Jianhong Zhang, Qijia Zhang, Shenglong Ji, Wenle Bai
As an emergent-architecture, mobile edge computing shifts cloud service to the edge of networks. It can satisfy several desirable characteristics for IoT systems. To reduce communication pressure from IoT devices, data aggregation is a good candidate. However, data processing in MEC may suffer from many challenges, such as unverifiability of aggregated data, privacy-violation and fault-tolerance. To address these challenges, we propose PVF-DA: privacy-preserving, verifiable and fault-tolerant data aggregation in MEC based on aggregator-oblivious encryption and zero-knowledge-proof. The proposed scheme can not only provide privacy protection of the reported data, but also resist the collusion between MEC server and corrupted IoT devices. Furthermore, the proposed scheme has two outstanding features: verifiability and strong fault-tolerance. Verifiability can make IoT device to verify whether the reported sensing data is correctly aggregated. Strong fault-tolerance makes the aggregator to compute an aggregate even if one or several IoTs fail to report their data. Finally, the detailed security proofs are shown that the proposed scheme can achieve security and privacy-preservation properties in MEC.
Blockchains are globally gaining traction and gradually disrupting the traditional transactional eco-systems by eliminating the non-value adding parties in the value chain. Although blockchains enables digital currency transactions, distributed consensus models and provenance, the problem of scalability, security and privacy has to be solved for the blockchains to be utilized in its full potential. Typically all the transactions recorded in blockchain are visible to all the participants. Even though some blockchain frameworks offers private transactions they still lack transactional privacy and confidentiality. Privacy preserving smart contracts is an emerging field which guarantees the privacy of transactions during runtime and ensures confidentiality as well. In this paper we analyze various frameworks and methodologies and propose a systematic way of choosing the right privacy preserving smart contract framework for enterprise needs and requirements.
Edge computing is a promising paradigm to expand the capability of Internet of Things (IoT) devices by computation offloading. To establish a distributed ledger to provide a secure and trusted environment for the resource allocation between edge servers and IoT devices, the emerging blockchain technology has attracted a lot of attention recently. However, in practice, edge resource allocation in IoT devices often involves multi-layer structures, which poses a challenge due to information incompleteness among different layers. Moreover, how to design a suitable and efficient blockchain framework for hierarchical resource allocation markets is a critical issue. In this paper, we apply blockchain to propose a secure and efficient hierarchical resource allocation framework for edge computing. First, we study the edge computing resource allocation problem in the hierarchical market of IoT devices, in which the IoT devices beyond the coverage of Access Points can participate in the resource allocation through middlemen. To solve the problem, a smart contract-based hierarchical auction mechanism is developed. The edge computing resources allocated in the top market can be continually reallocated to the sub-markets based on the mechanism, which then leads an efficient solution that maximizes the social welfare of the whole participants. Moreover, the mechanism is implemented as a smart contract in the blockchain, which enforces the rule of the hierarchical auction in a non-deniable and automated manner. Finally, the extensive simulations demonstrate the correctness and performance of the proposed mechanism.
Aug 1, 2020·2020 7th IEEE International Conference on Cyber Security and Cloud Computing (CSCloud)/2020 6th IEEE International Conference on Edge Computing and Scalable Cloud (EdgeCom)
Smart health has attracted a huge amount of attention nowadays with the advancement of information and communications technology. Meanwhile, the medical data is imperative to support smart health techniques. However, the storage of medical data faces serious security and privacy issues from the hacktivists, cloud service providers and even medical institutions. Therefore, we propose a novel data repository named Derepo to address these issues by securing the storage with the decentralized access control mechanism and preserving privacy via the homomorphic encryption scheme. We adopt the distributed ledger technology to endow the access control mechanism with trustworthy properties such as Byzantine fault tolerance. Besides, we utilize the fully homomorphic encryption scheme to protect data privacy and preserve the computability in the meanwhile. The design of Derepo is user-centric. Only the data owner can make the access control policy and decrypt their data while the authorized third parties can enforce the data processing processes on their encrypted data without knowing the original values. Furthermore, the prototype of Derepo is evaluated by security analysis and demonstrates the feasibility.
