Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

3,460 papersLast indexed Aug 31, 2026
Search papers

Paper index

3,460 results · page 115 of 145

Clear filters
Aug 1, 2019·2019 IEEE 2nd International Conference on Computer and Communication Engineering Technology (CCET)
14 cites
A Blockchain-Based Framework for Secure Log Storage

Wenren Huang

Logs are critical data, which can help us to troubleshoot and identify the person in charge of an unexpected accident. Log systems have been widely used for log storage. However, the traditional log system can't prevent the log from being tampered. Centralized servers are more vulnerable to be attacked. Those who have permission to operate records can easily tamper with logs. Blockchain is a disruptive technology in recent years, which has the advantages of decentralization, tamper-proof and traceability. Given its decentralization and tamper-proof properties, the paper proposed a blockchain-based framework for secure log storage. However, the cost of storing big files in the blockchain is very high. Thus, the paper utilized the InterPlanetary File System(IPFS) to store log files instead of a blockchain. Besides, the paper adopted Ethereum blockchain to store the hash of log files and a smart contract to create an index for log files. The solution is not only applicable to log but also other scenarios requiring secure data storage and efficient retrieval.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Aug 1, 2019·2019 International Conference on Information Management and Technology (ICIMTech)
12 cites
Robust Crypto-Governance Graduate Document Storage and Fraud Avoidance Certificate in Indonesian Private University

Rohmat Taufiq, Agung Trisetyarso, Meyliana Meyliana, Raymond Kosala · 7 authors

In this study, we considered crypto-governance as a solution for critical problems in private university management: fraud avoidance diplomas, transcripts and diploma supplement. To avoid fraud, it can be done by blockchain technology by the use of University, Company, Traceability, Profit and Policy-making of crypto-governance. Crypto-governance is able to use IBM using hyperledger fabric protocol and private blockchain network. Muhammadiyah Tangerang University (UMT) saved the graduate documents storage manually by human resources. Moreover, it would be wasting time for many tasks, for example when staffs searched database, they would consume a lot of time and the graduate documents were vulnerable to damage in the disaster. Based on the problems above it would face the research questions; how did we keep the graduate documents storage secure and how it could be authentic guaranteed? Blockchain technology with distributed ledger and consensus is considered to overcome this problem. There were 5 steps taken in this research starting from discussing, literature review, analyzing, learning blockchain technology, creating system model and making a conclusion. The conclusions of this study were expected that the data of graduate students could find faster, easily and authentic guaranteed.

Blockchain Technology in Education and Learning
Cloud Data Security Solutions
Blockchain Technology Applications and Security
Original source
Aug 1, 2019·2019 IEEE International Conference on Smart Internet of Things (SmartIoT)
58 cites
A Blockchain System for E-Learning Assessment and Certification

Chuyang Li, Junqi Guo, Guangzhi Zhang, Yaofei Wang · 6 authors

Nowadays, the applications of blockchain technology spring up rapidly, providing opportunities for solving the weaknesses in online education field, such as the complexity of e-learning assessment, the lack of a unified e-learning assessment standard and the insecurity of digital education certificates. In this paper, we propose a blockchain system for e-learning assessment and certification, which includes an entirely new network structure on the basis of the combination of the public and private blockchains, as well as four specific smart contract schemes for the realization of the e-learning assessment and credit exchange, the digital certificate issuance and secure storage, the digital certificate verification and the e-learning voucher allocation, respectively. The proposed system has been demonstrated as a promising candidate solution to establish a fairer, healthier and more open e-learning and online education environment.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Aug 1, 2019·Software Practice and Experience
81 cites
Blockchain‐based trusted data sharing among trusted stakeholders in IoT

