Temidayo Abayomi-Zannu, Isaac Odun-Ayo, T. F. Barka
Abstract Voting is fundamental to any consensus-based society and is one of the most critical functions of democracy. Mobile voting (m-voting) was utilized as a means for voters to easily and conveniently cast their votes using their mobile devices which have been the most adopted means of communication but has a major problem which is safely securing the casted votes and avoiding any form of tampering. In this paper, we propose an m-voting framework that utilizes blockchain technology to securely store the casted votes and multi-factor authentication to authenticate the voters before they cast their votes while also providing an easily accessible, secure and transparent m-voting system.
The current land administration system of many countries including India is plagued with incomplete and damaged records. Different departments pertaining to land administration system store their own copy of records, which lead to incomplete verification and document forgery. In this paper, we present a blockchain-powered land administration system, termed as LandLedger, which provides accountable, transparent, efficient, secure and scalable land property administration. The proposed architecture of LandLedger realizes property verification, registration and revocation using specially designed transactions on a permissioned blockchain, which is managed by various departments such as Registrar's office, The Income tax department, The Revenue department and so on. LandLedger uses Merkle Patricia Tree to implement ownership verification and property history checking efficiently. The implementation of LandLedger shows its practicality with enhanced features in comparison to the current practice used in many countries including India.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Elections are one of a democratic society's primary pillars, but the Internet's emerging influence is continually challenging the voting process. Recently, E-voting based-Blockchain has already taken place in some countries. However, there are vulnerabilities issues around the E-voting system based- blockchain. This paper aims to highlight some of the risks and opportunities of the e-voting systems based blockchain. As well, we believe that this study can bring a valuable contribution as it illustrates some of the risks and opportunities of e-voting systems based-blockchain. That to offer users and developers a broad view of the potential risks and opportunities associated with the adoption of blockchain in the e-voting system.
Growing interest in educational data mining (EDM) and learning analytics (LA) to leverage big data and to benefit education and the science of learning has made data ownership an important focus point for institutions and students. While EDM and LA can provide important information that help enhance the quality of teaching and learning, it has become critical to ensure data privacy and student agency over data. In this paper, we introduce Kratos: an immutable and publicly verifiable data management system that enables EDM and LA, while maintaining data privacy and empowering students with a user interface for data governance and participation in school processes. The system aims to achieve data interoperability, which facilitates EDM and LA as incentives to educational stakeholders (policy makers, educators, developers of education technologies, etc.), while prioritizing student agency over their data. Our system gives students and schools an immutable log along with comprehensive access to data that is otherwise scattered across systems and vendors. The underlying set of rules of the system are defined in a set of smart contracts, codified from existing non-virtual agreements [1] between schools and education technology (edutech) vendors. We propose the smart contracts to be deployed on a public blockchain (like Ethereum or Bitcoin), for notarizing and time-stamping various interactions which users of Kratos may have with data. Third parties requesting access to school data have a unique virtual token assigned to them on the blockchain which helps keep track of data modifications, access and use.
Muntadher Sallal, Steve Schneider, Matthew Casey, Constantin Cătălin Drăgan · 9 authors
Online voting in the UK generally takes place without verifiability mechanisms, with providers that are trusted to provide ballot privacy and correctness of the result. However, replacing existing systems with verifiable voting systems with brand new algorithms and code presents a business risk to election providers. We present an approach for incremental change: adding a Selene-based verifiability layer to an existing online voting system. Selene is a verifiable e-voting protocol that publishes votes in plaintext alongside tracking numbers that enable voters to confirm that their votes have been captured correctly by the system. This results in a system where even the election authority running the system cannot change the result in an undetectable way. This gives stronger guarantees on the integrity of the election than were previously present. This gives an end-to-end verifiable system we call Verify My Vote (VMV). In addition, we outline how this approach supports further incremental changes towards the deployment of fully trustworthy online voting systems. The paper also describes the use of distributed ledger technology as a component of VMV to manage the verifiability data in a decentralised way for resilience and trust.
