In the past, electronic voting systems have not seen widespread adoption due to data privacy concerns. Previously proposed e-voting systems make use of a central database to store data, resulting in the servers used to store these databases being a single point of failure. These systems have also been found to be vulnerable to DoS attacks, leading to concerns over their reliability. Blockchains have been used to build secure and scalable distributed systems which have shown several benefits over centralized systems. They have seen uses in sectors ranging from finance and healthcare to food and energy. In this paper, we present VoteChain, a blockchain based voting system to help bring transparency and security to polls. We report on our implementation of VoteChain, as well as the results obtained in testing the system in a real-world poll which prove that such a system can be used in practice for large-scale elections.
Smart city is one of the major Internet of Things (IoT) applications and has become an emerging paradigm with the recent advancements of IoT devices and sensors. But the heterogenous nature of a smart city IoT environment makes it vulnerable to many privacy and security concerns and introduces significant challenges for access control of IoT resources especially where access needs to be provided to third parties and external organizations. This paper proposes a new structural relationships-based access control (SRBAC) model that can be used to delegate resource access rights to users in a large scale IoT scenario like smart city while keeping the resource owner in full control. The proposed architecture uses smart contracts and public blockchain for managing access control for external users and a local off-block chain storage for managing access control for organization’s internal users and enforcing fine-grained access control for the resources.
Kristián Košťál, Rastislav Bencel, Michal Ries, Ivan Kotuliak
Some forms of voting have been here ever since. Mostly used form all over the world are paper ballots. Electronic voting schemes are being popular only in the last decade and they are still unsolved. E-voting schemes bring problems mainly regarding security, credibility, transparency, reliability, and functionality. Estonia is the pioneer in this field and may be considered the state of the art. But there are only a few solutions using blockchain. Blockchain can deliver an answer to all of the mentioned problems and furthermore bring some advantages such as immutability and decentralization. The main problems of technologies utilizing blockchain for e-voting are their focus on only one field or lack of testing and comparison. In this paper, we present a blockchain-based e-voting platform, which can be used for any kind of voting. It is fully utilized by blockchain and all processes can be handled within it. After the start of the voting, the platform behaves as fully independent and decentralized without possibilities to affect the voting process. The data are fully transparent, but the identity of voters is secured by homomorphic encryption. We have tested and compared our solution in three different blockchains. The results show, that both public and private blockchains can be used with only a little difference in the speed. The key novelty of our solution is a fully decentralized management of e-voting platform through blockchain, transparency of the whole process and at the same time security and privacy of the voters thanks to homomorphic encryption.
Sina Rafati Niya, Sebastian Allemann, Arik Gabay, Burkhard Stiller
Data leaks and privacy scandals have been a growing concern of the last decade. While most traditional, i.e., centralized, online platforms require users to register with their personal data, they potentially expose the user's identity and data to be used for unintended purposes. This work proposes TradeMap as an integrated architecture, designing and enabling an online end-to-end (e2e) trading market place, while supporting anonymous management features. TradeMap addresses the Swiss Financial Market Supervisory Authority (FINMA) regulations by designing a FINMA-complaint Know Your Customer (KYC) platform. Additionally, TradeMap is based on blockchains and employs Ethereum Smart Contracts (SC). Thus, trust and anonymity between the market place and the KYC system relies on zero knowledge proof-based SCs used for user identification processes. With this management approach proposed, the user authentication is only verified within the KYC platform, providing a legally valid and fully anonymous online trading platform.
Matteo Varvello, Iñigo Querejeta Azurmendi, Antonio Nappa, Panagiotis N. Papadopoulos · 6 authors
Distributed Virtual Private Networks (dVPNs) are new VPN solutions aiming to solve the trust-privacy concern of a VPN's central authority by leveraging a distributed architecture. In this paper, we first review the existing dVPN ecosystem and debate on its privacy requirements. Then, we present VPN0, a dVPN with strong privacy guarantees and minimal performance impact on its users. VPN0 guarantees that a dVPN node only carries traffic it has "whitelisted", without revealing its whitelist or knowing the traffic it tunnels. This is achieved via three main innovations. First, an attestation mechanism which leverages TLS to certify a user visit to a specific domain. Second, a zero knowledge proof to certify that some incoming traffic is authorized, e.g., falls in a node's whitelist, without disclosing the target domain. Third, a dynamic chain of VPN tunnels to both increase privacy and guarantee service continuation while traffic certification is in place. The paper demonstrates VPN0 functioning when integrated with several production systems, namely BitTorrent DHT and ProtonVPN.
