Shunli Ma, Yi Deng, Mengqiu Bai, Debiao He · 6 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
3,460 results · page 109 of 145
Shunli Ma, Yi Deng, Mengqiu Bai, Debiao He · 6 authors
No abstract is available for this record.
James P. Howard, Maria E. Vachino
Under current Federal Information Security Management Act of 2002 (FISMA) requirements, all new federal IT programs and modernization efforts using blockchain must meet National Institute of Standards and Technology (NIST) cryptographic standards. This article evaluates four major blockchain technologies-Ethereum, Hyperledger Fabric, R3's Corda, and Multichain-to determine their level of NIST compliance.
Shashank Agrawal, Srinivasan Raghuraman
No abstract is available for this record.
Mazin Debe, Khaled Salah, Raja Jayaraman, Junaid Arshad
An enormous amount of drug supply is regularly wasted due to several reasons related to incorrect prescription, purchase of unnecessary quantities, drug intolerance, allergy, or interactions. On the other hand, these medicines may be needed by patients who cannot afford to purchase them. To address this challenge, we propose a fully decentralized solution that governs the return and redistribution of unused drugs that are fit for usage. Our approach exploits the decentralized blockchain technology, smart contracts, and decentralized storage systems such as the Interplanetary File Systems (IPFS). We develop a system that provides the ability for customers as well as pharmacies to return re-usable, resellable drugs for donation or resale at a lower price. The proposed scheme tracks the production of drugs from manufacturers to traders that subsequently sell them to customers. Unused drugs can be returned after approval by specialized entities and then redistributed. In particular, we present the decentralized system architecture and implement a prototype on a test Ethereum blockchain platform to present the suggested workflow. Further, we provide system evaluation focused on assessing system functionality, performance, execution cost, and security of smart contracts and their robustness. We have also made our smart contracts code publicly available on Github.
Xiaodong Yang, Xizhen Pei, Meiding Wang, Ting Li · 5 authors
Cloud storage services provide convenient data storage services for individuals and enterprises. Data owners can remotely access and update outsourcing data. But there are still many security problems, such as data integrity. Although the public audit schemes allow users to authorize third-party auditors (TPA) to verify the integrity of cloud data, there are still a series of problems in the existing public audit schemes. First of all, most of the existing schemes are based on the traditional or identity public key infrastructure. There is a problem of certificate management or key escrow. And they do not support dynamic data update and user identity tracking for group users. Then, existing multi-replica data public audit schemes store all replicas on a cloud storage server. Once the cloud server fails, all replicas will be damaged. Finally, most existing schemes require TPA to be trusted. In practice, TPA may deviate from the public audit protocol or collude with cloud servers to deceive users. To solve these problems, we propose a certificateless multi-replica and multi-cloud data public audit scheme based on blockchain technology. In our scheme, the dynamic hash table and modification record table are introduced to achieve dynamic update of group user data and identity tracking. All replicas are stored in different cloud servers, and their integrity can be audited at the same time. In addition, we use the unpredictability of blocks in the blockchain to construct fair challenge information, thereby preventing malicious TPA and cloud servers from colluding to deceive users. Each audit result is written into the blockchain, which is convenient for users to audit the behavior of TPA. The analysis results show that our proposed scheme is secure in the random oracle model and has higher efficiency in communication and computation cost compared with similar schemes.
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada, Takashi Yamakawa
No abstract is available for this record.
Xixi Yan, Xiaohan Yuan, Qing Ye, Yongli Tang
In order to solve the problem that most of the existing blockchain-based searchable encryption schemes only support exact keyword search and mutual distrust between the cloud server and the user, a searchable encryption scheme based on blockchain, that has functions such as file update dynamically, search results verification, fuzzy keyword search, and fair payment, is proposed. We use edit distance to generate the fuzzy keywords set. According to the un-modification characteristic of Ethereum blockchain and the security of the RSA accumulator, our scheme can verify the search results by the smart contract and realize the service-payment fairness between the user and the cloud server. The security analysis shows that the proposed scheme achieves non-adaptive semantic security. Performance analysis and experiment show that our scheme is efficient and meets the demand of search application in the cloud environment.
Rui Carreira, Pedro Pinto, António Pinto
No abstract is available for this record.
Rémi Clarisse, Olivier Sanders
No abstract is available for this record.
