Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

449 papersLast indexed Aug 31, 2026
Search papers

Paper index

449 results · page 7 of 19

Clear filters
Nov 7, 2023·Cluster Computing
26 cites
Blockchain-based biometric identity management

Sherif Hamdy Gomaa Salem, Ashraf Yehia Hassan, Marwa S. Moustafa, Mohamed Nabil Hassan

Abstract In recent years, face biometrics recognition systems are a wide space of a computer usage which is mostly employed for security purpose. The main purpose of the face biometrics recognition system is to authenticate a user from a given database. Due to the widespread expansion of the surveillance cameras and facial recognition technology, a robust face recognition system required. The recognition system needs to store a large number of training samples in any storage unit, that time hackers can access and control that data. So, Protecting and managing sensitive data is essential object. This requires a technique that preserve the privacy of individuals, maintain data integrity, and prevent information leakage. The storage of biometric templates on centralized servers has been associated with potential privacy risks. To address this issue, we have developed and implemented a proof-of-concept facial biometric identification system that uses a private Blockchain platform and smart contract technology. So, the proposed approach is presented a secure and tamper-proof from data breaches as well as hacks with data availability, by using the Blockchain platform to store face images. This paper aims to utilize Blockchain technology to identify individuals based on their biometric traits, specifically facial recognition system makes it tamper-proof (immutable) ensuring security. The system consists of enrolment and authentication phases. Blockchain technology uses peer-to-peer communication, cryptography, consensus processes, and smart contracts to ensure the security. The proposed approach was tested on two popular datasets: CelebFaces Attributes (CelebA) and large-scale face UTKFace datasets. The experimental results indicate that the system yields highly performance outcomes, as evidenced by the Equal Error Rate (EER) values of 0.05% and 0.07% obtained for the CelebA and UTKFace datasets, respectively. The system was compared to three baseline methods and scored the lowest Equal Error Rate.

Open access
Face recognition and analysis
Biometric Identification and Security
User Authentication and Security Systems
Original source
Nov 3, 2023·Proceedings of the 6th International Conference on Information Technologies and Electrical Engineering
2 cites
Consent Management System Based on User Data Security and Privacy Using Hyperledger Fabric Blockchain

Faisal Mehmood, Umara Khalid, Shahid Karim

The challenge of safeguarding user data privacy becomes pronounced when private data is outsourced to cloud services, potentially exposing it to unauthorized access. The challenge of centralized storage of user data introduces heightened security risks and a dependence on a single authority, posing difficulties in safeguarding against internal breaches. This study is dedicated to advancing user privacy and data security, especially in scenarios involving the sharing of sensitive information within or across organizations, including small enterprises functioning in a distributed environment. The research introduces a consent management framework built on Blockchain technology, with a particular focus on user consent management. This framework is designed to prioritize the principles of privacy, security, scalability, and data integrity. It utilizes Hyperledger Fabric which is a permissioned distributed ledger solution, and incorporates Hyperledger Composer to establish and maintain a secure record of user data. To enhance the security of stored data, the framework incorporates the Interplanetary File System (IPFS) and employs a unique cryptographic public key encryption algorithm for data encryption. The overarching aim of this research is to establish a robust security solutions foundation against cyber threats by harnessing the inherent capabilities of blockchain technology, ultimately strengthening the security landscape for sharing user information.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
User Authentication and Security Systems
Original source
Nov 1, 2023·IEEE Transactions on Consumer Electronics
30 cites
A Secure Architectural Model Using Blockchain and Estimated Trust Mechanism in Electronic Consumers

Akshay Kumar, Geetanjali Rathee, Chaker Abdelaziz Kerrache, Muhammad Bilal · 5 authors

