Mobile Ad-hoc Cloud (MAC) is the constellation of nearby mobile devices to serve the heavy computational needs of the resource-constrained edge devices. One of the major challenges of MAC is to convince the mobile devices to offer their limited resources for the shared computational pool. Credit-based rewarding system is considered as an effective way of incentivizing the arbitrary mobile devices for joining the MAC network and to earn the credits through computational crowdsourcing. The next challenge is to get the reliable computation as incentives attract the malicious devices to submit fake computational results for claiming their reward and we have used the blockchain based reputation system for identifying the malicious participants of MAC. This paper presents a malicious node identification algorithm integrated within the Iroha based permissioned blockchain. Iroha is a project of hyperledger which is focused on mobile devices and thus light-weight in nature. It is used for keeping the track of rewarding and reputation system driven by the malicious node detection algorithm. Experiments are conducted for evaluating the implemented test-bed and results show the effectiveness of algorithm in identifying the malicious devices and conducting reliable data analysis through the blockchain based computational crowdsourcing in MAC.
Mobile crowdsensing(MCS) is an emerging pattern which means task initiators attract mobile users sensing with their own devices by some platforms. MCS could exploit idle resources in low cost, while it has lots of flaws, which impede its developments. First, isolations between different MCS systems leads to wastage of social resources. What's more, current MCS always operate in a centralized way, which causes it vulnerable and unbelievable. Blockchain is a promising technology which could supply a credible and transparent environment. This paper construct a blockchain based MCS market and design smart contract for its operation. In our design, platform breaks isolation by blockchain, task initiators and mobile users manage their tasks by smart contract and bargain price with distributed algorithm. By this way, resource could be exploited better, and the market could be more fair. What's more, the paper analyzes Walrasian Equilibrium (WE) in the market, and details how to deploy MCS in blockchain. Evalution results shows that Equilibrium could be found.
Imen Riabi, Yosr Dhif, Hella Kaffel Ben Ayed, Khaled Zaatouri
Traditional access control models rely on a central entity. This may cause single point of failure, ethical and privacy problems when applied in the Internet of Things (IoT). A distributed access control can overcome the single point failure problem of centralized access models. In this paper, we propose a distributed and trustworthy access control solution for the IoT by applying the smart contract-enabled blockchain.
The blockchain uses a decentralized consensus mechanism to maintain the books in an immutable way, which ensures the blockchain smart contract system highly secure. In existing blockchain systems, all user information is disclosed in the blockchain. However, currently users begin to pay more and more attention to personal privacy, therefore the future blockchain smart contract system needs not only to keep immutability but also to protect user privacy. To achieve this goal, in this paper we propose a privacy-encrypted blockchain system, where all data is encrypted within a controllable period of time. Although the data is visible from a historical perspective, our design can effectively protect user privacy and against deceivers, making the system more secure and healthy.
There has been a considerable amount of interest in exploring blockchain technologies for enabling marketplaces of different kinds. In this work, we provide a blockchain implementation that enables an "AI marketplace": a platform where consumers and data providers can transact data and/or models and derive value. Preserving privacy and trust during these transactions is a paramount concern. As an enabling use case, we consider a transfer learning setting. In this setting, a consumer entity wants to acquire a large training set, from different private data providers, that matches a small validation dataset provided by the consumer. Data providers expect fair value for their contribution and the consumer also wants to maximize its benefit. We implement a distributed protocol on a blockchain that provides guarantees on privacy and consumer's benefit. We also demonstrate that our blockchain implementation plays a crucial role in addressing the issue of fair value attribution and privacy in a trustable way. We consider three different designs for a blockchain implementation that trades off trust requirements on different entities and the overhead in terms of time taken for completion of the task. The first design provides no trust guarantees. The second one guarantees trust with respect to other participants if the platform is trustworthy. The third one guarantees complete trust with no requirements. Our experiments show that the performance in the second and third cases, with partial/complete trust guarantees, degrade by roughly 2× and 5× respectively, compared to the baseline with no trust guarantees.
