Fergus Dall, Gabrielle De Micheli, Thomas Eisenbarth, Daniel Genkin · 7 authors
Intel Software Guard Extensions (SGX) allows users to perform secure computation on platforms that run untrusted software. To validate that the computation is correctly initialized and that it executes on trusted hardware, SGX supports attestation providers that can vouch for the userâs computation. Communication with these attestation providers is based on the Extended Privacy ID (EPID) protocol, which not only validates the computation but is also designed to maintain the userâs privacy. In particular, EPID is designed to ensure that the attestation provider is unable to identify the host on which the computation executes. In this work we investigate the security of the Intel implementation of the EPID protocol. We identify an implementation weakness that leaks information via a cache side channel. We show that a malicious attestation provider can use the leaked information to break the unlinkability guarantees of EPID. We analyze the leaked information using a lattice-based approach for solving the hidden number problem, which we adapt to the zero-knowledge proof in the EPID scheme, extending prior attacks on signature schemes.
OpenLitterMap rewards users with Littercoin for producing open data on litter. Open data on the geospatial characteristics of litter provide means of invoking and evaluating responses to plastic pollution. OpenLitterMap currently works as a web app on all devices with native mobile apps in development. The stack includes the integration of the Laravel PHP Framework on the backend; Vue for frontend reactivity; NativeScript-Vue for mobile apps; Bulma for CSS; Leaflet for web-mapping; Turf.js for geospatial analysis; the Ethereum Blockchain for tokenization; Stripe; ChartJS; AWS; and more. Anywhere from a single cigarette butt to the contents of an entire beach or street clean can be logged in a single geotagged photo. Alternatively, a simple index may be used if litter is incalculable. The open data includes an increasing 100+ pre-defined types of litter; 20+ corporate brands; verification status; coordinates; timestamp; phone model; the latest OpenStreetMap address at each location; and the litter presence as a Boolean. To date, 100% of all submitted data (~ 8200 photos, ~ 28,000 litter from over 150 contributors) has been manually verified which is being used to develop machine learning algorithms.
Blockchain recording of digital transactions could have many healthcare applicationsâfrom patient records to tracing pillsâreports Stephen Armstrong , but is its potential overhyped? The cryptocurrency boom may be over, according to recent reports,1 but interest in its underlying technology, the blockchain, is far from it. Digital health experts are starting to wonder if blockchain could solve NHS data problems, and the UKâs first trial of blockchain technology to create and support electronic health records will begin in July at a southwest London general practice group (box 1).8 Box 1 ### Blockchain examples in health #### Countering counterfeits âThe blockchain provides a granular trail of a productâs journey,â explains Peter Bryant, chief operating officer of UK based global drug tracking system FarmaTrust. With the Drug Supply Chain Security Act in the US rolling out between 2015 and 2023,2 and the equivalent Falsified Medicines Directive in the EU coming into force next spring,3 all pharmaceutical products will require a label with a unique serial number, name, lot number, batch number, and expiry date. FarmaTrust is talking to 13 manufacturers as well as the Mongolian government to offer a blockchain tracking system that can link with existing databases. The company is also working with medicinal poppy and marijuana growers and the government in Thailand to ensure that products are traceable and the farmers are taxed on profits. #### Patient records Technology company Medicalchain is partnering with southwest London general practice group, The Groves, in the UKâs first trial of blockchain to create and support electronic health records.4 It offers registered patients a free digital wallet to hold and manage access to their health records. The platform includes a cryptocurrencyâMedicalchainâs MedTokensâto encourage patients to participate, which they can use as private patients to pay for telemedicine services. Elsewhere, MIT research project MedRec is trialling a health records system that leaves patient ⊠RETURN TO TEXT
Edgar GonzĂĄlez FernĂĄndez, Guillermo Morales-Luna, FeliĂș Sagols Troncoso
Zero-Knowledge Proofs ZKP provide a reliable option to verify that a claim is true without giving detailed information other than the answer. A classical example is provided by the ZKP based in the Graph Isomorphism problem (GI), where a prover must convince the verifier that he knows an isomorphism between two isomorphic graphs without publishing the bijection. We design a novel ZKP exploiting the NP-hard problem of finding the algebraic ideal of a multivariate polynomial set, and consequently resistant to quantum computer attacks. Since this polynomial set is obtained considering instances of GI, we guarantee that the protocol is at least as secure as the GI based protocol.
