Internet of Things (IoT) is an advanced computing network where all physical objects are connected to the internet. All these objects are able to communicate and interact with each other using many technologies such as radio-frequency identification (RFID) technology, wireless technologies and other sensors technologies. Security concept is the main concern to ensure the sustainable development in IoT and to achieve confidentiality, Integrity, Availability (CIA) and Privacy. Blockchain (BC) is a technology based on the concept of trust and security that is the base of in the cryptocurrency such as Bitcoin and Ethereum. BC has three main pillars of transparency, immutability and distributed DB. Nowadays, Blockchain is paving the way to provide security and privacy in peer-to-peer networks with similar topologies to IoT. This paper proposes an integrated framework for implementing IoT with blockchain technology to guarantee high level of security and validation process based on the integration between consensus algorithms of blockchain (PBFT and Tangle). In addition, this paper proposes a direction algorithm to direct IoT transactions to appropriate BC algorithm to be validated by PBFT or Tangle. The propose framework ensure security, scalability and high performance by optimizing the data transmission overhead and enhancing the validation process by using the propose direction algorithm with reducing both of the resource utilization and the latency time. The conducted experimental results for the propose framework state that the latency time is reduced by 50% than using each consensus BC algorithm separately and mitigate the apprehensive from Sybil attack because of the load balance between consensus algorithms and the dynamic of validation.
Advancements in Artificial Intelligence (AI) and Big Data technologies are reshaping the global economy. The community currency network is receiving more attention through enhancing social ties within a community. As the most popular type of community currency, Time Banking (TB) is a generalized community exchange economy, which uses the time to evaluate each participant's contributions on the same scale rather than any equivalence with the official national currency. TB is a noble idea with the potential to improve the quality of life through prosocial, reciprocally beneficial activities among community members. However, it also brings new concerns about security and trust issues. Inspired by blockchain and smart contract, this paper introduces a Blockchain Integrated Timebanking (BIT) system to secure a decentralized community exchange economy. In BIT system, service providers and recipients can securely exchange effort through a self-executing smart contract without relying on a third-party trust authority. The blockchain network ensures immutability, auditability, and traceability of all data and service transactions recorded on the distributed ledger. A proof-of-concept prototype was implemented and tested on a private Ethereum network. The experimental results verify the feasibility of the proposed BIT to provide decentralized community service exchanges with limited computation overhead and network latency.
Srđan Daniel Simić, Robert Šajina, Nikola Tanković, Darko Etinger
Recent advances in blockchain gained significant social attention, mainly due to substantial price fluctuations of Bitcoin and Ethereum cryptocurrencies. By its design, blockchain is an open, distributed ledger that can record transactions between two parties efficiently and in a verifiable and permanent way, providing solutions for many complex tasks without third party involvement. To achieve that, they employ a set of Byzantine Fault-tolerant consensus algorithms that require the implemented logic to be deterministic. The lacking source of randomness is a consequential limitation since many application domains, like games, lotteries, or random elections, require random sources. Given the Byzantine Fault-tolerance, generating random numbers should also be publicly-verifiable and tamper-resistant, but still hold the premises of being unpredictable.In this paper, we will provide an overview of the current research surrounding pseudo-random number generation on a decentralized network that satisfies those requirements.
The problem of counterfeiting diplomas in education with the advancement of digital technology is increasingly pronounced. The process of forging documents is almost always accompanied by reduced transparency in issuing the documents with no possibility to easily check the validity of the document. One of the currently very attractive and challenging technology in digitized society is the blockchain technology and all the sequential systems that have emerged based on it. One such system is the Ethereum platform, which uses blockchain technology and enables the creation of decentralized applications programmed to run on the Ethereum network. One of the Ethereum use is a Smart Contract, which allows applications to be executed online, completely autonomously without the influence of a third party, once a previously defined condition is satisfied. The objective of this research is to explore the possibility of using a Smart Contract in the process of the creation and issuance of diplomas at a higher education institution. At the end of the analysis, we provide an overview of the advantages and disadvantages of this procedure, as well as potential possibilities for its improvements. The possibilities of automation and the cost of such a process were also considered.
