FOG-enabled cyber-physical systems (FOG-CPSs) open new security challenges as the local edge devices are easier to compromise than a traditional cloud server. Remote data integrity checking (RDIC) plays an important role in safeguarding against data corruption from a storage server. Certificateless cryptography (CLPKC)-based RDIC schemes do not suffer from the drawbacks of the public key infrastructure (PKI)-based RDIC protocols. Most of the CLPKC-based RDIC schemes proposed in the literature deal with personal data. However, in a FOG-CPS, it is also important to audit a data file shared by a group of edge devices. Most of the existing group shared data auditing schemes lack mechanisms to defend against a semi-trusted data auditor applicable for a FOG-CPS scenario. In order to address these issues, in this paper, we propose a novel CLPKC-based group shared data auditing protocol tailored to the specific security requirements of a FOG-CPS. Besides, we perform a detailed cryptanalysis of two existing CLPKC-based privacy-preserving group shared data auditing schemes. The formal security analysis of our proposed protocol establishes metadata and data integrity proof unforgeability and claimed zero-knowledge privacy and reliability properties through rigorous proofs in the random oracle model setting. Performance evaluations establish the efficiency of our proposed protocol.
In the internet of things, user information is usually collected by all kinds of smart devices. The collected user information is stored in the cloud storage, and there is a risk of information leakage. In order to protect the security and the privacy of user information, the user and cloud provider will periodically execute a protocol called proof of retrievability scheme. A proof of retrievability scheme ensures the security of the data by generating proof to convince the user that the cloud provider does correctly store the user information. In this paper, we construct a proof of retrievability scheme using the blockchain technology. Using the advantage that the stored data cannot be tampered with in blockchain, this ensures the integrity of the data. Specifically, some related definitions, security models, and a blockchain-based construction of a proof of retrievability scheme are given. Then the validity and security of the scheme are proved later. As a result, user information can be protected by our scheme.
Blockchain technology has become a trend in various sectors, both industrial and public sectors. There have been many questions regarding this blockchain technology in terms of competition in the public sector. Mainly among these are the concerns that become issues around governance and control in distributed ledgers. From an information security point of view this article investigates the influence of blockchain technology on public domain processes. It contains an outline of the development of the provision of public services and one-way information by the government to the community, the exchange of information and communication between the public and the government through the current blockchain application, and the current development of blockchain technology. We use a triad, Confidentiality-Integrity-Accessibility to guide our discussion of the interrelationships of security, operation, and regulation of this generation. By leveraging the triad model, we offer a framework for public managers who may also be able to recommend blockchain technology, and we observe the positive benefits that arise from the denial of a distributed ledger. In particular, we look at the benefits of blockchain technology which has to do with disclaimers to help public managers understand how to leverage blockchain generation for an application process.
Internet of Things (IoT) technology is now widely used in energy, healthcare, services, transportation, and other fields. With the increase in industrial equipment (e.g., smart mobile terminals, sensors, and other embedded devices) in the Internet of Things and the advent of Industry 4.0, there has been an explosion of data generated that is characterized by a high volume but small size. How to manage and protect sensitive private data in data sharing has become an urgent issue for enterprises. Traditional data sharing and storage relies on trusted third-party platforms or distributed cloud storage, but these approaches run the risk of single-node failure, and third parties and cloud storage providers can be vulnerable to attacks that can lead to data theft. To solve these problems, this paper proposes a Hyperledger Fabric blockchain-based secure data transfer scheme for enterprises in the Industrial Internet of Things (IIOT). We store raw data in the IIoT in the InterPlanetary File System (IPFS) network after encryption and store the Keyword-index table we designed in Hyperledger Fabric blockchain, and enterprises share the data by querying the Keyword-index table. We use Fabric's channel mechanism combined with our designed Chaincode to achieve privacy protection and efficient data transmission while using the Elliptic Curve Digital Signature Algorithm (ECDSA) to ensure data integrity. Finally, we performed security analysis and experiments on the proposed scheme, and the results show that overall the data transfer performance in the IPFS network is generally better than the traditional network, In the case of transferring 5 MB file size data, the transmission speed and latency of IPFS are 19.23 mb/s and 0.26 s, respectively, and the IPFS network is almost 4 times faster than the TCP/IP network while taking only a quarter of the time, which is more advantageous when transferring small files, such as data in the IIOT. In addition, our scheme outperforms the blockchain systems mainly used today in terms of both throughput, latency, and system overhead. The average throughput of our solution can reach 110 tps (transactions are executed per second), and the minimum throughput in experimental tests can reach 101 tps.
