J. Logeshwaran, Venkata Ashok K Gorantla, Venkataramaiah Gude, Bhargavi Gorantla
Crypto currency is subject to persistent and dynamic cyber security risks. As with all types of online assets, digital wallets, exchanges and even individual user accounts are often subject to both malicious attacks and other vulnerabilities. Blockchain technology, due to its distributed nature, is more secure and provides a strong platform on which to build digital currency platforms. This paper seeks to examine the performance of Blockchain technology for improving the security of crypto currency transactions. To assess the system's performance in this regard, we conduct a series of tests to evaluate the system's resilience against various types of attacks, including distributed denial of service (DDoS) and other specialized cyber attacks. We assess the performance of various cyber security measures employed by the crypto currency and Blockchain platforms, including multi-signature wallets, distributed identity solutions, and data encryption approaches. The proposed model achieved 86.82 % hit rate, 87.05%miss rate and 88.57% fall out. Our results, based on an extensive empirical study of crypto currency transactions and Blockchain records, indicate that Blockchain technology significantly enhances the security of crypto currency transactions compared to other technologies. Our findings offer quantitative evidence that Blockchain-secured crypto currency networks are less vulnerable to attack than conventional payment systems.
Syed Anas Ansar, Shruti Aggarwal, Swati Arya, Mohd Asim Sayeed · 6 authors
As the world enters the 21st century, the imperative of safeguarding cybersecurity has intensified. Considering the expanding dependence on information technology (IT) systems for a broad spectrum of military operations, the stakes have never been higher for thwarting successful cyberattacks. Conventional security protocols have become increasingly precarious in the face of evolving cyber threats. This necessitates the adoption of avant-garde and nascent technologies to bolster the military's cybersecurity stance. The paper delves into an array of incipient technologies that proffers the prospect of enhancing cybersecurity in the realm of defence. These include artificial intelligence (AI), machine learning (ML), blockchain, and quantum computing. AI can be leveraged to automate numerous cybersecurity functions, such as threat detection and response. ML can augment the precision of threat detection and response systems. Blockchain, a distributed ledger technology, can safeguard data and transactions. Quantum computing, a nascent technology, harbours the potential to revolutionize computation. It could be utilized to breach present-day encryption standards, thereby rendering data vulnerable to attackers. Moreover, the paper appraises the exigencies and possibilities in defence cyber security and scrutinizes the policy and practice ramifications of these emergent technologies and best practices.
With the development of big data and cloud computing, ensuring authenticity and validity has become paramount issue. This paper introduces a novel verification mechanism, which is based on game theory and smart contracts, to validate the genuineness of results from cloud services given to users. It not only vouches for the veracity of these results but also promotes participation from trustworthy cloud service providers by introducing a strategically designed incentive system. The designed game-theoretical model combined with the execution sequence of the smart contracts acts as a deterrent against deceitful actions by potential malicious service entities. Experimental results prove the effectiveness and feasibility of this method.
Yizhong Liu, Xinxin Xing, Z. Tong, Xun Lin · 8 authors
The cloud-edge-end architecture is suitable for many essential scenarios, such as 5 G, the Internet of Things (IoT), and mobile edge computing. Under this architecture, cross-domain and cross-layer data sharing is commonly in need. Considering cross-domain data sharing under the zero-trust model, where each entity does not trust the others, existing solutions have certain problems regarding security, fairness, scalability, and efficiency. Aiming at solving these issues, we conduct the following research. First, a new plaintext checkable encryption scheme is constructed, which can be used on lightweight IoT devices to verify the ciphertext validity sent by a data owner. Second, we propose a new multi-domain cloud-edge-end architecture based on sharding blockchains and design a cross-domain data sharing scheme under the partial trust model to achieve security, scalability, and high performance. Third, a cross-domain data sharing scheme under the zero trust model is further designed, which can ensure the fairness of both parties in data sharing. Fourth, we give a formal security definition and analysis of cross-domain data sharing. Fifth, we conduct a detailed theoretical analysis of the protocol and give an in-depth functional test and performance test, including the throughput and latency of data sharing policy registration and execution.
