In this study, a blockchain-based Decentralized Application (DApp) for certificate authentication and verification from accredited colleges or certification bodies is presented. The DApp uses decentralized ledger technology, built on the Ethereum blockchain and smart contracts, to guarantee the integrity and authenticity of digital certificates. It uses a number of technologies, including Streamlit, Ganache-cli, Truffle, Pinata (for IPFS), and Docker, to expedite the certificate validation process and lower the risk of manipulation and forgery. The Institute, which is in charge of awarding certifications, and the Verifier, which is in charge of providing strong verification procedures, are the two primary players in the system. By utilizing Pinata, IPFS improves certificate permanence and accessibility without depending on centralized data storage. The advantages of blockchain attributes such as immutability, transparency, and decentralization in building confidence in the certification and education domains are empirically demonstrated. Future studies will concentrate on compatibility with other blockchain ecosystems, scalability, and smart contract efficiency. All things considered, this work provides a framework for safe document verification and recommends blockchain-based DApps as a remedy for data security and integrity in a variety of industries.
Sana Naz, Mohsin Javaid Siddiqui, Scott Uk-Jin Lee
To be a stakeholder/validator/token holder is not so difficult in the Proof of Stake (POS)-based blockchain networks; that is why the number of validators is large in these networks. These validators play an essential part in the block creation process in the PoS-based blockchain network. Due to the large validators, the block creation time and communication message broadcasting overhead get increased in the network. Many consensus algorithms use different techniques to reduce the number of validators, such as Delegated Proof of Stake (DPoS) consensus algorithms, which select the set of delegators via stake transactions for the block creation process. In this paper, we propose S&SEM, a secure and speed-up election process to select the ‘z’ number of validators/delegators. The presented election process is based on a traditional voting style with multiple numbers of rounds. The presented election mechanism reduces the possibility of malicious activity in the voting process by introducing a special vote message and a round that checks duplicate votes. We did horizontal scaling in the network to speed up the election process. We designed an improved incentive mechanism for the fairness of the election process. The designed reward and penalty procedure controls the nodes’ behaviors in the network. We simulate the S&SEM, and the result shows that the presented election process is faster and more secure to select delegators than the existing process used by DPOS.
The paper introduces SoulCert, a decentralized application that leverages blockchain technology to address the challenges of academic certification. Utilizing soul-bound non-fungible tokens (NFTs), SoulCert provides a secure and transparent system for issuing, verifying, and managing tamper-proof academic credentials. The system extends the ERC721 standard with additional functionalities from ERC5192 for locking and unlocking tokens, ensuring the integrity and authenticity of certificates. The paper discusses various Ethereum token standards, their use cases, and the methodology behind SoulCert, highlighting its potential to revolutionize the academic certification process. The paper also presents performance comparison between different operation within SoulCert and economic feasibility for real world application.
Harsh Gupta, Khushi S. Kasat, Abhijeet R. Raipurkar, Praful R. Pardhi
As digital identities become increasingly valuable and vulnerable, the protection of personal credentials has become a critical concern. This paper introduces a fresh perspective on credential management, focusing on enhancing privacy and security. We propose a user-centric approach that revolves around the idea of creating a safe space for digital credentials within decentralized wallets. By leveraging existing social login mechanisms and establishing secure tokenized containers for credentials, users can securely store and manage their digital identity. Our framework aims to empower individuals by providing them with control over their credentials while minimizing the risk of exposure to third parties. This paper outlines the core concepts and objectives of our approach, highlighting its potential to revolutionize the way we manage and protect our digital identities.
The world is rapidly heading towards digitization and digital documentation.The COVID-19 pandemic has highlighted the significance of digitization in our daily lives.Nowadays, fake documents are widely available and easy to obtain, harming both our financial system and social trust.Consequently, there is a growing demand for procedures to verify and authenticate various crucial documents, including transactional, financial, governmental, and personal certificates, as well as educational certificates.This type of practice can be done using blockchain and cryptography technology.In this paper, we propose a Blockchain based Digital Identity Management System (BDIMS) that empowers organizations to generate instantaneously authenticated and tamper-resistant digital credentials.It issues a signed document and stores the signature on the blockchain.The verifier can easily verify the signature from the blockchain instantly using the digital signature concept.BDIMS also provides a QR-code system for real-time identity verification.It also introduces zero-knowledge proof for verifying the part of an identity without revealing the original statement.Furthermore, a user can store and share all their identities on a single platform using BDIMS.The proposed model effectively addresses the shortcomings of traditional methods by ensuring a comprehensive and streamlined approach.It successfully bridges the gaps and overcomes the difficulties inherent in conventional document verification systems, meeting all the necessary criteria for a robust and reliable verification process.
