Provable data possession (PDP) is a crucial means of protecting the integrity of data in the domain of cloud storage. In the post-quantum era, the PDP scheme that uses lattices relies too heavily on the third-party auditor (TPA), which is not entirely trustworthy and is easily affected by a single point of failure. Moreover, the scheme often leads to the leakage of private user data while attempting to satisfy the demand for public verification. In response to the above problems, this paper designs a protocol for post-quantum privacy-preserving PDP and uses it to develop a scheme based on smart contracts. The proposed scheme has the characteristics of being post quantum and can satisfy the demand for public verification while preserving user privacy. The property of noninteraction of the protocol can reduce transaction fees incurred owing to the frequent operation of the blockchain, and the smart contract with a deposit mechanism can ensure fair payments to all parties. The results of a theoretical analysis and experiments show that the proposed scheme is highly secure and efficient.
[[abstract]]With the advancement and popularization of science and technology, much research explores the provision of health care services or health management with the assistance of information technology in addition to traditional clinical diagnosis. Personal Health Records (PHR) are available for personalized health record information in the autonomous management system. The personal health record system is to improve disease management or strengthen personal health management. However, users are concerned about the safety and confidentiality of PHR in healthcare systems. In 2008, the blockchain architecture was proposed by Satoshi as a peer-to-peer network architecture that contains a Distributed Ledger Technology (DLT). In this study, we proposed a blockchain-based PHR system using the homomorphic encryption to improve the privacy and security of the users. It allows a third party to perform operations on the ciphertext which can be retrieved correctly later, while the privacy and security of the nodes on the chain are ensured and provided for multiple users to protect the security of their information.
Alaa Haddad, Mohamed Hadi Habaebi, Fakher Eldin M. Suliman, Elfatih A. A. Elsheikh · 6 authors
Accessing healthcare services by several stakeholders for diagnosis and treatment has become quite prevalent owing to the improvement in the industry and high levels of patient mobility. Due to the confidentiality and high sensitivity of electronic healthcare records (EHR), the majority of EHR data sharing is still conducted via fax or mail because of the lack of systematic infrastructure support for secure and reliable health data transfer, delaying the process of patient care. As a result, it is critically essential to provide a framework that allows for the efficient exchange and storage of large amounts of medical data in a secure setting. The objective of this research is to develop a Patient-Centered Blockchain-Based EHR Management (PCEHRM) system that allows patients to manage their healthcare records across multiple stakeholders and to facilitate patient privacy and control without the need for a centralized infrastructure by means of granting or revoking access or viewing one’s records. We used an Ethereum blockchain and IPFS (inter-planetary file system) to store records because of its advantage of being distributed and ensuring the immutability of records and allowing for the decentralized storage of medical metadata, such as medical reports. To achieve secure a distributed, and trustworthy access control policy, we proposed an Ethereum smart contract termed the patient-centric access control protocol. We demonstrate how the PCEHRM system design enables stakeholders such as patients, labs, researchers, etc., to obtain patient-centric data in a distributed and secure manner and integrate utilizing a web-based interface for the patient and all users to initiate the EHR sharing transactions. Finally, we tested the proposed framework in the Windows environment by compiling a smart contract prototype using Truffle and deploy on Ethereum using Web3. The proposed system was evaluated in terms of the projected medical data storage costs for the IPFS on blockchain, and the execution time for a different number of peers and document sizes. The findings of the study indicate that the proposed strategy is both efficient and practicable.
Rahul Mishra, Dharavath Ramesh, Salil S. Kanhere, Damodar Reddy Edla
Public auditing and data deduplication are integral considerations in providing efficient and secure cloud storage services. Nevertheless, the traditional data deduplication models that support public auditing can endure the enormous waste of storage and computation resources induced through data redundancy and repeated audit work by multiple tenants on trusted third-party auditor (TPA). In this work, we introduce blockchain-based secure decentralized public auditing in a decentralized cloud storage with an efficient deduplication model. We employ blockchain to take on the task of centralized TPA, which also mitigates the implications of malicious blockchain miners by using the concept of a decentralized autonomous organization (DAO). Specifically, we employ the idea of redactability for blockchain to handle often neglected security issues that would adversely affect the integrity of stored auditing records on blockchain in decentralized auditing models. However, the proposed model also employs an efficient deduplication scheme to attain adequate storage savings while preserving the users from data loss due to duplicate faking attacks. Moreover, the detailed concrete security analysis demonstrates the computational infeasibility of the proposed model against proof-of-ownership, duplicate faking attack (DFA), collusion attack, storage free-riding attack, data privacy, and forgery attack with high efficiency. Finally, the comprehensive performance analysis shows the scalability and feasibility of the proposed model.
