Public key infrastructures (PKIs) provide the foundations for securing Internet communications. Currently, PKIs are operated by centralized authorities, which have been involved in numerous security incidents. Blockchain or smart contract PKIs employ their distributed, fault-tolerant log of transactions to store either all identity records, or, constant-sized data to verify identity records stored off-chain. However, as most of these systems have never been implemented, there is little information regarding their practical implications. In this article, we implement, evaluate, and provide a complete security proof for the smart contract-based PKI of (Patsonakis et al.) on Ethereum. This construction incurs constant-sized storage at the expense of computational complexity. To explore this tradeoff, we propose and implement a second construction which, eliminates the need for trusted setup, preserves its security properties and show that it is the only version with constant-sized state that can be deployed on Ethereum's live chain. We compare these constructions with the simple approach of storing all identity records on the smart contract's state, to illustrate several shortcomings of Ethereum and its cost model. We propose several modifications for fine tuning the model, which should be considered for any smart contract platform like Ethereum so that it may support arbitrary distributed applications.
Muhammed Siraj, Mohd Izuan Hafez Ninggal, Nur Izura Udzir, Muhammad Daniel Hafiz Abdullah · 5 authors
Sensitive records stored in the cloud such as healthcare records, private conversation and credit card information are targets of hackers and privacy abuse. Current information and record management systems have difficulties achieving privacy protection of such sensitive records in a secure, transparent, decentralized and trustless environment. The Blockchain technology is a nascent and a promising technology that facilitates data sharing and access in a secure, decentralized and trustless environment. The technology enables the use of smart contracts that can be leveraged to complement existing traditional systems to achieve security objectives that were never possible before. In this paper, we propose a framework based on Blockchain technology to enable privacy-preservation in a secured, decentralized, transparent and trustless environment. We name our framework SmartCoAuth. It is based on Ethereum Smart Contract functions as the secure, decentralized, transparent authentication and authorization mechanism in the framework. It also enables tamper-proof auditing of access to the protected records. We analysed how SmartCoAuth could be integrated into a cloud application to provide reliable privacy-preservation among stakeholders of healthcare records stored in the cloud. The proposed framework provides a satisfactory level of data utility and privacy preservation.
Badr Eddine Sabir, Mohamed Youssfi, Omar Bouattane, Hakim Allali
The Internet of Things (IoT) is becoming an indispensable part of the actual Internet and continues to extend deeper into the daily lives of people, offering distributed and critical services. Mobile agents are widely used in the context of IoT and due to the possibility of transmitting their execution status from one device to another in an IoT network, they offer many advantages such as reducing network load, encapsulating protocols, exceeding network latency, etc. Also, Blockchain Technology is growing rapidly allowing for the addition of an approved security layer in many areas. Security issues related to mobile agent migration can be resolved with the use of Blockchain. This paper aims to demonstrate how Blockchain Technology can be used to secure mobile agents in the context of the IoT using Ethereum and a Smart Contract. The transactions within the Blockchain are used to detect the malevolent mobile agents that could infiltrate the IoT systems. The proposed model aims to provide a secure migration of mobile agents to ensure security and protect the IoT applications against malevolent agents. The case of a smart home with multiple applications is applied to verify the proposed solution. The model presented in this paper could be extended to a wider selection of IoT systems outside of the smart home.
Francesco Buccafurri, Vincenzo De Angelis, Roberto Nardone
The Internet of Things is constantly capturing interest from modern applications, changing our everyday life and empowering industrial applications. Interaction and the collaboration among smart devices offer new challenges to security since they conflict with economic and energy consumption requirement constraints. On the other hand, the lack of security measures could negatively impact the concrete adoption of this paradigm. This paper focuses on the Message Queuing Telemetry Transport (MQTT) protocol, widely adopted in the Internet of Things. This protocol does not implement natively secure authentication mechanisms, which are demanded to developers. Hence, this paper proposes a novel OTP (one-time password)-authentication schema for MQTT, which uses the Ethereum blockchain to implement a second-factor out-of-band channel. The proposal enables the authentication of both local and remote devices preserving user privacy and guaranteeing trust and accountability via Ethereum smart contracts.
