Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results ยท page 23 of 38

Clear filters
Jul 21, 2023ยท2023 IEEE 6th International Conference on Electronic Information and Communication Technology (ICEICT)
1 cites
A Reputation-Based Learning Nodes Selection Algorithm for Decentralized Federated Learning

Jing Qu, Yunxia Feng, Hongda Xu, Kang Xie

Due to the increasing risk of data security, distributed learning model based on real-world data analytics has attracted more attention, and it has been applied in a variety of areas ranging from medical screening to agriculture, industry, finance, and defense science. Generally, participants provide their own private datasets to efficiently train the distributed models on real-world data, which inevitably leads to privacy and security concerns. Without uploading raw training data, Federated Learning enables large-amount nodes to train a distributed model and preserves security and privacy of user sensitive information. However, Federated Learning is limited by expensive computational costs during collective parameter server aggregation. Moreover, malicious nodes among computing nodes interfere model training to some extent and further cause the leakage of data privacy. To address the above-mentioned problems, we propose a novel Decentralized Federated Learning by integrating blockchain and federation learning for efficient node selection and communication. Based on the proposed model, a reputation-based learning nodes selection algorithm is presented to measure the probability of honest participation of distributed nodes. The simulation results demonstrate that our RBLNS is capable of improving the training result significantly and decreasing convergence time.

Privacy-Preserving Technologies in Data
Cryptography and Data Security
Access Control and Trust
Original source
Jul 10, 2023ยทModern Optimization Methods for Decision Making Under Risk and Uncertainty
0 cites
Authentication for Coalition Groups

ะ. ะ’. ะะฝะธัะธะผะพะฒ, Andrey Novokshonov

We give a short tutorial survey of authentication protocols for two parties. We also describe a new authentication protocol based on the splitting of a secret given by a trusted third party. We describe a fast three-round mutual authentication protocol for parties A and B belonging to the same coalition group. A coalition group is a group of mutually trusted entities that act independently in an unreliable, possibly malicious, environment and communicate through unsecured open channels. Parties A and B keep their own independent long-term private keys that are used in the process of authentication and can be used for other purposes. The scheme assumes an initial setup with a trusted third party. This party initiates another secret information that includes factors of a large RSA modulus. For authentication, both parties must demonstrate each other the knowledge of their private keys without revealing them and the ability to factorize a large RSA modulus. Thus, the protocol based on the suggested scheme provides reciprocal authentication. The scheme possesses all desirable properties of an interactive proof, i.e., completeness, soundness, and honest-verifier zero-knowledge. The security of the protocol relies on assumptions of difficulty of the RSA factorization and existence of a cryptographic hash function.

Access Control and Trust
Korean Peninsula Historical and Political Studies
Original source
Jul 10, 2023ยทNational Institute of Standards and Technology
0 cites
A Security Perspective on the Web3 Paradigm

Dylan Yaga

Certain commercial equipment, instruments, software, or materials, commercial or non-commercial,

Open access
Information and Cyber Security
Access Control and Trust
Privacy, Security, and Data Protection
Original source
Jul 4, 2023ยทUPCommons institutional repository (Universitat Politรจcnica de Catalunya)
0 cites
Ownership-based access control based on NFTs

Fortiร  Ramirez, Gabriel

During the past years a concept that has emerged in the Blockchain space is tokenization, which is the process of transforming ownerships and rights of assets owned by an individual into a digital form. Thanks to tokenization, internet services can now leverage access control systems that do not grant access based on identity (who you are) but rather on ownership (what you own). These types of systems can be classified as Ownership Based Access Control (OBAC) systems. The aim of this project is to prove the viability and compatibility with the current authorization paradigm of these kind of systems by implementing an access control enforcement service for digital resources based on the ownership of Non-Fungible Tokens (NFTs). The results show that OBAC is feasible and can be integrated with the existing industry-standard protocols for authorization. It has been proved that, by using OBAC users no longer have to disclose their identity when accessing a service, resulting in improved privacy. Furthermore, access to a digital service becomes transferable and tradeable if its access is based on ownership of a NFT.

Open access
Access Control and Trust
Blockchain Technology Applications and Security
Digital Rights Management and Security
Original source
Jul 1, 2023ยทHeliyon
19 cites
A blockchain-enabled sharing platform for personal health records

Yibin Dong, Seong K. Mun, Yue Wang

Background: Longitudinal personal health record (PHR) provides a foundation for managing patients' health care, but we do not have such a system in the U.S. except for the patients in the Department of Veterans Affairs. Such a gap exists mainly in the rest of the U.S. by the fact that patients' electronic health records are scattered across multiple health care facilities and often not shared due to privacy, security, and business interests concerns from both patients and health care organizations. In addition, patients have ethical concerns related to consent. To patients, data security, privacy, and consent are based on trustfulness, rather than patients' engagement in ensuring only authorized people can view their PHRs with patient-managed granularity. Resolving these challenges is an important step in making longitudinal PHR useful for patient care. Objective: This research aims to design and implement a blockchain-enabled sharing platform prototype for PHR with desired patient-controlled data security, privacy, and consent granularity. Methods: Built upon our prior work of a blockchain-enabled access control (BAC) model, we design a blockchain-enabled sharing platform for PHR with patient-controlled security, privacy, and consent granularity. We further implement the construct by building a prototypical platform among a patient and two typical health care organizations. Health organizations that hold the patient's electronic health records can join the platform with trust based on the validation from the patient. The mutual trust can be established through a rigorous validation process by both the patient and the built-in Hyperledger Fabric blockchain consensus mechanism. Results: We proposed a system trusted by patients and health care providers and constructed a Web-based PHR sharing platform with patient-controlled security, privacy, and consent granularity. We analyzed the system scalability in three aspects and showed millisecond range of performance when simultaneously changing access permissions on hundreds of PHRs. Consent, security and privacy of the model are ensured by the merits of the BAC model. We discovered the current blockchain model limits the system scalability due to using a non-graphical database. A new graphical database is suggested for future improvements. Conclusions: In this research, we report a solution to electronically sharing and managing patients' electronic health records originating from multiple organizations, focusing on privacy, security, and granularity control of consent in the U.S. Specifically, the system protects data security and privacy, and provides auditability, scalability, distributedness, patient consent autonomy, and zero-trust capabilities. The prototypical instantiation of the designed model suggested the feasibility of combining emerging blockchain technology with next generation access control model to tackle a longstanding longitudinal PHR problem.

