Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

3,460 papersLast indexed Aug 31, 2026
Search papers

Paper index

3,460 results · page 50 of 145

Clear filters
May 25, 2023·2023 International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI)
2 cites
Block Chain and Distributed Computing Aided with Cloud Technology- A Specific Reference to Security Issues of Healthcare Industry

C. Murugumani, Bhaludra R Nadh Singh, K. Pravalika, P Amrutha Sai Sri · 6 authors

There has been a significant uptick in the need for user-centric electronic records to save the many characteristics of a patient's medical history as they are recorded at a hospital during treatment and to make those records available as and when they are needed for future treatment, care, or invoicing. Blockchain technology allows us to save these data on a distributed ledger, allowing us to begin and enable use at breakneck speeds while still maintaining a transparent and secure system. To save records safely and in an interoperable fashion, a distributed system with ledger functionality is used. Block chain technology has the potential to revolutionize the way digital assets are transacted by removing the need for a trusted third party to authenticate data authenticity, record asset ownership, or mediate financial or data transactions. Immutability, decentralisation, and transparency are three of its defining characteristics, making it well suited to resolving pressing problems in the healthcare industry, such as the lack of comprehensive peer-to-peer files and the inability to easily access patients' medical histories. Health care systems that are efficient and successful depend on interoperability, the capacity of different health organisations and manufacturers of different software products to connect and share data in a safe and smooth manner. Many problems in modern healthcare can be traced back to a lack of interoperability, such as siloed data, sluggish communications, and different workflow tools. To address this, it is recommended to implement a system that provides secure, pseudo-anonymous access to complete, recognised longitudinal medical records stored in silos. In this article, we conducted a system overview and literature review of block chain technology in a fog computing environment, both of which are capable of processing vast amounts of data in a decentralised fashion. Our in-progress experimental study reveals weaknesses in existing systems and foreshadows directions for future investigation.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 25, 2023·Third International Conference on Machine Learning and Computer Application (ICMLCA 2022)
1 cites
Three technical aspects and security issues of Ethereum

Hongtian Shi, Ting Xiao, Jaiyi Zhang

Ethereum is a blockchian-based technology that enables a public ledger to be created and maintained without a trusted third party. Ethereum uses elliptic curve cryptography to create accounts and signature, the consensus of PoW as well as PoS to verify transactions and create blocks, and stores data in the modified Merkle Patricia tree. This paper introduced the main three technical aspects of Ethereum and updated some concepts as its technology is updating over time. At the time of Ethereum's transition from PoW to PoS, this paper compared the two mechanism and concluded that PoS is more vulnerable to security issues and more analysis is needed to maintain its long-time security. The paper also discussed uncle block attack and proposed two possible strategies to prevent.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Peer-to-Peer Network Technologies
Original source
May 24, 2023·2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD)
13 cites
Secure Data Sharing for Cross-domain Industrial IoT Based on Consortium Blockchain

Xinze Yu, Yunzhou Xie, Qiujie Xu, Zhuqing Xu · 5 authors

Industrial Internet of Things (IIoT) is considered one of the most revolutionary technologies that can significantly improve manufacturing efficiency and realize intelligent production. With the increasing complexity of industrial manufacturing, the manufacturing process of a product often involves several different IoT domains (e.g., factories). To achieve a common production goal, devices from various domains share their data for cooperative work, which raises privacy and security concerns for cross-domain communication. Most existing data-sharing schemes rely on a trusted third party. Hence, the privacy and security issues in cross-domain data sharing are still challenging research directions. This paper proposes CBDS, a consortiumblockchain-based cross-domain IIoT data-sharing mechanism. Specifically, we introduce consortium blockchain to construct trust among different domains in IIoT. A group signature is presented to ensure each device’s privacy to achieve anonymous authentication. In addition, the collected data should be stored in the ciphertext. The smart contract and proxy re-encryption are utilized in the CBDS to realize secure cross-domain data sharing. The experimental results demonstrate the effectiveness and efficiency of the proposed CBDS.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 24, 2023·2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD)
7 cites
NFT Cross-Chain Transfer Method Under the Notary Group Scheme

