This thesis presents a generalised comprehensive framework for evaluating anonymity of cryptocurrency schemes. The framework was developed using security modelling with emphasis on a wide range of factors affecting anonymity, irrespective of the underlying implementation. The case studies presented in the thesis demonstrate how this framework facilitates the evaluation of anonymity of different cryptocurrencies in a standardised manner and the analysis of these findings reveals the complexity of the notion of anonymity.
In order to reduce the key update time delay of the Internet of Things and reduce the device location error rate and location time, a new key update and device location of Internet of Things based on smart contract was designed. Adopt improved MVIF security mechanism of both parties to build smart contract security mechanism, and the key update of the Internet of Things is realized through key predistribution, user registration and login, and key update. On this basis, multidimensional scaling technology is used to abstract Internet of Things devices into relative coordinates in multidimensional space, and the absolute coordinates are obtained by eliminating the distance estimation error to achieve Internet of Things device positioning. Experimental results show that the proposed method has a lower key update time delay, a lower amount of data used in the key update process, a lower positioning error rate of Internet of Things devices, and a shorter positioning time, which fully verifies the effectiveness of the proposed method.
In the machine learning, data sharing between different participants can increase the amount of data, improve the quality of the dataset, and thereby improve the quality of the model. Under the condition of data supervision, federated learning, as a distributed machine learning, aims to protect data while training models through collaboration among all parties to achieve data sharing and improve model quality. However, there are still some issues. For instance, the lack of trust between the participants makes it impossible to establish a secure and reliable sharing mechanism. In addition, how to fairly share the benefits generated by the model, identify honest participants and punish malicious participants is still a challenge. In this paper, we propose a new federated learning scheme based on blockchain architecture for federated learning data sharing. Moreover, an incentive mechanism based on reputation points and Shaply values is proposed to improve the sustainability of the federated learning system, which provides a credible participation mechanism for data sharing based on federated learning and fair incentives. The experimental results and analysis show that the loss of federated learning is more smooth than that of centralized machine learning.
With the development of electronic systems, ideas have repeatedly arisen to create an electronic analogue of cash for remote payment. Cryptocurrency technology was originally aimed at the absence of a trusted node - one whose actions are guaranteed to be true and who can confirm the correctness of other people's operations. For the first time, this problem was solved in the Bitcoin system due to the artificial complication of making changes to the transaction history register.
Adeeba Naaz, T. V. Pavan Kumar B, Maria Francis, Kotaro Kataoka
Authentication while maintaining anonymity when availing a service over the internet is a significant privacy challenge. Anonymous credentials (AC) address this by providing the user with a credential issued by a trusted entity that convinces the service provider (SP) that the user is authenticated but reveals no other information. The existing AC schemes assume a single trusted authority (certifier) that validates all the user attributes. In practice, however, a user may require different attributes to be attested by different certifiers. This means that the user has to get multiple credentials, increasing the burden on theSPwho has to verify each one of them. Moreover, complete anonymity can be misused. We propose adecentralized threshold revocable anonymous credential (DTRAC)scheme over blockchains that supports – a) attestation of attributes by multiple certifiers, and b) anonymity revocation through a set of distributed openers, by integrating threshold opening to the state-of-the-art threshold anonymous credential issuance scheme, Coconut [34]. DTRAC generates a single credential on attributes that are attested by multiple certifiers, freeing the SP from the hassle of verifying multiple credentials. We analyze the security of DTRAC formally in the universal composability (UC) framework. We also implement a prototype on Ethereum using smart contracts and give a detailed analysis of its performance.We compare the verification time for credentials with attributes attested by multiple certifiers in both DTRAC and Coconut and see that in terms of execution time and gas consumption, DTRAC performs significantly better than Coconut. It also scales better, with the performance gain of DTRAC over Coconut increasing linearly with the number of certifiers.
