Blockchain is a decentralized transaction and data management technology. It was developed for the world's first cryptocurrency known as Bitcoin in 2008. The reason behind its popularity was its properties which provide pseudonymity, security, and data integrity without third-party intervention. Initially, most of the researches were focused on the Bitcoin system and its limitation, but later other applications of Blockchain e.g. smart contracts and licensing [1] also got famous. Blockchain technology has the potential to change the way how transactions are conducted in daily life. It is not limited to cryptocurrencies but could be possibly applied in various environments where any forms of transactions are done. This article presents a comprehensive overview of Blockchain technology, its development, applications, security issues, and their countermeasures. In particular, the security towards illegal data insertion and the countermeasures is focused. Our analysis of countermeasures of illegal data insertion can be combined for increased efficiency. After the introduction of the Blockchain and consensus algorithm, some famous Blockchain applications and expected future of Blockchain are deliberated. Then, the technical challenges of Blockchain are discussed, in which the main focus here is on the security and the data insertion in Blockchain. The review of the possible countermeasures to overcome the security issues related to data insertion are elaborated.
Yan Zhang, Bing Li, Ben Liu, Jiaxin Wu · 6 authors
The Internet of Things (IoT) benefits our lives by integrating physical devices to the real world and offers a crucial internet infrastructure for future civilization. Because IoT devices are widely distributed and restricted in resources, it is difficult for them to adopt traditional security methods to resist malicious attacks. Unauthorized access to IoT devices, which results in severe privacy and security problems, has become a major challenge that has impeded IoT technology from being widely adopted. Therefore, the access control for IoT devices urgently needs to be improved when dealing with authorization issues. In this paper, we propose an attribute-based access control scheme that provides decentralized, flexible, and fine-grained authorization for IoT devices. Blockchain is utilized to provide authentic and reliable credentials. More importantly, a verifiable collaboration mechanism is designed to meet the needs of controlled access authorization in emergencies. Authority nodes are constructed to execute major computation tasks and interact with the blockchain. The security analysis shows that our scheme can reliably guarantee the security of authorized access. More than security assurance, a proof-of-concept prototype has been implemented to prove that our scheme is scalable, efficient, and accommodates IoT devices well.
Blockchain shows great potential to be applied in wireless IoT ecosystems for establishing the trust and consensus mechanisms without central authority's involvement. Based on RAFT consensus mechanism, this letter investigates the security performance of wireless blockchain networks in the presence of malicious jamming. We first map and model the blockchain transaction as a wireless network composed of uplink and downlink transmissions by assuming the follower nodes' position as a Poisson Point Process (PPP) with selected leader location. The probability of achieving successful blockchain transactions is derived and verified by extensive simulations. The results provide analytical guidance for the practical deployment of wireless blockchain networks.
Mingxiao Du, Qijun Chen, Jieying Chen, Xiaofeng Ma
Medical information is private, and medical data are valuable for medical research. Thus, medical information sharing is challenging because the data might be manipulated improperly and revealed during the operational process. The accuracy and integrity of medical information should be guaranteed throughout the sharing process. Medical institutions require shared information for scientific research and development; however, the issue of privacy inhibits the sharing process. In this article, we propose a new business process and a blockchain-based platform for medical information sharing. Our method exploits the advantages of blockchain in medical information recording and sharing. Information can be stored, shared, and credibly verified among parties in the distributed network. In addition, we propose a new consensus algorithm and a universal anonymous sharing model. These methods improve the efficiency and security of medical information sharing between users. In this way, both the information and the traces of the transaction can be stored in a distributed manner to prevent manipulation and fraud. Consequently, the value of medical information can be fully utilized.
Yeṣem Kurt Peker, Xavier Rodríguez, James Ericsson, Suk Jin Lee · 5 authors
Blockchain is a developing technology that can be utilized for secure data storage and sharing. In this work, we examine the cost of Blockchain-based data storage for constrained Internet of Things (IoT) devices. We had two phases in the study. In the first phase, we stored data retrieved from a temperature/humidity sensor connected to an Ethereum testnet blockchain using smart contracts in two different ways: first, appending the new data to the existing data, storing all sensor data; and second, overwriting the new data onto the existing data, storing only a recent portion of the data. In the second phase, we stored simulated data from several sensors on the blockchain assuming sensor data is numeric. We proposed a method for encoding the data from the sensors in one variable and compared the costs of storing the data in an array versus storing the encoded data from all sensors in one variable. We also compared the costs of carrying out the encoding within the smart contract versus outside the smart contract. In the first phase, our results indicate that overwriting data points is more cost-efficient than appending them. In the second phase, using the proposed encoding method to store the data from several sensors costs significantly less than storing the data in an array, if the encoding is done outside the smart contract. If the encoding is carried out in the smart contract, the cost is still less than storing the data in an array, however, the difference is not significant. The study shows that even though expensive, for applications where the integrity and transparency of data are crucial, storing IoT sensor data on Ethereum could be a reliable solution.
