With the development of the Internet and edge computing technology, many industrial Internet applications have emerged, followed by a large amount of data in the Industrial Internet. How to securely store and share this data has become a hot topic in current research. Firstly, a blockchain and IPFS based on-chain and off-chain storage architecture is proposed, which detects data through machine learning algorithms and stores data without anomalies. Then, the roles of users were classified and various smart contracts were designed for registering users, deleting users, and managing roles and their permissions. Finally, an experimental platform was built through open-source software to verify the feasibility of the proposed scheme and realize the safe storage and sharing of normal data.
Saeed Ranjbar Alvar, Mohammad Akbari, David Yue, Yong Zhang
In today's digital world, enterprises and individuals are generating massive data that is potentially useful for many data consumers with data driven applications. The emergence of data marketplaces is a step toward helping the data owners to monetize their digital assets and get connected to the potential buyers. The current data marketplaces cannot handle the challenges related to data ownership claims, illegal redistribution, and data ownership traceability. To overcome these problems in a general-purpose market, we propose a marketplace based on watermarking and Non-Fungible Token (NFT) technologies. In the proposed NFT-based marketplace, the owner's data is stored as an NFT where the underlying content of the NFT holds the watermarked data. The watermarked data is obtained by embedding some information about the owners and the buyers into the original data. The embedded information can later be extracted to identify the owner and the buyer of the traded data. Furthermore, the transactions corresponding to the NFT provide verifiable ownership proof and traceable ownership history. A Proof-Of-Concept (POC) implementation of the proposed marketplace that will be integrated within AI-Gallery Data Marketplace service in Huawei Cloud is presented for trading image data. An extensive set of experiments to measure the gas consumption on the blockchain and evaluate the robustness of the watermarked assets against 51 attacks are performed. Finally, a method based on error correction codes is proposed for improving the watermarking robustness in the implemented marketplace. The link for the codes and the POC demo is provided in the appendix.
Smart contracts are simply computer programs. These programs are deployed on distributed nodes over the blockchain network. These are executed without the need for third-party authentication. Usually, smart contracts are used for transferring assets so it requires the error-free execution of smart contract code. But, due to computer code pitfalls, it may be the possibility of errors or exceptions that may vulnerable to the security of smart contracts. Thus, this paper surveys the smart contract security issues and smart contract code vulnerabilities that have been investigated and security analysis tools are presented. A series of vulnerable codes is presented that may have the risk of stealing assets and information. The solution to these vulnerabilities has also been discussed. A comparison with existing work has also been presented.
Due to certain unique qualities and capabilities, Blockchain is a highly beneficial approach that may be used to safely manage various gadgets in a smart city. It has several uses, particularly in dispersed situations where elements such as wireless sensor nodes must be confident of the server's legitimacy. Because modern blockchain solutions that handle post-quantum problems have not been developed, we explore a blockchain in the quantum-resistant cryptography context and strive to find how it might withstand quantum computing assaults throughout this work. Furthermore, the newly born Proof of Stake (PoS) provides faster and cheaper transactions, but its security is not proven in comparison to its forefather Proof of Work (PoW). As a result, a new quantum-resistant proof of stake (Quantum-Resistant PoS) agreement technique for smart city application services has been developed. The proposed model has the ability to protect a distributed ledger system against a quantum assault and also provides scalability and inexpensive transactions. Additionally, user-based post-quantum authentication is included in the transaction process to create a simple payment verification node. Following that, we present a detailed rundown of how to execute a post-quantum simple payment verification and transaction on a blockchain. Thus, our study will contribute to imminent quantum-resistant blockchain exploration along with the design or structure of potentially distributed ledger technology-based ubiquitous computing.
Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Stealth addresses are a privacy-enhancing technology that provides recipient anonymity on blockchains. In this work, we investigate the recipient anonymity and unlinkability guarantees of Umbra, the most widely used implementation of the stealth address scheme on Ethereum, and its three off-chain scalability solutions, i.e., Arbitrum, Optimism, and Polygon. Specifically, we define and evaluate four heuristics to uncover the real recipients of stealth payments. We find that for the majority of Umbra payments, it is straightforward to establish the recipient, hence nullifying the benefits of using Umbra. In particular, we identify the real recipient of 48.5%, 25.8%, 65.7%, and 52.6% of all Umbra transactions on the Ethereum main net, Polygon, Arbitrum, and Optimism networks, respectively. Finally, we suggest easily implementable countermeasures to evade our deanonymization and linking attacks.
Aydin Abadi, Dan Ristea, Artem Grigor, Steven J. Murdoch
Time-Lock Puzzles (TLPs) enable a client to lock a message such that a server can unlock it only after a specified time. They have diverse applications, such as scheduled payments, secret sharing, and zero-knowledge proofs. In this work, we present a scalable TLP designed for real-world scenarios involving a large number of puzzles, where clients or servers may lack the computational resources to handle high workloads. Our contributions are both theoretical and practical. From a theoretical standpoint, we formally define the concept of a “Delegated Time-Lock Puzzle (D-TLP)”, establish its fundamental properties, and introduce an upper bound for TLPs, addressing a previously overlooked aspect. From a practical standpoint, we introduce the “Efficient Delegated Time-Lock Puzzle” (ED-TLP) protocol, which implements the D-TLP concept. This protocol enables both the client and server to securely outsource their resource-intensive tasks to third-party helpers. It enables realtime verification of solutions and guarantees their delivery within predefined time limits by integrating an upper bound and a fair payment algorithm. ED-TLP allows combining puzzles from different clients, enabling a solver to process them sequentially, significantly reducing computational resources, especially for a large number of puzzles or clients. ED-TLP is the first protocol of its kind. We have implemented ED-TLP and conducted a comprehensive analysis of its performance for up to 10,000 puzzles. The results highlight its significant efficiency in TLP applications, demonstrating that EDTLP securely delegates 99% of the client’s workload and 100% of the server’s workload with minimal overhead.
Crowdsourcing has emerged as a prevalent method for mitigating the risks of correctness and security in outsourced cloud computing. This process involves an aggregator distributing tasks, collecting responses, and aggregating outcomes from multiple data sources. Such an approach harnesses the wisdom of crowds to accomplish complex tasks, enhancing the accuracy of task completion while diminishing the risks associated with the malicious actions of any single entity. However, a critical question arises: How can we ensure that the aggregator performs its role honestly and each contributor's input is fairly evaluated? In response to this challenge, we introduce a novel protocol termed $\mathsf{zkTI}. This scheme guarantees both the honest execution of the aggregation process by the aggregator and the fair evaluation of each data source. It innovatively integrates a cryptographic construct known as zero-knowledge proof with a category of truth inference algorithms for the first time. Under this protocol, the aggregation operates with both correctness and verifiability, while ensuring fair assessment of data source reliability. Experimental results demonstrate the protocol's efficiency and robustness, making it a viable and effective solution in crowdsourcing and cloud computing.
We present a novel method for a multi-party, zero-trust validator infrastructure deployment arrangement via smart contracts to secure Proof-of-Stake (PoS) blockchains. The proposed arrangement architecture employs a combination of non-fungible tokens (NFTs), a treasury contract, and validator smart contract wallets to facilitate trustless participation in staking mechanisms. The NFT minting process allows depositors to exchange their capital for an NFT representing their stake in a validator, while the treasury contract manages the registry of NFT holders and handles rewards distribution. Validator smart contract wallets are employed to create a trustless connection between the validator operator and the treasury, enabling autonomous staking and unstaking processes based on predefined conditions. In addition, the proposed system incorporates protection mechanisms for depositors, such as triggered exits in case of non-payment of rewards and a penalty payout from the validator operator. The arrangement benefits from the extensibility and interoperability of web3 technologies, with potential applications in the broader digital ecosystem. This zero-trust staking mechanism aims to serve users who desire increased privacy, trust, and flexibility in managing their digital wealth, while promoting greater decentralization and transparency in the PoS ecosystem.