Evidence is a tangible demonstrative artifact that proves a fact and shapes the investigation of various misconduct cases involving for instance corruption, misbehavior, or violation. It is imperative to maintain proper evidence management to guarantee the admissibility of an evidence in a court of law. Chain of custody forms the forensic link of evidence sequence of control, transfer, and analysis to preserve evidence's integrity and to prevent its contamination. Blockchain, a distributed tamper-resistant ledger can be leveraged to offer a decentralized secure digital evidence system. In this paper, we propose a secure chain of custody framework by utilizing the blockchain technology to store evidence metadata while the evidence is stored in a reliable storage medium. The framework is built on top of a private Ethereum blockchain to document every transmission from the moment the evidence is seized, thus ensuring that evidence can only be accessed or possessed by authorized parties. The framework is integrated with the digital evidence system where evidence is physically stored and locked using smart locks. To secure the sequence of evidence submission and retrieval, only an authorized party can possess the key to unlock the evidence. Our proposed framework offers a secure solution that maintains evidence integrity and admissibility among multiple stakeholders such as law enforcement agencies, lawyers, and forensic professionals. The research findings shed light on hidden opportunities for the efficient usage of blockchain in other realms beyond finance and cryptocurrencies.
R. Sujatha, C. Navaneethan, Rajesh Kaluri, S. Prasanna
The blockchain concept relies on cryptography that links the blocks and each block holds the cryptographic hash of a previous block and timestamp along with data to be transferred. Blockchain is an emerging technology which has gained interest from various sources like energy industries, startups, financial institutions, supply firms, national and international governments, and so on. These sources are aiming, from different backgrounds such as voting, taxation and land registration, to identify blockchain, which has potential drives to bring substantial welfares and innovation. The blockchain helps people to keep data secure by allowing health record data to be moved whenever they need without any illegal activities like forgery, theft and malice. The chapter provides information on the latest digital payments. It focuses on the operative mechanism of Bitcoin, blockchain technology and describes the scope of this application. Bitcoins are transactions stored in encrypted form with certain conditions for financial transactions.
K Arjun, N. M. Sreenarayanan, K. Sampath Kumar, Raajay Viswanathan
Distributed computing involves many loosely coupled computing platforms, located in different places connected in a network by using LAN or WAN for achieving a common goal. The computing entities have autonomous behavior of computing different operations by using their own computing power and storage capacity. Distributed computing systems can run on homogenous and heterogeneous computing platforms, different hardware that is provided by several vendors and software may use a variety of standard based software elements. These single autonomous systems use independent fundamental software and various communication protocols. Distributed computing requires support from various programming languages and operating system levels. Communication between these independent systems conceptuale through complex message passing methods. Dedicated lightweight processes all have the capacity to communicate with each other via message passing. The nature of distributed systems is unpredictable because they use complex algorithms making it impossible to solve using a deterministic algorithm. Algorithms are different strong applied mathematical game theoretic complex algorithms for placing a single computing entity in the distributed system. The result of the complex placement of the computing entity leads to higher security. Each single entity contributes their job result only without knowing the other entities connected in the network computing pool. In the computing system’s hardware diagnosis of participating computing node is performed by using underlying software that running on many nodes. It is hard to predict the behavior of full or individual components so that distributed computing is invulnerable, non-deterministic and secure. The advancement of distributed computing enables new technology for invulnerability, reliability and performance. Blockchain is the current underlying technology, collaborating used for distributed ledgers. One of the popular applications of blockchain is cryptocurrency – Bitcoin. In Bitcoin each node can act as a distributed system. All the participating nodes share their transactions and each of them keeps its own personal ledger. The application of the blockchain extends to all areas like government, business, finance, etc.
