The dramatically growing trend of vehicles equipped with driving camera recorders has allowed realizing real-time crowdsourced video sharing in vehicular edge computing (VEC). Such cameras can assist in monitoring objects directly in front of and behind the vehicles, enabling them to provide important visual information through real-time video streaming in case of possible accidents. Exploiting the on-board units (OBUs) for VEC can allow drivers and passengers to share and access on-road video surveillance services. However, data security and privacy concerns of video generators (owners) are two key challenges that can severely limit video sharing in a VEC environment. In this article, we propose a blockchain empowered publish/subscribe (P/S) scheme to enable one-to-many secure video sharing in the VEC scenario. Then, we design an attribute-based encryption algorithm with static and dynamic attributes (ABE-SD) to achieve fine-grained access control in a mobile environment. Finally, We utilize permissioned blockchain and smart contracts to record access policy and publish and subscribe events, thus resulting in user self-certification and event traceability. The numerical results indicate that our proposed scheme ABE-SD outperforms traditional centralized CP-ABE methods in terms of encryption and decryption performance. The simulation experiments demonstrated that the proposed video-sharing scheme is secure and efficient.
The advent of 6G communications technology will bring about a transition from the “Internet of Everything” to the “Intelligent Connection of Everything”. 6G-enabled vehicular ad hoc networks (VANETs) will enjoy lower latency, higher speed, and greater capacity network services. Nevertheless, achieving secure data sharing will be an even tougher challenge. Given this, we propose an attribute-based data sharing scheme with blockchain for 6G-enabled VANETs. First, we propose an efficient multi-tree-based user revocation mechanism. With the Chinese remainder theorem, our mechanism supports user batch revocation and batch joining. Second, we achieve distributed data storage by utilizing the blockchain and smart contracts. To solve the problem of insufficient storage capacity on the blockchain, we adopt a combination of on-chain and off-chain storage. Third, to reduce the computation burden on users, our proposal supports online/offline encryption and verifiable outsourced decryption. Meanwhile, our mechanism supports policy hiding, data revocation, and cross-domain data sharing. The proposed scheme is proven to satisfy the indistinguishability under chosen plaintext attack (IND-CPA) in the standard model. Theoretical analysis shows that our mechanism outperforms existing schemes in functionality and security. Simulation experiments show that our proposal is efficient and suitable for 6G-enabled VANETs.
The unexpected and rapid spread of the COVID-19 pandemic has amplified the acceptance of remote healthcare systems such as telemedicine. Telemedicine effectively provides remote communication, better treatment recommendation, and personalized treatment on demand. It has emerged as the possible future of medicine. From a privacy perspective, secure storage, preservation, and controlled access to health data with consent are the main challenges to the effective deployment of telemedicine. It is paramount to fully overcome these challenges to integrate the telemedicine system into healthcare. In this regard, emerging technologies such as blockchain and federated learning have enormous potential to strengthen the telemedicine system. These technologies help enhance the overall healthcare standard when applied in an integrated way. The primary aim of this study is to perform a systematic literature review of previous research on privacy-preserving methods deployed with blockchain and federated learning for telemedicine. This study provides an in-depth qualitative analysis of relevant studies based on the architecture, privacy mechanisms, and machine learning methods used for data storage, access, and analytics. The survey allows the integration of blockchain and federated learning technologies with suitable privacy techniques to design a secure, trustworthy, and accurate telemedicine model with a privacy guarantee.
Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare and Education
The Blockchain (BCT) is the first decentralized ledger to include a trust mechanism in its design. It establishes a trustworthy framework for distributed commands by using data redundancy at several nodes. Conspicuously, the current study presents a BCT-based lightweight IoT information exchange security architecture for data exchange. The proposed technique uses a dual chain methodology, namely transaction and data BCT working together to provide distributed storage and tamper-proofing of data. Moreover, Transaction BCT is enhanced by a consensus algorithm using a practical Byzantine fault-tolerant (PBFT) mechanism. The proposed algorithm can increase data registering efficiency, transactions, and privacy protection BCT. It is deduced that local dominance can be avoided using the dynamic game strategy of node cooperation. Furthermore, by reporting the node’s global reputation value, the status of the unknown node may be approximated. The high-trust measure is utilized to adjust the weight of the affected node in the combined node-set, leading to the Bayesian equilibrium. The proposed model is validated in several experimental simulations and results are compared with state-of-the-art techniques. Based on the results, enhanced performance is registered for the proposed techniques in terms of temporal delay, statistical efficiency, reliability, and stability.
