Ethereum Private Sidechains are permissioned Ethereum blockchains which allow authorised participants to interact privately using Smart Contracts. Permissioned blockchains are appropriate for use in scenarios in which the list of blockchain participants and the code and state of contracts on the blockchain must be kept secret. Ethereum Registration Authorities are a system of Smart Contracts which can be used to resolve bootstrap information based on domain names to allow Ethereum Private Sidechains to be established between parties which have not previously interacted. This paper presents the architecture, design, and gas usage of a reference implementation for the Ethereum Registration Authority system. It analyses the security properties of the system and shows that it is secure, decentralized, and censorship resistant. The reference implementation gas usage is analysed and shown to be independent of the length of domain name and number of entries in the Smart Contracts.
Rosario Gennaro, Michele Minelli, Anca Nitulescu, Michele Orrù
Zero-knowledge SNARKs (zk-SNARKs) are non-interactive proof systems with short and efficiently verifiable proofs. They elegantly resolve the juxtaposition of individual privacy and public trust, by providing an efficient way of demonstrating knowledge of secret information without actually revealing it. To this day, zk-SNARKs are being used for delegating computation, electronic cryptocurrencies, and anonymous credentials. However, all current SNARKs implementations rely on pre-quantum assumptions and, for this reason, are not expected to withstand cryptanalitic efforts over the next few decades. In this work, we introduce the first designated-verifier zk-SNARK based on lattice assumptions, which are believed to be post-quantum secure. We provide a generalization in the spirit of Gennaro et al. (Eurocrypt'13) to the SNARK of Danezis et al. (Asiacrypt'14) that is based on Square Span Programs (SSPs) and relies on weaker computational assumptions. We focus on designated-verifier proofs and propose a protocol in which a proof consists of just 5 LWE encodings. We provide a concrete choice of parameters as well as extensive benchmarks on a C implementation, showing that our construction is practically instantiable.
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Juan Zhao · 6 authors
Cyber-physical systems (CPS) including power systems, transportation, industrial control systems, etc. support both advanced control and communications among system components. Frequent data operations could introduce random failures and malicious attacks or even bring down the whole system. The dependency on a central authority increases the risk of single point of failure. To establish an immutable data provenance scheme for CPS, the authors adopt blockchain and propose a decentralized architecture to assure data integrity. In business-driven CPS, end users are required to share their personal information with multiple third parties. To prevent data leakage and preserve user privacy, the authors isolate and feed different information retrieval requests using tokens specifically generated for each type of request. Providing both traceability of data operations, and unlinkability of end user activities, a robust blockchain-based CPS is prototyped. Evaluation indicates the architecture is capable of assured data provenance validation and user privacy preservation at a low overhead.
As cloud services greatly facilitate file sharing online, there's been a growing awareness of the security challenges brought by outsourcing data to a third party. Traditionally, the centralized management of cloud service provider brings about safety issues because the third party is only semi-trusted by clients. Besides, it causes trouble for sharing online data conveniently. In this paper, the blockchain technology is utilized for decentralized safety administration and provide more user-friendly service. Apart from that, Ciphertext-Policy Attribute Based Encryption is introduced as an effective tool to realize fine-grained data access control of the stored files. Meanwhile, the security analysis proves the confidentiality and integrity of the data stored in the cloud server. Finally, we evaluate the performance of computation overhead of our system.
He Zhu, Yichuan Wang, Xinhong Hei, Wenjiang Ji · 5 authors
Application services in cloud computing model have complex scheduling, composition, configuration and deployment conditions, even in the multi-condition requirements, it can also be based on the change of time to schedule virtual services. Therefore, the demand of optimizing cloud computing scheduling strategy to ensure cloud data security and recovery ability is increasingly prominent. This paper proposes a trusted distributed audit method for cloud task scheduling, which is used for the trusted storage of cloud task scheduling information in the cloud cluster. This method mainly uses a distributed solution that combines block chain technology and traditional cloud server to solve the problem of integrity and security of cloud task scheduling, in order to prevent potential. The vulnerabilities in the system cause significant losses to the system. The architecture of this paper is composed of four parts: cloud cluster, control system, block chain network, and cloud database. We store the hash data of cloud task scheduling information into blockchain network and store the original data to the cloud data base, which guarantees the cloud task within the cloud cluster. Data security and integrity, and provide a new idea for future research system recovery.
