Nowdays, cloud storage technology has become a hot topic, and an increasing number of users are concerned with the security of their data in the cloud. Many auditing schemes on the cloud are proposed and the introduction of a third-party auditor to assist users in verifying the integrity of cloud data. As a centralized node, the third-party auditor has to communicate with all cloud users and cloud service providers, which becomes the bottleneck of the whole scheme. To solve this problem, we design a blockchain-based flexible cloud data auditing scheme. In our scheme, a decentralized auditing framework is proposed to eliminate the dependency on the third-party auditor, which increases the stability, security and performance of the whole scheme. Since the cloud service provider can automatically generates auditing proofs, our scheme can relieve the communication burdens of the cloud service provider. The proposed scheme also adapts the Merkle Hash tree to improve the verification performance. Security analysis and experiments show that the proposed scheme is secure and has better stability and verification efficiency.
The database design based on blockchain is regarded as a distributed ledger combined with technologies such as distributed storage and encryption algorithms. It has the characteristics of decentralization and high security. Multiple entities of the Consortium Blockchain are subject to centralized supervision and have strict access mechanisms. Therefore, this paper attempts to study the data management model based on the Consortium Blockchain in the context of education big data, with the school archive management as the entry point, which is a safe and reliable information system with low data sharing cost, non-tamperable, and traceable. Design and application exploration route.
Priyanka Pandit, Alp Tezbasaran, Arjun Earthperson, Mihai Diaconeasa
Abstract The approval process from the U.S. Nuclear Regulatory Commission (NRC) for nuclear power plants is sequential. It involves several government bodies such as the Advisory Committee on Reactor Safeguards (ACRS), public meetings, and hearings. If the submissions made to the NRC do not contain enough information to meet the regulation requirements, the NRC issues a Request for Additional Information (RAI). Thus, the licensee has to go through a paperwork-intensive process that involves multiple regulatory agencies for the various licensing requirements. Moreover, sending applications to the NRC is limited to using an electronic submission generation tool called the Packing Slip Wizard (PSW). This paper presents a methodology to implement Distributed Ledger Technology (DLT) to address the need for a real-time, digitized documentation platform in the nuclear power industry’s licensing and regulation process. The evaluation of DLT’s implementation resulted in the formulation of a methodology to accept submissions from an applicant on a web application and storing the received data on a distributed ledger. The presented method offers a real-time submission of the available information of an application. It facilitates the NRC with a real-time feedback capability expediting the review process. RAI’s can be reduced in number by ensuring that the NRC’s information requirements are defined as smart contracts.
Blockchain technology is one of the most important and disruptive technologies in the world. Nowadays the healthcare center needs to share patient databases over all departments of the healthcare centers. Although, electronic healthcare records overcome several problems compared with manual records, but still suffer from many issues such as security, the privacy of patient data overall as we should transfer over a database from a central database to a decentralized database. In this paper, we proposed a good security system to manage the data of patients based on blockchain technology and a decentralized database. Depending on decentralized database and blockchain. Our proposed system provides the secure exchange of patient data, reliability, and high efficiency in sharing data during transaction data network equivalence checking to perform this validation of patient information in the blockchain and healthcare centers.
James A. Cunningham, Gail Davidge, Nigel Davies, Sarah Devaney · 9 authors
Data providers holding sensitive medical data often need to exchange data pertaining to patients for whom they hold particular data. This involves requesting information from other providers to augment the data they hold. However, revealing the superset of identifiers for which a provider requires information can, in itself, leak sensitive private data. Data linkage services exist to facilitate the exchange of anonymized identifiers between data providers. Reliance on third parties to provide these services still raises issues around the trust, privacy and security of such implementations. The rise and use of blockchain and distributed ledger technologies over the last decade has, alongside innovation and disruption in the financial sphere, also brought to the fore and refined the use of associated privacy-preserving cryptographic protocols and techniques. These techniques are now being adopted and used in fields removed from the original financial use cases. In this paper we present a combination of a blockchain-native auditing and trust-enabling environment alongside a query exchange protocol. This allows the exchange of sets of patient identifiers between data providers in such a way that only identifiers lying in the intersection of sets of identifiers are revealed and shared, allowing further secure and privacy-preserving exchange of medical information to be carried out between the two parties. We present the design and implementation of a system demonstrating the effectiveness of these exchange protocols giving a reference architecture for the implementation of such a system.
