Blockchain's properties in addressing trust in highly decentralized environments can make it an enabler for novel sharing economy services. In this paper, we demonstrate the practicality of blockchain-based Secure IoT as a Service (SIoTaaS), where an IoT device can be rented from a service provider, securely and in a privacy-preserving fashion. Our framework allows the simultaneous operations of distinct providers of IoT-based sharing economy services at a large scale. Multiple parties can securely share text and multimedia in the context of location and point-of-interest sharing, perform financial transactions by hiding true identity of parties involved in various online transactions, perform user and IoT registration, transfer value transactions via Ethereum tokens between providers and consumers, as well as raw IoT data payload. This can turn smart room IoT devices, such as smart locks, light bulbs, air conditioning and fans into rentable business entities within a secure sharing economy platform. We will demonstrate such a proof of concept IoT sharing economy framework, which is specifically designed to support the temporary IoT needs of very large numbers of users, such as Hajj pilgrims concentrating for a short period of time at a single area in Saudi Arabia.
Niclas Kannengießer, Sebastian Lins, Tobias Dehling, Ali Sunyaev
When developing peer-to-peer applications on distributed ledger technology (DLT), a crucial decision is the selection of a suitable DLT design (e.g., Ethereum), because it is hard to change the underlying DLT design post hoc. To facilitate the selection of suitable DLT designs, we review DLT characteristics and identify trade-offs between them. Furthermore, we assess how DLT designs account for these trade-offs and we develop archetypes for DLT designs that cater to specific requirements of applications on DLT. The main purpose of our article is to introduce scientific and practical audiences to the intricacies of DLT designs and to support development of viable applications on DLT.
Niclas Kannengießer, Sebastian Lins, Tobias Dehling, Ali Sunyaev
When developing peer-to-peer applications on Distributed Ledger Technology (DLT), a crucial decision is the selection of a suitable DLT design (e.g., Ethereum) because it is hard to change the underlying DLT design post hoc. To facilitate the selection of suitable DLT designs, we review DLT characteristics and identify trade-offs between them. Furthermore, we assess how DLT designs account for these trade-offs and we develop archetypes for DLT designs that cater to specific quality requirements. The main purpose of our article is to introduce scientific and practical audiences to the intricacies of DLT designs and to support development of viable applications on DLT.
Blockchain technologies have grown swiftly in recent years, primarily due to the advent of Bitcoin. Blockchain is a consensus of data structures or blocks programmed for cryptographically storing organized data, which is spread across nodes, so that various operations can be executed on it. Originally blockchain was designed for storing digital coins as system states and now has grown beyond crypto-currencies to support user-defined decentralized autonomous applications or smart contracts with Ethereum. Growing interest from the industry and wide range of applications has triggered development of new blockchain platforms. As the technology is progressing quickly, it is necessary and challenging to have a more profound perspective of what the core technology platforms have to provide in order to establish which blockchain implementation should be leveraged for a particular application. We therefore grasp the key aspects of blockchain and compare how the current blockchain implementations are different from each other, both qualitatively and quantitatively in terms of design architecture, codebase, consensus algorithms and performance. Drawing from the comparison we identify the current challenges as well as performance issues in blockchain adoption, thus suggesting possible solutions and future implementations to improve performance of blockchain and provide subsequent research directions.
Stanis law Dro .zd .z, Ludovico Minati, Pawe l O 'swi kecimka, Marek Stanuszek · 5 authors
Based on the high-frequency recordings from Kraken, a cryptocurrency exchange and professional trading platform that aims to bring Bitcoin and other cryptocurrencies into the mainstream, the multiscale cross-correlations involving the Bitcoin (BTC), Ethereum (ETH), Euro (EUR) and US dollar (USD) are studied over the period between July 1, 2016 and December 31, 2018. It is shown that the multiscaling characteristics of the exchange rate fluctuations related to the cryptocurrency market approach those of the Forex. This, in particular, applies to the BTC/ETH exchange rate, whose Hurst exponent by the end of 2018 started approaching the value of 0.5, which is characteristic of the mature world markets. Furthermore, the BTC/ETH direct exchange rate has already developed multifractality, which manifests itself via broad singularity spectra. A particularly significant result is that the measures applied for detecting cross-correlations between the dynamics of the BTC/ETH and EUR/USD exchange rates do not show any noticeable relationships. This may be taken as an indication that the cryptocurrency market has begun decoupling itself from the Forex.
