Multi-access Edge Computing (MEC), as an extension of cloud computing, provides storage resources at the network edge to enable low-latency data retrieval for users. Due to limited physical sizes and constrained storage resources, individual edge servers cannot store a large amount of data when operating independently. They often need to offload data to other edge servers to serve users collaboratively. Operated by different edge infrastructure providers, edge servers usually work in a distrusted environment. Incentive and trust are the two main challenges in facilitating collaborative edge storage. This article proposes CSEdge, a novel decentralized system that tackles these challenges to enable collaborative edge storage based on blockchain. On CSEdge, edge servers can submit data offloading requests for others to contend for. Winners are selected based on their reputations. They will store the offloaded data and receive rewards for successfully finishing data offloading tasks. Via a distributed consensus, their performance will be recorded on blockchain for future reputation evaluation. A prototype of CSEdge is built on Hyperledger Sawtooth and experimentally evaluated against a baseline system and two start-of-the-art systems in a simulated MEC environment. The results demonstrate that CSEdge can effectively and efficiently facilitate collaborative edge storage among edge servers.
Mpyana Mwamba Merlec, Youn Kyu Lee, Seng-Phil Hong, Hoh Peter In
A massive amount of sensitive personal data is being collected and used by scientists, businesses, and governments. This has led to unprecedented threats to privacy rights and the security of personal data. There are few solutions that empower individuals to provide systematic consent agreements on distinct personal information and control who can collect, access, and use their data for specific purposes and periods. Individuals should be able to delegate consent rights, access consent-related information, and withdraw their given consent at any time. We propose a smart-contract-based dynamic consent management system, backed by blockchain technology, targeting personal data usage under the general data protection regulation. Our user-centric dynamic consent management system allows users to control their personal data collection and consent to its usage throughout the data lifecycle. Transaction history and logs are recorded in a blockchain that provides trusted tamper-proof data provenance, accountability, and traceability. A prototype of our system was designed and implemented to demonstrate its feasibility. The acceptability and reliability of the system were assessed by experimental testing and validation processes. We also analyzed the security and privacy of the system and evaluated its performance.
IoT devices’ storage and computation capacities are constantly increasing in recent years, which brings critical challenges in data privacy protection. Federated learning (FL) and blockchain technology are two popular techniques used in IoT data aggregation, where FL enables data training with privacy protection, and blockchain provides a decentralized architecture for data storage and mining. However, very few the state-of-the-art works consider the applicability of the combination of FL and blockchain. In this paper, we adopt the federated averaging algorithm to reduce the communication overhead between the blockchain and end users to achieve higher performance. We also apply the double-mask-then-encrypt approach for end users to submit their local updates in order to protect data privacy. Finally, we propose and implement a non-interactive Public Verifiable Secret Sharing (PVSS) algorithm with Distributed Hash Table (DHT) that solves the user-drop-out problem and improves the communication efficiency between blockchain and end-users. At last, we theoretically analyze the security strengths of the proposed solution and conduct experiments to measure the execution time of PVSS on both the server and clients sides.
Samiksha Kodgire Samiksha, Padma Adane, Ajay Jadhav, Aman R. Agrawal · 5 authors
Transactions over the internet have increased rapidly and so is the need to prove one’s identity and have a secured system to keep records. To overcome identity theft and fraud cases, Self-Sovereign Identity (SSI) was introduced which gives the user complete control over their identity on the internet. Self-Sovereign Identity eliminates the centralized authority and brings Zero-knowledge proof concepts into account to help in easy transactions over the internet. It avoids revealing unnecessary information and correlation attacks. Self-Sovereign Identity, on top of blockchain public ledger features, provides an extra security layer to the system that can be used to monitor the entries in confidential places. This research paper describes a software module, that we have developed, to grant verifiable credentials to users. These credentials, on verification, can grant entry into any security system with which the module is integrated. The module utilizes the facilities provided by Hyperledger Indy and Hyperledger Aries for the creation of verifiable credentials and subsequent verification in a secure manner.
