Andreas Polyvios Delladetsimas, Stamatis Papangelou, Elias Iosif, George M. Giaglis
This review examines the integration of blockchain technology with the IoT in the Marine Internet of Things (MIoT) and Internet of Underwater Things (IoUT), with applications in areas such as oceanographic monitoring and naval defense. These environments present distinct challenges, including a limited communication bandwidth, energy constraints, and secure data handling needs. Enhancing BIoT systems requires a strategic selection of computing paradigms, such as edge and fog computing, and lightweight nodes to reduce latency and improve data processing in resource-limited settings. While a blockchain can improve data integrity and security, it can also introduce complexities, including interoperability issues, high energy consumption, standardization challenges, and costly transitions from legacy systems. The solutions reviewed here include lightweight consensus mechanisms to reduce computational demands. They also utilize established platforms, such as Ethereum and Hyperledger, or custom blockchains designed to meet marine-specific requirements. Additional approaches incorporate technologies such as fog and edge layers, software-defined networking (SDN), the InterPlanetary File System (IPFS) for decentralized storage, and AI-enhanced security measures, all adapted to each application’s needs. Future research will need to prioritize scalability, energy efficiency, and interoperability for effective BIoT deployment.
Block reorganization (reorg) may occur when a blockchain fork is deliberately instigated and remains poorly solved on Ethereum. We utilize an agent-based modeling approach to simulate the block generation and decision-making processes of reorg attackers and ordinary validators. We analyze the impact of six validator network structures (i.e., random, regular, small-world, scale-free, hierarchical, and community networks) and four fork selection rules (i.e., LMD GHOST, HLMD GHOST, Goldfish, and RLMD GHOST) on the success rate of reorg attacks. The results show that the community network is more vulnerable to reorg attacks, while the hierarchical network is more resilient to such attacks. In addition, the Goldfish fork-choice rule can significantly reduce the success rate of reorg attacks.
Ali Yeganeh, Xuelong Hu, Sandile Charles Shongwe, Frans F. Koning
In the area of multivariate process quality control, it is sometimes important to monitor the ratio of two normal random variables denoted by RZ over time. The concept of control charts has often been harnessed in this field, leading to the application of various types of statistical models, including Shewhart, Exponentially Weighted Moving Average (EWMA), and so forth. However, there is little attention to implementation of machine learning-based control charts. To bridge this gap, a novel machine learning based model incorporating the attention mechanism approach, as an implemented Artificial Intelligence (AI) model, is proposed to monitor the RZ in Phase II applications. The proposed RZ method not only provides quicker Out-of-Control (OC) shift detection than conventional RZ control charts but also does not require the quality controller to have any prior information about the upward or downward shift patterns, which is a major assumption in most of the previous RZ models. We provide extensive performance comparison results to discuss the statistical performance of our proposed method through Monte Carlo simulations. Moreover, a comprehensive real example about surveillance of the cryptocurrency market is provided to illustrate the practical application of our proposed method. Through simulation and back-testing results, it is shown how the proposed method can lead to an automated trading strategy.
N. Gayathri, M. Aswin, Mr. A Shishand, Mr. A.T Sabarigireeson · 5 authors
This paper explores a blockchain-based approach to redefining digital ownership through Non-Fungible Tokens (NFTs). Phase 1 focused on developing smart contracts on the Ethereum blockchain, minting unique NFTs, and implementing secure transfer mechanisms. These steps ensure transparency, immutability, and decentralized verification of ownership via blockchain hashes, demonstrating the potential of NFTs to revolutionize asset ownership. Looking ahead, Phase 2 will involve designing a user-friendly web interface for an NFT marketplace. This platform will enhance accessibility and engagement by simplifying NFT creation, buying, and selling while integrating features like intuitive design and wallet compatibility. Together, these efforts aim to bridge blockchain technology and mainstream adoption, transforming the landscape of digital ownership. Keywords: Blockchain, NFTs, Smart Contracts, Digital Ownership, Ethereum, NFT Marketplace, Decentralized Verification.
