Network storage services have benefited countless users worldwide due to the notable features of convenience, economy and high availability. Since a single service provider is not always reliable enough, more complex multi-cloud storage systems are developed for mitigating the data corruption risk. While a data auditing scheme is still needed in multi-cloud storage to help users confirm the integrity of their outsourced data. Unfortunately, most of the corresponding schemes rely on trusted institutions such as the centralized third-party auditor (TPA) and the cloud service organizer, and it is difficult to identify malicious service providers after service disputes. Therefore, we present a blockchain-based multi-cloud storage data auditing scheme to protect data integrity and accurately arbitrate service disputes. We not only introduce the blockchain to record the interactions among users, service providers, and organizers in data auditing process as evidence, but also employ the smart contract to detect service dispute, so as to enforce the untrusted organizer to honestly identify malicious service providers. We also use the blockchain network and homomorphic verifiable tags to achieve the low-cost batch verification without TPA. Theoretical analyses and experiments reveal that the scheme is effective in multi-cloud environments and the cost is acceptable.
Data credibility plays a key role in facilitating evidence-based decision making in organizations and governments (e.g., policy making). One of the key data sources is the Internet of Things (IoT) devices and systems, say within a fog environment. However, the increasing complexity and interconnectivity of such IoT and fog environments can result in security vulnerabilities (e.g., due to implementation errors or flaws in the underpinning devices or systems), which can be exploited to compromise the credibility of the data. Therefore, in this article, we propose a secure Blockchain-based scheme to guarantee the credibility of nodes and data and ensure data transmission security in the fog environment. We then demonstrate the feasibility of the proposed scheme using experiments.
Nowadays, large amount of data is stored on the cloud which is required to be protected from the unauthorized users. To maintain the privacy and security of data various algorithms are used. The objective of every system is to achieve confidentiality, integrity, availability (CIA). However, the existing centralized cloud storage lacks to provide these CIA properties. So, to enhance the security of data and storing techniques, decentralized cloud storage is used along with blockchain technology. It effectively helps to protect data from tampering or deleting a part of data. The data stored in blockchain is linked to each other by a chain of blocks. Each block has its hash value, which is stored in next block. Thus it reduces the chances of data altering. For this purpose, SHA-512 Hashing algorithm is used. Hashing algorithm is used in many aspects, where the security of data is required such as message digest, password verification, digital certificates and in blockchain. By the combination of these methods and algorithms, data becomes more secure and reliable. However, with the help of various algorithms, the security of the data can be enhanced. Also, Advance Encryption Standard (AES) is used to encrypt and decrypt the data due to the significant features of this algorithm.
With the rapid growth in the sector of information technology and easy access to cheap and advanced office instruments in the market, the faking of important documents has become a matter of concern nowadays. Therefore, the need for verification and authentication practices of various important documents in the form of banking documents, government documents, transaction documents, educational certificates etc is also increasing. However, various challenging and tedious processes have made document verification very complex and time-consuming which motivated us to conduct this research. In this paper, we present a decentralized web application for digital document verification using Ethereum blockchain-based technology in P2P cloud storage to enhance the verification process by making it more open, transparent, and auditable. The proposed model includes several methods such as public/private key cryptography, online storage security, digital signatures, hash, peer-to-peer networks and proof of work which has made the verification of any uploaded documents for any organization or authority faster and convenient with just a click. Furthermore, respective hash values are also assigned to each individual document. Our proposed model successfully meets up all the criteria for a digital document verification system by alleviating the gaps and difficulties in the traditional methods in document verification.
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Advanced Steganography and Watermarking Techniques
Abstract The sharing of electronic health records (EHR) has shown significant advantages in the accurate diagnosis of patients and the development of medical institutions. However, due to the privacy and sensitivity of medical data, it is easy to cause security issues such as difficulty in data sharing among different medical institutions and easy leakage of data privacy. Because the blockchain has the characteristics of non-tampering, anonymity, and decentralization. We propose a blockchain-based searchable proxy re-encryption scheme for EHR security storage and sharing. First, we use blockchain and cloud server to store encrypted EHR together to prevent EHR from being tampered with and leaked. Secondly, we use a certificateless encryption and proxy re-encryption based on identity and type scheme as a data sharing protocol. Meanwhile, searchable encryption technology is used to generate a keyword index. Moreover, the proxy node is selected by the delegated proof-of-stake (DPOS) consensus algorithm, which ensures the privacy, immutability and security. It realizes the safe access of third-party data users to medical health data. Finally, security analysis and evaluation show that our scheme can resist identity disguise and replay attacks. In addition, it has stronger security and higher efficiency.
