Pavlos Papadopoulos, Nikolaos Pitropakis, William J. Buchanan
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,379 results · page 37 of 58
Pavlos Papadopoulos, Nikolaos Pitropakis, William J. Buchanan
No abstract is available for this record.
Abdullah Al Omar, Abu Kaisar Jamil, Amith Khandakar, Abdur Razzak Uzzal · 7 authors
A smart city ensures quality maintenance in diverse sectors, namely citizen safety, security, healthcare, transportation, and energy. Besides, data privacy and security have become an uprising concern for Electronic Health Records (EHR) in smart cities. This is because the EHR platforms are constantly getting cyber threats from cybercriminals. On the other hand, health insurance companies offer certain specific policies that require the association of patients' financial data with EHRs. Thus, additional security concern arises as fraudulent entities can alter these insurance policies. An extra challenge is triggered as patients need to validate their identities separately while communicating with different smart healthcare entities. This is because these healthcare facilities and insurance companies ought to ensure authenticity before offering any service for an individual. Hence, we have implemented a blockchain framework to safeguard patients' personal information and insurance policy. In this paper, we propose a solution for the healthcare system that provides data privacy and transparency. Furthermore, in the proposed system, insurance policies are incorporated in blockchain via the Ethereum platform and data privacy is shielded with cryptographic tools.
Mehdi Sookhak, Mohammad Reza Jabbarpour, Nader Sohrabi Safa, F. Richard Yu
No abstract is available for this record.
Lihua Song, Xinran Ju, Zongke Zhu, Mengchen Li
Abstract Information security has become the focus problem in the Internet of Things, and the traditional centralized access control model is faced with threats such as single point failure, internal attack, and central leak. In this paper, we proposed a model to improve the access control security of the Internet of Things, which is based on zero-knowledge proof and smart contract technology in the blockchain. Firstly, we deployed the attribute information of access control in the blockchain, which relieves the pressure and credibility problem brought by the third-party information concentration; Secondly, the encrypted access control token is used to gain the access permission of the resources, which makes the user's identity invisible and effectively avoids the attribute ownership exposure problem; Besides, the use of smart contracts solves the problem of low computing efficiency of Internet of Things devices and the waste of blockchain computing power resources; Finally, a prototype of Internet of Things access control system based on blockchain and zero-knowledge proof technology is implemented. The test analysis results show that the model achieves effective attribute privacy protection, compared with the Attribute-Based Access Control model of the same security level, the access efficiency increases linearly with the increase of access scale.
Achraf Fayad
The interconnection of private resources on public infrastructure, user mobility and the emergence of new technologies (vehicular networks, sensor networks, Internet of things, etc.) have added new requirements in terms of security on the server side as well as the client side. Examples include the processing time, mutual authentication, client participation in the choice of security settings and protection against traffic analysis. Internet of Things (IoT) is in widespread use and its applications cover many aspects of today's life, which results in a huge and continuously increasing number of objects distributed everywhere.Security is no doubt the element that will improve and strengthen the acceptability of IoT, especially that this large scale deployment of IoT systems will attract the appetite of the attackers. The current cyber-attacks that are operational on traditional networks will be projected towards the Internet of Things. Security is so critical in this context given the underlying stakes; in particular, authentication has a critical importance given the impact of the presence of malicious node within the IoT systems and the harm they can cause to the overall system. The research works in this thesis aim to advance the literature on IoT authentication by proposing three authentication schemes that satisfy the needs of IoT systems in terms of security and performance, while taking into consideration the practical deployment-related concerns. One-Time Password (OTP) is an authentication scheme that represents a promising solution for IoT and smart cities environments. This research work extends the OTP principle and propose a new approach to generate OTP based on Elliptic Curve Cryptography (ECC) and Isogeny to guarantee the security of such protocol. The performance results obtained demonstrate the efficiency and effectiveness of our approach in terms of security and performance.We also rely on blockchains in order to propose two authentication solutions: first, a simple and lightweight blockchain-based authentication scheme for IoT systems based on Ethereum, and second, an adaptive blockchain-based authentication and authorization approach for IoT use cases. We provided a real implementation of our proposed solutions. The extensive evaluation provided, clearly shows the ability of our schemes to meet the different security requirements with a lightweight cost in terms of performance.
