Vladimir Kukharenko, Kirill Ziborov, Rafael Faritovich Sadykov, Alexandr Naumchev · 6 authors
The extent of formal verification methods applied to industrial projects has always been limited. The proliferation of distributed ledger systems (DLS), also known as blockchain, is rapidly changing the situation. Since the main area of DLSs' application is the automation of financial transactions, the properties of predictability and reliability are critical for implementing such systems. The actual behavior of the DLS is determined by the chosen consensus protocol, which properties require strict specification and formal verification. Formal specification and verification of the consensus protocol is necessary but not sufficient. It is required to ensure that the software implementation of the DLS nodes complies with this protocol. The verified software implementation of the protocol must run on a fairly reliable operating system. The so-called “smart contracts”, which are an important part of the applied implementations of specific business processes based on DLSs, must be verifiable as well. In this paper, we describe an ongoing industrial project that will result in a DLS verified at least at the four technological levels described above. We then share our experience with the formal specification and verification of HotStuff, a leader-based fault-tolerant protocol that ensures reaching distributed consensus in the presence of Byzantine processes.
The development of Internet of Things (IoT) and Mobile Edge Computing (MEC) has led to close cooperation between electronic devices. It requires strong reliability and trustworthiness of the devices involved in the communication. However, current trust mechanisms have the following issues: (1) heavily relying on a trusted third party, which may incur severe security issues if it is corrupted, and (2) malicious evaluations on the involved devices which may bias the trustrank of the devices. By introducing the concepts of risk management and blockchain into the trust mechanism, we here propose a blockchain-based trust mechanism for distributed IoT devices in this paper. In the proposed trust mechanism, trustrank is quantified by normative trust and risk measures, and a new storage structure is designed for the domain administration manager to identify and delete the malicious evaluations of the devices. Evidence shows that the proposed trust mechanism can ensure data sharing and integrity, in addition to its resistance against malicious attacks to the IoT devices.
Facebook will soon launch the world's first digital payment currency: Libra. Libra's mission is to foster the development of a simple global currency and financial infrastructure that serves billions of people. This document presents the project, based on a new decentralized blockchain, a cryptomonnaie low volatility and a smart contract platform. The combination of these elements aims to create a new opportunity for innovative and responsible financial services. Libra will be sustained through a small charge per transaction on the blockchain. Many of these charges will be transferred to vendors who can then absorb the costs themselves or relay them to users. Collaboration and innovation with the financial sector (especially with of regulators and experts from various sectors) is the only way to ensure that this new system is based on a durable, secure and reliable framework. This can also lead to a real step towards a low-cost, more accessible and more connected global financial system. Washington and Brussels are calling for far-reaching regulation of Facebook. Responsible citizens have the courage to deal with the ideas of dissidents in social networks, and they have the ability to do so rationally and critically.
Blockchain systems store transaction data in the form of a distributed ledger where each node stores a copy of all data, which gives rise to storage issues. It is well-known that the tremendous storage and distribution of the block data are common problems in blockchain systems. In the literature, some types of secret sharing schemes are employed to overcome these problems. The secret sharing method is one of the most significant cryptographic protocols used to ensure the privacy of the data. The main purpose of this paper is to improve the recent distributed storage blockchain systems by proposing an alternative secret sharing method. We first propose a secure threshold verifiable multi-secret sharing scheme that has the verification and private communication steps based on post-quantum lattice-based hard problems. We then apply the proposed threshold scheme to the distributed storage blockchain (DSB) system to share transaction data at each block. In the proposed DSB system, we encrypt the data block with the AES-256 encryption algorithm before distributing it among nodes at each block, and both its secret key and the hash value of the block are privately shared among nodes simultaneously by the proposed scheme. Thereafter, in the DSB system, the encrypted data block is encoded by the Reed–Solomon code, and it is shared among nodes. We finally analyze the storage and recovery communication costs and the robustness of the proposed DSB system. We observe that our approach improves effectively the recovery communication cost and makes it more robust compared to the previous DSB systems. It also improves extremely the storage cost of the traditional blockchain systems. Furthermore, the proposed scheme brings to the DSB system the desirable properties such as verification process and secret communication without private channels in addition to the known properties of the schemes used in the previous DSB systems. As a result of the flexibility on the threshold parameter of the scheme, a diverse range of qualified subsets of nodes in the DSB system can privately recover the secret values.
