With the fast boom of Internet of Medical Things (IoMT) devices and an increasing focus on personal health, personal health data are extensively collected by IoMT and stored as personal health records (PHRs). PHRs are frequently shared for accurate diagnosis, prognosis prediction, health advice consulting, etc. Since PHRs are highly private, the data-sharing process leads to wide-ranging concerns on privacy leakage and security compromise. Existing research has shown that the centralized systems, as the mainstream mode, are under the great risks. Motivated by this, we propose a consortium blockchain-based PHR management and sharing scheme, which is both security aware and privacy preserving. We adopt the interplanetary file system (IPFS) to store the PHR ciphertext of IoMT. Then, zero-knowledge proof can provide evidence for verifying keyword index authentication on blockchain. Moreover, the scheme jointly leverages modified attribute-based cryptographic primitives and tailor-made smart contracts to achieve secure search, privacy preservation, and personalized access control in IoMT scenarios. Security analysis is conducted to show that the designed protocols attain the expected design goals. This is followed by extensive evaluation results derived from real-world data sets, which demonstrate the superiority of the proposed scheme over current leading ones.
Rihab Habeeb Sahib, Prof. Dr. Eman Salih Al-Shamery
Regular E-voting systems for elections may count the votes in less time,less cost,save the privacy of citizens,but still considered risky as votes can be tampered.E-voting systems based on a network distributed ledger show fast results,more trusted,save privacy,cannot be tampered,and distributed in which no central organization controls the system.This paper illustrate an e-voting system to solve the challenge of a massive ledger that is distributed among network-nodes using a data reduction technique as a security-matching-tool,singular value decomposition(SVD) that handle a copy of election results in another form and matched with the SQL-database results to announce a successful election-event representing a transparency-powerful-secured-system
The demand for the digital monitoring of environmental ecosystems is high and growing rapidly as a means of protecting the public and managing the environment. However, before data, algorithms, and models can be mobilized at scale, there are considerable concerns associated with privacy and security that can negatively affect the adoption of technology within this domain. In this paper, we propose the advancement of electronic environmental monitoring through the capability provided by the blockchain. The blockchain’s use of a distributed ledger as its underlying infrastructure is an attractive approach to counter these privacy and security issues, although its performance and ability to manage sensor data must be assessed. We focus on a new distributed ledger technology for the IoT, called IOTA, that is based on a directed acyclic graph. IOTA overcomes the current limitations of the blockchain and offers a data communication protocol called masked authenticated messaging for secure data sharing among Internet of Things (IoT) devices. We show how the application layer employing the data communication protocol, MAM, can support the secure transmission, storage, and retrieval of encrypted environmental sensor data by using an immutable distributed ledger such as that shown in IOTA. Finally, we evaluate, compare, and analyze the performance of the MAM protocol against a non-protocol approach.
The advances made in genome technology have resulted in significant amounts of genomic data being generated at an increasing speed. As genomic data contain various privacy-sensitive information, security schemes that protect confidentiality and control access are essential. Many security techniques have been proposed to safeguard healthcare data. However, these techniques are inadequate for genomic data management because of their large size. Additionally, privacy problems due to the sharing of gene data are yet to be addressed. In this study, we propose a secure genomic data management system using blockchain and local differential privacy (LDP). The proposed system employs two types of storage: private storage for internal staff and semi-private storage for external users. In private storage, because encrypted gene data are stored, only internal employees can access the data. Meanwhile, in semi-private storage, gene data are irreversibly modified by LDP. Through LDP, different noises are added to each section of the genomic data. Therefore, even though the third party uses or exposes the shared data, the owner’s privacy is guaranteed. Furthermore, the access control for each storage is ensured by the blockchain, and the gene owner can trace the usage and sharing status using a decentralized application in a mobile device.
