In this paper, a blockchain-based data sharing and access control system is proposed, for communication between the Internet of Things (IoT) devices. The proposed system is intended to overcome the issues related to trust and authentication for access control in IoT networks. Moreover, the objectives of the system are to achieve trustfulness, authorization, and authentication for data sharing in IoT networks. Multiple smart contracts such as Access Control Contract (ACC), Register Contract (RC), and Judge Contract (JC) are used to provide efficient access control management. Where ACC manages overall access control of the system, and RC is used to authenticate users in the system, JC implements the behavior judging method for detecting misbehavior of a subject (i.e., user). After the misbehavior detection, a penalty is defined for that subject. Several permission levels are set for IoT devices’ users to share services with others. In the end, performance of the proposed system is analyzed by calculating cost consumption rate of smart contracts and their functions. A comparison is made between existing and proposed systems. Results show that the proposed system is efficient in terms of cost. The overall execution cost of the system is 6,900,000 gas units and the transaction cost is 5,200,000 gas units.
Muhammad Ajmal Azad, Samiran Bag, Feng Hao, Andrii Shalaginov
The Internet of Things (IoT) is the network of connected computing devices that have the ability to transfer valued data between each other via the Internet without requiring human intervention. In such a connected environment, the social IoT (SIoT) has become an emerging trend where multiple IoT devices owned by users support communication within a social circle. Trust management in the SIoT network is imperative as trusting the information from compromised devices could lead to serious compromises within the network. It is important to have a mechanism where the devices and their users evaluate the trustworthiness of other devices and users before trusting the information sent by them. The privacy preservation, decentralization, and self-enforcing management without involving trusted third parties are the fundamental challenges in designing a trust management system for SIoT. To fulfill these challenges, this article presents a novel framework for computing and updating the trustworthiness of participants in the SIoT network in a self-enforcing manner without relying on any trusted third party. The privacy of the participants in the SIoT is protected by using homomorphic encryption in the decentralized setting. To achieve the properties of self-enforcement, the trust score of each device is automatically updated based on its previous trust score and the up-to-date tally of the votes by its peers in the network with zero-knowledge proofs (ZKPs) to enforce that every participant follows the protocol honestly. We evaluate the performance of the proposed scheme and present evaluation benchmarks by prototyping the main functionality of the system. The performance results show that the system has a linear increase in computation and communication overheads with more participants in the network. Furthermore, we prove the correctness, privacy, and security of the proposed system under a malicious adversarial model.
Transgender community face serious socio-economic predicaments due to the discrepancy between their current gender expression and assigned gender identity at birth. Even though, a considerable amount work have been done to protect their basic human rights such as security, equality and social acceptance; trans people are still large victims of hate related crimes. With GDPR and other data protection laws and policies in place, now it is ever more important to protect the confidentiality of gender change information as well as to establish technical solutions that can prevent from inferring any sense of gender change from historical data. In this context, distributed ledger technologies such as blockchain present great opportunities for information integrity, security, privacy and access. However, at the same time provenance information extracted from immutable blockchain can be exploited to infer gender change. Addressing this paradox here we propose recommendations for managing gender change information in the blockchain environment in context of present sociopolitical, legislative and technical challenges associated with gender change.
Blockchain serves as an immutable ledger which allows transactions to take place in a decentralized manner. The proposed solution incorporates the use of Blockchain for Supply Chain Management of Relief Materials after a Disaster. The proposed solution also provides many additional features when compared to the current system like being tamper-proof, providing anonymity and accountability to the users. Our solution incorporates a box-in-box approach whilst keeping tabs via tamper-proof barcodes. Barcodes will be frequently scanned at designated locations. Users also have the facility to track the donated items online through a dedicated website. For blockchain infrastructure, we have used Hyperledger Fabric.
Permission delegation in access control provides the subject with a second method to obtain object permissions in addition to permission granting. It is especially applicable when the owner and manager of the object are inconsistent. With the development of the Internet of Things, there are more and more scenes where object owners and managers are inconsistent, but the research on permission delegation in access control based on blockchain is not perfect. Therefore, once implemented in these blockchain-based access control algorithms, the permission delegation tends to have an unauthorized access. Based on the analysis of the causes for the unauthorized access vulnerability, this paper proposes a token-constrained permission delegation algorithm (TCPDA), which converts the access control policy corresponding to permissions into constraints for permission use, embeds the constraints in the permission token, and forms constraints on the transfer of tokens. Only subjects that meet the constraint conditions can receive tokens, thereby solving unauthorized access vulnerability caused by permission delegation. Since not all access control models can transform strategies into constraints and integrate them into blockchain tokens, this paper also proposes a permission delegation algorithm for decision-making entities to make desirable decisions. Finally, the security analysis shows that the two proposed schemes can overcome the unauthorized access vulnerability caused by permission delegation, and the algorithm performance is analyzed through experiments.
Rustam Pirmagomedov, Aleksandr Ometov, Dmitri Moltchanov, Xi Lu · 9 authors
Wireless traffic produced by modern mobile devices displays high temporal and spatial dynamics as users spontaneously engage in collective applications where a significant portion of generated data remains localized. As a result, conventional service provisioning approaches may no longer be sufficient in beyond fifth generation (B5G) systems. The challenge of increased dynamics on the access networks can be mitigated with moving cells. However, the deployment time of these temporary serving entities may lag behind the service demand lifetime. Another viable solution to offload excessive cellular traffic is to rely upon locally available radio resources offered by user devices via direct mmWave-based mesh interworking. An important challenge in such systems is related to the incentivization of users to partake in collaborative resource sharing. To leverage multi-hop mesh capabilities, we propose the use of emerging blockchain technology that offers cryptographically-strong accounting while maintaining the anonymity of the participants. With system-level evaluations, we demonstrate that the utilization of mobile blockchain methods allows for a non-incremental improvement in the offloading gains. This demonstrates the potential of the outlined proposal for becoming a successful mechanism in the emerging B5G systems.
