Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results · page 25 of 38

Clear filters
Sep 27, 2022·2022 4th Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS)
14 cites
Collaborative Administration of Role-Based Access Control in Smart Contracts

Stefan Cras, Andreas Lackner, Nedim Begić, Seyed Amid Moeinzadeh Mirhosseini · 5 authors

The emergence of blockchain technologies, including smart contracts, enables the decentralization of applications that were previously controlled by a single entity. In many cases, however, smart contracts still need to distinguish between different user roles according to their assigned duties. To ensure security, smart contracts often apply a simple form of role-based access control (RBAC), where a dedicated administrator assigns users to roles that are authorized to invoke specific smart contract functions. As this solution contradicts the blockchain principles of decentralization and democratic decision making, smart contracts may also form decentralized autonomous organizations where governance decisions are based on voting by all participants. Many applications would benefit from a hybrid approach that involves roles with different permissions while still allowing for collaborative management. Therefore, we propose a novel mechanism for RBAC administration in smart contracts based on hierarchical roles and configurable administration rules for each role. Any change in the user-role relation requires joint approval by members of selected roles according to the associated rule. This enables decentralized organizational charts with flexible administration constraints, where each role corresponds to specific permissions in the decentralized application and any change is transparently and securely recorded on the blockchain. The practical feasibility of the approach is demonstrated by means of a prototypical implementation for the Ethereum blockchain. Several benchmarks are performed to analyze the potential overhead of different solution variants.

Cryptography and Data Security
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Sep 23, 2022·arXiv (Cornell University)
2 cites
Self-Sovereign Identity in a World of Authentication: Architecture and Domain Usecases

Morgan Reece, Sudip Mittal

Self-Sovereign Identity (SSI) is projected to become part of every person's life in some form. The ability to verify and authenticate that an individual is the actual person they are purported to be along with securing the personal attributes could have wide spread implications when engaging with third party organizations. Utilizing blockchains and other decentralized technologies, SSI is a growing area of research. The aspect of securing personal information within a decentralized structure has possible benefits to the public and private sectors. In this paper, we describe the SSI framework architecture as well as possible use cases across domains like healthcare, finance, retail, and government. The paper also contrasts SSI and its decentralized architecture with the current widely adopted model of Public Key Infrastructure (PKI).

Open access
2 source records
cs.CR
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Sep 1, 2022·Energies
17 cites
Centralized and Decentralized Distributed Energy Resource Access Control Implementation Considerations

Georgios Fragkos, Jay Johnson, Eirini Eleni Tsiropoulou

A global transition to power grids with high penetrations of renewable energy generation is being driven in part by rapid installations of distributed energy resources (DER). New DER equipment includes standardized IEEE 1547-2018 communication interfaces and proprietary communications capabilities. Interoperable DER provides new monitoring and control capabilities. The existence of multiple entities with different roles and responsibilities within the DER ecosystem makes the Access Control (AC) mechanism necessary. In this paper, we introduce and compare two novel architectures, which provide a Role-Based Access Control (RBAC) service to the DER ecosystem’s entities. Selecting an appropriate RBAC technology is important for the RBAC administrator and users who request DER access authorization. The first architecture is centralized, based on the OpenLDAP, an open source implementation of the Lightweight Directory Access Protocol (LDAP). The second approach is decentralized, based on a private Ethereum blockchain test network, where the RBAC model is stored and efficiently retrieved via the utilization of a single Smart Contract. We have implemented two end-to-end Proofs-of-Concept (PoC), respectively, to offer the RBAC service to the DER entities as web applications. Finally, an evaluation of the two approaches is presented, highlighting the key speed, cost, usability, and security features.

