The ubiquitous application of emerging blockchain technology in numerous technological projects leads to a tremendous hype. The significantly high prices of digital currencies and initial coin offerings as the new funding approach has fostered the public perception of blockchain as a cure-all and driven the hype even further. In this evolution, a clear view of the reasonable application of blockchain technology is not given and therefore, the purposeful use of traditional technologies is undermined. To clarify this situation, we derive a novel decision model for evaluating the applicability of blockchain technology that considers two key factors: the remediation of central governance and the management of digital objects. Based on these key factors, we closely analyse the domain of identity management for conscious blockchain application. Finally, we examine uPort, Sovrin, and ShoCard as distinct projects in this scope with regard to the inevitable necessity to implement a blockchain by using our decision model.
Debiao He, Yudi Zhang, Ding Wang, Kim‐Kwang Raymond Choo
Mobile device and application (app) security are increasingly important, partly due to the constant and fast-paced cyberthreat evolution. To ensure the security of communication (e.g., data-in-transit), a number of identity-based signature schemes have been designed to facilitate authorization identification and validation of messages. However, in many of these schemes, a user's private key may leak when a new signature is generated since the private keys are stored on the device. Seeking to improve the security of the private key, we propose the first two-party distributed signing protocol for the identity-based signature scheme in the IEEE P1363 standard. This protocol requires that two devices separately store one part of the user's private key, and allows these two devices to generate a valid signature without revealing the entire private key of the user. We formally prove that the security of the protocol in the random oracle model. Then, we implement the protocol using the MIRACL library and evaluate the protocol on two mobile devices. Compared with the protocol of Lindell (CRYPTO'17) that uses the zero-knowledge proof for its security, our protocol is more suitable for deployment in the mobile environment.
The public key infrastructure (PKI) based authentication protocol provides the basic security services for vehicular ad-hoc networks (VANETs). However, trust and privacy are still open issues due to the unique characteristics of vehicles. It is crucial for VANETs to prevent internal vehicles from broadcasting forged messages while simultaneously protecting the privacy of each vehicle against tracking attacks. In this paper, we propose a blockchain-based anonymous reputation system (BARS) to break the linkability between real identities and public keys to preserve privacy. The certificate and revocation transparency is implemented efficiently using two blockchains. We design a trust model to improve the trustworthiness of messages relying on the reputation of the sender based on both direct historical interactions and indirect opinions about the sender. Experiments are conducted to evaluate BARS in terms of security and performance and the results show that BARS is able to establish distributed trust management, while protecting the privacy of vehicles.
Gihan J. Mendis, Moein Sabounchi, Wei Jin, Rigoberto Roche
Deep learning algorithms have recently gained attention due to their inherent capabilities and the application opportunities that they provide. Two of the main reasons for the success of deep learning methods are the availability of processing power and big data. Both of these two are expensive and rare commodities that present limitations to the usage and implementation of deep learning. Decentralization of the processing and data is one of the most prevalent solutions for these issues. This paper proposes a cooperative decentralized deep learning architecture. The contributors can train deep learning models with private data and share them to the cooperative data-driven applications initiated elsewhere. Shared models are fused together to obtain a better model. In this work, the contributors can both design their own models or train the models provided by the initiator. In order to utilize an efficient decentralized learning algorithm, blockchain technology is incorporated as a method of creating an incentive-compatible market. In the proposed method, Ethereum blockchain's scripting capabilities are employed to devise a decentralized deep learning mechanism, which provides much higher, collective processing power and grants access to large amounts of data, which would be otherwise inaccessible. The technical description of the mechanism is described and the simulation results are presented.
