Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results · page 30 of 38

Clear filters
Jul 1, 2019·2019 International Conference on Communications, Information System and Computer Engineering (CISCE)
17 cites
An Access Control Model and Its Application in Blockchain

Xiangwu Ding, Jianming Yang

Access control technology is an important information security mechanism. At present, most of the database systems and enterprise information systems are role-based access control technologies, this rights management system has been running stably. However, due to the simple role access control, its flexibility and control granularity sometimes can't meet the requirements of actual access control. This paper proposes a secure access control model ARBACV1 based on RBACV1 combined with ABAC model, which is more flexible than RBACV1 and can perform fine-grained access control. The open transparency of data in the blockchain has caused people's high attention to data privacy protection issues[1]. A complete access control mechanism has not been provided in the Ethereum blockchain. To this end, according to the blockchain architecture, the proposed access control model ARBACV1 is applied to the blockchain through smart contracts, and the access of the blockchain users is controlled securely, and the code is written in Solidity language in Ethereum[2]. ARBACV1-based access control is implemented in blockchain.

Access Control and Trust
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Jul 1, 2019·2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS)
12 cites
Trust Mends Blockchains: Living up to Expectations

Leila Bahri, Ơarƫnas Girdzijauskas

At the heart of Blockchains is the trustless leader election mechanism for achieving consensus among pseudo-anonymous peers, without the need of oversight from any third party or authority whatsoever. So far, two main mechanisms are being discussed: proof-of-work (PoW) and proof-of-stake (PoS). PoW relies on demonstration of computational power, and comes with the markup of huge energy wastage in return of the stake in cyrpto-currency. PoS tries to address this by relying on owned stake (i.e., amount of crypto-currency) in the system. In both cases, Blockchains are limited to systems with financial basis. This forces non-crypto-currency Blockchain applications to resort to "permissioned" setting only, effectively centralizing the system. However, non-crypto-currency permisionless blockhains could enable secure and self-governed peer-to-peer structures for numerous emerging application domains, such as education and health, where some trust exists among peers. This creates a new possibility for valuing trust among peers and capitalizing it as the basis (stake) for reaching consensus. In this paper we show that there is a viable way for permisionless non-financial Blockhains to operate in completely decentralized environments and achieve leader election through proof-of-trust (PoT). In our PoT construction, peer trust is extracted from a trust network that emerges in a decentralized manner and is used as a waiver for the effort to be spent for PoW, thus dramatically reducing total energy expenditure of the system. Furthermore, our PoT construction is resilient to the risk of small cartels monopolizing the network (as it happens with the mining-pool phenomena in PoW) and is not vulnerable to sybils. We evluate security guarantees, and perform experimental evaluation of our construction, demonstrating up to 10-fold energy savings compared to PoW without trading off any of the decentralization characteristics, with further guarantees against risks of monopolization.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
May 13, 2019·Companion Proceedings of The 2019 World Wide Web Conference
9 cites
Towards a Decentralized, Trusted, Intelligent and Linked Public Sector: A Report from the Greek Trenches

Themis Beris, Iosif Angelidis, Ilias Chalkidis, Charalampos Nikolaou · 7 authors

This paper is a progress report on our recent work on two applications that use Linked Data and Distributed Ledger technologies and aim to transform the Greek public sector into a decentralized, trusted, intelligent and linked organization. The first application is a re-engineering of Diavgeia, the Greek government portal for open and transparent public administration. The second application is Nomothesia, a new portal that we have built, which makes Greek legislation available on the Web as linked data to enable its effective use by citizens, legal professionals and software developers who would like to build new applications that utilize Greek legislation. The presented applications have been implemented without funding from any source and are available for free to any part of the Greek public sector that may want to use them. An important goal of this paper is to present the lessons learned from this effort.

Open access
Semantic Web and Ontologies
Access Control and Trust
Blockchain Technology Applications and Security
Original source
May 1, 2019·2019 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
12 cites
SDPP: Streaming Data Payment Protocol for Data Economy

Rahul Radhakrishnan, Gowri Ramachandran, Bhaskar Krishnamachari

Applications in the area of IoT and smart cities rely heavily on data to manage and control their operational environments. In such applications, machine learning and artificial intelligence algorithms help the government officials, city administrators, and industries to make an informed decision on managing their cities and factories using the data collected from various sources. As we step into the era where ”data is termed as new oil”, there is a need for protocols with support for selling and buying data without giving up the data ownership to third-parties. In this demo, we present Streaming Data Payment Protocol (SDPP), which is an application layer protocol for selling and buying data. SDPP uses blockchain and distributed ledger technology for micropayments and immutable storage of transaction records. In addition, our protocol has a built-in mechanism to set data granularity since the bulk transfer of data between a seller and a buyer may lead to a loss for the seller if the buyer terminates the connection after receiving the data without making a payment. In this demo, we present SDPP and explain how it can contribute to the emerging data economy using a proof-of-concept implementation that uses TCP protocol for data communication and IOTA as both cryptocurrency and a distributed ledger.