Open access
Electronic Health Records Systems
Blockchain Technology Applications and Security
Access Control and Trust
Original source
May 30, 2023ยทVidhyayana
0 cites
Secure Access Control in Cloud Computing Environments: Smart Contract Blockchain

Hritwika Dubey, Kashish Roy

Over the years, Cloud Computing has become rapidly embraced due to its flexibility and cost-effectiveness. However, it also presents a number of security challenges, especially with regards to access control. Conventional access control methods, like Role-based Access Control, have limitations in terms of centralized control, lack of transparency, and susceptibility to cyber-attacks. As a result, there is a need for more efficient, transparent, and secure Access Control mechanisms in Cloud Computing environments. In this Research paper, we put forward a non-centralized and tamper-proof Access Control mechanism that uses smart contract blockchain technology to address these limitations. Our model leverages the Ethereum platform's smart contract feature to stockpile access control programs and enable secure verification of userโ€™s access requests. The smart contract blockchain is immutable, transparent, and decentralized, which makes it resistant to tampering and provides a high degree of transparency in the access control process. Our proposed model has several advantages over traditional access control mechanisms. Firstly, it provides an effective and automated approach to manage access control policies. With our model, access control policies can be easily updated and enforced through smart contracts, which eliminates the need for manual updates and reduces the risk of errors. Secondly, it provides a high degree of transparency in the access control process, which allows users to verify the legitimacy of their access requests and ensures that access control policies are being enforced fairly. Finally, it offers a heightened level of security, as the Smart Contract Blockchain is resistant to tampering and it offers a platform for Access Control that is both secure and non-centralized. To assess the efficacy of our model for Access Control management, we performed a series of experiments in a simulated Cloud Computing environment. The findings revealed that our model offers a superior and secure approach for managing access control programs compared to conventional methods. To conclude, our study suggests a secure and non-centralized access control solution by utilizing blockchain technology through smart contracts, to address the limitations of conventional Access Control methods in Cloud Computing environments. Our model provides a more efficient, transparent, and secure way to manage Access Control program to maintain the authenticity and confidentiality of Cloud services.

Open access
Access Control and Trust
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
May 17, 2023ยทInternational Journal on Recent and Innovation Trends in Computing and Communication
7 cites
Web3 Chain Authentication and Authorization Security Standard (CAA)

Nilesh P. Sable, Rahul Ganpatrao Sonkamble, Vijay U. Rathod, Swati Shirke ยท 6 authors

Web3 is the next evolution of the internet, which uses blockchains, cryptocurrencies, and NFTs to return ownership and authority to the consumers. The potential of Web3 is highlighted by the creation of decentralized applications (dApps), which are more secure, transparent, and tamper-proof than their centralized counterparts, allowing for new business models that were previously impossible on the traditional internet.Web3 also focuses on user privacy, where users have more control over their personal data and can choose to share only what they want. The emergence of Web3 represents an exciting new frontier in blockchain technology, and its focus on decentralization, user privacy, and trustless systems has the potential to transform the way we interact with the internet.Web3 authentication is required for enhanced security, increased privacy, and simplified user interface. Traditional login procedures and an authorization flow using web3 authentication work together seamlessly. However, there are several challenges associated with Web3, including scalability and regulatory issues. Chain Authentication and Authorization (CAA) is a multi-layer security mechanism that allows users to choose the security layer that suits them, just like a heavy iron chain, where the user and CAA developers act as blacksmith and form their security protocol that suits them. CAA is a solution to the challenges associated with Web3 authentication and authorization, and it focuses on creating a secure and decentralized authentication and authorization system that is scalable, flexible, and user-friendly.

Open access
Privacy, Security, and Data Protection
Spam and Phishing Detection
Access Control and Trust
Original source
May 10, 2023ยทarXiv (Cornell University)
0 cites
Speranza: Usable, privacy-friendly software signing

Kelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen Sollins

Software repositories, used for wide-scale open software distribution, are a significant vector for security attacks. Software signing provides authenticity, mitigating many such attacks. Developer-managed signing keys pose usability challenges, but certificate-based systems introduce privacy problems. This work, Speranza, uses certificates to verify software authenticity but still provides anonymity to signers using zero-knowledge identity co-commitments. In Speranza, a signer uses an automated certificate authority (CA) to create a private identity-bound signature and proof of authorization. Verifiers check that a signer was authorized to publish a package without learning the signer's identity. The package repository privately records each package's authorized signers, but publishes only commitments to identities in a public map. Then, when issuing certificates, the CA issues the certificate to a distinct commitment to the same identity. The signer then creates a zero-knowledge proof that these are identity co-commitments. We implemented a proof-of-concept for Speranza. We find that costs to maintainers (signing) and end users (verifying) are small (< 1 ms), even for a repository with millions of packages. Techniques inspired by recent key transparency systems reduce the bandwidth for serving authorization policies to 2 KiB. Server costs in this system are negligible. Our evaluation finds that Speranza is practical on the scale of the largest software repositories. We also emphasize practicality and deployability in this project. By building on existing technology and employing relatively simple and well-established cryptographic techniques, Speranza can be deployed for wide-scale use with only a few hundred lines of code and minimal changes to existing infrastructure. Speranza is a practical way to bring privacy and authenticity together for more trustworthy open-source software.

