Thar Baker, Muhammad Asim, Hezekiah Samwini, Nauman Shamim · 6 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
2,533 results · page 64 of 106
Thar Baker, Muhammad Asim, Hezekiah Samwini, Nauman Shamim · 6 authors
No abstract is available for this record.
Othmane Hireche, Chafika Benzaïd, Tarik Taleb
Along with the high demand for network connectivity from both end-users and service providers, networks have become highly complex; and so has become their lifecycle management. Recent advances in automation, data analysis, artificial intelligence, distributed ledger technologies (e.g., Blockchain), and data plane programming techniques have sparked the hope of the researchers’ community in exploring and leveraging these techniques towards realizing the much-needed vision of trustworthy self-driving networks (SelfDNs). In this vein, this article proposes a novel framework to empower fully distributed trustworthy SelfDNs across multiple domains. The framework vision is achieved by exploiting (i) the capabilities of programmable data planes to enable real-time in-network telemetry collection; (ii) the potential of P4 – as an important example of data plane programming languages – and AI to (re)write the source code of network components in a fashion that the network becomes capable of automatically translating a policy intent into executable actions that can be enforced on the network components; and (iii) the potential of blockchain and federated learning to enable decentralized, secure and trustable knowledge sharing between domains. A relevant use case is introduced and discussed to demonstrate the feasibility of the intended vision. Encouraging results are obtained and discussed.
Yichen Wan, Youyang Qu, Longxiang Gao, Yong Xiang
No abstract is available for this record.
Shivam Kalra, Junfeng Wen, Jesse C. Cresswell, Maksims Volkovs · 5 authors
No abstract is available for this record.
Hisham Ali, Pavlos Papadopoulos, Jawad Ahmad, Nikolaos Pitropakis · 6 authors
Threat information sharing is considered as one of the proactive defensive approaches for enhancing the overall security of trusted partners. Trusted partner organizations can provide access to past and current cybersecurity threats for reducing the risk of a potential cyberattack - the requirements for threat information sharing range from simplistic sharing of documents to threat intelligence sharing. Therefore, the storage and sharing of highly sensitive threat information raises considerable concerns regarding constructing a secure, trusted threat information exchange infrastructure. Establishing a trusted ecosystem for threat sharing will promote the validity, security, anonymity, scalability, latency efficiency, and traceability of the stored information that protects it from unauthorized disclosure. This paper proposes a system that ensures the security principles mentioned above by utilizing a distributed ledger technology that provides secure decentralized operations through smart contracts and provides a privacy-preserving ecosystem for threat information storage and sharing regarding the MITRE ATT\&CK framework.
Sankarshan Damle, Boi Faltings, Sujit Gujar
AI applications find widespread use in a variety of domains. For further acceptance, mostly when multiple agents interact with the system, we must aim to preserve the privacy of participants information in such applications. Towards this, the Yao’s Millionaires’ problem (YMP), i.e., to determine the richer among two millionaires’ privately, finds relevance. This work presents a novel, practical, and verifiable solution to YMP, namely, Secure Comparison Protocol (SCP). We show that SCP achieves this comparison in a constant number of rounds, without using encryption and not requiring the participants’ continuous involvement. SCP uses semi-trusted third parties - which we refer to as privacy accountants - for the comparison, who do not learn any information about the values. That is, the probability of information leak is negligible in the problem size. In SCP, we also leverage the Ethereum network for pseudo-anonymous communication, unlike computationally expensive secure channels such as Tor. We present a Secure Truthful cOmbinatorial aUction Protocol (STOUP) for single-minded bidders to demonstrate SCP’s significance. We show that STOUP, unlike previous works, preserves the privacies relevant to an auction even from the auctioneer. We demonstrate the practicality of STOUP through simulations.
Qianyu Wang, Shaowen Qin
A blockchain is an ever-growing list of records that are linked to each other in a distributed network. These linked records called ledgers are immutable in nature providing resistance to change. Blockchain provides a secure way of processing the data in a distributed environment. It was widely involved in crypto currencies in the earlier days and however its application in bit coin motivated and inspired other applications to adapt its concepts. Its application in healthcare requires blockchain to be highly secure, provide a more trusted environment than the traditional blockchain, that is by design should be an enterprise level blockchain by restricting access to the public. Hyperledger Fabric caters to all these requirements in providing a secure and distributed environment for healthcare systems. In healthcare there are a lot of fields where Hyperledger Fabric can be adopted, but the focus here is given to management of patient's medical records. Traditionally the medical records are either stored centrally in a database that is accessible to only the hospitals owning it, this creates a several of problems for patients. The aim is to consider the records are handled, how the patient will interact in the real world and design a system using hyper ledger Fabric to tackle major problems using smart contract.