Nowadays, blockchain is developing as a secure and trustworthy platform for secure information sharing in areas of application like banking, supply chain management, food industry, energy, the Internet, and medical services. Besides, the blockchain can be described in a decentralized manner as an immutable ledger for recording data entries. Furthermore, this new technology has been developed to interrupt a variety of data-driven fields, including the health sector. However, blockchain refers to the distributed ledger technology, which constitutes an innovation in the information recording and sharing without a trusted third party. In this paper, blockchain and Distributed Ledger-based Improved Biomedical Security system (BDL-IBS) has been proposed to enhance the privacy and data security across healthcare applications. Further, our goal is to make it possible for patients to use the data to support their care and to provide strong consent systems for sharing data among different organizations and applications, since this includes managing and accessing a high amount of medical information, and this technology can maintain data to ensure reliability. Finally, results show that new blockchain-based digital platforms allow for fast, easy, and seamless interactions between data suppliers to enhance privacy and data security, including for patients themselves.
Artificial intelligence (AI) has demonstrated huge potential in a variety of real-world applications. However, some significant considerations like fairness, transparency and trustworthiness are still challenging when applying AI to trust-oriented applications such as E-voting. E-voting plays a significant role in democratic societies, which requires voters and initiators have strong mutual trust. In this paper, we aim to facilitate the consolidation of AI ecosystems by developing a blockchain-based traceable self-tallying e-voting system. We take advantage of an event-oriented linkable group signature and a homomorphic time-lock puzzle to balance the anonymity and accountability, and the voting scale and efficiency of an e-voting system. The proposed e-voting protocol supports additional functions like multi-choice and self-tallying. We prove that the proposed protocol satisfies anonymity, time-bounded privacy, linkability and full-traceability. We also evaluate the time cost of off-chain operations and the gas cost of on-chain operations, which show the proposed e-voting protocol is practical and can be adopted in real-world applications.
Increased collaborative production and dynamic selection of production partners within industry 4.0 manufacturing leads to ever-increasing automatic data exchange between companies. Automatic and unsupervised data exchange creates new attack vectors, which could be used by a malicious insider to leak secrets via an otherwise considered secure channel without anyone noticing. In this paper we reflect upon approaches to prevent the exposure of secret data via blockchain technology, while also providing auditable proof of data exchange. We show that previous blockchain based privacy protection approaches offer protection, but give the control of the data to (potentially not trustworthy) third parties, which also can be considered a privacy violation. The approach taken in this paper is not utilize centralized data storage for data. It realizes data confidentiality of P2P communication and data processing in smart contracts of blockchains.
Murshedul Arifeen, Abdullah Al Mamun, M. Shamim Kaiser, Mufti Mahmud
Contact tracing has become an indispensable tool of various extensive measures to control the spread of COVID-19 pandemic due to novel coronavirus. This essential tool helps to identify, isolate and quarantine the contacted persons of a COVID-19 patient. However, the existing contact tracing applications developed by various countries, health organizations to trace down the contacts after identifying a COVID-19 patient suffers from several security and privacy concerns. In this work, we have identified those security and privacy issues of several leading contact tracing applications and proposed a blockchain-based framework to overcome the major security and privacy challenges imposed by the applications. We have discussed the security and privacy measures that are achieved by the proposed framework to show the effectiveness against the security and privacy issues raised by the existing mobile contact tracing applications.
