With the development of various applications of blockchain, blockchain-assisted searchable encryption technology has received wide attention as it can eliminate misbehaviours of malicious servers through the verification and incentive mechanism of blockchain. However, most existing solutions update the encrypted data by means of appending new transactions, which does not scale and wastes resources. In this paper, we explore the potential of redactable blockchain and propose a privacy-preserving dynamic searchable encryption framework (DSE-RB), which is a general scheme that guarantees reliable queries and updates on encrypted data. In particular, we first use transaction-level editing technology to achieve a more flexible update operation of encrypted data without additional transactions while avoiding the waste of storage on the chain. To better support practical applications, we use an index partition method to divide the traditional binary tree index into a plurality of sub-indexes and introduce the concept of polynomials to simplify the whole access control mechanism. We define the security model and conduct repeated experiments on real data sets to test the efficiency. Experimental results and theoretical analysis show the practicability and security of our scheme.
The Distributed Ledger Technology (DLT) technology is one of the future drivers of distributed form of data handling especially with blockchain dominating with immutable and secured e-transactions. With its influence and pre-dominant implementation in various sectors like banking, DLT has different use-cases applied in the E-Governance too. Countries like Estonia have come up with various blockchain based e-services for more transparency and privacy. Smart contracts / chain code in the permissioned blockchain could provide the basic Smart Governance needs such as simplified beneficiary authentication, transparency, privacy, security, automation, cost control, faster processing time and so on. This shows the DLT as a catalyst for automation in the future of Smart Governance along with other technologies like IoT, digital twin and so on. This paper analyses the benefits and challenges of blockchain based E-Governance implementation as well as the different DLT types available such as DAG, hashgraph, etc. apart from the blockchain and their potential for an effective citizen centric E-Governance.
Block Chain is an emerging technology which includes a number of features by default such as, distributed ledger, decentralised storage, authentication, security, and traceability. In health sector, patient data are sensitive and it is very essential to be secured, which can be done using blockchain technology. Exchange of healthcare data between hospitals is limited by privacy and dependency on centralized data management systems. Such a centralised storage can be a concern since it can lead to data leakage, data manipulation, mistrust, and single point of failure. Blockchain offers a decentralised computing and storage solution that can help with these issues. It includes smart contracts, identity verification and more. Integrating block chain technology with identity management will be the solution for some issues, such as centralized governing of identities. This system proposes Ethereum based blockchain data management for healthcare application, to store and review the patient record by web application allowing only identity verified users like patient, doctors, family members and hospital staff to have the secure access to health information. Ethereum currently uses a proof-of-work consensus mechanism. Solidity is the popular language for writing Ethereum smart contracts. The data on Ethereum blockchain is stored using tire data structures to manage temporary and permanent data. To protect data integrity, ownership, and permissions, smart contracts are created. Since the business can be handled by smart contracts, there won't be a need for centralised authority to oversee and authorise it, which will cut costs.
An optimistic rollup (ORU) scales a blockchain's throughput by delegating computation to an untrusted remote chain (L2), refereeing any state claim disagreements between mutually distrusting L2 operators via an interactive dispute resolution protocol. State-of-the-art ORUs employ a monolithic dispute resolution protocol that tightly couples an L1 referee with a specific L2 client binary--oblivious to the system's higher-level semantics. We argue that this approach (1) magnifies monoculture failure risk, by precluding trust-minimized and permissionless participation using operator-chosen client software; (2) leads to an unnecessarily large and difficult-to-audit TCB; and, (3) suffers from a frequently-triggered, yet opaque upgrade process--both further increasing auditing overhead, and broadening the governance attack surface. To address these concerns, we outline a methodology for designing a secure and resilient ORU with a minimal TCB, by facilitating opportunistic 1-of-N-version programming. Due to its unique challenges and opportunities, we ground this work concretely in the context of the Ethereum ecosystem--where ORUs have gained significant traction. Specifically, we design a semantically-aware proof system, natively targeting the EVM and its instruction set. We present an implementation in a new ORU, Specular, that opportunistically leverages Ethereum's existing client diversity with minimal source modification, demonstrating our approach's feasibility.