We present an implementation of a Web3 platform that leverages the Groth16 Zero-Knowledge Proof schema to verify the validity of questionnaire results within Smart Contracts. Our approach ensures that the answer key of the questionnaire remains undisclosed throughout the verification process, while ensuring that the evaluation is done fairly. To accomplish this, users respond to a series of questions, and their answers are encoded and securely transmitted to a hidden backend. The backend then performs an evaluation of the user's answers, generating the overall result of the questionnaire. Additionally, it generates a Zero-Knowledge Proof, attesting that the answers were appropriately evaluated against a valid set of constraints. Next, the user submits their result along with the proof to a Smart Contract, which verifies their validity and issues a non-fungible token (NFT) as an attestation of the user's test result. In this research, we implemented the Zero-Knowledge functionality using Circom 2 and deployed the Smart Contract using Solidity, thereby showcasing a practical and secure solution for questionnaire validity verification in the context of Smart Contracts.
The work corresponds to the security of Big Data, the key element of the modern digital world. The distributed ledger technology is widely applied to achieve data integrity and confidentiality. However, all relevant solutions are grounded in specific application environments and platforms, what determines the goal to create a universal approach in which Big Data processing components can vary and interchange. The paper proposes a method for ensuring the traceability of Big Data processing in heterogeneous data systems. Traceability is the ability to ensure that data is completely traceable across the entire system. This allows data to be easily followed all the way back to the original sources, audited and controlled. Big Data processing models have been presented. HashGraph and Blockchain distributed ledger mechanisms have been adapted to monitor Big Data processing chains. For tracing Big Data, the appropriate components of the distributed ledger have been modified and implemented. The experiments have been arranged on the test data system processing the big network traffic input, and it has been confirmed that the proposed solution is universal for the ledger technology, does not depend on the Big Data processing platform, and provides Big Data security preserving the computing resources of the protected system.
Abstract Zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) are the most efficient proof systems in terms of proof size and verification. Currently, Groth’s scheme from EUROCRYPT 2016, $$\textsf{Groth16}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Groth</mml:mi> <mml:mn>16</mml:mn> </mml:mrow> </mml:math> , is the state-of-the-art and is widely deployed in practice. $$\textsf{Groth16}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Groth</mml:mi> <mml:mn>16</mml:mn> </mml:mrow> </mml:math> is originally proven to achieve knowledge soundness, which does not guarantee the non-malleability of proofs. There has been considerable progress in presenting new zk-SNARKs or modifying $$\textsf{Groth16}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Groth</mml:mi> <mml:mn>16</mml:mn> </mml:mrow> </mml:math> to efficiently achieve strong Simulation extractability, which is shown to be a necessary requirement in some applications. In this paper, we revise the Random oracle based variant of $$\textsf{Groth16}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Groth</mml:mi> <mml:mn>16</mml:mn> </mml:mrow> </mml:math> proposed by Bowe and Gabizon, BG18, the most efficient one in terms of prover efficiency and CRS size among the candidates, and present a more efficient variant that saves 2 pairings in the verification and 1 group element in the proof. This supersedes our preliminary construction, presented in CANS 2020 (Baghery et al. in CANS 20, volume 12579 of LNCS, Springer, Heidelberg. pp 453-461, 2020), which saved 1 pairing in the verification, and was proven in the generic group model. Our new construction also improves on BG18 in that our proofs are in the algebraic group model with Random Oracles and reduces security to standard computational assumptions in bilinear groups (as opposed to using the full power of the generic group model (GGM)). We implement our proposed simulation extractable zk-SNARK (SE zk-SNARK) along with BG18 in the library, and compare the efficiency of our scheme with some related works. Our empirical experiences confirm that our SE zk-SNARK is more efficient than all previous simulation extractable (SE) schemes in most dimensions and it has very close efficiency to the original $$\textsf{Groth16}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>Groth</mml:mi> <mml:mn>16</mml:mn> </mml:mrow> </mml:math> .
