Recently, distributed databases have achieved tremendous realistic performances and developed one of the most essentially utilized tools in society communication applications. However, the existing distributed databases often contain users’ sensitive information and are vulnerable to web attackers, which may cause severe privacy issues and economic loss. In this paper, we first attempt to propose a novel protocol to dispose of the potential verification risks in distributed databases. Compared with currently distributed databases, the requester can steal important data without any payment. Therefore, our model faces two primary challenges including guaranteeing the efficiency and security of the distributed databases, the data verification procedure may lead to data leakage. To address the above problems, we utilize zero-knowledge proof to dispose of the data verification issue for the requester. Moreover, a secure and effective proof protocol is established to achieve database responses the privacy data access. From our extensive experimental results, we can conclude that our developed framework can achieve an effective performance with reasonable communication costs.
Blockchain, on the other hand, is a groundbreaking technology that provides a distributed and Decentralized environment in which nodes in a list of networks can connect to each other without the need for a central authority. It has the potential to overcome the limits of Electronic Health Record (EHR) management and create a more secure, Decentralized, and safer environment for exchanging EHR data. Further, blockchain is a distributed ledger on which data can be stored and shared in a cryptographically secure, validated, and mutually agreed-upon manner across all mining nodes. The blockchain stores data with a high level of integrity and robustness, and it cannot be altered. Electronic health records (EHRs) are digitally saved health records that provide information about a person’s health. EHRs are generally shared among healthcare stakeholders, and thus are susceptible to power failures, data misuse, a lack of privacy, security, and an audit trail, among other problems. The aim of our proposed framework is firstly to implement blockchain technology for EHR and secondly to provide secure storage of electronic records by defining granular access rules for the users of the proposed framework. Moreover, this framework also discusses the scalability problem faced by the blockchain technology in general via use of off-chain storage of the records. This framework provides the EHR system with the benefits of having a scalable, secure and integral blockchain-based solution.
Recent booming development of Generative Artificial Intelligence (GenAI) has facilitated model commercialization to reinforce the model performance, including licensing or trading Deep Neural Network (DNN) models. However, DNN model trading may violate the benefit of the model owner due to unauthorized replications or misuse of the model. Model identity auditing is a challenging issue in protecting DNN model ownership, and verifying the integrity and ownership of models is one of the critical obstacles. In this paper, we focus on the above issue and propose an \underline{A}ccumulator-enabled \underline{A}uditing for \underline{D}ecentralized \underline{Id}entity of DNN \underline{M}odel (A2-DIDM) that utilizes blockchain and zero-knowledge techniques to protect data and function privacy while ensuring the lightweight on-chain ownership verification. The proposed model presents a scheme of identity records via configuring model weight checkpoints with zero-knowledge proofs, which incorporates predicates to capture incremental state changes in model weight checkpoints. Our scheme ensures both computational integrity and programmability in DNN training process so that the uniqueness of the weight checkpoint sequence in a DNN model is preserved. %to ensure the correctness of model identity auditing, so that the uniqueness of the weight checkpoint sequence in a DNN model is preserved. A2-DIDM also addresses privacy protections in decentralized identity. We systematically analyze the security and robustness of our proposed model and further evaluate the effectiveness and usability of auditing DNN model identities. The code is available at https://github.com/xtx123456/A2-DIDM.git.
The rapid advancement of technology has brought about profound changes in various spheres of our society. Among these improvements, the Internet of Things (IoT) stands out as a transformative force, revolutionizing visibility across diverse domains. By furnishing real-time data and insights, IoT empowers businesses to refine their operations and significantly enhance overall efficiency. However, the decentralized nature of IoT architecture presents a substantial challenge in terms of security. As technology proliferates, security emerges as a paramount concern, particularly in safeguarding IoT devices and the data they generate against unauthorized access, data breaches, and potential harm. Simultaneously, the imperative for real-time data streaming underscores the need for a rapid dissemination protocol as a fundamental requirement. Our proposed solution adeptly addresses both of these critical aspects by integrating BDLS, a promising Byzantine Fault Tolerance (BFT) protocol, with Hyperledger Fabric for IoT devices. This integration not only enhances security but also ensures the rapid and secure dissemination of data. Through rigorous evaluation, our study demonstrates the outstanding performance of BDLS Fabric integration in terms of throughput (TPS), surpassing CFT-type protocols and numerous other proposed solutions utilizing PBFT, thereby reinforcing the importance of security in IoT deployments. Moreover, by securing the edge servers and the cloud replica using Hyperledger Fabric-BDLS integration, our solution fortifies the IoT ecosystem against potential threats, establishing a robust foundation for future innovations in distributed ledger technology.