Saeed Hamood Alsamhi, Faris A. Almalki, Fatemeh Afghah, Ammar Hawbani · 7 authors
Edge Intelligence is an emerging technology which has attracted significant attention. It applies Artificial Intelligence (AI) closer to the network edge for supporting Beyond fifth Generation (B5G) needs. On the other hand, drones can be used as relay station (mobile drone edge intelligence) to gather data from smart environments. Federated Learning (FL) enables the drones to perform decentralized collaborative learning by developing local models, sharing the model parameters with neighbors and the centralized unit to improve global model accuracy in smart environments. However, drone edge intelligence faces challenges such as security and decentralization management, limiting its functions to support green smart environments. Blockchain is a promising technology that enables privacy-preserving data sharing in a distributed manner. There are several challenges that still need to be addressed in blockchain-based applications, such as scalability, energy efficiency, and transaction capacity. Motivated by the significance of FL and blockchain, this survey focuses on the synergy of FL and blockchain to enable drone edge intelligence for green sustainable environments. Moreover, we discuss the combination of FL and blockchain technological aspects, motivation, and framework for green smart environments. Finally, we discuss the challenges and opportunities, and future trends in this domain.
Hyperledger was set up with the aim of being an open-source platform targeted at accelerating industry-wide collaboration hosted by The Linux Foundation for developing robust and dependable blockchain and distributed ledger-based technological platform that may be applied across several industry sectors to improve the efficiency, performance, and transactions of different business operations. For these purpose, various distributed ledger frameworks and libraries have been developed inside the platform. In this paper, the Ursa cryptographic library, which is one of the libraries being developed in this platform to offer its users with dependable, secure, user friendly and plug-able cryptographic applications, has been examined and the performances of both the anonymous identity creation process and the presented cryptographic algorithms are examined.
Rabimba Karanjai, Lei Xu, Zhimin Gao, Lin Chen · 6 authors
In this paper, we present the design and implementation of a privacy preserving event based UTXO (Unspent Transaction Output) transaction system. Unlike the existing approaches that often depend on smart contracts where digital assets are first locked in a vault, and then released according to event triggers, the event based transaction system encodes event outcome as part of the UTXO note and safeguards event privacy by shielding it with zero-knowledge proof based protocols such that associations between UTXO notes and events are hidden from the validators. Without relying on any triggering mechanism, the proposed transaction system separates event processing from the transaction processing where confidential event based UTXO notes (event based UTXOs or conditional UTXOs) can be transferred freely with full privacy in an asynchronous manner, only with their asset values conditional to the linked event outcomes. The main advantage of such design is that it enables free trade of event based digital assets and prevents the assets from being locked. We implemented the proposed transaction system by extending the Zerocoin data model and protocols. The system is implemented and evaluated using xJsnark.
During times of pandemics, the healthcare system may collapse due to the high demand for healthcare resources. Hence, there is a need for an online-automated platform that enables remote collection of symptoms from suspected patients, accurate and fast diagnostics, and data sharing among different entities within the healthcare system. However, many privacy and scalability challenges face such a platform. To address such challenges, we propose a custom-designed blockchain enabled platform that guarantees privacy-preservation via a mixture of group signature and random numbers that support anonymity of suspected patients and unlinkability of data while enabling mutual interaction between the suspected patient and the platform; provides automatic diagnostics via a deep neural network-based detector that runs on a smart contract within the blockchain; and offers access and administrative authority of the healthcare entities to the database of symptoms and their diagnoses via a consortium-based blockchain architecture. Experimental studies demonstrate a detection accuracy of 90 percent based on a deep convolutional recurrent neural network. A case study of 500 expected patients is examined giving promising results. Every patient can know the test results after only 14 min of submitting the data. The storage requirements are as low as 0.52 MB for each suspected patient and 0.6 MB for each hospital.