Ensuring security for highly dynamic peer-to-peer (P2P) networks has always been a challenge, especially for services like online transactions and smart devices. These networks experience high churn rates, making it difficult to maintain appropriate access control. Traditional systems, particularly Role-Based Access Control (RBAC), often fail to meet the needs of a P2P environment. This paper presents a blockchain-based access control framework that uses Ethereum smart contracts to address these challenges. Our framework aims to close the gaps in existing access control systems by providing flexible, transparent, and decentralized security solutions. The proposed framework includes access control contracts (ACC) that manage access based on static and dynamic policies, a Judge Contract (JC) to handle misbehavior, and a Register Contract (RC) to record and manage the interactions between ACCs and JC. The security model combines impact and severity-based threat assessments using the CIA (Confidentiality, Integrity, Availability) and STRIDE principles, ensuring responses are tailored to different threat levels. This system not only stabilizes the fundamental issues of peer membership but also offers a scalable solution, particularly valuable in areas such as the Internet of Things (IoT) and Web 3.0 technologies.
This study provides a comprehensive analysis of the growth rates and correlations among non-fungible tokens (NFTs), Bitcoin (BTC), Ethereum (ETH), and the NASDAQ Composite Index from 2018 to 2021. Utilizing data from Statista, CoinMarketCap, and Yahoo Finance, this study examines annual growth rates, standard deviations, and Pearson correlation coefficients to understand the dynamics of these diverse markets. The findings reveal significant volatility in the NFT and cryptocurrency markets, with NFTs experiencing an unprecedented growth rate of 5.552 percent from 2018 to 2019, followed by stabilization. In contrast, BTC and ETH exhibit notable fluctuations, reflecting the speculative nature of cryptocurrencies. The NASDAQ Index, representing traditional financial markets, displayed more consistent growth and lower volatility (Nath, 2020). These results suggest a complex interplay between the digital and traditional asset classes (Ante, 2022). This study highlights the importance of understanding market volatility and correlation patterns for investors and policymakers and emphasizes the need for adaptive investment strategies and regulatory frameworks in the evolving landscape of digital assets. Future research should focus on the causal factors influencing these market dynamics and the role of investor behavior in shaping market trends.
Francesco Maria De Collibus, Carlo Campajola, Guido Caldarelli, Claudio J. Tessone
We explore patterns, regularities, and correlations in the evolving landscape of Ethereum-based tokens, both ERC-20 (fungible) and ERC-721 (non-fungible) to understand the factors contributing to the rise in certain tokens over others. By applying network science methodologies, minimum spanning trees, econometric autoregressive–moving-average (ARMA) models, and the study of accumulation processes, we are able to highlight a rising centralisation process. Not only do “rich” tokens get richer, but past transactions also emerge as more reliable predictors of new transactions. Our findings are validated across different samples of tokens.
This research explores the integration of blockchain technology in healthcare, focusing on enhancing the security and efficiency of Electronic Health Record (EHR) management. We propose a novel Ethereum-based system that empowers patients with secure control over their medical data. Our approach addresses key challenges in healthcare blockchain implementation, including scalability, privacy, and regulatory compliance. The system incorporates digital signatures, Role-Based Access Control, and a multi-layered architecture to ensure secure, controlled access. We developed a decentralized application (dApp) with user-friendly interfaces for patients, doctors, and administrators, demonstrating the practical application of our solution. A survey among healthcare professionals and IT experts revealed strong interest in blockchain adoption, while also highlighting concerns about integration costs. The study explores future enhancements, including integration with IoT devices and AI-driven analytics, contributing to the evolution of secure, efficient, and interoperable healthcare systems that leverage cutting-edge technologies for improved patient care.