Suhui Liu, Liquan Chen, Ge Wu, Huaqun Wang · 5 authors
Patient-centered data management and sharing of personal health records (PHRs) are difficult to be realized as data is controlled by doctors/hospitals. In addition, security and privacy, oppressive costs, search and tracing unreliability, and complicated access authorization caused by traditional encryption severely hinder the widespread adoption of PHRs. To overcome these challenges, we propose a blockchain-backed data sharing framework for PHRs, where the blockchain achieves reliable search and tracing. Furthermore, we design a hybridblockchain-backedsearchableproxysigncryption scheme, namedBC-SPSC. Specifically, an identity-based proxy signature (IBPS) is utilized to perform the authorization from patients to doctors to achieve authentic patient-centricity, therefore the blockchain can relate data with associated patients and doctors during data tracing. Moreover, BC-SPSC supports two search modes. The first mode adopts attribute-based encryption with keyword-based search (SABE), where all legitimate users can implement searches, but only users whose attributes satisfy the access structure can successfully decrypt. By contrast, the second mode utilizes attribute-based searchable encryption (ABSE) to accomplish fine-grained authorization in both search and data access/decryption, that is, who can search is also constrained by data owners. Adequate performance comparisons and simulation experiments indicate significant advantages of the BC-SPSC scheme in storage and computation overheads.
Due to the sharp growth of employing mobile devices and IoT (Internet of Things) sensors in daily life, tremendous generated or collected data become one of the most valuable assets for not only users but also numerous applications, which provide various services using user data. However, a large portion of such data is possessed by only a few giant companies in a centralized manner. This incurs the concerns of how user data are harnessed and used and who can use such data because of many cases of privacy violence and data leakage. Therefore, in this paper, we propose a decentralized data sharing marketplace using Ethereum to enable users to share their data in a privacy-preserving and self-governing manner. Users can only share parts of the data from their devices they want to share in the marketplace and gain rewards from the bidding of buyers anonymously. Furthermore, a federated learning use case is demonstrated as a privacy-enhanced application of the proposed marketplace to encourage users to share processed data to avoid raw data leakage.
Sacha Servan-Schreiber, Simon Beyzerov, Eli Yablon, Hyojae Park
Function Secret Sharing (FSS; Eurocrypt 2015) allows a dealer to share a function f with two or more evaluators. Given secret shares of a function f, the evaluators can locally compute secret shares of f (x) for any input x, without learning information about f in the process.In this paper, we initiate the study of access control for FSS. Given the shares of f, the evaluators can ensure that the dealer is authorized to share the provided function. For a function family $\mathcal{F}$ and an access control list defined over the family, the evaluators receiving the shares of $f \in \mathcal{F}$ can efficiently check that the dealer knows the access key for f.This model enables new applications of FSS, such as: (1) anonymous authentication in a multi-party setting, (2) access control in private databases, and (3) authentication and spam prevention in anonymous communication systems.Our definitions and constructions abstract and improve the concrete efficiency of several recent systems that implement ad-hoc mechanisms for access control over FSS. The main building block behind our efficiency improvement is a discrete-logarithm zero-knowledge proof-of-knowledge over secret-shared elements, which may be of independent interest.We evaluate our constructions and show a 50–70× reduction in computational overhead compared to existing access control techniques used in anonymous communication. In other applications, such as private databases, the processing cost of introducing access control is only 1.5–3×, when amortized over databases with 500,000 or more items.
