Yustus Eko Oktian, Elizabeth Nathania Witanto, Sandra Kumi, Sang-Gon Lee
The payment of a subscription-based model for the cloud service is regularly operated with the association of the bank as a centralized trustful third party. This system taxes the parties involved by requiring them to pay high transaction costs to the bank. In this paper, we propose a protocol to enable Fixed Subscription and Pay As You Go Subscription payments in the cloud service without the use of the third party. We achieve this goal by decentralizing the payment with blockchain. In return, this decentralized system generates low transaction costs. We implement our idea in the form of two smart contracts in Ethereum network. We also evaluate the security properties of our protocol. Based on the performance analysis, we can argue that all of the operations in the smart contract produces reasonable gas costs and the contracts are usable in the real network.
A blockchain is a technology that allows transactions to be processed and committed data to be shared among participants without a central server. To implement applications among restricted parties with permission such as asset sales and trades, a special type of blockchain system called a private blockchain is used. Additionally, the demand for privacy preservation where sensitive information such as the trade amounts and balances is not disclosed is increasing. However, privacy preservation in a typical blockchain setting is difficult because it prevents parties that are not involved in the transaction from checking the correctness of the transaction being processed, which may lead to unintended or invalid transactions. To address this issue, herein we propose a protocol that allows the consistency with regard to the transaction amount and the balance to be checked without disclosing their values. Specifically, we exploit a homomorphic encryption to encrypt the transaction amount and balance. Thus, the correctness of a transaction can be publicly verified by the parties using the zero-knowledge proof without a trusted third party.
The need for cloud computing is gradually increasing day by day. The cloud computing security is the major difficulty. Since the data in the cloud has to be transferred through internet, the security of data becomes a major concern. The key mechanisms for data protections like integrity, accountability, privacy, access control, authentication, authorization must be maintained. Blockchain is a technology which makes cloud computing better. Blockchain overcomes the security issues in cloud computing. This survey aims at analyzing and comparing various issues in the cloud environment and security issues using blockchain.
Ingo Weber, Qinghua Lu, An Binh Tran, Amit Deshmukh · 6 authors
Blockchain has attracted a broad range of interests from start-ups, enterprises and governments to build next generation applications in a decentralized manner. Similar to cloud platforms, a single blockchain-based system may need to serve multiple tenants simultaneously. However, design of multi-tenant blockchain-based systems is challenging to architects in terms of data and performance isolation, as well as scalability. First, tenants must not be able to read other tenants' data and tenants with potentially higher workload should not affect read/write performance of other tenants. Second, multi-tenant blockchain-based systems usually require both scalability for each individual tenant and scalability with number of tenants. Therefore, in this paper, we propose a scalable platform architecture for multi-tenant blockchain-based systems to ensure data integrity while maintaining data privacy and performance isolation. In the proposed architecture, each tenant has an individual permissioned blockchain to maintain their own data and smart contracts. All tenant chains are anchored into a main chain, in a way that minimizes cost and load overheads. The proposed architecture has been implemented in a proof-of-concept prototype with our industry partner, Laava ID Pty Ltd (Laava). We evaluate our proposal in a three-fold way: fulfilment of the identified requirements, qualitative comparison with design alternatives, and quantitative analysis. The evaluation results show that the proposed architecture can achieve data integrity, performance isolation, data privacy, configuration flexibility, availability, cost efficiency and scalability.
Same story for Ethereum as well as overall crypto opened with gaps today and some covered it already (Litecoin for example). After price opened with a $31 gap upwards, price consolidated in blue area and started making a steady drop towards the opening l
The Blockchain technology was initially adopted to implement various cryptocurrencies. Currently, Blockchain is foreseen as a general purpose technology with a huge potential in many areas. Blockchain-based applications have inherent characteristics like authenticity, immutability and consensus. Beyond that, records stored on Blockchain ledger can be accessed any time and from any location. Blockchain has a great potential for managing and maintaining educational records. This paper presents a Blockchain-based Educational Record Repository (BcER2) that manages and distributes educational assets for academic and industry professionals. The BcER2 system allows educational records like e-diplomas and e-certificates to be securely and seamless transferred, shared and distributed by parties.