Blockchain is a distributed ledger technology used for trading digital assets, such as cryptocurrency, and trail records that need to be audited by third parties. The use cases of blockchain are expanding beyond cryptocurrency management. In particular, the token economy, in which tokenized assets are exchanged across different blockchain ledgers, is gaining popularity. Cross-chain technologies such as atomic swap have emerged as security technologies to realize this new use case of blockchain. However, existing approaches of cross-chain technology have unresolved issues, such as application limitations on different blockchain platforms owing to the incompatibility of the communication interface and crypto algorithm and inability to handle a complex business logic such as the escrow trade. In this study, the ConnectionChain is proposed, which enables the execution of an extended smart contract using abstracted operation on interworking ledgers. Moreover, field experimental results using the system prototype are presented and explained.
Regional medical consortium systems facilitates medical information sharing. However, many security issues exposed by the dominant centralized architectures, such as single points of failure, unauthorized operations and illegal access, are increasingly apparent constraints on the security and efficiency of data sharing across domains. Even more, any malicious operation detected, effective measures should be executed promptly for identity tracing. In this paper, we propose a secure and efficient cross-domain authentication scheme based on two cooperative blockchains (BCs) for medical consortium systems. Specifically, an intra-domain BC records any legal users’ registration and authentication information while an inter-domain BC is responsible for writing users’ cross-domain authentication information. In each domain, the general hospital acts as a trusted third service provider to achieve cross-chain interactions. For the entire cross-domain authentication procedure, anonymity mechanism is utilized to enhance security, and to trace malicious users, the improved chameleon hash is used in the intra-domain BC to redact the state of the user, and blacklist merkle tree is extended in the inter-domain BC to protect different domains’ services from illegal accessing. In addition, security analysis and performance evaluation are completely given to prove the superior security features and performance compared with other schemes.
Elizabeth Nathania Witanto, Yustus Eko Oktian, Sang-Gon Lee
AI has been implemented in many sectors such as security, health, finance, national defense, etc. However, together with AI’s groundbreaking improvement, some people exploit AI to do harmful things. In parallel, there is rapid development in cloud computing technology, introducing a cloud-based AI system. Unfortunately, the vulnerabilities in cloud computing will also affect the security of AI services. We observe that compromising the training data integrity means compromising the results in the AI system itself. From this background, we argue that it is essential to keep the data integrity in AI systems. To achieve our goal, we build a data integrity architecture by following the National Institute of Standards and Technology (NIST) cybersecurity framework guidance. We also utilize blockchain technology and smart contracts as a suitable solution to overcome the integrity issue because of its shared and decentralized ledger. Smart contracts are used to automate policy enforcement, keep track of data integrity, and prevent data forgery. First, we analyze the possible vulnerabilities and attacks in AI and cloud environments. Then we draw out our architecture requirements. The final result is that we present five modules in our proposed architecture that fulfilled NIST framework guidance to ensure continuous data integrity provisioning towards secure AI environments.
Blockchains and smart contracts are gaining momentum as enabling technologies for a wide set of applications where data distribution and sharing among decentralized infrastructures is required. In this work, we present a distributed application developed using blockchain technologies that allows individuals and health insurance organizations to come into agreement during the implementation of the healthcare insurance policies in each contract. For this purpose, health standards and semantic web technologies were used for the formal expression of both the insured individual's data and contract terms. Accordingly, a fine-grained data access policy was applied for evaluating contract terms on the basis of relevant data captured in healthcare settings. A prototype was implemented involving the development of several different smart contracts for the Ethereum platform as well as the necessary visual environment for accessing them. The developed system validates various features related to blockchain and smart contract features that are briefly discussed in this work, part of which can be mitigated or resolved through the use of a private permissioned blockchain. The application of well-established techniques for potential malfunctions of external services could also boost the security of the system and prevent it from potential attacks.
