Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

3,460 papersLast indexed Aug 31, 2026
Search papers

Paper index

3,460 results · page 99 of 145

Clear filters
Sep 2, 2020·arXiv (Cornell University)
3 cites
zkay v0.2: Practical Data Privacy for Smart Contracts

Nick Baumann, Samuel Steffen, Benjamin Bichsel, Petar Tsankov · 5 authors

Recent work introduces zkay, a system for specifying and enforcing data privacy in smart contracts. While the original prototype implementation of zkay (v0.1) demonstrates the feasibility of the approach, its proof-of-concept implementation suffers from severe limitations such as insecure encryption and lack of important language features. In this report, we present zkay v0.2, which addresses its predecessor's limitations. The new implementation significantly improves security, usability, modularity, and performance of the system. In particular, zkay v0.2 supports state-of-the-art asymmetric and hybrid encryption, introduces many new language features (such as function calls, private control flow, and extended type support), allows for different zk-SNARKs backends, and reduces both compilation time and on-chain costs.

Open access
2 source records
Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Sep 1, 2020·2020 International Conference on Modern Education and Information Management (ICMEIM)
11 cites
Management of Online Education Based on Blockchains

Lei Gao

With the rapid development of network technology, online education becomes indispensable to the whole education system, which has been paid an increasing attention to by various education institutions, but the management of online learning process, certificates or other data is still far from perfection. To solve these problems, the paper proposes to use the blockchain technology in online education, which is conducive to the management of educational resources, student data, certification of students' achievements and students' employment. By means of public blockchains and private blockchains, the learning users, education institutions, education regulators and the talent markets can make direct communication with each other as different nodes on the blockchain, which can promote the healthy development of online education.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Sep 1, 2020·IEEE Internet Computing
25 cites
COM-PACE: Compliance-Aware Cloud Application Engineering Using Blockchain

Gagangeet Singh Aujla, Masoud Barati, Omer Rana, Schahram Dustdar · 10 authors

The COVID19 Pandemic has highlighted our dependence on online services (from government, e-commerce/retail, and entertainment), often hosted over external cloud computing infrastructure. The users of these services interact with a web interface rather than the larger distributed service provisioning chain that can involve an interlinked group of providers. The data and identity of users are often provided to service provider who may share it (or have automatic sharing agreement) with backend services (such as advertising and analytics). We propose the development of compliance-aware cloud application engineering, which is able to improve transparency of personal data use -- particularly with reference to the European GDPR regulation. Key compliance operations and the perceived implementation challenges for the realization of these operations in current cloud infrastructure are outlined.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cloud Data Security Solutions
Original source
Sep 1, 2020·2020 IEEE 3rd 5G World Forum (5GWF)
2 cites
Hybrid-Trusted Party Contract Agrees on Clients Input

Anwar Alruwaili, Dov Kruger

Modern applications implemented on distributed ledgers and blockchain platforms serve a wide variety of purposes in automating business and end-user processes. Smart contracts, which are immutable records of functions, are used to mitigate and reduce the administration cost of these implementations. This paper describes a hybrid-trusted multi-party contract to identify the input of a client and validate a transaction. A policy is defined to create the initial relationship, using trusted parties to authorize a particular input and verify that an owner initially owns that input. This ties the reality into the blockchain and requires that trusted parties set up the initial blockchain database. After that, transactions are performed without trusted third parties, reducing costs.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Cryptography and Data Security
Original source
Sep 1, 2020·2020 2nd Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS)
4 cites
Veritaa - The Graph of Trust

Jakob Schaerer, Severin Zumbrunn, Torsten Braun

Today the integrity of digital documents and the authenticity of their origin is often hard to verify. Existing Public Key Infrastructures (PKIs) are capable of certifying digital identities but do not provide solutions to immutably store signatures, and the process of certification is often not transparent. In this work we propose Veritaa, a Distributed Public Key Infrastructure and Signature Store (DPKISS). The major innovation of Veritaa is the Graph of Trust, a directed graph that uses relations between identity claims to certify the identities and stores signed relations to digital document identifiers. The distributed architecture of Veritaa and the Graph of Trust enables a transparent certification process. To ensure non-repudiation and immutability of all actions that have been signed on the Graph of Trust, an application specific Distributed Ledger Technology (DLT) is used as secure storage. In this work a reference implementation of the proposed architecture was designed and implemented. Furthermore, a testbed was created and used for the evaluation of Veritaa. The evaluation of Veritaa shows the benefits and the high performance of the proposed architecture.