Seyed Amid Moeinzadeh Mirhosseini, Ali Fanian, T. Aaron Gulliver
The advent of Bitcoin, and consequently Blockchain, has ushered in a new era\nof decentralization. Blockchain enables mutually distrusting entities to work\ncollaboratively to attain a common objective. However, current Blockchain\ntechnologies lack scalability, which limits their use in Internet of Things\n(IoT) applications. Many devices on the Internet have the computational and\ncommunication capabilities to facilitate decision-making. These devices will\nsoon be a 50 billion node network. Furthermore, new IoT business models such as\nSensor-as-a-Service (SaaS) require a robust Trust and Reputation System (TRS).\nIn this paper, we introduce an innovative distributed ledger combining Tangle\nand Blockchain as a TRS framework for IoT. The combination of Tangle and\nBlockchain provides maintainability of the former and scalability of the\nlatter. The proposed ledger can handle large numbers of IoT device transactions\nand facilitates low power nodes joining and contributing. Employing a\ndistributed ledger mitigates many threats, such as whitewashing attacks. Along\nwith combining payments and rating protocols, the proposed approach provides\ncleaner data to the upper layer reputation algorithm.\n
Vehicular Digital Forensics (VDF) is essential to enable liability cognizance of accidents and fight against crimes. Ensuring the authority to timely gather, analyze, and trace data promotes vehicular investigations. However, adversaries crave the identity of the data provider/user, damage the evidence, violate evidence jurisdiction, and leak evidence. Therefore, protecting privacy and evidence accountability while guaranteeing access control and traceability in VDF is no easy task. To address the above-mentioned issues, we propose Eunomia: an anonymous and secure VDF scheme based on blockchain. It preserves privacy with decentralized anonymous credentials without trusted third parties. Vehicular data and evidence are uploaded by data providers to the blockchain and stored in distributed data storage. Each investigation is modeled as a finite state machine with state transitions being executed by smart contracts. Eunomia achieves fine-grained evidence access control via ciphertext-policy attribute-based encryption and Bulletproofs. A user must hold specific attributes and a temporary-and-unexpired token/warrant to retrieve data from the blockchain. Finally, a secret key is embedded into data to trace the traitor if any evidence breach happens. We use a formal analysis to demonstrate the strong privacy and security properties of Eunomia. Moreover, we build a prototype in a WiFi-based Ethereum test network to evaluate its performance.
This paper presents a design for a blockchain solution aimed at the prevention of unauthorized secondary use of data. This solution brings together advances from the fields of identity management, confidential computing, and advanced data usage control. In the area of identity management, the solution is aligned with emerging decentralized identity standards: decentralized identifiers (DIDs), DID communication and verifiable credentials (VCs). In respect to confidential computing, the Cheon-Kim-Kim-Song (CKKS) fully homomorphic encryption (FHE) scheme is incorporated with the system to protect the privacy of the individual’s data and prevent unauthorized secondary use when being shared with potential users. In the area of advanced data usage control, the solution leverages the PRIV-DRM solution architecture to derive a novel approach to licensing of data usage to prevent unauthorized secondary usage of data held by individuals. Specifically, our design covers necessary roles in the data-sharing ecosystem: the issuer of personal data, the individual holder of the personal data (i.e., the data subject), a trusted data storage manager, a trusted license distributor, and the data consumer. The proof-of-concept implementation utilizes the decentralized identity framework being developed by the Hyperledger Indy/Aries project. A genomic data licensing use case is evaluated, which shows the feasibility and scalability of the solution.
Fan Zhang, Shaoyong Guo, Xuesong Qiu, Siya Xu · 6 authors
With the rapid development of the 5G and 6G technology, it has become an inevitable trend to share the cross-domain scattered data and enhance data value transmission. As a new data-sharing technology with intelligence and privacy computing, federated learning (FL) receives wide attention. It can realize data value delivery and data privacy protection at the same time, however, it lacks supervision in the application process, and the reliability of the calculation process and result transmission cannot be guaranteed. As a distributed ledger technology, blockchain has the trust property but lacks computing power. Therefore, we propose to extend the computing and supervision capabilities of blockchain with state channel, using state channel to create sandboxes and instantiate FL tasks in order to realize the trust supervision mechanism based on sandboxes. In this article, we establish an FL-based distributed data-sharing architecture and on the basis of the architecture we design a state channel-based distributed data-sharing trust supervision mechanism. Through theoretical analysis and experimental verification, the supervision mechanism we designed has an excellent performance in improving system security, resisting malicious attacks, and improving data model quality.
With the popularity of the internet 5G network, the network constructions of hospitals have also rapidly developed. Operations management in the healthcare system is becoming paperless, for example, via a shared electronic medical record (EMR) system. A shared electronic medical record system plays an important role in reducing diagnosis costs and improving diagnostic accuracy. In the traditional electronic medical record system, centralized database storage is typically used. Once there is a problem with the data storage, it could cause data privacy disclosure and security risks. Blockchain is tamper-proof and data traceable. It can ensure the security and correctness of data. Proxy re-encryption technology can ensure the safe sharing and transmission of relatively sensitive data. Based on the above situation, we propose an electronic medical record system based on consortium blockchain and proxy re-encryption to solve the problem of EMR security sharing. Electronic equipment in this process is connected to the blockchain network, and the security of data access is ensured through the automatic execution of blockchain chaincodes; the attribute-based access control method ensures fine-grained access to the data and improves the system security. Compared with the existing electronic medical records based on cloud storage, the system not only realizes the sharing of electronic medical records, but it also has advantages in privacy protection, access control, data security, etc.
Institutions in highly regulated domains such as finance and healthcare often have restrictive rules around data sharing. Federated learning is a distributed learning framework that enables multi-institutional collaborations on decentralized data with improved protection for each collaborator's data privacy. In this paper, we propose a communication-efficient scheme for decentralized federated learning called ProxyFL, or proxy-based federated learning. Each participant in ProxyFL maintains two models, a private model, and a publicly shared proxy model designed to protect the participant's privacy. Proxy models allow efficient information exchange among participants without the need of a centralized server. The proposed method eliminates a significant limitation of canonical federated learning by allowing model heterogeneity; each participant can have a private model with any architecture. Furthermore, our protocol for communication by proxy leads to stronger privacy guarantees using differential privacy analysis. Experiments on popular image datasets, and a cancer diagnostic problem using high-quality gigapixel histology whole slide images, show that ProxyFL can outperform existing alternatives with much less communication overhead and stronger privacy.
Mingyu Liang, Ioanna Karantaidou, Foteini Baldimtsi, Steven Gordon · 5 authors
Abstract We propose a new theoretical approach for building anonymous mixing mechanisms for cryptocurrencies. Rather than requiring a fully uniform permutation during mixing, we relax the requirement, insisting only that neighboring permutations are similarly likely. This is defined formally by borrowing from the definition of differential privacy. This relaxed privacy definition allows us to greatly reduce the amount of interaction and computation in the mixing protocol. Our construction achieves O ( n· polylog( n )) computation time for mixing n addresses, whereas all other mixing schemes require O ( n 2 ) total computation across all parties. Additionally, we support a smooth tolerance of fail-stop adversaries and do not require any trusted setup. We analyze the security of our generic protocol under the UC framework, and under a stand-alone, game-based definition. We finally describe an instantiation using ring signatures and confidential transactions.
In recent years, securely sharing personal information between two parties involves high risk. Most of the medical health records and financial transactions includes huge uncertainty while storing and retrieving from cloud for query processing. Blockchain is an open platform where each transaction is tampered proof. Various methods like zero knowledge proof or hashing methods used to hide the sensitive information from the real world. When associating blockchain with cloud this uncertainty is reduced. The user information is segregated into two categories sensitive and non-sensitive using linear regression method before processing in cloud. To improve security and increase privacy from various attacks, the sensitive part of data is encrypted using ECC and non- sensitive part of data is encrypted using RSA algorithm. Using Ethereum blockchain the policy of the user is verified and query processing is done. The performance of the model is compared with the existing techniques and results are evaluated using the classification error rate and performance of security against manual attacks.
