In this paper, we propose a system for mixing transactions in payment networks such as credit networks. Credit networks like Ripple and Stellar are increasingly popular, and can facilitate crosscurrency transactions in a fraction of the time it would take for banks or other financial institutions to process the same transaction, and at a fraction of the cost. Unlike for cryptocurrencies, there has been little work in the area of designing secure and private mixers for credit networks. Mixers for cryptocurrencies such as Bitcoin cannot be directly applied to the credit network domain because credit networks have an inherently different structure and purpose than cryptocurrencies. We design a system that uses cryptographic constructs such as ring signatures, commitments, and zero knowledge proofs to provide security/integrity of all transactions, ensures privacy of the users involved in a transaction, as well as privacy of the amount transacted. We also provide preliminary experimental results.
Consensus mechanism is the heart of any blockchain network. Many projects have proposed alternative protocols to improve restricted scalability of Proof of Work originated since Bitcoin. As an improvement of Delegated Proof of Stake, in this paper, we introduce a novel consensus, namely, Delegated Proof of Reputation, which is scalable, secure with an acceptable decentralization. Our innovative idea is replacing pure coin-staking by a reputation ranking system essentially based on ranking theories (PageRank, NCDawareRank and HodgeRank).
In this paper, we consider a scenario where a bitcoin liquidity provider sells bitcoins to clients. When a client pays for a bitcoin online, the provider is able to link the client's payment information to the bitcoin sold to that client. To address the privacy concerns of clients, we require that the bitcoin provider cannot tell the relationship between the real identities of clients and the sold bitcoins in the blockchain. This requirement can be effectively achieved by using blind signatures. However, existing blind signature schemes are incompatible with the Elliptic Curve Digital Signature Algorithm (ECDSA) which is used by most of the existing bitcoin protocol, thus cannot be applied directly in Bitcoin. In this paper, we propose a new blind signature scheme that allows generating a blind signature compatible with the standard ECDSA. Afterwards, we make use of the new scheme to achieve bitcoin transaction anonymity. The new scheme is built on a variant of the Paillier cryptosystem and its homomorphic properties. As long as the modified Paillier cryptosystem is semantically secure, the new blind signature scheme has blindness and unforgeability.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Samvid Dharanikota, Michael Jensen, Sebastian Rom Kristensen, Mathias Sass Michno · 7 authors
Randomness beacons are services that periodically emit a random number, allowing users to base decisions on the same random value without trusting anyone: ideally, the randomness beacon does not only produce unpredictable values, but is also of low computational complexity for the users, bias-resistant and publicly verifiable. Such randomness beacons can serve as an important primitive for smart contracts in a variety of contexts. This paper first presents a structured security analysis, based on which we then design, implement, and evaluate a trustworthy and efficient randomness beacon. Our approach does not require users to register or run any computationally intensive operations. We then compare different implementation and deployment options on distributed ledgers, and report on an Ethereum smart contract-based lottery using our beacon.
This article aims at introducing a new configurable and multipurpose electronic voting service based on the blockchain infrastructure. The objective is to design an architecture to automatically translate service configuration defined by the end user into a cloud-based deployable bundle, automating business logic definition, blockchain configuration, and cloud service provider selection. The article presents the preliminary results of the system and a SOA-based services definition implemented with smart contracts.
Blockchain technology is useful with the record keeping of digital transactions, IoT, supply chain management etc. However, we have observed that the traditional attacks are possible on blockchain due to lack of robust identity management. We found that Sybil attack can cause severe impact in public/permissionless blockchain, in which an attacker can subvert the blockchain by creating a large number of pseudonymous identities (i.e. Fake user accounts) and push legitimate entities in the minority. Such virtual nodes can act like genuine nodes to create disproportionately large influence on the network. This may lead to several other attacks like DoS, DDoS etc. In this paper, a Sybil attack is demonstrated on a blockchain test bed with its impact on the throughput of the system. We propose a solution directive, in which each node monitors the behavior of other nodes and checks for the nodes which are forwarding the blocks of only particular user. Such nodes are quickly identified, blacklisted and notified to other nodes, and thus the Sybil attack can be restricted. We analyze experimental results of the proposed solution.
Online voting is an alternative to age old paper ballot system and the currently popular electronic voting machines (EVM). An electronic voting portal should offer security and integrity along with the transparency of votes and privacy of voters. This paper proposes an e-voting system based on blockchain that eliminates some of the limitations in existing voting systems. The paper also presents state of art of some blockchain frameworks for e-voting. The presented implementation is suitable for small scale elections like inside corporate houses, board rooms etc. The implementation uses smart contract from Ethereum. Truffle framework is used in this paper for development, testing and deploying smart contracts. Ganache is used as Ethereum client for testing. Here Meta-mask is used as browser wallet.
