Recently, Oblivious Storage has been proposed to prevent privacy leakage from user access patterns, which obfuscates and makes it computationally indistinguishable from the random sequences by fake accesses and probabilistic encryption. The same data exhibits distinct ciphertexts. Thus, it seriously impedes cloud providersâ efforts to improve storage utilization to remove user redundancy, which has been widely used in the existing cloud storage scenario. Inspired by the successful adoption of removing duplicate data in cloud storage, we attempt to integrate obliviousness, remove redundancy, and propose a practical oblivious storage, PEO-Store. Instead of fake accesses, introducing delegates breaks the mapping link between a valid access pattern and a specific client. The cloud interacts only with randomly authorized delegates. This design leverages non-interactive zero-knowledge-based redundancy detection, discrete logarithm problem-based key sharing, and secure time-based delivery proof. These components collectively protect access pattern privacy, accurately eliminate redundancy, and prove the data delivery among delegates and the cloud. Theoretical proof demonstrates that, in our design, the probability of identifying the valid access pattern with a specific client is negligible. Experimental results show that PEO-Store outperforms state-of-the-art methods, achieving an average throughput of up to 3 times faster and saving 74% of storage space.
In cross-silo federated learning (FL), organizations cooperatively train a global model with their local datasets. However, some organizations may act as free riders such that they only contribute a small amount of resources but can obtain a high-accuracy global model. Meanwhile, some organizations can be business competitors, and they do not trust each other or any third-party entity. In this work, our goal is to design a framework that motivates efficient cooperation among organizations without the coordination of a central entity. To this end, we propose a blockchain-empowered incentive mechanism framework for cross-silo FL. Under this incentive mechanism framework, we develop a distributed algorithm that enables organizations to achieve social efficiency, individual rationality, and budget balance without private information of the organizations. Our proposed algorithm has a proven convergence guarantee and empirically achieves a higher convergence rate than a benchmark method. Moreover, we propose a transaction minimization algorithm to reduce the number of transactions made among organizations in the blockchain. This algorithm is proven to achieve a performance no worse than twice the minimum value. The experimental results in a testbed show that our proposed framework enables organizations to achieve social efficiency within a relatively short iterative process.
Implementing federated learning within the Internet of Everything (IoE) framework poses substantial computational challenges, stemming from extensive client involvement, which can lead to escalated training expenses and diminished convergence rates. While many studies have investigated the combination of federated learning and blockchain networks, the integration of public and private chains to enhance federated learning performance remains largely unexplored. In this study, we introduce an innovative methodology that unifies public and private chains to mitigate clientsâ computational demands while preserving data privacy and security, demonstrating compatibility within the IoE milieu and yielding favorable outcomes. To facilitate secure model migration and expedite training without incurring excessive computation costs, we delineate a blockchain-anchored model migration scheme tailored for resource-limited IoT infrastructures, establishing a private chain mechanism to incentivize companies possessing multiple devices or clients to prioritize model training. Employing blockchain technology guarantees trustworthiness in model migration, precluding the disclosure of devicesâ confidential data. Overall, our innovative method provides an effective solution that improves the accuracy, privacy, and security of federated learning while reducing clientsâ computational burdens within the context of the Internet of Everything (IoE).
Soil is an indispensable resource with critical implications in various fields such as agriculture, environmental science, climate change, hydrology, ecology, and geoscience. Accuracy and accessibility of soil data are crucial for informed decision making. However, the sharing and harmonization of soil data present significant challenges, particularly owing to the lack of a comprehensive identification system that ensures privacy and stewardship in a federated data sharing framework. Moreover, the inherent heterogeneity of soil properties across space and time complicates the establishment of connections between soil profiles and their corresponding properties. To address these challenges, a novel and persistent soil-data identifier, called SoilPrint, akin to a fingerprint, was proposed. SoilPrint utilizes a mathematical algorithm to effectively integrate the properties of soil profile layers (SPLP) with Geohashes, providing an efficient solution. The incorporation of SoilPrint streamlines the data federation process within a secure and distributed ledger, eliminating the need for complex data mapping or alignment. This approach ensures data privacy throughout the sharing process and addresses concerns associated with data management. To demonstrate the practical applications of SoilPrint, a case study using soil data from Ontario, Canada was presented. The results underscored the unique identification capabilities of SoilPrint for soil profiles and their associated properties, establishing it a promising tool for soil data management. SoilPrint facilitates data tracking, reuse, and analysis, thereby enhancing the efficiency and effectiveness of soil-related research and decision-making processes.
