Alexander Omran, Mahmoud Abouyoussef, Muhammad Ismail, Surbhi Bhatia
During pandemics, diagnostic tests are essential to provide quick treatment of patients and limit the disease spread. The high demand for testing resources can stress the healthcare system. Thus, a remote collection of symptoms and reporting the results via an automated diagnostic system is highly desirable. However, such a system is challenged by privacy and scalability issues. Hence, we propose a sharded blockchain-based system that (a) introduces a set of shards that distributes the testing load among a group of local nodes (LNs), hence, offering high scalability for country-wide adoption, (b) uses ring signatures and unique random identifiers to ensure the anonymity of the users and the unlinkability of test requests, hence, supporting privacy-preservation, (c) deploys a detection strategy at the LNs based on deep neural networks, which is implemented on smart contracts, hence, enabling autonomous diagnosis, and (d) provides healthcare entities with authorized access to the symptoms and test results, hence, enabling efficient data sharing that supports future research. We provide an implementation of the proposed system and our experimental results demonstrate the high scalability and privacy of the system while achieving a testing accuracy up to 90%. We present a case study for U.S. wide deployment showing that a total daily test request of 2, 407, 462 can be performed and reported in 11 minutes compared to 63 days in absence of sharding. Moreover, sharding decreased the user storage requirement to be 0.18 MB at maximum instead of 723 MB without sharding.
Path validation assures operational integrity in 5G networks with various network infrastructures where nodes en route are operated by multiple untrusted network slicing authorities. However, in order to correctly validate a path, traditional solutions require the entire path to be revealed to all parties involved, which may potentially expose the network structure to malicious attackers. In this work, we propose a decentralized privacy-preserving path validation protocol utilizing XOR, hashing and Non-interactive zero-knowledge proof (NIZK) that guarantees security and privacy but circumvents performance compromise. We tested our protocols in a simulated multi-authority network to show how the privacy-preserving path validation can protect node privacy without significantly degrading performance.
Xiaoyan Hu, Jun Yin, Guang Cheng, Jian Gong · 7 authors
Due to its efficiency, low overhead, and high scalability, consortium blockchain has been deeply applied in various fields of society. Order financing is one of the scenarios of applying consortium blockchain. Since data on the consortium blockchain is available to the blockchain members, information of a financing order written directly to the blockchain will leak the commercial privacy of the purchaser and supplier. Therefore, the financing order data should be encrypted when published as a transaction on the consortium blockchain. However, the investor needs to verify the financing order data on a consortium blockchain before loaning money to the supplier. It is tricky to efficiently satisfy the verifiability of encrypted financing order data on the consortium blockchain. This work proposes VmppOrder, a verifiable model for privacy-preserving financing orders on a consortium blockchain based on zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARKs). By the supplier publishing zero-knowledge proofs generated from the financing order, the investor can verify the encrypted financing order published on the consortium blockchain without decrypting it. We elaborate on the specific construction of VmppOrder and analyze the security of the constructed circuit with zero-knowledge proof. We implement a prototype of the model on Hyperledger Fabric based on Libsnark and conduct comprehensive experiments to evaluate its performance. Our experimental results validate the efficiency of the proposed model. Its order proof generation takes about 6.31 seconds, the order verification takes only 2.58 milliseconds, and the transaction processing speed is about 660 transactions per second on a moderately equipped machine.
Large-scale applications of electronic medical records (EHRs) based on blockchain technology have prompted us to find an intelligent way to realize insurance compensation, which brings convenience for both insurance companies and patients. However, due to the public verifiability of blockchains, straightforward utilizing a blockchain to construct an insurance compensation scheme would cause leakage of patients’ privacy. In this paper, we propose an agent compensation model based on smart contract to guarantee the credibility of EHRs and to enable automatical insurance compensation without requiring interactions between insurance companies and patients. A hybrid smart contract privacy-preserving insurance compensation scheme is put forward based on the agent compensation model. The "private" and "public" smart contracts are deployed on the private and public blockchain respectively. By designing private smart contracts, we limit the visitors of private data and prevent third parties from accessing patient private data. By deploying public smart contract that introduces zero-knowledge proof and blockchain oracles, we realize compensations information verification and agent payment without privacy data leakage. Security analysis and performance evaluations are conducted to prove that our scheme is secure against various attacks while achieving high efficiency.
