Iryna Kondrat, Roman Drala
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
3,460 results · page 116 of 145
Iryna Kondrat, Roman Drala
No abstract is available for this record.
Navya Gouru, NagaLakshmi Vadlamani
The importance and usage of the distributed cloud is increasing rapidly over a traditionally centralized cloud for the storing and exchanging of digital assets between untrusted parties in many business sectors. Storing the digital assets in the distributed cloud is considered superior to traditional cloud computing in terms of environmentally friendly, cost, security and other technical dimensions. In this article, a contemporary architecture DistProv is proposed where an open source distributed cloud IPFS is used to store and transfer the digital assets between the consignor and consignee. These two are untrusted parties exchanging sensitive documents secured by cryptographic algorithms with permission-based access verified by ethereum smart contracts using zero-knowledge proof (ZKP) and simultaneously publishing the provenance data about the digital asset as a transaction on the blockchain. This article also discusses on verifying the integrity of the digital assets and authentication of the consignor and thus preserving a strong CIA triad.
Claudio A. Ardagna, Rasool Asal, Ernesto Damiani, Nabil El Ioini · 5 authors
Today, Internet of Things (IoT) implements an ecosystem where a panoply of interconnected devices collect data from physical environments and supply them to processing services, on top of which cloud-based applications are built and provided to mobile end users. The undebatable advantages of smart IoT systems clash with the need of a secure and trustworthy environment. In this paper, we propose a service-based methodology based on blockchain and smart contracts for trustworthy evidence collection at the basis of a trustworthy IoT assurance evaluation. The methodology balances the provided level of trustworthiness and its performance, and is experimentally evaluated using Hyperledger fabric blockchain.
Daniel E. O’Leary
Summary This paper reviews some recent blockchain‐based applications for information capture, distribution and preservation. As part of that review, this paper examines two key concerns with current blockchain designs for accounting and supply chain transactions: data independence and multiple semantic models for the same information distribution problem. Blockchain applications typically integrate database, application and presentation tiers all in the same ledger. This results in a general inability to query information in the ledger and other concerns. Further, since most applications appear to be private blockchain applications, there is a concern of agents needing to accommodate multiple blockchains depending on who their trading partners are and what they request. Finally, this paper uses a distributed database to design a ‘blockchain‐like’ system for virtual organizations.
Chelsea M. Anderson, Vivian W. Fang, James Moon, Jonathan E. Shipman
ABSTRACT This paper explores U.S. public firms’ cryptocurrency holdings and accounting practices from 2013 to 2022 against the backdrop of the recently enacted crypto accounting rule, ASU 2023‐08. Descriptive analyses suggest exponential growth in corporate crypto holdings and significant variation in crypto accounting practices, underscoring the rule's necessity. Hypothesis tests using the pre‐rule data reveal three insights with direct relevance to the rule. First, firms appear to view crypto assets more akin to investments than intangible assets, consistent with the rule's mandate of the fair value model. Second, Big 4 auditors steer firms toward the impairment model and less detailed presentation choices. This conservative approach is unlikely to meet the new rule's goal of providing the most decision‐useful information. Third, increased liquidity of crypto markets prompts the use of the fair value model and a more detailed presentation, consistent with the rule's focus on more actively traded tokens. However, within our sample, we find some evidence consistent with fair value reporting increasing stock return volatility and no evidence that it enhances earnings informativeness.