Truth discovery with crowdsourcing has become increasingly popular in recent years by leveraging the wisdom of crowd to solve complex tasks. So far, many existing crowd-sourcing applications utilize a central server for deployment, which collects and processes data from a crowd of workers. However, this kind of centralized model also introduces security concerns, including data privacy, integrity of processed data, and single point of failure. In this paper, we propose a secure decentralized framework for truth discovery with a privacy-preserving and reliable realization. Instead of relying on the central servers (e.g., public cloud servers)to behave correctly, our framework delegates the data aggregation and processing tasks to distributed entities, whose behaviors are enforced and verified by utilizing the emerging blockchain-based smart contract technology. Meanwhile, as the blockchain lacks support for on-chain data confidentiality, we utilize the privacy-preserving solution and integrate it with blockchain for privacy protection. Moreover, given the decentralized nature of our framework, it also overcomes the limitation of single point of failure. We implement a prototype of our framework using Ethereum blockchain and demonstrate its practical performance.
Blockchain is a database technology that provides the integrity and trust of the system can't make arbitrary modifications and deletions by being an append-only distributed ledger. That is, the blockchain is not a modification or deletion but a CRAB (Create-Retrieve-Append-Burn) method in which data can be read and written according to a legitimate user's access right(For example, owner private key). However, this can not delete the created data once, which causes problems such as privacy breach. In this paper, we propose an on-off block-chained Hybrid Blockchain system to separate the data and save the connection history to the blockchain. In addition, the state is changed to the distributed database separately from the ledger record, and the state is changed by generating the arbitrary injection in the XOR form, so that the history of modification / deletion of the Off Blockchain can be efficiently retrieved.
With the development of cloud computing technology, data can be outsourced to the cloud and conveniently shared among users. However, in many circumstances, users may have concerns about the reliability and integrity of their data. It is crucial to provide data sharing services that satisfy these security requirements. We introduce a reliable and secure data sharing scheme, using the threshold secret sharing technique and the Chaum-Pedersen zero-knowledge proof. The proposed scheme is not only effective and flexible, but also able to achieve the semantic security property. Moreover, our scheme is capable of ensuring accountability of users’ decryption keys as well as cheater identification if some users behave dishonestly. The efficiency analysis shows that the proposed scheme has a better performance in terms of computational cost, compared with the related work. It is particularly suitable for application to protect users’ medical insurance data over the cloud.
With the growth in popularity for cryptocurrencies the need for privacy preserving blockchains is growing as well. Zcash is such a blockchain, providing transaction privacy through zero-knowledge proofs. In this paper we analyze transaction linkability in Zcash based on the currency minting transactions (mining). Using predictable usage patterns and clustering heuristics on mining transactions an attacker can link to publicly visible addresses over 84% of the volume of the transactions that use a ZK-proof. Since majority of Zcash transactions are not yet using ZK-proofs, we show that overall 95.5% of the total number of Zcash transactions are potentially linkable to public addresses by just observing the mining activity.
Data sharing and privacy securing present extensive opportunities and challenges in vehicular network. This paper introduces `trust access authentication scheme' as a mechanism to achieve real-time monitoring and promote collaborative sharing for vehicles. Blockchain, which can provide secure authentication and protected privacy, is a crucial technology. However, traditional cloud computing performs poorly in supplying low-latency and fast-response services for moving vehicles. In this situation, edge computing enabled Blockchain network appeals to be a promising method, where moving vehicles can access storage or computing resource and get authenticated from Blockchain edge nodes directly. In this paper, a hierarchical architecture is proposed consist of vehicular network layer, Blockchain edge layer and Block-chain network layer. Through a authentication mechanism adopting digital signature algorithm, it achieves trusted authentication and ensures valid verification. Moreover, a caching scheme based on many-to-many matching is proposed to minimize average delivery delay of vehicles. Simulation results prove that the proposed caching scheme has a better performance than existing schemes based on centralized model or edge caching strategy in terms of hit ratio and average delay.
