Recently, blockchain-based covert communication has gained momentum, for the decentralization, anonymity, and immutability feature of blockchain. Nevertheless, some challenges impair its security and efficiency. Most schemes have a weak generalization ability, and can merely be applied to a specific blockchain platform. Storage-based covert transmission schemes usually have limited space for data embedding, affecting their Information delivery efficiency. Besides, static data sifting rules raise the risk of information leakage. In this paper, we design DLCCB(Dynamic Labeling based Covert Communication on Blockchain). We first split the information to be delivered into several pieces and utilize the destination address of each transaction to embed them. Then a dynamic labeling method is proposed for updating sifting rules without extra negotiation between sender and receiver. Besides, we design two kinds of sifting algorithms, namely online and offline sifting algorithm. We perform our solution on Ropsten, a test net of Ethereum. The experiment result verifies the feasibility of our scheme.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Many existing anonymous parking payment schemes lack high efficiency and flexibility. For instance, the calculation and communication costs involved in payment may linearly increase with the payment amount. In this paper, we propose an anonymous payment system (dubbed AnoPay) for vehicle parking, which leverages updatable attribute-based anonymous credentials and efficient zero-knowledge proof (ZKP) to achieve user anonymity and constant overhead for parking fee payment. To further improve the efficiency, we design a secure parking fee aggregation protocol based on linear homomorphic encryption to aggregate parking transactions, where the amount of each parking transaction is hidden and the privacy of the parking lot in terms of its revenue is guaranteed. AnoPay achieves both unlinkability and accountability, malicious payments can be efficiently traced when it is necessary. We provide a security model and rigorous proof for each security property of AnoPay. Extensive experiments and comparisons demonstrate the efficiency and practicality of the system.
Dominic Grandjean, Lioba Heimbach, Roger Wattenhofer
In September 2022, Ethereum transitioned from Proof-of-Work (PoW) to Proof-of-Stake (PoS) during "the merge" - making it the largest PoS cryptocurrency in terms of market capitalization. With this work, we present a comprehensive measurement study of the current state of the Ethereum PoS consensus layer on the beacon chain. We perform a longitudinal study of the history of the beacon chain. Our work finds that all dips in network participation are caused by network upgrades, issues with major consensus clients, or issues with service operators controlling a large number of validators. Further, our longitudinal staking power decentralization analysis reveals that Ethereum PoS fairs similarly to its PoW counterpart in terms of decentralization and exhibits the immense impact of (liquid) staking services on staking power decentralization. Finally, we highlight the heightened security concerns in Ethereum PoS caused by high degrees of centralization.
Thiruvaazhi Uloli, K Sowmiya, P Vedhakalaivani, R Nathiyaa
Blockchain has become a technology and business disruptor with a significant potential for both use and misuse. The distributed architecture combined with the integrity assurance given by the hash as well as the anonymity provided because of the use of identity derived from the public key has made this a revolutionary combination. The positive popularity is because of the anonymity it provides to the transactions and the same is also the reason that regulators, governments, and law enforcement authorities the world over are genuinely concerned about it. Hence it is essential for anyone who wants to track this technology to understand the depth of anonymity it provides. In this paper, we survey, analyse and present the methods by which it is possible to deanonymize and reveal the identity of interesting entities of bitcoin transactions.
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
To address the problems that current studies for enhancing network accountability based on IPv6 addresses do not support cross-Autonomous Systems (AS) or restrict threatener behaviors, a distributed IPv6 Address Traceback and Threatener Restriction Mechanism (ATTRM6) based on smart contract is proposed. Tracing servers of each AS form a blockchain and invoke smart contract functions to store address information of different ASes on the blockchain. When IPv6 address traceback is needed across ASes, the traceback server of a specific AS reads addresses information stored on the blockchain to identify the threatener. Considering the restriction scheme for threatener associated with IPv6 addresses, and proposing a Punishment-Forgiveness Policy (PFP) to dynamically adjust the reputation of threatener, and store restricted threatener and their reputation on the blockchain, thus providing data support to each AS to take restriction measures. Compared with information sharing based on a centralized database, the ATTRM6 mechanism can accomplish more reliable sharing. Experimental results show that the ATTRM6 mechanism has low overhead and can effectively perform IPv6 address traceback and threatener restriction.