Xiangyu Niu, Lanju Kong, Fuqi Jin, Xiaolin Song · 6 authors

With the development of blockchain, the demand for the cross-chain transfer of the on-chain digital assets, such as Non-Fungible Tokens (NFTs), is increasing. The notary scheme is a kind of cross-chain mechanisms with low complexity to achieve the above demand. Although many NFT cross-chain methods and protocols have been invented, the method based on the notary scheme has not been widely studied at this stage. Therefore, we improve the traditional notary scheme and propose an NFT cross-chain transfer model with it. In this paper, we introduce NCTN, a trusted NFT cross-chain transfer model based on the notary group and design the cross-chain transaction protocol in detail according to NCTN’s architecture. To ensure the availability of the model, we then present an effective reputation value model, which is used as the basis for the reliable election in the notary group. Experiments show that our model can well complete the tasks of cross-chain transfers of NFTs and has good performance in transaction response time; our reputation value model can well avoid the problem of excessive centralization and can ensure the reliability of notaries.

Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cloud Data Security Solutions
Original source
May 24, 2023·2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD)
0 cites
Research on Medical Data Storage and Secure Sharing Scheme Based on Blockchain

Wenxu Han, Qi Li, Meiju Yu, Ru Li

With the explosive development of technology and Internet communication, it has become an inevitable trend to realize the secure storage and sharing of electronic medical data among hospitals. In recent researches, there are also many problems in realizing secure storage and sharing of electronic medical data, such as "data silos", leakage of patient sensitive information due to data sharing and having no reliability about the original data uploaded by patients. To solve the above problems, we propose a blockchain-based medical data storage and secure sharing scheme. In the scheme, we utilize IPFS-based Web3.Storage for medical data storage, propose a sensitivity classification and access control strategy for sensitive data leakage and present a blockchain-based original data reliability checking strategy to check the reliability of the original data. Our scheme is explained in detail in the paper, and the performance analysis of this scheme is carried out to prove the feasibility of this scheme.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 23, 2023
9 cites
Creation of a Unified University Blockchain for the Purpose of Storing the University’s Teaching Mate rials

Krisztián Bálint

The use of blockchain technology gives universities the opportunity to create their own blockchain. By rethinking the Bologna program applied in education, in the future, universities will be able to work together even more closely in the field of joint curriculum development. It can be observed that different universities teach the same subjects. As a result, university lecturers have even more burdens outside of teaching, as lecturers must prepare the same teaching materials for each university. The aim of the research is to create a blockchain in practice, as well as to present it in detail, where university lecturers could upload uniformly prepared teaching materials. In the long run, a unified and universally accepted university curriculum will certainly bring many advantages. If the university also wants to upload paid course content to the blockchain, a smart contract must be used. With the help of a smart contract, payments for teaching materials would be carried out in an automated manner, so additional burdens could be taken off the shoulders of universities. Since the blocks in the blockchain are closely built on top of each other, it is difficult to modify them with the educational materials stored in them. Since universities must provide students with up-to-date knowledge, the teaching materials must also be up to date. The modification of teaching materials at specified intervals could be solved using the Soft-Fork blockchain process.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 22, 2023·Security and Communication Networks
12 cites
Blockchain for Credibility in Educational Development: Key Technology, Application Potential, and Performance Evaluation

Yongshan Wang, Xin Cong, Lingling Zi, Qiuyan Xiang

Blockchain proposes many innovative technologies to establish credible mechanisms in an open environment and therefore, it becomes a promising solution to the problem of credibility in educational development. To better understand the role of the blockchain, we aim to provide an extensive survey focusing on its key technology, application potential, and performance evaluation. First, from the perspective of blockchain characteristics, we summarize its application architecture in educational credibility. Next, we extensively discuss application potential of the blockchain, such as data storage, data sharing, achievement certification, and activity evaluation. Moreover, we investigate the performance evaluation, including basic performance metrics and specialized metrics for credibility. Finally, we analyze the challenges and research trends of blockchain in educational credibility and provide useful insights for future research.