Open access
2 source records
cs.CR
Security and Verification in Computing
Access Control and Trust
Original source
May 8, 2023ยทNOMS 2023-2023 IEEE/IFIP Network Operations and Management Symposium
0 cites
Enabling Auditable Trust in Autonomous Networks with Ethereum and IPFS

Jaime Fรบster de la Fuente, รlvaro Pendรกs-Recondo, Leon Wong, Paul Harvey

Operation and management of telecommunication networks are increasingly difficult with the demands and behaviors of users exceeding the capacity of network engineers to keep pace. This has led to increased automation of the network, enabled by various forms of intelligent software. One such proposal from the ITU-T Focus Group on Autonomous Networks (standardization group) is an architecture to achieve self-driven automation (i.e. autonomy) of network operation, whereby technology from different operators and third parties is self-assembled and deployed in production networks. This raises questions and challenges regarding transparency, auditability, and trust while maintaining interoperability.This work presents an initial study of a distributed and decentralized marketplace to bring transparent and auditable trust to the proposed architecture without sacrificing interoperable functionality. We demonstrated this by our proof of concept implementation of both the proposed architecture and marketplace based on the combination of Ethereum and IPFS.

Open access
Access Control and Trust
Software-Defined Networks and 5G
Smart Grid Security and Resilience
Original source
May 7, 2023ยทarXiv (Cornell University)
0 cites
Which Games are Unaffected by Absolute Commitments?

Daji Landis, Nikolaj I. Schwartzbach

We identify a subtle security issue that impacts mechanism design in scenarios in which agents can absolutely commit to strategies. Absolute commitments allow the strategy of an agent to depend on the commitments made by the other agents. This changes fundamental game-theoretic assumptions by inducing a meta-game in which agents choose which strategies they commit to. We say that a game that is unaffected by such commitments is Stackelberg resilient and show that computing it is intractible in general, although it can be computed efficiently for two-player games of perfect information. We show the intuitive, but technically non-trivial result, that, if a game is resilient when some number of players have the capacity to make commitments, it is also resilient when these commitments are available to fewer players. We demonstrate the non-triviality of Stackelberg resilience by analyzing two escrow mechanisms from the literature. These mechanisms have the same intended functionality, but we show that only one is Stackelberg resilient. Our model is particularly relevant in Web3 scenarios, where these absolute commitments can be realized by the automated and irrevocable nature of smart contracts. Our work highlights an important issue in ensuring the secure design of Web3. In particular, our work suggests that smart contracts already deployed on major blockchains may be susceptible to these attacks.

Open access
3 source records
cs.GT
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
May 1, 2023ยท2023 IEEE/ACM International Conference on Software and System Processes (ICSSP)
3 cites
Adding Generic Role- and Process-based Behaviors to Smart Contracts using Dynamic Condition Response Graphs

Yibin Xu, Tijs Slaats, Boris Dรผdder, Thomas Hildebrandt

Smart contracts executed on blockchains are interactive programs where external actors generate events that trigger function invocations. Events can be emitted by participants asynchronously. However, some functionalities should be restricted to participants inhabiting specific roles in the system, which might be dynamically adjusted while the system evolves. We argue that current smart contract languages adopting imperative programming paradigms require additional complicated access control code. Furthermore, smart contracts are often developed independently and cannot share a joint access control policy. We propose to use Dynamic Condition Response Graphs for role-based and declarative access control for smart contracts. We show that they allow to capture and visualize a form of dynamic access control where access rights evolve as the contract state progresses. Their use supports straight-forward declaration of access control rights, improved code auditing, programming error reduction and improves usersโ€™ understanding of smart contracts.

Blockchain Technology Applications and Security
Access Control and Trust
FinTech, Crowdfunding, Digital Finance
Original source
Apr 28, 2023ยทCompanion Proceedings of the ACM Web Conference 2023
0 cites
Trusting Decentralised Knowledge Graphs and Web Data at the Web Conference

John Domingue, Allan Third, Marรญa-Esther Vidal, Philipp D. Rohde ยท 7 authors

Knowledge Graphs have become a foundation for sharing data on the web and building intelligent services across many sectors and also within some of the most successful corporations in the world. The over centralisation of data on the web, however, has been raised as a concern by a number of prominent researchers in the field. For example, at the beginning of 2022 a โ‚ฌ2.7B civil lawsuit was launched against Meta on the basis that it has abused its market dominance to impose unfair terms and conditions on UK users in order to exploit their personal data. Data centralisation can lead to a number of problems including: lock-in/siloing effects, lack of user control over their personal data, limited incentives and opportunities for interoperability and openness, and the resulting detrimental effects on privacy and innovation. A number of diverse approaches and technologies exist for decentralising data, such as federated querying and distributed ledgers. The main question is, though, what does decentralisation really mean for web data and Knowledge Graphs? What are the main issues and tradeoffs involved? These questions and others are addressed in this workshop.