The sharing of health-related data has become challenging in terms of data security which may lead to compromise patient’s privacy. Generally, once the report generated by the health provider is final, it will be uploaded to the hospital’s private repository. When it comes to the hospital as an organization, many participants [Doctor, Patient, Researcher, Insurance company] requires the report of patients for one or other reasons. Providing a single platform for all participants to share confidential data securely is a difficult and challenging task. Care should be taken such that the personal data of the patients should not be misused or tampered. Existing methods have been proved insufficient to effectively manage and secure health records. Blockchain technology, a recent research trend, has shown promising results for such secure data sharing. Since the contents of blockchain are tamper-proof, all participants can access the data but cannot change the data. By employing smart contracts and access control programs one can monitor data activity in the blockchain network. In this article, a blockchain architecture has been designed and discussed for secure and easy sharing of patient’s Personal Health Report(PHR) among the different players of health organization. Further, Inter-Planetary File System (IPFS) has also used in the proposed blockchain architecture for faster retrieval of PHR’s. We demonstrate the strengths of our proposed model, its user-centric focus and also the experimental results.
While enjoying the convenience brought by Location Based Service (LBS), the location privacy of vehicles in VANET may be disclosed. Distributed k-anonymity, as one of the most popular privacy protection methods, fails to take the trustworthiness of participants into account, resulting in malicious tracing of vehicles, which further leads to the sensitive information leakage, and even the safety threat of personal property. To address this issue, we propose a blockchain enabled trust-based location privacy protection scheme in VANET. Specifically, by analyzing the different requirements of the request vehicle and the cooperative vehicle during the process of constructing the anonymous cloaking region, as well as combining the characteristics of these two roles, we devise the trust management method based on Dirichlet distribution, such that both the requester and the cooperator will only cooperate with the vehicles they trust. Moreover, by employing blockchain, we also proposed the data structure to record the trustworthiness of vehicles on publicly available blocks timely, so that any vehicle can access the historical trust information of counterparties whenever necessary. Finally, the construction process of anonymous cloaking region is presented. Security analysis and extensive experiments indicate that the proposal is resilient to various trust model attacks, it can effectively detect the malicious vehicles, and preserve the location privacy of vehicles in the anonymous cloaking region construction, while the required time delay is limited.
Konstantin D. Pandl, Scott Thiebes, Manuel Schmidt-Kraepelin, Ali Sunyaev
Developments in Artificial Intelligence (AI) and Distributed Ledger\nTechnology (DLT) currently lead to lively debates in academia and practice. AI\nprocesses data to perform tasks that were previously thought possible only for\nhumans. DLT has the potential to create consensus over data among a group of\nparticipants in uncertain environments. In recent research, both technologies\nare used in similar and even the same systems. Examples include the design of\nsecure distributed ledgers or the creation of allied learning systems\ndistributed across multiple nodes. This can lead to technological convergence,\nwhich in the past, has paved the way for major innovations in information\ntechnology. Previous work highlights several potential benefits of the\nconvergence of AI and DLT but only provides a limited theoretical framework to\ndescribe upcoming real-world integration cases of both technologies. We aim to\ncontribute by conducting a systematic literature review on previous work and\nproviding rigorously derived future research opportunities. This work helps\nresearchers active in AI or DLT to overcome current limitations in their field,\nand practitioners to develop systems along with the convergence of both\ntechnologies.\n
Hong Liu, Pengfei Zhang, Geguang Pu, Tao Yang · 6 authors
The dynamic environment due to traffic mobility and wireless communication from/to vehicles make identity authentication and trust management for privacy preservation based on vehicular edge computing (VEC) an increasingly important problem in vehicular networks. However, existing authentication schemes mainly focus on communication between a single trusted edge computing node and multiple vehicles. This framework may suffer the bottleneck problem due to the single edge computing node, and the performance depends heavily on its resources. In this paper, a blockchain empowered group-authentication scheme is proposed for vehicles with decentralized identification based on secret sharing and dynamic proxy mechanism. Sub-authentication results are aggregated for trust management based blockchain to implement collaborative authentication. The edge computing node with a higher-reputation stored in the tamper-proof blockchain can upload the final aggregated authentication result to the central server to achieve the decentralized authentication. This work analyzes typical attacks for this scheme and shows that the proposed scheme achieves cooperative privacy preservation for vehicles while also reducing communication overhead and computation cost.
