Roberto Di Pietro, Xavier Salleras, Matteo Signorini, Erez Waisbard
One of the biggest challenges for the Internet of Things (IoT) is to bridge the currently fragmented trust domains. The traditional PKI model relies on a common root of trust and does not fit well with the heterogeneous IoT ecosystem where constrained devices belong to independent administrative domains. In this work we describe a distributed trust model for the IoT that leverages the existing trust domains and bridges them to create end-to-end trust between IoT devices without relying on any common root of trust. Furthermore we define a new cryptographic primitive, denoted as obligation chain designed as a credit-based Blockchain with a built-in reputation mechanism. Its innovative design enables a wide range of use cases and business models that are simply not possible with current Blockchain-based solutions while not experiencing traditional blockchain delays. We provide a security analysis for both the obligation chain and the overall architecture and provide experimental tests that show its viability and quality.
David Vangulick, Bertrand Cornélusse, Damien Ernst
Energy communities and peer-to-peer energy exchangesare expected to play an important role in the energy transition. In this context, the blockchain approach can be employed to foster this decentralized energy market. In [1],we evaluated several designs that should allow a Distribution System Operator (DSO) to accept peer-to-peer energyexchanges supported by this technology. This acceptanceis based on criteria such as a strong link with the wholesale/retail market, the resilience of the consensus to approve a block, the accuracy, traceability, privacy and security of the proposed schemes. We concluded that proof-ofstake (PoS), where the choice of node that creates a block isbased on a measure of its wealth, is the only method to fulfill these requirements. In the present paper, we clarify theidentification and estimation of bidding models to ensurethat the PoS that we are developing is a correct responseto two major issues with the PoS methodology, namely theconcentration of wealth and the ”nothing to stake” issue.1
In year 2017, Bitcoin attracted most investors because high return of investment. The system for Bitcoin transaction is known as blockchain. The blockchain is blocks of transaction history that shared publicly using secured cryptography. Each block contains the previous transaction information, timestamp and new transaction data in secured cryptographic hash programming language. This paper evaluates the Bitcoin framework whether the security of the system is satisfied with a definition of reliable computer system. In the same time, this paper discovers the reliability of the programming process that involved in blockchain system. The finding of this paper will help investors to understand the blockchain system properly in developing better understanding of cryptocurrency framework. The better understanding of the blockchain will help investors making proper decision in their investment portfolio to gain better profit and preventing loss.
Zijian Bao, Wenbo Shi, Debiao He, Kim‐Kwang Raymond Choo
There has been increasing interest in the potential of blockchain in enhancing the security of devices and systems, such as Internet of Things (IoT). In this paper, we present a blockchain-based IoT security architecture, IoTchain. The three-tier architecture comprises an authentication layer, a blockchain layer and an application layer, and is designed to achieve identity authentication, access control, privacy protection, lightweight feature, regional node fault tolerance, denial-of-service resilience, and storage integrity. We also evaluate the performance of IoTchain to demonstrate its utility in an IoT deployment.
Jun 6, 2018·World Academy of Science, Engineering and Technology, International Journal of Electrical, Computer, Energetic, Electronic and Communication Engineering
The paper analyzes the specific nature of high-tech systems in IT area in terms of the transition to the digital economy (Digital Economy of the Russian Federation program). The research identifies the characteristics of legal regulation of databases, distributed ledgers, and blockchain technology. The author determines that the legal regime of databases is admissible with regard to the above-mentioned systems. The study reveals the aspects of special sectoral laws and regulations applied to databases in order to introduce distributed ledgers and blockchain technology. The research considers the dual nature of database laws governing blockchain technology in different ways. The author concludes that laws and regulations concerning databases can be implemented to introduce distributed ledgers and blockchain technology considering their specific legal nature for particular legal relations.
The purpose of this article is to determine how the use of a bitcoin as an instrument of payment can affect the system of international financial payments and the banking system. The method of critical analysis of scientific and methodological literature is used and the materials of research executed by leading experts in the fields of international finance and IT in 2009-2017 are summarized. A bitcoin can become a serious competitor to banks, payment systems such as SWIFT in the implementation of major cross-border payments. It is even compared with gold because there is no risk for the counterparty in operations with it. We suggest that a bitcoin is an outstanding digital technology which can fundamentally change the world banking system, payment settlements and the global economy. The article proposes a classification of advantages, disadvantages and prospects of using a bitcoin as a means of payment between large financial institutions and banks. The perspective of increased competition between leading international payment systems in conducting large cross-border payments is substantiated. The prospects of further studies are determined. How do central banks need to reform the system of international financial payments in view of the inevitable introduction of cryptocurrency? How to implement new financial instruments based on blockchain technology and a bitcoin? What changes in legislation should be made to get the names of buyers and sellers of bitcoins, which will help to reduce financing of illegal activities?