Fake news and misinformation are prevalent on the Internet in this day and age. The popularity of social media such as Facebook, Instagram, TikTok has encouraged the people to share news or information over Internet without knowing whether it is a truth or fake information. The outbreak of COVID-19 affected the social activities of all levels of society as people were asked to stay at home to self-quarantine. It indirectly encourages the growth of the social activities online. Even though COVID- 19 is no longer a big threat to the world, people already used to rely on the Internet for the daily activities. Therefore, the trustworthy of the information on the Internet is getting crucial. ETHERST is a blockchain- based PKI that implemented rewarding and punishment mechanism using Ethereum ECR-20 token named PKIToken to improve the trustworthiness of information published by the blockchain nodes. In this paper, we implement an Ethereum-based distributed application (dapp) that allowed the community members to act on trusting and untrusting on information provided by any of the members. With the ETHERST framework as the backend, the ETHERSTWEB is equipped with the rewarding and punishment mechanism to keep the community from misusing the trusting and untrusting action to maintain the trustworthiness of information of a member. With the PKIToken amount level implemented in the backend, it provides an index to the trustworthiness of a member in the community. It has the advantages over the existing rating or review systems that are commonly implemented in many traditional web applications.
Abstract A rising number of educational solutions based on blockchain technology have been designed. Students and other authorities responsible for verifying certificates are very concerned about the authenticity of academic credentials, either because the institutions that issue them no longer exist or because they do not keep adequate records. Blockchain technology has much to offer in education, including its high level of security, improved data access control, low cost, improved accountability, identity authentication, transparency, increased trust, and improved efficiency in managing student records. We proposed a decentralized blockchain‐based secure platform for the storage of academic certificates and student assessments with double encryption. Apart from speeding up the verification process, it will increase the safety of personal education data and assessments of all kinds of misuse. The data would only be accessed using a stakeholder's private key, and storing documents on a blockchain would increase security. We proposed a framework to offer a secure channel for educational resources. We are storing documents over blockchain utilizing an IPFS distributed data server. We give a thorough explanation of the system development, design, and evaluation of the suggested solution in terms of security and cost. Finally, we put the proposed framework to the test by deploying a smart contract prototype on the Ethereum TESTNET network in a Windows environment. The study's findings revealed that the proposed method is effective and feasible.
The Blockchain Organized Framework for Unified Systems (BOFUS) and the Comprehensive Ledger Assessment for Robust Interoperability and Trustworthiness (CLARITY) initiatives address the challenges of understanding, standardizing, and enabling interoperability between diverse blockchain systems. BOFUS is a comprehensive 5-layer model that systematically organizes core blockchain components, while the CLARITY assessment provides a standardized method for evaluating and comparing blockchains using the CONFIGURE acronym. Together, these initiatives aim to facilitate a deeper understanding of blockchain technology, promote effective communication and collaboration between stakeholders, and ultimately advance the development and adoption of distributed ledger technologies. This paper presents an in-depth discussion of the BOFUS architecture and the CLARITY assessment, exploring their utility in various blockchain scenarios and their potential implications for the future of blockchain technology.
Ethereum (ETH) is a popular Layer-1 blockchain platform that has been used to create decentralized applications (dApps) and smart contracts. Ethereum 2.0, or Serenity, is a significant update to the network that intends to address numerous issues with scalability, security, and energy efficiency. The Proof-of-Stake (PoS) consensus method will replace the Proof-of-Work (PoW) mechanism, which is one of the major new features of Ethereum 2.0. Given that PoS doesn’t require miners to do intensive mathematical calculations in order to validate transactions, it has the potential to be more energy-efficient than PoW. Additionally, this Ethereum upgrade will also be more secure due to the introduction of a new mechanism called “Casper” that will ensure that validators are always in agreement on the state of the blockchain. The paper begins by discussing the current issues facing Ethereum, including the limitations of the Proof of Work (PoW) consensus mechanism and the need for more efficient and scalable solutions. In this study, we peered at the major changes introduced by Ethereum 2.0, such as the new consensus method (Proof-of-Stake) and the addition of shard chains (Ethereum 2.0), as well as the associated development timelines, benefits and the community criticism on this upgrade.
A large number of raw data collected by satellites are processed by the production chain to obtain a large number of product data, of which the secure exchange and storage is of interest to researchers in the field of remote sensing information science. Authentic, secure data provide a critical foundation for data analysis and decision-making. Traditional centralized cloud computing systems are vulnerable to attack and, once the central server is successfully attacked, all data will be lost. Distributed ledger technology (DLT) is an innovative computer technology that can ensure information security and traceability, is tamper-proof, and can be applied to the field of remote sensing. Although there are many advantages to using DLT in remote sensing applications, there are some obstacles and limitations to its application. Remote sensing data have the characteristics of a large data volume, a spatiotemporal nature, global scale, and so on, and it is difficult to store and interconnect remote sensing data in the blockchain. To address these issues, this paper proposes a trustworthy and decentralized system using blockchain technology. The novelty of this paper is the proposal of a multi-level blockchain architecture in which the system collects remote sensing data and stores them in the Interplanetary File System (IPFS) network; after generating the IPFS hash, the network rehashes the value again and uploads it on the Ethereum chain for public query. The distributed data storage improves data security, supports the secure exchange of information, and improves the efficiency of data management.