Blockchain-based implementations of non-fungible tokens represent ownership of specific digital objects and are indivisible, irreplaceable and unique. However, there are currently two problems: 1) Due to the low throughput rate of the blockchain system, it cannot meet the needs of large-scale scenarios of non-fungible tokens assets. As the core technology of blockchain scaling, Layer2 has become an important factor affecting the performance of blockchain. 2) The current liquidity mechanism of non-fungible tokens greatly limits its liquidity. Therefore, this paper combines cryptographic zero-knowledge proof technology with off-chain scaling technology to design and implement a system architecture that can significantly improve the liquidity of non-fungible tokens. Firstly, this paper proposes a zk-rollup based off-chain scaling architecture RBHLT, on top of which a high liquidity protocol for non-fungible tokens is implemented. Analysis and experimental results show that RBHLT enables higher liquidity of non-fungible tokens while reducing transaction costs.
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Advanced Steganography and Watermarking Techniques
The widespread application of outsourced computation meets the growing computing demands. However, due to the payment issues and data security, achieving fair interaction between clients and workers in a zero-trust environment has become a bottleneck of restricting the development of outsourced computation. Most existing solutions, including blockchain-based and traditional e-cash system, may compromise the client's or the worker's fairness. To deal with this issue, several fair payment schemes based on trusted third parties (TTP) have been proposed in the literature. However, the involvement of TTP reduced the feasibility of these schemes. In order to remove the aforementioned limitations, we propose a lightweight bitcoin-based fair payment (LBFP) scheme for outsourced computation environment. LBFP is able to achieve the robust fairness and compatibility by integrating cryptographic components (including one-way accumulator, bitcoin-based timed commitment, and symmetric encryption). In addition, we give the security analysis of LBFP and make a comparison with the related schemes which show that LBFP has a better application prospect.
Current consensus protocols for permissionless blockchain cannot balance security, performance and centralization issues. In the paper, we present a reputation based consensus, FPoR, which combines reputation, committee based consensus, PBFT, reward and penalization mechanisms. FPoR can balance scalability, security and decentralization, and promote fairness, increase participation and strengthen security. Experiment results show that FPoR is with high performance and scalability, which can be used for permissionless blockchain. FPoR can also be extended to permissioned blockchain applications.
In recent years, many frameworks and applications have been proposed to ensure tamper resistant data in supply chain using Block chain technologies. Block chain technology as a base design ensures that the content of the information is ‘tamper-resistant’. So far, no other study was presented with a low impact on the environment and minimum cost for each transaction sent by the supply chain. In order to protect the access of malicious user, we tend to propose an immutable data storage environment that is based on Algorand Blockchain. It uses the Pure Proof-of-Stake mechanism of consensus that needs less computational power, and is highly scalable and environmentally sustainable. It will make the data immutable and available in real-time for final consumers. Hence it can tolerate malicious users and achieving consensus without a central authority.
Dec 1, 2022·2022 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA/BDCloud/SocialCom/SustainCom)
Users worldwide widely use cloud storage because of its efficiency, convenience, and high availability. Multi-cloud storage is usually selected to ensure the high availability of data. Unfortunately, when data is migrated and replicated between multi-cloud data centers, it is not easy to guarantee data con-sistency. This paper proposes an efficient, secure, and new data consistency verification scheme using blockchain technology. In order to reduce the computation and communication overhead in the verification process, our scheme uses encrypted tags to build Merkle hash tree to generate unique and lightweight verification proofs and does not use third-party auditors. The final theoretical and experimental analysis shows that our scheme has higher security and a faster verification process in multi-cloud storage.