Elections are an important event that is responsible for shaping democracies around the world, but still there are many populations around the world who do not fully trust the electoral system which has become one of the major concerns for democracies around the world. Even the world’s greatest democracies, such as India and Japan, have a flawed legal system. Vote rigging, EVM (Electronic Vote Machine) hacking, election tampering, booth capture squares, etc. are the main causes of the problems in the current voting method utilized in these countries. It has proven challenging to develop an electronic voting system that is both secure and safe and that offers a higher level of security, fairness, and privacy than current voting techniques while simultaneously offering the transparency and flexibility. Replacing the existing pen-andpaper (ballot-based voting) approach with a new election system offers the potential to reduce fraud and increase security while also increasing efficiency. Blockchain is a technology that promises to increase the overall robustness and security of various e-voting systems. The paper outlines a great attempt to develop a trustworthy and efficient voting system using blockchain’s properties, including its transparency and cryptographic foundations. The system offers end-to-end verifiability and satisfies the fundamental criteria for e-voting methods. The paper covers the electronic voting system and how it would work on the Multichain network.
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Blockchain is a decentralized, distributed ledger that records transactions between two parties. A blockchain-based software system is a new and innovative approach to software engineering that uses blockchain technology. This approach has several advantages over traditional software engineering approaches, including improved security and transparency. The most common software engineering approaches are waterfall, agile and hybrid models. Each of these has its strengths and weakness. A blockchain-based system has the advantage of being more secure and transparent than any of these approaches. It also can track changes more accurately, which can improve quality control. Blockchain technologies have incredible potential but also have some problems. One problem is security and privacy issues, which brings into question the resilience of existing security and trust mechanisms. The distributed application (dApp) framework for the proposed electronic voting system is built with the help of blockchain technology in this proposal. As a result, fewer crimes has committed against sensitive data during the electoral process because of immutability, transparency and privacy. Ganache, Metamask and hashing algorithms are used to develop the dApp. The paper's strengths lie in its ability to create and analyze threat models for blockchain-enabled-electronic voting systems and to identify the types of threats using Microsoft STRIDE.
Viji Rajendran, A. Jasrotia, Ghulam Murtaza, Rohit Sharma
Any democracy must have an open voting<br> process that satisfies the needs of the populace to give the<br> appropriate individual the power. Additionally, the<br> traditional voting systems currently in use have<br> significant flaws and lack security and transparency. It<br> has long been difficult to create a safe electronic voting<br> system that provides the transparency and flexibility<br> provided by electronic systems, while maintaining the<br> fairness and privacy of present voting schemes. In this<br> project, we assess a blockchain-based implementation of<br> distributed electronic voting systems. It addresses some<br> of the well-known blockchain frameworks with the aim<br> of building a blockchain-based electronic voting system<br> and presents a novel electronic voting system based on<br> blockchain that tackles some of the shortcomings in<br> existing systems. In particular, we evaluate the potential<br> of distributed ledger technologies through the<br> description of a case study; namely, the process of an<br> election, and the implementation of a blockchain-based<br> application, which improves the security and decreases<br> the cost of hosting a nationwide election.
The rapid digital revolution in recent decades has resulted in an overwhelming amount of information, particularly in the realm of modern education systems and related materials. This phenomenon, often referred to as information overload, necessitates the development of educational systems that can effectively search, classify, and categorize this vast amount of available information. Of utmost importance for such educational information systems is the safeguarding of personal data, which refers to information that can identify an individual or their family. School records, for example, contain various types of personal data such as the individual’s name, address, contact details, disciplinary history, as well as their grades and progress checks. Even if individuals choose to make this data public, it remains inherently personal. Another category of data involves more sensitive topics such as student biometrics (e.g. fingerprints, photographs), religious beliefs, health information (e.g. allergies), or dietary restrictions, which may imply religious or health-related aspects. Processing data in this category can pose risks to individuals; hence, strict rules and appropriate consent are necessary to ensure their protection. To address these challenges, this research paper proposes a zero-knowledge proof intelligent recommendation system designed to protect students’ data privacy in the digital age. The proposed method incorporates an Intelligent Recommendation System (IRS) that utilizes an optimized version of the Matrix Factorization technique, calculated as an Eulerian Walk chart. Furthermore, the Schnorr Zero-Knowledge Proof format, based on the discrete logarithm problem, ensures the privacy of personal data during message exchange between educational entities.