Roy Cerqueti, Massimiliano Giacalone, Raffaele Mattera
Recently, cryptocurrencies have attracted a growing interest from investors, practitioners and researchers. Nevertheless, few studies have focused on the predictability of them. In this paper we propose a new and comprehensive study about cryptocurrency market, evaluating the forecasting performance for three of the most important cryptocurrencies (Bitcoin, Ethereum and Litecoin) in terms of market capitalization. At this aim, we consider non-Gaussian GARCH volatility models, which form a class of stochastic recursive systems commonly adopted for financial predictions. Results show that the best specification and forecasting accuracy are achieved under the Skewed Generalized Error Distribution when Bitcoin/USD and Litecoin/USD exchange rates are considered, while the best performances are obtained for skewed Distribution in the case of Ethereum/USD exchange rate. The obtain findings state the effectiveness -- in terms of prediction performance -- of relaxing the normality assumption and considering skewed distributions.
Vinicius Branco, Bruno Lippert, Roben Castagna Lunardi, Henry C. Nunes · 9 authors
Após a introdução do Bitcoin, a tecnologia de \textit{blockchain} evoluiu como uma solução para fornecer integridade, não repúdio e disponibilidade de dados para diferentes sistemas. Cenários sensíveis a dados, como Health Care, também podem se beneficiar dessas propriedades da blockchain. Assim, diferentes propostas, tanto da Academia quanto da Indústria, foram implantadas para permitir a adoção de blockchain em aplicativos de assistência médica. No entanto, existem poucas discussões sobre métodos de incentivo para ajudar a motivar novos usuários a adotar sistemas de saúde. Além disso, pouco se discute sobre o desempenho para executar códigos em blockchains públicos e privados. Para resolver esses problemas, este trabalho apresenta uma avaliação do TokenHealth, um aplicativo para monitoramento colaborativo de práticas de saúde com gamificação e incentivos baseados em tokens, em diferentes redes da Ethereum. A solução proposta é implementada por meio de smart contracts usando a linguagem Solidity e executada em máquinas virtuais da Ethereum (EVM). Avaliamos o desempenho da rede de teste Ropsten e de uma instância privada da Ethereum. Os resultados preliminares mostram que a execução de smart contracts leva menos de um minuto para um ciclo completo de diferentes smart contracts. Além disso, apresentamos uma discussão sobre os custos do uso de uma instância privada e da rede principal pública do Ethereum.
One of the major challenges in the healthcare industry is the information sharing and patient's privacy. The implementation of the Health Insurance Portability and Accountability Act (HIPPA) [30] in 1996 made difficult for software vendors to manage the documents and records of the patients. Blockchain based technology, which uses cryptography to facilitate exchange and transaction of values and goods over a network, has been proposed to resolve this issue. The decentralized ledge of blockchain would provide immutability, confidentiality, accountability and transparency for information sharing between healthcare stakeholders. In this paper, we implemented the Ethereum Smart Contract, an extended part of the blockchain in healthcare industry with objectives of keeping all the records and transactions safe and secure, and at the same time, reducing the number of user data breaches. We carried out a number of experiments in order to demonstrate the usability and efficiency of our proposed approach.
Digital economy has become the new driving force of China's economic development. Therefore, this paper creatively designs a three-tier digital intelligent ecological model based on the framework of the block chain cloud. Its core part is ethereum protocol, mainly including smart contract, whisper, swarm, etc. Through it to abstract, condense and adapt to the economic, social, cultural and life scenes related to the industrial Park, it contributes an innovative integrated industrial park platform which is decentralized, autonomous, intelligent and ecological. The construction and implementation path, measures and guarantee of the platform system are also considered.
Spanish abstract: El presente trabajo ofrece soluciones a los problemas juridicos que plantean los smart contracts, por tratarse de clausulas contractuales autoimplementadas en un codigo informatico que autoejecuta su contenido. Estos versan sobre su discutida naturaleza juridica, la adhesion del consumidor 2.0 mediante Blockchain, su personalizacion con Ethereum, los errores de programacion y la responsabilidad civil, la proteccion y encriptacion de datos de caracter personal, y la formacion y ejecucion del contrato. Las dificultades que plantean los smart contracts requieren de una regulacion europea, inspirada en las legislaciones existentes en algunos territorios de los Estados Unidos y Francia, asi como en los estudios formulados en el ambito de UNIDROIT y la CNUDMI.
English abstract: This paper suggests legal remedies for smart contracts, based on a code that self-implement contractual clauses to self-execute its content. These problems refer to its legal nature, the adhesion of adprosumer through Block-chain, the personalization of smart contracts with Ethereum, programming errors and civil liability, protection and encryption of personal data, and contract formation and execution. All these difficulties need an EU Law inspired in US Law, French Law and in studies in the field of UNIDROIT and UNCITRAL.