Michael L. Rosenberg, Jacob White, Christina Garman, Ian Miers
Frequently, users on the web need to show that they are, for example, not a robot, old enough to access an age restricted video, or eligible to download an ebook from their local public library without being tracked. Anonymous credentials were developed to address these concerns. However, existing schemes do not handle the realities of deployment or the complexities of real-world identity. Instead, they implicitly make assumptions such as there being an issuing authority for anonymous credentials that, for real applications, requires the local department of motor vehicles to issue sophisticated cryptographic tokens to show users are over 18. In reality, there are multiple trust sources for a given identity attribute, their credentials have distinctively different formats, and many, if not all, issuers are unwilling to adopt new protocols.We present and build zk-creds, a protocol that uses general-purpose zero-knowledge proofs to 1) remove the need for credential issuers to hold signing keys: credentials can be issued to a bulletin board instantiated as a transparency log, Byzantine system, or even a blockchain; 2) convert existing identity documents into anonymous credentials without modifying documents or coordinating with their issuing authority; 3) allow for flexible, composable, and complex identity statements over multiple credentials. Concretely, identity assertions using zk-creds take less than 150ms in a real-world scenario of using a passport to anonymously access age-restricted videos.
While the Internet of things brings convenience to people's lives, it will also bring people hidden worries about data security. As an important barrier to protect data security, identity authentication is widely used in the Internet of things. However, it is necessary to protect users' identity privacy while authenticating their identity. Anonymous authentication technology is often used to solve the contradiction between legitimacy and privacy in the authentication process. The existing anonymous authentication scheme has many problems in practical application such as the inability to achieve complete anonymity, the high computational complexity of the algorithm, and the corruption of the central authority. Aiming at the privacy of authentication, we propose Zero-Cerd, a self-blindable anonymous authentication system based on blockchain and dynamic accumulator. The self-blinding properties of the credential enable the users themselves to generate a new validly pseudonymous credential. With the help of zero-knowledge proof technology, users can prove the validity of their credentials without disclosing any information. Security analysis shows that our scheme has achieved the expected security objectives. Compared with the existing schemes, our scheme has the advantages of complete anonymity and high efficiency, and is more suitable for IoT applications with privacy protection requirements.
Dana Alsagheer, Nour Diallo, Rabimba Karanjai, Lei Xu · 5 authors
Researchers have started to recognize the necessity for a well-defined ML governance framework based on the principle of decentralization and comprehensively defining its scope of research and practice due to the growth of machine learning (ML) research and applications in the real world and the success of blockchain-based technology. In this paper, we study decentralized ML governance, which includes ML value chain management, decentralized identity for the ML community, decentralized ownership and rights management of ML assets, community-based decision-making for the ML process, decentralized ML finance, and risk management.
Konstantin D. Pandl, Chun-Yin Huang, Ivan Beschastnikh, Xiaoxiao Li · 6 authors
Existing research on data valuation in federated and swarm learning focuses on valuing client contributions and works best when data across clients is independent and identically distributed (IID). In practice, data is rarely distributed IID. We develop an approach called DDVal for decentralized data valuation, capable of valuing individual data points in federated and swarm learning. DDVal is based on sharing deep features and approximating Shapley values through a k-nearest neighbor approximation method. This allows for novel applications, for example, to simultaneously reward institutions and individuals for providing data to a decentralized machine learning task. The valuation of data points through DDVal allows to also draw hierarchical conclusions on the contribution of institutions, and we empirically show that the accuracy of DDVal in estimating institutional contributions is higher than existing Shapley value approximation methods for federated learning. Specifically, it reaches a cosine similarity in approximating Shapley values of 99.969 % in both, IID and non-IID data distributions across institutions, compared with 99.301 % and 97.250 % for the best state of the art methods. DDVal scales with the number of data points instead of the number of clients, and has a loglinear complexity. This scales more favorably than existing approaches with an exponential complexity. We show that DDVal is especially efficient in data distribution scenarios with many clients that have few data points - for example, more than 16 clients with 8,000 data points each. By integrating DDVal into a decentralized system, we show that it is not only suitable for centralized federated learning, but also decentralized swarm learning, which aligns well with the research on emerging internet technologies such as web3 to reward users for providing data to algorithms.
