The focus of this position paper is to study and identify trust requirements in blockchain systems. So far, we have found that the overall trust-related requirements engineering knowledge is far from what is needed for successful engineering of various trust-related challenges in blockchain systems. We have identified an urgent need and challenge to revisit requirements engineering models to effectively include trust requirements; and to produce a trust engineering taxonomy, models, and techniques for achieving and fulfilling blockchain system trust requirements and goals.
Nachiket Tapas, Giovanni Merlino, Francesco Longo, Antonio Puliafito
Cloud storage adoption, due to the growing popularity of IoT solutions, is steadily on the rise, and ever more critical to services and businesses. In light of this trend, customers of cloud-based services are increasingly reliant, and their interests correspondingly at stake, on the good faith and appropriate conduct of providers at all times, which can be misplaced considering that data is the "new gold", and malicious interests on the provider side may conjure to misappropriate, alter, hide data, or deny access. A key to this problem lies in identifying and designing protocols to produce a trail of all interactions between customers and providers, at the very least, and make it widely available, auditable and its contents therefore provable. This work introduces preliminary results of this research activity, in particular including scenarios, threat models, architecture, interaction protocols and security guarantees of the proposed blockchain-based solution.
Alina Buzachis, Antonio Celesti, Maria Fazio, Massimo Villari
The digitization of health records has massively increased Health Information Exchange (HIE) activities among different practitioners, but it has lagged behind Electronic Health/Medical Records (EHRs/EMRs) adoption for numerous reasons, including confidentiality, interoperability, integrity, and privacy-related concerns. In this paper, we present a Blockchainas-a-Service based solution for HIE (BaaS-HIE). In particular, our design work involves the use of a private Blockchain and smart contracts as access control manager to medical records. In order to maintain high level of performance for applications, thus that such applications could be economically viable, all of the health data are encrypted and stored into a decentralised InterPlanetary File System (IPFS) and the hash of the assets URI is stored in blockchain. Our experimental results demonstrate the feasibility of the proposed approach in offering a decentralized and fine-grained accessibility mechanism for the patient and the doctor in a given healthcare system.
Abhilash Kancharla, Jongho Seol, Nicole Park, Indy Park · 5 authors
This paper presents a work on how to assure the dependability of a crypto system built across on and off the blockchain by using the proposed adaptive checkpoint and rollback algorithm, and a prototype is developed for demonstration purpose.The theoretical background of the proposed checkpoint and rollback algorithm is studied to characterize the variables affecting the dependability such as security, authenticity and reliability with respect to the rates of hit by any events of those issues, the rates to detect and diagnose, and then the rate to vote for a consensus whether to trigger a rollback or not. Based on the variables characterization in a stochastic manner, then steady state probabilities and state transition probabilities are derived in order to assure the ultimate effective dependability of each individual dependability variable (i.e., security, authenticity and reliability), then finally to assure the dependability in a compound manner with each variable assigned a weight depending on the nature of the systems specifications.Based on the theoretical study, a protype of a crypto system is built to demonstrated the underlying architecture and operations and to justify the need for such system to take synergistic advantages from both on- and off-chain blockchains, with an experimental result of a benefit in gas fee which is the most exigently addressed issue today in blockchain systems especially in Ethereum network of blockchains. An astonishing gas fee saving results are demonstrated. It is observed that the crypto system benefits more if more computationally intensive transactions are executed off-chain while vice versa.
Hang Xu, Jing Cao, Jian Zhang, Liangyi Gong · 5 authors
The following topics are dealt with: learning (artificial intelligence); data mining; social networking (online); pattern classification; text analysis; security of data; feature extraction; Internet; graph theory; computer network security.
Blockchain is a database technology that provides the integrity and trust of the system can't make arbitrary modifications and deletions by being an append-only distributed ledger. That is, the blockchain is not a modification or deletion but a CRAB (Create-Retrieve-Append-Burn) method in which data can be read and written according to a legitimate user's access right(For example, owner private key). However, this can not delete the created data once, which causes problems such as privacy breach. In this paper, we propose an on-off block-chained Hybrid Blockchain system to separate the data and save the connection history to the blockchain. In addition, the state is changed to the distributed database separately from the ledger record, and the state is changed by generating the arbitrary injection in the XOR form, so that the history of modification / deletion of the Off Blockchain can be efficiently retrieved.