Mohammad M. Jalalzai, Jianyu Niu, Chen Feng, Fangyu Gai
he HotStuff protocol is a recent breakthrough in Byzantine Fault Tolerant (BFT) consensus that enjoys both responsiveness and linear view change by creatively adding a round to classic two-round BFT protocols like PBFT. Despite its great advantages, HotStuff has a few limitations. First, the additional round of communication during normal cases results in higher latency. Second, HotStuff is vulnerable to certain performance attacks, which can significantly deteriorate its throughput and latency. To address these limitations, we propose a new two-round BFT protocol called Fast-HotStuff, which enjoys responsiveness and efficient view change that is comparable to the linear view-change in terms of performance. Our Fast-HotStuff has lower latency and is more robust against the performance attacks that HotStuff is susceptible to.
<em>The intersection of cryptocurrencies and franchising is generating a wave of innovation and curiosity. While cryptocurrencies offer the potential for streamlined transactions, increased security, and global reach, they also bring a host of legal considerations that must be meticulously addressed in franchising contracts. In this article, we delve into key legal consequences that arise when utilizing cryptocurrencies in franchising agreements.</em>
Smart contracts, programs running on a blockchain, play a crucial role in driving Web 3.0 across a variety of domains, such as digital finance and future networks. However, they currently face significant security vulnerabilities that could result in potential risks and losses. This paper outlines the inherent vulnerabilities of smart contracts, both those typical of their applications and those unique to Web 3.0 applications. We then systematically classify the techniques based on their core approach to detecting vulnerabilities in smart contracts. Using these approaches, we conduct a comparative analysis of existing tools in terms of their vulnerability coverage, detection effectiveness, open-source availability, and integration capabilities. Finally, we present the Co-Governed Sovereignty Multi-Identifier Network (CoG-MIN) as a case study to demonstrate the significance of smart contract application security in establishing a community with a shared future in cyberspace during the Web 3.0 era and anticipate future research directions with challenges. To conclude, this study addresses the gap in integrating existing smart contract security research with the advancement of Web 3.0 development, while also providing recommendations for future research directions.
Annisa Dini Handayani, Sa'aadah Sajjana Carita, Nia Yulianti
Zero-knowledge proof is a tool in cryptography that ensures the privacy of the users. In general, zero-knowledge (ZK) proves that a user (called the prover) knows one secret value to another (called the verifier) without revealing the secret value itself. This proof is used, for instance, in password verification or authentication process. The concept of ZK has been implemented in various fileds, including secure multi-party computation and blockchain technology. ZK proof could use pairing as the interactive function, through which the prover and verifier play their roles. ZK proof usually protects one secret, meaning the prover only certifies their knowledge of one single secret value. In this paper, we proposed a zero-knowledge scheme using a bilinear map which could help a user prove their knowledge related to multiple secret values to others. We also show that this scheme satisfies completeness and soundness properties, implying the proposed scheme is a proof of knowledge.
All Distributed Ledger Technologies (DLTs) are subject to the "blockchain trilemma”, which states that the level of decentralization, security, and scalability cannot all be maximized at the same time. Thus, no single DLT can fulfill the requirements of all the use cases. However, linking multiple ledgers by an Interledger can help overcome this limitation. Unfortunately, there are three key problems affecting Interledgers: 1) they are solely focusing on transferring funds, 2) are only compatible with certain types of ledgers, and 3) are too complex (e.g. require changes to the ledgers to be connected), and most current solutions suffer from at least one of them. As a concept, bridging type Interledgers are the most promising approach, and specifically, the Decentralized Interledger Bridge (DIB) addresses all three problems. It is a lightweight solution enabling general-purpose atomic data transfer across heterogeneous distributed ledgers without having any restrictive assumptions on the client ledgers or requiring any changes to them, and the decentralized architecture provides trustworthiness and resiliency to the solution. However, the DLT used for coordinating the multiple nodes of the bridge creates a throughput and scalability bottleneck. This thesis optimizes the throughput and scalability of DIB with a new design that eliminates the coordinating DLT while still preserving the decentralized architecture for increased trustworthiness and resiliency. The results show that the throughput per node of the new design is an order of magnitude higher and the design also scales close to linearly as a function of nodes in the bridge, while the failure tests show that it maintains essentially the same resiliency and robustness as the original design.