We explore the existence of covert communication channels in the Bitcoin system. Our attention is paid to the channels whose usage is hard or impossible to detect. Seven covert channels are considered. Some of them have already been known: there are two low-rate channels obtained by manipulation with parameters of cryptographic primitives used to construct a transaction, a channel created by the use of unspendable outputs, and digital signature algorithm (DSA) channel that hides a message in the cofactor used in the signature creation. The new channels that, to the best of our knowledge, have not been considered in the literature, are based on permutations of transaction inputs and outputs, and on distribution of payments. We describe the construction of all channels and characterize their capacity to transmit hidden data. Almost all channels can be used simultaneously and independently and provide wide opportunities for undetectable covert communications over the Bitcoin blockchain.
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Ethereum is one of the most popular blockchain platforms and is the second most valuable cryptocurrency. It allows developers to create smart contracts - small computer programs that sit on the blockchain. These programs can be written in programming languages like solidity and are executed by the Ethereum Virtual Machine (EVM). Since Ethereum is a public blockchain, all the data of the blockchain is available publicly. However, getting smart contract data is a tedious process and public data-sets for smart contracts are not available for further analysis. Therefore, in this work, we collect a total of 1.9M smart contracts till the block height of 7.1M, and provide a first of its kind analysis across different parameters like duplicity, ether balance, ether moved, etc. We observe that across all these different parameters, only a small fraction of the smart contracts are dominant. We label such 2900 dominant contracts as the `Contracts of Importance' and use it for further analysis using the various tools available to give us an insight into the vulnerability trends and patterns in smart contracts.
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
<em>In the second decade of the new millennium, with the development of Blockchain technology, the interest of many applications in the world has come to the attention of exciting applications. One of the challenging applications of Blockchain technology is in the area of electronic voting. The issue of preventing fraud and establishing democracy has always been a major challenge in all countries. Since 2015, various implementations of electronic voting with Blockchain have been introduced. Among these, some of the proposed methods have been implemented in small and medium scales in some countries. With respect to this fact that almost all of the above-mentioned methods use proof-of-work (PoW) consensus mechanism, the most significant shortcoming of such implementations is energy consumption. In the near future it is expected that this problem will be resolved through replacing PoW mechanism by new ones such as proof-of-stake (PoS) and its other variants. In this paper, we present security policy model parameters for e-voting, based on Blockchain technologies. The contribution of this paper is two-fold. First, this paper is the first to classify the requirements of e-voting according to confidentiality-integrity-availability, well-known as CIA principles in security terminology. Second, it provides a statistical analysis to extract hidden inter-dependencies among the requirements.</em>
With the current rise in the demand and usage of the blockchain technology for a variety of purposes, ranging from finance, medical, identification amongst others, major focus has been dedicated towards its legal implications rather than leveraging on the practical applications in administration. In this paper, we discuss the concepts of blockchain and how it can be implemented as an efficient solution towards public voting while aiming to destroy the disadvantages of the current voting system in India, at the same time providing a better, more reliable, secure and transparent means of public governance. We also aim to provide an exemplified voting solution for India with the integration of the current Aadhaar identification system as implemented by UIDAI.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Maximilian Schiedermeier, Omar M. Hassan, Lionel Brunie, Tobias Mayer · 5 authors
High voter turnout in elections and referendums is very desirable in order to ensure a robust democracy. Secure electronic voting is a vision for the future of elections and referendums. Such a system can counteract factors that hinder strong voter turnout such as the requirement of physical presence during limited hours at polling stations. However, this vision brings transparency and confidentiality requirements that render the design of such solutions challenging. Specifically, the counting must be implemented in a reproducible way and the ballots of individual voters must remain concealed. In this paper, we propose and evaluate a referendum protocol that ensures transparency, confidentiality, and integrity, in trustless networks. The protocol is built by combining Secure Multi-Party Computation (SMPC) and Distributed Ledger or Blockchain technology. The persistence and immutability of the protocol communication allows verifiability of the referendum outcome on the client side. Voters therefore do not need to trust in third parties. We provide a formal description and conduct a thorough security evaluation of our proposal.