Peichang Shi, Huaimin Wang, Shangzhi Yang, Chang Chen · 5 authors

Summary Sharing trusted data among trusted stakeholders is very important to large‐scale Internet of Things (IoT) applications. However, the entities and organizations involved in IoT naturally lack trusted relationships, which poses significant challenges to the above vision. Specifically, the first challenge is to ensure that the data in the physical world can be objectively and truly injected into the information world of IoT. The second is to ensure the credibility of the entities' identities in IoT. The third is to ensure the authenticity of data, the credibility of identity, and the reliable transmission of data when a third trusted party is unable to provide the expected trusted services. In view of the above challenges, this paper proposes a secure and lightweight triple‐trusting architecture (SLTA), which fully uses a blockchain‐related supporting technology. The architecture includes an oracle‐based data collection mechanism, which ensures that the data collected from edge devices of IoT cannot be modified, and the distributed identity management mechanism, which enhances personal privacy, security, and control of digital identities. Furthermore, a series of innovative designs for applying the blockchain to special large‐scale cooperation scenario in IoT are proposed, which is also a part of the key mechanisms of the SLTA. The innovative design includes a new software‐defined blockchain structure model and a lightweight Byzantine fault‐tolerant algorithm that provides credible support for decentralized data collection, identity management, and data transfer, as well as low‐overhead sequential storage mechanism.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Aug 1, 2019
38 cites
Practical Key Recovery Model for Self-Sovereign Identity Based Digital Wallets

Reza Soltani, Uyen Trang Nguyen, Aijun An

Recent years have seen an increased interest in digital wallets for a multitude of use cases including online banking, cryptocurrency, and digital identity management. Digital wallets play a pivotal role in the secure management of cryptographic keys and credentials, and for providing certain identity management services. In this paper, we examine a proof-of-concept digital wallet in the context of Self-Sovereign Identity and provide a practical decentralized key recovery solution using Shamir's secret sharing scheme and Hyperledger Indy distributed ledger technology.

Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Jul 31, 2019·Computers
70 cites
An Attribute-Based Access Control Model in RFID Systems Based on Blockchain Decentralized Applications for Healthcare Environments

Santiago Figueroa-Lorenzo, Javier Añorga, Saioa Arrizabalaga

The growing adoption of Radio-frequency Identification (RFID) systems, particularly in the healthcare field, demonstrates that RFID is a positive asset for healthcare institutions. RFID offers the ability to save organizations time and costs by enabling data of traceability, identification, communication, temperature and location in real time for both people and resources. However, the RFID systems challenges are financial, technical, organizational and above all privacy and security. For this reason, recent works focus on attribute-based access control (ABAC) schemes. Currently, ABAC are based on mostly centralized models, which in environments such as the supply chain can present problems of scalability, synchronization and trust between the parties. In this manuscript, we implement an ABAC model in RFID systems based on a decentralized model such as blockchain. Common criteria for the selection of the appropriate blockchain are detailed. Our access control policies are executed through the decentralized application (DApp), which interfaces with the blockchain through the smart contract. Smart contracts and blockchain technology, on the one hand, solve current centralized systems issues as well as being flexible infrastructures that represent the relationship of trust and support essential in the ABAC model in order to provide the security of RFID systems. Our system has been designed for a supply chain environment with an use case suitable for healthcare systems, so that assets such as surgical instruments containing an associated RFID tag can only access to specific areas. Our system is deployed in both a local and Testnet environment in order to stablish a deep comparison and determining the technical feasibility.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jul 24, 2019·CPP 2020: Proceedings of the 9th ACM SIGPLAN International Conference on Certified Programs and Proofs, January 2020, Pages 215-228
30 cites
ConCert: a smart contract certification framework in Coq

Danil Annenkov, Jakob Botsch Nielsen, Bas Spitters

We present a new way of embedding functional languages into the Coq proof assistant by using meta-programming. This allows us to develop the meta-theory of the language using the deep embedding and provides a convenient way for reasoning about concrete programs using the shallow embedding. We connect the deep and the shallow embeddings by a soundness theorem. As an instance of our approach, we develop an embedding of a core smart contract language into Coq and verify several important properties of a crowdfunding contract based on a previous formalisation of smart contract execution in blockchains.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jul 19, 2019·Journal of Medical Internet Research
178 cites
A Blockchain Framework for Patient-Centered Health Records and Exchange (HealthChain): Evaluation and Proof-of-Concept Study

