Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

3,460 papersLast indexed Aug 31, 2026
Search papers

Paper index

3,460 results · page 112 of 145

Clear filters
Dec 2, 2019·Proceedings of the 12th IEEE/ACM International Conference on Utility and Cloud Computing Companion
16 cites
Blockchain as a Trusted Component in Cloud SLA Verification

Amir Teshome Wonjiga, Sean Peisert, Louis Rilling, Christine Morin

Migrating an application from local compute resources to commercial cloud resources involves giving up full control of the physical infrastructure, as the cloud service provider (CSP) is responsible for managing the physical infrastructure, including its security. The reliance of a tenant on a CSP can create a trust issue around whether the CSP is upholding its end of the bargain. CSPs acknowledge this and provide a guarantee through a Service Level Agreement (SLA). SLAs need to be verified for satisfaction of the defined objectives. To avoid raising the trust issue again, such a verification procedure needs to be unbiased and independently achievable by both tenants and CSPs without one relying on the other party. In this paper, we consider an SLA offered by the provider that guarantees the integrity of tenants' data, and propose to verify the SLA using an integrity checking method based on a distributed ledger. Our proposed method allows both CSPs and tenants to perform integrity checking without one party relying on the other. The method uses a blockchain as a distributed ledger to store evidence of data integrity. Assuming the ledger as a secure, trusted source of information, the evidence can be used to resolve conflicts between providers and tenants. In addition, we present a prototype implementation and an experimental evaluation to show the feasibility of our verification method and to measure the time overhead.

Open access
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Dec 1, 2019·2019 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)
11 cites
Trust Modeling for Blockchain-Based Wearable Data Market

Mohammad Jabed Morshed Chowdhury, Md Sadek Ferdous, Kamanashis Biswas, Niaz Chowdhury · 7 authors

Wearable devices continuously produce physiological data that can provide individuals critical information about their daily routine or fitness level in combination with their smartphones without requiring manual calculations or maintaining log-books. Real-time participant-generated data can enable large scale observational studies of health conditions, provide better insights into medical conditions of individuals and streamline clinical trial processes in medical research. However, privacy is a major concern for health data and there can be a lack of trust among different parties in the health data collection process. In addition, individuals often do not have sufficient control over the sharing of their data from the wearable devices. The lack of control, trust and privacy are key barriers to research participants being prepared to share their personal data from wearable devices. In this work, we propose a trust model to overcome the trust deficit among different parties. Then, we present a reference system architecture, rooted on the developed trust model, that provides incentive for individuals to securely share their health data through a data marketplace. By encouraging individuals to share their real-time health data, researchers will have access to large data sets at low cost.

Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Dec 1, 2019·2019 4th Technology Innovation Management and Engineering Science International Conference (TIMES-iCON)
13 cites
Blockchain-based Integrity Protection System for Cloud Storage

Pratima Sharma, Rajni Jindal, Malaya Dutta Borah

Data are now an invaluable asset; therefore, in most machine-aided human activities, it guides all organizational decisions. Attacks to data integrity are therefore of paramount importance, as essential organization decisions can be maliciously affected by manipulation of information. This problem is particularly true in cloud computing settings where information owners are unable to monitor basic information elements such as access control and physical data storage. Recently, Blockchain has appeared as an intriguing technology that offers convincing data integrity characteristics among others. In this paper, we design a blockchain-based cloud architecture, focusing the threats of data integrity. We propose a methodology in peer to peer cloud storage to verify integrity based on blockchain, making checking more transparent, open, and publicly available. In this framework, we confirm the data integrity by using merkle trees and design a smart contract for the authentication process. Furthermore, we present an elementary model of an e□icient blockchain structure for cloud computing settings. Thus, this methodology helps in enhancing the security and integrity of the cloud storage system.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
Dec 1, 2019·2019 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA/BDCloud/SocialCom/SustainCom)
0 cites
Secure and Scalable Multi-Company Management in Enterprise Cloud Storage Broker System