Personal data are often collected and processed in a decentralized fashion, within different contexts. For instance, with the emergence of distributed applications, several providers are used to correlate their records, to provide personalized services to their clients. As such, to protect users' privacy, different pseudonyms are generally used for different contexts. These pseudonyms have to be unlinkable to prevent identifying records to be associated to the same user. Although unlinkable, these pseudonyms have to be processed and exchanged according to their owners' consent and in a privacy-preserving fashion. In this paper, we propose BDUA, a new Blockchain-based Data Usage Auditing system, that ensures a controlled yet privacy preserving exchange of distributed data, such that a set of authorized auditing entities are able to conduct an accurate auditing relying on registered blockchains' transactions.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
With the development of information and communication technology, the amount of data in the world is increasing dramatically every day. Now data has been recognized as a valuable asset, and monetization from valuable data becomes an urgent need. In light of this, many data trading platforms have emerged in recent years. Existing data trading schemes, however, generally rely on a third party to trade data. These schemes suffer from complex transaction process, high transaction cost, and possibly unfair exchange. In this paper, we propose two secure, fair and efficient data trading schemes that do not rely on any third party using blockchain. The first scheme achieves direct raw data exchange for large amount of data, while the second scheme achieves data statistics trading. We implement both our schemes with smart contracts, and conduct comprehensive experiments to evaluate their performance. The experiment results show that they are highly efficient in trading data: the first scheme can trade 100,000 data records within 1.51s, while the second scheme can process a statistic over a data set of 1,024 records within 1.99s.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Many civil engineering malpractices can be avoided if there are timely, transparent, and unalterable records of these activities. This paper describes an approach to achieve this purpose with blockchain technology. A novel blockchain system designed to avoid high volatility in token price and encourage public participation in maintaining the ledger is introduced. Civil engineering and construction are the first testing fields for the system. It is anticipated that the system, after successfully implemented, can extend its scope to other areas as well.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Usage-based Insurance (UBI) for vehicles determines the insurance premiums according to actual usage and driving pattern. It can significantly reduce insurance costs for safe drivers, however, UBI schemes require detailed driving data to determine the insurance premiums, which may lead to serious privacy breach for drivers. Moreover, most existing UBI schemes require a centralized insurance company as the intermediary to manage insurances. Such a centralized solution incurs too much monetary costs as well as time cost. In this paper, we propose PRIDE, a privacy-preserving and decentralized UBI scheme using the blockchain to record encrypted driving data, and the smart contract running on the blockchain to calculate insurance premiums. Different from existing UBI schemes, PRIDE achieves security and privacy without relying on any centralized party or any trusted/tamper-proof hardware. We have analyzed security of PRIDE and evaluated its performance. The results show that PRIDE is very efficient in processing UBI insurances - each insurance request can be processed in about 898ms.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Despite that the cloud computing is considered as the panacea of processing and analyzing IoT data, it shows drawbacks in many other aspects like latency, bandwidth, and mobility when transferring data from connected devices to the cloud. The fog computing paradigm extends the cloud and refers to a geographically distributed computing paradigm at the edge of loT networks. However, realizing fog computing still has a long way to go, especially when it comes to security in the context of loT unconventional characteristics such as scalability, heterogeneity, mobility and limited resources. In addition, applying social network principles to the loT seems to be appealing to build the Internet of Things as a network of peer-to-peer networks. In this paper, we introduce a hybrid architecture for the Internet of things, combing fog computing to ensure security in the trustless loT environment. By enabling our fog computing architecture with blockchain-based social networks, users could easily manage smart objects via establishing tamper-proof digital identities in a trustless environment and build a new class of authentication and authorization mechanisms for the loT. We also demonstrate and analyze the feasibility of our architecture with a prototype.
