To solve the problem of climate warming, countries around the world have paid special attention to the construction of carbon governance. Carbon emission accounting is an important policy tool to control the vented CO2. But at present, there are third-party agencies in carbon emission accounting that cannot ensure the fairness and impartiality of accounting, and there may be risks such as illegal use and leakage of sensitive information in the process of carbon emission data transmission. Therefore, We design the blockchain-based carbon emission security accounting scheme (BCESAS) and propose cross-chain verification contract to ensure the efficiency of cross-chain information accounting. In addition, bilinear pairing is used to ensure data integrity, and we encrypt private data using an improved and more secure homomorphic encryption algorithm to ensure that privacy is not leaked during the transfer of carbon emission data, which is more efficent than other homomorphic encryption algorithms. We also use reputation mechanism to regulate the behavior of carbon emission auditors. The theoretical and experimental analysis demonstrates that BCESAS can verify the integrity, correctness and privacy of cross-chain data calculation result effectively, realizing secure and reliable expansion of blockchain.
Michalis Pingos, Panayiotis Christodoulou, Andreas S. Andreou
Data meshes are an approach to data architecture and organization that treats data as a product and focuses on decentralizing data ownership and access. It has recently emerged as a field that presents quite a few challenges related to data ownership, governance, security, monitoring, and observability. To address these challenges, this paper introduces an innovative algorithmic framework leveraging data blueprints to enable the dynamic creation of data meshes and data products in response to user requests, ensuring that stakeholders have access to specific portions of the data mesh as needed. Ownership and governance concerns are addressed through a unique mechanism involving Blockchain and Non-Fungible Tokens (NFTs). This facilitates the secure and transparent transfer of data ownership, with the ability to mint time-based NFTs. By combining these advancements with the fundamental tenets of data meshes, this research offers a comprehensive solution to the challenges surrounding data ownership and governance. It empowers stakeholders to navigate the complexities of data management within a decentralized architecture, ensuring a secure, efficient, and user-centric approach to data utilization. The proposed framework is demonstrated using real-world data from a poultry meat production factory.
Nowadays, Internet of Things platforms are being deployed in a wide range of application domains. Some of these include use cases with security requirements, where the data generated by an IoT node is the basis for making safety-critical or liability-critical decisions at system level. The challenge is to develop a solution for data exchange while proving and verifying the authenticity of the data from end-to-end. In line with this objective, this paper proposes a novel solution with the proper protocols to provide Trust in Data, making use of two Roots of Trust that are the IOTA Distributed Ledger Technology and the Trusted Platform Module. The paper presents the design of the proposed solution and discusses the key design aspects and relevant trade-offs. The paper concludes with a Proof-of-Concept implementation and an experimental evaluation to confirm its feasibility and to assess the achievable performance.
Multi-cloud environments such as OnApp and Cloudflare have turned the cloud marketplace towards a new horizon where end-users can host applications transparently over different cloud service providers (CSPs) simultaneously by taking the best from each. Existing cloud federations are typically driven by a broker service which provides a trusted interface allowing the participant CSPs and end-users to coordinate. However, such a broker has the limitations of any centralized trusted authority like risk of manipulation, bias, censorship, single point of failure, etc. In this paper, we propose a decentralized trustless cloud federation architecture calledCollabCloudwhich eliminates any central mediator while addressing the challenges introduced by byzantine participants.CollabCloudutilizes blockchain, and introduces a novel interoperability protocol bridging a permissionless blockchain as an open interface for the end-users, and a permissioned blockchain as a coordination platform for the CSPs. We have implementedCollabCloudwith Ethereum, Hyperledger Fabric and Burrow platforms. Experiments with a proof-of-concept testbed emulating 3 CSPs show thatCollabCloudcan operate within an acceptable response latency for resource allocation, while scaling upto 64 parallel requests per second. Scalability analysis over Mininet emulation platform indicates that the platform can scale well with minimal impact on the response latency as the number of participating CSPs increases. % for resource scheduling and allocation. %trustless, transparency, immutability properties of %By utilizing trustless, transparency, immutability and verifiability features of a distributed ledger technology, % Such multi-cloud environments bring the notion of cloud federation where various CSPs can buy and sell cloud resources, and thus collaborate among themselves to provide better capacity with less capital expenditure. %The novelty ofCollabCloudis in designing the interfacing between the two different