Xiaohai Dai, Jiang Xiao, Wenhui Yang, Chaofan Wang · 5 authors
The pioneer blockchain platform Bitcoin has drawn massive attention from various sectors in society, with its promising decentralized, irreversible, and trust-free natures. Increasing volume of Bitcoin transactions makes it impractical for each user to store a full copy of whole ledger, especially for a normal user who makes few transactions and owns constrained storage space. There are already some works conducted to reduce the storage overhead by redesigning the system protocol, based on different trust assumptions. An example is running light nodes, which trust the full nodes to store its relevant data and reply to its data request timely. However, it introduces the risks of permanent data loss, as the data relevant to a light node may be tailored by all the full nodes later. Another attempt is conducted by organizing the nodes into several cooperative units based on a trust assumption, which is hard to satisfy in practice. In this paper, we propose a novel Jigsaw-like Data Reduction (Jidar) approach. Each node in Jidar only stores transactions of interest and relevant Merkle branches from the complete blocks, just like selecting several pieces from the jigsaw puzzles. A node can maintain and verify all its relevant data locally and safely without any trust assumptions. To verify the validity of a newly proposed transaction, Merkle branches relevant to the inputs are provided along with the transaction by the proposer. In view of the requirement that a user wants to cohere all the fragments stored in different nodes into a complete block, just like stitching all the pieces into a complete jigsaw-puzzle picture, a mechanism to query full data is added to Jidar. Experimental results demonstrate that Jidar can reduce a normal node's storage cost to about 1.03% of the original Bitcoin system at a low communication cost
Matthias Lohr, Jonathan Hund, Jan Jürjens, Steffen Staab
In railway incidents, data from sensors installed on railway tracks can help finding the cause of the incident and identifying the responsible parties. Since the data collected may contain business-relevant information, it is usually treated as confidential by the companies collecting it. However, this data can only be considered as evidence if it can be proven that the data is genuine and unaltered, even if it is only accessible for involved companies in the first place. In this paper, we present an approach to ensure the genuineness of confidential railway measurement data using distributed ledgers and describe an approach for selectively sharing parts of the data without compromising confidentiality or the verifiability of genuineness. We discuss the specific characteristics of rail wayside measurement data, existing approaches to ensure data genuineness and the necessary modifications to apply them to rail wayside measurement data. We also discuss how our approach can be generalized beyond the railway domain to show how distributed ledger-based approaches can be used to ensure the genuineness of confidential and selectively shared data.
Jun Dai, Na He, Haizong Yu
ABSTRACT Industry 4.0 uses many technologies, such as smart sensors and IoT, to fundamentally improve manufacturing processes. These advanced tools can also be utilized by auditors for the purpose of achieving real-time auditing and monitoring, pushing the profession toward a new generation: “Audit 4.0.” Blockchains and smart contracts should be utilized to overcome new challenges in the transformation toward Audit 4.0. This paper explores the potential of blockchain and smart contracts to reengineer current audit procedures, thereby enabling Audit 4.0. First, this paper demonstrates a framework that summarizes where blockchain and smart contracts should be applied to help implement Audit 4.0. Then, it designs and implements a system to facilitate accountability audit for Chinese government officials regarding air pollution control. In this case, real air quality data are collected via crowdsourcing, verified and analyzed by blockchain and smart contracts to achieve a continuous audit of government officials' performance on air protection.
Zhentian Liu, Jing Liu
A smart contract is a computer protocol intended to digitally facilitate and enforce the negotiation of a contract in undependable environment. However, the number of attacks using the vulnerabilities of the smart contracts is also growing in recent years. Many solutions have been proposed in order to deal with them, such as documenting vulnerabilities or setting the security strategies. Among them, the most influential progress is made by the formal verification method. In this paper, we propose a formal verification method based on Colored Petri Nets (CPN) to verify smart contracts in blockchain system. First, we develop the smart contract models with possible attacker models based on hierarchical CPN modeling, then the smart contract models are executed by step-by-step simulation to validate their functional correctness, and finally we utilize the branch timing logic ASK-CTL based model checking technology in the CPN tools to detect latent vulnerabilities in smart contracts. We demonstrate that our CPN modeling based verification method can not only detect the logical vulnerabilities of the smart contract, but also consider the impacts of users behavior to find out potential non-logical vulnerabilities in the contracts, such as the vulnerabilities caused by the limitations of the Solidity language.
Felix Härer, Hans-Georg Fill
Decentralized attestation methods for blockchains are currently being discussed and standardized for use cases such as certification, identity and existence proofs. In a blockchain-based attestation, a claim made about the existence of information can be cryptographically verified publicly and transparently. In this paper we explore the attestation of models through globally unique identifiers as a first step towards decentralized applications based on models. As a proof-of-concept we describe a prototypical implementation of a software connector for the ADOxx metamodeling platform. The connector allows for (a.) the creation of claims bound to the identity of an Ethereum account and (b.) their verification on the blockchain by anyone at a later point in time. For evaluating the practical applicability, we demonstrate the application on the Ethereum network and measure and evaluate limiting factors related to transaction cost and confirmation times.