Diabetes is a serious medical condition and regular screening for diabetes is of great importance as treatment options are most effective in the early stages of diabetes. Digital imaging of retina is considered as a low-cost method for screening and could be used in conjunction with computer-based image processing techniques to automatically detect early signs of diabetes utilizing diabetes-related pathologies visible in retinal fundus images. This research proposes a novel computer-assisted diagnosis (CAD) system for assisting with the screening of the population as up to 50% of the affected population are not aware of having diabetes. Moreover, these screenings are often carried out by an optometrist who receives some training with the patients being referred to an ophthalmologist if they show symptoms. Having a computer-assisted diagnosis system assisting the optometrist during the screening can greatly increase the detection rate for patients with diabetes by providing a second opinion and highlighting any suspicious pathologies. For achieving the highest detection rate possible, a hybrid machine learning approach is proposed in this research by combining Deep Learning with the AdaBoost classifier. The proposed computer-assisted diagnosis system starts with the segmentation of the blood vessels. Then, microaneurysms and exudates are segmentation from the image. Statistical and regional features are then extracted utilizing first, second, and higher-order image features. A Deep Learning framework will be utilized for extracting additional statistical image descriptors as a Deep Learning has superior contextual analysis capabilities compared to other machine learning techniques. Finally, the most informative features are selected by a minimal-redundancy maximal-relevance feature selection approach with an AdaBoost classifier analyzing all the features and informing the operator regarding the patient’s condition. Ethereum Swarm blockchain-based decentralized cloud file storage provides the proposed CAD users with a secure storage olution to access the patient information and related images. The sensitivity, specificity, and accuracy of the classification will be measured under clinical conditions. Healthcare, government, and public users would receive the most benefit from this project.
As the core of present blockchain applications, smart contracts are designed to help multiple parties reach an agreement. Along with the promotion of smart contract applications, a large number of economic losses caused by attacks on smart contract vulnerabilities have emerged. Since most smart contracts only disclose bytecode, in recent years, there have been numerous researches on the vulnerability detection of smart contract bytecode, mainly for Ethereum smart contracts, achieving considerable results. My survey summarizes the methods and supported vulnerability types of these tools, aimed at Ethereum or EOSIO, over the years. The problems reflected in it shed light on the future work of smart contract bytecode vulnerability detection.
Ashish Rajendra Sai, Jim Buckley, Brian Fitzgerald, Andrew Le Gear
Bitcoin introduced delegation of control over a monetary system from a select few to all who participate in that system. This delegation is known as the decentralization of controlling power and is a powerful security mechanism for the ecosystem. After the introduction of Bitcoin, the field of cryptocurrency has seen widespread attention from industry and academia, so much so that the original novel contribution of Bitcoin, i.e., decentralization, may be overlooked, due to decentralizations’ assumed fundamental existence for the functioning of such crypto-assets. However, recent studies have observed a trend of increased centralization in cryptocurrencies such as Bitcoin and Ethereum. As this increased centralization has an impact the security of the blockchain, it is crucial that it is measured, towards adequate control. This research derives an initial taxonomy of centralization present in decentralized blockchains through rigorous synthesis using a systematic literature review. This is followed by iterative refinement through expert interviews. We systematically analyzed 89 research papers published between 2009 and 2019. Our study contributes to the existing body of knowledge by highlighting the multiple definitions and measurements of centralization in the literature. We identify different aspects of centralization and propose an encompassing taxonomy of centralization concerns. This taxonomy is based on empirically observable and measurable characteristics. It consists of 13 aspects of centralization, classified over six architectural layers: Governance, Network, Consensus, Incentive, Operational, and Application. We also discuss how the implications of centralization can vary depending on the aspects studied. We believe that this review and taxonomy provides a comprehensive overview of centralization in decentralized blockchains involving various conceptualizations and measures.
