The Coronavirus disease 2019 has manifested into a global pandemic spreading into almost all the countries and territories in the world. Contact tracing, followed by testing and isolation, have been identified as important tools in containing the proliferation of the disease. Because of manual contact tracing limitations, smartphone apps for digital contact tracing have been deployed by authorities in multiple countries. However, many of these apps have faced criticism because of interoperability, privacy and security issues. This paper proposes an open architecture based on blockchain technology that addresses some of these criticisms. It enables interoperability through a publicly-readable consortium blockchain database, preserving privacy by distributing usersâ partial identities among multiple decentralised authorities and providing security through digital signature and asymmetric key encryption. In addition, the architecture provides a fast proof-of-authority based consensus algorithm using reputation as a stake to add and validate blocks on the blockchain efficiently and a swift contact tracing algorithm using Spatio-temporal and key-valued databases.
Yue Wang, Tingyu Che, Xiaohu Zhao, Tao Zhou · 6 authors
Due to the competitive relationship among different smart factories, equipment manufacturers cannot integrate the private information of all smart factories to train the intelligent manufacturing equipment fault prediction model and improve the accuracy of intelligent manufacturing equipment fault detection. The use of a low fault recognition rate model for smart factories will cause additional losses for them. In this work, we propose a blockchain-based privacy information security sharing scheme in Industrial Internet of Things (IIoT) to solve the sharing problem of private information in smart factories. Firstly, we abstract smart factories as edge nodes and build decentralized, distributed trusted blockchain networks based on Ethereum clients on simulated edge devices and propose an Intelligent Elliptic Curve Digital Signature Algorithm (IECDSA) to guarantee the ownership of shared information by edge nodes. Secondly, we propose the Reputation-based Delegated Proof of Stake (RDPoS) consensus algorithm to improve the security and reliability of the Delegated Proof of Stake (DPoS) consensus algorithm. Furthermore, we design and implement an incentive mechanism based on information attributes to increase the motivation of edge nodes to share information. Finally, the proposed solution is simulated. Through theoretical and simulation experiments, it is proved that the blockchain-based privacy information security sharing scheme in IIoT can improve the enthusiasm of edge nodes to share information on the premise of ensuring the security of information sharing.
Tingting Xiao, Chen Chen, Qingqi Pei, Houbing Song
The rapid advancement of intelligent vehicles is deemed crucial to the emergence of diverse compute-intensive applications of assisted driving, which consist of automatic driving, speed recognition, hybrid sensing data fusion, etc. Nevertheless, resources-constraint vehicles with high mobility cannot always meet the computing and communication demands when the above applications occur. Additionally, considering the expensive and inflexible deployment of edge servers, offloading application tasks to âEdgeâ in the vehicular networks is not always working well. To effectively mitigate the above issues, the complicated application tasks are motivated to offload to the vehicle platoon, where the vehicles travel synchronously in a string with small headway. Benefiting from the stable connectivity, adjustable mobility, and reasonable charge, the task vehicle would like to process the task by leveraging the idle resources of each platoon member (PM). To make more effective use of the resources on the mobile edge platoon cloud (MEPC), we investigate the resource allocation strategy based on the task vehicleâs service pricing strategy in this work. We first formulate the interactions between MEPC and task vehicle as a Stackelberg game to study the joint utility maximization of the MEPC and task vehicle. Then the Stackelberg Equilibrium (SE) for the proposed game is characterized and proved. The proposed algorithm Hook-Jeeves-based Stackelberg game (HJSG) can reach the SE. Finally, we introduce the consortium blockchain to ensure the security and privacy of service transactions. The entire system helps enhance task processing efficiency, protect transaction data, and improve service experience. Experimental results over numerical simulation based on practical scenarios demonstrate that compared with Multi-round Stackelberg Game (MRSG), uniform pricing, and the local computation strategy, the proposed HJSG algorithm can attain less execution time and faster convergence performance.
Digital Health Passes (DHP), systems of digitally validating quarantine and vaccination status such as the New York IBM Excelsior Pass, demonstrate a lawful means to approach some benefits offered by "true elimination" treatment strategies-which focus on the complete elimination of cases instead of investing more in controlling the progression of the disease-of COVID-19. Current implementations of DHPs require region-based control and central storage of Protected Health Information (PHI)-creating a challenge to widespread use across different jurisdictions with incompatible data management systems and a lack of standardized patient privacy controls. In this work, a mechanism for decentralized PHI storage and validation is proposed through a novel two-stage handshaking mechanism update to blockchain proof-of-stake consensus. The proposed mechanism, when used to support a DHP, allows individuals to validate their quarantine and testing universally with any jurisdiction while allowing their right of independent movement and the protection of their PHI. Implementational details on the protocol are given, and the protocol is shown to withstand a 1% disturbance attack at only 923 participants via a Monte-Carlo simulation: further validating its stability.