Yashita Goswami, Ankit Agrawal, Ashutosh Bhatia
E-governance, i.e., the use of information technology for government activities to provide services, exchange information, etc. are becoming increasingly popular. One such area of e-governance is e-tendering. While e-tendering makes the tendering process more efficient, a trust deficit remains between the citizens and the government, due to the centralized management of the whole tendering process. Several research works provide a decentralized solution to make the process of e-tendering more secure, transparent, and fair. However, in the present time, the government posts the problems/issues currently they are dealing with; and seems interested in taking the suggestions from the citizens to make the better solution for the problem. Thus, in this paper, a permissioned blockchain-based approach to provide a transparent and fair tendering system with citizens' active participation and tracking of funds is presented. In the proposed scheme, the citizens can see the tendering activities transparently and give ideas and suggestions to solve the government's posted problems and receive a due credit of that contribution is a fair manner.
Francisco José de Haro-Olmo, Ángel Jesús Varela‐Vaca, José Antonio Álvarez Bermejo
The research presented aims to investigate the relationship between privacy and anonymisation in blockchain technologies on different fields of application. The study is carried out through a systematic literature review in different databases, obtaining in a first phase of selection 199 publications, of which 28 were selected for data extraction. The results obtained provide a strong relationship between privacy and anonymisation in most of the fields of application of blockchain, as well as a description of the techniques used for this purpose, such as Ring Signature, homomorphic encryption, k-anonymity or data obfuscation. Among the literature researched, some limitations and future lines of research on issues close to blockchain technology in the different fields of application can be detected. As conclusion, we extract the different degrees of application of privacy according to the mechanisms used and different techniques for the implementation of anonymisation, being one of the risks for privacy the traceability of the operations.
Kaida Jiang, Yifei Gao, Jiawei Xiao, Futai Zou
In traditional centralized application construction and data storage modes, the application servers and the users are not in equal position in user information management. The application server can store and abuse the user's information under the circumstances that the users are not aware, and the user cannot revoke the authorization from the application server. Therefore, this paper proposes an identity management system combined with blockchain technology, which can return the management right of user information to users. This system adopts a three-layer architecture composed of blockchain layer, virtual chain layer and storage layer, and encapsulates all functions in each layer. It has good flexibility, and is easy to add new technologies, with good extensibility. The blockchain records the user's information state to realize the consensus and integrity of the user's data. The virtual chain layer is responsible for the main logical functions and encapsulates the user's request into a blockchain transaction, maintaining a good portability. The storage layer is responsible for the actual file storage and is responsible for file routing, backup, and query. Comprehensively speaking, based on the above three layers' architecture, the system implements the user's privacy granularity control, the user file's external storage, and combines the zero-knowledge proof to update the user's private key. In view of the application environment of this system, the access time delay and efficiency of the P2P storage system are simulated. It solves the problems of centralized application construction and data storage mode under which users cannot fully control personal information and privacy protection.
U. P. Ellewala, W.D.H.U Amarasena, H.V Sachini Lakmali, L.M.K Senanayaka · 5 authors
The boundaries between personal and business communications is a key issue faced by most organizations. Use of unsecured and unsafe applications in workplaces pose enormous security risks. Companies are not adequately aware about the applications that are being used in their employees' devices. When it comes to critical business communication involving exchanging trade secrets, making business referrals and strategic business decisions, protecting of messages and shared files becomes a challenge. Most publicly available communication platforms do not empower organizations to regulate, track and scale their communication and does not provide compliance with data protection frameworks, which can result in cross industry system risks. As a result, both individuals and organizations express deep concern about data security and protection of privacy when using Instant Messaging applications. Non-repudiation in communications not only conveys to the user, recognition of the communication process, but it is also a crucial way to establish a relationship of trust and to overcome trust disputes. Our primary objective, through this research, is to develop a chat application with more secure channels of enterprise level communication. Using new technologies such as blockchain, which operate on a decentralized model, we can surmount the drawbacks of traditional messaging applications, thereby ensuring confidentiality, integrity and availability of official data, along with advanced auditing features.
