With the spread of pragmatic approaches to blockchains and distributed ledger technologies (DLTs), the need to operate securely across multiple DLTs has become apparent. The class of operations that span two or more DLTs is generally referred to as interledger. Various interledger approaches have been proposed, researched and taken into use, including for example, atomic cross-chain transactions, sidechains, bridging approaches, ledger-of-ledger structures, and layered value transfer protocols, such as the W3C Interledger Protocol (ILP).In this demonstration, we exemplify ongoing work in our research group at Aalto University. We demonstrate how a resource-constrained IoT device may be made able to interact with an “IoT-friendly” ledger, with an interledger gateway service bridging to a public permissionless ledger. The demo use case reflects a scenario where an IoT device advertizes a service that is available for anyone on the Internet, pending a successful and validated payment has been made on the Ethereum ledger. This demonstration shows how this can be accomplished in an auditable and secure manner across ledgers using hashed timelock agreements (HTLAs) to provide payment escrow.
Vysakh Anilkumar, Joseph Antony Joji, Asif Afzal, Reshma Sheik
Blockchain technology has been shining like a star after the introduction and widespread acceptance of the Bitcoin, the very first cryptocurrency in people's everyday lives. At the beginning, Blockchain was used only for monetary transactions but studies have proven that it has many more applications. Blockchain platforms introduce a decentralized mode of control are rapidly being developed in the world on a large scale and their survey along with their characteristics are being discussed in this paper. But since developing Blockchain applications on a Blockchain network are more costly, there is a need for a simulation platform to refine and test the applications before it can be committed to the network There are a huge number of Blockchain simulation platforms available. The real task is to choose one among them that is best suited for decentralised application (DApp) developers. In this paper, a study is made using an E-voting application [7] to compare different Ethereum simulation platforms.
With the increasing electric vehicle (EV) integration, challenges arise in the operation of a distribution network in that charging numerous EVs at the same time may overload distribution facilities. The charging power should be distributed among the charging stations in such a way that both individual EV charging demands and security constraints are met. Meanwhile, there usually does not exist a coordinator over all EV charging stations. This paper proposes an EV charging coordination method by designing a charging power quota (permissible charging power of a charging station) trading platform on blockchain. After collecting the future charging demands from charging stations, the proposed platform distributes initial charging power quotas in an equitable and secure manner while considering facility ratings. Then, considering the elasticity of different charging stations, the platform allows EV charging stations to trade the initially-allocated charging power quota via a double auction. By matching the submitted offers and bids from charging stations, the optimal allocation of charging power quotas is realized. By designing corresponding smart contracts, a charging power quota allocation and trading platform is established based on the Ethereum blockchain, ensuring the transparency, trustfulness, and intelligence of the charging power quota trading. A case study based on an Ethereum private blockchain shows the fairness and efficiency of the proposed mechanism and the effectiveness of the method.
Christian Killer, Bruno Rodrigues, Burkhard Stiller
A cooperative network defense is one approach to fend off large-scale Distributed Denial-of-Service (DDoS) attacks. In this regard, the Blockchain Signaling System (BloSS) is a multi-domain, blockchain-based, cooperative DDoS defense system, where each Autonomous System (AS) is taking part in the defense alliance. Each AS can exchange attack information about ongoing attacks via the Ethereum blockchain. However, the currently operational implementation of BloSS is not interactive or visualized, but the DDoS mitigation is automated. In realworld defense systems, a human cybersecurity analyst decides whether a DDoS threat should be mitigated or not. Thus, this work presents the design of a security management dashboard for BloSS, designed for interactive use by cyber security analysts.
Z. Zinonos, Panayiotis Christodoulou, Andreas S. Andreou, Savvas A. Chatzichristofis
The IoT ecosystem is evolving quickly, developing several applications in different sectors. The majority of these applications use centralized infrastructures something that poses several challenges especially related to trust and data security. Recently, blockchain has been introduced as an effective solution to IoT applications trying to provide solutions to these challenges. In this paper, we introduce a new decentralized IoT application using blockchain technology, namely, ParkChain. The ParkChain application operates in a way that no one can delete, revert, hack or question the time a registered vehicle securely entered a parking area. In order to evaluate ParkChain, we have implemented the smart contract on top of Ethereum Blockchain along with a traditional Image Processing / Computer Vision approach for License Plate Recognition, and using a Raspberry Pi we control the access on a parking place. We report on several experiments that assess the performance of ParkChain application.