In recent years, permissionless blockchains have gained significant attention for their ability to secure and provide transparency in transactions. The development of blockchain technology has shifted from cryptocurrency to decentralized finance, benefiting millions of unbanked individuals, and serving as the foundation of Web3, which aims to provide the next generation of the internet with data ownership for users. The rise of NFTs has also helped artists and creative workers to protect their intellectual property and reap the benefits of their work. However, privacy risks associated with permissionless blockchains have become a major concern for individuals and institutions. The role of blockchain in the transition from Web2 to Web3 is crucial, as it is rapidly evolving. As more individuals, institutions, and organizations adopt this technology, it becomes increasingly important to closely monitor the new risks associated with permissionless blockchains and provide updated solutions to mitigate them. This paper endeavors to examine the privacy risks inherent in permissionless blockchains, including Remote Procedure Call (RPC) issues, Ethereum Name Service (ENS), miner extractable value (MEV) bots, on-chain data analysis, data breaches, transaction linking, transaction metadata, and others. The existing solutions to these privacy risks, such as zero-knowledge proofs, ring signatures, Hyperledger Fabric, and stealth addresses, shall be analyzed. Finally, suggestions for the future improvement of privacy solutions in the permissionless blockchain space shall be put forward.
Nowadays, data between hospitals are usually not interoperable, which brings great inconvenience to medical data sharing and patients’ medical treatment. In addition, patients do not want their medical data to be leaked during the sharing process. Researchers have employed blockchain to build data-sharing systems to address these issues. However, current systems do not restrict the power of participants, nor do they prevent visitors from sharing the obtained data to unauthorized parties. To address these issues, we propose a private data-sharing system with symmetric encryption for the medical industry that implements power restriction and access control, and prevents the leakage of private data. To be specific, firstly, symmetric encryption algorithm is utilized to encrypt medical data to protect the privacy of data owner. Secondly, our proposed system is built on a new blockchain framework, in which only visitors with permission can access the medical data. Thirdly, we employ chameleon signature to prevent visitors from sharing data with other parties without permission. Finally, we make the power of participants in the system revocable to prevent them from abusing their power. Our proposed system has been proven to be secure through security analysis and can protect the privacy of patients. In addition, the experimental results show that our system has excellent performance in terms of time overhead compared to other systems.
COVID-19 is a serious epidemic that not only endangers human health, but also wreaks havoc on the development of society. Recently, there has been research on using artificial intelligence (AI) techniques for COVID-19 detection. As AI has entered the era of big models, deep learning methods based on pre-trained models (PTMs) have become a focus of industrial applications. Federated learning (FL) enables the union of geographically isolated data, which can address the demands of big data for PTMs. However, the incompleteness of the healthcare system and the untrusted distribution of medical data make FL participants unreliable, and medical data also has strong privacy protection requirements. Our research aims to improve training efficiency and global model accuracy using PTMs for training in FL, reducing computation and communication. Meanwhile, we provide a secure aggregation rule using differential privacy and fully homomorphic encryption to achieve a privacy-preserving Byzantine robust federal learning scheme. In addition, we use blockchain to record the training process and we integrate a Byzantine fault tolerance consensus to further improve robustness. Finally, we conduct experiments on a publicly available dataset, and the experimental results show that our scheme is effective with privacy-preserving and robustness. The final trained models achieve better performance on the positive prediction and severe prediction tasks, with an accuracy of 85.00% and 85.06%, respectively. Thus, this indicates that our study is able to provide reliable results for COVID-19 detection.
