In this paper, we present ethnographic data that unpacks the everyday work of some of the many infrastructuring agents who contribute to creating, sustaining and growing the Blockchain information infrastructure. We argue that this infrastructuring work takes the form of entrepreneurial actions, which are self-initiated and primarily directed at sustaining or increasing the initiator's stake in the emerging information infrastructure. These entrepreneurial actions wrestle against the affordances of the installed base of the Blockchain infrastructure, and take the shape of engaging or circumventing activities. These activities purposefully aim at either influencing or working around the enablers and constraints afforded by the Blockchain information infrastructure, as its installed base is gaining inertia. This study contributes to our understanding of the purpose of infrastructuring, seen from the perspective of heterogeneous entrepreneurial agents. It supplements existing accounts of the "when" and "how" of infrastructure, with a lens for examining the "why" of infrastructure.
Sachin Shetty, Val A. Red, Charles Kamhoua, Kevin Kwiat · 5 authors
Ever increasing adoption of cloud technology scales up the activities like creation, exchange, and alteration of cloud data objects, which create challenges to track malicious activities and security violations. Addressing this issue requires implementation of data provenance framework so that each data object in the federated cloud environment can be tracked and recorded but cannot be modified. The blockchain technology gives a promising decentralized platform to build tamper-proof systems. Its incorruptible distributed ledger/blockchain complements the need of maintaining cloud data provenance. In this paper, we present a cloud based data provenance framework using block chain which traces data record operations and generates provenance data. We anchor provenance data records into block chain transactions, which provide validation on provenance data and preserve user privacy at the same time. Once the provenance data is uploaded to the global block chain network, it is extremely challenging to tamper the provenance data. Besides, the provenance data uses hashed user identifiers prior to uploading so the blockchain nodes cannot link the operations to a particular user. The framework ensures that the privacy is preserved. We implemented the architecture on ownCloud, uploaded records to blockchain network, stored records in a provenance database and developed a prototype in form of a web service.
Purpose The purpose of this paper is to critically analyse research surrounding the anonymity of online transactions using Bitcoin and report on the feasibility of law enforcement bodies tracing illicit transactions back to a user’s real-life identity. Design/methodology/approach The design of this paper follows on from the approach taken by Reid and Harrigan (2013) in determining whether identifying information may be collated with external sources of data to identify individual users. In addition to conducting a detailed literature review surrounding the anonymity of users, and the potential ability to track transactions through the blockchain, four Bitcoin exchange services are examined to ascertain whether information provided at the sign-up stage is sufficiently verified and reliable. By doing so, this research tests the ability for law enforcement to reasonably rely upon this information when attempting to prosecute individuals. Additionally, by submitting fake information for verification, the plausibility of these services accepting fraudulent or illegitimate information is also tested. Findings It may be possible to identify and prosecute bad actors through the analysis of transaction histories by tracing them back to an interaction with a Bitcoin exchange. However, the compliance and implementation of anti-money laundering legislation and customer identification security standards are insufficiently used within some exchange services, resulting in more technologically adept, or well-funded, criminals being able to circumvent identification controls and continue to transact without revealing their identities. The introduction of and compliance with know-your customer and customer due diligence legislation is required before law enforcement bodies may be able to accurately rely on information provided to a Bitcoin exchange. This paper highlights the need for research to be undertaken to examine the ways in which criminals are circumventing identity controls and, consequently, financing their illicit activities. Originality/value By ascertaining the types of information submitted by users when exchanging real currency for virtual currency, and seeing whether this information may be accepted despite being fraudulent in nature, this paper elucidates the reliability of information that law enforcement bodies may be able to access when tracing transactions back to an individual actor.
Emerging decentralized storage services such as Storj and Filecoin show promise as a new paradigm for data outsourcing. These services tie cryptocurrency to personal storage resources and leverage blockchain technology to ensure data integrity in distributed networks. Compared to current cloud storage, they are expected to be more scalable, cost effective, and secure. In addition to the features above, strong guarantees of data privacy are seriously desired due to today's prevalent data leak and abuse incidents. However, simply using end-to-end encryption limits the search capability and thus will degrade the user experience. In this paper, we propose an encrypted decentralized storage architecture that can support trustworthy and private keyword search functions. We start from searchable encryption to achieve search on encrypted data. Yet, only adopting this primitive is not sufficient to address particular threats in our target decentralized service model. Service peers would maliciously return incorrect results, while user peers would fraudulently refuse to pay service fees. To resolve those threats, we devise specific secure data addition and keyword search protocols to enable client-side verifiability and blockchain based fair judgments on the search results. For practical considerations, we integrate an efficient dynamic searchable encryption scheme to our protocols as an instantiation to lower the blockchain overhead. Our security and performance analysis indicates the advance of the proposed architecture.