With the recent hype around the Metaverse and NFTs, Web3 is getting more and more popular. The goal of Web3 is to decentralize the web via decentralized applications. Wallets play a crucial role as they act as an interface between these applications and the user. Wallets such as MetaMask are being used by millions of users nowadays. Unfortunately, Web3 is often advertised as more secure and private. However, decentralized applications as well as wallets are based on traditional technologies, which are not designed with privacy of users in mind. In this paper, we analyze the privacy implications that Web3 technologies such as decentralized applications and wallets have on users. To this end, we build a framework that measures exposure of wallet information. First, we study whether information about installed wallets is being used to track users online. We analyze the top 100K websites and find evidence of 1,325 websites running scripts that probe whether users have wallets installed in their browser. Second, we measure whether decentralized applications and wallets leak the user's unique wallet address to third-parties. We intercept the traffic of 616 decentralized applications and 100 wallets and find over 2000 leaks across 211 applications and more than 300 leaks across 13 wallets. Our study shows that Web3 poses a threat to users' privacy and requires new designs towards more privacy-aware wallet architectures.
The sharing of high-quality information is essential for improving the user experience in distributed systems such as vehicular networks or IoT-based monitoring systems. Crowd-sourced data collection systems rely heavily on a secure and efficient consensus algorithm. However, consensus algorithms are often considered a bottleneck for scalability. With the emergence of blockchains, proof-of-work (PoW) has become the most popular and secure consensus algorithm for open and asynchronous distributed networks. However, PoW has been criticized for its energy consumption and waste of resources. To address this issue, alternative consensus protocols such as proof-of-stake (PoS) and proof-of-authority (PoA) have been proposed. Reputation-based consensus algorithms have recently gained attention but suffer from limitations in terms of privacy and predictability. In this paper, we propose a privacy-preserving proof-of-reputation (PoR) mechanism that combines ring signatures and dlog-based zero-knowledge proof systems. The proposed PoR algorithm aims to build unpredictable blockchain consensus algorithms that are privacy-friendly for permissioned blockchains. We describe the main algorithms used in PoR, demonstrate their security, and evaluate their performance through an experimental study. We conclude by discussing how these algorithms can be scaled to permissionless blockchain settings.
Due to increasingly widespread electoral corruption, citizens are slowly starting to lose trust in the fairness of democratic elections. The main objective of VoteChain is the elimination of the aspect of trust from the electoral process, in order to make voting more secure, transparent, and easily accessible. This paper proposes and implements a robust system that enhances voting efficiency by creating an electronic platform on top of a distributed Bitcoin Cash blockchain ledger. Blockchain represents a time-stamped series of immutable data records shared across a distributed network. When utilized in the context of voting, it guarantees full anonymity, vote integrity, and a fair, incontrovertible ledger with verifiable election results to all voters. Moreover, the system offers the ability to vote via any Internet-enabled computer or smartphone, dramatically decreasing the overall election organization costs. The system is envisioned as an application that connects to the Bitcoin Cash blockchain network via a custom feature-rich library. After discussing the system's characteristics, design, and underlying technology, this paper presents an example election scenario explaining how VoteChain works in-depth. In the end, the system's possible shortcomings are outlined, along with its prospective evolution and potential improvements that can be implemented.
With natural language processing as an important research direction in deep learning, the problems of text similarity calculation, natural language inference, question and answer systems, and information retrieval can be regarded as text matching applications for different data and scenarios. Secure matching computation of text string patterns can solve the privacy protection problem in the fields of biological sequence analysis, keyword search, and database query. In this paper, we propose an Intelligent Semi-Honest System (ISHS) for secret matching against malicious adversaries. Firstly, a secure computation protocol based on the semi-honest model is designed for the secret matching of text strings, which adopts a new digital encoding method and an ECC encryption algorithm and can provide a solution for honest participants. The text string matching protocol under the malicious model which uses the cut-and-choose method and zero-knowledge proof is designed for resisting malicious behaviors that may be committed by malicious participants in the semi-honest protocol. The correctness and security of the protocol are analyzed, which is more efficient and has practical value compared with the existing algorithms. The secure text matching has important engineering applications.