Open access
COVID-19 diagnosis using AI
Privacy-Preserving Technologies in Data
Artificial Intelligence in Healthcare and Education
Venkatagurunatham Naidu Kollu, Vijayaraj Janarthanan, Muthulakshmi Karupusamy, R. Manikandan
Data sharing is proposed because the issue of data islands hinders advancement of artificial intelligence technology in the 5G era. Sharing high-quality data has a direct impact on how well machine-learning models work, but there will always be misuse and leakage of data. The field of financial technology, or FinTech, has received a lot of attention and is growing quickly. This field has seen the introduction of new terms as a result of its ongoing expansion. One example of such terminology is “FinTech”. This term is used to describe a variety of procedures utilized frequently in the financial technology industry. This study aims to create a cloud-based intrusion detection system based on IoT federated learning architecture as well as smart contract analysis. This study proposes a novel method for detecting intrusions using a cyber-threat federated graphical authentication system and cloud-based smart contracts in FinTech data. Users are required to create a route on a world map as their credentials under this scheme. We had 120 people participate in the evaluation, 60 of whom had a background in finance or FinTech. The simulation was then carried out in Python using a variety of FinTech cyber-attack datasets for accuracy, precision, recall, F-measure, AUC (Area under the ROC Curve), trust value, scalability, and integrity. The proposed technique attained accuracy of 95%, precision of 85%, RMSE of 59%, recall of 68%, F-measure of 83%, AUC of 79%, trust value of 65%, scalability of 91%, and integrity of 83%.
John Domingue, Allan Third, María-Esther Vidal, Philipp D. Rohde · 7 authors
Knowledge Graphs have become a foundation for sharing data on the web and building intelligent services across many sectors and also within some of the most successful corporations in the world. The over centralisation of data on the web, however, has been raised as a concern by a number of prominent researchers in the field. For example, at the beginning of 2022 a €2.7B civil lawsuit was launched against Meta on the basis that it has abused its market dominance to impose unfair terms and conditions on UK users in order to exploit their personal data. Data centralisation can lead to a number of problems including: lock-in/siloing effects, lack of user control over their personal data, limited incentives and opportunities for interoperability and openness, and the resulting detrimental effects on privacy and innovation. A number of diverse approaches and technologies exist for decentralising data, such as federated querying and distributed ledgers. The main question is, though, what does decentralisation really mean for web data and Knowledge Graphs? What are the main issues and tradeoffs involved? These questions and others are addressed in this workshop.
In recent years, the use of cloud services for data sharing poses a severe threat to the security and privacy of the data being shared over a public communication channel. The owners not only lose complete ownership of the data being uploaded to the cloud but the security and privacy of the data are also at stake. The interplanetary file system, IPFS has introduced a decentralized way to store data on a large scale, thereby overcoming the issue of a single point of failure and unavailability of data at all times. For added security, the use of attribute-based encryption before uploading the data on the IPFS provides an extra layer of security and confidentiality. ABE enables data owners to encrypt their data under a list of attributes with only the user possessing those attributes can decrypt the said file. The use of ABE provides fine-grained access control on the data being shared and provides the facility for easy updations of access rights. In this paper, we analyzed various data-sharing schemes based on Ethereum and IPFS and presented a scheme incorporating ciphertext policy, attribute-based encryption, CP-ABE along with Ethereum and smart contracts for enabling data storage and data sharing in the Internet of Medical Things, IoMT. The use of partial decryption also reduces the load on the resource-constrained IoT devices of a user. To further make the framework efficient and always available, the ability to access the file using a keyword search is also added to the framework. Experimental results prove that the proposed scheme uses less storage overhead as compared to some of the existing schemes thus reducing the computation time and cost too.
Facing the requirements of intelligent vehicles for massive data processing, vehicular edge computing (VEC) utilizes computing resources deployed on the roadside infrastructure to provide proximity computing services for vehicles and forms a novel computing paradigm. Thus, vehicles can reduce the burden of local computing and improve computing efficiency by offloading tasks to roadside computing servers or neighboring resource-idle vehicles for execution via cooperative computation offloading (CO). However, dynamic communication channel states and data handover among multiple VEC servers caused by vehicle mobility pose challenges for CO decision-making and data security. This article applies blockchain to the cooperative CO of VEC and thus proposes a cooperative CO and secure handover framework with a consensus mechanism to guarantee the efficiency of cooperative CO and secure handover. In this framework, models for vehicle mobility and cooperative CO handover are constructed, and a consensus mechanism is proposed. This mechanism ensures the synchronization and immutability of offloaded data in the CO handover. A cooperative CO decision optimization is also formulated considering secure handover with blockchain technology to optimize the latency of vehicular computing tasks. To solve this complex problem, this optimization is transformed into a Markov decision process and a cooperative CO decision algorithm with multiagent deep reinforcement learning is designed, thus achieving the optimal solution. Extensive simulations verified the performance and effectiveness of the proposed method.