Blockchain technology is more and more popular for its advantage of decentralization, transparency, and nonmodifiable. In an electronic voting system, voting can be fair and secure by blockchain technology without a trusted third party. In this paper, we propose an economical and efficient electronic voting system based on the Ethereum Smart Contract that can also protect voters' privacy. The privacy of voters and votes can be protected by blind signature and homomorphic encryption. More importantly, the encryption algorithm is implemented in the Trusted Execution Environment (TEE), which can effectively reduce the complex operations in the contract and make the cost of Gas as low as possible. In addition, we also evaluated the system's implementation cost and designed a proposal to better protect voters' privacy for board-scale elections.
The massive spread of harmful content on the internet is hard to filter. Meanwhile, blacklist content filtering cannot keep up with the rapid growth of content creations. As a result, an extra protection layer is required to provide a safe internet for children. However, implementing a network or application firewall requires an expert's knowledge and complicated maintenance. In this paper, we proposed a framework to automate internet protection by using whitelist packet filtering. We use the blockchain smart contract as the secure collaboration media to determine the filtering rules. Meanwhile, the SDN controller automates the packet filtering by installing the determined forwarding rules into the network switches. We evaluate the whitelist packet filtering by using Mininet for the network emulation and Ethereum Rinkeby networks for the smart contract implementation. The result shows that the proposed whitelist system can filter the packet without incurring significant latency. It supports fast content update with a maximum speed of ≈ 1200 valid contents per-minute by using a three-votes verification system.
The lack of supervision is an important reason that hinders the development of cryptocurrencies. In the case of Bitcoin, many lawless elements use Bitcoin for illegal transactions. With the decentralization and anonymity provided by Blockchain, it is difficult for finance institudes to identify them by traditional means of supervision. Based on the existing research on Bitcoin server tracing, this paper proposes an efficient Bitcoin client tracing mechanism to trace from Bitcoin server to the client through traffic analysis. Experiments are carried out and show that under the condition of general network connection, the tracing accuracy is close to no error.
The potentials of using blockchains and distributed ledgers to support voting processes have attracted significant attention in the electronic voting community. Most of these recent ideas are centered on blockchain-based e-voting protocols. Others focus on how blockchain can be exploited to simultaneously deliver auditability and anonymity of voters in the voting process. A common feature of these research efforts is the use of blockchain within e-voting contexts. We elaborate in this work the integrity requirements that must be supported by blockchain in online voting as well as offline voting prevalent in developing countries. The framework conditions for blockchain-based voting are also discussed.
Zero-knowledge schemes have recently become a popular attempt to offer users privacy in an attribute-based credential system. In this article, we do not contest the mathematics of these schemes; we assume it is logically sound. Instead, we draw attention to the trade-off that is made when employing cryptography instead of trusted parties to protect user privacy. We assert that, for these approaches to create the trust required by credential verifiers, they must introduce mechanisms that limit their utility and create significant privacy risk to the user that cuts against data minimization goals. Greater trust must be placed in the shelf life of cryptography to prevent the user from being unwantonly correlated than alternative approaches. Just as we would discourage storing encrypted private data on public blockchains, we discourage this approach here. Lastly, this article introduces the concept of a trusted witness which provides privacy for honest users and solves the privacy-trust problem without the disadvantages of the zero-knowledge approach.
Oscar Avellaneda, Alan Bachmann, Abbie Barbir, Joni Brenan · 9 authors
The technology category now widely known as “decentralized identity” and more narrowly as “self-sovereign identity” didn’t even exist four years ago. At that time, the cutting edge of digital identity technology consisted of Internet- scale federated identity protocols such as OpenID Connect and user-centric data sharing protocols such as User-Managed Access (UMA). Then along came Bitcoin and a surge of interest in blockchain and distributed ledger technology (DLT). Although the initial uses of this technology focused primarily on cryptocurrency, it didn’t take long for the digital identity community to begin applying it to digital identity scenarios.
Election is a significant job in our Elective Government. As technology progress with upcoming days, its impact becomes more optimistic. One such outcome is the Blockchain. It is possible to transform the process of voting system due to its decentralized property of immutability. Voting in most places are non-transparent and common with the corruption. In this paper we proposed the technology, is Blockchain technology. The concept of this paper is to develop a decentralized application for voting system. From there, the transaction votes are stored in the blockchain could be illustrated by the examining the block hashes. The outcome of the project shows the transaction of tokens from voter’s wallet into the candidate’s wallet. This application can deploy on a test platform using the Ethereum Virtual Machine (EVM) it provides the network to test the application. From there, the integrity of the blockchain technology is illustrated.
Smart contracts on a blockchain behave precisely as specified by their code. A vulnerability in this code can lead to unexpected behaviour, which is hard to fix because a blockchain does not allow to change smart contract code after its deployment. Such vulnerabilities have led to several incidents. In the aftermath of such an event, a hard-fork between Ethereum and Ethereum classic was the result. This thesis proposes to develop a new smart contract programming language with the primary focus on safety, auditability, and the intention to prevent as many of the known categories of vulnerabilities by design as possible. The programming language's code is validated during deployment and afterwards isolated from other smart contracts running on the same blockchain to enforce compile-time guarantees during runtime. The designed programming language does evaluate new concepts and paradigms rarely used in non-smart contract environments for their potential benefit in a smart contract environment.
Recently, blockchain technology has become a topic in the spotlight but also a hotbed of various cybercrimes. Among them, phishing scams on blockchain have been found making a notable amount of money, thus emerging as a serious threat to the trading security of the blockchain ecosystem. In order to create a favorable environment for investment, an effective method for detecting phishing scams is urgently needed in the blockchain ecosystem. To this end, this paper proposes an approach to detect phishing scams on Ethereum by mining its transaction records. Specifically, we first crawl the labeled phishing addresses from two authorized websites and reconstruct the transaction network according to the collected transaction records. Then, by taking the transaction amount and timestamp into consideration, we propose a novel network embedding algorithm called trans2vec to extract the features of the addresses for subsequent phishing identification. Finally, we adopt the oneclass support vector machine (SVM) to classify the nodes into normal and phishing ones. Experimental results demonstrate that the phishing detection method works effectively on Ethereum, and indicate the efficacy of trans2vec over existing state-of-the-art algorithms on feature extraction for transaction networks. This work is the first investigation on phishing detection on Ethereum via network embedding and provides insights into how features of large-scale transaction networks can be embedded.
We study the liquid democracy problem, where each voter can either directly vote to a candidate or delegate his voting power to a proxy. We consider the implementation of liquid democracy on the blockchain through Ethereum smart contract and to be compatible with the realtime self-tallying property, where the contract itself can record ballots and update voting status upon receiving each voting massage. A challenge comes due to the gas fee limitation of Ethereum mainnet, that the number of instruction for processing a voting massage can not exceed a certain amount, which restrict the application scenario with respect to algorithms whose time complexity is linear to the number of voters. We propose a fast algorithm to overcome the challenge, such that i) shifts the on-chain initialization to off-chain and ii) the on-chain complexity for processing each voting massage is O(\log n), where n is the number of voters.
Abstract This article proposes a simple, efficient, and easy‐to‐use mechanism to add privacy and fine‐grained access control features to a traditional Blockchain. It uses standard cryptographic algorithms and techniques, along with a novel key derivation algorithm and a fuzzy extractor component (that derives a cryptographic key from a biometric), to make access control functionality very simple for nonexpert users. Such a Blockchain would be suitable for the storage of participant data postings in long‐term–isolated environments.