Kun Zhu, Lu Huang, Jiangtian Nie, Yang Zhang · 7 authors
For future Internet of Things (IoT) systems, data-driven and dynamic spectrum-sharing schemes can significantly improve the spectrum utilization and efficiency. However, conventional centralized architecture of such dynamic IoT spectrum-sharing systems is often considered to be nontransparent, costly, and vulnerable to potential attacks and single-point failures. To address the aforementioned issues, a blockchain-based dynamic spectrum-sharing scheme has been proposed and investigated in this work, which aims at enhancing the system by providing desirable features, such as decentralization, transparency, immutability, and auditability. By considering the privacy and transaction dynamics issues when blockchain is integrated into spectrum-sharing systems, a privacy-preserving double auction mechanism based on differential privacy is developed for incentivizing spectrum sharing, where the time-varying valuations of the spectrum resources are also taken into consideration. In the proposed auction, a winner determination problem (WDP) is formulated to decide the winning bidders and spectrum allocation. A deep reinforcement learning (DRL)-based method is then proposed for efficiently solving the WDP. The proposed auction mechanism can be integrated with smart contracts on blockchain platforms. Furthermore, the computation of the DRL-based method for solving the WDP is designed as part of the consensus mechanism in the blockchain. Theoretical analysis show that the proposed privacy-aware double auction mechanism satisfies the properties of differential privacy, individual rationality, and truthfulness. Finally, simulation results are provided to validate the performance of the spectrum-sharing approach.
Abdullah Lakhan, Mazin Abed Mohammed, Jan Nedoma, Radek Martinek · 8 authors
These days, the usage of machine-learning-enabled dynamic Internet of Medical Things (IoMT) systems with multiple technologies for digital healthcare applications has been growing progressively in practice. Machine learning plays a vital role in the IoMT system to balance the load between delay and energy. However, the traditional learning models fraud on the data in the distributed IoMT system for healthcare applications are still a critical research problem in practice. The study devises a federated learning-based blockchain-enabled task scheduling (FL-BETS) framework with different dynamic heuristics. The study considers the different healthcare applications that have both hard constraint (e.g., deadline) and resource energy consumption (e.g., soft constraint) during execution on the distributed fog and cloud nodes. The goal of FL-BETS is to identify and ensure the privacy preservation and fraud of data at various levels, such as local fog nodes and remote clouds, with minimum energy consumption and delay, and to satisfy the deadlines of healthcare workloads. The study introduces the mathematical model. In the performance evaluation, FL-BETS outperforms all existing machine learning and blockchain mechanisms in fraud analysis, data validation, energy and delay constraints for healthcare applications.
Nowadays, the number of corona patients is increasing significantly. The relationship between the Internet of Medical Things (IoMT) and the Internet is struggling to keep up with this number of patients. The transmission of Patient Health Records (PHR) to the care of a patient through Internet plays an important role in the remote monitoring and fast detection of new contaminated patient with coronavirus. Moreover, it has generated significant security and privacy concerns for the global health care system due to tampering of control messages. This paper focuses on the application of blockchain and smart contract mechanisms to solve the shortcomings of the current health application and propose a new security schema based on context-aware CP-ABE. The proposed schema includes context-aware policies to achieve a robust authentication of identity and confidentiality of patient's healthcare data. Therefore, the proposed schema shows promising results in enhancing security and minimizing encryption time in Fog cloud environments based on proxy-fog and reinforcement of security policies.
In spite of growth in technology, Indian Judiciary system somehow lacks digitalization. In the court trials cases, every argument by the lawyers, evidence presentation, witness/suspect cross examination everything will be noted down by the stenographer and everyday hearings details will be printed at the end of every court sessions. Therefore, the details about particular case will be in physical files as well as in digital format and can be accessed whenever it is needed like in the situation of case reopening. Data integrity is important in the judiciary system; when it comes to court cases, evidence integrity must be protected because even little changes in the evidence can lead to false judgments, and historical data is crucial. Where historical data archiving is necessary, Blockchain technology is suited. In the modern era, Blockchain technology is regarded as more reliable technology than any other. Blockchain technology can be used in the justice system to provide privacy and integrity, as well as efficient auditability and traceability, for storing case records and evidences. This research study has proposed a novel method using InterPlanetary File System distributed data storage to store case details and evidences on top of the Ethereum Blockchain. The case details can be stored using text and image files. The Ethereum smart contract is used for storing hash value of data in the Blockchain. The storage and access of the data in InterPlanetary File System is studied and explained using an experimental setting.
