Blockchains like Bitcoin and Ethereum have seen significant adoption in the past few years and show promise to design applications without any centralized reliance on third parties. In this paper, we present Endolith, an auditing framework for verifying file integrity and tracking file history without third party reliance using a smart contract-based blockchain. Annotated files are continuously monitored and metadata about changes including file hashes are stored tamper-proof on the blockchain. Based on this, Endolith can prove that a file stored a long time ago has not been changed without authorization or, if it did, track when it has changed, by whom. Endolith implementation is based on Ethereum and Hadoop Distributed File System (HDFS). Our evaluation on a public blockchain network shows that Endolith is efficient for files that are infrequently modified but often accessed, which are common characteristics of data archives.
Jieying Chen, Xiaofeng Ma, Du Mingxiao, Zhuping Wang
Medical information are private and medical data are valuable for medical research. Medical information sharing is challenging as the data might be manipulated improperly and revealed during the whole operational process. Medical institutions need shared information for scientific research and develop, on the contrary, privacy issue inhibits the sharing process. In this paper, a new business process and a novel architecture for medical information sharing based on blockchain are proposed. Exploiting the advantage of blockchain in recording transactions, information can be shared and verified among parties like a distributed ledger. On the other hand, medical information can be shared securely between users without an intermediary. The main benefit is that both the information and the traces of the transaction can be distributed stored which avoid manipulation and fraud. Consequently, the value of information can be fully utilized.
Deepak Puthal, Nisha Malik, Saraju P. Mohanty, Elias Kougianos · 5 authors
The blockchain is emerging as one of the most propitious and ingenious technologies of cybersecurity. In its germinal state, the technology has successfully replaced economic transaction systems in various organizations and has the potential to revamp heterogeneous business models in different industries. Although it promises a secure distributed framework to facilitate sharing, exchanging, and the integration of information across all users and third parties, it is important for the planners and decision makers to analyze it in depth for its suitability in their industry and business applications. The blockchain should be deployed only if it is applicable and provides security with better opportunities for obtaining increased revenue and reductions in cost. This article presents an overview of this technology for the realization of security across distributed parties in an impregnable and transparent way.
This paper aims at showing a conceptual approach for security and traceability of shared information in the process of transportation of dangerous goods. Concerning the transport of dangerous goods, the process generates particular information, which is necessary to share with the stakeholders involved in this process. This information is considered sensitive, because it may contain the timestamp of movement of goods, information related to the goods, contractual business details, etc., and unauthorized parties should not access them. At any level, the process should remain transparent between stakeholders', with immutable properties on data sharing and the whole process should be auditable. We examine a general procedure for contractual issues for transportation of dangerous goods between stakeholders and its conceptual implementation by blockchain based on smart contracts.
Blockchains, such as Bitcoin and Ethereum and their respective P2P networks have seen significant adoption in many sectors in the past few years. All these technologies that use the Blockchain pattern show that it is possible to rebuild any transactional system with better performance without relying on any trusted parties to manage transactions between peers. This insight has lead many companies to invest millions to understand the technology and to find a way to migrate from centralized to decentralized solutions. These solutions need to store large amounts of data in a secure and confidential way. Many distributed storage systems now exist using Blockchain technology (Cloud, FileSystems, etc.). But none of the tools proposed are able to manage the document life cycle nor archive documents based on regulatory compliance. In this paper, we describe our protocol named NFB (Notarizing Files over the Blockchain). This protocol ensures the communication between two systems: a permissive Blockchain and a secured centralized archiving Document Management System. The method described is used to allow users to archive, control, analyze and validate their transactions in a system that offers confidentiality, security and distribution features.
Blockchain systems establish a cryptographically secure data structure for storing data in the form of a hash chain. We use a novel combination of distributed storage, private key encryption, and Shamirs secret sharing scheme to distribute transaction data, without significant loss in data integrity. Additionally, using Shamirs secret sharing scheme on the hash values and dynamic zone allocation, we further enhance the integrity. We highlight the tradeoff in storage cost and data loss probability with varying zone size choices. We also study the tradeoff between recovery cost and security from adversarial corruption with varying recovery mechanisms. Then, we formulate code design, given a probability of data recovery and targeted corruption, as an integer program. Using the coding scheme we establish a mechanism to insure data, for instance in blockchain-based cloud storage systems, based on the value of the data, by understanding the costs involved for the service provider.
