Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results · page 26 of 38

Clear filters
Feb 25, 2022·International Journal of Information Security and Privacy
0 cites
An Efficient Accountable Oblivious Transfer With Access Control Scheme in the Public Cloud

Xin Liu, Bin Zhang

In an oblivious transfer with access control (AC-OT) scheme, the database provider (DBP) can define different access control policies for each data record, and users are allowed to hide their choices from the DBP when accessing data. An accountable AC-OT (AAC-OT) scheme is an enhanced version of AC-OT that allows the DBP to revoke the access rights of malicious users. However, existing AAC-OT schemes have defects in their security model definition, malicious user revocation mechanism, and user-side performance. Therefore, the authors proposed an improved AAC-OT scheme that applies to the public cloud environment. In the definition of the security model, the definitions of access authorization and revocation are considered. By modifying the user tracing mechanism, the DBP can independently revoke the access rights of fraudulent users. In addition, the number of bilinear pairing operations performed by users in the transfer phase is kept constant by optimizing the generation of the underlying zero-knowledge proofs.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Jan 1, 2022·IEEE Access
3 cites
Decentralized Review and Attestation of Software Attribute Claims

Oliver Stengele, Christina Westermeyer, Hannes Hartenstein

Software can be described, like human users and other objects, through attributes. For this work, we define software attributes as humanly verifiable, falsifiable, or judgeable statements regarding characteristics of said software. Much like attributes in general, software attributes require robust identities for their source but also for their target, meaning a software in general or a binary in particular. As software can be of critical importance, performing an independent review of attribute claims appears beneficial. We posit that decentralized platforms that were developed and refined over the past decade can bridge the gap between existing tools and methods for software review and their open, transparent, and accountable use for the benefit of users. In this work, we explore the feasibility and implications of decentralizing an independent review of software attribute claims. We envision the decentralization of a review process from initialization and execution to the persistent recording of results. We sketch the available design space by decomposing the overall process into a modular design and describe how each component covers overarching objectives. To illustrate practical implications and trade-offs, we present ETHDPR, a proof of concept implementation based on Ethereum and IPFS. Through a quantitative and qualitative evaluation, we show that a decentralized software review is practically feasible. We illustrate the flexibility of the proposed approach using a toy example of a software component in automotive systems. Lastly, we provide a discussion on fundamental limits and open issues of facilitating independent reviews via technological means.

Open access
Advanced Malware Detection Techniques
Security and Verification in Computing
Access Control and Trust
Original source
Jan 1, 2022·Computers, materials & continua/Computers, materials & continua (Print)
1 cites
Policy-Based Group Signature Scheme from Lattice

Yongli Tang, Yuanhong Li, Qing Ye, Ying Li · 5 authors

Although the existing group signature schemes from lattice have been optimized for efficiency, the signing abilities of each member in the group are relatively single. It may not be suitable for complex applications. Inspired by the pioneering work of Bellare and Fuchsbauer, we present a primitive called policy-based group signature. In policy-based group signatures, group members can on behalf of the group to sign documents that meet their own policies, and the generated signatures will not leak the identity and policies of the signer. Moreover, the group administrator is allowed to reveal the identity of signer when a controversy occurs. Through the analysis of application scenarios, we concluded that the policy-based group signature needs to meet two essential security properties: simulatability and traceability. And we construct a scheme of policy-based group signature from lattice through techniques such as commitment, zero-knowledge proof, rejection sampling. The security of our scheme is proved to be reduced to the module short integer solution (MSIS) and module learning with errors (MLWE) hard assumptions. Furthermore, we make a performance comparison between our scheme and three lattice-based group signature schemes. The result shows that our scheme has more advantages in storage overhead and the sizes of key and signature are decreased roughly by 83.13%, 46.01%, respectively, compared with other schemes.

