Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
The financial industry is faced with attractive business opportunities to adopt blockchain. To make such an investment, decision makers need answers to a number of questions including: what existing business problems will be solved, will blockchain solve them, and what long term benefits and new business opportunities blockchain can create. In this paper we analyze security aspects of these questions, focusing on the protection of integrity of data and financial transactions. We start from the analysis of an essential security architecture of financial systems which is based on the perimeter protection and traditional business process safeguards such as maker-checker. Subsequently, we look at the options on how to improve such an architecture to provide protection against malicious internal users and malware implanted inside the system; the vulnerabilities that have been exploited by organized criminal teams of attackers in the attacks seen lately. We show that the improvements based on the preventive safeguards, inherent to blockchain security architecture, provide strong protection against those attacks. Finally, we argue that in comparison with typically used detective measures (e.g. monitoring), security architecture based on the blockchain model provides superior protection against attacks using attack scenarios never seen before.
Frank YeongâSung Lin, ChiuâHan Hsiao, YeanâFu Wen, Yang-Che Su
Transactions and blocks must be synchronized among the blockchain miners on the Internet. Software-defined networking and network function virtualization techniques support dynamically assigning computing resources into servers of the core and edge clouds. In this paper, an adaptive broadcast algorithm is proposed for blockchain authentication, authorization, and accounting (AAA) services. The cryptography is propagated throughout the Internet by using a broadcast mechanism. The broadcast message may incur a propagation delay and duplicate transmissions. The total propagation delay is assumed to be a combination of transmission time and computational time for data verification. A mathematical programming model is formulated to address the secure broadcast problem as a minimum spanning tree problem. The objective is to minimize the processing and transmission delay through reduced duplicate transmissions. Computational experiments demonstrate proof of concept to adopt blockchain techniques. The dynamic AAA architecture and path selection enable the blockchain operator to efficiently make decisions and achieve more secure services.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Kai Fan, Yanhui Ren, Zheng Yan, Shangyang Wang ¡ 6 authors
The era of information has arrived. As an important part of new generation of information technology., Internet of Things (IoT)., which is developing rapidly., requires higher and higher time accuracy. However, the malicious nodes located in network can influence the time synchronization. The security issue of time transfer and consistency is critical and challenging. In this paper, we propose a secure scheme based on blockchain to solve the problem of time announcement in IoT. In this distributed network, a closed blockchian to record and broadcast time is utilized, which minimize attacks from external environments. Moreover, this scheme has the advantage of adapting the changes of network topology. By employing POS consensus mechanism, time synchronization can be implemented efficiently. At last, the analysis results show that this secure scheme can be achieved with high efficiency and less communication cost.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Many civil engineering malpractices can be avoided if there are timely, transparent, and unalterable records of these activities. This paper describes an approach to achieve this purpose with blockchain technology. A novel blockchain system designed to avoid high volatility in token price and encourage public participation in maintaining the ledger is introduced. Civil engineering and construction are the first testing fields for the system. It is anticipated that the system, after successfully implemented, can extend its scope to other areas as well.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
This publication explores global problem areas where properties offered by Blockchain provide workable solutions for the existing widely unsolved problems of Accountability, Traceability, Identification, Visibility vs. Privacy, and Connection of Non-Deterministic to Deterministic timed events. Using BlockChain-based transactions, we demonstrate that operations related to trust are reducible to five directly implementable cryptographic actions, which then create relationships to five categories of trust that we define in this document. The solution outlined will take the approach that the identified global problems will be solved by blockchain as cybersecurity of the future moves in a direction of individualized transactional-based security & privacy. Developers and organizations looking to implement new solutions or integrate blockchain into existing applications would be interested in this publication. Methods described provide workable solutions for implementing trust relationships using blockchain for positive use cases which can be related directly to cyber security industry solutions.
