Yangguang Tian, Atsuko Miyaji, Koki Matsubara, Hui Cui · 5 authors
Abstract Policy-based chameleon hash is a useful primitive for blockchain rewriting systems. It allows a user to create a mutable transaction associated with an access policy, whereas a modifier who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, it lacks a revocation mechanism. The modifiers can always rewrite the mutable transactions even if their given rewriting privileges are compromised. In this work, we introduce revocable policy-based chameleon. The property of revocation allows some modifiers’ rewriting privileges to be revoked, regardless of whether their rewriting privileges are compromised or not.
Xiao Liang, Ningyu An, Da Li, Qiang Zhang · 5 authors
In the smart grid, the sharing of power data among various energy entities can make the data play a higher value. However, there may be unauthorized access while sharing data, which makes many entities unwilling to share their data to prevent data leakage. Based on blockchain and ABAC (Attribute-based Access Control) technology, this paper proposes an access control scheme, so that users can achieve fine-grained access control of their data when sharing them. The solution uses smart contract to achieve automated and reliable policy evaluation. IPFS (Interplanetary File System) is used for off-chain distributed storage to share the storage pressure of blockchain and guarantee the reliable storage of data. At the same time, all processes in the system are stored in the blockchain, ensuring the accountability of the system. Finally, the experiment proves the feasibility of the proposed scheme.
An accumulator is a function that hashes a set of inputs into a short, constant-size string while preserving the ability to efficiently prove the inclusion of a specific input element in the hashed set. A concrete accumulator is constructed by using strong RSA assumption. Thanks to their practical features, accumulators are used in various protocols such as zero-knowledge proofs, group signatures, and blockchain. However, lattice-based accumulators are not as well studied as the strong RSA assumption. In 2019, Ling et al. constructed a lattice-based accumulator that is enable to update the member in the list, called LLNW in this paper. However, the update algorithm of the LLNW scheme is not complete, since it requires recalculation to any member regardless of whether or not the member is updated. In this paper, we propose an efficient update algorithm, called EfficientAccWitUpdate, to LLNW, which enables us to update members more efficiently than that in LLNW. In our method, only a member who updates requires recalculation. Specifically, the number of multiplications required for updating in EfficientAccWitUpdate is$\frac{1}{2}$of LNWX, and the number of additions required for updating in EfficientAccWitUpdate is$\frac{nk+1}{2nk-1}$of LNWX. Consequently, by incorporating the EfficientAccWitUpdate accumulator scheme into the zero-knowledge protocol, group signature, and blockchain, it is possible to realize a more efficient application.
With the development of blockchain applications, the requirements for file storage in blockchain are increasing rapidly. Many protocols, including Filecoin, Arweave, and Sia, have been proposed to provide scalable decentralized file storage for blockchain applications. However, the reliability is not well promised by existing protocols. Inspired by the idea of insurance, we innovatively propose a decentralized file storage protocol in blockchain, named as FileInsurer, to achieve both scalability and reliability. While ensuring scalability by distributed storage, FileInsurer guarantees reliability by enhancing robustness and fully compensating for the file loss. Specifically, under mild conditions, we prove that no more than 0.1\% value of all files should be compensated even if half of the storage collapses. Therefore, only a relatively small deposit needs to be pledged by storage providers to cover the potential file loss. Because of lower burdens of deposit, storage providers have more incentives to participate in the storage network. FileInsurer can run in the top layer of the InterPlanetary File System (IPFS), and thus it can be directly applied in Web 3.0, Non-Fungible Tokens, and Metaverse.
Cameron Hickert, Ali Tekeoglu, Joseph Maurio, Ryan Watson · 8 authors
Incorporating smart technology into critical infras-tructure (CI) and smart cities promises substantial efficiency improvements as networks of machines communicate and make rapid decisions autonomously. Yet the promise of greater effi-ciency that such cyber-physical systems (CPS) bring is tempered by increased fragility unless machine-to-machine (M2M) trust is enhanced, particularly in Internet of Things (IoT) networks. This work makes two contributions toward improving M2M trust. First, it proposes a multifaceted trust framework comprised of identity verification, experience, context, and recommendation scores to enable high-integrity M2M interactions. Second, this trust framework is implemented via an IoT-friendly distributed ledger on a physical testbed, where it is shown to identify and mitigate errors due to a compromised system component. This implementation mirrors real-world IoT systems in which resource-constrained endpoint devices pose trust score compu-tation challenges and the number of devices raises scalability obstacles for information sharing among nodes.
