Decentralized Identifiers have recently expanded into Internet of Things devices and are crucial in securing users' digital identities and data. However, Decentralized Identifiers face challenges in scenarios necessitating authority delegation and anonymity, such as when dealing with legal guardianship for minors, device loss or damage, and specific medical contexts involving patient information. This paper aims to strengthen data sovereignty within the Decentralized Identifier system by implementing a secure authority delegation and anonymity scheme. It suggests optimizing verifiable presentations by utilizing a sequential aggregate signature, a Non-Interactive Zero-Knowledge Proof, and a Merkle tree to prevent against linkage and Sybil attacks while facilitating delegation. This strategy mitigates security risks related to delegation and anonymity, efficiently reduces the computational and verification efforts for signatures, and reduces the size of verifiable presentations by about 1.2 to 2 times.
In this paper, we developed a Blockchain-based User Authentication Data-Sharing (BC-UADS) framework. In BC-UADS, several hospital servers form a consortium blockchain network to maintain the transparency, immutability, and authenticity of the patient's Electronic Healthcare (Record EHR) medical data. The BC-UADS framework allows doctors to share or retrieve a patient's EHR metadata from the blockchain network. Since, the metadata is stored on a blockchain platform, it is more secure and trusted for real-time applications to utilize the medical data. The data-sharing protocol of the BC-UADS framework is implemented based on Proof-of-Reputation consensus algorithm in a blockchain network. The BC-UADS framework is analyzed in the AVISPA (Automated Validation of Internet Security Protocols and Applications) tool, demonstrating that it is secure against active and passive attacks. Besides, the BC-UADS framework is provably secure in the random oracle model based on the hardness assumption of Elliptic Curve-based Computational Diffie-Hellman (ECCDH) problem. The mutual authentication property of the BC-UADS framework is analyzed in the BAN (Burrows-Abadi-Needham) logic model. We have computed the communication, execution, and storage costs of the BC-UADS framework in different security levels: 80-bit, 112-bit, 128-bit, 192-bit, and 256-bit using PBC library. The proposed BC-UADS framework is compared with the state-of-the-art schemes.
The project aims to develop a decentralized file-sharing platform that harnesses the power of blockchain technology, Ethereum smart contracts, and InterPlanetary File System (IPFS) to create a secure, censorship-resistant, and user-centric file-sharing ecosystem, eliminating reliance on centralized intermediaries, enhancing data privacy, and reducing the risk of censorship or data loss for a future of decentralized and secure data management.
Min Deng, Y. F. Lyu, Chunmeng Yang, Fang Xu · 8 authors
In order to realize an intelligent IoT system, various resource-constrained IoT devices today play an important role in data transmission and processing. However, the novel data protection requirements appear since constrained resources like computation power or energy of IoT devices cannot support classic data protection methods like encryption algorithms. To tackle the above issues, we propose a lightweight Blockchain-Based Trust Management (BBTM) scheme in Resource-constrained Intelligent IoT Systems. The BBTM initially establishes a genesis block at the onset of network operation. Messages transmitted between nodes are recorded as transactions, forming blocks that are linked to the blockchain. As the network operates, nodes’ behaviors are monitored, and their trust values are updated in real-time. When two nodes encounter each other, a credibility formula based method is used to determine trustworthiness based on historical behaviors. Nodes that pass the trust verification utilize asymmetric encryption for message transmission. The primary aim of this scheme is to develop a lightweight, blockchain based secure communication module for Intelligent IoT Systems. It encrypts information using asymmetric cryptography and manages trust during node interactions to ensure security and privacy by blocking malicious or selfish nodes. Compared with the existing solutions, the simulation results show that this scheme can effectively block the attacks from malicious nodes without overly consuming network resources. At the same time, trust verification and encrypted information transmission are effectively managed in resource-constrained intelligent IoT systems.