IoT and Edge/Fog Computing
Distributed systems and fault tolerance
Access Control and Trust
Original source
Apr 8, 2019·Immunotechnology
21 cites
A Reputation Scheme for a Blockchain-based Network Cooperative Defense

Andreas Gruhler, Bruno Rodrigues, Burkhard Stiller

Distributed Denial-of-Service (DDoS) attacks rise in frequency, diversity, and intensity. Often, centralized defense approaches lack hard- and software capabilities. A cooperative, multi-domain DDoS mitigation system provides defense services on top of an existing, distributed infrastructure. However, participants in these systems lack incentives for cooperation and reputation. Thus, reward systems can fill this gap by providing necessary incentives for cooperation among service providers and consumers. This paper presents the design, implementation, and evaluation of a reputation scheme for the Blockchain Signaling System (BloSS). A smart contract-enabled process automates reputation management to diminish malicious behavior by incentive design. Among other metrics, Beta reputation provides intelligence to identify and reward honest participants.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Access Control and Trust
Original source
Apr 1, 2019·2019 IEEE 5th World Forum on Internet of Things (WF-IoT)
33 cites
DCACI: A Decentralized Lightweight Capability Based Access Control Framework using IOTA for Internet of Things

Sandeep Kiran Pinjala, Krishna M. Sivalingam

Security and Privacy are some of the important aspects to be considered in the large-scale deployment of Internet of Things (IoT) systems. Due to the large number of IoT devices and the different administrative domains in which they operate, traditional approaches involving a Centralized server for managing Authorizations will not be scalable or efficient. In this paper, we propose a Decentralized Capability-Based Access Control framework using IOTA (DCACI); IOTA is an open-source distributed ledger that enables fee-less micro transactions for the IoT. The DCACI framework enables complete privacy and integrity of the Capability tokens using IOTA's Masked Authenticated Messaging (MAM) technology. It enables device owners and users to Grant, Update, Delegate and Revoke the capability tokens. The proposed DCACI framework has been implemented as a proof-of-concept on a resource constrained machine; the results indicate that it is capable of scaling up to large-scale infrastructure such as a Smart City, having millions of IoT devices.

Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Apr 1, 2019·2019 26th International Conference on Telecommunications (ICT)
10 cites
An access control scheme with fine-grained time constrained attributes based on smart contract and trapdoor

Xuanmei Qin, Yongfeng Huang, Zhen Yang, Xing Li

Attribute-based encryption describes the access policy with the attribute information of users. In practice, attributes usually have a certain lifespan. The existing time-based access control methods directly relate attribute keys to time. Thus, under the constraint of fine-grained time, when the attribute expires, the update of key and policy adds a large additional burden to the data user and owner. In this paper, we propose a dynamic attribute-based access control scheme to set a fine-grained valid time period for each attribute, which not only facilitates dynamic data sharing, but also enables flexible attribute revocation. We use smart contract to set valid time period for attributes. It provides smart management on users' attributes and avoids the waiting time of CSP caused by manual operations. We also introduce trapdoor that are indirectly related to time and proxy decryption method to reduce computational cost on data owners and users. Extensive security and performance analysis shows the security strength and effectiveness of the proposed scheme.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Mar 31, 2019·Advances in information security, privacy, and ethics book series
1 cites
How to Authenticate MQTT Sessions Without Channel- and Broker Security

Reto E. Koenig, Lukas Laederach, Cédric von Allmen

This paper describes a new but state-of-the-art approach to provide authenticity in mqtt sessions using the means of zero-knowledge-proofs. This approach completely voids session hijacking for the mqtt protocol and provides authenticity without the need for any network-security nor channel-security nor broker-based predefined ACLs. The presented approach does not require the broker to keep any secrets for session handling, what so ever. Moreover, it allows the clientID, which represents the identification for a session, to be publicly known. The presented approach allows completely anonymous but authentic sessions, hence the broker does not need any a priori knowledge of the client-party. As it is especially targeted for applications within the world of IoT, the presented approach is tuned to require only the minimum in extra power in terms of energy and space. The approach does not introduce any new concept, but simply fusions a state-of-the-art cryptographic zero knowledge proof of identity with the existing MQTT-5 specification. Thus no protocol extension is required in order to provide the targeted security properties. The described approach is completely agnostic to the application layer at the client side and is only required during mqtt-session establishment.

