We present a state-of-art design in healthcare industry with blockchain technology. In our design of the systems, an individual's identity can be verified, and the electronic health records are processed through blockchain networks. The goal of creating such kind of systems is to facilitate identity verification, to provide ease of data access and sharing of electronic health records, and to maximize the protection of patients' data.
A phishing attack is one of the severe threats to the smartphone users. As per the recent lookout report, mobile phishing attack is increasing 85% year to year and going to become a significant threat to the smartphone users. This social engineering attack attempts to get the user’s password by disguising as trusted service provider. Most of the smartphone users are using the Internet services outside of the traditional firewall. Cloud-based documents are one of the primary targets of this phishing attack in mobile cloud computing. Also, most smartphone users are using the cloud storage in their device. To secure against this password attack in a mobile cloud environment, we propose a new authentication scheme to provide novel security to the mobile cloud services. This scheme will verify the user and service provider without transmitting the password using the Zero-knowledge proof based authentication protocol. Moreover, the proposed scheme will provide mutual authentication between the communication entities. The effectiveness of proposed scheme would be verified using protocol verification tool called Scyther.
Sidechains have long been heralded as the key enabler of blockchain scalability and interoperability. However, no modeling of the concept or a provably secure construction has so far been attempted. We provide the first formal definition of what a sidechain system is and how assets can be moved between sidechains securely. We put forth a security definition that augments the known transaction ledger properties of liveness and safety to hold across multiple ledgers and enhance them with a new “firewall” security property which safeguards each blockchain from its sidechains, limiting the impact of an otherwise catastrophic sidechain failure. We then provide a sidechain construction that is suitable for proof-of-stake (PoS) sidechain systems. As an exemplary concrete instantiation we present our construction for an epoch- based PoS system consistent with Ouroboros (Crypto 2017), the PoS blockchain protocol used in Cardano which is one of the largest pure PoS systems by market capitalisation, and we also comment how the construction can be adapted for other protocols such as Ouroboros Praos (Eurocrypt 2018), Ouroboros Genesis (CCS 2018), Snow White and Algorand. An important feature of our construction is merged-staking that prevents “goldfinger” attacks against a sidechain that is only carrying a small amount of stake. An important technique for pegging chains that we use in our construction is cross-chain certification which is facilitated by a novel cryptographic primitive we introduce called ad-hoc threshold multisignatures (ATMS) which may be of independent interest. We show how ATMS can be securely instantiated by regular and aggregate digital signatures as well as succinct arguments of knowledge such as STARKs and bulletproofs with varying degrees of storage efficiency.
Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez
We explore practical tradeoffs in blockchain-based biometric template storage. We first discuss opportunities and challenges in the integration of blockchain and biometrics, with emphasis in biometric template storage and protection, a key problem in biometrics still largely unsolved. Blockchain technologies provide excellent architectures and practical tools for securing and managing the sensitive and private data stored in biometric templates, but at a cost. We explore experimentally the key tradeoffs involved in that integration, namely: latency, processing time, economic cost, and biometric performance. We experimentally study those factors by implementing a smart contract on Ethereum for biometric template storage, whose cost-performance is evaluated by varying the complexity of state-of-the-art schemes for face and handwritten signature biometrics. We report our experiments using popular benchmarks in biometrics research, including deep learning approaches and databases captured in the wild. As a result, we experimentally show that straightforward schemes for data storage in blockchain (i.e., direct and hash-based) may be prohibitive for biometric template storage using state-of-the-art biometric methods. A good cost-performance tradeoff is shown by using a blockchain approach based on Merkle trees.
Recently, blockchain has been a disruptive technology for many systems, such as finance, e-health, supply-chain, and etc. Secure access to blockchain is the grand challenge for many systems. Key management is one of challenges to ensure secure access to blockchain. In this paper, we propose a framework for secure accessing to blockchain via multi-factor authentication. We combine both biometric and password authentications to secure private keys of users. The framework contains a secure device which has a biometric sensor to ensure secure access to private keys that extends the usability for secure accessing to blockchain.