Abstract Blockchain-enabled cold-chain logistics system (BCCLS) has well solved the centralized problem in traditional systems. However, along with that different logistics entities establish their own distributed blockchain ledger, which brings new “data island” and privacy leakage problems for BCCLS. In this paper, a transaction ring signing model with a multi-chain fusion mechanism has been introduced first which helps to achieve secure cross-chain data sharing. Meanwhile, a ring signature (RS) scheme is proposed with lattice assumption, which can protect the user privacy and cross-chain transactions. The lattice hard problem improves the anti-quantum security of the transaction ring signing model. Then, the security proof has been executed with random oracle model, and the results show that this RS scheme can get anonymity under full key exposure and unforgeability under insider attack. The efficiency comparison and performance evaluation show the efficiency and practical of the proposed multi-chain fusion model and RS scheme.
Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Alpesh Bhudia, Anna Cartwright, Edward Cartwright, Darren Hurley-Smith · 5 authors
Consensus algorithms facilitate agreement on and resolution of blockchain functions, such as smart contracts and transactions. Ethereum uses a Proof-of-Stake (PoS) consensus mechanism, which depends on financial incentives to ensure that validators perform certain duties and do not act maliciously. Should a validator attempt to defraud the system, legitimate validators will identify this and then staked cryptocurrency is `burned' through a process of slashing. In this paper, we show that an attacker who has compromised a set of validators could threaten to perform malicious actions that would result in slashing and thus, hold those validators to ransom. We use game theory to study how an attacker can coerce payment from a victim, for example by deploying a smart contract to provide a root of trust shared between attacker and victim during the extortion process. Our game theoretic model finds that it is in the interests of the validators to fully pay the ransom due to a lack of systemic protections for validators. Financial risk is solely placed on the victim during such an attack, with no mitigations available to them aside from capitulation (payment of ransom) in many scenarios. Such attacks could be disruptive to Ethereum and, likely, to many other PoS networks, if public trust in the validator system is eroded. We also discuss and evaluate potential mitigation measures arising from our analysis of the game theoretic model.
Electronic voting systems have the potential to improve the efficiency and accessibility of elections, but they also introduce unique challenges in terms of security, privacy, and voter anonymity. In this paper, we propose a secure and privacy-preserving voting system based on zero-knowledge proofs and homomorphic encryption. Our system ensures the integrity, confidentiality, and authenticity of votes while preserving the anonymity of voters. We present the system architecture, design, and implementation, along with a detailed analysis of the cryptographic techniques employed. The evaluation of our proposed system demonstrates its effectiveness, efficiency, and scalability, making it suitable for use in large-scale elections. This work contributes to the ongoing efforts to develop more secure, transparent, and accessible electronic voting systems for the future.
As a promising paradigm of distributed learning, federated learning has garnered considerable attention since its emergence. However, traditional federated learning solutions based on a central server are not efficient and scalable. Moreover, the centralized design relies on a trustworthy party coordinating participants. This also leads to trust and reliability issues, such as a compromised central server or a single-point failure. To address this issue, blockchain-based federated learning has been proposed as a decentralized variant. Blockchain-based decentralized federated learning seems promising. However, a new attack surface appears. Because blockchain records each transaction on a public ledger, all peers can obtain a legal copy of the local model of each participant, severely violating the privacy and interests of the participants. Challenged by this dilemma, we provide an alternative design for secure federated learning in a decentralized way, addressing data confidentiality and fairness issues simultaneously. Unlike previous studies, we construct a produce-and-consume model for parameter aggregation on a blockchain, auditing the behavior of participants in case of free-riding and false-reporting attacks. Furthermore, we design a consensus protocol called APoS, which provides an incentive and review mechanism and enforces honest training of federated learning participants.
