DynChain-Vul: Adaptive Blockchain Sharding and Secure Cross-Shard Vulnerability Data Sharing for Cloud-Based Vulnerability Lifecycle Governance
Main Article Content
Abstract
Cloud-based vulnerability lifecycle governance requires continuous sharing of vulnerability intelligence, security evidence, remediation records, exploit verification results, and risk assessment information among cloud service providers, security operation centers, software vendors, and regulatory agencies. These security data are highly distributed, dynamically generated, and privacy-sensitive, demanding scalable, trustworthy, and auditable cross-domain data sharing. Although blockchain provides decentralized trust, tamper resistance, and traceability, conventional blockchain architectures suffer from limited throughput, excessive storage redundancy, and inefficient cross-shard data exchange, making them difficult to support large-scale cloud vulnerability governance involving heterogeneous computing resources. This paper proposes DynChain-Vul, an adaptive blockchain sharding architecture for secure vulnerability data sharing in cloud-based vulnerability lifecycle governance. DynChain-Vul first profiles node computing capability, network bandwidth, communication latency, and storage resources, and then employs Gaussian mixture modeling together with dynamic weighted consistent hashing to allocate virtual nodes according to heterogeneous resource characteristics, thereby improving shard balance and overall system scalability. To accommodate continuously changing workloads, a dynamic shard mapping index supports adaptive shard splitting and merging while minimizing data migration overhead. For secure cross-shard vulnerability information exchange, DynChain-Vul integrates multi-path redundant indexing based on Kademlia routing with a threshold-signature verification mechanism, enabling reliable vulnerability data retrieval without relying on a centralized trusted coordinator. Experimental results on a blockchain emulation platform demonstrate that DynChain-Vul increases system throughput from 725.98 TPS to 1493.17 TPS as the number of shards increases from 2 to 8, reduces transaction confirmation latency from 39.23 ms to 5.92 ms, maintains shard-load covariance within 0.12– 0.15, and keeps aggregated cross-shard signature storage nearly constant. These results indicate that adaptive blockchain sharding combined with verifiable cross-shard vulnerability data sharing provides an efficient and trustworthy foundation for cloud-based vulnerability lifecycle governance, supporting scalable collaborative vulnerability intelligence sharing and secure security operations.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
X. Fang, S. Misra, G. Xue, and D. Yang, “Smart Grid—The New and Improved Power Grid: A Survey,” IEEE Communications Surveys & Tutorials, vol. 14, no. 4, pp. 944–980, 2012, doi: https://doi.org/10.1109/SURV.2011.101911.00087.
V. C. Gungor, D. Sahin, T. Kocak, S. Ergut, C. Buccella, C. Cecati, and G. P. Hancke, “Smart Grid Technologies: Communication Technologies and Standards,” IEEE Transactions on Industrial Informatics, vol. 7, no. 4, pp. 529–539, 2011, doi: https://doi.org/10.1109/TII.2011.2166794.
W. Wang and Z. Lu, “Cyber security in the Smart Grid: Survey and challenges,” Computer Networks, vol. 57, no. 5, pp. 1344–1371, 2013, doi: https://doi.org/10.1016/j.comnet.2012.12.017.
E. Androulaki, A. Barger, V. Bortnikov, C. Cachin, K. Christidis, A. De Caro, D. Enyeart, C. Ferris, G. Laventman, Y. Manevich, S. Muralidharan, C. Murthy, B. Nguyen, M. Sethi, G. Singh, K. Smith, A. Sorniotti, C. Stathakopoulou, M. Vukolic, S. Weed Cocco, and J. Yellick, “Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains,” in Proceedings of the Thirteenth EuroSys Conference, 2018, pp. 1–15, doi: https://doi.org/10.1145/3190508.3190538.
L. Da Xu, Y. Lu, and L. Li, “Embedding Blockchain Technology Into IoT for Security: A Survey,” IEEE Internet of Things Journal, vol. 8, no. 13, pp. 10452–10473, 2021, doi: https://doi.org/10.1109/JIOT.2021.3060508.
A. Reyna, C. Martin, J. Chen, E. Soler, and M. Diaz, “On blockchain and its integration with IoT. Challenges and opportunities,” Future Generation Computer Systems, vol. 88, pp. 173–190, 2018, doi: https://doi.org/10.1016/j.future.2018.05.046.
S. Pal, A. Dorri, and R. Jurdak, “Blockchain for IoT access control: Recent trends and future research directions,” Journal of Network and Computer Applications, vol. 203, p. 103371, 2022, doi: https://doi.org/10.1016/j.jnca.2022.103371.
Q. Lu and X. Xu, “Adaptable Blockchain-Based Systems: A Case Study for Product Traceability,” IEEE Software, vol. 34, no. 6, pp. 21–27, 2017, doi: https://doi.org/10.1109/MS.2017.4121227.
T. Nguyen, H. Nguyen, and T. N. Gia, “Exploring the integration of edge computing and blockchain IoT: Principles, architectures, security, and applications,” Journal of Network and Computer Applications, vol. 226, p. 103884, 2024, doi: https://doi.org/10.1016/j.jnca.2024.103884.
L. Luu, V. Narayanan, C. Zheng, K. Baweja, S. Gilbert, and P. Saxena, “A Secure Sharding Protocol For Open Blockchains,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016, pp. 17–30, doi: https://doi.org/10.1145/2976749.2978389.
E. Kokoris-Kogias, P. Jovanovic, L. Gasser, N. Gailly, E. Syta, and B. Ford, “OmniLedger: A Secure, Scale-Out, Decentralized Ledger via Sharding,” in 2018 IEEE Symposium on Security and Privacy (SP), 2018, pp. 583– 598, doi: https://doi.org/10.1109/SP.2018.000-5.