Juan Carlos Farah, Andrii Vozniuk, María Jesús Rodríguez‐Triana, Denis Gillet
The need to ensure privacy and data protection in educational contexts is driving a shift towards new ways of securing and managing learning records. Although there are platforms available to store educational activity traces outside of a central repository, no solution currently guarantees that these traces are authentic when they are retrieved for review. This paper presents a blueprint for an architecture that employs blockchain technology to sign and validate learning traces, allowing them to be stored in a distributed network of repositories without diminishing their authenticity. Our proposal puts participants in online learning activities at the center of the design process, granting them the option to store learning traces in a location of their choice. Using smart contracts, stakeholders can retrieve the data, securely share it with third parties and ensure it has not been tampered with, providing a more transparent and reliable source for learning analytics. Nonetheless, a preliminary evaluation found that only 56% of teachers surveyed considered tamper-evident storage a useful feature of a learning trace repository. These results motivate further examination with other end users, such as learning analytics researchers, who may have stricter expectations of authenticity for data used in their practice.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
The emerging data-driven techniques have greatly increased the demand for effective data sharing infrastructure, which is our fundamental motivation in designing effective data trade paradigms. One of the critical challenges of data sharing is to achieve a good trade-off between the privacy and data utility. To address this challenge, in this paper we exploit the Blockchain techniques and contract theory to design a Blockchain-based peer-to-peer data trading mechanism. In our proposed mechanism, the data trading is supported by Ethereum Blockhain technique. To effectively capture and regulate the complex interaction between the data aggregators (AGG) and the data owners, we propose a contract theoretic approach to design the smart contract that is the essential component of Ethereum Blockchain. The performance of our proposed Blockchain-enabled data trading mechanism is evaluated.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Public key distribution and device authentication remain the main security challenges in many systems and applications. Existing solutions are based on Public Key Infrastructures (PKI) backed by Certificate Authorities (CA) to validate the authenticity of the devices. However, distributing and provisioning certificates for each client showed to be impractical especially for Internet of Things (IoT) devices. In this paper we propose a distributed PKI (Public Key Infrastructure) platform based on the Ethereum Blockchain. It contains a decentralized key-store that holds the public keys of all devices, and includes a generic protocol for PSK (Pre-Shared Keys) distribution. PSK keys can then be used by PSK-based security protocols (TLS-PSK, DTLS-PSK, SRTP...) for securing the communication channel between two devices. This platform includes a client-side module, a public key management module configured on the server, and a smart contract software deployed on the Ethereum Blockchain network. This generic platform can be used by many applications for client and server authentication, data integrity, and secure peer to peer communications. Moreover, this promising system may potentially eliminate the trust requirement imposed by the existing PKI/CAs infrastructure on clients.
Leveraging the wisdom of crowd for knowledge discovery and monetization is increasingly popular nowadays. Among others, one popular way of leveraging the crowd wisdom is crowdsensing with truth discovery, which is able to discover truthful knowledge from the unreliable sensory data harvested from mobile clients. In order to become truly successful, however, a number of challenges are yet to be addressed. First, safeguarding clients' sensory data is demanded for privacy protection. Second, in many real crowdsensing applications, data are usually collected in a streaming manner, so truth discovery is naturally required to be efficiently conducted in a streaming fashion. Thirdly, knowledge monetization should be made full-fledged, endowed with features of transparency and streamlined processing while fully addressing the practical needs of parties in the monetization ecosystem. In this paper, we present our initial effort on a crowdsensing framework that enables privacy-preserving knowledge discovery and full-fledged blockchain-based knowledge monetization. Our framework enables privacy-preserving and efficient truth discovery over encrypted crowdsensed data streams for truthful knowledge discovery. Meanwhile, with careful integration of the newly emerging blockchain-based smart contract technology, our framework allows full-fledged knowledge monetization. Tackling the challenges of monetization fairness and (on-chain) knowledge confidentiality, our customized knowledge monetization design well respects the interests of knowledge seller and requester, with full support of transparency, streamlined processing, and automatic quality-aware rewards for clients. Extensive experiments on Microsoft Azure cloud and Ethereum blockchain demonstrate the practically affordable performance of our design.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Blockchain is one type of distributed ledger technology, which comes from Bitcoin, a peer to peer electronic cash system. Its characteristics like decentralization and immutability make it possible to resolve data barrier and security problems in centralized system. In this paper, we discussed the existing problems of advanced manufacturing and several advantages while applying blockchain. Then we proposed a blockchain model for industrial internet based on well-known blockchain system such as bitcoin ethereum and hyperledger fabric. After that, we gave the workflow for a personalized service in this blockchain model.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
According to HIPAA (Health Insurance Portability and Accountability Act), the medical insurance claim process is carried out by healthcare providers, insurance companies, and clearinghouses. The clearinghouse coordinates the medical insurance claims between providers and insurance companies. As centralized communication hubs, clearinghouses may maliciously or unintentionally leak patient information. In this work, we propose a distributed solution to replace the role of clearinghouses during health insurance claim process and mitigate the risk of data leakage among parties in Healthcare sector. Our solution enhances the patients' privacy protection through developing a HIPAA compliance system for the medical insurance claim process in a decentralized manner using blockchain technology. Blockchain ensures transaction integrity and anonymity of cryptocurrencies by using distributed immutable ledgers. We first design data structures for patient information, medical service record, insurance payment, and insurance agreements within the ledger. We then focus on defining smart contracts for privacy assurance, as well as automating the insurance claim process. We implement and evaluate the proposed framework with Hyperledger Fabric, showing promising performance and response time.