Ray Hylock, Xiaoming Zeng

BACKGROUND: Blockchain has the potential to disrupt the current modes of patient data access, accumulation, contribution, exchange, and control. Using interoperability standards, smart contracts, and cryptographic identities, patients can securely exchange data with providers and regulate access. The resulting comprehensive, longitudinal medical records can significantly improve the cost and quality of patient care for individuals and populations alike. OBJECTIVE: This work presents HealthChain, a novel patient-centered blockchain framework. The intent is to bolster patient engagement, data curation, and regulated dissemination of accumulated information in a secure, interoperable environment. A mixed-block blockchain is proposed to support immutable logging and redactable patient blocks. Patient data are generated and exchanged through Health Level-7 Fast Healthcare Interoperability Resources, allowing seamless transfer with compliant systems. In addition, patients receive cryptographic identities in the form of public and private key pairs. Public keys are stored in the blockchain and are suitable for securing and verifying transactions. Furthermore, the envisaged system uses proxy re-encryption (PRE) to share information through revocable, smart contracts, ensuring the preservation of privacy and confidentiality. Finally, several PRE improvements are offered to enhance performance and security. METHODS: The framework was formulated to address key barriers to blockchain adoption in health care, namely, information security, interoperability, data integrity, identity validation, and scalability. It supports 16 configurations through the manipulation of 4 modes. An open-source, proof-of-concept tool was developed to evaluate the performance of the novel patient block components and system configurations. To demonstrate the utility of the proposed framework and evaluate resource consumption, extensive testing was performed on each of the 16 configurations over a variety of scenarios involving a variable number of existing and imported records. RESULTS: The results indicate several clear high-performing, low-bandwidth configurations, although they are not the strongest cryptographically. Of the strongest models, one's anticipated cumulative record size is shown to influence the selection. Although the most efficient algorithm is ultimately user specific, Advanced Encryption Standard-encrypted data with static keys, incremental server storage, and no additional server-side encryption are the fastest and least bandwidth intensive, whereas proxy re-encrypted data with dynamic keys, incremental server storage, and additional server-side encryption are the best performing of the strongest configurations. CONCLUSIONS: Blockchain is a potent and viable technology for patient-centered access to and exchange of health information. By integrating a structured, interoperable design with patient-accumulated and generated data shared through smart contracts into a universally accessible blockchain, HealthChain presents patients and providers with access to consistent and comprehensive medical records. Challenges addressed include data security, interoperability, block storage, and patient-administered data access, with several configurations emerging for further consideration regarding speed and security.

Open access
Blockchain Technology Applications and Security
Machine Learning in Healthcare
Cloud Data Security Solutions
Original source
Jul 19, 2019·Future Generation Computer Systems
177 cites
Trust management in a blockchain based fog computing platform with trustless smart oracles

Petar Kochovski, Sandi Gec, Vlado Stankovski, Marko Bajec · 5 authors

Trust is a crucial aspect when cyber-physical systems have to rely on resources and services under ownership of various entities, such as in the case of Edge, Fog and Cloud computing. The DECENTER’s Fog Computing Platform is developed to support Big Data pipelines, which start from the Internet of Things (IoT), such as cameras that provide video-streams for subsequent analysis. It is used to implement Artificial Intelligence (AI) algorithms across the Edge-Fog-Cloud computing continuum which provide benefits to applications, including high Quality of Service (QoS), improved privacy and security, lower operational costs and similar. In this article, we present a trust management architecture for DECENTER that relies on the use of blockchain-based Smart Contracts (SCs) and specifically designed trustless Smart Oracles. The architecture is implemented on Ethereum ledger (testnet) and three trust management scenarios are used for illustration. The scenarios (trust management for cameras, trusted data flow and QoS based computing node selection) are used to present the benefits of establishing trust relationships among entities, services and stakeholders of the platform.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Jul 15, 2019·SN Applied Sciences
100 cites
A Survey on Zero Knowledge Range Proofs and Applications

