The Internet pervades many aspects of modern life offering up seemingly boundless opportunities to connect, inform and be informed. As the range and number of sources for information online explode, how people go about selecting and interpreting information has become a pertinent area for study, not least in the recent light of the prevalence of fake-news—as people are well known to act upon information they believe to be trustworthy. Where the decision to act incurs risk, an inability to accurately select and assess the credibility of information presents a challenge. <br/><br/>This extended abstract summarizes findings from a study of 57 Bitcoin users. Our analysis shows that this self-identifying technical and expert community was not significantly influenced by confirmation bias (a facet of fake-news). However, the same users also failed to demonstrate a true reliance upon the facts contained in news articles, often deferring trust to the source of the news which could still render them susceptible to fake-news, and, in turn, place their speculation of the crypto-currency at risk.
Cross-institutional healthcare predictive modeling can accelerate research and facilitate quality improvement initiatives, and thus is important for national healthcare delivery priorities. For example, a model that predicts risk of re-admission for a particular set of patients will be more generalizable if developed with data from multiple institutions. While privacy-protecting methods to build predictive models exist, most are based on a centralized architecture, which presents security and robustness vulnerabilities such as single-point-of-failure (and single-point-of-breach) and accidental or malicious modification of records. In this article, we describe a new framework, ModelChain, to adapt Blockchain technology for privacy-preserving machine learning. Each participating site contributes to model parameter estimation without revealing any patient health information (i.e., only model data, no observation-level data, are exchanged across institutions). We integrate privacy-preserving online machine learning with a private Blockchain network, apply transaction metadata to disseminate partial models, and design a new proof-of-information algorithm to determine the order of the online learning process. We also discuss the benefits and potential issues of applying Blockchain technology to solve the privacy-preserving healthcare predictive modeling task and to increase interoperability between institutions, to support the Nationwide Interoperability Roadmap and national healthcare delivery priorities such as Patient-Centered Outcomes Research (PCOR).
Today's vehicles are becoming cyber-physical systems that not only communicate with other vehicles but also gather various information from hundreds of sensors within them. These developments help create smart and connected (e.g., self-driving) vehicles that will introduce significant information to drivers, manufacturers, insurance companies, and maintenance service providers for various applications. One such application that is becoming crucial with the introduction of self-driving cars is forensic analysis of traffic accidents. The utilization of vehicle-related data can be instrumental in post-accident scenarios to discover the faulty party, particularly for self-driving vehicles. With the opportunity of being able to access various information in cars, we propose a permissioned blockchain framework among the various elements involved to manage the collected vehicle-related data. Specifically, we first integrate vehicular public key infrastructure (VPKI) to the proposed blockchain to provide membership establishment and privacy. Next, we design a fragmented ledger that will store detailed data related to vehicles such as maintenance information/ history, car diagnosis reports, and so on. The proposed forensic framework enables trustless, traceable, and privacy-aware post-accident analysis with minimal storage and processing overhead.
Vehicular Ad Hoc Networks (VANETs) play a vital role in enabling smart transportation systems by facilitating communication between vehicles. However, existing vehicular announcement systems face two major challenges: preserving user privacy and motivating users to share reliable traffic information. In this paper, we propose CreditCoin, a privacy-presing blockchain-based incentive announcement network. The system utilizes an anonymous vehicular announcement aggregation protocol combined with blockchain technology to ensure secure, tamper-resistant, and decentralized communication. Users can broadcast traffic updates anonymously while earning incentives for participation, thereby improving network reliability. A Trace Manager enables conditional privacy by identifying malicious users without compromising honest participants. The proposed system is implemented using Python, Web3, and a simulated VANET environment. Experimental results demonstrate improved efficiency, reduced computation time, and enhanced data reliability compared to traditional approaches. This work contributes toward secure and incentive-driven communication in smart transportation systems. In this paper, we propose CreditCoin, a privacy-preserving blockchain-based incentive announcement network. The system utilizes an anonymous vehicular announcement aggregation protocol combined with blockchain technology to ensure secure, tamper-resistant, and decentralized communication. Users can broadcast traffic updates anonymously while earning incentives for participation, thereby improving network reliability. A Trace Manager enables conditional privacy by identifying malicious users without compromising honest participants. Keywords— VANET; Blockchain; Privacy Preservation; Incentive Mechanism; Smart Vehicles; CreditCoin
Hanyue Guo, Jiting Zhou, Jiaqi Wang, Xiaodong Wang
Leakage of user privacy and vandalism of the sharing bike have been the most serious problem since sharing bike came on the scene. Accordingly, it is very urgent to rebuild the underlying trust mechanism. Most bike sharing systems are centralized, leading to overpressure on the central server. This paper proposes a bike sharing system based on blockchain service platform and a shared operation mode of C2C. The system uses the blockchain system as the trust guarantee. The extra chain payment - lightning network is used to improve the efficiency of the blockchain system and the smart contract is used to provide the rights and interests of the two parties.
