We introduce FairSwap -- an efficient protocol for fair exchange of digital goods using smart contracts. A fair exchange protocol allows a sender S to sell a digital commodity x for a fixed price p to a receiver R. The protocol is said to be secure if R only pays if he receives the correct x. Our solution guarantees fairness by relying on smart contracts executed over decentralized cryptocurrencies, where the contract takes the role of an external judge that completes the exchange in case of disagreement. While in the past there have been several proposals for building fair exchange protocols over cryptocurrencies, our solution has two distinctive features that makes it particular attractive when users deal with large commodities. These advantages are: (1) minimizing the cost for running the smart contract on the blockchain, and (2) avoiding expensive cryptographic tools such as zero-knowledge proofs. In addition to our new protocols, we provide formal security definitions for smart contract based fair exchange, and prove security of our construction. Finally, we illustrate several applications of our basic protocol and evaluate practicality of our approach via a prototype implementation for fairly selling large files over the cryptocurrency Ethereum.
Stefan Dziembowski, Sebastian Faust, Kristina Hostáková
One of the fundamental challenges that hinder further adaption of decentralized cryptocurrencies is scalability. Because current cryptocurrencies require that all transactions are processed and stored on a distributed ledger -- the so-called blockchain -- transaction throughput is inherently limited. An important proposal to significantly improve scalability are off-chain protocols, where the massive amount of transactions is executed without requiring the costly interaction with the blockchain. Examples of off-chain protocols include payment channels and networks, which are currently deployed by popular cryptocurrencies such as Bitcoin and Ethereum. A further extension of payment networks envisioned for cryptocurrencies are so-called state channel networks. In contrast to payment networks that only support off-chain payments between users, state channel networks allow execution of arbitrary complex smart contracts. The main contribution of this work is to give the first full specification for general state channel networks. Moreover, we provide formal security definitions and prove the security of our construction against powerful adversaries. An additional benefit of our construction is the use of channel virtualization, which further reduces latency and costs in complex channel networks.
Nur Sakinah Burhanuddin, Fadhlan Hafizhelmi Kamaru Zaman, Ahmad Ihsan Mohd Yassin, Nooritawati Md Tahir
Two of the most familiar method of voting is through voting polls and online voting. The main problem with conventional method is the insecurity of the votes to be untemper. Another problem of voting methods is the existence of fraud in voting system. This paper is to propose a method in overcoming these flaws and problems by using the Blockchain technology. Blockchain technology is a secured database and has very high security. The technical concept of the Blockchain technology has many advantages and benefits that could be applied to many technical sectors and have the possibility in changing the world. The concept for this project is to develop a cryptocurrency implementation in the voting system. From there, the transaction votes are kept in the blockchain could be illustrated by examining the block hashes. The outcome of the project shows a transaction of coins from one voter’s wallet into two candidates’ wallet. The transactions were approved through a process of mining and the transactions of coins were a success. The data of the transactions were kept in the blockchain where unique blockhash, which acted as the block’s fingerprint were generated. From there, the integrity of the blockchain technology is illustrated.
It’s has been years and we still have a lot of downtimes in the major online platforms we use. When we go deep down and understand the problem, it’s all because of SPOF i. e. Single point of failure (which is a part of a system that, if it fails, it will stop the entire system from working). By this there is a possibility of downtime or hack or tampering of data or loss of data. Bitcoin is the first application of blockchain, then a lot of communities like Ethereum , etc. have been developing dApp protocols and frameworks to build applications in blockchain. Also a world renowned framework called Hyperledger Project is also in development made by an open source community consisting of people from large organisations. Early days and also now we have been using a technology called Torrent which is also decentralized. And now the question why to use decentralized systems in regards of issues with the largest social media company the problem was with the data that it had stored. Imagine a network that gives you the full control and privacy of data you share, send and get. Also not having a single second of service unavailability. The main aim of the project is to build a database system to achieve the goal of decentralized internet.
Oct 1, 2018·2018 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation (SmartWorld/SCALCOM/UIC/ATC/CBDCom/IOP/SCI)
The widespread adoption of fax machines in the 1980s revolutionised everyday communications. It was quickly adopted as the standard form of communication across the globe. Since then, the internet has replaced fax as a truly global form of instant communication. However, the fax machine still reigns as the primary form of communication in a number of industries, healthcare being one of them. This paper presents a system that uses a blockchain and an off-chain centralised data storage to give patients and medical professionals instant access to their medical records from anywhere. By assigning each medical record a pseudo anonymous identifier, a second layer "blockchain" for each user can be created allowing for the rapid collection and querying of data. The off-chain pseudo anonymous data storage allows for the data to remain unencrypted enabling the rapid generation of anonymous medical datasets which can be used for machine learning and data mining on the data, potentially bringing many benefits to the healthcare industry.