Yan Zhu, Chunli Lv, Zichuan Zeng, Jingfu Wang · 5 authors
Abstract Different from the current cloud storage solutions, which are mostly centralized storage providers, this paper proposes a decentralized storage system based on blockchain technology, which can make full use of the remaining space of personal hard disks of users around the world. Storage provider performs a data integrity certificate to the user, and after verifying that the verification is passed, the user pays the storage fee to the storage provider through the lightning network technology. All proofs and payment information are stored in the blockchain, which guarantees the security and credibility of the system. Compared with the current mainstream distributed storage systems, this scheme has been improved in terms of system access and payment methods.
With the development of cloud computing technology, data can be outsourced to the cloud and conveniently shared among users. However, in many circumstances, users may have concerns about the reliability and integrity of their data. It is crucial to provide data sharing services that satisfy these security requirements. We introduce a reliable and secure data sharing scheme, using the threshold secret sharing technique and the Chaum-Pedersen zero-knowledge proof. The proposed scheme is not only effective and flexible, but also able to achieve the semantic security property. Moreover, our scheme is capable of ensuring accountability of users’ decryption keys as well as cheater identification if some users behave dishonestly. The efficiency analysis shows that the proposed scheme has a better performance in terms of computational cost, compared with the related work. It is particularly suitable for application to protect users’ medical insurance data over the cloud.
We introduce an improvement fair exchange method called Themis, which does not require Trusted Third Parties. Themis system is implemented based on blockchain, and can provide escrow services for secure exchanging between cryptocurrencies and physical goods. We propose many application scenarios for Themis, such as peer-to-peer escrow payments, exchanges among digital currencies. We implement a test-net for Themis and the experimental results shows that Themis protocol is practical in real-world distributed environment.
A. Badr, Laura Rafferty, Qusay H. Mahmoud, Khalid Elgazzar · 5 authors
While academic institutions maintain records such as transcripts and certificates, they are often requested to share these records with other institutions at the request of students for credit transfer, or prerequisites for acceptance into new academic programs. While the transfer of academic records is a regular daily activity for the institutions, there is often significant overhead involved as the process of transfer and verification is extremely manual. The need for an automated end-to-end solution for the transfer and verification of academic records between institutions is on the edge to reduce wait times for students to transfer their records, as well as to provide a reliable verification method to avoid academic fraud. This paper presents a permissioned blockchain-based system to allow institutions to securely and dependably transfer and verify academic records at the student request. Permissioned blockchains, such as Hyperledger, provide a more scalable and cost-effective and private solution for enterprise applications. Our solution is comprised of a web interface for enrolling and requesting the transfer, with a backend using Hyperledger Fabric and Hyperledger Composer to retain the hash of the records on the blockchain for verification.
Custom tokens are an integral component of decentralized applications (dapps) deployed on Ethereum and other blockchain platforms. For Ethereum, the ERC20 standard is a widely used token interface and is interoperable with many existing dapps, user interface platforms, and popular web applications (e.g., exchange services). An ERC20 security issue, known as the "multiple withdrawal attack", was raised on GitHub and has been open since November 2016. The issue concerns ERC20's defined method approve() which was envisioned as a way for token holders to give permission for other users and dapps to withdraw a capped number of tokens. The security issue arises when a token holder wants to adjust the amount of approved tokens from N to M (this could be an increase or decrease). If malicious, a user or dapp who is approved for N tokens can front-run the adjustment transaction to first withdraw N tokens, then allow the approval to be confirmed, and withdraw an additional M tokens. In this paper, we evaluate 10 proposed mitigations for this issues and find that no solution is fully satisfactory. We then propose 2 new solutions that mitigate the attack, one of which fully fulfills constraints of the standard, and the second one shows a general limitation in addressing this issue from ERC20's approve method.
Darya Korepanova, Maria Nosyk, Alex Ostrovsky, Yury Yanovich
Zero-knowledge proofs are an emerging cryptographic technology that have many potential applications for blockchains. Exonum is an extensible open-source framework for creating blockchain applications. In this article, we describe how zero-knowledge proofs, specifically bulletproofs, can be applied to build a privacy-focused service using Exonum. The token logic is implemented as a platform service and is a proof of concept.
