKIs in non-hierarchical contexts has exposed them to many types of attacks. Here, we discuss weaknesses exploited in past attacks and we propose a solution based on an original consensus algorithm developed for use on blockchain technology. In this implementation we retain the full functionality around X.509 certificates, i.e., for the triad (server name, server address, X.509 server certificate), and demonstrate a mechanism for obtaining fast consensus. The main properties of the solution are that a consensus may be reached even when not all members of the involved PKI participate in a transaction, and that no advanced trust agreement among PKIs is needed. The proposed solution is able to detect PKI attacks and can distinguish errors from attacks, allowing precise management of anomalies.
Before the invention of the various technologies, managing various activities and actions over the internet was achieved through a centralized server to guarantee valid data. With the expanding measure of accessible storage space and the quickening of data stream incited by the internet, a developing enthusiasm for data about the creation procedure and sources of information has developed. While this wide scope of use territories would profit by provenance data, the kind of provenance information, manipulation and querying facilities required vary from application to application. In this way, to discover the distinctions and similitudes between the different application and information model provenance needs and present a general plan for the arrangement of provenance. By characterizing this plan and applying it to existing work we plan to uncover open inquiries in the region of information provenance In this paper we survey the blockchain and provenance of the data in rice supplychain. We implement our proposed approach using smart contract which is to be deploy on ethereum blockchain network in rice supplychain to show the security and provenance of the data . We can track the progress of rice batch after each stage in blockchain and also discussed the need of provenance of assets in supplychain as it increase the trust of the customer
Nasrin Sohrabi, Xun Yi, Zahir Tari, Ibrahim Khalil
Controlling the access over the stored data in the cloud is one of the fundamental security requirements, especially with the wide usage of cloud storage servers for nearly most of the enterprise applications. Traditional cloud-based access control solutions are based on a centralized approach (i.e. a cloud server becomes the central authority to control accesses to the data), which makes it difficult to prevent malicious cloud servers from disclosing user’s data; and therefore compromising the privacy of the stored data. Additionally, the centralization of authority can cause a single point of failure. Furthermore, to provide confidentiality, which is one of the essential security requirements, user’s data is encrypted before it is stored on the cloud. Most of the cloud servers store the decryption keys, after they encrypt the data, in their premises. This compromises data privacy. In this paper we propose a new model that addresses the aforementioned issues. To address the centralization problem, we distributed the access control tasks to smart contracts over a decentralized network, i.e. blockchain. To address the latter, we used Shamir secret sharing scheme to manage the encryption keys. Then we introduced a new type of node, called master node, to our blockchain platform, to store the decryption key parts.
Traditional centralized data storage and processing solutions manifest limitations with regards to overall operational cost and the security and auditability of data. One of the biggest issues with existing solutions is the difficulty of keeping track of who has had access to the data and how the data may have changed over its lifetime; while providing a secure and easy-to-use mechanism to share the data between different users. The ability to electronically regulate data sharing within and across different organizational entities in the supply chain (SC) is an open issue that is only addressed partially by existing legal and regulatory compliance frameworks. In this article, we present Cydon, a decentralized data management platform that executes bespoke distributed applications utilizing a novel search and retrieve algorithm leveraging metadata attributes. Cydon utilizes a smart distributed ledger to offer an immutable audit trail and transaction history for all different levels of data access and modification within a SC and for all data flows within the environment. Results suggest that Cydon provides authorized and fast access to secure distributed data, avoids single points of failure by securely distributing encrypted data across different nodes while maintains an “always-on” chain of custody.
Mohammed Amine Bouras, Qinghua Lu, Zhang Fan, Yueliang Wan · 6 authors
Electronic healthcare (eHealth) identity management (IdM) is a pivotal feature in the eHealth system. Distributed ledger technology (DLT) is an emerging technology that can achieve agreements of transactional data states in a decentralized way. Building identity management systems using Blockchain can enable patients to fully control their own identity and provide increased confidence in data immutability and availability. This paper presents the state of the art of decentralized identity management using Blockchain and highlights the possible opportunities for adopting the decentralized identity management approaches for future health identity systems. First, we summarize eHealth identity management scenarios. Furthermore, we investigate the existing decentralized identity management solutions and present decentralized identity models. In addition, we discuss the current decentralized identity projects and identify new challenges based on the existing solutions and the limitations when applying it to healthcare as a particular use case.