blockchain platforms, through which the end-users access resources over multi-clouds in a secured way. %Need to reduce to 200 words. %The broker works like a trusted entity that takes care of various management tasks of the federation. %as the decentralized federation marketplace needs to provide a unified interface to the end-users while maintaining an agreement on pricing, fair scheduling of resources and securing resource access to the end-users. %InCollabCloud, we achieve the above goals by developing a unique interface through interconnecting a public (permissionless) blockchain platform with a private (permissioned) blockchain platform. %Cloud federation helps multiple cloud service providers to come into collaboration and share their resources for their overall benefit. However, the current implementations of federated clouds depend on a trusted federation broker that takes care of the handling end-user requests, resource allocation as well as scheduling and pricing for the shared resources under the federation. This central broker provides a unified interface to the end-users, through which they can access the federation as a single entity. The unified interface presents the federation as a single larger cloud provider which can fulfill a broader set of user demands and at a better pricing. Although the cloud broker plays a crucial role in the federation, it has the limitations of any centralized trusted authority like risk of manipulation, biasness, censorship, single point of failure, etc.. In this work, we propose a trustless, decentralized and democratic architecture for cloud federations which is free from any cloud broker. This democratic system leverages a combination of permissionless and permissioned blockchain which keeps all the functionalities of a broker based federation intact. Our system provides a trustless unified interface for the federation as well as brokerless scheduling, transfer of resources, catalog maintainance etc.. We implement the system with a fair scheduling smart contract and evaluate it with respect to end-to-end request processing time and analyze its overheads. The outcome of the analysis gives a clear view that the proposed system keeps all functionalities of cloud federation intact, while maintaining the required quality of experience(QoE) to the end-users.
Engin Zeydan, Josep Mangues‐Bafalluy, Şuayb S. Arslan, Yekta Türk
Identity and access management frameworks address user access rights and data governance for organizations, vendors and users. In response to the problems associated with centralized authorities (e.g. single point of failure , limited scalability, lack of user control), new identity management models have emerged, such as Self-Sovereign Identity (SSI), which relies on verifiable data registers to validate Decentralized Identifier (DIDs) and can be achieved in many different ways, e.g. through Distributed Ledger Technology (DLT), distributed databases or other decentralized systems. The main goal of SSI is to enable users to take control of managing their data shared with different services. In this paper, we examine a possible application of the SSI concept to aerial base station (ABS)- integrated networks. The paper presents the effective use of DID implementation to provide a secure and decentralized way to create, associate and verify credentials and identities of ABSs, ensuring secure communication between Ground Base stations (GBSs) and other nodes in the network in a multi-operator scenario. In the numerical results, the average values of various metrics (namely, the average credential presentation time, the average credential offer time, the average DIDcomm connection creation time, the average DIDcomm signing time, and the average DIDcomm revoke credential time) related to credential operations in a DID management system are given for three different number of requests (50 K, 75 K, and 100 K). We have also provided the values of the different status codes that occurred in 100 K operations in the same DID management system. Towards the end of the paper, a comparison is made between SSI-based and Non-fungible token (NFT)-based blockchain solutions, also discussing the challenges and future directions of SSI solutions in the context of ABS-integrated networks.
Data deduplication schemes have been widely used in cloud storage systems to save storage space by eliminating duplicate outsourced data. However, the reduction of redundancy leads to decreased data availability and unbalanced data distribution. This paper proposes a blockchain-based decentralized storage system with reliable deduplication and storage balance strategy to provide reliability for deduplicated outsourced data. Encrypted data is split into chunks by a ramp secret sharing scheme, and it is distributed to multiple independent cloud servers. States of the chunks are recorded on the tamper-proofed blockchain and they can be used to recover the raw data or support the verification of user identity. To balance the distribution of data among storage servers, a heuristic matching algorithm is designed to efficiently allocate the available storage space. The allocation services are published by autonomous smart contracts and other participants gain rewards by giving the best matching results of data chunks and storage servers. Formulation analysis demonstrates the correctness of the proposed scheme in terms of data consistency, integrity, and reliability. Experimental results show that the proposed scheme preserves the confidentiality of outsourced data with acceptable computational consumption.