Shan Wang, Ming Yang, Tingjian Ge, Yan Luo · 5 authors
Chain of custody is needed to document the sequence of custody of sensitive big data. In this paper, we design a blockchain big-data sharing system (BBS) based on Hyperledger Fabric. We denote the data stored outside of a ledger for sharing as "off-state" and "big data" (referring to extremely large data) is in this category. In our off-state sharing protocol, a sender registers a file with BBS for sharing. To acquire the file, an authenticated and authorized receiver has to use transactions and interacts with BBS in four phases, including the file transfer request, encrypted file transfer, key retrieval, and file decryption. The corresponding transactions are recorded in the ledger and serve as chain of custody to document the trail of the data. Compared with related work, BBS can perform the four phases autonomously. It utilizes the permissioned blockchain, i.e. Hyperledger Fabric, for access control and can defeat dishonest receivers. We design and implement a prototype of BBS for big file sharing. Extensive experiments were performed to validate its feasibility and performance.
In the 6G era, Internet of Things (IoT) devices can form a blockchain network, which also faces the problems of data sharing. The data transmitted and stored through the network have the risk of privacy leaking. Encrypting the shared data can satisfy the need of the privacy, and retrieving the encrypted data can make the data used efficiently. However, to enable users to retrieve encrypted data and perform fine-grained authorization on their encrypted files is still a great challenge. Although attribute-based keyword search (ABKS) is a well-received solution to the challenge, there are still privacy and efficiency issues if the traditional ABKS schemes are directly used in blockchain data sharing. In order to solve the problems, this article proposes privacy protection data retrieval scheme with an inverted index, which is an application of attribute-based encryption. First, our scheme is proved secure against the outside keyword guessing attack (KGA) and chosen keyword attack (CKA) under the semitrusted model. Second, the scheme returns a multikeywords ranked result. Third, we analyze the efficiency of our scheme and verify it by simulation. The results show that our scheme has improvement in efficiency and can meet the data sharing needs of the blockchain network composed of IoT devices.
5G heterogeneous network (HetNet) is a novel network topology that integrates various kinds of wireless access technologies such as 4G Long-Term Evolution (LTE), Wi-Fi, and so on. Despite greatly improving spectrum efficiency, it poses enormous challenges to spectrum e-auction. Firstly, due to high mobility, bidders may be interested in different spectrums in terms of time or geolocation. Secondly, one’s bidding value should be protected against rival bidders or adversaries to avoid vicious competition as well as privacy leakage. Thirdly, the ubiquitous HetNet requires a trustworthy distributed auction framework rather than a centralized auctioneer-based pattern. Aiming at overcoming these obstacles above, we proposed a blockchain-based combinatorial spectrum e-auction framework. Different from other blockchain-based solutions of using SGX to realize trust processing in the auction phase, we adopt Zether, a privacy-preserving smart contract, as the main building block. Besides, the bidding value is preserved from the beginning to the end, even though the time-consuming Paillier homomorphic encryption and garbled circuits are absent. We provide the auction security by leveraging <a:math xmlns:a="http://www.w3.org/1998/Math/MathML" id="M1"> <a:mi mathvariant="normal">Σ</a:mi> </a:math> -Bullets, a zero-knowledge proof mechanism. Theoretical analysis and extensive evaluation also indicate that our approach is better than the state-of-the-art works in terms of efficiency and effectiveness.
The recent simultaneous research expansion of machine learning (ML) and mobile computing has given birth to the concept of Federated Learning (FL). FL downscales ML’s enormous computation power requirement by delegating parts of learning tasks to smaller devices using the devices’ own dataset. Results of these bits then proceed to be aggregated to produce a global model. Blockchain, a (semi-)decentralized distributed ledger, enhances FL in reliability, security, correctness, and availability. Nevertheless, a plain blockchain-based FL (BFL) is not always ideal in mobile settings: mobile devices have limited resources to process blockchain routines and training. Plain BFL also relies on wireless connection which is often unstable. In addition, the heterogeneous nature of these devices cannot guarantee optimal model quality. Thus, this survey covers issues in mobile BFL and recent works which give effort to solving the problems and identifies further research potentials in this field. At the end, this work offers a hypothetical prototype of an ideal mobile-based BFL (MBFL).