In this competitive world, it is hard to get a job. It requires some specific qualifications and experience according to the post. If a person is not fulfilling these required entities, then not able to apply for that post. Therefore, some people, who are not eligible may use different forgery approaches like fake mark sheets, fake experience certificates, fake medical certificates, etc. However, despite being these fake certificates, some people may have a criminal background also. Therefore, large numbers of resources are required to verify the educational records, criminal background, and experience of a person. Therefore, the proposed system provides an efficient solution to these problems using blockchain technology. In the proposed work, we used three different modules like college, organisation, and police. The college is responsible for providing academic qualifications and the organisation is responsible for providing experience while police are responsible for proving and verification of the criminal record. The proposed system is implemented on the Ethereum blockchain platform and effectively can be used by the organisations for verifying the record of their employees.
Christian Sri Kusuma Aditya, M. Akash, pothuru eswar akash, M. Amitkumar · 8 authors
The complexity of providing secure access, protecting critical data and end-user privacy in cloud data centre is leading to a demand for a new approach in network and data security. Recently, blockchain technology is being used in claims management to provide a decentralized and secure solution. The issue of security is crucial in the Virtual machine authorization in the cloud data centers. In the traditional approach of VM authorization, SSH key and IP address is given to the user to log into virtual machines. This opens much vulnerability as it might get spoofed or sniffed from the network, leading to accesses of private data to intruder. In this work, we propose a method which intends to aid in the security of the VM authorization using claims-based authorization system in conjunction with Blockchain based decentralized storage. Furthermore, the proposed system automates the process of launching a VM in OpenStack orchestration software.
Nowadays, as lightweight mobile clients become more powerful and widely used, more and more information is stored on lightweight mobile clients, user sensitive data privacy protection has become an urgent concern and prob... | Find, read and cite all the research you need on Tech Science Press
Blockchain has a strong capacity to monitor and retain educational records. The paperless future has yet to become a reality, even with the ability to digitally generate documents. Physical copy of records are still regularly printed which makes them susceptible to document fraud. Thus, the issue of fake certificates and academic records has risen drastically. In this paper, we have made a reliable verification method to avoid academic frauds. The idea presented here is developed over Hyperledger. The University or The Educational Institute is responsible for issuing the certificates, mark-sheets, transcripts, etc. and mining it over the blockchain. The student is provided with the hash number which is the reference number. This number serves the reference of the data. The Organization or the Industry Personal using the hash number checks for the integrity of the submitted document. The present study discusses about importance of block chain and it’s applicability especially for the applications like verification of Academic Records.
The security of operation and maintenance phase in systems that share long-life cycles like weapon systems is of great importance. Even if the system passes the security evaluation at the development stage before release, it can be adversely affected by the penetration of counterfeit components (parts) during the operation and maintenance phase. Such security issues are concatenated with data related to supply chain, accordingly, system parts need to fulfill the traceability on a fundamental basis. In addition to traceability, supply chains should also meet the data security standards of availability, integrity and confidentiality in the long run. Also, even without trusted third party, these data should be available to users. In this paper, we, therefore, propose a framework that utilizes blockchain and key escrow encryption system in a bid to optimize the security of supply chains for long-lifecycle systems and provide better measures to improve services for global business survivability.
In the digital era, electronic medical record (EMR) has been a major way for hospitals to store patients’ medical data. The traditional centralized medical system and semi-trusted cloud storage are difficult to achieve dynamic balance between privacy protection and data sharing. The storage capacity of blockchain is limited and single blockchain schemes have poor scalability and low throughput. To address these issues, we propose a secure and efficient medical data storage and sharing scheme based on double blockchain. In our scheme, we encrypt the original EMR and store it in the cloud. The storage blockchain stores the index of the complete EMR, and the shared blockchain stores the index of the shared part of the EMR. Users with different attributes can make requests to different blockchains to share different parts according to their own permissions. Through experiments, it was found that cloud storage combined with blockchain not only solved the problem of limited storage capacity of blockchain, but also greatly reduced the risk of leakage of the original EMR. Content Extraction Signature (CES) combined with the double blockchain technology realized the separation of the privacy part and the shared part of the original EMR. The symmetric encryption technology combined with Ciphertext-Policy Attribute-Based Encryption (CP–ABE) not only ensures the safe storage of data in the cloud, but also achieves the consistency and convenience of data update, avoiding redundant backup of data. Safety analysis and performance analysis verified the feasibility and effectiveness of our scheme.