This paper presents a distributed payment system based on payment tokens using Blockchain technology; these payment tokens protect the consumer from identity theft by unauthorized usage of his payment card details (PAN,CVV), due to mismanagements from other parties of the payment system. Furthermore, a private Blockchain consortium consolidates the security and privacy of the proposed payment system; this consortium consists of a private Blockchain called Bank Authority that acts as the interoperability domain, in addition to two other private Blockchains, each serves as the acquirer Bank and the issuer Bank, respectively, the security of this payment system is reinforced by introducing special nodes that verify and validate transactions, in order to detect and block fraud attempts. Moreover, to keep the payment system confidentiality and protect the economic interests of all the Banks in the system, only the transaction hash is recorded in the consortium's Blockchain and only the Banks involved in a transaction will have access to its details.
Amar Rasheed, Ray R. Hashemi, Ayman Bagabas, Jeffrey A. Young · 6 authors
The Internet of Things (IoT) has revolutionized the way of how pervasive computing devices communicate and disseminate information over the global network. A plethora of user data is collected and logged daily into cloud-based servers. Such data can be analyzed by the IoT infrastructure to capture users' behaviors (e.g. users' location, tagging of smart home occupancy). This brings a new set of security challenges, specifically user anonymity. Existing access control and authentication technologies failed to support user anonymity. They relied on the surrendering of the device/user authentication parameters to the trusted server, which hence could be utilized by the IoT infrastructure to track users' behavioral patterns. This paper, presents two novel configurable privacy-preserving authentication schemes. User anonymity capabilities were incorporated into our proposed authentication schemes through the implementation of two crypto-based approaches (i) Zero Knowledge Proof (ZKP) and (ii) Verifiable Common Secret Encoding (VCSE). We consider a user-oriented approach when determining user anonymity. The proposed authentication schemes are dynamically capable of supporting various levels of user privacy based on the user preferences. To validate the two schemes, they were fully implemented and deployed on an IoT testbed. We have tested the performance of each proposed schemes in terms of power consumption and computation time. Based on our performance evaluation results, the proposed ZKP-based approach provides better performance compared to the VCSE-based approach.
V M Harshini, Shreevani Danai, H R Usha, Manjunath R Kounte
The world is moving towards progress, to achieve the desired progress, the world should have a healthy population and health records are the projections of an individual's health over time. The centralised approach of maintaining the health records lead to data breaches. According to 2017 Ponemon Cost of Data Breach Study, the cost of the data breach for healthcare organizations estimated to be $380 per record. According to 2016 Breach Barometer Report, 27,314,647 patient records were affected. So we moved towards institution-driven approach of record maintenance, which didn't make much difference with the previously existing one. Since the patient have no control over the data, the chances of data being misused is high. So we need a patient-centered approach which is completely decentralised, which can identify data thefts, prevent data manipulation, and patient has the right in access control. Blockchain Technology serves as a best solution to address all the problems and fulfill the needs. Blockchain being a decentralised and distributed ledger it can also impact on billing, record sharing, medical research, identify thefts and financial data crimes in days to come. Implementation of smart contracts in health care can simplify things even better. Where invoking, record creation and validation will be done on Blockchain. This paper highlights on the patient-driven model of record maintenance using Blockchain technology where smart contracts can be incorporated in future days making it more potential in data exchange. Finding its huge scope, hoping that more researches will be carried out and practically implemented.
Counterfeiting constitutes a major challenge in current supply chains leading to millions of dollars of lost revenue for the involved parties every year. Hardware-based authentication solutions built upon Physically Unclonable Functions (PUF) and RFID tags prevent counterfeiting in a multiparty supply chain context. Unfortunately, these solutions cannot prevent counterfeiting and duplication attacks by supply chain parties themselves, as they can simply equivocate by duplicating products in their local and unique activity ledger. In this work, we study the benefits and challenges of using distributed ledger technology (or blockchain) to prevent counterfeiting even in the presence of malicious supply chain parties. In particular, we show that the provision of a distributed and append-only ledger jointly governed by supply chain parties themselves, by means of a distributed consensus algorithm, makes permissioned blockchains such as Hyperledger Fabric a promising approach towards mitigating counterfeiting. At the same time, the distributed nature of the ledger also possesses a privacy challenge as competing supply chain parties strive to protect their businesses from the prying eyes of competitors. Additionally, we show our efforts to build a blockchain-based counterfeiting prevention system for automotive supply chains, albeit the lessons learned are seamlessly applied to other supply chains. From our experience, we highlight two lessons: (i) the requirement of adding identities other than supply chain entities themselves to facilitate the tracking of goods; and (ii) the challenges derived from privacy enforcement in such a permissioned scenario. We thus finalize this work with a set of challenges that need to be overcome to achieve the best of both worlds: a solution to the counterfeiting problem using distributed ledger technology while providing the privacy notions of interest for supply chain parties.