A. P. Pushpalatha, Gowtham Senthil, P M M Jawahar, E Kartheesan
Onkart is a blockchain decentralized e-commerce platform for buying and selling e-commerce products. The seller can sell the product and the buyer can purchase the product directly without the intervention of a third party. When a seller adds a product to the platform, they stake 1% of the price of the product in their stake on the platform, and similarly place an equal number of tokens together when a buyer places an order for the product. Price tokens for items in the platform's stake. If the buyer confirms receipt of the product without dispute, the seller will receive their stock tokens and the price of the product. Similarly, buyers receive their stake on the platform. This incentive mechanism will make the admins do their work without any manipulation. This mechanism avoids the seller/ buyer from doing malpractices since their amount is in stake in the platform. Hence, this provides decentralized application which is friendly to use. This system follows Consensus based Blockchain network which is more secure, and its functionality is protected by smart contracts. In terms of latency and throughput demonstrating the Onkart decentralization effectiveness in the products of e-commerce, the results are discussed for the betterment of safety of products and to ensure that there is sustainability in terms of society and finances.
In the last two years, due to the pandemic and restrictive measures, the dependence of music creators and artists on the Internet, where they could promote their work, organize live streaming concerts, and talk to the public, has increased and expanded even more and seeks higher revenue from digital music platforms. An important issue that arises from the above statement is protecting the authors' copyright regarding the uses and sharing in the digital services of their works with protected content. Although circulated in digital information, the protected content is not information but a product of ethical and commercial value. While it has an intangible owner and it owes its existence to the creative idea of its creator, it is not an idea. The imposition of legal and commercial conditions on its movement cannot be associated with any restrictions on the free movement of information, as it is not related to them. In general, the unauthorized exchange of digital music files via peer-to-peer violates copyright law. The exchange of files is unauthorized, as it does not have the relevant permission from the creators and beneficiaries and is therefore illegal. With this in mind, this paper proposes a highly effective way of protecting the copyright of music technology, which is based on the widespread use of artificial intelligence, blockchain, and cryptography technologies. Specifically, an advanced blockchain model based on Hyperledger Fabric is introduced, which, however, uses Quantum Homomorphic Encryption and Quantum Zero-Knowledge Arguments. Music files are implemented as Nonfungible Tokens (NFTs), which activate smart contracts. Finally, an advanced collaborative filtering algorithm provides recommendations for effectiveness in securing the copyrights of music industry creators. A specialized scenario was built to model the proposed system to verify the degree of protection on music intellectual property in developing a security simulation with an innovative consensus-based zero knowledge and the quantum fully homomorphic encryption technique. Experiment results show that this technique can aid in implementing a technologically aware system capable of providing a powerful answer to a current real-world problem.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Blockchain, which stores data in an appending form, cannot achieve the purpose of expanding the storage capacity by increasing the number of nodes. As the system runs, nodes will face problems of insufficient storage space. In the existing peer-to-peer (P2P) blockchain network model, all network nodes participate in data storage, and the generated blocks need to be verified among the network-wide nodes. This approach suffers from low system transaction throughput and data storage redundancy. In order to solve the above existing problems, this article proposes a block data storage model based on the double-layer blockchain network (DLBN), which improves the internal data composition structure of the blockchain. The DLBN contains two types of blockchain nodes, which form the storage and consensus layers of the system, respectively. The consensus layer is responsible for tasks, such as transaction sequencing, validation, and block packing, thus increasing the system transaction throughput. The nodes in the storage layer are divided into multiple storage units (SUs), and all nodes in the SU jointly maintain a copy of the complete blockchain, thereby reducing the storage pressure on the nodes. Based on the DLBN model, we design a reputation-based consensus mechanism, block storage allocation algorithm, and transaction query optimization algorithm, respectively. Through experimental verification and analysis, the storage model based on the DLBN can effectively improve the system transaction throughput and reduce the node storage capacity while ensuring system security.