Background The healthcare industry is significantly transforming toward digital and smart healthcare. Blockchain, as an emerging distributed collaborative paradigm, offers a promising solution for ensuring trustworthiness and high availability of services in this evolving healthcare. This paper aims to provide a comprehensive survey of blockchain-based applications in smart healthcare. Methods We first present real-world blockchain use cases in smart healthcare and related fields, outlining the motivations for this study. Next, we review cutting-edge blockchain applications in various domains, including health data sharing, public health management, drug supply chains, insurance claims, and the Internet of Medical Things. A detailed analysis of several blockchain-based healthcare data sharing scenarios is included. Results The findings illustrate the diverse applications of blockchain technology in enhancing healthcare systems, along with a detailed examination of challenges related to technical implementation and adoption. Conclusion We discuss the challenges facing blockchain integration in smart healthcare and propose potential solutions to guide future research in this area.
Rahul Ganpatrao Sonkamble, Anupkumar M. Bongale, Shraddha Phansalkar, Deepak Dharrao
An Electronic Health Record (EHR) store essential and sensitive patient's medical information. Since health information is highly confidential data, it should be accessible with the consent of the patient. Blockchain based EHR management system offers improvised privacy and patient-centric approach. EHR management systems are available with multiple blockchain platforms. Generally, EHRs are maintained at several independent blockchain platforms. EHR management systems should be capable of securely exchange data on cross platform blockchain network. The interoperability in such blockchain platforms should facilitate seamless cross-chain interaction and information exchange. This article proposes a method that facilitates secure EHR exchange on Ethereum and Hyperledger fabric network using hepatitis dataset. The key contributions of the proposed method include:•Hash lock based interoperable cross-chain method for EHR exchange across Ethereum and Hyperledger fabric.•Additional security to the EHR is ensured by partitioning EHR as on-chain (blockchain platform) and off-chain InterPlanetary File System (IPFS)•Secure Password Authentication-Based Key Exchange (SPAKE) based session management for EHR exchange across two parties.The proposed patient centric method is validated to ensures the successful exchange of patient EHR across Ethereum and Hyperledger fabric.
Medical research benefits from large quantities of high-quality data. Internet-based data-sharing platforms bring the advantage of rapidly sharing data medical data. However, ensuring security and accountability in networked medical systems remains a challenge. In this paper, we propose a secure and auditable data-sharing platform for hospitals and research groups based on a distributed ledger. A two-party protocol for recoverable key agreement lies at the basis of securing the data sharing. This protocol enables two parties to agree on an encryption key and put the encryption key under the escrow of a board of semi-trusted auditors. A quorum of these auditors is required in order to recover the encryption key. The recoverable key agreement ensures that past communication can be audited, even if one of the two parties is malicious. We provide a realization of the protocol and analyze its complexity and performance. Based on these analyses, we demonstrate that the protocol is suitable for real-world use cases and resource-constrained devices.
In recent years, with the increasing integration of intelligent modules into vehicles, intelligent transportation systems (ITS) have increasingly assumed a pivotal role in augmenting driver safety. As an ITS, vehicle ad hoc networks (VANETs) not only establish a secure traffic environment for users but also provides them with an efficient means of exchanging traffic information. However, during vehicle communication processes, security challenges such as the leakage of vehicle privacy information and tampering with shared task information must be addressed. Therefore, this paper proposes a decentralized anonymous authentication and secure traffic task information-sharing scheme based on blockchain and zk-SNARK. Specifically, the proposed scheme utilizes blockchain technology and the interplanetary file system (IPFS) to securely and efficiently store and share task information in a fully decentralized manner. Vehicle users anonymously participate in tasks within VANETs using pseudonym information generated during registration with a trusted authority (TA). Additionally, by employing zk-SNARK to generate zero-knowledge proofs, the validity and integrity of task information can be verified without revealing any private information. Performance comparisons indicate that the proposed scheme enhances the security of vehicle-to-roadside unit (V2R) and vehicle-to-vehicle (V2V) communications while reducing communication and computational costs.
