Federated learning (FL) serves as an enabling technology for intelligent edge computing, where high-quality machine learning (ML) models are collaboratively trained over large amounts of data generated by various Internet of Things devices while preserving data privacy. To further provide data confidentiality, computation auditability, and participant incentives, the blockchain framework has been incorporated into FL. However, it is an open question whether the model updates from participants in blockchain-assisted FL can disclose properties of the private data the participants are unintended to share. In this article, we propose a novel property inference attack that exploits the unintended property leakage in blockchain-assisted FL for intelligent edge computing. More specifically, we present an active attack to learn the property leakage from model updates of participants and to identify a set of participants with a certain property. We also design a dynamic participant selection strategy tailored to the setting of large-scale FL, which accelerates the selection process of target participants and improves attack accuracy. We evaluate the proposed attack through extensive experiments with publicly available data sets. The experimental results demonstrate that the proposed attack is effective and efficient in inferring various properties of training data, while maintaining the high quality of the main tasks in FL.
Ahstract- The traditional centralized database management mode brings security and privacy issues to user data. In this paper, we propose a verifiable distributed database access control (VDAC) scheme based on the ciphertext policy attribute-based encryption (CP-ABE) and decentralized ledger technology (DLT). In the VDAC scheme, CP-ABE is used to achieve fine-grained access authorization control on user data, and DLT is employed to publish authorization parameters and guarantee their immutability. Particularly, the decentralized authorization mechanism for distributed database is realized by using Hyperledger fabric platform. Comparison analysis shows that the VDAC scheme not only provides verifiable database access control, but also protects user privacy and system security. Experimental results demonstrate the efficiency and practicality of the VDAC scheme.
Compared with traditional insurance schemes, usage-based insurance (UBI) for vehicles is more economic and accurate for drivers since its insurance premium calculation depends on how vehicles are driven. However, UBI requires sensitive driving data to determine insurance premiums, and this could result in serious privacy breach for drivers. Meanwhile, existing UBI solutions rely on a centralized entity (i.e., the insurance company) to manage insurances. In this article, we design a decentralized and privacy-preserving UBI scheme, called DUBI, based on the blockchain technology and zero-knowledge proof. In our scheme, a smart contract running over the blockchain serves as a “decentralized” insurance company, while drivers continuously upload their committed driving data to the blockchain. Periodically, the driver submits accumulated driving statistics with a zero-knowledge proof to the smart contract, which verifies the proof and calculates the insurance premium from the submitted statistics. We formulate an ideal functionality for DUBI under the universal composability framework, and then provide a formal security proof for DUBI. Furthermore, we give in-depth analysis and performance evaluation for DUBI with an implementation based on Ethereum. It shows that DUBI is highly efficient in processing UBI insurances in both storage and computation: DUBI is about seven times more efficient than existing schemes in storage, and proof generation and verification take only 7 and 30 ms, respectively.
Various emerging applications and services such as smartphones, wearable devices, and Inter-net of Things (IoT) have brought great convenience to people's daily life, while producing huge amounts of data. Mass data have become a valuable asset, which creates a new business pattern called data trading. However, fairness becomes a challenge when conducting online data trading between participants who are not fully trusted by each other. That is, if a data seller sends the data before being paid, a data buyer might obtain the data without paying, and conversely if a data buyer pays before receiving the data, the data seller might not send the data contractually. Traditionally, a trusted third party is usually employed to settle the disputes between buyers and sellers, but this centralized party is vulnerable to the single-point-of-failure issue. Fortunately, Blockchain provides an approach to realizing data trading without centralized trusted third parties. In this article, we introduce Fairtrade, a decentralized fair data trading framework, to solve the challenges of data availability and trading fairness in decentralized data trading. We propose two different models with potential instantiations. In the first solution, we take advantage of homomorphic encryption and data sample techniques to improve the reliability of the system, and further guarantee the availability of the data during data trading. In the second solution, we integrate double-authentication-preventing signatures with smart contracts to achieve fairness during data trading. We also evaluate Fairtrade by implementing both frameworks, in which we test the time consumption of the main algorithms and also test the gas cost of the functions in the smart contracts on the blockchain. The experimental results show the practicality of the proposal.