Ke Yuan, Yingjie Yan, Tong Xiao, Wenchao Zhang · 6 authors
In response to the rapid growth of credit-investigation data, data redundancy among credit-investigation agencies, privacy leakages of credit-investigation data subjects, and data security risks have been reported. This study proposes a privacy-protection scheme for a credit-investigation system based on blockchain technology, which realizes the secure sharing of credit-investigation data among multiple entities such as credit-investigation users, credit-investigation agencies, and cloud service providers. This scheme is based on blockchain technology to solve the problem of islanding of credit-investigation data and is based on zero-knowledge-proof technology, which works by submitting a proof to the smart contract to achieve anonymous identity authentication, ensuring that the identity privacy of credit-investigation users is not disclosed; this scheme is also based on searchable-symmetric-encryption technology to realize the retrieval of the ciphertext of the credit-investigation data. A security analysis showed that this scheme guarantees the confidentiality, the availability, the tamper-proofability, and the ciphertext searchability of credit-investigation data, as well as the fairness and anonymity of identity authentication in the credit-investigation data query. An efficiency analysis showed that, compared with similar identity-authentication schemes, the proof key of this scheme is smaller, and the verification time is shorter. Compared with similar ciphertext-retrieval schemes, the time for this scheme to generate indexes and trapdoors and return search results is significantly shorter.
Yufeng Li, Yuling Chen, Tao Li, Xiaojun Ren
In the blockchain-based energy transaction scenario, the decentralization and transparency of the ledger will cause the users’ transaction details to be disclosed to all participants. Attackers can use data mining algorithms to obtain and analyze users’ private data, which will lead to the disclosure of transaction information. Simultaneously, it is also necessary for regulatory authorities to implement effective supervision of private data. Therefore, we propose a supervisable energy transaction data privacy protection scheme, which aims to trade off the supervision of energy transaction data by the supervisory authority and the privacy protection of transaction data. First, the concealment of the transaction amount is realized by Pedersen commitment and Bulletproof range proof. Next, the combination of ElGamal encryption and zero-knowledge proof technology ensures the authenticity of audit tickets, which allows regulators to achieve reliable supervision of the transaction privacy data without opening the commitment. Finally, the multibase decomposition method is used to improve the decryption efficiency of the supervisor. Experiments and security analysis show that the scheme can well satisfy transaction privacy and auditability.
Yong Wang, Aiqing Zhang, Peiyun Zhang, Youyang Qu · 5 authors
With the fast boom of Internet of Medical Things (IoMT) devices and an increasing focus on personal health, personal health data are extensively collected by IoMT and stored as personal health records (PHRs). PHRs are frequently shared for accurate diagnosis, prognosis prediction, health advice consulting, etc. Since PHRs are highly private, the data-sharing process leads to wide-ranging concerns on privacy leakage and security compromise. Existing research has shown that the centralized systems, as the mainstream mode, are under the great risks. Motivated by this, we propose a consortium blockchain-based PHR management and sharing scheme, which is both security aware and privacy preserving. We adopt the interplanetary file system (IPFS) to store the PHR ciphertext of IoMT. Then, zero-knowledge proof can provide evidence for verifying keyword index authentication on blockchain. Moreover, the scheme jointly leverages modified attribute-based cryptographic primitives and tailor-made smart contracts to achieve secure search, privacy preservation, and personalized access control in IoMT scenarios. Security analysis is conducted to show that the designed protocols attain the expected design goals. This is followed by extensive evaluation results derived from real-world data sets, which demonstrate the superiority of the proposed scheme over current leading ones.
Rihab Habeeb Sahib, Prof. Dr. Eman Salih Al-Shamery
Regular E-voting systems for elections may count the votes in less time,less cost,save the privacy of citizens,but still considered risky as votes can be tampered.E-voting systems based on a network distributed ledger show fast results,more trusted,save privacy,cannot be tampered,and distributed in which no central organization controls the system.This paper illustrate an e-voting system to solve the challenge of a massive ledger that is distributed among network-nodes using a data reduction technique as a security-matching-tool,singular value decomposition(SVD) that handle a copy of election results in another form and matched with the SQL-database results to announce a successful election-event representing a transparency-powerful-secured-system
Pranav Gangwani, Alexander Perez-Pons, Tushar Bhardwaj, Himanshu Upadhyay · 6 authors
The demand for the digital monitoring of environmental ecosystems is high and growing rapidly as a means of protecting the public and managing the environment. However, before data, algorithms, and models can be mobilized at scale, there are considerable concerns associated with privacy and security that can negatively affect the adoption of technology within this domain. In this paper, we propose the advancement of electronic environmental monitoring through the capability provided by the blockchain. The blockchain’s use of a distributed ledger as its underlying infrastructure is an attractive approach to counter these privacy and security issues, although its performance and ability to manage sensor data must be assessed. We focus on a new distributed ledger technology for the IoT, called IOTA, that is based on a directed acyclic graph. IOTA overcomes the current limitations of the blockchain and offers a data communication protocol called masked authenticated messaging for secure data sharing among Internet of Things (IoT) devices. We show how the application layer employing the data communication protocol, MAM, can support the secure transmission, storage, and retrieval of encrypted environmental sensor data by using an immutable distributed ledger such as that shown in IOTA. Finally, we evaluate, compare, and analyze the performance of the MAM protocol against a non-protocol approach.