M. Zamani, M. Movahedi, and M. Raykova, “RapidChain: Scaling Blockchain via Full Sharding,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018, pp. 931– 948, doi: https://doi.org/10.1145/3243734.3243853.
M. Al-Bassam, A. Sonnino, S. Bano, D. Hrycyszyn, and G. Danezis, “Chainspace: A Sharded Smart Contracts Platform,” in Proceedings 2018 Network and Distributed System Security Symposium, 2018, doi: https://doi.org/10.14722/ndss.2018.23241.
J. Wang and H. Wang, “Monoxide: Scale out Blockchains with Asynchronous Consensus Zones,” in 16th USENIX Symposium on Networked Systems Design and Implementation, 2019, pp. 95–112. [Online]. Available: https://www.usenix.org/conference/nsdi19/presentation/wang-jiaping
L. N. Nguyen, T. D. T. Nguyen, T. N. Dinh, and M. T. Thai, “OptChain: Optimal Transactions Placement for Scalable Blockchain Sharding,” in 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS), 2019, pp. 525–535, doi: https://doi.org/10.1109/ICDCS.2019.00059.
G. Yu, X. Wang, K. Yu, W. Ni, J. A. Zhang, and R. P. Liu, “Survey: Sharding in Blockchains,” IEEE Access, vol. 8, pp. 14155–14181, 2020, doi: https://doi.org/10.1109/ACCESS.2020.2965147.
C. Li, H. Huang, Y. Zhao, X. Peng, R. Yang, Z. Zheng, and S. Guo, “Achieving Scalability and Load Balance across Blockchain Shards for State Sharding,” in 2022 41st International Symposium on Reliable Distributed Systems (SRDS), 2022, pp. 284–294, doi: https://doi.org/10.1109/SRDS55811.2022.00034.
J. Xu, Q. Xie, S. Peng, C. Wang, and X. Jia, “AdaptChain: Adaptive Scaling Blockchain With Transaction Deduplication,” IEEE Transactions on Parallel and Distributed Systems, vol. 34, no. 6, pp. 1909–1922, 2023, doi: https://doi.org/10.1109/TPDS.2023.3267071.
R. Belchior, A. Vasconcelos, S. Guerreiro, and M. Correia, “A Survey on Blockchain Interoperability: Past, Present, and Future Trends,” ACM Computing Surveys, vol. 54, no. 8, pp. 1–41, 2021, doi: https://doi.org/10.1145/3471140.
R. Qiao, X.-Y. Luo, S.-F. Zhu, A.-D. Liu, X.-Q. Yan, and Q.-X. Wang, “Dynamic Autonomous Cross Consortium Chain Mechanism in e-Healthcare,” IEEE Journal of Biomedical and Health Informatics, vol. 24, no. 8, pp. 2157–2168, 2020, doi: https://doi.org/10.1109/JBHI.2019.2963437.
S. Guo, F. Wang, N. Zhang, F. Qi, and X. Qiu, “Master-slave chain based trusted cross-domain authentication mechanism in IoT,” Journal of Network and Computer Applications, vol. 172, p. 102812, 2020, doi: https://doi.org/10.1016/j.jnca.2020.102812.
V. Shoup, “Practical Threshold Signatures,” in Advances in Cryptology – EUROCRYPT 2000, Springer, 2000, pp. 207–220, doi: https://doi.org/10.1007/3-540-45539-6_15.
Q. Feng, K. Yang, M. Ma, and D. He, “Efficient Multi-Party EdDSA Signature With Identifiable Aborts and its Applications to Blockchain,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 1937–1950, 2023, doi: https://doi.org/10.1109/TIFS.2023.3256710.
P. Maymounkov and D. Mazieres, “Kademlia: A Peer-to-Peer Information System Based on the XOR Metric,” in Peer-to-Peer Systems, Springer, 2002, pp. 53–65, doi: https://doi.org/10.1007/3-540-45748-8_5.
D. A. Reynolds, T. F. Quatieri, and R. B. Dunn, “Speaker Verification Using Adapted Gaussian Mixture Models,” Digital Signal Processing, vol. 10, no. 1–3, pp. 19–41, 2000, doi: https://doi.org/10.1006/dspr.1999.0361.
D. Johnson, A. Menezes, and S. Vanstone, “The Elliptic Curve Digital Signature Algorithm (ECDSA),” International Journal of Information Security, vol. 1, no. 1, pp. 36–63, 2001, doi: https://doi.org/10.1007/s102070100002.
P. Zheng, Z. Zheng, J. Wu, and H. N. Dai, “XBlock-ETH: Extracting and Exploring Blockchain Data From Ethereum,” IEEE Open Journal of the Computer Society, vol. 1, pp. 95–106, 2020, doi: https://doi.org/10.1109/OJCS.2020.2990458.
H. Huang, Z. Yin, Q. Chen, J. Zheng, X. Luo, G. Ye, X. Peng, Z. Zheng, and S. Guo, “BrokerChain: A Blockchain Sharding Protocol by Exploiting Broker Accounts,” IEEE Transactions on Networking, vol. 33, no. 4, pp. 1930–1945, 2025, doi: https://doi.org/10.1109/TON.2025.3550502.
J. Newell, S. ur Rehman, Q. Mamun, and M. Z. Islam, “EASL: Enhanced append-only skip list index for agile block data retrieval on blockchain,” Future Generation Computer Systems, vol. 164, p. 107554, 2025, doi: https://doi.org/10.1016/j.future.2024.107554.