Electronic voting (e-voting) is an electronic means for casting and counting votes. It is an efficient and cost-effective way for conducting a voting procedure, which has characteristic of being magnanimous data and real time and requesting high safety. However, concerns on security of networking and privacy of communication for e-voting have been grown. Securing e-voting is very urgent and has becoming a popular topic in the area of communications and networking. We present techniques to exploit blockchain in P2P network to improve the security of e-voting. First, we design a synchronized model of voting records based on distributed ledger technology (DLT) to avoid forgery of votes. Second, we design a user credential model based on elliptic curve cryptography (ECC) to provide authentication and non-repudiation. Third, we design a withdrawal model that allows voters to change their vote before a preset deadline. By integrating the above designs, a blockchain-based e-voting scheme in P2P network is proposed for essential requirements of e-voting process. To prove and verify the scheme, a blockchain-based e-voting system for multiple candidates has been designed on Linux platforms in P2P network. The system involves electronic voting theory, cryptography, and software engineering theory. The implementation result shows that it is a practical and secure e-voting system, which solves the problem on forgery of votes during e-voting. The blockchain-based e-voting system can be applied to a variety of networking applications directly.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Zero-Knowledge Proof-of-Identity from trusted public certificates (e.g.,\nnational identity cards and/or ePassports; eSIM) is introduced here to\npermissionless blockchains in order to remove the inefficiencies of\nSybil-resistant mechanisms such as Proof-of-Work (i.e., high energy and\nenvironmental costs) and Proof-of-Stake (i.e., capital hoarding and lower\ntransaction volume). The proposed solution effectively limits the number of\nmining nodes a single individual would be able to run while keeping membership\nopen to everyone, circumventing the impossibility of full decentralization and\nthe blockchain scalability trilemma when instantiated on a blockchain with a\nconsensus protocol based on the cryptographic random selection of nodes.\nResistance to collusion is also considered.\n Solving one of the most pressing problems in blockchains, a zk-PoI\ncryptocurrency is proved to have the following advantageous properties:\n - an incentive-compatible protocol for the issuing of cryptocurrency rewards\nbased on a unique Nash equilibrium\n - strict domination of mining over all other PoW/PoS cryptocurrencies, thus\nthe zk-PoI cryptocurrency becoming the preferred choice by miners is proved to\nbe a Nash equilibrium and the Evolutionarily Stable Strategy\n - PoW/PoS cryptocurrencies are condemned to pay the Price of Crypto-Anarchy,\nredeemed by the optimal efficiency of zk-PoI as it implements the social\noptimum\n - the circulation of a zk-PoI cryptocurrency Pareto dominates other PoW/PoS\ncryptocurrencies\n - the network effects arising from the social networks inherent to national\nidentity cards and ePassports dominate PoW/PoS cryptocurrencies\n - the lower costs of its infrastructure imply the existence of a unique\nequilibrium where it dominates other forms of payment\n
Lyra2REv2 is a hashing algorithm that consists of a chain of individual hashing algorithms, and it is used as a proof-of-work function in several cryptocurrencies. The most crucial and exotic hashing algorithm in the Lyra2REv2 chain is a specific instance of the general Lyra2 algorithm. In this work, we present the first hardware implementation of the specific instance of Lyra2 that is used in Lyra2REv2 and we explain how several properties of this algorithm can be exploited in order to optimize the design. Moreover, we present an FPGA-based hardware implementation of a full miner chain for Lyra2REv2 on a Xilinx Multi-Processor System on Chip. Our proposed Lyra2REv2 miner chain is shown to be significantly more energy efficient than both a GPU and a commercially available FPGA-based miner. Finally, we also explain how our simplified Lyra2 and Lyra2REv2 architectures can be modified with minimal effort to also support the recent Lyra2REv3 chained hashing algorithm.