Vehicular fog computing has emerged as a complementary framework for edge computing by leveraging the under-utilized computational resources of vehicles. However, how to reduce task offloading delay, queuing delay, and handover cost with incomplete information while simultaneously ensuring privacy, fairness, and security remains an open issue. In this paper, we develop a secure and intelligent task offloading framework to address these challenges. We exploit blockchain and smart contract to facilitate fair task offloading and mitigate various security attacks. Then, we design a subjective logic-based trustfulness metric to quantify the possibility of task offloading success, and develop a trustfulness assessment mechanism. An online learning-based intelligent task offloading algorithm named QUeuing-delay aware, handOver-cost aware, and Trustfulness Aware Upper Confidence Bound (QUOTA-UCB) is proposed, which can learn the long-term optimal strategy and achieve a well-balanced tradeoff among task offloading delay, queuing delay, and handover cost. Finally, extensive theoretical analysis and simulations are carried out to demonstrate the reliability, feasibility, and efficiency of the proposed secure and intelligent task offloading scheme.
Raza Nowrozy, A. S. M. Kayes, Paul Watters, Mamoun Alazab · 7 authors
In the healthcare setting, electronic databases are extensively used, specifically for storing and recalling data for improved medical interventions. However, the currently employed systems in healthcare organizations, such as hospitals and laboratories, have major security issues such as data breaches, unauthorized access, and loss of personal information. Blockchain has been regarded as an effective alternative for providing a secure data sharing for healthcare and other institutions. This is due to the cryptographic features associated with the blockchain technology that can make data breaching difficult and improve data access and sharing. However, it requires a robust and secure framework for effective operations. In order to understand the needs and requirements for a blockchain-based framework for data sharing in the healthcare, an extensive overview of the literature has been carried out, and a proposal is drafted to understand the concepts behind the data sharing framework. This is performed to delineate the requirements of an effective framework for data sharing based on blockchain. This will serve as a cornerstone for the actual research, where the associated requirements would be further researched and utilized in proposing a general data sharing framework. Through a survey of the literature, it has been identified that blockchain-based data sharing can provide better security on access control. Open research issues are also discussed, along with the existing literature.
Driverless parking, an influential application of Mobility as a Service (MaaS) model, is one of the clear early benefits for autonomous vehicles, given often narrow spaces and multiple potential hazards (such as pedestrians stepping out from in between other vehicles). In recent years, real momentum has been building up for designing automated parking models for vehicles. However, in such an autonomous parking design, location privacy and identity privacy issues are always overlapping due to the improper sharing of data. Most existing studies barely investigate and poorly address such privacy issues. Motivated by this, we develop (and evaluate) an experience-driven, secure and privacy-aware framework of parking reservations for automated cars. Our idea of using differential privacy with zero-knowledge proof provides both security and privacy guarantees to users. Furthermore, the performance of the developed model is enhanced by exploiting reinforcement learning approach such that the utility of the system and the parking reservation rate can be maximized. Extensive evaluation demonstrates the superiority of the proposed model.
Financial technology (FinTech) has been playing an increasingly critical role in driving modern economies, society, technology, and many other areas. Smart FinTech is the new-generation FinTech, largely inspired and empowered by data science and new-generation AI and (DSAI) techniques. Smart FinTech synthesizes broad DSAI and transforms finance and economies to drive intelligent, automated, whole-of-business and personalized economic and financial businesses, services and systems. The research on data science and AI in FinTech involves many latest progress made in smart FinTech for BankingTech, TradeTech, LendTech, InsurTech, WealthTech, PayTech, RiskTech, cryptocurrencies, and blockchain, and the DSAI techniques including complex system methods, quantitative methods, intelligent interactions, recognition and responses, data analytics, deep learning, federated learning, privacy-preserving processing, augmentation, optimization, and system intelligence enhancement. Here, we present a highly dense research overview of smart financial businesses and their challenges, the smart FinTech ecosystem, the DSAI techniques to enable smart FinTech, and some research directions of smart FinTech futures to the DSAI communities.
