The redesign of cloud storage with the amalgamation of cooperative cloud and an immutable and unhackable distributed database blockchain thrives towards a strong CIA triad and secured data provenance. The conspiracy ideology associated with the traditional cloud has economized with cooperative cloud storage like Storj and Sia, decentralized storage, which allows renting the unused hard drive space and getting monetary compensation in an exchange with cryptocurrency. In this article, the authors explain how confidentiality, integrity and availability can be progressed with cooperative cloud storage along with tamper-proof data provenance management with ethereum smart contracts using zero-knowledge proof (ZKP). A contemporary architecture is proposed with regards to storing data on the cooperative cloud and collecting and verifying the provenance data from the cloud and publishing the provenance data into blockchain network as transactions.
Envisioned 5G use cases arise challenges around the realization of inter-domain relationships beyond traditional Border Gateway Protocol (BGP) peering, e.g. end-to-end service deployments tailored to specific business needs (a.k.a. slices). Blockchain technologies bring consensus among decentralized non-trusting counterparts as a shared ledger, offering potential approaches for multi-administrative domain networking seeking agile, transparent end-to-end sliceable Service Level Agreements (SLAs). This demo showcases an experimental prototype based on best of breed open source components (e.g., Ethereum, OVS, Neo4j, Ryu/OpenFlowv1.3, ARIA/TOSCA) illustrating blockchain Decentralized Application (DApp) functionalities for life cycle management of multi-administrative domain network services.
Yinghui Zhang, Robert H. Deng, Ximeng Liu, Dong Zheng
As a milestone in the development of outsourcing services, cloud computing enables an increasing number of individuals and enterprises to enjoy the most advanced services from outsourcing service providers. Because online payment and data security issues are involved in outsourcing services, the mutual distrust between users and service providers may severely impede the wide adoption of cloud computing. Nevertheless, most existing solutions only consider a specific type of services and rely on a trusted third-party to realize fair payment. In this paper, to realize secure and fair payment of outsourcing services in general without relying on any third-party, trusted or not, we introduce BPay, an outsourcing service fair payment framework based on blockchain in cloud computing. We first propose the system architecture, adversary model and design goals of BPay, then describe the design details. Our security and compatibility analysis indicates that BPay achieves soundness and robust fairness and it is compatible with the Bitcoin blockchain and the Ethereum blockchain. The key to the robust fairness and compatibility lies in an all-or-nothing checking-proof protocol and a top-down checking method. In addition, our experimental results show that BPay is computationally efficient. Finally, we present the applications of BPay in outsourcing services.
K. Aditya Shastry, H D Aishwarya, M Madhushree, P Pooja · 5 authors
The blockchain is a decentralized, distributed database. A decentralized application utilizing blockchain technology enables you to perform similar activities you would do today yet without a trusted outsider. It is a shared system, a peer-to-peer network. Blockchain solves primary issues like transparency, security, accessibility that are the fundamental issues in current law based races. Ethereum is a platform that can be utilized to assemble the decentralized application. The blockchain is a changeless record of exchanges (votes) that are distributed in the system. Everyone’s information that is the votes is stored in blockchain as transactions. The past votes can't be changed, while the present can't be hacked, on the grounds that each exchange is checked by each and every hub in the system. What's more, any outside or inside aggressor must have control of the hubs in the system to modify the record. Along these lines, every one of the exchanges stored on the blockchain is unchanged and thus this makes the application more secure in every aspect.
Jialiang Chang, Bo Gao, Hao Xiao, Jun Sun · 6 authors
Ethereum smart contracts are an innovation built on top of the blockchain technology, which provides a platform for automatically executing contracts in an anonymous, distributed, and trusted way. The problem is magnified by the fact that smart contracts, unlike ordinary programs, cannot be patched easily once deployed. It is important for smart contracts to be checked against potential vulnerabilities. In this work, we propose an alternative approach to automatically identify critical program paths (with multiple function calls including inter-contract function calls) in a smart contract, rank the paths according to their criticalness, discard them if they are infeasible or otherwise present them with user friendly warnings for user inspection. We identify paths which involve monetary transaction as critical paths, and prioritize those which potentially violate important properties. For scalability, symbolic execution techniques are only applied to top ranked critical paths. Our approach has been implemented in a tool called sCompile, which has been applied to 36,099 smart contracts. The experiment results show that sCompile is efficient, i.e., 5 seconds on average for one smart contract. Furthermore, we show that many known vulnerabilities can be captured if user inspects as few as 10 program paths generated by sCompile. Lastly, sCompile discovered 224 unknown vulnerabilities with a false positive rate of 15.4% before user inspection.