Abstract This article introduces a blockchain-based insurance scheme that integrates parametric and collaborative elements. A pool of investors, referred to as surplus providers, locks funds in a smart contract, enabling blockchain users to underwrite parametric insurance contracts. These contracts automatically trigger compensation when predefined conditions are met. The collaborative aspect is embodied in the generation of tokens, which are distributed to surplus providers. These tokens represent each participant’s share of the surplus and grant voting rights for management decisions. The smart contract is developed in Solidity, a high-level programming language for the Ethereum blockchain, and deployed on the Sepolia testnet, with data processing and analysis conducted using Python. In addition, open-source code is provided and main research challenges are identified, so that further research can be carried out to overcome limitations of this first proof of concept.
The world is witnessing a noticeable increase in financial exchange in digital currencies such as Bitcoin, Ethereum, and others, as transactions in electronic markets have begun to rise recently, which increases the difficulty of maintaining security and trust in decentralized financial systems that use distributed databases and the technologies that interact with them in Ethereum networks, blockchain, etc. This study presents a hybrid model based on the PyCaret library and includes 12 machine learning classifiers, with the aim of identifying fraudulent activities in Bitcoin transactions and enhancing the security of Ethereum networks and blockchain technology. The results reveal the effectiveness of different models in identifying fraudulent activities on the Ethereum network through a comprehensive performance comparison. The classifiers that showed the highest accuracy scores, which ranged from 0.9814 to 0.9862, were the Random Forest classifier, the visual gradient boosting machine, and the additive tree classifier. It is important to note that both Gradient Boosting Classifier and K Neighbors Classifier performed well, with accuracies above 0.96 and AUC scores above 0.99. However, some models, such as Naive Bayes, showed lower accuracy and AUC scores, suggesting that they have limitations in terms of accurately detecting fraudulent transactions. These results highlight the importance of choosing appropriate machine learning models for fraud detection tasks in general, with ensemble techniques such as Extra Trees and Random Forest showing great promise in this regard.
In South Africa, many people are homeless or doing informal work for which they receive small amounts of cash from caring individuals. The world is moving towards cashless transactions, but devices are needed to support that move. Many people in need cannot afford such devices and usually receive cash, but fewer donors carry cash. Consequently, people in need receive less informal financial support. We propose a system that allows donors to give digital vouchers that can be redeemed at participating stores and institutions of care. This study aimed to investigate the use of blockchain technology in digital voucher management and to demonstrate the application of smart contracts to disintermediate the value transfer process specific to the donation process. A demonstrator was built to include a front end for the user to interact with and a back end containing the application logic, which was built on the Polygon blockchain, a second-layer solution for the Ethereum blockchain. The model included tokenising vouchers as non-fungible tokens, and the smart contracts governed their logic and the conditions to be met. The demonstrator was validated using smart contract and unit tests to evaluate the security and functionality. While the model was not implemented in reality, a fully functioning demonstrator was developed. The platform achieved the aim of disintermediating the voucher management process. A real-world implementation could help many in need to receive tokens for food, shelter and clothing from direct, individual donors.
Shabnam Fazliani, Mohammad Mowlavi Sorond, Arsalan Masoudifard
The advent of smart contracts has enabled the rapid rise of Decentralized Finance (DeFi) on the Ethereum blockchain, offering substantial rewards in financial innovation and inclusivity. This growth, however, is accompanied by significant security risks such as illicit accounts engaged in fraud. Effective detection is further limited by the scarcity of labeled data and the evolving tactics of malicious accounts. To address these challenges with a robust solution for safeguarding the DeFi ecosystem, we propose $\textbf{SLEID}$, a $\textbf{S}$elf-$\textbf{L}$earning $\textbf{E}$nsemble-based $\textbf{I}$llicit account $\textbf{D}$etection framework. SLEID uses an Isolation Forest model for initial outlier detection and a self-training mechanism to iteratively generate pseudo-labels for unlabeled accounts, enhancing detection accuracy. Experiments on 6,903,860 Ethereum transactions with extensive DeFi interaction coverage demonstrate that SLEID significantly outperforms supervised and semi-supervised baselines with $\textbf{+2.56}$ percentage-point precision, comparable recall, and $\textbf{+0.90}$ percentage-point F1 -- particularly for the minority illicit class -- alongside $\textbf{+3.74}$ percentage-points higher accuracy and improvements in PR-AUC, while substantially reducing reliance on labeled data.
