Nym credentials solve the problem of privacy-enhanced authentication amongst a decentralized open-ended ecosystem of services. Many blockchain systems offer decentralized services, but at the cost of revealing all transactions in a public ledger, which is clearly not suitable for high-value transactions involving personal data. Nym credentials deploy anonymous authentication credentials as an identity system that maintains user privacy. Due to the validators being decentralized, the system is compatible with blockchain-based systems. Tokens can be used to show the "right to access" privacy-enhanced services. Nym validators transform these tokens into Nym credentials that validated publicly in a decentralized manner via a modified Coconut signature scheme capable of the open-ended embedding arbitrary attributes.
Alexander Papageorgiou, Antonis Mygiakis, Konstantinos Loupos, Thomas Krousarlis
As the technology of Internet-of-Things advances, the potential benefit of compromising such a network increases as well. Conventional security stacks already deployed in proven scenarios, such as public key infrastructure on the world wide web, have been applied to the context of Internet-of-Things, however they fail to address certain issues that are prevalent in these networks, the foremost being a secure methodology of verifying the identities of devices without a central point of failure or lack of proper scalability. This paper describes a novel public key infrastructure system that discerns itself from conventional implementations by establishing a distributed network rather than a monolithic one. This enables one to horizontally scale the solution, as there is no reliance on a central authority. Instead, a blockchain is deployed and utilized as the record-keeping of device identities in tandem with smart contracts that interface with the underlying blockchain storage. This solution solves the issues of central point of failure, increases the overall resilience of the public key infrastructure security component and can be arbitrarily enhanced to support a wider array of functionality by introducing new smart contracts within the network itself.
Wilson S. Melo, Raphael C. S. Machado, Daniel Peters, Mahbuba Moni
Public-Key Infrastructures are elementary building blocks to implement digital signatures (i.e., digital notarization) and, hence, ensure information integrity, authenticity, and nonrepudiation. This feature is a promising alternative to improve the reliability of smart meters. However, conventional PKIs can be too expensive in scenarios that consist of a significant number of meters. In this work, we propose a blockchain-based PKI, describing how to tailor this solution to deal with specific aspects related to smart meter protection. We also implement our proposal as a smart contract with the Hyperledger Fabric platform. The results show our solution's feasibility and provide a reliable model to manage digital certificates for a wide diversity of smart devices.
Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi
Nowadays, blockchain technology is seen as one of the main technological innovations to emerge since the advent of the internet. Many applications can benefit from blockchain to protect their exchanges. Nonetheless, applications with more restricted interests cannot use public blockchains. Permissioned blockchains promise to combine effectiveness of blockchains with stricter permissions to join blockchain's network. In permissioned blockchain, the number of participating entities is limited compared to public blockchain. However, by targeting the peers of the blockchain, the attackers can easily take control of consensus process and halt the blockchain operations. In this paper, we propose BrainChain, a scalable and efficient scheme to protect permissioned blockchain nodes from the largest ever Distributed Denial of Service (DDoS) attack (i.e., Domain Name System (DNS) amplification attack) in the context of software defined networks (SDN). BrainChain consists of 4 schemes: (1) Flow statistics collection scheme (FS) to gather the features of flows in an efficient way using sFlow; (2) Entropy based scheme (ES) to measure disorder of network features; (3) Bayes Network based Filtering scheme (BF) to classify, based on entropy values, illegitimate DNS requests; and (4) DNS Mitigation (DM) scheme to mitigate in an effective way the illegitimate flows (i.e., illegitimate DNS requests). Experimental results show that BrainChain can quickly and effectively detect and mitigate the attacks (i.e., DNS amplification attacks) with a high accuracy and a small false positive rate making it a promising scheme to protect blockchain applications from DNS Amplification attacks.
Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi
Smart grids (SGs) and advanced metering infrastructures (AMIs) are considered as the new evolution of classical electrical grids. The recent emergence of smart meters is paving the way for the proliferation of smart grids, where billions of smart meters are interconnected to provide novel pervasive services (e.g., real time pricing application and real time energy consumption), and automate diagnostic and daily energy metering (i.e., gas, electric) tasks (e.g., billing, monitoring, planning and predicting of energy usage). The recent explosion in the number of insecure smart meters is changing the view towards SG from enabler of smart homes into a powerful amplifying tool that creates new vectors for cyberattacks (i.e., smart-homes Distributed Denial-of-Service (DDoS) attacks) at large scale. This motivated us to design a new flexible, secure, efficient and trustworthy access control scheme based on blockchain and smart contract. Although access control exists in AMI, it is based on a centralized model (i.e., router/gateway, firewall) which introduces a bottleneck (i.e., single point of failure) and causes the collapse of the system. In this paper, we propose a new decentralized-based access control architecture for SG based on blockchain; it uses smart contracts (i.e., Ethereum's smart contracts) in order to manage permissions in a fully distributed and trustworthy manner. The architecture is implemented, tested and deployed on the Ethereum official test network Ropsten [1]. The results confirm that the proposed blockchain based access control scheme achieves security, flexibility, efficiency, and cost effectiveness making it a promising solution to mitigate DDoS attacks in SGs.
Cryptocurrencies are the digital currencies designed to replace the regular cash money while taking place in our daily lives especially for the last couple of years. Mining cryptocurrencies are one of the popular ways to have them and make a profit due to unstable values in the market. This attracts attackers to utilize malware on internet users’ computer resources, also known as cryptojacking, to mine cryptocurrencies. Cryptojacking started to be a major issue in the internet world. In this case, we developed MiNo, a web browser add-on application to detect these malicious mining activities running without the user’s permission or knowledge. This add-on provides security and efficiency for the computer resources of the internet users. MiNo designed and developed with double-layer protection which makes it ahead of its competitors in the market.
Blok zincir (Blockchain) teknolojisinin bir ürünü olarak ortaya çıkan Bitcoin ve türevi kripto paralar son on yılın en önemli ekonomik yeniliğidir. Bitcoin, eşler arası veri paylaşım ağını (Peer-to-Peer) temel alan, merkezi bir otorite tarafından kontrol edilmeyen (decentralized), kamuya açık hesap kaydı tutma özelliğine sahip (PublicLedger), temelde online ödeme yapmayı sağlayan sanal bir para birimidir. Bitcoin, kripto paraların ekonomik olarak tanınmasında temel teşkil etmiştir. Bununla birlikte günümüzde genel veya özel fonksiyonlu pek çok Bitcoin türevi (Altcoin) kripto para birimi geliştirilmiştir. Kripto paralar her geçen gün daha fazla sayıda ticari işlemde kullanılmaya başlanmıştır. Kripto paralarla yapılan işlemlerin nasıl muhasebeleştirileceğine ilişkin henüz belirgin bir düzenleme bulunmaması farklı yaklaşımları da beraberinde getirmektedir. Bu çalışmanın amacı, mevcut yaklaşımlar ışığında kripto paraların nasıl muhasebeleştirilebileceğini tartışmaktır.<br>
According to the Internet Organised Crime Threat Assessment (IOCTA) 2019 report, Bitcoin is still the currency of choice in criminal markets and as payment for cyber-related extortion attempts, such as from ransomware or a Distributed Denial-of-Service (DDoS) attack. Bitcoin is a peer-to-peer electronic cash system first proposed by Satoshi Nakamoto in 2008. By design, Bitcoin is a pseudonymous coin, meaning that users can transact with the currency without revealing their true identity. To tackle the challenge of Bitcoin-related crime, a range of deanonymization techniques have been proposed. In general, these solutions are limited by the time and resources required to predict likely transaction owners. In this paper, we propose the first software-defined network (SDN)-based Bitcoin transaction mapping solution. We analyse the Bitcoin transaction process in an SDN environment and demonstrate a deterministic approach to deanonymize users in Bitcoin's network.