Today's banking system has seen revolutionary change within a decode or more. The foremost reason being the adaptation of information technology in the banking system. Although , this has strengthened the economy of our country, it has also led to many frauds and scams in the recent times. In this research paper, we have tried to collect information on the above events and tried to preview the actual positioning of India's banking system. There has also been some discussion on the understanding, growth, usability and adaptability of crypto currencies such as Bitcoins, Ethereum, Litecoin, Dash etc. The overall discussion helps us to understand how the inner complexities of Indian banking system is leading to consumer's thoughts and interest shifting towards crypto currency. Some suggestions have also been provided as different steps which can be taken in the present situation.
Innerhalb der letzten Jahre wurden Blockchain-Technologien in vielen traditionellen Sektoren (z.B. im Finanzbereich) adaptiert. Dadurch wurden existierende Systeme neu überdacht und ganzheitlich neuartige Systeme erfunden. Allerdings blieb während dieser Zeit des raschen Fortschritts der Fokus stets auf der schnellen Produktentwicklung, was zu vielen Sicherheitsproblemen geführt hat durch die mehrere hundert Millionen von USD gestohlen oder verloren wurden. Nahezu alle derzeitig öffentlichen Blockchains bieten keine formale Semantik oder formales Framework zur Verifizierung von Smart-Contract-Code. Diese Arbeit präsentiert eine neuartige Semantik für Smart-Contract-Interaktionen und eine state-of-the-art Implementierung eines smart-contract-basierenden Investmentfonds für die Ethereum Blockchain. Der Fokus liegt darauf, eine formale Semantik für Smart Contracts mit dem tatsächlichen, wirtschaftlichen Anwendungsfall eines Investmentfonds zu verbinden. Genauer gesagt, die eingeführte Semantik bietet einen neuartigen Denkansatz dadurch, dass sie Smart Contract Interaktionen und nicht einzelne Smart-Contract-Ausführungen in den Mittelpunkt stellt. Die Blockchain wird durch einen Global State repräsentiert, auf welchem komplexe Transaktionen durch eine Big-Step-Semantik modelliert werden können. Der im Laufe dieser Arbeit entwickelte Investmentfonds ERCFund macht es möglich, in ein aktiv verwaltetes Portfolio von ERC20-Tokens und Ether zu investieren. Dies wird realisiert durch Tokens, welche als Anteil des Investmentfonds genutzt werden und je nach Bedarf gemünzt und vernichtet werden können. Außerdem unterstützt die Software mehrere fortgeschrittene Funktionen, wie z.B. Cold-Wallet-Support und Multi-Signature-Schutz durch Off-Chain-Signaturen. Wir zeigen, dass die eingeführte Semantik in einer realen, geschäftlichen Situation anwendbar ist, indem wir eine wesentliche Sicherheitsfunktion des Investmentfonds adaptieren und formal beweisen.
Jonathan Coignard, Eric Munsing, Jason MacDonald, Jonathan Mather
The increased penetration of Distributed Energy Resources (DERs) on the distribution network creates local challenges in balancing consumption and generation. To coordinate the roll-out and the operation of DERs, distribution-level energy markets have been proposed, but there are currently few tools for simulating the operation of DERs in these proposed markets. We present a framework which utilizes a grid co- simulation platform (Mosaik) to simulation DER operation, while simulating market clearing operations with a blockchain network (Ethereum). The use of blockchains, an emerging technology for decentralized computing and data storage, allows us to model secure decentralized execution of market clearing functions and payment processes. By unifying simulation of market clearing rules and the physical grid, we are able to ensure that economic incentives are aligned with physical constraints, helping facilitate the development of more effective distributed energy markets. We demonstrate the use of this new simulation platform on a small feeder, for which a market mechanism to incentivize DER integration is explored.
