Zhenpeng Liu, Shuo Wang, Yi Liu
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
5,430 results · page 73 of 227
Zhenpeng Liu, Shuo Wang, Yi Liu
No abstract is available for this record.
Ronglei Hu, Ziwei Ma, Li Li, Peiliang Zuo · 7 authors
Ciphertext policy-attribute-based encryption (CP-ABE), which provides fine-grained access control and ensures data confidentiality, is widely used in data sharing. However, traditional CP-ABE schemes often choose to outsource data to untrusted third-party cloud service providers for storage or to verify users' access rights through third parties, which increases the risk of privacy leakage and also suffers from the problem of opaque permission verification. This paper proposes an access control scheme based on blockchain and CP-ABE, which is based on multiple authorization centers and supports policy updating. In addition, blockchain technology's distributed, decentralized, and tamper-proof features are utilized to solve the trust crisis problem in the data-sharing process. Security analysis and performance evaluation show that the proposed scheme improves the computational efficiency by 18%, 26%, and 68% compared to previous references. The proposed scheme also satisfies the indistinguishability under chosen-plaintext attack (IND-CPA).
Kouadio Rodrigue N’Goran, Jean-Louis Tetchueng, Yvon Kermarrec, Pacôme Brou · 5 authors
Collaboration through resource sharing (hardware and software) offers many advantages to companies in terms of scalability and economic growth. The community cloud provides a platform for organizations to share and cooperate. However, the reliability of interactions within this distributed and heterogeneous infrastructure is linked to an efficient management of identities of the actors. It requires a control and an autonomy of each entity in the management of its users and the means of identification of its peers. Several works have proposed identity and access management systems for distributed systems, the most recent of which are based on distributed ledger technologies such as the blockchain. In addition to identity, collaboration within a community requires mutual trust, evidence of voluntary commitment and validation of consensual member integration. In this paper, we propose a decentralized identity and access management system based on smart contracts and a network of blockchain oracles. Our model uses decentralized identifiers and digital signature aggregation through the Boneh, Lynn and Shacham (BLS) signature algorithm for identification and registration of an organization in the community. Furthermore, verifiable credentials are used for authentication and resources access authorization. In addition, oracles serve as an interface for transmitting information necessary for smart contracts for evaluation, trust monitoring and exchange within the community.
Wei Du, Hanxu Liu, Guannan Luo, Jiyuan Zhang · 5 authors
Procuratorates, as the prosecutor in public interest litigation (PIL), need to obtain evidence from other PIL stakeholders including citizens, companies, governmental agencies, IoT monitoring devices and so on. However, the evidence sharing is not smooth due to the lack of secure data sharing and privacy protection during case investigation and evidence collection. Therefore, the authors propose a consortium blockchain-based secure data sharing and privacy protection scheme named PILChain. The involved organizations are connected as peers in PILChain. The safety of uploaded evidence and user privacy can be guaranteed with a fine-grained access control and zero-knowledge identity proof. InterPlanetary File System is introduced to store large evidence files off-chain, further enhancing the data security and system scalability. The security of PILChain is analyzed in terms of access control, evidence confidentiality, evidence integrity, traceability, privacy, and scalability. Last, the authors evaluate the performance of the developed prototype system by implementing PILChain on Hyperledger Fabric.
Varbinka Stefanova-Stoyanova, Ivan Stankov, Bogdan Danov
The need to send secure messages without having to disclose additional information beyond the content; checking data integrity without having visibility into the data itself; Providing the integrity of various systems through validation that does not require the disclosure of sensitive data leads to the discovery of the potential of Zero Knowledge Proof (ZKP) and the technique of Smart Questioning (SQ) to verify the authenticity of the given statement, which involves asking specific questions.
Ruiyun Yu, Ann Move Oguti, Mohammad S. Obaidat, Shu Li · 6 authors
No abstract is available for this record.
Kasra Ahmadi, Molud Esmaili, Siavash Khorsandi
Online merchandising plays an important role in internet users’ behavior. With the advent of Web3.0 and blockchain technologies, online markets can be adapted to these new changes. In traditional online markets, buying and selling are performed in a centralized manner, which, in addition to the problems of centralized systems, also brings the challenge of users’ trust. One of the challenges in online markets is maintaining the privacy and not revealing the exchanged file to unauthorized entities. Another challenge is to have a mechanism to detect fraud in the market. If the wrong file or key is sent by the seller, the fraud detection mechanism guaranties that the smart contract will be informed and the buyer will be refunded. On the other hand, the seller will be paid if a correct file and its corresponding key have been sent.Blockchain network is not suitable for file storing. Therefore, there are centralized or decentralized methods to store files in building a blockchain based file sharing market. In this work, we selected a distributed file system storage called IPFS (InterPlanetary File system). We integrated IPFS network with a suitable smart contract which is deployed on Ethereum blockchain. We provided a decentralized dispute resolution mechanism to resolve any dispute that happens between market users.