Abhishek Kaudare, Milan Kumar Hazra, Anurag Shelar, Manoj K. Sabnis
Elections and voting are the basic mechanisms of a democratic system. There have been various attempts to make modern elections more flexible by using digital technologies. Basic characteristics of free and fair elections are intractability, immutable, transparency and the privacy of the involved actors. This corresponds to a few of the many features of blockchain-like decentralized ownership, the immutability of chain, anonymity and distributed ledger. This work-in-progress paper attempts to do a comparative analysis of various blockchain technologies under development and propose a `Blockchain based Electronic Voting System' solution by weighing these technologies based on the need for the proposed solution. The main aim of this paper is to present a robust blockchain-based election mechanism that not only will be reliable but also flexible according to present needs.
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
We propose a blockchain-based IoT devices anonymous access system using zero-knowledge proof in cloud-based radio over optical fiber networks (C-RoFN) to prevent device sensitive information from being exposed to massive IoT devices.
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
When Proof-of-Stake (PoS) underlies a consensus protocol, parties who are eligible to participate in the protocol are selected via a public selection function that depends on the stake they own. Identity and stake of the selected parties must then be disclosed in order to allow verification of their eligibility, and this can raise privacy concerns. In this paper, we present a modular approach for addressing the identity leaks of selection functions, decoupling the problem of implementing an anonymous selection of the participants, from the problem of implementing others task, e.g. consensus. We present an ideal functionality for anonymous selection that can be more easily composed with other protocols. We then show an instantiation of our anonymous selection functionality based on the selection function of Algorand.
The topic of performing safe and secure elections is a long-standing debate. Regardless, of the various attempts for electronic or Internet-based voting, the majority of countries still use paper ballots. Nevertheless, with major advancements occurring over the last years in both cryptography and distributed ledgers we believe that there is space now for re-investigating this area. In this paper, we propose ethVote an Internet voting system that makes use of the Ethereum blockchain, state of the art cryptographic mechanisms and a P2P-based front-end to ensure a secure voting process. In addition, we provide an open-source proof of concept implementation that features the majority of the needed components for securely using ethVote. Our proposal is tested both in terms of unit testing, requirement verification, and with regard to the feasibility to perform such an operation in a public distributed ledger.
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Ferenc Béres, István András Seres, András A. Benczúr, Mikerah Quintyne-Collins
Ethereum is the largest public blockchain by usage. It applies an account-based model, which is inferior to Bitcoin's unspent transaction output model from a privacy perspective. Due to its privacy shortcomings, recently several privacy-enhancing overlays have been deployed on Ethereum, such as non-custodial, trustless coin mixers and confidential transactions. In our privacy analysis of Ethereum's account-based model, we describe several patterns that characterize only a limited set of users and successfully apply these quasi-identifiers in address deanonymization tasks. Using Ethereum Name Service identifiers as ground truth information, we quantitatively compare algorithms in recent branch of machine learning, the so-called graph representation learning, as well as time-of-day activity and transaction fee based user profiling techniques. As an application, we rigorously assess the privacy guarantees of the Tornado Cash coin mixer by discovering strong heuristics to link the mixing parties. To the best of our knowledge, we are the first to propose and implement Ethereum user profiling techniques based on quasi-identifiers. Finally, we describe a malicious value-fingerprinting attack, a variant of the Danaan-gift attack, applicable for the confidential transaction overlays on Ethereum. By incorporating user activity statistics from our data set, we estimate the success probability of such an attack.
Dimitris Geneiatakis, Yannis Soupionis, Gary Steri, Ioannis Kounelis · 6 authors
With the continuous development of distributed ledger and blockchain technologies, new use cases apart from cryptocurrencies have come into the spotlight. In this article, we evaluate whether an e-government service could be a suitable candidate for a blockchain transformation. We selected as a reference test system an existing cross-border e-government service that is used for supporting goods exchanges across the European Union. We show how such an indicative paradigm can be transformed into a blockchain system. In order to do so, we deployed it in an emulated architecture for evaluating its performance under various realistic conditions. Our results show that the deployed system is able to meet the requirements, both in terms of throughput and transaction speed. Moreover, it shows clear advantages in terms of usability and synchronization between all entities.
This paper describes techniques to help with COVID-19 automated contact tracing, and with the restoration efforts. We describe a decentralized protocol for ``proof-of-contact'' in zero knowledge where a person can publish a short cryptographic proof attesting to the fact that they have been infected and that they have come in contact with a set of people without revealing any information about any of the people involved. More importantly, we describe how to compose these proofs to support broader functionality such as proofs of $n$th-order exposure which can further speed up automated contact tracing. The cryptographic proofs are publicly verifiable, and places the burden on the person proving contact and not on third parties or healthcare providers rendering the system more decentralized, and accordingly more scalable.
Jacob Swambo, Spencer Hommel, Bob McElrath, Bryan Bishop
A bitcoin \textit{covenant} is a mechanism to enforce conditions on future bitcoin transactions. A bitcoin \textit{vault} is a specific type of covenant transaction that enforces a time-lock on the transfer of control of funds to a hot wallet, but enables an immediate transfer of funds into a deep cold recovery wallet. This paper demonstrates how to integrate a bitcoin vault into a custody protocol and demonstrates the security properties of that protocol. The vault is implemented using pre-signed transactions with secure key deletion (as proposed in \cite{Swambo2020cov}). It is shown that vault-custody protocols enable the wallet owner to specify their desired balance for an inherent trade-off between the security of and accessibility of bitcoin holdings by adjusting the length of time-locks used. It is also demonstrated that wallet owners have increased control of risk-management by compartmentalizing funds across numerous vault transactions. While it isn't realistic to completely prevent theft, the most likely theft scenarios (compromising the hot wallet) have severely limited profitability for an attacker, deterring attempts at theft from the beginning. The proposed architecture was designed to offer defence-in-depth through redundancy and fault-tolerant functionality as well as countermeasures for class breaks through diversity across hardware and software layers. Finally, the architecture employs a detection (a watchtower) and response system that enables fail-safe recovery from attempted or partial thefts through a second type of covenant transaction, a push-to-recovery-wallet transaction.
E-voting is one of the valid use cases of blockchain technology with many blockchain e-voting systems already proposed. But efforts that focus on critical analysis of blockchain e-voting architectures for national elections from stakeholders’ perspectives are mostly lacking in the literature. Therefore, government decision-makers and election stakeholders do not yet have a sufficient basis to understand the potential risks, challenges, and prospects that are associated with blockchain e-voting. This paper demonstrates how the use of the Architecture Trade-off Analysis Method (ATAM) can enable stakeholders in national elections to understand the risks, prospects, and challenges that could be associated with a blockchain e-voting system for national elections. By using a study context of South Africa, a proposed blockchain e-voting architecture was used as a basis to aid election stakeholders to reason on the concept of blockchain e-voting to get them to understand the potential risks, security threats, critical requirements attributes, and weaknesses that could be associated with using blockchain e-voting for national elections. The study found that blockchain e-voting can prevent many security attacks, internal vote manipulation, and promote transparency. However, voter validation and the security of the blockchain architecture are potential weaknesses that will need significant attention.
Today, the entire world is facing incredible health and economic challenges due to the rapid spread of the life threatening novel Coronavirus Disease - 2019 (COVID-19). In the prevailing situation when a vaccine is many months away, the way forward seems to be a controlled exit from the lockdown - where, infected/exposed people are strictly quarantined and recovered/unexposed people are allowed to carry on with their day to day business activities. However, appropriate physical distancing norms will have to be strictly followed for such relaxations. Therefore, mechanisms are required that will assist people in following the social and physical distancing norms in public places. In this paper, we propose an anonymity preserving blockchain based framework that allows people, through use of their smart phones and other communication devices, to protect themselves from infections as they conduct their daily business activities.
Double-spending is a potential flaw in cryptocurrencies. In recent years, double-spend attacks have caused severe economic damage to many Bitcoin consumers, thus double-spending problems have attracted wide attention. Studying related countermeasures and mitigations against such attacks is imperative. In this article, we briefly introduce a new form of combined attack: double-spending with a Sybil attack in the Bitcoin network and discuss how to mitigate it. We propose two mitigations such as charging an identity fee and setting a deadline to defend against this attack, and we evaluate the effect of these two mitigations through an economic analysis.
Over the years, the flourish of crowd computing has enabled enterprises to accomplish computing tasks through crowdsourcing in a large-scale and high-quality manner, and therefore how to efficiently and securely implement crowd computing becomes a hotspot. Some recent work innovatively adopted a P2P (peer-to-peer) network as the communication environment of crowdsourcing. Based on its decentralized control, issues like single-point-of-failure or DDoS attack can be overcome to some extent, but the huge computing capacity and storage costs required by this scheme is always unbearable. Federated learning is a distributed machine learning that supports local storage of data, and clients implement training through interactive gradient values. In our work, we combine blockchain with federated learning and propose a crowdsourcing framework named CrowdSFL, that users can implement crowdsourcing with less overhead and higher security. In addition, to protect the privacy of participants, we design a new re-encryption algorithm based on Elgamal to ensure that interactive values and other information will not be exposed to other participants outside the workflow. Finally, we have proved through experiments that our framework is superior to some similar work in accuracy, efficiency, and overhead.
In this article, we propose the first self-tallying decentralized e-voting protocol for a ranked-choice voting system based on Borda count. Our protocol does not need any trusted setup or tallying authority to compute the tally. The voters interact through a publicly accessible bulletin board for executing the protocol in a way that is publicly verifiable. Our main protocol consists of two rounds. In the first round, the voters publish their public keys, and in the second round they publish their randomized ballots. All voters provide Non-interactive Zero-Knowledge (NIZK) proofs to show that they have been following the protocol specification honestly without revealing their secret votes. At the end of the election, anyone including a third-party observer will be able to compute the tally without needing any tallying authority. We provide security proofs to show that our protocol guarantees the maximum privacy for each voter. We have implemented our protocol using Ethereum's blockchain as a public bulletin board to record voting operations as publicly verifiable transactions. The experimental data obtained from our tests show the protocol's potential for the real-world deployment.
Muhammad Asaad Cheema, Hassaan Khaliq Qureshi, Chrysostomos Chrysostomou, Marios Lestas
In this paper, we present a distributed machine learning based intrusion detection system in Internet of Things (IoT) utilizing Blockchain technology. In particular, spectral partitioning is proposed to divide the IoT network into autonomous systems (AS) enabling traffic monitoring for intrusion detection (ID) to be performed by the selected AS border area nodes in a distributed manner. The ID system is based on machine learning, where a support-vector machine algorithm is trained using prominent IoT data sets and detection of the attackers is provided. Furthermore, the integrity of the attackers' list is offered by utilizing Blockchain technology, which enables a distributed sharing of the attackers' information among the AS border area nodes of the Blockchain network. Simulations are performed to evaluate different aspects of the proposed IoT system and demonstrate the potential of integrating machine learning based ID to a distributed spectral partitioned Blockchain network.
Faulty access control in API-based multi-service setups can lead to violations of consent declarations through unauthorized Third Parties. This threatens Service Providers to lose the trust of their Service Consumers and to be exposed to sensitive fines as defined by the GDPR.Addressing this problem, in this paper, we propose a novel, blockchain-based approach for enabling economically motivated and technically mediated detection of violations of consent declarations in multi-service setups and derive its legal viability from a thorough analysis of the GDPR. The herein introduced Violation Detection mechanism allows for a censorship-resistant and publicly verifiable detection of violations to registered Consent Policies based on off-chain computed violation claims utilizing non-interactive zero-knowledge proofs. The corresponding System Design specifies all required roles and artifacts to integrate the Violation Detection mechanism with standard procedures for consent-based access control. The integration of our system supports Service Providers to fulfill legal requirements and, therefore, paves the way towards automated policy violation detection within GDPR-compliant consent-based access control solutions.