Jihad Fraij, Ashraf ALDabbas, Nemer Aburumman
Blockchain as a distributed system that confirms security and reliability have started a new era of a solid and consensus system.Blockchains focus on cryptocurrency is encouraging many other processes to follow the same reliable approach of security.Almost all procedures and operations are now invited to be electronically performed in the digital Ethereum network that has been presented. Moreover, this study proposed the use of an Ethereum network on a blockchain platform in the study when it was moved to a blockchain network to confirm transparency.An E-voting system sample has been tested by using an Ethereum network smart contracts inwhich solidity language and wallets were used. In the voting test, the Ethereum blockchain will be able to collect records in which voters can use their Ethereum wallets or android devices to submit their votes in a consensus node.The researchers studied the voting system taking Jordan as a case study.This study recommended the adaptation of e-voting to support transparency and voters trust to reduce corruption and unreliability in the voting processes. Moreover, the use of this system will allow a voter to vote from home in the time of the pandemic.\n\n
Anderson Boa Morte, Anália Cristina Bezerra Tiburtino Meira, Rostand Costa, Dênio Mariz
A tecnologia de registro distribuído (DLT – Distributed Ledger Technology) pode ser muito útil para o tratamento de dados pessoais em conformidade com a Lei Geral de Proteção de Dados Pessoais (LGPD), devido a características como transparência e segurança. No entanto, outras características como a imutabilidade e o caráter distribuído podem dificultar essa tarefa. Assim, este trabalho analisa os desafios da conciliação entre DLT e o tratamento de dados em conformidade com a LGPD. Como objeto de análise, utilizou-se o projeto Datavalid do SERPRO - Serviço Federal de Processamento de Dados, contratado pela Uber, em um cenário hipotético em que o tratamento de dados foi realizado utilizando-se o Hyperledger Fabric.
Pedro Ivo de Castro Oyama, Jó Ueyama, Paulo Matias
Social media has become part of our daily lives. It brought significant developments in the way we communicate, but it also raised some concerns, including privacy and censorship. In this context, this work presents a social media platform -- EtherYou -- that makes use of cryptographic primitives and an Ethereum smart contract to overcome these issues. Experiments were conducted to evaluate the operating costs involved. The results showed considerable values for senders, zero for receivers, and zero maintenance costs, indicating its potential in scenarios with a reduced number of content producers and a large number of consumers. The proposal offers users privacy over their data, transparency on the system behaviour and censorship resistance.
Qinan Li, Zhihao Xue
With the rapid development of blockchain, many service providers tend to provide users with network resources and services on the basis of blockchain, and most network resources are inseparable from the authorization. However, the current authorization mechanism based on blockchain is not perfect, which is easy to cause the user's identity attributes to be leaked, and not conducive to protecting the privacy of users. In order to improve the authorization mechanism based on the blockchain and protect the user's privacy to the greatest extent during the authorization process, we proposed a privacy-protecting authorization system based on blockchain and zk-SNARK. First of all, SP can authorize users through the blockchain smart contract. Second, in the authorization process, we introduced zk-SNARK. Using the zero-knowledge property of zk-SNARK, the SP can still authorize the users without knowing the identity attribute value of the users. Therefore, the proposed system can better protect the users' attribute privacy. Finally, we analyze the security of the proposed system, and the results show that it is computationally infeasible for an attacker to attack the system.
