Andrea Flamini, Giada Sciarretta, Mario Scuro, Amir Sharif · 6 authors
Verifiable credentials are a digital analogue of physical credentials. Their authenticity and integrity are protected by means of cryptographic techniques, and they can be presented to verifiers to reveal attributes or even predicates about the attributes included in the credential. One way to preserve privacy during presentation consists in selectively disclosing the attributes in a credential. In this paper we present the most widespread cryptographic mechanisms used to enable selective disclosure of attributes identifying two categories: the ones based on hiding commitments - e.g., mdl ISO/IEC 18013-5 - and the ones based on non-interactive zero-knowledge proofs - e.g., BBS signatures. We also include a description of the cryptographic primitives used to design such cryptographic mechanisms. We describe the design of the cryptographic mechanisms and compare them by performing an analysis on their standard maturity in terms of standardization, cryptographic agility and quantum safety, then we compare the features that they support with main focus on the unlinkability of presentations, the ability to create predicate proofs and support for threshold credential issuance. Finally we perform an experimental evaluation based on the Rust open source implementations that we have considered most relevant. In particular we evaluate the size of credentials and presentations built using different cryptographic mechanisms and the time needed to generate and verify them. We also highlight some trade-offs that must be considered in the instantiation of the cryptographic mechanisms.
Christian Delgado‐von‐Eitzen, Luis Anido, Manuel J. Fernández Iglesias
The issuance and verification of academic certificates face significant challenges in the digital era. The proliferation of counterfeit credentials and the lack of a reliable, universally accepted system for issuing and validating them pose critical issues in the educational domain. Certificates, traditionally issued by centralized educational institutions using their proprietary systems, pose challenges for straightforward verification, generating uncertainty about the credibility of academic achievements. In addition to diplomas issued by academic entities, it is now necessary in virtually all professional fields to stay updated and obtain accreditation for certain skills or experiences, which is a determining factor in securing or enhancing employment. Yet, there is no platform available to consistently demonstrate these capabilities and experiences. This article introduces a novel model for issuing and verifying academic information using non-fungible tokens (NFTs) supported by blockchain technologies, focused on compliance with the General Data Protection Regulation (GDPR). It describes a model that grants control to the data subject, enabling the management of information access while adhering to key GDPR principles. Simultaneously, it remains compatible with existing systems within organizations, and is flexible in certifying various types of academic information. The implications of this model are discussed, emphasizing the importance of addressing privacy in blockchain-based applications.
Electronic tickets (e-tickets) are gradually being adopted as a substitute for paper-based tickets to bring convenience to customers, corporations, and governments. However, their adoption faces a number of practical challenges, such as flexibility, privacy, secure storage, and inability to deploy on IoT devices such as smartphones. These concerns motivate the current research on e-ticket systems, which seeks to ensure the unforgeability and authenticity of e-tickets while simultaneously protecting user privacy. Many existing schemes cannot fully satisfy all these requirements. To improve on the current state-of-the-art solutions, this paper constructs a blockchain-enhanced privacy-preserving e-ticket system for IoT devices, dubbed PriTKT, which is based on blockchain, structure-preserving signatures (SPS), unlinkable redactable signatures (URS), and zero-knowledge proofs (ZKP). It supports flexible policy-based ticket purchasing and ensures user unlinkability. According to the data minimization and revealing principle of GDPR, PriTKT empowers users to selectively disclose subsets of (necessary) attributes to sellers as long as the disclosed attributes satisfy ticket purchasing policies. In addition, benefiting from the decentralization and immutability of blockchain, effective detection and efficient tracing of double spending of e-tickets are supported in PriTKT. Considering the impracticality of existing e-tickets schemes with burdensome ZKPs, we replace them with URS/SPS or efficient ZKP to significantly improve the efficiency of ticket issuing and make it suitable for use on smartphones.
With the rapid development of artificial intelligence (AI) in the healthcare industry, the sharing of personal healthcare data plays an essential role in advancing medical AI. Unfortunately, personal healthcare data sharing is plagued by challenges like ambiguous data ownership and privacy leakage. Blockchain, which stores the hash of shared data on-chain and ciphertext off-chain, is treated as a promising approach to address the above issues. However, this approach lacks a flexible and reliable mechanism for incremental updates of the same case data. To avoid the overhead of authentication, access control, and rewards caused by on-chain data changes, we propose a blockchain and trusted execution environment (TEE)-based privacy-preserving sharing scheme for healthcare data that supports incremental updates. Based on chameleon hash and TEE, the scheme achieves reliable incremental updates and verification without changing the on-chain data. In the scheme, for privacy concerns, off-chain data are protected through symmetric encryption, whereas data verification, decryption, and computation are performed within TEE. The experimental results show the feasibility and effectiveness of the proposed scheme.