Traditional healthcare systems store and process personal healthcare record (PHR) in the centralized client-server architecture. PHR stored in a healthcare institution remain in depository which is not easily shared with other institutions due to technical and infrastructure related restrictions. In such a way, if a patient has to visit distinct institutions/hospitals or physicians, there is no effective and privacy-preserving data sharing mechanism. Furthermore, even if patients' privacy is protected by Health Insurance Portability and Accountability Act (HIPAA), it is still doubtful owing to the lack of the consideration of if the patient is directly involved. With the recent bloom of interest around blockchain, a technology with well-defined decentralized framework, privacy-preserving in healthcare information system (HIS) should be revisited to examine the new possibility. Actually, in the literature, the blockchain-based researches about the privacy and security in healthcare are prevalent in decentralized platform. However, they have drawn attention on the personal healthcare record management rather than focus on how to distribute the encryption/decryption key used to guarantee the confidentiality of PHR. Blockchain provides a shared, immutable and transparent history of all the transactions to build systems with trusty and decentralized environment. This provides an opportunity to develop a secure and trusty PHR data management system by blockchain technology. This paper presents the solution aiming at the patient's control by holding the knowledge of the encryption/decryption key which can be deduced from the previous transaction in blockchains. In such a way, a patient can control the personal healthcare record by controlling key usage.
The increasing complexity of modern hardware and software platform along with the imperative assurance on stability deems runtime verification of task fulfillment necessary in distributed systems. Distributing the burden of a central verification monitor to individual devices could improve the efficiency. Our previous work shows the possibility of achieving decentralized runtime verification by incorporating some mechanisms of the blockchain technology for locating the accountability when error occurs. However, traditional blockchain technology disallows branching and hence does not support verification of tasks which involves multiway dependencies. In this paper, we introduce a novel approach of smart marker that can be included in a blockchain to enable multiway branching and merging in order to verify the fulfillment of tasks that involve one-to-many and many-to-one dependencies. The design of smart marker satisfies three requirements of recognizability, compatibility, and authenticability. We implement a prototype of the smart marker scheme and analyze its performance.
Sara Ghaemi, Sara Rouhani, Rafael Belchior, Rui Santos Cruz · 6 authors
The maturing of blockchain technology leads to heterogeneity, where multiple solutions specialize in a particular use case. While the development of different blockchain networks shows great potential for blockchains, the isolated networks have led to data and asset silos, limiting the applications of this technology. Blockchain interoperability solutions are essential to enable distributed ledgers to reach their full potential. Such solutions allow blockchains to support asset and data transfer, resulting in the development of innovative applications. This paper proposes a novel blockchain interoperability solution for permissioned blockchains based on the publish/subscribe architecture. We implemented a prototype of this platform to show the feasibility of our design. We evaluate our solution by implementing examples of the different publisher and subscriber networks, such as Hyperledger Besu, which is an Ethereum client, and two different versions of Hyperledger Fabric. We present a performance analysis of the whole network that indicates its limits and bottlenecks. Finally, we discuss the extensibility and scalability of the platform in different scenarios. Our evaluation shows that our system can handle a throughput in the order of the hundreds of transactions per second.
Presented herein is a User-SpecificKey Scheme based on Elliptic Curve Cryptography that defeats man-inthe-middle attacks on cryptocurrency exchange accounts. In this scheme, a separate public and private key pair is assigned to every account and the public key is shifted either forward or backward on the elliptic curve by a difference of the account user’s password. When a user logs into his account, the server sends the shifted public key of his account. The user computes the actual public key of his account by reverse shifting the shifted public key exactly by a difference of his password. Alternatively, shifting can be applied to the user’s generator instead of the public key. Described in detail is as to how aman-in-the-middle attack takes place and how the proposed scheme defeats the attack. Provided detailed security analysis in both the cases of publickey shifting and generator shifting. Further, compared the effectiveness of another three authentication schemes in defending passwords against MITM attacks.
Nguyen B. Truong, Gyu Myoung Lee, Kai Sun, Florian Guitton · 5 authors
Blockchain technology has been envisaged to commence an era of decentralised applications and services (DApps) without the need for a trusted intermediary. Such DApps open a marketplace in which services are delivered to end-users by contributors which are then incentivised by cryptocurrencies in an automated, peer-to-peer, and trustless fashion. However, blockchain, consolidated by smart contracts, only ensures on-chain data security, autonomy and integrity of the business logic execution defined in smart contracts. It cannot guarantee the quality of service of DApps, which entirely depends on the services' performance. Thus, there is a critical need for a trust system to reduce the risk of dealing with fraudulent counterparts in a blockchain network. These reasons motivate us to develop a fully decentralised trust framework deployed on top of a blockchain platform, operating along with DApps in the marketplace to demoralise deceptive entities while encouraging trustworthy ones. The trust system works as an underlying decentralised service providing a feedback mechanism for end-users and maintaining trust relationships among them in the ecosystem accordingly. We believe this research fortifies the DApps ecosystem by introducing an universal trust middleware for DApps as well as shedding light on the implementation of a decentralised trust system.