A current trend in both retailing and retail financial services aims to match customers to their purchases with the least amount of friction. For depositary institutions this entails enabling customers to deal with their financial affairs, including purchases, through whatever channel the customer chooses (branch, ATM, web, mobile, etc.). For merchants, it entails shipping and delivering the purchase when and how the customer chooses (in store, at a desired location, at a pick-up point, etc.), while settling outstanding financial claims with the different actors involved in the manufacturing, storage, shipping and distribution network. This essay briefly explores the potential use of distributed ledger technology (DLT) to deliver integrated omni-channel solutions
Jonathan Bell, Thomas D. LaToza, Foteini Baldmitsi, Angelos Stavrou
The scientific community is facing a crisis of reproducibility: confidence in scientific results is damaged by concerns regarding the integrity of experimental data and the analyses applied to that data. Experimental integrity can be compromised inadvertently when researchers overlook some important component of their experimental procedure, or intentionally by researchers or malicious third-parties who are biased towards ensuring a specific outcome of an experiment. The scientific community has pushed for "open science" to add transparency to the experimental process, asking researchers to publicly register their data sets and experimental procedures. We argue that the software engineering community can leverage its expertise in tracking traceability and provenance of source code and its related artifacts to simplify data management for scientists. Moreover, by leveraging smart contract and blockchain technologies, we believe that it is possible for such a system to guarantee end-to-end integrity of scientific data and results while supporting collaborative research.
This conceptual research reflects the understanding of the wider and more coherent use of crypto-currencies and Blockchain' algorithms for the security and equity of operations. This is especially important for the transactions between the collective actors on different hierarchical positions, e.g., the State and private companies or associations, or individuals. The fog computing' hardware and software are helpful for the aims of improving taxation and ensuring reliability of any transactions. The neuron technologies provide creating and developing a multi-criteria assessment of assets or actions, which represent more correct system of affective and socially acceptable evaluations, than it can be calculated on the basis of the cognitive judgments. The ability to provide a high level of information security through systems like Etherium allows of building a reliable and transparent system of taxation and of regulation of all interactions between social, economic and political agents, including the financial and non-financial measurements.
Until now, most systems for Internet of Things (IoT) management, have been designed in a Cloud-centric manner, getting benefits from the unified platform that the Cloud offers. However, a Cloud-centric infrastructure mainly achieves static sensor and data streaming systems, which do not support the direct configuration management of IoT components. To address this issue, a virtualization of IoT components (Virtual Resources) is introduced at the edge of the IoT network. This research also introduces permission-based Blockchain protocols to handle the provisioning of Virtual Resources directly onto edge devices. The architecture presented by this research focuses on the use of Virtual Resources and Blockchain protocols as management tools to distribute configuration tasks towards the edge of the IoT network. Results from lab experiments demonstrate the successful deployment and communication performance (response time in milliseconds) of Virtual Resources on two edge platforms, Raspberry Pi and Edison board. This work also provides performance evaluations of two permission-based blockchain protocol approaches. The first blockchain approach is a Blockchain as a Service (BaaS) in the Cloud, Bluemix. The second blockchain approach is a private cluster hosted in a Fog network, Multichain
The increasing popularity of blockchain-based cryptocurrencies has made scalability a primary and urgent concern. Compared with the completely open, uncontrolled public blockchain system, private blockchain can provide better access control management. This paper proposes an architecture for distributed private blockchain. At the same time, we propose three strategies to improve the scalability of private blockchain: optimization of block construction, block size and time control optimization, and transaction security mechanism optimization. This system also redesigns the format of the trading, block structure and the way how system constructs blocks, makes it more suitable for the requirements of the private blockchain. From experiment results, we show that our system achieves better performance and scalability without compromising security guarantees.