Industry 4.0 integrates industrial Internet of Things (IIoT), artificial intelligence, and cloud computing. The advent of the 5G era has undoubtedly provided a new impetus for the development of many Industry 4.0 applications, but it also presents some key security hurdles. The network scale is becoming larger and larger, the network environment is becoming increasingly complex, and security risks are prominent. Frequent issues, such as malicious attacks, privacy information disclosure, and data transmission security. In order to improve the reliability and security of cyberspace, this article proposes a blockchain-based hierarchical IIoT security solution mechanism. In addition, we propose a random reputation voting mechanism and blockchain (RRV-BC) scheme based on verifiable random function and reputation voting to reduce the communication cost during blockchain consensus communication. Meanwhile, the node credit scoring mechanism is introduced to dynamically evaluate the node credit. The simulation results show that the scheme improves the reliability of data communication and the fault tolerance of consensus mechanism by an average of 5% compared with the traditional practical byzantine fault tolerance (PBFT) protocol method.
The deep integration of Internet of Medical Things (IoMT) and Artificial intelligence makes the further development of intelligent medical services possible, but privacy leakage and data security problems hinder its wide application. Although the combination of IoMT and federated learning (FL) can achieve no direct access to the original data of participants, FL still can't resist inference attacks against model parameters and the single point of failure of the central server. In addition, malicious clients can disguise as benign participants to launch poisoning attacks, which seriously compromises the accuracy of the global model. In this paper, we design a new privacy protection framework (BFG) for decentralized FL using blockchain, differential privacy and Generative Adversarial Network. The framework can effectively avoid a single point of failure and resist inference attacks. In particular, it can limit the success rate of poisoning attacks to less than 26%. Moreover, the framework alleviates the storage pressure of the blockchain, achieves a balance between privacy budget and global model accuracy, and can effectively resist the negative impact of node withdrawal. Simulation experiments on image datasets show that the BFG framework has a better combined performance in terms of accuracy, robustness and privacy preservation.
Yuan Feng, Zhangdui Zhong, Xiaofang Sun, Lei Wang · 6 authors
Abstract With the introduction of emerging technologies such as cloud computing, the railway communication network has the characteristics of complex structure and blurred boundaries, which leads to a series of security threats including information leakage and malicious access. Specifically, the third-party cloud services are difficult to be supervised, and network traffic is untrustworthy. To ensure system security, we propose a zero-trust security model in this paper. Then, we introduce blockchain and Merkle tree to build a distributed identity storage scheme for guaranteeing reliable, confidential and efficient data updates, and improving authentication efficiency. Furthermore, the proxy was introduced for two-way authentication with cloud servers, so that internal and external threats could be counteracted. Moreover, reputation assessment mechanism has been adopted to reduce the possibility of nodes accessing malicious cloud services. Performance analysis demonstrated that the proposed security model is able to enhance the security, efficiency and stability of the system, and consequently can guarantee the safety and reliability of railway transportation.
Xin Liu, Xiaomeng Liu, Naixue Xiong, Dan Luo · 6 authors
With the rapid development of cloud computing and other modern technologies, collaborative computing between data is increasing, and privacy protection and secure multi-party computation are also attracting more attention. The emergence of cloud computing provides new options for data holders to perform complex computing problems and to store images; however, data privacy issues cannot be ignored. If a graphic is encrypted and stored in the cloud, the cloud server will perform confidential similar matching when the user searches. At present, most research on searchable encryption is focused on text search, with few schemes researched on how to finish the graphic search. To solve this problem, this paper proposes a secure search protocol based on graph shape under the semi-honest model. Using the cut-choose method and zero-knowledge proof, further designs of the anti-malicious attack graphic similarity judgment system (AAJS) based on the Paillier encryption algorithm, can achieve the secure search and matching of the graph while resisting malicious adversary attacks. The proposed protocol’s security is proved by the real/ideal model paradigm. This paper conducts performance analysis and experimental simulation on the existing scheme and the experiments demonstrate that the system achieves high execution efficiency.