Focusing on the overlapping areas of the logistics industry with a large number of mature blockchain applications and the public welfare industry that requires high transparency and credibility, this paper designs and implements an innovative philanthropy logistics platform based on blockchain technology through the Ethereum platform. Our platform makes use of the open, transparent, and irrevocable features of the blockchain, combined with a unique Responsibility Relay System and Evaluation and Reporting Mechanism, and can achieve the consistency of the data on the chain with real-world status, as well as the authenticity and transparency of philanthropy logistics data. This paper also establishes a model for evaluating philanthropy material donations for social welfare based on the classic network maximum flow algorithm. After four months of empirical analysis, we have concluded that the blockchain platform can greatly increase the user's trust in the project, enhance the system's cleanliness coefficient and increase the quality of philanthropically raised materials, thereby improving the public welfare of charitable donations. The paper draws the conclusion that this blockchain platform is a technical solution for maximizing social welfare.
Blockchain is a distributed system with efficient transaction recording and has been widely adopted in sharing economy. Although many existing privacy-preserving methods on the blockchain have been proposed, finding a trade-off between keeping speed and preserving privacy of transactions remain challenging. To address this limitation, we propose a novel Fast and Privacy-preserving method based on the Permissioned Blockchain (FPPB) for fair transactions in sharing economy. Without breaking the verifying protocol and bringing additional off-blockchain interactive communication, FPPB protects the privacy and fairness of transactions. Additionally, experiments are implemented in EthereumJ (a Java implementation of the Ethereum protocol) to measure the performance of FPPB. Compared with normal transactions without cryptographic primitives, FPPB only slows down transactions slightly.
Blockchains such as those used by the Bitcoin and Ethereum cryptocurrencies provide a global, observable record of all transactions and associated data. Analyzing blockchain data is useful for tasks such as detecting fraudulent activities, studying the use and growth of the system, and understanding its levels of anonymity and traceability. Such analysis is challenging due to the high volume and rapidly changing characteristics of popular blockchains. In particular, online (soft real-time) analysis of blockchains requires methods that adapt organically to changes in the data. This paper describes such a method based on self-organizing maps and reports on experiments using the Bitcoin blockchain data.
Blockchain Technology Applications and Security
Data Stream Mining Techniques
Advanced Steganography and Watermarking Techniques
Paul Sarda, Mohammad Jabed Morshed Chowdhury, Alan Colman, Muhammad Ashad Kabir · 5 authors
Current job recruitment process involves a good number of documentations. It is not uncommon for job applicants to misrepresent, overstate or falsify past employment, specifically work experience, and skills. Where this occurs and the applicant is subsequently appointed, a company may be exposed to significant commercial and legal risk. Companies usually employ third party HR recruitment agencies to verify the authenticity of an applicant's listed work experience. However, verification of applicant's past work experience is both time consuming and costly. Moreover, companies have to rely on the third parties, which may not be trustworthy. Therefore, small and medium size companies usually avoid the verification process. In this research, we demonstrate how blockchain technology can provide cost-effective, and real-time work history verification. The proposed approach also ensures trustworthy and privacy-preserving (work-history) data sharing. Furthermore, we have implemented a prototype to demonstrate how individuals can share and verify work history using Ethereum-based public blockchain.
With the development of computer and network technology, on-board computers have more stronger capability of computing and network communication. Multiple vehicles can form an Autonomous Vehicular Cloud (AVC) for the certain need to provide cloud computing services for customers. However, the infrastructure of AVC is open completely, how to guarantee the non-repudiation of task execution information is a very important issue during the process of task execution. Blockchain technology is a proven technology with information security and non-repudiation in distributed environments. Smart contract of Ethereum used to design a kind of task scheduling strategy which is suitable for the AVC environment in this paper. The strategy can guarantee the non-repudiation of task execution information. This paper builds the private chain of Ethereum on simulation vehicles node and creates and deploys the smart contract. Experiments show that the task scheduling strategy is very effective.
