Increasingly, information systems rely on computational, storage, and network resources deployed in third-party facilities or are supported by service providers. Such an approach further exacerbates cybersecurity concerns constantly raised by numerous incidents of security and privacy attacks resulting in data leakage and identity theft, among others. These have in turn forced the creation of stricter security and privacy related regulations and have eroded the trust in cyberspace. In particular, security related services and infrastructures such as Certificate Authorities (CAs) that provide digital certificate service and Third-Party Authorities (TPAs) that provide cryptographic key services, are critical components for establishing trust in Internet enabled applications and services. To address such trust issues, various transparency frameworks and approaches have been recently proposed in the literature. In this paper, we propose a Transparent and Trustworthy TPA using Blockchain (T3AB) to provide transparency and accountability to the trusted third-party entities, such as honest-but-curious third-party IaaS servers, and coordinators in various privacy-preserving machine learning (PPML) approaches. T3AB employs the Ethereum blockchain as the underlying public ledger and also includes a novel smart contract to automate accountability with an incentive mechanism that motivates participants' to participate in auditing, and punishes unintentional or malicious behaviors. We implement T3AB, and show through experimental evaluation in the Ethereum official test network, Rinkeby, that the framework is efficient. We also formally show the security guarantee provided by T3AB, and analyze the privacy guarantee and trustworthiness it provides.
翻译:信息系统日益依赖在第三方设施部署的计算、储存和网络资源,或得到服务提供者的支持。这种方法进一步加重了许多安全和隐私攻击事件不断引发的网络安全关切,这些事件导致数据泄漏和身份盗窃等,进而迫使制定更严格的安全和隐私条例,削弱了对网络空间的信任,特别是提供数字证书服务的证书管理局和提供加密关键服务的第三方当局等与安全有关的服务和基础设施,是建立对因特网应用程序和服务的信任的关键组成部分。为了解决这些信任问题,文献中最近提出了各种透明度框架和办法。在本文件中,我们提议采用透明和可信赖的TPA, 利用Black链(T3AB)向信任的第三方实体提供透明和问责,例如诚实但可靠的第三方IaAS服务器,以及各种保密机器学习(PML)方法的协调员。我们利用Eexium连锁系统作为基础公共分类系统,并包括新颖的智能合同,用以解决这些信任问题。我们提议采用透明、可信赖的TPAPAP,3, 利用B链(T3) 来向受信任的第三方实体提供透明和问责。我们通过测试机制,正式地展示了恶意行为。