Open access
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Access Control and Trust
Original source
Apr 13, 2023ยทHradec Economic Days ...
1 cites
Decentralized Autonomous Organizations and Trust: Approach to Trust in DAO in the Context of Existing Trust Theory

David ล imลฏnek

We are witnessing how numerous trends, including decentralization and the growing role of technology, permeate the way companies are organized, intersecting with the phenomenon of Decentralized Autonomous Organizations (DAO).This technologybased organization carries a pattern known as a zero-trust policy, aiming to eliminate the need for trust in an organization.It appears to oppose the existing research on trust in management and its usefulness to organizations.That brings the question of whether DAOs represent a change from a trend defined by a standard trust theory.This conceptual paper answers by looking at the Decentralized Autonomous Organizations phenomenon through the existing knowledge on trust, specifically through Dirks & Ferrin's trust theory, and compares the concept with the traditional organization.The investigation suggests that DAOs only partially eliminate or transform the need for trust compared to traditional organizations;the need for trust is still present and may even grow in future concept development.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
FinTech, Crowdfunding, Digital Finance
Original source
Mar 28, 2023ยทIEEE Transactions on Dependable and Secure Computing
14 cites
HCA: Hashchain-Based Consensus Acceleration Via Re-Voting

Zijian Zhang, Xuyang Liu, Meng Li, Hao Yin ยท 7 authors

In the context of consortium blockchain, consensus protocols set permission mechanisms to maintain a relatively fixed group of participants. They can easily use distributed consistent algorithms for achieving deterministic and efficient consensus and generate incessant blocks as the ledger. However, most of the existing consensus protocols do not sufficiently leverage the chain structure of blocks, and therefore leaving room for performance improvement. In this paper, we first propose a Hashchain-based Consensus Acceleration (HCA) protocol. The HCA protocol enables a leader to generate blocks that contain a quorum of votes on the previous block, and allow voters to re-vote for accelerating the block generation to Byzantine Fault Tolerance (BFT) consensus protocols. Then, we present a rolling-based leader selection (RLS) scheme to further optimize the HCA protocol. In the RLS scheme, the leader is changed in a round-robin fashion. Finally, theoretical analysis proves the safety, liveness and responsiveness of the optimized HCA protocol, while experimental evaluation shows that the optimized HCA protocol outperforms the existing BFT consensus protocols, from the viewpoint of efficiency.

Distributed systems and fault tolerance
Access Control and Trust
Cryptography and Data Security
Original source
Mar 16, 2023ยทarXiv (Cornell University)
3 cites
Nakamoto Consensus under Bounded Processing Capacity

Lucianna Kiffer, Joachim Neu, Srivatsan Sridhar, Aviv Zohar ยท 5 authors

For Nakamoto's longest-chain consensus protocol, whose proof-of-work (PoW) and proof-of-stake (PoS) variants power major blockchains such as Bitcoin and Cardano, we revisit the classic problem of the security--performance tradeoff: Given a network of nodes with finite communication- and computation-resources, against what fraction of adversary power is Nakamoto consensus (NC) secure for a given block production rate? State-of-the-art analyses of NC fail to answer this question, because their bounded-delay model does not capture the rate limits to nodes' processing of blocks, which cause congestion when blocks are released in quick succession. We develop a new analysis technique to prove a refined security--performance tradeoff for PoW NC in a bounded-capacity model. In this model, we show that, in contrast to the classic bounded-delay model, Nakamoto's private attack is no longer the worst attack, and a new attack we call the teasing strategy, that exploits congestion, is strictly worse. In PoS, equivocating blocks can exacerbate congestion, making traditional PoS NC insecure except at very low block production rates. To counter such equivocation spamming, we present a variant of PoS NC we call Blanking NC (BlaNC), which achieves the same resilience as PoW NC.

Open access
3 source records
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Cryptography and Data Security
Original source
Mar 15, 2023ยท2023 IEEE 15th International Symposium on Autonomous Decentralized System (ISADS)
0 cites
ISADS 2023 Cover Page

Authors unavailable

Welcome to the fifteenth Jubilee International Symposium on Autonomous Decentralized Systems (ISADS).As Lifetime Honorary Chair, I would like to thank you for coming to ISADS 2023. ISADS was founded in 1993 atKawasaki, Japan.Since then, ISADSs have been held world-wide every two years except in 2021 due to pandemic.They were successful in their high quality and broad international participation from academia, government and industry.At the first ISADS, the concept of autonomous decentralized systems (ADS) was well recognized.During the last 30 years, fields of ADS have been substantially advanced to provide solutions for control, communication, computing, service systems and further to organization and finance management, such as FinTech along with rapid development of other related technologies and management.ISADS 2023 reflects not only such maturity but also innovation in ADS concept, technology and application as well as further integration with other heterogeneous fields.Now, structures of Society, Value, Business and Technology have been unpredictably and rapidly transformed under climate change, pandemic and economic turmoil.ADS, which behaves as a living system comprised of largely autonomous and decentralized subsystems, has been successfully contributing to fulfill adaptive, reliable and expandable properties under changing and transforming environment as consistent concept.The continuous growth of ISADS in size and diversity is reflected by the sponsoring society, the Computer Society of the Institute of Electrical and Electric Engineers (IEEE) together with the cooperating societies including the International Federation for Information Processing (IFIP), the International Federation of Automatic Control (IFAC), the Institute of Electronics, Information and Communication Engineers (IEICE), Japan and Object Management Group (OMG), as well as the strong supporting organization of Universidad Panamericana, Mexico.I hope that you will find the program stimulating and that you will take the opportunity to meet with your colleagues from around the world to engage in social as well as technical discussions.In addition, technical sessions and workshops on the hot topics of technologies and their advanced applications are jointly arranged.The success of the symposium depends on the dedication and contributions of many volunteers, committee members, authors, reviewers, speakers, workshop chairs, session chairs and supporting personnel, and the strong organizations.I would like to thank Honorary Chairs, Bojan Cukic and General Chair, Carlos Perez for their direction.