A banking or identity provider can set up a customer identification data verification process between reliant parties with the use of the electronic know your customer (e-KYC) system. Due to its high degree of accessibility and availability and its efficient resource usage, the majority of banks choose to implement their e-KYC system on the cloud. All of the KYC procedures used by banks rely on encryption, which is a cumbersome process that may cause consumer data to be disclosed to unaffiliated financial institutions. Blockchain technology can be used to increase the efficiency of this system because it can automate a lot of human labor and is impervious to attacks of all kinds. The distributed ledger and immutable blockchain block make the perfect addition to the KYC process. The use of smart contacts can automate the identification of fraud. Any kind of KYC can be used to store information related to KYC identity. Consequently, financial institutions can establish a shared private blockchain on their premises for the purpose of document validation. This allows the user to maintain control over their private documents while also simplifying the process for banks to obtain the records needed for compliance
With the rise of healthcare digitization, it has become a critical priority to safeguard patient privacy and ensure data security. Conventional methods of data access control mechanisms have proven to be insufficient in the dynamic management of patient data access with a fine-grained access control mechanism. In this paper, we have proposed ZeroMedChain which explores an innovative solution for enhancing the security of medical records in the field of healthcare. The proposed paper makes use of Layer 2 security measures and Zero-Knowledge Proof (ZKP) technologies. Since the basic focus of the paper is decentralized identity and access management, we have integrated Zero-knowledge Proof with a layer of privacy that permits the patients to share the necessary medical details without revealing their identity. Further, the simulation carried out of the proposed ZeroMedChain along with the conventional consensus algorithm of Proof-of-work proved that ZeroMedChain has better time complexity by 34%.
Battula Venkata Satish Babu, Kare Suresh Babu, Durga Prasad Kare
The secure access and reliable access revocation methods of modern digital systems are based on access control mechanisms.Access policies, which are used in access control mechanisms, are very important in safeguarding security and ensuring data protection.It is evident that the protection and tamper-proofing of such policies are very important.In addition, efficient access revocation schemes are required to promptly remove access privileges when users are no longer needed or authorized.The shortcomings of existing systems in ensuring efficient, streamlined access revocation and tamper-proof protection of access control policies underscore the need for innovative solutions.In this paper, we have introduced the novel Blockchain Attribute-Based Secure Data Management Model (BAB-SDMM).Our model is the first to integrate attribute-based encryption (ABE), Attribute-Based Access Control (ABAC), and blockchain to achieve multiple security features as well as provide partial and complete revocation at the same time.The experimental results and analysis, performed using the Ethereum blockchain network, demonstrated the enhanced performance of the proposed BAB-SDMM compared to existing research works.
Recent developments in Distributed Ledger Technology (DLT), including Blockchain offer new opportunities in the manufacturing domain, by providing mechanisms to automate trust services (digital identity, trusted interactions, and auditable transactions) and when combined with other advanced digital technologies (e.g. machine learning) can provide a secure backbone for trusted data flows between independent entities. This paper presents an DLT-based architectural pattern and technology solution known as SmartQC that aims to provide an extensible and flexible approach to integrating DLT technology into existing workflows and processes. SmartQC offers an opportunity to make processes more time efficient, reliable, and robust by providing two key features i) data integrity through immutable ledgers and ii) automation of business workflows leveraging smart contracts. The paper will present the system architecture, extensible data model and the application of SmartQC in the context of example smart manufacturing applications.
Cloud computing enables on-demand computation on remote servers and computers. Thanks to the adaptability and scalability of the infrastructure for data storage, processing, and management. To solve the security problems arising in cloud identity management techniques such as, dependency on a third-party token provider, leakage of user’s details, single point of failure, etc., decentralized cloud identity management systems came into the picture. Blockchain is a decentralized database providing immutability and transparency to recorded transaction data. The current token-based decentralized cloud identity management systems have limitations, including the absence of data access management procedures and a lack of security features. This paper suggests a Blockchain based Secure Cloud Identity and Access Management (BSCIAM) model for secure identity and access management, utilizing encryption and key sharing techniques. The proposed model has been implemented using Ethereum smart contracts for token-based identity management.