With the advent of the Big Data era, industry, business and academia have developed various data exchange schemes to make data more economically beneficial. Unfortunately, most of the existing systems provide only one-time data exchanges without the ability to track the provenance and transformations of datasets. In addition, existing systems encrypt the data to protect data privacy, which hinders demanders from verifying the correctness of the data and evaluating its value.To provide data traceability and privacy while ensuring fairness during data exchanges, we design and implement ZKDET, a traceable data exchange scheme based on non-fungible token and zero-knowledge, which is able to (i) track all transformations of data during their lifecycle and record them on the blockchain; (ii) provide zero-knowledge proofs to securely guarantee that all complex transformations and data contents are correct and meet specific requirements; and (iii) warrant exchange fairness and data privacy in public storage platforms. Security analysis and evaluations on ZKDET show that it can support traceable data exchange while preserving data privacy and maintaining high throughput despite large data volumes.
In recent years, technological research and studies have accelerated in the agriculture and food industry to protect and improve the trust of consumers. In 2008, with the publication of the white paper on “Bitcoin: Peer-to-peer Electronic Cash Payment System” by Satoshi Nakamoto, the world met with blockchain technology, where there are no middlemen and transfers are made securely. In the following years, with the development of Ethereum by Vitalik Buterin and the interpretation of the concept of Smart Contracts with blockchain technology, blockchain technology has begun to influence all sectors, thanks to its benefits such as increasing transparency and reliability in contracts between parties. Blockchain technology, in addition to providing solutions to financial systems that have become dysfunctional, also brings alternatives to supply chain management, where data needs to be transferred securely and quickly. Blockchain applications used in FSC emerge as a technology that will enable us to solve problems such as food security, food integrity, food fraud, etc. In this paper, It has been studied on how to use blockchain technology in the food supply chain, how to choose the suitable blockchain platform, and how It will be facilitating for solutions such as tracking from field to fork, back-tracking are examined the data saved in the blocks and the working mechanism will be discussed in the background.
Jangho Na, Hye-Young Kim, Nohpill Park, Beomjoo Seo
This paper reports the use of the Schnorr Digital Signature as a new alternative instead of the Elliptic Curve Digital Signature Algorithm (ECDSA) currently used in Ethereum. Elliptic curve cryptography, which is the cryptographic background of blockchain digital signature, is explained in the background and related works. This study then examined, the problems facing ECDSA and how the Schnorr Digital Signature could solve them. The test was performed by comparing Schnorr and ECDSA implemented in a private Ethereum network environment. The performance results showed that Schnorr Digital Signature has strengths in terms of efficiency over ECDSA. The efficiency deals with the gas price, signature size, block size, block elapsed time, and signature algorithm calculation time.
Cloud Data Security Solutions
Advanced Steganography and Watermarking Techniques
Diao Xiaohong, Jiang Linru, Jin Yuan, Lin Cheng · 6 authors
To solve the issues that the existing blockchain technology suffers from insufficient computing power and unreliable computing when using the computing-intensive machine learning model for decision-making, a blockchain intelligent computing scheme that is based on a trusted execution environment is proposed. By placing heavy computing tasks in the trusted execution environment off-chain, the computing burden of processing on-chain data is reduced and trusted computing capability is provided. At the same time, in order to apply the trusted execution environment to the intelligent calculation of data on the blockchain chain, this scheme proposes a data trust management module to ensure the trusted supply and consumption of data and a data computing process and input and output trusted intelligent computing module. Finally, the security of the scheme is analyzed theoretically, and verify the feasibility of the scheme which is based on the scheme prototype implemented on the private Ethereum blockchain.
This paper presents a hybrid blockchain-edge architecture for managing Electronic Health Records (EHRs) with attribute-based cryptographic mechanisms. The architecture introduces a novel attribute-based signature aggregation (ABSA) scheme and multi-authority attribute-based encryption (MA-ABE) integrated with Paillier homomorphic encryption (HE) to protect patients' anonymity and safeguard their EHRs. All the EHR activities and access control events are recorded permanently as blockchain transactions. We develop the ABSA module on Hyperledger Ursa cryptography library, MA-ABE module on OpenABE toolset, and blockchain network on Hyperledger Fabric. We measure the execution time of ABSA's signing and verification functions, MA-ABE with different access policies and homomorphic encryption schemes, and compare the results with other existing blockchain-based EHR systems. We validate the access activities and authentication events recorded in blockchain transactions and evaluate the transaction throughput and latency using Hyperledger Caliper. The results show that the performance meets real-world scenarios' requirements while safeguarding EHR and is robust against unauthorized retrievals.
