Umair B. Chaudhry, Aysha Kattakath Mulangat Hydros
Abstract Cyber security in the banking sector is of high importance nowadays. The rate of cyberattacks is spiking every year, and the implementation of strong cybersecurity models is required to ensure the confidentiality and integrity of data. Since protecting a bank requires a wide range of security practices, this paper focuses on protecting the bank resources from malicious actors and securing the transactions using a blockchain consensus mechanism that uses a zero‐trust security approach among the participants in the transaction. In addition to the framework, an algorithm for blockchain‐based online transactions was designed to make use of practical implementation in the future. The ideas formulated during the research and literature review were integrated to design the framework and the algorithm. The proposed framework ensures that the security of the banking sector can be enhanced by adopting the zero‐trust concept and blockchain technology. The consensus algorithms used for the transaction make it immutable and decentralized. Zero‐trust principles adopted in the model ensure the confidentiality and integrity of the banking system.
S. Geetha, R Naveenkumaran, Kaushik Selvaraju, C Kishore · 5 authors
As cloud-based data storage becomes increasingly prevalent, data breache risks and compromises of data grows. Data can be altered, and malevolent actors could take advantage of this. Clients require cloud services for different variety of applications. Cloud Service Providers ensure that the client data is correct and trustworthy. To address the issue, this paper proposes a solution that utilizes encryption and data verification to enhance data integrity and reduce vulnerability through the use of blockchain technology. Specifically, the proposed approach involves encrypting data and storing it on the Ethereum blockchain, allowing clients to quickly determine whether their data has been tampered with before the cloud service provider becomes aware of any potential security breaches. Even in cases where the data has been compromised, the proposed system enables clients to auto-verify data integrity, providing greater peace of mind and enhanced security. Overall, the proposed solution represents a promising approach for enhancing the security and integrity of data stored in cloud, and could be of significant value to individuals and organizations alike. This paper outlines the standards of data security and its ground-level implementation. The suggested system relies on a back-end service that uses a private cryptocurrency and does not require any advanced setup procedures. A wallet setup for the selected coin by the client is needed.
P D Prakruthi, K Yashawanth, D. L. Chethan, Bhuvan Kumar · 7 authors
AWS is an upcoming technology along with decentralized infrastructure. This knowledge is employed in variety of different domains including cloud computing, finance, energy, messaging and others. AWS really takes up vital part in military message passing which enables certainty and safety of messages by dodging changes created to data that is collected in blocks. AWS needs the access where each user is an authorized user. In this paper we will be proposing different cryptographic techniques along with AWS technology to ensure safe and secure passage of messages between different teams in the defence sector.
Shaima AL Amri, Leonardo Aniello, Vladimiro Sassone
The Ethereum blockchain is one of the main public platforms to run smart contracts and enable decentralised applications. Since data stored in a blockchain is considered immutable, smart contracts deployed in Ethereum are regarded as tamper-proof and therefore offer strong protection against attacks aiming at tinkering with the execution flow of an application. Yet, like any other software, a smart contract needs to be maintained over time to fix bugs or add new features. Deploying every updated version as a brand-new smart contract in Ethereum leads to problems such as migrating the contract state from the old version and enabling clients to point to the new version in a timely fashion. The OpenZeppelin framework addresses this limitation by providing libraries that enable the deployment of upgradeable smart contracts. This is achieved by relying on proxies that act as intermediaries between clients and smart contracts, allowing the latter to be updated transparently. In this paper, we present the upgradeable smart contract patterns supported by OpenZeppelin and compare them in terms of security, cost, and performance. To show this paradigm’s prevalence in Ethereum, we also analyse the usage of OpenZeppelin Upgradeable smart contracts over the last four years.
