Muhammad Mansab Uzair, Emadul Karim, Shair Sultan, Syed Sheeraz Ahmed
The block chain technology has been in the topic of much discussion due to its successful application in the crypto currency known as “Bitcoin" which has investment experts, economists, billion dollar financial institutes, big banks as well as governments taking sides on whether it should be legitimized and used as a currency or make it illegal to be used as a means of exchange. However, experts from different field like supply chain management and even from the medical field are more interested in how the block chain technology’s decentralized record keeping and numerous other benefits can be of use to them in their fields of work. This study concentrates on the block chain being used for real estate record keeping, since most geography’s have different procedures for record keeping, this study focuses on Defence Housing Authority in Karachi to check what the impact of applying the block chain technology to this area in Karachi would have on investors, real estate agents, residents and the government.
Cansu Şarkaya İçellioğlu, Merve Büşra Engin Öztürk
Güvenlik açısından kriptoloji (şifreleme) bilimini kullanan, dijital ve sanal bir para birimi anlamına gelen kriptopara, son yıllarda en çok tartışılan ekonomik kavramlardan biri olmuştur. Kriptopara, herhangi bir döviz kuruna ya değerli bir madene bağlı olmamakla birlikte, herhangi bir yasal otorite tarafından da kontrol edilememektedir. En başarılı kriptopara olarak değerlendirilen Bitcoin, ilk çıktığı yıldan bu yana çok yüksek bir oranda değerlenmesinden ötürü cazip bir yatırım aracı olarak görülmekte, ancak taşıdığı belirsizlik ve risklerden ötürü çeşitli endişeleri de beraberinde getirmektedir. Bu çalışmada Bitcoin’in özellikleri ve işleyişi ele alınarak, Bitcoin ile seçili döviz kurları arasındaki ilişki araştırılmaktadır. Araştırmada birim kök testleri uygulanmış, seriler arasındaki uzun dönemli ilişki Engel-Granger Eşbütünleşme testi ve Johansen Testi ile ve kısa dönemli ilişki Granger nedensellik testi ile sınanmıştır. Çalışmanın sonucunda Bitcoin ile Dolar, Euro, Sterlin, Yen ve Yuan arasında uzun ve kısa dönemli bir ilişkinin varlığına rastlanamamıştır.
Beltrán Borja Fiz Pontiveros, Robert Norvill, Radu State
Mining pools are collection of workers that work together as a group in order to collaborate in the proof of work and reduce the variance of their rewards when mining. In order to achieve this, Mining pools distribute amongst the workers the task of finding a block so that each worker works on a different subset of the candidate solutions. In most mining pools the selection of transactions to be part of the next block is performed by the pool manager and thus becomes more centralized. A mining Pool is expected to give priority to the most lucrative transactions in order to increase the block reward however changes to the transaction policy done without notification of workers would be difficult to detect. In this paper we treat the transaction selection policy performed by miners as a classification problem; for each block we create a dataset, separate them by mining pool and apply feature selection techniques to extract a vector of importance for each feature. We then track variations in feature importance as new blocks arrive and show using a generated scenario how a change in policy by a mining pool could be detected.
Eung Seon Kang, Seung Jae Pee, Jae Song, Ju Wook Jang
The MicroGrid., as the need for renewable energy emerges, are becoming essential, renewable energy trading platforms are being developed and established in the microgrid. With the proliferation of technologies such as Smart home based of Internet of Things, interconnected networks, and Blockchain, microgrid has introduced a variety of applications and innovative solutions for efficient system maintenance. This paper, in a blockchain-based smart home, it is impossible to forge data called transaction generated by using blockchain. With this unforgeable transactions, home miner that centrally processes all the transactions generated in smart home know information about energy. Based on this information, we proposes renewable energy trading platform using ethereum's smart contract to ensure secure energy trading run automatically without the third party intervention in a microgrid.