Eduardo Morais, Tommy Koens, Cees van Wijk, Aleksei Koren

In last years, there has been an increasing effort to leverage Distributed Ledger Technology (DLT), including blockchain. One of the main topics of interest, given its importance, is the research and development of privacy mechanisms, as for example is the case of Zero Knowledge Proofs (ZKP). ZKP is a cryptographic technique that can be used to hide information that is put into the ledger, while still allowing to perform validation of this data. In this work we describe different strategies to construct Zero Knowledge Range Proofs (ZKRP), as for example the scheme proposed by Boudot in 2001; the one proposed in 2008 by Camenisch et al, and Bulletproofs, proposed in 2017. We also compare these strategies and discuss possible use cases. Since Bulletproofs is the most efficient construction, we will give a detailed description of its algorithms and optimizations. Bulletproofs is not only more efficient than previous schemes, but also avoids the trusted setup, which is a requirement that is not desirable in the context of Distributed Ledger Technology (DLT) and blockchain. In case of cryptocurrencies, if the setup phase is compromised, it would be possible to generate money out of thin air. Interestingly, Bulletproofs can also be used to construct generic Zero Knowledge Proofs (ZKP), in the sense that it can be used to prove generic statements, and thus it is not only restricted to ZKRP, but it can be used for any kind of Proof of Knowledge (PoK). Hence Bulletproofs leads to a more powerful tool to provide privacy for DLT. Here we describe in detail the algorithms involved in Bulletproofs protocol for ZKRP. Also, we present our implementation, which was open sourced.

Open access
3 source records
cs.CR
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jul 10, 2019·IEEE Transactions on Cloud Computing
93 cites
CIPPPA: Conditional Identity Privacy-Preserving Public Auditing for Cloud-Based WBANs Against Malicious Auditors

Xiaojun Zhang, Jie Zhao, Chunxiang Xu, Hongwei Li · 6 authors

Wireless body area networks (WBANs) rely on powerful cloud storage services to manage massive medical data. As precise medical diagnosis analysis is heavily based on these medical data, any altered medical data may cause severe consequences, the integrity of outsourced medical data has become the most concerning security issue. Up to date, most existing public auditing mechanisms have been proposed to check the data integrity, but they could not achieve conditional identity privacy, any patient would not like others to know his/her real identity corresponding to certain serious disease, and some malicious patients should be revoked timely due to misbehaviors. Additionally, they are vulnerable to malicious auditors, by colluding with the cloud server to cheat patients. In this paper, we propose a conditional identity privacy-preserving public auditing (CIPPPA) mechanism for cloud-based WBANs. CIPPPA is the first public auditing mechanism achieving conditional identity privacy of patients in WBANs, the real identity of a patient is unknown to anyone in cloud-based WBANs other than the private key generator (PKG). We attempt to integrate Ethereum blockchain into CIPPPA, which gives assistance to patients for validating malicious auditing behaviors. Formal security analysis and performance evaluation demonstrate that CIPPPA is practical for cloud-based WBANs.

Cloud Data Security Solutions
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jul 8, 2019·Wireless Communications and Mobile Computing
78 cites
TrustChain: A Privacy Preserving Blockchain with Edge Computing

