Yinghui Zhang, Robert H. Deng, Jiangang Shu, Kan Yang · 5 authors
As a very attractive computing paradigm, cloud computing makes it possible for resource-constrained users to enjoy cost-effective and flexible resources of diversity. Considering the untrustworthiness of cloud servers and the data privacy of users, it is necessary to encrypt the data before outsourcing it to the cloud. However, the form of encrypted storage also poses a series of problems, such as: How can users search over the outsourced data? How to realize user-side verifiability of search results to resist malicious cloud servers? How to enable server-side verifiability of outsourced data to check malicious data owners? How to achieve payment fairness between the user and the cloud without introducing any third party? Towards addressing these challenging issues, in this paper, we introduce TKSE, a trustworthy keyword search scheme over encrypted data without any third party, trusted or not. In TKSE, the encrypted data index based on digital signature allows a user to search over the outsourced encrypted data and check whether the search result returned by the cloud fulfills the pre-specified search requirements. In particular, for the first time, TKSE realizes server-side verifiability which protects honest cloud servers from being framed by malicious data owners in the data storage phase. Furthermore, blockchain technologies and hash functions are used to enable payment fairness of search fees without introducing any third party even if the user or the cloud is malicious. Our security analysis and performance evaluation indicate that TKSE is secure and efficient and it is suitable for cloud computing.
Throughout the history of mankind, trusted relationships have played a vital part in every \ntransaction humans have made. Those transactions belong to a spectrum that starts from \neveryday life decisions and acts, to a more complex, sensitive and wide area that even nations \nare involved. \nBefore the era of globalization of telecommunications that we live in, achieving trust was \nmore related to human relations. Even though that the meaning of trust is known to all, it is \nhard to find a definition that strictly describes it. \nTrust is multidimensional, multidisciplinary and multifaceted concept. Many definitions can \nbe found in literature and are related to notions as goodness, strength, reliability, integrity, \nability or character of a person or thing. A trust relationship involves two parties, a trustor \nand a trustee. The trustor is the person that holds confidence, belief on the reliability of \nanother person or thing which is the other party, the trustee. (Zheng & Valtteri Niemi, \nTowards User Driven Trust Modeling and Management, 2009) \nHow though trust is established in modern computer networks, where the notions of the \ntrustor and trustee are not represented by strictly humans, but from entities that might never \nhave had a relationship upon the trust can be build. \nIn this project we will study the achievement of trust in traditional kinds of networks such as \nad-hoc, mobile and wireless and we will examine the ability to elevate the trust level in a \ncomputer network using the under development and mostly promising blockchain network. \nThe network is going to be setup as a private blockchain network, where all the nodes that \nconsist it, will be pre-set from an administrative team. The computers that will participate will \nhave all the requirements in order to connect to the private network running as services on \nboot. \nThe application will run on each node and on starting the application the very first check will \nbe to start the node and connect to the network. Only if the network has been found and the \nnode is connected to it, the application proceeds with checking the presence of web3js and \nonly after successfully checking the communication of the web3js with the network, the user \nis prompt with the login page. \nThe authorization of the user is checked upon a smart contract on the blockchain network \nand after a successfully prompt from the smart contract, the credentials are checked, in our \ncase, on a fake backend where a JWT token is issued to the user in order to use the application \ndepending on the role that he has.
Weiqi Dai, Jun Deng, Qinyuan Wang, Changze Cui · 6 authors
Due to the increasing total value of the digital currency, the security of encryption wallet is becoming more and more important. The hardware-based wallet is safe, but it is inconvenient because users need to carry an additional physical device, the software-based wallet is convenient, but the safety cannot be guaranteed. All these wallets need to synchronize the blockchain, while most current mobile devices do not have the capability to store all blocks. To solve these problems, mobile devices can use simplified payment verification (SPV). Nevertheless, in existing methods, there is no good way to protect the verification process of the transaction. In this paper, we design a secure blockchain lightweight wallet based on Trustzone to protect SPV. It is more portable compared with the hardware wallet, and safer than the software wallet. Through the isolation, it can also protect the private key and the wallet's address from being stolen by the attackers no matter whether the Rich OS is malicious or not. Meanwhile, it can protect the verification process by verifying transactions in the secure execution environment (SEE), and keep the local block headers unreadable directly from the Rich OS through encryption. We deploy it on the RASPBERRY PI 3 MODEL B development board. The result of the experiment shows that it has little impact on the system.