Olivia Choudhury, Issa Sylla, Noor Fairoza, Amar K. Das
The cost and complexity of conducting multi-site clinical trials have significantly increased over time, with site monitoring, data management, and Institutional Review Board (IRB) amendments being key drivers. Trial sponsors, such as pharmaceutical companies, are also increasingly outsourcing trial management to multiple organizations. Enforcing compliance with standard operating procedures, such as preserving data privacy for human subject protection, is crucial for upholding the integrity of a study and its findings. Current efforts to ensure quality of data collected at multiple sites and by multiple organizations lack a secure, trusted, and efficient framework for fragmented data capture. To address this challenge, we propose a novel data management infrastructure based on a permissioned blockchain with private channels, smart contracts, and distributed ledgers. We use an example multi-organizational clinical trial to design and implement a blockchain network: generate activity-specific private channels to segregate data flow for confidentiality, write channel-specific smart contracts to enforce regulatory guidelines, monitor the immutable transaction log to detect protocol breach, and auto-generate audit trail. Through comprehensive experimental study, we demonstrate that our system handles high-throughput transactions, exhibits low-latency, and constitutes a trusted, scalable solution.
Donghui Ding, Kang Li, Linpeng Jia, Zhongcheng Li · 6 authors
The blockchain technology has been applied to wide areas. However, the open and transparent properties of the blockchains pose serious challenges to users' privacy. Among all the schemes for the privacy protection, the zero-knowledge proof algorithm conceals most of the private information in a transaction, while participants of the blockchain can validate this transaction without the private information. However, current schemes are only aimed at blockchains with the UTXO model, and only one type of assets circulates on these blockchains. Based on the zero-knowledge proof algorithm, this paper proposes a privacy protection scheme for blockchains that use the account and multi-asset model. We design the transaction structure, anonymous addresses and anonymous asset metadata, and also propose the methods of the asset transfer and double-spending detection. The zk-SNARKs algorithm is used to generate and to verify the zero-knowledge proof. And finally, we conduct the experiments to evaluate our scheme.
Delivering electronic health care (eHealth) services across multi-cloud providers to implement patient-centric care demands a trustworthy brokering architecture. Specifically, such an architecture should aggregate relevant medical information to allow informed decision-making. It should also ensure that this information is complete and authentic and that no one has tampered with it. Brokers deployed in eHealth services may fall short of meeting such criteria due to two key behaviors. The first involves violating international health-data protection laws by allowing user anonymity and limiting user access rights. Second, brokers claiming to provide trustworthy transactions between interested parties usually rely on user feedback, an approach vulnerable to manipulation by malicious users. This paper addresses these data security and trust challenges by proposing HealthyBroker, a novel, trust-building brokering architecture for multiple cloud environments. This architecture is designed specifically for patient-centric cloud eHealth services. It enables care-team members to complete eHealth transactions securely and access relevant patient data on a “need-to-know” basis in compliance with data-protection laws. HealthyBroker also protects against potential malicious behavior by assessing the trust relationship and tracking it using a neutral, tamper-proof, distributed blockchain ledger. Trust is assessed based on two strategies. First, all transactions and user feedback are tracked and audited in a distributed ledger for transparency. Second, only feedback coming from trustworthy parties is taken into consideration. HealthyBroker was tested in a simulated eHealth multi-cloud environment. The test produced better results than a benchmark algorithm in terms of data accuracy, service time, and the reliability of feedback received as measured by three malicious behavior models (naïve, feedback isolated, and feedback collective). These results demonstrate that HealthyBroker can provide care teams with a trustworthy, transparent ecosystem that can facilitate information sharing and well-informed decisions for patient-centric care.
Oliver Stengele, Andreas Baumeister, Pascal Birnstill, Hannes Hartenstein
The integrity of executable binaries is essential to the security of any device that runs them. At best, a manipulated binary can leave the system in question open to attack, and at worst, it can compromise the entire system by itself. In recent years, supply-chain attacks have demonstrated that binaries can even be compromised unbeknownst to their creators. This, in turn, leads to the dissemination of supposedly valid binaries that need to be revoked later.
Innovating business processes involves cutting-edge technologies where the Internet of Things (IoT) and Blockchain are technological breakthroughs. IoT is envisioned as a global network infrastructure consisting of numerous connected devices over the Internet. Many attempts have been made to improve and adapt business workflows for best utilizing IoT services. One possible solution is to digitize and automate internal processes using IoT services, in which Blockchain smart contract is a viable solution to establish the trust of process executions without intermediaries. Modern business processes are composed of disparate services; many of them tend to be delivered based on IoT. Interoperating with such services poses major challenges: 1) time for finality settlement of transactions is unpredictable and usually experiencing delay; 2) several implementations of permissioned Blockchain pose a major concern of trust regarding nodes that perform consensus; and 3) trust of process executions and IoT information is the major factor to the success of modern business processes, which require the composition of distributed IoT services. Traditional business processes are mostly managed by a single entity, which induces the problem of trust of process executions. In this paper, a smart contract for establishing the trust of process executions that fits into the IoT environment is presented. A consensus approach with selected validators extended from Practical Byzantine Fault Tolerance (PBFT) is introduced to address time and prejudice challenges.
