Cryptocurrencies are a mean of executing online transactions. They use a variety of cryptographic techniques to secure and verify these transactions, which are functionally supported by the Blockchain platform. Blockchain is a continuously growing, distributed ledger of files that contains all transactions between users of cryptocurrencies in a verifiable and permanent manner. It consists of blocks that are connected and secured cryptographically. Cryptocurrencies use algorithms to produce pairs of public and private keys. These pairs, cryptographically merged with a message between the participants, are the building blocks of the relevant transactions. Bitcoin uses the ECDSA algorithm to produce the above-mentioned keys. The purpose of our work is to present some useful motifs for the domain parameters of base point (P) and the order (n) of the subgroup produced by it, while choosing the elliptic curve and the Galois field on which we formulate the algorithm, in order to obtain safer private keys. The results of the research are experimental due to the limited infrastructure, but explanatory for the purpose of our work. The resulting conclusions highlight the value of the proper selection of the structural parameters of these algorithms and possible alternatives to the curve, field and domain parameters that can be used.
Traditional construction supply chains suffer from extra delays, costs and information wastages due to information intermediaries. Blockchain, a decentralized infrastructure, can provide irreversibility, undeniableness, uniqueness and anonymity for trades. Hence, we first propose a blockchain-based construction supply chain framework to reduce limitations in traditional ones. However, payment security by blockchain must be guaranteed and token assets in accounts must be protected. Although the loss of private keys will not result in the exposure or the modification of records in blockchain due to merkle root and blockheader hash, fake payments can be generated and all tokens in the accounts controlled by the private keys may be stolen by attackers. Existing approaches towards private-key protections include biometric-basic signature schemes, index-hidden private key designs and post-quantum blockchain schemes. Nevertheless, none of them can recover lost private keys. Therefore, we design a private-key distribution protocol in blockchains to preserve security of private keys with key recovery. Specifically, our scheme not only uses secret sharing to improve possibilities of recovering lost keys but also introduces network protocols to guarantee security of secret share transmission. The proposed scheme is then proven secure and feasible both in theoretical and experimental analysis.
Stefanos Malliaros, Christos Xenakis, George Moldovan, John Mantas · 6 authors
INTRODUCTION: Individuals and healthcare providers need to trust that the EHRs are protected and that the confidentiality of their personal information is not at stake. AIM: Within CrowdHEALTH project, a security and privacy framework that ensures confidentiality, integrity, and availability of the data was developed. METHODS: The CrowdHEALTH Security and Privacy framework includes Privacy Enhancing Technologies (PETs) in order to comply with the GDPR EU laws of data protection. CrowdHEALTH deploys OpenID Connect, an authentication protocol to provide flexibility, scalability, and lightweight user authentication as well as the attribute-base access control (ABAC) mechanism which supports creating efficient access control policies. RESULTS: CrowdHEALTH integrates ABAC with OpenID Connect to build an effective and scalable base for end-users' authorization. CrowdHEALTH's security and privacy framework interacts with other CrowdHEALTH's components, for instance the Big Data Platform, that depends on user authentication and authorization. CrowdHEALTH users are able to access the CrowdHEALTH's database based on the result of an ABAC request. Moreover, due to the fact that the CrowdHEALTH system requires proofs during the interactions with data producers of low trust or low reputation level, the requirements for the Trust and Reputation Model have been identified. CONCLUSION: The CrowdHEALTH Integrated Holistic Security and Privacy framework meets the security criteria for an e-health cross-border system, due to the adoption of security mechanisms, such as user authentication, user authorization, access control, data anonymization, trust management and reputation modelling. The implemented framework remains to be tested to ensure its robustness and to evaluate its performance. The holistic security and privacy framework might be adapted during the project's life circle according to new legislations.
SUMMARY Blockchain is a disruptive technology that offers advantages to the audit profession such as transparency into all transactions, an immutable ledger, and the potential for real-time auditing. However, to realize these benefits, the profession must be prepared to gain comfort over blockchains as a component of organizations' information technology infrastructure. This paper considers risks to private and permissioned blockchains through the lens of information technology general controls (ITGCs) as part of an audit of internal control over financial reporting. I discuss new ITGC areas of focus for auditors to consider, along with areas of risk that blockchain could eliminate. To help readers better understand this emerging topic, I provide illustrations, a summary table of key points, and a glossary of blockchain-related terms used throughout the paper. This paper should be viewed as a primer of ITGC considerations on blockchain audits, as more nuanced concerns will emerge as the technology evolves.