Open access
Mobile Agent-Based Network Management
Access Control and Trust
Distributed systems and fault tolerance
Original source
Mar 15, 2023ยทCyber Security and Applications
96 cites
Securing distributed systems: A survey on access control techniques for cloud, blockchain, IoT and SDN

Lewis Golightly, Paolo Modesti, Rรฉmi Garcia, Victor Chang

Access Control is a crucial defense mechanism organizations can deploy to meet modern cybersecurity needs and legal compliance with data privacy. The aim is to prevent unauthorized users and systems from accessing protected resources in a way that exceeds their permissions. The present survey aims to summarize state-of-the-art Access Control techniques, presenting recent research trends in this area. Moreover, as the cyber-attack landscape and zero-trust networking challenges require organizations to consider their Information Security management strategies carefully, in this study, we present a review of contemporary Access Control techniques and technologies being discussed in the literature and the various innovations and evolution of the technology. We also discuss adopting and applying different Access Control techniques and technologies in four upcoming and crucial domains: Cloud Computing, Blockchain, the Internet of Things, and Software-Defined Networking. Finally, we discuss the business adoption strategies for Access Control and how the technology can be integrated into a cybersecurity and network architecture strategy.

Open access
Access Control and Trust
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Mar 13, 2023ยทSustainability
11 cites
A Quantitative and Qualitative Review of Blockchain Research from 2015 to 2021

Xiaolin Li, Hongbo Jiao, Liming Cheng, Yilin Yin ยท 7 authors

Blockchain has the potential to reconfigure the contemporary economic, legal, political and cultural landscape, causing a flood of research on this topic. However, limited efforts have been made to conduct retrospective research to appraise the blockchain studies in the recent period, easily leading to a neglect of new technological trends. Consequently, the present research designs a quantitative- and qualitative-analysis procedure to review the latest research status. Adopting a four-step workflow, six research hotspots (i.e., the specific application areas of blockchain technology, the integration of blockchain and other technologies, the driving factors of blockchain, the values of blockchain technology, the types of blockchain and the core technologies of blockchain) and five research frontiers (i.e., entrepreneurship, contract, industrial internet, data management and distributed ledger technology) were detected using quantitative analysis. Furthermore, three other topics (i.e., the Internet of things, access control and trust) and two research gaps (i.e., the true effect of blockchain technology on firmsโ€™ operational efficiency and the regulation of the โ€œdark sidesโ€ of blockchain technology) were also identified, using qualitative analysis. Finally, the evolutionary paths were qualitatively analyzed, and then three phases of blockchain research were summarized. The conclusions are able to provide a more comprehensive enlightenment regarding blockchainโ€™s research hotspots, research frontiers, evolutionary paths and research gaps in the recent period, from 2015 to 2021, and to provide a reference for future research.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
IoT and Edge/Fog Computing
Original source
Mar 1, 2023ยทSeoul National University Open Repository (Seoul National University)
0 cites
Entity Classification Framework for Decentralized Autonomous Organization from Korean Unincorporated Entity Law Perspective