As a service platform, blockchain has faced compliance issues since the General Data Protection Regulation (GDPR) came into effect in May 2018. Although many technical solutions have been proposed to solve the compatibility issues between blockchain and the GDPR, unresolved challenges remain. This study presents the gaps between the blockchain and the GDPR and explores solutions to bridge the gap.We review 91 previously published articles using a systematic literature review methodology. Then, we answer the following research questions: 1) Which solutions have been explored to allow the blockchain to comply with the GDPR? 2) What are the research gaps in the blockchain compliance field? Finally, we present five research gaps in this field: 1) development of a consent ontology model; 2) development of a methodology for monitoring fairness in the blockchain; 3) resolution of the contradiction between auditing and obfuscation; 4) development of a methodology for tracking controllers in the blockchain; and 5) integration of the different-purposed technical solutions without conflicts. Our research can raise the compatibility level of the blockchain and GDPR and guide the company adopting a blockchain to comply with the GDPR. Furthermore, it can advise the regulator to embrace new technologies into the GDPR while protecting a blockchain’s nature.
Fidelia Cascini, Flavia Beccia, Francesco Andrea Causio, Andrea Gentili · 7 authors
The recent progress of genomics research is providing unprecedented insight into human genetic variance, susceptibility to disease and risk stratification. Current trends predict that a massive amount of genomic data will be produced in the upcoming years which, when coupled with the fast-paced development of the field, will create new social, ethical, and legal challenges. In the complex legislative environment of the European Union, genomic data sharing policies will have to weigh the benefits of scientific discovery against the ethical risks posed by the act of sharing sensitive data. In this complex, interconnected environment, blockchain provides a unique and novel solution to accountability, traceability, and transparency issues regarding genomic data sharing. Implementing a distributed ledger technology-based database could empower both patients and citizens to responsibly use genomic data pertaining to them because it allows for a higher degree of control over the recipients of their data and their uses. The blockchain technology will engage both data owners and policymakers to address the multiple issues of genomic data sharing and allow us to redefine the way we look at genomics.
The rapid advancement in the area of the Internet of Vehicles (IoV) has provided numerous\ncomforts to users due to its capability to support vehicles with wireless data communication. The\nexchange of information among vehicle nodes is critical due to the rapid and changing topologies,\nhigh mobility of nodes, and unpredictable network conditions. Finding a single trusted entity to\nstore and distribute messages among vehicle nodes is also a challenging task. IoV is exposed to\nvarious security and privacy threats such as hijacking and unauthorized location tracking of smart\nvehicles. Traceability is an increasingly important aspect of vehicular communication to detect and\npenalize malicious nodes. Moreover, achieving both privacy and traceability can also be a challenging\ntask. To address these challenges, this paper presents a blockchain-based efficient, secure, and\nanonymous conditional privacy-preserving and authentication mechanism for IoV networks. This\nsolution is based on blockchain to allow vehicle nodes with mechanisms to become anonymous and\ntake control of their data during the data communication and voting process. The proposed secure\nscheme provides conditional privacy to the users and the vehicles. To ensure anonymity, traceability,\nand unlinkability of data sharing among vehicles, we utilize Hyperledger Fabric to establish the\nblockchain. The proposed scheme fulfills the requirement to analyze different algorithms and\nschemes which are adopted for blockchain technology for a decentralized, secure, efficient, private,\nand traceable system. The proposed scheme examines and evaluates different consensus algorithms\nused in the blockchain and anonymization techniques to preserve privacy. This study also proposes\na reputation-based voting system for Hyperledger Fabric to ensure a secure and reliable leader\nselection process in its consensus algorithm. The proposed scheme is evaluated with the existing\nstate-of-the-art schemes and achieves better results.
Junaid Arshad, Muhammad Ajmal Azad, Alousseynou Prince, Jahid Ali · 5 authors
Reputation systems are an important means to facilitate trustworthy interactions between on-and off-chain services and users. However, contemporary reputation systems are typically dependent on a trusted central authority to preserve privacy of raters or on adding noise into the user feedback. Moreover, the accuracy of reputation values relies on the integrity of user feedback or input; this feedback should not be tampered with or misused for other purposes. This paper presents blockchain-based reputation system named REPUTABLE (A Decentralized Reputation System for blockchain-based Ecosystems), which computes the reputation of service providers and external services within a blockchain ecosystem through decentralized on-chain and off-chain implementation. Specifically, REPUTABLE not only ensures privacy, but also reliability, integrity and accuracy of reputation values, while incurring minimal overhead. It also enables performing certain data or statistical analytics functions on user feedback, whilst preserving security, privacy, accountability and unlinkability of participants and their feedback. We present a proof-of-concept implementation and a demonstration of the REPUTABLE system. Finally, by means of formal and empirical evaluation, we show the effectiveness of our proposed system to preserve the anonymity of user feedback and the high performance of its blockchain-based implementation.