Macià Mut–Puigserver, Miquel À. Cabot-Nadal, M. Magdalena Payeras–Capellà
Recently several proposals of blockchain-based solutions for traditional e-commerce applications have been presented, taking advantage of the fact that blockchain is a technology that offers an immutable registry of data. Among these proposals we can find solutions for certified notifications, digital signature of contracts, escrow protocols, fair payments and registered deliveries. In order to execute fair exchanges, most solutions involve trusted third parties, known as TTP, supervising the exchanges in a way or another. Until now, two solutions have been presented for Registered electronic Delivery (eDelivery) services. This service allows a user to prove that he has sent some data to a set of receivers. These protocols differ in the properties achieved and also in the use of trusted third parties. The first protocol is a blockchain-based solution without TTP for the eDelivery of non-confidential data. The second protocol allows also the eDelivery of confidential data. However, this second proposal requires the involvement of a TTP in a non-mandatory resolution phase. In this paper we present a new protocol that achieves the best properties of the previous solutions at the same time. The new protocol doesn't require the involvement of a TTP at any moment while it allows the eDelivery of confidential data, satisfying the security requirements for this service.
Data tracking is of great significance and a central part in digital forensics. In today's complex network design, Internet of Things (IoT) devices communicate with each other and require strong security mechanisms. In maintaining an audit trail of IoT devices or provenance of IoT device data, it is important to know the origins of requests to ensure certain level of trust in IoT data. Blockchain can provide traceability of records generated from IoT devices in a sensitive environment. In this paper, we present an application layer data provenance model that works on execute-order architecture for cloud based IoT networks. It supports high throughput of transactions on the blockchain network with lightweight security overhead by using outsourced encryption on edge nodes. All communications among the IoT devices are connected to a blockchain network and stored on permissioned blockchain peers. The proposed system is evaluated to have less cryptographic load by offloading the IoT nodes with Edge nodes.
Cryptocurrencies are getting massive momentum in the last few years. Cryptocurrencies depend upon a secure distributed ledger called blockchain which stores blocks in a secure and chronological order. Although a large cryptocurrencies wallet management scheme has been proposed but they suffer from weak security. Thus effective cryptocurrency key management has become a much needed requirement for modern cryptocurrencies. In this paper, we propose a more effective, usable and secure cryptocurrency key management system named rashi that provides security enhanced storage, no password authentication. The performance analysis shows that our proposed system requires minimal additional overhead and has low time delays, enhanced security and efficient real -world deployment.
The Solid (Social Linked Data) project focuses on data sharing and privacy security and aims to build a decentralized ecosystem that radically changes the way web applications work today. Our goal is to introduce a “trust access authentication system” to achieve secure authentication and fine-grained access control, thereby promoting the implementation of Solid. Blockchain, equipped with multiple security properties and authentication functions, is a crucial technology. In this paper, we present a blockchain-assisted system for secure authentication in Solid and for implementation of fine-grained access control policies. Specifically, we explore to integrate threshold RSA signatures in a permissioned blockchain system to enable a fault-tolerant distributed signature scheme, thereby enhancing the resilience and robustness of authentication system. Moreover, we utilize smart contract to control transaction flows and manage access control policies automatically. Experimental results show that our proposed trust access authentication system enhances security, scales well, and is efficient and economically feasible.
In this thesis, we present novel methods for verifying, implementing and specifying protocols. In particular, we focus properties modeling data protection and the protection of privacy. In the first part of the thesis, the author introduces protocol verification and presents a model for verification that encompasses so-called Zero-Knowledge (ZK) proofs. These ZK proofs are a cryptographic primitive that is particularly suited for hiding information and hence serves the protection of privacy. The here presented model gives a list of criteria which allows the transfer of verification results from the model to the implementation if the criteria are met by the implementation. In particular, the criteria are less demanding than the ones of previous work regarding ZK proofs. The second part of the thesis contributes to the area of protocol implementations. Hereby, ZK proofs are used in order to improve multi-party computations. The third and last part of the thesis explains a novel approach for specifying data protection policies. Instead of relying on policies, this approach relies on actual legislation. The advantage of relying on legislation is that often a fair balancing is introduced which is typically not contained in regulations or policies.