Muriel Figueredo Franco, Eder J. Scheid, Lisandro Zambenedetti Granville, Burkhard Stiller
Network Functions Virtualization (NFV) is transforming the way in which network operators acquire and manage network services. By using virtualization technologies to move packet processing from dedicated hardware to software, NFV has introduced a new market focused on the offer and distribution of Virtual Network Functions (VNF). Infrastructure Providers (InP) can benefit from an NFV market by providing their infrastructures to fulfill demands of end-users that, in turn, acquire VNFsas- a-Service (VNFaaS). In this context, solutions that promote the competition between InPs can lead to lower prices, while increasing VNF performance to accommodate specific demands of end-users. In this paper, BRAIN, a blockchain-based reverse auction is presented to introduce an auditable solution in which InPs can compete to host VNFs taking into account the demands of each particular end-user. Such a solution helps reduce costs involved in VNF's commercialization and also monetize NFVenabled infrastructures. BRAIN is supported by a case study that provides evidence of the solution's feasibility and effectiveness. A discussion regarding blockchain advantages and drawbacks in this use-case (e.g., , additional costs and time) concludes this paper.
The anonymity and de-anonymity of blockchain and Bitcoin have always been a hot topic in blockchain related research. Since Bitcoin was created by Nakamoto in 2009, it has, to some extent, deviated from its currency attribute as a trading medium but instead turned into an object for financial investment and operations. In this paper, the power-law distribution that the Bitcoin network obeys is given, while traditional de-anonymous methods such as clustering fail to satisfy it. Therefore, considering the profit-oriented characteristics of Bitcoin traders in such occasion, we put forward a deanonymous heuristic approach that recognizes and analyzes the behavioral patterns of financial High-Frequency Transactions(HFT), with real-time exchange rate of Bitcoin involved. Basing on the heuristic approach, finally we established the de-anonymous method that matches the activity information of the IP with the transaction records in blockchain. Experiments on IP matching method are applied to the actual data. It turns out that similar behavioral pattern between IP and transaction records are shown, which indicates the superiority of IP matching method.
Amin Kharraz, Zane Ma, Paul Murley, Charles Lever · 9 authors
In-browser cryptojacking is a form of resource abuse that leverages end-users' machines to mine cryptocurrency without obtaining the users' consent. In this paper, we design, implement, and evaluate Outguard, an automated cryptojacking detection system. We construct a large ground-truth dataset, extract several features using an instrumented web browser, and ultimately select seven distinctive features that are used to build an SVM classification model. Outguardachieves a 97.9% TPR and 1.1% FPR and is reasonably tolerant to adversarial evasions. We utilized Outguardin the wild by deploying it across the Alexa Top 1M websites and found 6,302 cryptojacking sites, of which 3,600 are new detections that were absent from the training data. These cryptojacking sites paint a broad picture of the cryptojacking ecosystem, with particular emphasis on the prevalence of cryptojacking websites and the shared infrastructure that provides clues to the operators behind the cryptojacking phenomenon.
Ethereum is an open-source, public, blockchain-based distributed computing platform and operating system featuring smart contract functionality. In this paper, we proposed an Ethereum based eletronic voting (e-voting) protocol, Ques-Chain, which can ensure the authentication can be done without hurting confidentiality and the anonymity can be protected without problems of scams at the same time. Furthermore, the authors considered the wider usages Ques-Chain can be applied on, pointing out that it is able to process all kinds of messages and can be used in all fields with similar needs.
Reza M. Parizi, Sajad Homayoun, Abbas Yazdinejad, Ali Dehghantanha · 5 authors
Blockchains are turning into decentralized computing platforms and are getting worldwide recognition for their unique advantages. There is an emerging trend beyond payments that blockchains could enable a new breed of decentralized applications, and serve as the foundation for Internet's security infrastructure. The immutable nature of the blockchain makes it a winner on security and transparency; it is nearly inconceivable for ledgers to be altered in a way not instantly clear to every single user involved. However, most blockchains fall short in privacy aspects, particularly in data protection. Garlic Routing and Onion Routing are two of major Privacy Enhancing Techniques (PETs) which are popular for anonymization and security. Garlic Routing is a methodology using by I2P Anonymous Network to hide the identity of sender and receiver of data packets by bundling multiple messages into a layered encryption structure. The Onion Routing attempts to provide low-latency Internet-based connections that resist traffic analysis, deanonymization attack, eavesdropping, and other attacks both by outsiders (e.g. Internet routers) and insiders (Onion Routing servers themselves). As there are a few controversies over the rate of resistance of these two techniques to privacy attacks, we propose a PET-Enabled Sidechain (PETES) as a new privacy enhancing technique by integrating Garlic Routing and Onion Routing into a Garlic Onion Routing (GOR) framework suitable to the structure of blockchains. The preliminary proposed GOR aims to improve the privacy of transactions in blockchains via PETES structure.