Elizabeth Nathania Witanto, Yustus Eko Oktian, Sang-Gon Lee, Jin-Heung Lee
As the usage growth rate of Internet of Things (IoT) devices is increasing, various issues related to these devices need attention. One of them is the distribution of the IoT firmware update. The IoT devices’ software development does not end when the manufacturer sells the devices to the market. It still needs to be kept updated to prevent cyber-attacks. The commonly used firmware update process, over-the-air (OTA), mostly happens in a centralized way, in which the IoT devices directly download the firmware update from the manufacturer’s server. This central architecture makes the manufacturer’s server vulnerable to single-point-of-failure and latency issues that can delay critical patches from being applied to vulnerable devices. The Open Connectivity Foundation (OCF) is one organization contributing to providing interoperability services for IoT devices. In one of their subject areas, they provide a firmware update protocol for IoT devices. However, their firmware update process does not ensure the integrity and security of the patches. In this paper, we propose a blockchain-based OCF firmware update for IoT devices. Specifically, we introduce two types of firmware update protocol, direct and peer-to-peer updates, integrated into OCF firmware update specifications. In the direct scenario, the device, through the IoT gateway, can download the new firmware update from the manufacturer’s server. Meanwhile, in the peer-to-peer scheme, the device can query the update from the nearby gateways. We implemented our protocol using Raspberry Pi hardware and Ethereum-based blockchain with the smart contracts to record metadata of the manufacturer’s firmware updates. We evaluated the proposed system’s performance by measuring the average throughput, the latency, and the firmware update distribution’s duration. The analysis results indicate that our proposal can deliver firmware updates in a reasonable duration, with the peer-to-peer version having a faster completion time than the direct one.
Recursive Length Prefix (RLP) is used to encode a wide variety of data in Ethereum, including transactions. The work described in this paper provides a formal specification of RLP encoding and a verified implementation of RLP decoding, developed in the ACL2 theorem prover. This work has led to improvements to the Ethereum documentation and additions to the Ethereum test suite.
Mohammad Dabbagh, Mohsen Kakavand, Mohammad Tahir, Angela Amphawan
Recent years have witnessed a sizeable growth of Blockchain applications in enterprises. Blockchain is transforming the traditional approach of storing and managing data in a single location into a decentralized ledger. Although many industries are keen on adopting Blockchain technology for enhanced transaction transparency, the performance of the current Blockchain platforms is still perplexing to stakeholders. Therefore, this research aims to conduct an empirical study to evaluate the performance of two prominent Blockchain platforms, Hyperledger Fabric and Ethereum. The performance evaluation is based on measuring four metrics including success rate, average latency, throughput, and resource consumption. The experimental results of executing 100 transactions show that Hyperledger Fabric generally surpasses Ethereum against the four performance metrics. The presented results in this research would assist practitioners in their decision-making process of adopting the ideal Blockchain platform into their IT systems based on application requirements.
S. A. Jayalath, Chathura Rajapakse, Janaka Senanayake
Ticketing mechanism in a public transportation system is a major factor which defines the service quality of the system. Current online payment systems (credit/debit cards, PayPal, etc.) are not compatible with micropayments because transaction processing companies need a minimum transaction amount to make the transaction profitable for them. Therefore, an acceptable micro-transaction model is required in the micropayments domain. In blockchain systems, a third-party intermediary is not facilitating the transactions. Therefore, transaction fees decrease drastically. Using consortium blockchain concept, these fees can be further minimized when proof of work is also handled by a set of approved entities. In this study, an Ethereum based micro-transaction model is proposed to be implemented within the ticketing system in Sri Lankan public transport sector. Bus tickets are programmed as Ethereum smart contracts to handle the payment distribution. Consortium blockchain concept is used in the blockchain-based model where there are regulated bodies as nodes such as the national transport commission to handle the proof of work. Digital currency and Quick Response (QR) codes are incorporated to identify and complete the transaction process. The methodology of this development-oriented research can be described under three major phases. In the first phase, interviews were carried out with relevant stakeholders to identify the process of the current system and its limitations. Also, a broad and extensive study of literature was done parallel to this. During the second phase, identified issues, limitations and downfalls were addressed by designing a novel architecture. In the final phase a prototype is being developed to demonstrate the architecture, In the final phase a prototype is being developed to demonstrate the architecture, then prototype validation and testing were done with simulated data and several key use cases in the domain. The preliminary results of the prototype model show signs of considerable improvement in the service level of the public transport ticketing process and a significant reduction of transaction fees.