Dec 1, 2021·2021 IEEE 23rd Int Conf on High Performance Computing & Communications; 7th Int Conf on Data Science & Systems; 19th Int Conf on Smart City; 7th Int Conf on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC/DSS/SmartCity/DependSys)
To solve the data silos and data security dilemma faced by machine learning (ML), the concept of federated learning (FL) was first proposed, and federated learning has also attracted great attention from the information security community in recent years, where the most concerned issue is the security of data and models in federated learning. The current centralized federated learning scheme is prone to single point of failure as well as central server evil problem, so blockchain is used to replace the central server, but the blockchain network is not immune to poisoning attacks by participants on the global model and inference attacks on participants' local data. To this end, in this paper, we propose a blockchain-based federated learning security and privacy protection framework (BFLSP), design a model storage scheme on the blockchain, and add a node scoring mechanism as well as a node election scheme to ensure the security of the model and data during the training process while guaranteeing the accuracy of the model. Finally, we design experiments to confirm the feasibility as well as the security of the framework.
Abstract Double auction mechanisms have been designed to trade a variety of divisible resources (e.g., electricity, mobile data, and cloud resources) among distributed agents. In such divisible double auction, all the agents (both buyers and sellers) are expected to submit their bid profiles, and dynamically achieve the best responses. In practice, these agents may not trust each other without a market mediator. Fortunately, smart contract is extensively used to ensure digital agreement among mutually distrustful agents. The consensus protocol helps the smart contract execution on the blockchain to ensure strong integrity and availability. However, severe privacy risks would emerge in the divisible double auction since all the agents should disclose their sensitive data such as the bid profiles (i.e., bid amount and prices in different iterations) to other agents for resource allocation and such data are replicated on all the nodes in the network. Furthermore, the consensus requirements will bring a huge burden for the blockchain, which impacts the overall performance. To address these concerns, we propose a hybridized TEE-Blockchain system (system and auction mechanism co-design) to privately execute the divisible double auction. The designed hybridized system ensures privacy, honesty and high efficiency among distributed agents. The bid profiles are sealed for optimally allocating divisible resources while ensuring truthfulness with a Nash Equilibrium. Finally, we conduct experiments and empirical studies to validate the system and auction performance using two real-world applications.
Elnaz Rabieinejad, Abbas Yazdinejad, Ali Dehghantanha, Reza M. Parizi · 5 authors
In recent years, Internet of Things (IoT) devices such as drones, smartphones, and smart vehicles have increased, and Smart Vehicular Networks (SVNs) have formed. SVN are one of the vital components in smart cities and improves their functionality and efficiency. Despite the many applications that SVN have shown, they have security vulnerabilities issues, and there are many reports of them being hacked. Most attacks on SVN occur due to wireless communications and information sharing between vehicles. Also, due to the communication among vehicles, failures can spread from the victim device to the entire network and cause widespread damages. SVN features include mobility, decentralization, resource constraints that make traditional security solutions unsuitable for it. We propose a secure framework using blockchain and Deep Neural networks (DNN) to address these challenges. In this framework, we consider cluster-based architecture that vehicles in each cluster can securely communicate using the blockchain. Also, DNN is adopted to detect abnormal vehicles that have been attacked using their network traffic analysis in each zone. We assess blockchain impacts on throughput using different miners with multiple block sizes in our proposed framework. The experimental result indicates the throughput improvement with an increase in miners and block size. In addition, we evaluated the DNN performance for abnormal vehicle detection, which represents 99.82% in terms of accuracy.
Medical health care centres are seen as a potential paradigm for dealing with large amounts of data utilizing artificial intelligence (AI). The fast growth in the massive volume of data created by connected devices in the health paradigm brings up new opportunities for data sharing to improve the quality of service for developing applications. Traditional AI approaches frequently need centralized data gathering and model training within a single company, which is a significant flaw owing to the lack of privacy and security of raw data transfer through mobile networks. The leakage of sensitive data can result in substantial consequences for the providers, in addition to financial loss. For that, we first build a blockchain-enabled safe data sharing architecture for distributed multiple parties in this paper. Then, by adding suggested privacy-preserved federated learning, we turn the data-sharing problem into a machine-learning challenge. Recommendations are based on the user’s previous search values, and data privacy is protected by providing the data model rather than the raw figures. Finally, we include federated learning into the permissioned blockchain consensus process, allowing the consensus computing effort to be used for federated training. According to numerical findings generated from data sets, the suggested data sharing method delivers good accuracy, high efficiency, and increased security.
