Ensuring the integrity of executable binaries is of vital importance to systems that run and depend on them. Additionally, supply-chain attacks and security related bugs demonstrate that binaries, once deployed, may need to be revoked and replaced with updated versions.
Pedro Ivo de Castro Oyama, Jó Ueyama, Paulo Matias
Social media has become part of our daily lives. It brought significant developments in the way we communicate, but it also raised some concerns, including privacy and censorship. In this context, this work presents a social media platform -- EtherYou -- that makes use of cryptographic primitives and an Ethereum smart contract to overcome these issues. Experiments were conducted to evaluate the operating costs involved. The results showed considerable values for senders, zero for receivers, and zero maintenance costs, indicating its potential in scenarios with a reduced number of content producers and a large number of consumers. The proposal offers users privacy over their data, transparency on the system behaviour and censorship resistance.
Abstract While gaining more popularity both as a financial asset and a commodity, a number of cryptocurrencies are emerging with a loosely regulated market microstructure which is a challenge to their efficiency. We have ranked 6 out of the top 10 cryptocurrencies based on their inefficiency ratios, using a novel time‐varying generalised Hurst exponent methodology. All the six crypto markets exhibit a time‐varying efficiency throughout the studied period, thus indicating a varying degree of exploitable profitable trading opportunities. The inefficiency ratio indicates that Bitcoin is the third most inefficient market, while the first and second most inefficient markets are DASH and NEM, respectively, thus they provide the most abnormal profit opportunities. However, the most efficient crypto markets are Ethereum and Ripple according to the order of their rankings. Further research could be performed on the factors affecting the inefficiency index to understand the efficiency determination of these cryptocurrency markets.
Aigerim Iskakova, H. S. V. S. Kumar Nunna, Pierluigi Siano
Blockchain is one of the emerging security technologies that have enormous potential in diverse sectors such as financial organization, academic institutions, national government, business sphere. In this paper, we focus on the application of blockchain systems in the energy industry addressing potential challenges and limitations in this area. The deployment of the proliferation of distributed energy resources requires an efficient and reliable transactive energy (TE) management system in terms of peer-to-peer energy trading. Independence of the energy management system from financial transactions can cause an insecure and vulnerable energy exchange environment. The proposed system design focuses on eliminating gaps in the security by the integration of decentralized application technology with the TE management and Multi-Agent System. The paper discusses the Ethereum blockchain-based peer-to-peer energy trading platform based on the enforced smart contract that controls both financial transactions and energy interchange operations for power trading systems.
Blockchain technologies make agreement among untrusted parties possible, without the need for certification authorities. Proposed frameworks have been put forward in sector as diverse as finance, health care, notary, intellectual property management, identity, provenance, international cooperation, social good, and security to cite but a few. Smart contracts, that is, self-enforcing agreements in terms of executable software running on blockchains, have been developed in several contexts. Such an under-definition computational model introduces innovative aspects, such as the economics and trust of the decentralized computation relying on the shared contribution of peers and their decentralized consensus. Following the first edition of the International Workshop on Future Perspectives of Decentralized APPlications, FPDAPP (held in conjunctions to EURO-PAR conference), this special issue primarily carries new results from revised and substantially extended versions of papers presented at the workshop. Moreover, this volume contains new contributions that rigorously explore and evaluate the potentiality of novel decentralized frameworks and applications. After a thorough peer-reviewing process focused on quality, innovative contribution, applicability to real-world scenarios, we have selected six manuscripts for publication. The paper “Analysis of multi-input multi-output transactions in the Bitcoin network” proposes an exploratory analysis on the Bitcoin network focused on mixing-like behaviors based on multi-input/output transactions. The article “Trusted systems of records based on