This paper addresses the challenge of preserving user privacy within the Internet of Things (IoT) ecosystem using blockchain technology. Several approaches consider using blockchain and encryption to enhance the privacy of IoT applications and constrained IoT devices. However, existing blockchain platforms such as Ethereum and Hyperledger Fabric already use encryption to store data blocks and secure communication. Therefore, introducing an additional cryptographic layer on top of these platforms could potentially increase processing overhead and reduce response time. In this work, we investigate the integration of IoT and blockchain for privacy preservation. More specifically, we propose a new model that leverages the properties of private blockchain and smart contracts to ensure user data privacy when shared with others. We define policy-based algorithms and notations to assist users in managing smart contracts responsible for registering and controlling their IoT devices. We also specify multiple smart contracts designed to enhance privacy by creating a private channel for communication between the user and the blockchain network.
Smart contracts are self-executing programs on blockchain platforms like Ethereum, which have revolutionized decentralized finance by enabling trustless transactions and the operation of decentralized applications. Despite their potential, the security of smart contracts remains a critical concern due to their immutability and transparency, which expose them to malicious actors. Numerous solutions for vulnerability detection have been proposed, but it is still unclear which one is the most effective. This paper presents a systematic literature review that explores vulnerabilities in Ethereum smart contracts, focusing on automated detection tools and benchmark evaluation. We reviewed 3,380 studies from five digital libraries and five major software engineering conferences, applying a structured selection process that resulted in 222 high-quality studies. The key results include a hierarchical taxonomy of 192 vulnerabilities grouped into 13 categories, a comprehensive list of 219 detection tools with corresponding functionalities, methods, and code transformation techniques, a mapping between our taxonomy and the list of tools, and a collection of 133 benchmarks used for tool evaluation. We conclude with a discussion about the insights into the current state of Ethereum smart contract security and directions for future research.
The modern food supply chain often involves multiple layers of participants spread across different countries and continents. This complex system offers significant benefits to businesses worldwide; however, it also presents several challenges. One major problem is the inability to trace the product flow back to its origin, a critical issue in many industries. Another issue is the lack of trust among supply chain participants. Blockchain technology can help address these and other challenges faced by the supply chain industry. However, it is surprising that, globally, there are still not many examples of the technology's adoption, with most projects remaining in the pilot stage. This paper explores the field of custom blockchain design tailored to specific applications, with a focus on supply chain operations in the food industry. It includes the development of a lightweight yet fully featured Python prototype for a decentralized blockchain system. In addition to common features like block validation and state updates, the prototype includes a newly designed type of transaction tailored specifically for supply chain operations. These transactions eliminate the need for smart contracts, making the system more lightweight compared to general-purpose blockchain platforms such as Ethereum and less prone to security vulnerabilities. The prototype is designed as a public blockchain network, with Proof of Work selected as the consensus algorithm. The novelty of this research work lies in advancing the concept of a custom blockchain solution for the food industry. The key elements of the prototype have been unit tested. The overall evaluation was completed using a Python script that simulates product flow through an example supply chain, allowing product provenance to be determined by tracing the product flow back to its origin.
The aim of this article is to examine the reasons why cryptocurrency volatility hinders its potential to replace fiat money as legal tender. We focus on Bitcoin and Ethereum for this analysis. By applying an augmented Dickey-Fuller stationarity test, we demonstrate that cryptocurrencies lack a long-term trend; instead, their movement is erratic and highly volatile. Furthermore, eGARCH models indicate that volatility tends to decrease and is expected to persist in this pattern. In summary, theoretical and empirical analysis suggests that, due to their nature based solely on supply and demand and their high volatility, cryptocurrencies are not suitable as primary investment instruments or stores of value.
