Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

13,597 papersLast indexed Aug 16, 2026
Search papers

Paper index

13,597 results · page 491 of 567

Clear filters
Oct 17, 2019·IEEE Transactions on Industrial Informatics
274 cites
Differential Privacy-Based Blockchain for Industrial Internet-of-Things

Keke Gai, Yulu Wu, Liehuang Zhu, Zijian Zhang · 5 authors

Contemporarily, two emerging techniques, blockchain and edge computing, are driving a dramatical rapid growth in the field of Internet-of-Things (IoT). Benefits of applying edge computing is an adoptable complementarity for cloud computing; blockchain is an alternative for constructing transparent secure environment for data storage/governance. Instead of using these two techniques independently, in this article, we propose a novel approach that integrates IoT with edge computing and blockchain, which is called blockchain-based Internet of Edge model. The proposed model, designed for a scalable and controllable IoT system, sufficiently exploits advantages of edge computing and blockchain to establish a privacy-preserving mechanism while considering other constraints, such as energy cost. We implement experiment evaluations running on Ethereum. According to our data collections, the proposed model improves privacy protections without lowering down the performance in an energy-efficient manner.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 16, 2019·IISE Transactions on Healthcare Systems Engineering
8 cites
Secure decentralized decisions to enhance coordination in consolidated hospital systems

Adrien Badré, Shima Mohebbi, Leili Soltanisehat

Shared decision making has become a crucial solution to build a consolidated healthcare system. While there is some research in the healthcare literature discussing the advantages and disadvantages of shared decision making, its efficiency has not been addressed quantitatively. In this paper, we propose a Decentralized Patients Assignment System (DPAS) as a universal decentralized decision making architecture. It utilizes the blockchain technology, machine learning, and integer programing to enhance coordination among healthcare providers and patients in consolidated hospital systems. To test the efficiency of the proposed DPAS, a prototype system is developed using an Agent-based model and Ethereum and is compared to the current practice of central referral systems in consolidated hospital systems. The agent-based model consists of four agents including patients, physicians, hospitals, and miners interacting within a decentralized system. The proposed system highlights the importance of interoperability and consensus among healthcare agents in the decision making process. The results demonstrate the DPAS efficiency in decreasing computational time and rejection rates for patients transfer.

Blockchain Technology Applications and Security
Healthcare Operations and Scheduling Optimization
Transportation and Mobility Innovations
Original source
Oct 16, 2019·Sensors
14 cites
PRICHAIN: A Partially Decentralized Implementation of UbiPri Middleware Using Blockchain

Iago Sestrem Ochôa, Luís Augusto Silva, Gabriel de Mello, Bruno Alves da Silva · 8 authors

With the popularization of the Internet-of-Things, various applications have emerged to make life easier. These applications generate a large amount of user data. Analyzing the data obtained from these applications, one can infer personal information about each user. Considering this, it is clear that ensuring privacy in this type of application is essential. To guarantee privacy various solutions exist, one of them is UbiPri middleware. This paper presents a decentralized implementation of UbiPri middleware using the Ethereum blockchain. Smart contracts were used in conjunction with a communication gateway and a distributed storage service to ensure users privacy. The results obtained show that the implementation of this work ensures privacy at different levels, data storage security, and performance regarding scalability in the Internet of Things environments.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 16, 2019·Energies
28 cites
RETRACTED: Blockchain-Enabled Charging Right Trading Among EV Charging Stations