Open access
Blockchain Technology Applications and Security
Cloud Computing and Resource Management
Cloud Data Security Solutions
Original source
May 19, 2023·IEEE Transactions on Services Computing
20 cites
Verifiable Carbon Accounting in Supply Chains

Jonathan Heiss, Tahir Oegel, Mehran Shakeri, Stefan Tai

<p>In face of the ongoing climate change, both reduction and offsetting of carbon emissions are critical. To this end, accurate, reliable emission data, and service-oriented architectures for processing the data are needed. Current carbon accounting practices, however, are often error-prone, costly, and time-consuming. Even in digital monitoring, reporting and verification (MRV) systems, the employment of single, trusted verification bodies inhibits transparent, fine-granular, and verifiable accounting on product instance-level in high-throughput supply chains. We propose Verifiable Carbon Accounting (VCA) as a novel accounting approach that leverages authenticity and zero-knowledge proofs in service-oriented architectures for creating non-disclosing emission reports that are peer-to-peer verifiable on blockchains. VCA builds upon and extends both conventional and digital MRV systems but ensures the confidentiality of business emission data and calculations while allowing for peer-to-peer transparency and verifiability. We introduce the concept and demonstrate VCA application for accounting product carbon footprints (PCFs) in supply chains. We present a proof-of-concept technical system design and implementation and discuss experimental findings, deriving both insights on VCA practicability and next steps. Overall, we show how VCA advances the state of art in carbon accounting in and beyond supply chains, and how VCA can serve as the basis for next-generation, accurate carbon accounting.</p>

Open access
3 source records
Blockchain Technology Applications and Security
Green IT and Sustainability
Cloud Data Security Solutions
Original source
May 17, 2023
8 cites
Blockchain-based Access Control Model for Student Academic Record with Authentication

M. Maheswari, S. Prasath, R. Rajesh, D. Ramalakshmi

Schools and Institutions maintain student’s records and certificates for future needs like verification and credit transfer. These procedures are carried out manually to ensure that documents and the data are valid and non-tampered, which usually needs more energy and time. Converting these procedures into digital form minimizes the time and energy consumption but with the cost of high-security risks. Storing student’s data on a centralized system has problems like data breaches due to human error, injection attacks, and buffer overflow attacks, and even if the server gets damaged physically, it’ll take more time to repair and recover the damaged data and start running. But in blockchain technology, the data stored in blocks with a cryptographical code of the previous block, gives enhanced security compared to the traditional database. If anyone tries to tamper or hack the data, the decentralized technology can easily recognize the modification and prevent it from happening. Three layers of blockchain are being employed to give the Academic Record System the highest level of security possible. Data Storage Blockchain is the third layer of the model which stores the student’s records. The Access Control Model Blockchain is the second layer, which includes additional layer security to the Data Storage Blockchain as it records all the activities around it. And the final layer is the Authentication Blockchain, which is based on Ethereum Blockchain. This model validates transaction using Smart Contracts given to them, creating a new user and validating the login process securely for the Authority, Institution, and the Student for accessing the Data Storage.