Consumer electronics devices, such as refrigerators, washing machines, TVs, smartphones, and household appliances, have become integral to human activities. However, these devices are vulnerable to security breaches and cyber-criminal threats, which can result in the theft and misuse of sensitive information. Existing security surveys and proposed schemes have encountered limitations in terms of redundancy and effectiveness. In this paper, we present a novel approach that ensures secure and transparent communication in consumer electronics. We introduce a multi-criterion decision-making model called TOPSIS, along with a weighted product model, to enhance the security and accuracy of the system. Furthermore, our proposed scheme employs a blockchain system for continuous tracking and monitoring of devices, ensuring accountability and surveillance of their past communications. Through comprehensive validation and verification against existing approaches using various security metrics, our proposed scheme demonstrates superior performance and effectiveness.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Malware Detection Techniques
Original source
Oct 30, 2023·arXiv (Cornell University)
0 cites
Incorporating Zero-Knowledge Succinct Non-interactive Argument of Knowledge for Blockchain-based Identity Management with off-chain computations

Pranay Kothari, Deepak Chopra, Manjot Singh, Shivam Bhardwaj · 5 authors

In today's world, secure and efficient biometric authentication is of keen importance. Traditional authentication methods are no longer considered reliable due to their susceptibility to cyber-attacks. Biometric authentication, particularly fingerprint authentication, has emerged as a promising alternative, but it raises concerns about the storage and use of biometric data, as well as centralized storage, which could make it vulnerable to cyber-attacks. In this paper, a novel blockchain-based fingerprint authentication system is proposed that integrates zk-SNARKs, which are zero-knowledge proofs that enable secure and efficient authentication without revealing sensitive biometric information. A KNN-based approach on the FVC2002, FVC2004 and FVC2006 datasets is used to generate a cancelable template for secure, faster, and robust biometric registration and authentication which is stored using the Interplanetary File System. The proposed approach provides an average accuracy of 99.01%, 98.97% and 98.52% over the FVC2002, FVC2004 and FVC2006 datasets respectively for fingerprint authentication. Incorporation of zk-SNARK facilitates smaller proof size. Overall, the proposed method has the potential to provide a secure and efficient solution for blockchain-based identity management.

Open access
3 source records
cs.CR
Biometric Identification and Security
User Authentication and Security Systems
Original source
Oct 27, 2023·Proceedings of the 2023 4th Asia Service Sciences and Software Engineering Conference
0 cites
Humanode: The First Crypto-Biometric Network

Dato Kavazi, Victor Smirnov, Sasha Shilina, Jonathan Shomroni · 7 authors

We present a novel 1 Human = 1 Node blockchain protocol which aims to overcome problems arising from plutocratic principles upon which Proof-of-Work (PoW) and Proof-of-Stake (PoS) heavily rely on. The advent of blockchain technology has led to a massive wave of different decentralized ledger technology (DLT) solutions. Projects such as Bitcoin and Ethereum managed to shift the paradigm of how to transact value in a decentralized manner, yet their core technologies give rise to a significant early adopters’ control bias and have led to financial systems flawed by massive inequality and centralization of power. In this paper we propose an alternative to modern decentralized financial networks by introducing the Humanode network. Humanode is a network safeguarded by cryptographically secure bio-authorized nodes on which users are able to deploy nodes by staking their encrypted biometric data. This approach can potentially lead to the creation of a truly public, permissionless financial network, based on consensus between equal human nodes with algorithmic emission mechanisms targeting real value growth and contribution-based wealth distribution.

Open access
Biometric Identification and Security
User Authentication and Security Systems
Chaos-based Image/Signal Encryption
Original source
Oct 24, 2023·2023 Fifth International Conference on Blockchain Computing and Applications (BCCA)
8 cites
Secure and Decentralized Generation of Secret Random Numbers on the Blockchain

Pouria Fatemi, Amir Kafshdar Goharshady

We propose a trustless blockchain-based protocol for secure and decentralized generation of secret random numbers. In our protocol, which can be implemented as a smart contract, a client Cassie can ask for a secret random number$r$. The protocol will then allow anyone on the blockchain network to contribute to the process of generating$r$, but crucially, only Cassie would be able to see the final result. Additionally, our approach is auditable, i.e. if Cassie later wishes to announce her secret random number$r$, she can prove that the output of the process was indeed the claimed value. Finally, we ensure no one else is able to deduce$r$before Cassiediscloses it. A primary use-case of this approach is to enable auditable online gambling and casinos with verifiable and tamper-proof randomness. If Cassie is a casino, she can ask for a secret random number$r$at the beginning of the day, and then use it as a seed in a predefined pseudo-random number generator which is in turn used as the source of randomness for all bets during the day. At the end of the day, Cassie can prove that the seed was indeed generated by our decentralized protocol. Thus, she can prove that the casino had no control over the outcomes of the bets. Moreover, this is a cost- and time-efficient approach as it does not require us to generate a new random number for every bet.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
User Authentication and Security Systems
Original source
Oct 20, 2023·Journal of Computing and Information Science in Engineering
13 cites
Sensor Data Protection Through Integration of Blockchain and Camouflaged Encryption in Cyber-Physical Manufacturing Systems

Zhangyue Shi, Boris Oskolkov, Wenmeng Tian, Kan Chen · 5 authors

Abstract The advancement of sensing technology enables efficient data collection from manufacturing systems for monitoring and control. Furthermore, with the rapid development of the Internet of Things (IoT) and information technologies, more and more manufacturing systems become cyber-enabled, facilitating real-time data sharing and information exchange, which significantly improves the flexibility and efficiency of manufacturing systems. However, the cyber-enabled environment may pose the collected sensor data with high risks of cyber-physical attacks during the data and information sharing. Specifically, cyber-physical attacks could target the manufacturing process and/or the data transmission process to maliciously tamper the sensor data, resulting in false alarms or failures in anomaly detection in monitoring. In addition, cyber-physical attacks may also enable illegal data access without authorization and cause the leakage of key product/process information. Therefore, it becomes critical to develop an effective approach to protect data from these attacks so that the cyber-physical security of the manufacturing systems can be assured in the cyber-enabled environment. To achieve this goal, this paper proposes an integrative blockchain-enabled data protection method by leveraging camouflaged asymmetry encryption. A real-world case study that protects the cyber-physical security of collected sensor data in additive manufacturing is presented to demonstrate the effectiveness of the proposed method. The results demonstrate that malicious tampering could be detected in a relatively short time (less than 0.05 ms), and the risk of unauthorized data access is significantly reduced as well.

Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
User Authentication and Security Systems
Original source
Oct 15, 2023·Research Explorer (The University of Manchester)
0 cites
SafeNFT Mart: A DSR Approach to a Secure NFT Marketplace

Kasthuri, Ashok, Pahuja, Aseem, Guo, Zhiling, Jiang, Lingxiao · 5 authors

NFT marketplaces have witnessed exponential growth. The unique attributes of NFTs, encapsulated by the acronym CRAVED (concealable, removable, available, valuable, enjoyable, disposable), make them susceptible to multifaceted thefts. In response, we introduce "SafeNFT Mart," an NFT marketplace architecture devised to thwart counterfeiting and uphold both asset and ownership integrity. We leverage Zero Knowledge Proofs (ZKPs) for ownership verification and integrate a stringent punishment protocol to deter illicit activities. Our design draws from the design science research (DSR) approach. Expert interviews were conducted to fortify our findings, focusing on relevance, adaptability, and technological viability in tandem with real-world and strategic implications. An initial analytical model is provided to gauge the efficacy of our punitive mechanism. This research culminates with future work, outlining the further development and refinement of the proposed marketplace solution.

Open access
Physical Unclonable Functions (PUFs) and Hardware Security
Innovative Human-Technology Interaction
User Authentication and Security Systems
Original source
Oct 13, 2023·Future Generation Computer Systems
64 cites
A scalable and lightweight group authentication framework for Internet of Medical Things using integrated blockchain and fog computing

Norah Alsaeed, Farrukh Nadeem, Faisal Albalwy

The Internet of Medical Things (IoMT) is the network of medical devices, software applications, and healthcare information systems used for remote monitoring and delivery of healthcare services. Despite the several advantages of IoMT for today smart healthcare, security issues are growing due to the inadequate computation, limited storage and insufficient self-protection capabilities of IoMT devices. Authentication of IoMT devices is the main requirement to secure IoMT systems. Although, the recent authentication schemes based on tamper-proof decentralized architecture of blockchain technology are robust and enjoy a high level of security, yet they require high computation, more storage, and long authentication time. These issues lead to reduced scalability and time efficiency, which are necessary for large-scale, time-sensitive IoMT systems. To this end, this paper proposes a novel group authentication framework for IoMT Systems. The group authentication scheme is implemented through a four-phase process, including setup, registration, secret construction, and authentication. To enhance both efficiency and scalability, the proposed group authentication framework employs a combination of elliptic curve cryptography (ECC), Shamir’s secret sharing (SSS) algorithm, and blockchain-based fog computing technologies. We simulated the proposed framework through the Ethereum platform and Solidity language and its performance is evaluated using the Hyperledger Caliper tool. The simulation experiments of the proposed framework showed that the average latency of authenticating IoMT devices was 0.5 second and the throughput was 400 transactions per second. Our analysis of the proposed framework’s performance against other cutting-edge blockchain-based authentication techniques showed that it outperformed them in terms of latency and throughput. A security analysis of the proposed framework was conducted using the widely accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The formal and informal security analysis demonstrated that the proposed framework is secure and resistant to potential authentication-related attacks. We also noted that the average latency of the proposed framework maintains a fairly narrow range when the number of submitted transactions rises, indicating that it supports the scalability of the IoMT system.

Open access
Advanced Authentication Protocols Security
User Authentication and Security Systems
Blockchain Technology Applications and Security
Original source
Oct 7, 2023·Symmetry
14 cites
Secure Registration Protocol for the Internet of Drones Using Blockchain and Physical Unclonable Function Technology

Norbert Oláh, B. Molnár, Andrea Huszti

Unmanned aerial vehicles (UAVs) have become increasingly popular in recent years and are applied in various fields, from commercial and scientific to military and humanitarian operations. However, their usage presents many challenges, including limited resources, scalability issues, insecure communication, and inefficient solutions. We developed a secure and scalable registration protocol to address these issues using LoRa technology. Our solution involves the usage of the physical unclonable function (PUF) and blockchain technology for key exchange. PUF also ensures security against physical tampering, and blockchain is applied to share the symmetric key among the base stations. After the registration, the later communication messages are encrypted with AES-GCM to provide authentication and confidentiality between the parties. We conducted a security analysis of the registration protocol using the ProVerif tool, and our solution meets the security requirements, including the mutual authentication of entities, key freshness, key secrecy and also key confirmation properties. Besides the Proverif-based analysis, an informal security analysis is also provided that shows that the registration is protected against a variety of well-known active and passive security attacks. As drone resources are limited, we also prepared a proof of concept to test our solution under real-life conditions, focusing on efficiency and lightweight operations.

Open access
User Authentication and Security Systems
Advanced Authentication Protocols Security
Physical Unclonable Functions (PUFs) and Hardware Security
Original source
Sep 30, 2023·Al-Qadisiyah Journal for Engineering Sciences
4 cites
Blockchain Fog-based scheme for identity authentication in smart building

Alexander Varfolomeev, Liwa H. Al-Farhani, Liwa H. Al-Farhani

This paper presents a proposal for an authentication scheme for smart building systems and environments based on blockchain, its positive features, and fog computing. The most important feature that can be distinguished in the submitted proposal is its adoption of the principle of decentralization in contrast to traditional centralized documentation protocols, i.e. the proposed authentication system in which users and smart devices are implemented in a distributed and decentralized manner on the blockchain, that will provide a solution to a significant problem of low overall efficiency of the authentication process caused by a bottleneck in such important areas as computing capacity as well as centralized storage of a single authentication authority in the traditional model. There are also benefits from adding fog computing, and because it has higher computing and storage capabilities, it makes the data processing process more efficient, faster, more streamlined, and in line with the common necessities of the real-time IoT environment. The proposed scheme also provides solutions to protect the privacy of user data and increase the level of confidentiality, protection, and security, since a mysterious extractor was used to increase the confidentiality of the proposed model of the authentication system. Comparing a set of security schemes and conducting a security and performance analysis of the proposed scheme, the comparisons showed that the scheme can be characterized as having a good security level and an important efficiency level. The paper focused on specific aspects design of the authentication system, such as the registration and authentication process of all network entities, regardless of the specifics of the implementation of blockchain smart contracts.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Sep 8, 2023·SN Applied Sciences
38 cites
NFT-based identity management in metaverses: challenges and opportunities

Saeed Banaeian Far, Seyed Mojtaba Hosseini Bamakan

Abstract A considerable number of people worldwide start their second lives in the digital world soon. The 3D Internet reflects the digital world. Metaverse, the most famous example of the 3D Internet, is very popular and practical in people’s daily lives. However, combining Metaverse with newly-emerging technologies (e.g., blockchain) provides new user-friendly features such as autonomy, accessibility, removing central authorities, etc. Despite the mentioned attractive features, blockchain-based metaverses suffer various challenges, such as one user with multiple identities, certificate issuing for users in Metaverse, authentication-related issues, and arresting malicious users. Generally, identity management in a distributed environment where no central authority exists is a challenging issue. This study focuses on the challenge of distributed identity management in Metaverses to strike a balance between users’ privacy and regulation. The study proposes the use of Non-Fungible Tokens (NFTs) as a tool for managing identities in metaverses, as they are considered an excellent choice for this purpose. In addition to explaining the importance of this idea, this paper identifies its challenges, including distributed identity management, authentication issues, and security and privacy aspects. It then proposes possible solutions (e.g., using cryptographic tools). Despite existing challenges, there are many opportunities in the popularization of Metaverse, such as relying on blockchain technology, emerging many Metaverse-related jobs, in-Metaverse investments for huge revenues, and applying digital twins to provide realistic senses. This study also highlights the critical role of artificial intelligence (AI) in metaverses.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Original source
Aug 8, 2023·Research Square
0 cites
Zero Knowledge and Oblivious Ads Recommendation

Anirudh Rajagopalan, Kunwar Singh, Balaji Jayashrri, Anu John

No abstract is available for this record.

Open access
2 source records
Privacy, Security, and Data Protection
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Aug 2, 2023·Frontiers in Blockchain
18 cites
EasyChain: an IoT-friendly blockchain for robust and energy-efficient authentication

Anand K. Bapatla, Deepak Puthal, Saraju P. Mohanty, Venkata P. Yanambaka · 5 authors

The Internet of Everything (IoE) is a bigger picture that tries to fit the Internet of Things (IoT) that is widely deployed in smart applications. IoE brings people, data, processes, and things to form a network that is more connected and increases overall system intelligence. A further investigation of the IoE can really mean creating a distributed network focusing on edge computing instead of relying on the cloud. Blockchain is one of the recently distributed network technologies which by structure and operations provide data integrity and security in trust-less P2P networks such as IoE. Blockchain can also remove the need for central entities which is the main hurdle for the wide adoption of IoT in large networks. IoT “things” are resource-constrained both in power and computation to adopt the conventional blockchain consensus algorithms that are power and compute-hungry. To solve that problem, this paper proposes EasyChain, a blockchain that is robust along with running on a lightweight authentication-based consensus protocol that is known as Proof-of-Authentication (PoAh). This blockchain based on the lightweight consensus protocol replaces the power-hungry transaction, blocks validation steps, and provides ease of usage in resource-constrained environments such as IoE. The proposed blockchain is designed using the Python language for an easy understanding of the functions and increased ease of integration into IoE applications. The designed blockchain system is also deployed on a single-board computer to analyze its feasibility and scalability. The latency observed in the simulated and experimental evaluations is 148.89 ms which is very fast compared to the existing algorithms.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Jul 8, 2023·Blockchain Research and Applications
21 cites
Care4U: Integrated healthcare systems based on blockchain

Randa Kamal, Ezz El‐Din Hemdan, Nawal El‐Fishway

During the crisis of COVID-19, the need to stay at home has raised dramatically. In addition, the number of sick people, especially elderly persons, has increased exponentially. In such a scenario, home monitoring of patients can ensure remote healthcare at home using advanced technologies such as the Internet of Medical Things (IoMT). The IoMT can monitor and transmit sensitive health data, however, it may be vulnerable to various attacks. In this paper, an efficient healthcare security system is proposed for IoMT's applications. In the proposed system, the medical sensors can transmit sensed encrypted health data via a mobile application to the doctor for privacy. Then, three consortium blockchains are constructed for load balancing of transactions and reducing transaction latency. They store the credentials of system entities, doctor's prescriptions, and recommendations according to the data transmitted via mobile applications and the medical treatment process. Besides, cancelable biometrics are used for providing authentication and increasing the security of the proposed medical system. The investigational results show that the proposed system outperforms existing work where the proposed model consumed less processing time by values of 18%, 22%, and 40%, and less energy for processing a 200 KB file by values of 9%, 13%, and 17%. Finally, the proposed model consumed less memory usage by values of 7%, 7%, and 18.75%. From these results, it is clear the proposed system gives a very reliable and secure performance for efficiently securing medical applications.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
Jul 1, 2023·arXiv
1 cites
Quarks: A Secure and Decentralized Blockchain-Based Messaging Network

Mirza Kamrul Bashar Shuhan, Tariqul Islam, Enam Ahmed Shuvo, Faisal Haque Bappy · 6 authors

Over the past two decades, the popularity of messaging systems has increased both in enterprise and consumer level. Many of these systems used secure protocols like end-to-end encryption to ensure strong security features such as “future secrecy” for one-to-one communication. However, the majority of them rely on centralized servers owned by big IT companies, which allows them to use their users’ personal data. Also it allows the government to track and regulate their citizens’ activities, which poses significant threats to “digital freedom”. Also, these systems have failed to achieve security attributes like confidentiality, integrity, privacy, and future secrecy for group communications. In this paper, we present a novel blockchain-based secure messaging system named Quarks that overcomes the security pitfalls of the existing systems and eliminates the centralized control. We have analyzed our design of the system with security models and definitions from existing literature to demonstrate the system’s reliability and usability. We have developed a Proof of Concept (PoC) of the Quarks system leveraging Distributed Ledger Technology (DLT), and conducted load testing on that. We noticed that our PoC system achieves all the desired attributes that are prevalent in a traditional centralized messaging scheme despite the limited capacity of the development and testing environment. Therefore, this assures us the applicability of such systems in near future if scaled up properly.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Original source
Jun 28, 2023·International Journal of Information Security
3 cites
Anonymous provision of privacy-sensitive services using blockchain and decentralised storage

Stanisław Barański, Julian Szymański, Higinio Mora

Abstract Lawyers, laboratories, auditors, and banks often need access to sensitive personal data to provide services such as genetic testing, paternity testing, STD testing, credit scoring, or legal advice. Processing such data exposes both service providers (SPs) and users to privacy risks: SPs risk violating laws like the General Data Protection Regulation (GDPR) and the Consumer Protection Act (CPA), while users risk losing their privacy. We observe that personal data is often only needed for logistical purposes like payment or communication and could be provided anonymously if suitable methods existed. To address this, we present a solution that enables services to be delivered without collecting personal data. Our protocol combines anonymous payment methods (e.g., cash, privacy-preserving cryptocurrencies), blockchain for fairness, and distributed content-addressable storage networks to deliver results. Compared to existing approaches, our protocol achieves anonymity under weaker assumptions, supports the transfer of physical materials and conflict resolution, and eliminates the need for customer interaction with a trusted arbiter in conflict-free cases-making it more practical. We analyze the protocol’s fairness and implement a prototype using Ethereum as a message board, Monero for anonymous payments, and Powergate (IPFS/Filecoin) as a decentralized storage solution.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
User Authentication and Security Systems
Original source
Jun 16, 2023·Cyber Security and Applications
13 cites
Design of blockchain-enabled secure smart health monitoring system and its testbed implementation

Siddhant Thapliyal, Shubham Singh, Mohammad Wazid, Devesh Pratap Singh · 5 authors

Smart healthcare technology is transforming from the traditional healthcare system in every manner conceivably. Smart healthcare provides several advantages over the existing approaches. However, it suffers from healthcare data security and privacy issues. As the Internet attackers may get access to sensitive healthcare data through the use of various types of cyber attacks. In this paper, an architecture of a blockchain-enabled secure smart health monitoring system has been presented (in short, it is called as BSSHM). BSSHM consists of various health data monitoring sensors, i.e., temperature, heartbeat, etc., which monitor the real time health data of the different patients. The healthcare data of the patients can be transmitted to the connected health servers in a secure way, where this data can be stored securely for its various uses. The formal security verification of the proposed BSSHM is also done through the widely-accepted Scyther tool. It has been proved that BSSHM is able to defend various potential attacks.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Advanced Authentication Protocols Security
Original source
Jun 1, 2023·2023 IEEE International Conference on Metaverse Computing, Networking and Applications (MetaCom)
13 cites
A Blockchain-based Authentication Protocol for Metaverse Environments using a Zero Knowledge Proof

Awaneesh Kumar Yadav, An Braeken, Mika Ylianttila, Madhusanka Liyanage

The metaverse, which consists of several universes called verses, is predicted to be the Internet of the future. Recently, this idea has received a lot of discussions, but not enough attention has been paid to the security concerns of these virtual worlds. Primarily when the user and platform server communicate with each other and share sensitive information using the public channel, any attacker can capture the message and can perform various types of attacks such as privacy attack, violation of perfect forward secrecy, impersonation attack, ephemeral secret leakage attack and traceability attack. Therefore, there is impelling need to design an authentication protocol for the metaverse environment that can secure the communication between the user and the platform server. Taking this into account, we designed a zero-knowledge proof authentication protocol based on blockchain for the metaverse environment. The security of the designed protocol is verified through the Burrows-Abadi-Needham (BAN) logic, Scyther tool, and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The outcome of the security verification demonstrates that the designed metaverse authentication protocol mitigates all the attacks mentioned above. Moreover, we evaluated the performance of the designed metaverse authentication protocol in terms of computational, communication, storage costs, and energy consumption and compared it with existing metaverse authentication protocols, showing good results taking into account the additional security strength.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Privacy, Security, and Data Protection
Original source
May 25, 2023·Electronics
10 cites
Bridge of Trust: Cross Domain Authentication for Industrial Internet of Things (IIoT) Blockchain over Transport Layer Security (TLS)

Fatemeh Stodt, Christoph Reich

The Industrial Internet of Things (IIoT) holds significant potential for improving efficiency, quality, and flexibility. In decentralized systems, there are no trust-based centralized authentication techniques, which are unsuitable for distributed networks or subnets, as they have a single point of failure. However, in a decentralized system, more emphasis is needed on trust management, which presents significant challenges in ensuring security and trust in industrial devices and applications. To address these issues, industrial blockchain has the potential to make use of trustless and transparent technologies for devices, applications, and systems. By using a distributed ledger, blockchains can track devices and their data exchanges, improving relationships between trading partners, and proving the supply chain. In this paper, we propose a model for cross-domain authentication between the blockchain-based infrastructure and industrial centralized networks outside the blockchain to ensure secure communication in industrial environments. Our model enables cross authentication for different sub-networks with different protocols or authentication methods while maintaining the transparency provided by the blockchain. The core concept is to build a bridge of trust that enables secure communication between different domains in the IIoT ecosystem. Our proposed model enables devices and applications in different domains to establish secure and trusted communication channels through the use of blockchain technology, providing an efficient and secure way to exchange data within the IIoT ecosystem. Our study presents a decentralized cross-domain authentication mechanism for field devices, which includes enhancements to the standard authentication system. To validate the feasibility of our approach, we developed a prototype and assessed its performance in a real-world industrial scenario. By improving the security and efficiency in industrial settings, this mechanism has the potential to inspire this important area.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
User Authentication and Security Systems
Original source
May 17, 2023·ACM Computing Surveys
55 cites
Security Aspects of Cryptocurrency Wallets—A Systematic Literature Review

Sabine Houy, Philipp Schmid, Alexandre Bartel

Cryptocurrencies are gaining prominence among individuals and companies alike, resulting in the growing adoption of so-called cryptocurrency wallet applications, as these simplify transactions. These wallets are available in a myriad of different forms and specifications. All of them are susceptible to various ways the attacker can exploit the vulnerabilities and steal money from victims. Cryptocurrency wallets create a unique field as they combine features of password managers, banking applications, and the need to keep their users and their transactions anonymous. We collect the findings from previous literature to provide an overview of the different attack surfaces, possible countermeasures, and further research. Existing literature focused on one of the features mentioned before, while we considered all of them. Our systematic study shows that there is a considerable variety of attack vectors, which we have divided into six subcategories, (i) Memory and Storage, (ii) Operating Systems, (iii) Software Layer, (iv) Network Layer, (v) Blockchain Protocol, and (vi) Others. We have found a large gap between the possible countermeasures and their actual adoption. Therefore, we provide a list of possible directions for future research to tackle this gap.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Spam and Phishing Detection
Original source
May 11, 2023·IEEE Transactions on Intelligent Transportation Systems
33 cites
Aggregated Zero-Knowledge Proof and Blockchain-Empowered Authentication for Autonomous Truck Platooning

Wanxin Li, Collin Meese, Hao Guo, Mark Nejad

Platooning technologies enable trucks to drive cooperatively and automatically, providing benefits including less fuel consumption, greater road capacity, and safety. To establish trust during dynamic platooning formation, ensure vehicular data integrity, and guard platoons against potential attackers in mixed fleet environments, verifying any given vehicle’s identity information before granting it access to join a platoon is pivotal. Besides, due to privacy concerns, truck owners may be reluctant to disclose private vehicular information, which can reveal their business data to untrusted third parties. To address these issues, this is the first study to propose an aggregated zero-knowledge proof and blockchain-empowered system for privacy-preserving identity verification in truck platooning. We provide the correctness proof and the security analysis of our proposed authentication scheme, highlighting its increased security and fast performance. The platooning formation procedure is re-designed to seamlessly incorporate the proposed authentication scheme, including the 1st catch-up and cooperative driving steps. The blockchain performs the role of verifier within the authentication scheme and stores platooning records on its digital ledger to guarantee data immutability and integrity. In addition, the proposed programmable access control policies enable truck companies to define who is allowed to access their platoon records. We implement the proposed system and perform extensive experiments on the Hyperledger platform. The results show that the blockchain can provide low latency and high throughput, the aggregated approach can offer a constant verification time of 500 milliseconds regardless of the number of proofs, and the platooning formation only takes seconds under different strategies. The experimental results demonstrate the feasibility of our design for use in real-world truck platooning.

Open access
3 source records
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
User Authentication and Security Systems
Original source
May 7, 2023·Electronics
22 cites
Blockchain-Based Authentication Protocol Design from a Cloud Computing Perspective

Zhiqiang Du, W. Jiang, Chenguang Tian, Xiaofeng Rong · 5 authors

Cloud computing is a disruptive technology that has transformed the way people access and utilize computing resources. Due to the diversity of services and complexity of environments, there is widespread interest in how to securely and efficiently authenticate users under the same domain. However, many traditional authentication methods involve untrusted third parties or overly centralized central authorities, which can compromise the security of the system. Therefore, it is crucial to establish secure authentication channels within trusted domains. In this context, we propose a secure and efficient authentication protocol, HIDA (Hyperledger Fabric Identity Authentication), for the cloud computing environment. Specifically, by introducing federated chain technology to securely isolate entities in the trust domain, and combining it with zero-knowledge proof technology, users’ data are further secured. In addition, Subsequent Access Management allows users to prove their identity by revealing only brief credentials, greatly improving the efficiency of access. To ensure the security of the protocol, we performed a formal semantic analysis and proved that it can effectively protect against various attacks. At the same time, we conducted ten simulations to prove that the protocol is efficient and reliable in practical applications. The research results in this paper can provide new ideas and technical support for identity authentication in a cloud environment and provide a useful reference for realizing the authentication problem in cloud computing application scenarios.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Cloud Data Security Solutions
Original source