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The anonymity and decentralization of Bitcoin make it widely accepted in illegal transactions, such as money laundering, drug and weapon trafficking, gambling, to name a few, which has already caused significant security risk all around the world. The obvious de-anonymity approach that matches transaction addresses and users is not possible in practice due to limited annotated data set. In this paper, we divide addresses into four types, exchange, gambling, service, and general, and propose targeted addresses identification algorithms with high fault tolerance which may be employed in a wide range of applications. We use network representation learning to extract features and train imbalanced multi-classifiers. Experimental results validated the effectiveness of the proposed method.
We present TendrilStaller, an eclipse attack targeting at Bitcoin's peer-to-peer network. TendrilStaller enables an adversary to delay block propagation to a victim for 10 minutes. The adversary thus impedes the victim from getting the latest blockchain state. It only takes as few as one Bitcoin full node and two light weight nodes to perform the attack. The light weight nodes perform a subset of the functions of a full Bitcoin node. The attack exploits a recent block propagation protocol introduced in April 2016. The protocol prescribes a Bitcoin node to select 3 neighbors that can send new blocks unsolicited. These neighbors are selected based on their recent performance in providing blocks quickly. The adversary induces the victim to select 3 attack nodes by having attack nodes send valid blocks to the victim more quickly than other neighbors. For this purpose, the adversary deploys a handful of light weight nodes so that the adversary itself receives new blocks faster. The adversary then performs the attack to delay blocks propagated to the victim. We implement the attack on top of current default Bitcoin protocol We deploy the attack nodes in multiple locations around the globe and randomly select victim nodes. Depending on the round-trip time between the adversary and the victim, 50%-85% of the blocks could be delayed to the victim. We further show that the adoption of light weight nodes greatly increases the attack probability by 15% in average. Finally, we propose several countermeasures to mitigate this eclipse attack.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Muhammad Saad, Victor Cook, Lan N. Nguyen, My T. Thai · 5 authors
Bitcoin is the leading example of a blockchain application that facilitates peer-to-peer transactions without the need for a trusted intermediary. This paper considers possible attacks related to the decentralized network architecture of Bitcoin. We perform a data driven study of Bitcoin and present possible attacks based on spatial and temporal characteristics of its network. Towards that, we revisit the prior work, dedicated to the study of centralization of Bitcoin nodes over the Internet, through a fine-grained analysis of network distribution, and highlight the increasing centralization of the Bitcoin network over time. As a result, we show that Bitcoin is vulnerable to spatial, temporal, spatio-temporal, and logical partitioning attacks with an increased attack feasibility due to network dynamics. We verify our observations by simulating attack scenarios and the implications of each attack on the Bitcoin . We conclude with suggested countermeasures.
Jordi Zayuelas i Munoz, José Suárez‐Varela, Pere Barlet‐Ros
In the last few years, cryptocurrency mining has become more and more important on the Internet activity and nowadays is even having a noticeable impact on the global economy. This has motivated the emergence of a new malicious activity called cryptojacking, which consists of compromising other machines connected to the Internet and leverage their resources to mine cryptocurrencies. In this context, it is of particular interest for network administrators to detect possible cryptocurrency miners using network resources without permission. Currently, it is possible to detect them using IP address lists from known mining pools, processing information from DNS traffic, or directly performing Deep Packet Inspection (DPI) over all the traffic. However, all these methods are still ineffective to detect miners using unknown mining servers or result too expensive to be deployed in real-world networks with large traffic volume. In this paper, we present a machine learning-based method able to detect cryptocurrency miners using NetFlow/IPFIX network measurements. Our method does not require to inspect the packets' payload; as a result, it achieves cost-efficient miner detection with similar accuracy than DPI-based techniques.
Federated identity management enables users to access multiple systems using\na single login credential. However, to achieve this a complex privacy\ncompromising authentication has to occur between the user, relying party (RP)\n(e.g., a business), and a credential service provider (CSP) that performs the\nauthentication. In this work, we use a smart contract on a blockchain to enable\nan architecture where authentication no longer involves the CSP. Authentication\nis performed solely through user to RP communications (eliminating fees and\nenhancing privacy). No third party needs to be contacted, not even the smart\ncontract. No public key infrastructure (PKI) needs to be maintained. And no\nrevocation lists need to be checked. In contrast to competing smart contract\napproaches, ours is hierarchically managed (like a PKI) enabling better\nvalidation of attribute providers and making it more useful for large entities\nto provide identity services for their constituents (e.g., a government) while\nstill enabling users to maintain a level of self-sovereignty.\n
In the past few years in many countries people have experienced the erosion of trust in the main pillars of democracy, the voting and election systems. Many authors envisage the blockchain technology as a tool for restoration of trust (Tapscott 2016; Swislow 2016; Shin 2016). Our research is aimed at the potential use of blockchain technology in social systems for enhancing trust and increasing participation. We aim to explore whether the blockchain technology is suitable for voting or elections in large communities and the issues to be addressed for real world applications to leverage democratic rights. Our final conclusion is that there are both theoretical and practical obstacles in the way of such direct applications.
