The blockchain provides a reliable and scalable method for enabling source-tracing functionality in large-scale Internet of Things (IoT) systems. Traditional blockchain-based source tracing applications are generally based on the hypothesis that the raw data collected by each IoT node are credible and consistent, which however may not always be the truth. As no mechanism ensures the reliability of the original data collected from the IoT devices, these data may be accidently screwed up or maliciously tampered with before they are uploaded on-chain. To address this issue, we propose the Multi-dimensional Certificates of Origin (MCO) method to filter out the potentially incredible data-till all the data uploaded to the chain are credible. To achieve this, we devise the Multi-dimensional Information Cross-Verification (MICV) and Multi-source Data Matching Calculation (MDMC) methods. MICV verifies whether a to-be-uploaded datum is consistent or credible, and MDMC determines which data should be discarded and which data should be kept to retain the most likely credible/untampered ones in the circumstance when data inconsistency appears. Large-scale experiments show that our scheme ensures on the credibility of data and off the chain with an affordable overhead.
In recent years, blockchain networks have attracted significant attention in many research areas beyond cryptocurrency, one of them being the Edge of Things (EoT) that is enabled by the combination of edge computing and the Internet of Things (IoT). In this context, blockchain networks enabled with unique features, such as decentralization, immutability, and traceability, have the potential to reshape and transform the conventional EoT systems with higher security levels. Particularly, the convergence of blockchain and EoT leads to a new paradigm, calledBEoTthat has been regarded as a promising enabler for future services and applications. In this article, we present a state-of-the-art review of recent developments in the BEoT technology and discover its great opportunities in many application domains. We start our survey by providing an updated introduction to blockchain and EoT along with their recent advances. Subsequently, we discuss the use of BEoT in a wide range of industrial applications, from smart transportation, smart city, smart healthcare to smart home, and smart grid. Security challenges in the BEoT paradigm are also discussed and analyzed, with some key services, such as access authentication, data privacy preservation, attack detection, and trust management. Finally, some key research challenges and future directions are also highlighted to instigate further research in this promising area.
Jesús García-Rodríguez, Rafael Torres Moreno, Jorge Bernal Bernabé, Antonio Skármeta
Despite the latest efforts to foster the adoption of privacy-enhancing Attribute-Based Credential (p-ABC) systems in electronic services, those systems are not yet broadly adopted. The main reasons behind this are performance efficiency issues, lack of interoperability with standards, and the centralized architectural scheme that relies on a unique Identity Provider (IdP) for credential issuance. To cope with these limitations, this paper describes the first implementation of the Pointcheval–Sanders Multi-Signatures (PS-MS) crypto scheme proposed by Camenisch et al. and its integration in a distributed and privacy-preserving identity management system proposed in OLYMPUS H2020 European research project. Our efficient implementation provides remarkable privacy-preservation features for identity management in online transactions leveraging p-ABC systems, including unforgeability, minimal disclosure of personal data through zero-knowledge proofs, unlinkability in online transactions and fully distributed credential issuance across different IdPs, thereby removing the IdP as a unique point of failure. The performance of the implementation has been exhaustively analyzed and evaluated with different curves, signers and number of attributes, and compared against Identity Mixer, the best known p-ABC system, outperforming significantly the credential issuance and zero-knowledge proving and verification processes (2–4 times less execution time).
The wealth of user data acts as a fuel for network intelligence toward the sixth generation wireless networks (6G). Due to data heterogeneity and dynamics, decentralized data management (DM) is desirable for achieving transparent data operations across network domains, and blockchain can be a promising solution. However, the increasing data volume and stringent data privacy-preservation requirements in 6G bring significantly technical challenge to balance transparency, efficiency, and privacy requirements in decentralized blockchain-based DM. In this paper, we investigate blockchain solutions to address the challenge. First, we explore the consensus protocols and scalability mechanisms in blockchains and discuss the roles of DM stakeholders in blockchain architectures. Second, we investigate the authentication and authorization requirements for DM stakeholders. Third, we categorize DM privacy requirements and study blockchain-based mechanisms for collaborative data processing. Subsequently, we present research issues and potential solutions for blockchain-based DM toward 6G from these three perspectives. Finally, we conclude this paper and discuss future research directions.