Zero-knowledge proof (ZKP) is a cryptographic protocol that allows one party to prove the correctness of a statement to another party without revealing any information beyond the correctness of the statement itself. It guarantees computation integrity and confidentiality, and is therefore increasingly adopted in industry for a variety of privacy-preserving applications, such as verifiable outsource computing and digital currency.
Ali Ghalehban Zanjanab, Navidreza Ahadi, Gladness L. Monametsi, Shahryar Sorooshian · 5 authors
scientific research is expanding at an astounding rate, introducing new and compounding existing challenges and exacerbating those that already exist with regard to peer review quality, scholarly publishing and the emergence of predatory journals, and challenges with academic integrity and frauds in publication. To address this problem, this article suggests using NFT (Non Fungible Token) as a new, less costly, and more equitable means of publishing when it comes to intangible property ownership and identification. Blockchain enables autonomous, decentralized data, eventually resulting in a shared infrastructure where transactions are recorded and preserved. Our method covers the whole spectrum of NFT capabilities for academic manuscripts and scholarly publications through a decentralised solution using open-access tools
Human-human or human-device communication has traditionally been the most prevalent kind of communication, however, the Internet of Things (IoT) promises to dramatically expand the Internet by enabling machinemachine (M2M) communication.The ever-increasing reliance on data to form the bases associated with decision-making processes requires data that can be trusted emanating from known devices.These devices often contain important and confidential data such as personal credentials, financial status, health data, and other private and sensitive data.Therefore, the integrity of these devices and associated data are imperative for further usage and processing.Moreover, due to the deployment and participation of a massive number of devices in the IoT ecosystem, management of identities and mitigating security vulnerabilities are two major challenges that must be addressed.The large majority of these devices are susceptible to breaches and malicious actions compromising the integrity of their data, therefore identity validation of these devices is crucial as it is a means to ensure whether data attained from these devices can be trusted.An innovative technology called blockchain has recently been developed to address several IoT security concerns and ensure the integrity of the data collected from these IoT devices.This paper proposes a technique for IoT identity management called PUF-based Device Identity Management (PUF-DIM) that employs Physical Unclonable Function (PUF) to perform device identity management to establish trust in the data associated with each device and a device's unique identifier.Moreover,a review of the major security problems with IoT and how blockchain plays a significant role in tackling those issues is discussed.Finally, a blockchain-based IoT data integrity technique is proposed for ensuring that IoT data is authentic and tamper-proof.The presented technique incorporates the consensus mechanism as well as the chain structure within the data integrity scheme for IoT.
Millions of individuals today utilize cryptocurrencies, which have a strong open-source community and payment network. The first study to predict cryptocurrency prices using news and social media emotion was published in In this paper, we apply sentiment analysis and machine learning principles to find the correlation between "public sentiment" and "market sentiment". We use twitter data to predict public mood and use the predicted mood and cryptocurrency financial news to predict the market movements.
The adoption of modern health records is growing more mature, yet security issues always accompany it. Interplanetary file system (IPFS) and blockchain are developing technologies with decentralization, distributed fault tolerance, and trustworthiness. Using IPFS and blockchain technology to tackle medical health record data security issues is a very promising trend, and it is presently being utilized to secure medical health record data security. This article first explains the idea of IPFS and highlights the classification of existing IPFS and blockchain techniques before briefly discussing distributed ledger to tackle the existing medical health record data security challenges and faults. Finally, to preserve medical health records, a new medical health record storage architectural model based on IPFS and blockchain technologies is presented.
The certificates of the Secondary School Leaving Certificate (SSLC), the Higher Secondary Leaving Certificate (HSLC), and academic certificates are all digitized at the academic institution and made available to the students in today’s digital environment. The rise in the number of security breaches creates a threat to the users’ right to privacy regarding their academic digital certificates. Validation and verification of the digital certificates is very challenging for the institution and the business. The system can able to give a digital certificate validation that is both safer and more efficient thanks to the use of blockchain technology. The purpose of this proposed system is to provide a suggestion for a certificate administration and verification system that, by using blockchain technology, has the ability to provide a viable answer for the problem of academic credential issuance and verification. Hash, public-private key cryptography, mining peer-to-peer networks, and proof of work are only few of the capabilities that are included in blockchain technology.