Ruijiu Jin, Xiangfeng Zhang, Zhijie Wang, Wengang Sun · 6 authors

Increasing penetration of electric vehicles (EVs) gives rise to the challenges in the secure operation of power systems. The EV charging loads should be distributed among charging stations in a fair and incentive-compatible manner while ensuring that power transmission and transformation facilities are not overloaded. This paper first proposes a charging right (or charging power ration) trading mechanism and model based on blockchain. Considering all kinds of random factors of charging station loads, we use Monte Carlo modeling to determine the charging demand of charging stations in the future. Based on the charging demand of charging stations, a charging station needs to submit the charging demand for a future period. The blockchain first distributes initial charging right in a just manner and ensures the security of facilities. Given that the charging urgency and elasticity differences vary by charging stations, all charging stations then proceed with double auction and peer-to-peer (P2P) transaction of charging right. Bids and offers are cleared via double auctions if bids are higher than offers. The remaining bids and offers are cleared via the P2P market. Then, this paper designs the charging right allocation and trading platform and smart contract based on the Ethernet blockchain to ensure the safety of the distribution network (DN) and the transparency and efficiency of charging right trading. Simulation results based on the Ethereum private blockchain show the fairness and efficiency of the proposed mechanism and the effectiveness of the method and the mechanism.

Open access
Blockchain Technology Applications and Security
Electric Vehicles and Infrastructure
Transportation and Mobility Innovations
Original source
Oct 14, 2019
7 cites
BARRETT BlockchAin Regulated REmote aTTestation

Michail Bampatsikos, Christoforos Ntantogian, Christos Xenakis, Stelios C. A. Thomopoulos

Today, an increasing number of Internet of Things (IoT) healthcare devices, crucial to a person's wellbeing and life, connects to the internet and consequently is exposed to a variety of threats. These devices possess low computational resources, and as a result they cannot use security tools such as antivirus or firewalls. Consequently, they become easy targets for cyber-attacks and malware infection, thus putting a person's life at risk. One way to protect these devices from malware infection is Remote Attestation (RA), a process by which a device with low computational power (prover) verifies its internal state to a party with higher computational resources (verifier) upon the latter's request. However, in case the verifier is malicious, it may constantly send numerous requests for RA to a prover to prevent it from performing the functions it was designed for. Thus, keeping it busy and rendering it unusable to its legit users as well as services. In short, the verifier performs a Computational Denial of Service (CDoS) attack against the prover. This paper proposes the BARRETT architecture which uses a Public Ethereum Network (PEN) in conjunction with an RA protocol to protect the prover from CDoS attacks. In particular, the PEN in BARRETT deters CDoS by forcing the verifier to pay a fee in Ether cryptocurrency every time they wish to send an Attestation Request (AR) to a prover. The verifier pays the fee since in BARRETT it can send the AR only via Ethereum transactions. Consequently, any attempt to perform a CDoS becomes prohibitively expensive.

Open access
Security and Verification in Computing
Advanced Malware Detection Techniques
IoT and Edge/Fog Computing
Original source
Oct 12, 2019·arXiv (Cornell University)
49 cites
A blockchain-orchestrated Federated Learning architecture for healthcare consortia

Jonathan Passerat‐Palmbach, Tyler Farnan, Robert Miller, Marielle S. Gross · 6 authors

We propose a novel architecture for federated learning within healthcare consortia. At the heart of the solution is a unique integration of privacy preserving technologies, built upon native enterprise blockchain components available in the Ethereum ecosystem. We show how the specific characteristics and challenges of healthcare consortia informed our design choices, notably the conception of a new Secure Aggregation protocol assembled with a protected hardware component and an encryption toolkit native to Ethereum. Our architecture also brings in a privacy preserving audit trail that logs events in the network without revealing identities.

Open access
2 source records
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Oct 10, 2019·Cambridge University Press eBooks
3 cites
Smart Contracts and the Courts

Marc Clément

Chapter 15 derives some general features of smart contracts by examining the technological approach for these contracts proposed by Ethereum and Solidity language. It relies on the concept of ‘interfaces’ to designate the relationships between the computer code of a smart contract and other external elements. According to this chapter, these interfaces are the exact locations of the legal connections between a specific piece of software and the real world. In particular, it argues that the smart contract environment is not a ‘lawyer-free environment’ due to the fact that smart contracts would necessarily interfere with real world persons or institutions that would by the nature of our societies lead to legal issues.