Distributed file storage aims to support credible access to data on distributed nodes. There are some application scenarios, for example, data centers, peer-to-peer (P2P) storage systems, and storage in wireless networks. Nevertheless, among these applications, data blocks are inevitably replaced and inaccessible when there exists nodes failure. As a result, data integrity and credibility is absent. To overcome such a challenge, blockchain is explored to protect the distributed data. Through analysis and evaluation, we demonstrate that blockchain advocates data integrity and credibility for distributed file storage, as well as the application of blockchain technology for distributed file storage.
The existing cross-domain authentication mechanisms are established based on well-known Public Key Infrastructure (PKI) systems, where digital certificates issued by Certificate Authority(CA) serve to authenticate the identity of entities. The complex authentication path, accompanied by multiple signatures and verifications, causes low authentication efficiency. In addition, resulting from an “update gap” between Certificate Revocation List(CRL) and Online Certificate Status Protocol(OCSP) mechanism, the revoked certificates will be exposed to DDoS attacks. For addressing aforementioned two challenges, an efficient blockchain-based authentication and secure certificate revocation scheme is proposed. Based on the non-tamperability and traceability of the blockchain, the signature module of X.509 digital certificate is replaced by the certificate hash value which serves as the trust certificate between domains. Furthermore, a consensus algorithm is adopted for random number hash broadcasting to improve efficiency. Theoretical analysis shows the proposed scheme has the security characteristics of non-repudiation, anonymity and anti DDoS attack. The experimental results demonstrate the proposed scheme has the advantage over existing cross-domain authentication and certificate revocation scheme at communication and computing cost and security respectively.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The privacy of Electronic Health Records (EHRs) is facing a major hurdle with outsourcing private health data in the cloud as there exists danger of leaking health information to unauthorized parties. In fact, EHRs are stored on centralized databases that increases the security risk footprint and requires trust in a single authority which cannot effectively protect data from internal attacks. This research focuses on ensuring the patient privacy and data security while sharing the sensitive data across same or different organisations as well as healthcare providers in a distributed environment. This research develops a privacy-preserving framework viz Healthchain based on Blockchain technology that maintains security, privacy, scalability and integrity of the e-health data. The Blockchain is built on Hyperledger fabric, a permissioned distributed ledger solutions by using Hyperledger composer and stores EHRs by utilizing InterPlanetary File System (IPFS) to build this healthchain framework. Moreover, the data stored in the IPFS is encrypted by using a unique cryptographic public key encryption algorithm to create a robust blockchain solution for electronic health data. The objective of the research is to provide a foundation for developing security solutions against cyber-attacks by exploiting the inherent features of the blockchain, and thus contribute to the robustness of healthcare information sharing environments. Through the results, the proposed model shows that the healthcare records are not traceable to unauthorized access as the model stores only the encrypted hash of the records that proves effectiveness in terms of data security, enhanced data privacy, improved data scalability, interoperability and data integrity while sharing and accessing medical records among stakeholders across the healthchain network.
Aman Luthra, James Cavanaugh, Hugo Renzzo Olcese, Rina M. Hirsch · 5 authors
Consider the problem of auditing an investment fund. This usually involves inspecting each transaction in its trading history, and accumulating its capital gains and losses, so that its net asset value can be computed precisely to avoid financial frauds. We present ZeroAUDIT, a confidential and privacy preserving auditing platform, which accomplishes this goal without having to know any of a transaction’s details. Sitting at the heart of the system is a zero knowledge proof protocol, in the discrete logarithm setting, which allows one to reason about the elements of a Merkle tree. Using it, we can prove that a trading transaction is occurring at a fair market price without disclosing which securities are being traded. We have implemented the system on the Hyperledger Fabric platform and we report the use of batch verification techniques in improving its efficiency.
A tecnologia de registro distribuído (DLT – Distributed Ledger Technology) pode ser muito útil para o tratamento de dados pessoais em conformidade com a Lei Geral de Proteção de Dados Pessoais (LGPD), devido a características como transparência e segurança. No entanto, outras características como a imutabilidade e o caráter distribuído podem dificultar essa tarefa. Assim, este trabalho analisa os desafios da conciliação entre DLT e o tratamento de dados em conformidade com a LGPD. Como objeto de análise, utilizou-se o projeto Datavalid do SERPRO - Serviço Federal de Processamento de Dados, contratado pela Uber, em um cenário hipotético em que o tratamento de dados foi realizado utilizando-se o Hyperledger Fabric.