Perubahan teknologi semakin lama semakin pesat diberbagai bidang, termasuk teknologi digital yang merupakan revolusi dari teknologi analog dan elektronik. Dekade ini semua serba bermetamorfosis menjadi digital, termasuk akhirnya muncul uang digital, yaitu cryptocurrency. Cryptocurrency sebagai bentuk digital cash beroperasi dengan bantuan teknik yang disebut kriptografi. Kriptografi sendiri adalah proses yang menerjemahkan semua informasi yang dapat dibaca menjasi kode yang tidak dapat dipecah sama sekali. Cryptocurrency menggunakan blockchain sebagai buku utama, yang semua sistemnya dikelola oleh yang disebut penambang. Mata uang crypto memiliki sistem yang sedikit rumit yang tidak dengan mudah dapat dipahami, jadi pengetahuan tentang cryptocurrency mau tidak mau harus dipelajari, dipahami agar dalam implementasi tidak mengalami dampak yang merugikan. Jenis jenis cryptocurrency, serta kekurangan dan kelebihannya akan dikupas sekilas dalam artikel ini.
Authentication and authorization constitute the essential security component, access control, for preventing unauthorized access to cloud services in mobile cloud computing (MCC) environments. Traditional centralized access control models relying on third party trust face a critical challenge due to a high trust cost and single point of failure. Blockchain can achieve the distributed trust for access control designs in a mutual untrustworthy scenario, but it also leads to expensive storage overhead. Considering the above issues, this work constructed an authentication and authorization scheme based on blockchain that can provide a dynamic update of access permissions by utilizing the smart contract. Compared with the conventional authentication scheme, the proposed scheme integrates an extra authorization function without additional computation and communication costs in the authentication phase. To improve the storage efficiency and system scalability, only one transaction is required to be stored in blockchain to record a user's access privileges on different service providers (SPs). In addition, mobile users in the proposed scheme are able to register with an arbitrary SP once and then utilize the same credential to access different SPs with different access levels. The security analysis indicates that the proposed scheme is secure under the random oracle model. The performance analysis clearly shows that the proposed scheme possesses superior computation and communication efficiencies and requires a low blockchain storage capacity for accomplishing user registration and updates.
In recent years, the rapid and wide-ranging implementation of a cloud-based electronic healthcare record (EHR) storage system has shown significant advantages in effectively managing EHR for healthcare organizations and patients. However, in the cloud-based EHR storage model, the patients no longer have direct control of their EHR, whereas healthcare organizations may access the outsourced EHR whenever necessary. It may always cause severe security issues, specifically when healthcare organizations collude with the cloud service provider (CSP) to conceal any medical malpractice. Therefore, to deal with these significant concerns, we have introduced a novel blockchain based efficient tamper-proof model for EHR storage in decentralized InterPlanetary File System (IPFS) storage in the cloud - “TAC-EHR”. The key idea of the model is that every operation involves outsourcing EHRs and integrating these EHRs into a transaction on the public blockchain provides computationally unforgeability to the outsourced EHRs. Moreover, the proposed EHR storage model can also manage batch outsourcing, i.e., numerous EHR outsourcing for multiple patients by multiple doctors simultaneously, in an effective manner. The experimental and security analysis demonstrates that the proposed blockchain based cloud-assisted EHR storage model efficiently assures intractability computationally and outperforms the existing models in terms of computational and communication overhead.
Yijia Liu, Jie Wang, Zheng Yan, Zhiguo Wan · 5 authors
Internet of Things (IoT) aims to create a vast network with billions of things that can seamlessly create and exchange data, establishing intelligent interactions between people and objects around them. It is characterized with openness, heterogeneity, and dynamicity, which inevitably introduce severe security, privacy, and trust issues that hinder the widespread application of IoT. Trust management (TM) holds great promise in identifying malicious nodes, maintaining trust relationships, and enhancing system security. Traditional TM systems (TMSs) can be classified into centralized, semi-centralized, and distributed ones, all three of which suffer from critical challenges and thus are not sufficient for facilitating IoT development. Blockchain, as a disruptive technology, can help addressing the challenges of TM in IoT, thanks to its advanced features, such as decentralization, consistency, and tamper-proofing. As a result, blockchain-based TM (BC-TM) has been extensively studied in recent years to achieve decentralized TM in IoT. However, it still lacks a comprehensive survey on the current state of the arts. To fill this gap, in this article, we conduct a serious survey on BC-TM in IoT. We first propose a set of evaluation criteria that should be met by a TMS in IoT. Then, we propose a taxonomy of TMSs and continue with a thorough review on BC-TM in IoT by employing the proposed criteria. In the end, based on the review, a series of open issues are identified, and future research directions are suggested.