Healthcare data exists in silos. These siloed systems lack open standards surrounding how data is stored, labeled, and tagged. In turn, these data silos decrease data liquidity, or the ability of data to flow throughout the healthcare system. Undeniably, the healthcare industry sees the value in responsibly sharing health data to extract more value and new insights using predictive analytics, open science, and collaborative solutions. Effective collaboration requires collaborative data. Particularly with health-related data, “sending that data from one peer to another in a secure manner, in a compliant manner, and in a transparent manner” is vital. While organizations share this sentiment, a complex regulatory framework combined with data usage agreements and non-interoperable, proprietary databases add friction to this data exchange. Particularly in healthcare, blockchain enables greater transparency between healthcare professionals sharing data, and it empowers patients to have control over their data. First, this paper briefly discusses blockchain. Next, this paper outlines issues that plague the healthcare industry including the laws that serve as the framework. Finally, this paper discusses architecture considerations for a blockchain based healthcare data exchange that also respects the current regulatory environment.
Digital identities and credentials are gradually replacing physical documents, as they can be verified with more accuracy and efficiency. Since online privacy is becoming more crucial than ever, it is essential to preserve the privacy of individuals whenever possible. Therefore, anonymous attestation of digital credentials should be feasible, where provers can selectively disclose attributes and create abstractions over attributes in their credential, in order to solely disclose the minimum amount of information required to complete the goal of verification.<br/><br/>Many schemes in the field of attribute-based credentials consider a single root authority issuing credentials to provers. This is coherent to the traditional way of the issuance of credentials since the process of producing physical documents is costly to distribute to multiple issuers. Digital identities provide the opportunity for authorities to distribute credential issuance rights (consecutively) to smaller entrusted entities.<br/><br/>To the best of our knowledge, we propose the first protocol which combines both anonymous attestation with attribute-based credentials and the delegation of selective signing rights for the issuance of these credentials. Root authorities could delegate signing rights for selective attributes consecutively to trustees, which are able to create anonymous attribute-based credentials with the acquired attributes for provers. Verifiers are able to verify presentation tokens with solely the public key of the root authority, without gaining knowledge about the identities of the prover and intermediate delegators. We introduce three adapted signature schemes based on existing work in order to realize a concrete instantiation of the protocol. Anonymity is achieved by incorporating Schnorr's zero-knowledge proof of knowledge with bilinear pairings to efficiently prove the correctness of presentation tokens.<br/><br/>We realized a prototype of our concrete instantiation and optimized the verification algorithm in order to achieve optimal pairing performance. Complexity analysis of the protocol shows improvement in efficiency by aggregating attribute signatures throughout signing right delegation. Experimental results demonstrate a degree of practical feasibility for the verification of presentation tokens on commodity hardware within the challenging public transportation access control time bound of 300 ms.<br/>
A device-to-device (D2D) underlying cellular network is pervasive to support various wireless applications. However, due to the dramatic increase of data transmission in the network with limited amount of wireless resource, a few users may be required to temporarily disconnect from the network to avoid the interruption of data transmission in the whole network. A critical issue of determining the user access in D2D underlying networks is the authenticity of channel state information (CSI), and usually, a user with a higher CSI can be allocated a larger amount of wireless resource or have a higher probability of staying in the network. In this paper, we propose a blockchain consensus-based scheme to verify the authenticity of CSI and add the users who intentionally advocate a higher value of CSI into a fraud chain. Also, we consider both the cross-tier interference caused by a mobile user and the presence of a user in the fraud chain to determine the access of a user. The analysis results show that our proposed user access scheme can enhance the network performance by efficiently controlling the use access in mobile applications.