A great many cloud users face a difficult challenge in respect of the forthcoming EU General Data Protection Regulation, which comes into effect on 25th May, 2018. While all computer systems are continuously under attack, those who operate conventional distributed network systems stand a far greater chance of being able to demonstrate compliance than those who use cloud based systems. The main reason for this discrepancy between the two approaches is down to the as yet unsolved cloud forensic problem, meaning many cloud users will be completely unable to demonstrate compliance with the new regulation, thus exposing themselves to potentially massive fines after 25th May. We consider the possible use of a crypto-currency based mechanism to address the as yet unsolved cloud forensic problem. Crypto-currencies are becoming a global phenomenon, gaining more attention from media, venture capitalists, financial and government institutions. We focus on the operational risk and the market risk related to crypto-currencies, especially the dominating Bitcoin. Operational risk encompasses the actions that undermine the technological infrastructure and security assumptions of crypto-currencies. We discuss how blockchain technology could improve the efficiency of financial infrastructures, as well as the inevitable vulnerabilities of operational risk of software, open-source governance, and code maintenance. We summarise the literature findings on the co-movement of crypto- currencies with different currencies, indices, and commodities, to show the role of crypto-currency as a commodity, currency, or a speculative investment under portfolio diversification theory. Particularly now that we have seen successful attacks on crypto- currencies in action, it is important to understand where these weaknesses lie, and to endeavour to find out to what extent the use of such technology might expose companies using this technology for GDPR compliance. In the light of the robustness of this approach, we consider whether the underlying blockchain technology could, in turn, be practically applied to addressing the cloud forensic problem. This paper looks at the pros and cons of the blockchain/bitcoin approach, seeking to identify weaknesses, potential benefits offered versus the additional resource costs/latency involved, and considers whether such an approach might be used to secure cloud forensic trails.
Jun Duan, Alexei Karve, Vugranam C. Sreedhar, Sai Zeng
Business interest in blockchain technology is increasing due the potential for change that it offers. Large scale adoption in enterprise IT environments brings about a need for service management and DevOps processes for blockchain deployments. Nodes in the network may fail or be taken down for maintenance requiring visibility across hybrid, traditional, cloud enabled and cloud native deployments. Service management is necessary to ease deployment woes for those looking to install code within their own data centers on-premises or on dedicated cloud servers and further to handle the life cycle of the deployments that includes security patches, critical updates, upgrades, change management and restarting services. In this paper, we provide a mechanism to optimally perform such operations with no disruption to the consensus and transactions for such emerging blockchain applications.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
With the development of Internet of Things (IoT) and blockchain technologies, people find more and more blockchain applications in the IoT domain. While it is reasonable that IoT systems use hierarchical network structures, their sheer large scales may lead to hundreds or even thousands of non-leaf nodes, which may serve as full nodes when participating in IoT blockchains. From IoT blockchain design perspective, it is important to understand the scalability of the energy consumption feature of IoT blockchains. In our research we have collected real-world data that reflect the energy consumption features of several consensus algorithms of blockchain. In this work-in-progress paper, we report our results based on linear regression models. These models provide reference estimations of the energy consumption impact in designing blockchains for IoT systems.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Harsha S. Gardiyawasam Pussewalage, Vladimir Oleshchuk
Modern electronic healthcare (e-health) settings constitute collaborative environments requiring sophisticated fine-grained access control mechanisms to cater their access demands. Access delegatability is quite crucial to realize fine-grained, flexible access control schemes compatible with such environments. In this paper, we addressed this issue through proposing an attribute based access control scheme integrated with controlled access delegation capabilities suitable for a multi-domain e-health environment. We have utilized the blockchain technology to manage attribute assignments, delegations as well as revocations. The scheme enables delegations in a controlled manner without jeopardizing the security of the system. The control is achieved via granting each delegating user the capability of controlling the subsequent delegations made by the delegatee as well as limiting the length of a chain of delegations. Furthermore, it is equipped with a superior attribute revocation mechanism and induces substantially lower key management overhead to the end-users in comparison to the existing access control schemes with delegatability.
In recent times, data has become an inevitable factor in cloud computing. The word data eventually seeks its issue on privacy and security. With the rise of new technologies, the need for data storage has increased. Massive increase in the datasets has led to the evolution of cloud storage. The benefits of cloud computing are immense, but on the contrary there is an increasing risk to the security of the data stored in the cloud. This paper deals with a survey on the security issues which highlights the effectiveness of security that has been implied in the forms of cloud computing and blockchain technologies. The survey also includes a deep understanding of a PoW-based blockchain model using the blockchain technology. The idea behind this work is to provide a detailed survey about the blockchain technology which is growing tremendously.