Open access
Cryptography and Data Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Jan 1, 2022·Springer optimization and its applications
4 cites
On Trust, Blockchain, and Reputation Systems

Bruno Rodrigues, Muriel Figueredo Franco, Christian Killer, Eder J. Scheid · 5 authors

No abstract is available for this record.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jan 1, 2022·IEEE Access
29 cites
Formal Modeling and Verification of a Blockchain-Based Crowdsourcing Consensus Protocol

Hamra Afzaal, Muhammad Imran, Muhammad Umar Janjua, Sarada Prasad Gochhayat

Crowdsourcing is an effective technique that allows humans to solve complex problems that are hard to accomplish by automated tools. Some significant challenges in crowdsourcing systems include avoiding security attacks, effective trust management, and ensuring the system’s correctness. Blockchain is a promising technology that can be efficiently exploited to address security and trust issues. The consensus protocol is a core component of a blockchain network through which all the blockchain peers achieve an agreement about the state of the distributed ledger. Therefore, its security, trustworthiness, and correctness have vital importance. This work proposes a Secure and Trustworthy Blockchain-based Crowdsourcing (STBC) consensus protocol to address these challenges. Model checking is an effective and automatic technique based on formal methods that is utilized to ensure the correctness of STBC consensus protocol. The proposed consensus protocol’s formal specification is described using Communicating Sequential Programs (CSP#). Safety, fault tolerance, leader trust, and validators’ trust are important properties for a consensus protocol, which are formally specified through Linear Temporal Logic (LTL) to prevent several security attacks, such as blockchain fork, selfish mining, and invalid block insertion. Process Analysis Toolkit (PAT) is utilized for the formal verification of the proposed consensus protocol.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Jan 1, 2022·IEEE Access
3 cites
Circuitree: A Datalog Reasoner in Zero-Knowledge

Tom Godden, Ruben De Smet, Christophe Debruyne, Thibaut Vandervelden · 6 authors

Driven by the increased consciousness in data ownership and privacy, zero-knowledge proofs (ZKPs) have become a popular tool to convince a third party of the truthfulness of a statement without disclosing any further information. As ZKPs are rather complex to design, frameworks that transform high-level languages into ZKPs have been proposed. We propose Circuitree, a Datalog reasoner in zero-knowledge. Datalog is a high-level declarative logic language that is generally used for querying. Furthermore, as a logic language, it can also be used to solve logic problems. An application using Circuitree can efficiently generate ZKPs, based on Datalog rules and encrypted data, to prove that a certain conclusion follows from a Datalog ruleset and encrypted input data. Compared to existing frameworks, which generally use their own limited imperative languages, Circuitree uses an existing high-level declarative language. We point out several applications for Circuitree, including EU Digital COVID Certificates and privacy-preserving access control for peer-to-peer (p2p) networks. Circuitree’s performance is evaluated for access control in a p2p network. First results show that our approach allows for fast proofs and proof verification for this application.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Jan 1, 2022·IEEE Access
35 cites
CTB-PKI: Clustering and Trust Enabled Blockchain Based PKI System for Efficient Communication in P2P Network

Amrutanshu Panigrahi, Ajit Kumar Nayak, Rourab Paul, Bibhuprasad Sahu · 5 authors

