Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results · page 27 of 38

Clear filters
Aug 24, 2021·VBN Forskningsportal (Aalborg Universitet)
8 cites
Adapting the TPL Trust Policy Language for a Self-Sovereign Identity World

Lukas Alber, Stefan More, Sebastian Mödersheim, Anders Schlichtkrull

Trust policies enable the automated processing of trust decisions for electronic transactions. We consider the Trust Policy Language TPL of the LIGHTest project [Mö19] that was designed for businesses and organizations to formulate their trust policies. Using TPL, organizations can decide if and how they want to rely on existing trust schemes like Europe’s eIDAS or trust scheme translations endorsed by them. While the LIGHTest project is geared towards classical approaches like PKI-based trust infrastructures and X.509 certificates, novel concepts are on the rise: one example is the self-sovereign identity (SSI) model that enables users better control of their credentials, offers more privacy, and supports decentralized solutions. Since SSI is based on distributed ledger (DL) technology, it is a question of how TPL can be adapted so that organizations can continue to enjoy the benefits of flexible policy descriptions with automated evaluation at a very high level of reliability. Our contribution is a first step towards integrating SSI and the interaction with a DL into a Trust Policy Language. We discuss this on a more conceptual level and also show required TPL modifications. We demonstrate that we can integrate SSI concepts into TPL without changing the syntax and semantics of TPL itself and have to add new formats and introduce a new built-in predicate for interacting with the DL. Another advantage of this is that the “business logic” aspect of a policy does not need to change, enable re-use of existing policies with the new trust model.

Open access
Access Control and Trust
Original source
Jul 31, 2021·IJNSA 13 (2021) 23-40
21 cites
Proof-of-Reputation: An Alternative Consensus Mechanism for Blockchain Systems

Oladotun Aluko, Anton Kolonin

Blockchains combine other technologies, such as cryptography, networking, and incentive mechanisms, to enable the creation, validation, and recording of transactions between participating nodes. A consensus algorithm is used in a blockchain system to determine the shared state among distributed nodes. An important component underlying any blockchain-based system is its consensus mechanism, which principally determines the performance and security of the overall system. As the nature of peer-to- peer(P2P) networks is open and dynamic, the security risk within that environment is greatly increased mostly because nodes can join and leave the network at will. Thus, it is important to have a system that can check against malicious behaviour. In this work, we propose a reputation-based consensus mechanism for blockchain-based systems, Proof-of-Reputation(PoR) where the nodes with the highest reputation values eventually become part of a consensus group that determines the state of the blockchain.

Open access
2 source records
cs.SI
cs.DB
Blockchain Technology Applications and Security
Original source
Jun 14, 2021·Journal of Medical Internet Research
63 cites
Blockchain for Increased Trust in Virtual Health Care: Proof-of-Concept Study

Anton Hasselgren, Jens-Andreas Hanssen Rensaa, Katina Kralevska, Danilo Gligoroski · 5 authors

BACKGROUND: Health care systems are currently undergoing a digital transformation that has been primarily triggered by emerging technologies, such as artificial intelligence, the Internet of Things, 5G, blockchain, and the digital representation of patients using (mobile) sensor devices. One of the results of this transformation is the gradual virtualization of care. Irrespective of the care environment, trust between caregivers and patients is essential for achieving favorable health outcomes. Given the many breaches of information security and patient safety, today's health information system portfolios do not suffice as infrastructure for establishing and maintaining trust in virtual care environments. OBJECTIVE: This study aims to establish a theoretical foundation for a complex health care system intervention that aims to exploit a cryptographically secured infrastructure for establishing and maintaining trust in virtualized care environments and, based on this theoretical foundation, present a proof of concept that fulfills the necessary requirements. METHODS: This work applies the following framework for the design and evaluation of complex intervention research within health care: a review of the literature and expert consultation for technology forecasting. A proof of concept was developed by following the principles of design science and requirements engineering. RESULTS: This study determined and defined the crucial functional and nonfunctional requirements and principles for enhancing trust between caregivers and patients within a virtualized health care environment. The cornerstone of our architecture is an approach that uses blockchain technology. The proposed decentralized system offers an innovative governance structure for a novel trust model. The presented theoretical design principles are supported by a concrete implementation of an Ethereum-based platform called VerifyMed. CONCLUSIONS: A service for enhancing trust in a virtualized health care environment that is built on a public blockchain has a high fit for purpose in Healthcare 4.0.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Access Control and Trust
Original source
Jun 1, 2021·2021 IEEE 34th Computer Security Foundations Symposium (CSF)
13 cites
Formal security analysis of MPC-in-the-head zero-knowledge protocols