Moving large amounts of data between networks for data analysis and computations presents several issues related to privacy and security. In collaboration with the TOTEM project [1], we propose a solution to these problems, by moving computations to the residence of the data. We introduce a novel approach for managing access to remote datasets and resources by blockchain technology through Hyperledger Fabric. Organizations with similar interests may join a consortium, which will form a private channel on the blockchain network, i.e., a separate ledger. Participating organizations will enroll their users, who thereafter must obtain a one-time-code using a smart contract in order to gain access to remote resources. We utilize Ansible for remotely deploying Hadoop clusters for computation, which will comprise several Docker containers. A user may run computations at several remote locations separately, and subsequently retrieve a combined result without having to share data between organizations. To ensure privacy between participating organizations we utilize chaincode and private data collections in Hyperledger Fabric. Finally, we demonstrate three ways of deploying the solution: locally, as a single cluster in the cloud using Azure, and across multiple clusters in the cloud using Azure. Our solution ensures data privacy by allowing data providing organizations to connect their own computational resources for data consumers to use. By running computations inside Docker containers on these resources, we ensure that these processes are isolated from the host system.
Jan 1, 2020·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Blockchain is an emerging exponential technology that disrupts the existing way of doing business. During the last 10 years its importance has been highlighted and many organizations worldwide have embraced it and developed innovative applications. Even though Blockchain has been adopted by many sectors, Universities are reluctant to propose new academic programs on this field at bachelor and postgraduate level and fail to efficiently educate students on Blockchain technology and cryptocurrencies. Consequently, universities have failed to investigate the business, technical, legal and other aspects of this technology. As a result, we have the paradox where industry and economy would like to experiment and adopt Blockchain solutions but there is a lack of people with appropriate and adequate skills to work on these solutions. Obviously, this holds back the adoption and the widespread of this technology and currently there are problems in scaling up Blockchain technology. The goal of this paper is to explore the area of Blockchain education and training and propose the structure of a master program that can be used as a model. In doing so, we expand the body of knowledge and we shed light to an important area with limited available information and use cases.
As a quite attractive secure search mechanism in cloud environments, searchable encryption allows encrypted files to be searched by keyword and does not reveal any information about original data files. However, most existing searchable encryption schemes only support single keyword ciphertext retrieval, and they cannot resist against inside keyword guessing attacks. Besides, the previous schemes rarely focus on integrity verification and fair transactions without any third party. Focusing on these problems, we propose a multi-keyword certificateless searchable public key authenticated encryption scheme based on blockchain. We use certificateless cryptosystem to encrypt keywords, which avoids the problems of certificate management in traditional cryptosystem and key escrow in identity-based cryptosystem. Our scheme also supports multi-keyword search, which locates encrypted files precisely and returns the desired files. Moreover, we upload the real encrypted files to the cloud server, while the encrypted indexes are put in blockchain, which ensures the anti-tampering, integrity and traceability of the encrypted indexes. The anti-tampering of blockchain also ensures that users can receive accurate search results without any third party verification. Furthermore, we utilize smart contract to track monetary rewards, which enables fair transactions between data owners and users without any trusted third party. We prove that the proposed scheme is secure against inside keyword guessing attacks in the random oracle model. Finally, our performance evaluation shows that the proposed scheme has higher computational performance than other related schemes.
Traditional centralized access control has some shortcomings in robustness, trustworthiness and circulation. Blockchains have the advantages of fault tolerance and trust. Smart contracts have the characteristics of automatic execution and flexible expansion. Tokens can well record credential information and transfer easily. In this paper, blockchain, smart contract and token are integrated and applied to access control to solve the shortcomings of traditional access control. First, access control, blockchain, smart contract and token are briefly described. Second, this paper proposes a solution by giving the general data structure of access control token, elaborating the equivalence, split, merge and verification algorithms of access control token, and explaining the system architecture of token-based access control. Last, this paper uses a token-based access control simulation system to verify that token-based access control has certain comparative advantages in robustness, trustworthiness, circulation, concurrency and so on.