European and International Contract Law
Law, Economics, and Judicial Systems
Law, AI, and Intellectual Property
Original source
Oct 10, 2019·International Journal of Engineering and Advanced Technology
3 cites
Directed Acyclic Graph-based Distributed Ledgers – An Evolutionary Perspective

Kiran Kumar Kondru, R. Saranya

Blockchain platforms like Bitcoin and Ethereum have introduced a distributed and decentralized cryptocurrency system with no third-party intermediation required. These peer to peer network systems allows Internet users to directly transact with each other. However due to the heavy emphasis on decentralization, scalability has taken a back seat. It has also become a key issue in the wider adoption of these technologies. The change to the underlying data organizing structure to Direct Acyclic Graphs (DAG) of the distributed ledger, has significantly increased transaction scalability. In this paper, we analyse some of the Distributed Ledger Technologies that use DAGs and have shown marked improved in transaction performance without weakening security.

Open access
Blockchain Technology Applications and Security
Peer-to-Peer Network Technologies
Distributed systems and fault tolerance
Original source
Oct 10, 2019·Proceedings of the ACM on Programming Languages
100 cites
Safer smart contract programming with Scilla

Ilya Sergey, Vaivaswatha Nagaraj, Jacob Johannsen, Amrit Kumar · 6 authors

The rise of programmable open distributed consensus platforms based on the blockchain technology has aroused a lot of interest in replicated stateful computations, aka smart contracts. As blockchains are used predominantly in financial applications, smart contracts frequently manage millions of dollars worth of virtual coins. Since smart contracts cannot be updated once deployed, the ability to reason about their correctness becomes a critical task. Yet, the de facto implementation standard, pioneered by the Ethereum platform, dictates smart contracts to be deployed in a low-level language, which renders independent audit and formal verification of deployed code infeasible in practice. We report an ongoing experiment held with an industrial blockchain vendor on designing, evaluating, and deploying Scilla, a new programming language for safe smart contracts. Scilla is positioned as an intermediate-level language, suitable to serve as a compilation target and also as an independent programming framework. Taking System F as a foundational calculus, Scilla offers strong safety guarantees by means of type soundness. It provides a clean separation between pure computational, state-manipulating, and communication aspects of smart contracts, avoiding many known pitfalls due to execution in a byzantine environment. We describe the motivation, design principles, and semantics of Scilla, and we report on Scilla use cases provided by the developer community. Finally, we present a framework for lightweight verification of Scilla programs, and showcase it with two domain-specific analyses on a suite of real-world use cases.

Open access
Security and Verification in Computing
Distributed systems and fault tolerance
Logic, programming, and type systems
Original source
Oct 9, 2019·International Journal of Ethics and Systems
36 cites
Crypto-currencies narrated on tweets: a sentiment analysis approach

Saeed Rouhani, Ehsan Abedin

Purpose Crypto-currencies, decentralized electronic currencies systems, denote a radical change in financial exchange and economy environment. Consequently, it would be attractive for designers and policy-makers in this area to make out what social media users think about them on Twitter. The purpose of this study is to investigate the social opinions about different kinds of crypto-currencies and tune the best-customized classification technique to categorize the tweets based on sentiments. Design/methodology/approach This paper utilized a lexicon-based approach for analyzing the reviews on a wide range of crypto-currencies over Twitter data to measure positive, negative or neutral sentiments; in addition, the end result of sentiments played a training role to train a supervised technique, which can predict the sentiment loading of tweets about the main crypto-currencies. Findings The findings further prove that more than 50 per cent of people have positive beliefs about crypto-currencies. Furthermore, this paper confirms that marketers can predict the sentiment of tweets about these crypto-currencies with high accuracy if they use appropriate classification techniques like support vector machine (SVM). Practical implications Considering the growing interest in crypto-currencies (Bitcoin, Cardano, Ethereum, Litcoin and Ripple), the findings of this paper have a remarkable value for enterprises in the financial area to obtain the promised benefits of social media analysis at work. In addition, this paper helps crypto-currencies vendors analyze public opinion in social media platforms. In this sense, the current paper strengthens our understanding of what happens in social media for crypto-currencies. Originality/value For managers and decision-makers, this paper suggests that the news and campaign for their crypto in Twitter would affect people’s perspectives in a good manner. Because of this fact, the firms, investing in these crypto-currencies, could apply the social media as a magnifier for their promotional activities. The findings steer the market managers to see social media as a predictor tool, which can analyze the market through understanding the opinions of users of Twitter.