Current cryptocurrencies, such as Bitcoin and Ethereum, enable anonymity by using public keys to represent user accounts. On the other hand, inferring blockchain account types (i.e., miners, smart contracts or exchanges), which are also referred to as blockchain identities, is significant in many scenarios, such as risk assessment and trade regulation. Existing work on blockchain deanonymization mainly focuses on Bitcoin that supports simple transactions of cryptocurrencies. As the popularity of decentralized application (DApp) platform blockchains with Turing-complete smart contracts, represented by Ethereum, identity inference in blockchain faces new challenges because of user diversity and complexity of activities enabled by smart contracts. In this paper, we propose I$^2$GL, an identify inference approach based on big graph analytics and learning to address these challenges. Specifically, I$^2$GL constructs a transaction graph and aims to infer the identity of nodes using the graph learning technique based on Graph Convolutional Networks. Furthermore, a series of enhancement has been proposed by exploiting unique features of blockchain transaction graph. The experimental results on Ethereum transaction records show that I$^2$GL significantly outperforms other state-of-the-art methods.
In recent years, the deployment of Cloud Computing (CC) has become more popular both in research and industry applications, arising form various fields including e-health, manufacturing, logistics and social networking. This is due to the easiness of service deployment and data management, and the unlimited provision of virtual resources (VR). In simple scenarios, users/applications send computational or storage tasks to be executed in the cloud, by manually assigning those tasks to the available computational resources. In complex scenarios, such as a smart city applications, where there is a large number of tasks, VRs, or both, task scheduling is exposed as an NP-Hard problem. Consequently, it is preferred and more efficient in terms of time and effort, to use a task scheduling automation technique. As there are many automated scheduling solutions proposed, new possibilities arise with the advent of Fog Computing (FC) and Blockchain (BC) technologies. Accordingly, such automation techniques may help the quick, secure and efficient assignment of tasks to the available VRs. In this paper, we propose an Ant Colony Optimization (ACO) algorithm in a Fog-enabled Blockchain-assisted scheduling model, namely PF-BTS. The protocol and algorithms of PF-BTS exploit BC miners for generating efficient assignment of tasks to be performed in the cloud’s VRs using ACO, and award miner nodes for their contribution in generating the best schedule. In our proposal, PF-BTS further allows the fog to process, manage, and perform the tasks to enhance latency measures. While this processing and managing is taking place, the fog is enforced to respect the privacy of system components, and assure that data, location, identity, and usage information are not exposed. We evaluate and compare PF-BTS performance, with a recently proposed Blockchain-based task scheduling protocol, in a simulated environment. Our evaluation and experiments show high privacy awareness of PF-BTS, along with noticeable enhancement in execution time and network load.
Autonomous vehicles (AV) utilize various machine learning (ML) models for performing tasks such as pedestrian detection, charging station prediction, routing path prediction, intrusion detection, to name a few. To improve the robustness of such applications, decentralized collaboration is imperative in a vehicular network. Moreover, decentralized collaboration poses threats, such as forged message injection, forged identity, and repudiatory activities, as most vehicles are stranger to each other. In recent years, blockchain technology has been widely used in the vehicular network to enhance trust, provenance, and eliminate unauthorized access to the vehicular services. However, most of the existing vehicular blockchain suffers from issues related to scalability, efficiency, and transaction verification. In this paper, we propose a lightweight vehicular blockchain architecture for distributed model sharing to enhance trust, verifiability, and non-repudiation in distributed vehicular collaboration. We propose a novel PoVS-BFT protocol and an effective two-step transaction verification mechanism for model sharing applications. Finally, simulation results are presented to conform to the efficacy of our proposed architecture. Simulation results show that the proposed PoVS-BFT protocol can minimize the size of consensus committee up to 62.5% which in turn reduces communication complexity during the consensus process.
