Crowdsourcing is a process wherein an individual or an organisation utilizes\nthe talent pool present over the Internet to accomplish their task. The\nexisting crowdsourcing platforms and their reputation computation are\ncentralised and hence prone to various attacks or malicious manipulation of the\ndata by the central entity. A few distributed crowdsourcing platforms have been\nproposed but they lack a robust reputation mechanism. So we propose a\ndecentralised crowdsourcing platform having an immutable reputation mechanism\nto tackle these problems. It is built on top of Ethereum network and does not\nrequire the user to trust a third party for a non malicious experience. It also\nutilizes IOTAs consensus mechanism which reduces the cost for task evaluation\nsignificantly.\n
Li Peng, Wei Feng, Zheng Yan, Yafeng Li · 6 authors
Permissionless blockchain, as a kind of distributed ledger, has gained considerable attention because of its openness, transparency, decentralization, and immutability. Currently, permissionless blockchain has shown a good application prospect in many fields, from the initial cryptocurrency to the Internet of Things (IoT) and Vehicular Ad-Hoc Networking (VANET), which is considered as the beginning of rewriting our digital infrastructure. However, blockchain confronts some privacy risks that hinder its practical applications. Though numerous surveys reviewed the privacy preservation in blockchain, they failed to reveal the latest advances, nor have they been able to conduct a unified standard comprehensive classification of the privacy protection of permissionless blockchain. Therefore, in this paper, we analyze the specific characteristics of permissionless blockchain, summarize the potential privacy threats, and investigate the unique privacy requirements of blockchain. Existing privacy preservation technologies are carefully surveyed and evaluated based on our proposed evaluation criteria. We finally figure out open research issues as well as future research directions from the perspective of privacy issues.
Siming Wang, Dongdong Ye, Xumin Huang, Rong Yu · 6 authors
Vehicular edge computing (VEC) extends edge computing to vehicular networks by exploiting computation resources of vehicles to offload tasks from other vehicles and pedestrians. However, VEC faces several critical challenges such as the potential security issues caused by untrusted and opaque environment and the lack of incentive mechanism under asymmetric information scenario. To solve the above challenges, we propose a consortium blockchain for secure resource sharing in VEC. We first design multi-step smart contracts to achieve secure resource sharing and defend against the malicious behaviours of service requesters and vehicles with selfish purposes. Then, a byzantine fault tolerance-based proof-of-stake (BFT-based PoS) consensus protocol is applied in consortium blockchain to reach consensus efficiently. Furthermore, we design a contract-based incentive mechanism to motivate vehicles to share their computation resources with service requesters. The optimal contracts are derived to maximize the service requesters' expected utility as well as social welfare. Finally, simulation results demonstrate that the proposed incentive mechanism is more effective and efficient than the traditional schemes.
Cloud-based storage services have been the dominating outsourcing solution for both individuals and organizations to share data digitally. Despite the advantages, users must rely on storage services for data confidentiality, data access control, user privacy, and data availability. Whereas data confidentiality can be protected by advanced encryption algorithms, the rest remain challenging. First, in existing centralized storage services, even though data access controls are mainly defined by data owners, they are maintained and enforced by the services, which can deny data retrieval requests of authorized users or allow requests of illegitimate users. Second, the identity of a user is often known to the services to verify its eligibility to access requested data according to the access control, thus making the user traceable in the system. More importantly, the lack of anonymity may make users reluctant to use such services in sensitive contexts. Third, a huge amount of data is daily generated and stored on a centralized party, simultaneously serving requests from many users, which may cause a collapse of the system during peak periods. To address all these concerns, we propose a privacy-preserving blockchain-based data sharing platform for the InterPlanetary File System (IPFS), a content-addressable peer-to-peer storage system. The platform allows protecting both user anonymity, data confidentiality, and provides high data availability due to being deployed upon the IPFS network.
With the rapid development and application of information technology, blockchain technology (BT) has become an important means to promote the integration of the real economy and the digital economy. BT reached a certain level of development for application in asset transactions, finance, and traceability. However, existing technology provides no reasonable trading method and application framework for the use of BT in peer-to-peer (P2P) transactions. This article proposed a blockchain-based P2P transaction method, which we simulated using Go programming language. We apply BT to smart contracts and electronic transactions, and introduce a mechanism of association between digital assets and physical assets. The proposed method can ensure the data security and establish trust among entities. It can also reduce business divergence and costs. For the sensitive data involved in a transaction, we propose an encoding algorithm to prevent the leaks of sensitive data in circulation. The calculations of the matrices of the algorithm can use the computing resources of all nodes in the blockchain to calculate in parallel, and then summarize the results. This makes full use of the massive graphic processing unit resources in the blockchain, and makes the calculation valuable.