Open access
3 source records
cs.NI
cs.CR
Security and Verification in Computing
Original source
Mar 29, 2019·HAL (Le Centre pour la Communication Scientifique Directe)
0 cites
SLAs pour la supervision de sĂ©curitĂ© dans les clouds : le cas de l’intĂ©gritĂ© des donnĂ©es

Amir Teshome Wonjiga, Louis Rilling, Christine Morin

The cloud computing business model introduced a new paradigm in terms of ownership of a system. Before the cloud, a user acquires physical infrastructure and uses it by installing and configuring according to her/his needs. In that scenario, the full system is owned by a single entity. In the cloud, when the user outsources a service for a cloud provider the user owns some part of the system while the provider owns the remaining part. Thus, ownership in the cloud is divided between different entities. Clients hosting their information system need to trust and rely on what the providers claim. At the same time providers try to give assurance for some aspects of the provided service (e.g. availability) through service level agreements (SLAs). We aim at extending SLAs to include security monitoring terms. In a previous study [1] we proposed an SLA verification method for security monitoring SLAs describing the performance on an NIDS.In this paper we consider an SLA guaranteeing the integrity of tenants’ data stored in the cloud. The tenant outsources data storage service to a Storage as a Service cloud provider. In such a system the data is owned by the tenant while the provider owns the infrastructure. We consider an SLA offered by the provider to guarantee the integrity of tenants’ data. In this paper, we propose a verification method, i.e. an integrity checking method, which is based on a distributed ledger. Specifically, our proposed method allows both providers and tenants to perform integrity checking without one party relying on the other. The method uses a blockchain as a distributed ledger to store evidences of data integrity. Assuming the ledger as a secure, trusted source of information, the evidence can be used to resolve conflicts between providers and tenants. In addition, we present a prototype implementation and an experimental evaluation to show the feasibility of our verification method and to measure the time overhead introduced.

Open access
Cloud Data Security Solutions
Access Control and Trust
Blockchain Technology Applications and Security
Original source
Mar 22, 2019·LA Referencia (Red Federada de Repositorios Institucionales de Publicaciones Científicas)
0 cites
Context-Aware Access Control Models using Smart Contracts

Marcos Vinicius Menezes Rodrigues de Souza

Coordenação de Aperfeiçoamento de Pessoal de Nível Superior (CAPES)

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Mobile Agent-Based Network Management
Original source
Mar 20, 2019·Computers & Security
220 cites
A blockchain based approach for the definition of auditable Access Control systems

Damiano Di Francesco Maesa, Paolo Mori, Laura Ricci

This work proposes to exploit blockchain technology to define Access Control systems that guarantee the auditability of access control policies evaluation. The key idea of our proposal is to codify attribute-based Access Control policies as smart contracts and deploy them on a blockchain, hence transforming the policy evaluation process into a completely distributed smart contract execution. Not only the policies, but also the attributes required for their evaluation are managed by smart contracts deployed on the blockchain. The auditability property derives from the immutability and transparency properties of blockchain technology. This paper not only presents the proposed Access Control system in general, but also its application to the innovative reference scenario where the resources to be protected are themselves smart contracts. To prove the feasibility of our approach, we present a reference implementation exploiting XACML policies and Solidity written smart contracts deployed on the Ethereum blockchain. Finally, we evaluate the system performances through a set of experimental results, and we discuss the advantages and drawbacks of our proposal.