Upul Jayasinghe, Gyu Myoung Lee, Áine MacDermott, Woo Seop Rhee

Recent advancements in the Internet of Things (IoT) has enabled the collection, processing, and analysis of various forms of data including the personal data from billions of objects to generate valuable knowledge, making more innovative services for its stakeholders. Yet, this paradigm continuously suffers from numerous security and privacy concerns mainly due to its massive scale, distributed nature, and scarcity of resources towards the edge of IoT networks. Interestingly, blockchain based techniques offer strong countermeasures to protect data from tampering while supporting the distributed nature of the IoT. However, the enormous amount of energy consumption required to verify each block of data make it difficult to use with resource-constrained IoT devices and with real-time IoT applications. Nevertheless, it can expose the privacy of the stakeholders due to its public ledger system even though it secures data from alterations. Edge computing approaches suggest a potential alternative to centralized processing in order to populate real-time applications at the edge and to reduce privacy concerns associated with cloud computing. Hence, this paper suggests the novel privacy preserving blockchain called TrustChain which combines the power of blockchains with trust concepts to eliminate issues associated with traditional blockchain architectures. This work investigates how TrustChain can be deployed in the edge computing environment with different levels of absorptions to eliminate delays and privacy concerns associated with centralized processing and to preserve the resources in IoT networks.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Jul 7, 2019·Proceedings of the 2019 International Electronics Communication Conference
9 cites
An Auditable and Secure Model for Permissioned Blockchain

Zhenshan Bao, Kaixuan Wang, Wenbo Zhang

The intrinsic tamper-resistant characteristic of blockchain enables transaction to be permanently stored as immutable record, which provides extremely reliable information traceability for some application scenarios such as supply chain and copyright protection. However, in fact, even the Byzantine fault-tolerant consensus algorithm cannot fundamentally guarantee that transaction information is real and legitimate in reality. Therefore, the normal operation of the blockchain system requires the establishment of a special supervisory body to audit the transaction information, which can ensure that the data sources are credible rather than spurious or illegal. In addition, in the environment of permissioned blockchain, the realization of access mechanism often relies on centralized certificate authority. Unfortunately, a highly centralized management entity is not entirely trustworthy and reliable because it may be corrupt or attacked, which inevitably triggers many information security incidents such as privacy leakage and data loss. In order to realize the secure governance of permissioned blockchain system, a novel multi-supervised permissioned blockchain (MSPB) model is proposed in this paper, which supports auditing and eliminates the centralized entities in the system, including certification authority and auditing authority. We evaluated the security and performance of the proposed model to demonstrate its feasibility, reliability and effectiveness.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Jul 3, 2019·Proceedings of the 24th European Conference on Pattern Languages of Programs
9 cites
BlockBD

Julio Moreno, Eduardo B. Fernández, Eduardo Fernández‐Medina, Manuel Serrano

Big Data is changing the perspective on how to obtain valuable information from data stored by organizations of all kinds. By using these insights, companies can make better decisions and thus achieve their business goals. However, each new technology can create new security problems, and Big Data is no exception. One of the major security issues in a Big Data ecosystem is what level of trust in data and data sources stakeholders can have: without reliable data, the results of data analysis lose value. In this paper, we propose a security pattern to improve traceability and veracity of data through the use of Blockchain technologies. In this pattern, Blockchain will be used as a distributed ledger where all operations performed on the data will be registered. Therefore, the veracity of the data will increase, as will the confidence in the insights obtained from the analysis. The purpose of this paper is to help Chief Security Officer and Big Data architects incorporate this mechanism to improve the security of their environment.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cloud Computing and Resource Management
Original source
Jul 2, 2019·Proceedings of the 2019 ACM International Symposium on Blockchain and Secure Critical Infrastructure
18 cites
Blockchain-enabled Data Provenance in Cloud Datacenter Reengineering

Haochen Li, Keke Gai, Zhengkang Fang, Liehuang Zhu · 6 authors

Cloud datacenter reengineering has become an emerging technical term along with the rapid growth of cloud computing. There are a few reasons for implementing cloud reengineering. One of the key driven forces of adopting cloud reengineering is that securing data provenance is a major restriction for most contemporary applications. Many cloud-based applications require multiple cloud vendors' collaborations, such that data usage can be rarely controlled or governed during the data life cycle. This work focuses on the issue of data provenance in cloud computing and proposes an approach that uses blockchain techniques to achieve data tracing for a full data life cycle. The proposed method em- phasizes tracing data transfers between cloud datacenter. The data regeneration also is concerned by the proposed approach. Our experiment evaluation has assessed the efficiency performance of our approach.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Scientific Computing and Data Management
Original source
Jul 2, 2019·Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
37 cites
Practical Aggregate Signature from General Elliptic Curves, and Applications to Blockchain