Aditya Pribadi Kalapaaking, Ibrahim Khalil, Mohammad Saidur Rahman, Mohammed Atiquzzaman · 6 authors
This article proposes a blockchain-based federated learning (FL) framework with Intel Software Guard Extension (SGX)-based trusted execution environment (TEE) to securely aggregate local models in Industrial Internet-of-Things (IIoTs). In FL, local models can be tampered with by attackers. Hence, a global model generated from the tampered local models can be erroneous. Therefore, the proposed framework leverages a blockchain network for secure model aggregation. Each blockchain node hosts an SGX-enabled processor that securely performs the FL-based aggregation tasks to generate a global model. Blockchain nodes can verify the authenticity of the aggregated model, run a blockchain consensus mechanism to ensure the integrity of the model, and add it to the distributed ledger for tamper-proof storage. Each cluster can obtain the aggregated model from the blockchain and verify its integrity before using it. We conducted several experiments with different CNN models and datasets to evaluate the performance of the proposed framework.
Vehicular Ad-hoc NETworks (VANETs), a special kind of Mobile Ad-hoc NETworks (MANETs), play an important role in Intelligent Transportation Systems (ITS). Via wireless technology, vehicles exchange information related to road conditions and their status, and, thereby, VANETs enhance transportation safety and efficiency. A critical aspect of VANETs is providing privacy for the vehicles. The employment of pseudonym certificates is a well-known solution to the privacy problems in VANETs. However, certificate management faces challenges in renewing certificates and revoking vehicles. The centralized certificate management, especially resulting in the delay of the revocation process, harms the nodes of VANETs. This paper proposes a blockchain structure-based certificate management for VANETs and voting-based revocation to halt misbehaving vehiclesâ actions. Moreover, this paper presents extended privacy for the participants of the voting process using ring signatures.
Miners of a blockchain exchange information about blocks and transactions with one another via a peer-to-peer (P2P) network. The speed at which they learn of new blocks and transactions in the network determines the likelihood of forks in the chain, which in turn has implications for the efficiency as well as security of proof-of-work (PoW) blockchains. Despite the importance of information propagation delays in a blockchain's peer-to-peer network, little is known about them. The last known empirical study was conducted, for instance, by Decker and Wattenhofer in 2013 [11].
Federated Learning (FL) is a promising solution for training using data collected from heterogeneous sources (e.g., mobile devices) while avoiding the transmission of large amounts of raw data and preserving privacy. Current FL approaches operate in an iterative manner by selecting a subset of participants each round, asking them to training using their latest local data over the most recent version of the global model, before collecting these local model updates and aggregating them to form the next iteration of the global model, and so forth until convergence is reached. Unfortunately, existing FL approaches typically select randomly the set of clients to use each round, which can negatively impact the quality of the model trained, as well the training round time due to the straggler problem. Moreover, clients, especially mobile devices with limited resources, should be incentivized to participate as federated learning is essentially a form of crowdsourcing for AI which requires monetization. We argue that the integration of blockchain and smart contract technologies to FL can solve the two aforementioned issues. In this paper, we present FL-MAB (FL- Multi-Auction using Blockchain), a client selection mechanism for FL operating in a smart contract which rewards clients for their participation using cryptocurrencies. FL-MAB employs a multidimensional auction mechanism for selecting users based on the compute and network resources offered by each client, as well as the quality of their local data. This auction is realized in a reliable and auditable manner through a smart contract. This allows FL-MAB to measure the relative contribution of each client by calculating a Shapley value, and allocating rewards accordingly. We have implemented FL-MAB using Solidity and tested on the Ethereum blockchain with various popular datasets. Our results show that FL-MAB outperforms existing baseline schemes by improving accuracy and reducing the no. of FL rounds.
Abstract Healthcare Records are becoming more valuable than ever due to the emergence of various new diseases and the current pandemic. These records are scattered throughout multiple healthcare providers in several places. Keeping them in physical form is timeâconsuming; thus, they need to be kept in electronic form. Electronic Healthcare Records (EHRs) are mostly managed at the individual company level, creating a single point of failure and exposing users to various security risks, including amateurâlevel attacks and data breaches by hackers. This article proposes a permissioned blockchainâbased framework to overcome the above issues for secured storage and sharing of EHRs over the network. For the overall implementation of the framework Hyperledger Fabric (HLF), InterPlanetary Distributed File System (IPFS), and Identity Based Proxy ReâEncryption (IBâPRE) algorithm are used. To create proposed blockchain network, HLF is used. To manage EHRs on the blockchain, IPFS is used where the actual encrypted massive data is stored offâchain, and their corresponding hash values are stored on the blockchain. Further, IBâPRE algorithm is used to share EHRs in a safe manner, where a proxy node retrieves requested data from IPFS, performs reâencryption, and returns the reâencrypted data to the requester thus, ensures user privacy and data integrity. Finally, the Hyperledger Caliper tool is used to run a performance test to check the system efficiency in terms of throughput and latency. Features and performanceâbased comparisons of the proposed and existing related work are made to demonstrate the effectiveness.