Cloud Data Security Solutions
Cryptography and Data Security
Blockchain Technology in Education and Learning
Original source
May 17, 2023·2023 International Conference on Communication, Computing and Digital Systems (C-CODE)
8 cites
Blockchain based Secure Data Management for Healthcare Applications

Muhammad Zalkifal Khan, Maham Nadeem, Mohammad Kaleem, Sajid Nazir

Blockchain technology is poised to transform the data storage and data interchange models. A blockchain is a distributed ledger of transactions stored across a network of nodes. This decentralized model provides immutability and traceability of the records and is known as Distributed Ledger Technology (DLT). In the implemented healthcare system, we used a decentralized blockchain based peer to peer architecture ensuring data security, availability, and reliability. We leverage the Substrate framework, part of Polkadot ecosystem for building blockchains. Once the patient logs into their profile, they are able to view their medical history along with any doctor’s prescriptions and laboratory reports. When the doctor accesses a patient’s profile, they can make new entries to the medical records and prescriptions. In addition, we show that a tamper-proof record of the healthcare assets can be securely maintained, and accessible to the authorized entities.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 17, 2023·2023 7th International Conference on Intelligent Computing and Control Systems (ICICCS)
1 cites
Optimizing the KYC Verification System using Ethereum Blockchain

Ujwala Ravale, Aditya Ramakrishnan, Anand Borkar, Suchit Deshmukh

People utilise their personal identity documents on a regular basis with current increase in digitization, which are shared with third parties without their explicit authorization and kept in numerous random locations. Financial organizations that include government institutions, banks, credit agencies, etc. store such identification information in their own databases. Having such sensitive information at multiple locations increases the chances of vulnerabilities. The financial sector has been on a search for solutions for such problems for a long time and one viable solution to this is blockchain. By keeping a single safe database on blockchain, the Know Your Customer (KYC) verification procedure reduces the repetitive KYC checks that banks presently do. Because blockchain is immutable and unalterable by definition, illegal modifications to data are instantly invalidated. Blockchain’s decentralised design will enable the collection of data from different authoritative service providers into a single immutable, safe, and verified database. The Blockchain KYC system uses a secure, public digital ledger to provide rapid and fully secure identity verification.

2 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
May 15, 2023·IEEE Transactions on Network and Service Management, 2023
32 cites
Smart Policy Control for Securing Federated Learning Management System

Aditya Pribadi Kalapaaking, Ibrahim Khalil, Mohammed Atiquzzaman

The widespread adoption of Internet of Things (IoT) devices in smart cities, intelligent healthcare systems, and various real-world applications have resulted in the generation of vast amounts of data, often analyzed using different Machine Learning (ML) models. Federated learning (FL) has been acknowledged as a privacy-preserving machine learning technology, where multiple parties cooperatively train ML models without exchanging raw data. However, the current FL architecture does not allow for an audit of the training process due to the various data-protection policies implemented by each FL participant. Furthermore, there is no global model verifiability available in the current architecture. This paper proposes a smart contract-based policy control for securing the Federated Learning (FL) management system. First, we develop and deploy a smart contract-based local training policy control on the FL participants' side. This policy control is used to verify the training process, ensuring that the evaluation process follows the same rules for all FL participants. We then enforce a smart contract-based aggregation policy to manage the global model aggregation process. Upon completion, the aggregated model and policy are stored on blockchain-based storage. Subsequently, we distribute the aggregated global model and the smart contract to all FL participants. Our proposed method uses smart policy control to manage access and verify the integrity of machine learning models. We conducted multiple experiments with various machine learning architectures and datasets to evaluate our proposed framework, such as MNIST and CIFAR-10.

Open access
2 source records
cs.CR
cs.LG
Privacy-Preserving Technologies in Data
Original source
May 12, 2023·Future Generation Computer Systems
32 cites
A Flexible Approach to Multi-party Business Process Execution on Blockchain

Flavio Corradini, Alessandro Marcelletti, Andrea Morichetta, Andrea Polini · 6 authors