Young-Hoon Park, Yejin Kim, Junho Shim
The advances made in genome technology have resulted in significant amounts of genomic data being generated at an increasing speed. As genomic data contain various privacy-sensitive information, security schemes that protect confidentiality and control access are essential. Many security techniques have been proposed to safeguard healthcare data. However, these techniques are inadequate for genomic data management because of their large size. Additionally, privacy problems due to the sharing of gene data are yet to be addressed. In this study, we propose a secure genomic data management system using blockchain and local differential privacy (LDP). The proposed system employs two types of storage: private storage for internal staff and semi-private storage for external users. In private storage, because encrypted gene data are stored, only internal employees can access the data. Meanwhile, in semi-private storage, gene data are irreversibly modified by LDP. Through LDP, different noises are added to each section of the genomic data. Therefore, even though the third party uses or exposes the shared data, the owner’s privacy is guaranteed. Furthermore, the access control for each storage is ensured by the blockchain, and the gene owner can trace the usage and sharing status using a decentralized application in a mobile device.
Rabimba Karanjai, Lei Xu, Zhimin Gao, Lin Chen · 6 authors
In this paper, we present the design and implementation of a privacy preserving event based UTXO (Unspent Transaction Output) transaction system. Unlike the existing approaches that often depend on smart contracts where digital assets are first locked in a vault, and then released according to event triggers, the event based transaction system encodes event outcome as part of the UTXO note and safeguards event privacy by shielding it with zero-knowledge proof based protocols such that associations between UTXO notes and events are hidden from the validators. Without relying on any triggering mechanism, the proposed transaction system separates event processing from the transaction processing where confidential event based UTXO notes (event based UTXOs or conditional UTXOs) can be transferred freely with full privacy in an asynchronous manner, only with their asset values conditional to the linked event outcomes. The main advantage of such design is that it enables free trade of event based digital assets and prevents the assets from being locked. We implemented the proposed transaction system by extending the Zerocoin data model and protocols. The system is implemented and evaluated using xJsnark.
Bingyu Liu, Shangyu Xie, Yuanzhou Yang, Rujia Wang · 5 authors
Abstract Double auction mechanisms have been designed to trade a variety of divisible resources (e.g., electricity, mobile data, and cloud resources) among distributed agents. In such divisible double auction, all the agents (both buyers and sellers) are expected to submit their bid profiles, and dynamically achieve the best responses. In practice, these agents may not trust each other without a market mediator. Fortunately, smart contract is extensively used to ensure digital agreement among mutually distrustful agents. The consensus protocol helps the smart contract execution on the blockchain to ensure strong integrity and availability. However, severe privacy risks would emerge in the divisible double auction since all the agents should disclose their sensitive data such as the bid profiles (i.e., bid amount and prices in different iterations) to other agents for resource allocation and such data are replicated on all the nodes in the network. Furthermore, the consensus requirements will bring a huge burden for the blockchain, which impacts the overall performance. To address these concerns, we propose a hybridized TEE-Blockchain system (system and auction mechanism co-design) to privately execute the divisible double auction. The designed hybridized system ensures privacy, honesty and high efficiency among distributed agents. The bid profiles are sealed for optimally allocating divisible resources while ensuring truthfulness with a Nash Equilibrium. Finally, we conduct experiments and empirical studies to validate the system and auction performance using two real-world applications.
Hajar Moudoud, Soumaya Cherkaoui, Lyes Khoukhi
Federated learning (FL) is a distributed machine learning (ML) technique that enables collaborative training in which devices perform learning using a local dataset while preserving their privacy. This technique ensures privacy, communication efficiency, and resource conservation. Despite these advantages, FL still suffers from several challenges related to reliability (i.e., unreliable participating devices in training), tractability (i.e., a large number of trained models), and anonymity. To address these issues, we propose a secure and trustworthy blockchain framework (SRB-FL) tailored to FL, which uses blockchain features to enable collaborative model training in a fully distributed and trustworthy manner. In particular, we design a secure FL based on the blockchain sharding that ensures data reliability, scalability, and trustworthiness. In addition, we introduce an incentive mechanism to improve the reliability of FL devices using subjective multi-weight logic. The results show that our proposed SRB- FL framework is efficient and scalable, making it a promising and suitable solution for federated learning.