This paper provides a vision and proposes mechanisms to transform the blockchain duplicated computing into distributed parallel computing architecture by transforming smart contract which features data driven from the ground up to support moving computing to native data strategy. This new distributed parallel computing architecture can be employed to build a large size of data set from various distributed hosted medical data sets which might consist of personal electronic medical record (EMR) and various medical data. This large medical data set will enable researchers to jump start the deep learning research for medical domain. Distributed data management, distributed data sharing, and distributed learning are the core mechanisms in the new architecture. The required new researches and developments to employ Google federated learning and transfer learning algorithms in this new architecture are discussed. The approach and mechanism enabled by the new architecture is illustrated to build a real world evidence of clinical trial toward personal and precision medicine. Research issues and technical challenges are provided.
Γεώργιος Σπαθούλας, Anastasija Collen, Pankaj Pandey, Niels Alexander Nijdam · 10 authors
The European research project GHOST challenges the traditional cyber security solutions for the Internet of Things (IoT) sector by exploiting novel technologies, such as blockchain, to provide resilience and integrity of decision making on the communication exchange in a smart home context. When it comes to novel cyber security solutions for extremely heterogeneous environments like IoT and smart homes, the key focus is typically given to the understanding of network activities and elimination of suspicious traffic. The GHOST project adds an extra dimension to this approach by integrating blockchain technology at its core decision mechanism. On a daily basis, each GHOST installation is encountering malicious behaviour and suspicious IoT communications, where easy information sharing with other installations, as well as decentralised decision making, are mandatory features for the efficient protection of the end-user. GHOST's Smart Contracts (SC) are designed to tackle in an easy, yet productive way, the reporting on suspicious IP addresses which the IoT devices in a smart home are trying to communicate with. Two variations of blacklisting smart contracts are presented in this paper, covering a diverse spectrum of possible attack vectors while closely following the Privacy by Design (PbD) principles. A reputation scoring scheme for malicious IPs reporting is integrated in the SC, uncovering the implementation details on the penalisation of existing entries in case of malicious behaviour of reporting devices.
Mobile peer to peer (P2P) networks offer a huge potential for distributed mobile P2P crowd services (MPCS), which enable data and computational tasks to be offloaded and executed directly between mobile devices. Similar to centralised mobile crowd services, such as mobile crowdsensing, incentivisation mechanisms are core to encouraging mobile users to participate in MPCS systems. However, due to the impact of task execution failures and unreliable behaviours of mobile users (particularly task requesters), it is a daunting task to design and implement an incentivisation mechanism to cater for the needs of MPCS systems. In this paper, we propose a fault-tolerant incentivisation mechanism (FTIM) for MPCS systems. With conditional payment strategies, FTIM is proven to accommodate the requirements of two important application scenarios by achieving mechanism properties such as incentive compatibility, economic efficiency, individual rationality, and weak budget balance. Moreover, to tackle the practical challenges in implementing FTIM in the real world, we design a MPCSTo-ken smart contract to facilitate its service auction, task execution and payment settlement process. We implement the MPCSToken contract on Ethereum blockchain. Both real-world experiment and simulation results show that the system is cost effective for deployments and improves the overall mobile users' utility by exploring the opportunities offered by MPCS.
Blockchain is one of the technology innovations for sharing data across organizations through a peer to peer overlay network. Many blockchain- based data sharing applications, such as sharing Electronic Health Records (EHRs) among different Care Delivery Organizations (CDOs), require privacy preserving verification services with dual capabilities. On one hand, the users want to verify the authenticity of EHR data as well as the identity of the signer. On the other hand, the signer wants to keep his real identity private such that others cannot trace and infer his identity information. However, typical blockchain systems that use pseudonyms as public keys, such as Bitcoin's blockchain, cannot support such privacy-preserving verification. In such systems, it is hard to verify the authenticity of signer's identity, and adversaries or curious parties can guess the real identity from the series of statements and actions taken with a specific pseudonym through inference attacks, such as by transaction graph analysis. In this paper, we propose a decentralized attribute- based signature scheme for healthcare blockchain, which provides efficient privacy-preserving verification of authenticity of EHR data and signer's identity. We also describe a holistic on-chain and off- chain collaborative storage system for efficient storage and verification EHR data. The analysis and experiments show that our scheme is effective and deployable.