Storage is a promising application for permission-less blockchains. Before blockchain, cloud storage was hosted by a trusted service provider. The centralized system controls the permission of the data access. In web3, users own their data. Data must be encrypted in a permission-less decentralized storage network, and the permission control should be pure cryptographic. Proxy re-encryption (PRE) is ideal for cryptographic access control, which allows a proxy to transfer Aliceâs ciphertext to Bob with Aliceâs authorization. The encrypted data are stored in several copies for redundancy in a permission-less decentralized storage network. The redundancy suffers from the outsourcing attack. The malicious resource provider may fetch the content from others and respond to the verifiers. This harms data integrity security. Thus, proof-of-replication (PoRep) must be applied to convince the user that the storage provider is using dedicated storage. PoRep is an expensive operation that encodes the original content into a replication. Existing PRE schemes cannot satisfy PoRep, as the cryptographic permission granting generates an extra ciphertext. A new ciphertext would result in several expensive replication operations. We searched most of the PRE schemes for the combination of the cryptographic methods to avoid transforming the ciphertext. Therefore, we propose a new PRE scheme. The proposed scheme does not require the proxy to transfer the ciphertext into a new one. It reduces the computation and operation time when allowing a new user to access a file. Furthermore, the PRE scheme is CCA (chosen-ciphertext attack) security and only needs one key pair.
Kun Li, Huachun Zhou, Zhe Tu, Feiyang Liu · 5 authors
The malicious flow originating from massive access devices in 6G network will increase sharply. In order to effectively reduce malicious flow, we hope to establish a new framework for coordination of security monitoring and malicious behaviour control in 6G network. Federated learning provides data and privacy protection for the distributed network security behaviour knowledge base. However, since the equipment of its participants needs to upload the original data to the central server for model training, this may lead to data leakage in the knowledge base. Therefore, in this article, we first use the knowledge graph to describe network security behaviours, then build a universal network security malicious behaviour knowledge base, and discuss its application scenarios. Then, we propose a blockchain empowered federated learning (BeFL) for distributed network security malicious behaviour knowledge base architecture to ensure the security of knowledge transmission. Finally, we deployed the designed distributed knowledge base in the prototype system and compared it with the other two baseline methods to verify the performance. Relevant results show that our method outperforms other methods in terms of user identification, flow detection, and attack source tracing.
Federated learning (FL) has become a new form of data sharing by aggregating multi-party local models. Although the existing FL incentive system has reduced insufficient data supply under comprehensive information, it still confronts issues including free-riding, unfairness, and unreliability. Therefore, this paper proposes an incomplete information FL incentive mechanism based on blockchain and Bayesian games. The data transaction process is modeled by quantifying the cost-utility of the data providers and the payment reward of the data requesters, in which Shapley value is used to realize the fairness of reward distribution of data providers. We consider the heterogeneity and privacy protection of participating individuals. The data providers' resource allocation strategies are built as a Bayesian game model, which optimizes the local training strategy to realize the incentive effect on the data providers. Furthermore, we consider the effectiveness of the incentive mechanism, a privacy-preserving Bayesian game action strategy consensus algorithm (PPBG-AC) is proposed, which enables the data providers to realize Bayesian Nash equilibrium under a data trading platform based on blockchain. The comparison and analysis of the schemes reveal that the incentive mechanism presented in our paper assures benefit distribution fairness and resource allocation credibility. Simulation experiments and performance evaluations based on real datasets demonstrate the effectiveness of our incentive mechanism.
Minghui Xu, Zongrui Zou, Ye Cheng, Qin Hu · 6 authors
Decentralized learning involves training machine learning models over remote mobile devices, edge servers, or cloud servers while keeping data localized. Even though many studies have shown the feasibility of preserving privacy, enhancing training performance or introducing Byzantine resilience, but none of them simultaneously considers all of them. Therefore we face the following problem:how can we efficiently coordinate the decentralized learning process while simultaneously maintaining learning security and data privacy for the entire system?To address this issue, in this paper we propose SPDL, a blockchain-secured and privacy-preserving decentralized learning system. SPDL integrates blockchain, Byzantine Fault-Tolerant (BFT) consensus, BFT Gradients Aggregation Rule (GAR), and differential privacy seamlessly into one system, ensuring efficient machine learning while maintaining data privacy, Byzantine fault tolerance, transparency, and traceability. To validate our approach, we provide rigorous analysis on convergence and regret in the presence of Byzantine nodes. We also build a SPDL prototype and conduct extensive experiments to demonstrate that SPDL is effective and efficient with strong security and privacy guarantees.