Blockchain Technology Applications and Security
Sentiment Analysis and Opinion Mining
Stock Market Forecasting Methods
Original source
Oct 9, 2019·Energies
35 cites
Consortium Blockchain-Based Microgrid Market Transaction Research

Wenting Zhao, Jun Lv, Xilong Yao, Juanjuan Zhao · 8 authors

The microgrid trading market can effectively solve the problem of in-situ consumption of distributed energy and reduce the impact of distributed generation (DG) on the grid. However, the traditional microgrid trading model has some shortcomings, such as high operation cost and poor security. Therefore, in this paper, a microgrid market trading model was developed using consortium blockchain technology and Nash game equilibrium theory. Firstly, blockchain container is used to authenticate the users who want to participate in the transaction. Then, the pricing system collects and integrates transaction requests submitted by users, then formulates transaction pricing strategy of microgrid using Nash equilibrium theory. Finally, the price, trading volume, and user information are submitted to the blockchain container for transaction matching to achieve the transaction. After the transaction is completed, its related information is recorded in the hyperledger and the dispatch system is called. The scene simulation was implemented on Fabric 1.1 platform and the results analyzed. Results show that the trading model proposed in this paper greatly reduces the cost of electricity purchase and improves the benefits of electricity sales. Besides, the model is far more capable of handling transactions than the models based on Bitcoin and Ethereum.

Open access
Blockchain Technology Applications and Security
Smart Grid Energy Management
Caching and Content Delivery
Original source
Oct 8, 2019·2020 IEEE 17th Annual Consumer Communications & Networking Conference (CCNC)
45 cites
A Distributed Ledger Based Infrastructure for Smart Transportation System and Social Good

Mirko Zichichi, Stefano Ferretti, Gabriele D'Angelo

This paper presents a system architecture to promote the development of smart transportation systems. Thanks to the use of distributed ledgers and related technologies, it is possible to create, store and share data generated by users through their sensors, while moving. In particular, IOTA and IPFS are used to store and certify data (and their related metadata) coming from sensors or by the users themselves. Ethereum is exploited as the smart contract platform that coordinates the data sharing and provisioning. The necessary privacy guarantees are provided by the usage of Zero Knowledge Proof. We show some results obtained from some use case scenarios that demonstrate how such technologies can be integrated to build novel smart services and to promote social good in user mobility.

Open access
3 source records
Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Transportation and Mobility Innovations
Original source
Oct 6, 2019·arXiv (Cornell University)
11 cites
GasFuzz: Generating High Gas Consumption Inputs to Avoid Out-of-Gas Vulnerability.

Fuchen Ma, Ying Fu, Meng Ren, Wanting Sun · 8 authors

The out-of-gas error occurs when smart contract programs are provided with inputs that cause excessive gas consumption, and would be easily exploited to make the DoS attack. Multiple approaches have been proposed to estimate the gas limit of a function in smart contracts to avoid such error. However, under estimation often happens when the contract is complicated. In this work, we propose V-Gas, which could automatically generate inputs that maximizes the gas cost and reduce the under estimation cases. V-Gas is designed based on feedback-directed mutational fuzz testing. First, V-Gas builds the gas weighted control flow graph (CFG) of functions in smart contracts. Then, V-Gas develops gas consumption guided selection and mutation strategies to generate the input that maximize the gas consumption. For evaluation, we implement V-Gas based on js-evm, a widely used ethereum virtual machine written in javascript, and conduct experiments on 736 real-world transactions recorded on Ethereum. 44.02\% of the transactions would have out-of-gas errors under the estimation results given by solc, means that the recorded real gas consumption for those recorded transactions is larger than the gas limit value estimated by solc. While V-Gas could reduce the under estimation ratio to 13.86\%. Furthermore, V-Gas has exposed 25 previously unknown out-of-gas vulnerabilities in those widely-used smart contracts, 5 of which have been assigned unique CVE identifiers in the US National Vulnerability Database.