Yanqi Zhao, Yannan Li, Qilin Mu, Bo Yang · 5 authors
The cyber physical system (CPS) has gained considerable success in large-scale distributed integration environment. In such systems, the sensor devices collect data which would be disseminated via reliable manner to all interested co-operant entities from the physical world. However, highly unreliable environment of CPS, for example, a number of limitations of existing network middle wares, makes secure and reliable data distribution services a challenge issue. In this paper, we propose a new architecture called secure pub-sub (SPS) without middle ware, i.e., blockchain-based fair payment with reputation. In SPS, publishers publish a topic on the blockchain and subscribers specify an interest message by making a deposit to subscribing the topic. Then, if the interest message matches the topic, the publisher transmits the encrypted content of the topic to the blockchain such that the subscribers can decrypt the ciphertext to obtain the content, and mark the publisher as its reputation. Finally, the publisher receives the payment from the subscriber. The new proposal provides confidentiality and reliability of data, anonymity of subscribers and payment fairness between the publishers and subscribers. Different from the traditional pub-sub services, no trusted third party is involved in our system due to employing blockchain technique. The security of the proposed SPS is analyzed as well. The implementation of the protocol on Ethereum of smart contract demonstrates the validity of SPS.
Vikram Sadhya, Harshali Sadhya, Rudy Hirschheim, Edward Watson
The acceptance of Bitcoin as an electronic currency is steadily on the rise. This implies there is a surge in the diffusion and adoption of the blockchain technology introduced by Bitcoin as well. Moreover, the potential of this novel disruptive technology has been acknowledged by academic researchers and practitioners alike. IS research has shown that trust is a significant antecedent enabling the adoption of a novel technology and attenuating the apprehensions of risk and uncertainty among consumers. Trust in a technology is formed by the trusting beliefs of a trustor regarding the trustworthiness of the IT artifact. The blockchain technology, the trustee, has features like cryptography, decentralization, hash functions, digital signature, consensus mechanism, which embody trust in the technology. We present an extensive description of Bitcoin as an instantiation of the blockchain technology, while offering a detailed account of the literature on trust in a technology. We conceptually present, through the use of knowledge mapping, how blockchain ensures trust in the technology. We propose future research directions for trust research in the blockchain context and urge IS academics to explore trust in this novel context.
With the widespread of E-commerce, the need of a trusted system to ensure the delivery of traded items is crucial. Current proof of delivery (PoD) systems lacks transparency, traceability, and credibility. These systems are mostly centralized and rely on trusted third parties (TTPs) to complete the delivery between sellers and buyers. TTPs can be costly, a single point of failure, and subject to hacking, privacy evasion, and compromise. The blockchain is an immutable, trusted, and decentralized ledger with logs and events that can be used for transparency, traceability, and tracking. In this paper, we present a solution and a general framework using the popular permissionless Ethereum blockchain to create a trusted, decentralized PoD system that ensures accountability, auditability, and integrity. The solution uses Ethereum smart contracts to prove the delivery of a shipped item between a seller and a buyer irrespective of the number of intermediate transporters needed. In our proposed solution, all participating entities are incentivized to act honestly by using a double deposit collateral. Automated payment in ether is an integral part of a solution to ensure that every entity gets its intended share of ether upon successful delivery. An arbitration mechanism is also incorporated if a dispute arises during the shipping process. In this paper, we show how we implemented, verified, and tested the proper functionality of our PoD solution. We also provide security analysis and give estimates of the cost consumption in ether gas. We made the full code of the Ethereum smart contracts publicly available at Github.
A treasury system is a community-controlled and decentralized collaborative decision-making mechanism for sustainable funding of blockchain development and maintenance. During each treasury period, project proposals are submitted, discussed, and voted for; top-ranked projects are funded from the treasury. The Dash governance system is a real-world example of such kind of systems. In this work, we, for the first time, provide a rigorous study of the treasury system. We modelled, designed, and implemented a provably secure treasury system that is compatible with most existing blockchain infrastructures, such as Bitcoin, Ethereum, etc. More specifically, the proposed treasury system supports liquid democracy/delegative voting for better collaborative intelligence. Namely, the stake holders can either vote directly on the proposed projects or delegate their votes to experts. Its core component is a distributed universally composable secure end-to-end verifiable voting protocol. The integrity of the treasury voting decisions is guaranteed even when all the voting committee members are corrupted. To further improve efficiency, we proposed the world's first honest verifier zero-knowledge proof for unit vector encryption with logarithmic size communication. This partial result may be of independent interest to other cryptographic protocols. A pilot system is implemented in Scala over the Scorex 2.0 framework, and its benchmark results indicate that the proposed system can support tens of thousands of treasury participants with high efficiency.