Cloud Data Security Solutions
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Sep 1, 2020·IEEE Network
37 cites
Decentralized Public Key Infrastructures atop Blockchain

Yannan Li, Yong Yu, Chunwei Lou, Nadra Guizani · 5 authors

The public key infrastructure (PKi) has been widely adopted to create, manage, distribute, store and revoke digital certificates, which plays an important role in bootstrapping secure communications. A PKi system authenticates entities with the corresponding public keys and it lays the security foundation for public-key cryptosystems in public-key encryption and digital signatures. However, traditional PKi systems suffer from security breaches, such as single-point-of-failure and man-in-the-middle attacks due to the existence of a centralized certificate authority. in this article, we review the traditional centralized PKi system as well as the subjected security concerns, and then we propose possible solutions to address these issues with the emerging blockchain technology. Two frameworks are presented where blockchain is utilized as a public bulletin board or trusted majority. We implement the functions to evaluate the off-chain time costs and on-chain gas costs of the proposal, which demonstrate the feasibility and practicality of the proposal.

Cryptography and Data Security
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Sep 1, 2020·2020 International Symposium on Reliable Distributed Systems (SRDS)
33 cites
An Efficient Query Scheme for Hybrid Storage Blockchains Based on Merkle Semantic Trie

Qingqi Pei, Enyuan Zhou, Yang Xiao, Deyu Zhang · 5 authors

As a decentralized trusted database, the blockchain is finding applications in a growing number of fields such as finance, supply chain and medicine traceability, where large volumes of valuable data are stored on the blockchain. Currently, the mainstream blockchains employ a hybrid data storage architecture combining on-chain and off-chain storage. Real-time distributed search of mass data stored in this hybrid system is now a major need. However, previous fast retrieval schemes for the blockchain system are aimed only at on-chain data without considering their relevance to off-chain data, and thus fail to meet the requirement. In this paper, we propose an efficient blockchain data query scheme by introducing a novel Merkle Semantic Trie-based indexing technique without modifying the underlying database. A consensus on-chain index structure is constructed using the extracted semantic information of the off-chain data to create a mapping between the on-chain and off-chain data, thus enabling real-time data query both on and off the chain. Our scheme also provides multiple complex analytical query primitives to support semantic query, range query, and even fuzzy query. Experiments on three open data sets show that the proposed scheme has good query performance with shorter query latency for four different search types and offers better retrieval performance and verification efficiency than those available.

Blockchain Technology Applications and Security
Caching and Content Delivery
Cloud Data Security Solutions
Original source
Sep 1, 2020·2020 IEEE European Symposium on Security and Privacy (EuroS&P)
55 cites
Accountability in a Permissioned Blockchain: Formal Analysis of Hyperledger Fabric

Mike Graf, Ralf Küsters, Daniel Rausch

While accountability is a well-known concept in distributed systems and cryptography, in the literature on blockchains (and, more generally, distributed ledgers) the formal treatment of accountability has been a blind spot: there does not exist a formalization let alone a formal proof of accountability for any blockchain yet. Therefore, in this work we put forward and propose a formal treatment of accountability in this domain. Our goal is to formally state and prove that if in a run of a blockchain a central security property, such as consistency, is not satisfied, then misbehaving parties can be identified and held accountable. Accountability is particularly useful for permissioned blockchains where all parties know each other, and hence, accountability incentivizes all parties to behave honestly. We exemplify our approach for one of the most prominent permissioned blockchains: Hyperledger Fabric in its most common instantiation.

Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Aug 26, 2020·2020 International Symposium on Reliable Distributed Systems (SRDS), Shanghai, China, 2020, pp. 31-40
17 cites
TZ4Fabric: Executing Smart Contracts with ARM TrustZone : (Practical Experience Report)

Christina Muller, Marcus Brandenburger, Christian Cachin, Pascal Felber · 6 authors

Blockchain technology promises to revolutionize manufacturing industries. For example, several supply-chain use-cases may benefit from transparent asset tracking and automated processes using smart contracts. Several real-world deployments exist where the transparency aspect of a blockchain is both an advantage and a disadvantage at the same time. The exposure of assets and business interaction represent critical risks. However, there are typically no confidentiality guarantees to protect the smart contract logic as well as the processed data. Trusted execution environments (TEE) are an emerging technology available in both edge or mobile-grade processors (e.g., Arm TrustZone) and server-grade processors (e.g., Intel SGX). TEEs shield both code and data from malicious attackers. This practical experience report presents TZ4Fabric, an extension of Hyperledger Fabric to leverage Arm TrustZone for the secure execution of smart contracts. Our design minimizes the trusted computing base executed by avoiding the execution of a whole Hyperledger Fabric node inside the TEE, which continues to run in untrusted environment. Instead, we restrict it to the execution of only the smart contract. The TZ4Fabric prototype exploits the open-source OP-TEE framework, as it supports deployments on cheap low-end devices (e.g., Raspberry Pis). Our experimental results highlight the performance trade-off due to the additional security guarantees provided by Arm TrustZone. TZ4Fabric will be released as open-source.

Open access
2 source records
Blockchain Technology Applications and Security
Security and Verification in Computing
Cloud Data Security Solutions
Original source
Aug 26, 2020·International Journal of Interactive Multimedia and Artificial Intelligence
12 cites
Efficient Method Based on Blockchain Ensuring Data Integrity Auditing with Deduplication in Cloud.

Mohamed El Ghazouani, My Ahmed El Kiram, Latifa Er-Rajy, Yassine El Khanboubi

With the rapid development of cloud storage, more and more cloud clients can store and access their data anytime, from anywhere and using any device. Data deduplication may be considered an excellent choice to ensure data storage efficiency. Although cloud technology offers many advantages for storage service, it also introduces security challenges, especially with regards to data integrity, which is one of the most critical elements in any system. A data owner should thus enable data integrity auditing mechanisms. Much research has recently been undertaken to deal with these issues. In this paper, we propose a novel blockchain-based method, which can preserve cloud data integrity checking with data deduplication. In our method, a mediator performs data deduplication on the client side, which permits a reduction in the amount of outsourced data and a decrease in the computation time and the bandwidth used between the enterprise and the cloud service provider. This method supports private and public auditability. Our method also ensures the confidentiality of a client's data against auditors during the auditing process.

Open access
Cloud Data Security Solutions
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Aug 25, 2020·International journal of intelligent engineering and systems
2 cites
Secure and Verifiable Multi-Party Computation Using Indistinguishability Obfuscation

Smita Chaudhari, Gandharba Swain, Pragnyaban Mishra

In most practical cloud computing applications such as e-voting, auctions, health, and financial applications or cloud services in common, to prove the exactness of outsourced data is one of the major needs today. Most of the time, third party auditing is employed for this task. This auditing work is controlled by assigning the secret inputs to an entity trusted third party, or worker, who is liable for performing computations and hand over the result of the computation to the cloud users or clients. To verify the integrity of computations using traditional cryptographic techniques, the time required to generate and validate the proof is a major computation issue. This paper proposes an improved public auditing technique for multi-party computation to check the integrity of outsourced data using a cryptographic solution. Many researchers have given auditing protocols that generate and verify proof using a cryptographic solution. Most of these scheme uses Non-Interactive Zero-Knowledge Proof (NIZK) which are basically built on bilinear map technology. The verification time using these existing technique is computationally expensive which affect the performance of the auditing system. We propose an efficient protocol that verifies the result correctness using modern cryptographic technique Indistinguishability Obfuscation. The proposed system works in two phases, (i) auction and (ii) audit. During the auction phase, multiple clients share their encrypted bid value to the worker. The worker generates auction result and proof using Pedersen Commitment Scheme. The audit phase starts only after the completion of the auction phase which results in reduced verification time. During the Audit phase, clients can verify the integrity of results using NIZK with the IO technique. The results for reduced verification time in auction system have been presented. It is found that the performance of the proposed system has improved compared to the pertinent NIZK Proof technique. In our setting, we assumed that a worker is one of the trusted entity. By this notion, our protocol also guarantees privacy to the clients during the audit phase.

Open access
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Cloud Data Security Solutions
Original source
Aug 24, 2020·International Journal of Network Management
6 cites
Trustful ad hoc cross‐organizational data exchanges based on the Hyperledger Fabric framework

Laurens Van Hoye, Tim Wauters, Filip De Turck, Bruno Volckaert

Summary Organizations share data in a cross‐organizational context when they have the goal to derive additional knowledge by aggregating different data sources. The collaborations considered in this article are short‐lived and ad hoc, that is, they should be set up in a few minutes at most (e.g., in emergency scenarios). The data sources are located in different domains and are not publicly accessible. When a collaboration is finished, it is however unclear which exchanges happened. This could lead to possible disputes when dishonest organizations are present. The receipt of requests/responses could be falsely denied or their content could be point of discussion. In order to prevent such disputes afterwards, a logging mechanism is needed which generates a replicated irrefutable proof of which exchanges have happened during a single collaboration. Distributed database solutions can be taken from third parties to store the generated logs, but it can be difficult to find a party which is trusted by all participating organizations. Permissioned blockchains provide a solution for this as each organization can act as a consensus participant. Although the consensus mechanism of the permissioned blockchain Hyperledger Fabric (versions 1.0–1.4) is not fully decentralized, which clashes with the fundamental principle of blockchain, the framework is used in this article as an enabler to set up a distributed database, and a proposal for a logging mechanism is presented which does not require the third party to be fully trusted. A proof of concept is implemented which can be used to experiment with different data exchange setups. It makes use of generic web APIs and behaves according to a Markov chain in order to create a fully automated data exchange scenario where the participants explore their APIs dynamically. The resulting mechanism allows a data‐delivering organization to detect missing logs and to take action, for example, (temporarily) suspend collaboration. Furthermore, each organization is incentivized to follow the steps of the logging mechanism as it may lose access to data of others, otherwise. The created proof of concept is scaled to 10 organizations, which autonomously exchange different data types for 10 min, and evaluation results are presented accordingly.

Open access
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Cloud Data Security Solutions
Original source
Aug 24, 2020·First Monday
118 cites
Blockchain in education: Opportunities, applications, and challenges

Mara-Florina Steiu

This paper discusses the opportunities and challenges of applying blockchain technologies in the education sector. The key blockchain-in-education applications discussed are the digitalization and decentralization of educational certifications and the enhancement and motivation for lifelong learning. Some of the key challenges explored are data protection laws such as the General Data Protection Regulation and the California Consumer Protection Act, which pose impediments for application developers and scalability challenges that arise because of slow-speed blockchain transactions and the Scaling Trilemma. Additionally, market adoption and innovation challenges highlight that blockchain-in-education is a relatively immature innovation that governance bodies within educational institutions often disregard or perceive cautiously.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Aug 21, 2020·2020 International Conference on Advances in Computing, Communication & Materials (ICACCM)
14 cites
Data Provenance Assurance for Cloud Storage Using Blockchain

Abhishekh Patil, Amit Kumar Jha, Mohammed Moin Mulla, D. G. Narayan · 5 authors

Cloud forensics investigates the crime committed over cloud infrastructures like SLA-violations and storage privacy. Cloud storage forensics is the process of recording the history of the creation and operations performed on a cloud data object and investing it. Secure data provenance in the Cloud is crucial for data accountability, forensics, and privacy. Towards this, we present a Cloud-based data provenance framework using Blockchain, which traces data record operations and generates provenance data. Initially, we design a dropbox like application using AWS S3 storage. The application creates a cloud storage application for the students and faculty of the university, thereby making the storage and sharing of work and resources efficient. Later, we design a data provenance mechanism for confidential files of users using Ethereum blockchain. We also evaluate the proposed system using performance parameters like query and transaction latency by varying the load and number of nodes of the blockchain network.

