Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

5,430 papersLast indexed Aug 31, 2026
Search papers

Paper index

5,430 results · page 71 of 227

Clear filters
Oct 28, 2023·2023 16th International Congress on Image and Signal Processing, BioMedical Engineering and Informatics (CISP-BMEI)
2 cites
Design and Analysis of an Anonymous and Fair Trading Scheme for Electronic Resources with Blind Adaptor Signature

Xiaoming Hu, H. W. Chen

With the development of the blockchain technology, blockchain is being widely used in finance, education, healthcare and other important fields, and its decentralized nature also brings new ideas for solving the problems of credit risk, uncertainty of transactions and imperfect regulatory system that exist in third-party e-commerce platforms. For the privacy security problem of electronic resource transactions in blockchain, this paper proposes an anonymous and fair transaction scheme for electronic resource, which is based on a new blind adaptor signature technology, the blind adaptor signature combines the atomicity of the adaptor signature and the blindness of the blind signature, which is applied to the payment channel, and the transactions are carried out in the payment channel, so that the establishment of the payment channel does not require a deposit, and the transactions are settled instantly and with fairness, and at the same time improve the privacy security, has a good application prospect in the field of electronic resource transaction.

Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 26, 2023·Recent Trends in Computational Sciences
0 cites
Securing crime case summary and E-FIR using blockchain concept

Tanuja Kayarga, C Kavitha, P. Lokamathe, M. Yamuna · 5 authors

Electronic First Information Report (e-FIR) is a basic document filed to the police stations by a victim or someone on his/her behalf when a cognizable offense such as murder, kidnapping, rape, theft, etc. is committed. In the e-FIR database, the offense&s;s record can be compromised due to its centralized nature, and further the intentional registration of false e-FIR can occur. Thus, data integrity and transparency are key concerns in e-FIR database. In this paper, e-FIR data integrity and false registration appended with police stations in a centralized database are addressed via a consensus-based distributed blockchain solution, as an integral part of a smart city environment. Specifically, a smart contract based intelligent framework has been utilized to explore the potential of Ethereum blockchain in providing integrity to e-FIR data stored in a police station&s;s database. Local database is interfaced with Ethereum blockchain using Web3 Remote Procedure Call (RPC) protocol. Multiple simulations have been performed to evaluate the performance of the proposed framework. Our results show a trade-off between different hashing algorithm security level for the offenses data and number of transactions stored in a single block on blockchain ledger.

Digital and Cyber Forensics
Cybercrime and Law Enforcement Studies
Privacy-Preserving Technologies in Data
Original source
Oct 25, 2023·Future Generation Computer Systems
19 cites
Enabling Federated Learning at the Edge through the IOTA Tangle

Carlo Mazzocca, Nicolò Romandini, Rebecca Montanari, Paolo Bellavista

The proliferation of Internet of Things (IoT) devices, generating massive amounts of heterogeneous distributed data, has pushed toward edge cloud computing as a promising paradigm to bring cloud capabilities closer to data sources. In many cases of practical interest, centralized Machine Learning (ML) approaches can hardly be employed due to high communication costs, low reliability, legal restrictions, and scalability issues. Therefore, Federated Learning (FL) is emerging as a promising distributed ML approach that enables models to be trained on remote devices using their local data. However, “traditional” FL solutions still present open technical challenges, such as single points of failure and lack of trustworthiness among participants. To address these open challenges, some researchers have started to propose leveraging blockchain technologies. However, the adoption of blockchain for FL at the edge is limited by several factors nowadays, such as long waiting times for transaction confirmation and high energy consumption. In this work, we conduct an original and comprehensive analysis of the key design challenges to address towards an efficient implementation of FL at the edge, and analyze how Distributed Ledger Technologies (DLTs) can be employed to overcome them. Then, we present a novel architecture that enables FL at the edge by leveraging the IOTA Tangle, a next-generation DLT whose data structure is a directed acyclic graph (DAG), and the InterPlanetary File System (IPFS) to store and share partial models. Experimental results demonstrate the feasibility and efficiency of our proposed solution in real-world deployment scenarios.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
Oct 24, 2023·IEEE Transactions on Smart Grid
25 cites
Blockchain-Based Clustered Federated Learning for Non-Intrusive Load Monitoring

Tianjing Wang, Zhao Yang Dong

To address privacy concerns of state-of-the-art centralized machine learning in non-intrusive load monitoring (NILM) applications, the adoption of federated learning (FL) has emerged as a solution to transfer training processes from cloud servers to edge devices. Nevertheless, conventional FL encounters several challenges including architecture safety, incentive mechanism, computing cost, and personalization. To overcome these challenges, the study proposes a self-motivated decentralized FL scheme for NILM, named blockchain-based clustered FL, by combining blockchain mechanism with clustered FL, incentivizing suitable clients to participate in FL by offering rewards based on data size and model performance. Under NILM-related differential privacy protections, the Laplace noise is injected into the first layer of neural networks in the blockchain-based clustered FL, and a decay factor is employed to mitigate the adverse effects of excessive noise on performance. Lightweight training techniques such as data quantization and weight pruning are employed to reduce computational complexity. Furthermore, a clustering approach is utilized to create multiple global models, thereby enhancing the model personalization degree. It is verified by the case study that the blockchain-based clustered FL outperforms the conventional FL in both accuracy and operation risk, and offers much superior performance and a more robust model compared to local training.

Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Original source
Oct 24, 2023·2023 Fifth International Conference on Blockchain Computing and Applications (BCCA)
4 cites
BETA-FL: Blockchain-Event Triggered Asynchronous Federated Learning in Supply Chains

Mayank Gulati, Narges Dadkhah, Benedikt Groß, Gerhard Wunder · 7 authors

BETA-FL provides a distributed federated learning framework implemented for supply chains by tightly integrating private- permissioned blockchain for the trusted alliance among various actors involved in the supply chain. With a trusted ledger as the moderator in federated learning workflow, our approach ensures protection against malicious backdoor attacks on performance from both server and clients. Additionally, our asynchronous training regime allows scalability to a large number of federated clients with small and constant delay caused due to an event-triggering scheme. We showcase a classification task on spectrogram data as a potential use-case in the food supply chain to avoid food wastage. Finally, we facilitate a dedicated channel for regulatory bodies in our blockchain environment for inspections and audits pertaining to the functioning of the supply chain.

Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Oct 24, 2023·2023 Fifth International Conference on Blockchain Computing and Applications (BCCA)
3 cites
Blockchain-Based Consent Management for Privacy Persevering and Transparency in Intelligent Surveillance Systems

Fehmi Jaafar, Darine Amayed, Wissam Salhab, Hajer Bouani · 5 authors

Video cameras are becoming ubiquitous. They'd be interconnected within a larger pervasive infrastructure supported by artificial intelligence which helps ensure smart services relaying in real-time video analysis and image processing. However, such services and technologies involve a set of privacy concerns. If privacy concerns can be addressed, enabling real-time analytics on video streams in public spaces can be valuable in supporting many applications for security, public safety, and urban space management. This study aims to highlight privacy concerns in image and video processing in the context of intelligent IoT systems by proposing a blockchain-based approach for data transparency and privacy management. As a result, our proposed approach will provide IoT customers the ability to manage their consent using a distributed ledger securely.

Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
Original source
Oct 24, 2023·2023 Fifth International Conference on Blockchain Computing and Applications (BCCA)
8 cites
Verifiable Credentials with Privacy-Preserving Tamper-Evident Revocation Mechanism

Xu Li, Tianyu Li, Zekeriya Erkin

Verifiable Credential (VC) is a new standard proposed by the W3C association to facilitate the expression and verification of third-party-verified credentials on the Internet, such as passports or diplomas. However, the current VC data model lacks an explicit revocation design that guarantees the secure operations of the system, which limits its application. In this paper, we specify the requirements for a tamper-evident and privacy-preserving revocation mechanism, based on which we compare existing solutions and propose our revocation mechanism that satisfies all the requirements. Our design combines a cryptographic accumulator and a role-based blockchain. With zero-knowledge proof, the verifier can operate off-chain computation of the revocation status while ensuring the correctness of revocation information published on the blockchain. Our analysis shows that the proposed revocation mechanism can prevent fraud using forged and revoked credentials and relieve privacy concerns caused by the correlation of digital data. Our proof-of-concept implementation demonstrates that our revocation mechanism adds only 42.86 ms overhead in the presentation and 31.36 ms overhead in the verification of verifiable credentials. We also provide scalability analysis, which illustrates that the throughput of our blockchain can meet real-world needs.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Oct 24, 2023·arXiv (Cornell University)
0 cites
Redactable Signature Schemes and Zero-knowledge Proofs: A comparative examination for applications in Decentralized Digital Identity Systems

Bryan Kumara, Mark Hooper, Carsten Maple, Timothy Hobson · 5 authors

Redactable Signature Schemes and Zero-Knowledge Proofs are two radically different approaches to enable privacy. This paper analyses their merits and drawbacks when applied to decentralized identity system. Redactable Signatures, though competitively quick and compact, are not as expressive as zero-knowledge proofs and do not provide the same level of privacy. On the other hand, zero-knowledge proofs can be much faster but some protocols require a trusted set-up. We conclude that given the benefits and drawbacks, redactable signatures are more appropriate at an earlier stage and zero-knowledge proofs are more appropriate at a later stage for decentralized identity systems

Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Access Control and Trust
Original source
Oct 23, 2023·2023 3rd Intelligent Cybersecurity Conference (ICSC)
6 cites
Privacy-Preserving Genomic Analysis via PSO-Driven Federated Learning on Blockchain