High voter turnout in elections and referendums is very desirable in order to\nensure a robust democracy. Secure electronic voting is a vision for the future\nof elections and referendums. Such a system can counteract factors that hinder\nstrong voter turnout such as the requirement of physical presence during\nlimited hours at polling stations. However, this vision brings transparency and\nconfidentiality requirements that render the design of such solutions\nchallenging. Specifically, the counting must be implemented in a reproducible\nway and the ballots of individual voters must remain concealed. In this paper,\nwe propose and evaluate a referendum protocol that ensures transparency,\nconfidentiality, and integrity, in trustless networks. The protocol is built by\ncombining Secure Multi-Party Computation (SMPC) and Distributed Ledger or\nBlockchain technology. The persistence and immutability of the protocol\ncommunication allows verifiability of the referendum outcome on the client\nside. Voters therefore do not need to trust in third parties. We provide a\nformal description and conduct a thorough security evaluation of our proposal.\n
Payment channel networks (PCNs) are viewed as one of the most promising scalability solutions for cryptocurrencies today. Roughly, PCNs are networks where each node represents a user and each directed, weighted edge represents funds escrowed on a blockchain; these funds can be transacted only between the endpoints of the edge. Users efficiently transmit funds from node A to B by relaying them over a path connecting A to B, as long as each edge in the path contains enough balance (escrowed funds) to support the transaction. Whenever a transaction succeeds, the edge weights are updated accordingly. In deployed PCNs, channel balances (i.e., edge weights) are not revealed to users for privacy reasons; users know only the initial weights at time 0. Hence, when routing transactions, users typically first guess a path, then check if it supports the transaction. This guess-and-check process dramatically reduces the success rate of transactions. At the other extreme, knowing full channel balances can give substantial improvements in transaction success rate at the expense of privacy. In this work, we ask whether a network can reveal noisy channel balances to trade off privacy for utility. We show fundamental limits on such a tradeoff, and propose noise mechanisms that achieve the fundamental limit for a general class of graph topologies. Our results suggest that in practice, PCNs should operate either in the low-privacy or low-utility regime; it is not possible to get large gains in utility by giving up a little privacy, or large gains in privacy by sacrificing a little utility.
Ruiyang Xiao, Wei Ren, Tianqing Zhu, Kim‐Kwang Raymond Choo
Bitcoin transactions are not truly anonymous as an attacker can attempt to reveal a user's private information by tracing related transactions. Existing approaches to protect privacy (e.g., mixcoin, shuffle, and blinded token) suffer from a number of limitations. For example, some approaches assume the existence of a trusted third party, rely on exchanges among various currencies, or broadcast sensitive details before mixing. Therefore, there is a real risk of privacy breach or losing tokens. Thus in this paper, we design a mixing scheme with one decentralized signature protocol, which does not rely on a third party or require a transaction fee. Specifically, our scheme uses a negotiation process to guarantee transaction details, which is monitored by the participants. Furthermore, the scheme includes a signature protocol based on the ElGamal signature protocol and secret sharing. The proposed scheme is then proven secure.
Traditional elections satisfy neither citizens nor political authorities in recent years. They are not fully secure since it is easy to attack votes. It threatens also privacy and transparency of voters. Additionally, it takes too much time to count the votes. This paper proposes a solution using Blockchain to eliminate all the disadvantages of conventional elections. Security and data integrity of votes are absolutely provided theoretically. Voter privacy is another requirement that is ensured in the system. Lastly, the waiting time for results decreased significantly in the proposed Blockchain voting system.
Andrea Bracciali, Ioannis Chatzigiannakis, Andrea Vitaletti, Marco Zecchini
Smart cities leverage Information and Communication Technologies (ICTs) to enhance the quality of urban services. However, it is nowadays clear that the success of a smart city largely depends on the level of engagement of its citizens. In this paper we explore to what extent disruptive blockchain technologies can be used to incentivise the democratic participation of citizen. The investigated approach extends the standard IoT cycle 1) sense data, 2) cloudify and elaborate them, and 3) push information to the users. Here, the user takes an active role by means of data-informed votes on policies, therefore influencing behaviours. We illustrate such an approach by means of a proof-of-concept decentralised application (dApp) supporting the negotiation of polices for the management of urban water resources. The dApp consists of a smart contract that manages the execution of other smart contracts (the policies) according to the data-driven choices of the community. This use case demonstrates how suitably blockchain technologies can support fair and safe access to data and user engagement in smart cities.
Bitcoin cannot provide enough anonymity for its users and, thus, people started to worry about a possible traceability in their cryptocurrency transactions. More and more people get into the crypto-ecosphere while privacy concerns are paramount. In this paper, five well-known cryptocurrencies that claim they provide anonymity are analyzed to see how, if at all, they achieve anonymity. We then examine the considered cryptocurrencies: Dash, Monero, Verge, PIVX, and Zcash.