Gökay Saldamlı, Kavitha Karunakaran, Vidya K. Vijaykumar, Weiyang Pan · 6 authors
Automakers in collaboration with technology industries are swiftly innovating and transforming the automobile industry. The current trend of connected cars relies on retrieving various kinds of vehicular data since there is a huge demand from associated entities included insurance companies, vehicle buyers/sellers and government authorities. Currently, the data collection is done either manual or unsupervised that poses trust, legitimacy and accuracy issues such as duplicated or falsified vehicular data records, tampered safety checks and meddled driving history, etc. Hence, a strong tool that can protect the vehicular data; log the changes for audit purposes and eventually build the trust in the system is necessary. We propose the use of blockchain technology for these needs. The proposed solution involves connecting an IoT module to a car data port to collect rich telemetric data; analyze the driving behaviors on various fronts and storing the outcomes to a blockchain. For various good reasons we use the Ethereum blockchain in this study. However, other blockchain deployments can also be utilized. If adopted by the stakeholders, the proposed solution can provide a trusted, transparent and easily accessible platform to auto buyers/sellers, insurance agencies, vehicle dealers, law enforcements and vehicle history providers.
Blockchain Technology Applications and Security
Currency Recognition and Detection
Advanced Steganography and Watermarking Techniques
This paper presents a Blockchain-based voting mechanism that has the potential to disrupt current voting systems and fuel the development of decentralized governance. More specifically, the paper presents a study on the design and deployment of a Solidity smart contract that can interact with any Ethereum-based token (ERC-20) in order to help decentralized organizations to run public voting campaigns while at the same time engaging tokens holders in decision making. The use case scenarios outlined in the paper demonstrate with success the effectiveness of the proposed approach.
In recent years, the rapid development of Blockchain Technology has found its applications in sectors like Finance, Healthcare, Supply Chain Management, Internet of Things (IoT), and many more. In this paper, we propose use of Blockchain to the system of accreditation of Continuing Medical Evaluation (CME) credits and a physician's Medical Licence Renewal. To be able to practice medicine, a physician needs to possess a legitimate licence approved by a verified Medical Council and for this, certain credit hours need to be earned. CME is a global education system that aims to continually upgrade the knowledge of physicians with the advancements made in the medical domain. By including the highly robust features of blockchain like security, decentralization, and immutability in the existing system of CME Credits, many of the extant problems can be uprooted and a system can be established. This work aims at providing an Ethereum-based solution to enhance the existing CME Credits system by providing an automated credits accreditation and medical licence renewal system.
I P S P Wardhana, Gede Rasben Dantes, Kadek Yota Ernanda Aryanto
Abstract The falsification and embezzlement of personal data are still found in several cases in the past year. The reason is personal data in physical form are easily manipulated and difficult to be distinguished from the original. The most detrimental impact is if a person’s personal data is used for credit application fraud in the banking industry. Implementation of blockchain technologies, one of which is Ethereum, allows the use of contracts as a rule that must be fulfilled by the parties involved. All stored transactions are perpetual (cannot be deleted or changed), easy to be audited, transparent, and distributed at each participating node. This study aimed to develop a smart contract for personal data transactions with a case study of credit submission at the Bank. The authors developed a trial application using the prototype method in the process of assessment. Assessment was done by black box testing method in the scope of the lab with 10 credit submission data to be transacted. It is resulting in all credit submission data can be transacted and stored in the smart contract. The interview resulted in an opinion that blockchain technology can be used to store personal data and submit credit submissions at the Bank. The results of the analysis on assessments and interviews conclude that blockchain technology can be used as a medium to store personal data and secure credit applications. For future research, testing transactions can be done on Testnet networks with changing several blocks of data.
Block chain technology provides a decentralized and secure platform for executing transactions. Smart contracts in Ethereum have been proposed as the mechanism to automate legal contracts securely without the involvement of third parties. Yet, there are still several issues to be resolved especially regarding the updating of smart contracts in blockchain as well as the use of blockchain as part of a legal smart contracts system. In this work we propose a methodology and an architecture for building and deploying legal contracts in the blockchain. As the blockchain is immutable, we cannot update the code of the smart legal contracts, but in real life applications updating of contracts is a requirement that cannot be ignored. In this paper we address the problem of contract update by introducing a new versioning system that keeps track of the changes and links the different versions using a linked list. Moreover, we propose a system architecture where the user interface, the application logic and the blockchain are smoothly integrated in a manner that each part of the system contributes for producing a flexible and transparent execution. We show the applicability of our approach by implementing a system for the case of a rental agreement.