Nikolaj Sidorenco, Sabine Oechsner, Bas Spitters

Zero-knowledge proofs allow a prover to convince a verifier of the veracity of a statement without revealing any other information. An interesting class of zero-knowledge protocols are those following the MPC-in-the-head paradigm (Ishai et al., STOC '07) which use secure multiparty computation (MPC) protocols as the basis. Efficient instances of this paradigm have emerged as an active research topic in the last years, starting with ZKBoo (Giacomelli et al., USENIX '16). Zero-knowledge protocols are a vital building block in the design of privacy-preserving technologies as well as cryptographic primitives like digital signature schemes that provide post-quantum security. This work investigates the security of zero-knowledge protocols following the MPC-in-the-head paradigm. We provide the first machine-checked security proof of such a protocol on the example of ZKBoo. Our proofs are checked in the EasyCrypt proof assistant. To enable a modular security proof, we develop a new security notion for the MPC protocols used in MPC-in-the-head zero-knowledge protocols. This allows us to recast existing security proofs in a black-box fashion which we believe to be of independent interest.

Open access
Cryptography and Data Security
Advanced Authentication Protocols Security
Access Control and Trust
Original source
May 28, 2021·2021 IEEE International Conference on Artificial Intelligence and Industrial Design (AIID)
3 cites
Internet of Things Access Control System Based on Smart Contract

Long Xu, Li Yang

The rising of digital economy is due to the rapidly development of the new generation of information technology, represented by Internet of Things (IoT) technology. However, the huge number of sensors have limited resources and lack robust security mechanism, which brings a great risk challenges for centralized access control system. In order to deal with these challenges, the paper proposes a novel Capability-Based Access Control Model (NCBAC), which makes use of the advantages of Capability-Based Access Control (CBAC) decision-making mechanism and introduces role sets and attribute set for smart contract. This model is built for providing a decentralized, flexible, expandable and high-granularity access control system. Additionally, token has been conducted in access control model for enhancing the system's capability. Finally, the simulation experiment results showed the feasibility and effectiveness of the system, which also demonstrates the token mechanism promoting the access control performance of the system effectively.

Blockchain Technology Applications and Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
May 7, 2021·Studies in health technology and informatics
6 cites
A Mechanism for Verifying the Integrity and Immutability of Tuberculosis Data Using IOTA Distributed Ledger Technology

Vinícius Lima, Filipe Andrade Bernardi, Rui Rijo, Jó Ueyama · 5 authors

BACKGROUND: Intensified research and innovation and rapid uptake of new tools, interventions, and strategies are crucial to fight Tuberculosis, the world's deadliest infectious disease. The sharing of health data remains a significant challenge. Data consumers must be able to verify the consistency and integrity of data. Solutions based on distributed ledger technologies may be adequate, where each member in a network holds a unique credential and stores an identical copy of the ledger and contributes to the collective process of validating and certifying digital transactions. OBJECTIVES: This work proposes a mechanism and presents a use case in Digital Health to allow the verification of integrity and immutability of TB electronic health records. METHODS: IOTA was selected as a supporting tool due to its data immutability, traceability and tamper-proof characteristics. RESULTS: A mechanism to verify the integrity of data through hash functions and the IOTA network is proposed. Then, a set of TB related information systems was integrated with the network. CONCLUSION: IOTA technology offers performance and flexibility to enable a reliable environment for electronic health records.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Digital Rights Management and Security
Original source
May 3, 2021·2021 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
10 cites
Dynamic Management of Identity Federations using Blockchain

Ifteher Alom, Romana Mahjabin Eshita, Anam Ibna Harun, Md Sadek Ferdous · 7 authors

Federated Identity Management (FIM) is a model of identity management in which different trusted organizations can provide secure online services to their uses. Security Assertion Markup Language (SAML) is one of the widely-used technologies for FIM. However, a SAML-based FIM has two significant issues: the metadata (a crucial component in SAML) has security issues, and federation management is hard to scale. The concept of dynamic identity federation has been introduced, enabling previously unknown entities to join in a new federation facilitating inter-organization service provisioning to address federation management's scalability issue. However, the existing dynamic federation approaches have security issues concerning confidentiality, integrity, authenticity, and transparency. In this paper, we present the idea of facilitating dynamic identity federations utilizing blockchain technology to improve the existing approaches' security issues. We demonstrate its architecture based on a rigorous threat model and requirement analysis. We also discuss its implementation details, current protocol flows and analyze its performance to underline its applicability.

