Jing Chen, Xin Chen, Kun He, Ruiying Du · 6 authors
Audit log contains the trace of different activities in computing systems, which makes it critical for security management, censorship, and forensics. However, experienced attackers may delete or modify the audit log after their attacks, which makes the audit log unavailable in attack investigation. In this article, we focus on the log integrity audit in the same domain, in which a number of servers update audit logs for a single or several organizations as an alliance. We propose a distributed efficient log integrity audit framework, called DELIA, which employs the distributed ledger technique to protect audit information, and utilizes the idea of state channel to improve the throughput of distributed ledger. To generate stable state from the rapidly-updated logs in the domain, we propose a log state generation scheme, which not only generates state suitable for audit logs, but also enables mutual supervision within the domain. To overcome the high latency in existing state channel schemes, we propose a hierarchal multi-party state channel scheme, which makes the latency in our framework independent of the number of servers in the domain. We implement DELIA on Ethereum and evaluate its performance. The results show that our framework is efficient and secure in practice.
R. Aparna, Sanjay Raj R, Swapnonil Bandopadhyay, Anu Vikram K · 5 authors
Data deduplication is an important data compression technique to eliminate duplicate copies of data and has been widely used in cloud storage to reduce the amount of storage space and save bandwidth. However, even though most cloud service providers already employ deduplication techniques, they consume a lot of overhead bandwidth. Hence, we came up with a solution to reduce this overhead bandwidth by creating a middleware deduplication layer that checks the originality of a file without the need to communicate with the cloud. This results in reducing a substantial amount of internet overhead and at the same time making the deduplication process much quicker since it is closer to the edge device. We implement the deduplication layer using a decentralized blockchain structure due to its inherent security and scalability features.To protect the confidentiality of sensitive data while supporting deduplication, the convergent encryption techniques such as double hashing has been proposed to ensure that the user account credentials are secure and not misused. We implement our blockchain layer using Ganache that provides us with an Ethereum powered blockchain to test and deploy our prototype. Hence all the file transactions i.e., uploading, sharing and deletion of files will go through ganache and get added to our local blockchain network. We define Smart contracts to communicate with the ganache layer which mines a block every time a new file is uploaded or shared with another user and file metadata is stored in each of these blocks. Since every unique file will have its own block, the file metadata will help in achieving deduplication at this layer.
Three-dimensional (3D) data are easily collected in an unconscious way and are sensitive to lead biological characteristics exposure. Privacy and ownership have become important disputed issues for the 3D data application field. In this paper, we design a privacy-preserving computation system (SPPCS) for sensitive data protection, based on distributed storage, trusted execution environment (TEE) and blockchain technology. The SPPCS separates a storage and analysis calculation from consensus to build a hierarchical computation architecture. Based on a similarity computation of graph structures, the SPPCS finds data requirement matching lists to avoid invalid transactions. With TEE technology, the SPPCS implements a dual hybrid isolation model to restrict access to raw data and obscure the connections among transaction parties. To validate confidential performance, we implement a prototype of SPPCS with Ethereum and Intel Software Guard Extensions (SGX). The evaluation results derived from test datasets show that (1) the enhanced security and increased time consumption (490 ms in this paper) of multiple SGX nodes need to be balanced; (2) for a single SGX node to enhance data security and preserve privacy, an increased time consumption of about 260 ms is acceptable; (3) the transaction relationship cannot be inferred from records on-chain. The proposed SPPCS implements data privacy and security protection with high performance.
Francis Asuncion, Adam Brinckman, Dwayne Cole, Jeffrey H. Curtis · 28 authors
Blockchains have been around for more than ten years, and since 2015, a plethora of systems have been launched to target more flexible use cases. More recently, several enterprise blockchain systems, such as Consensys Quorum and Hyperledger Fabric, have been launched to make blockchain simpler to apply in complex organizational configurations. In this paper, we identify a specific Department of Defense use case, extrapolate requirements, and perform a thorough assessment of the different layers of the blockchain stack to identify the existing state of the art and undertake a gap analysis of the technology for this context. We describe a platform that meets many of these challenges and show how we architected, designed, and implemented a solution for this use case for deployment at NAVAIR. This solution connects transactions from two separate blockchain systems, Consensys Quorum and Hyperledger Fabric, by using a graph-based approach that preserves privacy while enabling full transparency across the military and supplier networks.