Open access
Access Control and Trust
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Mar 15, 2019·arXiv (Cornell University)
76 cites
Multi-Authority Attribute-Based Access Control with Smart Contract

Hao Guo, Ehsan Meamari, Chien-Chung Shen

Attribute-based access control makes access control decisions based on the assigned attributes of subjects and the access policies to protect objects by mediating operations from the subjects. Authority, which validates attributes of subjects, is one key component to facilitate attribute-based access control. In an increasingly decentralized society, multiple attributes possessed by subjects may need to be validated by multiple different authorities. This paper proposes a multi-authority attribute-based access control scheme by using Ethereum's smart contracts. In the proposed scheme, Ethereum smart contracts are created to define the interactions between data owner, data user, and multiple attribute authorities. A data user presents its attributes to different attribute authorities, and after successful validation of attributes, obtains attribute tokens from respective attribute authorities. After collecting enough attribute tokens, a smart contract will be executed to issue secret key to the data user to access the requested object. The smart contracts for multi-authority attribute-based access control have been prototyped in Solidity, and their performance has been evaluated on the Rinkeby Ethereum Testnet.

Open access
3 source records
Cryptography and Data Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
Jan 28, 2019·Mobile Networks and Applications
64 cites
Fuzzy Logic with Expert Judgment to Implement an Adaptive Risk-Based Access Control Model for IoT

Hany F. Atlam, Robert John Walters, Gary Wills, Joshua Daniel

Abstract The Internet of Things (IoT) is becoming the future of the Internet with a large number of connected devices that are predicted to reach about 50 billion by 2020. With proliferation of IoT devices and need to increase information sharing in IoT applications, risk-based access control model has become the best candidate for both academic and commercial organizations to address access control issues. This model carries out a security risk analysis on the access request by using IoT contextual information to provide access decisions dynamically. This model solves challenges related to flexibility and scalability of the IoT system. Therefore, we propose an adaptive risk-based access control model for the IoT. This model uses real-time contextual information associated with the requesting user to calculate the security risk regarding each access request. It uses user attributes while making the access request, action severity, resource sensitivity and user risk history as inputs to analyze and calculate the risk value to determine the access decision. To detect abnormal and malicious actions, smart contracts are used to track and monitor user activities during the access session to detect and prevent potential security violations. In addition, as the risk estimation process is the essential stage to build a risk-based model, this paper provides a discussion of common risk estimation methods and then proposes the fuzzy inference system with expert judgment as to be the optimal approach to handle risk estimation process of the proposed risk-based model in the IoT system.

Open access
Access Control and Trust
IoT and Edge/Fog Computing
Network Security and Intrusion Detection
Original source
Jan 24, 2019·arXiv (Cornell University)
0 cites
Mokka: BFT consensus

Egor Zuev

Mokka is a partial-synchronous, strong consistent BFT consensus algorithm for reaching the consensus about a certain value in open networks. This algorithm has some common approaches nested from RAFT, but its nature and design make Mokka a better solution for DLT (distributed ledger).

Open access
2 source records
cs.DC
Distributed systems and fault tolerance
Cryptography and Data Security
Original source
Jan 1, 2019·Figshare
0 cites
Practically Efficient Group Signature Scheme

Brandon Mendrick

Group signature schemes enable a set of members to anonymously sign data on behalf of the entire group. In order to prevent misuse, a designated group manager<br>has the ability to trace a given signature back to a member. Other extensions can also be realized in speci ffically designed schemes, such as veri fier local revocation (VLR) wherein only the verifi er needs information about the validity status of signing key pairs. This paper contributes two results towards group signature schemes. First, we present a new design for a group signature scheme that is secure under the standard<br>model, with common relaxations for anonymity. The scheme also enables VLR and allows for fully-dynamic groups; i.e. groups that allow members to both leave and join after creation. Secondly, we implement a preliminary version of the scheme to begin investigating the effi ciencies gained through utilizing one-time signing keys, instead of the traditional non-interactive, zero-knowledge proof systems.

Open access
Cryptography and Data Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
Jan 1, 2019·Computers, materials & continua/Computers, materials & continua (Print)
63 cites
A Blockchain-Based Authentication Protocol for WLAN Mesh Security Access

Xin Jiang, Mingzhe Liu, Chen Yang, Yanhua Liu · 5 authors

In order to deploy a secure WLAN mesh network, authentication of both users and APs is needed, and a secure authentication mechanism should be employed. However, some additional configurations of trusted third party agencies are still needed on-site to deploy a secure authentication system. This paper proposes a new block chain-based authentication protocol for WLAN mesh security access, to reduce the deployment costs and resolve the issues of requiring key delivery and central server during IEEE 802.11X authentication. This method takes the user’s authentication request as a transaction, considers all the authentication records in the mesh network as the public ledger and realizes the effective monitoring of the malicious attack. Finally, this paper analyzes the security of the protocol in detail, and proves that the new method can solve the dependence of the authentication node on PKI and CA.