Abdul Razzaq, Tao Zhang, Muhammad Numair, Abdulrahman Alreshidi · 9 authors
Abstract Metaverse—a three‐dimensional computational environment—combines physical and virtual reality to enable social relationships and immersive experiences by mimicking real‐world scenarios. Metaverse is considered the third wave of the internet revolution (exploiting Web 3.0), leveraging upcoming technologies such as extended reality and artificial intelligence shaping a new era of human–‐machine interactions. In recent years, increased research and development on educational technologies (EduTech) based on blockchain technology has seen substantial growth of metaverse‐based solutions within the higher education context. This research aims to synergize blockchain technology and metaverse environments to conduct online exams (metaExam) in a trustworthy, reliable, and secure way. The synergy between blockchain and the metaverse brings various benefits, such as improved security, cost effectiveness, and increased efficiency in the online examination process. One of the central features of the proposed solution metaExam is to leverage cryptographic protocols via blockchain to control data access, making verification faster and protecting against misuse. Exam scores and grades are stored on a blockchain ledger using a digital signature method to enhance security. We validated the proposed solution by testing a prototype on the Ethereum platform using the Sepolia Testnet network using Microsoft Windows environment. Evaluation results indicate (i) query response time (10–50 ms), (ii) and query execution performance (CPU utilization between 1%–5%) offering computationally feasible solution. This research contributes by integrating blockchain and metaverse technologies to offer a solution metaExam that can offer improved security and immersive user experience for exam management. The proposed solution and its validation can provide insights into transforming online exams, offering a fresh perspective on addressing concerns about exam grade authenticity and verifying academic credentials in EduTech.
One of the main security challenges when federating separate Internet of Things (IoT) administrative domains is effective Identity and Access Management, which is required to establish trust and secure communication between federated IoT devices. The primary goal of the work is to develop a “lightweight” protocol to enable authentication and authorization of IoT devices in federated environments and ensure the secure communication of IoT devices. We propose a novel Lightweight Authentication and Authorization Framework for Federated IoT (LAAFFI) which takes advantage of the unique fingerprint of IoT devices based on their configuration and additional hardware modules, such as Physical Unclonable Function, to provide flexible authentication and authorization based on Distributed Ledger technology. Moreover, LAAFFI supports IoT devices with limited computing resources and devices not equipped with secure storage space. We implemented a prototype of LAAFFI and evaluated its performance in the Hyperledger Fabric-based IoT framework. Three main metrics were evaluated: latency, throughput (number of operations or transactions per second), and network resource utilization rate (transmission overhead introduced by the LAAFFI protocol). The performance tests conducted confirmed the high efficiency and suitability of the protocol for federated IoT environments. Also, all LAAFFI components are scalable as confirmed by tests. We formally evaluated LAAFFI security using Verifpal as a formal verification tool. Based on the models developed for Verifpal, we validated their security properties, such as message secrecy, authenticity, and freshness. Our results show that the proposed solution can improve the security of federated IoT environments while providing zero-day interoperability and high scalability. Compared to existing solutions, LAAFFI is more efficient due to the use of symmetric cryptography and algorithms adapted for operations involving IoT devices. LAAFFI supports multiple authorization mechanisms, and since it also offers authentication and accountability, it meets the requirements of Authentication, Authorization and Accounting (AAA). It uses Distributed Ledger (DL) and smart contracts to ensure that the request complies with the policies agreed between the organizations. LAAFFI offers authentication of devices belonging to a single organization and different organizations, with the assurance that the encryption key will be shared with another device only if the appropriate security policy is met. The proposed protocol is particularly useful for ensuring the security of federated IoT environments created ad hoc for special missions, e.g., operations conducted by NATO countries and disaster relief operations Humanitarian Assistance and Disaster Relief (HADR) involving military forces and civilian services, where immediate interoperability is required.