El presente documento recoge el trabajo de toda una trayectoria universitaria que llega a
su fin abriendo paso a una nueva etapa. El objetivo de este trabajo es hacer resaltar la
importancia de las nuevas tecnologias que se presentan ante nosotros y las posibilidades y
nuevas metas que pueden abrirnos.
El tema de este trabajo son los Smart Contracts de la tecnologia Ethereum, llevando a
cabo un estudio de esta tecnologia e ideando un caso de estudio que pueda comprenderse
por el lector, sin necesidad de tener unos conocimientos muy avanzados en el mundo
tecnologico. Adicionalmente, se ha llevado a cabo el desarrollo de una Aplicacion Web,
para comprender mas facilmente el esfuerzo realizado.
Se ha construido por completo el sistema de control horario de parking (ORA) desde sus
cimientos, partiendo de una base completamente diferente a la actual, pero manteniendo
la misma esencia con varias mejoras que facilitaran la experiencia de usuario. Este nuevo
sistema es descentralizado y autogestionado por un Smart Contract de tecnologia
Ethereum. Las transacciones realizadas en este sistema se ejecutan automaticamente, a la
vez que el usuario puede interactuar con las mismas para ajusfar el pago a realizar. Todo
es llevado a cabo mediante la encriptacion propia de una cadena de bloques, lo que
proporciona gran seguridad.
Ventajas que destacar del sistema desarrollado son algunas como la Monitorizacion de la
ocupacion en tiempo real de las calles de la Zona SER, la devolucion del importe sobrante
en las sesiones de estacionamiento, inmutabilidad de las transacciones realizadas o la
descentralizacion completa sin puntos centrales de fallo.
Si tradujeramos los resultados o beneficios obtenidos en el desarrollo de este proyecto, se
podria definir como una potente alternativa al actual sistema de aparcamiento usando todo
el potencial de las nuevas tecnologias.---ABSTRACT---This document gathers the work of a whole university trajectory that comes to an end,
opening the way to a new stage. The objective of this work is to highlight the importance
of new technologies that are presented to us and the possibilities and new goals that can
open us.
The theme of this work is the Smart Contracts of the Ethereum technology, carrying out
a study of this technology and devising a case study that can be understood by the reader,
without needing to have very advanced knowledge in the technological world. Additionally,
the development of a Web Application has been carried out, to better understand the effort
made.
The parking time control system (ORA) has been completely built from its foundations,
starting from a completely different base than the current one, but maintaining the same
essence with several improvements that will facilitate the user experience. This new system
is decentralized and self-managed by a Smart Contract of Ethereum technology. The
transactions carried out in this system are executed automatically, while the user can
interact with them to adjust the payment to be made. Everything is carried out through
the own encryption of a chain of blocks, which provides great security.
Advantages that stand out of the developed system are some like the Monitoring of the
occupation in real time of the streets of the Zona SER, the refund of the excess amount in
the sessions of parking, immutability of the realized transactions or the complete
decentralization without central points of failure.
If we translate the results or benefits obtained in the development of this project, it could
be defined as a powerful alternative to the current parking system using the full potential
of new technologies.
Public blockchains in support of Smart Contracts (SC), like Ethereum enable everyone to represent scarce, valuable resources (like cryptocurrencies) as so-called tokens. Token issuing and management was the first blockchain use case. However, programming languages and runtime systems used in the current blockchains for their SCs lack a secure and straightforward way to implement and handle tokens. The unnecessary complexity in doing so can lead to erroneous implementation of tokens and applications built on top of these, including the loss or theft of tokens as it happened. The most known attack was "TheDAO" attack which led to the "loss" of tokens, valued at that time at approximately 60 M US Dollar. A better and secure token representation directly embedded into a SC runtime and SC programming language could prevent loss of tokens. Thus this paper presents an approach including parts of a programming language using it. The core of the model is to use opaque and substructural data types together with an onchain soundness checker to generically represent tokens securely as values similar to integers and booleans. Such opaque data types enforce that only a designated piece of code can create values of that type. The substructural data types allow arbitrary values to express scarcity by preventing the duplication and elimination of values. The on-chain soundness checker ensures that the deployed code does not violate guarantees given by the type system, which includes opaque and substructural data types.