Decentralized identity frameworks grant users full sovereignty over their digital assets in the Web3 ecosystem. However, allowing arbitrary creation of identifiers makes the system susceptible to Sybil attacks and puts assets at risk when keys are lost or compromised. Moreover, the lack of identification prevents anonymous credential schemes from deterring malicious transfers. While existing solutions attempt to address these issues by linking identifiers to entities through trusted intermediaries, these entities are not always accessible and require costly offline interactions. In this work, we introduce LinkDID, a decentralized identity scheme offering Sybil resistance, trustless key recovery, and nontransferable anonymous credentials. LinkDID creates blockchainbased bindings between identifiers and gradually combines identifiers belonging to the same holder into a unified associated identifier. As all identifiers within an association are presumed to belong to one individual, any fraudulent activity can be detected. The association grows larger as interactions increase, substantially reducing the likelihood of successful Sybil attacks. This mechanism allows holders to recover identifiers with lost or stolen keys by proving knowledge of specific association structures. Additionally, LinkDID prevents unauthorized transfers through blockchain-based identifier-key bindings and proofs of ownership for credentials. The evaluation shows that LinkDID effectively achieves progressive Sybil resistance while surpassing state-of-the-art anonymous credential schemes, achieving identifier association and credential presentation times of 2.41s and 3.31s on consumer-grade devices.
Zhijian Liu, Zihan Shen, Hongfei Wang, Qianjia Zou
With the increasing amount and trading volume, account security has become an issue that people have to consider. The security of Ethereum is discussed in four different aspects. This paper reviews the application of cryptography in Ethereum, including the importance of relevant hash algorithms and digital signature techniques for securing data. The basic structure of the Merkle Tree and the role of its modified data structure, performed in the security mechanism of Ethereum are also analyzed. This paper also analyzes the related Merkle Proof algorithm. Additionally, the definition and working mechanism of Gas in Ethereum are also provided, through which the operating mechanism and creation method of Gas can guarantee the security of Ethereum's processing power. Finally, this paper indicates the underlying vulnerabilities and possible attacks on Bitcoin and Ethereum, including double spending attacks under proof of work and further introduces the related solutions. This paper can provide researchers good references on Ethereum security problem.
Zero-knowledge proof is emerging to enable privacy. Among existing techniques, zk-SNARK (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) [1] supports the shortest verification time and the smallest proof size. However, using zk-SNARK requires the execution of trusted setup ceremony in advance. The trusted setup ceremony generates common reference string (CRS) which is shared with prover and verifier. Currently, an external trusted third party is assumed for trusted setup ceremony, which causes significant security vulnerability in zk-SNARK. In this paper, we propose a blockchain-based protocol of trusted setup ceremony without trusted third party. Three different types of protocols are classified in terms of where to store CRS and how to validate CRS through pairing check. We analyze the protocol complexity of CRS pairing check computations and on-chain storage space.
Tahiry Rabehaja, Shantanu Pal, Ambrose Hill, Michael Hitchens
The use of parametric insurance is promising as its payouts can be directly tied to hazard indicators and thus provide a fast-tracked claim-to-payout process, which improves liquidity in times of disaster. In parametric insurance, policies are determined by a loss threshold (modelled or sustained) or physical hazard severity (e.g., rainfall or wind speed). In the latter, when the severity of the hazard exceeds a threshold, a payout is automatically triggered according to the insurance contract terms to compensate the policyholder without needing a loss assessment. Recently, blockchains have been proposed to improve the efficiency of insurance product offerings (e.g., to cut administrative costs associated with the premium collection and claim processing) and to efficiently store and maintain information (e.g., immutable distributed storage for audits). While parametric insurance would certainly benefit from these blockchain implementations, existing proposals mostly depend on a single source of truth for payout calculations. In this paper, we present a novel trust-based framework to handle multiple sources of truth in parametric insurance products which use blockchain technology. This framework alleviates the reliance on a single point of failure (either through accidents or malicious abuses) and outperforms its statistical counterparts. We discuss how parametric insurance would work under such a framework using real-world use-case scenarios, show the use of subjective logic to reason about multiple sources of truth, present the architecture of the framework, and examine a detailed blockchain-based implementation using an Ethereum private blockchain. Our results show the feasibility of the proposed system in practice.