Ioannis Karagiannis, Konstantinos Mavrogiannis, John Soldatos, Dimitris Drakoulis · 6 authors
Recent security incidents in the finance sector have demonstrated the importance of sharing security information across financial institutions, as a means of mitigating risks and boosting the early preparedness against relevant attacks. However, financial institutions are in several cases reluctant to share security information beyond what is imposed by applicable regulations. In this paper, we introduce a blockchain-based solution for sharing security information in a decentralized way, which boosts security and trust in the information sharing process. We also illustrate how the information that is shared across financial institutions can serve as a basis for collaborative security services such as risk assessment.
2 source records
Blockchain Technology Applications and Security
Infrastructure Resilience and Vulnerability Analysis
Current architectures to validate, certify, and manage identity are based on centralised, top-down approaches that rely on trusted authorities and third-party operators. We approach the problem of digital identity starting from a human rights perspective, with a primary focus on identity systems in the developed world. We assert that individual persons must be allowed to manage their personal information in a multitude of different ways in different contexts and that to do so, each individual must be able to create multiple unrelated identities. Therefore, we first define a set of fundamental constraints that digital identity systems must satisfy to preserve and promote privacy as required for individual autonomy. With these constraints in mind, we then propose a decentralised, standards-based approach, using a combination of distributed ledger technology and thoughtful regulation, to facilitate many-to-many relationships among providers of key services. Our proposal for digital identity differs from others in its approach to trust in that we do not seek to bind credentials to each other or to a mutually trusted authority to achieve strong non-transferability. Because the system does not implicitly encourage its users to maintain a single aggregated identity that can potentially be constrained or reconstructed against their interests, individuals and organisations are free to embrace the system and share in its benefits.
Data breaches are an increasingly common part of consumers’ lives. No institution is immune to the possibility of an attack. Each breach inevitably risks the release of consumers’ personally identifiable information and the strong possibility of identity theft. Unfortunately, current solutions for handling these incidents are woefully inadequate. Private litigation like consumer class actions and shareholder lawsuits each face substantive legal and procedural barriers. States have their own data security and breach notification laws, but there is currently no unifying piece of legislation or strong enforcement mechanism. This Note argues that proactive solutions are required. First, a national data security law—setting minimum data security standards, regulating the use and storage of personal information, and expanding the enforcement role of the Federal Trade Commission—is imperative to protect consumers’ data. Second, a proactive solution requires reconsidering how to minimize the problem by going to its source: the collection of personally identifiable information in the first place. This Note suggests regulating companies’ collection of Social Security numbers, and, eventually, using a system based on distributed ledger technology to replace the ubiquity of Social Security numbers.
Lei Xu, Lin Chen, Zhimin Gao, Yanling Chang · 6 authors
Maritime transportation plays a critical role for the U.S. and global economies, and has evolved into a complex system that involves a plethora of supply chain stakeholders spread around the globe. The inherent complexity brings huge security challenges including cargo loss and high burdens in cargo inspection against illicit activities and potential terrorist attacks. The emerging blockchain technology provides a promising tool to build a unified maritime cargo tracking system critical for cargo security. However, most existing efforts focus on transportation data itself, while ignoring how to bind the physical cargo movements and information managed by the system consistently. This can severely undermine the effectiveness of securing cargo transportation. To fulfill this gap, we propose a binding scheme leveraging a novel digital identity management mechanism. The digital identity management mechanism maps the best practice in the physical world to the cyber world and can be seamlessly integrated with a blockchain-based cargo management system.
Over the past few decades, radio frequency identification (RFID) technology has been an important factor in securing products along the agri-food supply chain. However, there still exist security vulnerabilities when registering products to a specific RFID tag, particularly regarding the ease at which tags can be cloned. In this paper, a potential attack, labeled the "Hilt Shao attack", is identified which could occur during the initial phases of product registration, and demonstrate the type of attack using UID and CUID tags. Furthermore, a system is proposed using blockchain technology in order for the attacker to hide the cloned tag information. Results show that this attack, if carried out, can negate the profits of distributors along the supply chain, and negatively affect the consumer.