The emergence of the cloud storage has brought great convenience to people’s life. Many individuals and enterprises have delivered a large amount of data to the third-party server for storage. Thus, the privacy protection of data retrieved by the user needs to be guaranteed. Searchable encryption technology for the cloud environment is adopted to ensure that the user information is secure with retrieving data. However, most schemes only support single-keyword search and do not support file updates, which limit the flexibility of the scheme. To eliminate these problems, we propose a blockchain-enabled public key encryption scheme with multi-keyword search (BPKEMS), and our scheme supports file updates. In addition, smart contract is used to ensure the fairness of transactions between data owner and user without introducing a third party. At the data storage stage, our scheme realizes the verifiability by numbering the files, which ensures that the ciphertext received by the user is complete. In terms of security and performance, our scheme is secure against inside keyword guessing attacks (KGAs) and has better computation overhead than other related schemes.
In the area of cloud computing, data deduplication enables the cloud server to store a single copy of data by eliminating redundant files to improve storage and network efficiency. Proof-of-ownership (PoW) is a cryptographic function that verifies the user who really owns the data. Most of the existing schemes have tried to solve the deduplication problem by providing the same encryption key for identical data. However, these schemes suffer from dynamic changes in ownership management. In this paper, we propose an in-line block matching (IBM) protocol based on zero-knowledge proof for deduplication with dynamic ownership management, which eliminates the unauthorized access of sensitive data. In this proposed work, for a new file, the uploader randomly chooses a file encryption key and encrypts the file. The user also computes a unique proof for the uploaded file by dividing the file into number of blocks and stores this proof to the cloud server. The cloud server computes the group key for the ciphertext and re-encrypts it using this group key. The cloud server also does the proof verification against the subsequent uploader for an existing file. The cloud server is honest-but-curious, so the proposed scheme confirms that the cloud server does not know any information about file encryption key even though it plays a proxy role. The result shows that our proposed scheme protects the data from both cloud server and adversaries. Also, the computational cost is comparatively less than other existing schemes.
Rongjian Lan, Ganesha Upadhyaya, Stephen Tse, Mahdi Zamani
With the rise of digital currency systems that rely on blockchain to ensure ledger security, the ability to perform cross-chain transactions is becoming a crucial interoperability requirement. Such transactions allow not only funds to be transferred from one blockchain to another (as done in atomic swaps), but also a blockchain to verify the inclusion of any event on another blockchain. Cross-chain bridges are protocols that allow on-chain exchange of cryptocurrencies, on-chain transfer of assets to sidechains, and cross-shard verification of events in sharded blockchains, many of which rely on Byzantine fault tolerance (BFT) for scalability. Unfortunately, existing bridge protocols that can transfer funds from a BFT blockchain incur significant computation overhead on the destination blockchain, resulting in a high gas cost for smart contract verification of events. In this paper, we propose Horizon, a gas-efficient, cross-chain bridge protocol to transfer assets from a BFT blockchain to another blockchain (e.g., Ethereum) that supports basic smart contract execution.
Boris Düdder, Vladislav V. Fomin, Tan Gürpinar, Michael Henke · 9 authors
The early development of blockchain technology (BCT) has already demonstrated the technology's potential to serve the needs of different industries. BCT has also become established as a popular research topic in different scientific disciplines. This paper aims at introducing how several relevant scientific disciplines—supply chain management; management, economics and finance; computer science; security engineering—see the research and education perspectives for BCT. A field review is conducted to present challenges and opportunities of BCT, as well as suggestions for future research and education on the topic as seen from the selected different perspectives. The paper also presents methods for combining relevant disciplines in a modular online course to address the stated challenges and promote interdisciplinary blockchain education.
Open access
Blockchain Technology Applications and Security
Innovative Microfluidic and Catalytic Techniques Innovation
Public auditing schemes for cloud storage systems have been extensively explored with the increasing importance of data integrity. A third-party auditor (TPA) is introduced in public auditing schemes to verify the integrity of outsourced data on behalf of users. To resist malicious TPAs, many blockchain-based public verification schemes have been proposed. However, existing auditing schemes rely on a centralized TPA, and they are vulnerable to tempting auditors who may collude with malicious blockchain miners to produce biased auditing results. In this article, we propose a blockchain-based decentralized public auditing (BDPA) scheme by utilizing a decentralized blockchain network to undertake the responsibility of a centralized TPA, and also mitigate the influence of tempting auditors and malicious blockchain miners by taking the concept of decentralized autonomous organization (DAO). A detailed security analysis shows that BDPA can preserve data integrity against tempting auditors and malicious blockchain miners. A comprehensive performance evaluation demonstrates that BDPA is feasible and scalable.