Electronic Health Records (EHRs) are both crucial and sensitive as they contain essential information and are frequently shared among different parties including hospitals, pharmacies or private clinics. This information must remain correct, up to date, private, and accessible only to the authorized people. Moreover, the access must also be assured under special conditions mass crises like hurricanes or earthquakes where disruption, decentralized responses, and chaos could potentially lead to wrong procedures or even malicious behaviors. The introduction of blockchain a distributed ledger where the records are stored in a linked sequence of blocks and are theoretically difficult to delete or tamper with made possible to design and implement new solutions for more failure-resistant EHRs applications adopting a distributed and decentralized philosophy, in contrast with the central ones based on cloud infrastructures or even local solutions. In this context, this work provides a systematic study to understand whether permissioned blockchain implementations could be of any benefit to managing health records in emergency situations caused by natural disasters. After the design and implementation of a basic prototype for an EHRs management system in Hyperledger Fabric and the execution of a set of test cases based on the simulation of the Haiti earthquake of 2010, it was possible to discuss the benefits and tradeoffs that the system entails. The discussion focused on the performance parameters like throughput, latency, memory and CPU usage. The system allowed the patients and practitioners to share and access EHRs and be able to detect and react to the crisis situations. Moreover, it behaved correctly in the presence of malicious nodes assuring throughputs and latencies still lower, compared to current centralized systems like credit card payments, but already up to two orders of magnitude higher than permissionless blockchain implementations. Even though there is still a lot of work to do, the system represented by the prototype could be an interesting alternative for networks of healthcare companies to help ensuring the continuity of treatment while preserving privacy and confidentiality in extreme situations.
The vehicle to everything (V2X) requires the real-time integration of all kinds of information on roads, pedestrians, the environment, and vehicles themselves. This information also needs to be shared with other vehicles. The effective integration of information and the strong privacy protection are the key restrictions on the development of the V2X. The previous privacy protection model has mainly focused on the centralized network, and there were problems with the centralized gateway and single-point decision, which were not suitable for the decentralized scenario. Therefore, this paper proposes a remote attestation security model based on a privacy-preserving blockchain. The overall model involves two core steps. First, the vehicle provides the network with an evidence of a credible identity and integrity. Secured, the vehicles in the network calculate the nodes to make their respective decisions, and the accounting nodes summarize the sub-conclusions, form the final results, and write them into data blocks. The analysis shows that it possesses the security features of decentralization, traceability, anonymity, irreplaceability, and high efficiency. The model framework, core block chain structure, and protocol process are described in detail. The experimental results based on a realistic infrastructure are presented. These experimental results demonstrate that our scheme can effectively enhance the security of the communications of intelligent vehicles in the V2X.
Blockchain can potentially be deployed in a wide range of applications due to its capability to ensure decentralization, transparency, and immutability. In this paper, we design a cryptographic membership authentication scheme (i.e., authenticating graph data) to support blockchain-based identity management systems (BIMS). Such a system is designed to bind a digital identity object to its real-world entity. Specifically, we introduce a new transitively closed undirected graph authentication (TCUGA) scheme, which only needs to use node signatures (e.g., certificates for identifying nodes). The trapdoor hash function used in our scheme allows the signer to efficiently update the certificates without the need to re-sign the nodes. In other words, our scheme is efficient even though the graph dynamically adds or deletes vertices and edges. Moreover, our proposal can efficiently provide a proof when the edge between two vertices does not exist, thus solving the existing intractability issue in transitive signature (the main tool for authenticating graph data). Finally, we prove the security of our proposed TCUGA in the standard model and evaluate its performance to show its feasibility for BIMS.
On an EU level, the topic of electronic health data is a high priority. Many projects have been developed to realise a standard health data format to share information on a regional, national or EU level. All the projects favour and contribute to the development and improvement of the prerequisites for intra- and cross-border patient mobility. This work presents a new approach for the implementation of disruptive logging: an audit mechanism for cross-border exchange of eHealth data on OpenNCP, providing traceability and liability support within the OpenNCP infrastructure. Relevant parties could be legally obliged to keep a log of all privacy-critical operations performed by OpenNCP users.
Noureddine Lasla, Mohamed Younis, Wassim Znaïdi, Dhafer Ben Arbia
Cooperative Intelligent Transportation System (C- ITS) enables inter-networking of vehicles for alerts exchanging in order to improve road safety. While this technology is about to enter the market in the upcoming years, critical questions related to the communication security continue to be challenging research concerns. Current solutions to secure inter-vehicle communication depend mainly on the use of digital certificates for authentication. However, such an approach imposes significant overhead on vehicles since it is computationally demanding and requires validation of the certificate within a limited period. In addition, relying on a central node for deciding on issuing and revoking certificates introduces a single point of failure and could even risk the safety of motorists. In this paper, we propose the use of Blockchain to keep track of the certificate of each vehicle (valid or revoked) in distributed and immutable records. In essence we replace certificate verification with a lightweight blockchain-based authentication approach. In addition, we propose a fully distributed vehicle admission/revocation scheme. We show that our scheme could alleviate the computation overhead and enhance the response time while improving the overall system security.