Blockchain technology - a prototype for mileage storing in the automotive industry” proposes a blockchain-based trusted system of records to address the problem of asymmetric information on the used car market as described by Nobel laureate Akerlof. The paper “Blockchain applications beyond the cryptocurrency casino: The Punishment not Reward blockchain architecture” proposes an interesting punishment mechanism system as alternative to classical reward strategies for blockchain maintenance. The paper “Implementation and evaluation of smart contracts using a hybrid on- and off-blockchain architecture” introduces a novel hybrid architecture for the implementation of smart contracts, based on a centralized monitoring smart contract on the Ethereum blockchain. The paper “Design and practical implementation of verify-your-vote protocol” is focused on the highly debated and challenging problem of electronic voting. It proposes a verifiable blockchain-based online voting protocol that ensures security by using a variety of cryptographic primitives. Finally, the paper “Ensuring transparency and traceability of food local products: A blockchain application to a Smart Tourism Region” proposes a blockchain-oriented platform to guarantee the origin and provenance of food items in a Smart Tourism Region context where local food and beverage can become a good combination to attract tourist and to promote the area thanks to their clearly certified provenance. As guest editors, we would like to express our appreciation for the impressive contributions made by all authors. We would like also to thank all the reviewers that helped us to evaluate all submissions, providing valuable critics and suggestions to the authors. Finally, we would like to thank all editorial board members and all staff for allowing us to publish this Special Issue and for his great support throughout the entire publication process. The guest editors: Andrea Bracciali - University of Stirling Claudio Schifanella - University of Turin
Banking is the backbone of the financial sector of our times. Financial sector is one of the main facilitators in the progress of our society. The world we see today would not have been possible without the banking system. But the banking system currently has a centre dependency. CORE (Centralized Online Real-Time Exchange) banking has major disadvantages like single point of failure, power and authority for planning and decision making rest with top management organized around a hierarchical structure, dictatorial & inflexible. Decentralized/Distributed banking is the need of the hour as it gives anonymity, low/no interest rates, no single point of failure, power to the masses. It is resilient, inherently democratic and efficient. Crypto Banks are decentralized banking platforms that provide the usual services similar to centralized banks, primarily lending services and credit scoring. But it essentially cuts out all of the middlemen that a centralized bank uses. There is no centralization whatsoever. The employees needed in a centralized bank to structure financial data and approve loans are replaced in a crypto banking ecosystem by smart contracts and p2p, peer-to-peer, services. Since all issues can be solved online, most of the network will be online. The bank is moulded in the form of a computer interface, whether on a desktop or a phone, and the currencies dealt with are mostly cryptocurrencies. In this project, I have created a smart contract on Ethereum blockchain that functions as a bank. It covers basic banking operations - creating new accounts, adding/withdrawing money, giving interest to the account holders, showing balances. I used Solidity programming language to write the smart contract and wrote a few tests in Javascript. To test the smart contract, I used Remix IDE. The project gives an idea of how crypto banks work in a real-time environment.
Maintenance of immutable vaccination records and provision of accessing the records in order to prove immunity has been the need of the hour. The recent spread of Covid19 and related uncertainty over vaccinations and immunity have made the search for a secure trustable system for reporting vaccination data more essential. Multiple digital, as well as paper-based solutions have been tested but none has been reported successful enough. In this paper, a technique has been proposed to solve the problem by introducing blockchain-based solution to maintain records of vaccination and proof of immunity for individuals. The purpose has been to present a safe and efficient solution to the problem and hence the model proposed is based on concepts of smart contracts and built over Ethereum blockchain. The paper goes on to give a detailed study of the technique based on discussions of its various aspects like design, development and feasibility.
Hyeong Joon Kim, Hye Hyeon Kim, Hosuk Ku, Kyung Don Yoo · 11 authors
<sec> <title>BACKGROUND</title> The Health Avatar Platform provides a mobile health environment with interconnected patient Avatars, physician apps, and intelligent agents (termed <i>IoA<sup>3</sup></i>) for data privacy and participatory medicine; however, its fully decentralized architecture has come at the expense of decentralized data management and data provenance. </sec> <sec> <title>OBJECTIVE</title> The introduction of blockchain and smart contract technologies to the legacy Health Avatar Platform with a clinical metadata registry remarkably strengthens decentralized health data integrity and immutable transaction traceability at the corresponding data-element level in a privacy-preserving fashion. A crypto-economy ecosystem was built to facilitate secure and traceable exchanges of sensitive health data. </sec> <sec> <title>METHODS</title> The Health Avatar Platform decentralizes patient data in appropriate locations (ie, on patients’ smartphones and on physicians’ smart devices). We implemented an Ethereum-based hash chain for all transactions and smart contract–based processes to guarantee decentralized data integrity and to generate block data containing transaction metadata on-chain. Parameters of all types of data communications were enumerated and incorporated into 3 smart contracts, in this case, a health data transaction manager, a transaction status manager, and an application programming interface transaction manager. The actual decentralized health data are managed in an off-chain manner on appropriate smart devices and authenticated by hashed metadata on-chain. </sec> <sec> <title>RESULTS</title> Metadata of each data transaction are captured in a Health Avatar Platform blockchain node by the smart contracts. We provide workflow diagrams each of the 3 use cases of data push (from a physician app or an intelligent agents to a patient Avatar), data pull (request to a patient Avatar by other entities), and data backup transactions. Each transaction can be finely managed at the corresponding data-element level rather than at the resource or document levels. Hash-chained metadata support data element–level verification of data integrity in subsequent transactions. Smart contracts can incentivize transactions for data sharing and intelligent digital health care services. </sec> <sec> <title>CONCLUSIONS</title> Health Avatar Platform and interconnected patient Avatars, physician apps, and intelligent agents provide a decentralized blockchain ecosystem for health data that enables trusted and finely tuned data sharing and facilitates health value-creating transactions with smart contracts. </sec>
Supply chain integration remains an elusive goal for the construction and engineering industry. The high degree of fragmentation and the reliance on third-party financial institutions has pushed the physical and financial supply chains apart. The paper demonstrates how blockchain-based crypto assets (crypto currencies and crypto tokens) can address this limitation when used for conditioning the flow of funds based on the flow of products. The paper contrasts the integration between cash and product flows in supply chains that rely on fiat currencies and crypto assets for their payment settlement. Two facets of crypto asset-enabled integration, atomicity and granularity, are further introduced. The thesis is validated in the context of construction progress payments. The as-built data captured by unmanned aerial and ground vehicles was passed to an autonomous smart contract-based method that utilizes crypto-currencies and crypto tokens for payment settlement; the resulting payment datasets, written to the Ethereum blockchain, were analyzed in terms of their integration of product and cash flow. The work is concluded with a discussion of findings and their implications for the industry.
In this contribution we extend an ontology for modelling agents and their interactions, called Ontology for Agents, Systems, and Integration of Services (in short, OASIS), with conditionals and ontological smart contracts (in short, OSCs). OSCs are ontological representations of smart contracts that allow to establish responsibilities and authorizations among agents and set agreements, whereas conditionals allow one to restrict and limit agent interactions, define activation mechanisms that trigger agent actions, and define constraints and contract terms on OSCs. Conditionals and OSCs, as defined in OASIS, are applied to extend with ontological capabilities digital public ledgers such as the blockchain and smart contracts implemented on it. We will also sketch the architecture of a framework based on the OASIS definition of OSCs that exploits the Ethereum platform and the Interplanetary File System.
In this contribution we extend an ontology for modelling agents and their interactions, called Ontology for Agents, Systems, and Integration of Services (in short, OASIS), with conditionals and ontological smart contracts (in short, OSCs). OSCs are ontological representations of smart contracts that allow to establish responsibilities and authorizations among agents and set agreements, whereas conditionals allow one to restrict and limit agent interactions, define activation mechanisms that trigger agent actions, and define constraints and contract terms on OSCs. Conditionals and OSCs, as defined in OASIS, are applied to extend with ontological capabilities digital public ledgers such as the blockchain and smart contracts implemented on it. We will also sketch the architecture of a framework based on the OASIS definition of OSCs that exploits the Ethereum platform and the Interplanetary File System.
Muhammad Fajar Sidiq, Akbari Indra Basuki, Halim Firdaus, Muhammad Aldi Baihaqi
Pengawasan jaringan pada beberapa kantor yang berlokasi berjauhan sangat sulit dilakukan kerana keterbatasan tenaga ahli, biaya, dan teknologi pendukung. Penelitian yang sudah ada tidak dapat menyediakan sistem pengawasan jaringan yang mampu menjamin tiga aspek keamanan sekaligus, yaitu: availability, integrity, dan confidentiality. Teknologi blockchain mampu menyediakan sistem pengawasan jaringan secara terpusat dan aman dengan menjamin keamanan sistem komunikasi pelaporan dan sistem basis data pelaporan. Penelitian ini bertujuan untuk menyajikan purwarupa sistem pengawasan konfigurasi dan statistik jaringan menggunakan jejaring blockchain Ethereum. Metode pengawasan mengharuskan program controller pada setiap jaringan kantor untuk secara berkala menarik informasi flow-rules dari setiap perangkat jaringan dan melaporkan data tersebut dalam sebuah transaksi ke jejaring blockchain. Pada penelitian ini dianalisa dua jenis skema pengiriman transaksi: transaksi berbasis smart contract dan transaksi berbasis zero-payment. Berdasarkan hasil pengujian, transaksi berbasis zero-payment secara rerata hanya membutuhkan sekitar 6 % dari biaya transaksi smart contract. Perkiraan biaya bulanan untuk pensamplingan informasi setiap 10 menit adalah sekitar 1,19 ether per-perangkat jaringan. Meskipun demikian, metode pada penelitian ini lebih sesuai untuk diterapkan pada jejaring Ethereum jenis Proof-of-Authority (PoA) dibandingkan jenis Proof-of-Work (PoW) karena harga Ether yang mahal. AbstractCentralized monitoring of remote networks is hard to implement due to the high cost, lack of experts, and the missing key technologies. The existing researches are unable to provide a secure, centralized monitoring system that satisfies three security aspects, namely: availability, integrity, and confidentiality. Blockchain technology meets those three requirements by providing a reliable reporting and immutable database system. In this paper, we proposed a prototype of a centralized monitoring system that records network statistics and configurations into the blockchain ledger. The method requires the network controller to periodically fetch network information from every network device and submit it as a single blockchain transaction. We compare two kinds of transaction schema, smart-contract based and zero-payment based reporting schemes. The evaluations show that zero-payment transactions only cost 6 % of the smart-contract transactions. The estimation of the monthly cost is 1.19 ether per-device for 10-minutes data sampling. Nevertheless, the proposed method is applicable only for the Proof-of-Authority (PoA) Ethereum networks. It is not feasible for the Ethereum main network that uses Proof-of-Work (PoW) due to the high cost of Ether.
Beyond an emerging popular web applications runtime supported in almost all commodity browsers, WebAssembly (WASM) is further regarded to be the next-generation execution environment for blockchain-based applications. Indeed, many popular blockchain platforms such as EOSIO and NEAR have adopted WASM-based execution engines. Most recently, WASM has been favored by Ethereum, the largest smart contract platform, to replace the state-of-the-art EVM. However, whether and how well current WASM outperforms EVM on blockchain clients is still unknown. This article conducts the first measurement study to understand the performance on WASM VMs and EVM for executing smart contracts for blockchain-based applications. To our surprise, the current WASM VM does not provide expected satisfactory performance. The overhead introduced by WASM is really non-trivial. Our results shed the light on challenges when deploying WASM in practice, and provide insightful implications for improvement space.
As the most popular blockchain that supports smart contracts, there are already more than 296 thousand kinds of cryptocurrencies built on Ethereum. However, not all cryptocurrencies can be controlled by users. For example, some money is permanently locked in wallets' accounts due to attacks. In this paper, we conduct the first systematic investigation on locked cryptocurrencies in Ethereum. In particular, we define three categories of accounts with locked cryptocurrencies and develop a novel tool named CLUE to discover them. Results show that there are more than 216 million dollars value of cryptocurrencies locked in Ethereum. We also analyze the reasons (i.e., attacks/behaviors) why cryptocurrencies are locked. Because the locked cryptocurrencies can never be controlled by users, avoid interacting with the accounts discovered by CLUE and repeating the same mistakes again can help users to save money.
EIP-1559 is a proposal to make several tightly coupled additions to Ethereum's transaction fee mechanism, including variable-size blocks and a burned base fee that rises and falls with demand. This report assesses the game-theoretic strengths and weaknesses of the proposal and explores some alternative designs.
Healthcare data can be created, copied and modified faster than ever before. Data is the fuel behind more efficient care. Unfortunately, healthcare today suffers from compartmentalized and fragmented data, delayed communications, and disparate workflow tools caused by the lack of interoperability. Blockchain technology maybe the vehicle to solve these problems, as besides it possesses key properties, such as immutability, decentralization, and transparency, which potentially address pressing issues in healthcare, such as incomplete records at point of care and difficult access to patients' own health information. An efficient and effective healthcare system should be interoperable, allowing software apps and technology platforms to communicate securely and seamlessly, exchange data, and use the exchanged data across health organizations and app vendors. In this paper, we address the aspect of storage of Electronic Medical Records using smart contracts. The implementation is done using Ethereum's blockchain network to solve problems faced by centralized platforms. The results were encouraging, and the implementation was also successful in reducing storage costs by storing large files off-chain (IPFS).
Blockchain brings opportunities and challenges for financial data sharing services. The essential properties in a distributed multi-parties system are data access control and privacy control. This paper proposes a hierarchical data access model for financial services, which contains consent management and dynamic credits management. We implement fine-grained data access control through rating accredited data recipients (ADRs). By accessing corresponding blockchain service logs, ADRs' credits will dynamically be updated. The credits evaluation algorithm is responsible for calculating ADRs' credits based on their completion rate, business ethics rate, and feedback positive rate. Moreover, through applying smart contracts, the efficiency of consent management can be improved, and privacy policies can be managed elastically. Finally, we deploy smart contracts on the Ethereum Rinkeby testnet to evaluate the model feasibility. Furthermore, the theoretical analysis and experimental results indicate that the prototype is secure and efficient.
Currently, all blockchain-based applications conduct two primary operations, i.e., writing data on blockchain networks and reading these data from the networks. These tasks require users to have considerable knowledge in blockchain technology, and they become even more challenging if users want to utilize different blockchain platforms to write and read data. So far, we have not had a uniform mechanism to perform write and read operations on various blockchain platforms. In addition, writing a huge amount of data on blockchain networks is a time-consuming task and requires considerable transaction fees. To address these issues, we present in the paper a data mapping language named BML. BML allows developers to uniformly define mappings for data transformation from traditional data storage mechanisms into blockchain networks. Conversely, this language also assists users in reading transformed data. Currently, BML accepts five input data sources, including XML, JSON, XLSX, SQL (relational database), NoSQL, and supports two output platforms, including Hyperledger Sawtooth and Ethereum.
Confronted with the explosive growth of data in various cyber systems, decentralized storage has gained popularity thanks to its ubiquitousness, since the devices can share their idle storage space for higher scalability. However, current decentralized storage networks suffer the failure risk due to the insufficient trust among nodes, in addition to the lack of a reliable resource allocation mechanism. In this paper, we present a novel trusted shared storage network, namely TSSN, to achieve efficacious decentralized storage with trust. Designed under a shared storage framework, TSSN introduces blockchain via an on/off-chain collaborative protocol, which realizes the decentralized trust with promising efficiency. In the primary novelty of TSSN, we design an allocation mechanism based on trading and multi-attribute bilateral matching to maintain the stability and fluidity of resources. To verify the practical effectiveness of our solution, we implement a TSSN prototype on our testbed based on IPFS and Ethereum. The experimental results demonstrate the performance of TSSN within on-chain storage overhead, throughput, and latency.
Karamo Kanagi, Cheng‐Yuan Ku, Li-Kai Lin, Wen-Huai Hsieh
BACKGROUND: While electronic health records have been collected for many years in Taiwan, their interoperability across different health care providers has not been entirely achieved yet. The exchange of clinical data is still inefficient and time consuming. OBJECTIVES: This study proposes an efficient patient-centric framework based on the blockchain technology that makes clinical data accessible to patients and enable transparent, traceable, secure, and effective data sharing between physicians and other health care providers. METHODS: Health care experts were interviewed for the study, and medical data were collected in collaboration with Ministry of Health and Welfare (MOHW) Chang-Hua hospital. The proposed framework was designed based on the detailed analysis of this information. The framework includes smart contracts in an Ethereum-based permissioned blockchain to secure and facilitate clinical data exchange among different parties such as hospitals, clinics, patients, and other stakeholders. In addition, the framework employs the Logical Observation Identifiers Names and Codes (LOINC) standard to ensure the interoperability and reuse of clinical data. RESULTS: The prototype of the proposed framework was deployed in Chang-Hua hospital to demonstrate the sharing of health examination reports with many other clinics in suburban areas. The framework was found to reduce the average access time to patient health reports from the existing next-day service to a few seconds. CONCLUSION: The proposed framework can be adopted to achieve health record sharing among health care providers with higher efficiency and protected privacy compared to the system currently used in Taiwan based on the client-server architecture.