Hui Tian, Fulin Nan, Chin‐Chen Chang, Yongfeng Huang · 6 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
3,460 results · page 126 of 145
Hui Tian, Fulin Nan, Chin‐Chen Chang, Yongfeng Huang · 6 authors
No abstract is available for this record.
Jinha Song, Jongho Nang, Ju-Wook Jang
This paper proposes and implements a method to verify the blockchain healthiness and to detect a malicious node using data collected from the IoT blockchain such as the transaction generation interval, the blockchains generation rate, and the statistics of IoT data stored in the blockchain. Furthermore, this paper proposes, designs, and implements a visualization tool to efficiently monitor the blockchain healthiness and IoT data in a consistent view via visualization of real-time blockchain update events, blockchain network statistics, and finally the IoT sensing data stored in blockchain as a transaction.
Rui Qiao, Sifeng Zhu, Qingxian Wang, Jie Qin
Internet of Things is widely used in many fields such as industry, medical care, education, and supply chain. With the participation of multi-authorized entities, a large number of dynamic data will be generated in the basic dimension of time. The operations on these data have to be safe and traceable for use in various forensics and decisions. Therefore, the key point of dynamic data security protection is to reject tampering of unauthorized users and to realize the process in evidence and tracing of the dynamic data operation. In order to find a solution to the problem above, an optimization of dynamic data traceability mechanism based on consortium blockchain is proposed in this article. First, a mathematical model for the security of dynamic data storage has been established, followed by analysis on honest behavior motive of individual node decision-making in group game and distributed node cooperation essence in specific industry background. After that, ownership transition function and the architecture of the dynamic data storage system are optimized; quality and growth characteristics of the system under stochastic state model are analyzed. Result shows that the solution can effectively avoid potential attacks such as tampering and faking under approved accession mode. The mechanism has good application value while ensuring the dynamic data storage security.
Rosco Kalis, Adam Belloum
Data manipulation is often named as a serious threat to data integrity. Data can be tampered with, and malicious actors could use this to their advantage. Data users in various application domains want to be ensured that the data they are consuming are accurate and have not been tampered with. To validate the integrity of these data, we describe a blockchain-based hash validation method. The method assumes that the actual data is stored separately from the blockchain, and then allows a data identifier and a hash of these data to be submitted to the blockchain. The actual data can be validated against the hash on the blockchain at any time. Several use cases are described for blockchain-based hash validation, and to validate the method it is implemented inside an application audit trail to validate the audit trail data. This implementation shows that blockchain-based hash validation is able to detect malicious and accidental changes that were made to the data.
Dongdong Yue, Ruixuan Li, Yan Zhang, Wenlong Tian · 5 authors
With the popularity of cloud storage, how to verify the integrity of data on the cloud has become a challenging problem. Traditional verification framework involves the Third Party Auditors (TPAs) which are not entirely credible. In this paper, we present a framework for blockchain-based data integrity verification in P2P cloud storage, making verification more open, transparent, and auditable. In this framework, we present Merkle trees for data integrity verification, and analyze the system performance under different Merkle trees structures. Furthermore, we develop rational sampling strategies to make sampling verification more effective. Moreover, we discuss the optimal sample size to tradeoff the conflict between verification overhead and verification precision, and suggest two efficient algorithms of order of verification. Finally, we conduct a series of experiments to evaluate the schemes of our framework. The experimental results show that our schemes can effectively improve the performance of data integrity verification.
Guang Yang, Chunlei Li
This paper presents a blockchain-based architecture for electronic health record (EHR) systems. The architecture is built on top of existing databases maintained by health providers, implements a blockchain solution to improve interoperability of the current EHR systems, prevent tampering and malicious misuse of EHRs by means of tracking all events that happened to the data in the databases. This proposed architecture also introduces a new incentive mechanism for the creation of new blocks in the blockchain. The architecture is independent of any specific blockchain platforms and open to further extensions, hence potentially fits in with other electronic record systems that require protection against tampering and misuse.
