Blockchain is a promising technology and is becoming predominant for solving many problems in the field related to security under the control of both public and private sectors. Blockchain is gaining popularity within the domain of charity. Due to lack of transparency in the transactions involved in Donations the donor(s) are not able to know whether their donations are being utilized properly, which has made people lose trust in Charities. The paper proposes a Blockchain based Decentralized Donation tracking system built on Ethereum Blockchain which will provide full transparency, accountability and direct reach to the intended recipients.
Luca Foschini, Andrea Gavagna, Giuseppe Martuscelli, Rebecca Montanari
Hyperledger Fabric, created and supported by the Linux Foundation and IBM, is one of the most popular open-source blockchain permissioned platforms that has been already used in many industrial scenarios. One of the main characteristics of this platform is that it provides a smart contract system that relies on general-purpose languages instead of an ad hoc one. In fact, a chaincode in the Fabric platform (the equivalent of the Ethereum smart contract) is a software program which encapsulates the business logic for the creation and modification of logical assets in the ledger that can be written in different general-purpose programming languages (currently Java, Go, and Node.js). This paper analyses the transaction performance of the Fabric platform by identifying at a fine-grained degree level the factors that most contribute to the overall overhead. In particular, we focus on how the transaction latency is affected by the programming language adopted for implementing the chaincode and by varying the number of participating endorser peers. Finally, the paper shows a thorough test assessment aimed at evaluating the impact of the different chaincode implementation on performance overhead. As it emerges from our experimental results, Go is the most performing programming language.
Given the large adoption and economical impact of permissionless blockchains, the complexity of the underlying systems and the adversarial environment in which they operate, it is fundamental to properly study and understand the emergent behavior and properties of these systems. We describe our experience on a detailed, one-month study of the Ethereum network from several geographically dispersed observation points. We leverage multiple geographic vantage points to assess the key pillars of Ethereum, namely geographical dispersion, network efficiency, blockchain efficiency and security, and the impact of mining pools. Among other new findings, we identify previously undocumented forms of selfish behavior and show that the prevalence of powerful mining pools exacerbates the geographical impact on block propagation delays. Furthermore, we provide a set of open measurement and processing tools, as well as the data set of the collected measurements, in order to promote further research on understanding permissionless blockchains.
With the gradual development of blockchain technology and the decentralized demand of the Internet market, the programmable financial system with blockchain technology has been proposed. However, the uncertainty of smart contract in Ethereum application layer leads to fatal problems on Ethereum network, which affects the efficiency and usages. Moreover, most schools or enterprises have not mastered blockchain technology, so it is difficult to carry out experiments of Ethereum, such as the simple account transfer transaction and deployment of smart contract. The paper is to research the Ethereum private blockchain network locally, and provide an experimental platform, which can conduct operations of Ethereum account and block information among multiple nodes. Through the research on private blockchain multi-nodes platform, a test environment for some school lessons or enterprise projects is provided. Then we implement and test of smart contract applications on Ethereum to ensure the overall security of Ethereum network.
Smart grids are being continually adopted as a replacement of the traditional power grid systems to ensure safe, efficient, and cost-effective power distribution. The smart grid is a heterogeneous communication network made up of various devices such as smart meters, automation, and emerging technologies interacting with each other. As a result, the smart grid inherits most of the security vulnerabilities of cyber systems, putting the smart grid at risk of cyber-attacks. To secure the communication between smart grid entities, namely the smart meters and the utility, we propose in this paper a communication infrastructure built on top of a blockchain network, specifically Ethereum. All two-way communication between the smart meters and the utility is assumed to be transactions governed by smart contracts. Smart contracts are designed in such a way to ensure that each smart meter is authentic and each smart meter reading is reported securely and privately. We present a simulation of a sample smart grid and report all the costs incurred from building such a grid. The simulations illustrate the feasibility and security of the proposed architecture. They also point to weaknesses that must be addressed, such as scalability and cost.
Telesurgery (TS) with 5G-enabled Tactile Internet (TI) has enormous potential to deliver real-time ultra-responsive surgical services remotely with high quality and accuracy. It is quite beneficial for society in the prospect of highly precise surgical diagnosis. However, the existing TS systems have security, privacy, latency, and blockchain (BC) storage cost issues, which restricts its applicability in surgical procedures across the world in the near future. To mitigate the above-mentioned issues, in this paper, we propose an approach named AaYusH (Ethereum smart contract (ESC) and IPFS-based TS system). The security and privacy issues in AaYusH can be resolved through ESC, whereas storage cost issues with the InterPlanetary File System (IPFS) protocol. Moreover, we present a real-time SC written in Solidity and deployed in Truffle suite. We test the security bugs of AaYusH in MyThril open-source tool and detect no issues. Finally, we evaluate the performance of AaYusH in context to latency and data storage cost, and it outperforms as compared to the traditional telesurgery system.