Federated Learning (FL), which allows multiple participants to co-train machine Learning models without exposing local data, has been recognized as a promising method in the past few years. However, in the FL process, the server side may steal sensitive information of users, while the client side may also upload malicious data to compromise the training of the global model. Most existing privacy-preservation FL schemes seldom deal with threats from both of these two sides at the same time. In this paper, we propose a Blockchain based Privacy-preserving Federated Learning scheme named BPFL, which uses blockchain as the underlying distributed framework of FL. Homomorphic encryption and Multi-Krum technology are combined to achieve ciphertext-level model aggregation and model filtering, which can guarantee the verifiability of local models while realizing privacy-preservation. Security analysis and performance evaluation prove that the proposed scheme can achieve enhanced security and improve the performance of the FL model.
Naga Ramya Bhamidipati, Varsha Vakkavanthula, George Stafford, Masrik A. Dahir · 10 authors
Insurance claims processing involves multi-domain entities and multi-source data, along with a number of human-agent interactions. Consequently, this processing is traditionally manually-intensive and time-consuming. Blockchain technology-based platforms for intelligent automation can significantly improve the scale and response time of claims processing. However, there is a need to secure such platforms against fraud (e.g., duplicate claims) and the loss of data integrity caused due to cyber-attacks (e.g., Sybil attack). In this paper, we propose a novel “ClaimChain”, a consortium Blockchain platform that transforms the state-of-the-art NICB/ISO database architecture approach through increased shared intelligence and participation of insurance companies. ClaimChain features include: (a) automation of insurance claim processing via implementation of a Blockchain infrastructure, (b) infrastructure-level threat modeling via attack tree formalism for data integrity attacks, and (c) application-level fraud modeling for identified prominent red flags through machine learning models and risk scoring on the basis of risk severity. We evaluate the scalability of ClaimChain by simulating realistically large number of Blockchain transactions of claim processing. Further, we show that data integrity attacks at the infrastructure-level can be mitigated (as seen in reduction of 24% probability in loss) through implementation of security design principles. We also perform fraud-detection over an open dataset in ClaimChain to show how machine learning models can detect fraudulent activity with 98% accuracy.
The various data and privacy regulations introduced around the globe, require data to be stored in a secure and privacy-preserving fashion. Non-compliance with these regulations come with major consequences. This has led to the formation of huge data silos within organizations leading to difficult data analysis along with an increased risk of a data breach. Isolating data also prevents collaborative research. To address this, we present Private-Share, a framework that would enable secure sharing of large scale data. In order to achieve this goal, Private-Share leverages the recent advances in blockchain technology specifically the InterPlanetary File System and Ethereum.
Nowadays, online medical services have been greatly developing. Cryptocurrencies like Bitcoin and Ethereum are very suitable for online medical electronic payment scenarios that require identity privacy protection because of their good anonymity and financial payment attributes. However, cryptocurrencies varies widely, the need of cryptocurrencies exchange is urgent for patients to pay different doctors and platforms with diverse cryptocurrencies. Exchanging cryptocurrencies through centralized exchanges has problems such as high fees and cumbersome operations. The decentralized exchanges mainly focus on cross-blockchain connectivity but high intermediate fees charged by connectors are ignored. In order to minimize the exchange fees, we propose a cross-blockchain connector selection scheme utilizing the reverse Vickrey auction along with Interledger. Our scheme abstracts the connector nodes selection into a service provider bidding process, throught which we can find the very node with the lowest bid, namely, the least exchange fees, as the ideal cross-blockchain service provider. Our scheme implements cross-blockchain payment of different cryptocurrencies conveniently, quickly and cheaply, which can provide patients with better identity protection of personal privacy information. Security analysis and performance evaluations show that our scheme can effectively promote the applications of cryptocurrencies in the field of medical care.