Lukas König, Yuliia Korobeinikova, Simon Tjoa, Peter Kieseberg
Since the introduction of Bitcoin, the term “blockchain” has attracted many start-ups and companies over the years, especially in the financial sector. However, technology is evolving faster than standardization frameworks. This left the industry in the position of having to use this emerging technology, without being backed by any international standards organization regarding for neither the technology itself, nor for a blockchain specific information security framework. In times of the General Data Protection Regulation and growing international trade conflicts, protecting information is more relevant than ever. Standardization of blockchains is an appeal to raise the development of information technologies to the next level. Therefore, this paper shall provide an overview of standardization organization’s publications about blockchains/distributed ledger technologies, a set of comparison criteria for future work and a comparison of the existing standards work itself. With that information, aligning to existing standardization efforts becomes easier, and might even present the possibility to create frameworks where there are none at the moment.
Diego Fernandes Gonçalves Martins, Marco Aurélio Amaral Henriques
Este artigo apresenta o protocolo de consenso Probabilistic Proof-of-Stake (PPoS) e analisa o mesmo dos pontos de vista teórico e prático, focando na sua probabilidade de produzir forks. O texto primeiramente explica o funcionamento do algoritmo, onde é possível entender como um nó participa de um sorteio em rodadas a fim de ganhar o direito de criar um novo bloco para uma cadeia. Em seguida ele apresenta os critérios para aceitação e para confirmação de blocos, seguidos de uma análise da probabilidade de forks e do número esperado de rodadas entre dois blocos consecutivos. Uma blockchain baseada neste protocolo foi implementada e seus resultados práticos mostraram uma boa concordância com a análise teórica, validando a mesma.
Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Advanced Steganography and Watermarking Techniques
Blockchain is one of the emerging technologies with the potential to disrupt many application domains. Cloud is an on-demand service paradigm facilitating the availability of shared resources for data storage and computation. In recent years, the integration of blockchain and cloud has received significant attention for ensuring efficiency, transparency, security and even for offering better cloud services in the form of novel service models. In order to exploit the full potential of blockchain-cloud integration, it is essential to have a clear understanding on the existing works within this domain. To facilitate this, there have been several survey papers, however, none of them covers the aspect of blockchain-cloud integration from a service-oriented perspective. This paper aims to fulfil this gap by providing a service oriented review of blockchain-cloud integration. Indeed, in this survey, we explore different service models into which blockchain has been integrated. For each service model, we review the existing works and present a comparative analysis so as to offer a clear and concise view in each category.
As an emerging service architecture of multi-technology integration, blockchain draws the attention of public because of smart contracts which implement a secure and tamper-proof programming. However, due to the complexity of this architecture, there exists endless attacks against blockchain. Smart contracts as the application layer prototype of blockchain, face more severe security risks. This paper detailly lists the security events of smart contracts in recent years, summarizes several common attack modes, then introduces their principles and analyzes the commonness. Finally, an original version of the contract code audit tool based on matching rules is given. The tool can ensure that the contract has a complete audit process before deployment, so as to decrease the DApp vulnerability caused by poor programming. Moreover, the matching rule library supports customization, the tool can be updated timely to enhance its audit ability.
Digital signature is a major component of transactions on Blockchain platforms, especially in enterprise Blockchain platforms, where multiple signatures from a set of peers need to be produced to endorse a transaction. However, such process is often complex and time-consuming. Multi-signature, which can improve transaction efficiency by having a set of signers cooperate to produce a joint signature, has attracted extensive attentions. In this work, we propose two multi-signature schemes, GMS and AGMS, which are proved to be more secure and efficient than state-of-the-art multi-signature schemes. Besides, we implement the proposed schemes in a real Enterprise Blockchain platform, Fabric. Experiment results show that the proposed AGMS scheme helps achieve the goal of high transaction efficiency, low storage complexity, as well as high robustness against rogue-key attacks and $k$ -sum problem attacks.
The abuse of personal identity information is one of the most serious problems worldwide. Most social services or businesses use the identity authorization to confirm their validity and legality and the copies of users' identity certification are usually recorded by the service providers. It is easy to leak the users' identity information due to the untrustworthy service provider or single-point security failure, and various social problems are then caused. To deal with such problems, this paper proposes a Blockchain-based Identity Authorization mechanism (BIA). First, an Identity Authorization Module (IAM) is devised, which reads the identity certificate and transform the identity plaintext to ciphertext under the authorization by the user's identity certificate entity and password. IAM guarantees the security of identity information by keeping its plaintext offline. Second, a Business Contract Module (BCM) is designed, which provides a general smart contract framework for identity authorization that can be adopted by most of social services or businesses. Third, a double-chain blockchain infrastructure is developed, whereby the encrypted identity information and service smart contracts are respectively recorded in the tamper-resistant, non-repudiable, and publicly verifiable way. Finally, a prototype system has been developed to verify the security, feasibility and effectiveness of the proposed BIA.
The 6G network will provide integrated ubiquitous coverage of air, space, ground and sea, and support the full connection of a large number of heterogeneous terminals. This kind of open network and access brings great security risks to the communication network. Therefore, security issues have become an important factor in the widespread promotion of Internet of Things (IoT) applications. This paper proposes a secure endogenous wireless access network architecture based on blockchain, including communication plane and blockchain plane, the later plane includes blockchain networks and their applications. Based on this architecture, a unified identity authentication framework is proposed, which is based on blockchain technology to manage the identity certificates of entities in the network and supervise the authority. Based on this framework, a distributed identity authentication scheme, a service discovery and provision scheme in the IoT combined with smart contracts are given. Numerical simulation results demonstrate that the proposed schemes outperform existing algorithm in terms of communication overhead and time consumption.
Rongli Gai, Xiaoyan Du, Shuya Ma, Na Chen · 5 authors
Abstract Blockchain is an emerging distributed database technology. It has the characteristics of decentralization, non-tampering, traceability and final consistency. Blockchain can solve data management problems in untrusted environments. Based on the research and analysis of the blockchain system, this article expounds the application of the blockchain system in the distributed database environment. First, this article introduces the concept of the blockchain system and the classification of the blockchain system from multiple aspects. Then it introduces the data storage technology and data encryption technology adopted by the blockchain system in detail. Finally, the application prospects of the blockchain system in today’s society are introduced.
Vehicular crowdsourcing networks (VCNs) enable vehicles to provide or obtain traffic-related services in a costefficient and flexible manner. Therefore, it is crucial to provide trusted management in VCNs for high reliability towards both service producers and consumers. However, most recent VCN platforms rely on a third party to manage crowdsourcing services which might be not fully trusted by users. For the issue, this paper proposes a blockchain-based trust management scheme for VCNs to provide a decentralized and trusted service management. A comprehensive trust evaluation model (TEM) is designed to quantify the trust degree of each vehicular node, and a vehicle-trust blockchain framework called VTchain is proposed to preserve the trust values of nodes while guaranteeing transparency and trustworthiness. Particularly, we leverage a trusted execution environment (TEE) to provide secure trust evaluation to tackle possible untrusted road-side units. In addition, we introduce TEM-based Proof of Trust to support blockchain maintenance, which works together with an efficient consensus algorithm Zyzzyva for improved scalability. Finally, extensive experiments are conducted by developing a testbed deployed on cloud servers for measurements.
S Siva Rama Krishnan, M Manoj, Thippa Reddy Gadekallu, Neeraj Kumar · 8 authors
The use of electronic medical records (EMRs) has simplified the processing of patient data because the patient does not need to carry documents and can simply show an identity card to retrieve a complete medical record history. This digitization has revolutionized the medical sector, but two major challenges exist with online records: security and trust. Data stored on the Internet is not secure and requires an additional security framework to safeguard and maintain complete trust with the data. In this paper, a blockchain-based security framework is proposed to maintain the confidentiality of EMRs. This solution is also used to securely access the patient's records in any hospital-using the patient's public key as a universal identifier-and to obtain the medical record history of a patient much more quickly even during emergencies. The proposed framework also uses a credit score approach to monitor the credibility of the entities authorized to input data into the blockchain. In this study, the Etherium platform is used to simulate the blockchain, and the InterPlanetary File System (IPFS) is used to store the EMRs. This approach improves trust with the uploaded data and reduces errors from the falsification of the data.
In 2008, the cryptocurrency Bitcoin, which is equivalent to the original idea of a blockchain, emerged as a new currency and revolutionized the digital exchange of value. Despite the great user and research interest, the customary practice is still complex. Poor usability and negative user experience lead to several security threats. This work examines the mitigation of third party attack vectors and non-malicious human failure types identified in the personal payment process. Current approaches are analyzed and a new payment protocol is specified to foster the exchange of preparatory payment information. The qualitative evaluation reveals a significant improvement over the current best-practice exchange procedure. The system demonstrates a balance between security and usability and provides a method for more user-friendly blockchain transactions.
Dinh C. Nguyen, Pubudu N. Pathirana, Ming Ding, Aruna Seneviratne
Blockchain and Mobile Edge Computing (MEC) are newly emerging technologies with great potential to revolutionize healthcare. This paper proposes a new decentralized healthcare architecture for distributed Electronic Medical Records (EMRs) sharing among federated hospitals based on blockchain and MEC. Unlike the existing schemes that often rely on a third-party for healthcare management, we focus on a fully decentralized access control solution by using smart contracts that enable EMRs access verification at the edge of the network without requiring any central authority. Moreover, a decentralized interplanetary file system (IPFS) platform is also integrated with smart contracts over the MEC network, which significantly reduces data retrieval latency and enhances security for EMRs sharing. The experimental results and analysis show the superior performance of the proposed scheme over the existing ones in terms of reduced data retrieval latency, enhanced blockchain performance, and security guarantees.
Kilian Becher, J. A. Gregor Lagodzinski, Thorsten Strufe
Cobalt is a key ingredient of lithium-ion batteries and therefore is crucial for many modern devices. To ensure ethical sourcing, consumers need a way to verify provenance of their cobalt-based products, including the percentage of artisanally mined (ASM) cobalt. Existing frameworks for provenance and supply chain traceability rely on distributed ledgers. Providing public verifiability via permissionless distributed ledgers is trivial. However, offering public verifiability based on confidential production details seems contradictory. Hence, existing frameworks lack public verifiability of ratios between commodities while ensuring confidentiality of supply chain details. We propose a protocol that allows end consumers to verify the percentage of ASM cobalt in their products. Unlike previous solutions, production details are published and processed entirely in encrypted form by employing homomorphic encryption and proxy re-encryption. Thus, it ensures a high level of confidentiality of supply chain data. It has constant consumer-side complexity, making it suitable for mobile devices.
Qi Feng, Debiao He, Min Luo, Zengxiang Li · 5 authors
In cryptocurrency and blockchain-based distributed ledgers, transfer of money (digital coins) can be presented as a transaction. Due to the irreversibility nature of blockchain transactions, a single fraudulent use of private key (used to sign transactions) could have significant consequences (e.g. financial loss). Key protection alone is not adequate in protecting cryptocurrencies, and threshold signature is a viable method to avoid fraudulent key usage or key theft. In this paper, we focus on the Edwards-curve digital security algorithm (EdDSA), which has been applied in several cryptocurrencies (e.g. Cardano, Zcash, and Decred) and design the first efficient two-party EdDSA signing protocol. Unlike standard secret sharing, a valid signature is generated using an interactive protocol without the original key ever being exposed. We mathematically prove the security of our proposed protocol. Findings from the performance evalation of the protocol show that it achieves good performance for curve Ed25519, with a single signing operation in the malicious setting taking approximately 3.32 ms between two devices.
Andreas Abraham, Stefan More, Christof Rabensteiner, Felix Hörandner
Identity management systems enable users (i.e., provers) to authenticate and provide attributes to verifiers by using certified credentials obtained from an authority. To accept such a credential, verifiers require information on whether the presented credentials are still valid or if they have been revoked. Up-to-date revocation information can be obtained from a revocation database; however, this requires that the verifier or prover is online. The problem becomes more interesting in the offline case when the prover (e.g., citizen) and verifier (e.g., police officer) do not have an Internet connection to query the revocation status of the presented credential (e.g., digital driver's license). In this paper, we extend the Self-Sovereign Identity (SSI) model to support both revocation as well as offline-verification. Our concept introduces attestations of validity for a point in time, which are issued by the SSI network for credentials that have not been revoked, i.e., added by authorized entities to a revocation list. The concept aims to be generic so that it can be used for various use cases, e.g., by giving users the control over the frequency of re-attestation. To show our concept's feasibility and practicality, we developed and evaluated an implementation that includes an efficient and privacy-preserving showing of credentials using noninteractive zero-knowledge proofs, all while being offline.