Document verification is a complicated domain with a variety of difficult and time-consuming methods to validate. Customized verification and authentication processes may be required for various sorts of papers, such as financial papers, government papers, transaction papers, educational credentials, and so on. A huge problem today we are facing is the number of fake certificates that are in circulation, this problem is quite predominant. This has become a new business for a long time. Hardworking people with genuine degrees/certificates have been suffering and they get rejected in the job market because of the lack of identification to differentiate between the original and the fake certificate. At times people are getting jobs through fake certificates and this becomes very dangerous. The scenario calls for a new system that can verify and authenticate certificates, their issuers, and their holders in a way that is much more efficient, simple, and intuitive to use, and efficiently mitigates widespread credential fraud. To combat the counterfeiting of academic certificates, our blockchain approach combines a verified distributed ledger with a cryptographic mechanism. Our Blockchain technology will also provide a standard sharing platform for storing and accessing documents, reducing overall verification time and allowing companies to quickly monitor and access real papers. Our system that helps to identify original certificates will help the hard-earned people to get their jobs in their desired organizations and all the fake circulation of certificates will be stopped because the system identifies the genuine true certificates.
Zhijie Sun, Dezhi Han, Dun Li, Xiangsheng Wang · 6 authors
Abstract Medical data involves a large amount of personal information and is highly privacy sensitive. In the age of big data, the increasing informatization of healthcare makes it vital that medical information is stored securely and accurately. However, current medical information is subject to the risk of privacy leakage and difficult to share. To address these issues, this paper proposes a healthcare information security storage solution based on hyperledger fabric and the attribute-based access control framework. The scheme first utilizes attribute-based access control, which allows dynamic and fine-grained access to medical information, and then stores the medical information in the blockchain, which can be secured and tamper-proof by formulating corresponding smart contracts. In addition, this solution also incorporates IPFS technology to relieve the storage pressure of the blockchain. Experiments show that the proposed scheme combining access control of attributes and blockchain technology in this paper can not only ensure the secure storage and integrity of medical information but also has a high throughput when accessing medical information
With the assistance of the Internet of Things, the fast developing Healthcare Internet of Things (H-IoT) has promoted the healthcare ecosystem into the era of Health 5.0 and enables many promising medical applications, such as remote healthcare that is crucial in pandemic (e.g., coronavirus disease 2019). Healthcare participants can make accurate diagnosis, treatment, and research based on the shared personal health records (PHRs) sensed from remote H-IoT devices. However, current H-IoT systems fall short of a secure and trustworthy PHR sharing service in remote healthcare, which is able to prevent user privacy leakage and PHR integrity violation together with high efficiency in key distribution alongside efficient data retrieval and fine-grained access control. In response, we present a blockchain-based hierarchical data sharing framework (BHDSF) to provide fine-grained access control and efficient retrieval over encrypted PHRs with low consumed hierarchical key distribution and key leakage resistance. Compared with the existing solutions, the BHDSF takes both untrusted cloud and malicious auditor into consideration simultaneously and achieves trustworthy PHR integrity auditing and metadata verification by leveraging the blockchain technique. Besides, the BHDSF enables efficiently aggregative authentication for the trustworthiness of source records from H-IoT devices, which is lacked in most of the existing data sharing frameworks. Finally, we demonstrate the feasibility of the BHDSF by conducting extensive empirical tests over a real-world dataset.
Credentials are one of the most important things to prove oneself in modern society. As the world goes digital, credentials change its form from paper to digital. However, digital data are easy to be forged and to be duplicated. To make digital data secure, cryptographic digital signature is the key technology ensuring its authenticity and integrity. And it is an inevitable choice for secure credential management systems. Recently blockchain has been raised as another key technology to guarantee data transparency. It is a decentralized and public ledger of transactions that anyone can participate and execute programs called smart contract. In this paper, we propose a credential management system based on Ethereum blockchain. This system provides users with a means both to manage their credentials by themselves and to prove their credentials without the issuer. We implemented its prototype on Ethereum, and analyzed the proposed system compared to previous systems.