The healthcare sector is constantly improving patient health record systems. However, these systems face a significant challenge when confronted with patient health record (PHR) data due to its sensitivity. In addition, patient’s data is stored and spread generally across various healthcare facilities and among providers. This arrangement of distributed data becomes problematic whenever patients want to access their health records and then share them with their care provider, which yields a lack of interoperability among various healthcare systems. Moreover, most patient health record systems adopt a centralized management structure and deploy PHRs to the cloud, which raises privacy concerns when sharing patient information over a network. Therefore, it is vital to design a framework that considers patient privacy and data security when sharing sensitive information with healthcare facilities and providers. This paper proposes a blockchain framework for secured patient health records sharing that allows patients to have full access and control over their health records. With this novel approach, our framework applies the Ethereum blockchain smart contracts, the Inter-Planetary File System (IPFS) as an off-chain storage system, and the NuCypher protocol, which functions as key management and blockchain-based proxy re-encryption to create a secured on-demand patient health records sharing system effectively. Results show that the proposed framework is more secure than other schemes, and the PHRs will not be accessible to unauthorized providers or users. In addition, all encrypted data will only be accessible to and readable by verified entities set by the patient.
Internet of Vehicles (IoV) has become an indispensable technology to bridge vehicles, persons and infrastructures, and is promising to make our cities smarter and more connected. It enables vehicles to exchange vehicular data (e.g., GPS, sensors, and brakes) with different entities nearby. However, sharing these vehicular data over the air raises concerns about identity privacy leakage. Besides, the centralized architecture adopted in existing IoV systems is fragile to single point of failure and malicious attacks. With the emergence of blockchain technology, it has the chance to solve these problems due to its features of tamper-proof, traceability and decentralization. In this paper, we propose a privacy-preserving vehicular data sharing framework based on blockchain. In particular, we design an anonymous and auditable data sharing scheme using Zero-Knowledge Proof (ZKP) technol-ogy so as to protect the identity privacy of vehicles while preserving the vehicular data auditability for Trusted Authorities (TAs). In response to high mobility of vehicles, we design an efficient multi-sharding protocol to decrease blockchain communication costs without compromising the blockchain security. We implement a prototype of our framework and conduct extensive experiments and simulations on it. Evaluation and analysis results indicate that our framework can not only strengthen system security and data privacy, but also increase the data authenticity verification efficiency by 5x comparing to existing privacy-preserving schemes.
Federated learning (FL) is a distributed machine learning (ML) technique that enables collaborative training in which devices perform learning using a local dataset while preserving their privacy. This technique ensures privacy, communication efficiency, and resource conservation. Despite these advantages, FL still suffers from several challenges related to reliability (i.e., unreliable participating devices in training), tractability (i.e., a large number of trained models), and anonymity. To address these issues, we propose a secure and trustworthy blockchain framework (SRB-FL) tailored to FL, which uses blockchain features to enable collaborative model training in a fully distributed and trustworthy manner. In particular, we design a secure FL based on the blockchain sharding that ensures data reliability, scalability, and trustworthiness. In addition, we introduce an incentive mechanism to improve the reliability of FL devices using subjective multi-weight logic. The results show that our proposed SRB- FL framework is efficient and scalable, making it a promising and suitable solution for federated learning.