Open access
Smart Grid Security and Resilience
Access Control and Trust
Software-Defined Networks and 5G
Original source
Sep 1, 2022·Lecture notes in computer science
9 cites
Authentication, Authorization, and Selective Disclosure for IoT Data Sharing Using Verifiable Credentials and Zero-Knowledge Proofs

Nikos Fotiou, Iakovos Pittaras, Spiros Chadoulos, Vasilios A. Siris · 7 authors

As IoT becomes omnipresent vast amounts of data are generated, which can be used for building innovative applications. However,interoperability issues and security concerns, prevent harvesting the full potentials of these data. In this paper we consider the use case of data generated by smart buildings. Buildings are becoming ever "smarter" by integrating IoT devices that improve comfort through sensing and automation. However, these devices and their data are usually siloed in specific applications or manufacturers, even though they can be valuable for various interested stakeholders who provide different types of "over the top" services, e.g., energy management. Most data sharing techniques follow an "all or nothing" approach, creating significant security and privacy threats, when even partially revealed, privacy-preserving, data subsets can fuel innovative applications. With these in mind we develop a platform that enables controlled, privacy-preserving sharing of data items. Our system innovates in two directions: Firstly, it provides a framework for allowing discovery and selective disclosure of IoT data without violating their integrity. Secondly, it provides a user-friendly, intuitive mechanisms allowing efficient, fine-grained access control over the shared data. Our solution leverages recent advances in the areas of Self-Sovereign Identities, Verifiable Credentials, and Zero-Knowledge Proofs, and it integrates them in a platform that combines the industry-standard authorization framework OAuth 2.0 and the Web of Things specifications.

Open access
3 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Aug 23, 2022·Proceedings of the 2022 ACM Conference on Information Technology for Social Good
2 cites
A Decentralized Architecture for Dynamic and Federated Access Control Facilitating Smart Tourism Services

Andrea Sabbioni, Carlo Mazzocca, Armir Bujari, Rebecca Montanari · 5 authors

Edge computing and the Internet of Things (IoT) are inextricably linked, and much work has been devoted to strengthening their symbiotic relationship, providing better coverage and quality of service. These solutions are typically vertically tailored, provider-specific and bound to work within one administrative domain, as they presume direct deployment and ownership of the resources controlled in a centralised fashion. This model has effectively created a myriad of physically interconnected elements, logically broken down into separate domain-specific islands, each possibly applying different security/privacy policies, device and process control mechanisms, service access and provisioning schemes etc. To address this data and service balkanization phenomena, complex and time-consuming interactions between multiple providers are required to set up and operate federation of resources across domains and/or providers. Without loss of generality, we envision a scenario where stakeholders in a Smart Tourism ecosystem participate in resource federations to enrich their services and exploit complementarities. In this context, we present a decentralized architecture, relying on Distributed Ledger Technology (DLT), providing a flexible and effective federated access control mechanism to data and services.

Blockchain Technology Applications and Security
Access Control and Trust
Caching and Content Delivery
Original source
Aug 22, 2022·2022 International Balkan Conference on Communications and Networking (BalkanCom)
0 cites
Trust Evaluation of Blockchain-Based Cryptocurrencies: The Cases of Bitcoin and Diem

Nada Elsokkary, Muhammad Habib ur Rehman, Sabah Suhail, Hermann Kaindl · 5 authors

Despite a recent increase in popularity, most individuals remain hesitant to use cryptocurrencies due to concerns about their volatility, general lack of understanding of blockchain technology, and various trust issues. Therefore, it is of high priority for the community to better understand such systems, and what increases or decreases trust in them. In this paper, we explore the current trust-related requirements on blockchain systems, focusing on the use of the dedicated requirements elicitation method TrUStAPIS. We evaluate Bitcoin and Diem trust issues and requirements. Based on the evaluation, we present a cryptocurrency trust model.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Aug 22, 2022·2022 International Conference on Platform Technology and Service (PlatCon)
11 cites
Decentralized Access Control for Internet of Things Using Decentralized Identifiers and Multi-signature Smart Contracts

Erzhena Tcydenova, Byoungjin Seok, Minjeong Cho, Changhoon Lee

The number of connected devices is growing enormously every year, and with the rapid development of 5G technology, it is expected to grow even more. The Internet of Things (IoT) deals with different types of information in different applications, including a huge amount of sensitive and personal information, so IoT security and privacy is becoming a major concern. Most IoT devices interact not only with the owner, but also with various third parties and its heterogeneity makes authentication and access control a challenging task. A new concept such as Decentralized Identifier (DID), which is unified identity that does not require a centralized trust anchor, has been gaining a lot of interest in both academia and industry recently. In this paper, we propose decentralized access control framework for Internet of Things utilizing smart contracts and DIDs. In our framework access control is managed by decentralized oracles using multi-signature for agreements to overcome single point of failure problem.