With the prevalence of blockchain, more and more Decentralized Applications (DApps) are deployed on Ethereum to achieve the goal of communicating without supervision. Users habits may be leaked while these applications adopt SSL/TLS to encrypt their transmission data. Encrypted protocol and the same blockchain platform bring challenges to the traffic classification of DApps. Existing encrypted traffic classification methods suffer from low accuracy in the situation of DApps.
2 source records
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Adriano Di Luzio, Danilo Francati, Giuseppe Ateniese
This work presents Arcula, a new design for hierarchical deterministic wallets that brings identity-based addresses to the blockchain. Arcula is built on top of provably secure cryptographic primitives. It generates all its cryptographic secrets from a user-provided seed and enables the derivation of new public keys based on the identities of users, without requiring any secret information. Unlike other wallets, it achieves all these properties while being secure against privilege escalation. We formalize the security model of hierarchical deterministic wallets and prove that an attacker compromising an arbitrary number of users within an Arcula wallet cannot escalate his privileges and compromise users higher in the access hierarchy. Our design works out-of-the-box with any blockchain that enables the verification of signatures on arbitrary messages. We evaluate its usage in a real-world scenario on the Bitcoin Cash network.
Francisco J. Marmolejo-Cossío, Eric Brigham, Benjamin Sela, Jonathan Katz
The Bitcoin protocol prescribes certain behavior by the miners who are responsible for maintaining and extending the underlying blockchain; in particular, miners who successfully solve a puzzle, and hence can extend the chain by a block, are supposed to release that block immediately. Eyal and Sirer showed, however, that a selfish miner is incentivized to deviate from the protocol and withhold its blocks under certain conditions. The analysis by Eyal and Sirer, as well as in followup work, considers a \emph{single} deviating miner (who may control a large fraction of the hashing power in the network) interacting with a remaining pool of honest miners. Here, we extend this analysis to the case where there are \emph{multiple} (non-colluding) selfish miners. We find that with multiple strategic miners, specific deviations from honest mining by multiple strategic agents can outperform honest mining, even if individually miners would not be incentivised to be dishonest. This previous point effectively renders the Bitcoin protocol to be less secure than previously thought.
Zhengbing Hu, Ivan Dychka, Mykola Onai, Yuri Zhykin
One of the most important problems of modern cryptocurrency networks is the problem of scaling: advanced cryptocurrencies like Bitcoin can handle around 5 transactions per second. One of the most promising solutions to this problem are second layer payment protocols: payment networks implemented on top of base cryptocurrency network layer, based on the idea of delaying publication of intermediate transactions and using base network only as a finalization layer. Such networks consist of entities that interact with the cryptocurrency system via a payment channel protocol, and can send, receive and forward payments. This paper describes a formal actor-based model of payment channel network and uses it to formulate a modified payment protocol that can be executed in the network without requiring any information about its topology and thus can hide information about financial relations between nodes.
Networks (Autonomous Systems-AS) allocate or revoke IP prefixes with the intervention of official Internet resource number authorities, and select and advertise policy-compliant paths towards these prefixes using the inter-domain routing system and its primary enabler, the Border Gateway Protocol (BGP). Securing BGP has been a long-term objective of several research and industrial efforts during the last decades, that have culminated in the Resource Public Key Infrastructure (RPKI) for the cryptographic verification of prefix-to-AS assignments. However, there is still no widely adopted solution for securing IP prefixes and the (AS-)paths leading to them; approaches such as BGPsec have seen minuscule deployment. In this work, we design and implement a Blockchain-based system that (i) can be used to validate both of these resource types, (ii) can work passively and does not require any changes in the inter-domain routing system (BGP, RPKI), and (iii) can be combined with currently available systems for the detection and mitigation of routing attacks. We present early results and insights w.r.t. scalability.
Secure access control to a wide variety of Internet of Things (IoT)devices has become critical. Blockchain-based access control frameworks are promising technologies to support secure access to IoT devices in pervasive computing applications. However, in most of the proposed solutions, the IoT devices rely on a trusted server to retrieve critical access control data from the blockchains. We propose a method for IoT devices to validate blockchain data without solely being dependent on a central server. In our approach, several witnesses on the network can be selected randomly by the devices to validate access control information. Our method is aided by Bloom filters, which are shown to be lightweight for resource-constrained devices.