There is rising global demand for the deployment of a central bank digital currency (CBDC) system to achieve financial stability. However, striking a balance between privacy, transparency, and auditability in such a system is technically difficult. We propose a CBDC system based on a consortium blockchain that adopts a privacy-preserving, transparent unspent transaction output (UTXO) model. The proposed system satisfies the travel rule of payment, unlike existing cryptocurrencies. Unlike the conventional UTXO approach, users use wallet-linked addresses for transactions rather than their actual wallet addresses. Each transacting address is generated using two keys: a random private key computed by the sender and the recipient's public key. The final private key is known only to the recipient, and it is required to spend the UTXO received using the address. Thus, each user holds only a single authorized public key and address, which eases regulatory compliance in the network without compromising anonymity and privacy. To manage the blockchain, the central bank and several certificate authorities execute the energy-efficient Clique consensus algorithm. Only the central bank supplies money to the network. A prototype of the system was implemented using Python-Flask, and it outperformed the state-of-the-art systems by providing a smaller transaction size (665 B) and lower verification time (9 ms).
Permissioned blockchain can provide a decentralized, tamper-evident and trusted computing environment and has been widely deployed in e-government, finance and supply chain management. Smart contracts need to be developed using a specific programming language. Limited by the architectural design of blockchain systems, smart contracts still face many challenges in performing complex computing tasks. For example, there are many matrix operations in the inference process of deep neural network models. Loading deep neural network models directly in smart contracts not only requires relatively large development costs, the inference process of deep neural network models generally consumes more computing resources. We use Intel SGX to design a flexible architecture that can outsource complex computing tasks that need to be processed in smart contracts to off-chain computing servers, while being able to use Freivalds’ Algorithm to ensure the correctness of the outsourced computing results.
<p>Cloud storage provides convenience in managing data for users. Data integrity becomes important because data owner (DO) loses control of their data once it is uploaded to the cloud server (CS). Public auditing is used to check data integrity in cloud storage. Traditional public auditing schemes introduce a third-party auditor (TPA) to help users check their data. However, TPA is assumed to be trusted in these schemes, which may not be practical. A dishonest TPA may provide a good report to DO without executing the auditing task timely. If the data loss could not be detected timely, it may cause a great loss to DO. In this paper we aim to solve these problems using blockchain technique. In our scheme DO, TPA and CS interact with blockchain via smart contracts. We utilize a time-locked deposit smart contract to incentive TPA and CS for their fulfillment in the auditing task honestly. Otherwise, they would be amerced. We use storage smart contracts to ensure the auditing process transparency, and utilize zero-knowledge proof to protect DO&rsquo;s privacy. The scheme is extended to support batch auditing to reduce the user&rsquo;s cost. Experimental results show that our scheme is efficient and practical.</p> <p>&nbsp;</p>
The most significant problems faced in electronic healthcare are data protection, sharing, and interoperability. These problems may be reliable by using Blockchain. With blockchain, transparency and trust can be established in transactional systems by using a peer-to-peer (P2P) distributed ledger technology. This technology enhances security, data exchange, interoperability, integrity, and real-time updating and access when correctly implemented. Blockchain regulates accessibility to the database, and transfers of rights among individuals based on certain situations and it facilitates access to the information of user profiles, the user will have full access to his information and control how his data will be shared. A blockchain would also securely store access control policies, and only the users could change them. This creates an environment of transparency and allows the user to make all decisions as to what data is collected and how the data is shared. However, the most difficult challenges for blockchain healthcare are the data backup and compliance with regulation. There are national and international privacy laws such as HIPAA, EU's General Data Protection Regulation, and the GDPR-like California Consumer Privacy Act. Decentralization in blockchain makes it impossible to have a full data backup.
Stefan More, Sebastian Ramacher, Lukas Alber, Marco Herzl
Authentication, authorization, and trust verification are central parts of an access control system. The conditions for granting access in such a system are collected in access policies. Since access conditions are often complex, dedicated languages -- policy languages -- for defining policies are in use. However, current policy languages are unable to express such conditions having privacy of users in mind. With privacy-preserving technologies, users are enabled to prove information to the access system without revealing it. In this work, we present a generic design for supporting privacy-preserving technologies in policy languages. Our design prevents unnecessary disclosure of sensitive information while still allowing the formulation of expressive rules for access control. For that we make use of zero-knowledge proofs (NIZKs). We demonstrate our design by applying it to the TPL policy language, while using SNARKs. Also, we evaluate the resulting ZK-TPL language and its associated toolchain. Our evaluation shows that for regular-sized credentials communication and verification overhead is negligible.