Ahmed Taha, Ahmed Zakaria, Dong‐Seong Kim, Neeraj Suri
Cloud computing offers a model where resources (storage, applications, etc.) are abstracted and provided “as-a- service” in a remotely accessible manner. Although there are numerous claimed benefits of the Cloud to ensure confidentiality, integrity, and availability of the stored data, the number of security breaches is still on the rise. The lack of security assurance and transparency prevented customers/enterprises from trusting the Cloud Service Providers (CSPs). Unless the customer’s security requirements are identified and documented by the CSPs, customers can not be assured that the CSPs will satisfy their requirements. Furthermore, the customer’s compensation upon a violation is a manual time intensive process. In this paper we address the aforementioned challenges by proposing a decentralized customer-based monitoring approach running over Ethereum blockchain. The proposed approach allows the customer(s) to validate the compliance of CSP(s) to the contracted services in the Service Level Agreements (SLAs) and “autonomsly” compensate customers in case of security breaches. At the same time, the proposed approach prevents customers from misreporting for financial gain. The approach builds upon the Ethereum blockchain infrastructure in order to securely store monitoring logs and incorporate SLAs as smart contracts. The compliance validation framework is implemented and its functionality is evaluated on Amazon EC2 and Ethereum Blockchain.
Yuechen Tao, Bo Li, Jingjie Jiang, Hok Chu Ng · 6 authors
Current blockchain systems suffer from a number of inherent drawbacks in its scalability, latency, and processing throughput. By enabling parallel confirmations of transactions, sharding has been proposed to mitigate these drawbacks, which usually requires frequent communication among miners through a separate consensus protocol.In this paper, we propose, analyze, and implement a new distributed and dynamic sharding system to substantially improve the throughput of blockchain systems based on smart contracts, while requiring minimum cross-shard communication. Our key observation is that transactions sent by users who only participate in a single smart contract can be validated and confirmed independently without causing double spending. Therefore, the natural formation of a shard is to surround one smart contract to start with. The complication lies in the different sizes of shards being formed, in which a small shard with few transactions tends to generate a large number of empty blocks resulting in a waste of mining power, while a large shard adversely affects parallel confirmations. To overcome this problem, we propose an inter-shard merging algorithm with incentives to encourage small shards to merge with one another and form a larger shard, an intra-shard transaction selection mechanism to encourage miners to select different subsets of transactions for validation, as well as a parameter unification method to further improve these two algorithms to reduce the communication cost and improve system reliability.We analyze our proposed algorithms using the game theoretic approach, and prove that they converge to a Nash Equilibrium. We also present a security analysis on our sharding design, and prove that it resists adversaries who occupy at most 33% of the computation power. We have implemented our designs on go-Ethereum 1.8.0 and evaluated their performance using both real-world blockchain transactions and large-scale simulations. Our results show that throughput has been improved by 7.2×, and the number of empty blocks has been reduced by 90%.
The paper bill of lading remains pervasive despite numerous problems associated with its form. Blockchain heralds change as it allows unique tokens to be possessed and traded peer-to-peer instantaneously over the internet without the need for a trusted central administrator. Blockchain furthermore promises to ease processes thanks to its applicability in smart contracting procedures. The Model Law on Electronic Transferable Records (MLETR), passed by UNCITRAL in 2017, provides the relevant legal framework for legal protection of the blockchain bill of lading. This paper proposes Ethereum as a viable smart contract-enabled blockchain platform for a bill of lading system and examines said system’s compatibility with the MLETR. The analysis also shows that blockchain technology may have significant consequences for the ‘control’ approach for establishing possession of an electronic transferable record.
This paper compares a number of stochastic volatility (SV) models for modeling and predicting the volatility of the four most capitalized cryptocurrencies (Bitcoin, Ethereum, Ripple, and Litecoin). The standard SV model, models with heavy-tails and moving average innovations, models with jumps, leverage effects and volatility in mean were considered. The Bayes factor for model fit was largely in favor of the heavy-tailed SV model. The forecasting performance of this model was also found superior than the other competing models. Overall, the findings of this study suggest using the heavy-tailed stochastic volatility model for modeling and forecasting the volatility of cryptocurrencies.