The blockchain emerged as a novel distributed consensus scheme that allows transactions, and any other data, to be securely stored and verified without the need of any centralized authority. Distributed trust and therefore security and privacy are at the core of the blockchain technologies, and have the potential to either make them a success or cause them to fail. This special issue of IEEE Security & Privacy is an attempt to collect the most interesting ideas from the community of researchers and professionals working on blockchain security and privacy.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Harsh Desai, Kevin Liu, Murat Kantarcıoğlu, Lalana Kagal
As more and more data is collected for various reasons, the sharing of such data becomes paramount to increasing its value. Many applications ranging from smart cities to personalized health care require individuals and organizations to share data at an unprecedented scale. Data sharing is crucial in today's world, but due to privacy reasons, security concerns and regulation issues, the conditions under which the sharing occurs needs to be carefully specified. Currently, this process is done by lawyers and requires the costly signing of legal agreements. In many cases, these data sharing agreements are hard to track, manage or enforce. In this work, we propose a novel alternative for tracking, managing and especially adjudicating such data sharing agreements using smart contracts and blockchain technology. We design a framework that generates smart contracts from parameters based on legal data sharing agreements. The terms in these agreements are automatically adjudicating by the system. Monetary punishment can be employed using secure voting by external auditors to hold the violators accountable. Our experimental evaluation shows that our proposed framework is efficient and low-cost.
Sara Rouhani, Luke Butterworth, Adam D. Simmons, Darryl G. Humphery · 5 authors
The set of distributed ledger architectures known as blockchain is best known for cryptocurrency applications such as Bitcoin and Ethereum. These permissionless block chains are showing the potential to be disruptive to the financial services industry. Their broader adoption is likely to be limited by the maximum block size, the cost of the Proof of Work consensus mechanism, and the increasing size of any given chain overwhelming most of the participating nodes. These factors have led to many cryptocurrency blockchains to become centralized in the nodes with enough computing power and storage to be a dominant miner and validator. Permissioned chains operate in trusted environments and can, therefore, avoid the computationally expensive consensus mechanisms. Permissioned chains are still susceptible to asset storage demands and non-standard user interfaces that will impede their adoption. This paper describes an approach to addressing these limitations: permissioned blockchain that uses off-chain storage of the data assets and this is accessed through a standard browser and mobile app. The implementation in the Hyperledger framework is described as is an example use of patient-centered health data management.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Existing client onboarding and Know Your Customer (KYC) processes are typically slow, expensive and often accomplished in-person. Moreover, the current identity management models in practice deprive users from having complete control over their digital identity data. Users' identity attributes are stored on multiple centralized repositories, which often follow inadequate security policies. In this paper, we take advantage of Hyperledger Indy, a public and permissioned distributed ledger technology (DLT), to develop a digital onboarding framework based on the Self-Sovereign Identity (SSI) principles. With this framework we take a step towards tackling a number of weaknesses in current KYC processes and identity management models, while addressing the requirements associated with SSI, Privacy by Design and European Union's General Data Protection Regulation (GDPR).
Blockchain, as a mechanism to decentralize services, security, and verifiability, offers a peer-to-peer system in which distributed nodes collaboratively affirm transaction provenance. In particular, blockchain enforces continuous storage of transaction history, secured via digital signature, and affirmed through consensus. In this study, we consider the recent surge in blockchain interest as an alternative to traditional centralized systems, and consider the emerging applications thereof. In particular, we assess the key techniques required for blockchain implementation, offering a primer to guide research practitioners. We first outline the blockchain framework in general, and then provide a detailed review of the component data and network structures. Additionally, we consider the breadth of applications to which blockchain has been applied, broadly implicating Internet of Things (IoT), Big Data, and Cloud and Edge computing paradigms, along with many other emerging applications. Finally, we assess the various challenges to blockchain implementation for widespread practical use, considering the security vulnerabilities to majority attacks, selfish mining, and privacy leakage, as well as performance limitations of blockchain platforms in terms of scalability and availability.