P. Chinnasamy, Ashwag Albakri, Mudassir Khan, A. Ambeth Raja · 6 authors
Healthcare comprises the largest revenue and data boom markets. Sharing knowledge about healthcare is crucial for research that can help healthcare providers and patients. Several cloud-based applications have been suggested for data sharing in healthcare. However, the trustworthiness of third-party cloud providers remains unclear. The third-party dependency problem was resolved using blockchain technology. The primary objective of this growth was to replace the distributed system with a centralized one. Therefore, security is a critical requirement for protecting health records. Efforts have been made to implement blockchain technology to improve the security of this sensitive material. However, existing methods depend primarily on information obtained from medical examinations. Furthermore, they are ineffective for sharing continuously produced data streams from sensors and other monitoring devices. We propose a trustworthy access control system that uses smart contracts to achieve greater security while sharing electronic health records among various patients and healthcare providers. Our concept offers an active resolution for secure data sharing in mobility computing while protecting personal health information from potential risks. In assessing existing data sharing models, the framework valuation and protection approach recognizes increases in the practicality of lightweight access control architecture, low network expectancy, and significant levels of security and data concealment.
Recent advancement in IoT technology has boosted the healthcare domain with enormous usage of IoT devices to provide elevated services to patients with chronic disorders on a real-time basis by the incorporation of IoT sensors on patients’ bodies. However, providing services ensuring security and maintaining the privacy of patients is a challenging task. Blockchain technology promises security in a distributed environment but popular consensus algorithms such as Proof of Work (PoW) and Proof of Stake (PoS) require huge computational resources and energy by making the IoT environment inefficient. This paper introduces a secure Practical Byzantine Fault Tolerance (PBFT) consensus-based lightweight blockchain algorithm for healthcare applications. To strengthen the PBFT consensus, highly trusted nodes were allowed to participate in the consensus algorithm using the Eigen Trust model and Verifiable Random Function (VRF) to select a random primary node from a group of trusted consensus nodes. The proposed algorithm is tested in a simulated environment and evaluated against the traditional PBFT consensus algorithm considering throughput, latency, and fault tolerance.
Linh Thủy Nguyễn, Lam Duc Nguyen, Thong Hoang, H. M. N. Dilum Bandara · 10 authors
The rise of data-sharing platforms, driven by public demand for open data and legislative mandates, has raised several pertinent issues. These encompass uncertainties over data accuracy, provenance and lineage, privacy concerns, consent management, and the lack of equitable incentives for data providers. The advanced nature of blockchain makes it well suited to address these concerns. Yet, the limitations of blockchains, particularly their restricted performance, scalability, and high cost, make them less adept at managing the four “Vs” of big data—volume, variety, velocity, and veracity. As the body of work proposing blockchain-based data-sharing solutions grows, so does the confusion in selecting between these platforms, particularly in terms of sharing mechanisms, services, quality of services, and applications. In this article, we aim to fill this knowledge gap through an in-depth survey of blockchain-based data-sharing architectures and applications. We first identify the key challenges of existing data-sharing techniques and lay out the foundations of blockchains. Our focus then shifts to the intersection of blockchain and data sharing, wherein we aim to clarify the existing landscape and propose a reference architecture for blockchain-based data sharing. Subsequently, we explore various industrial applications of blockchain-based data sharing, spanning healthcare, smart grids, transportation, and decarbonization. For each application, we draw from real-world deployments to present key lessons learned in the implementation of blockchain-based data sharing. Lastly, we shed light on current research challenges and open avenues for further study in this space. This article aims to serve as a comprehensive resource for researchers/practitioners looking to navigate the complex terrain of blockchain-based data-sharing solutions.
Abdul Mateen, Adia Khalid, Sihyung Lee, Seung Yeob Nam
Despite the rapid expansion in the insurance industry, many issues remain unresolved and may require immediate action. As the insurance sector continues to evolve with the development of new technologies, it faces more challenges, especially related to data security and fraud. The fraud-prevention data and tactics presently used by insurance firms are outdated and ineffective. Additionally, insurance firms have traditionally handled the settlement of all consumer claims through lengthy manual processes. These manual processes need to be changed to provide opportunities for insurance businesses to grow. In the case of vehicles, the information obtained from an automobile data recorder can be used as evidence. Data from automated vehicles are critical because they can help the police, law enforcement agencies, and insurance companies to reconstruct the events leading up to a collision. Insurance companies require the forensic analysis of accident videos, which is a time-consuming process and involves a large amount of storage. Due to hardware limitations and associated costs, the current standalone (and often dedicated) computing infrastructures used for this purpose are quite limited. Previous research focused on simple video analysis tasks within cloud computing and blockchain technology. The requirements for a large-scale auto-insurance system are quite high and need more thorough investigation. In this paper, a review of the contribution of recent approaches to storing accidental data in cloud computing using blockchain is provided. We focused on the latest cloud and blockchain studies related to auto-insurance along with the related issues and challenges. Some useful solutions and recommendations are provided to address the identified issues and challenges in the cloud-based and blockchain-based auto-insurance sector.