Prabhat Kumar, Randhir Kumar, Govind P. Gupta, Rakesh Tripathi
Green Connected and Autonomous Vehicles (CAVs) are the future of next-generation Intelligent Transportation Systems (ITS) that will help humans to improve road safety and reduce pollution, energy consumption, and travel delays. To increase the performance of green CAV, the data generated by Autonomous Vehicles (AVs) and associated infrastructure needs to be processed in real-time. Mobile Edge Computing (MEC) is a promising paradigm that can be integrated with green CAV to save energy and to improve the network performance in terms of low latency for data processing. However, MEC servers and other communication entities in green CAV environment cannot be fully trusted and may bring vulnerabilities related to data privacy and security. Motivated by the above challenges, we design a blockchain and Deep-Learning (DL)-enabled secure data processing framework for an edge-envisioned green CAV environment (hereafter referred to as BDEdge). In blockchain-based scheme, all communication entities are registered, verified and thereafter validated using smart contract-based Practical Byzantine Fault Tolerance (PBFT) consensus algorithm. The authenticated data is forwarded to DL scheme. In DL-based scheme, an Intrusion Detection System (IDS) based on a hybrid model of Sparse Auto-Encoder-enabled Attention Bidirectional Gated Recurrent Unit (SAE-ABIGRU) is designed by analyzing the link load behaviors of the MEC-enabled Road Side Unit (RSU) server. The security analysis and comparative simulation findings shows that the proposed BDEdge framework can significantly reduce false alarm rate and increase accuracy close to 99%.
The integration of information systems and physical systems is the development trend of today’s manufacturing industry. Intelligent manufacturing is a new model of manufacturing, based on advanced manufacturing technology with human–machine–material collaboration. Internet of Things technology is the core technology of intelligent manufacturing, and access control technology is one of the main measures to ensure the security of the IoT. In view of the problem that the existing IoT access control model does not support distributed and fine-grained dynamic access control, this paper uses the characteristics of blockchain, such as decentralization and non-tampering, combined with the attribute-based access control (ABAC) method, to propose a distributed access control method, applicable to the IoT environment in the process of intelligent manufacturing. This paper describes a fine-grained access control policy by defining the access control attribute values in a formal language, which supports complex logic operations in the policy and enhances the expressiveness of the model. Distributed access control decision making, using smart contracts for blockchain, improves the decision-making efficiency of the access control model, increases the post-facto audit of the access control behavior, and improves the overall security of IoT data protection. The paper concludes with proof of security and a performance analysis, and the experimental results, such as storage and computing overheads, show that this method can provide fine-grained, dynamic, and distributed access control for devices in intelligent manufacturing, ensuring the security and reliability of access control for IoT devices.
Blockchain is a distributed ledger that combines technologies such as timestamp, cryptography, consensus mechanism, and peer-to-peer network. In the field of data recording and management, the blockchain data query scheme based on smart contracts consumes a lot of resources, and blockchain platforms that do not support smart contracts cannot achieve convenient data query. This study proposes a blockchain data sharing query scheme based on threshold secret sharing. The secret elements used to query data are shared through the Blakley space plane equation to limit the rights of the inquirer, ensuring the security of blockchain data query. At the same time, the Blakley space plane equation coefficient matrix is used to segment the data to be uploaded to the blockchain. It solves the problem that the data cannot be directly stored in the block due to their large size. It facilitates data uploading to the blockchain. The experimental results show that the additional time consumption of the secret sharing and recovery, data segmentation, and reconstruction of this scheme is much less than the block generation time. Therefore, this solution will not affect the normal operation of blockchain applications and can improve the security and the fault tolerance rate of data query.
Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
The Internet of Vehicles is the specific instantiation of the Internet of Things in the field of transportation. Vehicle and driving data are often used to mine information about people’s lifestyles and preferences. Without advanced data encryption and strict authorization measures, personal privacy and security are at great risk. To solve the problem that the relatively low security of vehicles connected to the Internet may threaten the privacy of users, a blockchain-based sensitive data privacy-protection scheme for vehicles connected to the Internet is proposed. First, association rules are used to mine Big Data in the Internet of Vehicles. Then, a data security aggregation protocol is established. Finally, an end-to-end encryption mechanism is created. The privacy protection of Big Data in the Internet of Vehicles is achieved through static and dynamic strategies. The experimental results show that the scheme can improve the hiding rate of sensitive data, the key generation time and encryption time are shorter than those of typical technologies, and the encryption ability is better. Therefore, in protecting the privacy of Big Data in the Internet of Vehicles, the blockchain proposed in this paper has better privacy protection and encryption abilities and is applicable to the protection of sensitive data in the Internet of Vehicles.
Abstract Blockchain-based systems, coined by distributed ledger technologies (DLTs), have rapidly received tremendous interest from academia, industries, and governments. Recent literature has revealed many research and developments on applying DLTs to the Internet of things (IoT), cloud-edge computing. In this survey, we conduct a comprehensive survey of the newly appeared concepts, theories, platforms, and DLTs-facilitated applications of vehicular networks and mobile edge computing (MEC). We also review the selections of the available DLTs related platforms and tools. Future research directions and issues are discussed, including security, privacy, scalability issues, and multiple applications in various domains.
