Information management system is in general a tedious and an important one. Among the various system, student information management system is important as here the data is sensitive and needs regular updating until they complete their degree. Along with the recent data, the history is also necessary to keep track of the course completion. In literature, there are various method proposed for the same. Independent of the technology, security and privacy of the data is important. One of the major issues with the student information is the space and the duration for which it must be maintained. Student information’s must be maintained atleast for 5 years. This occupies for more space meanwhile the security of the data also becomes an important factor when it gets stored in cloud storage. In this paper, a Blockchain based student information management is proposed. The system contains a web interface in which the faculties enter the marks. These marks get stored in the Blockchain with the help of smart contract.
Blockchain Technology's first application is Bitcoin. It started its journey with cryptocurrency in 2008 by Satoshi Nakamoto. After that, it travelled in many areas such as Government, healthcare, academics, supply chain management, Intellectual property management, social welfare, and energy system. Australia, UAE, Japan are some of the top countries using blockchain technology in various government projects. One can use blockchain technology with decentralised storage of data, which is distributed, immutable, tamper resistance, and securable with a consensus mechanism. Today, many government sectors, organisations, companies, and institutions follow blockchain technology using smart contracts that do not require third-party agreements. We have conducted a systematic survey on blockchain-based digital certification to find the research gap in this research work. We carry out the following: (i) Investigation on the reasons to use the blockchain in education system (ii) Classification of blockchain projects into five categories based on services provided by the projects and platforms used for development (iii) Identification of the services provided by the project and the technologies used for the development.
A blockchain architecture lacks central authority, so control of single unit cannot be implemented in this structure. All the actions that happen involve one or another single node which is part of the network. The main objective of this work is to implement a dynamic trust model for a blockchain network for each node connected. The actions that are performed by the nodes while in the network would be monitored and based on negative and positive points being given to nodes. These points will constitute in calculating the rank or the reputation factor of a node in the network. These factors have given some weight which is accounted to build up the trust value and trust rank, which is visible to all the nodes and can decide which node is more trustable and which is not. The lower ranking in the network means a malicious node and high rank would mean the genuine node. After ranking, we can find the node which may or may not misbehave in the future and try to prevent those nodes to cause serious security threats like Sybil attacks and Byzantine fault tolerance. These passive attacks are hard to discover and harder to prevent. Hence, this dynamic trust model will incorporate methods by which blockchain could be more secure and resilient. To get the application-based advantage of the following dynamic trust model, a supply chain model application would be used to record the peer-to-peer transactions for recording in the blockchain and further processing for trust ranking of the nodes. This application would generalize the use of all blockchain applications. Since the introduction of blockchain, everyone talks about the properties it offers—and they are actually quite unique. The introduction of blockchain was not made only to build application of Bitcoin, but to support the decentralized architecture and its work in the transaction processing. Therefore, blockchain also involves threats like any other new technology. Now, to remove those threats, as well as using blockchain widely, is the motivation for this project. Two of the threats which could be solved by devising a dynamic trust model are Sybil attacks and Byzantine fault tolerance. These passive attacks have disrupting impact on the whole network and are proven to be lethal for destroying architecture and applications running over it. The literature has wide discussion on security of blockchain, security, and trust of blockchain and its applications in different environments. Today’s supply chains have high standards for their requirements and even when the software works just fine, maybe it is not recent enough or it was not specified and built to satisfy these requirements. For instance, concurrent payment and transaction verifiability might be a huge issue nowadays in the supply chain finance, but maybe it was not rated as a high importance problem 12 years ago. Therefore, the software from 12 years ago complied with different requirements than the ones from today and was not built to handle that specific problem well. Requirements evolve, and so should the technology, in order to support them. The characteristics of blockchain architecture and dynamic trust models seem to be a good solution for many of the identified problems in supply chains to be reduced or neutralized. Figure 3.1 shows the general architecture of a blockchain with few blocks. More details of the blockchain can be found in the literature. These architectures are the perfect means to achieve traceability of a supply chain transaction, and so, they are useful to achieve provenance, as well. At the same time, they are a secure, incorruptible, and immutable way to store information, with a fast synchronization time, being perpetually available to anyone who has permission, anywhere within the network. It would also be the way to close the analog gaps, turning the chain fully digital, and leading to the possibility of a global overview.