This paper presents a private blockchain environment designed to optimize energy exchanges and reach consensus between different users on a university grid. The objectives of this work are to present a fully distributed energy sharing framework that takes into account the individual preferences of the users, and to give guidelines for development of blockchain applications relative to energy sharing. A private Ethereum blockchain with a Proof-of-Authority mechanism is deployed on a local energy community. A smart contract written in Solidity is used to perform distributed optimization under a global power constraint. Python client are used to enable direct interactions between users and the smart contract. The simulations performed on real data show that consensus is obtained after a few iterations, and thus prove that our framework has the potential to be practically used in real situations.
Neville Grech, Michael Kong, Anton Jurisevic, Lexi Brent · 6 authors
Ethereum is a distributed blockchain platform, serving as an ecosystem for smart contracts: full-fledged intercommunicating programs that capture the transaction logic of an account. A gas limit caps the execution of an Ethereum smart contract: instructions, when executed, consume gas, and the execution proceeds as long as gas is available. Gas-focused vulnerabilities permit an attacker to force key contract functionality to run out of gas---effectively performing a permanent denial-of-service attack on the contract. Such vulnerabilities are among the hardest for programmers to protect against, as out-of-gas behavior may be uncommon in nonattack scenarios and reasoning about these vulnerabilities is nontrivial. In this paper, we identify gas-focused vulnerabilities and present MadMax: a static program analysis technique that automatically detects gas-focused vulnerabilities with very high confidence. MadMax combines a smart contract decompiler and semantic queries in Datalog. Our approach captures high-level program modeling concepts (such as "dynamic data structure storage" and "safely resumable loops") and delivers high precision and scalability. MadMax analyzes the entirety of smart contracts in the Ethereum blockchain in just 10 hours and flags vulnerabilities in contracts with a monetary value in billions of dollars. Manual inspection of a sample of flagged contracts shows that 81% of the sampled warnings do indeed lead to vulnerabilities.
U ovom diplomskom radu je opisan problem korištenja podataka iz vanjskih izvora u kontekstu raspodijeljene glavne knjige koji je poznat u literaturi pod nazivom "oracle problem". Istražena su i opisana postojeća rješenja tog problema te je pojašnjen pojam decentraliziranog oracle sustava. Navedeni su tipovi takvih sustava te je objašnjeno kako oni osiguravaju integritet podataka u blok-lancu eliminirajući jedinstvenu točku ispada. Istražene su postojeće implementacije i funkcionalnosti decentraliziranih rješenja za unos podataka iz nepovjerljivih vanjskih izvora. Razvijeno je programsko rješenje za studijski slučaj koji omogućuje primjenu blok-lanca uz korištenje podataka iz vanjskih izvora gdje se koristi rješenje Chainlink s pametnim ugovorima Ethereuma.
Joao Martins, Manuel Parente, Mário Amorim‐Lopes, Luis Amaral · 7 authors
Firms have available many forms of collaboration, including cooperatives or joint ventures, in this way leveraging their market power. Customers, however, are atomic agents with few mechanisms for collaborating, leading to an unbalanced buyer-supplier relationship and economic surpluses that shift to producers. Some group buying websites helped alleviate the problem by offering bulk discounts, but more advancements can be made with the emergence of technologies, such as the blockchain. In this article, we propose a customer-push e-marketplace built on top of Ethereum, where customers can aggregate their proposals, and suppliers try to outcompete each other in reverse auction bids to fulfil the order. Furthermore, smart contracts make it possible to automate many operational activities, such as payment escrows/release upon delivery confirmation, increasing the efficiency along the supply chain. The implementation of this network is expected to improve market efficiency by reducing transaction costs, time delays, and information asymmetry. Furthermore, concepts such as increased bargaining power and economies of scale, and their effects in buyer-supplier relationships, are also explored.