Digital identity is unsolved: after many years of research there is still no trusted communication over the Internet. To provide identity within the context of mutual distrust, this paper presents a blockchain-based digital identity solution. Without depending upon a single trusted third party, the proposed solution achieves passport-level legally valid identity. This solution for making identities Self-Sovereign, builds on a generic provable claim model for which attestations of truth from third parties need to be collected. The claim model is then shown to be both blockchain structure and proof method agnostic. Four different implementations in support of these two claim model properties are shown to offer sub-second performance for claim creation and claim verification. Through the properties of Self-Sovereign Identity, legally valid status and acceptable performance, our solution is considered to be fit for adoption by the general public.
Open access
3 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Intelligence is one of the most important aspects in the development of our future communities. Ranging from smart home to smart building to smart city, all these smart infrastructures must be supported by intelligent power supply. Smart grid is proposed to solve all challenges of future electricity supply. In smart grid, in order to realize optimal scheduling, an SM is installed at each home to collect the near-real-time electricity consumption data, which can be used by the utilities to offer better smart home services. However, the near-real-time data may disclose a user's private information. An adversary may track the application usage patterns by analyzing the user's electricity consumption profile. In this article, we propose a privacy-preserving and efficient data aggregation scheme. We divide users into different groups, and each group has a private blockchain to record its members' data. To preserve the inner privacy within a group, we use pseudonyms to hide users' identities, and each user may create multiple pseudonyms and associate his/ her data with different pseudonyms. In addition, the bloom filter is adopted for fast authentication. The analysis shows that the proposed scheme can meet the security requirements and achieve better performance than other popular methods.
Development of secure methods for storing log files is of tremendous importance for cyber security. One of the first actions by a hacker upon penetrating a machine is editing the log files to remove evidence of their presence. We propose to improve the security of these log files through a blockchain based solution. We show how our solution can be used to help organizations to mutually protect their sensitive log data even if some of them are compromised. Our solution allows data confidentiality between the collaborative parties.
Blockchains such as Bitcoin and Ethereum execute payment transactions securely, but their performance is limited by the need for global consensus. Payment networks overcome this limitation through off-chain transactions. Instead of writing to the blockchain for each transaction, they only settle the final payment balances with the underlying blockchain. When executing off-chain transactions in current payment networks, parties must access the blockchain within bounded time to detect misbehaving parties that deviate from the protocol. This opens a window for attacks in which a malicious party can steal funds by deliberately delaying other parties' blockchain access and prevents parties from using payment networks when disconnected from the blockchain.
In this policy review, we analyze two payments for hydrological services matching programs operating in the Antigua water basin in the state of Veracruz, Mexico. Mexico’s Matching Program was created to transition from the national payments for hydrological services program to programs that would be financed by local governments, local water users and the private sector. Based on the analysis of organizational documents and key informant interviews with institutional actors, we describe the distinctive origins and organizational structures of these two programs, and how these differences have led to unique challenges for each program. We conclude that payments for ecosystem services programs that incorporate community-level organization and extensive technical assistance, along with expanded direct payments from ecosystem service users, have the greatest potential for achieving long-term sustainability.
Conservation, Biodiversity, and Resource Management
Petar Tsankov, Andrei Dan, Dana Drachsler Cohen, Arthur Gervais · 6 authors
Permissionless blockchains allow the execution of arbitrary programs (called smart contracts), enabling mutually untrusted entities to interact without relying on trusted third parties. Despite their potential, repeated security concerns have shaken the trust in handling billions of USD by smart contracts. To address this problem, we present Securify, a security analyzer for Ethereum smart contracts that is scalable, fully automated, and able to prove contract behaviors as safe/unsafe with respect to a given property. Securify's analysis consists of two steps. First, it symbolically analyzes the contract's dependency graph to extract precise semantic information from the code. Then, it checks compliance and violation patterns that capture sufficient conditions for proving if a property holds or not. To enable extensibility, all patterns are specified in a designated domain-specific language. Securify is publicly released, it has analyzed >18K contracts submitted by its users, and is regularly used to conduct security audits by experts. We present an extensive evaluation of Securify over real-world Ethereum smart contracts and demonstrate that it can effectively prove the correctness of smart contracts and discover critical violations.