Hari Kishore Chaparala, Sai Vineeth Doddala, Ahmad Showail, Faisal Nawab
Integrating non-fungible tokens (NFTs) into decentralized user-facing applications like virtual worlds presents significant performance and security challenges. Traditional NFT marketplaces struggle with scalability and security, particularly when off-chain solutions are employed to enhance performance. To tackle these issues, we introduce DecentEdge (Decentralized Edge), a trusted off-chain NFT Marketplace (NFTM) designed to operate closer to the user at the edge. DecentEdge stands out by enabling concurrent, secure processing of multiple transactions on the same NFT off-chain, significantly boosting scalability. This is achieved through two key design ingredients: leveraging Trusted Execution Environments (TEEs) to secure off-chain operations, and implementing a Multi-Stage NFT transaction processing protocol. This protocol splits NFT transactions into off-chain and on-chain stages, effectively reducing the impact of on-chain latency in typical execution paths. However, this approach introduces potential conflicts between off-chain and on-chain stages, which we address with a carefully designed conflict resolution mechanism to ensure safety and security. Our experiments-conducted on a blockchain network-show that DecentEdge achieves over 300-fold throughput improvement when compared to the state-of-the-art NFTM, OpenSea.
Abstract The widespread adoption of cloud computing has dramatically altered how data is stored, processed, and accessed in an era. The rapid development of digital technologies characterizes all this. The widespread adoption of cloud services has introduced new obstacles to guaranteeing secure and expeditious access to sensitive data. Organizations of all types find user-friendly and cost-effective solutions crucial, which is why they consider cloud services essential. The availability of the cloud hampers access control security in systems that are constantly and remotely changing. Conventional methods of access control are efficient, but the advanced world of technology exposes them to more threats. Applying blockchain technology to cloud access control systems, which are decentralized, transparent, and tamper-proof, has overcome these challenges. This paper aims to discuss the potential of blockchain in enhancing access management, security and trust in cloud computing. Besides, this scholarly article reviews the evolving area of blockchain-based access control systems and synthesizes the findings of 118 selected papers from various academic repositories. Based on this systematic review of the studies, twelve different types of blockchain-based access control paradigms can be identified. This work provides a critical analysis of the research on blockchain technology in access control systems, with a focus on scalability, compatibility, and security challenges. It also highlights areas that require further research and proposes directions for future research to advance this rapidly growing area of scholarship.
The growing digitization of education presents significant challenges in maintaining the integrity and trustworthiness of educational content. Traditional systems often fail to ensure data authenticity and prevent unauthorized alterations, particularly in the evaluation of teachers' professional activities, where demand for transparent and secure assessment mechanisms is increasing. In this context, Blockchain technology offers a novel solution to address these issues. This paper introduces a Blockchain-enhanced framework for the Electronic Platform for Expertise of Content (EPEC), a platform used for reviewing and assessing educational materials. Our approach integrates the Polygon network, a Layer-2 solution for Ethereum, to securely store and retrieve encrypted reviews, ensuring both privacy and accountability. By leveraging Python, Flask, and Web3.py, we interact with a Solidity-based smart contract to securely link each review to a unique identifier (UID) that connects on-chain data with real-world databases. The system, containerized using Docker, facilitates easy deployment and integration through API endpoints. Our implementation demonstrates significant cost savings, with a 98\% reduction in gas fees compared to Ethereum, making it a scalable and cost-effective solution. This research contributes to the ongoing effort to implement Blockchain in educational content verification, offering a practical and secure framework that enhances trust and transparency in the digital education landscape.