George Kappos, Haaroon Yousaf, Mary Maller, Sarah Meiklejohn
Among the now numerous alternative cryptocurrencies derived from Bitcoin, Zcash is often touted as the one with the strongest anonymity guarantees, due to its basis in well-regarded cryptographic research. In this paper, we examine the extent to which anonymity is achieved in the deployed version of Zcash. We investigate all facets of anonymity in Zcash's transactions, ranging from its transparent transactions to the interactions with and within its main privacy feature, a shielded pool that acts as the anonymity set for users wishing to spend coins privately. We conclude that while it is possible to use Zcash in a private way, it is also possible to shrink its anonymity set considerably by developing simple heuristics based on identifiable patterns of usage.
Die Autoren gehen der Frage nach, ob KryptowĂ€hrungen als Sachen im Sinne des ZGB aufgefasst und daran namentlich Eigentumsrechte begrĂŒndet werden können. Dabei werden zunĂ€chst technische Grundlagen der sog. Blockchain-Technologie und der drei nach Markkapitalisierung grössten KryptowĂ€hrungen Bitcoin (BTC), Ethereum (Ether, ETH) und Ripple (XRP) dargestellt. Sodann wird untersucht, ob diese KryptowĂ€hrungen die Eigenschaften erfĂŒllen, welche fĂŒr die Qualifikation eines Objektes als Sache im Sinne des ZGB vorliegen mĂŒssen, und welches die Folgen einer solchen Qualifikation sind. Im Sinne einer modernen Auslegung des Sachbegriffs schliessen sich die Autoren der Auffassung an, wonach KryptowĂ€hrungen grundsĂ€tzlich als Sache und damit als Gegenstand des Eigentums zu behandeln sind.
Blockchain technology has been transforming the financial industry and has created a new crypto-economy in the last decade. The foundational concepts such as decentralized trust and distributed ledger are promising for distributed, and large-scale Internet of Things (IoT) applications. However, the applications of Blockchain beyond cryptocurrencies in this domain are few and far between because of the lack of understanding and inherent architectural challenges. In this paper, we describe the opportunities for applications of blockchain for the IoT and examine the challenges involved in architecting Blockchain-based IoT applications.
In the financial systems of the modern era, trust has always been a missing entity; concentrations of power and trust have given birth to numerous breakdowns. To resolve the problems at this end, the paper attempts for a solution using Blockchains, a data structure that allows for the creation of cryptically secured distributed tamperproof ledgers. The paper discusses the data structure and further disserts on the case study in consideration.
The past decade has witnessed the rapid evolution in blockchain technologies, which has attracted tremendous interests from both the research communities and industries. The blockchain network was originated from the Internet financial sector as a decentralized, immutable ledger system for transactional data ordering. Nowadays, it is envisioned as a powerful backbone/framework for decentralized data processing and data-driven self-organization in flat, open-access networks. In particular, the plausible characteristics of decentralization, immutability, and self-organization are primarily owing to the unique decentralized consensus mechanisms introduced by blockchain networks. This survey is motivated by the lack of a comprehensive literature review on the development of decentralized consensus mechanisms in blockchain networks. In this paper, we provide a systematic vision of the organization of blockchain networks. By emphasizing the unique characteristics of decentralized consensus in blockchain networks, our in-depth review of the state-of-the-art consensus protocols is focused on both the perspective of distributed consensus system design and the perspective of incentive mechanism design. From a game-theoretic point of view, we also provide a thorough review of the strategy adopted for self-organization by the individual nodes in the blockchain backbone networks. Consequently, we provide a comprehensive survey of the emerging applications of blockchain networks in a broad area of telecommunication. We highlight our special interest in how the consensus mechanisms impact these applications. Finally, we discuss several open issues in the protocol design for blockchain consensus and the related potential research directions.
The past decade has witnessed the rapid evolution in blockchain technologies, which has attracted tremendous interests from both the research communities and the industry. The blockchain network was originated in the Internet finical sector as a decentralized, immutable ledger system for transactional data ordering. Nowadays, it is envisioned as a powerful backbone/framework for decentralized data processing and data-driven self-organization in flat, open-access networks. In particular, the plausible characteristics of decentralization, immutability and self-organization are primarily owing to the unique decentralized consensus mechanisms introduced by blockchain networks. This survey is motivated by the lack of a comprehensive literature review on the development of decentralized consensus mechanisms in blockchain networks. In this survey, we provide a systematic vision of the organization of blockchain networks. By emphasizing the unique characteristics of incentivized consensus in blockchain networks, our in-depth review of the state-of-the-art consensus protocols is focused on both the perspective of distributed consensus system design and the perspective of incentive mechanism design. From a game-theoretic point of view, we also provide a thorough review on the strategy adoption for self-organization by the individual nodes in the blockchain backbone networks. Consequently, we provide a comprehensive survey on the emerging applications of the blockchain networks in a wide range of areas. We highlight our special interest in how the consensus mechanisms impact these applications. Finally, we discuss several open issues in the protocol design for blockchain consensus and the related potential research directions.