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
The Plug-and-Produce concept requires that after connecting a new module to a system, the exchange of the configuration data takes place. As further operation of the system depends on this initialization procedure, it is necessary to ensure that the data presented by the system and the newly attached component is authentic. Therefore, we propose a new concept for secure Plug-and-Produce functionality, which exploits the combination of the Asset Administration Shell (AAS) and Blockchain technology. On the one hand, the AAS shall be responsible for presenting uniform and standardized configuration data as well as for storing and managing Blockchain. On the other, Blockchain shall ensure authenticity and integrity of the configuration data.
Nowadays many applications have employed the blockchain technology from sam- ple cryptocurrency to smart contracts applications. Bitcoin is one of the cryp- tocurrency application and digital payment system. It is considered as the first decentralized digital currency system. It was invented by unidentified person or group under the name of Satoshi Nakamoto in 2009 (Nakamoto, 2008). The most three features should be achieved by Bitcoin are decentralized, users anonymity, and consensus. In order to achieve these vital features the Bitcoin system should be provably secure against the attacks. Many attacks have been proposed to change unfairly the reward system of the mining pool and allow the malicious miners to earn undue wage. Selfish Attack, Block Withholding (BWH) Attack and Fork- ing After Withholding (FAW) Attack are three attacks which abusing the reward system and letting the infiltration miners to receive un unearned profits and as a sequence this will affect the decentralized feature of the Bitcoin system. Some studies proposed a solution for Selfish Attack and Block Withholding attack such (Eyal and Sirer, 2014b) and (Bag et al., 2017). FAW attack is first introduced by (Kwon et al., 2017) where this attack combines two attacks: Selfish and BWH attacks. In order to come up with a solution for FAW attack (Kwon et al., 2017) propose partial countermeasures for preventing their FAW attack. However, their solution is neither perfect nor practical. Therefore this study addresses this attack and analyzes its strategy then come up with a prevention solution. The result of this study shows that our prevention solution is practical and more effcient.
The topic of blockchain has been inundated with the fanaticism of cryptocurrencies' enthusiasts in recent years. In fact, the theory of blockchain and technologies behind are more worthy to be discussed to bring revolution to nowadays business operation. In this paper, we conduct an interdisciplinary study on business logistics as well as the cutting edge information technologies. We discuss the ongoing projects of blockchain in business industry, and then we propose our assessment model and blockchain framework to seek an enhanced metric for delivery performance with real-time feature and higher accuracy. Based on the our analysis, we identify the shortcomings of traditional assessment on delivery performance in contemporary global supply chain management and we discuss the potential benefits brought by adoption of our proposed framework.