Lucas M. Palma, Martín Vigil, Фернандо Лобо Перейра, Jean Everson Martina
Summary The validation of academic credits and issuance of academic degree certificates in the Brazilian education system currently occurs in a semi or completely noncomputerized way. The actual digitization of this system could make it more secure and decrease bureaucracy in terms of document validation, saving in storage and labor. Due to the recent increase in forgeries and loss of records, it is paramount that this process becomes more transparent and reliable for all involved parties. This article presents a proposal and an implementation for the digitization of degree certificates and academic credits for higher education in the Brazilian education system. A transparent model based on blockchain is proposed, in which higher education institutions register students and their academic credits in a chain of records using the Brazilian Public Key Infrastructure for identity management. This information, associated with smart contracts, enables the reliable and decentralized issuance of degree certificates through the validation of a historical database and the triggering of transactions using smart contracts. The focus of this article is the demonstration of an experiment that validates this proposal.
With the rapid development and application of the Internet, the amount of electronic data based on computer and computer network has exploded. Specific and effective electronic data play an increasingly important role in proving the facts of a case. The most important issue of electronic evidence is trust and security. However, electronic evidence is stored in the centralized database at present, and there are data security and trust problems. This paper proposes an electronic evidence preservation model based on blockchain to ensure the data safe and reliable.
The emergence of electronic medical records has provided great convenience for the storage and analysis of medical data. However, electronic medical records contain a large amount of personal privacy information, it is still very difficult to share medical information among various medical institutions. As the underlying technology of Bitcoin, blockchain technology has the characteristics of decentralization, security, trustworthiness, collective maintenance, and cannot be tampered, it is suitable for data protection and sharing. In this paper, data masking technology and Inter Planetary File System (IPFS) are introduced to build a safe and efficient electronic medical record sharing model based on blockchain. The model can not only guarantee the security of medical data, but also save resources in blockchain.
Mozhdeh Farhadi, Daniele Miorandi, Guillaume Pierre
IoT provides services by connecting smart devices to the Internet, and exploiting data generated by said devices to enable value-added services to individuals and businesses. In such cases, if data is exposed, tampered or lost, the service would not behave correctly. In this article, we discuss data security in IoT applications across five dimensions: confidentiality, integrity, authenticity, non-repudiation and availability. We discuss how distributed ledger technology could be used to overcome these issues and propose to use a fog computing architecture as decentralized computational support to deploy the ledger.
For many identification systems, including those in government, finance and healthcare, it is critical that at most one identity exists for each human individual within a given system. Many existing approaches identify individuals through an exchange of verifiable documents attesting to basic identification information. However, the same basic information is collected for identification in almost every system, meaning that persons are linkable across different identity systems and are not in control of how their identity is used. We propose Unique Self-Sovereign Identity, (USI), combining Cancelable Biometrics [6] and W3C Verifiable Claims [8] to achieve privacy preserving and non-linkable identification, with guarantees against double enrolment with any system. Because our protocol is based on biometrics, it permits individuals to enrol without official identification documents. Our protocol can be used in a wide range of situations, offering data security for large organisations, access to basic services for over one billion people who lack official identifying documents, and personal identity control for all individuals.
Tobias Korb, David Michel, Oliver Riedel, Armin Lechler
For several years, blockchain technology have been used and tested in various prototypes for production environments. The main focus of these approaches is the feasibility of different applications. It is usually simply assumed that data in a blockchain is stored immutably. However, the path from data generation to entry into a blockchain is usually neglected. Exactly this topic is discussed in this paper and a solution proposal for a secure data flow from the machine to the blockchain is presented. For this, the hardware and software architecture of the solution is shown, followed by measurements of the operational capability of the solution.