Srđan Daniel Simić, Robert Šajina, Nikola Tanković, Darko Etinger
Recent advances in blockchain gained significant social attention, mainly due to substantial price fluctuations of Bitcoin and Ethereum cryptocurrencies. By its design, blockchain is an open, distributed ledger that can record transactions between two parties efficiently and in a verifiable and permanent way, providing solutions for many complex tasks without third party involvement. To achieve that, they employ a set of Byzantine Fault-tolerant consensus algorithms that require the implemented logic to be deterministic. The lacking source of randomness is a consequential limitation since many application domains, like games, lotteries, or random elections, require random sources. Given the Byzantine Fault-tolerance, generating random numbers should also be publicly-verifiable and tamper-resistant, but still hold the premises of being unpredictable.In this paper, we will provide an overview of the current research surrounding pseudo-random number generation on a decentralized network that satisfies those requirements.
With the features of decentralization and trustlessness and through distributed data storage, point-to-point transmission, and encryption algorithms, blockchain has shed new light on the security and protection of medical data, and it can resolve the contradiction between data sharing and privacy protection with proper security strategies. In this paper, we integrate the strengths of both blockchain and cloud computing and build the privacy protection scheme for medical data based on blockchain and cloud computing. This scheme introduces cloud computing and provides services to blockchain nodes with cloud server computing; meanwhile, it collects, analyzes, processes, and maintains medical data in the identity authentication interface and solves the insufficient computing abilities of some nodes in blockchain so as to verify the authenticity and reliability of data. The simulation experiment proves that the proposed scheme is effective. It can achieve the secure protection and integrity verification of medical data and address the problems of high computing complexity, data sharing, and privacy protection.
We consider a new blockchain empowered federated learning approach which uses wireless mobile miners at drones in the future sixth generation (6G) networks for a disaster response system. Our focus is on the blockchain latency, and energy consumption in the proposed architecture of the network of drones. Maintaining low delay in wireless communication between the drones is required to minimize blockchain forking events while performing blockchain operations. Therefore, we quantify the probability of occurrence of forking events to analyze the uncertainty of the system towards the additional energy wastage. The forked block (due to channel impairments or mobility) incurs re-computation energy. We develop pragmatic analyses of the expected energy consumption by considering the parameters like the number of miners as well as the power consumed during computing, block transfer and 6G channel dynamics for the system.
Xiantao Jiang, F. Richard Yu, Tian Song, Victor C. M. Leung
Video surveillance in intelligent transportation systems (ITSs) is in the rapid growth stage, where video analytics is a potential technology to improve the safety of the Internet of Autonomous Vehicles (IoAV). However, massive video data transmission and computation-intensive video analytics bring an overwhelming burden for vehicular networks. Moreover, owing to the unstable network connection, the video data are not always reliable, which makes data sharing a lack of security and scalability in IoAV. In this work, we first propose a video analytics framework, where the multiaccess edge computing (MEC) and blockchain technologies are integrated into IoAV to optimize the transaction throughput of the blockchain system as well as reducing the latency of the MEC system. Furthermore, based on deep reinforcement learning, the joint optimization problem is modeled as a Markov decision process (MDP), and the asynchronous advantage actor–critic (A3C) algorithm is adopted to solve this problem. Simulation results demonstrate that our approach can fast converge and significantly improve the performance of blockchain-enabled IoAV with MEC.