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Authentication is the act of confirming the validity of someone’s personal data. In the traditional authentication system, username and password are sent to the server for verification. However, this scheme is not secure, because the password can be sniffed. In addition, the server will keep the user’s password for the authentication. This makes the system vulnerable when the database server is hacked. Zero knowledge authentication allows server to authenticate user without knowing the user’s password. In this research, this scheme was implemented with Guillou-Quisquater protocol. Two login mechanisms were used: file-based certificate with key and local storage. Testing phase was carried out based on the Open Web Application Security Project (OWASP) penetration testing scheme. Furthermore, penetration testing was also performed by an expert based on Acunetix report. Three potential vulnerabilities were found and risk estimation was calculated. According to OWASP risk rating, these vulnerabilities were at the medium level.
In this paper, we propose a blockchain inspired Internet-of-Things architecture for creating a transparent food supply chain. The architecture uses a proof-of-object-based authentication protocol, which is analogous to the cryptocurrency's proof-of-work protocol. The complete architecture was realized by integrating a radio frequency identification (RFID)-based sensor at the physical layer and blockchain at the cyber layer. The RFID provides a unique identity of the product and the sensor data, which helps in real time quality monitoring. For this purpose, a small feature size 900-MHz RFID coupled sensor was fabricated and demonstrated for real time sensor data acquisition. The blockchain architecture aids in creating a tamper-proof digital database of the food packages at each instance. A detailed security analysis was performed to investigate the vulnerability of the proposed architecture under different types of cyber attacks.
Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez
Blockchain technology has become a thriving topic in the last years, making possible to transform old-fashioned operations to more fast, secured, and cheap approaches. In this study we explore the potential of blockchain for biometrics, analyzing how both technologies can mutually benefit each other. The contribution of this study is twofold: 1) we provide a short overview of both blockchain and biometrics, focusing on the opportunities and challenges that arise when combining them, and 2) we discuss in more detail blockchain for biometric template protection.
As Blockchain technology become more understood in recent years and its capability to solve enterprise business use cases become evident, technologist have been exploring Blockchain technology to solve use cases that have been daunting industries for years. Unlike existing technologies, one of the key features of blockchain technology is its unparalleled capability to provide, traceability, accountability and immutable records that can be accessed at any point in time. One application area of interest for blockchain is securing heterogenous networks. This paper explores the security challenges in a heterogonous network of IoT devices and whether blockchain can be a viable solution. Using an experimental approach, we explore the possibility of using blockchain technology to secure IoT devices, validate IoT device transactions, and establish a chain of trust to secure an IoT device mesh network, as well as investigate the plausibility of using immutable transactions for forensic analysis.
Electronic health records possess the patient's medication details and their health history. The health records attract the attention of the attackers' as it possesses invaluable information. Loss of electronic health record leads to a wrong medication or surgery. Healthcare systems provide fewer security measures to secure the health records. Blockchain is a distributed and decentralized ledger that plays a vital role in securing the data and transactions. Introduction of blockchain in the healthcare systems protects the health records from the attackers. However, the blockchain faces phishing, dictionary-based, cold wallets, and hot wallets attacks. This paper proposes a multilevel authentication-based scheme to protect the blockchain from the attacks mentioned above.