Institut Teknologi Bandung Bandung, Indonesia, Intan Muchtadi-Alamsyah, Muhammad Thufaili Imdad, Institut Teknologi Bandung Bandung, Indonesia · 6 authors
In the next few years, Blockchain will play a central role in IoT as a technology. It enables the traceability of processes between multiple parties independent of a central instance. Blockchain allows to make the processes more transparent, cheaper, and safer. This research paper was conducted as systematic literature search. Our aim is to understand current state of implementation in context of Blockchain Technology for digital protection of communication in industrial cyber-physical systems. We have extracted 28 primary papers from scientific databases and classified into different categories using visualizations. The results show that the focus in around 14\% papers is on solution proposal and implementation of use cases "Secure transfer of order data" using Ethereum Blockchain, 7\% papers applying Hyperledger Fabric and Multichain. The majority of research (around 43\%) is focusing on solution development for supply chain and process traceability.
В роботі розглянуто проект з відкритим кодом Ethereum Blockchain, що є одним з найпопулярніших представників блокчейн-технологій. В своїй канонічній реалізації Ethereum працює як відкрита публічна децентралізована система, що базується на алгоритмі консенсусу PoW та дозволяє користувачам керувати власною криптовалютою, розробляти та розгортати розумні контракти на базі EVM (Ethereum Virtual Machine), взаємодіяти з розумними контрактами інших користувачів. Оскільки такий алгоритм не задовольняє вимогам більшості корпоративних проектів на базі Ethereum Blockchain, був проведений порівняльний аналіз найпопулярніших алгоритмів консенсусу і на основі результатів цього аналізу проведена оптимізація роботи приватного блокчейн за допомогою вибору алгоритму консенсусу.
M.E in Computer Engineering from SVBIT, GTU, Gandhinagar, India., Pratik Patel, Pinkal Chauhan, M.E in Computer Engineering from LDRP, Gandhinagar, India.
In our everyday lives, IoT plays a vital role. It is crucial to sense, capture and share data from connected devices via internet. Existing system proposed centralized client/server approach where central authority keeps a record of all the activities. Failure of such centralized authority makes the whole system fail. A decentralized / distributed approach is therefore needed if a single failure point is avoided. In this paper contains information to integrating Blockchain in IoT ecosystem in order to achieve access control. We proposed smart contract based architecture which consist multiple permission contract, one decision contract and one entry contract, to achieve distributed and secure IoT device access control. To conclude system framework, we provide a case study in an IoT system with two laptops and one Raspberry Pi single-board computers, where the PCs, DC and EC are implemented based on the Ethereum smart contract platform to achieve the access control.
Νικόλαος Αλεξόπουλος, Emmanouil Vasilomanolakis, Stéphane Le Roux, Steven Rowe · 5 authors
Sophisticated mass attacks, especially when exploiting zero-day vulnerabilities, have the potential to cause destructive damage to organizations and critical infrastructure. To timely detect and contain such attacks, collaboration among the defenders is critical. By correlating real-time detection information (threat indicators) from multiple sources, defenders can detect attacks and take the appropriate measures in time. However, although the technical tools to facilitate collaboration exist, real-world adoption of such collaborative security mechanisms is still underwhelming. This is largely due to a lack of trust and participation incentives for companies and organizations. This paper proposes TRIDEnT, a novel collaborative platform that aims to enable parties to exchange network threat indicators, thus increasing their overall detection capabilities. TRIDEnT allows parties that may be in a competitive relationship, to selectively advertise, sell and acquire threat indicators in the form of (near) real-time peer-to-peer streams. To demonstrate the feasibility of our approach, we instantiate our design in a decentralized manner using Ethereum smart contracts and provide a fully functional prototype.
Haan Johng, Doohwan Kim, Grace Park, Jang‐Eui Hong · 6 authors
Blockchain technologies are intended to help enhance the trustworthiness of information, by improving transparency, traceability, and immutability of business logic and information, hence with the potential to be applicable to business process reengineering (BPR). However, an ad hoc approach to adopting blockchain technologies during BPR may lead to not better, but worse, than the current business processes, and with disappointments. In this paper, we present Fides - a framework for systematically utilizing blockchain towards enhancing business processes with trustworthiness. Fides takes a goal-oriented approach, in which trust-related concerns are explicitly represented as (soft)goals to be achieved, problems for achieving the goals are diagnosed, and then alternatives are explored in terms of business processes for eliminating or alleviating the problems, while at the same time achieving the goals. Finally, a selection is made among the alternatives that best utilize blockchain. To illustrate, and also see both strengths and weaknesses of Fides, a retail chain for a food supply chain is used throughout the paper, and is implemented using Ethereum and Hyperledger Fabric. Feedback from companies and students indicates that Fides leverages the level of confidence in the quality of the reengineered business processes, in utilizing blockchain.