With the rapid proliferation of Internet of Thing (IoT) devices, many security challenges could be introduced at low-end routers. Misbehaving routers affect the availability of the networks by dropping packets selectively and rejecting data forwarding services. Although existing Reputation Management (RM) systems are useful in identifying misbehaving routers, the centralized nature of the RM center has the risk of one-point failure. The emerging blockchain techniques, with the inherent decentralized consensus mechanism, provide a promising method to reduce this one-point failure risk. By adopting the distributed consensus mechanism, we propose a blockchain-based reputation management system in IoT networks to overcome the limitation of centralized router RM systems. The proposed solution utilizes the blockchain technique as a decentralized database to store router reports for calculating reputation of each router. With the proposed reputation calculation mechanism, the reliability of each router would be evaluated, and the malicious misbehaving routers with low reputations will be blacklisted and get isolated. More importantly, we develop an optimized group mining process for blockchain technique in order to improve the efficiency of block generation and reduce the resource consumption. The simulation results validate the distributed blockchain-based RM system in terms of attacks detection and system convergence performance, and the comparison result of the proposed group mining process with existing blockchain models illustrates the applicability and feasibility of the proposed works.
Lukáš Hellebrandt, Ivan Homoliak, Kamil Malinka, Petr Hanáček
Tor is a low-latency free anonymization network based on onion routing. In Tor, directory servers maintain a list of all nodes. It is, however, possible for a powerful adversary (e.g., law enforcement agencies) to seize or compromise enough directory servers and thus forge that list. Therefore, clients that obtained such a forged list of nodes can be effectively deanonymized. As a countermeasure, we propose to utilize a permissioned blockchain with a single voting committee that is privately “elected” by a verifiable random function (VRF). Since the blockchain provides us with integrity guarantees by design, we increase trust in the directory servers by decentralizing management of Tor nodes present in the shared list. We apply skiplist as an optimization reducing a validation overhead of newly joined nodes and clients. The proposed approach has only a small performance impact on the existing Tor infrastructure.
Liang Wang, Gilad Asharov, Rafael Pass, Thomas Ristenpart · 5 authors
We explore how to build a blind certificate authority (CA). Unlike conventional CAs, which learn the exact identity of those registering a public key, a blind CA can simultaneously validate an identity and provide a certificate binding a public key to it, without ever learning the identity. Blind CAs would therefore allow bootstrapping truly anonymous systems in which no party ever learns who participates. In this work we focus on constructing blind CAs that can bind an email address to a public key. To do so, we first introduce secure channel injection (SCI) protocols. These allow one party (in our setting, the blind CA) to insert a private message into another party's encrypted communications. We construct an efficient SCI protocol for communications delivered over TLS, and use it to realize anonymous proofs of account ownership for SMTP servers. Combined with a zero-knowledge certificate signing protocol, we build the first blind CA that allows Alice to obtain a X.509 certificate binding her email address alice@domain.com to a public key of her choosing without ever revealing ``alice'' to the CA. We show experimentally that our system works with standard email server implementations as well as Gmail.
The censorship attack is ubiquitous in prevailing blockchains, such as Bitcoin and Ethereum, yet has not been resolved well so far. According to known vulnerabilities of different consensus algorithms, censorship attacks can always achieve great benefits at low costs by various means. In this paper, we propose improvements to existing POS and POW algorithms to resolve censorship attacks in two methods. The first method improves the Tendermint consensus mechanism by introducing three new types of messages and an auxiliary role of network nodes. The method can automatically defend against censorship attacks and organize an honest chain. The second method is based on the CasperFFG consensus mechanism and can accurately identify the attackers by evaluating the suspicious scores of all validators. However, an honest validator has to manually choose the honest chain. Theoretical analyses show their effectiveness.