Jiaqi Wang, Ning Lu, Qingfeng Cheng, Lu Zhou · 5 authors
With the development of communication 5G networks and technologies, spectrum resources are increasingly scarce. The scarcity of the spectrum resource makes market-driven spectrum auction become an important means of spectrum allocation, and due to the complexity of the network environment, the security of spectrum auctions can not be ignored. Most existing secure spectrum auction schemes introduce a semi-honest agent to complete spectrum auction. However, the hypothetical semi-honest model does not guarantee the security of spectrum auction in the actual application scenario, which may lead to potential security threats: the agent may reveal the privacy of bidders, agent or auctioneer may collude with the bidder to manipulate the spectrum auction, and so on. In this paper, a secure spectrum auction scheme without a trusted party is proposed based on the smart contract technology, and the smart contract written into the blockchain replaces the traditional semi-honest agent to cooperate with the auctioneer server to complete the auction. In order to ensure the security of our scheme, a secure spectrum auction protocol is designed, in which the Software Guard Extensions (SGX) technology and Paillier cryptosystem are used to protect the privacy of bidders. Public verification is provided in our protocol by using extensive Pedersen commitment, which prevents the auctioneer server and the bidder from colluding with each other and verifies group bid sum values. Finally, the security analysis is given to propose several types of attacks that can be defended. Besides, theoretical analysis and simulation experiments of our protocol are also provided.
Rajesh Kumar, Abdullah Aman Khan, Zhang, Sinmin, Jay Kumar · 10 authors
With the increase of COVID-19 cases worldwide, an effective way is required to diagnose COVID-19 patients. The primary problem in diagnosing COVID-19 patients is the shortage and reliability of testing kits, due to the quick spread of the virus, medical practitioners are facing difficulty in identifying the positive cases. The second real-world problem is to share the data among the hospitals globally while keeping in view the privacy concerns of the organizations. Building a collaborative model and preserving privacy are the major concerns for training a global deep learning model. This paper proposes a framework that collects a small amount of data from different sources (various hospitals) and trains a global deep learning model using blockchain-based federated learning. Blockchain technology authenticates the data and federated learning trains the model globally while preserving the privacy of the organization. First, we propose a data normalization technique that deals with the heterogeneity of data as the data is gathered from different hospitals having different kinds of Computed Tomography (CT) scanners. Secondly, we use Capsule Network-based segmentation and classification to detect COVID-19 patients. Thirdly, we design a method that can collaboratively train a global model using blockchain technology with federated learning while preserving privacy. Additionally, we collected real-life COVID-19 patients' data open to the research community. The proposed framework can utilize up-to-date data which improves the recognition of CT images. Finally, we conducted comprehensive experiments to validate the proposed method. Our results demonstrate better performance for detecting COVID-19 patients.
Open access
3 source records
COVID-19 diagnosis using AI
Artificial Intelligence in Healthcare and Education
Abstract In recent years, the Internet of things (IoT) equipment has grown rapidly, and the scale of the IoT has also expanded. The IoT is deployed in the system in a centralized manner. At the same time that massive data has put a certain amount of pressure on the storage, the open network environment has not fully protected the privacy of the IoT data, which has become one of the important factors restricting the development of the IoT. Blockchain is a point‐to‐point distributed ledger technology based on cryptographic algorithms. The characteristics of decentralization, tamper resistance, anonymity, and public verifiability can alleviate data security issues in IoT. Ring signature and proxy reencryption are common encryption technologies in the field of privacy protection. Therefore, this article combines blockchain technology with ring signature and proxy reencryption to propose a privacy protection solution for the IoT. Through this solution, the data authorized for sharing in the IoT is transmitted in the system in the form of ciphertext, the identity information of the data sender is protected, and the distributed ledger eases the pressure of mass data storage on a centralized server. The correctness and safety of the proposed scheme are also analyzed.