์œ ์˜์šด

ํƒˆ์ค‘์•™ํ™”๋œ ์ž์œจ์กฐ์ง์€ ๋ธ”๋ก์ฒด์ธ ๋„คํŠธ์›Œํฌ์— ๊ธฐ๋ฐ˜ํ•˜์—ฌ ํ™œ๋™ํ•˜๋Š” ๊ตญ์ œ์ ์ธ ๋‹จ์ฒด๋กœ์„œ ์ด์‚ฌํšŒ์™€ ๊ฐ™์€ ๊ฒฝ์˜์ง„์ด ์•„๋‹Œ ๊ตฌ์„ฑ์›๋“ค์ด ์ง์ ‘ ์ž๋™ํ™”๋œ ์˜์‚ฌ๊ฒฐ์ •์‹œ์Šคํ…œ์„ ์ด์šฉํ•˜์—ฌ ์˜์‚ฌ๊ฒฐ์ •์„ ๋‚ด๋ฆฌ๊ณ , ๊ทธ ๊ฐ™์€ ๋‹จ์ฒด์˜์‚ฌ์— ๋”ฐ๋ผ ์šด์˜๋˜๋Š” ์ธ์  ๋‹จ์ฒด์ด๋‹ค. ์ด๋“ค์ด ํƒˆ์ค‘์•™ํ™”๋œ ๊ฐ€๋ฒ„๋„Œ์Šค๋ฅผ ๊ตฌ์ถ•ํ•˜๋Š” ๊ณผ์ •์€ ์‚ฌ๋‹จ์ด ์ •๊ด€ ๊ธฐํƒ€ ๊ทœ์•ฝ์„ ๋งˆ๋ จํ•˜๊ณ  ๊ทธ์— ๋”ฐ๋ผ ์กฐ์ง์„ ๊ฐ–์ถฐ์„œ ๋…๋ฆฝ๋œ ์‚ฌํšŒ์  ์‹ค์ฒด๋กœ ์ธ์ •๋ฐ›๋Š” ๊ณผ์ •๊ณผ ์œ ์‚ฌํ•œ ๋ฉด์ด ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ ํƒˆ์ค‘์•™ํ™”๋œ ์ž์œจ์กฐ์ง์€ ์‚ฌ๋‹จ์˜ ์„ฑ๊ฒฉ์„ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค๊ณ  ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ๊ตญ์ œ์ ์ธ ๋‹จ์ฒด๋กœ์„œ์˜ ์„ฑ๊ฒฉ์„ ๋„๋Š” ํƒˆ์ค‘์•™ํ™”๋œ ์ž์œจ์กฐ์ง์˜ ๋‹จ์ฒด๋ฒ•์  ์ง€์œ„๋ฅผ ํŒ๋‹จํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๊ตญ์ œ์กฐ์•ฝ๊ณผ ๊ตญ์ œ์‚ฌ๋ฒ•์ƒ์˜ ์Ÿ์ ์„ ๊ณ ๋ คํ•ด์•ผ ํ•œ๋‹ค. ๋‹ค๋งŒ, ์™ธ๊ตญ์˜ ๊ฒฝ์šฐ, ๋Œ€์ฒด๋กœ ์ด๋“ค์„ ์กฐํ•ฉ์ด๋‚˜ ํŒŒํŠธ๋„ˆ์‰ฝ๊ณผ ์œ ์‚ฌํ•œ ๋‹จ์ฒด๋กœ ๋ณด์•„ ๊ตฌ์„ฑ์›์˜ ์œ ํ•œ์ฑ…์ž„์„ ๋ถ€์ •ํ•˜๋Š” ๊ฒฝํ–ฅ์ด ์žˆ๋‹ค. ๊ทธ๋ฆฌํ•˜์—ฌ ๊ทธ ๊ตฌ์„ฑ์›๋“ค์—๊ฒŒ ์œ ํ•œ์ฑ…์ž„์„ ์ธ์ •ํ•˜๊ณ  ํƒˆ์ค‘์•™ํ™”๋œ ์ž์œจ์กฐ์ง์˜ ๋…๋ฆฝ๋œ ์‚ฌํšŒ์  ์‹ค์ฒด๋กœ์„œ์˜ ์ง€์œ„๋ฅผ ์ธ์ •ํ•˜๊ธฐ ์œ„ํ•ด, ์ด๋“ค์„ ์œ ํ•œ์ฑ…์ž„ํšŒ์‚ฌ๋กœ ์ธ์ •ํ•˜๋ ค๋Š” ์ž…๋ฒ•๋ก€๊ฐ€ ์ƒ๊ธฐ๊ธฐ๋„ ํ•˜์˜€๋‹ค. ์ด๋“ค ์กฐ์ง์„ ์šฐ๋ฆฌ๋‚˜๋ผ ๋‹จ์ฒด๋ฒ• ๊ด€์ ์—์„œ ์‚ดํŽด๋ณด๋Š” ๊ฒฝ์šฐ, ๋ฒ•์ธ ์•„๋‹Œ ์‚ฌ๋‹จ์œผ๋กœ ํ‰๊ฐ€ํ•  ์ˆ˜ ์žˆ์„์ง€๋ฅผ ์‚ดํŽด๋ณผ ํ•„์š”๊ฐ€ ์žˆ๋‹ค. ์™œ๋ƒํ•˜๋ฉด, ์ด๋“ค์ด ๋ฒ•์ธ ์•„๋‹Œ ์‚ฌ๋‹จ์œผ๋กœ ์ทจ๊ธ‰๋˜๋Š” ๊ฒฝ์šฐ, ์ด์œ ๊ทœ์ •์— ๋”ฐ๋ผ ๊ตฌ์„ฑ์›์˜ ์ฑ…์ž„์žฌ์‚ฐ์ด ๋ถ„๋ฆฌ๋˜์–ด ์‚ฌ์‹ค์ƒ ์œ ํ•œ์ฑ…์ž„๊ณผ ๊ฐ™์€ ํšจ๊ณผ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค. ๋‹ค๋งŒ, ๋ฌธ์ œ๋Š” ํƒˆ์ค‘์•™ํ™”๋œ ์ž์œจ์กฐ์ง์ด ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ํŠน์ง•๋“ค์„ ์šฐ๋ฆฌ ๋ฏผ๋ฒ•์ƒ์˜ ๋ฒ•์ธ ์•„๋‹Œ ์‚ฌ๋‹จ์˜ ๋ฒ•๋ฆฌ๋กœ ํฌ์„ญํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ์—ฌ๋ถ€์ด๋‹ค. ์˜ˆ๋ฅผ ๋“ค๋ฉด, ๋Œ€ํ‘œ์ž๊ฐ€ ์„ ์ž„๋˜์–ด ์žˆ์ง€ ์•Š๊ณ , ๊ตฌ์„ฑ์›์ง€์œ„ ๋“์‹ค ๋ณ€๊ฒฝ์„ ๊ฐ€๋ฒ„๋„Œ์Šค ํ† ํฐ์ด๋ผ๋Š” ๊ฐ€์ƒ์ž์‚ฐ๊ณผ ์—ฐ๋™์‹œํ‚ค๊ณ , ์กฐ์ง์ด ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ€์ƒ์ž์‚ฐ์„ ๊ตฌ์„ฑ์›๋“ค์—๊ฒŒ ๋ถ„๋ฐฐํ•˜๊ณ , ์˜๋ฆฌ ๋ชฉ์ ์œผ๋กœ ์šด์˜๋˜๋”๋ผ๋„ ์ด๋ฅผ ๋ฏผ๋ฒ•์ƒ ๋ฒ•์ธ ์•„๋‹Œ ์‚ฌ๋‹จ์œผ๋กœ ์ทจ๊ธ‰ํ•  ์ˆ˜ ์žˆ์„์ง€๋ฅผ ์‚ดํŽด๋ณด์•„์•ผ ํ•œ๋‹ค. ๊ณ„์†ํ•ด์„œ ์˜จ๋ผ์ธ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜์—ฌ ๋‹ค์–‘ํ•œ ๊ตญ์ œ์  ์„ฑ๊ฒฉ์„ ๋ˆ ๋‹จ์ฒด๊ฐ€ ์ƒ๊ฒจ๋‚  ๊ฒƒ์ด๋‹ค. ์ด๋“ค์ด ๋ฒ•์ธ๊ฒฉ์„ ์ทจ๋“ํ•˜์ง€ ๋ชปํ•œ ๊ฒฝ์šฐ, ๊ทธ ์†์ธ๋ฒ•์„ ์–ด๋–ป๊ฒŒ ๊ฒฐ์ •ํ•˜๊ณ , ๊ตญ๋‚ด ๋‹จ์ฒด๋ฒ•์ƒ ์ด๋“ค์„ ์–ด๋–ป๊ฒŒ ํ‰๊ฐ€ํ•ด์•ผ ํ• ์ง€๊ฐ€ ๊ณ ๋ฏผ๋  ์ˆ˜ ๋ฐ–์— ์—†๋‹ค. ์šฐ๋ฆฌ ๋ฒ•์ธ ์•„๋‹Œ ์‚ฌ๋‹จ ์ œ๋„์— ๋Œ€ํ•œ ๋น„ํŒ์ด ์žˆ๊ธฐ๋Š” ํ•˜์ง€๋งŒ, ๋ฏผ๋ฒ• ๊ฐœ์ • ์ž‘์—…์ด ๋งˆ๋ฌด๋ฆฌ๋˜๊ธฐ ์ „๊นŒ์ง€๋Š” ์ด ๊ฐ™์€ ๋‹จ์ฒด์˜ ๊ตญ๋‚ด ๋‹จ์ฒด๋ฒ•์ƒ ์ง€์œ„๋ฅผ ์‚ดํŽด๋ณผ ๋•Œ ์šฐ๋ฆฌ๋‚˜๋ผ ํŠน์œ ์˜ ๋ฒ•์ธ ์•„๋‹Œ ์‚ฌ๋‹จ์œผ๋กœ ์ทจ๊ธ‰ํ•  ์ˆ˜ ์žˆ์„์ง€ ๊ทธ๋ฆฌ๊ณ  ๊ทธ ์‹ค์ต์ด ๋ฌด์—‡์ผ์ง€๋„ ๊ณ ๋ฏผํ•ด ๋ณผ ํ•„์š”๊ฐ€ ์žˆ๋‹ค. A Decentralized Autonomous Organization (DAO) is an international organization that operates based on a blockchain network. It is a member-managed association that its members make decisions using an automated decision-making system by themselves without the board of directors and is operated according to the groups decision. The process of establishing decentralized governance is similar to the process in which an association is recognized as an independent social entity by establishing its organs according to its articles and bylaws. Therefore, a Decentralized Autonomous Organization can be seen as having the characteristics of an association. The governing law of DAO shall be determined by international treaties and Conflict of Laws. Foreign countries seem to have a tendency to deny DAO members' limited liability by viewing DAO as an entity similar to partnership. In order to allow limited liability to its members, some jurisdictions made new law to recognize DAO as LLC. When examinging DAO from Korean entity law perspective, it is necessary to consider whether they can be evaluated as an unincorporated association. If DAOs can be treated as an unincorporated association, DAOs creditor can not be reimbursed from members asset, the same effect as limited liability. However, the question is whether characteristics of DAO are permissible under the legal principles of traditional unincorporated association. For example, it is also necessary to consider whether its activities would fall under the legal frame of unincorporated association laws in Korea as DAO has no representative, distribute virtual asset to its members, and even can be operated for profit. There will continue to emerge various online based international entities. If they are not incorporated in any jurisdiction, it is necessary evaluate their legal status from the Korean unincorporated entity law perspective based on Conflicts of Law approach, When evaluating their legal status, it is necessary to consider whether they can be treated as Koean unincorporated association and pros and cons as well.