Muhammad I.H. Sukmana, Marvin Petzolt, Kennedy A. Torkura, Hendrik Graupner · 6 authors

CloudRAID for Business (CfB) is a proof-of-concept enterprise cloud storage broker (ECSB) system that provides data security in the cloud. It applies a single-authority ciphertext-based policy attribute-based encryption (CP-ABE) scheme into its key management system (KMS) to solve its scalability and access control issues for multi-users and multi-devices scenarios. Unfortunately, this approach is not suitable for managing multiple companies as CfB customers since it could not provide secure and scalable zero-knowledge file sharing in the system. In this paper, we propose the practical implementation of a modified multi-authority attribute-based encryption (MA-ABE) scheme for CfB to provide a better secure and scalable KMS and zero-knowledge file sharing in a multi-company management scenario. Our work allows each company to have the authority to manage its attributes and keys for the company's employees as CfB users while CfB manages multiple companies without global decryption power to decrypt the company's encrypted data. Our evaluation shows that our proposal provides better performance with the smaller size of ciphertext and key, faster processing time, and better security compared with current CfB system.

Cryptography and Data Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
Dec 1, 2019·2019 IEEE International Symposium on Smart Electronic Systems (iSES) (Formerly iNiS)
6 cites
Privacy Preserving Data Provenance Model Based on PUF for Secure Internet of Things

Hala Hamadeh, Akhilesh Tyagi

Data provenance to maintain data integrity and authenticity is a significant challenge in the Internet of Things (IoT) environments. Additionally, if the provenance metadata itself can be communicated in a privacy-preserving manner, it expands the usage of IoT systems to human societal domains where privacy is of paramount importance. In this paper, we present a scheme to combine data provenance and privacy-preserving solutions. Our scheme merges Physical Unclonable Function (PUF) technology with non-interactive zero-knowledge proof to provide trustworthy and dependable IoT systems. In this context, the IoT device can anonymously send data to the corresponding server associated with the proof of ownership. First, we propose a privacy-preserving data provenance protocol. This protocol was synthesized with Altera Quartus. It was implemented on an Altera Cyclone IV FPGA to demonstrate its practicality and feasibility. Most of the protocol steps take time of the order of 40u sec establishing its practicality.

Physical Unclonable Functions (PUFs) and Hardware Security
Security and Verification in Computing
Cloud Data Security Solutions
Original source
Dec 1, 2019·2019 IEEE Conference on Information and Communication Technology, Allahabad, India, 2019, pp. 1-7
44 cites
Decentralized Patient Centric e- Health Record Management System using Blockchain and IPFS

Gaganjeet Singh Reen, Manasi Mohandas, S. Venkatesan

Electronic Health Records(EHR) are gaining a lot of popularity all over the world. The current EHR systems however have their fair share of problems related to privacy and security. We have proposed a mechanism which provides a solution to most of these problems. Using a permissioned Ethereum blockchain allows the hospitals and patients across the world to be connected to each other. Our mechanism uses a combination of symmetric and asymmetric key cryptography to ensure the secure storage and selective access of records. It gives patients full control over their health records and also allows them to grant or revoke a hospital's access to his/her records. We have used IPFS(inter planetary file system) to store records which has the advantage of being distributed and ensures immutability of records. The proposed model also maintains the statistics of diseases without violating the privacy of any patient.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Cloud Data Security Solutions
Original source
Dec 1, 2019·arXiv (Cornell University)
7 cites
Zero knowledge Proofs for Cloud Storage Integrity Checking

Faen Zhang, Xinyu Fan, Xiang Lei, Jiahong Wu · 8 authors

With the wide application of cloud storage, cloud security has become a crucial concern. Related works have addressed security issues such as data confidentiality and integrity, which ensure that the remotely stored data are well maintained by the cloud. However, how to define zero-knowledge proof algorithms for stored data integrity check has not been formally defined and investigated. We believe that it is important that the cloud server is unable to reveal any useful information about the stored data. In this paper, we introduce a novel definition of data privacy for integrity checks, which describes very high security of a zero-knowledge proof. We found that all other existing remote integrity proofs do not capture this feature. We provide a comprehensive study of data privacy and an integrity check algorithm that captures data integrity, confidentiality, privacy, and soundness.