Realistic synthetic tabular data generation encounters significant challenges in preserving privacy, especially when dealing with sensitive information in domains like finance and healthcare. In this paper, we introduce \textit{Federated Tabular Diffusion} (FedTabDiff) for generating high-fidelity mixed-type tabular data without centralized access to the original tabular datasets. Leveraging the strengths of \textit{Denoising Diffusion Probabilistic Models} (DDPMs), our approach addresses the inherent complexities in tabular data, such as mixed attribute types and implicit relationships. More critically, FedTabDiff realizes a decentralized learning scheme that permits multiple entities to collaboratively train a generative model while respecting data privacy and locality. We extend DDPMs into the federated setting for tabular data generation, which includes a synchronous update scheme and weighted averaging for effective model aggregation. Experimental evaluations on real-world financial and medical datasets attest to the framework's capability to produce synthetic data that maintains high fidelity, utility, privacy, and coverage.
Aiming to address issues of query request submission, data transmission leakage, and vehicle privacy leakage caused by untrustworthy cooperating Partners (CPs) in privacy-preserving caching for Internet of Vehicles (IoV), this paper proposes a trust mechanism privacy protection scheme combining blockchain and multi-party evaluation (TMPP-BMPE). First, a data broadcasting mechanism is proposed based on the Paillier encryption algorithm and the Elliptic Curve Digital Signature Algorithm (ECDSA) for data protection. The homomorphic encryption algorithm and the ECDSA are applied for data privacy protection during transmission. Second, a trust mechanism based on multi-party assessment is proposed. The trustworthiness of CPs is comprehensively assessed considering assessment indicators from multiple entities, mitigating risks of interacting with untrustworthy CPs. Finally, a blockchain-assisted trust management scheme is designed to effectively prevent malicious tampering with trusted data. The simulation experiment results show that the TMPP-BMPE performs well in protecting data privacy, evaluating the trustworthiness of CPs, and preventing data tampering. It provides valuable insights for security and trust establishment in IoV.
Jie Cui, Yihu Zhu, Hong Zhong, Qingyang Zhang · 6 authors
Several studies have introduced edge computing and blockchain into the Industrial Internet of Things (IIoT) to satisfy the requirements of delay-sensitive applications and support cross-domain authentication. Although there have been many protocols to ensure the security and privacy of devices in the IIoT, existing protocols still suffer from problems. Updating keys and pseudonyms of devices by a trusted third party (e.g., certificate authority) will cause high communication and computation overhead, especially when the number of devices becomes much larger. Furthermore, an increasing number of transactions also cause high storage overhead on the blockchain. Therefore, we propose a blockchain-based cross-domain authentication protocol. Specifically, we propose a privacy-preserving method based on pseudonyms that offloads the task of generating pseudonyms from a trusted third party to edge servers to ensure the conditional anonymity of the devices. The device is allowed to request pseudonyms in bulk to reduce the number of transactions, thus reducing the storage overhead on the blockchain. Security analysis and experimental results demonstrate that our scheme achieves an efficient tradeoff between security and efficiency.
Considered to be the next-generation (NextG) Internet, the Metaverse faces various security risks inherited from its predecessor and new specialized threats. It is even more challenging to mitigate these issues in a large-scale setting with numerous wearable devices such as augmented, virtual reality (AR/VR) headsets. In this article, we aim to analyze the security aspect of the Metaverse thoroughly, focusing on blockchain and machine learning (ML) solutions. Firstly, we present a 4-layer architecture of the Metaverse and discuss potential solutions for Metaverse security based on blockchain and ML. Next, we develop a decentralized collaborative intrusion detection system (CIDS) based on blockchain and federated learning (FL) that allows such the Metaverse users to collaboratively protect this digital world. This helps solving the scalability and single-point-of-failure (SPoF) issues of traditional security approaches. Finally, we outline some key challenges and discuss future research directions for Metaverse security.