Cryptography and Data Security
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Aug 18, 2022·Computational Intelligence and Neuroscience
15 cites
On the Design of Secured and Reliable Dynamic Access Control Scheme of Patient E-Healthcare Records in Cloud Environment

Kirtirajsinh Zala, Hiren Kumar Thakkar, Rajendrasinh Jadeja, Neel H. Dholakia · 7 authors

Traditional healthcare services have changed into modern ones in which doctors can diagnose patients from a distance. All stakeholders, including patients, ward boy, life insurance agents, physicians, and others, have easy access to patients' medical records due to cloud computing. The cloud's services are very cost-effective and scalable, and provide various mobile access options for a patient's electronic health records (EHRs). EHR privacy and security are critical concerns despite the many benefits of the cloud. Patient health information is extremely sensitive and important, and sending it over an unencrypted wireless media raises a number of security hazards. This study suggests an innovative and secure access system for cloud-based electronic healthcare services storing patient health records in a third-party cloud service provider. The research considers the remote healthcare requirements for maintaining patient information integrity, confidentiality, and security. There will be fewer attacks on e-healthcare records now that stakeholders will have a safe interface and data on the cloud will not be accessible to them. End-to-end encryption is ensured by using multiple keys generated by the key conclusion function (KCF), and access to cloud services is granted based on a person's identity and the relationship between the parties involved, which protects their personal information that is the methodology used in the proposed scheme. The proposed scheme is best suited for cloud-based e-healthcare services because of its simplicity and robustness. Using different Amazon EC2 hosting options, we examine how well our cloud-based web application service works when the number of requests linearly increases. The performance of our web application service that runs in the cloud is based on how many requests it can handle per second while keeping its response time constant. The proposed secure access scheme for cloud-based web applications was compared to the Ethereum blockchain platform, which uses internet of things (IoT) devices in terms of execution time, throughput, and latency.

Open access
Cloud Data Security Solutions
Access Control and Trust
Innovation in Digital Healthcare Systems
Original source
Aug 15, 2022·Open MIND
5 cites
Smart Contract Synthesis Modulo Hyperproperties

Norine Coenen, Bernd Finkbeiner, Jana Hofmann, Julia Tillman

Smart contracts are small but highly security-critical programs that implement wallets, token systems, auctions, crowd funding systems, elections, and other multi-party transactions on the blockchain. A broad range of methods has been developed to ensure that a smart contract is functionally correct. However, smart contracts often additionally need to satisfy certain hyperproperties, such as symmetry, determinism, or an information flow policy. In this paper, we show how a synthesis method for smart contracts can ensure that the contract satisfies its desired hyperproperties. We build on top of a recently developed synthesis approach from specifications in the temporal logic TSL. We present HyperTSL, an extension of TSL for the specification of hyperproperties of infinite-state software. As a preprocessing step, we show how to detect if a hyperproperty has an equivalent formulation as a (simpler) trace property. Finally, we describe how to refine a synthesized contract to adhere to its HyperTSL specification.

Open access
3 source records
Security and Verification in Computing
Formal Methods in Verification
Distributed systems and fault tolerance
Original source
Aug 9, 2022·Institute of Electrical and Electronics Engineers (IEEE)
2 cites
Decentralized Identity Management: Prerequisiteof Web3 Identity Model

Pinky Bai, Charupriya Bisht

Web3 is the evolution of internet requisites decentralized identity management known as a new paradigm in the identity management system. Web3 conceptualizes decentralization and based upon that needs an identity model that fulfills the requirement of any business/technology model in the new trusted third-party free era. This article presents Web3, Web3 architecture, and technologies expansion for secure and scalable services. Further, the decentralized identity management model is presented with its components (DID), reusable verifiable credentials (VC), issuer, verifier, and user centricity in perspective with the Web3 identity model.