The decentralization feature of public and private blockchain-based applications is achieved by selecting different nodes as validator or Certificate Authority (CA) for each transaction. Public blockchain uses Proof of Work (PoW) to search for the validator. PoW causes an enormous amount of energy. Therefore, Proof of Stake (PoS), and Proof of Authority (PoA) emerged as alternate solutions. Selection of a newCAusingPoSorPoAalgorithms for each transaction may improve transaction security. However, a network may have a large number of transactions, and selecting aCAfor each transaction usingPoSorPoAmay cause a significant amount of block propagation delay. Moreover, an increase in the number of participant nodes may increase the block propagation delay even further. Therefore, higher block propagation delay reduces network efficiency drastically. This paper proposes a different approach to increase the efficiency of Blockchain-based Public Key Infrastructure (BC – PKI). The proposed approach creates clusters of participant nodes based on their validation time, response time, and trust. This method selects a cluster based on the budget of response time and validation time given by the node that intends to start a transaction. Thereafter, the node which has the highest trust in that cluster is chosen as aCAfor the next transaction. Instead of searching on all participant nodes, our approach searches on the nodes of the chosen cluster which reduces the searching space of theCAselection process. This research work adopts a trust evaluation approach where the trust factor is quantified based on its experience and reputation. The node trust is reevaluated after every successful and unsuccessful transaction. A node that performs more successful transactions has more trust value. The node that has a higher trust value has a higher probability to be selected as aCAfor a transaction. The trust reevaluation process is followed by the clustering process. The result shows the proposed approach can reduce ~38.5% response time and ~2.2% validation time as compared to infrastructure which does not implement clustering. Additionally, the proposedCTB – PKIcan be used in Blockchain 2.0 and Blockchain 3.0-related applications.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Jan 1, 2022·Journal of Blockchain Research
9 cites
Distributed ecosystem for identity management

Rishabh Garg

The blockchain identity ecosystem offers the possibility of rejecting the outdated identity system and eliminate the intermediaries. Identity management, through blockchain, can allow individuals to take ownership of their identity by creating a global identity (ID) to serve multiple purposes. For user security and ledger consistency, asymmetric cryptography and distributed consensus algorithms can be implemented. Blockchain technology would be able to save costs and increase efficiency due to its key features such as decentralization, persistence, anonymity and auditability. In addition, the digital identity platform would save citizens' time in accessing or exchanging their personal data and records. Instead of being required to appear physically before the service provider, the user may be provided with a digital ID through his/her personal device, such as a smartphone, through which he/she can share his identity details with the service provider, using distributed ledger technology (DLT).

Open access
Cognitive Computing and Networks
Big Data and Digital Economy
Access Control and Trust
Original source
Dec 15, 2021·The Transactions of The Korean Institute of Electrical Engineers
2 cites
ATL Model Checking for Analysis of Ethereum Smart Contracts

Wonhong Nam, Hyunyoung Kil

A blockchain is a growing list of cryptographically secured blocks to maintain shared data on decentralized systems, in order to archive transactions between untrusted participants. Smart contracts are computer programs that automatically execute legal events according to the terms of contracts. Although the Ethereum blockchain has been successfully applied to a number of interesting applications, there have been several events that subtle flaws in smart contracts induce a huge amount of financial loss such as the DAO attack. Accordingly, to analyze smart contracts, we propose a novel formal verification technique to employ ATL (Alternating-time Temporal Logic) model checking. Our methodology represents the interaction between users and smart contracts with a two-player game and verify game properties by using MCMAS that is an efficient ATL model checker.

Access Control and Trust
Digital Rights Management and Security
Security and Verification in Computing
Original source
Dec 10, 2021·IEEE Internet of Things Journal
4 cites
Smart Collaborative Contract for Endogenous Access Control in Massive Machine Communications

Fei Song, Letian Li, Yikun, Li - · 7 authors

Emerging information technologies have accelerated the construction of the Industrial Internet of Things (IIoT). Unfortunately, the explosive growth of various services has caused serious challenges to access control in terms of scalability and trustworthiness. In this paper, we proposed the smart collaborative contract based endogenous access control mechanism. First, access control procedures running on centralized servers are migrated to distributed equipment located inside the data plane, which can reduce the transmission overhead and improve service capacity. Second, the smart collaborative contract is designed for credibility enhancement since part of attackers may attempt to compromise access control. It covers terminal behavior assessment and service request recording. Experiments conducted in a prototype show that the performance of the proposed scheme is better than the traditional solution and is resistant to common attacks.