Rongyu Xiao, Guozi Sun, Jiale Yang, Yao Wang · 5 authors
Public chains represented by Bitcoin and Ethereum do not require users to use their real names, and transaction data are open to the whole network. Analysed based on this, researchers have achieved the deanonymization of blockchain transactions to a certain extent. Based on the existing blockchain transaction privacy protection scheme, the true link relationship between the transaction sender and receiver is hidden, which brings difficulties to regulation. In this paper, we propose a cryptocurrency mixing service RBSmix, which allows users to reestablish their financial privacy in Bitcoin and related cryptocurrencies. RBSmix, through blind signature to prevent attackers from linking input and output addresses, by the threshold secret sharing algorithm, encryption technology, and a regulation team, combined with the idea of voting, tracks the source of funds for illegal addresses. Experiments show that the scheme scales to large numbers of users and can provide users with better privacy protection.
Krishan Kumar, Jenifer Mahilraj, D. Swathi, R. Rajavarman · 8 authors
Recently, smart cities have emerged as an effective approach to deliver high-quality services to the people through adaptive optimization of the available resources. Despite the advantages of smart cities, security remains a huge challenge to be overcome. Simultaneously, Intrusion Detection System (IDS) is the most proficient tool to accomplish security in this scenario. Besides, blockchain exhibits significance in promoting smart city designing, due to its effective characteristics like immutability, transparency, and decentralization. In order to address the security problems in smart cities, the current study designs a Privacy Preserving Secure Framework using Blockchain with Optimal Deep Learning (PPSF-BODL) model. The proposed PPSF-BODL model includes the collection of primary data using sensing tools. Besides, z-score normalization is also utilized to transform the actual data into useful format. Besides, Chameleon Swarm Optimization (CSO) with Attention Based Bidirectional Long Short Term Memory (ABiLSTM) model is employed for detection and classification of intrusions. CSO is employed for optimal hyperparameter tuning of ABiLSTM model. At the same time, Blockchain (BC) is utilized for secure transmission of the data to cloud server. This cloud server is a decentralized, distributed, and open digital ledger that is employed to store the transactions in different methods. A detailed experimentation of the proposed PPSF-BODL model was conducted on benchmark dataset and the outcomes established the supremacy of the proposed PPSF-BODL model over recent approaches with a maximum accuracy of 97.46%.
Data management is the collection, processing, storing, and sharing of data. In today's dispensation, data sharing and collaborative data processing is a necessity for multi-partner organizations as it can lead to the discovery of new insight. Shared data is generally for the purpose of marketing, advertising, and other institutional decision-making reasons. A challenge however is that the collected data (mostly about individuals known as data subjects or producers) is disseminated among organizations without meaningful consent from the data subjects. Hence, data subjects are not aware of what is happening to their data regarding use and misuse. Furthermore, data subjects can hardly determine which third-party institutions have access to their data. In this paper, we opined that data should be managed in a manner that can persuade the trust of data subjects. To achieve this, data subjects should have the rights to be informed about details of their data. Thus, this paper proposes a cloud-based data management and sharing platform to enable data subjects to control who can access their data and consent to its collection and usage based on smart contracts. The proposed system leverages blockchain to enforce accountability, provenance, and auditability of all events. We implemented a dynamic consent management prototype on top of Ethereum blockchain to demonstrate the feasibility of the proposed work.