Open access
Access Control and Trust
Original source
Jul 18, 2022·Zero Trust Journey Across the Digital Estate
0 cites
Future Horizon of Zero Trust

Abbas Kudrati, Binil Pillai

Trust is a human emotion and is the single greatest vulnerability when we think about cyber security. Organizations are all-in with the Zero Trust strategy, and decision makers say it will continue to be the top security priority over the years. Organizations that have wholeheartedly embraced Zero Trust expect to double down on their investment in the next two years, and those who have not yet started adopting risk falling further behind. The mobile users access distributed data from multiple devices, from anywhere. Blockchain technology is revolutionizing across all industries. Over the past decade, the popularity of blockchain has significantly increased worldwide. As cryptocurrencies have expanded beyond the worlds of finance and banking, with a slew of new businesses and applications built on the technology, industries now prioritize a mass decentralization that will soon impact the whole world. The decentralized model is already relevant for blockchain-based solutions such as cloud storage, payment processing, and cybersecurity.

Access Control and Trust
Original source
Jun 13, 2022·IEEE Transactions on Services Computing
93 cites
A Semi-Centralized Trust Management Model Based on Blockchain for Data Exchange in IoT System

Yuan Liu, Chuang Zhang, Yu Yan, Xin Zhou · 6 authors

IoT data exchange plays a vital role in supporting various applications and services with massive IoT devices. However, the existence of malicious devices threatens the integrity and reliability of the exchanged data. Trust management has been used to mitigate the impact of malicious devices in centralized and decentralized architectures. However, most of these traditional trust management systems bear computation, storage, and communication challenges. In this study, we propose a semi-centralized trust management system architecture based on blockchain in both single and multiple domains. The IoT devices are centralized organized by cloud servers who coordinately sustain a rating data ledger within each domain based the proposed rotation based consensus protocol in a decentralized manner to support cross-domain data exchange. A computational trust model is proposed by aggregating the direct and indirect trust information, where we elaborately design decay function, recommendation credibility and adaptable weights so as to calculate the trust value of dynamic malicious devices. Finally, we evaluate the proposed system model in various situations through simulation based experiments and compare it with two classical models in the literature. The experimental results demonstrate the effectiveness of the proposed trust model in identifying malicious devices and mitigating the influence of malicious devices.

Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
May 23, 2022·National Institute of Standards and Technology (U.S.)
25 cites
Blockchain for access control systems

Vincent C. Hu

The rapid development and wide application of distributed network systems have made network security especially access control and data privacy ever more important. Blockchain technology offers features such as decentralization, high confidence, and tamper-resistance, which are advantages to solving auditability, resource consumption, scalability, central authority, and trust issues all of which are challenges for network access control by traditional mechanisms. This document presents general information for blockchain access control systems from the views of blockchain system properties, components, functions, and supports for access control policy models. Considerations for implementing blockchain access control systems are also included.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Internet Traffic Analysis and Secure E-voting
Original source
May 17, 2022·IEEE Security & Privacy
5 cites
Distributed Self-Sovereign-Based Access Control System

Dhiah el Diehn I. Abou-Tair, Ala’ Khalifeh

Distributed ledger technology has paved the way for new innovative approaches in the field of security and privacy. Self-sovereign identity contributed to empowering individuals to have control over their digital identifiers. The presented self-sovereign-based access control system utilizes both technologies.

Access Control and Trust
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
May 17, 2022·2022 IEEE 46th Annual Computers, Software, and Applications Conference (COMPSAC)
20 cites
Self-Sovereign Identity as a Service: Architecture in Practice

Yepeng Ding, Hiroyuki Sato

Self-sovereign identity (SSI) has gained a large amount of interest. It enables physical entities to retain ownership and control of their digital identities, which naturally forms a conceptual decentralized architecture. With the support of the distributed ledger technology (DLT), it is possible to implement this conceptual decentralized architecture in practice and further bring technical advantages such as privacy protection, security enhancement, high availability. However, developing such a relatively new identity model has high costs and risks with uncertainty. To facilitate the use of the DLT-based SSI in practice, we formulate Self-Sovereign Identity as a Service (SSIaaS), a concept that enables a system, especially a system cluster, to readily adopt SSI as its identity model for identification, authentication, and authorization. We propose a practical architecture by elaborating the service concept, SSI, and DLT to implement SSIaaS platforms and SSI services. Besides, we present an architecture for constructing and customizing SSI services with a set of architectural patterns and provide corresponding evaluations. Furthermore, we demonstrate the feasibility of our proposed architecture in practice with Selfid, an SSIaaS platform based on our proposed architecture.