Gaolei Li, Mianxiong Dong, Laurence T. Yang, Kaoru Ota · 6 authors
Edge computational intelligence, integrating artificial intelligence (AI) and edge computing into Internet of Things (IoT), will generate many scattered knowledge. To enable auditable and delay-sensitive IoT services, these knowledge will be shared among decentralized intelligent network edges (DINEs), end users, and supervisors frequently. Blockchain has a promising ability to provide a traceable, privacy-preserving and tamper-resistant ledger for sharing edge knowledge. However, due to the complicated environments of network edges, knowledge sharing among DINEs still faces many challenges. Firstly, the resource limitation and mobility of DINEs impede the applicability of existing consensus tricks (e.g., Poof of Work, Proof of Stake, and Paxos) of blockchain. Secondly, the adversaries may eavesdrop the content of edge knowledge or entice the blockchain to forks using some attacking models (like man-in-the-middle attack, denial of services, etc.). In this article, an user-centric blockchain (UCB) framework is proposed for preserving edge knowledge sharing in IoT. Significant superiorities of UCB benefit from the proof of popularity (PoP) consensus mechanism, which is more energy-efficient and fast. Security analysis and experiments based on Raspberry Pi 3 Model B demonstrate its feasibility with low block generating delay and complexity.
Location-based services (LBS) bring convenience to people's lives but are also accompanied with privacy leakages. To protect the privacy of LBS users, many location privacy protection algorithms were proposed. However, these algorithms often have difficulty to maintain a balance between service quality and user privacy. In this paper, we first overview the shortcomings of the existing two privacy protection architectures and privacy protection technologies, then we propose a location privacy protection method based on blockchain. Our method satisfies the principle of k-anonymity privacy protection and does not need the help of trusted third-party anonymizing servers. The combination of multiple private blockchains can disperse the user's transaction records, which can provide users with stronger location privacy protection and will not reduce the quality of service. We also propose a reward mechanism to encourage user participation. Finally, we implement our approach in the Remix blockchain to show the efficiency, which further indicates the potential application prospect for the distributed network environment.
Ehab Zaghloul, Tongtong Li, Matt W. Mutka, Jian Ren
Current systems used by medical institutions for the management and transfer of Electronic Medical Records (EMRs) can be vulnerable to security and privacy threats. In addition, these systems are centralized, often lack interoperability, and give patients limited or no access to their own EMRs. In this article, we propose a novel distributed data sharing scheme that applies the security benefits of blockchain to address these concerns. We deploy smart contracts on Ethereum blockchain and utilize a distributed storage system to alleviate the dependence on the record-generating institutions to manage and share patient records. To preserve privacy of patient records, we implement our smart contracts as a method to allow patients to verify attributes prior to granting access rights. Our proposed scheme also facilitates selective sharing of medical records among staff members that belong to different levels of a hierarchical institution. We provide extensive security, privacy, and evaluation analyses to show that our proposed scheme is both efficient and practical.
Wenlei Qu, Lei Wu, Wei Wang, Zhaoman Liu · 5 authors
Summary Compared with traditional voting methods, electronic voting can effectively avoid the phenomenon of fraud for personal gains in various links, it is faster and more accurate in the tallying stage. However, many electronic voting systems have many problems such as inability to verify ballots, easy to be forged, and low computing efficiency. We propose an electronic voting protocol based on homomorphic signcryption and blockchain. The protocol makes the voting process public through blockchain and replaces the traditional trusted third party with the smart contract. It uses the homomorphic encryption algorithm and the homomorphic signcryption algorithm to encrypt and sign the ballot and uses their aggregation properties to perform homomorphic tally on the encrypted votes. This not only reduces the excessive burden on the voters but also improves the voting efficiency. At the same time, it can satisfy the security of electronic voting, and the amount of calculation is small, so it is more convenient and flexible to use in large‐scale voting.
Marten Sigwart, Michael Borkowski, Marco Peise, Stefan Schulte · 5 authors
Abstract As data collected and provided by Internet of Things (IoT) devices power an ever-growing number of applications and services, it is crucial that this data can be trusted. Data provenance solutions combined with blockchain technology are one way to make data more trustworthy by providing tamper-proof information about the origin and history of data records. However, current blockchain-based solutions for data provenance fail to take the heterogeneous nature of IoT applications and their data into account. In this work, we identify functional and non-functional requirements for a secure and extensible IoT data provenance framework, and conceptualise the framework as a layered architecture. Evaluating the framework using a proof-of-concept implementation based on Ethereum smart contracts, we conclude that our framework can be used to realise data provenance concepts for a wide range of IoT use cases. While blockchain technology generally poses constraints on scalability and privacy, we discuss multiple solutions aiming to overcome these issues.
Learning from data owned by several parties, as in federated learning, raises challenges regarding the privacy guarantees provided to participants and the correctness of the computation in the presence of malicious parties. We tackle these challenges in the context of distributed averaging, an essential building block of federated learning algorithms. Our first contribution is a scalable protocol in which participants exchange correlated Gaussian noise along the edges of a network graph, complemented by independent noise added by each party. We analyze the differential privacy guarantees of our protocol and the impact of the graph topology under colluding malicious parties, showing that we can nearly match the utility of the trusted curator model even when each honest party communicates with only a logarithmic number of other parties chosen at random. This is in contrast with protocols in the local model of privacy (with lower utility) or based on secure aggregation (where all pairs of users need to exchange messages). Our second contribution enables users to prove the correctness of their computations without compromising the efficiency and privacy guarantees of the protocol. Our verification protocol relies on standard cryptographic primitives like commitment schemes and zero knowledge proofs.