Theophilus Onyekachukwu Oshoba, Nafiu Ikeoluwa Hammed, Olushola Damilare Odejobi
As organizations increasingly adopt cloud computing to achieve scalability and agility, ensuring compliance and maintaining secure audit trails in cloud configuration management have become critical challenges. Traditional configuration management approaches often lack transparency, are vulnerable to tampering, and offer limited assurance to regulators and stakeholders in highly regulated industries such as finance, healthcare, and government. This paper proposes a Blockchain-Enabled Compliance and Audit Trail Model for Cloud Configuration Management, designed to enhance accountability, trust, and regulatory alignment through the integration of distributed ledger technology. The model employs a layered architecture comprising configuration management tools, a blockchain layer, compliance enforcement mechanisms, and user-facing dashboards. Configuration changes initiated through DevOps pipelines or cloud-native tools are first validated against compliance requirements, such as GDPR, HIPAA, or ISO 27001. Approved changes are then immutably recorded on a blockchain, ensuring tamper-proof logs that serve as an authoritative audit trail. Smart contracts embedded within the blockchain automate compliance enforcement by validating configuration states in real time, rejecting or flagging non-compliant changes before deployment. Key features of the framework include immutable audit trails, automated compliance validation, multi-stakeholder transparency, and cryptographic assurance of integrity. The use of blockchain ensures that no single entity can alter audit records, fostering trust between cloud providers, enterprises, and regulators. Interoperability with APIs allows integration into diverse cloud environments and DevOps workflows, enabling seamless adoption without disrupting existing operations. Use cases span across sectors where compliance is mission-critical: financial services requiring stringent auditability, healthcare systems protecting sensitive patient data, and government services demanding transparent accountability. While challenges remain—such as blockchain scalability, transaction costs, and integration complexity—the model offers a promising pathway toward resilient, compliance-driven cloud governance. Ultimately, it transforms cloud configuration management into a secure, verifiable, and regulator-friendly ecosystem.
Di Wang, Yan Zhu, Yi Zhang, Guowei Liu
Classified protection is one of primary security policies of information system in many countries. With the increasing popularity of blockchain in various fields of applications, it is extremely necessary to promote classified protection for blockchain's risk assessment in order to push forward the sustainable development of blockchain. Taking the Level 3 in Chinese classified protection 2.0 as an example, this paper proposes the common evaluation rules on blockchain to ensure that blockchain can meet the needs of countries to build it as critical infrastructure. Both assessment requirements and enforcement proposals are presented and analyzed from the standpoint of blockchain's core technologies, e.g., peer-to-peer network, distributed ledger, contract's scripting system, and consensus mechanism. Moreover, the assessment results on three main platforms, Bitcoin, Ethereum, and Hyperledger, are summarized and analyzed in compliance with the control points specified in the level 3. Our investigation indicates that the current blockchain is able to satisfy the requirements of evaluation items in many aspects, such as software fault tolerance, resource control, backup and recovery, but further improvements are still needed for some aspects, including security audit, access control, identification and authentication, data integrity, etc., in order to satisfy the requirements of important fields on national security, economic development and human life.
Vangelis Malamas, Panayiotis Kotzanikolaou, Thomas K. Dasaklis, Mike Burmester
The health care ecosystem involves various interconnected stakeholders with different, and sometimes conflicting security and privacy needs. Sharing medical data, sometimes generated by remote medical devices, is a challenging task. Although several solutions exist in the literature covering functional requirements such as interoperability and scalability, as well as security & privacy requirements such as fine-grained access control and data privacy, balancing between them is not a trivial task as off-the-shelf solutions do not exist. On one hand, centralized cloud architectures provide scalability and interoperable access, but make strong trust assumptions. On the other, decentralized blockchain based solutions favor data privacy and independent trust management, but typically do not support dynamic changes of the underlying trust domains. To cover this gap, in this paper, we present a novel hierarchical multi expressive blockchain architecture. At the top layer, a proxy blockchain enables independently managed trust authorities to interoperate. End-users from different health care domains, such as hospitals or device manufacturers are able to access and securely exchange medical data, provided that a commonly agreed domain-wise access policy is enforced. At the bottom layer, one or more domain blockchains allow each domain (e.g. a hospital or device manufacturer) to enforce their policy and allow fine-grained access control with attribute-based encryption. This architecture is designed to provide the autonomous management of trusted medical data/devices and the transactions of mutually untrusted stakeholders, as well as an inherent forensics mechanism tailored for granular auditing. Smart contracts are used to enforce decentralized policies. Ciphertext-policy attribute based encryption (CP-ABE) is used to distribute the decryption process among end users and the system, as well as support an efficient credential revocation mechanism. We demonstrate the efficiency of the proposed architecture through a proof of concept implementation. Finally we analyse the major security and performance characteristics.