Open access
3 source records
cs.SE
Blockchain Technology Applications and Security
Peer-to-Peer Network Technologies
Original source
May 15, 2022·2022 30th Signal Processing and Communications Applications Conference (SIU)
0 cites
Performance of Graph-based Zero-knowledge Proofs

Doruk Gercel, Helin Kayabas, Kadir Ekmekci, Cansu Betin Onur · 5 authors

Zero-knowledge proofs (ZKP) are a widely used technology for privacy protection and data ownership that allows parties to verify the accuracy of a piece of information without sharing the data. In this study, we developed and performance tested two graph-based zero-knowledge proof methods, the Hamilton Cycle Based ZKP Algorithm (ZKPHC) and the Graph Isomorphism Based ZKP Algorithm (ZKPGI), using an open source library. As the graph sizes increased, we measured and compared the running times of these methods. We tested the completeness and robustness of the ZKPHC protocol for different modes. As the graph used grows, the ZKPHC method, which uses encryption at every stage, works much slower than ZKPGI.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
May 2, 2022·Security and Communication Networks
2 cites
A Right Transfer Access Control Model of Internet of Things Based on Smart Contract

Jiuru Wang, Ping Gong, Haifeng Wang, Wenyin Zhang · 6 authors

Sensor nodes play a crucial role in the promotion of development of Internet of Things (IoT). Through this transaction, RO defines access control policies in script form based on ABAC's access control model to grant access right. The identity of all users in the model is identified by address. This paper builds a more flexible right transfer access control model by means of combining the Attribute-Based Access Control model (ABAC) and blockchain technology. Owing to the characteristics of ABAC’s attributes and right association, the massive problems of some sensor nodes can be solved. At the same time, for the sake of addressing the dynamic problems such as node access and right transfer, right transfer contract (TS) and access control contract (CS) are employed on the chain to ensure efficient and safe transmission of rights. To solve on-chain storage problems and ensure transparency of the operation, the idea of Rollup in Ethereum expansion is used to upload the final state of protocol policy and right exchange to the chain. Any user can know the policy and current right transfer status at any time. Finally, comparative and security analysis show that the model presented here can solve IoT devices’ massive and dynamic problems more effectively and it is more secure than the traditional models.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Mar 30, 2022·International Journal of Artificial Intelligence Data Science and Machine Learning
0 cites
AI-Enabled Policy-Driven Web Governance: A Full-Stack Java Framework for Privacy-Preserving Digital Ecosystems