Blockchain is a distributed technology that works along with smart contracts to create immutable ledgers in different application domains. Extensive research is still ongoing on how to utilize blockchain in industries such as healthcare, education, and finance, just to name a few. This chapter proposes a blockchain-based academic credential verification. Replacing current verification systems in educational institutes with those based on blockchain proves to benefit all the stakeholders. The chapter evaluates this proposal and presents a system, CryptoCert, as a proof of concept. By removing the need for a third party for verification, a lot of time and money will be saved for the stakeholders. More importantly, blockchain’s immutability provides a unique and efficient way to curb the widespread fraud and falsification of academic credentials such as degrees, transcripts, and learning achievement certificates.
Blockchain technology appears to be the ideal solution for storing data in a transparent and decentralized manner. It also allows open access to data and enhances its immutable nature. This technology has helped prove its usefulness in several industries so far, however, distributed ledger technology does not work as a pure database. Therefore, some problems occur in accessing data. Querying data in the blockchain leads to performance and bandwidth problems. This primarily occurs because the blockchain does not have a primary query language, unlike regular databases. The distributed nature of the blockchain is in this case an obstacle. In this paper, a safe and fast method will be proposed to retrieve consistent data from the blockchain-based on the smart contract that will be opened after completing the transaction procedures. All nodes will sign the proposed transaction (by adding a special hash to each node resulting from the transaction information and node data). Upon completion of Transaction procedures, A smart contract will be opened (in which a QR is placed) resulting from converting the signatures in the transaction to QR When the smart contract data is retrieved, the QR for each transaction will be used All node signatures and transaction data will be extracted. The data will be retrieved by the QR generated for each transaction after it is stored in all nodes servers participating in the system. A new method was proposed to generate a hash for each node present in the system. The proposed method was tested in terms of time and complexity, and the algorithm was statistically analyzed, and all the results proved successful.
Cloud computing is a network model of on-demand access for sharing configurable computing resource pools. Compared with conventional service architectures, cloud computing introduces new security challenges in secure service management and control, privacy protection, data integrity protection in distributed databases, data backup, and synchronization. Blockchain can be leveraged to address these challenges, partly due to the underlying characteristics such as transparency, traceability, decentralization, security, immutability, and automation. We present a comprehensive survey of how blockchain is applied to provide security services in the cloud computing model and we analyze the research trends of blockchain-related techniques in current cloud computing models. During the reviewing, we also briefly investigate how cloud computing can affect blockchain, especially about the performance improvements that cloud computing can provide for the blockchain. Our contributions include the following: (i) summarizing the possible architectures and models of the integration of blockchain and cloud computing and the roles of cloud computing in blockchain; (ii) classifying and discussing recent, relevant works based on different blockchain-based security services in the cloud computing model; (iii) simply investigating what improvements cloud computing can provide for the blockchain; (iv) introducing the current development status of the industry/major cloud providers in the direction of combining cloud and blockchain; (v) analyzing the main barriers and challenges of integrated blockchain and cloud computing systems; and (vi) providing recommendations for future research and improvement on the integration of blockchain and cloud systems.
Following the footprints of Bitcoins, many other cryptocurrencies were developed mostly adopting the same or similar Proof-of-Work (PoW) approach. Since completing the PoW puzzle requires extremely high computing power, consuming a vast amount of electricity, PoW has been strongly criticised for its antithetic stand against the notion of green computing. Use of application-specific hardware, particularly application-specific integrated circuits (ASICs) has further fuelled the debate, as these devices are of no use once they become “legacy” and hence obsolete to compete in the mining race, thus contributing to electronics waste. Therefore, this paper surveys the currently available alternative approaches to PoW and evaluates their applicability - especially their appropriateness in terms of greenness.
In current scenario the patients’ medical report is stored digitally in medical industry. The report consists of patients’ details such as patients’ private details, medical reports, and doctor prescriptions. This sensitive information is stored in centralized storage model. The disadvantage of this system is that there is problem in safeguarding user’s security. The problems such as illegal access of private data such as identity data and illness of the patient, and their medical reports. To address this issue, distributed file system of medical data using Interplanetary File System and blockchain technology is proposed. Where hash value of the report is stored in blockchain thus reducing the size of blockchain and the file is stored in IPFS. In IPFS the file is stored as hash value of the file. This framework preserves patient privacy and facilitates easy access of details of patients by authorized users such as doctors and patients. From this framework availability, integrity and consistency was achieved.