Access Control and Trust
Digital Rights Management and Security
Privacy-Preserving Technologies in Data
Original source
Dec 1, 2021·DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
Credible distributed identity authentication system of microgrid based on blockchain

LIU Yin YANG Guanqun, ZHANG Jianhui XING Hongwei

Most of the blockchain-based identity authentication systems are based on public blockchain, which are still essentially traditional centralized identity management and verification methods, making it difficult to meet the needs of trusted access and fine-grained access control in microgrids. Therefore, based on the FISCO BCOS consortium blockchain technology, a distributed identity authentication system supporting multi-center was designed. A DID-based identity management protocol to achieve autonomous control of user identity in a practical scenarios was designed. Distributed trusted access technology for end nodes in microgrids was studied, and privacy-protecting credentials based on zero-knowledge proof were designed. This scheme meets the requirements of trustworthy and verifiable user identity in different privacy security scenarios, and achieves autonomous control of entity identity, fine-grained access control and trusted data exchange. The usability and effectiveness of the proposed algorithm are demonstrated through system experiments and performance analysis.

Open access
Blockchain Technology Applications and Security
Advanced Data and IoT Technologies
Technology and Security Systems
Original source
Dec 1, 2021·ACM SIGAPP Applied Computing Review
12 cites
A semantic-based access control approach for systems of systems

Mersedeh Sadeghi, Luca Sartor, Matteo Rossi

Access control management in a System of Systems---i.e., a collaborative environment composed of a multitude of distributed autonomous organizations---is a challenging task. To answer the challenge, in this paper we propose a novel approach that incorporates semantic technologies in the Attribute-Based Access Control (ABAC) approach. Building on the basic principles of ABAC, our approach allows for a highly expressive modeling of the context in which access decisions are made, by providing mechanisms to describe rich relationships among entities, which can evolve over time. In addition, our system works in a truly decentralized manner, which makes it suitable for geographically distributed enterprise systems. We show the feasibility in practice of our approach through some experimental results.

Access Control and Trust
Service-Oriented Architecture and Web Services
Business Process Modeling and Analysis
Original source
Dec 1, 2021·2021 IEEE International Conference on Blockchain (Blockchain)
10 cites
TRABAC: A Tokenized Role-Attribute Based Access Control using Smart Contract for Supply Chain Applications

Aisyah Ismail, Qian Wu, Mark Toohey, Young Choon Lee · 6 authors

The use of smart contracts for access control has shown to be promising as it ensures integrity and governs access to stored data, thanks to blockchain's immutability. While several recent studies have shown such usage, their applicability to supply chain applications remains limited due to less governance control capability and implementation complexity with smart contracts. This paper proposes the use of a tokenized role-attribute based access control (TRABAC) as a two-level access control for supply chain applications. In particular, TRABAC combines the simplicity of Role-Based Access Control (RBAC) and the flexibility and fine-grained capacity of Attribute-Based Access Control (ABAC). We consider these methods coupled with the use of Non-Fungible Token (NFT) as virtual assets in the supply chain. We also define four roles or parties that can have distinct and varied access rights. These roles are incorporated into TRABAC. The efficacy of TRABAC has been evaluated in five access control scenarios. Our experimental results show that TRABAC is capable of delegating access to four different supply chain roles. Importantly, TRABAC can effectively prevent unauthorized access requests by accounts that lack a valid Level 1 role or accounts that lack a valid token attribute or a tag in Level 2 of TRABAC.

Access Control and Trust
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Nov 4, 2021·IEEE Transactions on Circuits & Systems II Express Briefs
17 cites
Smart Contract-Based Access Control Through Off-Chain Signature and On-Chain Evaluation

Jialu Hao, Cheng Huang, Wenjuan Tang, Yang Zhang · 5 authors

Access control is essential in computer security systems to regulate the access to critical or valuable resources. Conventional access control models mainly rely on a centralized and trusted server to mediate each attempted access from client to resources, which face serious challenges of single point of failure and lack of transparency. In this brief, we propose a smart contract-based access control framework, which enables the owner to achieve resource access control in a reliable, auditable and scalable way. An access control contract is deployed on blockchain to manage attribute-based access policies of resources flexibly and make access decisions for clients credibly. A set of attributes is distributed to the clients through off-chain signatures signed by the owner to determine their privileges, without consuming the expensive on-chain storage space. Finally, we implement an experimental prototype on Ethereum test network and perform extensive experimental and theoretical analysis to evaluate its scalability and efficiency.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Nov 3, 2021·IEEE Internet of Things Journal
56 cites
Dynamic Access Control and Trust Management for Blockchain-Empowered IoT