Asraful Alam, Sara Mahmoudi Rashid, Md. Abdus Salam, Ariful Islam
This paper proposed an Electric voting (E-voting) model that ensures security, privacy and transparency. Our approach uses blockchain method, a distributed ledger technology where data are shared and distributed into a network. Blockchain system offers transparency, decentralization, irreversibility and reduces the involvement of intermediaries which is crucial for an election process. An optimized algorithm is proposed for blockchain based e-voting system. An internet of things (IOT) based system is designed to exchange data from e-voting devices to the nodes. Moreover, we proposed several possible techniques and improvements for voting scenarios.
The Estonian electronic voting system which is a leading electronic voting system still suffers from universal verifiability issues and may need improvement of its availability. To solve the problems, in this paper we propose a blockchain-based electronic voting system. A blockchain is a distributed database, where the complete data is shared among all participants in the network. A blockchain system by its nature has several advantages that suit an electronic voting system. Its distributed architecture provides high availability to the system because it does not rely on a centralized server. As all participants have complete data, the protocol allows them to verify each block that is appended to the chain. We try to combine the double envelope encryption technique and blockchain technology for our proposed electronic voting system.
Dharmendra Kumar, D. V. Chandini, B. Dinesh Reddy, Debnath Bhattacharyya · 5 authors
The Secure Electronic Voting System using Blockchain Technology is ensured to make the current voting process to take place in an honest, accurate and highly secure way. This system stores the details of the voters and votes in two separate blockchains, which provides transparency into election results by allowing voters to independently audit the ballot box while protecting each voter's right to privacy. All the details of the voters get stored into one Blockchain, and this guarantees greater security by providing a PIN confirmed before the vote is taken into consideration. By casting votes as transactions, we can create another blockchain which keeps track of the tallies of the votes. This way, everyone can count the votes themselves, they can verify that no votes were changed or removed, and no illegitimate votes were added and as a result, is made public everyone can agree upon the final count. This system is only taking the current process of voting in an election and bringing that process entirely online, in an attempt to make it highly secure and also more accessible by allowing the voter to vote at his/her location and also reducing the effort put by staff members.
Open access
2 source records
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Abstract Providing reliable and surreptitious communications is difficult in the presence of adaptive and resourceful state level censors. In this paper we introduce Tithonus, a framework that builds on the Bitcoin blockchain and network to provide censorship-resistant communication mechanisms. In contrast to previous approaches, we do not rely solely on the slow and expensive blockchain consensus mechanism but instead fully exploit Bitcoin’s peer-to-peer gossip protocol. We develop adaptive, fast and cost effective data communication solutions that camouflage client requests into inconspicuous Bitcoin transactions. We propose solutions to securely request and transfer content, with unobservability and censorship resistance, and free, pay-per-access and subscription based payment options. When compared to state-of-the-art Bitcoin writing solutions, Tithonus reduces the cost of transferring data to censored clients by 2 orders of magnitude and increases the goodput by 3 to 5 orders of magnitude. We show that Tithonus client initiated transactions are hard to detect, while server initiated transactions cannot be censored without creating split world problems to the Bit-coin blockchain.
In general, a botnet is a collection of compromised internet computers, controlled by attackers for malicious purposes. To increase attacks' success chance and resilience against defence mechanisms, modern botnets have often a decentralized P2P structure. Here, IoT devices are playing a critical role, becoming one of the major tools for malicious parties to perform attacks. Notable examples are DDoS attacks on Krebs on Security and DYN, which have been performed by IoT devices part of botnets. We take a first step towards detecting P2P botnets in IoT, by proposing AutoBotCatcher, whose design is driven by the consideration that bots of the same botnet frequently communicate with each other and form communities. As such, the purpose of AutoBotCatcher is to dynamically analyze communities of IoT devices, formed according to their network traffic flows, to detect botnets. AutoBotCatcher exploits a permissioned Byzantine Fault Tolerant (BFT) blockchain, as a state transition machine that allows collaboration of a set of pre-identified parties without trust, in order to perform collaborative and dynamic botnet detection by collecting and auditing IoT devices' network traffic flows as blockchain transactions. In this paper, we focus on the design of the AutoBotCatcher by first defining the blockchain structure underlying AutoBotCatcher, then discussing its components.