A. Sampathkumar, Shishir Kumar Shandilya, NebojĆĄa BaÄanin
In the area where privacy is of greater concern, federated learning,a distributed machine learning strategy for preserving privacy,is widely employed in several privacy concern applications. In the meantime, neural architectures became familiar with deep learning approaches for automatic tuning of the architecture of deep neural networks (DNN). While searching with neural architecture and federated learning has experienced several challenges, optimized neural architecture research in federated learning is extensively on demand. DNN faces numerous issues while training such user privacy and ensuring the integrity of the aggregated results obtained from a server. To provide solutions for the above-mentioned issues, enormous federated learning techniques worked towards preserving privacy and were applied in different situations. Still, it is an open challenge that enables users to verify if the cloud server functions appropriately while ensuring usersâ privacy while training. Federated Learning Method is a new way to improve the accuracy and precision, since the previous approach failed to opt the solutions. Here, Elliptical Curve Cryptography with Blockchain-based Federated Learning (ECC-BFL)is proposed to ensure the confidentiality of usersâ local gradients while performing federated learning. The parameters such as classification accuracy, running time, Communication overhead, Computation overhead, and transaction speed are considered. The values obtained for these parameters are compared against three standard methods, namely Biparing Method (BM) Homomorphic Cryptosystem (HC), and Multiple Authorities with Attribute-Based Signature scheme (MA-ABS)against proposed Elliptical Curve Cryptography with Blockchain-based Federated Learning (ECC-BFL). As a result, the proposed ECC-BFL achieved 95% of classification accuracy, 65 sec of running time, 76% of communication overhead, 63% of computation overhead, and 92% of transaction speed.
There are significant data privacy implications associated with Electronic Health Records (EHRs) sharing among various untrusted healthcare entities. Recently, a blockchain-based EHRs sharing system has provided many benefits. Decentralization, anonymity, unforgeability, and verifiability are all unique properties of blockchain technology. In this paper, we propose a secure, blockchain-based EHR sharing system. After receiving the data ownerâs authorization, the data requester can use the data providerâs keyword search to discover relevant EHRs on the EHR consortium blockchain and obtain the re-encryption ciphertext from the proxy server. To attain privacy, access control and data security, the proposed technique uses asymmetric searchable encryption and conditional proxy re-encryption. Likewise, proof of permission serves in consortium blockchains as the consensus method to ensure the systemâs availability. The proposed protocol can achieve the specified security goals, according to the security analysis. In addition, we simulate basic cryptography and put the developed protocol into practice on the Ethereum platform. The analysis results suggest that the developed protocol is computationally efficient.
The Industrial Internet ofThings (IIoT) plays an essential role in the digital renovation of conventional industries to Industry 4.0. With the connectivity of sensors, actuators, appliances, and other industrial objects, IIoT enables data availability, improved analytics, and automatic control. Thanks to the complex distributed nature, a wide range of stealthy and evolving cyberattacks become a major threat to the trustworthiness and security of IIoT systems. This makes the standard security procedures unable to assure the trustworthiness of IIoT that protect against cyberattacks. As a remedy, this article presents a blockchain-orchestrated edge intelligence (BoEI) framework that integrates an innovative decentralized federated learning (called Fed-Trust) for cyberattack detection in IIoT. In the Fed-Trust, a temporal convolutional generative network is introduced to enable semi-supervised learning from semi-labeled data. BoEI includes reputation-based blockchain to enable decentralized recording and verification of the transactions for guaranteeing the security and privacy of data and gradients. Fog computing is exploited to offload the block mining operation from the edge side thereby improving the overall computation and communication performance of Fed-Trust. Proof of concept simulations using two public datasets validate the robustness and efficiency of the Fed-Trust over the cutting-edge cyberattack detection approaches.