Open access
3 source records
Cloud Data Security Solutions
Cryptography and Data Security
Security and Verification in Computing
Original source
Nov 28, 2019·Journal of Corporate Accounting & Finance
49 cites
Blockchain security risk assessment and the auditor

Barbara S. White, Chula G. King, Jonathon Holladay

Abstract A blockchain is an Internet‐based peer‐to‐peer system that forms a network of independent and connected computers that simultaneously record and verify transactions. This peer‐to‐peer system focuses on who owns the information and how that information is transferred. Blockchains offer significant advantages over traditional databases where users can delete, modify, and change records. The advantages include improved efficiencies, lower costs, enhanced transparency, and an immutable audit history of all transactions. The advantages, however, are not without significant risks. The risks include technological risks, data security risks, interoperability risks, and third‐party vendor risks. Because of the inherent advantages in blockchains, auditors are being called upon to provide assurance services to clients who use blockchains and to advise clients on blockchain technology. Therefore, auditors must be equipped with the knowledge and expertise of not only blockchain technology, but also the assessment of risks inherent in blockchain technology.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
FinTech, Crowdfunding, Digital Finance
Original source
Nov 22, 2019·Information
25 cites
The Good, the Bad, and the Ethical Implications of Bridging Blockchain and Multi-Agent Systems

Davide Calvaresi, Jean-Paul Calbimonte, Alevtina Dubovitskaya, Valerio Mattioli · 6 authors

The agent based approach is a well established methodology to model distributed intelligent systems. Multi-Agent Systems (MAS) are increasingly employed in applications dealing with safety and information critical tasks (e.g., in eHealth, financial, and energy domains). Therefore, transparency and the trustworthiness of the agents and their behaviors must be enforced. For example, employing reputation based mechanisms can promote the development of trust. Nevertheless, besides recent early stage studies, the existing methods and systems are still unable to guarantee the desired accountability and transparency adequately. In line with the recent trends, we advocate that combining blockchain technology (BCT) and MAS can achieve the distribution of the trust, removing the need for trusted third parties (TTP), potential single points of failure. This paper elaborates on the notions of trust, BCT, MAS, and their integration. Furthermore, to attain a trusted environment, this manuscript details the design and implementation of a system reconciling MAS (based on the Java Agent DEvelopment Framework (JADE)) and BTC (based on Hyperledger Fabric). In particular, the agents’ interactions, computation, tracking the reputation, and possible policies for disagreement-management are implemented via smart contracts and stored on an immutable distributed ledger. The results obtained by the presented system and similar solutions are also discussed. Finally, ethical implications (i.e., opportunities and challenges) are elaborated before concluding the paper.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
Nov 19, 2019·IRIS Research product catalog (Sapienza University of Rome)
32 cites
Audita: A Blockchain-based Auditing Framework for Off-chain Storage

Danilo Francati, Giuseppe Ateniese, Abdoulaye Faye, Andrea Maria Milazzo · 7 authors

The cloud changed the way we manage and store data. Today, cloud storage services offer clients an infrastructure that allows them a convenient source to store, replicate, and secure data online. However, with these new capabilities also come limitations, such as lack of transparency, limited decentralization, and challenges with privacy and security. And, as the need for more agile, private and secure data solutions continues to grow exponentially, rethinking the current structure of cloud storage is mission-critical for enterprises. By leveraging and building upon blockchain's unique attributes, including immutability, security to the data element level, distributed (no single point of failure), we have developed a solution prototype that allows data to be reliably stored while simultaneously being secured, with tamper-evident auditability, via blockchain. The result, Audita, is a flexible solution that assures data protection and solves challenges such as scalability and privacy. Audita works via an augmented blockchain network of participants that include storage-nodes and block-creators. In addition, it provides an automatic and fair challenge system to assure that data is distributed and reliably and provably stored. While the prototype is built on Quorum, the solution framework can be used with any blockchain platform. The benefit is a system that is built to grow along with the data needs of enterprises, while continuing to build the network via incentives and solving for issues such as auditing and outsourcing.