Abhilash Kancharla, Jongho Seol, Nicole Park, Indy Park · 5 authors
This paper presents a work on how to assure the dependability of a crypto system built across on and off the blockchain by using the proposed adaptive checkpoint and rollback algorithm, and a prototype is developed for demonstration purpose.The theoretical background of the proposed checkpoint and rollback algorithm is studied to characterize the variables affecting the dependability such as security, authenticity and reliability with respect to the rates of hit by any events of those issues, the rates to detect and diagnose, and then the rate to vote for a consensus whether to trigger a rollback or not. Based on the variables characterization in a stochastic manner, then steady state probabilities and state transition probabilities are derived in order to assure the ultimate effective dependability of each individual dependability variable (i.e., security, authenticity and reliability), then finally to assure the dependability in a compound manner with each variable assigned a weight depending on the nature of the systems specifications.Based on the theoretical study, a protype of a crypto system is built to demonstrated the underlying architecture and operations and to justify the need for such system to take synergistic advantages from both on- and off-chain blockchains, with an experimental result of a benefit in gas fee which is the most exigently addressed issue today in blockchain systems especially in Ethereum network of blockchains. An astonishing gas fee saving results are demonstrated. It is observed that the crypto system benefits more if more computationally intensive transactions are executed off-chain while vice versa.
Internet of Thing devices (IoT devices) are often constrained in terms of computing, memory, storage, power, and network resources. This makes them ill-suited to operate as first-class citizens on a blockchain, such as Ethereum, preventing the IoT devices from attaining the security guarantees that are available to better resourced nodes that are able to operate as full, validating nodes on the blockchain. IoT devices may use so-called light protocols to interact with the blockchain with minimal resource requirements, but these protocols provide only probabilistic security guarantees. In this position paper, we propose a new mechanism where an operator of IoT devices is able to send a “ground truth state” to the devices via a new mechanism, which we call “decentralized beacons”, enabling them to gain full security guarantees of the blockchain state.
Over the last few years, interest has emerged in blockchain, a decentralized ledger technology (DLT) created for use in cryptocurrencies, but with a great potential to be used in other application domains. One of them is supply chain management, tracking and tracing, which are key processes to the logistics industry, made difficult due to the lack of standards or trust between actors, miscommunication, fraud and bureaucratic delays, among other issues. In order to overcome some of these challenges, the solution presented in this dissertation proposes a blockchain system application created with Ethereum smart contracts technology. Its main purpose is to be used in supply chain and logistics for the tracking and tracing products, where the storage of important data is done and verified in a trustworthy, decentralized system. The technical solution presented here implements methods for tracking, certification, quality control and authentication, and integrates the communication of blockchain with IoT devices, which play an important role in monitoring products and automating these processes. This approach is validated by the development of a smart contract system and two browser-based applications to interact with it. The first application allows users to access and view their product’s tracking data, while the second bridges the communication between an Arduino UNO microcontroller collecting temperature readings and our smart contract system. The work presented here highlights the benefits of these technologies applied to logistics and validates the feasibility of this approach, ultimately giving insight into the capabilities, qualities, but also of the limitations a system like this can have.
The rise of blockchain technology has paved the way for an increasing number of blockchain systems, each having different characteristics. The need for distributed applications that span across multiple blockchain systems is increasing. However, it is currently not possible to write a single-description smart contract which can be compiled to span across multiple blockchain systems. In this paper we present PORTHOS, a macroprogramming framework and domain specific language for writing commitment-based smart contracts that span multiple blockchain systems. The language allows programmers to write smart contracts at a higher level of abstraction by composing together contract blocks, without the need to specify how logic should be split across different blockchain instances. A runtime framework, including both on-chain and off-chain functionality, harmonises the features of different blockchain systems as well as enables communication across the smart contracts. A proof of concept, built on the Ethereum and Hyperledger Fabric blockchain systems and extendible to other systems, illustrates the technique and framework. We also show how the PORTHOS language is expressive enough to define a variety of applications.