The Block chain technology has the ability to revolutionize the healthcare business by providing a platform that is both secure and impartial for the exchange and storage of electronic health records (EHRs). This technology is on the verge of completely transforming the industry. The suggested system makes use of a decentralized network of nodes to store and verify EHR data, ensuring its immutability and protecting sensitive patient information. With the use of cryptographic algorithms, data privacy and confidentiality are maintained, while allowing authorized healthcare providers to access and contribute to a patient's EHR in real-time. The Block chain-based EHR system terminates the requirement for a chief authority and eliminates the risk of data breaches and malicious attacks. In this paper, we are utilizing real-time treatment decisions, which makes a list of specific patients in a state and accordingly care aid is generated by software to improve care. Additionally, the distributed ledger technology (Block chain) makes it possible to distribute and store electronic health records for patients in a more secure manner, which increases the efficiency of the process for exchanging health information within the medical field, safeguarded through a decentralized network of interconnected peers. The confidence is upheld through the issuance of an electronic certificate, which serves as evidence of accurate records.
The rapid development of the Industrial Internet-of-Things (IIoT) has led to an exponential growth in the deployment of industrial applications on user-owned smart devices, which poses significant challenges in identity management (IDM) concerning both privacy and quantity. The advent of blockchain technology can fulfill some of these requirements. However, as the number of identities in the IIoT environment grows exponentially, the storage occupied by nodes in the blockchain system gets larger gradually and can never be curtailed. In addition, to maintain the security of identity information, the characteristics of blockchain on openness and transparency are not appropriate for IDM. To this end, we propose a lightweight, secure, and trustworthy stateless blockchain-enabled IDM architecture for IIoT. Specifically, by incorporating the cryptographic accumulator with blockchain, the set of transactions can be turned into a length-constant proof that does not change when identities are modified, in which the identity information is concealed completely. Furthermore, the stateless blockchain structure is formulated and new consensus, identity modification and verification algorithms are presented. Then, we give a comprehensive threat model and security analysis of the proposed system. Finally, the experimental results demonstrate that total time cost and blockchain size are 130.25 ms and 100.13 MB, which significantly improves portability and efficiency in IIoT scenarios.
The advent of blockchain technology has introduced innovative solutions to various sectors, including education. Traditional academic certification systems face challenges such as fraud and inefficiency. This study explores the implementation of NFT-based certificates and proof of delivery in the education sector using Ethereum blockchain to offer a secure, verifiable, and efficient method for issuing, managing, and verifying educational credentials. In the proposed system includes detailed mechanisms for NFT minting, distribution, and management, ensuring verifiable, immutable, and secure academic records. It delves into various aspects such as Ethereum and ERC721 standards, and the benefits over traditional methods. The paper outlines the transaction expenses involved in executing the functions of our proposed NFT-based approach.
The increase in fraudulent credentials highlights the need for strong cloud security. Current verification systems, characterized by inaccuracy and a lack of transparency, requires more sophisticated approach. The User Authentication and Access Control Module improves access with multi-factor authentication and stringent controls, preventing unauthorized entry and enforcing permissions based on roles. The Blockchain Integration Module establishes an immutable ledger, heightening transparency and detecting unauthorized changes. The User Interface and Dashboard Module streamlines certificate management with a user-centric design. The integrated methodology adeptly addresses issues related to fake degrees and credentials. In diverse cloud scenarios, the system showcased superior performance exhibiting a 4.9% higher precision, 3.5% higher accuracy, 3.9% higher recall, 4.5% higher AUC, and 3.4% higher specificity in attack detection. This innovative approach enhances security and efficiency in certificate verification, fostering trust among institutions, employers, and individuals, heralding a paradigm shift in cloud security with the integration of blockchain technology.
Centralized signature verification methods in the Internet of Things (IoT) limit efficiency and introduce human error. This research proposes a novel multi-level signature verification system built upon smart contracts in a permissioned blockchain environment to enhance security and optimize efficiency within the Internet of Things (IoT). The system leverages user contracts created using IoT-Solidity, seamless integration with MetaMask and Ganache, and implements robust hash codes and multi-level verification processes. Performance evaluation utilizes critical metrics, such as gas limit and throughput, to quantify the system's effectiveness. This innovative approach presents a transformative solution for elevating the security paradigm within IoT by harnessing the combined power of multi-level verification and permissioned blockchain technology.
The high efficiency assets management is an ever topic and research direction. Block chain core thinks and methodologies were brought in assets management cleverly in order to improve the efficiency and quality of comprehensive assets management. The Verifiable Random Functions with Token(VRFwT) algorithm was proposed creatively around the Special Consensus Mechanism(SCM) and other main theories of block chain. It contains about two modules of Advanced Verifiable Random Functions(AVRF) algorithm and Proof of Stake with Token(PoSwT) according to the module design think. Specially, public key was used to validate the value obtained by special formula and parameters of privacy key and a given message in AVRF creatively. The two-steps validating methodology was proposed and constructed in order to validate the performance of VRFwT in multiple dimensions. It proved that VRFwT having better efficiency and robustness after a series tests were executed on three different sets combined with physical assets and digital assets. The designed think and methodology of VRFwT would be validated further and used in hybrid assets management scene. Moreover, it would bring a meaningful significance for innovation method of bigger variety of assets management.
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Advanced Steganography and Watermarking Techniques
This paper introduces the Distributed Key Architecture (DKA) and elucidates its primary contributions. The proposed architecture combines Shamir's Secret Sharing (SSS) and Distributed Key Generation (DKG) to create a secure and user-friendly blockchain wallet. The advantages of DKA lie in its ability to seamlessly integrate user accessibility with robust security measures. In addition to highlighting the technical aspects, this abstract delves into the contextual application of the methodology, emphasizing its necessity, and outlining the practical benefits it brings. By incorporating Shamir's Secret Sharing and Distributed Key Generation, the DKA not only addresses the current challenges but also redefines the landscape of secure and user-friendly blockchain applications. The experimental results presented herein validate the feasibility of implementing this approach in real-world scenarios, solidifying DKA's potential for practical deployment.
Manaswi Sharma, Abhishek Sharma, Deepak Shankar Ray, Saru Dhir
Blockchain technology and decentralized storage solutions have transcended their initial roles in cryptocurrency, playing pivotal roles in various sectors, redefining data management, security, and accessibility. They promote data security, interoperability, and trust across diverse domains, with applications in decentralized finance, supply chain management, and digital identity verification. Decentralized storage, as seen in the InterPlanetary File System (IPFS) and platforms like Storj, addresses content accessibility and resistance to censorship, offering a more secure, user-centric digital landscape. The integration of blockchain in cloud storage systems and patient-centric healthcare data management holds promise, providing tamper-resistant storage with improved data access control, scalability, and potential for broader adoption.
Blockchain technology, with its promise of decentralized and transparent systems, has garnered significant attention across diverse industries. In response to these challenges, this project presents a novel approach by integrating Elliptic Curve Cryptography (ECC) and the Keccak-256 hashing algorithm into Down-Coin, a cryptocurrency platform. ECC is utilized for robust key generation and digital signatures, while Keccak-256 ensures secure transaction hashing. By implementing these cryptographic techniques, Down-Coin addresses critical security concerns prevalent in the blockchain space. The integration of ECC and Keccak-256 enhances the integrity and reliability of transactions on the Down-Coin blockchain. ECC's efficient key generation and digital signature mechanisms bolster the platform's security, protecting user assets from unauthorized access and ensuring the authenticity of transactions. Similarly, the use of Keccak-256 for transaction hashing safeguards against data tampering and manipulation, preserving the immutability of the blockchain ledger. This initiative is poised to instill greater trust among users and stakeholders, fostering a conducive environment for innovation and growth in decentralized finance (DeFi). By countering prevalent security vulnerabilities, Down-Coin aims to position itself as a trusted and resilient platform for digital asset management and financial transactions. Through its implementation of ECC and Keccak-256, Down-Coin seeks to overcome existing market challenges and establish a robust foundation for the future of blockchain-based financial services. In summary, this project represents a significant step towards enhancing the security and integrity of blockchain transactions.