This paper proposes a JPEG-blockchain framework for trusted media transaction. The new distributed and tamperproof framework intends to aid an emerging JPEG Privacy and Security standard. The blockchain network records any media transaction with necessary information related to intellectual property rights, access control rules and content signature. The content signature, generated by compressed sensed samples or low-resolution, low bit-rate compression is used to verify the image integrity and authenticity. We propose that every blockchian record, linked to a unique transaction hash, is encapsulated within the metadata contained in the JPEG box structure. As an example use case we have chosen the GLAM (Galleries, Libraries, Archives and Museums) sector due to its emerging need. This paper presents the proof of the concept and reports preliminary infrastructural development.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
To ensure integrity, trust, immutability and authenticity of software and information (cyber data, user data and attack event data) in a collaborative environment, research is needed for cross-domain data communication, global software collaboration, sharing, access auditing and accountability. Blockchain technology can significantly automate the software export auditing and tracking processes. It allows to track and control what data or software components are shared between entities across multiple security domains. Our blockchain-based solution relies on role-based and attribute-based access control and prevents unauthorized data accesses. It guarantees integrity of provenance data on who updated what software module and when. Furthermore, our solution detects data leakages, made behind the scene by authorized blockchain network participants, to unauthorized entities. Our approach is used for data forensics/provenance, when the identity of those entities who have accessed/ updated/ transferred the sensitive cyber data or sensitive software is determined. All the transactions in the global collaborative software development environment are recorded in the blockchain public ledger and can be verified any time in the future. Transactions can not be repudiated by invokers. We also propose modified transaction validation procedure to improve performance and to protect permissioned IBM Hyperledger-based blockchains from DoS attacks, caused by bursts of invalid transactions.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Usage-based Insurance (UBI) for vehicles determines the insurance premiums according to actual usage and driving pattern. It can significantly reduce insurance costs for safe drivers, however, UBI schemes require detailed driving data to determine the insurance premiums, which may lead to serious privacy breach for drivers. Moreover, most existing UBI schemes require a centralized insurance company as the intermediary to manage insurances. Such a centralized solution incurs too much monetary costs as well as time cost. In this paper, we propose PRIDE, a privacy-preserving and decentralized UBI scheme using the blockchain to record encrypted driving data, and the smart contract running on the blockchain to calculate insurance premiums. Different from existing UBI schemes, PRIDE achieves security and privacy without relying on any centralized party or any trusted/tamper-proof hardware. We have analyzed security of PRIDE and evaluated its performance. The results show that PRIDE is very efficient in processing UBI insurances - each insurance request can be processed in about 898ms.
Jul 1, 2018¡2018 15th International Conference on Electrical Engineering/Electronics, Computer, Telecommunications and Information Technology (ECTI-CON)
Currently, government identification systems are still underdeveloped. The government has adopted computer technology to serve the policy of Thailand 4.0. Thai national ID still segmented and distributed between government agencies and has no centralization, and it brings bad experience to the users because each service must be registered and the users have to remember the username and password for every service. We demonstrated Thailand national Digital ID Framework based on Blockchain (NIDBC) to help improve digital identity government service to simple single sign-on and kept preserving privacy by providing personal information to service only when users grant permission for each service. In addition, the system is secure because the data is distributed to each node, making the attackers hard to attack or edit information. The security properties of the proposed protocol have been verified using Scyther tool and are presented here with results.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
In order to solve the problem of illegal memberâs tracking attack, which caused by the vehicle unitsâ privacy disclosure in vehicular ad hoc networks (VANETs), a vehicle identity authentication protocol based on lightweight group signature was proposed by analysis of topology and communication characteristics of VANETs in this paper, which can authenticate the vehicles anonymously in a fast and efficient way. The protocol has five stages. In the initialization phase, the public/private key pairs and system parameters of the group were generated by the VANETs system, then the group public key and system parameters were distributed to the on-board units by the roadside auxiliary facilities. The group private key was kept by the group manager. When a vehicle unit entered VANETs, the unitâs own identity was submitted to the group manager by the blind signature. A group certificate would be distributed to the vehicle unit by the group manager when authentication passed. In the cooperative communication stage, the vehicle member who owned the group certificates signed the state information with the valid certificate and group public key, then sent it to the nearby vehicle units by the car sensors, and achieved cooperative driving with surrounding vehicles. In the message verification stage, only can the legal vehicle members open the received status information by using group public key, but couldnât know the true identity of the message sender. In this way, the anonymous communication among vehicles was realized. In the stage of signature verification, when a vehicle unit broadcasted a false message for the purpose of exclusively using road resource and caused traffic accident, the group manager can open the signature of the message by using the group private key, and traversed the corresponding vehicle members to carry on the accountability. The innovation of the paper was the usage of improved lightweight group signature technology, which could ensure that the length of group public key and group signature didnât depend on the number of group members. Zero knowledge proof was also used as a means of membership authentication which improved the speed of authentication among the members. The security of the protocol was analyzed and proved mathematically in this paper, and a LAN simulation platform composed of 100 PC machines was built to simulate the cooperative communication among vehicle units in VANETs. The experimental results showed that authentication time of the protocol was about 7 ms among 100 vehicle users. The performance of the proposed protocol is superior to the contrasted schemes. It greatly reduced the storage and calculation burden of the vehicle units during the process of identity authentication.