Shlomi Linoy, Hassan Mahdikhani, Suprio Ray, Rongxing Lu · 6 authors
Blockchain technologies have recently received considerable attention, partly due to the success of cryptocurrency applications such as Bitcoin and Ethereum. As the adoption of blockchain technologies by various sectors increases, there is a demand for tools that enable regulatory enforcement, which include monitoring, examining and ensuring compliance of the data stored by the blockchain systems, all in a privacy preserving way. Current blockchain solutions store transactions in append-only and immutable fashion without any indexing, which contributes to limited and inefficient queries. Additionally, there is no support for privacy-preserving query processing. To address these issues, in this paper, we propose a system that can provide auditors, enforcing regulatory compliance, with efficient, scalable and richer blockchain query processing over Hadoop and synchronized Ethereum clients. The system additionally ensures auditors' privacy by utilizing cryptography techniques over semi-trusted servers to protect the auditors' identities, queries and their results.
Mary Maller
Zero-knowledge proofs have become an important tool for addressing privacy and scalability concerns in cryptographic protocols. For zero-knowledge proofs used in blockchain applications, it is desirable to have small proof sizes and fast verification. Yet by design, existing constructions with these properties such as zk-SNARKs also have a secret trapdoor embedded in a relation dependent structured reference string (SRS). Knowledge of this trapdoor suffices to break the security of these proofs. The SRSs required by zero-knowledge proofs are usually constructed with multiparty computation protocols, but the resulting parameters are specific to each individual circuit. In this thesis, we propose a model for constructing zero-knowledge arguments (i.e. zero-knowledge proofs with computational soundness) in which the generation of the SRS is directly considered in the security analysis. In our model the same SRS can be used across multiple applications. Further, the model is updatable i.e. users can update the universal SRS and the SRS is considered secure provided at least one of these users is honest. We propose two zero-knowledge arguments with updatable and universal SRSs, as well as a third which is neither updatable nor universal, but which through similar techniques achieves simulation extractability. The proposed arguments are practical, with proof sizes never more than a constant number of group elements. Verification for two of our constructions consist of a small number of pairing operations. For our other construction, which has the desirable property of a linear sized updatable and universal SRS, we describe efficient batching techniques so that verification is fast in the amortised setting.
Ivan Tarkhanov, Denis Fomin-Nilov, M. V. Fomin
Purpose The purpose of this paper is to address the problem of content immutability and integrity of online scientific periodicals on the sites of small publishers that can be violated not only by the external hack of the publisher’s site but also by publisher’s and author’s misconduct or by submitting different versions of a periodical to different sites. Design/methodology/approach The authors defined a list of requirements that verify online scientific publications immutability and integrity. Then, the authors analyzed existing projects and recently emerged information on security technologies and identified challenges met during the development and testing. The use of the public blockchain network Ethereum as a secure storage location for data was explained. Findings The authors developed the method of checking online scientific periodicals for immutability and presented ecosystem architecture to control immutability and integrity of data. On the example of the online periodical “Istoriya”, it was demonstrated how the immutability of online scientific publication has been verified with the use of the public blockchain over a six-month period. First, operating results were evaluated; challenges hampering the implementation of the suggested ecosystem on Ethereum now were identified; and potential advantages of the suggested approach as compared to similar projects were discovered. Research limitations/implications The considered prototype is not a ready-to-use system, but in future providing higher transparency and the development of general distributed ecosystem small publishers will have new opportunities for development given that the issues of scalability, reliability and operating speed on a public blockchain will be addressed. Introduction of the described ecosystem may even provoke some changes on such conservative market as that of publishing of academic papers. Originality/value This research is one of the first attempts to expand digital object identifier technology with the use of additional verifications based on the data storage and search in the public blockchain. The suggested idea is the example of “blockchainified science” that was brought to implementation in a real online journal. This method has some advantages compared to Crossmark service.
Bruno Tavares, Filipe Figueiredo Correia, André Restivo
No abstract is available for this record.
Thein Than Thwin, Sangsuree Vasupongayya
Personal health record system (PHR system) stores health-related information of an individual. PHR system allows the data owner to manage and share his/her data with selected individuals. The originality or tamper resistance feature is crucial for PHR system because of the irreversible consequence of incorrect information. Blockchain technology becomes a potential solution due to its immutability and irreversibility properties. Unfortunately, some technical impediments such as limited storage, privacy concern, consent irrevocability, inefficient performance, and energy consumption exist. This work aims to handle these blockchain drawbacks and propose a blockchain-based PHR model. The proposed model is built using the blockchain technology to support a tamper resistance feature. Proxy reencryption and other cryptographic techniques are employed to preserve privacy. Features of the proposed model include fine-grained and flexible access control, revocability of consent, auditability, and tamper resistance. A detailed security analysis shows that the proposed model is provably secure for privacy and tamper resistance. The performance analysis shows that the proposed model achieves a better overall performance compared with the existing approach in the literature. Thus the proposed model is more suitable for the PHR system usage.
Han Wang, Xu An Wang, Shuai Xiao, Zichen Zhou
No abstract is available for this record.
Cheng Xu, Ce Zhang, Jianliang Xu
Blockchains have recently been under the spotlight due to the boom of cryptocurrencies and decentralized applications. There is an increasing demand for querying the data stored in a blockchain database. To ensure query integrity, the user can maintain the entire blockchain database and query the data locally. However, this approach is not economic, if not infeasible, because of the blockchain's huge data size and considerable maintenance costs. In this paper, we take the first step toward investigating the problem of verifiable query processing over blockchain databases. We propose a novel framework, called vChain, that alleviates the storage and computing costs of the user and employs verifiable queries to guarantee the results' integrity. To support verifiable Boolean range queries, we propose an accumulator-based authenticated data structure that enables dynamic aggregation over arbitrary query attributes. Two new indexes are further developed to aggregate intra-block and inter-block data records for efficient query verification. We also propose an inverted prefix tree structure to accelerate the processing of a large number of subscription queries simultaneously. Security analysis and empirical study validate the robustness and practicality of the proposed techniques.
Muhammad El-Hindi, Martin Heyden, Carsten Binnig, Ravi Ramamurthy · 6 authors
In this demo we present BlockchainDB, which leverages blockchains as storage layer and introduces a database layer on top that extends blockchains by classical data management techniques (e.g., sharding). Further, BlockchainDB provides a standardized key/value-based query interface to facilitate the adoption of blockchains for data sharing use cases. With BlockchainDB we can thus not only improve the performance and scalability of blockchains for data sharing but also decrease the complexity for organizations intending to use blockchains for this use case.
Yuan Zhang, Chunxiang Xu, Jianbing Ni, Hongwei Li · 5 authors
Cloud storage enables users to outsource data to storage servers and retrieve target data efficiently. Some of the outsourced data are very sensitive and should be prevented for any leakage. Generally, if users conventionally encrypt the data, searching is impeded. Public-key encryption with keyword search (PEKS) resolves this tension. Whereas, it is vulnerable to keyword guessing attacks (KGA), since keywords are low-entropy. In this paper, we present a secure PEKS scheme called SEPSE against KGA, where users encrypt keywords with the aid of dedicated key servers via a threshold and oblivious way. SEPSE supports key renewal to periodically replace an existing key with a new one on each key server to thwart the key compromise. Furthermore, SEPSE can efficiently resist online KGA, where each keyword request made by a user is integrated into a transaction on a public blockchain (e.g., Ethereum), which allows key servers to learn the number of keyword requests made by the user without requiring a synchronization between them for per-user rate limiting. Security analysis and performance evaluation demonstrate that SEPSE provides a stronger security guarantee compared with existing schemes, at the expense of acceptable computational costs.
Fangyu Gai, Cesar Grajales, Jianyu Niu, Jalalzai, Mohammad Mussadiq · 5 authors
Sidechain technology has been envisioned as a promising solution to accelerate today's public blockchains in terms of scalability and interoperability. By relying on the mainchain for security, different sidechains can formulate their own rules to reach consensus. Although the literature has considered the possibility of using consensus protocols in the sidechain, so far a tailor-made consensus protocol for sidechains with high performance and formal security proof has not been attempted. To fill this gap, we introduce Cumulus, a low overhead, highly efficient, security provable sidechain protocol. Cumulus makes use of smart contracts to ensure that only one block proposed in the sidechain will be enforced on the mainchain in each round, thereby achieving consensus in an efficient manner. We give a formal specification of Cumulus which ensures safety and liveness without any online requirements of clients. For security analysis, we provide formal security definitions and proofs under Universally Composable Security (UCS) model. As a proof of concept, we implement Cumulus and evaluate it in an Ethereum testnet.