Blockchain provides trustworthy properties such as decentralization, traceability, and transparency, and has been applied in various fields. Given the complexity of guaranteeing the accuracy of the input data, erroneous data may be stored on the blockchain, making it hard to modify. As an effective solution, redactable blockchain allows on-chain data to be modified by introducing a chameleon hash function with a trapdoor, which enables on-chain erroneous data to be corrected. However, existing redactable blockchain solutions often require trusted third parties, have huge overhead, or lack effective accountability mechanisms to meet data security needs. Therefore, this paper proposes a secure, efficient and accountable data management scheme based on redactable blockchain. To cope with the possible frequent editing needs, we design an efficient and accountable distributed trapdoor recovery mechanism that reliably maintains data security while avoiding the security risks associated with centralized management. Various information during the trapdoor management process is also recorded on the chain as the basis for implementing accountability mechanisms. In addition, the one-time trapdoor technology allows the blockchain system to reduce the maintenance complexity of the system by eliminating the need to frequently update the system parameters when partial trapdoor information needs to be published. Theoretical and experimental results show that our scheme can achieve an efficient accountability mechanism while modifying the data on the chain at low cost.
Abstract The lattice-based cryptographic accumulators, which enable short zero-knowledge arguments of membership, have numerous applications in post-quantum privacy-preserving protocols. However, most efficient quantum-safe zero-knowledge arguments are PCP-based systems and rely on non-falsifiable assumptions. For non-PCP-based constructions using the state-of-the-art techniques on compressing lattice-based zero-knowledge proofs, the concrete size of the resulting proof for accumulators with $2^{32}$ members is at least 500 KB. In this paper, we propose a compact non-PCP zero-knowledge proof for the lattice-based Merkle-tree, which leads to an efficient post-quantum cryptographic accumulator. The complexity of our construction is logarithmic in $l\cdot n_{s}$, where $l$ and $n_{s}$ denote the depth of the underlying Merkle-tree and the size of a node, respectively, and the concrete size is only $143.7\ $KB when $l=32$. In particular, we provide an improved lattice-based Bulletproof with efficient knowledge extraction, which allows large challenge space but small soundness slack. Furthermore, the amortized technique can be applied to the Bulletproof without breaking the knowledge soundness due to our improved knowledge extraction. As a direct application, we present a practical lattice-based ring signature, which can achieve logarithmical signing/verifying computational complexity with the number of the ring, while the state-of-the-art constructions (CRYPTO 21) have linear computational complexity.
Yuri Bespalov, Lyudmila Kovalchuk, Hanna Nelasa, Roman Oliynykov · 5 authors
Sidechains are among the most promising scalability and extended functionality solutions for blockchains. Application of zero knowledge techniques (Latus, Mina) allows for reaching high level security and general throughput, though it brings new challenges on keeping decentralization where significant effort is required for robust computation of zk-proofs. We consider a simultaneous decentralized creation of various zk-proof trees that form proof-trees sequences in sidechains in the model that combines behavior of provers, both deterministic (mutually consistent) or stochastic (independent) and types of proof trees. We define the concept of efficiency of such process, introduce its quantity measure and recommend parameters for tree creation. In deterministic cases, the sequences of published trees are ultimately periodic and ensure the highest possible efficiency (no collisions in proof creation). In stochastic cases, we obtain a universal measure of prover efficiencies given by the explicit formula in one case or calculated by a simulation model in another case. The optimal number of allowed provers’ positions for a step can be set for various sidechain parameters, such as number of provers, number of time steps within one block, etc. Benefits and restrictions for utilization of non-perfect binary proof trees are also explicitly presented.