Xihua Zhang, S. B. Goyal, Miretab Tesfayohanis, Chaman Verma
The collection of amounts of useful data from various IoT devices through machine learning (ML) techniques has been extensively applied in lots of areas of the smart city. To improve the efficiency of machine learning, people realize efficient data classification by supporting the ML model, namely, the support vector machine (SVM) model, which is used in the realization of linear classification. However, data security and data protection are not addressed in SVM classifier training from multiple entity‐labeled IoT data. In the existing solution, they depend on the implicit hypothesis that learning data can be dependable collected from complex data providers, which is often not the reality. To solve the question between the above problems, in this article, we put forward a secure support vector machine—a secure SECURE SVM training scheme for protecting the privacy on encrypted IoT data based on blockchain. Firstly, a secure and dependable data encryption sharing platform is established among complex data providers by using blockchain technology, which is recorded in a distributed ledger. Secondly, the homomorphic cryptosystem is used to design secure components, and the secure polynomial multiplication is improved to design a secure SVM training algorithm, which only needs two interactions in one iteration and does not need a trusted third party. Finally, the experimental results display that the plan ensures the confidentiality of sensitive data of each data provider and the confidentiality and validity of SVM model parameters of data analysts.
Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
The electronic know your customer (e-KYC) is a system for the banking or identity provider to establish a customer identity data verification process between relying parties. Due to the efficient resource consumption and the high degree of accessibility and availability of cloud computing, most banks implement their e-KYC system on the cloud. Essentially, the security and privacy of e-KYC related documents stored in the cloud becomes the crucial issue. Existing e-KYC platforms generally rely on strong authentication and apply traditional encryption to support their security and privacy requirement. In this model, the KYC system owner encrypts the file with their host’s key and uploads it to the cloud. This method induces encryption dependency and communication and key management overheads. In this paper, we introduce a novel blockchain-based e-KYC scheme called e-KYC TrustBlock based on the public key encryption method binding with the client consent enforcement to deliver trust, security and privacy compliance. In addition, we introduce attribute-based encryption to enable the privacy preserving and fine-grained access of sensitive transactions stored in the blockchain. Finally, we conduct experiments to show that our system is efficient and scalable in practice.
Ibrahim Abunadi, Maha M. Althobaiti, Fahd N. Al‐Wesabi, Anwer Mustafa Hilal · 8 authors
The evolving “Industry 4.0” domain encompasses a collection of future industrial developments with cyber-physical systems (CPS), Internet of things (IoT), big data, cloud computing, etc. Besides, the industrial Internet of things (IIoT) directs data from systems for monitoring and controlling the physical world to the data processing system. A major novelty of the IIoT is the unmanned aerial vehicles (UAVs), which are treated as an efficient remote sensing technique to gather data from large regions. UAVs are commonly employed in the industrial sector to solve several issues and help decision making. But the strict regulations leading to data privacy possibly hinder data sharing across autonomous UAVs. Federated learning (FL) becomes a recent advancement of machine learning (ML) which aims to protect user data. In this aspect, this study designs federated learning with blockchain assisted image classification model for clustered UAV networks (FLBIC-CUAV) on IIoT environment. The proposed FLBIC-CUAV technique involves three major processes namely clustering, blockchain enabled secure communication and FL based image classification. For UAV cluster construction process, beetle swarm optimization (BSO) algorithm with three input parameters is designed to cluster the UAVs for effective communication. In addition, blockchain enabled secure data transmission process take place to transmit the data from UAVs to cloud servers. Finally, the cloud server uses an FL with Residual Network model to carry out the image classification process. A wide range of simulation analyses takes place for ensuring the betterment of the FLBIC-CUAV approach. The experimental outcomes portrayed the betterment of the FLBIC-CUAV approach over the recent state of art methods.
In recent years, cloud-based medical record sharing has greatly improved the process of researching the disease and patient diagnosis. However, since cloud systems are centralized, there is serious concern about data security and privacy. Blockchain technology is viewed as a promising method of dealing with privacy issues and data security because of its exclusive features of distributed ledgers, secrecy, verifiability, and enhanced security. The literature review has shown significant works on integrating blockchain technology with cloud system for managing and sharing healthcare data. It has been analyzed that previous works are primarily dependent on the centralized data storage approach, which raises privacy concerns. The previous works also do not emphasize handling big medical data and lack the reliability of the end-to-end security features system. This paper has presented an authorization framework for ensuring data security and privacy preservation using blockchain technology with IPFS as decentralized file storage and sharing system. The proposed study devises a proof of replication algorithm using smart contracts to provide a better access control mechanism. The implementation of the proposed framework is based on the symmetric encryption and Ethereum blockchain platform. The study outcome illustrates the efficiency and availability of the proposed scheme compared to the typical cloud-based blockchain method.