J. D. Preece, John M. Easton
This paper addresses the problem of uploading large quantities of sensitive industrial data to a public distributed network by proposing a new framework. The framework combines the existing technologies of the distributed web and distributed ledger to provide a mechanism of encrypting data and choosing whom to share the data with. The framework is designed to work with existing platforms; the InterPlanetary File System (IPFS) and the Ethereum blockchain platforms are used as examples within this paper, though it is stated that similar platforms are capable of providing the requirements for the framework to operate. The framework uses the concept of the Diffie-Hellman Key Exchange (DHKE), and is implemented in three different mechanisms of the DHKE: one-step Elliptical-Curve Diffie-Hellman Key Exchange (ECDH); two-step ECDH; and Supersingular Isogeny Diffie-Hellman Key Exchange (SIDH). The paper discusses the security of each along with individual advantages and disadvantages, and concludes that the SIDH is the most appropriate implementation for future use due to it being post-quantum secure.
Huan Zhou, Cees de Laat, Zhiming Zhao
Cloud Service Level Agreement (SLA) is challengeable due to lacking a trustworthy platform. This paper presents a witness model to credibly enforce the cloud service level agreement. Through introducing the witness role and using the blockchain based smart contract, we solve the trust issues about who can detect the service violation, how the violation is confirmed and the compensation is guaranteed. In this model, a verifiable consensus sortition algorithm proposed by us is firstly leveraged to select independent witnesses to form a witness committee. They are responsible for a specific service level agreement and get paid by monitoring and detecting service violation. Through carefully designing the witness' payoff function in the agreement, we further leverage game theory to analyze and prove that it is not the witness itself is trustworthy. Instead, the witness has to tell the truth because of its greedy nature, which is the desire to maximize its own revenue. As long as the service violation is confirmed by the witness committee, the compensation is automatically transferred to the customer by the smart contract. Finally, we implement a proof-of-concept prototype with the smart contract of Ethereum blockchain. It demonstrates the feasibility of our model.
Jayneel Vora, Anand Nayyar, Sudeep Tanwar, Sudhanshu Tyagi · 7 authors
In the present era of smart cities and homes, the private information of the patients such as their names, address, and disease is being breached on a regular basis, which indirectly related to the security of electronic health records (EHRs). The existing state-of-the-art schemes handling the security of EHRs have resulted in data being generally inaccessible to patients. These schemes struggle in providing the efficient balance between the data privacy, need for patients, and providers to regularly interact with data. Blockchain technology resolves the aforementioned issues because it shares the data in a decentralized and transactional fashion. This can be leveraged in the healthcare sector to maintain the balance between privacy and accessibility of EHRs. In this paper, we propose a Blockchain-based framework for efficient storage and maintenance of EHRs. This further provides the secure and efficient access to medical data by patients, providers, and third parties, while preserving the patient private information. The goals of this paper are to analyze how our proposed framework fulfills the needs of patients, providers, and third parties, and to understand how the framework maintains the privacy and security concerns in the healthcare 4.0.
Thomas Hepp, Alexander Schoenhals, Christopher Gondek, Béla Gipp
Abstract Currently, timestamps are certified by central timestamping authorities, which have disadvantages of centralization. The concept of the decentralized trusted timestamping (DTT) was developed by Gipp et al. to address these drawbacks. The paper provides insights into the architecture and implementation of a decentralized timestamp service taking the integration of multiple blockchain types into account. Furthermore, the components are introduced and the versatile application scenarios are presented. A future direction of research is the evaluation of blockchain technology and their suitability for timestamping.
Bin Lian, Gongliang Chen, Jialin Cui, Maode Ma
Compact E-cash achieves an efficient system by withdrawing 2n coins within O(1) operations and storing the coins in O(n) bits. For preventing a double-spender from cheating again, it is necessary to trace his e-coins. So full-tracing in compact E-cash system means tracing double-spender and tracing his coins. However, the efficiency problem caused by coin-tracing without TTP (trusted third party) has not been solved. For solving this problem, we introduce a non-standard construction into zero-knowledge proof of payment protocol, which leaks coin information when double-spending but is proven to be perfect zero-knowledge to verifier when spending a coin only once. Therefore, it achieves tracing dishonest users' coins and preserving the anonymity of honest users. Comparing with the existing most efficient method of coin-tracing without TTP, we improve computational complexity from O(k) to O(1) with less storage space. In addition, to improve efficiency and practicality further, batch-spending (spending any number of coins in one operation) and compact-spending (spending all coins in one operation) had been proposed. Based on the non-standard zero-knowledge proof, our scheme provides more efficient batch/compact-spending. Moreover, we also make a comparison with Bitcoin and Bitcoin Lightning Network, which have attracted considerable attention.