Dennis Krummacker, Benedikt Veith, Daniel Lindenschmitt, Hans D. Schotten
Abstract This manuscript investigates viable Distributed Ledger Technology (DLT) architecture approaches to be used as basis for the distribution of integrity verification data. We discuss what can be a Trust Anchor and how the property of trust can be enabled as a service for mobile communications infrastructures. This follows up on a preceding publication, in the course of which a service was developed that can be utilized to create trust and traceability in transactions between other services. Crucial for the integrity of such an audit trail is proof for which side was committing, in case a tampering was detected. For such verification in the aftermath, mechanisms for the distribution of meta data are necessary. Where our ultimate goal is to develop a versatile framework for Trust as a Service (TaaS), the work at hand contributes the investigation on header distribution. We put a major focus on providing Trust as a Service (TaaS) especially in the mobile communications domain since a reliable concept for trustworthiness is indispensable for the vision of organic infrastructures beyond 5G, which means that such networks are flexible regarding their composition and open for stakeholders.
Cloud computing promises great advantages in handling the exponential data growth. Secure deduplication can greatly improve cloud storage efficiency while protecting data confidentiality. In the meantime, when data are outsourced to the remote cloud, there is an imperative need to audit the integrity. Most existing works only consider the support for either secure deduplication or integrity auditing. Recently, there have been some research efforts aiming to integrate secure deduplication with integrity auditing. However, prior works are unsatisfactory in that they suffer from the leakage of ownership privacy and forgeability of auditing results for low-entropy data. In this paper, we propose a new scheme that delicately bridges secure deduplication and integrity auditing in encrypted cloud storage. In contrast with prior works, our scheme protects the ownership privacy and prevents the cloud service provider from forging the auditing results for low-entropy data. Furthermore, we propose a blockchain-based mechanism that helps to ensure key recoverability and reduce local storage cost of keys. Formal analysis is provided to justify the security guarantees. Experiment results demonstrate the modest performance overhead of our scheme.
A non-fungible token (NFT) references a data store location, typically, using a URL or another unique identifier. At the minimum, a NFT is expected to guarantee ownership and control over the tokenised asset. However, information stored on a third party data store may be copied and stolen. We propose a solution to give control back to the information owner by storing encrypted content on the data store and providing additional security against hacks and zero day exploits. The content on our data store is never decrypted or returned to its owner for decryption during rekeying. Also, the key size in our protocol does not increase with each rekeying. With this, we reduce the synchronisation steps and maintain a bounded key size.
Shams Mhmood Abd Ali, Mohd Najwadi Yusoff, Hasan Falah Hasan
The continuous advancements of blockchain applications impose constant improvements on their technical features. Particularly immutability, a highly secure blockchain attribute forbidding unauthorized or illicit data editing or deletion, which functions as crucial blockchain security. Nonetheless, the security function is currently being challenged due to improper data stored, such as child pornography, copyright violation, and lately the enaction of the “Right to be Forgotten (RtbF)” principle disseminated by the General Data Protection Regulation (GDPR), where it requires blockchain data to be redacted to suit current applications’ urgent demands, and even compliance with the regulation is a challenge and an unfeasible practice for various blockchain technology providers owing to the immutability characteristic. To overcome this challenge, mutable blockchain is highly demanded to solve previously mentioned issues, where controlled and supervised amendments to certain content within constrained privileges granted are suggested by several researchers through numerous blockchain redaction mechanisms using chameleon and non-chameleon hashing function approaches, and methods were proposed to achieve reasonable policies while ensuring high blockchain security levels. Accordingly, the current study seeks to thoroughly define redaction implementation challenges and security properties criteria. The analysis performed has mapped these criteria with chameleon-based research methodologies, technical approaches, and the latest cryptographic techniques implemented to resolve the challenge posed by the policy in which comparisons paved current open issues, leading to shaping future research directions in the scoped field.