Traditional paper certificates and electronic certificates have difficulties in preservation and management, not to mention other problems concerning inconvenient verification, poor reliability, anti-counterfeiting and anti-tampering. This paper proposes a scheme designed to build a decentralized certificate system that is based on blockchain technology and smart contract, in which a set of blockchain certificate system aiming at providing blockchain certificate services for college students' innovation and entrepreneurship competition is developed. In this system, certain functions of the certificate about management, issuing, verification and revocation are realized via smart contract. Signer information, certificate template and certificate information are stored in a smart contract that adopts structured data, thereby realizing more convenient callings in querying and validating certificate.
Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The topic of performing safe and secure elections is a long-standing debate. Regardless, of the various attempts for electronic or Internet-based voting, the majority of countries still use paper ballots. Nevertheless, with major advancements occurring over the last years in both cryptography and distributed ledgers we believe that there is space now for re-investigating this area. In this paper, we propose ethVote an Internet voting system that makes use of the Ethereum blockchain, state of the art cryptographic mechanisms and a P2P-based front-end to ensure a secure voting process. In addition, we provide an open-source proof of concept implementation that features the majority of the needed components for securely using ethVote. Our proposal is tested both in terms of unit testing, requirement verification, and with regard to the feasibility to perform such an operation in a public distributed ledger.
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Mario R. Morales, Luis Rosero-Correa, Santiago Morales Cardoso
La implementación de nuevas tecnologías en cualquier tipo de institución surge de la necesidad de generar mejoras en los procesos que éstas realizan con el fin de ofrecer mejores productos y servicios. En este artículo se analiza la propuesta de factibilidad de una aplicación basada en la tecnología Blockchain y en los contratos inteligentes para reproducir el proceso de asignar títulos académicos a estudiantes sin necesidad de un ente central, terceras personas y procesos burocráticos mientras se aprovecha las características de estas tecnologías como la transparencia, la seguridad y la inmutabilidad. Así, se desarrolló dos contratos inteligentes complementarios entre sí aprovechando las características que existen actualmente para crear estructuras que representan objetos de la vida real y funciones que manejen estas estructuras como parámetros. Estos contratos se ejecutaron en un entorno virtualizado el que se simuló una cadena de bloques de Ethereum con el conjunto de herramientas de Truffle. Se evaluó los contratos inteligentes ingresando datos de prueba y con estos registros almacenados en la cadena de bloques se ejecutó el proceso de asignar los títulos académicos a los estudiantes a través de una función dentro del contrato inteligente principal. Para validar que el proceso se ejecutó correctamente, se realizó consultas a la cadena de bloques y se verificó que los registros de asignaciones de títulos se generaron y almacenaron en la cadena de bloques con éxito. De esta manera se pudo concluir que es factible el modelo propuesto basado en tecnología blockchain y contratos inteligentes.
Sean Tan, Sourav S. Bhowmick, Huey Eng Chua, Xiaokui Xiao
Smart contracts enable developers to run instructions on blockchains (eg. Ethereum) and have broad range of real-world applications. Solidity is the most popular high-level smart contract programming language on Ethereum. Coding in such language, however, demands a user to be proficient in contract programming and debugging to construct smart contracts correctly. In practice, such expectation makes it harder for non-programmers to take advantage of smart contracts. In this demonstration, we present a novel visual smart contract construction system on Ethereum called latte to make smart contract development accessible to non-programmers. Specifically, it allows a user to construct a contract without writing Solidity code by manipulating visual objects in a direct manipulation-based interface. Furthermore, latte interactively guides users and makes them aware of the cost (in units of Gas) of visual actions undertaken by them during contract construction.
Pınar Kaya Soylu, Mustafa Okur, Özgür Çatıkkaş, Ayca Altintig
This paper examines the volatility of cryptocurrencies, with particular attention to their potential long memory properties. Using daily data for the three major cryptocurrencies, namely Ripple, Ethereum, and Bitcoin, we test for the long memory property using, Rescaled Range Statistics (R/S), Gaussian Semi Parametric (GSP) and the Geweke and Porter-Hudak (GPH) Model Method. Our findings show that squared returns of three cryptocurrencies have a significant long memory, supporting the use of fractional Generalized Auto Regressive Conditional Heteroscedasticity (GARCH) extensions as suitable modelling technique. Our findings indicate that the Hyperbolic GARCH (HYGARCH) model appears to be the best fitted model for Bitcoin. On the other hand, the Fractional Integrated GARCH (FIGARCH) model with skewed student distribution produces better estimations for Ethereum. Finally, FIGARCH model with student distribution appears to give a good fit for Ripple return. Based on Kupieck’s tests for Value at Risk (VaR) back-testing and expected shortfalls we can conclude that our models perform correctly in most of the cases for both the negative and positive returns.