Leveraging various mobile devices to train the shared model collaboratively, federated learning (FL) can improve the privacy and security of 6G communication. To economically encourage the participation of heterogeneous mobile devices, an incentive mechanism and a fair trading platform are needed. In this paper, we implement a blockchain-based FL system and propose an incentive mechanism to establish a decentralized and transparent trading platform. Moreover, to better understand the mobile devices’ behaviors, we provide economic analysis for this market. Specifically, we propose two strategy models for mobile devices, namely the discrete strategy model (DSM) and the continuous strategy model (CSM). Also, we formulate the interactions among the non-cooperative mobile devices as a dynamic game, where they adjust their strategies iteratively to maximize the individual payoff based on others’ previous strategies. We further prove the existence in Nash equilibrium (NE) of two different models and propose algorithms to achieve them. Simulation results demonstrate the convergence of the proposed algorithms and show that the CSM can effectively increase the mobile devices’ payoffs to 128.1 percent at most compared with DSM.
Mohammed Shuaib, Noor Hafizah Hassan, Sahnius Usman, Shadab Alam · 8 authors
Providing an identity solution is essential for a reliable blockchain-based land registry system. A secure, privacy-preserving, and efficient identity solution is essential but challenging. This paper examines the current literature and provides a systematic literature review in three stages based on the three research questions (RQ) that show the assessment and interpretation process step by step. Based on the parameters and RQ specified in the research methodology section, a total of 43 primary articles have been selected from the 251 articles extracted from various scientific databases. The majority of these articles are concerned with evaluating the existing self-sovereign identity (SSI) solutions and their role in the blockchain-based land registry system to address the compliance issues in the existing SSI solutions with SSI principles and find the best possible SSI solution to address the identity problems in the land registry. The existing digital identity solutions cannot handle the requirements of the identity principle and are prone to various limitations like centralization and dependency on third parties that further augment the chance of security threats. SSI has been designed to overcome these limitations and provide a secure, reliable, and efficient identity solution that gives complete control to the users over their personal identity information (PII). This paper reviews the existing SSI solutions, evaluates them based on the SSI principles, and comes up with the best possible SSI solution for a blockchain-based land registry system. It further provides a detailed investigation of each SSI solution to present its functionalities and limitations for further improvement.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Despite the continuous improvement of healthcare technology, implementing a patient health record system still has a significant challenge due to its sensitivity. Apart from storing and sharing patient data across various healthcare facilities, the system also has a tendency to distribute the data among various providers. Most patient health record systems (EHRs) use a centralized management structure to store and transmit patient information. This approach can create privacy concerns as it transfers sensitive information to a healthcare facility. Digitized Electronic Health Record EHRs that stores the patient’s medical history gathers from various IoT devices or from the centralized or decentralized database. These database records are often shared among various healthcare organizations. Most patient health record systems typically adopt a centralized approach and store their patient information in the cloud. This approach can raise privacy concerns due to the amount of sensitive information that is stored in the cloud. This paper proposes blockchain framework for secured electronic health records sharing and provides full data access to the patient, who is the owner of his health records. With this novel approach, our framework applies the Ethereum blockchain smart contracts, the Inter-Planetary File System (IPFS) as an off-chain storage system and key management. Blockchain based encryption creates an effective approach while sharing health records in distributed framework. Proposed framework is more secure than previously available framework. EHR’s will not be accessible from unauthorized users.
Many existing searchable encryption schemes are inflexible in retrieval patterns. The data usage authorization is almost permanent valid as long as the user is not revoked. This “all-or-nothing” authorization mode is not compatible with the “pay-as-you-use” commercial billing model. In this article, we propose a new notion called time controlled expressive predicate query with accountable anonymity. It realizes time controlled data query, where a time server issues time token to authorize search privilege in designated time period. The data users can anonymously query on encrypted data and the anonymity is accountable in a way that the trusted authority is able to deanonymize data users if they misbehave in the system. The underlying techniques are anonymous credential, Pederson commitment and non-interactive zero-knowledge proof. We firstly design an efficient expressive predicate query (EPQ) scheme, which is proved secure to protect the privacy of expressive search predicate. Based on EPQ, we present a concrete system instantiation, which realizes key-escrow free and time token nontransferability. The formal definition and security models are given out. The system is formally proved indistinguishable against chosen keyword-set attacks, unforgeable of time tokens and accountable of anonymous users. The comparison and experiment results demonstrate its scalability and efficiency.