Rafael Genés-Durán, Diana Yarleque-Ruesta, Marta Bellés-Muñoz, Antonio Jimenez-Viguer · 5 authors
New manufacturing paradigms require a large number of business interactions between multiple cyber-physical systems with different owners. In this context, public distributed ledgers are disruptive because they make it possible to securely and publicly record proofs of agreements between parties that do not necessarily trust each other. Many industry leaders have already achieved significant business benefits using this technology, including greater transparency, improved traceability, enhanced security, increased transaction speed and costs reduction. While the benefits of blockchain technologies for industrial applications are unquestionable, these technologies have an inherent complexity that might be overwhelming for many users. To decrease entry barriers for industry users to distributed ledger technologies, it is necessary to have an easy user onboarding process and a simple key life-cycle management. In this paper, we propose an architecture that facilitates these processes and simplifies how users utilize decentralized applications without sacrificing on the expected security. To achieve this goal, our architecture uses a middleware that allows us to decouple the digital signatures required for paying blockchain fees from the ones required for authorization. This approach has the advantage that users are not forced to create wallets, buy cryptocurrency, or protect their private keys. For these reasons, our solution is a promising way of enabling a reasonable transition to the integration of distributed ledger technologies in industrial business processes.
Pei Huang, Kai Fan, Hanzhe Yang, Kuan Zhang · 6 authors
Cloud storage system provides data owners with remote storage service, which allows them to outsource data without local storage burden. Nevertheless, the cloud storage service is not fully trustworthy since it may not be honest and remote data would be corrupted. One way to ensure trustworthy preservation of cloud data is the remote data auditing method, through which data owners can check storage reliability of cloud system on demand and avoid potential data corruption in time. However, private auditing methods fail to promise the mutual trust in auditing results. Thus, public auditing methods are introduced, in which traditionally a third party auditor is delegated to interact with cloud service providers for auditing tasks. Although the third party auditor serves as a medium to exchange trust, a centralized third party is hard to stay neutral, which exposes the remote data auditing to some threats such as collusion attacks. To address the trust problem between data owners and cloud service providers, we propose a collaborative auditing blockchain framework for cloud data storage. In this framework, all consensus nodes substitute for the single third party auditor to execute auditing delegations and record them permanently, thereby preventing entities from deceiving each other. Security analysis shows that the proposed framework has advantage of preserving remote data integrity from various attacks. Performance analysis demonstrates that the framework is more functional and resource-friendly than existing schemes.
Masoud Barati, Omer Rana, Ioan Petri, George Theodorakopoulos
Data privacy in Internet of Things (IoT) applications remains a major concern of regulation bodies. The introduction of the European General Data Protection Regulation (GDPR) enables users to control how their data is accessed and processed, requiring consent from users before any data manipulation is carried out on their (personal) data by smart devices or cloud-hosted services. Blockchains provide the benefits of a distributed and immutable ledger recording digital transactions across a global network of peer nodes. Blockchain support for tracking of operations carried out by an IoT-based system provides greater confidence to a user that the IoT device is not infringing user privacy (as the Blockchain can be audited to verify which operation was carried out, by which actor). A formal model (following the privacy-bydesign approach) is proposed for supporting GDPR compliance checking for smart devices. The privacy requirements of such applications are related to GDPR obligations of device (and software systems) operators (such as user consent, data protection, right to forget etc). Three smart contracts are proposed as a practical solution to support automated verification of operations carried out by devices on user data, in accordance with GDPR rules. We evaluate the performance and scalability costs of our approach using a Blockchain test network.
Moti Yung, Cem Paya, Daniel James
No abstract is available for this record.
Ahmad Sghaier Omar, Otman Basir
The smartphone industry is lucrative for device counterfeiting with over 1.5 billion devices sold annually in the last three years. In 2017, it is estimated that there were around 184 million counterfeit devices, valued at 45.3 billion EUR, 12.9% of total sales. Beyond its economic impact, smartphone counterfeiting affects various aspects of user security and privacy, harms manufacturer reputation, and degrades service quality. Furthermore, since smartphone devices are attached to different mobile networks globally, challenges arise on how devices’ identities are maintained and verified and how the supply chain actors can access the device identity throughout its life cycle with less control from third parties. Decentralized identifiers (DIDs) and verifiable claims implemented on a distributed ledger technology present a powerful candidate to address this challenge. Thanks to Blockchain’s use of cryptographic identifiers, record immutability, and provenance, and the features provided by the DIDs and verifiable claims that enable identity management decentralization, portability, and discoverability. This article proposes a smartphone anticounterfeiting system based on an integrated approach of the technologies mentioned above. The proposed system eliminates the need for a central authority and provides the features of identity creation, transfer of ownership, and the capability of fast and secure reporting of stolen devices.
Ying Miao, Qiong Huang, Meiyan Xiao, Hongbo Li
Cloud storage systems provide a flexible, convenient and friendly way for users to outsource data. However, users lose control of their data once outsourcing them to the cloud. Public auditing was introduced to ensure data integrity, in which a third-party auditor (TPA) is delegated to execute auditing tasks. In general, TPA generates and sends challenge information to the cloud server (CS), which proves data possession accordingly. However, the TPA may not perform public auditing protocol honestly or may even collude with CS to deceive users. Some existing public auditing schemes utilize blockchain to resist against the malicious TPA. However, the CS may guess the challenge messages and there is a risk that users' information may be leaked to the TPA during the process of auditing. In this paper, we propose a decentralized and privacy-preserving public auditing scheme based on blockchain (DBPA), in which a blockchain is utilized as an unpredictable source for the generation of (random) challenge information, and the auditor is required to record the audit process onto the blockchain. Due to the characteristics of blockchain, users can check the audit results publicly. Moreover, zero-knowledge proof is used in DBPA to protect user's privacy during the audit process so that the response information returned by the CS does not leak information about user's data. Security analysis and performance evaluation show that DBPA is secure and efficient.
Fang Peng, Hui Tian, Hanyu Quan, Jing Lu
No abstract is available for this record.
Authors unavailable
In recent years, cryptocurrency, and its foundational technology, blockchain, have become increasingly popular.As the value of some cryptocurrencies has cataclysmically risen and fallen, many people are curious about what the future of cryptocurrency prices look like, and what means are available to predict that future.We conducted experiments on three RNN models to determine whether one performed better than the others when predicting the price of Bitcoin, Ripple, and Litecoin.We also collected Google trends data for these three cryptocurrencies and ran additional experiments to explore whether this additional data significantly boosted the prediction accuracy of these models.After performing all our experiments, we found that among the three RNN models we tested, none performed significantly better than the others.Additionally, we concluded that supplementing the three models with Google trends data did not significantly boost the prediction accuracy of the models.We discuss implications of this research in the paper.
Ammar Battah, Mohammad Madine, Hamad Alzaabi, Ibrar Yaqoob · 6 authors
Multi-party authorization (MPA) typically involves multiple parties to control and grant access to shared data. MPA is used to solve the insider’s attack problem by ensuring that a single authority or party is not acting alone. Currently, almost all existing implementations of MPA are centralized and fall short in providing logs and events related to provenance of granting permissions in a trusted, secure, immutable, auditable, and decentralized manner. Moreover, for sharing data, proxy re-encryption algorithms are often used to give secure access to encrypted shared data. These schemes and algorithms are also centralized and cannot be trusted. In this paper, we propose a fully decentralized blockchain-based solution in which MPA is implemented using Ethereum smart contracts, and proxy re-encryption algorithms (which are computationally expensive) are implemented using multiple oracles to give access to encrypted shared data stored on a public and decentralized storage platform, such as the Interplanetary File Systems (IPFS). The smart contracts help to validate results based on the majority of encrypted results determined by the oracles. For this, we incorporate reputation mechanisms in the proposed smart contracts to rate the oracles based on their malicious and non-malicious behaviors. We present algorithms along with their full implementation, testing, and validation details. We evaluate the proposed system in terms of security, cost, and generalization to show its reliability and practicality. We make the smart contract source code publicly available on Github.
Marcel Müller, Nadine Ostern, Michael Rosemann
No abstract is available for this record.
Sarthak Gupta, Virain Malhotra, Shailendra Narayan Singh
No abstract is available for this record.
Liwei Liu, Maozhi Xu
No abstract is available for this record.