Scientific Computing and Data Management
Cloud Data Security Solutions
Cloud Computing and Resource Management
Original source
Aug 14, 2020·IEEE Internet of Things Journal
11 cites
Blockchain Enables Your Bill Safer

Qin Wang, Longxia Huang, Shiping Chen, Yang Xiang

As one of the most frequently used Internet-of-Things (IoT) devices, energy smart meter has been widely adopted to facilitate the measures of residential energy use. Residents pay for the bills from energy suppliers according to their monthly/seasonal usage. Practically, there is a demand from residents/governments to check whether the bills are in line with their real consumptions. However, it is challenging to realize this demand due to two critical problems. The first problem refers to the nonrepudiated privacy issue caused by access to residents’ energy consumption history (e.g., data integrity may be questioned, and residents’ daily timetables may be exposed). The second problem comes from the efficiency requirement for bulk auditing requests on residents’ bills and consumptions, usually risen by governments. So far, we have not found any solutions that can be directly used in this case. In this article, we propose using homomorphic encryption cooperated with the blockchain technique to leverage the data auditing and privacy-preserving requirements. We also employe a certificateless signature to resolve the efficiency bottleneck in batch auditing. This framework, calledpAuditChain, not only accepts personal requests from residents for consumption checking but also handles bulk auditing requests issued by governments. To validate the correctness of the framework functions, we carried out a series of theoretical analysis, especially on the privacy preserving and auditing processes. To the best of our knowledge, the proposed framework is among the first solutions to improve the security and privacy of bills without losing the auditing function. Our approach concerns with IoT smart meters in energy supply industries and could be further extended to other forms of IoT devices with the bill demands.

Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Aug 13, 2020·arXiv (Cornell University)
1 cites
Zecale: Reconciling Privacy and Scalability on Ethereum

Antoine Rondelet

In this paper, we present Zecale, a general purpose SNARK proof aggregator that uses recursive composition of SNARKs. We start by introducing the notion of recursive composition of SNARKs, before introducing Zecale as a privacy preserving scalability solution. Then, we list application types that can emerge and be built with Zecale. Finally, we argue that such scalability solutions for privacy preserving state transitions are paramount to emulate "cash" on blockchain systems.

Open access
2 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Aug 12, 2020·IEEE Network
54 cites
Blockchain-Based Massive Data Dissemination Handling in IIoT Environment

Aparna Kumari, Sudeep Tanwar, Sudhanshu Tyagi, Neeraj Kumar

Rapid development in Information and Communications Technologies (ICT), Internet of Things (IoT), and Big Data (BD) analytics has revolutionized the manufacturing industry, which introduces the Industrial Internet of Things (IIoT) in Industry 4.0. IIoT includes machinery, manufacturing processes, and automation mechanisms. The existing IIoT system uses a centralized architecture, where the trusted third party (TTP) performs transactions, which raises security and privacy concerns and may have a single point of failure. The emerging technology Blockchain is a prominent solution to address the aforementioned issues. Motivated by these facts, in this article we highlight the issues of data dissemination in the IIoT environment and present a blockchain-based decentralized model for IIoT (DMIIoT). The proposed model uses a secure Peer-to-Peer (P2P) network, where each node interacts with other nodes. Then we highlight the potential of the DMIIoT to improve various services in IIoT, such as better production visibility and Quality of Service (QoS). Finally, we present a case study on a Smart Grid (SG) system to evaluate the efficacy of the proposed model with data load balance, energy management costs, and transmission delay parameters.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cloud Data Security Solutions
Original source
Aug 11, 2020·Journal of Emerging Technologies in Accounting
6 cites
IT Governance Considerations for Permissioned Blockchains

Jose Victor Lineros

ABSTRACT The operational advantages of permissioned blockchains utilize collaborative, private, immutable, append-only distributed ledgers to strategically optimize business results. Accordingly, the importance of related IT governance frameworks is growing. Strategic IT governance, especially regarding permissioned blockchains, is crucial to accurate, valid, and complete accounting data. And while permissioned blockchains such as Hyperledger Fabric, Corda, and Quorum can enhance business collaborations, attention to IT governance is critical. Reviewing blockchain IT governance is necessary if the benefits of encryption, hashing, and distributed ledgers are to be realized. Understanding the potential weaknesses of flawed capacity planning (computational and storage), cybersecurity risks, litigation uncertainty, regulatory refutation, and smart contract vulnerabilities is key. Exacerbating the situation is that many of these weaknesses are likely to grow as permissioned blockchains propagate. If internal auditors do not preemptively address these IT governance issues, both management and internal audit departments could fail their stakeholders. Data Availability: Data are available from the public sources cited in the text.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
FinTech, Crowdfunding, Digital Finance
Original source