Ui-Jun Baek, Se-Hyun Ji, Jee- Tae Park, Min‐Seob Lee · 6 authors
Since the inception of Bitcoin, the first cryptocurrency to implement blockchain technology, the cryptocurrency market has experienced significant growth.However, this growth has also brought about numerous vulnerabilities and attacks that pose a threat to the Bitcoin ecosystem.These attacks are not only focused on the Bitcoin network itself but also extend to the services that utilize it.Recent surveys have indicated the need to analyze and identify Distributed Denial of Service (DDoS) attacks, considering the interconnectedness between network-level data and service-level DDoS attacks within the Bitcoin system.Typically, the Bitcoin network is considered resilient against DDoS attacks due to the decentralized nature of its ledger.Nevertheless, there are potential vulnerabilities that could be exploited, such as message spoofing using the Transmission Control Protocol (TCP).Additionally, DDoS attacks often target services associated with Bitcoin usage rather than directly impacting the network's performance or stealing currency.Although these service-level attacks may not have an immediate impact, they can ultimately undermine the value of Bitcoin, leading to depreciation.The majority of DDoS attacks on Bitcoin-related services occur on exchanges and mining pools.Our approach involves evaluating experimental outcomes based on proposed metrics to establish a correlation between network-level data and service-level DDoS attacks in the Bitcoin system.By doing so, we aim to detect and analyze these attacks, thereby identifying potential associations.Furthermore, we posit that the methodology employed in this study could be applicable to other blockchain systems, extending its usefulness beyond the Bitcoin network.
Zhenzhen Li, Jiangpan Hou, Hai Wang, Chencheng Wang · 6 authors
Ethereum is a blockchain platform that can run smart contracts and implement decentralized applications over a peer-to-peer(P2P) network. As the second-largest cryptocurrency in the world, Ethereum has attracted a lot of attention from industry and academia. Researches on Ethereum and other blockchain platforms focus on application, smart contracts, and P2P networks. Most of works use the data collected by active crawling, and rarely obtained data from the passive monitoring perspective, especially in the blockchain P2P network analysis. In this work, we propose a passive method using traffic association and machine learning to conduct online Ethereum node detection in NetFlow data, and monitor the Ethereum nodes in NetFlow traffic to gather nodes connection dataset. Based on the dataset, multi-dimensional measurement and analysis is made in order to reveal the true performance of Ethereum network.
Meryam Essaid, Daeyong Kim, Soo Hoon Maeng, Sejin Park · 5 authors
Recently Distributed Denial-of-Service (DDoS) are becoming more and more sophisticated, which makes the existing defence systems not capable of tolerating by themselves against wide-ranging attacks. Thus, collaborative protection mitigation has become a needed alternative to extend defence mechanisms. However, the existing coordinated DDoS mitigation approaches either they require a complex configuration or are highly-priced. Blockchain technology offers a solution that reduces the complexity of signalling DDoS system, as well as a platform where many autonomous systems (Ass) can share hardware resources and defence capabilities for an effective DDoS defence. In this work, we also used a Deep learning DDoS detection system; we identify individual DDoS attack class and also define whether the incoming traffic is legitimate or attack. By classifying the attack traffic flow separately, our proposed mitigation technique could deny only the specific traffic causing the attack, instead of blocking all the traffic coming towards the victim(s).
Ankit Gangwal, Samuele Giuliano Piazzetta, Gianluca Lain, Mauro Conti
Cybercriminals have been exploiting cryptocurrencies to commit various unique financial frauds. Covert cryptomining - which is defined as an unauthorized harnessing of victims' computational resources to mine cryptocurrencies - is one of the prevalent ways nowadays used by cybercriminals to earn financial benefits. Such exploitation of resources causes financial losses to the victims. In this paper, we present our novel and efficient approach to detect covert cryptomining. Our solution is a generic solution that, unlike currently available solutions to detect covert cryptomining, is not tailored to a specific cryptocurrency or a particular form of cryptomining. In particular, we focus on the core mining algorithms and utilize Hardware Performance Counters (HPC) to create clean signatures that grasp the execution pattern of these algorithms on a processor. We built a complete implementation of our solution employing advanced machine learning techniques. We evaluated our methodology on two different processors through an exhaustive set of experiments. In our experiments, we considered all the cryptocurrencies mined by the top-10 mining pools, which collectively represent the largest share (84% during Q3 2018) of the cryptomining market. Our results show that our classifier can achieve a near-perfect classification with samples of length as low as five seconds. Due to its robust and practical design, our solution can even adapt to zero-day cryptocurrencies. Finally, we believe our solution is scalable and can be deployed to tackle the uprising problem of covert cryptomining.