Privacy in online applications has drawn tremendous attention in recent years. With the development of cloud-based applications, protecting users' privacy while guaranteeing the expected service from the server has become a significant issue. This paper surveyed the most popular cryptographic algorithms in privacy-preserving online applications to provide a tutorial-like introduction to researchers in this area. Specifically, this paper focuses on introduction to homomorphic encryption, secret sharing, secure multi-party computation and zero-knowledge proof.
Yinghui Zhang, Robert H. Deng, Jiangang Shu, Kan Yang · 5 authors
As a very attractive computing paradigm, cloud computing makes it possible for resource-constrained users to enjoy cost-effective and flexible resources of diversity. Considering the untrustworthiness of cloud servers and the data privacy of users, it is necessary to encrypt the data before outsourcing it to the cloud. However, the form of encrypted storage also poses a series of problems, such as: How can users search over the outsourced data? How to realize user-side verifiability of search results to resist malicious cloud servers? How to enable server-side verifiability of outsourced data to check malicious data owners? How to achieve payment fairness between the user and the cloud without introducing any third party? Towards addressing these challenging issues, in this paper, we introduce TKSE, a trustworthy keyword search scheme over encrypted data without any third party, trusted or not. In TKSE, the encrypted data index based on digital signature allows a user to search over the outsourced encrypted data and check whether the search result returned by the cloud fulfills the pre-specified search requirements. In particular, for the first time, TKSE realizes server-side verifiability which protects honest cloud servers from being framed by malicious data owners in the data storage phase. Furthermore, blockchain technologies and hash functions are used to enable payment fairness of search fees without introducing any third party even if the user or the cloud is malicious. Our security analysis and performance evaluation indicate that TKSE is secure and efficient and it is suitable for cloud computing.
David Mendes, Irene Pimenta Rodrigues, César Fonseca, Manuel José Lopes · 6 authors
We introduce our solution developed for data privacy, and specifically for cognitive security that can be enforced and guaranteed using blockchain technology in SAAL (Smart Ambient Assisted Living) environments. Personal clinical and demographic information segments to various levels that assures that it can only be rebuilt at the interested and authorized parties and no profiling can be extracted from the blockchain itself. Using our proposal the access to a patient's clinical process resists tampering and ransomware attacks that have recently plagued the HIS (Hospital Information Systems) in various countries. The core of the blockchain model assures non-repudiation possible by any of the involved information producers thus maintaining ledger fidelity of the enclosed historical process information. One important side effect of this data infrastructure is that it can be accessed in open form, for research purposes for instance, since no individual re-identification or group profiling is possible by any means.
Internet of Things (IoT) and cloud computing are increasingly integrated, in the sense that data collected from IoT devices (generally with limited computational and storage resources) are being sent to the cloud for processing, etc., in order to inform decision making and facilitate other operational and business activities. However, the cloud may not be a fully trusted entity, like leaking user data or compromising user privacy. Thus, we propose a privacy‐preserving and user‐controlled data sharing architecture with fine‐grained access control, based on the blockchain model and attribute‐based cryptosystem. Also, the consensus algorithm in our system is the Byzantine fault tolerance mechanism, rather than Proof of Work.
In Bitcoin financial system, a user’s privacy is supposed to be protected by means of anonymity. However, the anonymity makes illegal trades possible because nobody is able to reveal the real identities of the illegal users. In this paper, we propose a regulation scheme based on the ciphertext-policy hierarchical attribute-based encryption (CP-HABE). In the scheme, users’ identities are encrypted by using access policy and are contained in their transaction. A type of user is defined as the dependable regulation node, which is responsible for the regulation of transactions and encrypted identities. A new signature algorithm instead of the elliptic curve signature is adopted to generate wallet key pairs, this establishes a connection between wallet addresses and encrypted identities. When a transaction is doubted to involve illegal activities, the authorized regulation nodes are capable of revealing the users’ real identities and add the illegal identities to a public blacklist. Our system is based on a new CP-HABE scheme which is proved to be secure against chosen-plaintext attack in the standard model under the Bilinear Diffie–Hellman Exponent assumption. Finally, we give a performance analysis of our system. The proposed regulation system can reveal criminals’ identities undertaking illegal activities.