Dimitris Vyzovitis, Yusef Napora, Dirk McCormick, David Dias · 5 authors
Permissionless blockchain environments necessitate the use of a fast and\nattack-resilient message propagation protocol for Block and Transaction\nmessages to keep nodes synchronised and avoid forks. We present GossipSub, a\ngossip-based pubsub protocol, which, in contrast to past pubsub protocols,\nincorporates resilience against a wide spectrum of attacks.\n Firstly, GossipSub's mesh construction implements an eager push model keeps\nthe fan-out of the pubsub delivery low and balances excessive bandwidth\nconsumption and fast message propagation throughout the mesh. Secondly, through\ngossip dissemination, GossipSub realises a lazy-pull model to reach nodes\nfar-away or outside the mesh. Thirdly, through constant observation, nodes\nmaintain a score profile for the peers they are connected to, allowing them to\nchoose the most well-behaved nodes to include in the mesh. Finally, and most\nimportantly, a number of tailor-made mitigation strategies designed\nspecifically for these three components make GossipSub resilient against the\nmost challenging Sybil-based attacks. We test GossipSub in a testbed\nenvironment involving more than 5000 VM nodes deployed on AWS and show that it\nstays immune to all considered attacks. GossipSub is currently being integrated\nas the main messaging layer protocol in the Filecoin and the Ethereum 2.0\n(ETH2.0) blockchains.\n
Proliferation of IoT devices in society demands a renewed focus on securing the use and maintenance of such systems. IoT-based systems will have a great impact on society and therefore such systems must have guaranteed resilience. We introduce cryptographic-based building blocks that strive to ensure that distributed IoT networks remain in a healthy condition throughout their lifecycle. Our presented solution utilizes deterministic and interlinked smart contracts on the Ethereum blockchain to enforce secured management and maintenance for hardened IoT devices. A key issue investigated is the protocol development for securing IoT device deployments and means for communicating securely with devices. By supporting values of openness, automation, and provenance, we can introduce novel means that reduce the threats of surveillance and theft, while also improving operator accountability and trust in IoT technology.
U ovom radu su istražene osnove tehnologije distribuirane glavne knjige i najpoznatiji algoritmi konsenzusa koji mijenjaju centralni autoritet. Uspored̄ene su njihove prednosti i mane. U nastavku je uvod u Ethereum protokol i njegovu arhitekturu. Objašnjen je način provod̄enja transakcija i izvršavanja programskog koda na Ethereum virtualnom stroju. Najveći dio rada je usmjeren postavljanju privatne Ethereum mreže izmed̄u čvorova raznorodnog sklopovlja. Detaljno je opisan postupak izrade novčanika, provod̄enja transakcija, postavljanja i izvršavanja programskog koda pametnog ugovora na blockchain. Ispitani su zahtjevi procesa zaduženog za sudjelovanje u mreži na svakom čvoru.
This project aims to create a blockchain-based model that addresses key challenges in digital voting. The goal is to develop a secure and transparent system that eliminates common issues such as delays in result announcements, voter identity verification concerns, and security risks [1]. Voting is the backbone of any democracy, and ensuring its integrity is crucial. Traditional digital voting systems often face problems like fraud, manipulation, and lack of transparency. Blockchain technology, with its decentralized and tamper-proof nature, offers a promising solution. It functions as a distributed ledger that records transactions securely in a peer-to-peer network, making it nearly impossible to alter past data [2]. This technology brings several benefits to voting, including decentralization, security, transparency, immutability, and voter anonymity [3]. A major highlight of this project is the integration of blockchain with smart contracts, which adds an extra layer of security and automation to the voting process [4]. The system is designed to work on the Ethereum blockchain, using smart contracts written in Solidity and accessed through blockchain wallets [5]. By eliminating the need for a central authority to oversee elections, this approach ensures a fair and transparent voting process where every vote is securely recorded and cannot be tampered with [6]. In essence, this project reimagines digital voting by leveraging blockchain’s strengths, making elections more secure, efficient, and trustworthy.