Credential management for emergency scenarios is vital for security, access control, accountability, and ensuring the effectiveness of response and recovery efforts while adhering to regulatory requirements. In the aftermath of a disaster or any emergency scenario, control stations/regulatory authorities access several response and recovery systems for providing services. Unauthorized access to these systems creates cyber-attacks. Also, the existing credentials management systems suffer from time-consuming procedures due to the involvement of numerous stakeholders and restricted information access, leading to increased administrative burden, and loss of trust and reputation in the system. As a result, several researchers and emergency response organizations have advised to use of blockchain technology which provides a secure, transparent, and tamper-proof ledger of credentials and access logs. This immutability ensures that no unauthorized changes or deletions occur, enhancing the trustworthiness of the credential data. Hence, this work exploits the concept of blockchain to enrich the credential management system by streamlining the validation mechanism and upgrading security mechanisms. This work develops BCredS, a blockchain-leveraged secure and intelligent credential management system by designing smart contracts that are resistant to hacking, and by utilizing blockchain, the security of the application will be improved since it employs strong cryptographic techniques. The efficiency of the proposed work will be evaluated through extensive simulation in Ethereum platform.
In the digital information age, the traditional centralized storage model is vulnerable to security attacks, which leads to the spread of false information and difficulty in tracing. This study proposes a decentralized campus information security system using blockchain technology and builds a tamper-proof, traceable, and privacy-protected architecture through Ethereum and Inter Planetary File System (IPFS). The system uses zero-knowledge proof and homomorphic encryption technology to ensure privacy and uses IPFS as an off-chain storage mechanism to improve the scalability of the system and data access speed. Experimental results show that compared with traditional digital applications, the system performs well in ensuring the authenticity and security of information and effectively protects user privacy.
As the importance of data privacy protection continues to grow, blockchain technology has emerged as a new avenue for safeguarding data privacy due to its immutable and decentralized characteristics. This paper proposes a blockchain-based provenance mechanism designed for data privacy protection, leveraging blockchain technology to ensure data integrity and traceability while securing personal privacy. First, the limitations of existing data protection mechanisms are analyzed, and the application of blockchain in various scenarios for data provenance is elaborated. Next, the critical role of smart contracts in the automatic execution of data processing and access control rules is explored, along with how blockchain's transparency and anonymity protect user privacy. Additionally, a novel blockchain architecture combining zero-knowledge proof technology is proposed to enable encrypted processing and verification of sensitive data without exposing the actual content. Finally, a series of experiments validate the effectiveness and efficiency of this mechanism. This research not only provides a new technical approach for data privacy protection but also lays a theoretical foundation for the application of blockchain in the field of data security.
Jean Gilbert Mbula Mboma, Obed Tshimanga Tshipata, Witesyavwirwa Vianney Kambale, Mohamed Salem · 6 authors
Verifying the authenticity of documents, whether digital or physical, is a complex and crucial challenge faced by a variety of entities, including governments, regulators, financial institutions, educational establishments, and healthcare services. Rapid advances in technology have facilitated the creation of falsified or fraudulent documents, calling into question the credibility and authenticity of academic records. Most existing blockchain-based verification methods and systems focus primarily on verifying the integrity of a document, paying less attention to examining the authenticity of the document’s actual content before it is validated and registered in the system, thus opening loopholes for clever forgeries or falsifications. This paper details the design and implementation of a proof-of-concept system that combines GPT-3.5’s natural language processing prowess with the Ethereum blockchain and the InterPlanetary File System (IPFS) for storing and verifying documents. It explains how a Large Language Model like GPT-3.5 extracts essential information from academic documents and encrypts it before storing it in the blockchain ensuring document integrity and authenticity. The system is tested for its efficiency in handling both digital and physical documents, demonstrating increased security and reliability in academic document verification.
Introduction: Botnets have become a significant threat to cybersecurity, as they can be used for a wide range of malicious activities, including Distributed Denial-of-Service (DDoS) attacks, spamming, and cryptocurrency mining. Bitcoin Mining, in particular, has become a lucrative target for cybercriminals, as it requires massive computing power and can generate significant profits. Methods: In this paper, the author presents a study on a botnet that uses an HTA file to gain initial access and execute code on a victim's device, followed by the installation of mining software to infect the device and bitcoins. Results: The author analyzes the botnet's behaviour, including its evasion techniques and Bitcoin Mining activities, and discusses the implications of current findings for cybersecurity and Bitcoin Mining. Conclusion: Future research should also investigate the use of different command and control servers and other advanced attack frameworks in botnet operations and examine the potential connections between botnets and other cybercrime activities, such as ransomware and espionage.