This paper proposes a novel adaptation of blockchain technology to information exchanges among vehicles traveling in a platoon. The aim is to protect platoon member privacy and security while providing a rapid sharing of telemetry data. We have identified key protocols for a distributed cryptographic authentication among vehicles in transit within a platoon. This work heralds consideration of cyber-attack types on platoons and our proposed remedies.
Hyperledger Fabric (HLF) is a modular and extensible permissioned blockchain platform released to open-source and hosted by the Linux Foundation. The platform's design exhibits principles required by enterprise grade business applications like supply-chains, financial transactions, asset management, food safety, and many more. For that end HLF introduces several innovations, two of which are smart contracts in general purpose languages (\emph{chaincode} in HLF), and flexible endorsement policies, which govern whether a transaction is considered valid. Typical blockchain applications are comprised of two tiers: the first tier focuses on the modelling of the data schema and embedding of business rules into the blockchain by means of smart contracts (\emph{chaincode}) and endorsment policies; and the second tier uses the SDK (Software Development Kit) provided by HLF to implement client side application logic. However there is a gap between the two tiers that hinders the rapid adoption of changes in the chaincode and endorsement policies within the client SDK. Currently, the chaincode location and endorsement policies are statically configured into the client SDK. This limits the reliability and availability of the client in the event of changes in the platform, and makes the platform more difficult to use. In this work we address and bridge the gap by describing the design and implementation of \emph{Service Discovery}. \emph{Service Discovery} provides APIs which allow dynamic discovery of the configuration required for the client SDK to interact with the platform, alleviating the client from the burden of maintaining it. This enables the client to rapidly adapt to changes in the platform, thus significantly improving the reliability of the application layer. It also makes the HLF platform more consumable, simplifying the job of creating blockchain applications.
When digital evidence is presented in front of a court of law, it is seldom associated with a scientific evaluation of its relevance, or significance. When experts are challenged about the validity of the digital evidence, the general answer is "yes, to a reasonable degree of scientific certainty". Which means all and nothing at the same time, since no scientific metric is volunteered. In this paper we aim at providing courts of law with weighted digital evidence. Each digital evidence is assigned with a confidence rating that eventually helps juries and magistrates in their endeavor. This paper presents a novel methodology in order to:
Recently, advancements in energy distribution models have fulfilled the needs of microgrids in finding a suitable energy distribution model between producer and consumer without the need of central controlling authority. Most of the energy distribution model deals with energy transactions and losses without considering the security aspects such as information tampering. The transaction data could be accessible online to keep track of the energy distribution between the consumer and producer (e.g., online payment records and supplier profiles). However this data is prone to modification and misuse if a consumer moves from one producer to other. Blockchain is considered to be one solution to allow users to exchange energy related data and keep track of it without exposing it to modification. In this paper, electrical transactions embedded in blockchain are validated using the signatures of multiple producers based on their assigned attributes. These signatures are verified and endorsed by the consumers satisfying those attributes without revealing any information. The public and private keys for these consumers are generated by the producers and endorsement procedure using these keys ensures that these consumers are authorized. This approach does not need any central authority. To resist against collision attacks, producers are given a secret pseudorandom function seed. The comparative analysis shows the efficiency of proposed approach over the existing ones.
In this article, the authors discuss the VAT treatment of sales and transfers of Bitcoin carried out in Mexico. For this purpose, they analyse the current state of Mexican law, but also review the applicable VAT regime in jurisdictions around the world, such as in Japan, Spain, Switzerland and the European Union. The authors then provide an overview of recently enacted legislation in Mexico and its foreseeable impact on the VAT treatment of Bitcoin.