Protecting Critical Infrastructure (CI) against increasing cyber threats has become as crucial as it is complicated. To be effective in identifying and defeating cyber attacks, cyber analysts require novel distributed detection and reaction methodologies based on information security techniques that can automatically analyse incident reports and securely share analysis results between Critical Infrastructure stakeholders. Our goal is to provide solutions in real-time that could replace human input for cyber incident analysis tasks (triage) to classify cyber incident reports, find related reports in a fast and scalable way, eliminate irrelevant information, and automate reporting life- cycle management. Our effective and fast incident management method is based on artificial intelligence and can support cyber analysts in establishing cyber situational awareness, and allow them to quickly adopt suitable countermeasures in the case of an attack. In this paper, we evaluate deep autoencoder neural network supported by Blockchain technology as a system for incident classification and management, and assess its accuracy and performance. This approach should reduce the number of manual operations and save storage space. We used a Blockchain smart contract technique to provide an automated trusted system for incident management workflow that allows automatic acquisition, classification and enrichment of incident data. We demonstrate how the presented techniques can be applied to support incident handling tasks performed by security operation centres.
This paper describes proposed methodology for evaluation of critical systems and prioritization of critical risks and assets identified in highly secured information systems. For different types of information assets or security environments it is necessary to apply different techniques and methods for their prioritization and evaluation. In this article, VECTOR matrix method for prioritization of critical assets and critical risks is explained and integrated into AHP (Analytic Hierarchy Process) technique as a set of fixed criteria for evaluation of defined alternatives. Bitcoin cryptocurrency was compared and evaluated along with other common Internet transaction systems by information security professionals according to defined VECTOR criteria. Also, the newly proposed hybrid AHP model is presented with potential case studies for future research. This article tries to discover security posture of Bitcoin cryptocurrency in the context of information security risks related to the existing most common online payment systems like e-banking, m-banking, and e-commerce
Abstract The exponential increase of the traffic volume makes Distributed Denial-of-Service (DDoS) attacks a top security threat to service providers. Existing DDoS defense mechanisms lack resources and flexibility to cope with attacks by themselves, and by utilizing other’s companies resources, the burden of the mitigation can be shared. Technologies as blockchain and smart contracts allow distributing attack information across multiple domains, while SDN (Software-Defined Networking) and NFV (Network Function Virtualization) enables to scale defense capabilities on demand for a single network domain. This proposal presents the design of a novel architecture combining these elements and introducing novel opportunities for flexible and efficient DDoS mitigation solutions across multiple domains.
Incidents of ransomware have been escalating, which could be fueled in part by the diffusion of crypto-currencies. Without crypto-currencies, the creation of ransomware is less desirable because other forms of payment are more traceable. The risk from ransomware can be considerable, and some companies hold supplies of bitcoins in reserve to pay extortionists if necessary. Here, the authors examine crypto-currencies’ effects on ransomware and look at what might influence a victim’s decision to pay.
Part I of this Article describes how the healthcare industry has arrived in this place of vulnerability, including (1) the history of the movement toward EHRs through HIPAA, (2) HIPAA’s meaningful use regulations and the background of current ransomware attacks, and (3) the distinctions between these attacks and other security breaches that have plagued large insurers and health systems within the last five years. Next, Part II will examine current industry culture when it comes to cybersecurity and review current legal and business approaches to address this growing threat. Then, Part III will argue that, while the current laws—including HIPAA and HITECH—are a good start, they do not go far enough to curb the current ransomware attacks and thus, should be amended. It will further argue that such amendments cannot be the only solution. Rather, the healthcare industry has to spur its own movement toward better and tighter security over its healthcare technology. Lastly, this Article will conclude with some suggestions and recommendations for how industry and government regulators can work together to assure that hospitals and health systems are not faced with the dilemma of having to choose between patient safety and the payment of a bitcoin ransom.