Zhangshuang Guan, Zhiguo Wan, Yang Yang, Yan Zhou · 5 authors
The disruptive blockchain technology is expected to have broad applications in many areas due to its advantages of transparency, fault tolerance, and decentralization, but the open nature of blockchain also introduces severe privacy issues. Since anyone can deduce private information about relevant accounts, different privacy-preserving techniques have been proposed for cryptocurrencies under the UTXO model, e.g., Zerocash and Monero. However, it is more challenging to protect privacy for account-model blockchains (e.g., Ethereum) since it is much easier to link accounts in the account-model blockchain. In this article, we proposeBlockMaze, an efficient privacy-preserving account-model blockchain based on zk-SNARKs. Along with dual-balance model, BlockMaze achieves strong privacy guarantees by hiding account balances, transaction amounts, and linkage between senders and recipients. Moreover, we provide formal security definitions and prove the security ofBlockMaze. Finally, we implement a prototype ofBlockMazebased on Libsnark and Go-Ethereum, and conduct extensive experiments to evaluate its performance. Our 300-node experiment results show that BlockMaze has high efficiency in computation and transaction throughput: one transaction verification takes about 14.2 ms, one transaction generation takes 6.1-18.6 seconds, and its throughput is around 20 TPS.
Blockchain as a service has evolved significantly from where it started as an underlying technology for Bitcoin cryptocurrency when introduced in 2008. Realization of the immense opportunities this technology possesses encouraged the development of several other Blockchain solutions such as Ethereum, which focused more on the unique competencies much beyond just the digital currency. In this chapter, the authors provided insights into the unmatchable capabilities of Blockchain to evade cyber-attacks that can facilitate a much-needed push for the scalable operation of autonomous vehicles by providing a safer and trustable ecosystem through smart contracts. The chapter also discusses the integration of Ethereum Blockchain with Confidential Consortium Framework (CFF) to overcome the shortcomings of Blockchain in terms of speed and volume. Towards the end, they talked about some of the modern technologies such as IoT and AI that can be benefitted by Blockchain.
Existing (popular) blockchain architectures, including the widely used Ethereum and Hyperledger, are generally not designed to achieve conflicting properties such as anonymity and regulation, and transparency and confidentiality. In this article, we propose a privacy-preserving permissioned blockchain architecture (PPChain) that permits one to also introduce regulation, where PPChain's architecture is modified from that of Ethereum. Specifically, we integrate the cryptographic primitives (group signature and broadcast encryption), and adopt practical byzantine fault tolerance consensus protocol with a validate-record separation mechanism, as well as removing the transaction fee and mining reward. To show the utility of PPChain, we provide qualitative security and privacy analysis, and performance analysis. We also explain how PPChain can be deployed in regulation applications, using cryptocurrency, food supply chain, and sealed-bid auctions as examples.
William Pourmajidi, Lei Zhang, John Steinbacher, Tony Erwin · 5 authors
Service Level Agreements (SLA) are employed to ensure the performance of Cloud solutions. When a component fails, the importance of logs increases significantly. All departments may turn to logs to determine the cause of the issue and find the party at fault. The party at fault may be motivated to tamper with the logs to hide their role. We argue that the critical nature of Cloud logs calls for immutability and verification mechanism without the presence of a single trusted party. This article proposes such a mechanism by describing a blockchain-based log storage system, called Logchain, which can be integrated with existing private and public blockchain solutions. Logchain uses the immutability feature of blockchain to provide a tamper-resistance platform for log storage. Additionally, we propose a hierarchical structure to address blockchains’ scalability issues. To validate the mechanism, we integrate Logchain into Ethereum and IBM Blockchain. We show that the solution is scalable and perform the analysis of the cost of ownership to help a reader select an implementation that would address their needs. The Logchain's scalability improvement on a blockchain is achieved without any alteration of blockchains’ fundamental architecture. As shown in this work, it can function on private and public blockchains and, therefore, can be a suitable alternative for organizations that need a secure, immutable log storage platform.
Blockchain works on the principle of distributed Internet system instead of coping with the digital content. The blockchain protocols act as a backbone for the network services. The major protocols are discussed in this chapter with their features, the transaction method utilized, and the pros and cons of the protocols. Some protocols are utilized only for money transfer, whereas others are for money transaction and material transaction. Some protocols act as open-source platforms for development activity along with the money transaction. Some protocols support cross-border transactions with near-zero transaction cost and achieve storage efficiency. All cryptocurrencies have their own way of performing transactions, security features, and the validation of the transaction. After the popularity of bitcoin, many other protocols have been defined for further development according to emerging technologies. The protocols discussed here are bitcoin, Ethereum, Ripple, and Litecoin.