After the European Union's new General Data Protection Regulation (GDPR) became applicable in May 2018, concerns about the legal compliance of public blockchain systems with rights guaranteed by GDPR have emerged, e.g., on the "right to be forgotten". In order to better understand how the blockchain sector sees the challenges raised by GDPR and how such their communications could influence their users, this paper reports our data-driven analysis of GDPR-related public online communications of blockchain developers and service providers. Our analysis covers 314 public blockchain systems, and two different online communication channels: legal documents in-cluding privacy policies, T&C (Terms and Conditions) documents and other similar legal documents published on systems' official websites and public tweets of their official Twitter accounts. Our analysis revealed that only a minority (86/314 ≈ 27.5%) of the investigated blockchain systems had covered GDPR at least once using one or both communication channels. Among the 86 systems, only 27 systems (8.6%) had at least one legal document that actually talks about GDPR for the corresponding blockchain system. We noticed a systematic lack of detail about why and how the GDPR compliance issue was addressed, and most systems made questionable statements about GDPR compliance. The results are surprising considering that the GDPR was enacted in 2016 and has been in effect since May 2018.
Academic publication of latest research results are crucial to advance the development of all disciplines. However, the current academic publication procedure lacks transparency in the review process, and reviewers do not have strong incentives to provide quality reviews for their peers. This may lead to misconducts in the review process, e.g. an anonymous reviewer may give biased comments to a paper without being noticed since the comments are seldom published for evaluation. In addition, it is ironic that the research community has to pay a lot to access papers reviewed by the community for free, though free sharing of research results is important for research advances.To address the above problems, we propose Open-Pub, a decentralized, transparent yet privacy-preserving academic publication scheme based on the blockchain technology. The blockchain promises transparency in the review process and provides an incentive mechanism based on cryptocurrency, but the privacy requirement in the double-blind review process still needs to be fulfilled. To this end, we first design a threshold identity-based group signature (TIBGS) using verifiable secret sharing to protect identity confidentiality. Then we develop a strong double-blind procedure to protect the identities of authors and reviewers. With this strong double-blind procedure, authors can choose to submit papers anonymously, and validators distribute papers anonymously to reviewers on the blockchain according to their research interests. This process is publicly recorded and traceable on the blockchain so as to realize transparent peer preview. To evaluate its efficiency, we implement Open-Pub based on Ethereum and conduct comprehensive experiments to evaluate its performance, including computation costs and processing delay. The experiment results show that Open-Pub is highly efficient in computation and processing anonymous transactions.
Sylvain Chatel, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Jean‐Pierre Hubaux
In the digital era, users share their personal data with service providers to obtain some utility, e.g., access to high-quality services. Yet, the induced information flows raise privacy and integrity concerns. Consequently, cautious users may want to protect their privacy by minimizing the amount of information they disclose to curious service providers. Service providers are interested in verifying the integrity of the users' data to improve their services and obtain useful knowledge for their business. In this work, we present a generic solution to the trade-off between privacy, integrity, and utility, by achieving authenticity verification of data that has been encrypted for offloading to service providers. Based on lattice-based homomorphic encryption and commitments, as well as zero-knowledge proofs, our construction enables a service provider to process and reuse third-party signed data in a privacy-friendly manner with integrity guarantees. We evaluate our solution on different use cases such as smart-metering, disease susceptibility, and location-based activity tracking, thus showing its versatility. Our solution achieves broad generality, quantum-resistance, and relaxes some assumptions of state-of-the-art solutions without affecting performance.
In this work we develop a rewarding framework that can be used as a building block in crowd-sensing applications. Our protocol allows users to submit data and obtain Bitcoin payments in a privacy-preserving manner, preventing curious providers from linking the data or the payments back to the user. At the same time, we thwart malicious user behavior such as double-redeeming attempts where a user tries to obtain rewards for multiple submissions of the same data. More importantly, we ensure the fairness of the exchange; by relying on the Blockchain, we eliminate the trust placed on third parties in traditional fair exchange protocols. Finally, our system is highly efficient as most of the protocol steps do not utilize the Blockchain network. When they do, we only rely on simple Bitcoin transactions as opposed to prior works that are based on the use of highly complex smart contracts.