Shibasis Patel, Anisha Sahoo, Bhabendu Kumar Mohanta, Soumyashree S. Panda · 5 authors
Over the past decade, a lot of evolution has happened in the field of security specifically authentication system. The most commonly used authentication service we use now is OAuth 2.0 based authentication. In this method, we are dependent on a 3rd party authentication service provider to which we need to trust. Though this model is used extensively nowadays, studies show that it is still vulnerable to several hacks. In addition to that, the 3rd party authentication provider has total control over the user data to which they can leak or modify at their will. Thus the use of OAuth 2.0 based protocol has raised security and privacy concerns. In this paper, blockchain and its use cases are studied and an alternative way of authentication service has been proposed based on Ethereum Blockchain called DAuth. Furthermore, a prototype has been developed which enables user authentication on the site. DAuth proposes to enhance transparency and user control in transactions which involves identity management.
In this paper we propose a novel system for identity verification by amalgamating online signature verification, machine learning, IOT and blockchain to garner their potentials to cope up and to contain this risk of identity theft specifically in the case of online transactions. In this system signals of roll, pitch and yaw values retrieved from MPU6050 sensor (Inertial Measurement Unit) are analysed using Digital Time Wrapping to obtain DTW minimum distance to verify the identity of the user. In case of cryptocurrencies, we propose a system where private key is not stored anywhere but the same unique private key, assigned to the user by Blockchain, is generated every time with the help of method incorporating biometrics and machine learning. The required data will then be sent to blockchain with the help of IOT system to complete the transaction.
Brain-computer interface can be currently accelerated to develop the exoskeleton for healthy people as well as patients who are unable to move muscles around the world. In this situation, the communication between the electroencephalogram (EEG) and prosthesis discovers the vulnerabilities to taking personal information. However, previous researches only focus on the analysis of attack pattern rather than fixing the vulnerability. In order to complement the vulnerability, we propose a blockchain platform in which try to identify the modulated data when server is attacked. Also, we find out potential risks in EEG data with non-blockchain environments after attack in our study. As a result, the proposed system can guarantee the integrity of EEG data by knowing the change of hash, and can prevent attacks such as hijacking, sniffing, and eavesdropping.
Yingying Yao, Xiaolin Chang, Jelena Mišić, Vojislav B. Mišić · 5 authors
As modern vehicles and distributed fog services advance apace, vehicular fog services (VFSs) are being expected to span across multiple geo-distributed datacenters, which inevitably leads to cross-datacenter authentication. Traditional cross-datacenter authentication models are not suitable for the scenario of high-speed moving vehicles accessing VFS, because these models either ignored user privacy or ignored the delay requirement of driving vehicles. This paper proposes a blockchain-assisted lightweight anonymous authentication (BLA) mechanism for distributed VFS, which is provisioned to driving vehicles. BLA can achieve the following advantages: 1) realizing a flexible cross-datacenter authentication, in which a vehicle can decide whether to be reauthenticated or not when it enters a new vehicular fog datacenter; 2) achieving anonymity, and granting vehicle users the responsibility of preserving their privacy; 3) it is lightweight by achieving noninteractivity between vehicles and service managers (SMs), and eliminating the communication between SMs in the authentication process, which significantly reduces the communication delay; and 4) resisting the attack that the database governed by one center is tampered with. BLA achieves these advantages by effectively combining modern cryptographical technology and blockchain technology. These security features are demonstrated by carrying out security analysis. Meanwhile, extensive simulations are conducted to validate the efficiency and practicality of BLA.
Blockchain technology has attracted a lot of attention in the previous years as a secure way to protect transactions in different processes. It has been particularly used to define cryptocurrencies. While inherently secure against classical single node attacks, the blockchain cryptocurrencies have recently been subject to attacks by malwares able to capture a single user wallet and its included keys. In this work we propose the use of biometric cryptosystems to control the access to the wallets on single machines. After a brief description of the blockchain, the cryptocurrencies and the possible attacks, the paper describes the use of convolutional neural network face recognition as a tool to extract biometric features that help in a key binding approach to protect the personal data in the wallet. Experiments have been conducted on three independent face datasets and the results obtained are satisfactory. The equal error rate between false acceptance and false rejection is negligible when testing on images from the same dataset used for the training of the convolutional neural network. This generalizes well when experimenting on two other independent datasets. These results prove that face cryptosystems can be used to protect the access on sensitive data existing in the wallets of many cryptocurrencies.