The evolution of Aadhaar, an identification system executed by the Indian government that provides each citizen with a unique identity, is analyzed within the context of the creation of Unique Identity Authority of India (UIDAI), which distributes and generates user identities based on and biometric and demographic information. The study gives a comprehensive outline of security issues related to the Aadhaar authentication process and analyzes the updates introduced over time. The main objective of this study is to comprehensively cover the security perspectives related to Aadhaar and provide conceivable arrangements to mitigate the security threats through the development and implementation of a decentralized fingerprinting system that uses Public Key Infrastructure (PKI) to empower secure peer-to-peer data exchange leveraging zero-knowledge proofs. The proposed solution shows the necessary data digitally by integrating data logging strategies to keep track of individuals accessing the data ensuring end-to-end encryption. In this way, it empowers Aadhaar holders to selectively disclose their information to authorized entities while preserving the confidentiality and integrity of the data.
Advanced Steganography and Watermarking Techniques
Hao Xu, Yunqing Sun, Zihao Li, Yao Sun · 6 authors
Web3 brings an emerging outlook for the value of decentralization, boosting the decentralized infrastructure. People can benefit from Web3, facilitated by the advances in distributed ledger technology, to read, write and own web content, services and applications more freely without revealing their real identities. Although the features and merits of Web3 have been widely discussed, the network architecture of Web3 and how to achieve complete decentralization considering law compliance in Web3 are still unclear. Here, we propose a perspective of Web3 architecture, deController, consisting of underlay and overlay network as Web3 infrastructures to underpin services and applications. The functions of underlay and overlay and their interactions are illustrated. Meanwhile, the security and privacy of Web3 are analyzed based on a novel design of three-tier identities cooperating with deController. Furthermore, the impacts of laws on privacy and cyber sovereignty to achieve Web3 are discussed.
Ring signcryption with no group administrator satisfies the decentralization and blockchain anonymity. In this article, we construct new lattice-based ring signcryption scheme suitable for consortium blockchain (CB-LRSCS), in which the smart contract controls the process of signcryption and unsigncryption to make the system be fair and reliable. CB-LRSCS can protect the user privacy by reducing the connection between blockchain and user information, and it satisfies the reliability in ethereum environment. CB-LRSCS also has the characteristics of high efficiency, anti-quantum, anti-forgery, confidentiality and unconditional anonymity, and it can be applied in the electronic finance system.
Delegated-Proof-of-Stake (DPoS) blockchains are governed by a committee of dozens of members elected via coin-based voting mechanisms. This paper presents a large-scale empirical study of two critical characteristics, personal impact and participation rate, of three leading DPoS blockchains. Our findings reveal the existence of decisive voters whose votes can alter election outcomes, as well as the fact that almost half of the coins have never been used in committee elections. Our research contributes to demystifying the actual use of coin-based voting governance and offers novel insights into the potential security risks of DPoS blockchains.
In today’s digital environment, the voting system has moved from paper based to a digital system. A digital e-voting system has many properties such as transparency, decentralization, irreversibility, and non-repudiation. The growth in the digital e-voting system raises many security and transparency issues. In this paper, we used the blockchain technology in the digital electronic voting system to solve the security issues and ful?ll the system requirements. It offers new opportunities to deploy a secure e-voting system in any organization or country. The solution is far better as compared to other solutions because it is a decentralized system, containing the results in the form of bit-coins, having different locations. We will also analyze the security of our proposed voting system, which shows our protocol is more secure as compared to other solutions. The paper proposes a novel electronic voting system based on block chain that addresses some of the limitations in existing systems and evaluates some of the popular blockchain frameworks for the purpose of constructing a blockchain based e-voting system. In particular, we evaluate the potential of distributed ledger technologies through the description of a case study namely, the process of an election, and the implementation of a blockchain based application, which improves the security and decreases the cost of hosting a nation wide election.
Federated learning (FL) is a technique that involves multiple participants who update their local models with private data and aggregate these models using a central server. Unfortunately, central servers are prone to single-point failures during the aggregation process, which leads to data leakage and other problems. Although many studies have shown that a blockchain can solve the single-point failure of servers, blockchains cannot identify or mitigate the effect of backdoor attacks. Therefore, this paper proposes a blockchain-based FL framework for defense against backdoor attacks. The framework utilizes blockchains to record transactions in an immutable distributed ledger network and enables decentralized FL. Furthermore, by incorporating the reverse layer-wise relevance (RLR) aggregation strategy into the participant’s aggregation algorithm and adding gradient noise to limit the effectiveness of backdoor attacks, the accuracy of backdoor attacks is substantially reduced. Furthermore, we designed a new proof-of-stake mechanism that considers the historical stakes of participants and the accuracy for selecting the miners of the local model, thereby reducing the stake rewards of malicious participants and motivating them to upload honest model parameters. Our simulation results confirm that, for 10% of malicious participants, the success rate of backdoor injection is reduced by nearly 90% compared to Vanilla FL, and the stake income of malicious devices is the lowest.