A trusted electronic election system requires that all the involved information must go public. However, it focuses not only on transparency but also on privacy issues. In other words, each ballot should be counted anonymously, correctly, and efficiently. In this work, an effective e-voting system is proposed for voters to minimize their trust in the authority or government. We ensure the transparency of election by putting all messages on the Ethereum blockchain; in the meantime, the privacy of individual voter is protected via an effective ring signature mechanism. Besides, the attractive self-tallying feature is also built in our system, which guarantees that everyone who can access the blockchain network is able to tally the result on his own, i.e., no third party is required after the voting phase. More importantly, we ensure the correctness of voting results and keep the Ethereum gas cost of individual participant as low as possible, at the same time. Moreover, the pre-described characteristics of stealth address in our system makes it more suitable for large-scale election on line.
Crypto currencies are considered as the next model of economics and monetary exchange. In recent years, popular cryptocurrency such as Bitcoin and Ethereum witness an exponential growth in economic sphere. In this paper empirical testing of four conventional machine learning methods is performed to predict the bitcoin prices using last eight years of transactional data. Linear and polynomial regression is implemented using all the features individually. Polynomial regression, Support Vector regression and KNN regression are hyper tuned with grid search logic. Results depicted that KNN regression outperformed others models in attaining mean square error of 0.00021.
Νικόλαος Αλεξόπουλος, Sheikh Mahbub Habib, Max Mühlhäuser
Authorization, and more generally Trust Management (TM), is an indispensable part of the correct operation of most IT systems. The advent of the Internet of Things (IoT), with its cyber-physical and distributed nature, creates new challenges, that existing TM systems cannot adequately address, such as for example the need for non-interactive exclusive access enforcement. In the meantime, a line of thought in the research community is that Distributed Ledgers (DLs), like the one implemented by the Ethereum blockchain, can provide strong security guarantees for distributed access control. However, this approach has not yet been examined in a scientific, systematic manner, and has many pitfalls, with arguably the most important one being scalability.
Peer-to-Peer (P2P) networking is a decentralized network topology that enables parties to communicate directly without central servers. The main obstacle preventing the heavy deployment of the P2P topology is the Network Address Translation (NAT) which serves as a solution for the exhaustion of IPv4 addresses. Methods proposed by the Internet Engineering Task Force (IETF) to solve the NAT traversal issues include Simple Traversal of UDP through NATs (STUN) and Traversal Using Relay NAT (TURN). STUN is limited by the type of deployed NAT, and TURN is limited by the peers' discovery mechanism which is application dependent. In this paper we propose a Blockchain-based platform that enables TURN servers to act as relays for Internet of Things (IoT) devices behind NAT. It also provides End-to-End (e2e) security for Constrained and Non-Constrained IoT devices. Results showed that the system has minimal impact on the existing network and can be a potential solution for advancing IoT deployment.
While blockchain services hold great promise to improve many different industries, there are significant cybersecurity concerns which must be addressed. In this paper, we investigate security considerations for an Ethereum blockchain hosting a distributed energy management application. We have simulated a microgrid with ten buildings in the northeast U.S., and results of the transaction distribution and electricity utilization are presented. We also present the effects on energy distribution when one or two smart meters have their identities corrupted. We then propose a new approach to digital identity management that would require smart meters to authenticate with the blockchain ledger and mitigate identity-spoofing attacks. Applications of this approach to defense against port scans and DDoS, attacks are also discussed.
Cryptocurrencies like Bitcoin not only provide a decentralized currency, but also provide a programmatic way to process transactions. Ethereum, the second largest cryptocurrency next to Bitcoin, is the first to provide a Turing-complete language to specify transaction processing, thereby enabling so-called smart contracts. This provides an opportune setting for attackers, as security vulnerabilities are tightly intertwined with financial gain. In this paper, we consider the problem of automatic vulnerability identification and exploit generation for smart contracts. We develop a generic definition of vulnerable contracts and use this to build TEE THER, a tool that allows creating an exploit for a contract given only its binary bytecode. We perform a large-scale analysis of all 38,757 unique Ethereum contracts, 815 out of which our tool finds working exploits for—completely automated.