ANDREI BOGDAN STANESCU, CATALIN VAJAIALA, Dragoş Cocîrlea
Abstract In the current digital world, ensuring efficient storage capabilities and increased data privacy, as well as high data availability and redundancy, are critical key performance indicators for organizations striving for customer excellence. To achieve these, a modern two-layer technical architecture is proposed in this study. The core layer of the solution is an InterPlanetary File System (IPFS) Cluster that leverages the distributed storage concept, and the second is an Ethereum-based blockchain that leverages privacy and immutability mechanisms. Next, the two-layer architecture is implemented and deployed to enhance data protection, as well as optimize data storage and access for a mid-size organization. The results reveal the enhancement of IPFS to overcome its privacy concerns via role-based access and cryptographic techniques. Moreover, the benefits of utilizing IPFS for data redundancy, efficient storage, and transfer through its distributed nature were reported. Finally, the integration of the IPFS Cluster with the Ethereum-based blockchain, as well as the overall benefits, we described.
This chapter discusses blockchain technology, how distributed ledger works, transactions function in blockchain, and how distributed transactions are operated. We then look at the consensus system of blockchain and digital signatures. Next, we look at the major industrial applications like cloud computing in blockchain, software engineering frameworks using blockchain, cryptocurrencies, smart contracts, energy trading using blockchain, supply chain management, healthcare, etc. We have proposed a model for manufacturing using blockchain-based distributed transactions, which aims to solve major industrial problems using techniques highlighted in the chapter.
K. Suganthi, Krishnansh Singh, Sajal Tayal, Mandeep Singh
In today’s rapidly growing economy with everincreasing inflation, the purchasing power of money keeps decreasing as time pass by therefore it becomes important to invest money to counter the growing inflation. Real estate investment has been a proven hedge against inflation over many decades. The Real Estate sector despite so much contribution to the financial system has seen relatively less innovation in terms of technology. Blockchain has shown a great affinity towards managing real estate properties and all the transactions involved. Investment in this sector usually requires huge capital as a result, small retail investors are not able to invest. This is where Real Estate Investment Trust (REIT) comes to the rescue of retail investors. This paper focuses on the ERC721M token standard and proposed architecture as to how a REIT company can make use of ERC721M to design their Decentralized Asset organization, or simply DAO, which will help them in adapting web3 technologies and bring automation in their procedure of operations with maximum transparency, We have also done a comparative analysis of ERC721Mv/s Standard Deployment and why ERC721M is the best token standard to be suited for creating smart contract interface for such an operation.
Andrea De Salve, Damiano Di Francesco Maesa, Paolo Mori, Laura Ricci · 5 authors
The recent interest for decentralised systems and decentralisation of the control over users’ data brings a shift in the way identities and their information are managed. Self Sovereign Identity (SSI) has been proposed as the next generation paradigm for decentralised identity management. Research on SSI is getting more and more traction, focusing mainly on the management of users’ identifiers and on providing a standard way to express and verify credentials. Instead, this paper focuses on the understanding of the role of trust in SSI and it provides new insight into the trust relationships existing between the different SSI actors. Indeed, the analysis of such roles and the relationships existing between SSI actors reveals that the current paradigm suffers from trust issues between the verifier and the issuer of a verifiable credential. In order to cope this problem, the paper proposes a new multi-layer framework that exploits trust relationships defined by the actors of the SSI standards (verifiers and issuers of verifiable credentials). An implementation of the framework through Solidity smart contracts has been proposed and deployed on both private and public blockchain networks in order to assess its capabilities. In addition, a dataset related to the spread of spam reviews has been exploited to test the benefits and performance of the proposed framework, demonstrating that it is able to improve the reliability of the SSI paradigm in real-world scenario.