Open access
2 source records
cs.CR
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Original source
Nov 18, 2019·Applied Sciences
61 cites
UniChain: A Design of Blockchain-Based System for Electronic Academic Records Access and Permissions Management

Eman Daraghmi, Yousef‐Awwad Daraghmi, Shyan‐Ming Yuan

Although blockchain technology was first introduced through Bitcoin, extending its usage to non-financial applications, such as managing academic records, is a new mission for recent research to balance the needs for increasing data privacy and the regular interaction among students and universities. In this paper, a design for a blockchain-based system, namely UniChain, for managing Electronic Academic Records (EARs) is proposed. UniChain is designed to improve the current management systems as it provides interoperable, secure, and effective access to EARs by students, universities, and other third parties, while keeping the students’ privacy. UniChain employs timed-based smart contracts for governing transactions and controlling access to EARs. It adopts advanced encryption techniques for providing further security. This work proposes a new incentive mechanism that leverages the degree of universities regarding their efforts on maintaining academic records and creating new blocks. Extensive experiments were conducted to evaluate the UniChain performance, and the results indicate the efficiency of the proposal in handling a large dataset at low latency.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Nov 13, 2019·In Proceedings of Middleware 2019: 20th ACM/IFIP International Middleware Conference (Middleware 2019). ACM, New York, NY, USA
1 cites
Designing for Privacy and Confidentiality on Distributed Ledgers for Enterprise (Industry Track)

Allison Irvin, Isabell Kiral-Kornek

Distributed ledger technology offers numerous desirable attributes to\napplications in the enterprise context. However, with distributed data and\ndecentralized computation on a shared platform, privacy and confidentiality\nchallenges arise. Any design for an enterprise system needs to carefully cater\nfor use case specific privacy and confidentiality needs. With the goal to\nfacilitate the design of enterprise solutions, this paper aims to provide a\nguide to navigate and aid in decisions around common requirements and\nmechanisms that prevent the leakage of private and confidential information. To\nfurther contextualize key concepts, the design guide is then applied to three\nenterprise DLT protocols: Hyperledger Fabric, Corda, and Quorum.\n

Open access
4 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Nov 11, 2019·Proceedings of the 2019 ACM SIGSAC Conference on Cloud Computing Security Workshop
22 cites
Verifiable Computation using Smart Contracts

Sepideh Avizheh, Mahmudun Nabi, Reihaneh Safavi–Naini, Muni Venkateswarlu K.

Outsourcing computation has been widely used to allow weak clients to access computational resources of a cloud. A natural security requirement for the client is to be able to efficiently verify the received computation result. An attractive approach to verifying a general computation is to send the computation to multiple clouds, and use carefully designed protocols to compare the results and achieve verifiability. This however requires a Trusted Third Party (TTP) to manage the interactions of the client and the clouds. Our goal is to employ a smart contract to act as the TTP. This also relieves the client from directly interacting with the clouds, and engaging in possibly a complex stateful protocol. We focus on a verifiable computation protocol of Canetti, Riva and Rothbulm (CRR) with provable security against a malicious cloud, and show that direct employment of the protocol with a smart contract will result in an attack that will undermine the security of the system. We describe and analyze the attack, and extend CRR protocol to protect against this attack, resulting in a secure verifiable computation system using smart contracts. We also give the pseudocode of a smart contract and the required functions that can be used to implement the protocol, written in the Solidity language, and explain its working.

Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Nov 6, 2019·arXiv
7 cites
zksk

Wouter Lueks, Bogdan Kulynych, Jules Fasquelle, Simon Le Bail-Collet · 5 authors

Zero-knowledge proofs are an essential building block in many privacy-preserving systems. However, implementing these proofs is tedious and error-prone. In this paper, we present zksk, a well-documented Python library for defining and computing sigma protocols: the most popular class of zero-knowledge proofs. In zksk, proofs compose: programmers can convert smaller proofs into building blocks that then can be combined into bigger proofs. zksk features a modern Python-based domain-specific language. This makes possible to define proofs without learning a new custom language, and to benefit from the rich Python syntax and ecosystem. The library is available at https://github.com/spring-epfl/zksk

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Nov 6, 2019·Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
12 cites
PIEs

Ethan Cecchetti, Ben Fisch, Ian Miers, Ari Juels

We present a new primitive supporting file replication in distributed storage networks (DSNs) called a Public Incompressible Encoding (PIE). PIEs operate in the challenging public DSN setting where files must be encoded and decoded with public randomness-i.e., without encryption-and retention of redundant data must be publicly verifiable. They prevent undetectable data compression, allowing DSNs to use monetary rewards or penalties in incentivizing economically rational servers to properly replicate data. Their definition also precludes critical, demonstrated attacks involving parallelism via ASICs and other custom hardware. Our PIE construction is the first to achieve experimentally validated near-optimal performance-within a factor of 4 of optimal by one metric. It also allows decoding orders of magnitude faster than encoding, unlike other comparable constructions. We achieve this high security and performance using a graph construction called a Dagwood Sandwich Graph (DSaG), built from a novel interleaving of depth-robust graphs and superconcentrators. PIEs' performance makes them appealing for DSNs, such as the proposed Filecoin system and Ethereum data sharding. Conversely, their near-optimality establishes concerning bounds on the practical financial and energy costs of DSNs allowing arbitrary data.

Open access
Advanced Data Storage Technologies
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Nov 6, 2019·Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
58 cites
A Formal Treatment of Deterministic Wallets

Poulami Das, Sebastian Faust, Julian Loss

In cryptocurrencies such as Bitcoin or Ethereum, users control funds via secret keys. To transfer funds from one user to another, the owner of the money signs a new transaction that transfers the funds to the new recipient. This makes secret keys a highly attractive target for attacks, and has lead to prominent examples where millions of dollars worth in cryptocurrency have been stolen. To protect against these attacks, a widely used approach are so-called hot/cold wallets. In a hot/cold wallet system, the hot wallet is permanently connected to the network, while the cold wallet stores the secret key and is kept without network connection. In this work, we propose the first comprehensive security model for hot/cold wallets and develop wallet schemes that are provable secure within these models. At the technical level our main contribution is to provide a new provably secure ECDSA-based hot/cold wallet scheme that can be integrated into legacy cryptocurrencies such as Bitcoin. Our construction and security analysis uses a modular approach, where we show how to generically build secure hot/cold wallets from signature schemes that exhibit a rerandomizing property of the keys.

Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Nov 4, 2019·arXiv
109 cites
Enabling Enterprise Blockchain Interoperability with Trusted Data Transfer (Industry Track)

Ermyas Abebe, Dushyant Behl, Chander Govindarajan, Yining Hu · 9 authors

The adoption of permissioned blockchain networks in enterprise settings has seen an increase in growth over the past few years. While encouraging, this is leading to the emergence of new data, asset and process silos limiting the potential value these networks bring to the broader ecosystem. Mechanisms for enabling network interoperability help preserve the benefits of independent sovereign networks, while allowing for the transfer or sharing of data, assets and processes across network boundaries. However, a naive approach to interoperability based on traditional point-to-point integration is insufficient for preserving the underlying trust decentralized networks provide. In this paper, we lay the foundation for an approach to interoperability based on a communication protocol that derives trust from the underlying network consensus protocol. We present an architecture and a set of building blocks that can be adapted for use in a range of network implementations and demonstrate a proof-of-concept for trusted data-sharing between two independent trade finance and supply-chain networks, each running on Hyperledger Fabric. We show how existing blockchain deployments can be adapted for interoperation and discuss the security and extensibility of our architecture and mechanisms.