The need to process the verity, volume and velocity of data generated by today's Internet of Things (IoT) devices has pushed both academia and the industry to investigate new architectural alternatives to support the new challenges. As a result, Edge Computing (EC) has emerged to address these issues, by placing part of the cloud resources (e.g., computation, storage, logic) closer to the edge of the network, which allows faster and context dependent data analysis and storage. However, as EC infrastructures grow, different providers who do not necessarily trust each other need to collaborate in order serve different IoT devices. In this context, EC infrastructures, IoT devices and the data transiting the network all need to be subject to identity and provenance checks, in order to increase trust and accountability. Each device/data in the network needs to be identified and the provenance of its actions needs to be tracked. In this paper, we propose a blockchain container based architecture that implements the W3C-PROV Data Model, to track identities and provenance of all orchestration decisions of a business network. This architecture provides new forms of interaction between the different stakeholders, which supports trustworthy transactions and leads to a new decentralized interaction model for IoT based applications.
Barbara Carminati, Elena Ferrari, Christian Rondanini
Today, most of the services one may think of are based on a collaborative paradigm (e.g., social media services, IoT-based services, etc.). One of the most relevant representative of such class of services are inter-organizational processes, where an organized group of joined activities is carried out by two or more organizations to achieve a common business goal. Inter-organizational processes are therefore vital to achieve business partnerships among different organizations. However, they may also pose serious security and privacy threats to the data each organization exposes. This is mainly due to the weak trust relationships that may hold among the collaborating parties, which result in a potential lack of trust on how data/operations are managed. In this paper, we discuss, how blockchain, one of today hottest technology, can be used in support of secure inter-organizational processes. We further point out which additional security issues the use of blockchain can bring, illustrate the ongoing research projects in the area and discuss future research directions.
Trust management has been a topic of keen interest in recent years. There has been a lot of discussion as to what new opportunities it can bring to markets, what benefits it can offer, and what system development possibilities it enables for software development. In this paper we discuss trust management and business critical information sharing in a definite group of stakeholders called Circle of Trust. We examine the key features of the Circle of Trust in military environments. We address the most essential problems and obstacles to be considered before the benefits of Circle of Trust can be fully enabled therein. As a solution to problems with the information transfer management, we propose a novel conceptual approach which ensures the privacy of the data source and transparency of information sharing utilizing the blockchain technology and modern cryptographic solutions. In addition, the concept presented enables the quantitative information trade and objective control mechanism for contractual liabilities within the consortium. The discussion and views presented in this paper can be adopted in any organization with doubts concerning the sensitive and classified contents of supply chain management or current ICT systems.
Oct 1, 2018·2018 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation (SmartWorld/SCALCOM/UIC/ATC/CBDCom/IOP/SCI)
Saqib Ali, Guojun Wang, Md Zakirul Alam Bhuiyan, Hai Jiang
Mission-critical applications such as industrial control, smart grids, security and surveillance systems are highly dependent on cloud-centric IoT networks. In such networks, the diverse IoT devices harvest the data from the remote environments and relay it to multiple intermediate agents over the wireless links towards the cloud for storage, analysis and decision making. Such systems require highly trustworthy data to guarantee accurate and timely decisions. However, in most of the cases, the IoT data becomes dubious during the transmission towards the cloud. Ensuring data provenance in such a heterogeneous multi-layered system is a critical security issue. Therefore, in this paper, we propose a secure data provenance framework for cloud-centric IoT network by utilizing the immutable, deterministic and public nature of the blockchain smart contracts with the traditional cloud infrastructure. In the framework, the cryptographic hash of the device metadata is stored in the blockchain whereas actual data is stored off-chain i.e., in the cloud, making it highly scalable for a dense deployment of IoT devices in the network. Multiple smart contracts are stationed in the blockchain to guarantee the provenance receipt to the data stored in the cloud. The initial evaluation revealed that the proposed framework is highly acceptable in achieving the data provenance for large-scale cloud-centric IoT networks.
Gregory Linklater, Christian Smith, Alan Herbert, Barry Irwin
Self-sovereign identity promises prospective users greater control, security, privacy, portability and overall greater convenience; however the immaturity of current distributed key management solutions results in general disregard of security advisories in favour of convenience and accessibility. This research proposes the use of intermediate certificates as a distributed key management solution. Intermediate certificates will be shown to allow multiple keys to authenticate to a single self-sovereign identity. Keys may be freely added to an identity without requiring a distributed ledger, any other third-party service or sharing private keys between devices. This research will also show that key rotation is a superior alternative to existing key recovery and escrow systems in helping users recover when their keys are lost or compromised. These features will allow remote credentials to be used to issuer, present and appraise remote attestations, without relying on a constant Internet connection.