Konstantinos Limniotis
Cryptography is traditionally considered as a main information security mechanism, providing several security services such as confidentiality, as well as data and entity authentication. This aspect is clearly relevant to the fundamental human right of privacy, in terms of securing data from eavesdropping and tampering, as well as from masquerading their origin. However, cryptography may also support several other (legal) requirements related to privacy. For example, in order to fulfil the data minimisation principle—i.e., to ensure that the personal data that are being processed are adequate and limited only to what is necessary in relation to the purposes for which they are processed—the use of advanced cryptographic techniques such as secure computations, zero-knowledge proofs or homomorphic encryption may be prerequisite. In practice though, it seems that the organisations performing personal data processing are not fully aware of such solutions, thus adopting techniques that pose risks for the rights of individuals. This paper aims to provide a generic overview of the possible cryptographic applications that suffice to address privacy challenges. In the process, we shall also state our view on the public “debate” on finding ways so as to allow law enforcement agencies to bypass the encryption of communication.
Yuan Liang, Qiang He, Feifei Chen, Jun Zhang · 8 authors
Multi-access Edge Computing (MEC), as an extension of cloud computing, provides storage resources at the network edge to enable low-latency data retrieval for users. Due to limited physical sizes and constrained storage resources, individual edge servers cannot store a large amount of data when operating independently. They often need to offload data to other edge servers to serve users collaboratively. Operated by different edge infrastructure providers, edge servers usually work in a distrusted environment. Incentive and trust are the two main challenges in facilitating collaborative edge storage. This article proposes CSEdge, a novel decentralized system that tackles these challenges to enable collaborative edge storage based on blockchain. On CSEdge, edge servers can submit data offloading requests for others to contend for. Winners are selected based on their reputations. They will store the offloaded data and receive rewards for successfully finishing data offloading tasks. Via a distributed consensus, their performance will be recorded on blockchain for future reputation evaluation. A prototype of CSEdge is built on Hyperledger Sawtooth and experimentally evaluated against a baseline system and two start-of-the-art systems in a simulated MEC environment. The results demonstrate that CSEdge can effectively and efficiently facilitate collaborative edge storage among edge servers.
Mpyana Mwamba Merlec, Youn Kyu Lee, Seng-Phil Hong, Hoh Peter In
A massive amount of sensitive personal data is being collected and used by scientists, businesses, and governments. This has led to unprecedented threats to privacy rights and the security of personal data. There are few solutions that empower individuals to provide systematic consent agreements on distinct personal information and control who can collect, access, and use their data for specific purposes and periods. Individuals should be able to delegate consent rights, access consent-related information, and withdraw their given consent at any time. We propose a smart-contract-based dynamic consent management system, backed by blockchain technology, targeting personal data usage under the general data protection regulation. Our user-centric dynamic consent management system allows users to control their personal data collection and consent to its usage throughout the data lifecycle. Transaction history and logs are recorded in a blockchain that provides trusted tamper-proof data provenance, accountability, and traceability. A prototype of our system was designed and implemented to demonstrate its feasibility. The acceptability and reliability of the system were assessed by experimental testing and validation processes. We also analyzed the security and privacy of the system and evaluated its performance.
Saide Zhu, Ruinian Li, Zhipeng Cai, Donghyun Kim · 6 authors
IoT devices’ storage and computation capacities are constantly increasing in recent years, which brings critical challenges in data privacy protection. Federated learning (FL) and blockchain technology are two popular techniques used in IoT data aggregation, where FL enables data training with privacy protection, and blockchain provides a decentralized architecture for data storage and mining. However, very few the state-of-the-art works consider the applicability of the combination of FL and blockchain. In this paper, we adopt the federated averaging algorithm to reduce the communication overhead between the blockchain and end users to achieve higher performance. We also apply the double-mask-then-encrypt approach for end users to submit their local updates in order to protect data privacy. Finally, we propose and implement a non-interactive Public Verifiable Secret Sharing (PVSS) algorithm with Distributed Hash Table (DHT) that solves the user-drop-out problem and improves the communication efficiency between blockchain and end-users. At last, we theoretically analyze the security strengths of the proposed solution and conduct experiments to measure the execution time of PVSS on both the server and clients sides.