Open access
3 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
José Eduardo de Azevedo Sousa, Vinícius Cunha Oliveira, Júlia Almeida Valadares, Glauber Dias Gonçalves · 7 authors
Summary Ethereum is a new blockchain‐based platform that is also capable of running smart contracts. Despite its increasing popularity, there is a lack of studies on characterizing this system, in special the fees paid by users and the respective delay to confirm the transactions, that is, the pending time . In this sense, we study the main features of Ethereum transactions and evaluate the common belief—for blockchain systems that rely on proof of work—that users who pay higher fees will have their transactions confirmed faster. Specifically, we collect information about 7.2 million of transactions in Ethereum and correlate their pending time to several fee‐related features. Moreover, we conduct our study evaluating different ranges of values for the features, such as default and unusual values adopted by users as well as clusters of users with similar behaviors. Our empirical analysis shows strong evidence that there is no clear correlation between fees‐related features and the pending time. Overall, we conclude from our investigation that transaction's features, including gas and gas price defined by users, cannot determine the pending time of transactions.
The proposed system is a decentralized authentic platform that aims to leverage blockchain along with other technologies to design a trusted framework which would enable charity donations to be as accountable, trustworthy and transparent. The paper explores the potential for deploying blockchain within existing organizations to support smooth conduction of charity funds from the donor to the actual needy person using a stable Ethereum based Blockchain oriented platform. In this fast developing world of modernization, some people are becoming too competitive to earn money while others have no clue about getting even a penny. But at the same time, there exist people who wish to contribute to the society out of altruism. There exist many online donation platforms in the world and yet issues concerning extra fees, accountability and processing delay still exist as well as these existing centralized systems for charities are so corrupt that people lose belief in these trustless systems and hence the charities become futile. This paper explores how the blockchain can be leveraged in the philanthropic sector, through charitable donation services via a web- based donor platform.
Gulshan Kumar, Rahul Saha, William J. Buchanan, G. Geetha · 8 authors
A distributed and transparent ledger system is considered for various e-commerce products including health medicines, electronics, security appliances, food products and many more to ensure technological and e-commerce sustainability. This solution, named as 'PRODCHAIN', is a generic blockchain framework with lattice-based cryptographic processes for reducing the complexity for tracing the e-commerce products. Moreover, we have introduced a rating based consensus process called Proof of Accomplishment (PoA). The solution has been analyzed and experimental studies are performed on Ethereum network. The results are discussed in terms of latency and throughput which prove the efficiency of PRODCHAIN in e-commerce products and services. The presented solution is beneficial for improving the traceability of the products ensuring the social and financial sustainability. This work will help the researchers to gain knowledge about the blockchain implications for supply chain possibilities in future developments for society.
R. Kalaipriya, S. Devadharshini, R. Rajmohan, M. Pavithra · 5 authors
This paper exhibits a Blockchain-based design for our current Electronic Health Records (EHR) frameworks. Electronic Health Records commonly comprise extremely penetrating and precarious records associated with patients. It needs to track all the events that occurred in the records to achieve data integrity for secure transactions. To solve these problems, we proposed two smart agreements, classified contracts, and user record associated contracts. The classified contract involves organizing the records in a distributed ledger format with secured interventions of Doctors and healthcare providers. The user record associated contracts validate the transactions requested by the concerned miners. We evaluate the proposed architecture by realizing the Ethereum framework, which includes Remix environment, Metamask wallet, and Solidity language. Compared to conventional EHR frameworks, the suggested structure with the employment of the Blockchain has improved efficiency and security for storing electronic health records.
This paper discusses a method to realize peer-to-peer electricity trading. In peer-to-peer trading, prosumers, consumers who can generate electricity by themselves, sell other prosumers surplus electricity. To practice this trading, electric utility might consider transmission loss and storage batteries. Also, there should be some kind of medium. In this research, electricity trading simulations with and without storage batteries will be executed, while using blockchain as a medium. Price of electricity is decided from amount of electricity and transmission loss. About 10 prosumers in small area are set as nodes of peer-to-peer electricity network. As a result, transmission loss in a small scale does not affect electricity trading so much and storage batteries prevented peer-to-peer trading.