Tariq Bontekoe, Dimka Karastoyanova, Fatih Türkmen
Privacy-preserving computation (PPC) methods, such as secure multiparty computation (MPC) and homomorphic encryption (HE), are deployed increasingly often to guarantee data confidentiality in computations over private, distributed data. Similarly, we observe a steep increase in the adoption of zero-knowledge proofs (ZKPs) to guarantee (public) verifiability of locally executed computations. We project that applications that are data intensive and require strong privacy guarantees, are also likely to require verifiable correctness guarantees, especially when outsourced. While the combination of methods for verifiability and privacy protection has clear benefits, certain challenges stand before their widespread practical adoption. In this work, we analyze existing solutions that combine verifiability with privacy-preserving computations over distributed data, in order to preserve confidentiality and guarantee correctness at the same time. We classify and compare 37 different schemes, regarding solution approach, security, efficiency, and practicality. Lastly, we discuss some of the most promising solutions in this regard, and present various open challenges and directions for future research.
Manisha Guduri, Chinmay Chakraborty, V. Uma Maheswari, Martin Margala
This study introduces a blockchain-based lightweight encryption strategy with federated learning to address the scalability and trust concerns of electronic health records (EHR). After implementing lightweight encryption, the EHR data is stored in a decentralized cloud system. The importance of protecting the privacy and security of distant patients’ health records is explored. Now that stakeholders have a secure portal and cloud data is inaccessible, assaults on electronic healthcare records should decrease. The study guarantees full encryption throughout the whole conversation with federated learning. Deprived of the essential for a trusted third party, the system sets up active smart contracts at runtime between the sensor and the data user to facilitate the transfer of EHR data. To ensure that the data is private between the owner and user during the contract’s execution, it employs a very effective proxy re-encryption mechanism with federated learning. To examine the performance of the proposed system, it has been built and deployed on an Ethereum-based testbed. It is observed that the PSNR and MSE of the proposed model are 39 (1.07×) and 229.6 (1.02×) respectively. The entropy of the image is assessed to be 7.8 for the proposed model. This is also compared with existing algorithms and proved to be a secured model.
Kumar Satyam, Ayush Sharma, Runumi Devi
A blockchain-based electronic health record (EHR) system has been proposed to manage patient data and maintain computerized records across different healthcare institutions. The main objective of this system is to provide immediate access to patient health information while addressing concerns about privacy and security. It is developed on the Ethereum network using programming languages, tools, and technologies such as Ganache, Solidity, and web3.js. The system uses smart contracts to provide security and privacy, and transactions are verified and propagated to the entire decentralized network. The system includes a cryptocurrency wallet (MetaMask) with a centralized privacy system that allows authorized parties to access and secure records quickly. The proposed system aims to achieve several objectives such as allowing users to receive the same data simultaneously, increasing efficiency, building trust, and reducing barriers. It secures data storage by restricting user access and enables the secure transfer of patient medical records. The solution allows for better transparency and ownership of sensitive data, which can be recorded and safeguarded via blockchain technology, therefore assisting the healthcare sector. This paper describes a medical record system and a new protocol that can be used quickly and safely, paving the way for more secure and efficient healthcare systems. Overall, the proposed system offers potential solutions to the challenges associated with traditional EHR systems and has the potential to revolutionize the healthcare industry.
Zhuoliang Qiu, Zhijun Xie, Xianliang Jiang, Chuan Ran · 5 authors
It is crucial to ensure the privacy and authenticity of the owner’s information in car insurance claims. However, the current traditional car insurance claims scenario suffers from inefficiency, complex service, unreliable data, and data leakage. Therefore, considering the privacy and sensitivity of insurance information and car owner data, we can use blockchain, smart contracts, and zero-knowledge proof technology to improve the current problems. This paper proposes a novel car insurance claim scheme based on smart contracts, blockchain, and zero-knowledge proof. Our scheme focuses on preserving privacy in the car insurance authorization and claim process. We design a private smart contract for the creation and revocation of car insurance and public smart contract for the authorization and validation of car insurance. By using ZoKrates, generating zero-knowledge proofs off chain and verifying the proofs on chain reduces the amount of data storage and computation on chain and provides privacy protection for sensitive information. Experimental results confirm the efficacy of our scheme in terms of security and performance.