The current medical cyber physical systems involve a wide range of institutions and a large number of participants. Data sharing among distributed medical institutions is already a development trend. However, the security is worrying; e.g., the access to medical data lacks uniformity and standardization. What is more, data is easy to be tampered with and leaked. This has a very negative impact on the medical industry. Therefore, a strict and reliable access control mechanism for data in the medical cyber physical systems is a prerequisite for ensuring the implementation of modern medical functions. We deal with how to design effective access control in medical cyber physical systems. Combined with blockchain technology, we design the medical cyber physical systems based on blockchain data access control mechanism and unite data in the chain of union Fabric network resources access control. We qualitatively classify medical data, define the weight level of different data, design a medical data access framework based on blockchain, build an applicable model, formulate access control strategy, and specify the role assignment and access task matching of users, so as to achieve secure and effective data access control. The Hyperledger Fabric network is established as the alliance chain for managing access control rights distribution through smart contracts so as to achieve case-based medical data access control under the blockchain.
Over the past decade, different blockchain technologies have contributed to the creation of thousands of blockchain networks which have hosted thousands of proofs of concepts and pilots, with generally satisfactory results for stakeholders. However, scalability has been a big roadblock for most of these projects. We believe that the reasons why most blockchain-based solutions do not scale well are that they are built on ledgers that are not properly designed as the instrumental piece of architecture needed by these projects and that it is not clear who is liable for what. There is rarely an upfront discussion about governance, data management and privacy, technical support, operational fees (e.g., tx fees), maintenance, regulatory risks, or sustainability in these decentralized networks. This framework is a set of recommendations that enables the creation of multipurpose network of networks that are robust, reliable, sustainable, compliant, scalable, and have clear definition of accountabilities. The framework can also be applied to both permissionless public and permissioned private blockchain networks, but can only be fully realized in a permissioned public infrastructure. The framework builds on the idea that in order to develop scalable blockchain projects and solutions, it is necessary to switch the conversation from blockchain technologies to blockchain networks.
Blockchain is a peer-to-peer (P2P) distributed ledger technology that provides openness and confidence for a new age of transactional applications. The fundamental fabric for bitcoin is blockchain, which is a design pattern made up of three core elements: a distributed network, a public ledger, and digital transactions. Digital transactions are recorded in a public ledger by members of the distributed network. Members of the network run algorithms to test and validate the planned transaction before adding it to the network. The latest transaction is applied to the public ledger if a number of the network participants believe that the transaction is legitimate. In minutes or seconds, changes to the public ledger are mirrored in all copies of the blockchain. A transaction is immutable after it has been added and cannot be reversed or deleted. No one user of the network has the ability to tamper with or change data, and everybody in the network has a full copy of the blockchain. Blockchain is a peer-to-peer (P2P) network of nodes made up of network members.
The sum of Big Data generated from different sources is increasing significantly with each passing day to extent that it is becoming challenging for traditional storage methods to store this massive amount of data. For this reason, most organizations have resolved to use third-party cloud storage to store data. Cloud storage has advanced in recent times, but it still faces numerous challenges with regard to security and privacy. This paper discusses Big Data security and privacy challenges and the minimum requirements that must be provided by future solutions. The main objective of this paper is to propose a new technical framework to control and manage Big Data security and privacy risks. A design science research methodology is used to carry out this project. The proposed framework takes advantage of Blockchain technology to provide secure storage of Big Data by managing its metadata and policies and eliminating external parties to maintain data security and privacy. Additionally, it uses mobile agent technology to take advantage of the benefits related to system performance in general. We present a prototype implementation for our proposed framework using the Ethereum Blockchain in a real data storage scenario. The empirical results and framework evaluation show that our proposed framework provides an effective solution for secure data storage in a Big Data environment.
Dae-Geun Yoon, Sung-Jin Moon, Kisung Park, Sungkee Noh
As the needs for personal data increase due to the advent of the AI era, many companies are collecting their users' data and using it to advance the service. As the use of personal data increases, the value of personal data also increases. Although these valuable personal data are generated by individuals, only centralized service providers get profit from the data. In this paper, we propose a blockchain-based personal data trading system using DID (Decentralized Identifiers) and VC (Verifiable Credentials). Our proposed system allows users to collect personal data in their own data storage provided by the system. DID and VC are used to authenticate the user's identity and to prove ownership of the data without any centralized systems, respectively. The integrity of the traded data and the history of the transactions are ensured by Hyperledger Fabric, which is a decentralized infrastructure composed of consortium blockchain nodes. We show how our system works by implementing the monitoring system that provides the current status of the user's data and trading. We verify that two end entities including a seller and a buyer can complete personal data trading by using our proposed system without centralized service providers.