Vibha Nehra, Aakarsh MJ, Hitesh Khanna, Naman Jindal
Decentralized digital identity verification systems based on blockchain technology, or D.D.I.V.S as they are popularly known, are linchpins for an entirely new way of authenticating our online identities. These systems possess a number of obvious merits compared to the traditional methods of identity verification, for instance elevated security level, privacy protection and practicability. This article introduces a Prototype system using MetaMask, a very well-known cryptocurrency wallet and Web3 gateway. The system offers significantly superior results than traditional approaches. Its parts include user registration and data extraction by means of public key registration, secure key storage with MetaMask, an uninterrupted connection between D-Apps (Decentralized Applications) and the wallet; and application of asymmetric cryptography to data encryption and decryption. Strict testing has confirmed the MetaMask-powered prototype system can provide a secure, private and practical decentralized digital identification verification platform. That heralds a promising change for all of us
With the vigorous development of the social network, massive data have generated by large amount of users. To utilize these data, social computing is widely used. However, due to the conflict between proprietary data and the use of data, it is a challenge to fully obtain data value in an efficient and legal way. Moreover, how to manage, govern and schedule data, a technical and feasible approach is still a major problem. To this end, as an emerging distributed ledger technology, blockchain is considered a promising technology for data security and privacy and is introduced for cross-domain data governance. In this paper, we propose a blockchain-assisted cross-domain data sharing scheme for social computing data governance. Specifically, permissioned blockchain is introduced to construct trust among different parties. A zero-knowledge proof scheme is designed to verify data ownership confidentially and anonymously. The security of the zero-knowledge proof scheme is also analyzed. The extensive simulations and experiments have proven the effectiveness and efficiency of the mechanism.
Account abstraction is a method that enhances the flexibility and extensibility of blockchain accounts. For the Ethereum blockchain, ERC-4337 is a proposal for implementing account abstraction without modifying the logic of the underlying consensus protocol. However, due to its complete implementation through smart contracts, the transaction costs associated with ERC-4337 remain expensive compared to regular Externally Owned Account (EOA) transactions. To evaluate the usage costs of ERC-4337, we introduce two innovative algorithms: the ERC-4337 Classification Algorithm and the ERC-4337 Gas Measure-ment Algorithm. The Classification Algorithm categorizes historical ERC-4337 transactions and logs, providing valuable insights into their nature and characteristics. The Gas Measurement Algorithm calculates the actual gas consumption for users and the incentives paid to bundlers that package the transactions of ERC-4337 (UserOperation) into an Ethereum standard transaction. We have implemented these algorithms within the official ERC-4337 deployment on the Ethereum network. Our findings indicate that creating an ERC-4337 account costs 381,489 gas, allowing only 78 accounts per block. Furthermore, a basic ERC-4337 transfer consumes 92,901 gas, which is four times the gas cost of an EOA transfer. These results confirm that high gas fees continue to pose a significant obstacle to the widespread adoption of ERC-4337. Moreover, our proposed algorithms can serve as a valuable toolset for evaluating the usage costs associated with different account abstraction proposals on Ethereum to contribute to the assessment and improvement of account abstraction mechanisms.
Since 2009 when the first cryptocurrency Bitcoin began to be inserted into the market of electronic currencies, today in 2023 there are more than 19,850 electronic cryptocurrencies [1]. According to information from the coinecko website, the cryptocurrency market has expanded dramatically from a market capitalization of $1 million in 2013 to $3 trillion in November 2021 [2]. Referring to the latest statistical data, 3 are the cryptocurrencies that rule the e-commerce market in November 2023, Bitcoin,Ethereum AND Tether USDt [3]. Robotic Process Automation (RPA) is a growing trend in the restructuring of business processes, combined with digital transformation. This technology can be applied in different areas of business processes and by organizations from any activity sector [4].With continuous advances in automated processes through RPA, mechanisms involving Artificial Intelligence (AI) were incorporated to influence real-life decision-making [5]. Artificial Intelligence (AI) allows improving the accuracy and execution of RPA processes in extracting information and recognizing, classifying, predicting and optimizing processes [6].Nowadays, artificial intelligence is affecting the way people process computer data, televisions have started to create avatars that they use for news reporting. In this paper we will study the impact that the use of automatic sale and purchase of electronic cryptocurrencies can have using IPA and RPA and the possibility of this process being realized through this process.
Abstract With the rapid development of the Internet of Medical Things (IoMT) and the increasing concern for personal health, sharing Electronic Medical Record (EMR) data is widely recognized as a crucial method for enhancing the quality of care and reducing healthcare expenses. EMRs are often shared to ensure accurate diagnosis, predict prognosis, and provide health advice. However, the process of sharing EMRs always raises significant concerns about potential security issues and breaches of privacy. Previous research has demonstrated that centralized cloud-based EMR systems are at high risk, e.g., single points of failure, denial of service (DoS) attacks, and insider attacks. With this motivation, we propose an EMR sharing scheme based on a consortium blockchain that is designed to prioritize both security and privacy. The interplanetary file system (IPFS) is used to store the encrypted EMR while the returned hash addresses are recorded on the blockchain. Then, the user can authorize other users to decrypt the EMR ciphertext via the proxy re-encryption algorithm, ensuring that only authorized personnel may access the files. Moreover, the scheme attains personalized access control and guarantees privacy protection by employing attribute-based access control. The safety analysis shows that the designed scheme meets the expected design goals. Security analysis and performance evaluation show that the scheme outperforms the comparison schemes in terms of computation and communication costs.