Permissionless Blockchains sind dezentrale Systeme, die Konsens erzielen. Das prominenteste Beispiel einer Permissionless Blockchain ist das elektronische Zahlungssystem Bitcoin, welches Konsens über die von Teilnehmern des Systems erzeugten Finanztransaktionen erzielt. Während verteilter Konsens seit Jahrzehnten Gegenstand zahlreicher Forschungsarbeiten ist, ist Bitcoin das erste bekannte System, welches Konsens im sog. permissionless-Modell erzielt, d.h. ohne die vorausgehende Feststellung der Identitäten der Teilnehmer des Systems. Die Teilnehmer von Permissionless Blockchains kommunizieren über ein unstrukturiertes Peer-to-Peer (P2P) Netzwerk miteinander. Da das Verfahren zur Konsensbildung von Permissionless Blockchains auf Daten basiert, die über dieses P2P-Netzwerk übertragen werden, können Sicherheitslücken in der Netzwerkschicht auch die Konsensbildung und damit die angestrebte Funktion des Systems beeinflussen. Während unstrukturierte P2P-Netzwerke in der Vergangenheit umfassend analysiert wurden, führt ihr Einsatz in Permissionless Blockchains zu Sicherheitsanforderungen und Angreifermodellen, die bisher noch nicht berücksichtigt wurden. Obwohl einzelne Angriffe auf die Netzwerkschicht von Permissionless Blockchains analysiert wurden, ist unklar, welche Sicherheitseigenschaften die Netzwerkschicht von Permissionless Blockchains haben sollte. Diese Unklarheit motiviert die erste in dieser Dissertation behandelte Forschungsfrage: Wie können Anforderungen und Zielkonflikte, die in den Mechanismen der Netzwerkschicht von Permissionless Blockchains vorhanden sind, untersucht werden? In dieser Dissertation wird eine Systematisierung von Angriffen auf die Netzwerkschicht von Bitcoin vorgestellt, in der Angriffe hinsichtlich der angegriffenen Mechanismen und der Auswirkungen der Angriffe auf höhere Schichten des Systems kategorisiert werden. Basierend auf der Systematisierung werden fünf Anforderungen für die Netzwerkschicht von Permissionless Blockchains abgeleitet: Leistung, niedrige Beteiligungskosten, Anonymität, Robustheit gegen Denial-of-Service Angriffe sowie Topologieverschleierung. Darüber hinaus werden der Entwurfsraum der Netzwerkschicht aufgezeigt und der Einfluss von Entwurfsentscheidungen auf die Erfüllung von Anforderungen qualitativ untersucht. Die durchgeführten Systematisierungen weisen auf inhärente Zielkonflikte sowie Forschungsmöglichkeiten hin und unterstützen die Entwicklung von Permissionless Blockchains. Weiterhin wird auf Grundlage von seit 2015 durchgeführten Messungen eine Charakterisierung des Bitcoin-P2P-Netzwerks präsentiert. Die Charakterisierung ermöglicht die Parametrisierung und Validierung von Simulationsmodellen und die Bewertung der Zuverlässigkeit von realen Experimenten. Darüber hinaus gewährt die Netzwerkcharakterisierung Einblicke in das Verhalten von Netzwerkknoten und deren Betreibern. Beispielsweise kann gezeigt werden, dass Sybil-Ereignisse in der Vergangenheit im Bitcoin-P2P-Netzwerk stattgefunden haben und dass die Leistung und die Anonymitätseigenschaften der Transaktions- und Blockausbreitung durch Implementierungs- und Protokolländerungen verbessert worden sind. Auf Grundlage dieser Charakterisierung werden zwei ereignisdiskrete Simulationsmodelle des Bitcoin-P2P-Netzwerks entworfen. Die Modelle werden durch einen Vergleich der simulierten Informationsausbreitungsverzögerung mit der beobachteten Informationsausbreitungsverzögerung im realen Netzwerk validiert. Da der Vergleich eine hohe Übereinstimmung zeigt, ermöglichen die vorgestellten Simulationsmodelle die Simulation des Bitcoin-Netzwerks mit einer Genauigkeit, die für die Analyse von Angriffen im Bitcoin-Netzwerk ausreicht. Die vorgestellten Simulationsmodelle sowie die durchgeführte Systematisierung von Angriffen verdeutlichen die Bedeutung der Kenntnis der Netzwerktopologie als Grundlage für Forschung und die Analyse von Deanonymisierungsangriffe. Daher adressiert die zweite Forschungsfrage dieser