Sina Rafati Niya, Florian Shupfer, Thomas Bocek, Burkhard Stiller
Smart Contracts (SC) extend the applicability of Blockchains (BC) in various decentralized use cases. This work demonstrates the design and implementation of a trading application which, employs SC and Ethereum BC. This Decentralized Application (Dapp) provides flexibility in requesting user Identity (ID) directly by seller/hirer and buyers/renter. To provide trust, deposits are paid by two sides while setting up contracts. WiFi- Direct is the chosen Device to Device (D2D) communication protocol which provides high data rates and secure data transmission. Light-Weight SC are introduced in this work which, use D2D communications for sending sold or rented object's or each party's images, and ID data directly to other party instead of storing them in the public BC to reduce the costs. Evaluations in terms of D2D deployment, transaction costs, and privacy, indicate that this system is time-efficient and manages the process in a cost-efficient fashion without the need to store and publish all of the user's ID information in BC.
Recently, Blockchain becomes a hot research topic due to the success of Blockchain in many applications, such as cryptocurrency, smart contract, digital assets, distributed cloud storage and so on. The power of Blockchain is that it can achieve the consensus of an ordered set of transactions among nodes which do not trust each other, even with the existence of malicious nodes. However, compared to traditional databases, the current Blockchain technology still cannot handle a massive number of transactions, which is caused by many factors, such as the consensus protocol, structure of the blocks and storage challenge. Among them, the high storage requirement is a key factor that prevents the wide usage of Blockchain on various devices such as mobile phones or low-end PCs. In this paper, to address the storage challenge, we introduce a novel concept called Consensus Unit (CU), which organizes different nodes into one unit and lets them to store at least one copy of Blockchain data in the system together. Based on this idea, we further define the Blocks Assignment Optimization (BAO) problem which determines the optimal assignment of blocks such that the storage space is fully used and the query cost is minimized. We prove that the BAO problem is NP-hard. Thus, we propose three efficient heuristic algorithms to solve the static assignment problem. Furthermore, we present solutions to address the dynamic scenarios when new blocks arrive and nodes join or depart from the CU. To verify the effectiveness of CU, we have conducted extensive experiments on synthetic data and BLOCKBENCH [1]. The results have confirmed the superiority of CU in saving the storage and maintaining the system throughput.
Jing Chen, Shixiong Yao, Quan Yuan, Kun He · 6 authors
In recent years, real-world attacks against PKI take place frequently. For example, malicious domains' certificates issued by compromised CAs are widespread, and revoked certificates are still trusted by clients. In spite of a lot of research to improve the security of SSL/TLS connections, there are still some problems unsolved. On one hand, although log-based schemes provided certificate audit service to quickly detect CAs' misbehavior, the security and data consistency of log servers are ignored. On the other hand, revoked certificates checking is neglected due to the incomplete, insecure and inefficient certificate revocation mechanisms. Further, existing revoked certificates checking schemes are centralized which would bring safety bottlenecks. In this paper, we propose a blockchain-based public and efficient audit scheme for TLS connections, which is called Certchain. Specially, we propose a dependability-rank based consensus protocol in our blockchain system and a new data structure to support certificate forward traceability. Furthermore, we present a method that utilizes dual counting bloom filter (DCBF) with eliminating false positives to achieve economic space and efficient query for certificate revocation checking. The security analysis and experimental results demonstrate that CertChain is suitable in practice with moderate overhead.
The two major roadblocks for state of the art Internet of Things (IoT) infrastructure like smart buildings, smart cities, etc. are lack of trust between various entities of system and single point of failure which is a vulnerability causing extreme damage to the whole system. This paper proposes a blockchain based IoT security solution where, trust is established through the immutable and decentralized nature of blockchain. The distributed nature of blockchain makes the system more robust and immune to single point of failure. We propose a mechanism to establish continuous security in the system by evaluating legitimate presence of user in valid IoT-Zone continuously without user intervention. Every user interaction in an IoT environment is stored in blockchain as a transaction and series of these transactions represent a user's IoT-trail. A unique digital crypto-token is required for a user interaction to be legitimate. This token is used as an access control mechanism to prevent any unauthorized access to the system. Tokens are pre-generated using a prediction model based on user's IoT-trail in the blockchain. By using blockchain as an underlying framework in IoT environment and through the method of continuous security, we made the system more secure, robust and interoperable.