Beatriz Soret, Lam Duc Nguyen, Jan Seeger, Arne Bröring · 10 authors
An Intelligent IoT Environment (iIoTe) is comprised of heterogeneous devices that can collaboratively execute semi-autonomous IoT applications, examples of which include highly automated manufacturing cells or autonomously interacting harvesting machines. Energy efficiency is key in such edge environments, since they are often based on an infrastructure that consists of wireless and battery-run devices, e.g., e-tractors, drones, Automated Guided Vehicle (AGV)s and robots. The total energy consumption draws contributions from multiple iIoTe technologies that enable edge computing and communication, distributed learning, as well as distributed ledgers and smart contracts. This paper provides a state-of-the-art overview of these technologies and illustrates their functionality and performance, with special attention to the tradeoff among resources, latency, privacy and energy consumption. Finally, the paper provides a vision for integrating these enabling technologies in energy-efficient iIoTe and a roadmap to address the open research challenges.
Abstract This chapter first introduces the fundamental principles of blockchain and the integration of blockchain and mobile edge computing (MEC). Blockchain is a distributed ledger technology with a few desirable security characteristics. The integration of blockchain and MEC can improve the security of current MEC systems and provide greater performance benefits in terms of better decentralization, security, privacy, and service efficiency. Then, the convergence of artificial intelligence (AI) and MEC is presented. A federated learning–empowered MEC architecture is introduced. To improve the performance of the proposed scheme, asynchronous federated learning is proposed. The integration of blockchain and federated learning is also presented to enhance the security and privacy of the federated learning–empowered MEC scheme. Finally, more MEC enabled applications are discussed.
Since its introduction, Bitcoin has received extensive attentions. With features like privacy and anonymity, Bitcoin has been widely used. However, the mainstream finance and business worlds have not fully embraced Bitcoin yet. This study analyzes the assumption of anonymity and privacy of Bitcoin, give a threat model to Bitcoin privacy. Then present a comprehensive overview on practical attacks on anonymity and privacy of Bitcoin and proposals to improve anonymity of Bitcoin. Compare the state of-the-art proposals that address the privacy threats and enables strong privacy in Bitcoin. Finally, future research directions on privacy of Bitcoin are discussed.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Sajad Meisami, Mohammad Beheshti Atashgah, Mohammad Reza Aref
With the advent of the Internet of Things (IoT), e-health has become one of the main topics of research. Due to the sensitivity of patient information, patient privacy seems challenging. Nowadays, patient data is usually stored in the cloud in healthcare programs, making it difficult for users to have enough control over their data. The recent increment in announced cases of security and surveillance breaches compromising patients' privacy call into question the conventional model, in which third-parties gather and control immense amounts of patients' Healthcare data. In this work, we try to resolve the issues mentioned above by using blockchain technology. We propose a blockchain-based protocol suitable for e-health applications that does not require trust in a third party and provides an efficient privacy-preserving access control mechanism. Transactions in our proposed system, unlike Bitcoin, are not entirely financial, and we do not use conventional methods for consensus operations in blockchain like Proof of Work (PoW). It is not suitable for IoT applications because IoT devices have resources-constraints. Usage of appropriate consensus method helps us to increase network security and efficiency, as well as reducing network cost, i.e., bandwidth and processor usage. Finally, we provide security and privacy analysis of our proposed protocol.
Poonam N. Railkar, Parikshit N. Mahalle, Gitanjali R. Shinde
IoT is a network of interconnected heterogeneous devices which sense, accumulate the data and forward the same to the cloud platform for analytical purposes. There are various IoT verticals in which huge research is going on. IoT security is the most challenging research area in which researchers are investing a huge number of efforts. The challenges in IoT security include access control, trust management, authentication, authorization, privacy, and secured device to device communication. To overcome these, this paper gives an overview of proposed trust based distributed access control approach in IoT. Some of the challenges and threats can be controlled by blockchain technology. Basically, blockchain is an open and distributed ledger of records that can be verified efficiently and stored permanently. This paper checks the feasibility study of the applicability of blockchain in the IoT ecosystem to apply access control mechanism and privacy-preserving policies. This paper discusses how access control and privacy can be addressed by blockchain without compromising security. This paper consists of rigorous gap analysis which is done on the top of comprehensive literature survey. The paper also addresses the challenges and issues which can be faced while applying access control mechanism using blockchain in the context of IoT.