There is a need for fast, automatic, and trusted verification of a person’s qualifications. This paper proposes the Smart CV (Curriculum Vita) that contains links to Blockchain-based certifications of the person’s qualifications. Also, the paper proposes an architecture for the Blockchain-based Smart CV consisting of five layers: 1) Trusted certificate Issuers; 2) Trusted Distributed Ledgers; 3) Trusted management; 4) Smart CV; 5) Users. Educational institutes, accreditation organizations, public authorities, employers and others can cooperate to issue and accept these Blockchain-based certificates presented on a person’s Smart CV.
To support new and more complex software systems, tools, and applications, the IT Infrastructures have evolved to be more flexible and grow both in size and complexity. To manage those Infrastructures, several tools are used. For large datacenters and public cloud infrastructures, complex managements systems have been developed in-house, according to specific implementations and philosophies. However, for the small, business owned, infrastructures, such tools are usually used independently. In this paper, we present the architecture of a new Orchestrator tool that aims to provide a single point of management, while also maintaining a resource inventory, by means of a Distributed Ledger, in order to maintain records of all the changes in the infrastructure, ensuring traceability over past changes, and even allowing for rollback of certain actions.
Decentralized cryptocurrency exchanges offer compelling security benefits over centralized exchanges: users control their funds and avoid the risk of an exchange hack or malicious operator. However, because user assets are fully accessible by a secret key, decentralized exchanges pose significant internal security risks for trading firms and automated trading systems, where a compromised system can result in total loss of funds. Centralized exchanges mitigate this risk through API key based security policies that allow professional users to give individual traders or automated systems specific and customizable access rights such as trading or withdrawal limits. Such policies, however, are not compatible with decentralized exchanges, where all exchange operations require a signature generated by the owner's secret key. This paper introduces a protocol based upon multiparty computation that allows for the creation of API keys and security policies that can be applied to any existing decentralized exchange. Our protocol works with both ECDSA and EdDSA signature schemes and prioritizes efficient computation and communication. We have deployed this protocol on Nash exchange, as well as around several Ethereum-based automated market maker smart contracts, where it secures the trading accounts and wallets of thousands of users.
Abstract Through virtualization and resource integration, cloud computing has expanded its service area and offers a better user experience than the traditional platforms, along with its business operation model bringing huge economic and social benefits. However, a large amount of evidence shows that cloud computing is facing with serious security and trust crisis, and building a trust-enabled transaction environment has become its key factor. The traditional cloud trust model usually adopts a centralized architecture, which causes large management overhead, network congestion and even single point of failure. Furthermore, due to a lack of transparency and traceability, trust evaluation results cannot be fully recognized by all participants. Blockchain is a new and promising decentralized framework and distributed computing paradigm. Its unique features in operating rules and traceability of records ensure the integrity, undeniability and security of the transaction data. Therefore, blockchain is very suitable for constructing a distributed and decentralized trust architecture. This paper carries out a comprehensive survey on blockchain-based trust approaches in cloud computing systems. Based on a novel cloud-edge trust management framework and a double-blockchain structure based cloud transaction model, it identifies the open challenges and gives directions for future research in this field.
Yang Yang, Robert H. Deng, Wenzhong Guo, Hongju Cheng · 7 authors
In this article, we proposedualtraceabledistributedattributebasedencryption withsubsetkeywordsearch system (DT-DABE-SKS, abbreviated as$\mathcal {DT}$) to simultaneously realize data source trace (secure provenance) and user trace (traitor trace) and flexible subset keyword search from polynomial interpolation. Leveraging non-interactive zero-knowledge proof technology,$\mathcal {DT}$preserves privacy for both data providers and users in normal circumstances, but a trusted authority can disclose their real identities if necessary, such as the providers deceitfully uploading false data or users maliciously leaking secret attribute key. Next, we introduce the new conception of updatable and transferable message-lock encryption (UT-MLE) for block-level dynamic encrypted file update, where the owner does not have to download the whole ciphertext, decrypt, re-encrypt and upload for minor document modifications. In addition, the owner is permitted to transfer file ownership to other system customers with efficient computation in an authenticated manner. A nontrivial integration of$\mathcal {DT}$and UT-MLE lead to the distributed ABSE with ownership transfer system ($\mathcal {DTOT}$) to enjoy the above merits. We formally define$\mathcal {DT}$, UT-MLE, and their security model. Then, the instantiations of$\mathcal {DT}$and UT-MLE, and the formal security proof are presented. Comprehensive comparison and experimental analysis based on real dataset affirm their feasibility.