Juan M. RomĂĄn-Belmonte, Hortensia De la CorteâRodrĂguez, E. Carlos RodrĂguezâMerchĂĄn
Although the best-known use of blockchain technology (BCT) is in the field of economics and cryptocurrencies in general, its usefulness is extending to other fields, including the biomedical field. The purpose of this article is to clarify the role that BCT can play in the field of medicine. We have performed a narrative review of the literature on BCT in general and on medicine in particular. The great advantage of BCT in the health arena is that it allows development of a stable and secure data set with which users can interact through transactions of various types. This environment allows the entry and operation of clinical data without compromising other sensitive data. Another important advantage of BCT is that the entire network is decentralized and is maintained by the users themselves; thus, there is no need to rely on organizations for storage. The Blockchain code is open source and can be used, modified and revised by its users. BCT literature is scarce so far. This article describes the basics of this technology and summarizes the various aspects in which BCT could change the paradigm of current medicine. The great potential of BCT, as well as its many applications in the field of health sciences, encompasses the fields of legal medicine, research, electronic medical records, medical data analysis (big data), teaching and the regulation of payment for medical services. If technological advances continue along these lines, it could bring about a revolution in medicine as we know it.
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare and Education
No abstract available.
 Editorâs note: A proposal to implement distributed ledger technology for electronic health records is outlined here. The rationale for integration of distributed ledgers in the healthcare domain is introduced, followed by a discussion of the features enabled by the use of a blockchain. An open source implementation of a distributed ledger is then presented. The article concludes with an examination of opportunities and challenges ahead in deploying blockchains for digital health.
Eric Zhang, C Hendrik, Yang Liu, Archit Sharma · 5 authors
In this paper we present the initial design of Minerva consensus protocol for Truechain and other technical details. Currently, it is widely believed in the blockchain community that a public chain cannot simultaneously achieve high performance, decentralization and security. This is true in the case of a Nakamoto chain (low performance) or a delegated proof of stake chain (partially centralized), which are the most popular block chain solutions at time of writing. Our consensus design enjoys the same consistency, liveness, transaction finality and security guarantee, a de-facto with the Hybrid Consensus. We go on to propose the idea of a new virtual machine on top of Ethereum which adds permissioned-chain based transaction processing capabilities in a permissionless setting. We also use the idea of data sharding and speculative transactions, and evaluation of smart contracts in a sharding friendly virtual machine. Finally, we will briefly discuss our fundamentally ASIC resistant mining algorithm, Truehash.
While the Internet of Things (IoT) technology has been widely recognized as the essential part of Smart Cities, it also brings new challenges in terms of privacy and security. Access control (AC) is among the top security concerns, which is critical in resource and information protection over IoT devices. Traditional access control approaches, like Access Control Lists (ACL), Role-based Access Control (RBAC) and Attribute-based Access Control (ABAC), are not able to provide a scalable, manageable and efficient mechanism to meet the requirements of IoT systems. Another weakness in today's AC is the centralized authorization server, which can be the performance bottleneck or the single point of failure. Inspired by the smart contract on top of a blockchain protocol, this paper proposes BlendCAC, which is a decentralized, federated capability-based AC mechanism to enable an effective protection for devices, services and information in large scale IoT systems. A federated capability-based delegation model (FCDM) is introduced to support hierarchical and multi-hop delegation. The mechanism for delegate authorization and revocation is explored. A robust identity-based capability token management strategy is proposed, which takes advantage of the smart contract for registering, propagating and revocating of the access authorization. A proof-of-concept prototype has been implemented on both resources-constrained devices (i.e., Raspberry PI node) and more powerful computing devices (i.e., laptops), and tested on a local private blockchain network. The experimental results demonstrate the feasibility of the BlendCAC to offer a decentralized, scalable, lightweight and fine-grained AC solution for IoT systems.
The concept of a decentralized ledger usually implies that each node of a blockchain network stores the entire blockchain. However, in the case of popular blockchains, which each weigh several hundreds of GB, the large amount of data to be stored can incite new or low-capacity nodes to run lightweight clients. Such nodes do not participate to the global storage effort and can result in a centralization of the blockchain by very few nodes, which is contrary to the basic concepts of a blockchain. To avoid this problem, we propose new low storage nodes that store a reduced amount of data generated from the blockchain by using erasure codes. The properties of this technique ensure that any block of the chain can be easily rebuild from a small number of such nodes. This system should encourage low storage nodes to contribute to the storage of the blockchain and to maintain decentralization despite of a globally increasing size of the blockchain. This system paves the way to new types of blockchains which would only be managed by low capacity nodes.