Yuichiro Chinen, Naoto Yanai, Jason Paul Cruz, Shingo Okamura
Ethereum smart contracts are programs that are deployed and executed in a consensus-based blockchain managed by a peer-to-peer network. Several re-entrancy attacks that aim to steal Ether, the cryptocurrency used in Ethereum, stored in deployed smart contracts have been found in the recent years. A countermeasure to such attacks is based on dynamic analysis that executes the smart contracts themselves, but it requires the spending of Ether and knowledge of attack patterns for analysis in advance. In this paper, we present a static analysis tool named \textit{RA (Re-entrancy Analyzer)}, a combination of symbolic execution and equivalence checking by a satisfiability modulo theories solver to analyze smart contract vulnerabilities to re-entrancy attacks. In contrast to existing tools, RA supports analysis of inter-contract behaviors by using only the Etherum Virtual Machine bytecodes of target smart contracts, i.e., even without prior knowledge of attack patterns and without spending Ether. Furthermore, RA can verify existence of vulnerabilities to re-entrancy attacks without execution of smart contracts and it does not provide false positives and false negatives. We also present an implementation of RA to evaluate its performance in analyzing the vulnerability of deployed smart contracts to re-entrancy attacks and show that RA can precisely determine which smart contracts are vulnerable.
Door locks connected to the internet, also known as smart locks, offer more convenience and security to control access to a place if compared to conventional locks that use physical keys or with those that use keypads. For instance, smart locks are managed remotely and even if someone once had access permission at some point, they cannot copy the key to attempt unauthorized access later. Those benefits, however, might be compromised due to the centralized system architecture offered by locks’ vendors and manufacturers which allow users to control their devices - someone could gain access over the user’s device and data.\nThis work explores how a permissionless blockchain – the public network of the Ethereum blockchain - can be leveraged to build a convenient and secure smart lock system, while giving the device owners full control over their devices by eliminating the central authority. It proposes an architecture and discusses in-depth the required components and other factors that must be taken into consideration while designing and implementing the system. Furthermore, a proof-of-concept application based on people that rent their places using hospitality services like Airbnb is implemented. The system allows hosts to remotely manage guests' permissions, delegate management rights to others, and allow guests to use a feature that blocks the owner’s permission to unlock the device during their stay.\nThe proof-of-concept is evaluated regarding its functionalities, how long they take to be processed by the blockchain, and how much they cost to be executed. Among the findings are: (i) the proposed architecture and implementation were capable of delivering the expected behaviors for the smart lock functionalities; (ii) the delay associated with using the Ethereum blockchain are reasonable and fit the application use cases; (iii) besides the one-time-only operation to deploy the smart contract in the blockchain, the cost yielded for all other actions stayed below CAD 0.40, which is believed to be feasible considering the application context.
This report intends to play out a precise audit to survey and establish the practicality of blockchain for implementing healthcare service records effectively. Traditional health records are both localized and expensive to operate; they can be improved upon by using blockchain based electronic health records (EHRs). EHRs are just electronic versions of a patient's whole clinical history. EHRs, when stored on blockchain, has some serious advantages when compared to their traditional centrally stored counterparts. The patient's medical records will be stored on a distributed network. An ethereum based decentralized application (DApp) can be incorporated to record and update medical information securely in real time using smart contracts. A decentralized application on a private blockchain network will ensure the integrity of data records and improve interoperability of the system by providing permanent access to essential details like patient's medical track record, prescription history, laboratory/ clinical reports etc. The application uses the efficiency and security of blockchain technology to solve the challenges faced by the healthcare domain.
Abstract Cryptocurrencies are unique and extra-ordinary currencies which to be econometrically forced into the linear model due to their systematic complexity and extreme movements. This paper was conducted to provide an alternative analysis as a solution for escaping the restrictions of traditional linear assumptions. Five predominant digital currencies such as Bitcoin (BTC), Stellar network (XLM), Litecoin (LTC), Ethereum Classic (ETC), and IOTA were chosen to be employed in the multiple processes based on Bayesian approaches. Market dominance and data regime classifications are the essential components that lead to successfully investigate the dependent structures and co-movements in the digital financial market. The empirical findings could assume that the modern time-series data was meticulously estimated by the flexible modern tool. Bayesian statistics and simulations have the sufficient potency as the suitable solution.