Basudeb Bera, Mohammad Wazid, Ashok Kumar Das, Joel J. P. C. Rodrigues
Drones, sometimes called unmanned aerial vehicles (UAVs), can be deployed in a flying Internet of Things (IoT)/Internet of Drones (IoD) environment to execute some specific tasks, like environmental monitoring, disaster management, aerial photography, monitoring and tracking of enemies at borders, and many more. For security reasons, the deployed drones can sense and collect the data from their surroundings, and then securely send the information to the ground station server. The ground station server then provides the collected data to the peer-to-peer cloud server (P2PCS) network after converting them into encrypted transactions in a secure way. Finally, the blocks are created from the encrypted transactions and added into a blockchain by applying consensus algorithms implemented by the P2PCS network. The deployed artificial intelligence (AI)-based big data analytics is required to predict the useful results from the collected and processed data. In this article, we propose a novel AI-envisioned smart-contract-based blockchain-enabled security framework for secure communication in IoD. The provided security analysis proves the security of the proposed framework against different potential attacks. The blockchain implementation of the proposed framework is then executed to identify its impact on the performance of the system.
Zain Abubaker, Asad Ullah Khan, Ahmad Almogren, Shahid Abbas · 7 authors
Abstract In this article, Internet of Things (IoTs) devices are used for sensing the data through which the device owners earn revenue. Interested users can purchase data from IoT device owners, according to their demands. However, users are not confident about the quality of data they are purchasing. Moreover, the users do not rely on the device owner and are not willing to initiate data trading. Currently, data trading systems have many drawbacks, as they involve a third party, security and reputation mechanisms. Therefore, in this article, IoTs and BlockChain (BC) are integrated to monetize IoT's data and provide trustful data trading. A BC based review system to monetize IoT's data trading is developed through Ethereum smart contracts. The review system encourages the owners to provide authentic data and solves the issues regarding data integrity, fake reviews and conflicts between entities. Reviews and ratings are stored in the BC database for providing a guarantee about the data quality to users. To maintain data integrity, we use an advanced encryption standard (AES)‐256 encryption technique to encrypt data. Moreover, an arbitrator entity is responsible to resolve conflicts between data owner and users. The incentive is provided to the users and arbitrators to increase user participation and honesty. Simulations are performed for the validation of our system. We examine the proposed model using three parameters: gas consumption, mining time and encryption time.
Viraaji Mothukuri, Reza M. Parizi, Seyedamin Pouriyeh, Ali Dehghantanha · 5 authors
Federated learning (FL) enables collaborative training of machine learning (ML) models while preserving user data privacy. Existing FL approaches can potentially facilitate collaborative ML, but ensuring secure trading/sharing of training data is challenging in practice, particularly in the presence of adversarial FL clients. The ongoing security concerns around FL and strict laws on personally identifiable information necessitate the design of a robust and trusted FL framework, for example, using blockchain. Existing blockchain-based solutions are generally not of industrial strength, where limitations include scalability and lack of engagement by participating clients. In this article, blockchain-in-the-loop FL is our proposed approach of intertwining classic FL and Hyperledger Fabric with a gamification component. Our proposed approach is a fusion of secure application integrated to seal and sign-off asynchronous and synchronous collaborative tasks of FL. The enterprise-level blockchain network provides an immutable ledger that can be leveraged at different FL layers to ensure auditable tracing and level-up security in industrial settings. We evaluate our proposed approach with three different datasets to demonstrate the security enhancements that improve the FL process, resulting in a more accurate global ML model to converge with the possible best performance.
Cryptography is traditionally considered as a main information security mechanism, providing several security services such as confidentiality, as well as data and entity authentication. This aspect is clearly relevant to the fundamental human right of privacy, in terms of securing data from eavesdropping and tampering, as well as from masquerading their origin. However, cryptography may also support several other (legal) requirements related to privacy. For example, in order to fulfil the data minimisation principle—i.e., to ensure that the personal data that are being processed are adequate and limited only to what is necessary in relation to the purposes for which they are processed—the use of advanced cryptographic techniques such as secure computations, zero-knowledge proofs or homomorphic encryption may be prerequisite. In practice though, it seems that the organisations performing personal data processing are not fully aware of such solutions, thus adopting techniques that pose risks for the rights of individuals. This paper aims to provide a generic overview of the possible cryptographic applications that suffice to address privacy challenges. In the process, we shall also state our view on the public “debate” on finding ways so as to allow law enforcement agencies to bypass the encryption of communication.