Peter Robinson
A Coordination Blockchain is a blockchain with the task of coordinating\nactivities of multiple private blockchains. This paper discusses the pros and\ncons of using Ethereum MainNet, the public Ethereum blockchain, as a\nCoordination Blockchain. The requirements Ethereum MainNet needs to fulfil to\nperform this role are discussed within the context of Ethereum Private\nSidechains, a private blockchain technology which allows many blockchains to be\noperated in parallel, and allows atomic crosschain transactions to execute\nacross blockchains. Ethereum MainNet is a permissionless network which aims to\noffer strong authenticity, integrity, and non-repudiation properties, that\nincentivises good behaviour using crypto economics. This paper demonstrates\nthat Ethereum MainNet does deliver these properties. It then provides a\ncomprehensive review of the features of Ethereum Private Sidechains, with a\nfocus on the potential usage of Coordination Blockchains for these features.\nFinally, the merits of using Ethereum MainNet as a Coordination Blockchain are\nassessed. For Ethereum Private Sidechains, we found that Ethereum MainNet is\nbest suited to storing long term static data that needs to be widely available,\nsuch as the Ethereum Registration Authority information. However, due to\nEthereum MainNet's probabilistic finality, it is not well suited to information\nthat needs to be available and acted upon immediately, such as the Sidechain\nPublic Keys and Atomic Crosschain Transaction state information that need to be\naccessible prior to the first atomic crosschain transaction being issued on a\nsidechain. Although this paper examined the use of Ethereum MainNet as a\nCoordination Blockchain within reference to Ethereum Private Sidechains, the\ndiscussions and observations of the typical tasks a Coordination blockchain may\nbe expected to perform are applicable more widely to any multi-blockchain\nsystem.\n
Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles Kamhoua · 5 authors
Ubiquitous adoption of cloud computing and virtualization technology has necessitated the need for strong security mechanisms. Multiple entities are involved in creating, exchanging, and altering data objects in the cloud environment, making it challenging to track malicious activities and security violations. To address these issues, there is a need for a data provenance framework, with which each data object in the federated cloud environment can be tracked and recorded. Although log-based provenance provides the ability to track operations conducted on digital assets, the provenance data are not transparent and immutable. Blockchain technology offers a promising mechanism for building a tamper-proof information system backed by strong cryptographic primitives. In this article, we propose BlockCloud, a blockchain-empowered data provenance architecture for the cloud computing platform. In addition, we present a proof-of-stake (PoS) consensus mechanism for BlockCloud to alleviate the overhead of computational requirements that the traditional proof-of-work (PoW) consensus needs. Finally, we discuss several research challenges and vulnerabilities that need to be addressed to realize BlockCloud.
Orlenys López‐Pintado, Marlon Dumas, Luciano García‐Bañuelos, Ingo Weber
Blockchain technology provides a tamper-proof mechanism to execute inter-organizational business processes involving mutually untrusted parties. Existing approaches to blockchain-based process execution are based on code generation. In these approaches, a process model is compiled into one or more smart contracts, which are then deployed on a blockchain platform. Given the immutability of the deployed smart contracts, these compiled approaches ensure that all process instances conform to the process model. However, this advantage comes at the price of inflexibility. Any changes to the process model require the redeployment of the smart contracts (a costly operation). In addition, changes cannot be applied to running process instances. To address this lack of flexibility, this paper presents an interpreter of BPMN process models based on dynamic data structures. The proposed interpreter is embedded in a business process execution system with a modular multi-layered architecture, supporting the creation, execution, monitoring and dynamic update of process instances. For efficiency purposes, the interpreter relies on compact bitmap-based encodings of process models. An experimental evaluation shows that the proposed interpreted approach achieves comparable or lower costs relative to existing compiled approaches.
Yun Chen, Hui Xie, Kun Lv, Shengjun Wei · 5 authors
No abstract is available for this record.