Lasse Herskind, Alberto Giaretta, Michele De Donno, Nicola Dragoni
Summary Disbursement registration has always been a cumbersome, opaque, and inefficient process, up to the point that most businesses perform cash‐flow evaluations only on a quarterly basis. We believe that automatic cash‐flow evaluations can actively mitigate these issues. In this paper, we present BitFlow, a blockchain‐based architecture that provides complete cash‐flow transparency and diminishes the probability of undetected frauds through the BitKrone, a non‐volatile cryptocurrency that maps to the Danish Krone ( DKK ). We show that confidentiality can be effectively achieved on a permissionless blockchain using Zero‐Knowledge proofs, ensuring verifiable transfers and automatic evaluations. Furthermore, we discuss several experiments to evaluate our proposal, in particular, the impact that confidential transactions have on the whole system, in terms of responsiveness and from an economical expenditure perspective.
Abstract Blockchain technology provides basic building blocks to support the execution of collaborative business processes involving mutually untrusted parties in a decentralized environment. Several research proposals have demonstrated the feasibility of designing blockchain-based collaborative business processes using a high-level notation, such as the Business Process Model and Notation (BPMN), and thereon automatically generating the code artifacts required to execute these processes on a blockchain platform. In this paper, we present the conceptual foundations of model-driven approaches for blockchain-based collaborative process execution and we compare two concrete approaches, namely Caterpillar and Lorikeet.
최근 블록체인은 중앙 집중형 데이터 관리 방식에 대한 대안으로 급부상하고 있다. 비트코인, 이더리움과 같은 기존의 블록체인에서는 신규블록을 신뢰성 있게 추가하는 방법으로 PoW(Proof of Work) 알고리즘을 사용하였는데, PoW는 해시함수 계산을 수행하기 때문에 빠른 거래가 불가능하고, 해시함수 계산에 필요한 전력비용은 매우 높다. 따라서 본 논문에서는 기존의 PoW방식을 대체할 수 있는 대표자 기반의 블록체인을 제안하며, 제안하는 블록체인에서는 기존 대표자 기반 블록체인(Delegated Proof of Stake)의 보안성을 강화하는 방법으로 전방향 안전서명(Forward secure signatures)을 사용하였다. 본 논문에서는 대표자 기반의 블록체인에 사용할 수 있는 전방향 안전서명을 구현하고, 전방향 안전서명으로 구축한 블록체인의 성능 및 안전성을 분석하였다.
Yongjun Ren, Fujian Zhu, Jian Qi, Jin Wang · 5 authors
Edge computing provides a unified platform for computing, networking, and storage resources, enabling data to be processed in a timely and efficient manner near the source. Thus, it has become the basic platform for industrial Internet of things (IIoT). However, computing′s unique features have also introduced new security problems. To solve the problem, in this paper, blockchain-based identity management combining access control mechanism is designed under edge computing. The self-certified cryptography is utilized to realize the registration and authentication of network entities. We bind the generated implicit certificate to its identity and construct the identity and certificate management mechanism based on blockchain. Secondly, an access control mechanism based on Bloom filter is designed and integrated with identity management. Moreover, for secure communication in resource-constrained edge devices, a lightweight secret key agreement protocol based on self-authenticated public key is constructed. These mechanisms work together to provide data security guarantees for IIoT such as authentication, auditability, and confidentiality.
Various start-up developers and academic researchers have investigated the\nusage of blockchain as a data storage medium due to the advantages offered by\nits tamper-proof and decentralized nature. However, there have not been many\nattempts to provide a standard platform for virtually storing the states of\nunique tangible entities and their subsequent modifications. In this paper, we\npropose NFTracer, a non-fungible token tracking proof-of-concept based on\nHyperledger Composer and Hyperledger Fabric Blockchain. To achieve the\ncapabilities of our platform, we use NFTracer to build an artwork auction and a\nreal estate auction, which vary in technical complexity and demonstrate the\nadvantages of being able to track entities and their resulting modifications in\na decentralized manner. We also present its accompanying modular architecture\nand system components, and discuss possible future works on NFTracer.\n