Decentralized file storage has emerged as a transformative solution to address the challenges of centralized data storage, offering enhanced security, privacy, and resilience in the digital age. This research paper explores the significance of decentralized file storage systems and examines the technologies involved, including blockchain, Polygon, Web3, IPFS, and MetaMask. Through a comprehensive analysis of the architecture, implementation details, security considerations, performance evaluations, and real-world applications, key findings highlight the advantages of decentralized storage solutions over traditional centralized counterparts. The research underscores the importance of decentralization in fostering data sovereignty, transparency, and inclusivity, while offering insights into the potential impact on various industries and scenarios.
Patient care has certainly enriched by implementing digitalization in healthcare. This digital transformation has posed obstacles with data security and privacy. By the introduction of e-health, huge volumes of sensitive and classified data is digitally processed and the likelihood of numerous personal health records (PHR) rules infractions or breaches has drastically increased by implementation of digitalization. Even with the advancement in technologies, it will take due time before a system development can effectively address the security issues and give patients, who are the natural guardians of their health data a total control over their personal data. Hence, there is an urgent need for a patient-centric system that maintains data privacy and gives patients a total control over their PHR. To redefine E-Health security, the cutting-edge technologies comprising of Distributed Hash Table (DHT), Blockchain, Self-Sovereign Identity (SSI), and Inter Planetary File solution (IPFS) needs integration. IPFS and DHT enables in improving Data privacy by providing a reliable and effective decentralized and distributed storage solution. Enabling safe access control over this information, a Decentralized Ledger Technology (DLT) leverages the transparent and unchangeable characteristics of Blockchain. The idea of SSI, which gives patients control over their digital identities and to manage their E-Health data, is fundamental to this paradigm. This study advocates for the widespread implementation of patient-powered electronic health record management system. Additionally providing encouraging paths to improve data security and privacy in the domain of digital healthcare.
In blockchains such as Bitcoin and Ethereum, transactions represent the primary mechanism that the external world can use to trigger a change of blockchain state. Transactions serve as key sources of evidence and play a vital role in forensic analysis. Timed transaction refers to a specific class of service that enables a user to schedule a transaction to change the blockchain state during a chosen future time-frame. This paper proposes T-Watch, a decentralized and cost-efficient approach for users to schedule timed execution of any type of transaction in Ethereum with privacy guarantees. T-Watch employs a novel combination of threshold secret sharing and decentralized smart contracts. To protect the private elements of a scheduled transaction from getting disclosed before the future time-frame, T-Watch maintains shares of the decryption key of the scheduled transaction using a group of executors recruited in a blockchain network before the specified future time-frame and restores the scheduled transaction at a proxy smart contract to trigger the change of blockchain state at the required time-frame. To reduce the cost of smart contract execution in T-Watch, we carefully design the proposed protocol to run in an optimistic mode by default and then switch to a pessimistic mode once misbehaviors occur. Furthermore, the protocol supports users to form service request pooling to further reduce the gas cost. We rigorously analyze the security of T-Watch and implement the protocol over the Ethereum official test network. The results demonstrate that T-Watch is more scalable compared to the state of the art and could reduce the cost by over 90% through pooling.
Akhmad Maariz, Muhammad Aqil Wiputra, Muhammad Randika Dafa Armanto
This study explores the transformative impact of blockchain technology on data integrity and security in digital environments. Through a comprehensive assessment of data integrity metrics across prominent blockchain networks, including Bitcoin, Ethereum, and Hyperledger Fabric, we unveil nuanced differences in immutability and reliability. Our security analysis delves into the cryptographic strength and resistance to unauthorized access, showcasing the outstanding security features of Hyperledger Fabric and Bitcoin, with Ethereum exhibiting commendable yet moderate security levels. The discussions underscore the multifaceted nature of blockchain technology, emphasizing the importance of selecting a platform aligned with specific use cases. Hyperledger Fabric and Bitcoin emerge as strong contenders for applications requiring high integrity and robust security, while Ethereum offers a reliable but moderate alternative. As blockchain technology continues to evolve, this study provides valuable insights for practitioners and researchers, guiding the strategic selection of blockchain platforms to harness their transformative potential in diverse digital environments.
