Security Issues and Weaknesses in Blockchain Cloud Infrastructure: A Review Article
Abstract
Cloud computing has become an essential technology due to its ability to provide scalable infrastructure and data services at a low cost and with minimal effort. It is widely adopted across various IT sectors and excels in providing flexible and scalable solutions for storage, computation, and networking. However, despite its widespread adoption, information security concerns remain a significant challenge, hampering its full potential. Issues such as data breaches, insufficient access controls, privacy risks, and vulnerability to external attacks persist, making security a critical obstacle for cloud computing’s growth. At the same time, blockchain technology has emerged as a promising solution for addressing these security challenges. Celebrated for ensuring data integrity, authenticity, and confidentiality, blockchain’s decentralized structure offers a potential safeguard against the risks cloud systems face. For instance, blockchain’s ability to maintain an immutable, tamper-proof ledger and decentralized control can mitigate unauthorised access risks, thereby enhancing cloud environments' transparency and security. One of the blockchain’s core components is the consensus protocol, a method through which a network of nodes validates transactions without needing to trust any single entity. In the case of Bitcoin, users follow the Proof of Work algorithm, dedicating hardware and energy resources to solve cryptographic puzzles and verify transactions. This decentralized verification process addresses fraud concerns, but it also brings challenges such as high energy consumption and network centralization, particularly in regions with cheap electricity. These concerns have led to worries about collusion risks and policy changes affecting the stability of the network. Blockchain’s decentralized nature has sparked significant interest, especially in its potential to enhance cloud computing security. Its ability to provide tamper-proof transaction logs, eliminate single points of failure, and grant users more control over data aligns well with the security demands of cloud environments. However, blockchain itself faces challenges, including scalability issues and its association with black-market trading due to its open-access model. Despite these concerns, blockchain’s integration into cloud systems presents a unique opportunity for addressing key security obstacles, thereby offering more robust solutions for corporate and financial applications.
Keywords
Full Text:
PDFReferences
H. A. Albaroodi, M. Abomaali, and S. Manickam, “Iraqi’s Organizations Awareness to Prompt Open Source Cloud Computing (OSCC) in Their Service: A Study”, vol. 1132 CCIS. 2020. doi: 10.1007/978-981-15-2693-0_22.
H. A. Albaroodi, M. Abomaali, A. Ismael, and S. Manickam, “Effectiveness of Open Source Cloud Computing in Developing Countries: Empirical Study,” ARPN J. Eng. Appl. Sci., vol. 14, no. 4-Supplement1, 2019, doi: 10.36478/JEASCI.2019.7313.7319.
H. Albaroodi, S. Manickam, and P. Singh, “Critical review of openstack security: Issues and weaknesses,” J. Comput. Sci., vol. 10, no. 1, 2013, doi: 10.3844/jcssp.2014.23.33.
W. F. Silvano and R. Marcelino, “Iota Tangle: A cryptocurrency to communicate Internet-of-Things data,” Futur. Gener. Comput. Syst., vol. 112, pp. 307–319, 2020.
S. J. Pee, J. H. Nans, and J. W. Jans, “A simple blockchain-based peer-to-peer water trading system leveraging smart contracts,” in Proceedings on the International Conference on Internet Computing (ICOMP), The Steering Committee of The World Congress in Computer Science, Computer …, 2018, pp. 63–68.
I. Zikratov, A. Kuzmin, V. Akimenko, V. Niculichev, and L. Yalansky, “Ensuring data integrity using blockchain technology,” in 2017 20th Conference of Open Innovations Association (FRUCT), IEEE, 2017, pp. 534–539.
B. R. Kandukuri and A. Rakshit, “Cloud security issues,” in 2009 IEEE International Conference on Services Computing, IEEE, 2009, pp. 517–520.