Critical infrastructure systems are vital to underpin the functioning of a society and economy. Due to the ever-increasing number of Internet-connected Internet-of-Things (IoT)/Industrial IoT (IIoT), and the high volume of data generated and collected, security and scalability are becoming burning concerns for critical infrastructures in industry 4.0. The blockchain technology is essentially a distributed and secure ledger that records all the transactions into a hierarchically expanding chain of blocks. Edge computing brings the cloud capabilities closer to the computation tasks. The convergence of blockchain and edge computing paradigms can overcome the existing security and scalability issues. In this article, we first introduce the IoT/IIoT critical infrastructure in industry 4.0, and then we briefly present the blockchain and edge computing paradigms. After that, we show how the convergence of these two paradigms can enable secure and scalable critical infrastructures. Then, we provide a survey on the state of the art for security and privacy and scalability of IoT/IIoT critical infrastructures. A list of potential research challenges and open issues in this area is also provided, which can be used as useful resources to guide future research.
Motivated by the increasingly powerful computing capabilities of end-user equipment, and by the growing privacy concerns over sharing sensitive raw data, a distributed machine learning paradigm known as federated learning (FL) has emerged. By training models locally at each client and aggregating learning models at a central server, FL has the capability to avoid sharing data directly, thereby reducing privacy leakage. However, the conventional FL framework relies heavily on a single central server, and it may fail if such a server behaves maliciously. To address this single point of failure, in this work, a blockchain-assisted decentralized FL framework is investigated, which can prevent malicious clients from poisoning the learning process, and thus provides a self-motivated and reliable learning environment for clients. In this framework, the model aggregation process is fully decentralized and the tasks of training for FL and mining for blockchain are integrated into each participant. Privacy and resource-allocation issues are further investigated in the proposed framework, and a critical and unique issue inherent in the proposed framework is disclosed. In particular, a lazy client can simply duplicate models shared by other clients to reap benefits without contributing its resources to FL. To address these issues, analytical and experimental results are provided to shed light on possible solutions, i.e., adding noise to achieve local differential privacy and using pseudo-noise (PN) sequences as watermarks to detect lazy clients.
Although the data trading platform has accelerated the flow of data, the current data trading platform still has many problems. According to the characteristics of the blockchain technology, from the aspects of the attack behavior in the blockchain and the security application of the blockchain technology in power transactions, this paper studies the security of the blockchain. Moreover, this article focuses on the privacy protection of the ciphertext strategy in the CP-ABE scheme, and protects the privacy information of the access strategy by designing appropriate ciphertext and key structures and access structure forms. In addition, the system efficiency is improved by computing outsourcing, and solutions to problems in outsourcing computing are proposed. Meanwhile, two efficient and flexible support policy hidden multi-authorization center access control schemes are constructed. Finally, this study analyzes the performance of the model through controlled experiments. The research results show that this scheme has excellent performance.
Iñigo Querejeta-Azurmendi, David Arroyo, Jorge López Hernández-Ardieta, Luis Hernández Encinas
This paper proposes NetVote, an internet voting protocol where usability and ease in deployment are a priority. We introduce the notion of strict coercion resistance, to distinguish between vote-buying and coercion resistance. We propose a protocol with ballot secrecy, practical everlasting privacy, verifiability and strict coercion resistance in the re-voting setting. Coercion is mitigated via a random dummy vote padding strategy to hide voting patterns and make re-voting deniable. This allows us to build a filtering phase with linear complexity, based on zero knowledge proofs to ensure correctness while maintaining privacy of the process. Voting tokens are formed by anonymous credentials and pseudorandom identifiers, achieving practical everlasting privacy, where even if dealing with a future computationally unbounded adversary, vote intention is still hidden. It is not assumed for voters to own cryptographic keys prior to the election, nor store cryptographic material during the election. This property allows voters not only to vote multiple times, but also from different devices each time, granting the voter a vote-from-anywhere experience. This paper builds on top of the paper published in CISIS’19. In this version, we modify the filtering. Moreover, we formally define the padding technique, which allows us to perform the linear filtering scheme. Similarly we provide more details on the protocol itself and include a section of the security analysis, where we include the formal definitions of strict coercion resistance and a game based definition of practical everlasting privacy. Finally, we prove that NetVote satisfies them all.