Yunlei Zhao

Aggregate signature (AS) allows non-interactively condensing multiple individual signatures into a compact one. Besides faster verification, it is useful to reduce storage and bandwidth, and is especially attractive for blockchain and cryptocurrency. In this work, we first demonstrate the subtlety of achieving AS from general groups, by a concrete attack that actually works against the natural implementations of AS based on almost all the variants of DSA and Schnorr's. Then, we show that aggregate signature can be de- rived from the -signature scheme proposed by Yao, et al. To the best of our knowledge, this is the first aggregate signature scheme from general elliptic curves without bilinear maps (in particular, the secp256k1 curve used by Bitcoin). The security of aggregate -signature is proved based on a new assumption proposed and justified in this work, referred to as non-malleable discrete-logarithm (NMDL), which might be of independent interest. When applying the resultant aggregate -signature to Bitcoin, the storage volume of signatures reduces about 49.8%, and the signature verification time can even reduce about 72%. Finally, we specify in detail the application of the proposed AS scheme to Bitcoin, with the goal of maximizing performance and compatibility. We adopt a Merkle-Patricia tree based implementation, and the resulting system is also more friendly to segregated witness and provides better protection against transaction malleability attacks.

Cryptography and Data Security
Cryptography and Residue Arithmetic
Cloud Data Security Solutions
Original source
Jul 2, 2019·Proceedings of the Seventh International Workshop on Security in Cloud Computing
33 cites
Cloud Data Provenance using IPFS and Blockchain Technology

Syed Saud Hasan, Nazatul Haque Sultan, Ferdous Ahmed Barbhuiya

Cloud is widely used for data storage. A user who has uploaded his/her private or commercial data to the cloud is always keen to know whether the data that he/she has stored is secure or not. Access logs of stored data can be used to trace the integrity of the data. Access logs are also known as provenance data. Provenance data contains private information of users. As provenance data can be used to check the integrity so, it becomes very important to securely store the provenance data. The stored provenance data should be immutable and also unreachable to adversaries, as it contains private information of users. Cloud users will be assured of their stored data, and Cloud Storage Providers can use this implementation to improve their brand value and performance. This paper aims at providing an efficient way to store provenance data securely using Blockchain technology and InterPlanetary File System (IPFS) so that it is out of reach of adversaries. This paper also proposed a framework through which a user can verify the integrity of its own data. This model is implemented, tested and analyzed using IPFS which is a decentralized storage mechanism backed by blockchain to store cloud provenance data and uses publicly available Tierion api to store the hash value of the provenance entries.

Scientific Computing and Data Management
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Jul 2, 2019·Proceedings of the 2019 ACM International Symposium on Blockchain and Secure Critical Infrastructure
53 cites
A Novel Architecture for Tamper Proof Electronic Health Record Management System using Blockchain Wrapper

Mohammad Saidur Rahman, Ibrahim Khalil, Pathum Chamikara Mahawaga Arachchige, Abdelaziz Bouras · 5 authors

In this paper, we present a novel architecture of blockchain-based tamper-proof electronic health record (EHR) management system. Recording electronic health data in cloud-based storage systems always pose a threat to information security. Intruders can delete or tamper EHR of patients, giving benefits to insurance companies or hiding medical malpractices (e.g. misdiagnosis and delayed diagnosis). A tamper-proof EHR management system is required that would essentially solve such issues. The blockchain is an emerging technology that can be adapted to develop a tamper-proof data management system. However, establishing a new blockchain based system replacing the existing system is expensive. In our proposed architecture, we introduce a wrapper layer integration mechanism, named as the blockchain handshaker, between the existing cloud-based EHR management system and public blockchain network to develop a tamper-proof health record management system. We implement a prototype to provide evidence on the feasibility of the proposed concept.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Original source
Jul 1, 2019·2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS)
8 cites
Dependable Public Ledger for Policy Compliance, a Blockchain Based Approach