To solve the problem that the safety data in the process of coal mine production are easy to be maliciously tampered with and deleted, a mine consortium blockchain data security monitoring system is proposed. The coal mine consortium blockchain includes supervision department, builds favourable centralized and decentralized production mode, and improves PBFT (Practical Byzantine Fault Tolerance) consensus mechanism to implement practical coal mine safety production. The evaluation shows that the architecture we proposed is more appropriate and efficient for the mine Internet of Things than the traditional blockchain architecture. The Hyperledger Fabric platform is used to build the mine consortium blockchain system to achieve the sensor data reliability, node consensus, safe operation automation management, and major equipment traceability.
Amirmohammad Pasdar, Zhongli Dong, Young Choon Lee
Blockchain is a form of distributed ledger technology (DLT) where data is shared among users connected over the internet. Transactions are data state changes on the blockchain that are permanently recorded in a secure and transparent way without the need of a third party. Besides, the introduction of smart contracts to the blockchain has added programmability to the blockchain and revolutionized the software ecosystem leading toward decentralized applications (DApps) attracting businesses and organizations to employ this technology. Although promising, blockchains and smart contracts have no access to the external systems (i.e., off-chain) where real-world data and events resides; consequently, the usability of smart contracts in terms of performance and programmability would be limited to the on-chain data. Hence, \emph{blockchain oracles} are introduced to mitigate the issue and are defined as trusted third-party services that send and verify the external information (i.e., feedback) and submit it to smart contracts for triggering state changes in the blockchain. In this paper, we will study and analyze blockchain oracles with regard to how they provide feedback to the blockchain and smart contracts. We classify the blockchain oracle techniques into two major groups such as voting-based strategies and reputation-based ones. The former mainly relies on participants' stakes for outcome finalization while the latter considers reputation in conjunction with authenticity proof mechanisms for data correctness and integrity. We then provide a structured description of patterns in detail for each classification and discuss research directions in the end.
Validasi dokumen merupakan hal yang sangat penting dalam menyangkut keaslian aset digital pemilik. Dimana validasi dokumen saat ini masih bersifat tradisional dengan mengunjungi tempat tersebut. Namun, saat pandemi proses validasi dokumen tidak dilakukan tatap muka karena pandemi Covid-19. Penelitian ini bertujuan agar penggunaan teknologi tanda tangan digital pintar yang menjamin keamanan dan validitasnya tanpa harus tatap muka. Smart digital signature adalah tanda tangan digital yang terenkripsi dengan RSA-SHA256 berbasis blockchain dengan fitur penyimpanan cloud storage yang memudahkan untuk berbagi dokumen. Metode analisa SWOT untuk mengetahui penggunaan sistem secara keseluruhan dimulai dari strategi, peluang, kekuatan dan kelemahan. Kombinasi SHA-256 dan Teknologi blockchain diterapkan pada Smart Digital Signature untuk menyimpan data dengan keamanan yang tinggi dan terjamin keabsahannya dan terhindar dari pemalsuan. Temuan dari penelitian ini sistem tanda tangan digital memiliki dampak yang signifikan dari pemalsuan, pengesahan dan keamanan dokumen.
The automotive industry is one of the lucrative markets in the world. With the advancement of the human lifestyle, everybody needs a car for their daily business. Before buying a used vehicle, the history of the vehicle should be verified. Currently, the history of the vehicle is obtained from the second-hand vehicle dealers. The data provided by dealers need not be correct because they do not maintain a proper record. The only way for the buyer is to believe the dealer and proceed with the deal. To resolve these problems, we proposed a distributed framework using blockchain technology to verify the history of the vehicles. The creator or deployer in the system is responsible for creating the registration of the vehicle with a unique VIN and it will be updated to the shared ledger. Then the vehicles are distributed to the trusted dealers in the system with the execution of the smart contract in the supply chain and finally released to the user. In the running phase, the proposed model records insurance, real-time data and maintenance services, and legal issues if any. The main advantage of the vehicle verification on the blockchain is that it can reduce the possibility of fraud and counterfeiting documents.