Xuan Son Ha, Hai Trieu Le, Nadia Metoui, Nghia Duong‐Trung
The cash on delivery (CoD) is currently one of the significant payment mechanism in many developing countries' E-commerce systems. A transaction between a seller and a purchaser is completed when the seller has agreed to exchange packaged goods for a payment from the purchaser. Building highly trustworthy, accountable, credible, and decentralized CoD systems to trace and track physical items is a very challenging task. Several technologies and models for deploying CoD-based applications have been proposed in the literature. In most scenarios, these models have been created with the aim of accommodating collaborative processes involving multiple participants, e.g. seller, purchasers, and shippers, that belong to independent organizations. However, these approaches face several limitations and require appropriate improvement to sustain CoD-based systems' adoption further. First of all, there are no incentives for participants to act honestly. Secondly, the shippers are often kept out of the delivery chain and are affected by or not involved in any incentives or logs. Last but not least, users' privacy can be easily compromised and sensitive data collected and generated during the transactions can be easily accessed and abused. Building upon these critical insights, we propose a novel decentralized marketplace mechanism using the smart contract via blockchain technology. Our approach operates by incentivizing all the participants to act honestly and fulfill their obligations without resorting to a trusted third party. It also integrates adapted access control protocols to protect user privacy. The model's architecture shows that our approach guarantees integrity and robustness. It contributes to effectively addressing the issues listed above. A complete code solution is publicized on the authors' GitHub repository to engage further reproducibility and improvement.
Arij Alfaidi, Edward Chow
Mobile health applications connect to wearable devices with inbuilt sensors to monitor critical human body parameters such as heart rate, pulse rate, body temperatures ,and others. This paper will introduce our system, Health Record Chain HRC, to investigate how to design and implement secure mobile health systems that leverage the smart mobile devices' new authentication and geo-location mechanism. HRC introduces an enhancing framework to ensure the users' security and privacy and conform to the related regulations ( General Data Protection Regulation GDPR, Health Insurance Portability and Accountability Act HIPPA) using blockchain. The immutability of blockchain conflicts with GDPR’ "Right to be forgotten" when the user can delete all of his/her data. This work implements a blockchain system with a mobile application and a web interface to address this conflict by hashing the Electronic health record EHR to Ethereum based blockchain.
Donghee Shin, William T. Bianco
Objectives This study considers the affordance of users' perceived technological property of blockchains and investigates how users discover the possible actions that can be performed within blockchain media. With a focus on the role of trust, it analyzes how motivational affordances in blockchain media influence user experience Methods Qualitative methods are used to obtain the depth of understanding and elicit the perspective of blockchain media. We then conduct a survey to analyze the affordance of trust in the acceptance of blockchain media Results Our confirmed model indicates a heuristic dimension of trust regarding underlying ties to affective and technological affordances. These findings imply that cognitive heuristics affect users' decision making about privacy and security on blockchain media. These heuristics lead users to engage in uncertain and even risky transactions in blockchain media. Conclusions Despite the exponential growth in blockchain development, there has been little attention paid on how technological innovations of blockchains can produce value in the media sector. Our findings provide a lens to understand the blockchain's usability problems by pairing heuristics to blockchain design and user experience principles.
Ae-Seon Son, Soo-Bin Yoo, Jung-Hwa Jo, Su-Min Yoo
스마트 컨트랙트는 분산 원장 환경에서 데이터를 기록하여 데이터의 무결성과 유효성이 검증된다는 점과 작성된 코드에 의하여 설정된 조건이 충족되면 자동으로 이행되는 특성 때문에 신뢰성을 요구하는 다양한 자동화 시스템에 적용되고 있다. 스마트 컨트랙트가 활발하게 사용되고 있는 분야 중 하나는 계약 체결과 관련된 분야이다. 하지만 블록체인이 가진 분산 원장 환경의 특성상 거래되는 데이터가 모든 네트워크 참여자들에게 공유되기 때문에 기밀성이 요구되는 데이터는 저장하지 못한다는 문제가 있다. 본 논문은 스마트 컨트랙트 기반의 계약 플랫폼에 비밀공유 기법을 이용한 계약 내용을 별도의 데이터베이스에 저장하는 방식을 적용하여 기밀성과 무결성을 보장함으로써 비대면으로 계약서를 작성하는 과정에서 신뢰성 있는 계약 체결이 가능하도록 하는 것에 궁극적 목표를 둔다.
Muhammad Al-Abdullah, Izzat Alsmadi, Ruwaida AlAbdullah, Bernie Farkas
Purpose The paper posits that a solution for businesses to use privacy-friendly data repositories for its customers’ data is to change from the traditional centralized repository to a trusted, decentralized data repository. Blockchain is a technology that provides such a data repository. However, the European Union’s General Data Protection Regulation (GDPR) assumed a centralized data repository, and it is commonly argued that blockchain technology is not usable. This paper aims to posit a framework for adopting a blockchain that follows the GDPR. Design/methodology/approach The paper uses the Levy and Ellis’ narrative review of literature methodology, which is based on constructivist theory posited by Lincoln and Guba. Using five information systems and computer science databases, the researchers searched for studies using the keywords GDPR and blockchain, using a forward and backward search technique. The search identified a corpus of 416 candidate studies, from which the researchers applied pre-established criteria to select 39 studies. The researchers mined this corpus for concepts, which they clustered into themes. Using the accepted computer science practice of privacy by design, the researchers combined the clustered themes into the paper’s posited framework. Findings The paper posits a framework that provides architectural tactics for designing a blockchain that follows GDPR to enhance privacy. The framework explicitly addresses the challenges of GDPR compliance using the unimagined decentralized storage of personal data. The framework addresses the blockchain–GDPR tension by establishing trust between a business and its customers vis-à-vis storing customers’ data. The trust is established through blockchain’s capability of providing the customer with private keys and control over their data, e.g. processing and access. Research limitations/implications The paper provides a framework that demonstrates that blockchain technology can be designed for use in GDPR compliant solutions. In using the framework, a blockchain-based solution provides the ability to audit and monitor privacy measures, demonstrates a legal justification for processing activities, incorporates a data privacy policy, provides a map for data processing and ensures security and privacy awareness among all actors. The research is limited to a focus on blockchain–GDPR compliance; however, future research is needed to investigate the use of the framework in specific domains. Practical implications The paper posits a framework that identifies the strategies and tactics necessary for GDPR compliance. Practitioners need to compliment the framework with rigorous privacy risk management, i.e. conducting a privacy risk analysis, identifying strategies and tactics to address such risks and preparing a privacy impact assessment that enhances accountability and transparency of a blockchain. Originality/value With the increasingly strategic use of data by businesses and the contravening growth of data privacy regulation, alternative technologies could provide businesses with a means to nurture trust with its customers regarding collected data. However, it is commonly assumed that the decentralized approach of blockchain technology cannot be applied to this business need. This paper posits a framework that enables a blockchain to be designed that follows the GDPR; thereby, providing an alternative for businesses to collect customers’ data while ensuring the customers’ trust.
Tyron Ncube, Nomusa Dlodlo, Alfredo Terzoli
The widespread adoption of blockchain technology has had a big impact on how people transact in the digital world. Individuals can transact in an anonymous but transparent manner. Their identities remain hidden but the records of their transactions are publicly available. This has had its benefits in certain application areas but might not be suited for transactions where it is important to know who you are dealing with and in circumstances where the data in the blockchain might be confidential. Private blockchain networks are better suited for such transactions as only authorized users can transact on the network. Sensitive data can also be stored on the blockchain as it is possible to restrict the users that can see the details of the transactions. This paper describes how to create a private blockchain network and how other users can join the network. It also details the benefits of using a private blockchain network with regards to data privacy as opposed to a public network.
Shaoyong Guo, Baoyu Xiang, Xuwei Xia, Zhenhua Yan · 5 authors
<title>Abstract</title> Data is the most important factor in building a smart city. City data is composed of many data islands, such as transportation, industry, and residents. In order to build a smart city, breaking data islands, achieving trusted and collaborative sharing of data, while protecting data privacy are essential. As a distributed ledger, the blockchain can solve the problem of data trust. Federated learning achieves data privacy protection by sharing model parameters instead of original data. However, it still has some problems such as malicious nodes and differential attacks. This paper proposes a data sharing mechanism that combines blockchain and federated learning over smart city. Firstly, the blockchain is combined to ensure the credibility of the performance information of the work nodes, then the work node selection algorithm is designed, and a consensus incentive mechanism IPoQ is proposed for efficient federated learning tasks. Finally, differential privacy technology is introduced to resist differential attack. Experimental results show that the methods proposed in this paper achieves an effective federated learning data sharing mechanism.