Ashar Ahmad, Muhammad Saad, Mostafa Bassiouni, Aziz Mohaisen
Audit logs serve as a critical component in the enterprise business systems that are used for auditing, storing, and tracking changes made to the data. However, audit logs are vulnerable to a series of attacks, which enable adversaries to tamper data and corresponding audit logs. In this paper, we present BlockAudit: a scalable and tamper-proof system that leverages the design properties of audit logs and security guarantees of blockchains to enable secure and trustworthy audit logs. Towards that, we construct the design schema of BlockAudit, and outline its operational procedures. We implement our design on Hyperledger and evaluate its performance in terms of latency, network size, and payload size. Our results show that conventional audit logs can seamlessly transition into BlockAudit to achieve higher security, integrity, and fault tolerance.
Subhra Mazumdar, Sushmita Ruj
Permissioned Blockchain has become quite popular with enterprises forming consortium since it prioritizes trust over privacy. One of the popular platforms for distributed ledger solution,Hyperledger Fabric, requires a transaction to beendorsedor approved by a group of special members known as endorsers before undergoing validation. To endorse a transaction, an endorser mentions its identity along with the signature so that it can be verified later. However, for certain transactions, difference in opinion may exist among endorsers. Disclosing the identity of an endorser may lead to conflict within the consortium. In such cases, an endorsement policy which not only allows an endorser to support a transaction discreetly, but at the same time takes into account the decision of the majority is preferred. Thus we propose an Anonymous Endorsement System which uses a threshold endorsement policy in order to address the issue. To realize at-out-of-nendorsement policy, using any of the existing threshold ring signature for our endorsement system would have violated the privacy of endorsers as either the identity or the secret key of the endorsers get revealed to the party who recombines the signature after collecting each signature share. All these factors motivated us to design a new ring signature scheme, calledFabric’s Constant-Sized Linkable Ring Signature(FCsLRS) withTransaction-Orientedlinkability for hiding identity of the endorsers. We have implemented the signature scheme in Golang and analyzed its security and performance by varying the Rivest-Shamir-Adleman (RSA) modulus size. Feasibility of implementation is supported by experimental analysis. Signature and tag generation time is quite fast and remains constant irrespective of change in message length or endorsement set size for a given RSA modulus value, assuming all the endorsers generates their signature in parallel. Each verifier is required to count and check individual valid ring signature. If the aggregate is above the threshold value, stated by the endorsement policy, then it confirms that the transaction is valid. This increases the verification time depending on the threshold value, but has very little effect on the scalability since generally$t<\!\!\!<n$. Lastly, we also discuss the integration of the scheme on v1.2 Hyperledger Fabric.
Zhi Li, Xinlai Liu, W.M. Wang, Ali Vatankhah Barenji · 5 authors
This paper proposes a trustable mold redesign knowledge-sharing platform, known as CKshare, based on private cloud and blockchain technology. Firstly, we use private cloud to store the mold redesign knowledge of each party to meet its own privacy and data format requirements. Secondly, a blockchain network is used for recording the knowledge and its transactions to ensure security and trustfulness. Thirdly, a simple retrieval mechanism is developed based on k-nearest neighbors for retrieving the codified knowledge on the platform. To realize CKshare, a prototype platform has been developed and explained based on real data from the case mold company.
Haiyang Yu, Zhen Yang
Cloud service providers offer massive storage space for individuals and enterprises. To guarantee the integrity of outsourced data, a range of data auditing schemes have been proposed. The auditing tasks in these schemes are typically performed by a Third Party Auditor (TPA)responsible for periodically checking the integrity of user data. However, such a centralized auditing framework is vulnerable and as a third party, the auditor cannot be fully trusted. In this paper, we propose a decentralized and smart public auditing scheme for cloud storage, which eliminates the involvement of the TPA and improves the reliability of auditing schemes. We build a protocol for automatic data integrity checking in a decentralized environment based on a smart contract, which eliminates the involvement of data owners and data users. Performance analysis and experiments show that our scheme is efficient and favorable.