Marco Marcozzi, Ernestas Filatovas, Linas Stripinis, Remigijus Paulavičius
The consensus protocol plays a vital role in the performance and security of a specific Distributed Ledger Technology (DLT) solution. Currently, the traditional classification of consensus algorithms relies on subjective criteria, such as protocol families (Proof of Work, Proof of Stake, etc.) or other protocol features. However, such classifications often result in representatives with strongly different characteristics belonging to the same category. To address this challenge, a quantitative data-driven classification methodology that leverages machine learning—specifically, clustering—is introduced here to achieve unbiased grouping of analyzed consensus protocols implemented in various platforms. When different clustering techniques were used on the analyzed DLT dataset, an average consistency of 78% was achieved, while some instances exhibited a match of 100%, and the lowest consistency observed was 55%.
Federated learning (FL), as an effective method to solve the problem of “data island”, has become one of the hot and widespread concern topics in recent years. However, with the using of FL technology in the practical applications, an increasing number of FL tasks make the training management be more complex and the trade-off of multi-task becomes difficult. To overcome this weakness, this work proposes a privacy-preserving FL framework with multi-tasks using partitioned blockchain, which can run several different FL tasks by multiple requesters. First, a temporary committee is formed for an FL task to facilitating visualization, organization and management of security aggregation. Second, the proposed framework combines Paillier homomorphic encryption with Pearson correlation coefficient to protect users' privacy and ensure the accuracy of global model. Finally, a new blockchain-based reward method is presented to inspire participants to share their valuable data. The experimental results show that the global model accuracy of our proposed framework is able to reach 98.43%. Obviously, the proposed framework is more suitable for practical application environment, especially in industrial application field.
Federated Learning (FL) has recently arisen as a revolutionary approach to collaborative training Machine Learning models. According to this novel framework, multiple participants train a global model collaboratively, coordinating with a central aggregator without sharing their local data. As FL gains popularity in diverse domains, security, and privacy concerns arise due to the distributed nature of this solution. Therefore, integrating this strategy with Blockchain technology has been consolidated as a preferred choice to ensure the privacy and security of participants. This paper explores the research efforts carried out by the scientific community to define privacy solutions in scenarios adopting Blockchain-Enabled FL. It comprehensively summarizes the background related to FL and Blockchain, evaluates existing architectures for their integration, and the primary attacks and possible countermeasures to guarantee privacy in this setting. Finally, it reviews the main application scenarios where Blockchain-Enabled FL approaches have been proficiently applied. This survey can help academia and industry practitioners understand which theories and techniques exist to improve the performance of FL through Blockchain to preserve privacy and which are the main challenges and future directions in this novel and still under-explored context. We believe this work provides a novel contribution respect to the previous surveys and is a valuable tool to explore the current landscape, understand perspectives, and pave the way for advancements or improvements in this amalgamation of Blockchain and Federated Learning.
James Kolapo Oladele, Arnold Adimabua Ojugo, Christopher Chukwufunaya Odiakaose, Frances Uchechukwu Emordi · 8 authors
Blockchain platforms propagate into every facet, including managing medical services with professional and patient-centered applications. With its sensitive nature, record privacy has become imminent with medical services for patient diagnosis and treatments. The nature of medical records has continued to necessitate their availability, reachability, accessibility, security, mobility, and confidentiality. Challenges to these include authorized transfer of patient records on referral, security across platforms, content diversity, platform interoperability, etc. These, are today – demystified with blockchain-based apps, which proffers platform/application services to achieve data features associated with the nature of the records. We use a permissioned-blockchain for healthcare record management. Our choice of permission mode with a hyper-fabric ledger that uses a world-state on a peer-to-peer chain – is that its smart contracts do not require a complex algorithm to yield controlled transparency for users. Its actors include patients, practitioners, and health-related officers as users to create, retrieve, and store patient medical records and aid interoperability. With a population of 500, the system yields a transaction (query and https) response time of 0.56 seconds and 0.42 seconds, respectively. To cater to platform scalability and accessibility, the system yielded 0.78 seconds and 063 seconds, respectively, for 2500 users.