Artificial Intelligence in Law
Data Mining Algorithms and Applications
Access Control and Trust
Original source
Feb 3, 2023ยทIEEE Sensors Journal
19 cites
DAC4SH: A Novel Data Access Control Scheme for Smart Home Using Smart Contracts

Hongzhi Li, Dezhi Han, Chinโ€Chen Chang

Smart home (s-home) is an important Internet of Things (IoT)-based application in improving the living environment. Many cryptography-based protection schemes have been proposed to guarantee data confidentiality in s-home. Access control is a promising method to protect generated data from unauthorized access, and it is also urgently needed in s-home. Current centralized access control schemes are not excellent in security and performance. For instance, it still faces the problems of a single point of failure, low reliability, and poor scalability. This study proposes a decentralized and reliable access control scheme for s-home using smart contracts, named DAC4SH. To be specific, this proposed framework consists of an access policy management contract (APMC), a data attribute management contract (DAMC), a subject attribute management contract (SAMC), and a data access control contract (DACC) for realizing the fine-grained data access control. Meanwhile, we record all the access activities into the immutable distributed ledgers for auditing. To verify the feasibility of our DAC4SH, we construct an Ethereum-based prototype system and evaluate the performance of DAC4SH in terms of computational and communication costs. According to the experimental results, we can conclude that the performance of DAC4SH is appropriate.

Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Jan 20, 2023ยทJournal of King Saud University - Computer and Information Sciences
8 cites
Blockchain-based dynamic trust access control game mechanism

Xianhui Deng, Binyong Li, Shaowei Zhang, Liangming Deng

The blockchain-based access control mechanism (BACM) is gradually becoming an essential paradigm for solving dynamic and trusted access control problems in the open network environment. However, since the current open network environment has such features as dynamic variability and the uncertainty of user identity, most of the existing BACM cannot solve the access control problems in the current open network environment in a dynamic, flexible, proactive, efficient, and fine-grained approach. In this paper, we propose a novel BACM scheme to address such problems. Specifically, we first design a new, proactive, and fine-grained access control model, by utilizing the dynamicity and fine-grain of the attribute-based access control model, flexibility shown by the trust evaluation mechanism in evaluating the trust level of users, and proactivity shown by the game evaluation mechanism in curbing malicious users who suddenly launch malicious access requests. Second, based on the above access control model, we propose a dynamic, flexible, and proactive BACM for the current open network environment, exploiting the trustworthiness and transparency that the smart contract and the transaction mechanism in blockchain technology show during program execution. Further, a double sliding storage window is built, guaranteeing accurate data acquisition by BACM while efficiently allowing it to acquire time-sensitive data during the permission management process. Meanwhile, a pre-authorization concept is introduced to improve the efficiency and flexibility of BACM in processing access control problems. Security analysis demonstrates that our proposed BACM scheme satisfies the simple security issue and the simple availability issue. Experiments on a real user trust record dataset demonstrate the high effectiveness of the proposed BACM scheme in evaluating and deciding on access requests and the superiorities over most existing schemes in dynamicity, fine granularity, flexibility, and proactivity.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jan 17, 2023ยทFrontiers in Blockchain
9 cites
Blockchain based Resource Governance for Decentralized Web Environments

Davide Basile, Claudio Di Ciccio, Valerio Goretti, Sabrina Kirrane

Decentralization initiatives such as Solid, Digi.me, and ActivityPub aim to give data owners more control over their data and to level the playing field by enabling small companies and individuals to gain access to data, thus stimulating innovation. However, these initiatives typically use access control mechanisms that cannot verify compliance with usage conditions after access has been granted to others. In this paper, we extend the state of the art by proposing a resource governance conceptual framework, entitled ReGov, that facilitates usage control in decentralized web environments. We subsequently demonstrate how our framework can be instantiated by combining blockchain and trusted execution environments. Through blockchain technologies, we record policies expressing the usage conditions associated with resources and monitor their compliance. Our instantiation employs trusted execution environments to enforce said policies, inside data consumersโ€™ devices. We evaluate the framework instantiation through a detailed analysis of requirments derived from a data market motivating scenario, as well as an assessment of the security, privacy, and affordability aspects of our proposal.

Open access
2 source records
cs.NI
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Jan 17, 2023ยทarXiv (Cornell University)
4 cites
The Universal Trust Machine: A survey on the Web3 path towards enabling long term digital cooperation through decentralised trust

Rohan Madhwal, Johan Pouwelse

Since the dawn of human civilization, trust has been the core challenge of social organization. Trust functions to reduce the effort spent in constantly monitoring others' actions in order to verify their assertions, thus facilitating cooperation by allowing groups to function with reduced complexity. To date, in modern societies, large scale trust is almost exclusively provided by large centralized institutions. Specifically in the case of the Internet, Big Tech companies maintain the largest Internet platforms where users can interact, transact and share information. Thus, they control who can interact and conduct transactions through their monopoly of online trust. However, as recent events have shown, allowing for-profit corporations to act as gatekeepers to the online world comes with a litany of problems. While so far ecosystems of trust on the Internet could only be feasibly created by large institutions, Web3 proponents have a vision of the Internet where trust is generated without centralised actors. They attempt to do so by creating an ecosystem of trust constructed using decentralised technology. This survey explores this elusive goal of Web3 to create a "Universal Trust Machine", which in a true decentralised paradigm would be owned by both nobody and everybody. In order to do so, we first motivate the decades-old problem of generating trust without an intermediary by discussing Robert Axelrod's research on the evolution of cooperation. Next, we present the challenges that would have to be overcome in order to enable long term cooperation. We proceed to present various reputation systems, all of which present promising techniques for encouraging trustworthy behaviour. Then, we discuss Distributed Ledger technologies whose secure transaction facilitating and privacy preserving techniques promise to be a good complement to the current limitations of vanilla reputation systems.

Open access
2 source records
Blockchain Technology Applications and Security
Access Control and Trust
Caching and Content Delivery
Original source
Jan 3, 2023ยทACM Transactions on Privacy and Security
3 cites
Cheesecloth: Zero-Knowledge Proofs of Real-World Vulnerabilities

Santiago Cuรฉllar Gempeler, Bill Harris, James Parker, Stuart Pernsteiner ยท 6 authors

Currently, when a security analyst discovers a vulnerability in critical software system, they must navigate a fraught dilemma: immediately disclosing the vulnerability to the public could harm the systemโ€™s users; whereas disclosing the vulnerability only to the softwareโ€™s vendor lets the vendor disregard or deprioritize the security risk, to the detriment of unwittingly-affected users. A compelling recent line of work aims to resolve this by using Zero Knowledge (ZK) protocols that let analysts prove that they know a vulnerability in a program, without revealing the details of the vulnerability or the inputs that exploit it. In principle, this could be achieved by generic ZK techniques. In practice, ZK vulnerability proofs to date have been restricted in scope and expressibility, due to challenges related to generating proof statements that model real-world software at scale and to directly formulating violated properties. This article presents Cheesecloth , a novel proof-statement compiler, which proves practical vulnerabilities in ZK by soundly-but-aggressively preprocessing programs on public inputs, selectively revealing information about executed control segments, and formalizing information leakage using a novel storage-labeling scheme. Cheesecloth โ€™s practicality is demonstrated by generating ZK proofs of well-known vulnerabilities in (previous versions of) critical software, including the Heartbleed information leakage in OpenSSL, a memory vulnerability in the FFmpeg multimedia encoding framework, a cryptographic implementation bug in the Secure Scuttlebutt decentralised social network, and a denial of service vulnerability in OpenSSL.

Open access
3 source records
Security and Verification in Computing
Advanced Malware Detection Techniques
Distributed systems and fault tolerance
Original source