In modern business scenarios, more and more organisations have to deal with the critical requirements of trustworthiness and flexibility, when collaborating in multi-party business processes. This calls for new kinds of systems able to manage collaborative processes in untrusted and dynamic environments. Concerning the collaborative perspective, the Business Process Management discipline has provided effective and standardised solutions for a long time, now. Regarding the trustworthiness perspective, blockchain is advocated as one of the most prominent technologies to guarantee trust in a multi-party setting. However, while the immutability of blockchain provides transparent and secure proof of past business interactions, it hinders the flexibility of the business process execution, as the business logic regulating the process execution is immutably stored in the blockchain. On the other hand, flexibility is a property that is becoming crucial in such a setting due to the high dynamism of the business scenarios. In fact, it permits to modify a process at run-time to deal with internal or external changes. In this paper, we face this issue by proposing an architecture for the flexible blockchain-based execution of multi-party business processes. In our approach, business processes are modelled by BPMN choreography diagrams translated into code, whose execution state is then stored in the blockchain. Flexibility is achieved by decoupling the business process’s logic from its execution state, thus allowing run-time changes to the process execution without losing the fundamental properties of trust provided by the blockchain. To show the effectiveness of our approach, we provide a prototypical implementation, called FlexChain, and we use it on a case study from the healthcare application domain. The results obtained by the analysis of cost for the reported case study show the feasibility of the approach. In particular, major costs to sustain relate to one-time operations, such as the deployment and the run-time update of the model, while the most frequent actions are quite efficient.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
May 12, 2023·arXiv (Cornell University)
0 cites
Torrent Driven (TD) Coin: A Crypto Coin with Built In Distributed Data Storage System

A. N. Paul

In recent years decentralized currencies developed through Blockchains are increasingly becoming popular because of their transparent nature and absence of a central controlling authority. Though a lot of computation power, disk space, and energy are being used to run this system, most of these resources are dedicated to just keeping the bad actors away by using Proof of Work, Proof of Stake, Proof of Space, etc., consensus. In this paper, we discuss a way to combine those consensus mechanism and modify the defense system to create actual values for the end-users by providing a solution for securely storing their data in a decentralized manner without compromising the integrity of the blockchain.

Open access
2 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Caching and Content Delivery
Original source
May 11, 2023·Research Square
2 cites
SSH-DAuth: Secret Sharing based Decentralized OAuth using Decentralized Identifier

Danda Prudhvi Krishna, R. Ramaguru, K. Praveen, M. Sethumadhavan · 7 authors

OAuth2.0 is a Single Sign-On approach that helps to authorize users to log into multiple applications without re-entering the credentials. Here, the OAuth service provider controls the central repository where data is stored, which may lead to third-party fraud and identity theft. To circumvent this problem, we need a distributed framework to authenticate and authorize the user without third-party involvement. This paper proposes a distributed authentication and authorization framework using a secret-sharing mechanism that comprises a blockchain-based decentralized identifier and a private distributed storage via an interplanetary file system. We implemented our proposed framework in Hyperledger Fabric (permissioned blockchain) and Ethereum TestNet (permissionless blockchain). Our performance analysis indicates that secret sharing-based authentication takes negligible time for generation and a combination of shares for verification. Moreover, security analysis shows that our model is robust, end-to-end secure, and compliant with the Universal Composability Framework.

Open access
2 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Spam and Phishing Detection
Original source
May 11, 2023·Journal of Reliable Intelligent Environments
50 cites
Secure data sharing with blockchain for remote health monitoring applications: a review

Venkatesh Upadrista, Sajid Nazir, Huaglory Tianfield

Remote Health Monitoring (RHM) is going to reinvent the future healthcare industry and bring about abundant value to hospitals, doctors, and patients by overcoming the many challenges currently being faced in monitoring patient's well-being, promoting preventive care, and managing the quality of drugs and equipment. Despite the many benefits of RHM, it is yet to be widely deployed due to the healthcare data security and privacy challenges. Healthcare data are highly sensitive and require fail-safe measures against unauthorized data access, leakages, and manipulations, and as such, there are stringent regulations governing how healthcare data can be secured, communicated, and stored, such as General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA). The challenges and regulatory demands in RHM applications can be addressed using blockchain technology due to its distinguishing features of decentralization, immutability, and transparency to address the challenges of data security and privacy. This article will provide a systematic review on the use of blockchain in RHM, focusing primarily on data security and privacy.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 10, 2023·arXiv (Cornell University)
0 cites
Speranza: Usable, privacy-friendly software signing

Kelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen Sollins

Software repositories, used for wide-scale open software distribution, are a significant vector for security attacks. Software signing provides authenticity, mitigating many such attacks. Developer-managed signing keys pose usability challenges, but certificate-based systems introduce privacy problems. This work, Speranza, uses certificates to verify software authenticity but still provides anonymity to signers using zero-knowledge identity co-commitments. In Speranza, a signer uses an automated certificate authority (CA) to create a private identity-bound signature and proof of authorization. Verifiers check that a signer was authorized to publish a package without learning the signer's identity. The package repository privately records each package's authorized signers, but publishes only commitments to identities in a public map. Then, when issuing certificates, the CA issues the certificate to a distinct commitment to the same identity. The signer then creates a zero-knowledge proof that these are identity co-commitments. We implemented a proof-of-concept for Speranza. We find that costs to maintainers (signing) and end users (verifying) are small (< 1 ms), even for a repository with millions of packages. Techniques inspired by recent key transparency systems reduce the bandwidth for serving authorization policies to 2 KiB. Server costs in this system are negligible. Our evaluation finds that Speranza is practical on the scale of the largest software repositories. We also emphasize practicality and deployability in this project. By building on existing technology and employing relatively simple and well-established cryptographic techniques, Speranza can be deployed for wide-scale use with only a few hundred lines of code and minimal changes to existing infrastructure. Speranza is a practical way to bring privacy and authenticity together for more trustworthy open-source software.

Open access
2 source records
cs.CR
Security and Verification in Computing
Access Control and Trust
Original source
May 10, 2023·Institute of Electrical and Electronics Engineers (IEEE)
0 cites
Security of the Current Blockchain Technologies: Viewpoint from 2023

Petar Radanliev

The first cryptocurrency was invested in 2008/09, but the Blockchain-Web3 concept is still in its infancy, and the cyber risk is constantly changing. Our cybersecurity should also be adapting to these changes to ensure security of personal data and continuation of business for organisations. This review paper starts with a comparison of existing cybersecurity standards and regulations from the National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) - ISO27001, followed by a discussion on more specific and recent standards and regulations, such as the Markets in Crypto-Assets Regulation (MiCA), Committee on Payments and Market Infrastructures and the International Organisation of Securities Commissions (CPMI-IOSCO), and more general cryptography and post-quantum cryptography, in the context of cybersecurity. These topics are followed up by a review of recent technical reports on cyber risk/security and a discussion on cloud security questions. Comparison of Blockchain cyber risk is also performed on the recent EU standards on cyber security, including European Cybersecurity Certification Scheme (EUCS) – cloud, and additional US standards – The National Vulnerability Database (NVD) Common Vulnerability Scoring System (CVSS). The study includes a review of Blockchain endpoint security, and new technologies e.g., IoT. The research methodology applied is a review and case study analysing secondary data on cybersecurity. The research significance is the integration of knowledge from the United States (US), the European Union (EU), the United Kingdom (UK), and international standards and frameworks on cybersecurity that can be alighted to new Blockchain projects. The results show that cybersecurity standards are not designed in close cooperation between the two major western blocks - US and EU. In addition, while the US is still leading in this area, the security standards for cryptocurrencies, internet-of-things, and blockchain technologies have not evolved as fast as the technologies have. The key finding from this study is that although the crypto market has grown into a multi-trillion industry, the crypto market has also lost over 70% since its peak, causing significant financial loss for individuals and cooperation’s. Despite this significant impact to individuals and society, cybersecurity standards and financial governance regulations are still in their infancy.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Cloud Data Security Solutions
Original source
May 10, 2023·Technology Analysis and Strategic Management
14 cites
NFT-based online prescription for data management in healthcare services