Olivia Choudhury, Issa Sylla, Noor Fairoza, Amar K. Das
The cost and complexity of conducting multi-site clinical trials have significantly increased over time, with site monitoring, data management, and Institutional Review Board (IRB) amendments being key drivers. Trial sponsors, such as pharmaceutical companies, are also increasingly outsourcing trial management to multiple organizations. Enforcing compliance with standard operating procedures, such as preserving data privacy for human subject protection, is crucial for upholding the integrity of a study and its findings. Current efforts to ensure quality of data collected at multiple sites and by multiple organizations lack a secure, trusted, and efficient framework for fragmented data capture. To address this challenge, we propose a novel data management infrastructure based on a permissioned blockchain with private channels, smart contracts, and distributed ledgers. We use an example multi-organizational clinical trial to design and implement a blockchain network: generate activity-specific private channels to segregate data flow for confidentiality, write channel-specific smart contracts to enforce regulatory guidelines, monitor the immutable transaction log to detect protocol breach, and auto-generate audit trail. Through comprehensive experimental study, we demonstrate that our system handles high-throughput transactions, exhibits low-latency, and constitutes a trusted, scalable solution.
Donghui Ding, Kang Li, Linpeng Jia, Zhongcheng Li · 6 authors
The blockchain technology has been applied to wide areas. However, the open and transparent properties of the blockchains pose serious challenges to users' privacy. Among all the schemes for the privacy protection, the zero-knowledge proof algorithm conceals most of the private information in a transaction, while participants of the blockchain can validate this transaction without the private information. However, current schemes are only aimed at blockchains with the UTXO model, and only one type of assets circulates on these blockchains. Based on the zero-knowledge proof algorithm, this paper proposes a privacy protection scheme for blockchains that use the account and multi-asset model. We design the transaction structure, anonymous addresses and anonymous asset metadata, and also propose the methods of the asset transfer and double-spending detection. The zk-SNARKs algorithm is used to generate and to verify the zero-knowledge proof. And finally, we conduct the experiments to evaluate our scheme.
The Internet of Things promises to connect more than 50 billion devices in a multitude of application domains. However, user privacy and security remain a major challenge in IoMT. In this paper, we present a work in progress for a lightweight blockchain based scheme aiming to secure the Internet of Medical Things (IoMT). The proposed approach consists of four main components: a cloud server, network cluster, medical facility, and smart medical devices. Each medical facility contains a “bolster”, a powerful computing device that operates as a gateway/server to support in-range smart medical devices. The bolster holds a private and secure block role. It is used to securely communicate with other blocks in the same blockchain. Experimental analysis shows that the proposed scheme presents a non-significant overhead; yet it brings major advantages to meet the standard security and privacy requirements in IoMT.
Sophie Dramé-Maigné, Maryline Laurent, Laurent Castillo
The ever-growing world of the Internet of Things (IoT) is yet to agree on an effective and practical access control solution. To overcome challenges such as limited resources, or unreliable connectivity, a number of schemes offload heavy computations onto a central entity, thus creating a single point of failure. Our contribution consists in the construction of a distributed attribute-based access control mechanism, relying on the blockchain technology to dynamically manage multi-endorsed attributes and trust anchors. The originality of our proposal is multifold. First, it enables the integration of multiple security domains into a single resilient access control system. Second, its focus on attributes offers flexibility, expressiveness, and user-centricity, accommodating the dynamic addition of subjects. Third, our attribute endorsement is open, scalable, and flexible, enabling multiple administrators without sacrificing ease of management. Finally, the final access control decision is taken by the device and only requires local connection to its gateway.
Biometrics have been used increasingly heavily for identity authentication in many critical public services, such as border passes or security check points. However, traditional biometrics-based identity management systems collect and store personal biometrical data in a centralized server or database, and an individual has no control over how her biometrics will be used for what purpose. Such kind of systems can result in serious security and privacy issues for sensitive personal data. In this paper, we design a novel approach to leveraging biometrics and blockchain/smart contract to enable secure and privacy preserving identity management. The basic idea is to use blockchain to store an authority's attestation and the transformed value of an individual's biometrics. The stored data on the blockchain is then controlled by smart contracts which define various access control policies, e.g., access parties, access times, etc. The owner of the biometrical data can flexibly change the access control policies through a white list, a timer and other methods to any identity verifiers. We used the well-known Ethereum platform to implement the proposed approach and tested the effectiveness as well as the flexibility of various access control policies.
