Tim Ruffing, Pedro Moreno-Sánchez
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
2,611 results · page 97 of 109
Tim Ruffing, Pedro Moreno-Sánchez
No abstract is available for this record.
Bruno Rodrigues, Thomas Bocek, Andri Lareida, David Hausheer · 6 authors
Abstract The rapid growth in the number of insecure portable and stationary devices and the exponential increase of traffic volume makes Distributed Denial-of-Service (DDoS) attacks a top security threat to services provisioning. Existing defense mechanisms lack resources and flexibility to cope with attacks by themselves, and by utilizing other’s companies resources, the burden of the mitigation can be shared. Emerging technologies such as blockchain and smart contracts allows for the sharing of attack information in a fully distributed and automated fashion. In this paper, the design of a novel architecture is proposed by combining these technologies introducing new opportunities for flexible and efficient DDoS mitigation solutions across multiple domains. Main advantages are the deployment of an already existing public and distributed infrastructure to advertise white or blacklisted IP addresses, and the usage of such infrastructure as an additional security mechanism to existing DDoS defense systems, without the need to build specialized registries or other distribution mechanisms, which enables the enforcement of rules across multiple domains.
Patrick McCorry, Siamak F. Shahandashti, Feng Hao
No abstract is available for this record.
Usman W. Chohan
No abstract is available for this record.
Shi-Feng Sun, Man Ho Au, Joseph K. Liu, Tsz Hon Yuen
No abstract is available for this record.
Thibault de Balthasar, Julio Hernández-Castro
No abstract is available for this record.
Katharina Krombholz, Aljosha Judmayer, Matthias Gusenbauer, Edgar Weippl
No abstract is available for this record.
Aggelos Kiayias, Alexander Russell, Bernardo David, Roman Oliynykov
No abstract is available for this record.
Majid Amjad Hussain, Sadia Khalil, Shahzad Saleem
With the increase in the use of virtual currencies across the globe, the security of Bitcoin wallets has become a serious concern for the Bitcoin community. The developers are trying to implement concrete security solutions in Bitcoin wallets to ensure that no vulnerability gets exploited. However, a large number of known, as well as zero-day attacks, are launched on the Bitcoin wallets on a daily basis, resulting in a loss of bitcoins. In this regard, this paper presents a security analysis of existing Android wallets. We demonstrate how the implemented security practices can be bypassed by malicious entities, causing financial loss to Bitcoin users. As a countermeasure, we present a smart card based authentication scheme which will protect the users from all of the identified attacks.
Shen Noether, Adam Mackenzie
This article introduces a method of hiding transaction amounts in the strongly decentralized anonymous cryptocurrency Monero. Similar to Bitcoin, Monero is a cryptocurrency which is distributed through a proof-of-work “mining” process having no central party or trusted setup. The original Monero protocol was based on CryptoNote, which uses ring signatures and one-time keys to hide the destination and origin of transactions. Recently the technique of using a commitment scheme to hide the amount of a transaction has been discussed and implemented by Bitcoin Core developer Gregory Maxwell. In this article, a new type of ring signature, A Multilayered Linkable Spontaneous Anonymous Group signature is described which allows one to include a Pedersen Commitment in a ring signature. This construction results in a digital currency with hidden amounts, origins and destinations of transactions with reasonable efficiency and verifiable, trustless coin generation. The author would like to note that early drafts of this were publicized in the Monero Community and on the #bitcoin-wizards IRC channel. Blockchain hashed drafts are available showing that this work was started in Summer 2015, and completed in early October 2015. An eprint is also available at http://eprint.iacr.org/2015/1098.
Sead Muftic
With the widespread use of Internet, Web, and mobile technologies, a new category of applications and transactions that requires anonymity is gaining increased interest and importance. Examples of such new applications are innovative payment systems, digital notaries, electronic voting, documents sharing, electronic auctions, medical applications, and many others. In addition to anonymity, these applications and transactions also require standard security services: identification, authentication, and authorization of users and protection of their transactions. Providing those services in combination with anonymity is an especially challenging issue, because all security services require explicit user identification and authentication. To solve this issue and enable applications with security and also anonymity we introduce a new type of cryptographically encapsulated objects called BIX certificates. “BIX” is an abbreviation for “Blockchain Information Exchange.” Their purpose is equivalent to X.509 certificates: to support security services for users and transactions, but also enhanced with anonymity. This paper describes the structure and attributes of BIX certificate objects and all related protocols for their creation, distribution, and use. The BIX Certification Infrastructure (BCI) as a distributed public ledger is also briefly described.