Aditya Narayan, K. H. Weng, Nirav R. Shah
UNSTRUCTURED This paper explores the relationship between the development of the internet and health care, highlighting their parallel growth and mutual influence. It delves into the transition from the early, static days of Web 1.0, akin to siloed physician expertise in health care, to the more interactive and patient-centric era of Web 2.0, which was accompanied by advancements in medical technologies and patient engagement. This paper then focuses on the emerging era of Web3—the decentralized web—which promises a transformative shift in health care, particularly in how patient data are managed, accessed, and used. This shift toward Web3 involves using blockchain technology for decentralized data storage to enhance patient data access, control, privacy, and value. This paper also examines current applications and pilot projects demonstrating Web3’s practical use in health care and discusses key questions and considerations for its successful implementation.
Ehsan Toreini, Maryam Mehrnezhad, Aad van Moorsel
Fair machine learning is a thriving and vibrant research topic. In this paper, we propose Fairness as a Service (FaaS), a secure, verifiable and privacy-preserving protocol to computes and verify the fairness of any machine learning (ML) model. In the deisgn of FaaS, the data and outcomes are represented through cryptograms to ensure privacy. Also, zero knowledge proofs guarantee the well-formedness of the cryptograms and underlying data. FaaS is model--agnostic and can support various fairness metrics; hence, it can be used as a service to audit the fairness of any ML model. Our solution requires no trusted third party or private channels for the computation of the fairness metric. The security guarantees and commitments are implemented in a way that every step is securely transparent and verifiable from the start to the end of the process. The cryptograms of all input data are publicly available for everyone, e.g., auditors, social activists and experts, to verify the correctness of the process. We implemented FaaS to investigate performance and demonstrate the successful use of FaaS for a publicly available data set with thousands of entries.
R. Regin, Akanksha Khanna, Vamsi Krishnan, Muskan Gupta · 6 authors
In response to the safety concerns surrounding the IoT, an attribute-based encryption and access control scheme (ABE-ACS) has been proposed. This scheme can be more effectively implemented through the use of cutting-edge technology and incorporating attribute-based encryption (ABE) and attribute-based access control (ABAC) models with features as the point of origin. Facing Edge-IoT is a heterogeneous network made up of certain nodes with more powerful computers and the majority of resource-constrained IoT devices. The authors provide a lightweight with an upgrade to the proof-of-work consensus to address the issues of excessive resource consumption and challenging deployment of existing platforms. To protect the confidentiality of the access control policies, the limits of the tree are utilised for transformation and allocation stored. Six smart contracts are created for devices and data to implement the ABAC and punishment mechanism, which outsources ABE to edge nodes for privacy and integrity. Thus, the plan implements device-controlled access and Edge-IoT privacy protection for data.
Prasanna Siddharth Mukkamala, Haiqin Wu, Boris Düdder
Truth discovery is an effective and compelling approach to addressing data conflicts among different workers and offers more trustworthy truths to task requesters in crowdsourcing. Prior research either focused on studying more accurate truth discovery algorithms or aimed to protect data privacy from the centralized and honest-but-curious crowdsourcing platforms. They all overlooked the stronger threats from the malicious crowdsourcing platform (e.g., may return incorrectly estimated truths) and many critical issues inherited from centralization. This paper proposes a blockchain-based decentralized truth discovery scheme for crowdsourcing, with computation integrity guarantees against malicious participants and support for efficient processing of generic streaming data. We adopt the idea of hybrid storage and computations to ease the expensive on-chain cost. Workers are grouped for off-chain partial truth estimation and smart contracts are leveraged for on-chain final truth aggregation. To prevent any improper computations from malicious entities, we record the hashes of data and worker weights on-chain occasionally. Through theoretical analysis and extensive experiments over real-world and synthetic datasets implemented in Ethereum, we demonstrate that our scheme 1) achieves our reliability goals with certain privacy assurance; 2) exhibits a higher truth estimation accuracy than existing approaches and a lower gas consumption than the baseline.
Rui Shi, Yang Yang, Yingjiu Li, Huamin Feng · 7 authors
Attribute-based anonymous credentials offer users fine-grained access control in a privacy-preserving manner. However, in such schemes obtaining a user's credentials requires knowledge of the issuer's public key, which obviously reveals the issuer's identity that must be hidden from users in certain scenarios. Moreover, verifying a user's credentials also requires the knowledge of issuer's public key, which may infer the user's private information from their choice of issuer. In this paper, we introduce the notion of double issuer-hiding attribute-based credentials (${\sf DIHAC}$) to tackle these two problems. In our model, a central authority can issue public-key credentials for a group of issuers, and users can obtain attribute-based credentials from one of the issuers without knowing which one it is. Then, a user can prove that their credential was issued by one of the authenticated issuers without revealing which one to a verifier. We provide a generic construction, as well as a concrete instantiation for${\sf DIHAC}$based on structure-preserving signatures on equivalence classes (JOC's 19) and a novel primitive which we calltag-based aggregatable mercurial signatures. Our construction is efficient without relying on zero-knowledge proofs. We provide rigorous evaluations on personal laptop and smartphone platforms, respectively, to demonstrate its practicability.