Hui Kang, Ting Dai, Nerla Jean-Louis, Shu Tao · 5 authors
On a Blockchain network, transaction data are exposed to all participants. To preserve privacy and confidentiality in transactions, while still maintaining data immutability, we design and implement FabZK. FabZK conceals transaction details on a shared ledger by storing only encrypted data from each transaction (e.g., payment amount), and by anonymizing the transactional relationship (e.g., payer and payee) between members in a Blockchain network. It achieves both privacy and auditability by supporting verifiable Pedersen commitments and constructing zero-knowledge proofs. FabZK is implemented as an extension to the open source Hyperledger Fabric. It provides APIs to easily enable data privacy in both client code and chaincode. It also supports on-demand, automated auditing based on encrypted data. Our evaluation shows that FabZK offers strong privacy-preserving capabilities, while delivering reasonable performance for the applications developed based on its framework.
This paper examines the way in which blockchain technology can be used to improve the verification of integrity of evidence in digital forensics. Some background into digital forensic practices and blockchain technology are discussed to provide necessary context. A particular scalable method of verifying point-in-time existence of a piece of digital evidence, using the OpenTimestamps (OTS) service, is described, and tests are carried out to independently validate the claims made by the service. The results demonstrate that the OTS service is highly reliable with a zero false positive and false negative error rate for timestamp attestations, but that it is not suitable for timesensitive timestamping due to the variance of the accuracy of timestamps induced by block confirmation times in the Bitcoin blockchain.
Jian An, Yang He, Xiaolin Gui, Wendong Zhang · 6 authors
With the rapid growth of smart terminals in recent years, crowdsensing which utilizes the human intelligence to solve complicated problems have gained considerable interest and exploit. The majority of the existing crowdsensing systems rely on a trusted third-party platform to complete sensing tasks and collect large-scale data. However, the platform cannot completely ensure trust in the real world. The issues of security and privacy caused by the center platform should not be ignored. In this paper, we propose a decentralized privacy-preserving model based on twice verifications and consensuses of blockchain (TCNS). In the prototype of TCNS, an anonymity strategy which can be verified based on the elliptic curve algorithm is proposed to protect the user identity privacy. Then, we propose a twice consensus mechanism, which ensures that the data can be traced and avoids data from being impersonated, tampered with, and denied. Moreover, we propose a user attribute protection scheme based on the lightweight homomorphic encryption algorithm. Finally, considering various influencing factors comprehensively, TCNS uses fuzzy theories to select the candidate mobile nodes. Further, we implement the prototype with real-world datasets, the experimental analysis of privacy protection and safety shows that TCNS can effectively prevent association analysis attacks and background knowledge attacks. More gratifying, the time overhead for generating a new block is acceptable.
Public blockchain network (PBN) has been widely used in wired networks such as bitcoin network, in which proof-of-work (PoW) algorithm is deployed among miners to reach consensus on users data during the mining process. However, the PoW consensus mechanism is computation-consuming which obstacles the application of PBN in wireless mobile networks since most Internet of Things/mobile devices (IMDs) are resource limited. Recently, mobile edge computing (MEC) has been regarded as a promising technology which can allow IMDs to offload their computation tasks to the edge nodes. Although IMDs can offload their computation tasks to the edge nodes, there is still lots of competition among enormous solo mining IMDs when reaching consensus. In this paper, we first formulate the computation resource allocation problem of PBN from the viewpoint of coalition game theory under the MEC environment. Then, we propose a coalition formation game-based algorithm to maximize the system sum utility and take both the individual profit of IMD and coalition profit into consideration. Furthermore, we prove the proposed algorithm converges to a Nash-stable partition in a fast convergence rate and finally reaches the near-optimal solution with low computational complexity. The simulation results demonstrate the optimality and convergence of the proposed algorithm, and the proposed algorithm outperforms other schemes in terms of system sum profit and ratio of rewarded IMDs to overall IMDs.