Cloud Data Security Solutions
Blockchain Technology Applications and Security
Access Control and Trust
Original source
May 3, 2021·2021 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
11 cites
BEAAS: Blockchain Enabled Attribute-Based Access Control as a Service

Ritik Kumar, Balaji Palanisamy, Shamik Sural

We propose BEAAS, a cloud service for Attribute-Based Access Control (ABAC) with security guarantee provided through the use of blockchain, specifically Ethereum. It enables user organizations to verify whether its access control data as well as access mediation decisions made by the cloud service were indeed done in an authorized manner. All the changes to the various ABAC components and access history are added to the Ethereum blockchain using efficiently written smart contracts in Solidity. We have developed a prototype system on the Rinkeby Ethereum test network and verified its functionality.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
May 3, 2021·2021 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
9 cites
A-PoA: Anonymous Proof of Authorization for Decentralized Identity Management

Jan Lauinger, Jens Ernstberger, Emanuel Regnath, Mohammad Hamad · 5 authors

Self-sovereign Identity Management (SSIM) pro-motes self-control of credentials without relying on external administration. However, the state-of-the-art SSIM based on Decentralized Identifiers and Verifiable Credentials (VCs) defined by the World Wide Web Consortium does not enable credential holders to verify whether a Credential Issuing Authority (CIA) legitimately issued a credential.As a remedy, our work constructs a secure authentication protocol, called A-PoA, to provide decentralized and anonymous authorization of CIAs. We leverage a cryptographic accumulator to enable the Root Authority (registering a Credential Schema) with the ability to authorize a CIA (registering a Credential Definition) to issue a credential. The proof of accumulator membership relies on a non-interactive zero-knowledge proof. This allows a credential holder or validator node to verify the validity of a CIA, while the CIA remains anonymous. Our security analysis shows the integrity and confidentiality of our protocol against hostile network participants and our experimental evaluation shows constant verification times independent of the number of authenticated CIAs. Hence, A-PoA introduces the missing building block to develop SSIM-capable and VC-compatible ecosystems acting as a drop-in replacement for traditional Public Key Infrastructure schemes.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Apr 12, 2021
25 cites
Trust management for widely distributed systems

Walt Yao

In recent years, we have witnessed the evolutionary development of a new breed of distributed systems. Systems of this type share a number of characteristics – highly decentralized, of Internet-grade scalability, and autonomous within their administrative domains. Most importantly, they are expected to operate collaboratively across both known and unknown domains. Prime examples include peer-to-peer applications and open web services. Typically, authorization in distributed systems is identity-based, e.g. access control lists. However, approaches based on predefined identities are unsuitable for the new breed of distributed systems because of the need to deal with unknown users, i.e. strangers, and the need to manage a potentially large number of users and/or resources. Furthermore, effective administration and management of authorization in such systems requires: (1) natural mapping of organizational policies into security policies; (2) managing collaboration of independently administered domains/organizations; (3) decentralization of security policies and policy enforcement. This thesis describes Fidelis, a trust management framework designed to address the authorization needs for the next-generation distributed systems. A trust management system is a term coined to refer to a unified framework for the specification of security policies, the representation of credentials, and the evaluation and enforcement of policy compliances. Based on the concept of trust conveyance and a generic abstraction for trusted information as trust statements, Fidelis provides a generic platform for building secure, trust-aware distributed applications. At the heart of the Fidelis framework is a language for the specification of security policies, the Fidelis Policy Language (FPL), and the inference model for evaluating policies expressed in FPL. With the policy language and its inference model, Fidelis is able to model recommendation-style policies and policies with arbitrarily complex chains of trust propagation. Web services have rapidly been gaining significance both in industry and research as a ubiquitous, next-generation middleware platform. The second half of the thesis describes the design and implementation of the Fidelis framework for the standard web service platform. The goal of this work is twofold: first, to demonstrate the practical feasibility of Fidelis, and second, to investigate the use of a policy-driven trust management framework for Internet-scale open systems. An important requirement in such systems is trust negotiation that allows unfamiliar principals to establish mutual trust and interact with confidence. Addressing this requirement, a trust negotiation framework built on top of Fidelis is developed. This thesis examines the application of Fidelis in three distinctive domains: implementing generic role-based access control, trust management in the World Wide Web, and an electronic marketplace comprising unfamiliar and untrusted but collaborative organizations.

Open access
Access Control and Trust
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Mar 22, 2021·Proceedings of the 36th Annual ACM Symposium on Applied Computing
5 cites
A semantic-based access control mechanism for distributed systems

Mersedeh Sadeghi, Luca Sartor, Matteo Rossi

Access control management in a collaborative environment composed of a multitude of distributed autonomous organizations is a challenging task. To answer the challenge, in this paper we propose a novel approach that incorporates semantic technologies in the Attribute-Based Access Control (ABAC) approach. Building on the basic principles of ABAC, our approach allows for a highly expressive modeling of the context in which access decisions are made, by providing mechanisms to describe rich relationships among entities, which can evolve over time. In addition, our system works in a truly decentralized manner, which makes it suitable for geographically distributed enterprise systems. We show the feasibility in practice of our approach through some experimental results.

Open access
Access Control and Trust
Service-Oriented Architecture and Web Services
Distributed systems and fault tolerance
Original source
Mar 3, 2021·2021 26th International Computer Conference, Computer Society of Iran (CSICC)
7 cites
An Improved Distributed Access Control Model in Cloud Computing by Blockchain

Akram Sabzmakan, Seyedeh Leili Mirtaheri

With the ever-expanding digital communications and the need for advanced interoperability and collaboration, organizations and entities need to share their digital assets. Cloud computing is now widely used for managing and storing resources. Access control is a critical issue, facing many challenges in distributed environments, including clouds. In this paper, we present a model of the cloud access control system. Our distributed model utilizes a role-based access control to enable the management of resources and the parties' access securely. We provide interoperability between multiple organizations to access shared resources using Ethereum Blockchain smart contracts and access levels for available resources. Roles define access permissions; however, unlike the traditional role-based access control model, the roles are determined according to the organizations involved' collaborative project, sometimes may not exist in any organization. They can only be created in their interactions. Finally, for evaluating its cost and time parameters. We use Ethereum smart contracts and deploy them in the Ethereum test network called Rinkby,.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Access Control and Trust
Original source
Feb 1, 2021·China Communications
26 cites
BC-BLPM: A multi-level security access control model based on blockchain technology

Xiang Yu, Zhangxiang Shu, Qiang Li, Jun Huang

Traditional multi-level security (MLS) systems have the defect of centralizing authorized facilities, which is difficult to meet the security requirements of modern distributed peer-to-peer network architecture. Blockchain is widely used in the field of access control with its decentralization, traceability and non-defective modification. Combining the blockchain technology and the Bell-LaPadula model, we propose a new access control model, named BC-BLPM, for MLS environment. The “multi-chain” blockchain architecture is used for dividing resources into isolated access domains, providing a fine-grained data protection mechanism. The access control policies are implemented by smart contracts deployed in each access domain, so that the side chains of different access domains storage access records from outside and maintain the integrity of the records. Finally, we implement the BC-BLPM prototype system using the Hyperledger Fabric. The experimental and analyt-ical results show that the model can adapt well to the needs of multi-level security environment, and it has the feasibility of application in actual scenarios.

Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Jan 27, 2021·2021 IEEE 11th Annual Computing and Communication Workshop and Conference (CCWC)
9 cites
CryptoRevocate: A Cryptographic Accumulator based Distributed Certificate Revocation List

İlker Özçelik, Anthony Skjellum

Verification of the certificate revocation status is a crucial process for Public Key Infrastructure (PKI) system reliability. Failing to detect a revoked certificate may lead to catastrophic system compromises. Existing verification systems use slow and centralized approaches like Certificate Revocation Lists (CRLs) and Online Certificate Status Protocol (OCSP). These systems are known to cause verification failures (soft fails) because of system and network delays. Additionally, the availability of these systems are a major concern. Recent developments in distributed ledger (blockchain) technologies enable this information to be reliably published on the Internet, in a distributed manner. However in a distributed system, synchronizing large amounts of data among the nodes is an expensive task. One way to combat this issue is to use cryptographic accumulators, a tool that can be used to reduce data size; when only membership test statuses are necessary from a set of data. In this study, we focus on the reliable and effective distribution of certificate revocation information. We present a design of an asymmetric cryptographic accumulator based effective certificate revocation system. To the best of our knowledge, this is the first study using asymmetric cryptographic accumulators to distribute certificate revocation data via blockchain.

Cryptography and Data Security
Access Control and Trust
Security in Wireless Sensor Networks
Original source
Jan 1, 2021·Lecture notes in computer science
0 cites
Policy-Compliant Signatures

Christian Badertscher, Christian Matt, Hendrik Waldner

No abstract is available for this record.

Cryptography and Data Security
Access Control and Trust
Security in Wireless Sensor Networks
Original source
Jan 1, 2021·Lecture notes in computer science
49 cites
SMILE: Set Membership from Ideal Lattices with Applications to Ring Signatures and Confidential Transactions

Vadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor Seiler

In a set membership proof, the public information consists of a set of elements and a commitment. The prover then produces a zero-knowledge proof showing that the commitment is indeed to some element from the set. This primitive is closely related to concepts like ring signatures and “one-out-of-many” proofs that underlie many anonymity and privacy protocols. The main result of this work is a new succinct lattice-based set membership proof whose size is logarithmic in the size of the set.

2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Jan 1, 2021·Lecture notes in computer science
26 cites
SoK: Auditability and Accountability in Distributed Payment Systems

Panagiotis Chatzigiannis, Foteini Baldimtsi, Konstantinos Chalkias

Enforcement of policy regulations and availability of auditing mechanisms are crucial building blocks for the adoption of distributed payment systems. In this work we review a number of existing proposals for distributed payment systems that offer some form of auditability for regulators. We identify two major distinct lines of work: payment systems that are not privacy-preserving such as Bitcoin, where regulation functionalities are typically tailored for organizations controlling many accounts, and privacy-preserving payment systems where regulation functionalities are typically targeted to user level. We provide a systematization methodology over several axes of characteristics and performance, while highlighting insights and research gaps that we have identified, such as lack of dispute-resolution solutions between the regulator and the entity under audit, and the incompatibility of ledger pruning or off-chain protocols with regulatory requirements. Based on our findings, we propose a number of exciting future research directions.

2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Internet Traffic Analysis and Secure E-voting
Original source
Jan 1, 2021·Proceedings of the 36th IFIP TC 11 International Conference on ICT Systems Security and Privacy Protection (IFIP SEC 2021)/IFIP Advances in Information and Communication Technology, vol. 625, 2021, 19-35
1 cites
Trust Me If You Can: Trusted Transformation Between (JSON) Schemas to Support Global Authentication of Education Credentials

Stefan More, Peter Grassberger, Felix Hörandner, Andreas Abraham · 5 authors

Recruiters and institutions around the world struggle with the verification of diplomas issued in a diverse and global education setting. Firstly, it is a nontrivial problem to identify bogus institutions selling education credentials. While institutions are often accredited by qualified authorities on a regional level, there is no global authority fulfilling this task. Secondly, many different data schemas are used to encode education credentials, which represents a considerable challenge to automated processing. Consequently, significant manual effort is required to verify credentials. In this paper, we tackle these challenges by introducing a decentralized and open system to automatically verify the legitimacy of issuers and interpret credentials in unknown schemas. We do so by enabling participants to publish transformation information, which enables verifiers to transform credentials into their preferred schema. Due to the lack of a global root of trust, we utilize a distributed ledger to build a decentralized web of trust, which verifiers can query to gather information on the trustworthiness of issuing institutions and to establish trust in transformation information. Going beyond diploma fraud, our system can be generalized to tackle the generalized problem for other domains lacking a root of trust and agreements on data schemas.

Open access
2 source records
cs.CY
Access Control and Trust
Cryptography and Data Security
Original source