The Domain Name System (DNS) has been providing a decentralized global namespace to support all Internet applications and usages over the last few decades. In the recent years, a number of blockchain-based name systems have emerged with the claim of providing better namespace decentralization than DNS. The community at large seems uncertain with regard to which of these systems is the best in providing decentralized Internet namespace control. In this paper, we first deconstruct the design of DNS, identify its three essential components and explain who controls each of them. We then examine the Ethereum Name Service (ENS) as a representative example of blockchain-based naming systems, gauge the degree of its decentralization. Finally, we conduct a comparative analysis between DNS and ENS to assess the validity and affordability of each design and the (de)centralization in their namespace control and name system operations.
A privacy pool enables clients to deposit units of a cryptocurrency into a shared pool where ownership of deposited currency is tracked via a system of cryptographically hidden records. Clients may later withdraw from the pool without linkage to previous deposits. Some privacy pools also support hidden transfer of currency ownership within the pool. In August 2022, the U.S. Department of Treasury sanctioned Tornado Cash, the largest Ethereum privacy pool, on the premise that it enables illicit actors to hide the origin of funds, citing its usage by the DPRK-sponsored Lazarus Group to launder over $455 million dollars worth of stolen cryptocurrency. This ruling effectively made it illegal for U.S. persons/institutions to use or accept funds that went through Tornado Cash, sparking a global debate among privacy rights activists and lawmakers. Against this backdrop, we present Derecho, a system that institutions could use to request cryptographic attestations of fund origins rather than naively rejecting all funds coming from privacy pools. Derecho is a novel application of proof-carrying data, which allows users to propagate allowlist membership proofs through a privacy pool's transaction graph. Derecho is backwards-compatible with existing Ethereum privacy pool designs, adds no overhead in gas costs, and costs users only a few seconds to produce attestations.
Ertem Nusret Tas, István András Seres, Yinuo Zhang, Márk Melczer · 7 authors
We introduce a blockchain Fair Data Exchange (FDE) protocol, enabling a storage server to transfer a data file to a client atomically: the client receives the file if and only if the server receives an agreed-upon payment. We put forth a new definition for a cryptographic scheme that we name verifiable encryption under committed key (VECK), and we propose two instantiations for this scheme. Our protocol relies on a blockchain to enforce the atomicity of the exchange and uses VECK to ensure that the client receives the correct data (matching an agreed-upon commitment) before releasing the payment for the decrypting key. Our protocol is trust-minimized and requires only constant-sized on-chain communication, concretely 3 signatures, 1 verification key, and 1 secret key, with most of the data stored and communicated off-chain. It also supports exchanging only a subset of the data, can amortize the server's work across multiple clients, and offers a general framework to design alternative FDE protocols using different commitment schemes. A prominent application of our protocol is the Danksharding data availability scheme on Ethereum, which commits to data via KZG polynomial commitments. We also provide an open-source implementation for our protocol with both instantiations for VECK, demonstrating our protocol's efficiency and practicality on Ethereum.
Burhan Ul Islam Khan, Asadullah Shah, Khang Wen Goh, Rusnardi Rahmat Putra · 6 authors
This paper presents a pioneering analytical framework for a secure payment system leveraging blockchain technology tailored to regions with suboptimal network connectivity. Contemporary payment mechanisms utilizing Ethereum are predominantly optimized for areas with robust network infrastructure, neglecting regions with less connectivity. To address this gap, the proposed model integrates novel security attributes and employs an analytical method to design a decentralized payment system. The framework facilitates communication between low-connectivity zones and Internet service providers through auxiliary nodes, creating a local blockchain network for residents, merchants, and auditors. A mathematical model quantifies operational costs, transaction processing, and synchronization of auxiliary nodes, ensuring a resilient and secure payment architecture. A unique aspect of the proposed approach is its robustness against auditor outages and network variability, coupled with an empirical analysis of incentive structures for auditors' block validation activities. Moreover, it delineates the minimum requirements for secure transaction completion. Empirical findings showed a significant improvement in system efficiency, including a 79% reduction in block time, a 28% increase in transaction throughput, a 30% decrease in energy consumption, a 68% shorter confirmation time, a 63% reduction in execution time, a 46% increase in block production rate, and 82% reduced network variability. This study's significant contribution lies in introducing a sustainable, cost-effective, and secure payment system for regions with inadequate network services.