In this paper, we present a prototype of multi-user system for access control to datasets stored in an untrusted cloud environment. Cloud storage like any other untrusted environment needs the ability to secure share information. Our approach provides an access control over the data stored in the cloud without the provider participation. The main tool of access control mechanism is ciphertext-policy attribute-based encryption scheme with dynamic attributes. Using a blockchain-based decentralized ledger, our system provides immutable log of all meaningful security events, such as key generation, access policy assignment, change or revocation, access request. We propose a set of cryptographic protocols ensuring privacy of cryptographic operations requiring secret or private keys. Only ciphertexts of hash codes are transferred through the blockchain ledger. The prototype of our system is implemented using smart contracts and tested on Ethereum blockchain platform.
Kuo‐Hui Yeh, Chunhua Su, Jia-Li Hou, Wayne Chiu · 5 authors
Recently, the popularity and universality of smart-devices has led to rapid advancement in the development of applications for mobile commerce around the world. Novel mobile payment schemes, such as Apple pay, Android pay, and Samsung pay are becoming an increasingly popular ways to conduct online transactions, no matter what type of smart devices are used. Due to the attendant growth in the importance of security, significant attention has been devoted to the challenge of designing and implementing a robust mobile payment scheme for securing online transactions. In this paper, we demonstrate a robust mobile payment scheme based on sturdy certificateless signatures with bilinear pairing. We elegantly refine the proposed mobile payment scheme to make it suitable for computation-constrained mobile devices. The practicability of the proposed mobile payment scheme is then certified via a rigorous security analysis and thorough performance evaluation using the Raspberry PI as the implementation platform for our proposed scheme. Furthermore, we implement a transaction repository with the aid of smart contract technology. The simulation results, based on Ethereum, demonstrate the feasibility of employing the smart contract technology to secure mobile payments.
Cryptocurrencies based on blockchain infrastructures have shown their advantages such as double-spending resistance and decentralization. Each transaction of cryptocurrency requires a certain amount of computation and attracts transaction fees. Often, in practice, many transactions are small; therefore, they add computation and transmission overheads to the system. In this paper, we introduce a cost-saving approach, which significantly reduces transaction time and storage for small amount of payment, i.e. micropayment. In our approach, with the notion of ‘transaction commitment’, the computation of each transaction is much more efficient. Therefore, our approach has advantages in comparison of other cryptocurrency systems such as the bitcoin system. Our approach can be applied to other existing cryptocurrency systems.
Blockchain is a new distributed and decentralized technology, and gradually attracts worldwide attention, but it is vulnerable to quantum attacks that would solve elliptic curve digital logarithm problem, which is mainly used for transaction authentication in blockchain. The key needed for authentication comes from the wallet. To ensure that the size of the wallet is fixed and easy to manage, deterministic wallets are required to be used. But if existing anti-quantum signature schemes, such as lattice-based signature are used directly in blockchain to solve the problem, it would have made the wallet bloat. In this paper, we present a novel anti-quantum transaction authentication scheme in the blockchain. In order to construct lightweight nondeterministic wallets, the key point is that public and private keys are generated from a set of master public and private key(Seed Key). We leverage on Bonsai Trees technology and propose a new authentication method which can extend a lattice space to multiple lattice spaces accompanied by the corresponding key. Every signature of a transaction uses a lattice space so as to ensure the randomness and the security of the master private key. And we give the complete security proof and analysis. This paper provides the theoretical support for the application of blockchain in the post quantum age.
Bruno Tavares, Filipe Figueiredo Correia, André Restivo, João Pascoal Faria · 5 authors
The applications of the blockchain technology are still being discov-ered. When a new potential disruptive technology emerges, there is a tendency to try to solve every problem with that technology. However, it is still necessary to determine what approach is the best for each type of application. To find how distributed ledgers solve existing problems, this study looks for blockchain frameworks in the academic world. Identifying the existing frameworks can demonstrate where the interest in the technology exists and where it can be miss-ing. This study encountered several blockchain frameworks in development. However, there are few references to operational needs, testing, and deploy of the technology. With the widespread use of the technology, either integrating with pre-existing solutions, replacing legacy systems, or new implementations, the need for testing, deploying, exploration, and maintenance is expected to in-tensify.