Yang Zhao, Jun Zhao, Jiawen Kang, Zehang Zhang · 7 authors
An increasing amount of users' sensitive information is now being collected for analytics purposes. To protect users' privacy, differential privacy has been widely studied in the literature. Specifically, a differentially private algorithm adds noise to the true answer of a query to generate a noisy response. As a result, the information about the dataset leaked by the noisy output is bounded by the privacy parameter. Oftentimes, a dataset needs to be used for answering multiple queries (e.g., for multiple analytics tasks), so the level of privacy protection may degrade as more queries are answered. Thus, it is crucial to keep track of the privacy spending which should not exceed the given privacy budget. Moreover, if a query has been answered before and is asked again on the same dataset, we may reuse the previous noisy response for the current query to save the privacy cost. In view of the above, we design and implement a blockchain-based system for tracking and saving differential-privacy cost. Blockchain provides a distributed immutable ledger that records each query's type, the noisy response used to answer each query, the associated noise level added to the true query result, and the remaining privacy budget in our system. Furthermore, since the blockchain records the noisy response used to answer each query, we also design an algorithm to reuse previous noisy response if the same query is asked repeatedly. Specifically, considering that different requests of the same query may have different privacy requirements, our algorithm (via a rigorous proof) is able to set the optimal reuse fraction of the old noisy response and add new noise (if necessary) to minimize the accumulated privacy cost. Experimental results show that the proposed algorithm can reduce the privacy cost significantly without compromising data accuracy.
Andrei Lihu, Jincheng Du, Igor Barjaktarević, Patrick Gerzanics · 5 authors
Bitcoin mining is a wasteful and resource-intensive process. To add a block of transactions to the blockchain, miners spend a considerable amount of energy. The Bitcoin protocol, named 'proof of work' (PoW), resembles a lottery and the underlying computational work is not useful otherwise. In this paper, we describe a novel 'proof of useful work' (PoUW) protocol based on training a machine learning model on the blockchain. Miners get a chance to create new coins after performing honest ML training work. Clients submit tasks and pay all training contributors. This is an extra incentive to participate in the network because the system does not rely only on the lottery procedure. Using our consensus protocol, interested parties can order, complete, and verify useful work in a distributed environment. We outline mechanisms to reward useful work and punish malicious actors. We aim to build better AI systems using the security of the blockchain.
We introduce the abstract framework of decentralized smart contracts system with balance and transaction amount hiding property over account-model blockchain. To build a concrete system with such properties, we utilize a homomorphic public-key encryption scheme and construct a highly efficient non-interactive zero knowledge (NIZK) argument based upon the encryption scheme to ensure the validity of the transactions. Our NIZK scheme is perfect zero knowledge in the common reference string model, while its soundness holds in the random oracle model. Compared to previous similar constructions, our proposed NIZK argument dramatically improves the time efficiency in generating a proof, at the cost of relatively longer proof size.
Crowdsensing is an emerging paradigm of data aggregation, which has a pivotal role in data-driven applications. By leveraging the recruitment, a crowdsensing system collects a large amount of data from mobile devices at a low cost. The critical issues in the development of crowdsensing are platform security, privacy protection, and incentive. However, the existing centralized, platform-based approaches suffer from the single point of failure which may result in data leakage. Besides, few previous studies have addressed the considerations of both the economic incentive and data quality. In this paper, we propose a decentralized crowdsensing architecture based on blockchain technology which will help improve the attack resistance. Furthermore, we present a hybrid incentive mechanism, which integrates the data quality, reputation, and monetary factors to encourage participants to contribute their sensing data while discouraging malicious behaviors. The effectiveness our of proposed incentive model is verified through a combination of the theory of mechanism design. The performance analysis and simulation results illustrate that the proposed hybrid incentive model is a reliable and efficient mean to promote data security and incentivizing positive conduct on the crowdsensing application.