The adoption of cloud-based electronic health record (EHR) systems and blockchain technology in healthcare is gaining attention for enhancing data security and interoperability. This research focuses on designing and implementing a blockchain-based cloud EHR system. It explores selecting suitable blockchain technology, cloud infrastructure, and data management methods to ensure patient data confidentiality, integrity, and availability. The architecture and components of the system, including the blockchain network, cloud storage layer, and user interface, are thoroughly discussed. A pilot study evaluates the system’s feasibility and performance, showcasing improved data protection, sharing, and management compared to traditional EHR systems. The potential benefits, drawbacks, and barriers to adoption of a blockchain-based cloud EHR system are examined. This research provides valuable insights and recommendations for healthcare institutions considering the implementation of such systems, addressing the challenges, and offering guidance for successful adoption.
In the past decade, edge computing and blockchain technology have been used in many applications with rapid growth. The chapter explores the intersection of blockchain technology and edge computing and investigates the security issues and solutions in this emerging domain. Edge computing refers to “the decentralized processing and storage of data at the network edge, closer to the data sources and end-users. It offers reduced latency, improved data privacy, and enhanced real-time decision-making capabilities.” However, it also introduces new security challenges due to the distributed and resource-constrained nature of edge devices. The integration of blockchain technology with edge computing holds promise in addressing these security issues. Blockchain can provide a decentralized and tamper-resistant ledger for recording and verifying transactions, ensuring data integrity, and establishing trust among edge devices and stakeholders. This chapter explores several use cases where blockchain and edge computing can synergistically enhance security.
Iulian Aciobăniţei, Ştefan-Ciprian Arseni, Emil Bureacă, Mihai Togan
The current shift towards digital transactions emphasizes the need for robust Qualified Electronic Signature (QES) frameworks that safeguard integrity and privacy. Having the potential to become the leading type of adopted QES, the main challenge that Remote QESs present to end users is choosing between transmitting the entire document or only its digest to the Trust Service Provider (TSP). The first option compromises the document’s confidentiality, while the second one requires the development of signature applications compliant with advanced signature formats, a task that often needs additional time and resources. In this paper, we introduce a comprehensive strategy for remote QESs, designed for seamless integration with current client applications, while simultaneously maintaining user privacy. The main topics approached in this paper are the following: a comprehensive architecture for privacy-aware remote QES systems, relevant standards and legislation, integration scenarios for clients, and remote QES standard protocols to assure communication between client and TSP environments. Furthermore, we also explore the integration of our proposed solution with an enhanced long-term preservation service that uses Ethereum smart contracts and methodologies to implement signature applications with advanced electronic signatures via open-source libraries while ensuring document privacy. The main result of this work is a flexible on-premise module that provides the ability to sign, validate, and preserve documents, with a minimal integration effort.
Ángel Jesús Varela‐Vaca, Rafael M. Gasca, David Iglesias, J.M. Gónzalez-Gutiérrez
Collaboration of business processes is essential for business-to-business (B2B) processes. Collaboration is interesting and important in connecting the digital context with the physical world (IoT) to feed processes with data or send data. However, it also presents multiple challenges, such as the lack of trust between participants with each other and additional privacy and security problems in the communicated data. Fraud detection is crucial for many type of organisations that deal with B2B transactions (banking, fintech, health, etc.) and are therefore exposed to a high risk of fraud. Fraud detection requires expensive professional investigations and intensive collaboration between processes of different organisations. This issue could be mitigated by effectively managing digital evidence, fostering trust and ensuring security for various stakeholders involved in the business processes. This paper proposes an approach to modelling and deploying any collaborative business process scenario, ensuring trust, security, and data privacy. Collaboration-level agreements are defined as a means to ensure trust, security, and data privacy. To accomplish this, our approach enables the automatic generation Smart Contract templates for the collaboration-level agreement specification involving different stakeholders in the collaboration. The Smart contracts are deployed in a Blockchain to ensure that the collaboration-level agreement conditions are signed by the parties. To validate the feasibility of our approach, a proof-of-concept for a fraud detection scenario is implemented, where different metrics are tested in relation to a set of threats and vulnerabilities.