In this paper, we study efficient and authorized rewriting of transactions already written to a blockchain. Mutable transactions will make a fraction of all blockchain transactions, but will be a necessity to meet the needs of privacy regulations, such as the General Data Protection Regulation (GDPR). The state-of-the-art rewriting approaches have several shortcomings, such as being coarse-grained, inability to expunge data, absence of revocation mechanisms, lack of user anonymity, and inefficiency. We present ReTRACe, an efficient framework for transaction-level blockchain rewrites, that is fine-grained and supports revocation. ReTRACe is designed by composing a novel revocable chameleon hash with ephemeral trapdoor scheme, a novel revocable fast attribute based encryption scheme, and a dynamic group signature scheme. We discuss ReTRACe, and its constituent primitives in detail, along with their security analyses, and present experimental results to demonstrate scalability.
Zero-knowledge set membership (ZKSM) proof is widely used in blockchain to enable private membership attestation. However, existing mechanisms do not fully consider dynamic issues in the blockchain scenario. Particularly, frequent addition/removal of set elements, not only brings the significant cost to keep public parameters up to date to provers and verifiers but also affects mechanism efficiency (e.g., generation time of the proof and verification, etc.). In this paper, we propose DIV to shard elements on blockchain into independent subsets with the same cardinality to reduce the effect of dynamic issues. However, due to the diverse proof frequency, an improper element-set assignment can result in frequently used elements being easily inferred and corrupted. Thus, we formalize the assignment problem under both element addition and removal cases as two optimization problems and prove their NP-hardness. For each problem, we consider two cases if each element proof frequency is known in advance by the set maintainer or not, and propose solutions with theoretical guarantees. We implement DIV on both Merkle tree and RSA-based ZKSM mechanisms to evaluate its efficiency and effectiveness and apply DIV on a ZKSMbased application named zkSync to demonstrate its applicability. Results show that DIV can achieve O(1) time/space cost on ZKSM under dynamic situations while protecting the information about frequently used elements. It also notably reduces the system latency of zkSync.
Cyril Naves Samuel, François Verdier, Severine Glock, Patricia Guitton-Ouhamou
Enterprises are realizing their distributed ledger use-cases with private blockchains as it is more secure, efficient,
and reliable compared to the public networks. Due to this reason we evaluate the behavior and performance of Ethereum clients namely Geth, OpenEthereum (Parity), and Hyperledger Besu along with their Proof of Authority consensus algorithms from an enterprise perspective. We propose a testing methodology adapted to Microsoft Azure Cloud infrastructure overcoming the drawbacks of existing works. We analyze the bottlenecks and their root causes in each of the clients and report it to the community.
Abstract With the rapid development of Internet of Things (IoT) technology, IoT devices have been widely used to collect physiological health data and provide diversified services to the terminal users. However, traditional data storage and sharing scheme cloud computing based in IoT face many challenges. For example, IoT devices are usually resource‐constrained (storage, computing power, battery capacity, etc.), data signed by IoT devices to ensure data integrity and authenticity will consume a lot of computing resources of IoT devices. At the same time, there is the challenge of high latency and unsafe data storage and sharing. To overcome these challenges, we propose a secure and efficient data storage and sharing scheme for blockchain‐based mobile‐edge computing. In our scheme, we construct the unique signature private key in a region into multiple key shares. IoT devices only need to submit the data and the random key shares allocated to the edge node. Edge node uses the recovered signature private key to realize data signature and homomorphic encryption. At the same time, the edge node will process timely data and return to the user. For data that need to be uploaded to the cloud for analysis, we use backup uploads to avoid data floods. Through experiments, it was found that our scheme can not only realize low‐latency message response for the terminal users, but also realize anonymous identity verification while ensuring data integrity and authenticity. The key shares of the signature private key are stored in different blocks of the blockchain to improve fault tolerance. The content extraction signature algorithm ensures that the key shares stored in different blocks are publicly verifiable. Safety analysis and performance analysis verify the feasibility and effectiveness of our scheme.
Healthcare blockchains provide an innovative way to store healthcare information, execute healthcare transactions, and build trust for healthcare data sharing and data integration in a decentralized open healthcare network environment. Although the healthcare blockchain technology has attracted broad interests and attention in industry, government and academia, the security and privacy concerns remain the focus of debate when deploying blockchains for information sharing in the healthcare sector from business operation to research collaboration. This article focuses on the security and privacy requirements for medical data sharing using blockchain, and provides a comprehensive analysis of the security and privacy risks and requirements, accompanied by technical solution techniques and strategies. First, we discuss the security and privacy requirements and attributes required for electronic medical data sharing by deploying the healthcare blockchain. Second, we categorize existing efforts into three reference blockchain usage scenarios for electronic medical data sharing, and discuss the technologies for implementing these security and privacy properties in the three categories of usage scenarios for healthcare blockchain, such as anonymous signatures, attribute-based encryption, zero-knowledge proofs, verification techniques for smart contract security. Finally, we discuss other potential blockchain application scenarios in healthcare sector. We conjecture that this survey will help healthcare professionals, decision makers, and healthcare service developers to gain technical and intuitive insights into the security and privacy of healthcare blockchains in terms of concepts, risks, requirements, development and deployment technologies and systems.