Dissertation Methoden der Topologieinferenz und der Deanonymisierung: Unter welchen Voraussetzungen und in welchem Maße sind netzwerkbasierte Topologieinferenz und Deanonymisierung in Bitcoin (un)möglich? Diese Frage wird durch Anwendung der vorgeschlagenen Methodenkombination aus Messungen, Simulationen und Experimenten beantwortet. In dieser Dissertation werden vier verschiedene Methoden zur Topologieinferenz vorgestellt und unter Verwendung von Experimenten und Simulationsstudien analysiert. Anhand von Experimenten wird gezeigt, dass ein Angreifer, der in der Lage ist, Verbindungen zu allen Knoten des Netzwerks zu etablieren, die direkten Nachbarn eines Netzwerkknotens mit hoher Sensitivität (recall) und Genauigkeit (precision) (87% recall, 71% precision) durch die Veröffentlichung von widersprüchlichen Transaktionen im Netzwerk herausfinden kann. Unter der Annahme eines passiven Angreifers, der in der Lage ist, sich mit allen erreichbaren Netzwerkknoten zu verbinden, war 2016 ein Rückschluss auf die Nachbarn eines Netzwerkknotens mit einer Sensitivität von 40% bei einer Genauigkeit von 40% durch Beobachtung von mindestens acht Transaktionen, die von diesem Netzwerkknoten stammen, möglich. Darüber hinaus ist es möglich, die Akkumulation mehrere Transaktionen zum Zwecke der Topologieinferenz zu geringen Kosten auszunutzen. Allerdings bleibt die erwartete Inferenzqualität aufgrund fehlender Validierungsmöglichkeiten unklar. Schließlich kann simulativ gezeigt werden, dass der Peer-Discovery-Mechanismus eines P2P-Netzwerks bei bestimmte Parametrisierungen Topologinferenz ermöglichen kann. Abschließend wird die Möglichkeit einer netzwerkbasierten Deanonymisierung bewertet, indem analysiert wird, ob eine Korrelation zwischen der IP-Adresse des Netzwerkknotens, der eine Transaktion veröffentlicht, und dem mutmaßlichen Ersteller der Transaktion besteht. Der zugrundeliegende Datensatz basiert auf den durchgeführten Messungen und besteht aus fast 10 Millionen Transaktionen mit zugehörigen IP-Adressen. Es wird gezeigt, dass Transaktionen von 5% bis 8.3% der Benutzer auffallend häufig von einzelnen Netzwerkknoten veröffentlicht wurden, was diese Benutzer dem Risiko netzwerkbasierter Deanonymisierungsangriffe aussetzt.
M. Francisca Hinarejos, Josep Lluís Ferrer Gomila, Llorenç Huguet-Rotger
The certified mail is a value-added service that is widely used in the paper world. However, the scientific community has not yet provided a solution for certified e-mail that has achieved widespread acceptance. This lack of a certified e-mail solution is not due to a lack of proposed approaches; because over the past 40 years, more than 100 protocols have been reported in journals and at conferences. The vast majority of these proposed protocols use a trusted third party (TTP) to achieve fairness. The few solutions without a TTP have not been successful due to their high computational and/or communication cost. Blockchain provides a new approach to develop the protocols without a TTP but without the prior drawbacks of the previous solutions without a TTP. Here, we present a new protocol for certified e-mail based on a blockchain without a conventional TTP that is integrated with the conventional e-mail infrastructure. The protocol is secure, efficient, and viable from a practical perspective.
In MOOCs, the learning resources authentication is a matter of great concern for the learners and teachers. Its construction is faced with the challenges of information security and privacy protection. Considering that the blockchain has the advantages of decentralisation, autonomous and non-tampering, this paper provides a solution to implement the construction based on blockchain technology, which includes the system architecture, experimental validation and key technologies such as decentralised transaction and tamper-resistance. The results prove the technical feasibility and safety reliability of blockchain to learning resource management in MOOCs.