Vanesa Daza, Roberto Di Pietro, Ivan Klimek, Matteo Signorini
The Internet of Things is gaining momentum thanks to the provided vision of seamlessly interconnected devices. However, a unified way to discover and to interact with the surrounding smart environment is missing. As an outcome, we have been assisting to the development of heterogeneous ecosystems, where each service provider adopts its own protocol- thus preventing IoT devices from interacting when belonging to different providers. And, the same is happening again for the blockchain technology which provides a robust and trusted way to accomplish tasks -unfortunately not providing interoperability thus creating the same heterogeneous ecosystems above highlighted. In this context, the fundamental research question we address is how do we find things or services in the Internet of Things. In this paper, we propose the first IoT discovery approach which provides an answer to the above question by exploiting hierarchical and universal multi-layered blockchains. Our approach does neither define new standards nor force service providers to change their own protocol. On the contrary, it leverages the existing and publicly available information obtained from each single blockchain to have a better knowledge of the surrounding environment. The proposed approach is detailed and discussed with the support of relevant use cases.
Martin Weiss, Adéle Botha, Marlien Herselman, Glaudina Loots
Blockchain technology underpins a radical rethink of information privacy, confidentiality, security and integrity. As a decentralised ledger of transactions across a peer-to-peer network, the need for a central third party intermediate verification authority is disrupted. To unlock the potential for mHealth, the need for authentication and verified access to often sensitive data, specialised services and transfer of value need to be realised. This paper interrogates current processes and aims to make a case for Blockchain technology as an improved security model that has the potential to lower the cost of trust and an alternative to managing the burden of proof. This is particularly relevant for mHealth that, by its nature, is often a distributed endeavour involving the goal-orientated collaboration of a number of stakeholders.
Saravanan Raju, Sai Boddepalli, Suraj Gampa, Qiben Yan · 5 authors
Cloud-centric cognitive cellular networks utilize dynamic spectrum access and opportunistic network access technologies as a means to mitigate spectrum crunch and network demand. However, furnishing a carrier with personally identifiable information for user setup increases the risk of profiling in cognitive cellular networks, wherein users seek secondary access at various times with multiple carriers. Moreover, network access provisioning - assertion, authentication, authorization, and accounting - implemented in conventional cellular networks is inadequate in the cognitive space, as it is neither spontaneous nor scalable. In this paper, we propose a privacy-enhancing user identity management system using blockchain technology which places due importance on both anonymity and attribution, and supports end-to-end management from user assertion to usage billing. The setup enables network access using pseudonymous identities, hindering the reconstruction of a subscriber's identity. Our test results indicate that this approach diminishes access provisioning duration by up to 4x, decreases network signaling traffic by almost 40%, and enables near real-time user billing that may lead to approximately 3x reduction in payments settlement time.
One of the major concerns on today's Software-Defined Network (SDN) is to enhance its security. Files sharing in SDN can be made much more secured against fraudulent activities by the implementation of blockchain technology. When the privacy of network's users is increased, the reliability of system increases correspondingly. Blockchain Security over SDN (BSS) is proposed which protects privacy and availability of resources against non-trusting members. Mininet emulator is used for simulating custom SDN network topology. OpenDaylight controller is integrated with OpenStack controller. For cloud data storage, OpenStack platform is used. For testing purpose of Blockchain, Pyethereum tester tool under Ethereum platform is implemented. Serpent programming is used for creating contract in the blockchain. BSS facilitates files sharing among SDN users in distributed peer-to-peer basis using OpenStack as a cloud storage platform.
Michal Elzbieta Janton-Drozdowska, Alicja Mikołajewicz-Woźniak
The year 2016 ended the period of migration from national payment services to the SEPA instruments and it has become apparent that some problems remained unresolved. Overcoming them requires finding suitable technological solutions. The potential of distributed ledger technology (DLT) is currently explored by financial sector and its implementation may affect the SEPA schemes in a variety of dimensions. The aim of the article is to determine the potential impact of the DLT transfer to banking sector on the future SEPA's functioning. The paper presents SEPA's assumptions and the project's current status as well as DLT's concept. It describes the technology transfer implications for banking industry and compares currently operating SEPA schemes with those based on DLT. It also indicates opportunities and threats being the consequence of the new technology implementation and their significance for SEPA.In the article the qualitative analysis is supplemented by the quantitative one. While characterizing the functioning of the main pillars of the SEPA Schemes the elements of descriptive statistics are used. The final conclusions are based on the comparative analysis of SEPA schemes and developed DLT applications. The existing problems might be solved by supplementing currently operating SEPA payment schemes with the applications based on DLT. The developed systems shall provide required real-time processing and a global reach as well as extend the SEPA schemes' functionalities with the ability to transfer other currencies. The technology implementation shall result not only in new financial products but first of all - in creating new business models. Consequently, we shall expect the modification of currently operating SEPA schemes, based rather on their supplement than total replacement in a short time horizon.