Stefano Angieri, Marcelo Bagnulo, Alberto García-Martínez, Bingyang Liu · 5 authors
In this paper, we present InBlock4, a blockchain-based alternative to RPKI for the provision of Route Origin validation for BGP. InBlock4 embeds an alternative trust model to protect entities obtaining a resource allocations from errors and abuses from other entities in the allocation hierarchy. InBlock4 is compatible with BGPsec. Moreover, InBlock4 can be bootstrapped using the information in the RPKI and it can coexists with RPKI-based route origin validation. In the paper, we also present a working implementation of InBlock4 for Ethereum and we quantify its performance.
Arjun Suresh, Akshay R. Nair, Aravind Lal, Mohana Kumaran S. · 5 authors
Digital growth with latest technologies have rendered more comfort to end-users in terms of online transactions. But such online transactions have paved for a steep increase in the crime rate with more fraudulent activities. Major cryptocurrencies such as Bitcoin and Ethereum play a major role in handling such illegal behavior of hackers. Blockchain is the basic concept of cryptocurrencies. It is realized as an immutable ledger which implements transactions in a decentralized manner. As the network is decentralized; achieving consensus between each node can be quite a difficult task. Fortunately, this problem can be solved with the help of consensus algorithms. There are numerous ways in which consensus can be achieved. However, in this paper, on proof-based consensus methods are primarily focused on. The majorities of the proof-based consensus algorithms are susceptible to a 51% attack and also lead to high transaction times. These problems can be overcome using a modified approach on an already existing hybrid proof-based algorithm known as “2-hop blockchain”.
Blockchain Technology Applications and Security
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Bhabendu Kumar Mohanta, Utkalika Satapathy, Meenu Rani Dey, Soumyashree S. Panda · 5 authors
Cyber-physical Systems (CPS) are reshaping the way of interaction with the physical world. Moreover, the true potential of CPS will be realized when a decentralized approach will be taken into account. Blockchain is an up-and-coming technology which can establish trust in CPS, where participants do not trust each other. Blockchain applications eliminate the middle man to provide trust and making the processes more efficient & cheaper. It's decentralized nature and cryptographic algorithm make it immune to attack and becomes a secure technology. When the data is stored on the blockchain it becomes immutable, ensuring trust in data. Nevertheless, this does not guarantee the trustworthiness of the device which is generating the data. We propose a blockchain-based signature storage solution to ensure trust among the participants which is further applicable to a diverse range of blockchain-based CPS applications. We have implemented our system using the Ethereum network and Docker Tools. Our proposed solution guarantees security properties i.e. device identification, authentication, integrity, and non-repudiation. Also, it reduces the storage space and storage cost than the traditional usage of blockchain in CPS.
Elie Kfoury, David Khoury, Ali AlSabeh, Jose Gomez · 6 authors
Blockchain technology is the cornerstone of digital trust and systems' decentralization. The necessity of eliminating trust in computing systems has triggered researchers to investigate the applicability of Blockchain to decentralize the conventional security models. Specifically, researchers continuously aim at minimizing trust in the well-known Public Key Infrastructure (PKI) model which currently requires a trusted Certificate Authority (CA) to sign digital certificates. Recently, the Automated Certificate Management Environment (ACME) was standardized as a certificate issuance automation protocol. It minimizes the human interaction by enabling certificates to be automatically requested, verified, and installed on servers. ACME only solved the automation issue, but the trust concerns remain as a trusted CA is required. In this paper we propose decentralizing the ACME protocol by using the Blockchain technology to enhance the current trust issues of the existing PKI model and to eliminate the need for a trusted CA. The system was implemented and tested on Ethereum Blockchain, and the results showed that the system is feasible in terms of cost, speed, and applicability on a wide range of devices including Internet of Things (IoT) devices.