U ovom završnom radu obrađen je pojam hardvera za rudarenje kriptovaluta. Nakon uvoda u prvom poglavlju opisana je prva kriptovaluta "Bitcoin". U drugom poglavlju objašnjen je protokol "Blockchain" na koji Bitcoin funkcionira. U trećem poglavlju opisane su transakcije, te posao rudara u bitcoin mreži. U četvrtom poglavlju je opisana povijest hardvera, te detaljan opis hardvera ovisno o generaciji. U zadnjem poglavlju je opisan suvremeni hardver te najbolje rješenje za Bitcoin i Ethereum, drugu najvrjedniju kriptovalutu.
Mustafa Al-Bassam, Alberto Sonnino, Vitalik Buterin
Light clients, also known as Simple Payment Verification (SPV) clients, are nodes which only download a small portion of the data in a blockchain, and use indirect means to verify that a given chain is valid. Typically, instead of validating block data, they assume that the chain favoured by the blockchain's consensus algorithm only contains valid blocks, and that the majority of block producers are honest. By allowing such clients to receive fraud proofs generated by fully validating nodes that show that a block violates the protocol rules, and combining this with probabilistic sampling techniques to verify that all of the data in a block actually is available to be downloaded, we can eliminate the honest-majority assumption, and instead make much weaker assumptions about a minimum number of honest nodes that rebroadcast data. Fraud and data availability proofs are key to enabling on-chain scaling of blockchains (e.g. via sharding or bigger blocks) while maintaining a strong assurance that on-chain data is available and valid. We present, implement, and evaluate a novel fraud and data availability proof system.
Mustafa Al-Bassam, Alberto Sonnino, Vitalik Buterin
Light clients, also known as Simple Payment Verification (SPV) clients, are\nnodes which only download a small portion of the data in a blockchain, and use\nindirect means to verify that a given chain is valid. Typically, instead of\nvalidating block data, they assume that the chain favoured by the blockchain's\nconsensus algorithm only contains valid blocks, and that the majority of block\nproducers are honest. By allowing such clients to receive fraud proofs\ngenerated by fully validating nodes that show that a block violates the\nprotocol rules, and combining this with probabilistic sampling techniques to\nverify that all of the data in a block actually is available to be downloaded,\nwe can eliminate the honest-majority assumption, and instead make much weaker\nassumptions about a minimum number of honest nodes that rebroadcast data. Fraud\nand data availability proofs are key to enabling on-chain scaling of\nblockchains (e.g. via sharding or bigger blocks) while maintaining a strong\nassurance that on-chain data is available and valid. We present, implement, and\nevaluate a novel fraud and data availability proof system.\n
Sep 22, 2018·2018 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation
Bitcoin, as a decentralized digital currency, has caused extensive research interest. There are many studies based on related protocols on Bitcoin, Bitcoin-based voting protocols also received attention in related literature. In this paper, we propose a Bitcoin-based decentralized privacy-preserving voting mechanism. It is assumed that there are n voters and m candidates. The candidate who obtains t ballots can get x Bitcoins from each voter, namely nx Bitcoins in total. We use a shuffling mechanism to protect voter's voting privacy, at the same time, decentralized threshold signatures were used to guarantee security and assign voting rights. The protocol can achieve correctness, decentralization and privacy-preservings. By contrast with other schemes, our protocol has a smaller number of transactions and can achieve a more functional voting method.