Open access
Blockchain Technology Applications and Security
Security and Verification in Computing
Smart Grid Security and Resilience
Original source
Oct 6, 2019·ACM Transactions on Internet Technology
16 cites
V-Gas: Generating High Gas Consumption Inputs to Avoid Out-of-Gas Vulnerability

Fuchen Ma, Ying Fu, Meng Ren, Wanting Sun · 8 authors

Out-of-gas errors occur when smart contract programs are provided with inputs that cause excessive gas consumption and which will be easily exploited to perform Denial-of-Service attacks. Various approaches have been proposed to estimate the gas limit of a function in smart contracts to avoid such error. However, underestimation often occurs when the contract is complex In this work, we propose V-Gas, which automatically generates inputs that maximize the gas cost and reduce underestimation. V-Gas is designed based on static analysis and feedback-directed mutational fuzz testing. First, V-Gas builds the gas weighted control flow graph of functions in smart contracts. Then, V-Gas develops gas consumption guided selection and mutation strategies to generate the input that maximize the gas consumption. For evaluation, we implement V-Gas based on js-evm, a widely used Ethereum virtual machine written in Javascript, and conduct experiments on 736 real-world transactions recorded on Ethereum. A total of 44.02% of the transactions would have out-of-gas errors based on the estimation results given by solc, meaning that the recorded real gas consumption for those transactions is larger than the gas limit estimated by solc. In comparison, V-Gas could reduce the underestimation ratio to 13.86%. To evaluate the performance of feedback-directed engine in V-Gas, we implemented other directed fuzzing engines and compared their performance with that of V-Gas. The results showed that V-Gas generates the same or higher gas estimation value on 97.8% of the transactions with less time, usually within 5 minutes. Furthermore, V-Gas has exposed 25 previously unknown out-of-gas vulnerabilities in widely used smart contracts, 6 of which have been assigned unique CVE identifiers in the U.S. National Vulnerability Database.

Open access
3 source records
cs.CR
Security and Verification in Computing
Network Security and Intrusion Detection
Original source
Oct 3, 2019·Open Repository and Bibliography (University of Luxembourg)
9 cites
A Data Science Approach for Honeypot Detection in Ethereum

Ramiro Daniel Camino, Christof Ferreira Torres, Mathis Baden, Radu State

Ethereum smart contracts have recently drawn a considerable amount of attention from the media, the financial industry and academia. With the increase in popularity, malicious users found new opportunities to profit by deceiving newcomers. Consequently, attackers started luring other attackers into contracts that seem to have exploitable flaws, but that actually contain a complex hidden trap that in the end benefits the contract creator. In the blockchain community, these contracts are known as honeypots. A recent study presented a tool called HONEYBADGER that uses symbolic execution to detect honeypots by analyzing contract bytecode. In this paper, we present a data science detection approach based foremost on the contract transaction behavior. We create a partition of all the possible cases of fund movements between the contract creator, the contract, the transaction sender and other participants. To this end, we add transaction aggregated features, such as the number of transactions and the corresponding mean value and other contract features, for example compilation information and source code length. We find that all aforementioned categories of features contain useful information for the detection of honeypots. Moreover, our approach allows us to detect new, previously undetected honeypots of already known techniques. We furthermore employ our method to test the detection of unknown honeypot techniques by sequentially removing one technique from the training set. We show that our method is capable of discovering the removed honeypot techniques. Finally, we discovered two new techniques that were previously not known.