Peng Wang, Ning Xu, Haibin Zhang, Wen Sun · 5 authors

The Internet of Things (IoT), while providing comprehensive interconnection and ubiquitous services, poses security issues by enabling resources sharing among various devices from different untrusted authorities. Blockchain, as a distributed ledger, provides a traceable and verifiable platform to ensure the secure access control in IoT. The existing works based on blockchain may bring up intolerable computing overhead and delay to the lightweight IoT devices. In this article, we propose a dynamic and lightweight attribute-based access control framework for blockchain-empowered IoT, to achieve secure and fine-grained authorization. The proposed scheme allows access to resources by evaluating attributes, operations, and the environment relevant to a request. The access policy is executed through smart contract in blockchain for security and flexibility. To further adapt to IoT device constraints, we design a access control framework based on decentralized application (DApp), which can maintain tamper proof in a timely manner and be adapt to the delay-intolerant application. When delay-intolerant access is required, access can be allowed according to local replica of the blockchain, without a consensus of blockchain network. Considering the time-varying attributes of IoT devices, a trust management scheme is proposed based on the Markov chain to resist the security fluctuation caused by the vulnerability of IoT devices. In the experiments, we deploy our system prototype on Ethereum to evaluate the feasibility and effectiveness of the scheme. The results show the proposed scheme can achieve secure, high throughput, and flexible access control in IoT.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Nov 1, 2021·Volume 8B: Energy
0 cites
Evaluating the Implementation of Distributed Ledger Technology for the Licensing and Regulation of Nuclear Power Plants

Priyanka Pandit, Alp Tezbasaran, Arjun Earthperson, Mihai Diaconeasa

Abstract The approval process from the U.S. Nuclear Regulatory Commission (NRC) for nuclear power plants is sequential. It involves several government bodies such as the Advisory Committee on Reactor Safeguards (ACRS), public meetings, and hearings. If the submissions made to the NRC do not contain enough information to meet the regulation requirements, the NRC issues a Request for Additional Information (RAI). Thus, the licensee has to go through a paperwork-intensive process that involves multiple regulatory agencies for the various licensing requirements. Moreover, sending applications to the NRC is limited to using an electronic submission generation tool called the Packing Slip Wizard (PSW). This paper presents a methodology to implement Distributed Ledger Technology (DLT) to address the need for a real-time, digitized documentation platform in the nuclear power industry’s licensing and regulation process. The evaluation of DLT’s implementation resulted in the formulation of a methodology to accept submissions from an applicant on a web application and storing the received data on a distributed ledger. The presented method offers a real-time submission of the available information of an application. It facilitates the NRC with a real-time feedback capability expediting the review process. RAI’s can be reduced in number by ensuring that the NRC’s information requirements are defined as smart contracts.

Digital Rights Management and Security
Access Control and Trust
Cloud Data Security Solutions
Original source
Oct 19, 2021·Lecture notes in computer science
57 cites
Three Attacks on Proof-of-Stake Ethereum

Caspar Schwarz-Schilling, Joachim Neu, Barnabé Monnot, Aditya Asgaonkar · 6 authors

Recently, two attacks were presented against Proof-of-Stake (PoS) Ethereum: one where short-range reorganizations of the underlying consensus chain are used to increase individual validators' profits and delay consensus decisions, and one where adversarial network delay is leveraged to stall consensus decisions indefinitely. We provide refined variants of these attacks, considerably relaxing the requirements on adversarial stake and network timing, and thus rendering the attacks more severe. Combining techniques from both refined attacks, we obtain a third attack which allows an adversary with vanishingly small fraction of stake and no control over network message propagation (assuming instead probabilistic message propagation) to cause even long-range consensus chain reorganizations. Honest-but-rational or ideologically motivated validators could use this attack to increase their profits or stall the protocol, threatening incentive alignment and security of PoS Ethereum. The attack can also lead to destabilization of consensus from congestion in vote processing.