Transparent e-voting is one of the applications that the turing complete public blockchain aspires to deliver by assuring verifiable votes. Public blockchains are much transparent, secure and have better auditing. In Blockchain based e-voting a voter identity is established with his account, whereas one account can cast a vote which leaves scope for user identity binding based on other activities on the blockchain. In this work we propose a privacy preserving and anonymous e-voting approach on the public blockchain. We introduce the concept of Proof of Vote.
We propose a hybrid system to utilize non-fungible tokens for event ticketing. By adding an intermediate database, we enjoy blockchain benefits such as fraud prevention and higher transparency over the secondary market while ensuring reasonable redemption speed. Furthermore, the additional step after ticket redemption is to verify through the smart contract whether the ticket holder’s signature is included, preventing event organizers from marking the ticket as used without the holder’s consent.
Roseline Oluwaseun Ogundokun, Micheal Olaolu Arowolo, Robertas Damaševičius, Sanjay Misra
The recent progress in blockchain and wireless communication infrastructures has paved the way for creating blockchain-based systems that protect data integrity and enable secure information sharing. Despite these advancements, concerns regarding security and privacy continue to impede the widespread adoption of blockchain technology, especially when sharing sensitive data. Specific security attacks against blockchains, such as data poisoning attacks, privacy leaks, and a single point of failure, must be addressed to develop efficient blockchain-supported IT infrastructures. This study proposes the use of deep learning methods, including Long Short-Term Memory (LSTM), Bi-directional LSTM (Bi-LSTM), and convolutional neural network LSTM (CNN-LSTM), to detect phishing attacks in a blockchain transaction network. These methods were evaluated on a dataset comprising malicious and benign addresses from the Ethereum blockchain dark list and whitelist dataset, and the results showed an accuracy of 99.72%.
Javier José Díaz Rivera, Waleed Akbar, Talha Ahmed Khan, Muhammad Afaq · 5 authors
Zero Trust Networking (ZTN) is a security model where no default trust is given to entities in a network infrastructure. The first bastion of security for achieving ZTN is strong identity verification. Several standard methods for assuring a robust identity exist (E.g., OAuth2.0, OpenID Connect). These standards employ JSON Web Tokens (JWT) during the authentication process. However, the use of JWT for One Time Token (OTT) enrollment has a latent security issue. A third party can intercept a JWT, and the payload information can be exposed, revealing the details of the enrollment server. Furthermore, an intercepted JWT could be used for enrollment by an impersonator as long as the JWT remains active. Our proposed mechanism aims to secure the ownership of the OTT by including the JWT as encrypted metadata into a Non-Fungible Token (NFT). The mechanism uses the blockchain Public Key of the intended owner for encrypting the JWT. The blockchain assures the JWT ownership by mapping it to the intended owner's blockchain public address. Our proposed mechanism is applied to an emerging Zero Trust framework (OpenZiti) alongside a permissioned Ethereum blockchain using Hyperledger Besu. The Zero Trust Framework provides enrollment functionality. At the same time, our proposed mechanism based on blockchain and NFT assures the secure distribution of OTTs that is used for the enrollment of identities.
A generalized scheme of remote electronic voice based on homomorphic encryption is considered. Two methods of protecting the voting system from the threat from the voter, consisting in incorrect filling of the ballot by the voter, are investigated. Both methods are based on the algorithms of “zero-knowledge proof”. Evaluations of the complexity of calculations in the formation of proof of the correctness of filling in the ballot by the voter and Evaluations of the complexity of verification of the proof by the controlling party are obtained. A comparative analysis of the complexity of the implementation of both methods has shown that the method based on the proof based on the equality of logarithms has less complexity of calculations on the voter's side compared to the method based on the mixing of votes. At the same time, the second method (the method of mixing votes) requires 1.67 times less calculations in the blockchain, which becomes a significant factor in choosing the second method in favor of a large number of voters.
Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques