To reduce the transmission cost of blockchain confidential transactions, we propose SymmeProof, a novel communication efficient non-interactive zero-knowledge range proof protocol without a trusted setup. We design and integrate two new techniques in SymmeProof, namely vector compression and inner-product range proof. The proposed vector compression is able to reduce the communication cost to log(n) for n-size vectors. The proposed inner-product range proof converts a range proof relation into an inner-product form, which can further reduce the range proof size with the vector compression technique. Based on these two techniques, SymmeProof can eventually achieve a log(n)-size range proof. The proposed SymmeProof can be used in many important applications such as blockchain confidential transactions as well as arguments for arithmetic circuits satisfiability. We evaluate the performance of SymmeProof. The results show that SymmeProof substantially outperforms representative methods such as Bulletproofs in the proof size without a trusted setup.
With the advent of Industry 4.0, information has become a key aspect for virtually any system. Critical infrastructures haven't been excluded by this technological revolution, which has led to several advantages in terms of communication, interoperability, and scalability. On the other hand, these systems are now targeted by new attacks, previously exclusive to cybersystems. The potential of data violation ranges from the interruption of the service provided to, in the worst cases, disastrous consequences in environmental, economic and safety terms. Consequently, ensuring data reliability is an essential task to prevent these kinds of attacks. Data provenance, a kind of metadata that identifies the derivation history of a data, can provide a possible solution. This paper aims to discuss solutions for a tamper proof data provenance extended, but not limited, to the healthcare scenario. The proposed approach is based on blockchain technology to ensure protection of sensitive data, such as medical records and healthcare data.
Mohammad Habibullah Rakib, Showkot Hossain, Mosarrat Jahan, Upama Kabir
Log data is an essential tool to identify the footprint of unauthorized activities executed in a network system. Hence, a compact storage mechanism is required for the massive volume of log data to protect them from malicious tampering attacks. In this regard, Blockchain (BC) has been used to design tamper-proof storage of log records. However, the existing BC-based solutions cannot efficiently handle continuously growing massive log data, creating tremendous storage overhead on the participating BC nodes. Although some works address the storage scalability issue through separate off-chain storage, these works cannot support log data confidentiality and essential query mechanisms to manage log data are missing. Moreover, due to inadequate analysis of the real-time implementation, the performance gain obtained by these schemes is not clearly understood. To handle these deficiencies, we propose a BC-based network log data storage and management scheme that uses an InterPlanetary File System (IPFS) to outsource most of the log data to external off-chain storage. In addition, the proposed scheme performs query and audit operations to manage plaintext and encrypted log records efficiently. Besides, we present a theoretical analysis to show our scheme’s scalability in storage gain. Extensive experiments on the prototype implementation of the proposed system show that storage gain increases exponentially with increasing log records per transaction. Moreover, our scheme attains nearly 93% storage reduction in supporting per day storage demand of log records. The experimental results also demonstrate that the proposed system can be realized with a low computational overhead.
Recently, the Industrial Internet of Things plays a vital role in the new round of technology innovation and industry competition, where the identity resolution system is its key component. However, there are some problems in the existing Handle-based identity resolution architecture. Therefore, a trusted identifier co-governance architecture is proposed, and a prototype system is designed and implemented in this article. Specifically, we design a blockchain-based decentralized framework for identifier service, identifier life cycle management based on smart contract, and a data storage mechanism for a trusted identifier. The whole architecture could solve the problems of single point of failure, data tampering, and governance deviation, and reduce the trust cost in the process of data circulation. The simulation results reveal that the system has achieved good results in terms of delay and throughput.
Jun 1, 2022·2022 IEEE 9th International Conference on Cyber Security and Cloud Computing (CSCloud)/2022 IEEE 8th International Conference on Edge Computing and Scalable Cloud (EdgeCom)
In recent years, blockchain technology has become one of the key technical innovation fields in the world. From the simple Bitcoin that can only be transferred at first to the blockchain application ecology that is now blooming, blockchain is gradually building a credible internet of value. However, with the continuous development and application of blockchain, even the blockchain based on cryptography is facing a series of network security problems and has caused great property losses to participants. Therefore, studying blockchain security and accelerating standardization of blockchain security have become the top priority to ensure the orderly and healthy development of blockchain technology. This paper briefly introduces the scope of blockchain security from the perspective of network security, sorts out some existing standards related to blockchain security, and gives some suggestions to promote the development and application of blockchain security standardization.
Crowdsourcing as a computing paradigm, has been widely used in industries and services. Accountability in crowdsourcing services enables participants to work honestly and improves the quality of services. The realization of accountability requires trusted evidence, multiparty verification, and fair reward or punishment. Blockchain technology, which is inherently tamper-resistant, traceable, and decentralized, puts forward a direction for realizing the requirements. However, in the process of data management and decentralized verification, it is hard to achieve a better trade-off between efficiency and security. This paper proposes a blockchain-based verification scheme integrated by trust management, ‘validatorRep’, that is suitable to enhance accountability in the crowdsourcing system. In detail, a decoupled blockchain model is proposed for the differentiated storage of business transactions and log transactions during data interaction. Additionally, a fine-grained trust model is proposed, including both the rep-utation of participants and the trust relationship between participants. Based on fine-grained trust, the decentralized verification scheme is designed to guarantee secure data access, trusted verification, and fair reward or punishment. Finally, the proposed framework is deployed on the Ethereum platform to observe its effectiveness and overall performance. Simulation results also reveal that the proposed fine-grained trust model can provide efficient accountability for crowdsourcing.
The embrace of cryptocurrencies by institutional investors is well underway. The futures market has already had a significant impact on this industry. Digital asset exposure may go up while the risk of loss is reduced by using derivatives. Decentralized finance and crypto-derivative trading are the focus of this article. We analyzed the function of a central clearing house (C.C.P.) and Exchange for Derivatives, especially Cryptocurrency derivatives. We mapped some critical attributes of DeFi (Decentralized Finance) to the concept of decentralized Exchange. In the light of this analysis, we reviewed an existing Cryptocurrency derivatives exchange that is trying to become a decentralized exchange. We studied dYdX, a major decentralized crypto-derivative exchange. We assessed its core purpose as a crypto-derivative exchange to investigate the positive aspects of the D.C.E. (Decentralized Crypto-derivative exchange). Decentralized crypto-derivative exchanges have considerable problems in terms of liquidity and market-making, and we determined that different incentive schemes by these exchanges have successfully overcome these issues. By linking additional trading nodes and boosting the trust of traders and investors, we believe these exchanges may be made more efficient.
Cloud computing has increased its service area and user experience above traditional platforms through virtualization and resource integration, resulting in substantial economic and societal advantages. Cloud computing is experiencing a significant security and trust dilemma, requiring a trust-enabled transaction environment. The typical cloud trust model is centralized, resulting in high maintenance costs, network congestion, and even single-point failure. Also, due to a lack of openness and traceability, trust rating findings are not universally acknowledged. "Blockchain is a novel, decentralised computing system. Its unique operational principles and record traceability assure the transaction data's integrity, undeniability, and security. So, blockchain is ideal for building a distributed and decentralised trust infrastructure. This study addresses the difficulty of transferring data and related permission policies from the cloud to the distributed file systems (DFS). Our aims include moving the data files from the cloud to the distributed file system and developing a cloud policy. This study addresses the difficulty of transferring data and related permission policies from the cloud to the DFS. In DFS, no node is given the privilege, and storage of all the data is dependent on content-addressing. The data files are moved from Amazon S3 buckets to the interplanetary file system (IPFS). In DFS, no node is given the privilege, and storage of all the data is dependent on content-addressing.
The secure Internet of Things (loT) increasingly relies on digital cryptographic signatures which require a private signature and public verification key. By their intrinsic nature, public keys are meant to be accessible to any interested party willing to verify a given signature. Thus, the storing of such keys is of great concern, since an adversary shall not be able to tamper with the public keys, e.g., on a local filesystem. Commonly used public-key infrastructures (PKIs), which handle the key distribution and storage, are not feasible in most use-cases, due to their resource intensity and high complexity. Thus, the general storing of the public verification keys is of notable interest for low-resource loT networks. By using the Distributed Ledger Technology (DLT), this paper proposes a decentralized concept for storing public signature verification keys in a tamper-resistant, secure, and resilient manner. By combining lightweight public-key exchange protocols with the proposed approach, the storing of verification keys becomes scalable and especially suitable for low-resource loT devices. This paper provides a Proof-of-Concept implementation of the DLT public-key store by extending our previously proposed NFC-Key Exchange (NFC-KE) protocol with a decentralized Hyperledger Fabric public-key store. The provided performance analysis shows that by using the decentralized keystore, the NFC- KE protocol gains an increased tamper resistance and overall system resilience while also showing expected performance degradations with a low real-world impact.
Electronic Health Records (EHR) are the healthcare sector's core digital strategy meant to improve the quality of care provided to patients. Despite the benefits afforded by this digital transformation initiative, adoption among healthcare organizations has been slower than desired. The sheer volume and sensitive nature of patient records compel these organizations to exercise a healthy amount of caution in implementing EHR. Cyberattacks have also increased the risks associated with non-optimal EHR implementations. An influx of high-profile data breaches has plagued the sector during the COVID-19 pandemic, which put the spotlight on EHR cybersecurity. One objective of this research project is to aid the acceleration of EHR adoption. Another objective is to ensure the robustness of the system to resist malicious attacks. For the former, a systematic review was used to unearth all the possible causes why the adoption of EHR has been anemic. In this paper, sixty-five existing proposed EHR solutions were analyzed and it was found that there are fourteen major challenges that need to be addressed to reduce friction and risk for health organizations. These were privacy, security, confidentiality, interoperability, access control, scalability, authentication, accessibility, availability, data storage, data ownership, data validity, data integrity, and ease of use. We propose EHRChain, a new framework that tackles all the listed challenges simultaneously to address the first objective while also being designed to achieve the second objective. It is enabled by dual-blockchains based on Hyperledger Sawtooth to allow patient data decentralization via a consortium blockchain and IPFS for distributed data storage.
Blockchain is a digital ledger where the data entries are recorded in a decentralized fashion that cannot be altered. This is likely to prosper in a variety of industries, including healthcare. According to a survey, 70% of healthcare professionals believe that blockchain has the largest influence on clinical report management, regulating documents, and creating a framework for sharing electronic health records (EHR) in the healthcare industry. Even though blockchain technology is having real potential for improving health information systems, the rise of this technology has also led to innovative proposals and applications. This review mainly focuses on EHR data exchange between the patient and the hospital entities like doctors, record verifiers, insurance companies, pharmaceuticals, etc. The proposed research study has also discussed about the techniques used in these models to counter the problems present in the traditionally used server-client model like a data breach, Unauthorized access, centralized data management, etc., and improvisation of the blockchain-based models. Further, a comparative analysis has been provided on various blockchain-based systems for hosting a secure EHR sharing.
Blockchain Technology, a decentralized and distributed ledger, has received extensive attention of industries to revamp operations and functionality of organizations. Implementing smart technologies such as Blockchain is an attractive solution for organizations, including the Higher Education Institutions (HEIs). Self-Sovereign Identity is one of Blockchain applications that promises to provide a more efficient management systems for organizations. This paper explains how a Self-Sovereign Identity using Blockchain Technology can be used to manage students' credentials in HEIs. It also proposes a framework to successfully implement the solution. This paper answers two questions: “How to use Self-Sovereign Identity as credentials management system” and “What are the major steps to be followed when implementing a Blockchain-based solution?”
Current blockchain-based cloud (BBC) systems have several security vulnerabilities regarding smart contracts (SC), and several attacks have been reported recently. The SC development lacks standard design processes that follow software lifecycle principles to model secure SC. Secondly, the security mechanisms in the SC are not constantly evolved to resist evolving adversary attacks. BBC systems lack self-adaptive security capability to make spontaneous decisions when adversarial attacks are encountered. To build a self-adaptive secure BBC system that follows standard software development lifecycle principles to model secure SC, we propose the so-called self-adaptive security RE_BBC framework. The framework would utilize the MAPE-BBC adaptation loop to make decisions internally based on the threat models, goal models, and service level agreement (SLA) SC security specifications. The framework identifies vulnerabilities and threats and takes precautionary measures using self-adaptive SC agents. We validated the proposed methodology theoretically and empirically, and statistically proved the research questions and hypothesis using the t-test and Mann–Whitney U test. Subsequently, we compare our proposed approach with the Security Quality Requirements Engineering approach (SQUARE). The feasibility results and the replicated study results indicate that the proposed approach outperformed the SQUARE approach in terms of artifacts quality, self-adaptive security evaluation quality, efficiency in response time, complexity, and usefulness of the proposed approach for the Healthcare Data Management (HDM) system. SC security developers can immensely benefit from our proposed methodology. They need not reengineer SC from scratch; depending on their security needs and plan, the contract can be adapted to execute a new plan.
Cloud network has become very popular in recent days due to its accessibility merits. The data stored in the cloud environment are accessible by the clients from any location. A reliable shielding approach will protect the data stored in the cloud from the hackers and malwares. Blockchain is one of the recent technologies implemented to the cloud network for storing the location of the saved data in an encrypted ledger format. This saves the stored data location without exploring it to the hacker’s algorithm. Hence the hacking algorithm fails by not knowing the location to be targeted. Deep learning is an advanced technique developed to act like that of the human neurological analysis on several problems. Implementation of deep learning algorithm to the cloud security module identifies the movement of malware and spywares in the cloud storage. Similarly the cryptography is an old technique structured to hide the information with a cover data or cover image. It allows the hacking algorithm to extract only the useless data. This paper reviews the recent advancements in the cloud security with blockchain, deep learning and cryptographic models.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Mohammad Khalid Imam Rahmani, Mohammed Shuaib, Shadab Alam, Shams Tabrez Siddiqui · 7 authors
The internet of medical things (IoMT) is a smart medical device structure that includes apps, health services, and systems. These medical equipment and applications are linked to healthcare systems via the internet. Because IoT devices lack computational power, the collected data can be processed and analyzed in the cloud by more computationally intensive tools. Cloud computing in IoMT is also used to store IoT data as part of a collaborative effort. Cloud computing has provided new avenues for providing services to users with better user experience, scalability, and proper resource utilization compared to traditional platforms. However, these cloud platforms are susceptible to several security breaches evident from recent and past incidents. Trust management is a crucial feature required for providing secure and reliable service to users. The traditional trust management protocols in the cloud computing situation are centralized and result in single-point failure. Blockchain has emerged as the possible use case for the domain that requires trust and reliability in several aspects. Different researchers have presented various blockchain-based trust management approaches. This study reviews the trust challenges in cloud computing and analyzes how blockchain technology addresses these challenges using blockchain-based trust management frameworks. There are ten (10) solutions under two broad categories of decentralization and security. These challenges are centralization, huge overhead, trust evidence, less adaptive, and inaccuracy. This systematic review has been performed in six stages: identifying the research question, research methods, screening the related articles, abstract and keyword examination, data retrieval, and mapping processing. Atlas.ti software is used to analyze the relevant articles based on keywords. A total of 70 codes and 262 quotations are compiled, and furthermore, these quotations are categorized using manual coding. Finally, 20 solutions under two main categories of decentralization and security were retrieved. Out of these ten (10) solutions, three (03) fell in the security category, and the rest seven (07) came under the decentralization category.
Mr. Anuj Mali, Mr. Bharath Shinde, Mr. Sahil Sharma, Mr. Saurabh Khatal · 5 authors
Block chains are now firmly established as a digital technology that combines cryptographic, data management, networking, and incentive mechanisms to support the verification, execution, and recording of transactions between parties. While block chain technologies were originally intended to support new forms of digital currency for easier and secure payments, they now hold great promise as a new foundation for all forms of transactions. Agribusiness stands to become a key beneficiary of this technology as a platform to execute ‘smart contracts’ for transactions, particularly for high-value produce. First it is important to distinguish between private digital currencies and the distributed ledger and block chain technologies that underlie them. The distributed and cross-border nature of digital currencies like Bit coin means that regulation of the core protocols of these systems by central banks is unlikely to be effective. Monetary authorities are focused more on understanding ‘on-ramps’ and ‘off-ramps’ that constitute the links to the traditional payments system rather than being able to monitor and regulate the currency itself. In contrast to the digital currency feature of block chain, the distributed ledger feature has the potential for widespread use in agribusiness and trade financing, especially where workflows involve many different parties with no trusted central entity.
Jianbin Wu, Sami Ahmed Haider, Manish Bhardwaj, Aditi Sharma · 5 authors
Recently, data integrity for multiagent-based big data environments has been challenging. This paper presents a blockchain-based Merkle DAG structure (M-DAG) for audit data integrity. M-DAG resolves the problem that arises due to the multicopy of a large data volume in a big data environment. It employed Boneh–Lynn–Shacham’s (BSL) signature to verify the integrity of identical multicopy on big data environments. The proposed M-DAG audit mechanism uses a consortium chain algorithm for decentralized traceability and audit to archive reliable data. The evaluation has been carried out for the efficiency of the data integrity audit.
Today, the majority of the web’s content and user data is controlled by a few large tech companies. There is a growing movement to devolve this control evenly across the entire internet, representing the transition to Web3. In order for this movement to be successful, technologies and protocols must be developed to enable web users to use the web securely without trusting any other user. That is, today’s web is structured so that users must trust these companies, so trustless alternatives haven’t already been developed. Broadly, this movement emphasizes developing peer-to-peer networks, blockchains, and distributed storage systems. These systems make use of cryptographic primitives to guarantee security.
Amit Kumar Tyagi, Saravanan Chandrasekaran, N. Sreenath
In these (several) past decades (1950 to 2018), the world is moved from wired things to wireless devices or electronics devices/ technology. This increment or development in networking technology faces several incidents like issues of leaking privacy of users, issue of surveillance and security breaches in systems. This paper discusses about compromising users” privacy as various issues, challenges and questions (raised in existed models). Note that due to these issues or breaches or loopholes, unknown users/ third-parties collect and control large amounts of personal data, also they may use this data against respective user, for example, for financial use, for blackmailing, etc. Hence, this article discusses about a new technology (i.e., Blockchain), on which every industry is trusting on. How this new technology has been growing as fastest technology only in the past decade to build among users and organization? Such answers have been given in this paper. Blockchain provides decentralized, distributed personal data management system which ensures users own and control their data or protect user's data any kind of breaches.
Lianshan Sun, Xue Bai, Chao Zhang, Yang Li · 6 authors
In the Big Data era, data provenance has become an important concern for enhancing the trustworthiness of key data that are rapidly generated and shared across organizations. Prevailing solutions employ authoritative centers to efficiently manage and share massive data. They are not suitable for secure and trustworthy decentralized data provenance sharing due to the inevitable dishonesty or failure of trusted centers. With the advent of the blockchain technology, embedding data provenance in immutable blocks is believed to be a promising solution. However, a provenance file, usually a directed acyclic graph, cannot be embedded in blocks as a whole because its size may exceed the limit of a block, and may include various sensitive information that can be legally accessed by different users. To this end, this paper proposed the BSTProv, a blockchain-based system for secure and trustworthy decentralized data provenance sharing. It enables secure and trustworthy provenance sharing by partitioning a large provenance graph into multiple small subgraphs and embedding the encrypted subgraphs instead of raw subgraphs or their hash values into immutable blocks of a consortium blockchain; it enables decentralized and flexible authorization by allowing each peer to define appropriate permissions for selectively sharing some sets of subgraphs to specific requesters; and it enables efficient cross-domain provenance composition and tracing by maintaining a high-level dependency structure among provenance graphs from different domains in smart contracts, and by locally storing, decrypting, and composing subgraphs obtained from the blockchain. Finally, a prototype is implemented on top of an Ethereum-based consortium blockchain and experiment results show the advantages of our approach.