Purpose Nowadays, to operate securely and legally and to achieve business objectives, secure valuable assets and support uninterrupted business processes, all organizations need to match a lot of internal and external compliance regulations such as laws, standards, guidelines, policies, specifications and procedures. An integrated system able to manage information security (IS) for their intranets in the new cyberspace while processing tremendous amounts of IS-related data coming in various formats is required as never before. These data, after being collected and analyzed, should be evaluated in real-time from an IS incident viewpoint, to identify an incident’s source, consider its type, weigh its consequences, visualize its vector, associate all target systems, prioritize countermeasures and offer mitigation solutions with weighted impact relevance. Different security information and event management (SIEM) systems cope with this routine and usually complicated work by rapid detection of IS incidents and further appropriate response. Modern challenges dictate the need to build these systems using advanced technologies such as the blockchain (BC) technologies (BCTs). The purpose of this study is to design a new BC-based SIEM 3.0 system and propose a methodology for its evaluation. Design/methodology/approach Modern challenges dictate the need to build these systems using advanced technologies such as the BC technologies. Many internet resources argue that the BCT suits the intrusion detection objectives very well, but they do not mention how to implement it. Findings After a brief analysis of the BC concept and the evolution of SIEM systems, this paper presents the main ideas on designing the next-generation BC-based SIEM 3.0 systems, for the first time in open access publications, including a convolution method for solving the scalability issue for ever-growing BC size. This new approach makes it possible not to simply modify SIEM systems in an evolutionary manner, but to bring their next generation to a qualitatively new and higher level of IS event management in the future. Research limitations/implications The most important area of the future work is to bring this proposed system to life. The implementation, deployment and testing onto a real-world network would also allow people to see its viability or show that a more sophisticated model should be worked out. After developing the design basics, we are ready to determine the directions of the most promising studies. What are the main criteria and principles, according to which the organization will select events from PEL for creating one BC block? What is the optimal number of nodes in the organization’s BC, depending on its network assets, services provided and the number of events that occur in its network? How to build and host the SIEM 3.0 BC infrastructure? How to arrange streaming analytics of block’s content containing events taking place in the network? How to design the BC middleware as software that enables staff to interact with BC blocks to provide services like IS events correlation? How to visualize the results obtained to find insights and patterns in historical BC data for better IS management? How to predict the emergence of IS events in the future? This list of questions can be continued indefinitely for a full-fledged design of SIEM 3.0. Practical implications This paper shows the full applicability of the BC concept to the creation of the next-generation SIEM 3.0 systems that are designed to detect IS incidents in a modern, fully interconnected organization’s network environment. The authors’ attempt to begin with a detailed description of the basics for a BC-based SIEM 3.0 system design is presented, as well as the evaluation methodology for the resulting product. Originality/value The authors believe that their new revolutionary approach makes it possible not to simply modify SIEM systems in an evolutionary manner, but to bring their next generation to a qualitatively new and higher level of IS event management in the future. They hope that this paper will evoke a lively response in this segment of the security controls market from both theorists and direct developers of living systems that will implement the above approach.
Bitcoin is a cryptocurrency and a financial transaction network implemented using blockchain technology. Users in the Bitcoin network use pseudonymous Bitcoin addresses and conduct transactions with others without revealing their real identities. In order to further enhance their privacy and convenience, users often use a large number of different addresses. In this paper, we analyze different patterns of transactions occurring in the Bitcoin network in order to cluster addresses that share the same ownership. In order to evaluate the proposed clustering approach, Bitcoin addresses belonging to known entities are tagged and these are used in conjunction with the Gini impurity index to test the accuracy of the recovered identity-based clusters. The results show that our heuristic was able to detect relationships between Bitcoin addresses that were missed by the existing heuristics.
Without the design for inherent security, the Border Gateway Protocol (BGP) is vulnerable to prefix/subprefix hijacks and other attacks. Though many BGP security approaches have been proposed to prevent or detect such attacks, the unsatisfactory cost-effectiveness frustrates their deployment. In fact, the currently deployed BGP security infrastructure leaves the chance for potential centralized authority misconfiguration and abuse. It actually becomes the critical yield point that demands the logging and auditing of misbehaviors and attacks in BGP security deployments. We propose a blockchain-based Internet number resource authority and trustworthy management solution, named BGPcoin, to facilitate the transparency of BGP security. BGPcoin provides a reliable origin advertisement source for origin authentication by dispensing resource allocations and revocations compliantly against IP prefix hijacking. We perform and audit resource assignments on the tamper-resistant Ethereum blockchain by means of a set of smart contracts, which also interact as one to provide the trustworthy origin route examination for BGP. Compared with RPKI, BGPcoin yields significant benefits in securing origin advertisement and building a dependable infrastructure for the object repository. We demonstrate it through an Ethereum prototype implementation, and we deploy it and do experiment on a locally-simulated network and an official Ethereum test network respectively. The extensive experiment and evaluation demonstrate the incentives to deploy BGPcoin, and the enhanced security provided by BGPcoin is technically and economically feasible.
Building a secure electronic voting system is a difficult task. The US Pentagon dropped their proposed online voting system which would have given overseas military personnel the opportunity to vote in the elections in 2005, citing the inability to ensure the legitimacy of votes as the reason. There is however a new cry in the wild to deploy a voting blockchain. The blockchain serves as a public ledger of transactions which cannot be reversed. The all-important consensus of transaction (i.e. legitimate votes) is achieved through 'miners' agreeing to validate new records being added. Whenever a new insertion is to be made e.g. votes, then a new transaction record is created by a voter adding details of their cast vote to the blockchain. Should it be deemed a valid transaction then the new vote is added to the end of the blockchain and remains there forever. What is neat about this solution is the fact that no centralized authority is needed to approve the votes but rather a majority consensus. Here everyone agrees on the final tally as they can count the votes themselves & because of the blockchain audit trail, anyone can verify that no votes were tampered with and no illegitimate votes were inserted. This paper discusses the application of blockchain to voting.