Javed Shaikh, Georgi Iliev
In recent years, Electronic Commerce (E-commerce) applications are attracting many users and merchants to conduct their daily business online which includes payment of bills, online banking, buying tickets and purchasing goods etc. E-commerce transaction security is a major concern for E-commerce websites along with its customers. The basic requirements for any E-commerce transaction are privacy, authentication, integrity and non-repudiation. In this paper, a transaction processing system (TPS) for E-commerce by using a Blockchain technology, zero-knowledge proof and modified elliptic curve cryptography encryption is proposed. Also a denial of service attack detection model for the E-commerce system is proposed which take care of the DoS attack during E-commerce transactions.
Alka Vishwa, Farookh Khadeer Hussain
There has been a vast increase in incidents related to multimedia copyright and security breaches in the past few years, compromising users' privacy. One such breach involved the seventh season of the TV series “Game of Thrones”, where episodes were illegally downloaded before the official release date etc. Such security breaches raise questions about the approaches and models that currently apply to data privacy and security, where the user saves and distributes his data personally or depends on a third party or stakeholder to manage the distribution rights of sensitive data. When it comes to multimedia, many companies or multimedia owners rely on third parties, distributors and sales persons to monitor their publicity, maintain their popularity and sell their multimedia content. Blockchain technology, which was originally devised for the digital currency (cryptocurrency), has distinct features such as distributed networking, data privacy, trust less computing etc. This technology attracts great interest from the research community due to its innovative properties which can be applied to many business applications, one being access control over data. In this paper, we present a decentralized data management framework that ensures user data privacy and control. We propose a protocol that uses blockchain technology to take control of the user's data. This protocol enables the user to have full control over his multimedia files and he doesn't need to trust a third party. The framework allows the user to not only store data but also to query and share data as well as auditing. Finally, we discuss possible future extensions of blockchain technology as a medium to ensure privacy, data control, auditing and trust management in different areas.
Majed M. Alblooshi, Khaled Salah, Yousof Al-Hammadi
Recently, blockchain has been foreseen by industry and research community as a transformational and disruptive technology that is poised to play a major role in transforming the way we transact, trade, bank, track and register assets, and do business. Blockchain can potentially be used to provide trusted authenticity, origin, and ownership for IoT devices, in a way that is secure and decentralized without the involvement of a Trusted Third Parties (TTP) or centralized authorities and services. A TTP can be a subject to a single point of failure, and it can be disrupted, compromised or hacked. A TTP can potentially misbehave and become corrupt in the future, even if it is trustworthy now. This paper shows how Ethereum blockchain (with the powerful feature of programmability through smart contracts) can provide a trusted ownership management for medical IoT (MIoT) devices. Tracking the true ownership of MIoT devices is of a paramount importance as using counterfeited MIoT devices can be life-threatening to patients. The paper presents a general framework and solution to manage and trace back the true origin of ownership for an MIoT; whereby an MIoT device can be owned by multiple parties during its life cycle. The paper presents a detailed overview of our proposed system architecture, design, entity relationship, and interactions among all involved parties. The source code of the Ethereum smart contracts is made publicly available. Key aspects related to the algorithms, interactions, implementation and testing are discussed in the paper. Furthermore, we provide security analysis of our proposed solution in terms of satisfying the general security goals and also resiliency against popular attacks as those of DDoS, eavesdropping and replay attacks.
Andrey Demichev, A. P. Kryukov, Nikolai Prikhodko
The paper suggests a new approach based on blockchain technologies and smart contracts to creation of a distributed system for managing provenance metadata, as well as access rights to data in distributed storages, which is fault-tolerant, safe and secure from the point of view of preservation of metadata records from accidental or intentional distortions. The implementation of the proposed approach is based on the permissioned blockchains and on the Hyperledger Fabric blockchain platform in conjunction with Hyperledger Composer.