Software Defined Networking (SDN) technology increases the evolution of Internet and network development. SDN, with its logical centralization of controllers and global network overview changes the network's characteristics, on term of flexibility, availability and programmability. However, this development increased the network communication security challenges. To enhance the SDN security, we propose the BCFR solution to avoid false flow rules injection in SDN data layer devices. In this solution, we use the blockchain technology to provide the controller authentication and the integrity of the traffic flow circulated between the controller and the other network elements. This work is implemented using OpenStack platform and Onos controller. The evaluation results show the effectiveness of our proposal.
Information-centric networking (ICN) supports efficient data provision and retrieval with in-network caching. The data life cycle over ICN includes atomic data collection, data publication, caching, and retrieval, suffering from various attacks, such as regulation violation and false claim. Existing solutions have not considered regulation compliance and typically focus on the protection of a specific procedure. To solve these problems, we propose a blockchain-based data life cycle protection framework (BDLP), which exploits the transaction and smart contract to provide a trusted and neutral environment in ICN. In BDLP, a special type of node, a data dam blockchain node, is designed to locally control registration and restrict data flow, besides the function of a blockchain node. BDLP consists of five types of transactions (RegT, CollectT, PubT, PayT, and PunT) to achieve accountability and four types of smart contracts (PubSC, PaySC, AccSC, and RepSC) to achieve authentication, regulation compliance, and neutrality. We elaborate on the data retrieval procedure in BDLP and analyze its scalability, demonstrating that BDLP can achieve a low data retrieval permission delay.
Imen Riabi, Hella Kaffel Ben Ayed, Leila Azzouz Saidane
Access control models for the Internet of Things (IoT) proposed in the literature are based on centralized architecture and raise security issues due to the spontaneous and dynamic interaction between IoT devices. In addition to the scalability and lightweight features, the need of secure and distributed access control architecture to overcome the single point failure problem of a centralized entity becomes a big challenge. This can be done through the Blockchain technology which is used recently to provide access control services. Exploiting this technology to manage access IoT devices in term of distribution, heterogeneity, scalability, fault tolerance capability, security and privacy are promising. In this paper, a comprehensive review of the existing access control models based on Blockchain is presented and discussed with comparison and analysis.
Kaihua Qin, Hadass, Henryk, Arthur Gervais, Joel Reardon
Lightweight Bitcoin clients execute a Simple Payment Verification (SPV) protocol to verify the validity of transactions related to a particular user. Currently, lightweight clients \nuse Bloom filters to significantly reduce the amount of bandwidth \nrequired to validate a particular transaction. This is despite the \nfact that research has shown that Bloom filters are insufficient \nat preserving the privacy of clients’ queries. \nIn this paper we describe our design of an SPV protocol \nthat leverages Private Information Retrieval (PIR) to create fully \nprivate and performant queries. We show that our protocol has \na low bandwidth and latency cost; properties that make our \nprotocol a viable alternative for lightweight Bitcoin clients and \nother cryptocurrencies with a similar SPV model. In contract \nto Bloom filters, our PIR-based approach offers deterministic \nprivacy to the user. \nAmong our results, we show that in the worst case, clients who \nwould like to verify 100 transactions occurring in the past week \nincurs a bandwidth cost of 33.54 MB with an associated latency \nof approximately 4.8 minutes, when using our protocol. The \nsame query executed using the Bloom-filter-based SPV protocol \nincurs a bandwidth cost of 12.85 MB; this is a modest overhead \nconsidering the privacy guarantees it provides.
Bitcoin, introduced in 2008 and launched in 2009, is the first digital currency to solve the double spending problem without relying on a trusted third party. Bitcoin provides a way to transact without any trusted intermediary, but its privacy guarantees are questionable. Despite the fact that Bitcoin addresses are not linked to any identity, multiple deanonymization attacks have been proposed. Alternative cryptocurrencies such as Dash, Monero, and Zcash aim to provide stronger privacy by using sophisticated cryptographic techniques to obfuscate transaction data. Previous work in cryptocurrency privacy mostly focused on applying data mining algorithms to the transaction graph extracted from the blockchain. We focus on a less well researched vector for privacy attacks: network analysis. We argue that timings of transaction messages leak information about their origin, which can be exploited by a well connected adversarial node. For the first time, network level attacks on Bitcoin and the three major privacy-focused cryptocurrencies have been examined. We describe the message propagation mechanics and privacy guarantees in Bitcoin, Dash, Monero, and Zcash. We propose a novel technique for linking transactions based on transaction propagation analysis. We also unpack address advertisement messages (ADDR), which under certain assumptions may help in linking transaction clusters to IP addresses of nodes. We implement and evaluate our method, deanonymizing our own transactions in Bitcoin and Zcash with a high level of accuracy. We also show that our technique is applicable to Dash and Monero. We estimate the cost of a full-scale attack on the Bitcoin mainnet at hundreds of US dollars, feasible even for a low budget adversary.