Abstract In the context of cloud computing, the interaction between clients in different application domains becomes more frequent, which makes cross‐domain identity authentication safely and efficiently become an important research topic. Public key infrastructure (PKI) is a technology to solve cross‐domain authentication. However, there are problems such as difficulty in mutual trust between multiple certificate authority nodes (CA), failure of single point, and low efficiency in the traditional PKI method. Blockchain is a promising technology for decentralized trust management by providing consistent data storage, which gives impetus to the further development of cross‐domain identity authentication. Thus, this article apply blockchain to cross‐domain identity authentication. To solve the defects of the traditional PKI method, the design requirements are analyzed firstly, based on the analysis result, we proposed a double‐layer cross‐domain identity authentication model by constructing a consortium blockchain which is comprised of authentication server nodes (AS) and some internal blockchain, the model can highly improve the scalability of the PKI system without changing the internal architecture. Then a novel authentication protocol was put forward. The protocol can improve the efficiency of online cross‐domain identity authentication transactions by verifying the hash instead of the signature of their certificate. By putting the generation process of the blockchain certificate and the storage process of its hash in the registration operation and reducing the authentication process for AS and CA, the efficiency is further improved. Finally, the protocol was evaluated by security and performance analysis. The results display our protocol can guarantee security and has an excellent performance in cross‐domain identity authentication transactions.
The security of HTTPS fundamentally relies on SSL/TLS certificates issued by Certificate Authorities (CAs), which, however, are vulnerable to be compromised to issue unauthorized certificates (i.e., certificates issued without domains’ permission). Current countermeasures such as Certificate Transparency (CT) can only detect unauthorized certificates rather than preventing them. In this article, we presentPistis, a framework for issuing authorized and trusted certificates with the distributed ledger and Trusted Execution Environment (TEE) technology. InPistis, TEE nodes validate whether the domain in a requested certificate passes the domain ownership validation (i.e., under corresponding applicants’ control) and submit attested results to a smart contract in the distributed ledger. The smart contract issues a certificate to the applicant when an attested result shows a pass. Therefore,Pistiscan ensure its issued certificates are authorized due to the domain ownership validation mechanism in the TEE. Furthermore, as the issued certificates are stored in a Merkle Patricia Tree (MPT) inPistis, they are trusted and can be verified by a normal user easily. The security ofPistisis formally proved in the Universally Composable (UC) framework. Compared with state-of-the-art,Pistisavoids potential damages by preventing unauthorized certificates from issuing.
Rabimba Karanjai, Lei Xu, Lin Chen, Fengwei Zhang · 6 authors
Modern computer systems tend to rely on large trusted computing bases (TCBs) for operations. To address the TCB bloating problem, hardware vendors have developed mechanisms to enable or facilitate the creation of a trusted execution environment (TEE) in which critical software applications can execute securely in an isolated environment. Even under the circumstance that a host OS is compromised by an adversary, key security properties such as confidentiality and integrity of the software inside the TEEs can be guaranteed. The promise of integrity and security has driven developers to adopt it for use cases involving access control, PKS, IoT among other things. Among these applications include blockchain-related use cases. The usage of the TEEs doesn't come without its own implementation challenges and potential pitfalls. In this paper, we examine the assumptions, security models, and operational environments of the proposed TEE use cases of blockchain-based applications. The exercise and analysis help the hardware TEE research community to identify some open challenges and opportunities for research and rethink the design of hardware TEEs in general.
Viraaji Mothukuri, Sai S. Cheerla, Reza M. Parizi, Qi Zhang · 5 authors
Hadoop Distributed File System (HDFS) is one of the widely used distributed file systems in big data analysis for frameworks such as Hadoop. HDFS allows one to manage large volumes of data using low-cost commodity hardware. However, vulnerabilities in HDFS can be exploited for nefarious activities. This reinforces the importance of ensuring robust security to facilitate file sharing in Hadoop as well as having a trusted mechanism to check the authenticity of shared files. This is the focus of this paper, where we aim to improve the security of HDFS using a blockchain-enabled approach (hereafter referred to as BlockHDFS). Specifically, the proposed BlockHDFS uses the enterprise-level Hyperledger Fabric platform to capitalize on files' metadata for building trusted data security and traceability in HDFS.
Over the past decade, service provisioning in federated cloud environments (FCE) through multiple cloud service providers (CSP) is distributed among multi-cloud users (CU). In such ecosystems, multiple broker entities facilitate seamless performance and delivery of cloud services among CU and CSP in FCE. However, due to the exchange of information through public heterogeneous channels, the service transactions among cloud stakeholders are bounded by security issues such as privacy, the authenticity of stakeholders, chronology among transactions, and responsive availability of CSP. Thus, in such peer decentralized ecosystems, the blockchain (BC) framework is applicable to solve the aforementioned issues. BC also automates the Service level agreement (SLA) contracts between CU and CSP through smart contract (SC) execution as logical software codes. In the same direction, the proposed survey addresses the gaps in earlier multi-cloud surveys and discusses a BC-based secure broker provisioning framework for performance and security parameters, concerning associated attack vectors. The proposed survey presents a detailed analysis of different existing solutions and proposes a solution taxonomy for service provisioning in BC-envisioned cloud ecosystems. The survey also identifies the research challenges for industry professionals, academicians, and the research community, to build scalable services for CUs in FCE.
NFT is a unit of data stored on a blockchain digital ledger to represent items such as photos, videos, audio, and other intellectual property. NFT certifies a digital asset to be unique i.e. not interchangeable. Current blockchain store the transaction from each node but it is required more security to show the proof of ownership. This paper proposes NFT secure blockchain architecture confirming the ownership of transaction and implement secure payment method to avoid mistake of transfer the token by escrow account on transaction confirmation node called J Node.
Young-Hoon Park, Yejin Kim, Shin-Ok Lee, Kwangman Ko
The security and privacy of electronic health records (EHRs) have received considerable attention from healthcare workers and researchers. To ensure security, various encryption and decryption schemes as well as key management protocols have been developed. However, owing to sharing and scalability issues, additional security technologies have been proposed. Nonetheless, these technologies cause other problems, such as efficiency issues. Blockchain-based EHR management systems have been proposed to overcome computational overhead. However, because most blockchain systems are installed by outsourcing companies, EHRs may be leaked to the company. Hence, we herein propose a blockchain-based EHR management scheme with proxy re-encryption. In this scheme, we set a proxy server that re-encrypts the ciphertext between file servers, thereby solving EHR sharing issues. Furthermore, because the server is separated from the blockchain system, the outsourcing company cannot manipulate the server or access the records. In addition, the blockchain assists in access control by using smart contracts, thereby enabling secure and efficient EHR sharing. By performing security analysis, we prove that our proposed scheme solves the aforementioned security problems. In addition, we experimentally demonstrate the efficient operation of the proposed system.
Distributed storage can store data in multiple devices or servers to improve data security. However, in today's explosive growth of network data, traditional distributed storage scheme is faced with some severe challenges such as insufficient performance, data tampering, and data lose. A distributed storage scheme based on blockchain has been proposed to improve security and efficiency of traditional distributed storage. Under this scheme, the following improvements have been made in this paper. This paper first analyzes the problems faced by distributed storage. Then proposed to build a new distributed storage blockchain scheme with sharding blockchain. The proposed scheme realizes the partitioning of the network and nodes by means of blockchain sharding technology, which can improve the efficiency of data verification between nodes. In addition, this paper uses polynomial commitment to construct a new verifiable secret share scheme called PolyVSS. This new scheme is one of the foundations for building our improved distributed storage blockchain scheme. Compared with the previous scheme, our new scheme does not require a trusted third party and has some new features such as homomorphic and batch opening. The security of VSS can be further improved. Experimental comparisons show that the proposed scheme significantly reduces storage and communication costs.
Jesús García-Rodríguez, Rafael Torres Moreno, Jorge Bernal Bernabé, Antonio Skármeta
Despite the latest efforts to foster the adoption of privacy-enhancing Attribute-Based Credential (p-ABC) systems in electronic services, those systems are not yet broadly adopted. The main reasons behind this are performance efficiency issues, lack of interoperability with standards, and the centralized architectural scheme that relies on a unique Identity Provider (IdP) for credential issuance. To cope with these limitations, this paper describes the first implementation of the Pointcheval–Sanders Multi-Signatures (PS-MS) crypto scheme proposed by Camenisch et al. and its integration in a distributed and privacy-preserving identity management system proposed in OLYMPUS H2020 European research project. Our efficient implementation provides remarkable privacy-preservation features for identity management in online transactions leveraging p-ABC systems, including unforgeability, minimal disclosure of personal data through zero-knowledge proofs, unlinkability in online transactions and fully distributed credential issuance across different IdPs, thereby removing the IdP as a unique point of failure. The performance of the implementation has been exhaustively analyzed and evaluated with different curves, signers and number of attributes, and compared against Identity Mixer, the best known p-ABC system, outperforming significantly the credential issuance and zero-knowledge proving and verification processes (2–4 times less execution time).