Ferenc Béres, István András Seres, András A. Benczúr, Mikerah Quintyne-Collins
Ethereum is the largest public blockchain by usage. It applies an account-based model, which is inferior to Bitcoin's unspent transaction output model from a privacy perspective. Due to its privacy shortcomings, recently several privacy-enhancing overlays have been deployed on Ethereum, such as non-custodial, trustless coin mixers and confidential transactions. In our privacy analysis of Ethereum's account-based model, we describe several patterns that characterize only a limited set of users and successfully apply these quasi-identifiers in address deanonymization tasks. Using Ethereum Name Service identifiers as ground truth information, we quantitatively compare algorithms in recent branch of machine learning, the so-called graph representation learning, as well as time-of-day activity and transaction fee based user profiling techniques. As an application, we rigorously assess the privacy guarantees of the Tornado Cash coin mixer by discovering strong heuristics to link the mixing parties. To the best of our knowledge, we are the first to propose and implement Ethereum user profiling techniques based on quasi-identifiers. Finally, we describe a malicious value-fingerprinting attack, a variant of the Danaan-gift attack, applicable for the confidential transaction overlays on Ethereum. By incorporating user activity statistics from our data set, we estimate the success probability of such an attack.
Oliver James Scholten, David Zendle, James Alfred Walker
Decentralised gambling applications are a new way for individuals to engage in online gambling. Decentralised gambling applications are distinguished from traditional online casinos in that individuals use cryptocurrency as a stake. Furthermore, rather than being stored on a traditional server, decentralised gambling applications are stored on a cryptocurrency’s blockchain.Previous work in the player behaviour tracking literature has examined the spending profiles of gamblers on traditional online casinos. However, parallel work has not taken place in the decentralised gambling domain. The profile of gamblers on decentralised gambling applications are therefore not known.This paper explores 2,232,741 transactions from 24,234 unique addresses to three such applications operating atop the Ethereum cryptocurrency network over 583 days. We present spending profiles across these applications, providing the first detailed summary of spending behaviours in this technologically advanced domain. We find that the typical user spends approximately \$110 equivalent across a median of 6 bets in a single day, although heavily involved bettors spend approximately \$100,000 equivalent over a median of 644 bets across 35 days. Our findings suggest that the use of decentralised gambling applications typically involves lower and less frequent expenditures than other online casinos, but that the most heavily involved players in this new domain spend substantially more. Our findings also demonstrate the use of these applications as a research platform, specifically for large scale longitudinal in-vivo data analysis.
This paper proposes a real-time chain and a novel embedded Markovian queueing model with variable bulk arrival (VBA) and variable bulk service (VBS) in order to establish and assure a theoretical foundation to design a blockchain-based real-time system with particular interest in Ethereum. Based on the proposed model, various performances are simulated in a numerical manner in order to validate the efficacy of the model by checking good agreements with the results against intuitive and typical expectations as a baseline. A demo of the proposed real-time chain is developed in this work by modifying the open source of Ethereum Geth 1.9.11. The work in this paper will provide both a theoretical foundation to design and optimize the performances of the proposed real-time chain, and ultimately address and resolve the performance bottleneck due to the conventional block-synchrony by employing an asynchrony by the real-time deadline to some extent.
Proof-of-Work~(PoW) based blockchains typically allocate only a tiny fraction (e.g., less than 1% for Ethereum) of the average interarrival time~($\mathbb{I}$) between blocks for validating transactions. A trivial increase in validation time~($τ$) introduces the popularly known Verifier's Dilemma, and as we demonstrate, causes more forking and increases unfairness. Large $τ$ also reduces the tolerance for safety against a Byzantine adversary. Solutions that offload validation to a set of non-chain nodes (a.k.a. off-chain approaches) suffer from trust issues that are non-trivial to resolve. In this paper, we present Tuxedo, the first on-chain protocol to theoretically scale $τ/\mathbb{I} \approx 1$ in PoW blockchains. The key innovation in Tuxedo is to separate the consensus on the ordering of transactions from their execution. We achieve this by allowing miners to delay validation of transactions in a block by up to $ζ$ blocks, where $ζ$ is a system parameter. We perform security analysis of Tuxedo considering all possible adversarial strategies in a synchronous network with end-to-end delay $Δ$ and demonstrate that Tuxedo achieves security equivalent to known results for longest chain PoW Nakamoto consensus. Additionally, we also suggest a principled approach for practical choices of parameter $ζ$ as per the application requirement. Our prototype implementation of Tuxedo atop Ethereum demonstrates that it can scale $τ$ without suffering the harmful effects of naive scaling in existing blockchains.