Since the ancient times, there exist all kinds of criminals in the world. In order to punish them, most authorities usually encourage the people to provide the evidence of a crime. To avoid the revenges from the criminals, it is necessary to study the anonymous reporting scheme with anonymous rewarding. In this paper, for the first time, we propose the novel concept of blockchain-based anonymous reporting scheme with anonymous rewarding (BB2AR). Our BB2AR scheme solves the open problem: how to realize the anonymous reporting and the anonymous rewarding simultaneously? First, we formalize the system model, definition, and security model of BB2AR. Second, we propose a concrete BB2AR scheme based on the elliptic curve public key cryptography. Our formal proof shows that our BB2AR scheme satisfies the anonymous reporting and the anonymous rewarding simultaneously. Finally, we analyze its efficiency and provide its prototype implementation. From the comparison, our BB2AR scheme is more efficient and practical.
Routing on the Internet is defined among autonomous systems (ASes) based on a weak trust model where it is assumed that ASes are honest. While this trust model strengthens the connectivity among ASes, it results in an attack surface which is exploited by malicious entities to hijacking routing paths. One such attack is known as the BGP prefix hijacking, in which a malicious AS broadcasts IP prefixes that belong to a target AS, thereby hijacking its traffic. In this paper, we proposeRouteChain: a blockchain-based secure BGP routing system that counters BGP hijacking and maintains a consistent view of the Internet routing paths. Towards that, we leverage provenance assurance and tamper-proof properties of blockchains to augment trust among ASes. We group ASes based on their geographical (network) proximity and construct a bihierarchical blockchain model that detects false prefixes prior to their spread over the Internet. We validate strengths of our design by simulations and show its effectiveness by drawing a case study with the Youtube hijacking of 2008. Our proposed scheme is a standalone service that can be incrementally deployed without the need of a central authority.
Raphael Matile, Bruno Rodrigues, Eder J. Scheid, Burkhard Stiller
Democracy in the digital age has attracted a lot of public attention in recent years. However, bringing the human right of secrecy in voting to electronic systems is difficult. Properties, such as the possibility of verifying universally that any vote counted was indeed carrying the decision made by a voter, are often conflicting and a trade-off must be found. This paper proposes a blockchain-based electronic voting system providing explicitly cast-as-intended verifiability. By using a non-interactive zero-knowledge proof of knowledge any voter can verify that his or her encrypted vote represents the decision voted for while maintaining at the same time the secrecy of the ballot. In addition, any required cryptographic material can be generated in linear time with respect to the number of voters, making the system suitable for large scale elections, thus scalable.
Managing the privileges of occupants and visitors of large commercial buildings to access different building areas, control systems and equipment therein is a challenging task. The best practice today involves giving long-term building occupants, for example employees working in the building, access privileges to their organization areas and requiring visitors to be escorted by them. This approach is conservative and inflexible. Ideally, an automated solution is needed to manage access delegations; however, traditional role-based access control models are unwieldy in that they require the specification of all roles and their relative authority, which is a challenge in large buildings home of multiple organizations and numerous visitors. In this paper, we present a methodology based on blockchain smart contracts to describe, grant, and revoke fine-grained permissions for building users in a decentralized fashion. This method supports access control using resource description framework (RDF) graphs and implements two APIs for client applications. Leveraging the metadata of a real building, we have applied the proposed method to manage privileges in some realistic use-cases and shown that it can greatly reduce the administration overhead while providing fine-grained access control.
The Blockchain-Enabled E-Voting uses a digital-currency analogy where in eligible voters can cast a ballot anonymously using a computing environment. BEV employs an encrypted key, smart biometrics and tamperproof realtime personal ID verification. Blockchain enable the creation of tamper-proof audit trails for voting. The idea of adapting digital voting systems to make the public electoral process cheaper, faster and easier, is a compelling one in modern society which normalizes it in the eyes of the voters, removes a certain power barrier between the voter and the elected candidate, thus making it an effective way for casting vote in this generation of technology.