Shahriar Mohammadi, Amir Ali Fatoorchi, Mehdi Babagoli

The development of electronic health (e-health) systems in the last decades led to the emergence of effective infrastructures for managing health records. Due to the vitality and massive amount of healthcare records, blockchain is considered one of the most important infrastructures to store and exchange health records. Access to patient’s medical histories and health record management are essential to healthcare systems. Patients’ records must be exchanged among various parts of the healthcare system and users should have access to manage their profiles and use online facilities in a secure manner. In this paper, for the first time, the non-fungible token (NFT), which is a nascent technology, is used to certify the information immutability of healthcare records in the blockchain infrastructure. The ownership of property and prevention of information disclosure is guaranteed using the encryption strategy is used in the proposed NFT technology. Furthermore, the proposed model satisfies all security criteria such as data integrity, non-repudiation, anonymity, confidentially and privacy. As a result, the proposed model outperforms the related research in the healthcare domain. The proposed model brings many facilities for both patients and physicians such as secure accessibility, data quality, patient consent, efficient record management and better availability and reliability.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
May 9, 2023·Electronics
14 cites
Formal Analysis of Reentrancy Vulnerabilities in Smart Contract Based on CPN

Yaqiong He, Hanjie Dong, Huaiguang Wu, Qianheng Duan

A smart contract is a special form of computer program that runs on a blockchain and provides a new way to implement financial and business transactions in a conflict-free and transparent environment. In blockchain systems such as Ethereum, smart contracts can handle and autonomously transfer assets of considerable value to other parties. Hence, it is particularly important to ensure that smart contracts function as intended since bugs or vulnerabilities may lead, and indeed have led, to substantial economic losses and erosion of trust for blockchain. While a number of approaches and tools have been developed to find vulnerabilities, formal methods present the highest level of confidence in the security of smart contracts. In this paper, we propose a formal solution to model a smart contract based on colored Petri nets (CPNs). Herein, we focus on the most common type of security bugs in smart contract, i.e., reentrancy bugs, which led to a serious financial loss of around USD 34 million for the Cream Finance project in 2021. We present a hierarchical CPN modelling method to analyze potential security vulnerabilities at the contract’s source code level. Then, modeling analysis methods such as correlation matrix, state space report and state space graph generated via CPN Tools simulation are exploited for formal analysis of smart contracts. The example shows the full state space and wrong path in accordance with our expected results. Finally, the conclusion was verified on the Ethereum network based on the Remix platform.

Open access
Blockchain Technology Applications and Security
Security and Verification in Computing
Cloud Data Security Solutions
Original source
May 7, 2023·Electronics
22 cites
Blockchain-Based Authentication Protocol Design from a Cloud Computing Perspective

Zhiqiang Du, W. Jiang, Chenguang Tian, Xiaofeng Rong · 5 authors

Cloud computing is a disruptive technology that has transformed the way people access and utilize computing resources. Due to the diversity of services and complexity of environments, there is widespread interest in how to securely and efficiently authenticate users under the same domain. However, many traditional authentication methods involve untrusted third parties or overly centralized central authorities, which can compromise the security of the system. Therefore, it is crucial to establish secure authentication channels within trusted domains. In this context, we propose a secure and efficient authentication protocol, HIDA (Hyperledger Fabric Identity Authentication), for the cloud computing environment. Specifically, by introducing federated chain technology to securely isolate entities in the trust domain, and combining it with zero-knowledge proof technology, users’ data are further secured. In addition, Subsequent Access Management allows users to prove their identity by revealing only brief credentials, greatly improving the efficiency of access. To ensure the security of the protocol, we performed a formal semantic analysis and proved that it can effectively protect against various attacks. At the same time, we conducted ten simulations to prove that the protocol is efficient and reliable in practical applications. The research results in this paper can provide new ideas and technical support for identity authentication in a cloud environment and provide a useful reference for realizing the authentication problem in cloud computing application scenarios.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Cloud Data Security Solutions
Original source