Aman Mishra, Yash Garg, Om Jee Pandey, Mahendra K. Shukla ¡ 6 authors
At present, the centralized learning models, used for IoT applications generating large amount of data, face several challenges such as bandwidth scarcity, more energy consumption, increased uses of computing resources, poor connectivity, high computational complexity, reduced privacy, and large latency towards data transfer. In order to address the aforementioned challenges, Blockchain-Enabled Federated Learning Networks (BFLNs) emerged recently, which deal with trained model parameters only, rather than raw data. BFLNs provide enhanced security along with improved energy-efficiency and Quality-of-Service (QoS). However, BFLNs suffer with the challenges of exponential increased action space in deciding various parameter levels towards training and block generation. Motivated by aforementioned challenges of BFLNs, in this work, we are proposing an actor-critic Reinforcement Learning (RL) method to model the Machine Learning Model Owner (MLMO) in selecting the optimal set of parameter levels, addressing the challenges of exponential grow of action space in BFLNs. Further, due to the implicit entropy exploration, actor-critic RL method balances the exploration-exploitation trade-off and shows better performance than most off-policy methods, on large discrete action spaces. Therefore, in this work, considering the mobile scenario of the devices, MLMO decides the data and energy levels that the mobile devices use for the training and determine the block generation rate. This leads to minimized system latency and reduced overall cost, while achieving the target accuracy. Specifically, we have used Proximal Policy Optimization (PPO) as an on-policy actor-critic method with it's two variants, one based on Monte Carlo (MC) returns and another based on Generalized Advantage Estimate (GAE). We analyzed that PPO has better exploration and sample efficiency, lesser training time, and consistently higher cumulative rewards, when compared to off-policy Deep Q-Network (DQN).
Ahmed Didouh, Anthony Bahadir Lopez, Houda Labiod, Yassin El Hillali ¡ 6 authors
Vehicular communications have become essential for functional and road safety purposes due to the development of vehicle fleets. However, these communications have made vehicles more vulnerable to cyber-attacks. The security of data exchanges in vehicular networks currently relies on a centralized architecture that is responsible for managing various security services such as authentication, confidentiality, non-repudiation, real-time misbehavior detection, certificate management and revocation. However, this centralized approach can be challenging and costly for authorities, and it may even weaken the network's overall security. In this paper, we propose a complementary solution that uses a decentralized security framework to help authorities better manage their network security by involving each vehicle in the overall security management. Our framework, TileChain, is blockchain based solution that use road information to manage the network's security dynamically. The architecture is designed to optimize any security service efficiently. To demonstrate the feasibility and performance of our proposed solution, we selected certificate revocation as a critical service and performed simulations using real vehicle traffic data provided by The French road operator DIR Nord. Our Smart Contract achieved an accuracy of 81.3% in misbehavior detection, leading to certificate revocation. Furthermore, the computation load for security management by authorities potentially reduced by a factor of 96.8%. In summary, our proposed solution, TileChain, offers a promising decentralized approach for managing vehicular network security that can potentially improve the overall security of the network while reducing the computational burden on authorities.
In todayâs digital landscape, the exponential growth of data heightens security risks associated with traditional centralized storage systems. Utilizing blockchain technology, a shift towards decentralized data storage provides a more secure and private alternative. Central to our work is the exploration of symmetry in data management, a concept woven into the fabric of our proposed solution to challenge the inherency in InterPlanetary File System (IPFS) technology. Through the strategic utilization of smart contract-invoked random functions, our blockchain-based solution fragments and securely stores data in order to ensure a symmetrical balance between confidentiality and integrity. Our research endeavors are to contribute a robust, ethically grounded data storage framework fostering advancements in secure data sharing. The implications of this paper are significant in addressing contemporary challenges of data management within the expansive realm of big data.