Open access
Vehicle License Plate Recognition
Smart Parking Systems Research
Advanced Steganography and Watermarking Techniques
William Pourmajidi, Lei Zhang, John Steinbacher, Tony Erwin · 5 authors
Logs contain critical information about the quality of the rendered services on the Cloud and can be used as digital evidence. Hence, we argue that the critical nature of logs calls for immutability and verification mechanism without the presence of a single trusted party. In this paper, we propose a blockchain-based log system, called Logchain, which can be integrated with existing private and public blockchains. To validate the mechanism, we create Logchain as a Service (LCaaS) by integrating it with Ethereum public blockchain network. We show that the solution is scalable (being able to process 100 log files per second) and fast (being able to "seal" a log file in 23 seconds, on average).
Internet of Things (IoT), an significant support for strategic emerging industries, is re-building industrial systems, such as transportation, healthcare and energy, while a number of new features and requirements like data cross-industry sharding appear in recent years. The emerging Blockchain technology has provided a promising opportunity to break information island and single-domain management in multi-domain IoT systems by leveraging distributed storage. On the other hand, the transaction consensus throughput in the mainstream blockchain systems, such as Ethereum and Fabric, is far from meeting the demand for massive data storage in time in multi-domain IoT systems. In this paper, we design a sharding protocol called MDIoTSP. The protocol first partitions the overall blockchains into many small shards, each of which generally recognized as a micro-blockchain according to the multiple domains, and then make the final consensus by merging the hash digests of the sub-blocks which generated from the shards for the multi-domain IoT blockchains ecosystem specifically. We also develop MicrothingsChains to run MDIoTSP in multi-domain IoT blockchains to prove our assumption that MDIoTSP scales up the transaction consensus throughput near linearly with the number of shards.
Andreas Schaufelbuhl, Sina Rafati Niya, Lucas Pelloni, Severin Wullschleger · 7 authors
Today's number of reputable academical publishers is dominated by few key players. This imbalance of supply and demand in publishing academic work makes the entire process inefficient. EUREKA is a blockchain-based scientific publishing platform, developed to address this imbalance. It offers the opportunity of a fair reward distribution for all contributors and immediate ownership rights to authors of an article. For the demonstration, the platform including the back-end and frontend integrated into the Ethereum blockchain is shown, and the interaction processes of users i.e., authors and reviewers are presented.
Recently, there has been increasing interest in employing blockchain in different applications, other than crypto-currencies. Blockchains allow a peer to peer distributed network where different nodes communicate with each other, in a trustless manner. Long Range Wide Area Network (LoRaWAN) is an Internet of Things (IoT) technology, which enables long range communication. Although LoRaWAN networks are secure, the LoRaWAN join procedure is susceptible to replay and jamming attacks. Moreover, trust between network server and LoRa end device is the basic foundation of LoRaWAN network however, the centralized nature of network servers raise trust issues between network operators and customers. To solve this problem, we propose a lightweight two factor authentication mechanism for LoRaWAN join procedure, based on blockchain technology. The proposed blockchain based framework provides an extra layer of security for LoRaWAN join procedure and build trust among LoRaWAN network components. The proposed framework is validated using the Ethereum blockchain. The results demonstrate that the proposed framework provides efficient system performance in terms of throughput and latency. The proposed blockchain architecture is a cost effective solution, which can be utilized in the LoRaWAN network with few network servers and LoRa end device, having no strict requirement of throughput and latency.
Among different concepts associated with the term blockchain, smart contracts have been a prominent one, especially popularized by the Ethereum platform. In this study, we unpack this concept within the framework of Transaction Cost Economics (TCE). This institutional economics theory emphasizes the role of distinctive (private and public) contract law regimes in shaping firm boundaries. We propose that widespread adoption of the smart contract concept creates a new option in public contracting, which may give rise to a smart-contract-augmented contract law regime. We discuss tradeoffs involved in the attractiveness of the smart contract concept for firms and the resulting potential for change in firm boundaries. Based on our new conceptualization, we discuss potential roles the three branches of government – judicial, executive, and legislative – in enabling and using this new contract law regime. We conclude the paper by pointing out limitations of the TCE perspective and suggesting future research directions.
Sina Rafati Niya, Danijel Dordevic, Atif Ghulam Nabi, Tanbir Mann · 5 authors
Supply Chain Tracking (SCT) is considered as a major challenge for stakeholders of heterogeneous production, processing, transporting, storing, and selling systems. Studies on solutions in SCT reveal that many centralized SCT applications lack a design, which can support or even enable main features of a reliable, transparent, and publicly accessible SCT system for end users. This work demonstrates the implementation of a SCT application which, employs SC on the Ethereum blockchain (BC). This Decentralized Application (Dapp) provides a hardware-and platform-independent approach that flexibly enables multiple object combinations and transformations to be tracked with a use case-agnostic design and utilization.
