Increasingly, information systems rely on computational, storage, and network resources deployed in third-party facilities or are supported by service providers. Such an approach further exacerbates cybersecurity concerns constantly raised by numerous incidents of security and privacy attacks resulting in data leakage and identity theft, among others. These have in turn forced the creation of stricter security and privacy related regulations and have eroded the trust in cyberspace. In particular, security related services and infrastructures such as Certificate Authorities (CAs) that provide digital certificate service and Third-Party Authorities (TPAs) that provide cryptographic key services, are critical components for establishing trust in Internet enabled applications and services. To address such trust issues, various transparency frameworks and approaches have been recently proposed in the literature. In this paper, we propose a Transparent and Trustworthy TPA using Blockchain (T3AB) to provide transparency and accountability to the trusted third-party entities, such as honest-but-curious third-party IaaS servers, and coordinators in various privacy-preserving machine learning (PPML) approaches. T3AB employs the Ethereum blockchain as the underlying public ledger and also includes a novel smart contract to automate accountability with an incentive mechanism that motivates participants' to participate in auditing, and punishes unintentional or malicious behaviors. We implement T3AB, and show through experimental evaluation in the Ethereum official test network, Rinkeby, that the framework is efficient. We also formally show the security guarantee provided by $T^3AB$, and analyze the privacy guarantee and trustworthiness it provides.
翻译:信息系统日益依赖在第三方设施部署的计算、储存和网络资源,或得到服务提供者的支持。这种方法进一步加重了许多安全和隐私攻击事件不断引发的网络安全关切,这些事件导致数据泄漏和身份盗窃等,进而迫使制定更严格的安全和隐私条例,削弱对网络空间的信任,特别是提供数字证书服务的证书管理局和提供加密关键服务的第三方当局等与安全有关的服务和基础设施,是建立对因特网应用程序和服务的信任的关键组成部分。为了解决这些信任问题,最近还在文献中提出了各种透明度框架和办法。我们提议采用透明和可信赖的TPA, 利用Black链(T3AB)向信任的第三方实体提供透明和问责,例如诚实但可靠的第三方IaAS服务器,以及各种保密机器学习(PML)方法的协调员。我们利用Eexium连锁链作为基本的公共分类,还包括对自动问责的新智能合同和办法。我们提议,利用Block链(T3AB),向受信任的第三方实体提供透明和问责。我们通过一个正式的测试机制,向参与者展示了风险风险审计或实验行为。