Wafa Ben Slama Souei, Chiraz El Hog, Layth Sliman, Raoudha Ben Djemaa · 5 authors
In recent years, Blockchain technology has proved its efficiency in many domains. A smart contract is a software component allowing exposing services via the Blockchain network. Smart contracts are small programs that automatically execute the terms of an agreement when predetermined terms and conditions are reached. With the increasing growth in the popularity of smart contracts, searching, retrieving and understanding smart contracts before executing them becomes a significant challenge. Nevertheless, the majority of these contracts are closed source contracts. Therefore, users cannot understand their functionality and their internal mechanism. In addition, their description lacks the expressiveness and it didn't cover the QOS parameters. In this paper, we propose a Uniform Description language for Smart Contract named UDL-SC. This proposal is an extension of USDL based on the MDA approach to promote trust and minimize the ambiguity between the user and the contract provider.
After successful completion of graduation, students receive the credits of the courses in the form of certificate issued by the respective University. A Student have to produce his/her documents to the employers or the authorities for employment or higher education. Today ,as the system is centralized all the data resides on the server which can be hacked or the data can be lost if the system crushes down. However, verifying a certificate by authorities, is a time-consuming process as there is an involvement of human resources ,for validating the details of the candidate from its University. Today , with the advancement in technologies and due to the easy availability of many efficient soft wares that have led to the forgery of credentials/certificates. The lack of anti-tampering mechanisms resulted in incidents where the forged graduation certificates are often found. Also ,in case certificates are out of place , applying for duplicate certificates and its issuance by the University consumes a lot of time. Use of blockchain technology in this process will make the system decentralized as blocks as cryptographically connected and all the nodes in the network shares the entire chain .Hence the proposed decentralized certificate verification system, uses blockchain technology incorporating all the essential features in developing a DAPP. This system is proposed to address the issue of certificate counterfeiting, faster certificate verification and issuance. Putting across all the issues, the system aims at addressing the problems and provide solutions to the current Certificate Issuance, verification and Validation Process.
With the increasing popularity of blockchain technology, Merkle trees (or hash trees) are playing significant roles in verifying and retrieving data for the implementation of blockchain for allowing efficient and secure verification of the contents of large data structures. This article gives systematical insights into Merkle trees with respect to their principles, properties, advantages, and applications.
Consensus protocols can help guarantee security and sustainability to maintain the decentralized Blockchain system used in different scenarios and applications due to their different features. There are two main prevalent protocols, Proof of Work (PoW) used in Bitcoin and Proof of Stake (PoS) used in Ethereum. This paper reviews these two consensus protocols, PoW and PoS, and their related improvements and applications. We first introduce the basic concepts, implementations, advantages, and disadvantages of PoW and PoW and make a detailed comparison between these two protocols. We find that though providing security when honest participants are the majority, PoW may lead to excessive power consumption. While PoS is relatively insecure and leads to monopoly (centralization), though energy efficient by discarding complex hash operations. Therefore, some newly proposed consensus protocols have attempted to find a pleasant compromise between these two classic protocols. After a detailed analysis, we investigate the researches related to the defect improvements of PoS and PoW. Finally, we describe various applications of PoS and PoW, including cryptocurrencies and information storage.
The beacon chain is the backbone of the Ethereum's evolution towards a proof-of-stake-based scalable network. Beacon clients are the applications implementing the services required to operate the beacon chain, namely validators, beacon nodes, and slashers. Security defects in beacon clients could lead to loss of funds, consensus rules violation, network congestion, and other inconveniences. We reported more than 35 issues to the beacon client developers, including various security improvements, specification inconsistencies, missing security checks, exposure to known vulnerabilities. None of our findings appears to be high-severity. We covered the four main beacon clients, namely Lighthouse (Rust), Nimbus (Nim), Prysm (Go), and Teku (Java). We looked for bugs in the logic and implementation of the new security-critical components (BLS signatures, slashing, networking protocols, and API) over a 3-month project that followed a preliminary analysis of BLS signatures code. We focused on Lighthouse and Prysm, the most popular clients, and thus the highest-value targets. Furthermore, we identify protocol-level issues, including replay attacks and incomplete forward secrecy. In addition, we reviewed the network fingerprints of beacon clients, discussing the information obtainable from passive and active searches, and we analyzed the supply chain risk related to third-party dependencies, providing indicators and recommendations to reduce the risk of backdoors and unpatchable vulnerabilities. Our results suggest that despite intense scrutiny by security auditors and independent researchers, the complexity and constant evolution of a platform like Ethereum requires regular expert review and thorough SSDLC practices.