Owing to the spread of COVID-19, the digitalization of various services is rapidly being promoted. In particular, online services such as obtaining a digital certificate (e.g., digital signature) from an authority are becoming increasingly important. Therefore, systems that can autonomously generate digital signatures are urgently required. However, the autonomous generation of signatures is difficult because the secret key for signatures must be strictly managed. Moreover, a decentralized autonomous systems should be publicly verifiable. Thus, schemes that preclude strict control of the secret key are desirable. In this study, we propose a new decentralized scheme that autonomously generates a digital signature without a secret key, using blockchain-based smart contracts. The fundamental concept behind our scheme is to eliminate secret keys by leveraging the closed nature of the processing operations of smart contracts within the blockchain; thus, the process of generating signatures and their output values satisfies the condition of immutability. Finally, we perform a security evaluation and feasibility study of our proposed scheme and show that it works securely on the Ethereum blockchain.
Arko Djajadi, Karunia Suci Lestari, Linda Evan Englista, Aldi Destaryana
The security and confidentiality of data are very important for institutions. Meanwhile, data fabrication or falsification of official documents is still common. Validation of the authenticity of documents such as certificates becomes a challenge for various parties, especially those who have to make decisions based on the validity of the document. Scanning-based signatures on printed and digital documents are still relatively easy to counterfeit and yet still difficult to distinguish from the original. The traditional approach is no longer reliable. Solutions to these problems require the existence of data security techniques, seamless online verification of the authenticity of printed documents, and e-certificates quickly. The objective of the study is to model the e-certificate verification process via blockchain and proof-of-stake consensus methods and use MD5 encryption. The data or identity listed on the e-certificate is secured with an embedded digital signature in the form of a QR code and can be checked for the truth online. A combination of technologies capable of suppressing or removing counterfeiting of digital assets will accelerate digital transformation across spectrums of modern life. The resulting architectural model can be used as a starting point for implementing a blockchain-based e-certificate verification and validation automation system.
The identity-based cryptography algorithm SM9 requires a trusted third-party key generation center KGC to generate the user's private key. This will bring the risks and problems of key escrow and single point failure. This paper proposes a distributed identity-based cryptography key management scheme. Participants generate partial identity private key and send to the user. The user locally generates its own identity private key. Meanwhile, the identity status data can be uploaded to the blockchain. This avoids the key escrowing problem, solves the single point failure and trust problem, and improves the system's availability and security. The proposed scheme has obvious advantages in terms of efficiency and bandwidth requirements.
Research efforts on Distributed Ledger Technologies (DLTs) for industrial applications have constantly been increasing over the last years. The use of DLTs in the Industry 4.0 paradigm provides traceability, integrity, and immutability of the generated industrial data. However, Industry 4.0 ecosystems are typically composed of multiple smart factory clusters belonging to several companies, which are immersed in constant interaction with other business partners, clients, or suppliers. In such complex ecosystems, multiple DLTs are necessarily employed to maintain the integrity of the data throughout the whole process, from when the data is generated until it is processed at higher levels. Moreover, industrial data is commonly heterogeneous, which causes compatibility issues, along with security and efficiency issues in the homogenization process. Thus, the data needs to be pre-processed and homogenized in a secure manner before being exploited. Consequently, in this work, we address the issues mentioned above by providing an industrial raw data pre-processing and homogenization process according to a standard data model. We employ decentralized blockchain oracles to guarantee the integrity of the external data during the homogenization process. Hereafter, we design an interoperable plant blockchain for trustworthy storage and processing of the resulting homogenized data across several industrial plants. We also present a prototype implementation of the aforementioned scheme and discuss its effectiveness. Finally, we design a monitoring scheme to overview the usage the performance of the architecture processes and identify possible performance and security issues.
Blockchain is emerging as one of the most promising and resourceful security technologies for cloud infrastructures. In a distributed database system, blockchain is used to store, read, and validate transactions. It can improve security, trustworthiness, and privacy by using an unchallengeable, shared distributed ledger on cloud nodes. Cloud-based healthcare systems (CHS) are vulnerable to various threats and attacks such as identity theft, medical fraud, insurance fraud, and alteration of critical patient data. Secure retrieval, access, and storage of data on CHS are necessary to protect critical medical data. Accordingly, the integrated cloud and BlockChain (ICBC) architecture emerge as a potential solution for shaping the next era of a healthcare system while providing efficient, secure, and effective patient care. In this context, this paper presents an in-depth exploration of advanced approaches to securing cloud-based healthcare data management systems using blockchain technologies. It provides a taxonomy and highlights the benefits and limitations of the approaches examined.