Ethereum 2.0 is a major upgrade to improve its scalability, throughput, and security. In this version, RANDAO is the scheme to randomly select the users who propose, confirm blocks, and get rewards. However, a vulnerability, referred to as the `Last Revealer Attack' (LRA), compromises the randomness of this scheme by introducing bias to the Random Number Generator (RNG) process. This vulnerability is first clarified again in this study. After that, we propose a Shamir's Secret Sharing (SSS)-based RANDAO scheme to mitigate the LRA. Through our analysis, the proposed method can prevent the LRA under favorable network conditions.
Abstract To meet the demand for high‐quality healthcare services, data trading can effectively promote the circulation of medical data and improve the level of healthcare services. To address the existing problems of data regulation difficulties and data privacy leakage in medical data trading, a trusted and regulated data trading scheme based on blockchain and zero‐knowledge proof is proposed. In this scheme, a regulatory institution is introduced to control the issuance of authorized tokens and ensure the controllability of data sharing activities. The blockchain takes over the task of generating public parameters to reduce the computational overhead of the system. Based on homomorphic proxy re‐encryption technology, users can perform data analysis in the cloud to ensure data security. Smart contracts and zero‐knowledge proof technology can automatically verify the validity of data to protect the rights and interests of data users; at the same time, efficient consensus algorithms can also increase the rate of transactions processed by the blockchain system. Finally, as the security and performance analysis shows, the scheme in this paper has better security, higher efficiency and more comprehensive functions.
Shayan Ahmed, Rifat Al Mamun Rudro, Afrina Jannat Prity, Suman Saha · 6 authors
The integrity of academic and professional creden-tials is a foundation in education and the professional fields. Traditional certificate verification methods are flawed by in-efficiencies, susceptibility to fraud, and a reliance on manual processes that compromise security and expedience. To address these issues, we present CredChain, a robust Academic and Professional Certificate Verification System that harnesses the power of blockchain technology. Our system utilizes Ethereum-based Decentralized Applications (DApps) and Smart Contracts integrated with the InterPlanetary File System (IPFS) to ensure immutable, secure, and transparent verification processes. We outline the novel algorithms for essential system functions such as certificate uploading, verification, and retrieval of certificates. The CredChain system has been subjected to rigorous testing and validation, demonstrating its effectiveness in mitigating the risk of fraudulent certificates and streamlining the verification process accurately.
Lakshmi Rama Kiran Pasumarthy, Hisham Ali, William J. Buchanan, Jawad Ahmad · 7 authors
There is an increasing need to share threat information for the prevention of widespread cyber-attacks. While threat-related information sharing can be conducted through traditional information exchange methods, such as email communications etc., these methods are often weak in terms of their trustworthiness and privacy. Additionally, the absence of a trust infrastructure between different information-sharing domains also poses significant challenges. These challenges include redactment of information, the Right-to-be-forgotten, and access control to the information-sharing elements. These access issues could be related to time bounds, the trusted deletion of data, and the location of accesses. This paper presents an abstraction of a trusted information-sharing process which integrates Attribute-Based Encryption (ABE), Homomorphic Encryption (HE) and Zero Knowledge Proof (ZKP) integrated into a permissioned ledger, specifically Hyperledger Fabric (HLF). It then provides a protocol exchange between two threat-sharing agents that share encrypted messages through a trusted channel. This trusted channel can only be accessed by those trusted in the sharing and could be enabled for each data-sharing element or set up for long-term sharing.