Data deduplication and public auditing are significant for providing secure and efficient network storage services. However, the existing data deduplication schemes supporting auditing not only cannot effectively alleviate the threats of the single point of failure and duplicate-faking attack, but also have to bear the massive waste of computation and storage resources caused by metadata redundancy and repetitive audit tasks. In this article, we propose a blockchain-based secure deduplication and shared auditing scheme in decentralized storage. Specifically, our scheme utilizes a novel deduplication protocol based on the double-server storage model to achieve efficient space-saving while protecting data users from losing data under a single point of failure and duplicate-faking attack. Besides, it sharply reduces the computation and storage costs of metadata by introducing a lightweight authenticator generation algorithm and update protocol. On this basis, our scheme further adopts a blockchain-based two-way shared auditing mechanism to achieve decentralized public auditing without the third-party auditor, in which the audit authenticators and results of outsourced data are shared among its users to avoid repetitive audit tasks. Security and performance analysis indicates the practicability of our scheme.
Despite increasingly emerging applications, a primary concern for blockchain to be fully practical is the inefficiency of data query. Direct queries on the blockchain take much time by searching every block, while indirect queries on a blockchain database greatly degrade the authenticity of query results. To conquer the authenticity problem, we propose a Verifiable Query Layer (VQL) that can be deployed in the cloud to provide both efficient and verifiable data query services for blockchain systems. The middleware layer extracts data from the underlying blockchain system and efficiently reorganizes them in databases. To prevent falsified data from being stored in the middleware, a cryptographic fingerprint is calculated based on each constructed database. The database fingerprint will be first verified by miners and then written into the blockchain. Moreover, public users can verify the entire databases or several databases that interest them in the middleware layer. We implement VQL together with the verification schemes and conduct extensive experiments based on a practical blockchain system. The evaluation results demonstrate that VQL can efficiently support various data query services and guarantee the authenticity of query results for blockchain systems.
Christos Chrysoulas, A. M. Thomson, Nikolaos Pitropakis, Pavlos Papadopoulos · 10 authors
The continuously advancing digitization has provided answers to the bureaucratic problems faced by eGovernance services. This innovation led them to an era of automation it has broadened the attack surface and made them a popular target for cyber attacks. eGovernance services utilize internet, which is currently a location addressed system where whoever controls the location controls not only the content itself, but the integrity of that content, and the access to that content. We propose GLASS, a decentralised solution which combines the InterPlanetary File System (IPFS) with Distributed Ledger technology and Smart Contracts to secure EGovernance services. We also create a testbed environment where we measure the IPFS performance.
Internet of Things (IoT) refers to a technology where computing devices are connected and form a network. IoT faces many security and privacy issues due to less computation power, heterogeneity, and limited resources available with its devices. Data is transferred among these devices with little or no human interaction. Data Confidentiality and Integrity are very critical parameters and can be achieved by securely sharing information in IoT scenarios. Managing and maintaining trust in exchanging information over IoT becomes very significant. Recent researches have focused on the applications of Blockchain technology for assuring trust management in IoT networks. Blockchain provides completely distinct and more secure approaches. This survey paper aims to illustrate the significance of integrating Blockchain technology in the IoT environment to ensure trust among IoT devices. Particularly, first we give an overview and security aspects of IoT and Blockchain technologies. Then we trace out some important challenges and issues of trusted IoT with potential solutions by Blockchain. Following this, we highlight some complications in the integration of Blockchain with IoT. Finally, we present a comparative analysis between traditional and Blockchain-based trust management techniques as proof of work to represent the significance of Blockchain in ensuring trust.