Public clouds have drawn increasing attention from academia and industry due to their high computational and storage performance. Attribute-based encryption (ABE) is the most promising technology to simultaneously achieve confidentiality and fine-grained access control of the cloud-stored data. However, traditional ABE that relies on centralized authority faces several key management issues, such as the key escrow, key distribution, key tracking, key update, and heavy communication and computing overhead for users, which will cause security concerns and impede its widespread application. On the other hand, blockchain technology preserves distributed ledgers to ensure the immutability and transparency of data, which can further solve the security vulnerabilities caused by system centralization. This paper proposes a blockchain-assisted transformation method to solve all the key management problems mentioned above in ciphertext-policy ABE by utilizing technologies such as secret sharing protocols. In addition, our transformation method realizes two additional benefits: outsourced decryption and efficient user revocation, which are extremely valuable for practical implementations. We simulate a demonstration by adopting the most popular permissioned blockchain, Hyperledger Fabric. The security and efficiency analysis reveals that the scheme obtained from our transformation method can achieve replayable chosen-ciphertext security with extremely efficient decryption.
IT Infrastructures have grown in both size and complexity. To help administrators to manage their infrastructure, several Infrastructure Management (IM) Tools have been created. However, none of them implements a secure and traceable log of changes that can bring accountability to the management of such infrastructures. On the other hand, recent research and development in blockchain technologies has allowed for the creation of Distributed Ledgers that can provide secure, immutable and traceable ledgers. These technologies have the potential to solve the problem by dynamically registering the changes the infrastructure management tools apply to IT infrastructures. For that purpose, a Proof-of-Concept tool was developed that incorporates a Permissioned Distributed Ledger, based on Hyperledger Fabric, as a middle layer to infrastructure management tools such as Ansible and Terraform, to prove the suitability of these technologies to provide a secure and immutable resource inventory and log of changes that enables for traceability and accountability of all modifications to the IT infrastructure, while also providing user identity management and control.
Data deduplication can solve the problem of resource wastage caused by duplicated data. However, due to the limited resources of Internet of Things (IoT) devices, applying data deduplication to IoT scenarios is challenging. Existing data deduplication frameworks for the IoT are prone to inefficiency or trust crises due to the random allocation of edge computing nodes. Furthermore, side-channel attacks remain a risk. In addition, after IoT devices store data in the cloud through data deduplication, they cannot share their data efficiently. In this paper, we propose a secure and efficient data deduplication framework for the IoT based on edge computing and blockchain technologies. In this scheme, we propose a model based on parallel use of three-layer and two-layer architectures and introduce the RAndom REsponse (RARE) scheme to resist side-channel attacks. We also design a label tree to realise one-to-many data-sharing, which improves efficiency and meets the needs of the IoT. In addition, we use blockchain to resist collusion attacks. Experiments were conducted to demonstrate that our framework has advantages over similar schemes in terms of communication cost, security and efficiency.
In this paper, we present a model of a multi-client framework for access control to datasets put away in an untrusted cloud climate. Distributed storage like some other untrusted climate needs the capacity to get share data. Our methodology gives an entrance command over the information put away in the cloud the supplier investment. The fundamental device of the access control instrument is a ciphertext-strategy trait-based encryption plot with dynamic credits. Utilizing a blockchain-based decentralized record, our framework gives a permanent log of all significant security occasions, for example, key age, access strategy task, change or repudiation, and access demand. We propose a bunch of cryptographic conventions guaranteeing the security of cryptographic tasks requiring mystery or private keys. Just ciphertexts of hash codes are moved through the blockchain record. The model of our framework is executed utilizing shrewd agreements and tried on the Ethereum blockchain stage. Keywords- cloud storage; attribute-based access control; ciphertext-policy attribute-based encryption; blockchain
The Industrial Internet of Things (IIoT) is the essential component of Industry 4.0. Blockchain is a promising technology for secure data sharing and trustable cooperation between IIoT devices. However, the ever-growing transaction records make it difficult for the storage-limited IIoT devices to join the blockchain network. In this article, an adaptive compression scheme is proposed to decrease the storage volume on each node. In the scheme, the block body is compressed by representing the included transactions as their remainders stored in the distributed nodes. The original transaction could be recovered based on the Chinese remainder theorem. In particular, each node adapts its compression ratio according to its storage resource. The nodes storing more data have advantages in transaction recovery, introducing an incentive mechanism for efficient storage utilization. The theoretical analysis and simulation results show that the proposed scheme can achieve a high compression ratio with good service availability. The proposed scheme dramatically lowers the threshold for IIoT devices to join the blockchain network, which is important for the large-scale application of blockchain in Industry 4.0.