Nur Arifin Akbar, Andi Sunyoto, M. Rudyanto Arief, Wahyu Caesarendra
Today, there is a tendency to reduce the dependence on local computation in favor of cloud computing. However, this inadvertently increases the reliance upon distributed fault-tolerant systems. In a condition that forced to work together, these systems often need to reach an agreement on some state or task, and possibly even in the presence of some misbehaving Byzantine nodes. Although non-trivial, Byzantine Agreement (BA) protocols now exist that are resilient to these types of faults. However, there is still a risk for inconsistencies in the application state in practice, even if a BA protocol is used. A single transient fault may put a node into an illegal state, creating a need for new self-stabilizing BA protocols to recover from illegal states. As self-stabilization often comes with a cost, primarily in the form of communication overhead, a potential lowering of latency - the cost of each message - could significantly impact how fast the protocol behaves overall. Thereby, there is a need for new network protocols such as QUIC, which, among other things, aims to reduce latency. In this paper, we survey current state-of-the-art agreement protocols. Based on previous work, some researchers try to implement pseudocode like QUIC protocol for Ethereum blockchain to have a secure network, resulting in slightly slower performance than the IP-based blockchain. We focus on consensus in the context of blockchain as it has prompted the development and usage of new open-source BA solutions that are related to proof of stake. We also discuss extensions to some of these protocols, specifically the possibility of achieving self-stabilization and the potential integration of the QUIC protocol, such as PoS and PBFT. Finally, further challenges faced in the field and how they might be overcome are discussed.
In known constructions of classical zero-knowledge protocols for NP, either of zero-knowledge or soundness holds only against computationally bounded adversaries. Indeed, achieving both statistical zero-knowledge and statistical soundness at the same time with classical verifier is impossible for NP unless the polynomial-time hierarchy collapses, and it is also believed to be impossible even with a quantum verifier. In this work, we introduce a novel compromise, which we call the certified everlasting zero-knowledge proof for QMA. It is a computational zero-knowledge proof for QMA, but the verifier issues a classical certificate that shows that the verifier has deleted its quantum information. If the certificate is valid, even unbounded malicious verifier can no longer learn anything beyond the validity of the statement. We construct a certified everlasting zero-knowledge proof for QMA. For the construction, we introduce a new quantum cryptographic primitive, which we call commitment with statistical binding and certified everlasting hiding, where the hiding property becomes statistical once the receiver has issued a valid certificate that shows that the receiver has deleted the committed information. We construct commitment with statistical binding and certified everlasting hiding from quantum encryption with certified deletion by Broadbent and Islam [TCC 2020] (in a black box way), and then combine it with the quantum sigma-protocol for QMA by Broadbent and Grilo [FOCS 2020] to construct the certified everlasting zero-knowledge proof for QMA. Our constructions are secure in the quantum random oracle model. Commitment with statistical binding and certified everlasting hiding itself is of independent interest, and there will be many other useful applications beyond zero-knowledge.
Ruonan Wang, Min Luo, Yihong Wen, Lianhai Wang · 6 authors
There has been increased interest in applying artificial intelligence (AI) in various settings to inform decision-making and facilitate predictive analytics. In recent times, there have also been attempts to utilize blockchain (a peer-to-peer distributed system) to facilitate AI applications, for example, in secure data sharing (for model training), preserving data privacy, and supporting trusted AI decision and decentralized AI. Hence, in this paper, we perform a comprehensive review of how blockchain can benefit AI from these four aspects. Our analysis of 27 English-language articles published between 2018 and 2021 identifies a number of research challenges and opportunities.
Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Artificial Intelligence in Healthcare and Education
Paulo Valente Klaine, Lei Zhang, Muhammad Ali Imran
Nowadays data is one of the most important assets that can be obtained, as many applications rely on data to generate useful services. However, a very few number of companies control, in a centralized manner, a large portion of data. That, combined with inefficiencies in centralized storage and recent data leak scandals, highlights the need for new ways in which data is shared and consumed, in which privacy and access control is guaranteed by design. Based on that, in this paper we present an implementation of a blockchain-based data marketplace utilizing the Go Ethereum (Geth) library. The implementation consists of an IoT node powered by a raspberry pi zero W, which is utilized to collect data from the environment and store it in an InterPlanetary File System (IPFS) external server, a web page that displays the marketplace, and a private blockchain that records transactions. Regarding the private blockchain, three smart contracts are developed in order to: 1) record information about the data in the marketplace; 2) record transactions that occur between users; 3) allow sellers to white/blacklist buyers' access to the data. This implementation shows that a decentralized blockchain-based marketplace is feasible and scalable, and we hope it can serve as an early model for future frameworks.
The IoT devices deployed in various application scenarios will generate massive data with immeasurable value every day. These data often contain the user’s personal privacy information, so there is an imperative need to guarantee the reliability and security of IoT data sharing. We proposed a new encrypted data storing and sharing architecture by combining proxy re-encryption with blockchain technology. The consensus mechanism based on threshold proxy re-encryption eliminates dependence on the third-party central service providers. Multiple consensus nodes in the blockchain network act as proxy service nodes to re-encrypt data and combine converted ciphertext, and personal information will not be disclosed in the whole procedure. That eliminates the restrictions of using decentralized network to store and distribute private encrypted data safely. We implemented a lot of simulated experiments to evaluate the performance of the proposed framework. The results show that the proposed architecture can meet the extensive data access demands and increase a tolerable time latency. Our scheme is one of the essays to utilize the threshold proxy re-encryption and blockchain consensus algorithm to support IoT data sharing.
Recently, with the great development of e-health, more and more countries have made certain achievements in the field of electronic medical treatment. The digitization of medical equipment and the structuralization of electronic medical records are the general trends. While bringing convenience to people, the explosive growth of medical data will further promote the value of mining medical data. Obviously, finding out how to safely store such a large amount of data is a problem that urgently needs to be solved. Additionally, the particularity of medical data makes it necessarily subject to great privacy protection needs. This reinforces the importance of designing a safe solution to ensure data privacy. Many existing schemes are based on single-server architecture, which have some natural defects (such as single-point faults). Although blockchain can help solve such problems, there are still some deficiencies in privacy protection. To solve these problems, this paper designs a medical data privacy protection system, which integrates blockchain, group signature, and asymmetric encryption to realize reliable medical data sharing between medical institutions and protect the data privacy of patients. This paper proves theoretically that it meets our security and privacy requirements, and proves its practicability through system implementation.
In mobile crowdsensing (MCS), sensing data uploaded by dishonest workers may be false or even malicious. Thus, a reputation management system is often set up by using workers’ historical behaviors to indicate the quality of sensing data. As existing management schemes usually protect the reputation update process, reputation scores are generally stored in plaintext, which may destroy the fair bidding property of an MCS system. To address this issue, we propose an anonymous reputation management system based on the dual blockchain architecture, where reputation scores are masked. More precisely, one chain is used to store and update reputation scores, and another chain is responsible for publishing tasks and storing task-related data. To anonymously update and verify the reputation scores without affecting their usages in data sensing process, a kind of ring signature and Pedersen commitment is employed in smart contracts. In addition, a Schnorr signature is generated to make the reputation scores verifiable in the MCS system. We implement a prototype system on Hyperledger Fabric, and simulation results are provided for comparisons with two existing schemes.