Open access
2 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Network Security and Intrusion Detection
Original source
Oct 2, 2019·arXiv (Cornell University)
3 cites
A Blueprint for Interoperable Blockchains

Tien Tuan Anh Dinh, Anwitaman Datta, Beng Chin Ooi

Research in blockchain systems has mainly focused on improving security and bridging the performance gaps between blockchains and databases. Despite many promising results, we observe a worrying trend that the blockchain landscape is fragmented in which many systems exist in silos. Apart from a handful of general-purpose blockchains, such as Ethereum or Hyperledger Fabric, there are hundreds of others designed for specific applications and typically do not talk to each other. In this paper, we describe our vision of interoperable blockchains. We argue that supporting interaction among different blockchains requires overcoming challenges that go beyond data standardization. The underlying problem is to allow smart contracts running in different blockchains to communicate. We discuss three open problems: access control, general cross-chain transactions, and cross-chain communication. We describe partial solutions to some of these problems in the literature. Finally, we propose a novel design to overcome these challenges.

Open access
2 source records
cs.DB
cs.DC
Blockchain Technology Applications and Security
Original source
Oct 1, 2019·IOP Conference Series Materials Science and Engineering
1 cites
Intelligent contract design based on block chain in logistics management

Ping Yang, Xiaolei Yang, Jianwei Li

Abstract Although the logistics management has been improving, the information management is still stagnant. The renewal mechanism of logistics information is the basic requirement of logistics system, but it is more important to solve the trust problem of logistics information. It is good for improving the logistics management to design a verifiable information management mechanism which can help relevant participants establish trust relationships. This paper analyzes the development status of block chain technology, then a decentralized and self-verifiable system management program model is designed. Finally, the application is implemented based on the intelligent contract design of Ethereum block chain.

Open access
Blockchain Technology Applications and Security
Supply Chain and Inventory Management
Digital Transformation in Industry
Original source
Oct 1, 2019
0 cites
Provably secure, smart contract-based naming services