Cloud storage plays an important role in the era of big data and Web 3.0. More and more data owners (DOs) store their data on Cloud for convenience and affordability. However, security and integrity completely depend on cloud storage service providers (CSPs) after data outsourcing. Once CSPs commit dishonest actions that lead to data tampering or loss, it will cause huge losses to DOs. Therefore, DOs need to audit the integrity of their data regularly. Traditional auditing schemes rely on trusted third parties (TPAs), which are not always trustworthy. This paper utilizes Blockchain instead of a trusted third-party auditor for data integrity auditing to address the trust crisis between data owners and cloud storage providers. Existing Rank-based Merkle Hash Tree (RMHT)-based auditing approaches suffer from high communication cost, limiting its applications to Blockchain scenarios. To address these issues, we enhance the auditing algorithm through extending the Rank-based Merkle Hash Tree (RMHT) for dynamic update of stored data and using a non-leaf node sampling strategy. These modifications significantly reduce the communication overhead during auditing and update phases. Such optimizations enable the algorithm to be well-suited for the Blockchain environment because proofs are stored on the Blockchain with gas fees. We implement a prototype and perform a security analysis of the proposed system. Experimental results demonstrate the security and effectiveness of the proposed approach.
Whilst the blessing of the cloud, which provides for adaptability and easy data sharing as well as storage, comes with some security doubts. We place a major responsibility on our backs of protecting the data provided by our users from any evil attempts to sneak in and also risks of being accidentally exposed and the ones that exist through shared infrastructure. This paper traverses this complex terrain by noting the need for targeted security solutions which are aimed towards dealing with the compounded nature of the fast-growing problem. By exploring such threats as data breaches, the possible encryption breaks and the nature of server sharing we will analyze the safety of cloud-based services. We position that the existing security methods, though very necessary, are not exclusive in responding to the ones posed by the new threats. This means we will therefore be rather flexible in our design of the data security in the cloud. By the way, we will employ innovative strategies, maybe, by replacing a word for words such as homomorphic encryption, zero-knowledge proofs, and federated learning, presenting how it holds promise for private and confidential assets. Furthermore, we investigate the exploding influence of blockchain technology, regarding the wages it might deserve in providing manipulated data authentication and creating trust. The work in this paper creates a path towards a future when database users' virtual information in the cloud is safe and certified. Through proposing a wide-ranged approach, which equates realized ideas with well-established security frameworks, we shall lead a cloud infrastructure where stability and power would prevail. Keywords – Cloud Computing, Security Issues, Security Challenges
B.P. Sreeja, G Rajeshkumar, Alagu Kiruthika B, Sasi Prabha N · 6 authors
Distributed storage, which is one of the main functions of distributed computing, enables clients of cloud services to think of their data as being stored in the cloud and to share it with qualified customers. In distributed storage, stable deduplication has been widely researched because it can eliminate overt repetitiveness within scrambled data to reduce storage space significantly. In the field of safety and protection, many current continuous deduplication schemes highlight to a large extent the associated characteristics: information classification, label consistency, access control animal attack assaults. One technique for ensuring the accuracy of information in garage outsourcing is confirmed information possession. The article discusses the development of a green PDP scheme for a distributed cloud garage to facilitate provider migration scalability and statistics, where we keep in mind the lifecycle of multiple cloud service providers to maintain and maintain collaborative customer statistics. The cooperative scheme relies entirely on verifiable homomorphic reactions. Completeness, knowledge soundness, and zero-knowledge qualities may all be satisfied by our multi-proof zero-knowledge proof system, which strengthens the security of our system. The experiment shows that this solution has lower computational and communication overhead than non-cooperative approaches.
Priyanka. A. Kadam, Swaroop V. Suryakar, Nishant R. Wagh, Vaibhav B. Kale · 5 authors
The rapid digitization of information sharing and document exchange in various sectors, including healthcare, finance, and governmental services, has underscored the critical need for robust security mechanisms. Traditional methods often fall short in ensuring the confidentiality, integrity, and availability of shared documents, leading to vulnerabilities in data privacy and security. This research paper introduces a groundbreaking approach to secure document exchange by leveraging the inherent properties of blockchain technology. Through a comprehensive analysis, we explore how blockchain's decentralized nature, cryptographic security, and immutability can be harnessed to create a secure and efficient platform for information sharing. We begin by delineating the current challenges in document exchange systems, such as susceptibility to cyber-attacks, fraud, and unauthorized access. Subsequently, we propose a blockchain-based framework that addresses these issues by enabling transparent and tamper-proof transactions, ensuring data integrity, and facilitating secure access control. Our methodology includes the development of a prototype system that employs smart contracts for automating and securing document exchange processes. Through rigorous testing and evaluation, we demonstrate the system's ability to withstand various security threats, including data breaches and interception attacks.