With the increase of IOT devices worldwide, Software-Defined Networking (SDN) has emerged as a critical tool to optimize and manage congested IP networks. The challenges faced with such networks are achieving optimal resource allocation and traceability. Network operators face network security attacks (eg. MITM) causing a breach in Service-Level Agreements (SLA). Traditional solutions have aimed to improve this using algorithms and additional hardware. This paper presents DecOp, a new methodology in operating a network based on peers instead of a centralized algorithm using Blockchain (BC). BC is a growing technology that is used primarily in the financial industry (eg. BITCON and ETHEREUM) because of its ability to bring dependable consensus amongst several users using distributed ledgers. DecOp makes use of the existing platforms infrastructure to process and store network configurations. This allows for a modular solution that can be implemented and verified with varying platforms. We designed a new method to allocate resources by integrating SDN and BC using the designed Secure Service Contract (SSC) chaincode, Secure Network Operator (SNO) chaincode, and modular communication middleware. This provides a dependable traceability by storing changes to the network state in an immutable ledger. A prototype is developed and tested with Hyperledger Fabric as the BC platform and OpenDaylight as the SDN Controller. Evaluation results focus on system performance versus the BC Network size, from 12 to 40 peers.
The anonymity of blockchain has caused Ponzi schemes to be transferred to smart contract platforms by scammers. These Ponzi schemes wearing the mask of smart contracts caused huge losses to people, which makes the detection of smart Ponzi schemes attract people's attention. Recent methods mainly focus on machine learning technology to enable automatic detection for smart Poniz schemes. However, there are some problems with their methods. Firstly, the gradient boosting algorithm in machine learning they used have the problem of prediction shift due to target leakage when processing category features and calculating gradient estimates. Secondly, they ignored the imbalance and repetitiveness of Ponzi schemes on smart contract platforms. These problems can directly lead to model overfitting and affect the generalization ability of trained models. This paper proposes a novel Ponzi schemes detection method on smart contract platform for blockchain. Our method addresses the above issues with the following strategies. Firstly, we leverage ordered target statistic (TS) to process the category features of smart contract. Secondly, we solve the imbalance of dataset through a data augmentation method. Thirdly, with the idea of ordered boosting algorithm, we train a PonziTect model to fight prediction shift caused by target leakage. Based on the above ideas, the experimental results fully manifest the effectiveness and reliability of our model in detecting smart Ponzi schemes on the blockchain. Specifically, our model achieves 98% F-score on the real-world dataset, which significantly outperforms the existing methods. Using our method, we estimate that there are about 532 Ponzi schemes on Ethereum.
Ignacio Huitzil, Alvaro Fuentemilla, Fernando Bobillo
This paper proposes a novel extension of blockchain systems with fuzzy ontologies. The main advantage is to let the users have flexible restrictions, represented using fuzzy sets, and to develop smart contracts where there is a partial agreement among the involved parts. We propose a general architecture based on four fuzzy ontologies and a process to develop and run the smart contracts, based on a reduction to a well-known fuzzy ontology reasoning task (Best Satisfiability Degree). We also investigate different operators to compute Pareto-optimal solutions and implement our approach in the Ethereum blockchain.
In Bitcoin and Ethereum, nodes require large storage capacity to maintain all the blockchain data, such as transactions, UTXOs, and account states. As of May 2020, the storage size of the Bitcoin blockchain has expanded to 270 GB, and it will continue to increase. This storage requirement is a major hurdle to becoming a block proposer or validator. Although many studies have attempted to reduce the storage size, in the proposed methods, a node cannot keep all blocks or cannot generate a block. We propose an architecture called Trail that allows nodes to hold all blocks in a small storage and to generate and validate blocks and transactions. Trail does not depend on a consensus algorithm or fork choice rule. In this architecture, a client who issues transactions has the data to prove its own balances and can generate a transaction containing the proof of balances. The nodes in Trail do not store transactions, UTXOs and account balances: they keep only blocks. The blocksize is approximately 8 KB, which is 100 times smaller than that of Bitcoin. Further, the block size is constant regardless of the number of accounts and the number of transactions. Compared to traditional blockchains, clients who issue transactions must store additional data. However, we show that proper data archiving can keep the account device storage size small. Trail allows more users to be block proposers and validators and improves the decentralization of the blockchain.