David Allessie, Martijn Janssen, Jolien Ubacht, Scott W. Cunningham · 5 authors
Blockchain technology has the potential to provide public services directly to the public. This challenges the need for public organizations, who traditionally provided these services. Much of the current work is focused on the technology, whereas the influence on public administration structure has gained less attention. The goal of this paper is to investigate the impact of blockchain technology on the governance of public service provision. For this, we performed a case study of an EU-wide system that monitors the movement of excise goods under duty suspension. We developed two scenarios for blockchain technology’s use based on a permissionless blockchain architecture on the one hand and a permissioned one on the other. The scenarios were evaluated based on their impact on transaction validation, data quality and governance. The findings show that blockchain technology alone cannot be an alternative for the current data quality controls, equal access assurances and adaptations to legislation conducted by public administrations. As such, governments will remain playing a key role in registration of documents and assets, however, the governance will likely change depending on the type of blockchain architecture.
As a decentralized cryptocurrency, Bitcoin has been in market for around a decade. Bitcoin transactions are thought to be pseudo-anonymous, however, there were many attempts to deanonymize these transactions making use of public data. Escrow services have been introduced as a good private and secure way to handle Bitcoin payments between untrusted parties, where the escrow service acts as the arbitrator in case of disputes. In our work, we examine the privacy and anonymity level of trades done through one of the Bitcoin trading websites offering such escrow services and how using the data they provide for open access through their APIs along with some public scraped data can compromise the privacy and anonymity of trades in some cases. In this paper, we suggest some heuristics and methods to deanonymize Bitcoin escrow trades done on LocalBitcoins.com, a well-known escrow service used especially by people seeking anonymity, and link them to suspect sets of Bitcoin transactions in the blockchain and suspect sets of users. Our research spots privacy weakness points of using escrow services that affects the privacy and anonymity of their users trades and identities. It also shows how tracking down criminals activities across escrow services is possible even without any authority on the escrow service making it less attractive for criminals to use cryptocurrencies and leading it to gain more trust.
Cryptocurrencies are digital assets which depend upon the use of distributed peer-to-peer networks. The method a new peer uses to initially join a peer-to-peer network is known as bootstrapping. The ability to bootstrap without the use of a centralized resource is an unresolved challenge. In this paper we survey the bootstrapping techniques used by 74 cryptocurrencies and find that censorship-prone methods such as DNS seeding and IP hard-coding are the most prevalent. In response to this finding, we test two other bootstrapping techniques less susceptible to censorship, Tor and ZMap, to determine if they are operationally feasible alternatives more resilient to censorship. We perform a global measurement study of DNS query responses for each the 92 DNS seeds discovered across 42 countries using the distributed RIPE Atlas network. This provides details of each cryptocurrencies' peer-to-peer network topology and also highlights instances of DNS outages and query manipulation impacting the bootstrapping process. Our study also reveals that the source code of the cryptocurrencies researched comes from only five main repositories; hence accounting for the inheritance of legacy bootstrapping methods. Finally, we discuss the implications of our findings and provide recommendations to mitigate the risks exposed.
Christof Ferreira Torres, Mathis Baden, Robert Norvill, Hugo Jonker
In recent years, smart contracts have suffered major exploits, losing millions of dollars. Unlike traditional programs, smart contracts cannot be updated once deployed. Though various tools were proposed to detect vulnerable smart contracts, they all fail to protect contracts that have already been deployed on the blockchain. Moreover, they focus on vulnerabilities, but do not address scams (e.g., honeypots). In this work, we introduce Æ GIS, a tool that shields smart contracts and users on the blockchain from being exploited. To this end, ÆGIS reverts transactions in real-time based on pattern matching. These patterns encode the detection of malicious transactions that trigger exploits or scams. New patterns are voted upon and stored via a smart contract, thus leveraging the benefits of tamper-resistance and transparency provided by blockchain. By allowing its protection to be updated, the smart contract acts as a smart shield.