Bo Tang, Hongjuan Kang, Jingwen Fan, Qi Li · 5 authors
Internet-of-Things (IoT) is a rapidly-growing transformative expansion of the Internet with increasing influence on our daily life. Since the number of "things" is expected to soon surpass human population, control and automation of IoT devices has received considerable attention from academia and industry. Cross-platform collaboration is highly desirable for better user experience due to fragmentation of user needs and vendor products with time. Centralized approaches have been used to build federated trust among platforms and devices, but limit diversity and scalability. We propose a decentralized trust framework, called IoT Passport, for cross-platform collaborations using blockchain technology. IoT Passport is motivated by the familiar use of passports for international travel but with greater dynamism. It enables platforms to establish arbitrary trust relations with each other containing specific rules for intended collaborations, enforced by a combination of smart contracts. Each interaction among devices is signed by the participants and recorded on the blockchain. The records are utilized as attributes for authorization and as proofs of incentive plans. This approach incorporates the preferences of participating platforms and end users, and opens new avenues for collaborative edge computing as well as research on blockchain-based access control mechanism for IoT environments.
Yongjun Ren, Yan Leng, Fujian Zhu, Jin Wang · 5 authors
Wireless body area networks (WBANs) are expected to play a vital role in the field of patient-health monitoring shortly. They provide a convenient way to collect patient data, but they also bring serious problems which are mainly reflected in the safe storage of the collected data. The privacy and security of data storage in WBAN devices cannot meet the needs of WBAN users. Therefore, this paper adopts blockchain technology to store data, which improves the security of the collected data. Moreover, a storage model based on blockchain in WBAN is proposed in our solution. However, blockchain storage brings new problems, for example, that the storage space of blockchain is small, and the stored content is open to unauthorized attackers. To solve the problems above, this paper proposed a sequential aggregate signature scheme with a designated verifier (DVSSA) to ensure that the user's data can only be viewed by the designated person and to protect the privacy of the users of WBAN. In addition, the new signature scheme can also compress the size of the blockchain storage space.
Offloading computation-intensive blockchain mining tasks to the edge servers (ESs) is a promising solution for blockchain-empowered Industrial Internet of Things (IIoT) because the computing capabilities in IIoT are usually limited, whereas the blockchain mining tasks are computationally intensive. However, the computation offloading solutions for data processing tasks and for blockchain mining tasks have been studied separately. Moreover, most of the existing solutions for offloading assume that all IIoT devices can directly connect to the ESs or cloud data centers. To address these issues, in this paper, we propose a multihop cooperative and distributed computation offloading algorithm that considers the data processing tasks and the mining tasks together for blockchain-empowered IIoT. First, we study the multihop computation offloading problem for both the data processing tasks and the mining tasks to minimize the economic cost of IIoT devices. Second, we formulate the offloading problem as a potential game in which the IIoT devices can make their decisions autonomously and prove the existence of Nash equilibrium (NE) for the game. Third, we design an efficient distributed algorithm based on exchanging messages between IIoT devices to achieve the NE with low computational complexity. Lastly, our experimental results demonstrate that our distributed algorithm scales well as the number of IIoT devices increases and has the minimum system cost compared with other approaches.
Roman Overko, Rodrigo Ordóñez-Hurtado, Sergiy Zhuk, Pietro Ferraro · 6 authors
We introduce a permissioned distributed ledger technology (DLT) design for crowdsourced smart mobility applications. This architecture is based on a directed acyclic graph architecture (similar to the IOTA tangle) and uses both Proof-of-Work and Proof-of-Position mechanisms to provide protection against spam attacks and malevolent actors. In addition to enabling individuals to retain ownership of their data and to monetize it, the architecture also is suitable for distributed privacy-preserving machine learning algorithms, is lightweight, and can be implemented in simple internet-of-things (IoT) devices. To demonstrate its efficacy, we apply this framework to reinforcement learning settings where a third party is interested in acquiring information from agents. In particular, one may be interested in sampling an unknown vehicular traffic flow in a city, using a DLT-type architecture and without perturbing the density, with the idea of realizing a set of virtual tokens as surrogates of real vehicles to explore geographical areas of interest. These tokens, whose authenticated position determines write access to the ledger, are thus used to emulate the probing actions of commanded (real) vehicles on a given planned route by "jumping" from a passing-by vehicle to another to complete the planned trajectory. Consequently, the environment stays unaffected (i.e., the autonomy of participating vehicles is not influenced by the algorithm), regardless of the number of emitted tokens. The design of such a DLT architecture is presented, and numerical results from large-scale simulations are provided to validate the proposed approach.