Χρήστος Πατσωνάκης

Οι υπηρεσίες ονοματοδοσίας παρέχουν τα απαραίτητα θεμέλια για την ανάπτυξη ποικίλων και σημαντικών εφαρμογών, όπως το ηλεκτρονικό εμπόριο και η ηλεκτρονική τραπεζική. Επί του παρόντος, αυτές οι υπηρεσίες ονοματοδοσίας βρίσκονται υπό τον έλεγχο κεντρικοποιημένων οντοτήτων, τις οποίες πρέπει να εμπιστευόμαστε ότι λειτουργούν σωστά. Δυστυχώς, η κεντρικοποίηση (εμπιστοσύνης) επιφέρει πολλά μειονεκτήματα όσον αφορά την ασφάλεια, τη διαθεσιμότητα και την ανοχή σφαλμάτων,όπως φαίνεται από μία πληθώρα περιστατικών ασφάλειας κατά τη διάρκεια των ετών όπου τέτοιες οντότητες έχουν παραβιαστεί. Η αποκέντρωση έχει προταθεί ως εναλλακτική λύση για την αντιμετώπιση αυτών των ζητημάτων. Παρ 'όλα αυτά,η αποκέντρωση εγείρει άλλα προβλήματα όπως, π.χ., η αντιμετώπιση της μη ανταποδοτικότητας και οι Σιβυλλικές επιθέσεις. Σε αυτή τη διατριβή, αξιοποιούμε την επεκτασιμότητα, την ασφάλεια, καθώς και τον ενσωματωμένο μηχανισμό παροχής κινήτρων των συστημάτων blockchain και προτείνουμε τον σχεδιασμό μιας αποκεντρωμένης υπηρεσίας ονοματοδοσίας βασισμένη σε έξυπνα συμβόλαια. Πιο συγκεκριμένα, είμαστε οι πρώτοι που παρουσιάζουμε τον πλήρη φορμαλισμό του προβλήματος σχεδιασμού υπηρεσιών ονοματοδοσίας στο πλαίσιο τoυ μοντέλου Γενικής Σύνθεσης και αποδεικνύουμε την ασφάλεια της κατασκευής μας υπό την ισχυρή υπόθεση RSA στο μοντέλο του Τυχαίου Μαντείου και την ύπαρξη μιας ιδεατής λειτουργικότητας έξυπνου συμβολαίου.Το κύριο εμπόδιο στην πραγματοποίηση μιας υπηρεσίας ονοματοδοσίας βασισμένη σε έξυπνα συμβόλαια είναι το μέγεθος της αποθηκευμένης πληροφορίας σε αυτά η οποία,όντας η πιο δαπανηρή πηγή πρόσβασης και τροποποίησης, θα πρέπει να ελαχιστοποιηθεί για να θεωρηθεί μια κατασκευή βιώσιμη. Επιλύουμε αυτό το ζήτημα ορίζοντας και χρησιμοποιώντας στην υπηρεσία ονοματοδοσίας μας έναν προσθετικό, παγκόσμιο κρυπτογραφικό συσσωρευτή δημόσιας κατάστασης σταθερού μεγέθους, ένα κρυπτογραφικό εργαλείο το οποίο μπορεί να είναι ανεξάρτητου ενδιαφέροντος στο πλαίσιο των πρωτοκόλλων blockchain. Αυτός ο συσσωρευτής προκαλεί αποθήκευση σταθερού μεγέθους πληροφορίας εις βάρος υπολογιστικής πολυπλοκότητας. Για να διερευνήσουμε το αντίκτυπο ανάμεσα σε αυτά τα δύο,προτείνουμε και υλοποιούμε μια δεύτερη κατασκευή, η οποία διατηρεί τις ιδιότητες ασφαλείας της πρώτης και, όπως απεικονίζεται μέσα από την αξιολόγησή μας, είναι η μόνη έκδοση με σταθερού μεγέθους αποθηκευμένη πληροφορία που μπορεί να αναπτυχθεί στη βασική αλυσίδα τουEthereum, της πιο αξιοσημείωτης δημόσιας πλατφόρμας έξυπνων συμβολαίων κατά τη στιγμή αυτής της γραφής. Συγκρίνουμε αυτές τις δύο κατασκευές με την απλή προσέγγιση των περισσότερων προηγούμενων υλοποιήσεων, π.χ., του EthereumName Service, όπου όλα τα αρχεία ταυτότητας αποθηκεύονται πάνω στο έξυπνο συμβόλαιο, για να καταδείξουμε αρκετές ελλείψεις του Ethereumκαι του μοντέλου κοστολόγησής του. Για την αντιμετώπιση αυτών των ζητημάτων, καθώς και άλλων,εισαγάγουμε ένα εναλλακτικό παράδειγμα για την ανάπτυξη εφαρμογών βασισμένες σε έξυπνα συμβόλαια στις οποίες το μέθεγος της αποθηκευμένης πληροφορίας σε αυτά είναι σταθερή και διευκολύνει την επαλήθευση των δεδομένων των εφαρμογών, τα οποία αποθηκεύονται σε και αναζητούνται από ένα εξωτερικό, δυνητικά αναξιόπιστο, δίκτυο αποθήκευσης. Αυτή η προσέγγιση είναι σχετική για ένα ευρύ φάσμα εφαρμογών, όπως κάθε σύστημα αποθήκευσης κλειδιών και τιμών.Δείχνουμε την αποτελεσματικότητα της προσέγγιση μας με την παρουσίαση μιας μελέτης όπου προσαρμόζουμε το πιο ευρέως αναπτυγμένο πρότυπο για ανταλλάξιμα νομίσματα, δηλ., το πρότυπο νομισμάτων ERC20.Αντιμετωπίζουμε τη μονοτονικά αυξανόμενη αποθηκευμένη πληροφορία του Ethereum η οποία, αν δεν ελεγχθεί, θα έχει άμεσο αντίκτυπο στην ασφάλεια του Ethereum και, τελικά, στη μακροζωία του. Εισαγάγουμε επαναλαμβανόμενα τέλη που είναι ανάλογα με την αποθηκευμένη πληροφορία στα έξυπνα συμβόλαια και ρυθμιζόμενα από τους κόμβους που διατηρούν το δίκτυο. Προτείνουμε ένα μοντέλο όπου το κόστος των λειτουργιών αποθήκευσης αντικατοπτρίζει την προσπάθεια που πρέπει να καταβάλουν οι κόμβοι για να τις εκτελέσουν. Δείχνουμε ότι κάτω από ένα τέτοιο σύστημα τιμολόγησης που ενθαρρύνει οικονομία στην αποθηκευμένη πληροφορία στα έξυπνα συμβόλαια, οι κατασκευές που παρουσιάζονται σε αυτή τη διατριβή μειώνουν τα τέλη συναλλαγών κατά μία τάξη μεγέθους. Υποστηρίζουμε ότι αυτές οι βελτιώσεις είναι λογικές για κάθε πλατφόρμα έξυπνων συμβολαίων που επιθυμεί να υποστηρίζει την ανάπτυξη αυθαίρετων κατανεμημένων εφαρμογών από τους χρήστες της.