Sunxuan Zhang, Zhao Wang, Zhenyu Zhou, Yan Wang · 9 authors
Cloud-edge-end collaboration enables harmonious and efficient resource allocation for the Power Internet of Things (PIoT). However, the security and complexity issues of computation offloading evolve into the main obstacles. In this article, we first propose a blockchain and AI-based secure cloud-edge-end collaboration PIoT (BASE-PIoT) architecture to ensure data security and intelligent computation offloading. Its advantages in flexible resource allocation, secure data sharing, and differentiated service guarantee are elaborated. Then the adaptability of three typical blockchains with PIoT is analyzed, and some typical application scenes of BASE-PIoT including computation offloading, energy scheduling, and access authentication are illustrated. Finally, we propose a blockchain-empowered federated deep actor-critic-based task offloading algorithm to address the secure and low-latency computation offloading problem. The coupling between the long-term security constraint and short-term queuing delay optimization is decoupled by using Lyapunov optimization. Numerical results verify its excellent performance in total queuing delay and consensus delay.
Remote voting has become more critical in recent years, especially since the COVID-19 outbreak. Blockchain technology and its benefits such as decentralization, security, and transparency have given rise to proposals for blockchain-based voting systems. However, the traceability of blockchain transactions violates voter anonymity in existing proposals. Besides, transaction costs also need to be considered. Solutions that may cause repeated elections should be avoided for a low-cost scalable voting system. In this work, we propose ElectAnon, a blockchain-based, self-tallying, and ranked-choice voting protocol focusing on anonymity, robustness, and scalability. ElectAnon achieves anonymity by enabling voters to register with identity commitments and cast their votes via zero-knowledge proofs. Robustness is realized by removing the direct control of the authorities in the voting process by using timed-state machines. Each voter encodes the ballot into a single integer and blinds the vote off-chain while making the verification on-chain. This makes the protocol infinitely scalable in the number of voters. ElectAnon is also a solution for governance in Decentralized Autonomous Organizations (DAO): It includes a candidate proposal module and an algorithm-agnostic mechanism to plug-in different tallying methods easily. The Merkle forest extension is proposed for conducting even more trustless elections. ElectAnon is implemented with smart contracts based on Ethereum Virtual Machine (EVM) and a zero-knowledge gadget, Semaphore. The implementation also includes two different sophisticated tallying methods, Borda Count and Tideman. Experimental results show that a 40-voter and 10-candidate election can be implemented with the gas consumption reduced up to 89% compared to previous works. While other studies could not exceed a 25,000-voter setup, ElectAnon has been observed to run safely for 1,000,000 voters. The implementation can be found at https://github.com/ceyonur/electanon .
I P Raghesh Kumar, Rithin Varghese, Nandu Nagesh, Vyshnav Sasidharan · 5 authors
A majority of the research on accident detection systems involves increasing the precision at which it can be detected. This approach proposes a test-bed for a vehicular incident detection system that uses real time data collected from OBD -II port of automobiles and later passed on to Edge devices within vehicles to detect an accident or other rash driving behavior patterns. Machine learning algorithms are developed and deployed onto edge devices like Jetsonnano for real time pattern recognition. Once an incident like accident or rash driving is triggered, the data is cached and written onto Inter Planetary File Systems (IPFS) a distributed file storage system and put onto Ethereum Blockchain for later analysis and documentation by various stakeholders like police, RTO, law, forensic team etc. Blockchain acts as an immutable ledger providing proof of all incidents. Further using the obtained data, dashboards of the incident can be generated for further visualization and understandability to the concerned stakeholder
With the rapid development of cloud servers, storing data on cloud servers has become a popular option. However, cloud servers are centralized. Storing data on centralized cloud servers may involve some risks. For example, the data access pattern may be revealed when accessing data on cloud servers. Therefore, protecting a user’s patterns has become a crucial concern. Oblivious RAM (ORAM) is a candidate solution to hide the data access pattern. However, it inherently induces some overhead of accessing data, and many blockchain-based applications also do not consider the access pattern leakage issues. In this paper, we address these issues above by proposing a decentralized database system with oblivious access in a (parallel) smart contract model. The interactions of oblivious access are asymmetric where the smart contract side is expected to put much effort into computation. The proposed system slightly reduces the overhead of ORAM and overcomes the issues stemming from the centralization of servers. The main techniques are to use the garbled circuits to reduce the cost of communication and to combine with the parallel smart contract model to (conceptually) improve the performance of smart contract execution on the blockchain.