The aim of this paper is to understand whether Distributed Ledger\nTechnologies (DLTs) are ready to support complex services, such as those\nrelated to Intelligent Transportation Systems (ITS). In smart transportation\nservices, a huge amount of sensed data is generated by a multitude of vehicles.\nWhile DLTs provide very interesting features, such as immutability,\ntraceability and verifiability of data, some doubts on the scalability and\nresponsiveness of these technologies appear to be well-founded. We propose an\narchitecture for ITS that resorts to DLT features. Moreover, we provide\nexperimental results of a real test-bed over IOTA, a promising DLT for IoT.\nResults clearly show that, while the viability of the proposal cannot be\nrejected, further work is needed on the responsiveness of DLT infrastructures.\n
Kai Fan, Qiang Pan, Kuan Zhang, Yuhan Bai · 7 authors
The vehicular social networks (VSNs) supports diverse kinds of services such as traffic management, road safety, and sharing data (videos, audios, roads photos, air quality, and so on). However, its complex, large-scale and dynamic network structure poses new security challenges. Among these challenges, secure data transmission has turned to be a spotlight. Ciphertext-policy attribute-based encryption (CP-ABE) may be adopted to realize one-to-many data sharing in VSNs. In traditional CP-ABE schemes, access policy is stored and granted by the could, which lacks credibility due to centralization. In this article, we propose a secure and verifiable one-to-many data sharing scheme to solve the above problem. We use blockchain to record the access policy, realizing user self-certification and cloud non-repudiation. Considering the computing capabilities of the vehicular user, we propose an effective scheme for certificating. Meanwhile, considering the sensitive information included in the access policy, we propose a policy hiding scheme. Our scheme also supports data revocation when a vehicular user no longer wants to share the data in VSNs. Finally, security analysis and simulation show our scheme is both secure and efficient.
Summary The emergence of mobile cloud computing enables mobile users to offload computation tasks to other resource‐rich mobile devices to reduce energy consumption and enhance performance. A direct peer‐to‐peer connection among mobile devices to offload computation tasks can be a highly promising solution to provide a fast mechanism, especially for deadline‐sensitive offloading tasks. The generic blockchain‐based system might fail in such a scenario due to it being a heavyweight mechanism requiring high power consumption in the mining process. To address these issues, in this article, we propose a directed acyclic graph‐enabled mobile offloading (DAGMO) algorithm. DAGMO model is empowered by traditional blockchain features and provides additional advantages to overcome the fundamental limitations of generic blockchain. A game‐theoretic approach is used to model the interactions between mobile devices. The numerical analysis proves the proposed model to enhance the overall welfare of the participating nodes in terms of computation cost and time.
Katarina Preikschat, Moritz Böhmecke‐Schwafert, Jan‐Paul Buchwald, Carolin Stickel
Summary Blockchain technology has the potential to bring transparency and trust to a multitude of use cases. Our research demonstrates that the technology can reduce asymmetric information in markets by bridging trust gaps. The combination of blockchain and Internet of Things technology that automatically collects sensor data, provides a feasible, decentralized technological solution for such an inefficient “Market of Lemons” coined by nobel laureate Georg Akerlof. In this paper, we develop a system prototype to reduce mileage fraud on the used car markets. Our work demonstrates the feasibility of a trusted system of records for (vehicle) data such as mileage data using a distributed database based on the public Ethereum network and smart contracts. We have identified eight requirements that are fulfilled by the prototype and the functional logic and design of thesolution can be reproduced to any other application area characterized by a lack of trust between actors or by the absence of a trusted central authority. However, the developed prototype suffers from similar limitations and challenges as the technology itself. Low throughput causes limitations in scalability and transaction costs are unpredictable. Further development of the blockchain technology and considering more cost‐efficient consensus mechanisms will address these issues.
Ciphertext-policy attribute-based encryption (CP-ABE) is widely used in fine-grained access control to achieve the secure data sharing. However, most of the existing CP-ABE access control schemes involve intermediary entities, which might suffer from a high trust-building cost, single point of failure and so on. Due to the decentralization and transparency of blockchain, some blockchain-based access control schemes are proposed to address these problems, but bring new challenges, such as the privacy leakage of access policy or attribute. In this paper, we propose a new trustworthy secure ciphertext-policy and attribute hiding access control scheme based on blockchain, named TrustAccess, to achieve trustworthy access while guaranteeing the privacy of policy and attribute. For one thing, to make the existing hidden policy CP-ABE more efficient and scalable for blockchain, we propose an optimized hidden policy CP-ABE, named OHP-CP-ABE, to ensure policy privacy while satisfying the large universe access requirement. For another thing, we use the multiplicative homomorphic ElGamal cryptosystem to ensure the attribute privacy during authorization validation. Finally, we theoretically prove the security of our TrustAccess from the aspects of blockchain operations and OHP-CP-ABE. Comprehensive comparisons and extensive experiments are conducted to demonstrate the advantages of our TrustAccess.