Organized surveillance, especially by governments poses a major challenge to individual privacy, due to the resources governments have at their disposal, and the possibility of overreach. Given the impact of invasive monitoring, in most democratic countries, government surveillance is, in theory, monitored and subject to public oversight to guard against violations. In practice, there is a difficult fine balance between safeguarding individual's privacy rights and not diluting the efficacy of national security investigations, as exemplified by reports on government surveillance programs that have caused public controversy, and have been challenged by civil and privacy rights organizations. Surveillance is generally conducted through a mechanism where federal agencies obtain a warrant from a federal or state judge (e.g., the US FISA court, Supreme Court in Canada) to subpoena a company or service-provider (e.g., Google, Microsoft) for their customers' data. The courts provide annual statistics on the requests (accepted, rejected), while the companies provide annual transparency reports for public auditing. However, in practice, the statistical information provided by the courts and companies is at a very high level, generic, is released after-the-fact, and is inadequate for auditing the operations. Often this is attributed to the lack of scalable mechanisms for reporting and transparent auditing. In this paper, we present SAMPL, a novel auditing framework which leverages cryptographic mechanisms, such as zero knowledge proofs, Pedersen commitments, Merkle trees, and public ledgers to create a scalable mechanism for auditing electronic surveillance processes involving multiple actors. SAMPL is the first framework that can identify the actors (e.g., agencies and companies) that violate the purview of the court orders. We experimentally demonstrate the scalability for SAMPL for handling concurrent monitoring processes without undermining their secrecy and auditability.
Muhammed F. Esgin, Raymond K. Zhao, Ron Steinfeld, Joseph K. Liu · 5 authors
We introduce MatRiCT, an efficient RingCT protocol for blockchain confidential transactions, whose security is based on "post-quantum'' (module) lattice assumptions. The proof length of the protocol is around two orders of magnitude shorter than the existing post-quantum proposal, and scales efficiently to large anonymity sets, unlike the existing proposal. Further, we provide the first full implementation of a post-quantum RingCT, demonstrating the practicality of our scheme. In particular, a typical transaction can be generated in a fraction of a second and verified in about 23 ms on a standard PC. Moreover, we show how our scheme can be extended to provide auditability, where a user can select a particular authority from a set of authorities to reveal her identity. The user also has the ability to select no auditing and all these auditing options may co-exist in the same environment. The key ingredients, introduced in this work, of MatRiCT are 1) the shortest to date scalable ring signature from standard lattice assumptions with no Gaussian sampling required, 2) a novel balance zero-knowledge proof and 3) a novel extractable commitment scheme from (module) lattices. We believe these ingredients to be of independent interest for other privacy-preserving applications such as secure e-voting. Despite allowing 64-bit precision for transaction amounts, our new balance proof, and thus our protocol, does not require a range proof on a wide range (such as 32- or 64-bit ranges), which has been a major obstacle against efficient lattice-based solutions. Further, we provide new formal definitions for RingCT-like protocols, where the real-world blockchain setting is captured more closely. The definitions are applicable in a generic setting, and thus are believed to contribute to the development of future confidential transaction protocols in general (not only in the lattice setting).
Blockchain is the technology that has attracted enormous interest recently as it provides security and privacy through immutable distributed ledger. It is the backbone of the most popular cryptocurrency, bitcoin. Due to its robust consensus mechanism and tamper proof data storage, it is widely adopted in the applications where trust is given utmost importance.Homomorphic Encryption algorithms can be used to operate on the data that is encrypted without the knowledge of private key. Operations can be performed on encrypted data without decrypting the data. Only client knows about the private key. These two technologies can be used to securely transfer and store data in the cloud systems.In this paper we propose how this blockchain technology and homomorphic encryption can be used to build reliable, tamper-proof and efficient electronic voting system. An electronic voting system should be secure, and itshould not allow duplicate votes and be fully tamper proof, while protecting the privacy of the voters. In this work, we have designed, implemented and tested an electronic voting application and providing hashing for votes and stored in blockchaincloud.If data in database is lost, then it can be retrieved from blockchain cloud.