H. Lo, R. Wang, and J. P. Garbini, “The state of enterprise software 2009,” Forrester Res. Cambridge, 2009.
C. Ji, Y. Li, W. Qiu, U. Awada, and K. Li, “Big data processing in cloud computing environments,” in 2012 12th international symposium on pervasive systems, algorithms and networks, IEEE, 2012, pp. 17–23.
C. Dannen, Introducing Ethereum and solidity, vol. 1. Springer, 2017.
G. J. Holzmann, “An analysis of bitstate hashing,” Form. methods Syst. Des., vol. 13, no. 3, pp. 289–307, 1998.
P. Kasireddy, “How does Ethereum work, anyway,” Medium, 2017.
M. Fleder, M. S. Kester, and S. Pillai, “Bitcoin transaction graph analysis,” arXiv Prepr. arXiv1502.01657, 2015.
M. Szydlo, “Merkle tree traversal in log space and time,” in International Conference on the Theory and Applications of Cryptographic Techniques, Springer, 2004, pp. 541–554.
T. Skopal, J. Pokorný, M. Krátký, and V. Snášel, “Revisiting M-tree building principles,” in East European Conference on Advances in Databases and Information Systems, Springer, 2003, pp. 148–162.
R. Qin, Y. Yuan, and F.-Y. Wang, “Research on the selection strategies of blockchain mining pools,” IEEE Trans. Comput. Soc. Syst., vol. 5, no. 3, pp. 748–757, 2018.
M. Kantarcioglu and C. Clifton, “Privacy-preserving distributed mining of association rules on horizontally partitioned data,” IEEE Trans. Knowl. Data Eng., vol. 16, no. 9, pp. 1026–1037, 2004.
J. A. Kroll, I. C. Davey, and E. W. Felten, “The economics of Bitcoin mining, or Bitcoin in the presence of adversaries,” in Proceedings of WEIS, Washington, DC, 2013.
M. Jakobsson, T. Leighton, S. Micali, and M. Szydlo, “Fractal Merkle tree representation and traversal,” in Cryptographers’ Track at the RSA Conference, Springer, 2003, pp. 314–326.
E. Androulaki et al., “Hyperledger fabric: a distributed operating system for permissioned blockchains,” in Proceedings of the thirteenth EuroSys conference, 2018, pp. 1–15.
T. Chakraborty, S. Mitra, S. Mittal, and M. Young, “A Policy Driven AI-Assisted PoW Framework,” arXiv Prepr. arXiv2203.10698, 2022.
N. Kheshaifaty and A. Gutub, “Preventing multiple accessing attacks via efficient integration of captcha crypto hash functions,” Int. J. Comput. Sci. Netw. Secure., vol. 20, no. 9, pp. 16–28, 2020.
R. Cross, J. Liedtka, and L. Weiss, “A practical guide to social networks,” Harv. Bus. Rev., vol. 83, no. 3, pp. 124–132, 2005.
A. Hooper and D. Holtbrügge, “Blockchain technology in international business: changing the agenda for global governance,” Rev. Int. Bus. Strateg., vol. 30, no. 2, pp. 183–200, 2020.
H. A. Albaroodi and M. Anbar, “Ethereum-inspired access management account control for a secured decentralized cloud storage,” J. Theor. Appl. Inf. Technol., vol. 100, no. 7, 2022.
J. De Kruijff and H. Weigand, “Towards a blockchain ontology,” Netherlands, pdfs. Semant. org/0782/c5badb4f407ee0964d07eda9f74a92de3298. pdf [dostęp 22.07. 2018], 2017.
M. Kuhn, F. Funk, G. Zhang, and J. Franke, “Blockchain-based application for the traceability of complex assembly structures,” J. Manuf. Syst., vol. 59, pp. 617–630, 2021.
K. Saini, “A future’s dominant technology blockchain: Digital transformation,” in 2018 international conference on computing, power and communication technologies (GUCON), IEEE, 2018, pp. 937–940.