Fog computing is a new computing paradigm for meeting ubiquitous massive access and latency-critical applications by moving the processing capability closer to end users. The geographical distribution/floating features with potential autonomy requirements introduce new challenges to the traditional methodology of network access control. In this paper, a blockchain-enabled fog resource access and granting solution is proposed to tackle the unique requirements brought by fog computing. The smart contract concept is introduced to enable dynamic, and automatic credential generation and delivery for an independent offer of fog resources. A per-transaction negotiation mechanism supports the fog resource provider to dynamically publish an offer and facilitates the choice of the preferred resource by the end user. Decentralized authentication and authorization relieve the processing pressure brought by massive access and single-point failure. Our solution can be extended and used in multi-access and especially multi-carrier scenarios in which centralized authorities are absent.
Recently, blockchain has gained momentum as a novel technology that gives rise to a plethora of new decentralized applications (e.g., Internet of Things (IoT)). However, its integration with the IoT is still facing several problems (e.g., scalability, flexibility). Provisioning resources to enable a large number of connected IoT devices implies having a scalable and flexible blockchain. To address these issues, we propose a scalable and trustworthy blockchain (STB) architecture that is suitable for the IoT; which uses blockchain sharding and oracles to establish trust among unreliable IoT devices in a fully distributed and trustworthy manner. In particular, we design a Peer-To-Peer oracle network that ensures data reliability, scalability, flexibility, and trustworthiness. Furthermore, we introduce a new lightweight consensus algorithm that scales the blockchain dramatically while ensuring the interoperability among participants of the blockchain. The results show that our proposed STB architecture achieves flexibility, efficiency, and scalability making it a promising solution that is suitable for the IoT context.
Ji Sun Shin, Shincheol Lee, Seoyun Choi, Minjae Jo · 5 authors
Blockchain, a distributed ledger technology, is used in various fields, including many types of critical infrastructure, such as smart grids. Recently, studies have dealt with privacy preservation in smart grids. One such study presented a privacy-preserving aggregation system that provides integrity and anonymity using blockchain technology in a smart grid. In earlier work, a Bloom filter was used for rapid authentication on the blockchain, and a key management center was used for user key management. However, due to its high dependence on the key management center, it was not able to provide a completely distributed environment, and there was a linkability problem. In addition, there was a limitation in that key revocation and update functions through the Bloom filter could not be provided. In this article, we propose a decentralized privacy-preserving ID scheme that provides a fully distributed environment to address the limitations of existing research. The proposed scheme provides unlinkability to protect the anonymity of users using a blind signature. It also provides update or revocation functionalities of the pseudonym by the counting Bloom filter or the revoked-pseudonym Bloom filter. In addition, fully distributed operation is guaranteed through the certification authority responsible for user key management. Our scheme is applicable not only to blockchain-based decentralized privacy-preserving systems such as billing systems in a smart grid or smart cities, but also to any critical infrastructure, such as banks, hospitals, and systems including e-bulletins, e-surveys, e-voting, and so on.
A reliable log system is a prerequisite for many applications. Financial systems need to have transactions logged in a precise manner, medical systems rely on having trusted medical records and security logs record system access requests in order to trace malicious attempts. Keeping multiple copies helps to achieve availability and reliability against such hackers. Unfortunately, maintaining redundant copies in a distributed manner in a byzantine setting has always been a challenging task, however it has recently become simpler given advances in blockchain technologies. In this work, we present a tamper-resistant log system through the use of a blockchain. We leverage the immutable write action and distributed storage provided by the blockchain as a basis to develop a secure log system, but we also add a privacy preserving layer that is essential for many applications. We detail the security and privacy aspects of our solution, as well as how they relate to performance needs in relevant settings. Finally, we implement our system over Hyperledger Fabric and demonstrate the system’s value for several use cases. In addition, we provide a scalability analysis for applying our solution in a large-scale system.