Shahzaib Tahir, Hasan Tahir, Ali Sajjad, Muttukrishnan Rajarajan · 5 authors
The outbreak of the COVID-19 virus has caused widespread panic and global initiatives are geared towards treatment and limiting its spread. With technological advancements, several mechanisms and mobile applications have been developed that attempt to trace the physical contact made by a person with someone who has been tested COVID-19 positive. While designing these apps, user's privacy has been an afterthought and has resulted in mass violations of privacy of the public and the patients. A total of 32 countries have designed apps and rely on them as a strategy to flatten the pandemic curve. Along with lack of privacy, these methodologies are centralized, where they are fully controlled by the government and the healthcare providers. Owing to these and many other concerns, people are hesitant in the adoption of these technologies. This paper presents a detailed analysis of user tracking apps belonging to 32 countries, thus demonstrating that they collect personal data and are a gross violation of user privacy. This paper presents a novel architecture for the efficient, effective and privacy-preserving contact tracing of COVID-19 patients using blockchain. The proposed architecture preserves the privacy of individuals and their contact history by encrypting all the data specific to an individual using a privacy-preserving Homomorphic encryption scheme and storing it on a permissioned blockchain network. The contacts made with a COVID-19 positive patient are identified by performing search queries directly over the Homomorphic encrypted data stored in the blocks. Therefore, only those contacts that are suspected to be COVID-19 positive may be decrypted by the healthcare professional or government for further contact tracing/diagnosis and COVID-19 testing; thereby leading to enhanced privacy.
In the traditional blockchain system, data is public and cannot be redacted. With the development of blockchain technology, the problem that the data cannot be altered will be more serious once it is written on the chain. Recently, some redactable blockchain schemes have been proposed. However, most of the schemes are based on the public blockchain, and the users’ identities and transaction data may be disclosed. To solve the problem of privacy disclosure, we propose a privacy-preserving transaction-level redactable blockchain. In the proposed scheme, symmetric encryption and ring signature are used to protect transaction data and the users’ identities, respectively. In order to prove the legality of data redaction, the transaction sender can reveal the invalid users’ identities and transaction data in an anonymous environment. To construct a transaction-level redactable blockchain, the users only need to replace a single transaction to complete the data redaction instead of replacing the entire block. The experimental results show that the proposed scheme saves 20% of the redaction time compared to the previous privacy-preserving blockchains, so the redaction efficiency is higher.
Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
Yiping Zuo, Shi Jin, Shengli Zhang, Yu Han · 5 authors
The proof-of-work (PoW) mining process requires a large amount of intensive computing, which leads to some plights such as heavy equipment and fixed access nodes in traditional blockchain networks. A novel mobile blockchain network with the help of a mobile edge computing (MEC) server is presented, where all mobile users participate in the PoW mining process. The traditional Bitcoin network adjusts the target difficulty value to ensure a stable block time. However, for MEC-assisted mobile blockchain networks, the adjusted difficulty value needs to be broadcast to all mobile users, which results in expensive communication costs. To maintain a stable block time of mobile blockchain networks, we formulate the delay-limited computation offloading strategy of the PoW-based mining task as a non-cooperative game that maximizes an individual revenue in the MEC-assisted mobile blockchain network. Specifically, the non-cooperative game problem can be divided into multiple sub-game optimization problems to obtain final solutions for all users. We analyze the sub-game optimization problem and prove the existence of Nash equilibrium (NE) of the non-cooperative game. Moreover, we design an alternating iterative algorithm based on the continuous relaxation and greedy rounding (CRGR) to achieve the NE of this game. Given the sub-optimal delay-limited computation offloading results, we also derive the optimal transmit power for an individual user within the maximum mining delay range. From the analytical results, we can see that the proposed CRGR-based alternating iterative algorithm can efficiently attain the sub-optimal delay-limited computation offloading strategies of all mobile users in the polynomial time. The individual transmit power increases accordingly with the delay-limited computation offloading strategies of all users. Numerical results demonstrate that the proposed CRGR-based alternating iterative algorithm has fast convergence and good stability.
IoT technology has been widely valued and applied, and the resulting massive IoT data brings many challenges to the traditional centralized data management, such as performance, privacy, and security challenges. This paper proposes an IoT data access control scheme that combines attribute-based encryption (ABE) and blockchain technology. Symmetric encryption and ABE algorithms are utilized to realize fine-grained access control and ensure the security and openness of IoT data. Moreover, blockchain technology is combined with distributed storage to solve the storage bottleneck of blockchain systems. Only the hash values of the data, the hash values of the ciphertext location, the access control policy, and other important information are stored on the blockchain. In this scheme, smart contract is used to implement access control. The results of experiments demonstrate that the proposed scheme can effectively protect the security and privacy of IoT data and realize the secure sharing of data.
Bitcoin and many other similar Cryptocurrencies have been in existence for\nover a decade, prominently focusing on decentralized, pseudo-anonymous\nledger-based transactions. Many protocol improvements and changes have resulted\nin new variants of Cryptocurrencies that are known for their peculiar\ncharacteristics. For instance, Storjcoin is a Proof-of-Storage-based\nCryptocurrency that incentivizes its peers based on the amount of storage owned\nby them. Cryptocurrencies like Monero strive for user privacy by using\nprivacy-centric cryptographic algorithms. While Cryptocurrencies strive to\nmaintain peer transparency by making the transactions and the entire ledger\npublic, user privacy is compromised at times. Monero and many other\nprivacy-centric Cryptocurrencies have significantly improved from the original\nBitcoin protocol after several problems were found in the protocol. Most of\nthese deficiencies were related to the privacy of users. Even though Bitcoin\nclaims to have pseudo-anonymous user identities, many attacks have managed to\nsuccessfully de-anonymize users. In this paper, we present some well-known\nattacks and analysis techniques that have compromised the privacy of Bitcoin\nand many other similar Cryptocurrencies. We also analyze and study different\nprivacy-preserving algorithms and the problems these algorithms manage to\nsolve. Lastly, we touch upon the ethics, impact, legality, and acceptance of\nimposing these privacy algorithms.\n
Philipp Winter, Anna Harbluk Lorimer, Peter Snyder, Benjamin Livshits
Much of the recent excitement around decentralized finance (DeFi) comes from hopes that DeFi can be a secure, private, less centralized alternative to traditional finance systems but the accuracy of these hopes has to date been understudied; people moving to DeFi sites to improve their privacy and security may actually end up with less of both.
In this work, we improve the state of DeFi by conducting the first measurement of the privacy and security properties of popular DeFi applications. We find that DeFi applications suffer from the same kinds of privacy and security risks that frequent other parts of the Web. For example, we find that one common tracker has the ability to record Ethereum addresses on over 56% of websites analyzed. Further, we find that many trackers on DeFi sites can trivially link a user's Ethereum address with PII (e.g., name or demographic information) or phish users.
This work also proposes remedies to the vulnerabilities we identify, in the form of improvements to the most common cryptocurrency wallet. Our wallet modification replaces the user's real Ethereum address with site-specific addresses, making it harder for DeFi sites and third parties to (i) learn the user's real address and (ii) track them across sites.
Message exchange among vehicles plays an important role in ensuring road safety. Emergency message dissemination is usually carried out by broadcasting. However, high vehicle density and mobility lead to challenges in message dissemination such as broadcasting storm and low probability of packet reception. This paper proposes a federated learning based blockchain-assisted message dissemination solution. Similar to the incentive-based Proof-of-Work consensus in blockchain, vehicles compete to become a relay node (miner) by processing the proposed Proof-of-Federated-Learning (PoFL) consensus which is embedded in the smart contract of blockchain. Both theoretical and practical analysis of the proposed solution are provided. Specifically, the proposed blockchain based federated learning results in more vehicles uploading their models in a given time, which can potentially lead to a more accurate model in less time as compared to the same solution without using blockchain. It also outperforms other blockchain approaches in reducing 65.2% of time delay in consensus, improving at least 8.2% message delivery rate and preserving privacy of neighbor vehicle more efficiently. The economic model to incentivize vehicles participating in federated learning and message dissemination is further analyzed using Stackelberg game. The analysis of asymptotic complexity proves PoFL as the most scalable solution compared to other consensus algorithms in vehicular networks.