The Intelligent vehicle is experiencing revolutionary growth in research and industry, but it still suffers from a lot of security vulnerabilities. Traditional security methods are incapable of providing secure IV, mainly in terms of communication. In IV communication, major issues are trust and data accuracy of received and broadcasted reliable data in the communication channel. Blockchain technology works for the cryptocurrency, Bitcoin which has been recently used to build trust and reliability in peer-to-peer networks with similar topologies to IV Communication world. IV to IV, communicate in a decentralized manner within communication networks. In this paper, we have proposed, Trust Bit (TB) for IV communication among IVs using Blockchain technology. Our proposed trust bit provides surety for each IVs broadcasted data, to be secure and reliable in every particular networks. Our Trust Bit is a symbol of trustworthiness of vehicles behavior, and vehicles legal and illegal action. Our proposal also includes a reward system, which can exchange some TB among IVs, during successful communication. For the data management of this trust bit, we have used blockchain technology in the vehicular cloud, which can store all Trust bit details and can be accessed by IV anywhere and anytime. Our proposal provides secure and reliable information. We evaluate our proposal with the help of IV communication on intersection use case which analyzes a variety of trustworthiness between IVs during communication.
The brave new world of blockchain potentially transforms the financial structures we have come to know and feel ambivalent about. What does a decentralized, secure system mean for our society?
Modern Trusted Execution Environments (TEEs), such as Intel SGX, gain more and more popularity in the blockchain community and their adoption has already been started. Combining smart-contract execution with TEEs promises efficient solutions for protecting data privacy in distributed ledgers, as an alternative to much more costly cryptographic protocols. This paper describes practical challenges that arise from the combination of smart contracts with TEEs. In particular, we discuss existing solutions and their conceptional differences of on-chain and off-chain execution followed by technical challenges on attestation, key management, and non-deterministic execution.
The emergence of distributed ledger technology (DLT) based upon a blockchain data structure, has given rise to new approaches to identity management that aim to upend dominant approaches to providing and consuming digital identities. These new approaches to identity management (IdM) propose to enhance decentralisation, transparency and user control in transactions that involve identity information; but, given the historical challenge to design IdM, can these new DLT-based schemes deliver on their lofty goals? We introduce the emerging landscape of DLT-based IdM, and evaluate three representative proposals: uPort; ShoCard; and Sovrin; using the analytic lens of a seminal framework that characterises the nature of successful IdM schemes.
Systems that use blockchain technology to improve the know-your-customer (KYC) process have only been proposed at a conceptual level and all share certain attributes that make their adoption very difficult. We propose and program a blockchain-based system that reduces and shares out among the financial institutions (FIs) that work with a customer the costs of the KYC process and also makes it possible for FIs to dynamically update information related to customers and disseminates this information among participating FIs. Additionally, our system addresses some of the attributes that hinder the adoption of previously proposed solutions by FIs. The result is a stand-alone solution that reduces the cost of the KYC process without requiring any central instance to store the customer's data, and in which FIs share the initial costs of the KYC process as well as the running costs of keeping the information about customers up to date.
Virtual machine (VM) measurements data in IaaS cloud play a crucial role in integrity evaluation and decision making. Hence, the secure storage for these data has attracted more attention recently. This paper proposes a novel approach, named Mchain, to enhance the integrity and controllability of the secure storage. Especially, to enhance the integrity, a two-layer blockchain network is introduced. In the first layer, after the production, the data packages are first verified by leveraging a correspondence between a package and a policy, and a one-to-one relation among a VM, a user, and a node. After that, we propose a consensus achievement algorithm to construct a semi-finished block on a candidate block arranged by data packages. Meanwhile, the semi-finished block is distributed to all nodes, which can provide a certain integrity. In the second-layer, tamper-resistant metadata is generated by performing PoW tasks on the semi-finished block, resulting in strong integrity. Further, to enhance the controllability, a revisable user-defined policy-based encryption method with KP-ABE is proposed. It helps to flexibly control the scope of authorized verifiers. The experimental results on six scenarios with simulated data set show that the proposed approach is appealing in integrity and controllability, and the time overhead of data storage.
Blockchain technology is expected to be an enabler of Ëtrust-free economic transactionsâ¢, which implies a frictionless economy without uncertainty and risks. Looking at current use cases of blockchains such as the peer-to-peer payment system Bitcoin, it i