Ravindra Putchakayala, Rajesh Cherukuri

The digital ecosystems have experienced a paradigm shift as there is a growing level of integration of Artificial Intelligence (AI), distributed computing apparatus, and robotic policy enforcement strategies. Governance structures are faced with the difficult task of negotiating the vagaries of privacy laws and decentralized data processing and the use of algorithmic decision-making with the migration of data-intensive applications to web-based environments. The increasing regulatory environment, such as GDPR, CCPA, and industry-specific data protection requirements, have significant forces on the requirement to have strong policy-driven governance infrastructures that entrench privacy and security at every layer of the web application stack. Although cloud platforms and microservice architectures have been developed, modern governance solutions have weaknesses in terms of scalability, being context-aware and dynamically adapting to changes in policy constraints. The research paper presents the AI-Enabled Policy-Driven Web Governance Framework that has been developed on the Full-Stack Java ecosystem which involves spring boot, Jakarta EE, containerized deployment platforms and intelligent agents which are rule-based. The framework incorporates machine learning-related policy interpretation, semantic arguments engines, as well as automated monitoring applications that regulate user interactions, data activities, service coordination, and cross-layer correspondence. AI agents will adapt legal and organizational privacy requirements into dynamic policies that are explicitly and dynamically implemented in real-time at the front-end, API, middleware, and database tiers. These challenges in digital governance that are solved are minimization of data, contextual privacy, verification of compliance, detection of anomalies, and fine-grained access control. The given architecture proposes a Multi-Layer Governance Orchestration Model (MGOM) that divides the governance issues into policy ingestion, AI interpretation, runtime enforcement, auditability, and compliance reporting. The framework also includes three levels of privacy shield with a static code analysis, user behavior analytics (UBA), and encrypted data pipelines. Through an extensive assessment analysis, it is evident that the framework has the ability to be highly precise in automated policy enforcement, decreases the latency of governance and enhances consistency of compliance over the traditional rule-based systems. The findings of the experiments point out that AI-enabled governance engine helps to improve the accuracy of policy compliance by 27.8 percent, minimize privacy invasions by 42.1 percent, and decrease administrative workload by 34.6 percent. A combination of a supervised learning, the natural language processing (NLP) and the symbolic rule mining allow the system to be autonomously adapted to new regulatory conditions without being reconfigured by human operators. Security benchmarks also indicate resiliency to partial attack vectors, such as inference attacks, unauthorized data elevation, and access patterns analysis. The paper will add value to the digital governance field by offering a holistic, scalable, and future-proof implementation that can assist with current web environments of many services including medicine, finance, online commerce, and smarter cities. The framework ensures the creation of a novel model of transparent, compliant, and privacy-conscious digital ecosystems by entrenching AI at the core of policy interpretation and enforcement. The publication contributes to the discussion of intelligent governance systems and offers a reference design to the developers, policymakers, and researchers, who seek to develop trustful and ethically aligned digital spaces

Open access
Access Control and Trust
Security and Verification in Computing
Cloud Data Security Solutions
Original source
Mar 15, 2022·Saudi Journal of Engineering and Technology
0 cites
The Design for Distributed Ledger Based on Main-Sub Ledger Architecture

Wenfeng Li

Distributed ledger technology (DLT) offers new and unique advantages for information systems, but some of its features are not a good fit for many applications. We review the properties of DLT and propose a new type of architecture for DLT based on main-sub ledger. Our scheme pays more attention to data privacy, effectively relieves the pressure of data storage for nodes, thereby improves data handling capability.

Open access
Peer-to-Peer Network Technologies
Caching and Content Delivery
Access Control and Trust
Original source
Mar 14, 2022·Blockchain in Healthcare Today
22 cites
Decentralized Identity Management for E-Health Applications: State-of-the-Art and Guidance for Future Work

Abylay Satybaldy, Anton Hasselgren, Mariusz Nowostawski

Background: The increasing use of various online services requires an efficient digital identity management (DIM) approach. Unfortunately, the original Internet protocols were not designed with built-in identity management, which creates challenges related to privacy, security, and usability. There is an increasing societal concern regarding the management of these sensitive data, access to it, and where it is stored. Blockchain technology can potentially offer a secure solution to address these issues in a decentralized manner without centralized authority. This is important for e-health services where the patient and the healthcare provider often are required to prove their identity. Blockchain technology can be utilized for creating digital identities and making its management easier, thus giving a higher degree of control to the user than what current solutions offer. It can be used to create a digital identity on the blockchain, making it easier for individuals and entities to manage, giving them greater control over who has their personal information and how they handle it. In addition, it might be utilized to create a higher degree of trust and security for e-health applications. Objective: The aim of this research work was to review the state-of-the-art regarding blockchain-based decentralized identity management for healthcare applications. Based on this summary, we provide a viewpoint on how blockchain-based decentralized identity frameworks might be utilized for virtualized healthcare applications. Methods: This research study applied a scoping, semi-systematic review approach to summarize the state-of-the-art. Included identity management systems were evaluated based on seven criteria: autonomy, authority, availability, approval, confidentiality, tenacity, and Interoperability. Results: Seven blockchain-based identity management systems were included and evaluated in this work: these include solutions built with Ethereum, Hyperledger Indy, Hyperledger Fabric, Hedera, and Sovrin blockchains. Conclusions: DIM is crucial for virtual health care. Decentralized identity management for healthcare purposes is currently being explored in both academia and the private sector. More work is needed with the aim of improving the efficiency of current DIM solutions and to fully understand what technical frameworks are best suited for e-health applications.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Advanced Authentication Protocols Security
Original source
Mar 8, 2022·Cogent Engineering
40 cites
A Blockchain Based Decentralized Identifiers for Entity Authentication in Electronic Health Records

Gunjan Kumar Chouhan, Shubhangi Singh, Aanya Jaduvansy, Priya Rai · 5 authors

Electronic Health Records (EHRs) are essential in contemporary healthcare as they facilitate the storage and sharing of personal patient data. Traditional cloud-based EHR systems, though, are afflicted with centralized control, privacy threats, restricted interoperability, and susceptibility to data breaches. To alleviate these challenges, this paper suggests a blockchain-based, patient-centered EHR management system that uses Ethereum smart contracts, Decentralized Identifiers (DIDs), and InterPlanetary File System (IPFS) for safe, distributed, and effective handling of health data.The system put forward puts patients at the forefront of EHR access and control, allowing them to grant or withdraw permissions to healthcare providers, insurers, or researchers using fine-grained, attribute-based policies executed through smart contracts. DIDs remove the need for third-party identity providers, providing secure and verifiable user authentication directly on the blockchain. IPFS, on the other hand, provides cost-effective, tamper-proof off-chain storage of medical records, with metadata and access logs stored on-chain to minimize gas usage.Extensive testing on the Ethereum Goerli testnet proves that the system provides greater security, lower storage costs, efficient access control, and better interoperability than conventional models. This method not only solves existing shortcomings in EHR systems but also opens the door to scalable, transparent, and patient-enabled healthcare data management.

Open access
2 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
Mar 1, 2022·2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)
2 cites
On the use of Petri Nets in Smart Contracts modeling, generation and verification

Andrea Pinna, Roberto Tonelli

We discuss the contribution of the Petri net formalism to the BOSE for Smart Contract design and development. We address this discussion based on the analysis of recently published literature works we obtained by querying Scopus and Google Scholar. Different types of Petri nets, including coloured Petri nets and workflow nets, and different types of tools emerge from our analysis. Our discussion includes the classification into three categories of application of the Petri net formalism in the design and development of Smart Contracts, namely modeling, generation, and verification.

Business Process Modeling and Analysis
Access Control and Trust
Outsourcing and Supply Chain Management
Original source
Mar 1, 2022·arXiv (Cornell University)
19 cites
Web3: A Decentralized Societal Infrastructure for Identity, Trust, Money, and Data

Joost Bambacht, Johan Pouwelse

A movement for a more transparent and decentralized Internet is globally attracting more attention. People are becoming more privacy-aware of their online identities and data. The Internet is constantly evolving. Web2 focused on companies that provide services in exchange for personal user data. Web3 commits to user-centricity using decentralization and zero-server architectures. The current digital society demands a global change to empower citizens and take back control. Citizens are locked into big-tech for personal data storage and their for-profit digital identity. Protection of data has proven to be essential, especially due to increased home Internet traffic during the COVID pandemic. Citizens do not possess their own travel documents. The European Commission aims to transition this governmental property towards self-sovereign identity, introducing many new opportunities. Citizens are locked into banks with non-portable IBAN accounts and unsustainable legacy banking infrastructures. Migration to all-digital low-fraud infrastructures and healthier competitive ecosystems is essential. The overall challenge is to return the power to citizens and users again. The transition to a more decentralized Internet is the first crucial step in the realization of user-centricity. This thesis presents the first exploratory study that integrates governmental-issued travel documents into a (decentralized) societal infrastructure. These self-sovereign identities form the authentic base to a private and secure transfer of money and data, and can effectively provide trust in authenticity that is currently missing in online conversations. A fully operational zero-server infrastructure that incorporates all our requirements has been developed for Android using the P2P network overlay IPv8, and a personalized blockchain called TrustChain...

Open access
2 source records
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Access Control and Trust
Original source