Yun Li, Cun Ye, Yuguang Hu, Ivring Morpheus · 10 authors
Devising a fair-exchange protocol for digital goods has been an appealing line of research in the past decades. The Zero-Knowledge Contingent Payment (ZKCP) protocol first achieves fair exchange in a trustless manner with the aid of the Bitcoin network and zero-knowledge proofs. However, it incurs setup issues and substantial proving overhead, and has difficulties handling complicated validation of large-scale data. In this paper, we propose an improved solution ZKCPlus for practical and flexible fair exchange. ZKCPlus incorporates a new commit-and-prove non-interactive zero-knowledge (CP-NIZK) argument of knowledge under standard discrete logarithmic assumption, which is prover-efficient for data-parallel computations. With this argument we avoid the setup issues of ZKCP and reduce seller's proving overhead, more importantly enable the protocol to handle complicated data validations. We have implemented a prototype of ZKCPlus and built several applications atop it. We rework a ZKCP's classic application of trading sudoku solutions, and ZKCPlus achieves 21-67 times improvement in seller efficiency than ZKCP, with only milliseconds of setup time and 1 MB public parameters. In particular, our CP-NIZK argument shows an order of magnitude higher proving efficiency than the zkSNARK adopted by ZKCP. We also built a realistic application of trading trained CNN models. For a 3-layer CNN containing 8,620 parameters, it takes less than 1 second to prove and verify an inference computation, and also about 1 second to deliver the parameters, which is very promising for practical use.
Federated machine learning (FL) allows to collectively train models on sensitive data as only the clients' models and not their training data need to be shared. However, despite the attention that research on FL has drawn, the concept still lacks broad adoption in practice. One of the key reasons is the great challenge to implement FL systems that simultaneously achieve fairness, integrity, and privacy preservation for all participating clients. To contribute to solving this issue, our paper suggests a FL system that incorporates blockchain technology, local differential privacy, and zero-knowledge proofs. Our implementation of a proof-of-concept with multiple linear regression illustrates that these state-of-the-art technologies can be combined to a FL system that aligns economic incentives, trust, and confidentiality requirements in a scalable and transparent system.
The EU data strategy postulates that by 2025 there will be a paradigm shift towards more decentralized intelligence and data processing at the edge. The convergence of a large number of nodes at the IoT edge along with multiple service providers and network operators exposes data owners and resource providers to potential threats. To address cloud-edge risks, trust-based decentralized management is needed. Blockchain technology has created an opportunity to decentralize IoT ecosystems, through its intrinsic properties and together with machine learning (ML) it can be used to provide a trusted backbone for managing IoT ecosystems to support automated and adaptive trust management. This paper presents a novel approach for crosslayer intelligent trust computation modelling leveraging ML and Blockchain for decentralized trust management in IoT ecosystems. The effectiveness of the proposed approach for flow-based trust assessment is demonstrated using the Hyperledger Framework and the Cooja-based simulation environment. Finally, an initial evaluation is presented to understand the performance in terms of scalability and trust convergence of the proposed model.
The concept of time release provides a new mode of sending information to the future, where the message will be available after a certainly specified period. Time-release encryption (TRE), as a promising approach, has a widespread releasing application and ensures data confidentiality. TRE relies on two main frameworks, one based on the time-lock puzzle and the other based on a trusted third party, while this primitive is impeded by frameworks’ unreliability limitations and time disclosure. We present ReleaseSC, a decentralized and privacy-aware system that combines smart contract with TRE. ReleaseSC leverages a novel three-part architecture that harmonizes time release and contracts, enabling efficient time-hidden smart contract. Our prototype is with reasonable performance through EVM evaluations on both private chain and official test network. ReleaseSC is built on the top of a new cryptographic notion named ID-based TRE that supports a flexible time policy and preserves the to-be-released time. We propose an ID-based TRE instantiation and show rigorous security analysis in formal security models. The insight from ReleaseSC will open more possibilities to address security issues in hybridized cryptography-blockchain systems.