Traditional voting and bidding systems largely rely on paperwork and human resources throughout the voting process, which can incur high costs in terms of both time and money. Electronic voting and electronic bidding systems can be used to reduce costs, and many new systems have been introduced. However, most systems require a powerful and trusted third party to guarantee system integrity and security. With developments in blockchain technology, research has begun to highlight the core concept of decentralization. In this study, we introduce the first decentralized electronic voting and bidding systems based on a blockchain and smart contract. We also use cryptographic techniques such as oblivious transfer and homomorphic encryptions to improve privacy protection. Our proposed systems allow voters and bidders to participate in the opening phase and improve participant anonymity, the privacy of data transmission, and data reliability and verifiability. Moreover, compared with other electronic voting and bidding systems, our systems are safer and more efficient.
Bruno Rodrigues, Lukas Eisenring, Eder J. Scheid, Thomas Bocek · 5 authors
The volume of traffic generated by modern Distributed Denial-of-Service (DDoS) attacks suggests that centralized defenses are not the most effective approach to counter these attacks. An alternative to reduce the burden of detection and mitigation is to combine centralized defense systems, creating a global and cooperative protection system. However, existing approaches suffer from the complexity of deployment and operation across different systems. Blockchains appear in this scenario as an alternative to simplify the exchange of information in a cooperative defense. This work evaluates in both local and global experimentations the performance of the blockchain system proposed in [8] concerning the latency to perform the signaling of blacklisted addresses.
With the surge in popularity of cryptocurrencies, Bitcoin has emerged as one of the most promising means for remittance, payments, and trading. Supplemented by the convenience offered by the smartphones, an increasing number of users are adopting Bitcoin wallet apps for different purposes.
Abrar O. Alkhamisi and Fathy Alboraei Abrar O. Alkhamisi and Fathy Alboraei
In recent years, the Internet of Things (IoT) plays a vital role in our daily activities .Owing to the increased number of vulnerabilities on the IoT devices, security becomes critical in the untrustworthy IoT environment. Access control is one of the top security concerns, however, implementing the traditional access control mechanisms in the resource-constrained nature of the IoT devices is a challenging task. With the emergence of blockchain technology, several recent research works have focused on the adoption of blockchain in IoT to resolve the security concerns. Despite, integrating the blockchain in the resource-constrained IoT context is difficult. To overcome these obstacles, the proposed work presents a privacy-aware IoT security architecture to ensure the access control based on Smart contract for resource-constrained and distributed IoT devices. The design of the proposed architecture incorporates three main components such as the contextual blockchain gateway, decentralized revocation manager, and non-interactive zero-knowledge proof based validation. By modeling the contextual blockchain gateway, the proposed architecture ensures the dynamic authentication and authorization based on the contextual information and access policies. Instead of integrating the blockchain technology into resource-constrained IoT devices, the smart contract-based distributed access control system with the contextual blockchain gateway provides the scalable solution. With the association of decentralized revocation manager in the smart contract, it prevents the resource access from the unauthorized users by dynamically generating and updating the revoked user list of all the nodes in the smart contract. Moreover, the proposed architecture employs the non-interactive zeroknowledge proof cryptographic protocol to ensure the transaction privacy within the smart contract. Consequently, it maintains the trade-off between the transparency and privacy while ensuring the security for the distributed IoT environment.
Adrià Rodríguez-Pérez, Pol Valletbó-Montfort, Jordi Cucurull
The transmission and tabulation of results are critical steps in the election process. If election results are provided quickly and transparently, they may inspire trust and confidence in the overall management of the contest. On the contrary, the late and questionable delivery of results might raise concerns and suspicion. In some cases, improper counting and tabulation procedures have brought candidates to question election results and even spurred long periods of violence. In this paper, we explore the potential of blockchain technology to enhance the counting and tabulation procedures during elections. Blockchains are distributed ledgers technologies whose transactions are protected cryptographically. It means that their contents cannot be tampered with nor modified in the long term. We argue that blockchain technology meets the requirements for electronic transmission and consolidation of election results. To prove so, we have implemented a proof of concept with a smart contract running on an Ethereum blockchain that registers the address of several polling stations and records the tally sheets that these submit at the end of the election. We also resort to the smart contract for the automatic and accurate consolidation of the election results once they have been submitted.