Samiksha Kodgire Samiksha, Padma Adane, Ajay Jadhav, Aman R. Agrawal · 5 authors
Transactions over the internet have increased rapidly and so is the need to prove one’s identity and have a secured system to keep records. To overcome identity theft and fraud cases, Self-Sovereign Identity (SSI) was introduced which gives the user complete control over their identity on the internet. Self-Sovereign Identity eliminates the centralized authority and brings Zero-knowledge proof concepts into account to help in easy transactions over the internet. It avoids revealing unnecessary information and correlation attacks. Self-Sovereign Identity, on top of blockchain public ledger features, provides an extra security layer to the system that can be used to monitor the entries in confidential places. This research paper describes a software module, that we have developed, to grant verifiable credentials to users. These credentials, on verification, can grant entry into any security system with which the module is integrated. The module utilizes the facilities provided by Hyperledger Indy and Hyperledger Aries for the creation of verifiable credentials and subsequent verification in a secure manner.
Seyed Amid Moeinzadeh Mirhosseini, Ali Fanian, T. Aaron Gulliver
The advent of Bitcoin, and consequently Blockchain, has ushered in a new era\nof decentralization. Blockchain enables mutually distrusting entities to work\ncollaboratively to attain a common objective. However, current Blockchain\ntechnologies lack scalability, which limits their use in Internet of Things\n(IoT) applications. Many devices on the Internet have the computational and\ncommunication capabilities to facilitate decision-making. These devices will\nsoon be a 50 billion node network. Furthermore, new IoT business models such as\nSensor-as-a-Service (SaaS) require a robust Trust and Reputation System (TRS).\nIn this paper, we introduce an innovative distributed ledger combining Tangle\nand Blockchain as a TRS framework for IoT. The combination of Tangle and\nBlockchain provides maintainability of the former and scalability of the\nlatter. The proposed ledger can handle large numbers of IoT device transactions\nand facilitates low power nodes joining and contributing. Employing a\ndistributed ledger mitigates many threats, such as whitewashing attacks. Along\nwith combining payments and rating protocols, the proposed approach provides\ncleaner data to the upper layer reputation algorithm.\n
Meng Li, Yifei Chen, Chhagan Lal, Mauro Conti · 6 authors
Vehicular Digital Forensics (VDF) is essential to enable liability cognizance of accidents and fight against crimes. Ensuring the authority to timely gather, analyze, and trace data promotes vehicular investigations. However, adversaries crave the identity of the data provider/user, damage the evidence, violate evidence jurisdiction, and leak evidence. Therefore, protecting privacy and evidence accountability while guaranteeing access control and traceability in VDF is no easy task. To address the above-mentioned issues, we propose Eunomia: an anonymous and secure VDF scheme based on blockchain. It preserves privacy with decentralized anonymous credentials without trusted third parties. Vehicular data and evidence are uploaded by data providers to the blockchain and stored in distributed data storage. Each investigation is modeled as a finite state machine with state transitions being executed by smart contracts. Eunomia achieves fine-grained evidence access control via ciphertext-policy attribute-based encryption and Bulletproofs. A user must hold specific attributes and a temporary-and-unexpired token/warrant to retrieve data from the blockchain. Finally, a secret key is embedded into data to trace the traitor if any evidence breach happens. We use a formal analysis to demonstrate the strong privacy and security properties of Eunomia. Moreover, we build a prototype in a WiFi-based Ethereum test network to evaluate its performance.
Meng Kang, Victoria L. Lemieux
This paper presents a design for a blockchain solution aimed at the prevention of unauthorized secondary use of data. This solution brings together advances from the fields of identity management, confidential computing, and advanced data usage control. In the area of identity management, the solution is aligned with emerging decentralized identity standards: decentralized identifiers (DIDs), DID communication and verifiable credentials (VCs). In respect to confidential computing, the Cheon-Kim-Kim-Song (CKKS) fully homomorphic encryption (FHE) scheme is incorporated with the system to protect the privacy of the individual’s data and prevent unauthorized secondary use when being shared with potential users. In the area of advanced data usage control, the solution leverages the PRIV-DRM solution architecture to derive a novel approach to licensing of data usage to prevent unauthorized secondary usage of data held by individuals. Specifically, our design covers necessary roles in the data-sharing ecosystem: the issuer of personal data, the individual holder of the personal data (i.e., the data subject), a trusted data storage manager, a trusted license distributor, and the data consumer. The proof-of-concept implementation utilizes the decentralized identity framework being developed by the Hyperledger Indy/Aries project. A genomic data licensing use case is evaluated, which shows the feasibility and scalability of the solution.