The popularity of Crypto currencies has not gone unnoticed, Bitcoin which is an electronic payment system and Internet money, is a leading crypto currency and continues to grow from being popular amongst the people who have knowledge about this technology, i.e. the developers, investors and tech-savvy enthusiasts and those that don't. If a person wants to use Bitcoin they need to have a Bitcoin wallet which stores the public and private keys used when sending and receiving bitcoins. Most of these Bitcoin wallets were developed for people who have access to technologies such as smart phones, computers and an Internet connection. This paper presents a simplified Short Message Service (SMS) system that can be used by people who do not have access to these technologies. The system was developed as a prototype and tested on a low-end mobile phone to demonstrate its capabilities. It still needs to be enhanced further to enable anyone to use it, e.g. increase the speed of transactions and SMS responses and the use of better security methods.
Despite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-the-middle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable.
I-Hsun Chuang, Bing-Jie Guo, Jen-Sheng Tsai, Yau-Hwang Kuo
Internet of Things (IoT) is an emerging network technology applied to provide various services in our daily life. Generally, IoT environments are composed of numerous heterogeneous devices with constrained resource. The limited capability of IoT devices makes it impractical to perform traditional security mechanisms, and thus IoT services are usually vulnerable to all kinds of security threats, such as impersonation and forgery attacks. Moreover, the inflexible protection provided by these security mechanisms leads to inefficiency because different services haves diverse requirements. To provide IoT services suitable security protection, Multi-graph Zero-knowledge-based Authentication System (M-ZAS), which is not only light-weight but also high-adaptive, is proposed. Compared to traditional authentication mechanisms as well as other Zero-knowledge-proof (ZKP) methods such as GMW-ZKP, M-ZAS provides higher performance and better security protection. In addition, M-ZAS has lower transmission overheads than GMW-ZKP does. Considering relevant contexts as parameters, M-ZAS provides adaptive protection to fulfill what users actually need. Experiment results show that M-ZAS is 3 times faster than GMW-ZKP and even 7 times than traditional authentication mechanisms in IoT devices. Also, M-ZAS reduces 3 times network traffic than GMW-ZKP. Thus, the proposed M-ZAS is the most practical authentication system in IoT environments.
In times of political effervescence, the number of pamphlets and newspapers editions tends to increase. Accordingly, the different instances in the life of a political movement can be traced through the type of intervention proposed by its publications. The rise of the anarchist movement publishing activity in Buenos Aires preceded its relevance within trade union during the first years of the 20th century. Until that moment the few "popular editions" published in the country consisted in literary works. In that context, Anarchism generated a novel circuit of texts through which an unprecedented relationship between printers, politics, authors, publishers and readers was established. Therefore, the decentralized financing and dissemination practices of the anarchist publishing movement revealed a broad thematic range of political concerns, that would finally shape, over the decades, the editorial interests of
Bugs severely hurt blockchain system dependability. A thorough understanding of blockchain bug characteristics is required to design effective tools for preventing, detecting and mitigating bugs. We perform an empirical study on bug characteristics in eight representative open source blockchain systems. First, we manually examine 1,108 bug reports to understand the nature of the reported bugs. Second, we leverage card sorting to label the bug reports, and obtain ten bug categories in blockchain systems. We further investigate the frequency distribution of bug categories across projects and programming languages. Finally, we study the relationship between bug categories and bug fixing time. The findings include: (1) semantic bugs are the dominant runtime bug category, (2) frequency distributions of bug types show similar trends across different projects and programming languages, (3) security bugs take the longest median time to be fixed, (4) 35.71% performance bugs are fixed in more than one year, performance bugs take the longest average time to be fixed.
Blockchain platforms, such as Ethereum, promise to facilitate transactions on a decentralized computing platform among parties that have not established trust. Recognition of the unique challenges of blockchain programming has inspired developers to create domain-specific languages, such as Solidity, for programming blockchain systems. Unfortunately, bugs in Solidity programs have recently been exploited to steal money. We propose a new programming language, Obsidian, to make it easier for programmers to write correct programs.