Reza Nourmohammadi, Iman Behravan, Kaiwen Zhang

Federated learning, a distributed machine learning method, trains statistical models over remote devices or servers with local data, without exchanging data samples. It preserves patient data securely behind hospital firewalls, sharing only anonymous model parameters, enhancing privacy and security. This innovative approach exchanges only untraceable learned feature representations. This study introduces a new federated learning framework an innovative aggregation methods based on Particle Swarm Optimization (PSO) algorithm for breast cancer prognosis. To safeguard patient data privacy, a privacy mechanism is implemented at the user's end. By utilizing the federated learning model, they've addressed the data scarcity problem, leading to improved accuracy in breast cancer progno-sis. Federated learning, as mentioned earlier, protects personal data by sending model parameters to agents instead of raw data to a central node, keeping data localized. However, the risk of malicious nodes injecting fake data into the global model is a concern. To address this, we need a verification mechanism to authenticate senders and their training data while preserving data privacy. We use zero-knowledge proof (ZKP) for verification without exposing raw data for this part. At the outset of the federated learning process, each client computes the Merkle tree root hash of their local training data and submits it to the federated learning contract for participation. In subsequent training rounds, the client's compiler checks the integrity of their data by comparing the Merkle tree root hash to the initial one. If they match, a trace file is generated and sent for proof generation, verification, fact creation, and registration. Leveraging the TCGAbiolinks package, we conducted experiments demonstrating the effectiveness of our approach with real data. Learner clients enhance their local models using a PSO algorithm, achieving remarkable results in binary classification tasks with 400 features while preserving patient data privacy via ZKP integration. Our framework reaches 97% accuracy with eight clients, compared to a comparable system's 82%, highlighting its practical applicability and efficiency in real-world scenarios, particularly when dealing with larger numbers of participants.

Privacy-Preserving Technologies in Data
AI in cancer detection
Blockchain Technology Applications and Security
Original source
Oct 23, 2023·IEEE Internet of Things Journal
19 cites
Data Verifiable Personalized Access Control Electronic Healthcare Record Sharing Based on Blockchain in IoT Environment

Hui Wang, Yong Xie, Yining Liu, Xiong Li · 5 authors

Electronic health records (EHRs) based on the Internet of Things (IoT) can provide real-time health data for quick intelligent medical services and give convenience to many data-sharing scenarios. However, EHRs also face various security threats since they are highly private. To the best of our knowledge, no recognized data-sharing work can satisfy the stringent privacy requirements of EHRs. Motivated by this, we propose a blockchain-based personalized access control EHR-sharing scheme with data verifiability, which can safeguard the interests of data owners (DOs) and users simultaneously. First, we take ciphertext-policy attribute-based encryption to achieve personalized access control for DOs. Second, we design an interactive zero-knowledge proof protocol between DOs and users, which can provide authenticity verification of EHR for users and prevent EHR away from forgery. In addition, smart contracts and the interplanetary file system are used to reduce the computation and storage costs of patients. Finally, the security analysis shows that the proposed scheme meets the predefined security goals. The performance analysis demonstrates that the proposed scheme is efficient and can be applied to practical electronic medical record sharing scenarios.

Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 23, 2023·arXiv (Cornell University)
0 cites
NFT formalised

Martha N. Kamkuemah, J. W. Sanders

Non-fungible tokens, NFT, have been used to record ownership of real estate, art, digital assets, and more recently to serve legal notice. They provide an important and accessible non-financial use of cryptocurrency's blockchain but are peculiar because ownership by NFT confers no rights over the asset. This work shows that it is possible to specify that peculiar property by combining functional and epistemic properties. Suitability of the specification is evaluated by proof that the blockchain implementation conforms to it, and by its use in an analysis of serving legal notice.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
cs.LO
Original source
Oct 23, 2023·2023 International Symposium on Networks, Computers and Communications (ISNCC)
3 cites
Blockchain, NFT, Federated Learning and Model Cards enabled UAV Surveillance System for 5G/6G Network Sliced Environment

Eranga Bandara, Sachin Shetty, Peter Foytik, Abdul Rahim Abdul Rahman · 7 authors

In recent years, the use of UAVs has expanded to various applications such as surveillance, disaster response, agriculture, and delivery. However, traditional UAV monitoring systems rely on direct communication between the UAV and the ground pilot, which has several limitations such as limited range, poor reliability, and susceptibility to interference. To overcome these limitations, there has been significant interest in integrating UAVs into cellular networks such as 5G/6G network slicing. The flexibility of network slicing allows UAVs to operate on different slices based on their communication needs, which can improve their performance and efficiency. However, integrating UAVs into network slicing also poses several challenges, such as managing communication and permissions of UAVs and base stations, access control of UAVs, and identity management of UAVs. To address these challenges, we propose a blockchain, Non-Fungible Token(NFT), Federated Learning(FL), and Zero-Trust(ZT) security-enabled UAV monitoring platform for 5G/6G network sliced environments. We propose a novel approach in which UAVs are represented as NFT tokens within the platform. This innovative representation allows for enhanced security and trust in the system, aligning with the principles of the Zero-Trust security model, which assumes no implicit trust in any network component or user. Furthermore, we propose a FL system that operates on top of the blockchain, which can analyze data from multiple UAVs across different network slices. Our proposed FL system uses coordinator-less models, which eliminates the attacks of a centralized coordinator. As a use case, we consider a scenario where our proposed system detects anomaly communications of UAVs and identifies attack surfaces via analyzing network traffic data of UAVs using FL. The 5G system testbed implemented with FreedomFi 5G gateway and Indoor Radio Cell.

Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
UAV Applications and Optimization
Original source
Oct 21, 2023·IET Blockchain
6 cites
Security and privacy issues in blockchain and its applications

Liangmin Wang, Victor S. Sheng, Boris Düdder, Haiqin Wu · 5 authors

Blockchain technology has emerged and evolved as a disruptive technology with the potential to be applied in various fields, including digital finance, healthcare, and the Internet of Things (IoT). Besides being a distributed ledger, blockchain enables decentralized and trusted storage/computation without relying on a central trusted party. However, the growing heterogeneity of blockchain platforms and the expanding range of applications have resulted in escalating security and privacy concerns. These concerns encompass persistent privacy breaches, vulnerabilities in smart contracts, and the “impossible triangle” problem. These challenges have emerged as the primary obstacles to the development and seamless integration of blockchain technology with industry applications. To address the security and privacy challenges in blockchain platforms and its applications, numerous researchers have conducted extensive studies in this field by leveraging advanced technologies, including new cryptographic protocols and deep learning techniques. This special issue aims to highlight research perspectives, articles, and experimental studies pertaining to “Security and Privacy Issues in Blockchain and Its Applications”. In this special issue, we received a total of nineteen papers, out of which seventeen underwent a rigorous peer-review process. However, two papers were excluded from the peer-reviewed selection because one was submitted in a draft form and the other was voluntarily withdrawn by the authors. Out of the seventeen papers submitted for review, ten were accepted for publication, six were rejected without being transferred, and one was rejected and referred to a transfer service. The exceptional quality of all the submissions played a crucial role in ensuring the success of this special issue. These accepted papers can be classified into two categories, namely blockchain application security and cross-chain interaction security. The papers in the first category focus on analyzing and providing insights into the security of blockchain applications. Their objective is to keep readers informed about the latest trends, developments, challenges, and opportunities in blockchain application security. Moreover, significant research efforts have been dedicated to security analysis and detection in typical blockchain applications. The papers in this category are of Zhou et al., Grybniak et al., Lv et al., Li et al., Gong et al., Xiao et al. and Videira et al. These contributions further enhance our understanding and capability to safeguard blockchain applications from potential security threats. The second category of papers presents novel solutions that target the enhancement of security in cross-system interactions. These papers are of Feng et al., Xu et al. and Yu et al. By addressing the specific challenges associated with cross-system communication, these solutions contribute to the development of robust and secure blockchain networks. A brief presentation of each of the papers in the special issue is as follows. Zhou et al. present WASMOD, a prototype system designed to detect vulnerabilities in WebAssembly (Wasm) smart contracts. WASMOD utilizes a combination of bytecode instrumentation, run-time validation, and grey-box fuzzing techniques to identify integer overflow and stack overflow vulnerabilities. The tool was effectively applied to the EOSIO blockchain, successfully detecting vulnerable smart contracts. Grybniak et al. propose “Waterfall: Gozalandia”, a distributed protocol based on the Proof of Stake approach. This protocol enables fast finality, proven safety, and liveness in a network utilizing BlockDAG structures. By employing cross-voting for block ordering, the protocol ensures swift consensus and the ability to detect dishonest behaviors. The protocol assumes the presence of a Coordinating network that holds information about the approved ordering. This Coordinating network serves to significantly enhance security and improve network synchronization in a qualitative manner. Through load testing, the protocol has demonstrated its ability to handle a throughput of 3200–3600 transactions per second, with an average confirmation waiting time of 20 s. Lv et al. propose a graph-based embedding classification method for phishing detection on the Ethereum blockchain. The method involves constructing multiple subgraphs using the transaction records collected from Ethereum and introduces a modified version of Graph2Vec called imgraph2vec. This modified approach aims to learn more meaningful information from the subgraphs. To identify phishing attempts, the Extreme Gradient Boosting (XGBoost) algorithm is utilized. Li et al. introduce BlockDetective, an innovative framework based on GCN that employs a student-teacher architecture to identify fraudulent cryptocurrency transactions. The framework incorporates pre-training and fine-tuning, enabling the pre-trained model (teacher) to effectively adapt to the new data distribution and improve prediction performance. Meanwhile, a lightweight model (student) is trained to provide abstract and high-level information. Experimental results demonstrate that BlockDetective outperforms state-of-the-art methods. Gong et al. propose a novel method called SCGformer, which aims to detect vulnerabilities in smart contracts. This novel method combines the power of a control flow graph (CFG) and a transformer model to enhance the accuracy and effectiveness of vulnerability detection. SCGformer involves constructing the CFGs using the operation codes (opcodes) of smart contracts. By focusing on the opcodes, SCGformer provides a language-agnostic solution, ensuring consistent vulnerability detection regardless of specific language versions. The authors conduct experiments to assess the efficacy of SCGformer, yielding an accuracy rate of 94.36%. Xiao et al. introduce a blockchain-based image copyright protection system named BB-RICP. By leveraging the distributed storage technique of blockchain, BB-RICP aims to solve the vulnerabilities of centralized storage, such as data loss and tampering. The system provides a novel solution for managing the entire lifecycle of copyright. It utilizes spread spectrum watermarking to enable traceability and incorporates GM algorithms and the PBFT consensus algorithm to enhance its functionality and effectiveness. Lastly, to enhance the practicality of the system, they implement a copyright blockchain framework called ICP-Chain and conduct evaluations to assess its security and reliability. Videira et al. propose a solution to tackle the offline puzzle in the implementation of central bank digital currencies (CBDC). This solution involves minting coins with unique serial numbers, which are then stored on a local blockchain within a smartphone or EMV card. The local blockchain is fortified by a two-stage