I. Shilov and D. Zakoldaev, “Multidimensional Blockchain as Robust Distributed Ledger,” in 2022 31st Conference of Open Innovations Association (FRUCT), IEEE, 2022, pp. 313–319.
N. El Ioini and C. Pahl, “A review of distributed ledger technologies,” in OTM Confederated International Conferences" On the Move to Meaningful Internet Systems", Springer, 2018, pp. 277–288.
L. Yue, H. Junqin, Q. Shengzhi, and W. Ruijin, “Big data model of security sharing based on blockchain,” in 2017 3rd International Conference on Big Data Computing and Communications (BIGCOM), IEEE, 2017, pp. 117–121.
M. A. Khan, F. Algarni, and M. T. Quasim, “Decentralised internet of things,” in Decentralised Internet of Things, Springer, 2020, pp. 3–20.
B. Preneel, “Cryptographic hash functions,” Eur. Trans. Telecommun., vol. 5, no. 4, pp. 431–448, 1994.
W. Penard and T. van Werkhoven, “On the secure hash algorithm family,” Cryptogr. Context, pp. 1–18, 2008.
S. Landau, “Find me a hash,” Not. AMS, vol. 53, no. 3, 2006.
I.-C. Lin and T.-C. Liao, “A survey of blockchain security issues and challenges.,” Int. J. Netw. Secur., vol. 19, no. 5, pp. 653–659, 2017.
F. A. Khan, M. Asif, A. Ahmad, M. Alharbi, and H. Aljuaid, “Blockchain technology, improvement suggestions, security challenges on smart grid and its application in healthcare for sustainable development,” Sustain. Cities Soc., vol. 55, p. 102018, 2020.
M. Jakobsson and A. Juels, “Proofs of work and bread pudding protocols,” in Secure information networks, Springer, 1999, pp. 258–272.
C. Gupta and A. Mahajan, “Evaluation of proof-of-work consensus algorithm for blockchain networks,” in 2020 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT), IEEE, 2020, pp. 1–7.
E. Ephrati and J. S. Rosenschein, “The Clarke Tax as a Consensus Mechanism Among Automated Agents.,” in AAAI, 1991, pp. 173–178.
C. Dierksmeier and P. Seele, “Cryptocurrencies and business ethics,” J. Bus. Ethics, vol. 152, no. 1, pp. 1–14, 2018.
A. Poelstra, “Distributed consensus from proof of stake is impossible,” Self-published Pap., 2014.
B. Laurie and R. Clayton, “Proof-of-work proves not to work; version 0.2,” in Workshop on economics and information, security, 2004.
F. Leal, A. E. Chis, and H. González–Vélez, “Performance evaluation of private ethereum networks,” SN Comput. Sci., vol. 1, no. 5, pp. 1–17, 2020.
D. Vujičić, D. Jagodić, and S. Ranđić, “Blockchain technology, bitcoin, and Ethereum: A brief overview,” in 2018 17th international symposium infoteh-jahorina (infoteh), IEEE, 2018, pp. 1–6.
H. Albaroodi, S. Manickam, and M. Anbar, “A proposed framework for outsourcing and secure encrypted data on OpenStack object storage (Swift),” J. Comput. Sci., vol. 11, no. 3, 2015, doi: 10.3844/jcssp.2015.590.597.
Q. Luo, J. Zhou, S. Yu, and D. Xiao, “Stereo matching and occlusion detection with integrity and illusion sensitivity,” Pattern Recognit. Lett., vol. 24, no. 9–10, pp. 1143–1149, 2003.
C. Wang, X. Chu, and Y. Qin, “Measurement and analysis of the bitcoin networks: A view from mining pools,” in 2020 6th International Conference on Big Data Computing and Communications (BIGCOM), IEEE, 2020, pp. 180–188.
T. D. Perez and S. Pagliarini, “A survey on split manufacturing: Attacks, defenses, and challenges,” IEEE Access, vol. 8, pp. 184013–184035, 2020.