Zhou Wu, Andrew B. Williams, Debbie Perouli

The ever increasing amount of personal data accumulated by companies offering innovative services through the cloud, Internet of Things devices and, more recently, social robots has started to alert consumers and legislative authorities. In the advent of the first modern laws trying to protect user privacy, such as the European Union General Data Protection Regulation, it is still unclear what are the tools and techniques that the industry should employ to comply with regulations in a transparent and cost effective manner. We propose an architecture for a public blockchain based ledger that can provide strong evidence of policy compliance. To address scalability concerns, we define a new type of off-chain channel that is based on general state channels and offers verification for information external to the blockchain. We also create a model of the business relationships in a smart home setup that includes a social robot and suggest a sticky policy mechanism to monitor cross-boundary policy compliance.

Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cloud Data Security Solutions
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
25 cites
Yugala: Blockchain Based Encrypted Cloud Storage for IoT Data

Sarada Prasad Gochhayat, Eranga Bandara, Sachin Shetty, Peter Foytik

Cloud storage enables users to upload, store and download their data. However, with the rapid growth of the Internet of Things (IoT) and edge devices, such as camera, the cloud not only manages the user generate data but also devices generated data. This increment in the volume of outsourced data has raised two important issues in big data management for cloud storage servers, namely, optimal data storage and data security. In order to solve the former issue, cloud storage employs a deduplication technique to avoids storing duplicate data; and uses encryption to solve the later issue. However, both these issues are orthogonal in nature. Thanks to convergent encryption that addresses both the issues simultaneously. Nevertheless, the existing approaches relies on proxy servers and put all the trust on third party, which is vulnerable to single point failure. In this paper, we propose a novel lightweight decentralized encrypted cloud storage architecture called, Yugula, which maintains file confidentiality, removes the centralized data deduplication and increases file integrity by using blockchain. In particular, we discuss two approaches for file confidentiality with data deduplication: one uses double hashing and the other symmetric encryption. In order to show the efficiency and usability, we implemented the proposed architecture and showed its results in terms of high transaction throughput requirement for IoT data management in cloud storage.

Cloud Data Security Solutions
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
31 cites
Air Gapped Wallet Schemes and Private Key Leakage in Permissioned Blockchain Platforms

Amanda Davenport, Sachin Shetty

In this paper we consider the threat surface and security of air gapped wallet schemes for permissioned blockchains as preparation for a Markov based mathematical model, and quantify the risk associated with private key leakage. We identify existing threats to the wallet scheme and existing work done to both attack and secure the scheme. We provide an overview the proposed model and outline justification for our methods. We follow with next steps in our remaining work and the overarching goals and motivation for our methods.

2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Jul 1, 2019·2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS)
29 cites
Xyreum: A High-Performance and Scalable Blockchain for IIoT Security and Privacy

Abubakar Sadiq Sani, Dong Yuan, Wei Bao, Phee Lep Yeoh · 7 authors

As cyber attacks to Industrial Internet of Things (IIoT) remain a major challenge, blockchain has emerged as a promising technology for IIoT security due to its decentralization and immutability characteristics. Existing blockchain designs, however, introduce high computational complexity and latency challenges which are unsuitable for IIoT. This paper proposes Xyreum, a new high-performance and scalable blockchain for enhanced IIoT security and privacy. Xyreum uses a Time-based Zero-Knowledge Proof of Knowledge (T-ZKPK) with authenticated encryption to perform Mutual Multi-Factor Authentication (MMFA). T-ZKPK properties are also used to support Key Establishment (KE) for securing transactions. Our approach for reaching consensus, which is a blockchain group decision-making process, is based on lightweight cryptographic algorithms. We evaluate our scheme with respect to security, privacy, and performance, and the results show that, compared with existing relevant blockchain solutions, our scheme is secure, privacy-preserving, and achieves a significant decrease in computation complexity and latency performance with high scalability. Furthermore, we explain how to use our scheme to strengthen the security of the REMME protocol, a blockchain-based security protocol deployed in several application domains.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source