This thesis presents new results in three fundamental areas of public-key cryptography: integrity, authentication and confidentiality. In each case we design new primitives or improve the features of existing ones. The first chapter, dealing with integrity, introduces a non-interactive proof for proper RSA public key generation and a contract co-signature protocol in which a breach in fairness provides the victim with transferable evidence against the cheater. The second chapter, focusing on authentication, shows how to use time measurements to shorten zeroknowledge commitments and how to exploit bias in zero-knowledge challenges to gain efficiency. This chapter also generalizes Fiat-Shamir into a one-to-many protocol and describes a very sophisticated smart card fraud illustrating what can happen when authentication protocols are wrongly designed. The third chapter is devoted to confidentiality. We propose public-key cryptosystems where traditional hardness assumptions are replaced by refinements of the CAPTCHA concept and explore the adaptation of honey encryption to natural language messages. Our final contributions focus on identity-based encryption (IBE) showing how to add broadcast features to hierarchical IBE and how to use IBE to reduce vulnerability exposure time of during software patch broadcast.
It is a widely spread belief that crypto-currencies implementing a proof of stake transaction validation system are less vulnerable to a 51% attack than crypto-currencies implementing a proof of work transaction validation system. In this article, we show that it is not the case and that, in fact, if the attacker's motivation is large enough (and this is common knowledge), he will succeed in his attack at no cost.
Applications on multi-application smart cards contain sensitive data and can exchange information. Thus a major concern is that these applications should not exchange data unless permitted by their respective policy. As modern smart cards allow post-issuance installation and removal of applications, traditional approaches for information flow analysis are not suitable. We suggest the Security-by-Contract approach for loading time application certification on the card, that will enable the stakeholders with the means to ensure the compliance of every update of the card with their security policy. We describe an extension of the card security architecture to deal with verification for different types of updates and present a Java Card prototype implementation of the Policy Checker with performance measurements.
Alessio Fioravanti, María Fernanda Cabrera-Umpiérrez, María Teresa Arredondo, Evangelos Bekiaris · 6 authors
GoodRoute is an R&D project, financed by the European commission in order to develop a decentralized system for minimum risk route calculation, re-routing, driver support, and enforcement. The article describes and discusses the outcomes of the final GoodRoute pilot tests, concerning the communication between the different modules involved in the use cases. An outlook is given on potential directions for further development, which are supposed to be important for a successful implementation of the system across Europe..
Leaking of the main key will make all other keys lose their functions.An algorithm of synthesizing the main key based on security tolerance is presented to avoid the problem.The main key was protected by distributing its shares to different key cards and the main key synthesizing server.Key cards,whose shares were modified,could be found by zero-knowledge proof technology.The project ensures that the compromise of a few system components does not compromise the secret information of the main key,and the main key is never reconstructed at a single online location.Security analysis proves that this algorithm makes the whole system have resilience and defence to collusive attack,and the system can keep working after it is attacked.
This paper points out the importance of protecting the main key. Because the conventional methods can do nothing about the flaws at all, this thesis puts forward the arithmetic of synthesized main key, which is based on the organic combination between the intrusion tolerance technology and the group zero-knowledge proof of the Elliptic Curve Cryptography (ECC). Through the share servers, the main key can be protected safely and validated without leaked information. Furthermore the system can work sequentially after being attacked. And this thesis strictly proves its correctness of the arithmetic by the means of the mathematics, and also reveals that this tactic effectively solves the problem of safely protecting the main key.
Omar Khadeer Hussain, Elizabeth Chang, Farookh Khadeer Hussain, Tharam S. Dillon · 5 authors
Risk is associated with almost every activity that is undertaken on a daily life. Risk associated with Trust, Security and Privacy. Risk is associated with transactions, businesses, information systems, environments, networks, partnerships, etc. Generally speaking, risk signifies the likelihood of financial losses, human casualties, business destruction and environmental damages. Risk indicator gives early warning to the party involved and helps avoid deserters. Until now, risk has been discussed extensively in the areas of investment, finance, health, environment, daily life activities and engineering. However, there is no systematic study of risk in Decentralised communication, which involves e-business, computer networks and service oriented environment. In this paper, we define risk associated with trusted communication in e-business and e-transactions; provide risk indicator calculations and basic application areas.