Rosa Pericàs-Gornals, Macià Mut–Puigserver, M. Magdalena Payeras–Capellà, Miquel À. Cabot-Nadal · 5 authors
Abstract Digital credentials are being issued by authorized entities to facilitate the digital identification of their users. Blockchain offers some inherent features that are highly advantageous for the management of credentials. Non-fungible tokens, or NFTs, might seem to be a perfect fit for the implementation of digital credentials. However, some crucial requirements for credentials are the non-transferability of the credential and that the authorized entity should receive explicit acceptance from the user who will own the new credential, which are features lacking in the current NFTs. This paper introduces a management system focused on issuing digital access credentials, enhancing traditional features by enabling the association of terms and conditions (T &C) during issuance and providing users with non-repudiation of reception evidence upon acceptance. Leveraging an enhanced version of the soulbound tokens (SBTs), called RejSBTs, introduced in our previous work, the new system guarantees non-repudiation of reception and origin proofs. Furthermore, we provide a detailed implementation of the system, including solidity smart contracts, accompanied by a comprehensive cost and security analysis.
Martin Ďuriška, Hana Neradilová, Gabriel Fedorko, Vieroslav Molnár · 5 authors
A Non-Fungible Token (NFT) is a digital asset that is proof of ownership and originality in the digital world. It is generally a unique data unit that can be created from a digital file. But it is not just any digital file; it must be audio, video, image, or photo. This fact is mainly limiting. However, there are many other digital files for which the connection with NFT and blockchain technology would make sense. Such digital files include, among other things, various simulation models. With the development of the use of simulation models for the needs of managing multiple types of logistics processes daily, the questions of how to prevent the unauthorised copying of any simulation model and protect the copyright of its authors are coming to the fore. NFT and blockchain represent a robust technology whose possibilities of use are gradually expanding, while simulation models could be one area of their application. The paper presents the result of research that will enable the implementation of NFT and blockchain technology in simulation models. The research outcome confirmed the possibility of creating an NFT through the decentralised public blockchain XRP Ledger (XRPL) and the marketplace xrp. cafe, which can be used to verify the ownership and originality of the simulation model.
Vijaykumar, Patil Pratik, Prerna Tulsiani, Sunil B. Mane
Public Cloud Computing has become a fundamental part of modern IT infrastructure as its adoption has transformed the way businesses operate. However, cloud security concerns introduce new risks and challenges related to data protection, sharing, and access control. A synergistic integration of blockchain with the cloud holds immense potential. Blockchain's distributed ledger ensures transparency, immutability, and efficiency as it reduces the reliance on centralized authorities. Motivated by this, our framework proposes a secure data ecosystem in the cloud with the key aspects being Data Rights, Data Sharing, and Data Validation. Also, this approach aims to increase its interoperability and scalability by eliminating the need for data migration. This will ensure that existing public cloud-based systems can easily deploy blockchain enhancing trustworthiness and non-repudiation of cloud data.
Empowered by the blockchain technology, cryptocurrencies have become quite popular in recent years. In account-based cryptocurrency systems, maintaining the state of every account is essential for a node to validate transactions, which generally requires a large storage space. In addition to this efficiency issue, privacy issues in cryptocurrency systems attract people's increasing attention. To address the above issues, this paper proposes a privacy-preserving stateless cryptocurrency system named PPSC. Specifically, PPSC reduces the storage cost of a node by employing the aggregatable sub-vector commitment scheme (aSVC). The node only needs to maintain a commitment of the large state vector. And transactions can be validated in a stateless manner. The aSVC scheme is also utilized to hide the value of a transaction. By utilizing the ring signature scheme, PPSC can hide the sender and the receiver of a transaction from third parties. Simulation results demonstrate that PPSC is space efficient, and the time overhead for privacy preserving is acceptable.
Many Internet of Things (IoT) applications are considering multi-tenancy to support for multiple entities sharing access to the same IoT devices. The challenge of ensuring IoT security and privacy is exacerbated in multi-tenant environments accommodating “guest” users, i.e., opportunistic users that the system has not encountered. Thus, there is a need for novel access control mechanisms capable of addressing the complexities introduced by the opportunistic nature of the users who create complex trust relationships within the IoT ecosystem. In this study, we proposed a solution that leverages Verifiable Credentials (VCs) to implement Attribute-Based Access Control (ABA C) for multi-tenant IoT environments and we integrate it with W3C's Web of Things (WoT) standards, enhancing interoperability. Through the utilization of VCs, the solution provides secure verification and efficient revocation of user attributes, enabling access control decisions based on the enclosed attributes. Additionally, the proposed system ensures privacy, since users can selectively disclose the necessary attributes to gain access to resources through the utilization of Zero Knowledge Proofs (ZKPs). Finally, the solution does not require users to have any “pre-existing” trust relationships with the protected system.