This paper presents the first comprehensive analysis of the address poisoning attack surged on the Ethereum blockchain. This phishing attack typically exploits the address shortening feature of Ethereum explorers and digital wallets (e.g., Etherscan and MetaMask) by crafting token transfer events with a seemingly correct address to poison victims' transfer history, waiting for them to mistakenly transfer assets to the attacker's address.
Burhan Ul Islam Khan, Khang Wen Goh, Megat F. Zuhairi, Rusnardi Rahmat Putra · 6 authors
Amidst the rising demands for data security across expansive networks, blockchain technology is witnessing an upsurge in its adoption, particularly within Internet of Things (IoT) applications, services, and smart cities. Blockchains offer an immutable property that bolsters security and aids in the structured management of distributed ledgers. Nevertheless, ensuring scalability remains a formidable challenge, especially within decentralized Ethereum systems. Current methods often fall short of offering tangible solutions, and the scrutiny of Ethereum-based cases reveals persistent deficiencies in addressing scalability issues due to inherent system complexities, dependency on resource-intensive consensus algorithms, lack of optimized storage solutions, and challenges in ensuring synchronous transaction validation across a decentralized network. This paper proposes a foundational scheme underpinned by a unique graph-based topology and hash bindings for nodes that join the system. The proposed scheme establishes an innovative indexing mechanism for all transactions and blocks within the IoT framework, ensuring optimal node accessibility. Transaction and block replications occur over the joining nodes' graphical structure, ensuring efficient subsequent retrieval. A standout feature of the proposed scheme is its ability to enable participating nodes to forgo retaining a complete ledger, making it non-reliant on individual node capabilities. Consequently, this facilitates a broader spectrum of nodes to participate in the consensus system, irrespective of their operational prowess. This study also offers a novel empirical model for Proof-of-Validation (PoV), which reduces computational intricacy and expedites the validation process in stark contrast to prevailing blockchain systems.
Cong Wu, Jing Chen, Ziming Zhao, Kun He · 10 authors
Decentralized finance has experienced phenomenal growth, revolutionizing the landscape of financial transactions and asset management via blockchain. Yet, this swift growth brings with it substantial challenges, notably the surge in scam tokens, imposing significant security threats on cryptocurrency investments and trading. Existing detection methods of scam token, primarily relying on analyzing contract codes or transaction patterns, struggle to catch increasingly sophisticated tactics employed by scammers. For example, contract-based analysis are unable to identify scams lacking overt malicious code, e.g., most rugpulls, while transaction-based methods generally lack the foresight to early-detect potential risks.
The COVID-19 pandemic has severely affected the world in terms of health, economy and peace. Fortunately, the countries are trying to overcome the situation by actively carrying out vaccinations. However, like any other massive operation involving humans such as human resource management, elections, surveys, etc., the vaccination process raises several questions about citizen privacy and misuse of personal data. In most of the countries, few attempts have been made to verify the vaccination statistics as reported by the health centers. These issues collectively require the solutions of anonymity of citizens' personal information, immutability of vaccination data and easy yet restricted access by adversarial bodies such as the government for the verification and analysis of the data. This paper introduces a blockchain-based application to simulate and monitor the vaccination process. The structure of data model used in the proposed system is based on the IEEE Standard for Data Format for Blockchain Systems 2418.2TM-2020. The proposed system enables authorized stakeholders to share and access relevant information for vaccination process chain while preserving citizen privacy and accountability of the system. It is implemented on the Ethereum blockchain and uses a Python API for the simulation and validation of each step of the vaccination process.