approval architecture that effectively mitigates attacks and facilitates non-repudiation handling. To enhance security, the coins are safeguarded by hardware keys embedded in the microchip and can be continuously mined by the wallet. Feng et al. introduce a novel federated learning framework that leverages a Directed Acyclic Graph (DAG) to enhance interoperability among different blockchains. The framework comprises a shard chain and a main chain, featuring replaceable consensus mechanisms and a weighted context graph to enhance efficiency. The experimental results unequivocally demonstrate the efficacy of the proposed federated framework. Specifically, the framework significantly reduces the global computation requirements while simultaneously increasing the blockchain throughput. Xu et al. introduce ChainKeeper, a cross-chain scheme for governing the chain by chain. ChainKeeper incorporates several key components, including a modular node proxy program, a verifiable node random selection method (VNRS), and a verifiable identity threshold signature method (VITS). These components work together to ensure universality, efficiency, and security throughout the cross-chain process. The scheme is resilient against malicious behaviors and collaborative attacks from both business nodes and supervision nodes. The experimental results demonstrate the effectiveness of ChainKeeper in cross-chain supervision scenarios. Yu et al. present SPRA, a policy-based regulatory architecture designed to regulate blockchain transactions. The architecture comprises four layers: permission layer, regulation layer, bridge layer, and business layer. To facilitate interoperability between these layers, they introduce XRPL, a regulatory policy description language. The regulation layer incorporates JuryBC, a decentralized jury mechanism based on the Shamir threshold secret sharing algorithm and Pedersen commitment. At the business layer, they implement RDShare, a secure and efficient regulatory data sharing mechanism that utilizes attribute-based encryption. All the selected papers in this special issue showcase the continuous advancements in the field of blockchain and its application security. However, it is important to recognize that security and privacy issues in blockchain and its applications continue to pose significant challenges. These challenges serve as a driving force for further research and exploration of new technologies. They highlight the need for ongoing efforts to enhance the security and privacy aspects of blockchain, fostering a more resilient and trustworthy blockchain ecosystem. This work is supported by the National Key R&D Program of China (2020YFB1005500) and the National Natural Science Foundation of China (62372105). The authors would like to express their sincere appreciation to all the contributors who have submitted their scientific findings to this special issue and the anonymous reviewers whose expertise and meticulous work have made this endeavor possible. The authors sincerely hope that this collaborative effort will make a meaningful contribution to the advancement of the field. Lastly, the authors would like to express their utmost appreciation to the editors-in-chief and the editorial office for their unwavering support and guidance throughout this venture. Liangmin Wang received his B.S. degree in computational mathematics in Jilin University, Changchun, China in 1999, and his PhD degree in cryptology from Xidian University, Xi'an, China in 2007. He is a full professor in the School of Cyber Science and Engineering, Southeast University, Nanjing, China. He has been honored as a “Wan-Jiang Scholar” of Anhui Province since November 2013. Now his research interests include data security and privacy. He has published over 70 technical papers at premium international journals and conferences, for example, IEEE/ACM Transactions on Networking and IEEE International Conference on Computer Communications. He has severed as a TPC member of many IEEE conferences, such as IEEE ICC, IEEE HPCC, IEEE Trust-COM. Victor S. Sheng received the master's degree in computer science from the University of New Brunswick, Canada, in 2003, and the PhD degree in computer science from Western University, Ontario, Canada, in 2007. He is an associate professor of computer science, Texas Tech University, and the founding director of the Data Analytics Lab (DAL). His research interests include data mining, machine learning, and related applications. He was an associate research scientist and NSERC postdoctoral fellow in information systems at Stern Business School, New York University, after he obtained his PhD. He is a senior member of the IEEE and a lifetime member of the ACM. He received the test-of-time award for research from KDD’20, the best paper award runner-up from KDD’08, and the best paper award from ICDM’11. He is an area chair and SPC/PC member for several international top conferences and an associate editor for several international journals. Boris Düdder is an associate professor at the department of computer science (DIKU) at the University of Copenhagen (UCPH), Denmark. He is head of the research group Software Engineering & Formal Methods at DIKU. His primary research interests are formal methods and programming languages in software engineering of trustworthy distributed systems, where he is studying automated program generation for adaptive systems with high-reliability guarantees. He is working on the computational foundations of reliable and secure Big Data ecosystems. His research is bridging the formal foundations of computer science and complex industrial applications. Haiqin Wu received her B.E. degree in computer science and Ph.D. degree in computer application technology from Jiangsu University in 2014 and 2019, respectively. She is an associate professor at the Shanghai Key Laboratory of Trustworthy Computing (Software Engineering Institute), East China Normal University, China. Before joining ECNU, she was a postdoctoral researcher in the Department of Computer Science, University of Copenhagen, Denmark. She was also a visiting student in the School of Computing, Informatics, and Decision Systems Engineering at Arizona State University, USA. Her research interests include data security and privacy protection, mobile crowdsensing/crowdsourcing, and blockchain-based applications. Huijuan Zhu received her master's degree at School of Computer Science and Communication Engineering in Jiangsu University, Zhenjiang, China in 2010 and her Ph.D. degree at School of Computer and Control Engineering in University of Chinese Academy of Sciences, Beijing, China in 2017. Her research interests include malware detection and machine learning. She is an associate professor in the School of Computer Science and Communication Engineering at Jiangsu University.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy-Preserving Technologies in Data
Original source
Oct 20, 2023·Third International Conference on Signal Image Processing and Communication (ICSIPC 2023)
1 cites
Blockchain-based ciphertext access control for data sharing

Wenli Wu, Jinyi Zhao, Taowei Chen, Yimin Yu

Currently, with the continuous in-depth research and application of blockchain access control, security issues on the blockchain have become a focus of attention. Based on CPABE, this paper proposes a trusted and secure blockchain access control scheme based on ciphertext policy. Firstly, a decentralized attribute-based encryption algorithm (DABE) is adopted to achieve distributed calculation of user attribute private keys, effectively solving the problems of high trust cost and single point of failure caused by the key center generating private keys in traditional CPABE. At the same time, a private key consensus verification protocol based on zero-knowledge proof is designed to ensure the correctness and security of user attribute private keys without leaking private key information. Through the analysis of on-chain security and experimental simulation, the results show that this scheme has better performance while maintaining high security and is more suitable for distributed access control with large attribute scales.

Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Oct 18, 2023·2023 IEEE Secure Development Conference (SecDev)
4 cites
Security and Privacy Threat Analysis for Solid

Omid Mirzamohammadi, Kristof Jannes, Laurens Sion, Dimitri Van Landuyt · 6 authors

This paper provides an in-depth security and privacy analysis of the Solid protocol. Solid is a specification that allows user data to be stored decentralized in a personal online datastore (pod) independent from the application. This allows users to easily migrate to a different service and have more control over who data is shared with. We provide a comprehensive overview of the authentication, identification, and authorization protocols within Solid. We make use of the SPARTA threat modeling tool to assess the security and privacy aspects of Solid by modeling a realistic finance analytics application envisioned by the Solid community. This concrete use case allowed us to prioritize the residual threats in Solid. We employ methodologies such as STRIDE and LINDDUN for robust security and privacy threat modeling. The findings highlight the existence of several critical threats in the Solid specification. This is especially the case for privacy threats, which although it is an essential aspect of Solid, has so far not yet received enough attention, as our results indicate. These findings can be employed in future work to prioritize which residual threats to address and mitigate first.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Oct 18, 2023·2023 IEEE International Performance, Computing, and Communications Conference (IPCCC)
5 cites
HCPP: A Data-Oriented Framework to Preserve Privacy during Interactions with Healthcare Chatbot

Ziyan Cai, Xin Chang, Li Ping

Healthcare chatbots are becoming increasingly popular, but with their use comes the issues of excessive personal information collection and privacy leakage. To address this issue, we propose a Healthcare Chatbot-based Privacy Preserving (HCPP) Framework that adopts a data-oriented approach to reduce the excessive disclosure of personal information. HCPP consists of two main components: the Healthcare Chatbot-based Minimized Personal Information (HCMPI) method and the Healthcare Chatbot-based Zero Knowledge Proof (HCZKP) method. HCMPI leverages large language models (LLMs) to minimize the acquisition of unnecessary personal health information without significantly affecting healthcare service. HCZKP further encrypts a part of the minimized information, making the data available but invisible. The experimental evaluation results demonstrate the effectiveness and feasibility of our approach.

Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Digital Mental Health Interventions
Original source
Oct 17, 2023·2023 IEEE 14th International Conference on Software Engineering and Service Science (ICSESS)
8 cites
Secure Multi-Party Computing for Financial Sector Based on Blockchain

Wenzheng Li, Yang Bing, Yuxuan Song

Data dominates in finance, which is significant. The financial industry needs a cross-institutional data circulation mechanism to promote development, but data sharing faces challenges such as low credibility, low sharing efficiency, and privacy security issues, and there are still data islands and security sharing problems. Combining the characteristics of blockchain and privacy computing technology, this paper designs a secure and efficient multi-party computing model based on blockchain to find the balance between privacy and practicality of financial data and solve the tense situation in the financial industry to the greatest extent. Considering the limitations of blockchain storage and computing power, the solution in this paper is to introduce IPFS to combine on-chain storage data with on-chain indexing as a storage environment, and to introduce cloud networks as computing centers.

Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 17, 2023·Big Data and Cognitive Computing
69 cites
ZeroTrustBlock: Enhancing Security, Privacy, and Interoperability of Sensitive Data through ZeroTrust Permissioned Blockchain

Pratik Thantharate, Anurag Thantharate

With the digitization of healthcare, an immense amount of sensitive medical data are generated and shared between various healthcare stakeholders—however, traditional health data management mechanisms present interoperability, security, and privacy challenges. The centralized nature of current health information systems leads to single points of failure, making the data vulnerable to cyberattacks. Patients also have little control over their medical records, raising privacy concerns. Blockchain technology presents a promising solution to these challenges through its decentralized, transparent, and immutable properties. This research proposes ZeroTrustBlock, a comprehensive blockchain framework for secure and private health information exchange. The decentralized ledger enhances integrity, while permissioned access and smart contracts enable patient-centric control over medical data sharing. A hybrid on-chain and off-chain storage model balances transparency with confidentiality. Integration gateways bridge ZeroTrustBlock protocols with existing systems like EHRs. Implemented on Hyperledger Fabric, ZeroTrustBlock demonstrates substantial security improvements over mainstream databases via cryptographic mechanisms, formal privacy-preserving protocols, and access policies enacting patient consent. Results validate the architecture’s effectiveness in achieving 14,200 TPS average throughput, 480 ms average latency for 100,000 concurrent transactions, and linear scalability up to 20 nodes. However, enhancements around performance, advanced cryptography, and real-world pilots are future work. Overall, ZeroTrustBlock provides a robust application of blockchain capabilities to transform security, privacy, interoperability, and patient agency in health data management.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Original source
Oct 17, 2023·Management Science
24 cites
Understanding Partnership Formation and Repeated Contributions in Federated Learning: An Analytical Investigation

Xuan Bi, Alok Gupta, Mochen Yang

Limited access to large-scale data is a key obstacle to building machine learning (ML) applications in practice, partly due to a reluctance of information exchange among data owners out of privacy and data security concerns. To address this “information silo” problem, federated learning (FL) techniques have been proposed to enable decentralized model training via an orchestrating central server and have received increasing attention in several industries (including healthcare and finance). Despite its superior privacy protection property, adoption of FL is limited by a lack of systematic understanding of its underlying economics. In this paper, we take an analytical approach to answer two questions: (1) when do data owners prefer to form a FL partnership over building ML models by themselves and (2) how can different contractual mechanisms be used to promote repeated contributions to FL (the cooperative outcome that benefits all participants). We formulate an iterated prisoner’s dilemma (IPD) model that accounts for unique FL characteristics, including the specification of the payoff matrix and the involvement of a central server to sanction noncooperation. We find that partnership formation requires participants to be not too forward-looking in temporal preferences, which is contrary to the conventional wisdom in IPD. Furthermore, to promote repeated contributions, it is insufficient to only rely on penalties imposed by the central server or by participants for noncooperation, but a combination of both is enough. Our work advances theoretical understanding of the economics of FL and provides prescriptive insights that can inform FL participant selection and contract design. This paper was accepted by D. J. Wu, information systems. Funding: This work was partially supported by Cisco Research. Supplemental Material: The online appendices are available at https://doi.org/10.1287/mnsc.2023.00611 .

Blockchain Technology Applications and Security
Sharing Economy and Platforms
Privacy-Preserving Technologies in Data
Original source
Oct 17, 2023·2023 IEEE 14th International Conference on Software Engineering and Service Science (ICSESS)
0 cites
A Secure and Trusted Capital Verification Model Based on Blockchain and Zero Knowledge Proof

Zichen Zhu, Jing He, Xiaofeng Ma

Data leakage, result tampering, and oversight issues are issues with traditional capital verification. These issues can be successfully resolved using a combination of blockchain technology, smart contracts, cryptography, and other technologies because it is a traceable and tamper-proof data structure. In order to prevent data leaking, this article suggests a blockchain-based capital verification methodology that uses zero-knowledge proof technology. Using smart contracts, the possibility of result fabrication is automatically verified and removed. Additionally, this approach establishes a penetrating supervision scheme, and regulators are heavily involved in every facet of capital verification. The results of the experiment demonstrate that the plan is reliable and effective, has low storage costs, and can successfully safeguard personal data.

Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 16, 2023·IEEE Transactions on Network Science and Engineering
71 cites
Blockchain-Aided Secure Access Control for UAV Computing Networks

Jingjing Wang, Zihan Jiao, Jianrui Chen, Xiangwang Hou · 6 authors

Multiple unmanned aerial vehicles (UAVs) form a UAV cluster, which relies on wireless communication networks to facilitate information interaction among the UAVs. UAV clusters offer enhanced efficiency and fault tolerance, making reliable computing services possible. Compared to terrestrial networks, UAV computing network presents several desirable features, including mobility, availability, and flexibility, affording the potential for seamless global coverage. However, due to the inherent openness of wireless communication networks, UAV computing networks are susceptible to various security attacks. Existing access control mechanisms for UAV computing networks predominantly rely on base stations or central servers. This reliance elevates communication overhead for UAVs and exposes them to potential attacks from adversaries. Therefore, we propose a blockchain-aided distributed secure access control scheme specifically tailored for UAV computing networks, enabling UAVs to autonomously manage and determine identity, attributes, and access policies. To address the communication complexity and scalability concerns associated with blockchains, we integrate committee elections and clustering optimizations into the scheme. Security analysis and performance evaluation demonstrate that the proposed scheme can withstand common external and internal attacks in UAV clusters while ensuring lightweight energy consumption and scalability of UAV computing networks.

Blockchain Technology Applications and Security
UAV Applications and Optimization
Privacy-Preserving Technologies in Data
Original source
Oct 13, 2023·Engineering Technology & Applied Science Research
8 cites
Efficient and Secure Access Control for IoT-based Environmental Monitoring

Asia Othman Aljahdali, Afnan Habibullah, Huda Aljohani

Environmental monitoring devices based on IoT collect a large amount of data about the environment and our surroundings. These data are collected and processed before being uploaded to third-party servers and accessed and viewed by ordinary or specialized users. However, they may hold sensitive information that should not be exposed to unauthorized users. Therefore, accessing this sensitive information must be strictly controlled and limited in order to prevent unauthorized access. This research intends to create an access control mechanism based on distributed ledger technologies. The idea is to use a hybrid of IOTA technology and Ciphertext-Policy Attribute-Based Signcryption (CP-ABSC) technology. The permissions to access these data are written in a token, and this token will be sent to the Tangle after being signcrypted with CP-ABSC. Consequently, the data will be safeguarded, their confidentiality and integrity will be maintained, and unauthorized individuals will be unable to access the information. The proposed system was evaluated in terms of performance and the results showed that the system is straightforward, rapid, and convenient to use. Furthermore, a security assessment was conducted by running several scenarios to evaluate its feasibility and protection.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Oct 13, 2023·IEEE Transactions on Parallel and Distributed Systems
7 cites
HybridChain: Fast, Accurate, and Secure Transaction Processing with Distributed Learning

Amirhossein Taherpour, Xiaodong Wang

In order to fully unlock the transformative power of distributed ledgers and blockchains, it is crucial to develop innovative consensus algorithms that can overcome the obstacles of security, scalability, and interoperability, which currently hinder their widespread adoption. This paper introduces HybridChain that combines the advantages of sharded blockchain and DAG distributed ledger, and a consensus algorithm that leverages decentralized learning. Our approach involves validators exchanging perceptions as votes to assess potential conflicts between transactions and the witness set, representing input transactions in the UTXO model. These perceptions collectively contribute to an intermediate belief regarding the validity of transactions. By integrating their beliefs with those of other validators, localized decisions are made to determine validity. Ultimately, a final consensus is achieved through a majority vote, ensuring precise and efficient validation of transactions. Our proposed approach is compared to the existing DAG-based scheme IOTA and the sharded blockchain Omniledger through extensive simulations. The results show that IOTA has high throughput and low latency but sacrifices accuracy and is vulnerable to orphanage attacks especially with low transaction rates. Omniledger achieves stable accuracy by increasing shards but has increased latency. In contrast, the proposed HybridChain exhibits fast, accurate, and secure transaction processing, and excellent scalability.

Open access
3 source records
cs.DC
Blockchain Technology Applications and Security
Advanced Memory and Neural Computing
Original source