Secure access control to a wide variety of Internet of Things (IoT)devices has become critical. Blockchain-based access control frameworks are promising technologies to support secure access to IoT devices in pervasive computing applications. However, in most of the proposed solutions, the IoT devices rely on a trusted server to retrieve critical access control data from the blockchains. We propose a method for IoT devices to validate blockchain data without solely being dependent on a central server. In our approach, several witnesses on the network can be selected randomly by the devices to validate access control information. Our method is aided by Bloom filters, which are shown to be lightweight for resource-constrained devices.
Alina Buzachis, Antonio Celesti, Maria Fazio, Massimo Villari
The digitization of health records has massively increased Health Information Exchange (HIE) activities among different practitioners, but it has lagged behind Electronic Health/Medical Records (EHRs/EMRs) adoption for numerous reasons, including confidentiality, interoperability, integrity, and privacy-related concerns. In this paper, we present a Blockchainas-a-Service based solution for HIE (BaaS-HIE). In particular, our design work involves the use of a private Blockchain and smart contracts as access control manager to medical records. In order to maintain high level of performance for applications, thus that such applications could be economically viable, all of the health data are encrypted and stored into a decentralised InterPlanetary File System (IPFS) and the hash of the assets URI is stored in blockchain. Our experimental results demonstrate the feasibility of the proposed approach in offering a decentralized and fine-grained accessibility mechanism for the patient and the doctor in a given healthcare system.
Recent years has witnessed a boom in fog-assisted crowdsensing, which exploits powerful sensing capabilities of various mobile devices or vehicles distributed in large-scale areas to efficiently gather information and make better decisions. However, the fog-assisted crowdsensing system is totally open, which provides the opportunity for malicious individuals or organizations to launch different attacks. In order to cope with the security threats from participants, a blockchain-based crowdsensing framework is proposed, which helps check the authentication of submitted sensor data and resists record tempering. Moreover, a bitcoin-based reward delivery scheme is designed to prevent requesters from denying payments. The sensing capability differences between users are considered in our design. Through security analysis and simulations evaluation, the performance superiority of the proposed framework and reward delivery scheme is demonstrated, in terms of malicious behaviour detection, user utility and sensor data quality.
Imen Riabi, Yosr Dhif, Hella Kaffel Ben Ayed, Khaled Zaatouri
Traditional access control models rely on a central entity. This may cause single point of failure, ethical and privacy problems when applied in the Internet of Things (IoT). A distributed access control can overcome the single point failure problem of centralized access models. In this paper, we propose a distributed and trustworthy access control solution for the IoT by applying the smart contract-enabled blockchain.
Md. Abdur Rahman, Mamunur Rashid, Stuart J. Barnes, M. Shamim Hossain · 6 authors
Once a subject is diagnosed with cancer, a patient goes through a series of diagnosis and tests, referred to as after cancer treatment. Due to the nature of the treatment and side effects on regular lifestyles, maintaining quality of life in the home environment is a challenging task. Sometimes within a home environment, a cancer patient's situation changes abruptly, as the functionality of certain organs deteriorate, which affects their quality of life. In this paper, we propose a Blockchain and off-chain based framework which will allow multiple medical and ambient intelligent IoT sensors to capture quality of life information from one's home environment and securely share it with one's community of interest. Using our proposed framework, both transactional records and multimedia big data - consisting of a user's physiological as well as mental states - can be shared with an oncologist or palliative care unit for real-time decision support. We have also developed Blockchain-based data analytics, which will allow a clinician to visualize the immutable history of the patient's data available from an in-home secure monitoring system for a better understanding of a patient's current or historical states. We further designed a generic oncologist smart contract and digital wallet for different stakeholders to automate the treatment plan of a particular patient. Finally, we will present our current implementation status, which provides significant encouragement for further development.
We present a state-of-art design in healthcare industry with blockchain technology. In our design of the systems, an individual's identity can be verified, and the electronic health records are processed through blockchain networks. The goal of creating such kind of systems is to facilitate identity verification, to provide ease of data access and sharing of electronic health records, and to maximize the protection of patients' data.
The aim of this paper is to provide a systematic literature review of blockchain hardware acceleration. Blockchain technology has achieved significant attention in recent years particularly in the area of cryptocurrency however it is gaining popularity in other applications such as supply chain management and e-government. Based on a structured, systematic review of the relevant literature, we present a classification of the primary areas in blockchain technology that make use of heterogeneous hardware for accelerating certain blockchain functions. Based on these findings, we identify various research gaps and future exploratory directions that are anticipated to be of significant value both for academics and industry practitioners.