Today, the global economy is dependent on the Internet and computational resources. Although they are tightly interconnected, it is difficult to evaluate their degree of interdependence. Keeping up with the pace of technology can be a challenging task, mainly when updating the hardware and software infrastructure. Every day, corporations and governments are faced with this issue; most have been victims of cyber attacks, security breaches, and data leaks. The consequences are significant in monetary losses; damage remediation is unattainable, even impossible, in certain circumstances. The repercussions might include reputational damage, legal responsibility, and threats to national security (when attacks are carried out against critical infrastructures to control the resources of a country), to name a few. Similarly, data has become such an integral part of many industries that it is one of the most critical targets for attackers that often is encrypted by ransomware, stolen, or corrupted. Without data, many companies are not able to continue operating as they do. The combination of all these factors complicates the ability of organizations to cooperate, trust, and share information in efforts to research and develop solutions for industry and government.This work proposes a Blockchain-based infrastructure solution provided by “Hyperledger Fabric” technology for companies to securely transmit and share information using the latest encryption and data storage technologies operating on the model of distributed systems and smart contracts. By presenting unique digital assets as Non-Fungible Tokens (NFT), the infrastructure is able to trust the integrity of the data, while protecting it from counterfeiting. Through the use of a Blockchain-based file storage system known as IPFS, and by connecting all the relevant elements together through a web-based application, it is possible to demonstrate that the implementation of such systems is feasible, highly scalable and a useful tool that many organizations can utilize to create new work systems and worktflows for digital asset management.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
In cloud computing circumstance, users upload data to the cloud server and verify data integrity through a third-party audit (TPA). However, verifying data integrity is still a computationally intensive and time-consuming operation. If there are illegal users or unreliable cloud servers, it can only be known from the verification result, resulting in invalid computation and time overhead. In order to solve the above problems, RSA algorithm is used to verify the legitimacy of the user, and when the verification passes, Merkle hash tree is used to filter unreliable servers. To prevent replay attacks, data integrity is verified through the bilinear mapping feature. Finally, the simulation results show that the scheme not only can detect the legitimacy of users, but also filter out unreliable servers, and effectively reduce the computational and time overhead of verifying data integrity.
When faced with massive data volumes, many current companies and institutions usually choose centralized databases or distributed databases to meet their data storage needs. But untrusted centralized third-party auditor can pose serious security problems. Malicious database service providers may tamper with or delete users data to achieve certain benefits, while returning false data integrity verification results to users. The traditional solution is to introduce a third-party auditor to ensure the reliability of the data verification results, but this third-party auditor may also be untrustworthy and partner with the database service provider to forge false data verification results. The centralization of the database system makes the verification of data integrity a difficult but necessary task. Therefore, we propose a data integrity verification scheme using smart contract (DIV-SC) to ensure the reliability of data integrity verification results in a centralized database environment. We introduce the blockchain as a decentralized third-party auditor. The immutability of the blockchain can ensure that the information stored on the blockchain will not be maliciously tampered with. Meanwhile, the smart contract deployed on the blockchain can ensure that the procedure of storing verification information and the verification procedure are correct and will not be affected by any malicious parties.
Hai‐Van Dang, Tran Viet Xuan Phuong, Thuc D. Nguyen, Thang Hoang
Zero-knowledge universal accumulator generates the succinct commitment to a set and produces the short (non) membership proof (universal) without leaking information about the set (zero-knowledge). In order to further support a generic set and zero-knowledge, existing techniques generally combine the zero-knowledge universal accumulator with other protocols, such as digital signatures and hashes to primes, which incur high overhead and may not be suitable for real-world use. It is desirable to commit a set of membership concealing the information with the optimal complexity. We devise ZAC, a new zero-knowledge Dynamic Universal Accumulator by taking the existing cryptographic primitives into account to produce a new efficient accumulator. Our underlying building blocks are Bloom Filter and vector commitment scheme in [19], utilizing the binary expression and aggregation to achieve efficiency, generic set support, zero-knowledge and universal properties. As a result, our scheme is improved in terms of proof size and proof time, also comparable to the RSA-based set accumulator in [8] in the verifying complexity. With 128 bit security, our proof size is 48 bytes while theirs is 1310 bytes and the running time of elliptic curve-based methods is faster than RSA-based counterpart. ZAC is proved to be complete, ϵ-sound and zero-knowledge. Extensively, based on ZAC as building block, we construct a new Zero-Knowledge Elementary Database (ZKEDB), which consumes 5 times less storage space, $\mathcal{O}\left( {\log N} \right)$ less bandwidth, and $\mathcal{O}\left( {\log N} \right)$ more efficient in proving and verification than the state-of-art work in [13] (where N is the domain space size). ZKEDB is proved to be complete, ϵ-sound and zero-knowledge. ZKEDB supports a new type of select top ℓ query, and can be extended to non-elementary databases.