Sidra Malik, Salil S. Kanhere, Raja Jurdak
An increased incidence of food mislabeling and handling in recent years has led to consumers demanding transparency in how food items are produced and handled. The current traceability solutions suffer from issues such as scattering of information across multiple silos and susceptibility in recording erroneous data and thus are often unable to produce reliable farm to fork stories of products. Blockchain (BC) is a promising technology that could play an important role in providing data transparency and integrity due to its salient features which include decentralisation, immutability and auditability. In this paper, we propose a permissioned blockchain framework which is governed by a consortium of key Food Supply Chain (FSC) entities including government and regulatory bodies to promote food provenance. We propose to use a sharded, three-tiered architecture which ensures availability of data to consumers, limits access to competitive partners and provides scalability for handling transaction load. We also propose a transaction vocabulary and access rights to manage read and write privileges to BC supported by the consortium. The framework, ProductChain, ensures that trade flows are kept confidential when provenance information is retrieved by consumers and stakeholders. Simulation results show that query time for a product ledger is of the order of a few milliseconds even when the information is collated from multiple shards. ProductChain is generalised and applicable to supply chains in diverse industries.
Shilan Yang, Huaimin Wang, Wei Li, Wei Liu · 5 authors
Blockchain is distributed ledger with the advantage of high security, tamper resistant and traceability. However, in the process of the growth of Blockchain, network isolation hinders the cooperative operation among different Blockchains and greatly restricts the development of Blockchain. There is an urgent need to break the barriers among Blockchains[1], thus cross-chain communication become a new trend of the Blockchain technology[2]. In this paper, we propose CVEM, a value exchange mechanism which supports different kind of tokens transfer cross-chain. First, we put the main exchange process execute off-chain and the final result on-chain. Then, we combine Revocable Sequence Maturity Contract (RSMC) with the idea of cross-token exchange of Blockchain, and use the mechanism of multi-signatures address to constrain the users' behaviors. In addition, we introduce the Simple Payment Verification Proof (SPV Proof) to verify transactions. Our work, to some degree, shortens the transaction process delay and also ensures the security and scalability of the value exchange.
Asic Chen, Arno Jacob-sen
Blockchain is steadily becoming a disruptive technology, capable of profoundly impacting a wide range of industries. Established applications such as cryptocurrency (e.g., Bitcoin, etc.) have brought blockchain into the limelight. Blockchains, as one implementation of distributed ledgers, promises the ability to maintain critical information in a trustworthy repository without any centralized management. The reliability of blockchain-enabled applications is based on the innate immutability of stored data, maintained through cryptographic means, which enables blockchains to provide transparency, efficiency, auditability, trust, and security. Technological additions such as smart contract capabilities and various consensus algorithms have allowed novel blockchain use cases in both the public sector (e.g., identity governance, regulations, healthcare, etc.) and the private sector (e.g., finance, supply chain management, etc.).
Changhee Hahn, Hyunsoo Kwon, Junbeom Hur
Attribute-based encryption (ABE) offers a promising solution for flexible access control over sensitive personal health records in a mobile healthcare system on top of a public cloud infrastructure. However, ABE cannot be simply applied to lightweight devices due to its substantial computation cost during decryption. This problem could be alleviated by delegating significant parts of the decryption operations to computationally powerful parties, such as cloud servers, but the correctness of the delegated computation would be at stake. Thus, previous works enabled users to validate the partial decryption by employing a cryptographic commitment or message authentication code (MAC). This paper demonstrates that the previous commitment or MAC-based schemes cannot support verifiability in the presence of potentially malevolent cloud servers. We propose two concrete attacks on previous commitment or MAC-based schemes. We propose an effective countermeasure scheme for securing resource-limited mobile healthcare systems and provide a rigorous security proof in the standard model, demonstrating that the proposed scheme is secure against our attacks. The experimental analysis shows that the proposed scheme provides the similar performance compared with the previous commitment-based schemes and outperforms the MAC-based scheme.
Daejun Park, Yi Zhang, Manasvi Saxena, Philip Daian · 5 authors
In this paper, we present a formal verification tool for the Ethereum Virtual Machine (EVM) bytecode. To precisely reason about all possible behaviors of the EVM bytecode, we adopted KEVM, a complete formal semantics of the EVM, and instantiated the K-framework's reachability logic theorem prover to generate a correct-by-construction deductive verifier for the EVM. We further optimized the verifier by introducing EVM-specific abstractions and lemmas to improve its scalability. Our EVM verifier has been used to verify various high-profile smart contracts including the ERC20 token, Ethereum Casper, and DappHub MakerDAO contracts.