Mustafa Al-Bassam, Alberto Sonnino, Vitalik Buterin
Light clients, also known as Simple Payment Verification (SPV) clients, are\nnodes which only download a small portion of the data in a blockchain, and use\nindirect means to verify that a given chain is valid. Typically, instead of\nvalidating block data, they assume that the chain favoured by the blockchain's\nconsensus algorithm only contains valid blocks, and that the majority of block\nproducers are honest. By allowing such clients to receive fraud proofs\ngenerated by fully validating nodes that show that a block violates the\nprotocol rules, and combining this with probabilistic sampling techniques to\nverify that all of the data in a block actually is available to be downloaded,\nwe can eliminate the honest-majority assumption, and instead make much weaker\nassumptions about a minimum number of honest nodes that rebroadcast data. Fraud\nand data availability proofs are key to enabling on-chain scaling of\nblockchains (e.g. via sharding or bigger blocks) while maintaining a strong\nassurance that on-chain data is available and valid. We present, implement, and\nevaluate a novel fraud and data availability proof system.\n
Guicang Peng, Songpu Ai, Li Zhang, Chunming Rong · 5 authors
Equipment management is gradually becoming more decentralized, and in many cases, the equipment owner, operator, maintainer and inspector are not the same legal entity. This slows down equipment data transmission between stakeholders and reduces business and technical process automation. In this paper we dis-cussed the use of a distributed ledger concept and propose to use private block-chain together with smart contract to resolve these challenges and to create a more automated and surveillance-free equipment lifecycle management process.
This paper proposes a novel blockchain-based technique for creating an environment where individuals can be the custodians of their official education records and can easily share those records with others. A blockchain is a digitized, decentralized, open record of all cryptographic data exchanges. One key characteristic of the blockchain is its decentralized nature. Unlike records or accounts maintained by department, college, university, government agencies and other institutions, the blockchain does not require an intermediary to complete education records or alter records. Our solution incorporating the advanced features of blockchain allows education providers to issue official certificates that supply proof of completion or achievement. The proposed framework could also provide the corresponding functions for the after-college education and many other further usages.
The issues of trust in the area of supply chain management are an immense concern among the stakeholders cooperating in the supply chain. For a sustainable process of transportation, efficient information sharing is considered crucial. The models that serve as a base for the current operations have several drawbacks in terms of data security and trust among stakeholders, who share information as part of their cooperation. Information is shared in a paper-based or semi-digitalized way due to the lack of trust or risk of competitive disadvantages in the current systems. This paper aims to analyze the trust issues in supply chain management and propose new ways of improving trust by considering these issues at the design level.
Usually, medical information including physical examination results and treatment of patients is stored in the hospital's centralized database. Although sophisticated access control strategy is adopted, it is still high-risk to expose patients' privacy in complex network environment. Moreover, a practical service platform is missed to share this kind of information under patients' authentication. To solve these problem, we elaborate an efficient and secure medical information service platform based on distributed cloud and blockchain technology, simultaneously guarantee security and confidentiality by hierarchical identity-based broadcast encryption system. Within our proposed framework, medical data are stored on distributed cloud after encryption. An incentive mechanism is designed to encourage customers and miners to maintain the platform. It shows that our platform is safe and effective in practice.
Beyond cryptocurrencies, blockchain technologies have shown great potential in enabling a wealth of decentralized applications (DApps), including but not limited to trustworthy auction, election, autonomous organization. While public blockchains are well recognized to allow participants mutually unbeknownst to achieve consensus, financial/business organizations also find great interest in consortium blockchains for better organizational collaborations. We will touch both types of blockchain and corresponding applications in this tutorial. In particular, we will summarize existing blockchain technologies and applications, elaborate the principles of designing and implementing secure DApps, and analyze the security concerns therein. Through concrete examples, we will discuss common practices and pitfalls, such as on-chain/off-chain interaction, randomness generation, and various corner cases. If time permits, we will also go through the implementation of the cloud-based blockchain backbone that powers this tutorial, possibly covering a layered architecture, and discuss deployment choices and security issues along the way. The tutorial will be interspersed with revisiting the security and implementation rules, so that participants are expected to readily apply the tutorial content into real-world practice. The design principles elaborated in this tutorial will be transferable to participants' development of secure and trustworthy blockchain applications and systems in their own workplaces.