Secure deduplication over encrypted data can greatly improve cloud storage efficiency and protect data privacy. Recently, there have been some research efforts aiming at designing secure deduplication schemes with the assistance of key servers (KSs). However, prior works are unsatisfactory in that they suffer from some limitations such as security degradation (the leakage at partial KSs will lead to all the ciphertexts being subject to offline brute-force attacks) or lack of scalability for handling the change of KSs. In this paper, we propose a new secure deduplication scheme for large-scale cloud storage service, which, to our best knowledge, is the first server-aided scheme that supports both tolerance of partial KSs leakage and dynamic change of KSs. Our scheme divides all the KSs into multiple groups and each KS group keeps a randomly generated secret key using threshold cryptography. We design a file-related KS group selection mechanism for assisting encryption key generation, which guarantees that the identical files of different users can be encrypted using the same keys. Our scheme is designed to update the KS groups regularly for supporting the joining and leaving of the KSs as well as maintaining long-term security. We leverage the blockchain to help divide KSs into groups in a fair way and securely migrate group secret keys during KS group updating. Formal analysis is provided to verify the correctness of our scheme and justify its security, and both theoretical and experimental results demonstrate that it has modest performance overhead.
Federated learning-based medical data privacy sharing can promote the development of medical industry intelligence, but limited by its own security and privacy deficiencies, federated learning still suffers from a single point of failure and privacy leakage of intermediate parameters. To address these problems, this paper proposes a privacy protection framework for medical data based on blockchain and cross-silo federated learning, using cross-silo federated learning to establish a collaborative training platform for multiple medical institutions to enhance the privacy of medical data, introducing blockchain and smart contracts to realize decentralized federated learning to enhance trust between distrustful medical institutions and solve the problem of a single point of failure. In addition, a secure aggregation scheme is designed using threshold homomorphic encryption to prevent the privacy leakage problem during parameter transmission. The experimental and analytical results show that the accuracy of this paper’s scheme is consistent with the original federated learning scheme, effectively deals with the problems of single-point failure and inference attacks of federated learning, improves system robustness, and is suitable for medical scenarios with more stringent requirements on security and accuracy.
Yongkai Fan, Binyuan Xu, Linlin Zhang, Gang Tan · 7 authors
Model prediction based on machine learning is provided as a service in cloud environments, but how to verify that the model prediction service is entirely conducted becomes a critical challenge. Although zero-knowledge proof techniques potentially solve the integrity verification problem when applied to the prediction integrity of massive privacy-preserving Convolutional Neural Networks (CNNs), the significant proof burden results in low practicality. In this research, we present psvCNN (parallel splitting zero-knowledge technique for integrity verification). The psvCNN scheme effectively improves the utilization of computational resources in CNN prediction integrity, proving by an independent splitting design. Through a convolutional kernel-based model splitting design and an underlying zero-knowledge succinct non-interactive knowledge argument, our psvCNN develops parallelizable zero-knowledge proof circuits for CNN prediction. Furthermore, psvCNN presents an updated Freivalds algorithm for a faster integrity verification process. Experiments show that psvCNN is practical and efficient in terms of proof time and storage, generating a prediction integrity proof with a proof size of 1.2MB in 7.65s for the structurally complicated CNN model VGG16. psvCNN is 3765 times faster than the latest zk-SNARK-based non-interactive method vCNN, and 12 times faster than the latest sumcheck-based interactive technique zkCNN in terms of proving time.
With the Industrial Internet of Things (IIoT) continuing to expand, lots of data collection, exchange, and authentication generated from an increasing number of access devices is required with heterogeneity, multidimension, and multiobjective networks as its characteristics. However, traditional IIoT systems are vulnerable to security challenges, such as data leakage, theft, and tampering. As one of the most promising solutions, blockchain has played an essential role in ensuring security and transparency in the IIoT. But there are still some challenges that prevent the secure and effective implementation of blockchain-based IIoT systems in consensus security, consensus efficiency, and consensus application. To address these problems, we propose an effective security blockchain consensus algorithm for heterogeneous IIoT nodes aiming to defend against the consensus attack and improve consensus efficiency. First, we design a blockchain-based IIoT system architecture. Then, we present an identity authentication and transformation protocol to defend against consensus attacks. Furthermore, we introduce a method for constructing communication directed acyclic graphs (DAGs) and transaction set DAGs to enhance transaction throughput. Based on these two DAGs, we propose an efficient and security consensus algorithm (DAG-D). DAG-D employs transaction sets instead of single transactions or blocks, leveraging communication DAG propagation to swiftly confirm transaction set DAGs based on parent transactions for associated confirmation. Experimental results show that our proposed DAG-D outperforms DAG-M, DAG-Avalanche, and DAG-CoDAG, regarding transaction throughput, transaction latency, and communication overhead.