Over the past few years, Ethereum has surfaced as a widely adopted standard Blockchain platform that is increasingly being utilized to develop Decentralized Applications (DApps). By introducing Smart Contracts to software developers and programmers, Ethereum has triggered the development of countless Blockchain solutions. Among its main applications, many involve the exchange of valuable financial assets. Simply put, we cannot afford to base our Blockchain solutions or applications on potentially vulnerable smart contracts. This is where the Security Analysis Tools come into picture, for the timely detection of vulnerabilities in the Smart Contracts. Since this is a recent phenomenon, it offers a lot of research opportunities for us to contribute towards improving the existing state of security analysis tools and resolving their shortcomings. Although most of these tools have been evaluated in terms of effectiveness, installation and reliability; the literature largely lacks the technical usability perspective i.e. execution and evaluation. Therefore, based on a selection criteria, we committed our time to 4 such tools for an extensive usability assessment. We designed our usability study in a manner that combined the advantages of multiple evaluation methods. The results were useful not only in terms of comparative analysis, but also as a validation of the need of identified usability improvements.
With the advancement in computing power and speed, the Internet is being transformed from screen-based information to immersive and extremely low latency communication environments in web 3.0 and the Metaverse. With the emergence of the Metaverse technology, more stringent demands are required in terms of connectivity such as secure access and data privacy. Future technologies such as 6G, Blockchain, and Artificial Intelligence (AI) can mitigate some of these challenges. The Metaverse is now on the verge where security and privacy concerns are crucial for the successful adaptation of such disruptive technology. The Metaverse and web 3.0 are to be decentralized, anonymous, and interoperable. Metaverse is the virtual world of Digital Twins and non-fungible tokens (NFTs). The control and possession of users' data on centralized servers are the cause of numerous security and privacy concerns. This paper proposes a solution for the security and interoperability challenges using Self-Sovereign Identity (SSI) integrated with blockchain. The philosophy of Self-Sovereign Identity, where the users are the only holders and owners of their identity, comes in handy to solve the questions of decentralization, trust, and interoperability in the Metaverse. This work also discusses the vision of a single, open standard, trustworthy, and interoperable Metaverse with initial design and implementation of SSI concepts.
The world of web3 is currently being plagued by security risks. In the first half of 2022 alone, web3 projects have lost more than $2 billion due to various security issues, out of which more than 76% of the projects have been audited. At present, the main attack surfaces on the web3 chain, including oracle manipulation, logical loopholes across smart contracts and MEV front-running transactions, cannot be defended through the current mainstream security methods, such as contract auditing, and can only be passively defended after receiving the alerts of malicious attacks. Hence, there is a huge demand for more proactive defense products in the market. However, most of the existing security products and security defense solutions are limited in defense capabilities, as they rely on external mechanisms and thus cannot effectively identify and counter hacker attacks during the contract execution. This paper proposes a new security system for smart contracts on the blockchain and demonstrates how it can actively defend against malicious attacks and provide effective protection for assets on the blockchain through experimental verification and comparison. It compares the existing on-chain security verification solutions as well as the engineering development model and performs logic-based argument verification during on-chain transaction execution and high-precision computation-intensive verification in the off-chain sandbox environment, thereby can prevent risky transactions, protect assets, and promote the security and development of the entire web3.