John Collomosse, Tu Bui, Alan Brown, John Sheridan · 9 authors
We present ARCHANGEL; a decentralised platform for ensuring the long-term integrity of digital documents stored within public archives. Document integrity is fundamental to public trust in archives. Yet currently that trust is built upon institutional reputation --- trust at face value in a centralised authority, like a national government archive or University. ARCHANGEL proposes a shift to a technological underscoring of that trust, using distributed ledger technology (DLT) to cryptographically guarantee the provenance, immutability and so the integrity of archived documents. We describe the ARCHANGEL architecture, and report on a prototype of that architecture build over the Ethereum infrastructure. We report early evaluation and feedback of ARCHANGEL from stakeholders in the research data archives space.
Smart contracts are a new paradigm that emerged with the rise of the blockchain technology. They allow untrusting parties to arrange agreements. These agreements are encoded as a programming language code and deployed on a blockchain platform, where all participants execute them and maintain their state. Smart contracts are promising since they are automated and decentralized, thus limiting the involvement of third trusted parties, and can contain monetary transfers. Due to these features, many people believe that smart contracts will revolutionize the way we think of distributed applications, information sharing, financial services, and infrastructures. To release the potential of smart contracts, it is necessary to connect the contracts with the outside world, such that they can understand and use information from other infrastructures. For instance, smart contracts would greatly benefit when they have access to web content. However, there are many challenges associated with realizing such a system, and despite the existence of many proposals, no solution is secure, provides easily-parsable data, introduces small overheads, and is easy to deploy. In this paper we propose PDFS, a practical system for data feeds that combines the advantages of the previous schemes and introduces new functionalities. PDFS extends content providers by including new features for data transparency and consistency validations. This combination provides multiple benefits like content which is easy to parse and efficient authenticity verification without breaking natural trust chains. PDFS keeps content providers auditable, mitigates their malicious activities (like data modification or censorship), and allows them to create a new business model. We show how PDFS is integrated with existing web services, report on a PDFS implementation and present results from conducted case studies and experiments.
The redesign of cloud storage with the amalgamation of cooperative cloud and an immutable and unhackable distributed database blockchain thrives towards a strong CIA triad and secured data provenance. The conspiracy ideology associated with the traditional cloud has economized with cooperative cloud storage like Storj and Sia, decentralized storage, which allows renting the unused hard drive space and getting monetary compensation in an exchange with cryptocurrency. In this article, the authors explain how confidentiality, integrity and availability can be progressed with cooperative cloud storage along with tamper-proof data provenance management with ethereum smart contracts using zero-knowledge proof (ZKP). A contemporary architecture is proposed with regards to storing data on the cooperative cloud and collecting and verifying the provenance data from the cloud and publishing the provenance data into blockchain network as transactions.
Yinghui Zhang, Robert H. Deng, Ximeng Liu, Dong Zheng
As a milestone in the development of outsourcing services, cloud computing enables an increasing number of individuals and enterprises to enjoy the most advanced services from outsourcing service providers. Because online payment and data security issues are involved in outsourcing services, the mutual distrust between users and service providers may severely impede the wide adoption of cloud computing. Nevertheless, most existing solutions only consider a specific type of services and rely on a trusted third-party to realize fair payment. In this paper, to realize secure and fair payment of outsourcing services in general without relying on any third-party, trusted or not, we introduce BPay, an outsourcing service fair payment framework based on blockchain in cloud computing. We first propose the system architecture, adversary model and design goals of BPay, then describe the design details. Our security and compatibility analysis indicates that BPay achieves soundness and robust fairness and it is compatible with the Bitcoin blockchain and the Ethereum blockchain. The key to the robust fairness and compatibility lies in an all-or-nothing checking-proof protocol and a top-down checking method. In addition, our experimental results show that BPay is computationally efficient. Finally, we present the applications of BPay in outsourcing services.
An insurance system based on blockchain is proposed for web identity security, which provides two insurance service models for personal web identity security of end users and data security of commercial websites, respectively. Claim evidences are uploaded automatically to the blockchain to keep their authenticity. Smart contracts are automatically applied between insurers and policyholders to build trust between them.