Francis Mendoza, Hans Walter Behrens
Smart cities have emerged as one of the most promising applications of cyber-physical systems (CPS), carrying the potential to serve the various interests of the public and private sectors at large. However, contemporary smart city infrastructure commonly uses heavily-centralized network architectures, reducing failure resilience and application flexibility. This centralization also imposes high barriers to entry for public access, limiting usage and oversight opportunities. To address these limitations, we describe Arbiter, a novel fog- and edge-based communication architecture based on the concept of a Decentralized Autonomous Organization (DAO). Arbiter aims to improve the socioeconomic equity of the local citizenry by (1) acting as a management layer for citywide CPS assets, (2) providing a compliance layer for managing human capital, and (3) offering a data protection layer to ensure that citizens retain full control of their personal data. We then analyze in detail the technical, socioeconomic, and ethical implications of Arbiter, and contextualize its role in the modern smart city.
Norah Alilwit
Blockchain is one of the most trending technologies in past five years and it is called the new generation of the internet. Bitcoin was the first technology that used blockchain concept in its system. Blockchain has intense attention from academic community, developers and programmers, because of its distinctive properties such as decentralization, persistency, anonymity and auditability. Blockchain technology has evolved and is applicable in various applications outside the field. This paper provides background on blockchain technology and presents a suitable and logical solution for user authentication based on blockchain via the unified smart pass platform that allows the user to login with all service providers channels.
Natalia Trojanowska, Michał Kędziora, Moataz Hanif, Houbing Song
The purpose of this paper is to present Ethereum decentralized application development methodology with focus on security issues and its verification. We introduce key concepts that are related to developing decentralized applications and Crypto Collectibles games. Moreover, the requirements for blockchain projects were presented along with a selection of use case examples. The paper concerns the application design process issues, starting from the methodology used, going through the description of requirements and specification, ending up with the implementation. Finally, an overview of the issues associated with the security of Ethereum decentralized applications is presented. We compared guidelines from Ethereum Smart Contract Best Practices by ConsenSys, Smart Contract Security Verification Standard created by SecuRing, Decentralized Application Security Project introduced by NCC Group, Security Considerations from Solidity documentation, Ethereum Smart Contracts Security Recommendations from Guylando Knowledge Lists, and Smart Contract Weakness Classification and Test Cases. It was discussed which guideline should be followed and when should the verification take place, considering the life cycle of the application. The paper covers different security risks related to blockchain games along with examples of how vulnerabilities can arise, how they can be detected during security verification phase, and countermeasures to address them.
James David Hackman
Received wisdom portrays digital records as guaranteeing perpetuity; as the New York Times wrote a decade ago: "the web means the end of forgetting". The reality however is that digital records suffer similar risks of access loss as the analogue versions they replace. Often this risk is outsourced to specialised third parties. Common use cases include Personal Information Management (PIM): e.g. calendars, diaries, tasks, etc. Frequently these are outsourced at two removes - firstly by the individual to their employer (e.g. using a company system) and then by their employer to an external provider. So enters a new risk: organisational change; by the time the information is required the organisational chain that links user to data may be broken: the employer transitions to a different provider, the employee leaves the company, the IS provider pivots to new offerings. The advent of Distributed Ledger Technology (DLT) could help mitigate these risks; and has led to a re-evaluation of the relationship between data creation and ownership. Although DLT is an imprecise term, it typically involves data storage across organisationally separate entities in a cryptographically secure form; and therefore could present a partial solution to the risk. This project presents the first research that applies DLT to the field of PIM, furthering design science state of the art by a novel implementation of a calendar application on the Ethereum blockchain. It also extends current research in utilising DLT in digital preservation, namely by enacting a continuum approach within a DL that allows for transfer of ownership of digital objects as they transition from individual to collective relevance. Finally it provides guidelines for future use of DLT within digital preservation.