Outsourcing storage and computation to clouds is popular but also raises security concerns. Most existing solutions mainly focus on an honest-but-curious cloud server, while security designs against a malicious server have not drawn enough attention. Although there are a few works addressing the issue of verifiable designs that enable the data owner to verify the integrity of search results. Unfortunately, these verification schemes are not efficient and or applicable from one scenario to another. Motivated by this, in this paper, we propose a publicly verifiable search framework for outsourced encrypted data based on blockchain. In our framework, we store the encrypted index in a decentralized blockchain (Ethereum) while outsourcing the corresponding encrypted data to the cloud or Interplanetary File System (IPFS). Thus, once a user is authorized, he/she can get the query results and check the query integrity efficiently by the designed smart contract anytime without data owner being online. Besides, to guarantee the privacy of the data user in the Ethereum, we construct a stealth authorization scheme to achieve access authorization delivery. The security analysis and performance evaluation show that the proposed scheme is secure and practical for verification of encrypted data.
Following Bitcoin's Nakamoto Consensus protocol (NC), hundreds of cryptocurrencies utilize proofs of work (PoW) to maintain their ledgers. However, research shows that NC fails to achieve perfect chain quality, allowing malicious miners to alter the public ledger in order to launch several attacks, i.e., selfish mining, double-spending and feather-forking. Some later designs, represented by Ethereum, Bitcoin-NG, DECOR+, Byzcoin and Publish or Perish, aim to solve the problem by raising the chain quality; other designs, represented by Fruitchains, DECOR+ and Subchains, claim to successfully defend against the attacks in the absence of perfect chain quality. As their effectiveness remains self-claimed, the community is divided on whether a secure PoW protocol is possible. In order to resolve this ambiguity and to lay down the foundation of a common body of knowledge, this paper introduces a multi-metric evaluation framework to quantitatively analyze PoW protocols' chain quality and attack resistance. Subsequently we use this framework to evaluate the security of these improved designs through Markov decision processes. We conclude that to date, no PoW protocol achieves ideal chain quality or is resistant against all three attacks. We attribute existing PoW protocols' imperfect chain quality to their unrealistic security assumptions, and their unsatisfactory attack resistance to a dilemma between "rewarding the bad" and "punishing the good". Moreover, our analysis reveals various new protocol-specific attack strategies. Based on our analysis, we propose future directions toward more secure PoW protocols and indicate several common pitfalls in PoW security analyses.
Felix Franz, Tobias Fertig, Andreas E. Schütz, Henry Vu
In the late 90s the author Ian Grigg defined that smart contracts have to be human-readable like paper contracts while remaining processible by computer programs. The Ethereum Foundation has created a new programming language Solidity that can be used to implement smart contracts. However, the contracts are neither easy to implement nor easy-to-use by the common user. In order to enable users without programming skills to take advantage of the new technology, we propose a generator for smart contracts. Our prototype uses a configuration wizard to determine the requirements of the generated contract. Based on the official ERC Standards of the Ethereum community we will implement a prototype that can configure and generate customized contracts. Moreover, we are covering the challenges that we have to face in order to support automated test case generation and automated deployment processes.
Recently there have been many emerging innovated Blockchain applications in various sectors including healthcare. In this paper, we propose a role-based access control system, namely, RBAC-HDE, which harnesses the powerful features of Blockchain such as immutability and decentralization, in order to facilitate secure data exchange for healthcare. We design and implement an Ethereum-based testbed to demonstrate the basic idea. Our preliminary results have shown the feasibility and potential of this approach.
Satish Ganta, B. Rebekka, N. Gunavathi, B. Malarkodi
Identity Management is all about managing attributes of an entity, it can be an individual or organization. Network infrastructure and VNFs will come back from completely different suppliers, therefore it involves multi domain orchestration to run the VNFs and configuring traffic steering rules between the VNFs. Most Identity Management schemes nowadays centralized wherever one entity like a corporation owns and controls the system. For Multidomain Networking Environment like NFV requires a more sophisticated and decentralized Identity Management since it involves Life Cycle and Configuration of different entities (Hardware/Software/Firmware) from different domains or department within the same domain. So, Blockchain Technology will be right candidate for Identity Management in NFV Market place. In this paper we proposed a novel Identity Management Scheme for managing entities in a typical NFV Environment using Ethereum Blockchain.
Smart contracts have been widely used on Ethereum to enable business services across various application domains. However, they are prone to different forms of security attacks due to the dynamic and non-deterministic blockchain runtime environment. In this work, we highlighted a general miner-side type of exploit, called concurrency exploit, which attacks smart contracts via generating malicious transaction sequences. Moreover, we designed a systematic algorithm to automatically detect such exploits. In our preliminary evaluation, our approach managed to identify real vulnerabilities that cannot be detected by other tools in the literature.