Nghia Duong‐Trung, Ha Xuan Son, Hai Trieu Le, Tan Tai Phan
Cross-institutional sharing of medical data is essential to provide e.ective collaborative treatment and clinical decisions for patients. Medical data privacy involves ensuring only authorized parties may access the health records under the awareness and approval of patients in any circumstances. This is crucial to any healthcare system because the protection of patients' clinical data is not only an ethical responsibility but also a legal mandate. Despite the importance of medical data sharing, today's healthcare systems have not provided enough protection of patients' sensitive information to be utilized deliberately or unintentionally. Hence, there is an urgent demand for a clinical transaction mechanism that allows patients to access, trace and control their health records. In this paper, the authors focus on several limitations in the literature and propose appropriate improvement in healthcare systems by (i) addressing information security and privacy, (ii) solving the lack of trust between providers, and (iii) encouraging scalability of healthcare interoperability. Building upon these key insights, we introduce several components of a patient-centered healthcare system using smart contracts via blockchain technology. A complete code solution is publicized on the authors' GitHub repository to engage further reproducibility and improvement.
By allocating tasks to participants, crowdsensing has shown large potential in addressing large-scale data sensing problems. Considering the problem of unfair payment, negative work of participants, and cooperative cheating, how to assess data quality of tasks reliably is an important problem in crowdsensing. Therefore, a lightweight blockchain-based model for data quality assessment is proposed in this article. First, there are two data quality assessment processes in the model. One is implemented in the selection of participants and the other is implemented in data quality assessment. Second, consensus mechanism and smart contracts are redesigned to be suitable for crowdsensing. The lightweight consensus mechanism delegated proof of reputation (DPoR) is proposed in the blockchain-based model instead of proof of work (PoW). Furthermore, three smart contracts, verifiers selection contract (VSC), participants employment contract (PEC), and data verify contract (DVC), are generated to constrain the behaviors of the involved parties. Finally, expectation-maximization (EM) algorithm with multiverifiers is proposed to evaluate the performance of task participants. Experiments on the open data sets Wine Quality show that our new method outperforms the existing methods in improving the quality of sensing task.
Data determination is the primary issue to be addressed in open data sharing. This paper proposes a personal data determination method based on blockchain and smart contract, which are used to solve the problem that the current data transaction market relies heavily on system-center entities. it is difficult for centralized method to confirm the data is true and reliable and cause the owner lose the control over data access. The method implements identity authentication by means of certificate authority, and uses digital signature and hash function to store a digest of the original data into the blockchain.By doing this can determine ownership of the data, and prevent it from being tampered with. Constructing a blockchain serving at data interaction platform to realize access control and transfer rights about personal data through the smart contract installed on it,because the operation record of data will be kept on the blockchain one by one.Then using resource state view to speed up the query process. According to experimental simulation concerning about throughput and latency, blockchain and smart contracts can guarantee the authenticity of the data and achieve the right to confirm the data and promote the open sharing of data.
Md. Ashraf Uddin, Andrew Stranieri, Iqbal Gondal, Venki Balasubramanian
Blockchain technologies recently emerging for eHealth, can facilitate a secure, decentralized and patient-driven, record management system. However, Blockchain technologies cannot accommodate the storage of data generated from IoT devices in remote patient management (RPM) settings as this application requires a fast consensus mechanism, careful management of keys and enhanced protocols for privacy. In this paper, we propose a Blockchain leveraged decentralized eHealth architecture which comprises three layers: (1) The Sensing layer – Body Area Sensor Networks include medical sensors typically on or in a patient body transmitting data to a smartphone. (2) The NEAR processing layer – Edge Networks consist of devices at one hop from data sensing IoT devices. (3) The FAR processing layer – Core Networks comprise Cloud or other high computing servers). A Patient Agent (PA) software replicated on the three layers processes medical data to ensure reliable, secure and private communication. The PA executes a lightweight Blockchain consensus mechanism and utilizes a Blockchain leveraged task-offloading algorithm to ensure patient’s privacy while outsourcing tasks. Performance analysis of the decentralized eHealth architecture has been conducted to demonstrate the feasibility of the system in the processing and storage of RPM data.