Recent attention to Bitcoin and other cryptocurrencies has opened investors and the public to the realm of digital currency. Greater exposure around the world has led to a frenzy of entry into the market and a test into the long-term feasibility of Bitcoin being able to remain a functioning peer-to-peer (P2P), decentralized currency. Its main structure is supported by the Proof-of-Work (PoW) protocol in which users can elect to participate in determining transaction approval and ensuring an honest blockchain. This system relies on elected users to expend computational power and energy to solve puzzles to prove the accuracy of the network’s transactions and create new blocks.\nEach cryptocurrency uses their own method to ensure blockchain accuracy, and this paper will focus on how a Proof-of-Stake (PoS) protocol is a superior algorithm to PoW by assigning mining ability equal to one’s stake within a coin, rather than her energy consumption, among other factors. We will discuss Bitcoin’s PoW as a baseline for our eventual analysis of PoS in terms of advantages and performance metrics. The main factors that can be compared between the two protocols is how each system can prevent itself against a variety of attacks from adversarial users within the network, as well as long-term sustainability.\nFinally, we will use the Cardano (ADA) cryptocurrency by IOHK as a case study for understanding how their Ouroboros Praos PoS protocol works. Our goal is to show how long-term adoption of PoS framework is more realistic from an energy perspective than PoW.
Identity-based cryptosystems mean that public keys can be directly derived from user identifiers, such as telephone numbers, email addresses, and social insurance number, and so on. So they can simplify key management procedures of certificate-based public key infrastructures and can be used to realize authentication in blockchain. Linearly homomorphic signature schemes allow to perform linear computations on authenticated data. And the correctness of the computation can be publicly verified. Although a series of homomorphic signature schemes have been designed recently, there are few homomorphic signature schemes designed in identity-based cryptography. In this paper, we construct a new ID-based linear homomorphic signature scheme, which avoids the shortcomings of the use of public-key certificates. The scheme is proved secure against existential forgery on adaptively chosen message and ID attack under the random oracle model. The ID-based linearly homomorphic signature schemes can be applied in e-business and cloud computing. Finally, we show how to apply it to realize authentication in blockchain.
Proof-of-stake (PoS) protocols are emerging as one of the most promising alternative to the wasteful proof-of-work (PoW) protocols for consensus in Blockchains (or distributed ledgers). However, current PoS protocols inherently disclose both the identity and the wealth of the stakeholders, and thus seem incompatible with privacy-preserving cryptocurrencies (such as ZCash, Monero, etc.). In this paper we initiate the formal study for PoS protocols with privacy properties. Our results include:
1.
A (theoretical) feasibility result showing that it is possible to construct a general class of private PoS (PPoS) protocols; and to add privacy to a wide class of PoS protocols,
2.
A privacy-preserving version of a popular PoS protocol, Ouroboros Praos.
ECDSA is a standardized signing algorithm that is widely used in TLS, code signing, cryptocurrency and more. Due to its importance, the problem of securely computing ECDSA in a distributed manner (known as threshold signing) has received considerable interest. However, despite this interest, there is still no full threshold solution for more than 2 parties (meaning that any t -out-of- n parties can sign, security is preserved for any t-1 or fewer corrupted parties, and tłeq n can be any value thus supporting an honest minority) that has practical key distribution. This is due to the fact that all previous solutions for this utilize Paillier homomorphic encryption, and efficient distributed Paillier key generation for more than two parties is not known. In this paper, we present the first truly practical full threshold ECDSA signing protocol that has both fast signing and fast key distribution. This solves a years-old open problem, and opens the door to practical uses of threshold ECDSA signing that are in demand today. One of these applications is the construction of secure cryptocurrency wallets (where key shares are spread over multiple devices and so are hard to steal) and cryptocurrency custody solutions (where large sums of invested cryptocurrency are strongly protected by splitting the key between a bank/financial institution, the customer who owns the currency, and possibly a third-party trustee, in multiple shares at each). There is growing practical interest in such solutions, but prior to our work these could not be deployed today due to the need for distributed key generation.