Alexander Bernauer, Sofia Faro, Rémy Hämmerle, Martin Huschenbett · 11 authors
Distributed ledger technologies, also known as blockchains for enterprises, promise to significantly reduce the high cost of automating multi-party business workflows. We argue that a programming language for writing such on-ledger logic should satisfy three desiderata: (1) Provide concepts to capture the legal rules that govern real-world business workflows. (2) Include simple means for specifying policies for access and authorization. (3) Support the composition of simple workflows into complex ones, even when the simple workflows have already been deployed. We present the open-source smart contract language Daml based on Haskell with strict evaluation. Daml achieves these desiderata by offering novel primitives for representing, accessing, and modifying data on the ledger, which are mimicking the primitives of today's legal systems. Robust access and authorization policies are specified as part of these primitives, and Daml's built-in authorization rules enable delegation, which is key for workflow composability. These properties make Daml well-suited for orchestrating business workflows across multiple, otherwise heterogeneous parties. Daml contracts run (1) on centralized ledgers backed by a database, (2) on distributed deployments with Byzantine fault tolerant consensus, and (3) on top of conventional blockchains, as a second layer via an atomic commit protocol.
Justice Odoom, Huang Xiao-fang, Samuel Akwasi Danso, Benedicta Nana Esi Nyarko
Recently, blockchain technology has garnered support. However, an attenuating factor to its global adoption in certain use cases is privacy-preservation owing to its inherent transparency. A widely explored cryptographic option to address this challenge has been ring signature which aside its privacy guarantee must be double spending resistant. In this paper, we identify and prove a catastrophic flaw for double-spending attack in a Lightweight Ring Signature scheme and proceed to construct a new, fortified commitment scheme using the signer’s entire private key. Subsequently, we compute a stronger key image to yield a double-spending-resistant signature scheme solidly backed by formal proof. Inherent in our solution is a novel, zero-knowledge-based, secured and cost-effective smart contract for public key aggregation. We test our solution on a private blockchain as well as Kovan testnet along with performance analysis attesting to efficiency and usability and make the code publicly available on GitHub.
Feruz K. Elmay, Mohammad Madine, Khaled Salah, Raja Jayaraman
The distribution, traceability, and management of shipping container logistics require secure data flow and trusted transactions. Digital Twins (DTs) can realize these features by offering shipping tracking and traceability, process flow and status monitoring, and management of the physical containers all in a remote manner. However, the data of a DT itself is typically stored, controlled, and managed by a centralized entity, which is often the original creator of the physical container. Having a centralized entity can cause mistrust. The centralized entity may alter, tamper, or delete the digital twin data. To overcome this problem, this paper proposes trusted sharing and management of DTs for shipping containers by using Non-Fungible Tokens (NFTs). NFTs are digital tokens that hold unique data stored, controlled, and managed in a decentralized and immutable blockchain ledger. We extend in this paper the use of NFTs to tokenize shipping container DTs and their metadata. The proposed solution uses NFTs and Ethereum blockchain smart contracts to offer decentralization, security, transparency, traceability, and immutability to the data and processes involved in the creation, storage, and management of DTs of shipping containers. To demonstrate our solution, we create a DT of a shipping container using Microsoft Azure Digital Twins services and showed how to tokenize it using NFT. We assess the system using various test cases to evaluate its main functionalities. Furthermore, we analyze the cost of transactions and the security of the smart contracts code. We have made the code of our smart contracts publicly available on GitHub.
Educational Documents and Certificates are a proof of professional achievements for anyone. Without these documents, it is not possible to start your career and hence play a very important role in everyone's professional life. Till date, Colleges, Universities and various educational institutes issue paper based degrees and certificates which are prone to get damaged or may be lost. The other drawback is that this process of issuing of degrees and manual process of verification of those documents by third parties is a time taking and cumbersome process. The employers take a lot of time for verifying these paper based degrees and certificates before they give the job offer. Forgery of paper based documents is also easier and has led to many educational scams. This paper aims to give the solution to the problems mentioned above through Blockchain Implementation. Block chain technology is not only limited to crypto currencies but is also of great applications in various fields like health, supply chain management, finance, etc. It has disrupted the traditional education system. This paper highlights as to how the educational certificates can be verified using the Ethereum platform and smart contracts. The traditional paper certificates would be converted to digital certificates on student's request, their hash value would be calculated using cryptographic hash functions and stored on Blockchain. A unique certificate ID and transaction hash value would be generated which would then be used to verify the certificates through a common platform.
Bin Qian Bin Qian, Yi Luo Bin Qian, Jiaxiang Ou Yi Luo, Yong Xiao Jiaxiang Ou · 5 authors
<p>As a new-style smart grid, Internet of Energy (IoE) is important and how to provide its trusted time-stamping service becomes a hit. For example, an energy provider needs to prove he/she transferred some energy to a consumer at some time. Nevertheless, traditional trusted time-stamping scheme with a central service provider is not suitable for IoE. Some researchers try to solve this problem via blockchain, due to its decentralization, traceability and tamper-proof. However, there are still chal&shy;lenges when using blockchain. Some have to introduce another kind of central participant. Some have to face the problem of accuracy and availability when using the Bitcoin blockchain. Some have to generate too many extra transactions. To address the aforementioned problems, we propose a fully decentralized trusted time-stamping scheme without any central participant and fulfill six design goals. Compared with the state-of-the-art blockchain-based time-stamping scheme named Chronos, our scheme enjoys less cryptographic operations. We then tested our scheme in the development (local) network and two live networks of the Ethereum. The experiment shows that we have implemented a simple, effective, accurate and low-cost decentralized trusted time-stamping scheme.</p> <p>&nbsp;</p>
Data integrity and tamper-proofing are of paramount importance in legal documents. To mitigate these issues of data tampering and data corruption in a centralized system, blockchain technology and Non-fungible tokens can be used. Blockchain is used to establish a trust-less system, eliminating the need for a facilitator or a centralized body to validate the correctness of data. Non Fungible Tokens can be used for their properties of immutability. The limitations of traditional NFTs such as data security and data corruption in a centralized and decentralized storage services are also discussed and a new method for data storage is proposed, i.e. On-Chain NFTs and their possible advantages and disadvantages, and how they provide an additional layer of security, making it more reliable than our current Off-Chain Non Fungible Token standards. Three novel approaches have been proposed, along with their respective pros and cons.
Zero-knowledge proof is one of the techniques implemented in a variety of data security applications. ZKP is a security procedure between two parties, one as the prover and the other as the verifier. The prover and the verifier exchange information without allowing any kind of sensitive information to leak. In this paper, we mention the challenges and limitations that face the zero-knowledge technique when utilized in authentication and privacy protection processes in different environments. We help to produce improvements to the most common zero-knowledge protocol to show many factors that would have greatly contributed to the success of the authentication process.
Joshua Roberts, Joanna F. DeFranco, D. Richard Kuhn
Distributed ledger technology (DLT) , including blockchain, has a number of properties that make it useful for distributed systems. However, the immutability of blockchain and most forms of DLT make it impossible to delete data, as is required for compliance with many privacy rules regarding personally identifiable information. Thus, there is a need for DLT that can provide the integrity-preserving property of DLT while also allowing support for privacy rules. The data block matrix (DBM) is a variant of distributed ledger technology. It provides the integrity assurance of blockchain but allows for controlled revision or deletion of data. This property is essential for using DLT in applications that must guarantee privacy requirements by the deleting of a user's private data at their request. The DBM design solves the blockchain privacy conflict thus expanding the range of blockchain applications by also allowing exception management. It has been implemented and is available ( https://csrc.nist.gov/projects/redactable-distributed-ledger ) as a configurable option for Hyperledger Fabric (HF) , with a proof-of-concept application for data sharing in a health care environment. Other potential applications include logistics management and digital currency. This paper will cover the DBM properties and data structure, the DBM implementation in HF, and a use case and application design of the DBM implementation using the pharmaceutical industry supply chain.