Shuang Sun, Shudong Chen, Rong Du, Weiwei Li · 5 authors
In this paper, we focuses on an access control issue in the Internet of Things (IoT). Generally, we firstly propose a decentralized IoT system based on blockchain. Then we establish a secure fine-grained access control strategies for users, devices, data, and implement the strategies with smart contract. To trigger the smart contract, we design different transactions. Finally, we use the multi-index table struct for the access right's establishment, and store the access right into Key-Value database to improve the scalability of the decentralized IoT system. In addition, to improve the security of the system we also store the access records on the blockchain and database.
Data driven networks applicable for shipping industrial applications to create decentralized system intelligence are considered in this study. Such system intelligence can facilitate to improve the respective operational efficiency in local (i.e. vessel operations) and global (i.e. logistics operations) scales in shipping as the main advantage. The main features of these data driven networks are summarized in the first part of this study. Two applications of digital models and blockchain technologies are discussed and compared with their features to illustrate their similarities and differences in the second part of this study. A digital model represents a vector based mathematical structure derived from ship performance and navigation data sets and has categorized as a low-level information model. It is also believed that the respective data sets from industrial IoT (internet of things) should go through such low-level models to improve their quality. These data driven networks can be used to quantify ship performance and navigation conditions, where the outcome can also be used to improve vessel energy efficiency and reduce engine emissions in a local scale. A blockchain represents a decentralized, distributed and digital ledger system in a public domain and can handle and record transactions executed by many users. That has categorized as a high-level information model due the high quality data sets from industrial processes that these networks are handling. Such data driven networks can be used to formulate various logistics operations in shipping and optimize their operational conditions in a global scale. The outcomes of these data driven networks can be used to improve operational efficiency and reduce the respective costs in the shipping industry.
Internet of Thing devices (IoT devices) are often constrained in terms of computing, memory, storage, power, and network resources. This makes them ill-suited to operate as first-class citizens on a blockchain, such as Ethereum, preventing the IoT devices from attaining the security guarantees that are available to better resourced nodes that are able to operate as full, validating nodes on the blockchain. IoT devices may use so-called light protocols to interact with the blockchain with minimal resource requirements, but these protocols provide only probabilistic security guarantees. In this position paper, we propose a new mechanism where an operator of IoT devices is able to send a “ground truth state” to the devices via a new mechanism, which we call “decentralized beacons”, enabling them to gain full security guarantees of the blockchain state.
Jamal N. Al‐Karaki, Amjad Gawanmeh, Meryeme Ayache, Ashraf Mashaleh
The healthcare industry is a complex system of interconnected entities. Each of these entities has disjoint information systems to manage patient data and records. The current IT solutions in healthcare systems have several challenges such as sharing and accessing medical records across several stakeholders while still maintaining security and privacy of these records. This global problem on how to create, maintain, and share sensitive medical records and clinical data among various stakeholders without sacrificing data privacy and integrity is still unresolved. In fact, existing healthcare records are decentralized, disjointed, non-uniform, and fragmented in nature. In this paper, we present a Blockchain-based framework, called DASS-CARE, that supports decentralized, accessible, scalable, and secure access to healthcare services including medical records. Such framework will greatly facilitate the process of real time access and updates without compromising security, integrity and confidentiality of patient data. Our objective is multifold. First, improve the quality of healthcare and lower the cost of delivery. Second, enhance medical records management including electronic health records unification. Finally, provide users with the ability to view their medical records regardless of their history, a task that is difficult to accomplish under the current fragmented systems.
Let’s put aside the question whether Blockchain is a real technology or a passing fad – a hype. The ups and downs of your fortunes in Bitcoin and similar cryptocurrencies in the last couple of years may have clouded your views. Short-term or long-term success, or failure, of cryptocurrencies may depend on the success, or failure, of Blockchain, but it is important to recognize that Blockchain and the Distributed Ledger Technology (DLT) have far greater uses in wide-ranging applications. One such use of Blockchain is as a key enabling technology of 5G applications. Prof. Chaudhry and Dr. Asad present their research to propose a Blockchain-based Network Slice and Resource Brokerage system to build an open, transparent, and fair 5G ecosystem. They explain the challenges of addressing the massive cooperation required among 5G devices and potential solutions using Blockchain.
Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
With ever more IoT (Internet of Things) and bigdata applications, the emerging blockchain techniques provide fundamental supports to credibly track the transactions of digital assets. Public blockchains, e.g., bitcoin, are often energy-consuming and low efficient. Therefore, an empirical study of operating permissioned blockchains in clouds is urgently needed. In this paper, we study the performance of Sawtooth, a well-known permissioned blockchain platforms from Hyperledger, in cloud environments. Our results provide insights for blockchain operators to optimize the performance of Sawtooth through adjusting the two configuration parameters, i.e., Scheduler and Maximum Batches Per Block. Our approach can be used to test other blockchain platforms.
Internet-of-Things has emerged to develop smart communities so that real time sensing and decision can improve operational efficiency and quality of lives. However, establishing such infrastructure can be exceptionally intricate due to the vast variety of devices and the implemented technologies. Also, it poses several unique challenges, such as heterogeneity of the infrastructure, type, and scale of deployment, security, privacy, and inter-operability. One primary concern in a smart city environment is the capabilities of typically end-IoT devices which are vulnerable to security threats and prone to confidentiality and integrity breach of data. Blockchain can potentially address these security challenges due to the distributed ledger's inherent properties. In this paper, we propose a decentralized architecture using the Blockchain to provide a secure and resilient smart city infrastructure that can run the ledger service over a distributed network. We consider a permissioned Blockchain, Hyperledger Sawtooth, and to automate and to overcome the infrastructural challenges concerning the smart city deployment, and we provide a systematic methodology that automates the deployment process and saves a significant amount of time. We simulate and deploy a Blockchain-integrated smart city environment using the proposed seamless deployment strategy using our automation module. With the proposed deployment scheme, we improve the Blockchain-based infrastructure development time by 82% compared to the traditional deployment approach.
We consider IoT resources with a Trusted Execution Environment (TEE) and propose a model to provide trusted resource access that is linked to blockchain payments, ensuring the integrity and confidentiality of the IoT data. The model is built on the widely used OAuth 2.0 open authorization framework, which provides delegated authorization for IoT resources. We utilize hash-lock and time-lock mechanisms to cryptographically link trusted resource access, provided by the IoT resource's TEE, to authorization grants and blockchain payments. The model is implemented in the OP-TEE open source port for the Raspberry Pi that uses ARM's TrustZone and is evaluated on the Rinkeby public Ethereum testnet.
Considering rapidly evolving Internet-of-Things services such as smart buildings, smart homes or secure e-health applications, the fog computing concept provides a technical basis for innovative application scenarios of the blockchain technology. We develop an enhancement of the fog computing architecture HCL-BaFog by the blockchain functionality to collect and securely share sensor data. They may arise from private IoT applications such as ambient assisted living which incorporate the need of an immutable, local storage and a sharing of protected real-time sensor data monitored at patients’ or people’s homes. Our proof-of-concept employs the fully virtualized functionality of a permissioned blockchain and a network of fog computing nodes and utilizes the container orchestration and management system Docker and the MultiChain framework. We investigate some basic performance metrics of our storage-and-sharing approach using a test bed of Raspberry Pi SBCs. Finally, some conclusions on the developed fog computing architecture with its integrated blockchain functionality are discussed and its current limitations are revealed.
Imen Riabi, Hella Kaffel Ben Ayed, Leila Azzouz Saidane
Access control models for the Internet of Things (IoT) proposed in the literature are based on centralized architecture and raise security issues due to the spontaneous and dynamic interaction between IoT devices. In addition to the scalability and lightweight features, the need of secure and distributed access control architecture to overcome the single point failure problem of a centralized entity becomes a big challenge. This can be done through the Blockchain technology which is used recently to provide access control services. Exploiting this technology to manage access IoT devices in term of distribution, heterogeneity, scalability, fault tolerance capability, security and privacy are promising. In this paper, a comprehensive review of the existing access control models based on Blockchain is presented and discussed with comparison and analysis.
Service Oriented Architecture is a viable option for developing applications in an Internet of Things (IoT) environment. One important consideration in developing services for an IoT environment is how to incentivize service providers and consumers so that a healthy IoT marketplace can come into practice with a balanced supply and demand for services. We argue that service providers should be specifically incentivized in some form to offer quality services in an IoT environment. In this paper, we present an IoT ecosystem, where each exchange of a service between a service provider and service consumer is logged as a transaction in a distributed ledger. For service sharing, we used OSGi Remote Services implementation of the Eclipse Communication Framework. For the distributed ledger, we used Swirlds Hashgraph. Each OSGi remote service is requested by digitally signing a commitment to use the service and upon service exchange, the signature is logged as a Hashgraph transaction. A proof-of-concept prototype has been implemented with positive results.
A. Badr, Laura Rafferty, Qusay H. Mahmoud, Khalid Elgazzar · 5 authors
While academic institutions maintain records such as transcripts and certificates, they are often requested to share these records with other institutions at the request of students for credit transfer, or prerequisites for acceptance into new academic programs. While the transfer of academic records is a regular daily activity for the institutions, there is often significant overhead involved as the process of transfer and verification is extremely manual. The need for an automated end-to-end solution for the transfer and verification of academic records between institutions is on the edge to reduce wait times for students to transfer their records, as well as to provide a reliable verification method to avoid academic fraud. This paper presents a permissioned blockchain-based system to allow institutions to securely and dependably transfer and verify academic records at the student request. Permissioned blockchains, such as Hyperledger, provide a more scalable and cost-effective and private solution for enterprise applications. Our solution is comprised of a web interface for enrolling and requesting the transfer, with a backend using Hyperledger Fabric and Hyperledger Composer to retain the hash of the records on the blockchain for verification.
IoT devices are quickly becoming a critical source of information about the physical world considered in business processes. Blockchains are a promising platform for such processes if they involve multiple parties with no shared, commonly trusted IT infrastructure. Transacting with a blockchain, however, requires software whose footprint overwhelms many lightweight IoT devices. In this paper we introduce the concept of a blockchain proxy to which an IoT device can offload a large part of this software footprint. The proxy only requires a slim proxy SDK on the device that holds a regular blockchain identity with its own private key, retaining full control of the transactions in the device. We discuss security implications and present cold-chain monitoring as a use case. Preliminary results show significant savings in CPU time and communication bandwidth for the IoT device.
Blockchains and smart contracts are an emerging, promising technology, that has received considerable attention. We use the blockchain technology, and in particular Ethereum, to implement a large-scale event-based Internet of Things (IoT) control system. We argue that the distributed nature of the "ledger," as well as, Ethereum's capability of parallel execution of replicated "smart contracts", provide the sought after automation, generality, flexibility, resilience, and high availability. We design a realistic blockchain-based IoT architecture, using existing technologies while by taking into consideration the characteristics and limitations of IoT devices and applications. Furthermore, we leverage blockchain's immutability and Ethereum's support for custom tokens to build a robust and efficient token-based access control mechanism. Our evaluation shows that our solution is viable and offers significant security and usability advantages.
The following topics are dealt with: data privacy; security of data; cryptography; Internet of Things; Internet; computer network security; contracts; authorisation; cryptocurrencies; cloud computing.
Ronald Doku, Danda B. Rawat, Moses Garuba, Laurent Njilla
The Internet of Things (IoT) and the blockchain are justly regarded as the technology for the future. The blockchain is a Distributed Ledger Technology (DLT) solution which has enormous potential as can be seen in the numerous avenues it has been deployed. Simplistically, it is a decentralized database which can revolutionize the current centralized world we live. IoT is the interconnection of devices with mostly bounded resources. IoT applications are also distributed in nature thereby making it inevitable that the paths of the blockchain and IoT will cross in the future. Blockchain's DLT will eventually play a crucial role in how IoT devices will communicate. The Proof of Work (PoW) mechanism was the original consensus technique introduced in the first blockchain based application (Bitcoin). PoW guaranteed consensus in the network by verifying transactions. However, the PoW had deficiencies. The solving of the PoW puzzle is computationally expensive which has become an impediment in the potential marriage of IoT and blockchain. This predicament arises as IoT devices are plagued with limited resources. In this work, we address this issue by presenting an approach where IoT devices can combine their resources to solve PoW puzzles that they might not have been able to solve on their own. This would ensure a successful merger between the blockchain and the IoT.
Shovon Paul, Jubair Islam Joy, Shaila Sarker, Ahmad Javid Shakib · 6 authors
Blockchain technology has opened the gate of creating decentralized applications, where security is a big concern. Here, any transaction ever held is recorded permanently. Over the years, some non-reputable sources have been publishing fake and attractive news stories. Due to the lack of any regulatory systems, this news cannot be verified. Hence, these unreliable sources can publish whatever they want, and even in some cases, it makes chaos in society. In recent times due to the ease in internet availability and social media, inappropriate news can spread more quickly than ever before. In some cases, fake news is more attractive than the real one. Thus, people become misguided. Using the advantages of Blockchain's peer-to-peer network concepts, we will discuss a way to detect fake news in social media.