Nida Khan, Abdelkader Lahmadi, Jérôme François, Radu State
Blockchain is an emerging foundational technology with the potential to create a novel economic and social system. The complexity of the technology poses many challenges and foremost amongst these are monitoring and management of blockchain-based decentralized applications. In this paper, we design, implement and evaluate a novel system to enable management operations in smart contracts. A key aspect of our system is that it facilitates the integration of these operations through dedicated 'managing' smart contracts to provide data filtering as per the role of the smart contract-based application user. We evaluate the overhead costs of such data filtering operations after post-deployment analyses of five categories of smart contracts on the Ethereum public testnet, Rinkeby. We also build a monitoring tool to display public blockchain data using a dashboard coupled with a notification mechanism of any changes in private data to the administrator of the monitored decentralized application.
Distributed ledger technologies (DLTs) are receiving much attention. As discussion focuses on the potential applications of DLTs, Blockchain-as-a-Service (BaaS) offerings are emerging to provide the underlying supporting infrastructure. BaaS entails a service provider supplying and managing aspects of a DLT infrastructure to facilitate and bring efficiencies regarding the development, experimentation, deployment, and the ongoing management of DLT applications. However, much of the interest in DLTs stems from their potential to decentralise, disintermediate, and enable `trustless' interactions. At first sight, BaaS - being offered by a provider - appears to run counter to this. In practice, whether BaaS raises substantive trust concerns depends on the nature of the offering, the application's specifics, and the participants' goals and risk appetite. This paper elaborates the nature of BaaS and explores the trust considerations it raises, particularly regarding the role of providers as part of a wider infrastructure.
Adrián E. Coronado Mondragón, Christian E. Coronado Mondragon, Etienne S. Coronado
The decentralized transaction and data management technology that characterizes blockchain can have a significant impact on manufacturing supply chains. This paper aims to investigate the applicability of blockchain technology in the supply chain of composite materials/carbon fibre, in particular the manufacturing of structures and components relying on semi-finished materials such as prepregs (preimpregnated) which require temperature-controlled transportation and storage conditions. In composite materials distributed ledger/blockchain technology can be used for the purpose of tamper proof history of product manufacturing, provenance, transportation, handling and storage.
Mohamed Tahar Hammi, Patrick Bellot, Ahmed Serhrouchni
Internet of Things becomes a major part of our lives, billions of autonomous devices are connected and communicate with each other. This revolutionary paradigm creates a new dimension that removes the boundaries between the real and the virtual worlds. The Wireless Sensor Networks are a masterpiece of the success of this technology, using limited capacity sensors and actuators, industrial, medical, agricultural and many other environments can be covered and managed automatically. This autonomous interacting things should authenticate each other, and communicate securely. Otherwise malicious users can cause serious damages on such systems. In this paper we propose a robust, transparent, flexible and energy efficient blockchain-based authentication mechanism called BCTrust, which is designed especially for devices with computational, storage and energy consumption constraints. In order to evaluate our approach, we realized a real implementation with C programming language, and Ethereum Blockchain.
Blockchain Technology Applications and Security
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
Maged M. Eljazzar, Mohamed Amr, Sally Kassem, Mohamed Ezzat
Technology has been playing a major role in our lives. One definition for technology is all the knowledge, products, processes, tools,methods and systems employed in the creation of goods or in providing services.This makes technological innovations raise the competitiveness between organizations that depend on supply chain and logistics in the global market. With increasing competitiveness, new challenges arise due to lack of information and assets tractability. This paper introduces three scenarios for solving these challenges using the Blockchain technology. In this work, Blockchain technology targets two main issues within the supply chain, namely, data transparency and resource sharing. These issues are reflected into the organizations strategies and plans.
The phenomenal growth of Internet-services has created a vibrant new domain for sharing economy. Millions of users around the world share personal services and possessions with others - often complete strangers. Such sharing schemes also increase the risk of violation of one's informational and physical privacy. Strangers often have to trust each other with their privacy (e.g. a surveillance camera in an Airbnb room). However, very little research has been devoted to investigate privacy in sharing economy. In this paper, we explore the privacy concerns associated with contractual renting or leasing of IoT devices-enabled home. We propose a methodology to eliminate privacy threats from IoT-enabled telematics devices in a smart home via blockchain-based smart contract. For the purpose of illustration, we focus on how we can circumvent the privacy threat from indoor surveillance IP cameras in a smart home-sharing economy.