Current electronic voting protocol require a centralized system to control the whole procedure from ballot inputs to result outputs and election monitoring. Meanwhile, blockchain technology provide a decentralized system which open across the whole network of untrusted participants. Applying blockchain technology into electronic voting protocol through a proper architecture can instil characteristic such as data confidentiality, data integrity and data authenticity. In this paper, we going to discuss a proposed method on how to leverage the advantages from blockchain into electronic voting protocol. This blockchain-based electronic voting protocol promise to provide a secure electronic election process given the proposed system works. We implement a protocol using blockchain to turn election protocol into an automated control system without relying any single point of entity. Lastly, we discuss the characteristics of our proposed blockchain-based electronic voting protocol in this paper. However, there are also emerging challenges and limitations awaiting to overcome. This paper gives a comprehensive overview of our proposed protocol.
Open access
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Permissionless blockchains reach decentralized consensus without requiring pre-established identities or trusted third parties, thus enabling applications such as cryptocurrencies and smart contracts. Consensus is agreed on data that is generated by the application and transmitted by the system's (peer-to-peer) network layer. While many attacks on the network layer were discussed so far, there is no systematic approach that brings together known attacks, the requirements, and the design space of the network layer. In this paper, we survey attacks on the network layer of permissionless blockchains, and derive five requirements: 1) performance; 2) low cost of participation; 3) anonymity; 4) DoS resistance; and 5) topology hiding. Furthermore, we survey the design space of the network layer and qualitatively show the effect of each design decisions on the fulfillment of the requirements. Finally, we pick two aspects of the design space, in-band peer discovery and relay delay, and demonstrate possible directions of future research by quantitatively analyzing and optimizing simplified scenarios. We show that while most design decisions imply certain tradeoffs, there is a lack of models that analyze and formalize these tradeoffs. Such models could aid the design of the network layer of permissionless blockchains. One reason for the lack of models is the deliberately limited observability of deployed blockchains. We emphasize that simulation based approaches cope with these limitations and are suited for the analysis of the network layer of permissionless blockchains.
Authentication is the issue most talked about nowadays. Comparing with Blockchain we want to research the justification for the blockchain technology to be used in enterprise log analysis and the appearance of blockchain technology to develop and make remarkable change in enterprise log analysis.
George-Andrei Dima, Andrei-Gabriel Jitariu, Claudio Pisa, Giuseppe Bianchi
The media has brought to the attention of the general public the issue of subjects claiming titles (e.g. academic degrees) which they have not achieved. Verifying these identity claims can be a cumbersome task. In this paper we show how identity claims can be supported through a permissioned blockchain. Although our approach can be applied to multiple contexts, we focus on the scenario where educational institutions provide graduation titles to subjects. The subjects can then demonstrate the possession of the given titles through transactions in the blockchain. We validate the feasibility of our approach through an implementation, named Scholarium, based on MultiChain, and provide a security analysis of the proposed system.
With the development of Internet-of-Things (IoT) technology, the notion of smart city concept comes to reality. Smart city covers a broad range of scenarios for citizens in their everyday life, such as smart home, smart traffic and smart healthcare. However, considering the IoT technology itself still under security threats, smart city security and resilience is a critical factor for truly embracing the smart age of everyday life. Current technology has a difficult time providing security in smart city architectures because of its decentralized and distributed nature. As a recently new technology, Blockchain uses a decentralized and distributed security approach to adding security to a decentralized and distributed IoT system. This paper presents a blockchain based solution to provide security and resilience in smart cities and analyze potential security concerns in the integration of blockchain technology into smart city infrastructure. Each of the concerns are discussed in detail.
In this paper, we explore the attack surfaces in open source permissioned blockchain project Hyperledger Fabric that can be exploited and compromised through cryptographic tactics. Attacks such as insider threats, DNS attacks, private key attacks, and certificate authority (CA) attacks are proposed and discussed. Points in transaction flow where the proposed attacks are threats to the permissioned blockchain are specified and analyzed. Key management systems are discussed, and a deep analysis of Hierarchical Deterministic wallets is conducted. The Membership Service Provider (MSP) proves to be a centralizing aspect of an otherwise decentralized system and proves to be a weakness of the permissioned blockchain network.