Open access
Blockchain Technology Applications and Security
Sharing Economy and Platforms
FinTech, Crowdfunding, Digital Finance
Original source
Oct 1, 2019
5 cites
SIPchain: SIP Defense Cluster With Blockchain

Aldo Febro, Hannan Xiao, Joseph Spring

The Session Initiation Protocol (SIP) is an application-layer control protocol for creating, modifying, and terminating Voice/Video over IP sessions. While deployed globally to facilitate multimedia communications, SIP is subject to various attacks. The defense against SIP attacks, however, often lack expertise due to the limited resources within the organization. When there is a large footprint of SIP systems, scaling and keeping up SIP defense becomes crucial in safeguarding these systems. This paper proposes SIPchain, a distributed SIP defense cluster system that leverages Blockchain technology as a distributed, highly-available, and permanent ledger of Indicator of Compromise (IOC). Each node in this cluster is a sensor and shares attack intelligence with other nodes via Blockchain. Each node reads information from the Blockchain and implements the appropriate firewall rule based on this information. This approach scales the defense because each node can leverage the actionable intelligence provided by other nodes and does not have to perform detection on their own. Experiments have been performed using a cluster of three SIP nodes in three different countries (US, UK, and Singapore) and the Ethereum Blockchain network. The result shows that when a node detected an attack, it produced and stored the IOC information at the Ethererum. Fellow SIP nodes retrieved this information, implemented firewall rule based on this information, and were proactively prepared when the same attack was launched against them. This SIPchain approach scales the SIP defense effort by utilizing Blockchain technology to secure the ever-growing footprint of SIP systems within the organization.

Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
User Authentication and Security Systems
Original source
Oct 1, 2019
5 cites
A Blockchain-based Lightweight Authentication Solution for IoT

Achraf Fayad, Badis Hammi, Rida Khatoun, Ahmed Serhrouchni

Internet of Things (IoT) systems are almost a part of our daily lives. The security of this new paradigm had always faced many challenge in order to insure user privacy and authentication. These security issues are still far from being solved by the classical centralized architectures which reaches their limits in terms of scalability especially when thousands or tens of thousands of IoT devices are connected in the same network. To remedy this architectural issue, we rely on blockchains in order to propose a simple and lightweight blockchain-based authentication solution for IoT systems. We provided a real implementation of our proposed scheme relying on Ethereum blockchain and using different devices in order to confirm its feasibility and evaluate its initial performances. The results obtained confirm its suitability to such environments.

Blockchain Technology Applications and Security
User Authentication and Security Systems
IoT and Edge/Fog Computing
Original source
Oct 1, 2019
1 cites
Blockchain-Based Metadata Protection for Archival Systems

Arnaud L'Hutereau, Dorian Burihabwa, Pascal Felber, Hugues Mercier · 5 authors

Long-term archival storage systems must protect data from powerful attackers that might try to corrupt or censor (part of) the documents. They must also protect the corresponding metadata information, which is essential to maintain and rebuild the stored data. In this practical experience report, we present metablock, a metadata protection system leveraging the Ethereum distributed ledger. We combine metablock with an existing secure long-term data archival system to provide a scalable design that allows external auditing, data validation and efficient data repair. We reflect on our experiences in using a blockchain for metadata protection, with the goal of providing valuable insights and lessons for developers of such secure systems, by highlighting the potential and limitations of the approach. Our prototype is available at https://github.com/ArnaudLhutereau/mb.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source