A. Begum, A. Tareq, M. Sultana, M. Sohel, T. Rahman, and A. Sarwar, “Blockchain attacks analysis and a model to solve double spending attack,” Int. J. Mach. Learn. Comput., vol. 10, no. 2, pp. 352–357, 2020.
R. Bhat, M. R. Ansari, and R. Khanam, “Effect of integrated power and clock networks on combinational circuits,” Int. J. Reconfigurable Embed. Syst., vol. 9, no. 3, p. 242, 2020.
J. Ho et al., “Can digital pathology result in cost savings? A financial projection for digital pathology implementation at a large integrated health care organization,” J. Pathol. Inform., vol. 5, no. 1, p. 33, 2014.
A. Zamyatin, N. Stifter, A. Judmayer, P. Schindler, E. Weippl, and W. J. Knottenbelt, “A wild velvet fork appears! inclusive blockchain protocol changes in practice,” in International Conference on Financial Cryptography and Data Security, Springer, 2018, pp. 31–42.
S. Bhatia and A. D. Wright de Hernandez, “Blockchain is already here. What does that mean for records management and archives?,” J. Arch. Organ., vol. 16, no. 1, pp. 75–84, 2019.
B. Cao et al., “Performance analysis and comparison of PoW, PoS and DAG based blockchains,” Digit. Commun. Networks, vol. 6, no. 4, pp. 480–485, 2020.
M. Bellare, A. Desai, E. Jokipii, and P. Rogaway, “A concrete security treatment of symmetric encryption,” in Proceedings 38th Annual Symposium on Foundations of Computer Science, IEEE, 1997, pp. 394–403.
D. Pointcheval, “Asymmetric cryptography and practical security,” J. Telecommun. Inf. Technol., pp. 41–56, 2002.
A. Rabie, K. El Shafie, A. Hammuoda, and M. Rohiem, “Data ecryption based on multi-order FrFT, and FPGA implementation of DES algorith,” Int. J. Reconfigurable Embed. Syst., vol. 9, no. 2, p. 141, 2020.
S. Sharma and Y. Gupta, “Study on cryptography and techniques,” Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol., vol. 2, no. 1, pp. 249–252, 2017.
B. Alaya and L. Sellami, “Clustering method and symmetric/asymmetric cryptography scheme adapted to securing urban VANET networks,” J. Inf. Secur. Appl., vol. 58, p. 102779, 2021.
T. R. N. Rao and K.-H. Nam, “Private-key algebraic-code encryptions,” IEEE Trans. Inf. Theory, vol. 35, no. 4, pp. 829–833, 1989.
R. Rothblum, “Homomorphic encryption: From private-key to public-key,” in Theory of cryptography conference, Springer, 2011, pp. 219–234.
D. E. Denning, “Digital signatures with RSA and other public-key cryptosystems,” Commun. ACM, vol. 27, no. 4, pp. 388–392, 1984.
A. A. Ayele and V. Sreenivasarao, “A modified RSA encryption technique based on multiple public keys,” Int. J. Innov. Res. Comput. Commun. Eng., vol. 1, no. 4, pp. 859–864, 2013.
R. Zuccherato, “Elliptic Curve Cryptography Support in Entrust,” Entrust ltd. Canada, Dated, 2000.
D. R. Stinson, “Some observations on the theory of cryptographic hash functions,” Des. Codes Cryptogr., vol. 38, no. 2, pp. 259–277, 2006.
J. E. Silva, “An overview of cryptographic hash functions and their uses,” GIAC, vol. 6, 20
DOI: https://doi.org/10.47738/jads.v6i1.324
Refbacks
- There are currently no refbacks.

Journal of Applied Data Sciences
| ISSN | : | 2723-6471 (Online) |
| Publisher | : | Bright Publisher |
| Website | : | http://bright-journal.org/JADS |
| : | taqwa@amikompurwokerto.ac.id (principal contact) | |
| support@bright-journal.org (technical issues) |
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0




.png)