Blockchain has led to a new way of storing data and guaranteeing data integrity and transparency. However, tensions still remain between blockchain and the current legal system, especially data protection law. This paper chooses the General Data Protection Regulation (GDPR) in the European Union to identify how blockchain can be compatible with the principles of modern data protection law and if blockchain can also be a way through which to achieve legal objectives. Finally, this paper proposes standardisation as a way to mitigate blockchain’s drawbacks and to leverage its advantages.
In this note, we remark that the aggregation property of the BLS signature scheme yields an efficient Content Extraction Signature (CES). This construction can be used to build digital credentials that support selective disclosure in various settings. Interestingly, this construction is efficient and well suited to build credential issuance schemes with various applications in the client-server or in the distributed ledger models. Finally, we sketch a protocol that combines the CES with the use of a NIZK which allows to prove predicate satisfaction on claims extracted from a credential, while keeping the data secret.
Smart vehicles can cooperate in teams to perform crowdsensing tasks in smart cities. A critical challenge in this regard is to build a secure model for nondeterministic vehicle teams to achieve maximum social welfare. Although several crowdsensing models have been proposed, none of them has focused on real-time vehicle teamwork. In this article, to the best of our knowledge, we propose the first secure model, called blockchain-based nondeterministic teamwork cooperation (BNTC), for nondeterministic teamwork cooperation in a vehicular crowdsensing system. We model the system as a multiconditional NP-complete problem by explicitly considering the dynamic features of task issuers and workers. To solve the problem, we propose the winning teams selected (WTS) algorithm based on a reverse auction and utilize a knapsack-based method to solve the models. We consider the credit of teams for determining the payment. Thus, we propose a credit-based team payment (CTP) algorithm for BNTC to maximize the welfare of the system. We also propose a general blockchain-based framework to address trust issues and security challenges to make the method suitable for use in practical applications. Based on theoretical analyses and extensive simulations, we demonstrate that the proposed model performs better than the baselines and can achieve the maximum social welfare. Implementation with Ethereum suggests our model can operate within a reasonable cost.
Due to the increasing medical data for coronary heart disease (CHD) diagnosis, how to assist doctors to make proper clinical diagnosis has attracted considerable attention. However, it faces many challenges, including personalized diagnosis, high dimensional datasets, clinical privacy concerns and insufficient computing resources. To handle these issues, we propose a novel blockchain-enabled contextual online learning model under local differential privacy for CHD diagnosis in mobile edge computing. Various edge nodes in the network can collaborate with each other to achieve information sharing, which guarantees that CHD diagnosis is suitable and reliable. To support the dynamically increasing dataset, we adopt a top-down tree structure to contain medical records which is partitioned adaptively. Furthermore, we consider patients' contexts (e.g., lifestyle, medical history records, and physical features) to provide more accurate diagnosis. Besides, to protect the privacy of patients and medical transactions without any trusted third party, we utilize the local differential privacy with randomised response mechanism and ensure blockchain-enabled information-sharing authentication under multi-party computation. Based on the theoretical analysis, we confirm that we provide real-time and precious CHD diagnosis for patients with sublinear regret, and achieve efficient privacy protection. The experimental results validate that our algorithm {outperforms} other algorithm benchmarks on running time, error rate and diagnosis accuracy.
Vehicular communication systems (VCS) are likely to play an increasingly important role in future smart city design, for example by improving road safety and traffic efficiency. However, there are underpinning security and privacy challenges, which may also result in under-utilization of vehicular data. In this paper, we introduce a new cryptographic primitive, namely: blockchain-based proxy re-encryption with equality test. Specifically, the proposed approach is designed to achieve reliable matching results by leveraging smart contracts, as well as efficient data sharing and privacy-preserving by combining the function of public-key encryption with equality test and proxy re-encryption. We also implement a prototype of the proposed approach and evaluate its performance with those of three other competing approaches. A comparative summary with three other competing approaches demonstrate that the proposed approach achieves all four features (i.e., decentralization, flexibility, non-interaction, and re-encryption). Findings from the prototype evaluation (using hyperledger fabric v1.4.2 as the test blockchain platform, and the fabric-sample repository) also demonstrate the utility of the proposed approach in practice.
As the key platform to deal with big data, Hadoop cannot fully protect data security of users by relying on a single Kerberos authentication mechanism. In addition, the single Namenode has disadvantages such as single point failure, performance bottleneck and poor scalability. To solve these problems, a big data security protection scheme is proposed. In this scheme, blockchain technology is adopted to deploy distributed Namenode server cluster to take joint efforts to safeguard the metadata and to allocate access tasks of users. We also improved the heartbeat model to collect user behavior so as to make a faster response to Datanode failure. The smart contract conducts reasonable allocation of user role through the judgment of user tag and risk value. It also establishes a tracking chain of risk value to monitor user behavior in real time. Experiments show that this scheme can better protect data security in Hadoop. It has the advantage of metadata decentralization and the data is hard to be tampered.