The upcoming technology in creating the distributed applications for different use cases in real world applications are Blockchain technologies. The application may be private or public depending upon the use cases. Most of the applications are built by using the Ethereum platform in blockchain for use of security purpose. The nodes in the distributed network shares all the data to the other nodes without any modification of the data in the blockchain technology. The transactions done by the nodes were trusted through the digital signatures. Here, no central control or the central system will be there to keep track of other nodes data. In this paper, we built the POA network by using the Ethereum blockchain platform. The network is called the Proof of Authority and its main purpose is to deploy the contracts especially with authority in the Ethereum blockchain platform. We also explained about the ERC20 tokens, the working process of using the POA network and the codes for connecting with the web page.
Claudio Di Ciccio, Giovanni Meroni, Pierluigi Plebani
Abstract Being the blockchain and distributed ledger technologies particularly suitable to create trusted environments where participants do not trust each other, business process management represents a proper setting in which these technologies can be adopted. In this direction, current research work primarily focuses on blockchain-oriented business process design, or on execution engines able to enact processes through smart contracts. Conversely, less attention has been paid to study if and how blockchains can be beneficial to business process monitoring. This work aims to fill this gap by (1) providing a reference architecture for enabling the adoption of blockchain technologies in business process monitoring solutions, (2) defining a set of relevant research challenges derived from this adoption, and (3) discussing the current approaches to address the aforementioned challenges.
With the rise of blockchain technology, the peer-to-peer (P2P) network system has once again caught people's attention to equipping a blockchain with a big storage capacity. In the traditional P2P file-sharing network systems, such as InterPlanetary File System (IPFS), data stored in the other nodes cannot be revoked by the owner and can only be removed by other nodes themselves. To comply with the criteria of the European Union's General Data Protection Regulation, it is important to ensure that personal data can be completely removed by their owners. To improve the privacy and security of the P2P file-sharing system, we propose a revocable and monitorable P2P file-sharing system over a consortium blockchain to achieve revocation of files in the decentralized environment. By using a trusted execution environment, such as Intel Software Guard Extensions (SGX), the proposed scheme can verify the integrity of the executables of the P2P file-sharing system and generate a file authentication code for each IPFS node to make sure that the system is synchronized correctly. This scheme elaborately integrates the autonomous smart contracts and Intel SGX hardware to obtain the monitorable merit. The experimental results suggest that enhancing the security and privacy take modest computing costs into consideration. To the best of our knowledge, this scheme is the first attempt to achieve the P2P file-sharing system with securely revocable functions.
Sejong Lee, Jaehyeon Kim, Yongseok Kwon, Teasung Kim · 5 authors
BACKGROUND: With the increasing sophistication of the medical industry, various advanced medical services such as medical artificial intelligence, telemedicine, and personalized health care services have emerged. The demand for medical data is also rapidly increasing today because advanced medical services use medical data such as user data and electronic medical records (EMRs) to provide services. As a result, health care institutions and medical practitioners are researching various mechanisms and tools to feed medical data into their systems seamlessly. However, medical data contain sensitive personal information of patients. Therefore, ensuring security while meeting the demand for medical data is a very important problem in the information age for which a solution is required. OBJECTIVE: Our goal is to design a blockchain-based decentralized patient information exchange (PIE) system that can safely and efficiently share EMRs. The proposed system preserves patients' privacy in the EMRs through a medical information exchange process that includes data encryption and access control. METHODS: We propose a blockchain-based EMR-sharing system that allows patients to manage their EMRs scattered across multiple hospitals and share them with other users. Our PIE system protects the patient's EMR from security threats such as counterfeiting and privacy attacks during data sharing. In addition, it provides scalability by using distributed data-sharing methods to quickly share an EMR, regardless of its size or type. We implemented simulation models using Hyperledger Fabric, an open source blockchain framework. RESULTS: We performed a simulation of the EMR-sharing process and compared it with previous works on blockchain-based medical systems to check the proposed system's performance. During the simulation, we found that it takes an average of 0.01014 (SD 0.0028) seconds to download 1 MB of EMR in our proposed PIE system. Moreover, it has been confirmed that data can be freely shared with other users regardless of the size or format of the data to be transmitted through the distributed data-sharing technique using the InterPlanetary File System. We conducted a security analysis to check whether the proposed security mechanism can effectively protect users of the EMR-sharing system from security threats such as data forgery or unauthorized access, and we found that the distributed ledger structure and re-encryption-based data encryption method can effectively protect users' EMRs from forgery and privacy leak threats and provide data integrity. CONCLUSIONS: Blockchain is a distributed ledger technology that provides data integrity to enable patient-centered health information exchange and access control. PIE systems integrate and manage fragmented patient EMRs through blockchain and protect users from security threats during the data exchange process among users. To increase safety and efficiency in the EMR-sharing process, we used access control using security levels, data encryption based on re-encryption, and a distributed data-sharing scheme.
Ransomware attacks have caused serious data loss, and a frequent/good backup is the only solution to deal with such risks. Unfortunately, current research of data backup mainly focuses on improving data recovery efficiency, and rarely takes backups confidentiality and service DDoS attacks resistance into consideration, which greatly limits their usability in practice. In this work, we propose a novel data backup scheme called RAP (RAnsomware Protection scheme based on blockchain) to make up for the above deficiencies. Based on the principle of data isolation, we first formally discuss the role of gateways in data backup systems and deploy mechanism on gateways to resist DDoS attacks. RAP employs an optimized all-or-nothing transform (AONT) and offers the scheme for setup, backups upload and data recovery through secure channel. We define and analyze the security of RAP for data confidentiality and DDoS attacks resistance. We instantiate RAP by a consortium blockchain based on Ethereum and evaluate its performance. The running time of each phase in RAP is less than 1 millisecond excluding the$r$ead/$w$rite delay of typic data size and our scheme would be compatible with most existing blockchains, which further demonstrate its practicality and scalability.
Xueyan Liu, Yukun Luo, Xiaotao Yang, Li Wang · 5 authors
The integrity auditing of outsourced data is becoming an essential process because an increasing number of people or organizations are opting to store health records in cloud servers to reduce local storage. Most existing public auditing schemes requiring complex certificate management are unsuitable for resource-limited mobile devices and are unable to resist quantum attacks; thus, we propose a lattice-based proxy-oriented public auditing scheme for electronic health records. We construct an identity-based auditing scheme based on the small integer solution to avoid complex certificate management issues. We also introduce the idea of proxy to reduce computing overhead from the user side significantly and enable the application of resource-limited mobile devices. Furthermore, we improve the proposed scheme by integrating the Ethereum blockchain to resist malicious proxies. We prove that the proposed scheme is proxy-protected, unforgeable, and privacy-protected. Results of an efficiency analysis show that our scheme demonstrates high computing efficiency on the user side and comprehensive functions.
Virtual Machine Image (VMI) is the building block of cloud infrastructure. It encapsulates the various applications and data deployed at the Cloud Service Provider (CSP) end. With the leading advances of cloud computing, comes the added concern of its security. Securing the Cloud infrastructure as a whole is based on the security of the underlying Virtual Machine Images (VMI). In this paper an attempt has been made to highlight the various risks faced by the CSP and Cloud Service Consumer (CSC) in the context of VMI related operations. Later, in this article a formal model of the cloud infrastructure has been proposed. Finally, the Ethereum blockchain has been incorporated to secure, track and manage all the vital operations of the VMIs. The immutable and decentralized nature of blockchain not only makes the proposed scheme more reliable but guarantees auditability of the system by maintaining the entire VMI history in the blockchain.
Document verification is the first step whenever we enter any organization or institute. In any organization, it is essential to track, verify, and check the person’s background who will become a part of the organization. This process is very time-consuming and hectic for both parties involved. Various governments provide cloud-based digital locker services for the citizens storing the public document on a centralized server. But due to its centralized nature, this type of service is weak against information breaches and Denial of Service (DoS) attacks. Also, there are some privacy concerns with such centralized digital locker services as the stored documents may contain users’ crucial personal information. This paper proposes a blockchain-based digital locker in a decentralized application using Ethereum Blockchain to securely store personal documents with high availability. The proposed solution also verifies documents with ease, confidentiality, access control, data privacy, authenticity, and maintaining the integrity of documents.