Carlos Molina-Jiménez, Ioannis Sfyrakis, Ellis Solaiman, Irene C. L. Ng · 7 authors
Decentralised (on-blockchain) and centralised (off–blockchain) platforms are available for the implementation of smart contracts. However, none of the two alternatives can individually provide the services and quality of services (QoS) imposed on smart contracts involved in a large class of applications. The reason is that blockchain platforms suffer from scalability, performance, transaction costs and other limitations. Likewise, off–blockchain platforms are afflicted by drawbacks emerging from their dependence on single trusted third parties. We argue that in several applications, hybrid platforms composed from the integration of on and off–blockchain platforms are more adequate. Developers that informatively choose between the three alternatives are likely to implement smart contracts that deliver the expected QoS. Hybrid architectures are largely unexplored. To help cover the gap and as a proof of concept, in this paper we discuss the implementation of smart contracts on hybrid architectures. We show how a smart contract can be split and executed partially on an off–blockchain contract compliance checker and partially on the rinkeby ethereum network. To test the solution, we expose it to sequences of contractual operations generated mechanically by a contract validator tool.
We propose Parsec, a web-scale State channel for the Internet of Value to exterminate the consensus bottleneck in Blockchain by leveraging a network of state channels which enable to robustly transfer value off-chain. It acts as an infrastructure layer developed on top of Ethereum Blockchain, as a network protocol which allows coherent routing and interlocking channel transfers for trade-off between parties. A web-scale solution for state channels is implemented to enable a layer of value transfer to the internet. Existing network protocol on State Channels include Raiden for Ethereum and Lightning Network for Bitcoin. However, we intend to leverage existing web-scale technologies used by large Internet companies such as Uber, LinkedIn or Netflix. We use Apache Kafka to scale the global payment operation to trillions of operations per day enabling near-instant, low-fee, scalable, and privacy-sustainable payments. Our architecture follows Event Sourcing pattern which solves current issues of payment solutions such as scaling, transfer, interoperability, low-fees, micropayments and to name a few. To the best of knowledge, our proposed model achieve better performance than state-of-the-art lightning network on the Ethereum based (fork) cryptocoins.
In the era of the Internet of Things (IoT), smart connected devices have the ability to generate data that could be of interest to the public. This paves the way for an emerging market for monetized data exchanges, where IoT device owners can sell access to live data generated by their connected devices to interested users. Implementing a trusted, cost‐efficient, automatic monetization solution of IoT data can be a challenging problem and usually involves intermediaries and centralised governance and management. Blockchain and smart contracts introduce a secure and trusted platform to carry out transactions in a highly trusted, secure, decentralised manner. In this study, they present a blockchain‐solution and implementation using Ethereum smart contracts for monetizing IoT data with automated payment involving no intermediary. The authors discuss key aspects related to architectural design, entity relations, interactions among participants, logic flow, implementation and testing of the overall system functionality.
Stefano Angieri, Alberto García-Martínez, Bingyang Liu, Zhiwei Yan · 6 authors
The current system to manage the global pool of IP addresses is centralized\nin five transnational organizations, the Regional Internet Registries (RIRs).\nEach of these RIRs manage the address pool for a large number of countries.\nBecause the RIRs are private organizations, they are subject to the legal\nframework of the country where they are based. This configuration results in a\njurisdictional overflow from the legal framework of the countries where the RIR\nis based to all the countries that the RIRs are serving (the countries served\nby the RIRs de facto become subjects of the legal system of the country where\nthe RIR is hosted). The situation is aggravated by the deployment of new\nsecurity techniques such as the RPKI and BGPsec, that enable enforcement of\nallocations by the RIRs. In this paper we present InBlock, a blockchain-based\ndistributed governance body aimed to provide de-centralized management of IP\naddresses. InBlock also aims to fulfil the same objectives as the current IP\naddress allocation system, namely, uniqueness, fairness, conservation,\naggregation, registration and minimized overhead. InBlock is implemented as a\nDecentralized Autonomous Organization, i.e., as a set of blockchain's smart\ncontracts in Ethereum. Any entity may request an allocation of addresses to the\nInBlock registry by solely performing a (crypto)currency transfer to the\nInBlock. The fee required, along with the annual renewal fee, serves as a\nmechanism to deter stockpiling and other wasteful practices. As with any novel\ntechnology, there are many open questions about the usage of blockchains to\nbuild an IP address registry. For this reason, we believe that practical\nexperimentation is required in order to have hands-on experiences about such a\nsystem. We propose to conduct an experiment on distributed address management\nusing InBlock as a starting point to inform future directions in this area.\n