When a user registers a digital service, the service provider often asks for the user's personal information, such as name, phone number and so on. With the digital services gradually becoming an indispensable part of our lives, the abuse and misappropriation of personal information have caused people's attention to the protection of it. At present, The technical schemes for personal information protection mainly focus on preventing information leakage. We provide protection in a different way: propose a traceable method for personal information registration based on blockchain, which can distinguish the service provider obtained the information legally or illegally, by storing the personal information transaction records on the blockchain. The proposed method includes both direct and third-party personal information transaction scenarios. In different scenarios, the user will send the encrypted personal information data or authorization file to the service provider. After the transaction record is confirmed to be on the blockchain, the certification center will assist the service provider to decrypt the personal information. With this method, users can clearly understand which personal information has been delivered to which service providers. Moreover, the user's personal information data involving privacy are not stored on or transmitted through the blockchain. Hence, there is no additional risk of information disclosure, so as to achieve the purpose of personal information protection. Additionally, we analyze the proposed method using Kailar logic, and conduct a transaction performance simulation using NS-3. It shows that our method has properties of privacy, reliability, and accountability, and can meet the transaction performance requirements under the practical application scene.
The era of deep learning has enabled various dimensions of predictive and preventive healthcare in medical science. However, the applications in dimension are limited due to sparse availability of data and computing resources, also the required expertise of data understanding, modeling and training is not common yet. These limitations are forcing a barrier in the widespread use of deep learning applications in healthcare. In this research we propose a decentralized transfer learning mechanism based on smart contracts using private blockchain. The idea is to involve various stakeholders which includes data scientists, deep learning experts, dataset holders and deep learning infrastructure providers into a single trustless deep learning-based analytics system. The framework will allow sharing of data, and expertise in the field of deep learning, along with processing power to solve a single task in a decentralized manner. The sharing mechanism will be based on smart contracts to ensure the intellectual property of an individual remains protected. The framework once deployed on public blockchain can turn transfer learning into a new domain of research and business and will define a new era of shared computing for various domains. The research will directly impact people working in isolation to come together and create opportunities for better analytics and optimized predictions for scientific society.
Safe and scalable dynamic autonomous data interaction between medical institutions can increase the number of clinical trial records, which is of great significance for improving the level of medical trial collaboration, especially for clinical decision-making with regard to rare diseases. Through a preset authorization access and consensus mechanism, consortium chain provides integrity and traceability management for medical clinical data. However, how to enable users have ownership of their own medical data and share their medical data safely and dynamically between different medical institutions remains an area of particular concern. To achieve dynamic communication between medical consortium chains, this paper proposes (i) a cross-chain communication mechanism by simplifying the heterogeneous node communication topology and (ii) the construction rules of the node identity credibility path-proof to carry out dynamic construction and verification of the path-proof for cross-chain transactions. In addition, the consensus of the cross-chain transaction is modeled as a threshold digital signature process with multiple privileged subgroups; thus, the intra-chain consortium consensus based on the verification node list is extended to the cross-chain consensus. A smart contract deployment and execution scheme based on rational node value transfer mechanism is proposed by analyzing the value transfer game between nodes. Experimental results showed that the proposed scheme can not only enable patients to share their records safely and autonomously in an authorized medical consortium chain within milliseconds but also realize dynamic adaptive interaction among heterogeneous consortium chains.
To build a proactive cyber defense system, sharing the cybersecurity information has been very popular by which any organization can get more information about unknown and new threats. Cybersecurity Information Exchange (CYBEX) is one of the important platforms which has been playing an important role in implementing proactive cyber defense system by allowing organizations sharing their cybersecurity information. However, they are centralized and therefore they may suffer from complete failure in case of any damage or accident. Moreover, while sharing private information it lacks the mechanism of providing rights to query organizations i.e., enabling the access control over the shared sensitive information. Finally, nonrepudiation of the system does not exist i.e., there is no way to track or keep the record what any organization is sharing and it is necessary to keep the record in case anyone denies after sharing false information. To address these issues, in this paper we propose blockchain based privacy preserving cybersecurity information sharing using proxy re-encryption and attribute-based encryption (BloCyNfo-Share) where the organization can achieve fine-grain access control by delegating which organization can have the access to its cybersecurity information leveraging the benefits of blockchain technology. We conduct privacy and experimental analysis of the proposed system and the findings show that the model is private as well as efficient.
Sharing the electronic health data helps to increase the accuracy of the diagnoses and to improve the quality of health services. This shared data can also be used in medical research and can reduce medical costs. However, health data are fragmented across decentralized hospitals, this prevents data sharing and puts patients’ privacy at risks. In recent years, blockchain has revealed solutions that make life easier in many areas thanks to its distributed, safe and immutable structure. There are many blockchain-based studies in the literature on providing data privacy and sharing in different areas. In some studies, blockchain has been used with technologies such as cloud computing and cryptology. In the field of healthcare blockchain-based solutions are offered for the management and sharing of Electronic health records. In these solutions, private and consortium blockchain types are generally preferred and Public Key Infrastructure (PKI) and encryption are used for data privacy. Within the scope of this study, blockchain-based studies on the privacy preserving data sharing of health data were examined. In this paper, information about the studies in the literature and potential issues that can be studied in the future were discussed. In addition, information about current blockchain technologies such as smart contracts and PKI is also given.