With the power system reform and the increase of distributed energy penetration, effective dispatch of distributed energy faces opportunities and challenges. Traditionally, the centralized power transaction mode has high maintenance cost, low efficiency and untimely settlement. Therefore, it is hard to adapt to the high-frequency and small-scale distributed energy trading scenarios. To this end, this paper mainly proposes a distributed power trading method based on blockchain considering security constraints. The paper first reviews the development history of blockchain technology, and explores the theory of blockchain technology. At the same time, it combines the analysis of distributed energy features and summarizes some requirements for building a distributed energy trading market. Then the mechanism and model of distributed power trading considering security constraints are constructed. Finally, a distributed power trading method based on blockchain is proposed to ensure the transparency of transactions, and to provide smart contracts for distributed power multilateral transactions. Through the example of the Ethereum blockchain, the distributed power trading method based on blockchain proposed in this paper can realize the over-limit correction of power flow and the multilateral trading of power, and realize the digital management of electric energy.
Truth discovery with crowdsourcing has become increasingly popular in recent years by leveraging the wisdom of crowd to solve complex tasks. So far, many existing crowd-sourcing applications utilize a central server for deployment, which collects and processes data from a crowd of workers. However, this kind of centralized model also introduces security concerns, including data privacy, integrity of processed data, and single point of failure. In this paper, we propose a secure decentralized framework for truth discovery with a privacy-preserving and reliable realization. Instead of relying on the central servers (e.g., public cloud servers)to behave correctly, our framework delegates the data aggregation and processing tasks to distributed entities, whose behaviors are enforced and verified by utilizing the emerging blockchain-based smart contract technology. Meanwhile, as the blockchain lacks support for on-chain data confidentiality, we utilize the privacy-preserving solution and integrate it with blockchain for privacy protection. Moreover, given the decentralized nature of our framework, it also overcomes the limitation of single point of failure. We implement a prototype of our framework using Ethereum blockchain and demonstrate its practical performance.
We consider IoT resources with a Trusted Execution Environment (TEE) and propose a model to provide trusted resource access that is linked to blockchain payments, ensuring the integrity and confidentiality of the IoT data. The model is built on the widely used OAuth 2.0 open authorization framework, which provides delegated authorization for IoT resources. We utilize hash-lock and time-lock mechanisms to cryptographically link trusted resource access, provided by the IoT resource's TEE, to authorization grants and blockchain payments. The model is implemented in the OP-TEE open source port for the Raspberry Pi that uses ARM's TrustZone and is evaluated on the Rinkeby public Ethereum testnet.
A blockchain based system integrity (BCSI) framework for assuring the integrity of information system processes is presented. BCSI is well suited for a broad class of large scale real-world information systems. Under the BCSI framework, the integrity of any information system I is assured by executing the finite state machine model for system I processes in a blockchain network. The BCSI framework is compared and contrasted with the Clark-Wilson (CW) system integrity model, and existing blockchain based frameworks like Ethereum.
Stored-value cards are used more and more widely. But there are some problems in the present stored-value card platform: 1. The service agreement of stored-value card is not clear enough; 2. The refund process of users is inconvenient; 3. The transfer of stored-value can not be realized among users; 4. The security of accounts is not guaranteed. Smart contracts are computer contracts written in code, which are enforced directly by computers. This paper proposes a stored-value card platform in which the service contracts are expressed with smart contracts. The smart contract is executed on the blockchain. Blockchain technology, in which accounts are decentralized and data is resistant to modification, is applied to improving reliability in the consumption process. The platform is built on the private blockchains of Ethereum, which is designed for small merchants. ECDSA (Elliptic Curve Digital Signature Algorithms) is used to asymmetrically encrypt accounts. Some functions, such as stored-value issuance, stored-value consumption, commodity purchase, are designed in this system.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Blockchains and smart contracts are an emerging, promising technology, that has received considerable attention. We use the blockchain technology, and in particular Ethereum, to implement a large-scale event-based Internet of Things (IoT) control system. We argue that the distributed nature of the "ledger," as well as, Ethereum's capability of parallel execution of replicated "smart contracts", provide the sought after automation, generality, flexibility, resilience, and high availability. We design a realistic blockchain-based IoT architecture, using existing technologies while by taking into consideration the characteristics and limitations of IoT devices and applications. Furthermore, we leverage blockchain's immutability and Ethereum's support for custom tokens to build a robust and efficient token-based access control mechanism. Our evaluation shows that our solution is viable and offers significant security and usability advantages.