With the growth of the Internet of Things (IoT) and improved interoperability between various IoT devices of different manufacturers and owners, verifying the authenticity and integrity of data becomes a challenge. Cryptographic signatures together with Distributed Public Key Infrastructures (DPKI) and Distributed Ledger Technology (DLT) are promising solutions to this challenge. In this work, we extended the Veritaa framework, a DLT-based DPKI with an immutable signature store, to support IoT applications and evaluate its applicability. Therefore, we propose the systems architecture and implement a low-power IoT client. We built a real-world testbed with different sensors to evaluate the proposed architecture and extensions. In the evaluation, we analyze the time required to secure sensor data on the DLT, the overhead introduced to assert authenticity, integrity, and immutability of the data, and the security of our proposed solution.
Shantanu Pal, Ambrose Hill, Tahiry Rabehaja, Michael Hitchens
There has been considerable advancement in the use of blockchain for trust management in large-scale dynamic systems. In such systems, blockchain is mainly used to store the trust score or trust-related information of interactions among the various entities. However, present trust management archi-tectures using blockchain lack verifiable interactions among the entities on which the trust score is calculated. In this paper, we propose a blockchain-based trust management framework that allows independent trust providers to implement different trust metrics on a common set of trust evidence and provide individual trust value. We employ geo-location as proof of interaction. Some of the existing proposals rely upon geo-location data, but they do not support trust calculation by multiple trust providers. Instead, they can only support a centralised system. Our proposed architecture does not depend upon a single centralised third-party entity to ensure trusted interactions. Our architecture is supported by provable interactions that can easily be verified using blockchain. Therefore, it allows a high degree of confidence in trust management by ensuring the actual interactions between the entities. We provide a detailed design and development of the architecture using real-world use case examples. The proof of prototype was implemented on the Ethereum blockchain platform. Experimental results demonstrate that the employment of independent trust providers adequately provides a high degree of trust scores and that the proposed architecture can be used in a real-world environment.
Along with applying blockchain technology in the health care service system (HSS), many distributed solutions have been proposed to solve the centralized, data island problems. Although blockchain-enabled HSS has significantly changed the traditional management mode of medical Big Data [e.g., electronic medical records (EMRs)], some new problems such as ledger corpulence, data searchable security, and quantum attack threat are exposed. In this article, we first introduce an efficient EMRs management model called on-chain ledger and off-chain storage (OLOS), in which the indexes of EMRs are uploaded on public blockchain and the real EMRs data are stored in native server. This model can relieve the public ledger and save the public cloud space. Meanwhile, it can protect data security by keeping off the direct operation on real EMRs data. Then, to protect the cross-institutional EMRs sharing security and improve the quantum-resist ability, we proposed a secure keyword-searchable attribute-based encryption (KS-ABE) scheme based on lattice cryptography. Moreover, the scheme can prove to be secure against adaptive chosen-keyword attack and adaptive chosen-policy attack in the random oracle model. Besides, comparison analysis and experimental results show that our KS-ABE scheme has fewer communication costs and smaller key sizes than similar literary works.
Tianyi Xu, Tie Qiu, Dengcheng Hu, Chaoxu Mu · 6 authors
Blockchain has been utilized to manage distributed multicloud storage in the industrial Internet of Things. Existing approaches commonly use trusted third-party servers or middlewares to search data allocation strategies and use blockchain to enhance security. However, finding a fair data allocation strategy is hard when the third-party brokers are manipulated. Moreover, the complex computing in generating blocks reduces efficiency and heavy communication cost in consensus leads to critical challenges to scalability. To address that, this article proposes a scalable two-layer blockchain system for distributed multi-cloud storage (STSM). We design a novel consensus mechanism called proof of storage allocation, which integrates data placement problems into leader selection to achieve fair strategy and high QoS of data storage. We also incorporate asynchronous consensus groups into the consensus process to enhance scalability. Extensive experiments verify that STSM gains high scalability and increases efficiency while achieving high QoS in distributed multicloud data allocation.