Zhangshuang Guan, Zhiguo Wan, Yang Yang, Yan Zhou · 5 authors
The disruptive blockchain technology is expected to have broad applications in many areas due to its advantages of transparency, fault tolerance, and decentralization, but the open nature of blockchain also introduces severe privacy issues. Since anyone can deduce private information about relevant accounts, different privacy-preserving techniques have been proposed for cryptocurrencies under the UTXO model, e.g., Zerocash and Monero. However, it is more challenging to protect privacy for account-model blockchains (e.g., Ethereum) since it is much easier to link accounts in the account-model blockchain. In this article, we proposeBlockMaze, an efficient privacy-preserving account-model blockchain based on zk-SNARKs. Along with dual-balance model, BlockMaze achieves strong privacy guarantees by hiding account balances, transaction amounts, and linkage between senders and recipients. Moreover, we provide formal security definitions and prove the security ofBlockMaze. Finally, we implement a prototype ofBlockMazebased on Libsnark and Go-Ethereum, and conduct extensive experiments to evaluate its performance. Our 300-node experiment results show that BlockMaze has high efficiency in computation and transaction throughput: one transaction verification takes about 14.2 ms, one transaction generation takes 6.1-18.6 seconds, and its throughput is around 20 TPS.
We discuss the challenge of achieving an auditable key management for cryptographic access control to high-value sensitive data. In such settings it is important to be able to audit the key management process - and in particular to be able to provide verifiable proofs of key generation. The auditable key management has several possible use cases in both civilian and military world. In particular, the new regulations for protection of sensitive personal data, such as GDPR, introduce strict requirements for handling of personal data and apply a very restrictive definition of what can be considered a personal data. Cryptographic access control for personal data has a potential to become extremely important for preserving industrial ability to innovate, while protecting subject’s privacy, especially in the context of widely deployed modern monitoring, tracking and profiling capabilities, that are used by both governmental institutions and high-tech companies. However, in general, an encrypted data is still considered as personal under GDPR and therefore cannot be, e.g., stored or processed in a public cloud or distributed ledger. In our work we propose an identity-based cryptographic framework that ensures confidentiality, availability, integrity of data while potentially remaining compliant with the GDPR framework.
Amira Kchaou, Samiha Ayed, Ryma Abassi, Sihem Guemara El Fatmi
In Ad-hoc Networks (VANETs), vehicles exchange safety and road information in order to reduce the number of accidents on the road and get the best updated information to optimize their road path. However, the secure communications face big challenges in the VANETs. In a previous work, we have proposed a distributed trust management scheme based on the blockchain technology in order to provide a secure vehicle communication by checking the correctness of the message. For this purpose, the Blockchain facilitates the sharing of secure in-formation or messages among vehicles. However, vehicles cannot share the resources with other entities using only the blockchain and cannot manage to access control their resources. In order to provide an access control policies of the resources requested by the vehicle, we propose a distributed access control model for vehicles based on smart contracts and ABAC model to share the resources through miners. Then, we evaluate the execution time and the storage of the proposal.
Existing (popular) blockchain architectures, including the widely used Ethereum and Hyperledger, are generally not designed to achieve conflicting properties such as anonymity and regulation, and transparency and confidentiality. In this article, we propose a privacy-preserving permissioned blockchain architecture (PPChain) that permits one to also introduce regulation, where PPChain's architecture is modified from that of Ethereum. Specifically, we integrate the cryptographic primitives (group signature and broadcast encryption), and adopt practical byzantine fault tolerance consensus protocol with a validate-record separation mechanism, as well as removing the transaction fee and mining reward. To show the utility of PPChain, we provide qualitative security and privacy analysis, and performance analysis. We also explain how PPChain can be deployed in regulation applications, using cryptocurrency, food supply chain, and sealed-bid auctions as examples.