Location-based services are at the heart of many applications that individuals use every day. However, there is often no guarantee of the truthfulness of users’ location data, since this information can be easily spoofed without a proof mechanism. In distributed system applications, preventing users from submitting counterfeit locations becomes even more challenging because of the lack of a central authority that monitors data provenance. In this work, we propose a decentralized architecture based on blockchains and decentralized technologies, offering a transparent solution for Proof of Location (PoL). We specifically address two main challenges, i.e., the issuing process of the PoL and the proof verification. We describe a smart contract based implementation in Reach, a blockchain-agnostic smart contract language, and the tests we conducted on different blockchains, i.e. Ethereum, Polygon, and Algorand, measuring latency and costs due to the payment of fees. Results confirm the viability of the proposal.
We exploit the idea of [Fen22] which proposes to build an efficient signature scheme based on a zero-knowledge proof of knowledge of a solution of a MinRank instance. The scheme uses the MPCitH paradigm, which is an efficient way to build ZK proofs. We combine this idea with another idea, the hypercube technique introduced in [AMGH+22], which leads to more efficient MPCitH-based scheme. This new approach is more efficient than classical MPCitH, as it allows to reduce the number of party computation. This gives us a first scheme called MIRA-Additive. We then present an other scheme, based on low-threshold secret sharings, called MIRA-Threshold, which is a faster scheme, at the price of larger signatures. The construction of MPCitH using threshold secret sharing is detailed in [FR22]. These two constructions allows us to be faster than classical MPCitH, with a size of signature around 5.6kB with MIRA-Additive, and 8.3kB with MIRA-Threshold. We detail here the constructions and optimizations of the schemes, as well as their security proofs.
We present a signature scheme based on the Syndrome-Decoding problem in rank metric. It is a construction from multi-party computation (MPC), using a MPC protocol which is a slight improvement of the linearized-polynomial protocol used in [Fen22], allowing to obtain a zero-knowledge proof thanks to the MPCitH paradigm. We design two different zero-knowledge proofs exploiting this paradigm: the first, which reaches the lower communication costs, relies on additive secret sharings and uses the hypercube technique [AMGH+22]; and the second relies on low-threshold linear secret sharings as proposed in [FR22]. These proofs of knowledge are transformed into signature schemes thanks to the Fiat-Shamir heuristic [FS86].
Ke Yuan, Haowen Cao, Suya Zhang, Chenxu Zhai · 6 authors
Many time-sensitive scenarios need to decrypt data at a specified time. The timed-release encryption (TRE) primitive can meet this requirement. However, in the single-time server TRE model, there is a single point of failure problem. Therefore, we propose a tamper-resistant timed secure data transmission protocol based on smart contracts. Firstly, by decomposing the ciphertext into ciphertext fragments, the amount of deposit that a single middleman needs to submit is reduced. Secondly, it provides the system with security redundancy that changes with the decomposition mode. Thirdly, the sender is required to submit the hash value of each ciphertext fragment to the blockchain network at the same time as sending data, so that the receiver can quickly verify the authenticity of the ciphertext to resist substitution attack. Security analysis shows that the proposed protocol model can resist interruption attacks, release-ahead attacks and replacement attacks. Finally, we conduct a monetary cost test on the Ethereum's Rinkeby test network. The results show that our running cost is almost double compared with the existing similar scheme, but it is still very low and almost negligible compared with the value of the content and the expected profits it brings.
Gyu Chol Kim, Gang Han, Ryong Chol Kim, Yong Bok Jong · 7 authors
We propose a single-tiered hybrid proof-of-work consensus protocol to encourage decentralization in bitcoin. Our new mechanism comprises coupled puzzles from which properties differ from each other; the one is the extant outsourceable bitcoin puzzle while the other is nonoutsourceable. Our new protocol enables miners to solve either puzzle as they want; therefore, blocks can be generated by either puzzle. Our hybrid consensus can be successfully implemented in bitcoin because it is backward-compatible with existing bitcoin mining equipment (more precisely, existing bitcoin mining ASICs).
Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Jesús García-Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio Skármeta
PREPRINT: The increasing user awareness and regulatory framework (e.g., GDPR) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems.<br> Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data.<br> Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by formalizing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations.