The construction of smart grids provides many benefits. Computational cost, however, drastically grows with an increase in scale since a large amount of data is generated, transmitted, collected, and treated. Although data aggregation technology is helpful when adopting smart grid applications, corresponding security and performance issues should be considered while implementing the mechanism. In this paper, a blockchain-enabled authenticated conserved data aggregation scheme is proposed to balance security concerns and the computational cost of the smart grid. Furthermore, several functions are developed in our scheme to highlight the contributions. First, efficient cryptographic algorithms are integrated instead of computationally-expensive ones. Second, the proposed scheme seamlessly incorporates a blockchain system into a smart grid for better decentralization which can avoid the possible threats and high cost of a centralized system. Third, the scheme is scalable, which can be adapted to manage a great number of metering devices. Fourth, the aggregational operations in our design combine power data and signature, which is more practical. Finally, the proposed scheme covers a one-time key pair and signature mechanism, thus upgrading the privacy protection of blockchain applications in the smart grid.
The Industrial Internet of Things (IIoT) is able to connect machines, analytics and people with IoT smart devices, gateway nodes and edge devices to create powerful intuitivenesses to drive smarter, faster and effective business agreements. IIoT having interconnected machines along with devices can monitor, gather, exchange, and analyze information. Since the communication among the entities in IIoT environment takes place insecurely (for instance, wireless communications and Internet), an intruder can easily tamper with the data. Moreover, physical theft of IoT smart devices provides an intruder to mount impersonation and other attacks. To handle such critical issues, in this work, we design a new private blockchain-envisioned access control scheme for Pervasive Edge Computing (PEC) in IIoT environment, called PBACS-PECIIoT. We consider the private blockchain consisting of the transactions and registration credentials of the entities related to IIoT, because the information is strictly confidential and private. The security of PBACS-PECIIoT is significantly improved due to usage of blockchain as immutability, transparency and decentralization along with protection of various potential attacks. A meticulous comparative analysis exhibits that PBACS-PECIIoT achieves greater security and more functionality features, and requires low costs for communication and computational as compared to other pertinent schemes.
Khaled Chait, Abdelkader Laouid, Mostefa Kara, Mohammad Hammoudeh · 6 authors
The transformative potential of blockchain technology has resulted in its widespread adoption, bringing about numerous advantages such as enhanced data integrity, transparency, and decentralization. Blockchain has effectively proven its ability to establish trustworthy systems across a multitude of applications. As the number of transactions recorded into a blockchain grows, the blockchain’s size expands significantly posing challenges to the network, particularly in terms of storage capacity and processing power. To address this problem, we present a cryptosystem based on RSA to provide aggregate signatures in blockchains. The aggregate signature replaces all transaction signatures of a block. In this scheme, all participating blockchain nodes use the same modulusN, each with its own private and public key pair generated fromN. Regardless of the number of transactions, nodes, and signers, the aggregate signature size is alwaysO(k), wherekis a security parameter. The miner that constructs a candidate block computes the aggregate signature σ, replaces all transaction signatures by σ, and transmits the block with only one aggregate signature. The proposed scheme incorporates a flexible and accountable subgroup aggregate signature mechanism, allowing any subsettofntotal elements to sign data, wheretis the required number of signers. To verify that a set of elements signed the block, the verifier requires the aggregate signature, the aggregate public key, and the data hash. This approach requires minimal interaction between the signers, which results in reduced network traffic. Regardless of the network size, there are alwayst+nexchanged messages. Experimental analysis shows the proposed aggregate signature scheme’s effectiveness in increasing security robustness and reducing block size and overall network traffic.
G. Sucharitha, V. Sitharamulu, Sachi Nandan Mohanty, Anjanna Matta · 5 authors
The use of encryption is essential to protect sensitive data, but it often poses challenges when it comes to locating and retrieving information without decryption. Searchable encryption provides an effective mechanism that achieves secure search over encrypted data. In this paper a new approach to address the fine-grained search and to protect sensitive data, Blockchain Assisted ciphertext policy decentralized attribute-based encryption (BA-CP-DABE) in cloud has been developed. The CP-DABE is employed to manage data access, secure key generation, while the immutability of blockchain ensures the confidentiality of ciphertext. By leveraging searchable encryption, it becomes possible to securely search encrypted data stored on the blockchain. Keywords are encrypted using attribute-based encryption and stored on a remote server, along with the corresponding ciphertext in the blockchain. One of the significant challenges in this approach is the assumptions-based technique i.e., bilinear mapping, which involves keyword ciphertext and trapdoor security. However, through extensive numerical experiments, the system has demonstrated its ability to generate key and trapdoor structures, as well as effectively find keywords within the encrypted data.
Abhishek Bisht, Ashok Kumar Das, Dusit Niyato, Youngho Park
Secure storage and sharing of Personal Health Records (PHRs) in Internet of Medical Things (IoMT) is one of the significant challenges in the healthcare ecosystem. Due to the high value of personal health information, PHRs are one of the favourite targets of cyber attackers worldwide. Over the years, many solutions have been proposed; however, most solutions are inefficient for practical applications. For instance, several existing schemes rely on the bilinear pairings, which incur high computational costs. To mitigate these issues, we propose a novel PHR-sharing scheme that is dynamic, efficient, and practical. Specifically, we combine searchable symmetric encryption, blockchain technology and a decentralized storage system, known as Inter-Planetary File System (IPFS) to guarantee confidentiality of PHRs, verifiability of search results, and forward security. Moreover, we provide formal security proofs for the proposed scheme. Finally, we have conducted extensive test-bed experiments and the results demonstrate that the proposed scheme can be used in practical scenarios related to IoMT environment.
In a permissionless system like Ethereum, participation may fluctuate dynamically as some participants unpredictably go offline and some others come back online. In such an environment, traditional Byzantine fault-tolerant consensus algorithms may stall - even in the absence of failures - because they rely on the availability of fixed-sized quorums. The sleepy model formally captures the main requirements for solving consensus under dynamic participation, and several algorithms solve consensus with probabilistic safety in this model assuming that, at any time, more than half of the online participants are well behaved. However, whether safety can be ensured deterministically under these assumptions, especially with constant latency, remained an open question. Assuming a constant adversary, we answer in the positive by presenting a consensus algorithm that achieves deterministic safety and constant latency in expectation. In the full version of this paper, we also present a second algorithm which obtains both deterministic safety and liveness, but is likely only of theoretical interest because of its high round and message complexity. Both algorithms are striking in their simplicity.
Conventional copyright systems are governed nationally, and there is no global ledger for storing copyright data. Due to the lack of a global copyright monitoring system, it is difficult to provide cross-border copyright protection. In this paper, we propose a novel decentralized copyright system based on a consortium blockchain, which ensures cross-border copyright protection of individuals’ digital content and solves existing challenges in international copyright management. The proposed system enables a synchronized platform to register and trade copyright globally without using a global cloud. Individual countries receive membership from a copyright federation and participate in block creation by executing the energy-efficient proof of authority consensus algorithm. These countries are regarded as the authorities of the platform. They validate transactions conducted by users and store them in the blockchain. Anyone, either registered or unregistered, can investigate a copyrighted work, but only registered users can make transactions. A token-based payment method is also proposed for paying copyright charges (i.e., transaction fees) to authorities through the federation. A prototype of the system was implemented, and its performance was evaluated. This paper provides direction and guidance towards international copyright management.
Ang Liu, Xiu‐Bo Chen, Gang Xu, Zhuo Wang · 6 authors
The rapid advancement of quantum technology poses significant security risks to blockchain systems. However, quantum technology can also provide solutions for enhancing blockchain security. In this paper, we propose a quantum... | Find, read and cite all the research you need on Tech Science Press
Cryptocurrencies use a secure, distributed ledger system called blockchain and mining is an essential part of it. It adds records of past transactions, enables consensus, and creates new units of currency. They are designed as peer-to-peer systems and rely on miners to validate transactions. The paper evaluates different mining techniques used by major cryptocurrencies, analyzing their strengths, weaknesses, and potential threats. It provides an overview of the various ways in which cryptocurrencies can be mined and highlights their unique strengths and vulnerabilities.
Gabriel Solomon, Peng Zhang, Rachael Brooks, Yuhong Liu
As resource-constrained Internet-of-Things (IoT) devices become popular targets of various malicious attacks, frequent updates to keep their software up to date are essential to their security. However, state-of-the-art software delivery and payment systems incorporate multiple services in a client-server structure requiring multiple transits of information between client and server, while also creating a wide attack surface. We propose a blockchain-based end-to-end secure software update delivery framework for Internet of Things (IoT) devices, which aims to ensure confidentiality, integrity, availability, efficiency, and audit-ability for verified software delivery, while offloading the cryptographic computation from resource-constrained IoT devices to a decentralized blockchain system. In particular, we leverage Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and design a customized authorization policy to not only ensure that software updates can only be decrypted and installed on authorized IoT devices but also significantly reduce the computational overhead for key generation and key delivery on the manufacturer side. Furthermore, secure and atomic software delivery and payments between IoT devices and the manufacturer are assured through smart contracts. The authenticity of the delivered software is guaranteed by offloading the computation-based signature validation to smart contracts. Compliance audits are satisfied through immutable records on the blockchain’s public ledger, and the smart contracts efficiently guarantee the delivery of software updates in exchange for payment. Security analysis and experiments are performed to compare the proposed framework with state-of-the-art studies and validate its effectiveness.
Blockchain technology, especially Bitcoin, has revolutionizedhow we think about and manage financial transactions.However, with the increasing demand and usage of blockchaintechnology, the security of cryptocurrency wallets has become acritical concern. Threshold signatures offer a promising solutionto this problem, allowing multiple parties to sign a transactionwithout revealing their private keys. This article presents an Androidmobile Bitcoin wallet application that uses Schnorr-basedthreshold signatures. The application also deploys smartwatchintegration for enhanced security and usability. This integrationprovides an additional layer of security by requiring physicalconfirmation from the user before approving any transaction.Our implementation provides a secure and efficient platform formanaging Bitcoin assets using threshold signatures while alsoproviding an intuitive and easy-to-use interface for interactingwith the application.
The inherent security and computational demands of classical consensus protocols are often presumed impervious to various forms of attack. However, quantum computing advancements present considerable threats to the assumed attack resistance of classical security strategies currently deployed within blockchain systems. Adopting consensus algorithms fortified with post-quantum security measures holds the potential to significantly enhance the privacy and security dimensions of traditional blockchains. Notable advantages of such post-quantum solutions in the context of blockchain consensus include accelerated transaction verification, clarified mining authorship, and resilience against quantum attacks. Yet, a comprehensive analysis of the implications of post-quantum solutions for blockchain consensus is notably absent in the existing scholarly discourse. This paper aims to bridge this gap by delivering a systematic review of Post-Quantum Blockchain Consensus (PQBC). The four primary contributions of this study are (i) a systematic approach to presenting a comprehensive overview of PQBC, (ii) the systematic selection and analysis of 29 key studies from an initial pool of 1192 papers, (iii) a critical review of methods, enhancements to security, scalability, trust, and privacy, as well as the evaluation employed for PQBC, and (iv) a discussion of primary gaps and prospective directions for future PQBC research.
Cloud computing has revolutionized organizational operations by providing convenient, on-demand access to resources. The emergence of the Internet of Things (IoT) has introduced a new paradigm for collaborative computing, leveraging sensors and devices that generate and process vast amounts of data, thereby resulting in challenges related to scalability and security, making the significance of conventional security methods even more pronounced. Consequently, in this paper, we propose a novel Scalable and Secure Cloud Architecture (SSCA) that integrates IoT and cryptographic techniques, aiming to develop scalable and trustworthy cloud systems, thus enabling multi-user systems and facilitating simultaneous access to cloud resources by multiple users. The design adopts a decentralized approach, utilizing multiple cloud nodes to handle user requests efficiently and incorporates Multicast and Broadcast Rekeying Algorithm (MBRA) to ensure the privacy and confidentiality of user information, utilizing a hybrid cryptosystem that combines MBRA, Post Quantum Cryptography (PQC) and blockchain technology. Leveraging IoT devices, the architecture gathers data from distributed sensing resources and ensures the security of collected information through robust MBRA-PQC encryption algorithms, while the blockchain ensures that the confidential data is stored in distributed and immutable records. The proposed approach is applied to several datasets and the effectiveness is validated through various performance metrics, including response time, throughput, scalability, security, and reliability. The results highlight the effectiveness of the proposed SSCA, showcasing a notable reduction in response time by 1.67 seconds and 0.97 seconds for 250 and 1000 devices, respectively, in comparison to the MHE-IS-CPMT. Likewise, SSCA demonstrated significant improvements in the AUC values, exhibiting enhancements of 6.30%, 6.90%, 7.60%, and 7.30% at the 25-user level, and impressive gains of 5.20%, 9.30%, 11.50%, and 15.40% at the 50-user level when compared to the MHE-IS-CPMT, EAM, SCSS, and SHCEF models, respectively.
In this paper, we first trace the evolution of cryptography from symmetric- and public-key primitives to the emerging paradigm of privacy computing. We systematically examine three pillars, namely, zero-knowledge proofs, fully homomorphic encryption, and secure multi-party computation, by highlighting their models, algorithms, and performance frontiers. The second half narrows the lens to recent deployed systems. In particular, we introduce the Plonk zk-SNARK powering Ethereum layer-2 roll-ups, and present a state-of-the-art privacy-preserving Vickrey auction algorithm. These case studies illustrate how privacy-computing techniques are transitioning from theory to production-grade blockchain applications.
As for the advancement of IoT and cloud computing in healthcare, outsourcing encrypted Electronic medical records (EMRs) created by the aggregation of medical treatment applications and health data collected from IoT devices enables high accessibility, effective collaboration, and zero computational operation cost. Current applications and research works generally concern the privacy of the finest EMRs that are encrypted with secure and lightweight cryptographic protocols before they are outsourced to the cloud. However, this process does not consider the security and privacy of the data collected by IoT devices, where the data being transferred can be leaked before they are aggregated. Furthermore, existing IoT-cloud based access control solutions have not addressed the outsourced encryption, privacy of IoT data transmission and aggregation, and the policy update of the EMRs in an integrated manner. In this paper, we propose an access control scheme called LightMED which provides secure, fine-grained, and scalable EMR sharing in a cloud-based environment integrated with fog computing, CP-ABE, and blockchain technology. We propose a secure IoT data transmission and aggregation method based on lightweight encryption and digital signing. At the core, we introduce outsourced encryption with a privacy-preserving access policy scheme and an outsourced encryption and decryption algorithm leveraged by the collaboration between fog nodes and blockchain. In addition, we introduce a novel lightweight policy update algorithm to enable the data owners of EMRs to effectively manage their policies in a secure and effective manner. Finally, we performed the comparative analysis to illustrate the computation cost and conducted experiments to evaluate the performance of our scheme and related works. The experimental results showed that our scheme outperformed existing works since it yielded least processing cost of both encryption and decryption at end-users’ devices, which demonstrates the higher efficiency and practicality of our scheme.
Cloud storage is an essential method for data storage. Verifying the integrity of data in the cloud is critical for the client. Traditional cloud storage approaches rely on third-party auditors (TPAs) to accomplish auditing tasks. However, third-party auditors are often not trusted. To eliminate over-reliance on third-party auditors, this paper designs a blockchain-based auditing scheme that uses blockchain instead of third-party auditors to ensure the reliability of data auditing. Meanwhile, our scheme is based on the audit method of the quad Merkle hash tree, using the root of the quad Merkle hash tree to verify the integrity of data, which significantly improves computing and storage efficiency. Automated verification of auditing activities by deploying smart contracts on the blockchain allows us to have a more up-to-date picture of data integrity. The performance of the scheme is evaluated through security analysis and experiments, which prove that the proposed scheme is secure and effective.
The emerging combination of Internet of Things (IoT) and aerospace integration aided by satellite and 6G communication techniques has stimulated the Internet of Unmanned Aerial Vehicles (UAVs), i.e., Internet of Drones (IoD). To accommodate and share the enormous real-time UAV data, cloud-based IoD is an inevitable choice to lower the heavy burden of mobile UAVs. Nevertheless, how to protect highly sensitive UAV data in such a honest-but-curious, open and distributed environment with resource-limited UAVs is a significant challenge. Although our previous work (PATLDAC) in SPNCE’21 devises a cloud-based UAV data access control scheme with policy privacy protection, limited access time and user traceability, it incurs inflexible and centralized cloud data storage and access as well as untrustworthy metadata in untrusted cloud environment for data access and user tracing. To this end, we further propose a blockchain-based privacy-aware data access control (BPADAC) scheme for distributed and secure UAV data sharing in cloud-based IoD. Based on fine-grained, traceable and privacy-preserving UAV data access characteristic of our previous work, we extend it by leveraging blockchain and Distributed Hash Table (DHT) for distributed and trustful UAV data access and storage, together with reliable and limited access mechanism to guarantee cloud UAV data sharing service provision. We also design public and undeniable user tracing mechanism to prevent user key abuse with traitor denial. Finally, we present formal security analysis and prototype the system leveraging the smart contracts of Ethereum blockchain for performance evaluation to show the feasibility of BPADAC.
Leonardo da Costa, Billy Pinheiro, Weverton Cordeiro, Roberto Araújo · 5 authors
Storing and sharing health records through electronic systems pose security risks. To address them, several countries’ regulations have established that healthcare information systems must fulfill security properties (confidentiality, access control, integrity, revocation and anonymity) and complementary ones (emergency access and interoperability). Upon tackling these issues, several proposals present security limitations and/or address specific properties only. We propose Sec-Health, a blockchain-based protocol that secures health records, addressing all of the main security and complementary properties defined in current regulations. We show that Sec-Health is a suitable solution by analyzing it under several attack scenarios and describing how it overcomes the problems of existing solutions. Furthermore, we evaluate a Sec-Health Proof of Concept, showing that it can reduce from 26% up to 90% the time to access health records, and reduce up to 50% client-side memory overhead, compared to related work.
Pierpaolo Loreti, Lorenzo Bracciale, Emanuele Raso, Giuseppe Bianchi · 6 authors
In the past few years, blockchain technology has emerged in numerous smart grid applications, enabling the construction of systems without the need for a trusted third party. Blockchain offers transparency, traceability, and accountability, which lets various energy management system functionalities be executed through smart contracts, such as monitoring, consumption analysis, and intelligent energy adaptation. Nevertheless, revealing sensitive energy consumption information could render users vulnerable to digital and physical assaults. This paper presents a novel method for achieving a dual balance between privacy and transparency, as well as accountability and verifiability. This equilibrium requires the incorporation of cryptographic tools like Secure Multiparty Computation and Verifiable Secret Sharing within the distributed components of a multi-channel blockchain and its associated smart contracts. We corroborate the suggested architecture throughout the entire process of a Demand Response scenario, from the collection of energy data to the ultimate reward. To address our proposal’s constraints, we present countermeasures against accidental crashes and Byzantine behavior while ensuring that the solution remains appropriate for low-performance IoT devices.
Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques