Gautham Narayan, Pavitra Haveri, B H Rashmi, Yashwardhan Deewan
Ensuring secure data provenance is crucial for maintaining accountability and confidentiality in cloud environments. Cloud data provenance involves recording the history of creation and operations performed on cloud data objects. However, establishing trust between cloud customers and service providers remains a challenge, highlighting the need for assured data provenance models in cloud storage. Blockchain technology has emerged as a solution for designing data provenance assurance mechanisms. It provides a decentralized and distributed ledger to record the provenance of digital assets. In this context, we present a blockchain-based framework for ensuring data provenance in cloud storage. Initially, we develop a cloud storage application using OpenStack swift storage. This application caters to the storage needs of university students and faculty while providing data provenance capabilities. Subsequently, we design a data provenance assurance framework for confidential files of users using the Ethereum blockchain. To evaluate the scalability and performance of the proposed framework, we analyze various factors such as transaction throughput, latency, network size, and load on the blockchain network. The performance of the system is compared under two consensus algorithms: Proof of Work and Proof of Authority. By conducting this analysis, we aim to assess the effectiveness and efficiency of the blockchain-based solution in ensuring data provenance in cloud storage environments.
Vijay U. Rathod, Yogesh Kisan Mali, Nilesh P. Sable, Rahul Ramkishan Rathod · 6 authors
Sensitive personal data is frequently uploaded on internet, which is currently misused or disclosed leading to compromise of financial assets and thus endangering the entire ecosystem for online transactions. As a result, academic resources as well as internet firms are interested in learning how to manage an online identity. We propose a solution that provides user with authority over their own identities, using Blockchain Based (BCB) identity management system. Proposed system allows users to store data on a blockchain in place of vulnerable servers. The blockchain enables users to securely register their personal information and documents, guaranteeing the immutability and integrity of their identification of data. Organizations on the other hand, play crucial role in using proposed BCB system to verify identity of persons for their requirements like recruitments, loan sanctioning, asset management, admission to schools and colleges. The proposed solution provides a blockchain network for user to store the KYC details for identification purpose. It also provides platform for users and organizations to join blockchain network and retrieve the KYC documents of the required persons. The verifier in blockchain network verifies the identity of person. Block chain is made lightweight using blockchain server. Reward system is introduced to motivate users/organizations in blockchain network to participate in verification of KYC document of any user.
Traditional proof-of-work (PoW) based cryptocurrencies require miners to solve hash functions, resulting in enormous energy waste. Proof-of-stake (PoS) is an energy-efficient alternative to PoW. However, PoS alone fails to create incentives for PoW miners to switch away from PoW due to their existing hardware investments that provide a competitive financial advantage. Thus, we introduce a framework that replaces energy wasted on PoW cryptocurrencies with a modified PoS consensus mechanism that allows miners to be rewarded for solving user-proposed problems. This mechanism could serve as a decentralized cloud computing platform.
Mahmoud Abbasi, Javier Prieto, Amin Shahraki, Juan M. Corchado
The Internet of Things (IoT) devices utilized in manufacturing industries produce vast volumes of valuable data that can revolutionize productivity and sustainability. While existing centralized data marketplaces facilitate data trading, they are often marred by trust issues, a single point of failure, and significant security and privacy vulnerabilities. Addressing these critical shortcomings, this paper introduces a blockchain-based industrial data trading system that not only ensures secure and transparent data trading but also offers advantages over conventional systems. Unlike traditional marketplaces, our proposed system emphasizes trustworthiness by mitigating third-party risks, enhancing data integrity through decentralized storage, and employing graph technology for efficient blockchain querying. Further, with integrated access control, our system elevates security standards. Preliminary evaluations reveal the system’s potential to offer a more secure, transparent, auditable, and trustworthy data trading environment, distinctly outpacing the capabilities of current marketplaces.
Chenhao Xu, Youyang Qu, Yong Xiang, Tom H. Luan · 5 authors
The consortium blockchain is being utilized in supply chains on the Internet of Things (IoT) for tracking and protecting supply chain data, such as manufacture, storage, and shipment. However, the supply chain data in a consortium blockchain is publicly accessible for all parties, which attracts widespread concerns about supply chain data privacy. Several existing attribute-based encryption (ABE)-based blockchain systems targeting to address the supply chain data privacy problem either bring about additional security problems or lack the feasibility analysis on IoTs. To address the aforementioned issues, in this article, a novel multiauthority ABE (MA-ABE)-based blockchain system is proposed to protect the data privacy for the supply chain on IoTs. Specifically, a four-way tradeoff optimization framework is designed so that the system decentralization, scalability, and storage consumption are not significantly affected by the improved privacy. The optimal attribute setting policies for different scale blockchain networks are dynamically generated by the nondominated sorting genetic algorithm II (NSGA-II). Extensive experiment results show that the proposed scheme remarkably improves data privacy protection for the supply chain without downgrading the other three key factors.
Cloud computing is a cost-effective way for organizations to access and use IT resources. However, it also exposes data to security threats. Authentication and authorization are crucial components of access control that prevent unauthorized access to cloud services. Organizations are turning to identity management solutions to help IT administrators face and mitigate security concerns. Identity management (IDM) has been recognized as a more robust solution for validating and maintaining digital identities. Identity management (IDM) is a key security mechanism for cloud computing that helps to ensure that only authorized users have access to data and resources. Traditional IDM solutions are centralized and rely on a single authority to manage user identities, which makes them vulnerable to attack. However, existing identity management solutions need to be more secure and trustworthy. Blockchain technology can create a more secure and trustworthy cloud transaction environment. Purpose: This paper investigates the security and trustworthiness of existing identity management solutions in cloud computing. Comparative results: We compared 14 traditional IDM schemes in cloud systems to explore contributions and limitations. This paper also compared 17 centralized, decentralized, and federated IDM models to explain their functions, roles, performance, contribution, primary metrics, and target attacks. About 17 IDM models have also been compared to explore their efficiency, overhead consumption, effectiveness to malicious users, trustworthiness, throughput, and privacy. Major conclusions: Blockchain technology has the potential to make cloud transactions more secure and reliable. It featured strong authentication and authorization mechanisms based on smart contracts on the Ethereum platform. As a result, it is still regarded as a reliable and immutable solution for protecting data sharing between entities in peer-to-peer networks. However, there is still a large gap between the theoretical method and its practical application. This paper also helps other scholars in the field discover issues and solutions and make suggestions for future research.
Peiheng Zhang, Min Tang, Willy Susilo, Mingwu Zhang
Polynomial commitment schemes (PCSs) are fundamental components that can effectively solve the problems arising from the combination of Internet of Things and blockchain. These allow a committer to commit to a polynomial and then later evaluate the committed polynomial at an arbitrary challenge point along with a proof of valid, without revealing any additional information about the polynomial. Recent works have presented polynomial commitment schemes based on the discrete logarithm assumption. Their schemes do not require a trusted setup, and the verifier uses homomorphism to check the polynomial evaluation proofs. However, these schemes require two-party interactions and satisfy only special soundness and special honest verifier zero-knowledge, which are infeasible for some nonsimultaneous online or decentralized applications. In this article, we propose a novel PCS inspired by the idea of the Fiat–Shamir heuristic. Our scheme is noninteractive between the committer and the verifier. Instead of waiting for the challenge values from the verifier, the committer generates the values by accessing a random oracle. Moreover, it satisfies computational soundness and zero-knowledge by using a group operation to enhance the unpredictability of challenge values. We also propose a trapdoor commitment scheme to ensure the honest use of challenge values by the committers. Finally, we present the security and performance analysis of our scheme, which shows that our scheme is feasible with an acceptable time overhead.
Yongxin Zhang, Jiacheng Yang, Hong Lei, Zijian Bao · 7 authors
Despite the existence of data privacy regulations, such as the general data protection regulation (GDPR), data leaks in the Internet of Things (IoT) still occur and cause significant harm due to the noncompliance of data users. To address this issue, a notable solution involves recording the process in an open, immutable blockchain and utilizing the trusted execution environment (TEE) for reliable compliance verification. Although substantial progress has been made in designing compliance schemes in recent years, current approaches suffer from various limitations, including compliance incompleteness, regulation faultiness, and privacy leak. This article introduces PACTA, an IoT data privacy regulation compliance scheme that leverages TEE and blockchain technology. In the protocol, PACTA efficiently handles both dynamic and static consent of data owners and utilizes TEE for compliance analysis of requests and processes. By storing encrypted critical data, the blockchain facilitates privacy-preserving audits of the entire compliance process. Additionally, we have designed a challenge–response protocol to address the silent behavior of the TEE. We demonstrate that PACTA effectively enforces regulation compliance while safeguarding privacy. We thoroughly evaluate our implementation’s efficiency and effectiveness using Ethereum and Intel SGX platforms.
Yang Shi, T. Luo, Jingwen Liang, Man Ho Au · 5 authors
Blockchain systems, such as Bitcoin and Ethereum, enable new applications, such as cryptocurrencies and smart contracts, using decentralized consensus without trusted authorities. Since the most widely used technique, proof-of-work, suffers from the costs of high latency and huge energy consumption, a number of blockchain systems based on proof-of-stake techniques have been proposed in recent years, many of which use verifiable random functions as fundamental building blocks, such as Ouroboros, Algorand, and Dfinity, etc. The secret key of a verifiable random function scheme, similar to that of a digital signature scheme, is critical to the security of a verifiable random function and the entire blockchain system built on it. To protect the secret keys of verifiable random functions and maintain the efficiency of the proof-of-stake protocol, we extend the objective of cryptographic program obfuscation to verifiable random functions and propose a novel obfuscatable verifiable random function scheme. In particular, we propose an obfuscator that can transform the implementation of the scheme's random string generation algorithm and the given secret key into an unintelligible form. Obfuscated implementations of the random string generation algorithm are deployed on peers of a blockchain for supporting normal routines of the proof-of-stake protocol. Even if a hacker has controlled a peer's host, the owner's secret key will not be compromised because the key has been hardwired into the obfuscated implementation in an “encrypted manner”. We formally prove the correctness and the security of the proposed verifiable random function and obfuscator. Since the proposed scheme supports the general semantics of verifiable random functions, it can be used as a building block for all blockchain systems that adopt proof-of-stake protocols based on Verifiable Random Functions (VRFs). The extensive experimental result indicated that the scheme performs well on various platforms, such as cloud servers, workstations, PCs, smartphones, and embedded devices.
Blockchain technology has altered the way transactions are conducted since its introduction. It offers a risk-free and secure way to exchange digital currency that is impervious to manipulation by those with bad intentions. In blocks that store the data, it stores all transactional data. The best example of decentralized, systematic data collection is blockchain technology. By storing the block in many locations across a distributed network arrangement, it offers a public ledger system that combines public key encryption of all transactions to solve the double spending problem, making change impossible and therefore more secure. This article explores the usefulness and benefits of Blockchain technology compared to traditional data management by outlining its fundamental concepts and how it has been adopted in different industries. The writers also discuss the factors that led to the adoption of Bitcoin and other cryptocurrencies as well as the shift to a decentralized crypto ledger. In-depth information on this technology's potential hazards, drawbacks, security features, threats, and vulnerabilities is also included in the article.
AI has found widespread application across various sectors, including security, healthcare, finance, and national defense. However, alongside its transformative advancements, there has been an unfortunate trend of malicious exploitation of AI capabilities. Concurrently, the rapid evolution of cloud computing technology has introduced cloud-based AI systems. Regrettably, vulnerabilities inherent in cloud computing infrastructure also pose risks to the security of AI services. We observe that the integrity of training data is pivotal, as any compromise therein directly impacts the efficacy of AI systems. Against this backdrop, we assert the paramount importance of preserving data integrity within AI systems. To address this imperative, we propose a data integrity architecture guided by the National Institute of Standards and Technology (NIST) cyber security framework. Leveraging block chain technology and smart contracts emerges as a fitting solution to tackle integrity challenges, owing to their characteristics of shared and decentralized ledgers. Smart contracts facilitate automated policy enforcement, enable continuous monitoring of data integrity, and mitigate the risk of data tampering.
Financial organizations are adopting an Open Bankings (OB) pattern for creativity in services and incorporation. OB permits Third-Party Servicing Providers (TSPs) to entry consumer financial data to identify optimal offers and enhance customer service. The reliance on third parties essential for the functioning of the OB environment prompts inquiries about digital identity incorporation, information exchange, and the safeguarding of secrets. Distributed Applications (DApps) for data classification and secret protection, user consent capturing, tracking TSP accessibility actions, controlling Applications Programming Interfaces (APIs), and maintaining Self-Sovereign Identity (SSI) are available; however, they have not yet been incorporated into a functional three-phase OB strategy. Upon evaluating the principal needs of main OB users, the research formulated a Blockchain-oriented Identity Managing and Access Controlling System (BIMACS) that incorporates benefits from both conventional banking and blockchain-based technologies. The BIMACS facilities utilize smart agreements and an undocumented authenticating system to establish a transaction security management system, which provides features such as distributed Third-Party Logins (TPL), OB account creation, information authorization, incorporated transactions, and TSP access tracking. The system efficiency study's findings demonstrate that the suggested structure's frequently executed functions incur a lower computational price than the median operations price on open Ethereum.
Mohamed Seifelnasr, Riham AlTawy, Amr Youssef, Essam Ghadafi
The three-tier IoT–Edge–Cloud paradigm enables low-end devices to use the computation capabilities of the more powerful edge nodes to meet efficiency constraints for real-time applications. Many symmetric-key-based schemes rely on an online trusted cloud admin (CA) to establish session keys between IoT devices and edge nodes. In this study, we propose a new provably-secure mutual authentication privacy-preserving protocol with forward secrecy (MAPFS), which eliminates the requirement for an online CA during IoT authentication. To achieve anonymity, our construction utilizes zero-knowledge proofs and randomizes the IoT authentication request. The security of our construction is based on the well-studied discrete logarithm and decisional Diffie–Hellman assumptions in elliptic curve groups. We formally prove that MAPFS ensures mutual authentication and semantic security for session keys. We also evaluate MAPFS performance in terms of the communication overhead, storage requirements, and computation complexity. Finally, we test the performance of MAPFS on a Raspberry Pi 4 and compare it against other certificate-less protocols.
Guzmán Llambías, Bruno Bradach, Juan J. Nogueira, Laura González · 5 authors
Blockchain is a distributed ledger technology (DLT) to manage data in a decentralised way. During the last years, interoperability has become one of the main challenges within blockchain research as blockchains increasingly require integration between each other. Indeed, blockchains work by design in silos of information as interoperability is not a native feature. The main efforts in the field are focused on blockchains, such as Bitcoin and Ethereum. However, interoperability in DLT remains as an almost untouched area of work as they introduce additional requirements focusing on privacy and identity. Although there are some interoperability solutions for DLT, they are either high-level design proposals not providing concrete implementations or focus on interoperability issues between business applications and blockchain platforms. In this paper we propose a gateway-based platform-to-platform interoperability solution for DLT, which comprises a detailed solution design and a reference implementation. The proposal was assessed through the development of a social security case scenario and the evaluation through two interoperability frameworks. A reference implementation was built using two DLT: Hyperledger Fabric and Corda. The experimental results shows that it is possible to achieve technical interoperability between two heterogeneous DLT platforms using a gateway-based interoperability solution, relaxing decentralisation, data privacy, identity and authorisation management properties.
Fog computing composes of neighboring devices, which are connected as cluster to collect and compute data via given algorithms. Compared with cloud computing, it collects and processes data at the edge of device layer, instead of remote data transmission and task scheduling. Fog computing reduces the communication and computation overhead in networking and data aggregating, while preserves data privacy against the cloud center. However, due to the different devices capacities, trust relations, security settings, the concerns are that, if the given data is real and sufficient for analyzing program as input, whether the data processing is done as appointed, and how to prevent secret leakage during the computation. This paper proposes a trustless layer for secure data computing in fog network, where the function accepts “hidden” data as input and generates zero-knowledge computing proof which can be easily verified by public. The combination of secure computing functions and blockchain systems escort trustful business in fog environment.
With the wide adoption of blockchains in data-intensive applications, enabling verifiable queries over a blockchain database is urgently required. Aiming at reducing costs, previous solutions embed a small-sized authenticated data structure (ADS) in each block header, so that a user can verify search results without maintaining a full copy of blockchain databases. However, existing studies focus on exact queries with difficulty to guarantee the freshness of search results. In this article, we propose two frameworks, called$\mathsf{veffChain}$and$\mathsf{veffChain++}$, to realize freshness authentication of rich queries over blockchain databases. Specifically,$\mathsf{veffChain}$concerns about verifiable latest-$K$exact queries and employs RSA accumulator to generate constant-size ADSs;$\mathsf{veffChain++}$integrates RSA accumulator into the Trie tree to further authenticate latest-$K$fuzzy queries. For improved scalability, an adaptive keyword splitting (AKS) solution is proposed to enable ADSs to be incrementally updated. Compared with the state-of-the-art work, our frameworks have the following merits: (1)Freshness Guarantee. The user can efficiently retrieve the freshest data from a blockchain database in a verifiable way. (2)Flexibility. The user can specify different query patterns on demand to retrieve data as accurately as possible. The detailed security analysis and extensive experiments validate the practicality of our frameworks.
Abstract Blockchain is employed as a technology holding a solutionist promise, while at the same time, it is hard for the promissory blockchain applications to become realized. Not only is the blockchain protocol itself not foolproof, but when we move from “blockchain in general” to “blockchain in particular,” we see that new governance structures and ways of collaborating need to be developed to make blockchain applications work /become real . The qualities ascribed to (blockchain) technology in abstracto are not to be taken for granted in blockchain applications in concreto . The problem of trust, therefore, does not become redundant simply through the employment of “trustless” blockchain technology. Rather, on different levels, new trust relations have to be constituted. In this article, we argue that blockchain is a productive force, even if it does not solve the problem of trust, and sometimes regardless of blockchain technology not implemented after all. The values that underpin this seemingly “trustless technology” such as control , efficiency , and privacy and the story that is told about these values co‐shape the actions of stakeholders and, to a certain extent, pre‐sort the path of application development. We will illustrate this by presenting a case study on the Red Button ( De Rode Knop ), a Dutch pilot to develop a blockchain‐based solution that enables people who are in debt to communicate to their creditors that they are, together with the municipality, working on improving their situation, thereby requesting a temporary suspension from debt collection.
Tariq Bontekoe, Dimka Karastoyanova, Fatih Türkmen
Privacy-preserving computation (PPC) methods, such as secure multiparty computation (MPC) and homomorphic encryption (HE), are deployed increasingly often to guarantee data confidentiality in computations over private, distributed data. Similarly, we observe a steep increase in the adoption of zero-knowledge proofs (ZKPs) to guarantee (public) verifiability of locally executed computations. We project that applications that are data intensive and require strong privacy guarantees, are also likely to require verifiable correctness guarantees, especially when outsourced. While the combination of methods for verifiability and privacy protection has clear benefits, certain challenges stand before their widespread practical adoption. In this work, we analyze existing solutions that combine verifiability with privacy-preserving computations over distributed data, in order to preserve confidentiality and guarantee correctness at the same time. We classify and compare 37 different schemes, regarding solution approach, security, efficiency, and practicality. Lastly, we discuss some of the most promising solutions in this regard, and present various open challenges and directions for future research.