Trust in the cloud is still a problem. Most are in agreement that 'transparency' is key to cloud trust, but transparency applies to a variety of cloud operations, which is why cloud trust research is diverse. Widely publicized breaches recently had to do with third parties. Untrusted third parties and data movement are closely related. There are valid use cases to duplicate data for redundancy, but this typically happens behind closed doors. We see that as a problem; there are no mechanisms that we know of to police or track data as it gets copied or moves between clouds. We are proposing an approach to cloud trust that leverages the innovative blockchain technology to help increase transparency and also reduce the problem of depending on TTPs. By using a consumer belief model tailored to the cloud we also show the relevance of consumer policies in trust with regards to their data. We propose to use smart contracts as the vehicle for the policies and a belief/recommendation model to help guide us to a successful outcome.
Hyperledger Fabric is a "permissioned" blockchain architecture, providing a consistent distributed ledger, shared by a set of "peers." As with every blockchain architecture, the core principle of Hyperledger Fabric is that all the peers must have the same view of the shared ledger, making it challenging to support private data for the different peers. Extending Hyperledger Fabric to support private data (that can influence transactions) would open the door to many exciting new applications, in areas from healthcare to commerce, insurance, finance, and more. In this work we explored adding private-data support to Hyperledger Fabric using secure multiparty computation (MPC). Specifically, in our solution the peers store on the chain encryption of their private data, and use secure MPC whenever such private data is needed in a transaction. This solution is very general, allowing in principle to base transactions on any combination of public and private data. We created a demo of our solution over Hyperledger Fabric v1.0, implementing a bidding system where sellers can list assets on the ledger with a secret reserve price, and bidders publish their bids on the ledger but keep secret the bidding price itself. We implemented a smart contract (aka "chaincode") that runs the auction on this secret data, using a simple secure-MPC protocol that was built using the EMP-toolkit library. The chaincode itself was written in Go, and we used the SWIG library to make it possible to call our protocol implementation in C++. We identified two basic services that should be added to Hyperledger Fabric to support our solution, and are now working on implementing them.
The increased deployment of Internet of Things (IoT) devices will make them targets for attacks. IoT devices can also be used as tools for committing crimes. In this regard, we propose Probe-IoT - a forensic investigation framework using a public digital ledger to find facts in criminal incidents in IoT-based systems. Probe-IoT collects interactions that take place among various IoT entities (clouds, users, and IoT devices) as evidence and stores them securely as transactions in public, distributed and decentralized blockchain network which is similar to the Bitcoin network. Probe-IoT presents a scheme that ensures integrity, confidentiality, anonymity, and non-repudiation of the evidence stored in the public ledger. Furthermore, during the investigation of a malicious incident, Probe-IoT provides a mechanism to acquire evidence from the ledger and verify the authenticity and integrity of the obtained evidence.
The blockchain technology witnessed a wide adoption and a swift growth in recent years. This ingenious distributed peer-to-peer design attracted several businesses and solicited several communities beyond the financial market. There are also multiple use cases built around its ecosystem. However, this backbone introduced a lot of speculation and has been criticized by several researchers. Moreover, the lack of legislations perceived a lot of attention. In this paper, we are concerned in analyzing blockchain networks and their development, focusing on their security challenges. We took a holistic approach to cover the involved mechanisms and the limitations of Bitcoin, Ethereum and Hyperledger networks. We expose also numerous possible attacks and assess some countermeasures to dissuade vulnerabilities on the network. For occasion, we simulated the majority and the re-entrancy attacks. The purpose of this paper is to evaluate Blockchain security summarizing its current state. Thoroughly showing threatening flaws, we are not concerned with favoring any particular blockchain network.
The Internet of Things (IoT) network of connected devices currently contains more than 11 billion devices and is estimated to double in size within the next four years. The prevalence of these devices makes them an ideal target for attackers. To reduce the risk of attacks vendors routinely deliver security updates (patches) for their devices. The delivery of security updates becomes challenging due to the issue of scalability as the number of devices may grow much quicker than vendors' distribution systems. Previous studies have suggested a permissionless and decentralized blockchainbased network in which nodes can host and deliver security updates, thus the addition of new nodes scales out the network. However, these studies do not provide an incentive for nodes to join the network, making it unlikely for nodes to freely contribute their hosting space, bandwidth, and computation resources. In this paper, we propose a novel decentralized IoT software update delivery network in which participating nodes (referred to as distributors) are compensated by vendors with digital currency for delivering updates to devices. Upon the release of a new security update, a vendor will make a commitment to provide digital currency to distributors that deliver the update; the commitment will be made with the use of smart contracts, and hence will be public, binding, and irreversible. The smart contract promises compensation to any distributor that provides proof-of-distribution, which is unforgeable proof that a single update was delivered to a single device. A distributor acquires the proof-of-distribution by exchanging a security update for a device signature using the Zero-Knowledge Contingent Payment (ZKCP) trustless data exchange protocol. Eliminating the need for trust between the security update distributor and the security consumer (IoT device) by providing fair compensation, can significantly increase the number of distributors, thus facilitating rapid scale out.