The study will be the first to offer empirical justification for time-varying stochastic volatility in Bitcoin returns. Specifically, it tests for time variation in both the trend and transitory components of the stochastic volatility using the unobserved components model that accounts for same. Thereafter, it calculates the Bayes factor using the approach of Chan (2018) which involves the Savage-Dickey density ratio in order to avoid the computation of the marginal likelihood. The results overwhelmingly support at least one time-varying stochastic volatility component in Bitcoin returns and the transitory component is favoured in this regard. These results are robust to different data frequencies.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Despite that the cloud computing is considered as the panacea of processing and analyzing IoT data, it shows drawbacks in many other aspects like latency, bandwidth, and mobility when transferring data from connected devices to the cloud. The fog computing paradigm extends the cloud and refers to a geographically distributed computing paradigm at the edge of loT networks. However, realizing fog computing still has a long way to go, especially when it comes to security in the context of loT unconventional characteristics such as scalability, heterogeneity, mobility and limited resources. In addition, applying social network principles to the loT seems to be appealing to build the Internet of Things as a network of peer-to-peer networks. In this paper, we introduce a hybrid architecture for the Internet of things, combing fog computing to ensure security in the trustless loT environment. By enabling our fog computing architecture with blockchain-based social networks, users could easily manage smart objects via establishing tamper-proof digital identities in a trustless environment and build a new class of authentication and authorization mechanisms for the loT. We also demonstrate and analyze the feasibility of our architecture with a prototype.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Significant improvements have been made in the way several businesses are conducted due to the influx of blockchain technology, which is a paradigm shift in research these days. Because of the several benefits this technology brings, including scalability, immutability, and the ability to secure data exchange among parties, data transfer becomes easier and simpler between entities. Automobile renting is a major business nowadays. Renting an auto summons numerous frameworks over a chain of procedures - including confirming the lessee's financial status, driving qualifications, accessible vehicle stock and car features. Leasing companies and financiers, however, need to recognize what is happening to the vehicles after the rent is agreed upon. There is also the problem of time consumption, as the traditional car lease process passes through a lot of stages before completion. The blockchain innovation can keep things up to speed with smart contracts. In this paper, we develop a car lease platform that is solely based on blockchain technology. The underlying principle utilized in this system is the smart contract, which is a programmable script that enforces decisions on all transactions made on the system, and also applies penalties to perpetrators. We evaluate the efficiency of our system by measuring the latency and throughput, and make comparisons with other related systems. Results indicate our system outperforms the others.
Kyoungmin Kim, Youngin You, Mookyu Park, Kyungho Lee
Distributed Denial of Service (DDoS) attacks are intense and are targeted to major infrastructure, governments and military organizations in each country. There are a lot of mitigations about DDoS, and the concept of Content Delivery Network (CDN) has been able to avoid attacks on websites. However, since the existing CDN system is fundamentally centralized, it may be difficult to prevent DDoS. This paper describes the distributed CDN Schema using Private Blockchain which solves the problem of participation of existing transparent and unreliable nodes. This will explain DDoS mitigation that can be used by military and government agencies.
Jul 1, 2018¡2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
This article explores the potential probability of blockchain technology in assisting enhanced application for ridesharing services. The development of the sharing economy brings numerous novel ideas and generates many innovative businesses. However, the wide range of the sharing economy also causes disputes and questions, including labor, organizations, and regulations. Blockchain technology (hereafter blockchain) can facilitate virtual and physical networking symbiosis. This situation would motivate a new model of governance, namely, the bottom-up organization. Therefore, the blockchain would push governances and citizens to reorganize current complicated systems. In this work, we demonstrate SmaRi to achieve a decentralized transaction system combined with the blockchain as our case. Our proposed system provides users with automated execution and immutable record and distributes more decision-making power from centralized organization to users. These measures may fulfill the core value of the sharing economy through peer-to-peer exchanges. Furthermore, we illustrate how SmaRi can be combined with current management systems. By linking with the original system, SmaRi can establish comprehensive functions quickly. In this work, we can expect modern society to become closer to future smart cities.