Péter Juhász, József Stéger, Dániel Kondor, Gábor Vattay
Bitcoin is a digital currency and electronic payment system operating over a peer-to-peer network on the Internet. One of its most important properties is the high level of anonymity it provides for its users. The users are identified by their Bitcoin addresses, which are random strings in the public records of transactions, the blockchain. When a user initiates a Bitcoin transaction, his Bitcoin client program relays messages to other clients through the Bitcoin network. Monitoring the propagation of these messages and analyzing them carefully reveal hidden relations. In this paper, we develop a mathematical model using a probabilistic approach to link Bitcoin addresses and transactions to the originator IP address. To utilize our model, we carried out experiments by installing more than a hundred modified Bitcoin clients distributed in the network to observe as many messages as possible. During a two month observation period we were able to identify several thousand Bitcoin clients and bind their transactions to geographical locations.
Nikola Bozic, Guy Pujolle, Stefano Secci
Recent interest about the blockchain technology brought questions about its application to other systems than the cryptocurrency one. In this paper we present blockchain and discuss key applications to network systems in the literature.
Burcu ASLANTAŞ ATEŞ
Kripto para birimleri, internet ve e-ticaretin gelismesiyle birlikte ortaya cikmis, merkezi bir otoriteye bagli olmayan ve kriptografik sistemler ile guvenligi saglanan dunya capinda kullanilan para birimleridir. En cok bilineni Bitcoin olmakla beraber cok cesitli kriptografik para birimi mevcuttur. Bu para birimlerine olan ilginin artisi ve kullaniminin yayginlasmasi vergi, hukuk ve muhasebe boyutunun da incelenmesini gerektirmektedir. Calismada genel itibariyle kriptografi, kripto para birimleri ve bu para birimlerinin muhasebe kayitlarinda ne sekilde yer almasi gerektigi ele alinmistir.
Yuanfeng Cai, Dan Zhu
The reputation system has been designed as an effective mechanism to reduce risks associated with online shopping for customers. However, it is vulnerable to rating fraud. Some raters may inject unfairly high or low ratings to the system so as to promote their own products or demote their competitors. This study explores the rating fraud by differentiating the subjective fraud from objective fraud. Then it discusses the effectiveness of blockchain technology in objective fraud and its limitation in subjective fraud, especially the rating fraud. Lastly, it systematically analyzes the robustness of blockchain-based reputation systems in each type of rating fraud. The detection of fraudulent raters is not easy since they can behave strategically to camouflage themselves. We explore the potential strengths and limitations of blockchain-based reputation systems under two attack goals: ballot-stuffing and bad-mouthing, and various attack models including constant attack, camouflage attack, whitewashing attack and sybil attack. Blockchain-based reputation systems are more robust against bad-mouthing than ballot-stuffing fraud. Blockchain technology provides new opportunities for redesigning the reputation system. Blockchain systems are very effective in preventing objective information fraud, such as loan application fraud, where fraudulent information is fact-based. However, their effectiveness is limited in subjective information fraud, such as rating fraud, where the ground-truth is not easily validated. Blockchain systems are effective in preventing bad mouthing and whitewashing attack, but they are limited in detecting ballot-stuffing under sybil attack, constant attacks and camouflage attack.
Xu Zhang, Mi Wen, Kejie Lu, Jingsheng Lei
No abstract is available for this record.
Edmund W. Cheng, Chan Wai Yin
This paper examines the antecedent and contingent causes sparking the Umbrella Movement in Hong Kong. Spurred by two contingent events generating pre-emptive and backlash mobilization, the movement is a spontaneous transformation of the staged Occupy Central campaign. Based on an onsite survey (n = 1681) and in-depth interviews (n = 18), this paper demonstrates how protest experience and social media networked and rallied autonomous individuals from diverse backgrounds to occupy the physical spaces, thereby sustaining a self-mobilized, horizontal and resilient movement. Spontaneity, however, did not come out of nowhere. As an integral part of Hong Kong’s bottom-up activism and ecology, this spontaneous episode encapsulates antecedent events diffusing stalwart actors, decentralized organization and transgressive repertories. This paper situates spontaneity in temporal, spatial and emotional contexts to understand the uncompromising claims and participatory practices of the spectacular occupation.
Ari Juels, Ahmed E. Kosba, Elaine Shi
Thanks to their anonymity (pseudonymity) and elimination of trusted intermediaries, cryptocurrencies such as Bitcoin have created or stimulated growth in many businesses and communities. Unfortunately, some of these are criminal, e.g., money laundering, illicit marketplaces, and ransomware. Next-generation cryptocurrencies such as Ethereum will include rich scripting languages in support of smart contracts, programs that autonomously intermediate transactions. In this paper, we explore the risk of smart contracts fueling new criminal ecosystems. Specifically, we show how what we call criminal smart contracts (CSCs) can facilitate leakage of confidential information, theft of cryptographic keys, and various real-world crimes (murder, arson, terrorism).
Roman Matzutt, Oliver Hohlfeld, Martin Henze, Robin Rawiel · 6 authors
As transaction fees skyrocket today, blockchains become increasingly expensive, hurting their adoption in broader applications. This work tackles the saving of transaction fees for economic blockchain applications. The key insight is that other than the existing "default'' mode to execute application logic fully on-chain, i.e., in smart contracts, and in fine granularity, i.e., user request per transaction, there are alternative execution modes with advantages in cost-effectiveness. On Ethereum, we propose a holistic middleware platform supporting flexible and secure transaction executions, including off-chain states and batching of user requests. Furthermore, we propose control-plane schemes to adapt the execution mode to the current workload for optimal runtime cost. We present a case study on the institutional accounts (e.g., coinbase.com) intensively sending Ether on Ethereum blockchains. By collecting real-life transactions, we construct workload benchmarks and show that our work saves 18%\sim 47%18%-47% per invocation than the default baseline while introducing 1.81%\sim 16.59%1.81%-16.59% blocks delay.
Gina Gallegos-García, Vincenzo Iovino, Alfredo Rial, Peter B. Roenne · 5 authors
In e-voting protocols, cryptographers must balance usability with strong security guarantees, such as privacy and verifiability. In traditional e-voting protocols, privacy is often provided by a trusted authority that learns the votes and computes the tally. Some protocols replace the trusted authority by a set of authorities, and privacy is guaranteed if less than a threshold number of authorities are corrupt. For verifiability, stronger security is demanded. Typically, corrupt authorities that try to fake the tally result must always be detected.To provide verifiability, many e-voting protocols use Non-Interactive Zero-Knowledge proofs (NIZK). Thanks to their non-interactive nature, NIZK allow anybody, including third parties that do not participate in the protocol, to verify the correctness of the tally. Therefore, NIZK can be used to obtain universal verifiability. Additionally, NIZK also improve usability because they allow voters to cast a vote non-interactively.The disadvantage of NIZK is that their security is based on setup assumptions such as the common reference string (CRS) or the random oracle model. The former requires a trusted party to generate a CRS. The latter, though a popular model for secure protocol design, has been shown to be unsound.We address the design of e-voting protocols that provide verifiability without any trust assumptions. We show that Non-Interactive Witness-Indistinguishable proofs can be used for this purpose. Our e-voting protocols are private under the Decision Linear assumption, while perfect individual verifiability, i.e. a fake tally is detected with probability 1, holds unconditionally. Perfect universal verifiability requires a trusted public bulletin board. We remark that our definition of verifiability does not consider eligibility or end-to-end verifiability. First, we present a general construction that supports any tally function. Then, we show how to efficiently instantiate it for specific types of elections through Groth-Sahai proofs.
Steve Huckle, Martin White
Bitcoin (BTC) is often cited as Libertarian. However, the technology underpinning Bitcoin, blockchain, has properties that make it ideally suited to Socialist paradigms. Current literature supports the Libertarian viewpoint by focusing on the ability of Bitcoin to bypass central authority and provide anonymity; rarely is there an examination of blockchain technology’s capacity for decentralised transparency and auditability in support of a Socialist model. This paper conducts a review of the blockchain, Libertarianism, and Socialist philosophies. It then explores Socialist models of public ownership and looks at the unique cooperative properties of blockchain that make the technology ideal for supporting Socialist societies. In summary, this paper argues that blockchain technologies are not just a Libertarian tool, they also enhance Socialist forms of governance.
Nurzhan Zhumabekuly Aitzhan, Davor Svetinović
Smart grids equipped with bi-directional communication flow are expected to provide more sophisticated consumption monitoring and energy trading. However, the issues related to the security and privacy of consumption and trading data present serious challenges. In this paper we address the problem of providing transaction security in decentralized smart grid energy trading without reliance on trusted third parties. We have implemented a proof-of-concept for decentralized energy trading system using blockchain technology, multi-signatures, and anonymous encrypted messaging streams, enabling peers to anonymously negotiate energy prices and securely perform trading transactions. We conducted case studies to perform security analysis and performance evaluation within the context of the elicited security and privacy requirements.
Tomoyuki Sanda, Hiroyuki Inaba
Recently, Wi-Fi hotspots are installed at several places. However most communications are not encrypted and the illegal can use it maliciously, therefore effective breakthrough are required. We propose a solution of these problems using a new method derived from Bitcoin. This method uses Blockchain and logs of user access are saved to it. The administrators can identify illegal person and collect user's statistics. Bitcoin address can be used as encryption keys for communications. The Blockchain also provides a platform of regional applications. Furthermore, systems can cooperate with others at different places.
Primavera De Filippi, Benjamin Loveluck
A trustless technology, Bitcoin tries to solve issues of social coordination and economic exchange by relying exclusively on technological means. Is technology alone able to resolve the social and political concerns affecting the Bitcoin network?