Custom tokens are an integral component of decentralized applications (dapps) deployed on Ethereum and other blockchain platforms. For Ethereum, the ERC20 standard is a widely used token interface and is interoperable with many existing dapps, user interface platforms, and popular web applications (e.g., exchange services). An ERC20 security issue, known as the "multiple withdrawal attack", was raised on GitHub and has been open since November 2016. The issue concerns ERC20's defined method approve() which was envisioned as a way for token holders to give permission for other users and dapps to withdraw a capped number of tokens. The security issue arises when a token holder wants to adjust the amount of approved tokens from N to M (this could be an increase or decrease). If malicious, a user or dapp who is approved for N tokens can front-run the adjustment transaction to first withdraw N tokens, then allow the approval to be confirmed, and withdraw an additional M tokens. In this paper, we evaluate 10 proposed mitigations for this issues and find that no solution is fully satisfactory. We then propose 2 new solutions that mitigate the attack, one of which fully fulfills constraints of the standard, and the second one shows a general limitation in addressing this issue from ERC20's approve method.
Bitcoin, which emerged in 2008 and is now being used rapidly in various sectors, is a crypto currency. Bitcoin was revealed by Satoshi Nakamoto (who or who is not specific to the person or a group). An official or private regulator is exported independently of the institution and therefore has no guarantee. Bitcoin was first used in the market in 2009. Although more than one crypto currency has emerged, Bitcoin has maintained its leadership since its release. However, in the years ahead, another crypto currency, Ethereum, will also go ahead of Bitcoin. Although there are countries that are prohibited to be used in countries of the world, the number of countries in which it is used is increasing day by day. In Turkey, shipping fees, employee salaries, cost of books, such as food shopping are being used in many fields.
Blockchain is a technology that has been gaining attention lately. When this was written there were over 1600 different cryptocurrencies and 33 % of the bankers [45] expect commercial blockchain adoption by next year. It is imperative that we understand this technology, which is sure to be in our near future. In this work, we will focus on Bitcoin, Ethereum and Hyperledger Fabric, because they are respectively: a blockchain based purely on Proof of Work, a blockchain that is on the verge of transitioning from Proof of Work to Proof of Stake, with two main projects and a private blockchain.
There are more than 1 million smart contracts in Ethereum and the number of ethers managed by smart contracts has exceeded 100 million, but the security vulnerabilities in smart contracts seriously jeopardize the financial security of Ethereum users. Existing method for defect detection of smart contract bytecode using symbolic execution does not take care of the accuracy and detection realtime at same time. In this paper a smart contract bytecode defect detection algorithm based on parallel symbolic execution is proposed. We split a smart contract in units of functions by analyzing the smart contract function selection process. A symbolic execution tree is constructed for each function to predict the function execution path. Then we partition the symbolic execution tree into multiple sub-trees evenly. Finally, a process pool is used to perform parallel symbolic execution on those sub-trees to reduce the analysis time of smart contract defect detection. Experimental data shows our method has a significant improvement in detection efficiency compared with existing symbolic execution method. The speedup ratio is up to 3.1x in a 4-core computer. Besides, it does not introduce false positives or false negatives.
We present and evaluate models that allow clients to access IoT resources using secure and trusted device-to-device (D2D) communication, while utilizing smart contracts to obtain the benefits of blockchain technology. These benefits include decentralized trust, immutability, transparency, and high availability. The models consider different network connection capabilities of the clients and the IoT resources, namely continuous network connectivity and D2D-only connectivity. We describe two approaches for utilizing blockchains and smart contracts in the authorization process: in the first approach, only hashes of the authorization information are recorded on the blockchain. In the second approach, a smart contract handles authorization requests. We implement the approaches using the OAuth 2.0 delegated authorization framework and evaluate the implementations on the public Ethereum testnet Rinkeby, in terms of execution cost, contract creation cost, and delay. Our evaluation quantifies the tradeoffs of blockchain cost and smart contract functionality, such as blocking and non-blocking operation, and the reduction of the transaction cost that can be achieved when multiple authorization requests are concatenated in a single transaction.