This paper presents an in-depth examination of privacy-enhancing methodologies in machine learning. It highlights the integration of federated learning with cutting-edge encryption techniques and explores how blockchain architectures contribute to data privacy. A major focus is on federated learning, a decentralized model training strategy, and its combination with privacy-protecting technologies like Homomorphic Encryption, Differential Privacy, and Secure Multi-Party Computation. We emphasize that federated learning naturally improves data privacy and, when paired with cryptographic methods, increases resilience against data breaches and cyber-attacks. Additionally, this study explores the potential of blockchain in enhancing data privacy. Blockchain's immutable and transparent characteristics, supplemented with shuffling technology, zero-knowledge proofs, and ring signatures, improve the confidentiality and integrity of data transactions. The paper also emphasizes the critical need for transparency and explainability in machine learning, advocating for methods that demystify the decision-making processes of ML models. This transparency is crucial for building trust and is becoming a regulatory requirement in many industries. Furthermore, the paper discusses the importance of auditing in machine learning, highlighting the need for comprehensive model validation and ethical considerations. In conclusion, the paper argues that achieving a balance 1 between functionality and privacy in ML applications is essential. It suggests that a combination of federated learning, advanced cryptographic techniques, and explainable AI principles can create effective and privacy-respecting systems.
Yibing Li, Yangjie Cao, Yan Zhuang, Jie Li ¡ 6 authors
With the advancement of intelligent transportation systems, location-based services (LBS) have been widely applied in vehicular ad hoc networks (VANETs). LBS utilizes mobile devices to gather vehicle location data, which is then processed using relevant technologies. By combining this data with additional information, LBS offers users personalized and intelligent services. However, providing LBS brings critical security issues related to the exposure of vehicle positions, as well as privacy-preserving problems during the process of collecting location information in VANETs. We propose a distributed trust-based k anonymity scheme to address the aforementioned issues. Our proposed scheme adopts a trust framework among vehicles for various types of LBS. This framework involves a multiparty evaluation and consideration of trust value fluctuations to enhance the efficiency of establishing a reliable k anonymous cloaking region. Furthermore, by leveraging the tamper-proof and decentralized nature of blockchain, we employ a lightweight consortium blockchain to maintain the security of the trustworthiness data throughout the entire model. Extensive security analysis and rigorous experiments have been conducted to demonstrate that the scheme exhibits a certain degree of resilience against attacks on various trust models. Additionally, it has the ability to construct anonymous regions with limited time delay, thereby preserving the privacy of vehicle locations. In comparison to other schemes, it exhibits lower computational complexity and enhanced security.
Blockchain technology has been incorporated into the Healthcare Internet of Things (IoT) landscape as a revolutionary solution to tackle issues related to the sharing of medical records. This paper presents an innovative method that utilizes Temporal Blockchain for the purpose of Provenance Tracking. The introductory section provides context by delineating the significance of trust and transparency in medical data sharing within the healthcare IoT ecosystem. The study examines current blockchain solutions, delving into frameworks such as Hyperledger Fabric, Ethereum, Corda, and specialized approaches like temporal blockchain. The paper examines the difficulties associated with tracking the origin of data, concerns regarding privacy, problems related to scalability, and the need to comply with regulations. These challenges provide the context for the proposed methodology. The main emphasis is on Temporal Blockchain, integrating temporal elements to improve the tracking of origin and history. The evaluation parameters, such as security, provenance tracking, scalability, interoperability, privacy compliance, and performance, undergo a thorough assessment. The attained values demonstrate a strong emphasis on security at a high level, thorough tracking of origin and history, and strict adherence to privacy regulations. Nevertheless, the need for scalability and interoperability necessitates meticulous consideration. The study showcases the capacity of Temporal Blockchain to establish trust and enhance transparency in the sharing of medical records. The future scope focuses on tackling scalability challenges, improving interoperability, and making continuous optimization efforts. The proposed approach highlights notable accomplishments and emphasizes the continuous development and collaborative aspect of Blockchain-Based Medical Record Sharing in Healthcare IoT.
Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Artificial Intelligence in Healthcare and Education
Abstract The article aims to investigate the potential of blockchain technology in mitigating certain cybersecurity risks associated with artificial intelligence (AI) systems. Aligned with ongoing regulatory deliberations within the European Union (EU) and the escalating demand for more resilient cybersecurity measures within the realm of AI, our analysis focuses on specific requirements outlined in the proposed AI Act. We argue that by leveraging blockchain technology, AI systems can align with some of the requirements in the AI Act, specifically relating to data governance, record-keeping, transparency and access control. The study shows how blockchain can successfully address certain attack vectors related to AI systems, such as data poisoning in trained AI models and data sets. Likewise, the article explores how specific parameters can be incorporated to restrict access to critical AI systems, with private keys enforcing these conditions through tamper-proof infrastructure. Additionally, the article analyses how blockchain can facilitate independent audits and verification of AI system behaviour. Overall, this article sheds light on the potential of blockchain technology in fortifying high-risk AI systems against cyber risks, contributing to the advancement of secure and trustworthy AI deployments. By providing an interdisciplinary perspective of cybersecurity in the AI domain, we aim to bridge the gap that exists between legal and technical research, supporting policy makers in their regulatory decisions concerning AI cyber risk management.
The transition from patient-centered medical services to Health 5.0, which provides medical services to all customers using smart healthcare, has led to the use of the Internet of Things (IoT) for medical diagnosis and research based on the personal health records (PHR) of service users. However, PHR contain sensitive personal information, which can cause privacy issues. Additionally, as emergencies may occur in real medical environments, multi-authority delegation must be considered. Although various methods are being studied for data sharing, they often do not meet the necessary security requirements in a real PHR sharing environment. In this study, we propose a system that uses key aggregate searchable encryption (KASE) to satisfy security requirements and leverages blockchain and smart contracts to improve data integrity, data audit records, and transparency. We also propose a method that ensures the data subject rights of PHR data owners when delegating multiple rights using attribute tokens. We conduct formal and informal security analyses to verify the robustness of the proposed system against potential adversarial attacks. Finally, a performance evaluation is conducted to verify the effectiveness of the proposed scheme.
This paper presents a cryptographic solution for establishing trust in peer-to-peer (P2P) networks, addressing issues of privacy, performance, and anonymity. Our protocol utilizes Zero-Knowledge Proofs (ZKP) for continuous trust validation during data transfers. This procedure compels each node to continually demonstrate its integrity, significantly decreasing the potential for network at- tacks. Upon evaluation, the protocol proved to be highly scalable and efficient, expanding network reach without requiring additional control messages. This result validates the protocolâs robustness, suggesting its potential use in larger and more intricate P2P network architectures.
Blockchain as an open and immutable ledger is being posited as the next frontier in healthcare that will help solve the industry's interoperability challenges. However, immutability in processing personal data is no longer legal since the General Data Protection Regulation (GDPR) requires the âright to be forgottenâ as a critical data subject right. To observe such data regulation, it is desirable to build a healthcare blockchain with data redaction in a controlled way. Moreover, electronic health records (EHRs) usually are sensitive and the conventional blockchain lacks systematic and formal security analysis of data confidentiality, especially in the multi-user setting. Furthermore, EHRs are typically helpful in medical research for predicting epidemic diseases and valuable in insurance agencies making business plans. Hence, in healthcare blockchain systems, data confidentiality and flexible key distribution have become the most challenging issues that should be urgently resolved. In this paper, we propose a privacy-preserving and redactable healthcare blockchain system (PRHBS). Our solution offers fine-grained block-level data reduction and secure data sharing with flexible key distribution mechanisms. We give the formal definition and security models of PRHBS, and propose a generic construction based on trapdoor-based chameleon-hash function, attribute-based encryption, and puncturable encryption. We present formal security analysis and give an instantiation based on our proposed generic construction. The comprehensive comparison and experimental simulation demonstrate that our implementation exhibits comparable performance, while surpassing the most relevant solutions in terms of functionality.
The technological advancements in the field of E-healthcare have resulted in unprecedented generation of medical data which increases the risk of data security and privacy. Ensuring the privacy of Electronic Health Records (EHR) has become challenging due to outsourcing of healthcare information in the cloud. This increases the chance of data leakage to unauthorized users and affects the privacy and integrity of the user data. It requires a trustworthy central authority to protect the sensitive patient information from both internal and external attacks. This paper presents a blockchain based privacy preservation framework for securing EHR data. The proposed framework integrates the immutability and decentralized nature of blockchain with advanced cryptographic techniques to ensure the confidentiality, integrity and availability of EHR. The EHR data are stored in an InterPlanetary File System (IPFS) which is encrypted using a hybrid cryptographic algorithm. In addition, a novel smart contact based patient-centric access control is designed in this paper using a blockchain-based SHA-256 hashing algorithm to protect the privacy of patient data. The experimental results show that the proposed framework enables secure sharing of health information between network users with improved data privacy and security. Furthermore, the optimized search process reduces the time and space complexity compared to the traditional search process. Through the utilization of smart contracts, this framework enforces patient-centric access controls and allows patients to manage and authorize access to their medical data.