Nowadays, Blockchain Technology and Cryptocurrency have gained the attention of world media, both technological and business sectors. This study assessed the importance of implementing Cryptocurrency project in Ethiopia by collecting empirical data. "Cryptocurrency is a digital currency in which encryption techniques are used to regulate the generation of units of currency and verify the transfer of funds, operating independently of a central bank "(Cambridge Dictionary, 1995). Cryptocurrency uses the technology called Blockchain, Blockchain is a shared ledger or a continually updated list of transaction. This ledger keeps every transaction that has ever happened in a completely decentralized form and distributed among users. Because of that, third parties such as (Bank and central bank etc.) who were traditionally in charge of the ledger are no longer needed. The technology is huge, and it has applications not only in currency but in other industries such as land registration, voting and smart contracts. This study employed a case study which is used to "provide quantitative or numerical description of trends, attitudes and opinions of participants, hence participants were selected based on their knowledge and experience of the technology. The source of data were both primarily and secondary, such as, published or unpublished and public or private documents. The collected Cross-sectional data were organized and analyzed through descriptive data analysis technique so that the research can come to a conclusion and derive important information. The research finding shows the important role of Cryptocurrency and its backbone Blockchain technology to minimize the current Ethiopia's foreign currency problems and to further help the country meet its millennial development goals.
Internet is a system of inter-connected computer networks and is today’s significant platform of information & transmission. Its far-flung utilization has led to its entrance in the sphere of trade and commerce, which, in turn, has given escalate to cyber crimes. It is the troubling for parliament as well as law enforcement agencies because of absolute wideness and outreach of cyber space. So to tackle this, cyber security is an essential component to be considered if any person wants to get protected from mischievous people and malicious software from the internet. Internet is the one tool which gives rise to various threats to the computer and often these threats are intentional and developed by people those who are having malicious intention. Before the commencement of Information Technology Act, 2000, the Act which was regulating such crimes was The Indian Penal Code, 1860. But The Indian Penal Code, 1860 was found inadequate to serve and regulate the demands of new crimes that were rising from widespread Internet expansion. Moreover some of the traditional crimes such as fraud, espionage, solicitation, conspiracy, securities etc. are now being performed through Internet which necessitates a new legislation to check them. So this was lead to enactment of I.T Act, 2000 and motive behind this act was prevention and control of cyber crimes. But after commencement of this act, it turned indispensable to institute certain amendments in the various provisions of IPC, 1860 and The Indian Evidence Act, 1872, so that it could meet the prerequisite of the cyber space crimes. The I.T. Act, 2000 is based on UNCITRAL Model on e-commerce, 1996. The methodology used in the research on this study is exploratory-study and case-study approach and input from certain study materials, newspapers and internet.
Blockchain technologies, such as smart contracts, present a unique interface for machine-to-machine communication that provides a secure, append-only record that can be shared without trust and without a central administrator. We study the possibilities and limitations of using smart contracts for machine-to-machine communication by designing, implementing, and evaluating AGasP, an application for automated gasoline purchases. We find that using smart contracts allows us to directly address the challenges of transparency, longevity, and trust in IoT applications. However, real-world applications using smart contracts must address their important trade-offs, such as performance, privacy, and the challenge of ensuring they are written correctly.
Since most of the organizations are going online these days, such organizations have become dependent to their data over the internet. Hence, it has become more critical to secure data by taking adequate security measures. One of the measures that can be taken to secure data from attackers and intruders is access control. Along with the changing trend, even the data used is evolving. `Bitcoin' is the new data that has gained importance in the market. Every third person in the world has Bitcoin to their share. So it becomes important to secure Bitcoin and the information it possesses. Blockchain helps in preventing Bitcoin - the digital currency and therefore stores the information securely. In this paper, we survey and study how the rising of Blockchain technology has affected traditional transactional banking and also outline possible directions for future research.
Jun 1, 2018·2018 5th IEEE International Conference on Cyber Security and Cloud Computing (CSCloud)/2018 4th IEEE International Conference on Edge Computing and Scalable Cloud (EdgeCom)
Information Centric Networking (ICN) achieves high efficient via in-networking cache and direct object retrieval, i.e., content can be replicated and cached at any network nodes. However, the content is out of owner's control after published. With access control issues becoming more prominent, we propose combining the blockchain with traditional access control schemes in this paper. As all we know, blockchain has become one of the most popular technologies in recent years. This technology has been applied to various cryptographic currency, such as Bitcoin, Litecoin and so on. Due to its decentralized and untempered paradigm, using blockchain in access control is an ideal scheme. We utilize xor-based encoding/decoding scheme to realize fast encryption and decryption, which would save content provider plenty of time. Especially, when the content provider is off-line, our scheme could realize that authorized users also can obtain decryption information related contents. The security analysis proves that our access control framework is pretty safe.