Open access
IPv6, Mobility, Handover, Networks, Security
Access Control and Trust
Advanced Authentication Protocols Security
Original source
Jan 1, 2019·Acta Informatica Medica
10 cites
The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project

Stefanos Malliaros, Christos Xenakis, George Moldovan, John Mantas · 6 authors

INTRODUCTION: Individuals and healthcare providers need to trust that the EHRs are protected and that the confidentiality of their personal information is not at stake. AIM: Within CrowdHEALTH project, a security and privacy framework that ensures confidentiality, integrity, and availability of the data was developed. METHODS: The CrowdHEALTH Security and Privacy framework includes Privacy Enhancing Technologies (PETs) in order to comply with the GDPR EU laws of data protection. CrowdHEALTH deploys OpenID Connect, an authentication protocol to provide flexibility, scalability, and lightweight user authentication as well as the attribute-base access control (ABAC) mechanism which supports creating efficient access control policies. RESULTS: CrowdHEALTH integrates ABAC with OpenID Connect to build an effective and scalable base for end-users' authorization. CrowdHEALTH's security and privacy framework interacts with other CrowdHEALTH's components, for instance the Big Data Platform, that depends on user authentication and authorization. CrowdHEALTH users are able to access the CrowdHEALTH's database based on the result of an ABAC request. Moreover, due to the fact that the CrowdHEALTH system requires proofs during the interactions with data producers of low trust or low reputation level, the requirements for the Trust and Reputation Model have been identified. CONCLUSION: The CrowdHEALTH Integrated Holistic Security and Privacy framework meets the security criteria for an e-health cross-border system, due to the adoption of security mechanisms, such as user authentication, user authorization, access control, data anonymization, trust management and reputation modelling. The implemented framework remains to be tested to ensure its robustness and to evaluate its performance. The holistic security and privacy framework might be adapted during the project's life circle according to new legislations.

Open access
Access Control and Trust
Privacy, Security, and Data Protection
Information and Cyber Security
Original source
Jan 1, 2019·Proceedings of the 16th International Joint Conference on e-Business and Telecommunications - Volume 2: SECRYPT, 325-332, 2019, Prague, Czech Republic
18 cites
ZKlaims: Privacy-preserving Attribute-based Credentials using Non-interactive Zero-knowledge Techniques

Martin Schanzenbach, Thomas Kilian, Julian SchĂŒtte, Christian Banse

In this paper we present ZKlaims: a system that allows users to present attribute-based credentials in a privacy-preserving way. We achieve a zero-knowledge property on the basis of Succinct Non-interactive Arguments of Knowledge (SNARKs). ZKlaims allow users to prove statements on credentials issued by trusted third parties. The credential contents are never revealed to the verifier as part of the proving process. Further, ZKlaims can be presented non-interactively, mitigating the need for interactive proofs between the user and the verifier. This allows ZKlaims to be exchanged via fully decentralized services and storages such as traditional peer-to-peer networks based on distributed hash tables (DHTs) or even blockchains. To show this, we include a performance evaluation of ZKlaims and show how it can be integrated in decentralized identity provider services.

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Jan 1, 2019·UPCommons institutional repository (Universitat PolitÚcnica de Catalunya)
35 cites
Distributed Access Control with Blockchain

Jordi Paillissé, Jordi Subira, Albert López, Alberto Rodríguez-Natal · 7 authors

The specification and enforcement of network-wide policies in a single administrative domain is common in today's networks and considered as already resolved. However, this is not the case for multi-administrative domains, e.g. among different enterprises. In such situation, new problems arise that challenge classical solutions such as PKIs, which suffer from scalability and granularity concerns. In this paper, we present an extension to Group-Based Policy -- a widely used network policy language -- for the aforementioned scenario. To do so, we take advantage of a permissioned blockchain implementation (Hyperledger Fabric) to distribute access control policies in a secure and auditable manner, preserving at the same time the independence of each organization. Network administrators specify polices that are rendered into blockchain transactions. A LISP control plane (RFC 6830) allows routers performing the access control to query the blockchain for authorizations. We have implemented an end-to-end experimental prototype and evaluated it in terms of scalability and network latency.

Open access
3 source records
cs.NI
cs.CR
Software-Defined Networks and 5G
Original source