Federated learning (FL) has shown promise in smart industries as a means of training machine-learning models while preserving privacy. However, it contradicts FL’s low communication latency requirement to rely on the cloud to transmit information with data owners in model training tasks. Furthermore, data owners may not be willing to contribute their resources for free. To address this, we propose a single contract to dual contract approach to incentivize both model owners and workers to participate in FL-based machine learning tasks. The single-contract incentivizes model owners to contribute their model parameters, and the dual contract incentivizes workers to use their latest data to participate in the training task. The latest data draw out the trade-off between data quantity and data update frequency. Performance evaluation shows that our dual contract satisfies different preferences for data quantity and update frequency, and validates that the proposed incentive mechanism is incentive compatible and flexible.
Lu Zhou, Abebe Diro, Akanksha Saini, Shahriar Kaisar · 5 authors
Identity sharing systems, regardless of their architectural models, share common vulnerabilities. These systems compel users to divulge personal information and furnish proof of identity for accessing services, leaving them susceptible to data breaches that can culminate in identity theft and jeopardize online data security. While blockchain technology offers a potential remedy, delivering enhanced security, immutability, and traceability, it simultaneously raises pertinent concerns surrounding privacy and transparency. The integration of zero-knowledge proof (ZKP) technology has emerged as a promising solution, particularly in enhancing privacy within the transparent blockchain ecosystem. Our paper conducts an exhaustive survey of the existing literature, with a particular focus on the assimilation of ZKP technology into blockchain for the secure sharing of user identities. We undertake a critical evaluation of the advancements achieved in this domain, pinpoint the formidable challenges that must be confronted, and uncover nascent opportunities for further exploration. Our contribution transcends the realms of mere summarization and analysis; we go a step further by offering recommendations drawn from real-world case studies and delineating future research directions.
Abstract Timed-release encryption (TRE) is a cryptographic primitive that can control the decryption time and has significant application value in time-sensitive scenarios. To solve the reliability issue of nodes in existing TRE anonymous interaction schemes, we propose a blockchain-based TRE protocol for anonymous query time trapdoors. In our protocol, the recipient divides the encrypted trapdoor request information into n ciphertext fragments using secret sharing technology near the decryption time, and employs the idea of onion routing to perform layer-by-layer encryption, creating onion-type data transmitted through middlemen selected from the smart contract. After receiving the ciphertext fragments, the time server integrates them to obtain the trapdoor request information and returns the corresponding time trapdoor to the recipient. This allows the recipient to query any time trapdoor anonymously. Our protocol provides a normative design for the smart contract and specific constraints on the participants’ behavior. Compared with the related anonymous query trapdoor schemes, our protocol improves the probability of successful queries. Security analysis shows that our protocol can resist release-ahead attack, interruption attack, eavesdropping attack, and replacement attack. Performance analysis shows that our protocol outperforms related protocols regarding anonymity, efficiency, and flexibility, achieving highly efficient anonymous interactions. Finally, we conducted an experiment in the Ethereum Rinkeby test network. For the settings of ciphertext fragment number $$n=3$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"><mml:mrow><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:math> and ciphertext fragment threshold $$t=2$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"><mml:mrow><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:math> , the gas consumption for a user to execute the contract was $5.66, which was higher than the contract cost of related schemes, but the contract execution cost was within an acceptable range.
In recent years, Wireless Sensor Networks (WSNs) have become integral in various applications ranging from environmental monitoring to defense. However, the security and reliability of these networks remain a paramount concern due to their susceptibility to various types of cyber-attacks and failures. This paper proposes a novel integration of blockchain technology with WSNs to address these challenges. Blockchain, with its decentralized and tamper-resistant ledger, offers a robust framework to enhance the security and reliability of sensor networks. The study begins by analyzing the current security threats and challenges faced by WSNs, emphasizing the need for a solution that can ensure data integrity, confidentiality, and network resilience. We then introduce blockchain technology and discuss its key features such as decentralization, immutability, and consensus algorithms, which are beneficial in creating a secure and reliable WSN environment. Subsequently, we present a detailed architecture of how blockchain can be integrated with WSNs. This includes the deployment of a lightweight blockchain protocol suited for the limited computational resources of sensor nodes. We also explore the use of smart contracts for automated, secure data handling and network management within WSNs. To validate the proposed integration, we conduct a simulations based on network attacks. The results demonstrate significant improvements in the security and reliability of WSNs when blockchain is implemented. This is evidenced by enhanced resistance to common attacks, such as data manipulation and node compromise and increased network uptime.