Integrating the Industrial Internet of Things (IIoT) into supply chain management enables flexible and efficient on-demand exchange of goods between merchants and suppliers. However, realizing a fair and transparent supply chain system remains a very challenging issue due to the lack of mutual trust among the suppliers and merchants. Furthermore, the current system often lacks the ability to transmit trade information to all participants in a timely manner, which is the most important element in supply chain management for the effective supply of goods between suppliers and the merchants. This paper presents a blockchain-based supply chain management system in the IIoT. The proposed system takes advantage of blockchain technology in terms of its transparency and tamper-proof nature to support fair goods exchange between merchants and suppliers. Additionally, the decentralization and pseudonymity property will play a significant role in preserving the privacy of participants in the blockchain. In particular, fairness in the IIoT is first defined. Then, a design for a smart contract for fair goods exchange is presented to prevent malicious behavior through imposing penalties. The proposed system was prototyped on Ethereum and experiments were conducted to demonstrate its feasibility.
As a decentralized distributed ledger technology,the main function of blockchain is to reach a consensus among untrusted nodes.In the blockchain,a suitable consensus mechanism can improve the blockchain performance and guarantee transaction data security.This paper proposes a new solution strategy for the “nothing at stake” problem in the Proof of Stakes(PoS).This strategy allows voting nodes to send agreement disagreement votes.If the node votes for a fork and the fork wins,the node will gain the profit.Otherwise,if the node votes against a fork and the fork fails,the node will also gain the profit.A smart contract is deployed on the Ethereum platform to validate the voting strategy.Results show that the proposed strategy can run normally and the nodes finally reach consensus.
Shubhani Aggarwal, Mohammad Shojafar, Neeraj Kumar, Mauro Conti
Data Dissemination is the distribution of data/statistics to the end users. With the adoption of Internet of Drones (IoD) environment for data dissemination, an efficient scheme is proposed which provides data integrity, identity anonymity, authentication, authorization, accountability (AAA) to the system model. We propose a system model having Ethereum based public blockchain distributed network in order to secure drone communication for the data collection and transmission. The proposed model provides secure communication between the drones and the users in a decentralized way. In this paper, blockchain technology is used for the storage of collected data from the drones and update the information into the distributed ledgers to reduce the burden of drones. It also provides integrity, authentication, and authorization to the collected data by the drones in the system model. Motivated by this consideration, the goal of this paper is threefold. First, we select a forger node from the number of drones. Second, we create blocks and validate their processes. Third, we provide secure data dissemination by applying Proof-of-Stake consensus mechanism. Afterward, we evaluate the security of the presented system model compared against the corresponding ones of some state-of-the-art in terms of communication time/cost. The results confirm that our system model is reliable and scalable for data dissemination in the IoD environment.
Robert Norvill, Beltran Fiz, Radu State, Andréa Cullen
Ethereum smart contracts have become common enough to warrant the need for standards to ensure ease of use. The most well known standard was created for the emerging token ecosystem and the exchanges serving it: the ERC20 standard. In this work we use the function selectors present in Ethereum smart contract bytecode to define contract purpose. Contracts are clustered according to the selectors they have. A Reverse look-up from selectors to function names is used to label clusters. We use the function names in clusters to suggest candidates for ERC standardisation.
Michał Król, Alberto Sonnino, Mustafa Al-Bassam, Argyrios G. Tasiopoulos · 6 authors
As cryptographic tokens and altcoins are increasingly being built to serve as utility tokens, the notion of useful work consensus protocols is becoming ever more important. With useful work consensus protocols, users get rewards after they have carried out some specific tasks useful for the network. While in some cases the proof of some utility or service can be provided, the majority of tasks are impossible to verify reliably. To deal with such cases, we design “Proof-of-Prestige” (PoP)—a reward system that can run directly on Proof-of-Stake (PoS) blockchains or as a smart contract on top of Proof-of-Work (PoW) blockchains. PoP introduces “prestige,” which is a volatile resource that, in contrast to coins, regenerates over time. Prestige can be gained by performing useful work, spent when benefiting from services, and directly translates to users minting power. Our scheme allows us to reliably reward decentralized workers while keeping the system free for the end-users. PoP is resistant against Sybil and collusion attacks and can be used with a vast range of unverifiable tasks. We build a simulator to assess the cryptoeconomic behavior of the system and deploy a full prototype of a content dissemination platform rewarding its participants. We implement the blockchain component on both Ethereum (PoW) and Cosmos (PoS), provide a mobile application, and connect it with our scheme with a negligible memory footprint. Finally, we adapt a fair exchange protocol allowing us to atomically exchange files for rewards also in scenarios where not all the parties have Internet connectivity. Our evaluation shows that even for large Ethereum traces, PoP introduces sub-millisecond computational overhead for miners in Cosmos and less than 0.013$ smart contract invocation cost for users in Ethereum.