Holger Kinkelin, Valentin Hauner, Heiko Niedermayer, Georg Carle
Numerous IoT applications, like building automation or process control of industrial sites, exist today. These applications inherently have a strong connection to the physical world. Hence, IT security threats cannot only cause problems like data leaks but also safety issues which might harm people. Attacks on IT systems are not only performed by outside attackers but also insiders like administrators. For this reason, we present ongoing work on a Byzantine fault tolerant configuration management system (CMS) that provides control over administrators, restrains their rights, and enforces separation of concerns. We reach this goal by conducting a configuration management process that requires multi-party authorization for critical configurations to prevent individual malicious administrators from performing undesired actions. Only after a configuration has been authorized by multiple experts, it is applied to the targeted devices. For the whole configuration management process, our CMS guarantees accountability and traceability. Lastly, our system is tamper-resistant as we leverage Hyperledger Fabric, which provides a distributed execution environment for our CMS and a blockchain-based distributed ledger that we use to store the configurations. A beneficial side effect of this approach is that our CMS is also suitable to manage configurations for infrastructure shared across different organizations that do not need to trust each other.
In 2017, the Blockchain-based crypto currency market witnessed enormous growth. Bitcoin, the leading crypto currency, reached all-time highs many times over the year leading to speculations to explain the trend in its growth. In this paper, we study Bitcoin and explore features in its network that explain its price hikes. We gather data and analyze user and network activity that highly impact Bitcoin price. We monitor the change in the activities over time and relate them to economic theories. We identify key network features that determine the demand and supply dynamics of a crypto currency. Finally, we use machine learning methods to construct models that predict Bitcoin price. Our regression model predicts Bitcoin price with 99.4% accuracy and 0.0113 root mean squared error (RMSE).
E-government system has greatly improved the efficiency and transparency of daily operations of a government. However, most of existing e-government services are provided in a centralized manner and heavily rely on human individuals to control. The highly centralized IT infrastructure is more vulnerable to outside attacks. Also, it is relatively easy to compromise the data integrity by inside rogue users. Furthermore, relying on individuals to monitor and control some of the working flows makes the system error-prone and leaves room for corruption. To address these challenges, we propose to use the blockchain technology and decentralized autonomous organization (DAO) to improve the e-government system. The blockchain-based DAO system works in a fully decentralized way and is immune to both outside and inside attacks. At the same time, operations of such system is only controlled by pre-defined rules; thus, the uncertainty and errors caused by human processes are greatly reduced. We provide a concrete use case to demonstrate the usage of DAO e-government and evaluate its effectiveness.
Sina Rafati Niya, Sanjiv S. Jha, Thomas Bocek, Burkhard Stiller
This work proposes an IoT- and Blockchain-based, distributed system, for automated measuring, storing, and monitoring of water and air quality in environments such as lakes, mountains, urban areas, or factories. Comparable state-of-the-art solutions, require human interaction to access the data or require high power consumption or space requirements, or they are based on centralized architectures. The proposed pollution monitoring system here, on one hand, employs LoRa to address the high power consumption and long-range transmission challenges of IoT protocols. On the other hand, it is designed to be fully decentralized by using the Ethereum Blockchain to store and retrieve the data recorded by IoT sensors. Thus, data integrity is provided without the need for a Trusted Third Party (TTP) and data is collected and captured automatically without any manual operations needed. Observations on the four different types of sensors for measuring Potential Hydrogen (PH), Turbidity, Carbon monoxide (CO), and Carbon dioxide (CO2), revealed a high accuracy with the expected time-lines of measurements, non-falsified experimental values collected and can be used as reliable evidence of presence of pollution.