Open access
3 source records
Distributed systems and fault tolerance
Internet Traffic Analysis and Secure E-voting
Security and Verification in Computing
Original source
Oct 1, 2021·2021 IEEE 30th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE)
3 cites
DART: Towards a role-based trust management system on blockchain

Luca Franceschi, Andrea Lisi, Andrea De Salve, Paolo Mori · 5 authors

In the past years, trust management systems have been proven suitable for solving the authorization problem in distributed systems, such as peer to peer systems, social networks, cloud, mobile ad-hoc networks, and Internet of things. Trust management systems could be either managed by a central authority or decentralized. In both cases the entity or, respectively, the set of entities managing the system need to be trusted for all users. To overcome this limitation, this paper brings blockchain technology into trust management systems, proposing a novel implementation of the Role-based Trust management framework (RT) on blockchain. The approach relies on smart contracts to represent user trust networks and to infer new trust relations through the chain discovery algorithm. We evaluated a prototype implemented on Ethereum on a representative set of policies related to different scenarios.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Oct 1, 2021·2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
10 cites
Privacy-Preserving eID Derivation to Self-Sovereign Identity Systems with Offline Revocation

Andreas Abraham, Karl Heinz Koch, Stefan More, Sebastian Ramacher · 5 authors

Digital identities play a vital role in an increasingly digital world. These identities often rely on central authorities to issue and manage them. Central authorities have the drawback of being a central trusted party, representing a bottleneck and single point of failure with exclusive control of identity-related data. Self-sovereign identity (SSI) tackles those problems by utilizing distributed ledger technology and making users the sovereign owners of their identity data. Nevertheless, SSI, as recent technology, still lacks qualified identity data. This is especially a problem since sensitive services like eGovernment or banking services require identity data issued by a qualified identity provider; thus, SSI - based identities cannot be used for these services. In this paper, we propose a concept for deriving identity data from an existing identity system into an SSI in a fully privacy-preserving way by additionally supporting offline verification. This way, we enable a chain of trust from the existing identity system to the SSI system by introducing a novel trust model. Our concept utilizes novel cryptographic primitives to support efficient and privacy-preserving identity showing as well as revo-cation. To underline the feasibility of our concept, we implement a proof system and benchmark the related use cases.

Cryptography and Data Security
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Oct 1, 2021·2021 IEEE 30th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE)
5 cites
Automatic Generation of Access Control for Permissionless Blockchains: Ethereum Use Case

Insaf Achour, Hanen Idoudi, Samiha Ayed

Access control in Blockchain context is a crucial step. During this process it is important to verify that users have the right roles to get access to the protected resources. To model its access control, the Ethereum Blockchain is based on RBAC model. The whole process is written in a smart Contract imported from The OpenZepplin Library [1]. However, the automatic generation of the access control policy still missing. This automation can widely enhance and simplify the implementation of access control for developers of blockchain based applications. In this paper, we propose a new model for automatically generating the access control smart contract. Our approach is based on the Model Driven Engineering (MDE).

Access Control and Trust
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Sep 29, 2021·2021 International Conference on Innovation and Intelligence for Informatics, Computing, and Technologies (3ICT)
3 cites
On the Implementation of Access Control in Ethereum Blockchain

Insaf Achour, Samiha Ayed, Hanen Idoudi

Access control is a main component in Blockchain systems. It is usually implemented in smart contracts and defines the security policy, in other words, it determines who can access a protected resource in the network. In this paper, we present a review of the major implementations of access control in Ethereum platform. The latter is based on RBAC model (Role-Based Access Control). Implementations require to take into account the whole RBAC process, that is, user role assignment and permission assignment. Three implementations currently exist and are described and compared in this work according to several features: RBAC-SC, Smart policies and OpenZepplin contracts.

Blockchain Technology Applications and Security
Access Control and Trust
Cryptography and Data Security
Original source
Sep 13, 2021·2021 IEEE International Symposium on Systems Engineering (ISSE)
52 cites
Sovrin Network for Decentralized Digital Identity: Analysing a Self-Sovereign Identity System Based on Distributed Ledger Technology

Nitin Naik, Paul Jenkins

Digital identity is the key to the evolving digital society and economy. Since the inception of digital identity, numerous Identity Management (IDM) systems have been developed to manage digital identity depending on the requirements of the individual and that of organisations. This evolution of IDM systems has provided an incremental process leading to the granting of control of identity ownership and personal data to its user, thus producing an IDM which is more user-centric with enhanced security and privacy. A recently promising IDM known as Self-Sovereign Identity (SSI) has the potential to provide this sovereignty to the identity owner. The Sovrin Network is an emerging SSI service utility enabling self-sovereign identity for all, therefore, its assessment has to be carefully considered with reference to its architecture, working, functionality, strengths and limitations. This paper presents an analysis of the Sovrin Network based on aforementioned features. Firstly, it presents the architecture and components of the Sovrin Network. Secondly, it illustrates the working of the Sovrin Network and performs a detailed analysis of its various functionalities and metrics. Finally, based on the detailed analysis, it presents the strengths and limitations of the Sovrin Network.

Cryptography and Data Security
Access Control and Trust
Cloud Data Security Solutions
Original source
Sep 6, 2021·International Journal of Network Management
4 cites
Veritaa: A distributed public key infrastructure with signature store

Jakob Schaerer, Severin Zumbrunn, Torsten Braun

Summary Today, the integrity and authenticity of digital documents and data are often hard to verify. Existing public key infrastructures (PKIs) are capable of certifying digital identities but do not provide solutions to store signatures immutably, and the process of certification is often not transparent. We propose Veritaa, a distributed public key infrastructure with an integrated signature store (DPKISS). The central part of Veritaa is the Graph of Trust that manages identity claims and singed declarations between identity claims and document identifiers. An application‐specific distributed ledger is used to store the transactions that form the Graph of Trust immutably. For the distributed certification of identity claims, a reputation system based on signed trust declarations and domain vetting is used. In this work, we have designed and implemented the proposed architecture of Veritaa, created a testbed, and performed several experiments. The experiments show the benefits and the high performance of Veritaa.

Open access
Access Control and Trust
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Aug 31, 2021·IEEE Internet of Things Journal
27 cites
Policychain: A Decentralized Authorization Service With Script-Driven Policy on Blockchain for Internet of Things

E Chen, Yan Zhu, Zhiyuan Zhou, Shou-Yu Lee · 6 authors

The decentralization mechanism provides manufacturers and distributors with greater customization and flexibility they need through Internet of Things (IoT)-based industrial collaboration systems (IoT-ICS), but it has brought forward security concerns about the shared data-processing tasks and IoT-based access to services and resources. To address them, we propose a practical blockchain solution to achieve decentralized policy management and evaluation on attribute-based access control (ABAC). By offloading the responsibility of ABAC policy administration and decision making to blockchain nodes, a blockchain-based access control framework, called Policychain, is presented to ensure policy with high availability, autonomy, and traceability. To deliver a solid design, we first present a transaction-oriented policy expression scheme with a well-defined syntax and semantics. The scheme can translate ABAC policies into the blockchain transactions with JavaScript object notation (JSON) syntax and script-based logical expression. We further realize a script-driven policy evaluation by extending blockchain inherent scripting instructions to support attribute acquisition of ABAC entities. Furthermore, we propose a policy lifecycle management scheme from policy creation, renovation, to revocation, in which policies are verified by three validation principles at the transaction level. Finally, we provide sophisticated analysis and experiments to show that our framework is secure and practical for decentralized policy management on ABAC in IoT-ICS.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source