With the rapid development of healthcare-based cyber physical systems (CPSs), more and more healthcare data is collected from clinical institutions or hospitals. Due to the private and fragmented nature, healthcare data is quite suitable to be processed by federated learning (FL) paradigm, where a shared global model is aggregated by a central server while keeping the sensitive healthcare data in local hospitals. However, there are two practical issues: (1) the centralized FL server may not honestly aggregate the final model, and (2) the FL participants lack incentive to contribute their efforts. In this study, we propose a blockchain-empowered FL framework for healthcare-based CPSs. A distributed ledger is maintained by a task agreement committee which is composed by the representators of the hospitals who execute FL tasks. A secure FL task model training-based consensus process is proposed to generate consistent blocks. Furthermore, a contribution point-based incentive mechanism is designed to fairly reward FL participators for contributing their local data. We evaluate the proposed system base on real healthcare data and the numerical results demonstrate its effectiveness in achieving FL model aggregation truthfulness and efficiency in providing incentives for FL participants.
Internet of Things (IoT) devices has completely new challenges regarding security and privacy. Blockchain technology could be a great to mitigate challenges of data security and privacy relay in the IoT. Crypto currency networks like Bit coin, can prove to be required towards understanding concept of decentralized, security and Leveraging of blockchain for privacy preserving. Differential privacy is a mathematical technique of adding a controlled amount of randomized noise to a dataset to prevent anyone from getting information about individuals in the dataset. The added randomized noise is in controlled manner. Therefore, the resultant dataset is still accurate enough to generate aggregate output while maintaining the privacy of individual participants. As Block chain is a peer-to-peer distributed ledger, it is an optimal way for preventing identity, monitoring, non-repudiation and providing tracking in IoT, so due to these aspects we can explore future research challenges to preserve privacy in blockchain.
Currently, most of the personal health data (PHD) are managed and stored separately by individual medical institutions. When these data need to be shared, they must be transferred to a trusted management center and approved by data owners through the third-party endorsement technology. Therefore, it is difficult for personal health data to be shared and circulated over multiple medical institutions. On the other hand, the use of directly exchanging and sharing the original data has become inconsistent with the data rapid growth of medical institutions because of the need of massive data transferring across agencies. In order to secure sharing and managing the mass personal health data generated by various medical institutions, a federal personal health data management framework (PHDMF, https://hvic.biosino.org/PHDMF) has been developed, which had the following advantages: 1) the blockchain technology was used to establish a data consortium over multiple medical institutions, which could provide a flexible and scalable technical solution for member extension and solve the problem of third-party endorsement during data sharing; 2) using data distributed storage technology, personal health data could be majorly stored in their original medical institutions, and the massive data transferring process was of no further use, which could match up with the data rapid growth of these institutions; 3) the distributed ledger technology was utilized to record the hash value of data, given the anti-tampering feature of the technology, malicious modification of data could be identified by comparing the hash value; 4) the smart contract technology was introduced to manage users' access and operation of data, which made the data transaction process traceable and solved the problem of data provenance; and 5) a trusted computing environment was provided for meta-analysis with statistic information instead of original data, the trusted computing environment could be further applied to more health data, such as genome sequencing data, protein expression data, and metabolic profile data through combining the federated learning and blockchain technology. In summary, the framework provides a convenient, secure, and trusted environment for health data supervision and circulation, which facilitate the consortium establish over medical institutions and help achieve the value of data sharing and mining.
Information sharing has become an important application in modern supply chain management systems with business technology development. Because traditional supply chain information systems have problems such as easy data tampering, low information transparency, and interaction delays, blockchain has been taken consideration into supply chain information sharing research. Furthermore, blockchain technology is expected to provide decentralized supply chain information sharing solutions to enhance security, availability, and transparency. However, with the in-depth study of the application of blockchain technology in supply chain information sharing, people have found that the data stored publicly in the blockchain are still threatened by privacy leakage. In addition, due to the openness and accessibility of the blockchain, the lack of fine-grained access control is also apparent. In order to improve the security of data, we propose a novel privacy-preserving multiauthority attribute-based access control scheme for secure blockchain-based information sharing in a supply chain. In this scheme, blockchain stores encrypted supply chain information on distributed nodes. Multiple attribute authorities manage different attributes of users to achieve fine-grained access control and flexible authorization. Even if some attribute authorities fail, the userâs private key will not be leaked. In user secret key generation, we adopt an anonymous key generation protocol to realize the secure distribution of user keys by the attribute authorities. Furthermore, in order to meet the protection of communication privacy between blockchain nodes, properties of policy hiding and identity hiding are considered. Finally, we design experiments to analyze the performance of our scheme, including secret key sizes and running time of encryption and decryption.