Remittance is a global service used to transfer money to family and friends. Throughout the world, many companies offer remittance services to families who depend on them for their livelihood. Regrettably, there is an aspect of the remittance transaction that is not adequately addressed in the current remittance model. A majority of remittance transactions are initiated with the clear intention that the receiver will acquire a service, for example, pay for school fees, medical procedures or groceries. Unfortunately, the current model stops managing the remittance transaction when the beneficiary collects the money and does not ensure that the remittance is correctly used to acquire the intended service. This research addresses this limitation in proposing a model of remittance that considers all the steps necessary to ensure that the remittance transaction concurs with the intention of the expeditor: sending the money, acquiring a service and paying for a service or returning the money in the case that the service is not provided. In this model, the amount transferred through remittance will only be used for its intended purpose as expected by the remittance’s expeditor; otherwise, the expeditor of the remittance gets the money back.
This type of remittance of service is called a trusted remittance of service (TRS) compared with the legacy remittance of money that stops with the collection of the money by the beneficiary. After conducting an in-depth analysis of the current limitations of the remittance of money in the city of Kinshasa, in the Democratic Republic of Congo, as an example, this thesis proposes a generic model for TRS. The proposed 3-layered stack model includes the logical (business requirements) and technological requirements needed to safely conduct a trusted remittance of service. This proposed model, independent of any technology, allows for better design and implementation of not only trusted remittance of service transactions, but also of other business transactions that behave similarly.
The validation steps of the proposed 3-layered stack model showed that the emerging distributed ledger technology (DLT) and blockchain technologies reduce the development time needed to develop a prototype. By design, DLT provides the foundational layer of the 3-layered stack model, which is the layer that verifies and further guarantees the security and authentication of the remittance actors and their respective transaction.
This thesis presents all the steps leading to the experimentation of a working prototype based on the proposed 3-layered stack model. The research results concluded that indeed, the 3-layered stack model can be implemented using Ethereum blockchain technology to show the potential of the TRS model proposed. However, it also showed that when using this technology as the foundational layer for implementing the 3-layered stack, additional elements inherent to this technology, such as the notion of gas or a penalty for running code in the Ethereum Virtual Machine, have to be considered in order to provide end users with a financially seamless experience similar to those they can expect from the current remittance methods of money providers.
Osama Alkadi, Nour Moustafa, Benjamin Turnbull, Kim‐Kwang Raymond Choo
There has been significant research in incorporating both blockchain and intrusion detection to improve data privacy and detect existing and emerging cyberattacks, respectively. In these approaches, learning-based ensemble models can facilitate the identification of complex malicious events and concurrently ensure data privacy. Such models can also be used to provide additional security and privacy assurances during the live migration of virtual machines (VMs) in the cloud and to protect Internet-of-Things (IoT) networks. This would allow the secure transfer of VMs between data centers or cloud providers in real time. This article proposes a deep blockchain framework (DBF) designed to offer security-based distributed intrusion detection and privacy-based blockchain with smart contracts in IoT networks. The intrusion detection method is employed by a bidirectional long short-term memory (BiLSTM) deep learning algorithm to deal with sequential network data and is assessed using the data sets of UNSW-NB15 and BoT-IoT. The privacy-based blockchain and smart contract methods are developed using the Ethereum library to provide privacy to the distributed intrusion detection engines. The DBF framework is compared with peer privacy-preserving intrusion detection techniques, and the experimental outcomes reveal that DBF outperforms the other competing models. The framework has the potential to be used as a decision support system that can assist users and cloud providers in securely migrating their data in a timely and reliable manner.
Atomic Crosschain Transaction technology allows composable programming across permissioned Ethereum blockchains. It allows for inter-contract and inter-blockchain function calls that are both synchronous and atomic: if one part fails, the whole call graph of function calls is rolled back. This paper analyses the processing overhead of using this technique compared to using multiple standard non-atomic single blockchain transactions. The additional processing is analysed for three scenarios involving multiple blockchains: the Hotel - Train problem, Supply Chain with Provenance, and an Oracle. The technology is shown to reduce the performance of Hyperledger Besu from 375 tps to 39.5 tps if all transactions are instigated on one node, or approaching 65.2 tps if the transactions are instigated on a variety of nodes, for the Hotel-Train scenario.