Open access
2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Nov 1, 2019·2019 International Conference on Advanced Information Technologies (ICAIT)
16 cites
Storage Structure of Student Record based on Hyperledger Fabric Blockchain

Khin Su Su Wai, Ei Chaw Htoon, Nwe Nwe Myint Thein

Student records (SR) are needed to be regularly protected for safe access and security control. The blockchain system can support security, confidentiality, unchangeable, transparency and access control service. Although Hyperledger Fabric blockchain is a scalability modular architecture, various configuration elements affect the performance of transaction access time. Moreover, it cannot provide an efficient indexing capability on the transaction. In this paper, a storage structure that provides better access time is presented. Firstly, the suitable block size is proposed for transactions based on the configuring parameter and the transaction arrival rate to reduce the latency of transaction storage time. Secondly, the metadata of the SR block is replicated on an off-chain database to overcome the limitation of indexing capability and performance issue. SR data will be accessed transparently with greater performance and lower the costs of manpower and time.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Currency Recognition and Detection
Original source
Nov 1, 2019·2019 Sixth HCT Information Technology Trends (ITT)
6 cites
EPPR: Using Blockchain For Sharing Educational Records

Akram Alkouz, Ahmed HaiYasien, Abdulsalam Alarabeyyat, Khalid Samara · 5 authors

There have been recent, marked increases in the challenges of privacy, data interoperability and quality of Educational Professional Personal Record (EPPR). This calls into question the current model, in which different parties generate, exchange and monitor massive amounts of personal data related to EPPR. Ethereum blockchain has demonstrated that trusted, auditable transactions is visible using a decentralized network of nodes accompanied by a general ledger. Thus, the rapid development of educational and professional data generators such as online universities and distance learning, learners need to engage in detail into their EPPR as well as the educational and professional data generators. In this paper, we propose a novel decentralized approach to manage EPPR using Ethereum blockchain technology. The decentralized approach provides the owner of the EPPR a comprehensive immutable log and ease of access to their educational records across the educational record editors and consumers. Utilizing Ethereum blockchain features, can provide solutions with the main concerns of exchanging data between parties such as privacy, accountability and data interoperability. The aim of this approach is to also facilitate educational stakeholders (universities and employing agencies) to participate in the network as blockchain miners rewarded by pseudonymized data in compliance with General Data Protection Rules (GDPR) in United Arab Emirates (UAE).

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
Nov 1, 2019·2019 Sixth HCT Information Technology Trends (ITT)
3 cites
Permissioned Blockchain Design for Integrated Healthcare Data Management

Anang Hudaya Muhamad Amin, Sharmila Siddartha, Rashed Khalifa Matar Obaid M Almehairi, Yousuf Hussain Mohammad Ali Albalooshi · 7 authors

With increasing demand for collaborative work on healthcare data for research and effective healthcare management, the need for a distributed mechanism for resource sharing is inevitable. Common implementation for integrated healthcare data management usually rely upon a centralized data processing and repository, in which data is extracted as needed. However, such implementation is unscalable and prone to security and privacy issues, specifically when dealing with private and confidential health data. In this paper, we propose a preliminary design of permissioned blockchain application for integrated health data management. Our proposed scheme utilizes distributed ledger mechanism for data storage and verification, which allows participating entities to access and verify healthcare data in a distributed manner without depending on centralized facility. The proposed design reflected a simulated scenario involving medical institutions and military service in healthcare data management in national service recruitment.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source