Jan 19, 2024¡Proceedings of the 2024 Guangdong-Hong Kong-Macao Greater Bay Area International Conference on Digital Economy and Artificial Intelligence
With the widespread application of blockchain technology, various range proof protocols based on zero-knowledge proofs have been proposed. However, existing range proof protocols suffer from issues such as high communication overhead and computational complexity. Therefore, this paper introduces an efficient and secure Zero-Knowledge Set Membership Proof Protocol (ZSMPP) to address these challenges. Building upon improvements to the proof structure of range proof protocols, the paper integrates the SM2 identity-based digital signature algorithm, effectively avoiding the time-consuming bilinear pairing operations and reducing computational costs. The proposed protocol offers an efficient and secure solution for the given problem. Experimental results demonstrate that, compared to protocols proposed by Bootle, Deng, Mao, and others, the protocol presented in this paper exhibits superior computational efficiency, providing an efficient and secure solution for data security and individual privacy protection in the digital age.
Abstract The most important and difficult challenge the digital society has recently faced is ensuring data privacy and security in cloudâbased Internet of Things (IoT) technologies. As a result, many researchers believe that the blockchain's Distributed Ledger Technology (DLT) is a good choice for various clever applications. Nevertheless, it encountered constraints and difficulties with elevated computing expenses, temporal demands, operational intricacy, and diminished security. Therefore, the proposed work aims to develop a Decentralized Identifiable Distributed Ledger TechnologyâBlockchain (DIDLTâBC) framework that is intelligent and effective, requiring the least amount of computing complexity to ensure cloud IoT system safety. In this case, the Rabin algorithm produces the digital signature needed to start the transaction. The public and private keys are then created to verify the transactions. The block is then built using the DIDLT model, which includes the block header information, hash code, timestamp, nonce message, and transaction list. The primary purpose of the Blockchain Consent Algorithm (BCA) is to find solutions for numerous unreliable nodes with varying hash values. The novel contribution of this work is to incorporate the operations of Rabin digital data signature generation, DIDLTâbased blockchain construction, and BCA algorithms for ensuring overall data security in IoT networks. With proper digital signature generation, key generation, blockchain construction and validation operations, secured data storage and retrieval are enabled in the cloudâIoT systems. By using this integrated DIDLTâBCA model, the security performance of the proposed system is greatly improved with 98% security, less execution time of up to 150 ms, and reduced mining time of up to 0.98 s.
Leiming Chen, Dehai Zhao, Liping Tao, Kai Wang ¡ 7 authors
Federated learning enables cooperative computation between multiple participants while protecting user privacy. Currently, federated learning algorithms assume that all participants are trustworthy and their systems are secure. However, the following problems arise in real-world scenarios: (1) Malicious clients disrupt federated learning through model poisoning and data poisoning attacks. Although some research has proposed secure aggregation methods to solve this problem, most methods have limitations. (2) Due to the variance in data quality and computational resources among participants, rewards cannot be distributed equally. Some clients also exhibit free-rider behavior, seeking to cheat the reward system and manipulate global models. Evaluating client contribution and distributing rewards also present challenges.To address these challenges, we design a trustworthy federated framework to ensure secure computing throughout the federated task process. First, we propose a malicious model detection method for secure model aggregation. Then, we also propose a fair method of assessing contribution to identify client-side free-riding behavior. Lastly, we develop a computation process grounded in blockchain and smart contracts to guarantee the trustworthiness and fairness of federated tasks. To validate the performance of our framework, we simulate different types of client attacks and contribution evaluation scenarios on several open-source datasets. The experiments show that our framework guarantees the federated taskâs credibility and achieves fair client contribution evaluation.