Mahyar Sadrishojaei, Faeze Kazemian
No abstract is available for this record.
Wenxuan Ye, Chendi Qian, Xueli An, Xueqiang Yan · 5 authors
Integrating native AI support into the network architecture is an essential objective of 6G. Federated Learning (FL) emerges as a potential paradigm, facilitating decentralized AI model training across a diverse range of devices under the co-ordination of a central server. However, several challenges hinder its wide application in the 6G context, such as malicious attacks and privacy snooping on local model updates, and centralization pitfalls. This work proposes a trusted architecture for supporting FL, which utilizes Distributed Ledger Technology (DLT) and Graph Neural Network (GNN), including three key features. First, a pre-processing layer employing homomorphic encryption is incorporated to securely aggregate local models, preserving the privacy of individual models. Second, given the distributed nature and graph structure between clients and nodes in the pre-processing layer, GNN is leveraged to identify abnormal local models, enhancing system security. Third, DLT is utilized to decentralize the system by selecting one of the candidates to perform the central server's functions. Additionally, DLT ensures reliable data management by recording data exchanges in an immutable and transparent ledger. The feasibility of the novel architecture is validated through simulations, demonstrating improved performance in anomalous model detection and global model accuracy compared to relevant baselines.
Carlos Efrain Quintero-Narvaez, Raúl Monroy-Borja
We present an implementation of a Web3 platform that leverages the Groth16 Zero-Knowledge Proof schema to verify the validity of questionnaire results within Smart Contracts. Our approach ensures that the answer key of the questionnaire remains undisclosed throughout the verification process, while ensuring that the evaluation is done fairly. To accomplish this, users respond to a series of questions, and their answers are encoded and securely transmitted to a hidden backend. The backend then performs an evaluation of the user's answers, generating the overall result of the questionnaire. Additionally, it generates a Zero-Knowledge Proof, attesting that the answers were appropriately evaluated against a valid set of constraints. Next, the user submits their result along with the proof to a Smart Contract, which verifies their validity and issues a non-fungible token (NFT) as an attestation of the user's test result. In this research, we implemented the Zero-Knowledge functionality using Circom 2 and deployed the Smart Contract using Solidity, thereby showcasing a practical and secure solution for questionnaire validity verification in the context of Smart Contracts.
Yipeng Zou, Tao Peng, Guojun Wang, Entao Luo · 5 authors
No abstract is available for this record.
Rui Shi, Yang Yang, Huamin Feng, Feng Yuan · 6 authors
No abstract is available for this record.
Jingchi Zhang, Anwitaman Datta
In traditional cloud storage systems, users benefit from the convenience of data accessibility but face significant risks related to security. Ciphertext-policy attribute-based encryption (CP-ABE) schemes are employed to achieve fine-grained access control in cloud services to ensure confidentiality while maintaining data-sharing capabilities. However, existing approaches are impaired by two critical issues: illegal authorization and privacy leakage. Despite extensive discussions in the literature on interoperability, performance, scalability, and stability, the security of ABE-based cloud storage and data-sharing systems against adversaries-particularly those involving adaptively corrupt attribute authorities gaining unauthorized access to users' data-has not been sufficiently explored. Notably, few existing works even address security in the presence of adversaries, raising concerns about the practicality of these systems in real-world scenarios where malicious behavior is a genuine threat. Another pressing issue is privacy leakage, where sensitive user information, such as medical histories in healthcare use cases, embedded within the access policies, may be exposed to all users. This problem is exacerbated in ABE schemes that integrate blockchain technology for enhanced decentralization and interoperability, as using a public ledger shared across multiple users can further compromise privacy. To address these, we propose an enhanced blockchain-based data governance system that employs blockchain technology and attribute-based encryption to prevent illegal authorization and privacy leakage. Our novel ABE encryption system supports multi-authority use cases while hiding access policy and ensuring identity privacy, which also protects data sharing against corrupt authorities. Utilizing the Advanced Encryption Standard (AES) for data encryption, our system is optimized for real-world efficiency. Notably, the encrypted data is stored in a decentralized storage system, like the InterPlanetary File System (IPFS), which does not rely on any centralized service provider and can, therefore, be leveraged to achieve resilience against single-point failures. With the integration of smart contracts and multi-authority attribute-based encryption, coupled with blockchain's inherent transparency and traceability, our system realizes a balanced solution for fine-grained access control with preserved privacy, further fortifying against credential misuse. Besides the system design, we also present security proofs to demonstrate the robustness of the proposed system.
Hedieh Sajedi, Fatemeh Mohammadipanah
No abstract is available for this record.
Chenquan Gan, Hongpeng Yang, Qingyi Zhu, Yiye Zhang · 5 authors
No abstract is available for this record.