With the development of the data-sharing system in recent years, financial management systems and their privacy have sparked great interest. Existing financial data-sharing systems store metadata, which include a hash value and database index on the blockchain, and store high-capacity actual data in the center database. However, current data-sharing systems largely depend on centralized systems, which are susceptible to distributed denial-of-service (DDoS) attacks and present a centralized attack vector. Furthermore, storing data in a local center database has a high risk of information disclosure and tampering. In this paper, we propose the ChainMaker Privacy Computing (CPC) system, a new decentralized data-sharing system for secure financial data, to solve this problem. It provides a series of financial data information and a data structure rather than actual data on the blockchain to protect the privacy of data. We utilize a smart contract to establish a trusted platform for the local database to obtain encrypted data. We design a resource catalog to provide a trusted environment of data usage in the privacy computing system that is visible for members on the blockchain. Based on cipher-policy attribute-based encryption (CP-ABE), We design a CPC-CP-ABE algorithm to enable fine-grained access control through attribute based encryption. Finally, We propose an efficient scheme that allows authenticated data-sharing systems to perform Boolean searches on encrypted data information. The results of experiment show that the CPC system can finish trusted data sharing to all organizations on the blockchain.
The increasing popularity of blockchain and cryptocurrencies has led to a considerable proliferation of the cryp-tocurrency market in recent years, pulling more investors into the trillion-dollar industry. The increasing number of users has led to increasing privacy concerns. While the network's ability to facilitate financial inclusion is enhanced by the blockchain's openness and public nature, it also exposes users' transaction histories, raising the possibility of privacy violations and other concerns, such as user profiling. To address these privacy challenges, various techniques emerged, categorized as joint transactions and mixing services. While promising, these methods have limitations, such as potential information leakage and the need for trust in centralized entities. To overcome these shortcomings, we propose a novel system that combines joint transactions and mixing services, incorporating Zero-Knowledge Proofs (ZKPs) for enhanced privacy guarantees. Our proof of concept on the Ethereum blockchain demonstrates improved privacy while providing the basic requirements. The evaluation includes performance metrics and security analysis, focusing on key considerations—unlinkability, verifiability, and double-spending. Our method achieves unlinkability by obfuscating transaction paths through multiple stages (ZKPs, CoinJoin, CoinSwap), ensures verifiability through signatures and commitment exchanges, and prevents double-spending through nonce utilization, all while maintaining a feasible execution time.
The PDPA laws are the first data privacy laws to protect all Thai citizens since 2018. The consent management system (CMS) is a core module of Thailand’s PDPA laws. It maintains complex and dynamic contents of user consent which are updated and changed all the time. The best network that can store a CMS’s historical data is blockchain while the best tool for maintaining it is a smart contract which works on Ethereum-based blockchain. This paper aims to apply the Smart contract technique to enhance a consent management system to perform a better data privacy service. This research paper proposes a Smart Contract-Based Consent Management System (SCCMS) as an innovative solution to enhance data privacy protection. By leveraging blockchain technology and smart contracts, the SCCMS aims to provide a transparent, secure, and decentralized framework for managing user consent, thereby ensuring greater control and transparency in the handling of personal data. Our experiment result outperforms a regular CMS system
As the artificial intelligence, large model, Metaverse, and Web 3.0 develop rapidly, data is being traded constantly. Existing data exchange methods primarily rely on trusted third parties, which compromises fairness and decentralization. Moreover, existing methods often overlook data access control during trading and typically employ an one-to-one model, resulting in high communication and computational overhead. To address these issues, this article makes the following contributions. First, we propose a blockchain-based secure and fair data trading scheme named fair data trading (FairDT). By leveraging blockchain and smart contracts, FairDT achieves decentralized data trading with high throughput and scalability. Second, we design a fair data exchange mechanism that utilizes commitment schemes, Merkle trees, and other techniques to facilitate dispute resolution with constant on-chain cost when conflicts arise. Third, we incorporate attribute-based encryption to enable fine-grained access control in data trading, thereby reducing the computational burden on data sellers. Finally, we prove that FairDT satisfies access control, fair exchange, completeness, and termination properties. Experimental results on the Ethereum testnet demonstrate that the on-chain cost remains constant, showing that FairDT is highly efficient.
Digital certificate forgery is becoming increasingly common and impacting information security. This research develops a framework and system for verifying digital document signing certificates by applying blockchain technology and smart contracts. Smart contracts are created on the Ethereum network to define various conditions in developing information systems that support adding digital certificates to the blockchain, verifying digital certificates, and accessing digital certificates. The research tested the security of smart contracts using the Slither tool and analyzed the shortcomings of smart contract development using the Solhint tool. The research results indicate that smart contracts can function correctly without security risks and can be used to verify digital certificate forgery. Additionally, smart contracts can be utilized in developing information systems and further developed with other related research in the future.
Federated learning (FL) has emerged as an exceptionally promising method within the realm of machine learning, enabling multiple entities to jointly train a global model while maintaining decentralized data. This paper presents a comprehensive review of federated learning methodologies, applications, and challenges. We begin by elucidating the fundamental concepts underlying FL, including federated optimization algorithms, communication protocols, and privacy-preserving techniques. Subsequently, we delve into various domains where FL has found significant traction, examples include healthcare, finance, and the Internet of Things (IoT), showcasing successful deployments and innovative strategies. Furthermore, we discuss the inherent challenges associated with federated learning, such as communication overhead, heterogeneity of data sources, and privacy concerns, and explore state- of-the-art solutions proposed in literature. Finally, we outline future research directions in federated learning, including advancements in privacy-preserving techniques, scalability improvements, and extension of FL to emerging domains. This thorough examination provides a valuable asset for researchers, practitioners, and policymakers keen on grasping the panorama of federated learning and its ramifications for collaborative machine learning in dispersed settings.
Daryn Monteiro, Ishaan Mavinkurve, Parth Kambli, Prof. Sakshi Surve
Abstract: Artificial Intelligence has found widespread use across various industries, from optimizing manufacturing workflows to diagnosing health conditions. However, the large volumes of data required to train AI models raise privacy concerns, especially when stored in centralized databases vulnerable to leaks. Federated Learning solves this problem by training models collaboratively by avoiding centralization of the sensitive data, preserving privacy while allowing decentralized models to be exported to edge devices. This paper explores Federated Learning, focusing on its technical aspects, algorithms, and decentralized architecture. By keeping raw data localized, Federated Learning enables global models while safeguarding individual privacy, fostering collaboration across sectors like healthcare, finance, and IoT. It also addresses challenges such as privacy vulnerabilities and model aggregation across devices, proposing solutions to strengthen Federated Learning's effectiveness. Ultimately, this study highlights Federated Learning's pivotal role in the future of AI, where privacy preservation and collaboration are key. By balancing model performance with data privacy, Federated Learning stands as a promising framework for responsible and inclusive AI development.
Background: Land records have traditionally derived their credibility from a central database of local government records, with copies issued to land owners. Physical records are the only credible source of any information related to land ownership that has been in existence for a long time. However, physical records are prone to manipulation and fraud. Recently, some academic research has begun to address the potential use of blockchain technology to improve the security and reliability of land registration processes. Objective: The purpose of the present work is to propose an architecture for blockchain-based access control for distribution, ensuring information privacy. We take advantage of the benefits of blockchain technology in improving land record management while granting access to electronic data through user permissions. Methods: This approach replicates cryptographic primitives, while smart contracts are used to assist land record owners and users in interacting with each other using the Ethereum blockchain in the proposed system. The approach includes performance evaluation by the execution of a smart contract and security analysis to check the system robustness. Results: The performance evaluation and security analysis prove the proposed blockchain architecture to be secure and feasible for practical implementation in managing land records. Conclusion: The research proves how the application of blockchain technology can significantly enhance both security and reliability in land registration processes, giving credibility to tamper-resistant systems for maintaining information about land ownership.
J. V. Anchitaalagammai, S. Kavitha, S. Murali, J. Janci Rani · 6 authors
Blockchain is the technology through which distributed ledger ensures the secure, transparent, and tamper-proof recording of information across a decentralized network. Its need arises from growing concerns over data security, privacy, and the risk of unauthorized alterations, especially in institutions handling sensitive information, such as libraries. Libraries today face huge risks, the most common being hacking, data breaches, and unauthorized manipulation of data. The use of blockchain technology will ensure assets by augmenting the integrity of data, hence records are changed and not reliable. The paper explores the technical features of blockchain: how it can be used in decentralizing and also ensuring immutability, and consequently protect library systems from data tampering and ensure more transparency in the processes. It also analyzes the successes and shortcomings of blockchain-related applications in other fields, inspiring the belief that this technology can really make the library systems stronger and enhance further the safety and reliability of their business procedures.
Nana Kong, Zhifeng Wan, Cui Xu, Xukai Liu · 6 authors
In the Industrial Internet of Things (IIoT) environment, a multitude of sensing devices continually gather critical data. These data are indispensable for the operations and advancements across diverse industries. However, the sharing of these data poses privacy threats, with attackers exploiting channel analysis and physical device attacks to access sensitive data. To address this, we propose a privacy protection scheme that combines smart contracts (SCs), key-insulated technology, and certificateless anonymous signature (CLBS). This scheme aims to ensure data privacy during sharing and maintain user anonymity. By leveraging SCs, our scheme enables fair and automated key distribution, replacing traditional key generation centers. Key-insulated technology ensures that the signer’s key changes periodically, enhancing system stability. The security of our solution is validated through a random oracle model, and we have optimized an elliptic curve point to reduce signature length and minimize communication overhead. Our scheme outperforms other CLBS schemes in terms of computational and communication efficiency.
Federated learning (FL), as a distributed machine learning paradigm, facilitates collaborative training without sharing raw data and holds promise for effective application in the Internet of Vehicles (IoV) for tasks, such as traffic flow prediction and driving behavior analysis. However, the efficiency of FL systems relies on the integrity of the local dataset and the level of user contribution. Vulnerabilities to attacks by malicious users and suboptimal aggregation methods can compromise system performance. To address these issues, this article proposes a blockchain-based FL secure aggregation algorithm to bolster FL robustness. Specifically, in the absence of a centralized trust authority in the IoV, we establish a hierarchical blockchain-empowered IoV reputation management framework that leverages smart contracts to create a trustworthy environment for reputation sharing. Additionally, a lightweight consensus protocol tailored for blockchain efficiency is proposed, thus facilitating a flexible and effective implementation of FL in the IoV. Furthermore, we introduce a reputation-based model selection evaluation scheme and, based on this, a robust FL secure aggregation algorithm. This novel reputation assessment strategy mitigates the effects of interaction uncertainties and integrates a broader spectrum of IoV-specific reputation determinants, thereby enhancing the precision of model selection. The simulation results validate the proposed framework’s superiority in terms of robustness, adaptability, and security.
ABSTRACT With the increasing trend of outsourcing data to cloud services, ensuring data security and privacy has become crucial. Typically, data are stored on cloud servers in encrypted form to mitigate risks. However, accessing the encrypted data requires an access key distributed by a third party. If this third party is untrustworthy, it poses a significant security threat to the system. To address this challenge, we propose a Decentralized Secure Data Outsourcing System (DSDOS) that uses blockchain technology to ensure data security and privacy. The DSDOS system comprises three modules: data security and privacy, access control and authorization, and data integrity and availability. The data security and privacy module uses a hybrid encryption scheme that combines Advanced Encryption Standard (AES), partially homomorphic encryption (PHE), and Diffie–Hellman (DH) to ensure secure data storage and access. The access control and authorization module uses a blockchain‐based smart contract system to manage access to the encrypted data. The data integrity and availability module uses hash‐based message authentication code (HMAC) to ensure that the data are not tampered with and is always available. We conducted a security and performance analysis of the DSDOS system and found that it outperforms previous schemes in terms of security and performance. The DSDOS system is a secure and privacy‐preserving data outsourcing system that can be used to mitigate the security risks associated with traditional cloud storage systems.
Leveraging blockchain in Federated Learning (FL) emerges as a new paradigm for secure collaborative learning on Massive Edge Networks (MENs). As the scale of MENs increases, it becomes more difficult to implement and manage a blockchain among edge devices due to complex communication topologies, heterogeneous computation capabilities, and limited storage capacities. Moreover, the lack of a standard metric for blockchain security becomes a significant issue. To address these challenges, we propose a lightweight blockchain for verifiable and scalable FL, namely LiteChain, to provide efficient and secure services in MENs. Specifically, we develop a distributed clustering algorithm to reorganize MENs into a two-level structure to improve communication and computing efficiency under security requirements. Moreover, we introduce a Comprehensive Byzantine Fault Tolerance (CBFT) consensus mechanism and a secure update mechanism to ensure the security of model transactions through LiteChain. Our experiments based on Hyperledger Fabric demonstrate that LiteChain presents the lowest end-to-end latency and on-chain storage overheads across various network scales, outperforming the other two benchmarks. In addition, LiteChain exhibits a high level of robustness against replay and data poisoning attacks.
Federated learning, a potent paradigm for collaborative machine learning across multiple parties, offers significant promise for contemporary industries. Nonetheless, its collaborative essence necessitates addressing concerns pertaining to data security and privacy. Sensitive user information, encompassing preferences, behaviors, and identities, remains vulnerable to adversarial analysis, thereby revealing the inadequacies of conventional privacy preservation strategies within federated learning frameworks. To mitigate these challenges, this paper proposes GSFL, an innovative federated learning architecture that amalgamates smart contracts with group signatures. GSFL facilitates secure and reliable distributed machine learning data sharing, while concurrently bolstering privacy protection. Furthermore, its enhanced decentralization fosters greater user participation in federated learning initiatives. Empirical analysis and testing validate GSFL's efficacy in satisfying the prerequisites for data sharing and privacy preservation in federated learning contexts.