Most algorithms deployed in healthcare do not consider gender and sex despite the effect they have on individuals' health differences. Missing these dimensions in healthcare information systems is a point of concern, as neglecting these aspects will inevitably perpetuate existing biases, produce far from optimal results, and may generate diagnosis errors. An often-overlooked community with distinct care values and needs are LGBT+ older adults, which has traditionally been under-surveyed in healthcare and technology design. This paper investigates the implications of missing gender and sex considerations in distributed ledger technologies for LGBT+ older adults. By using the value sensitive design methodology, our contribution shows that many value meanings dear to marginalized communities are not considered in the design of the blockchain, such as LGBT+ older adults' interpretations of trust, privacy, and security. By highlighting the LGBT+ older population values, our contribution alerts us to the potential discriminatory implications of these technologies, which do not consider the gender and sex differences of marginalized, silent populations. Focusing on one community throughout - LGBT+ older adults - we emphasize the need for a holistic, value sensitive design approach for the development of ledger technologies for healthcare, including the values of everyone within the healthcare ecosystem.
Procuratorates, as the prosecutor in public interest litigation (PIL), need to obtain evidence from other PIL stakeholders including citizens, companies, governmental agencies, IoT monitoring devices and so on. However, the evidence sharing is not smooth due to the lack of secure data sharing and privacy protection during case investigation and evidence collection. Therefore, the authors propose a consortium blockchain-based secure data sharing and privacy protection scheme named PILChain. The involved organizations are connected as peers in PILChain. The safety of uploaded evidence and user privacy can be guaranteed with a fine-grained access control and zero-knowledge identity proof. InterPlanetary File System is introduced to store large evidence files off-chain, further enhancing the data security and system scalability. The security of PILChain is analyzed in terms of access control, evidence confidentiality, evidence integrity, traceability, privacy, and scalability. Last, the authors evaluate the performance of the developed prototype system by implementing PILChain on Hyperledger Fabric.
Non-fungible tokens (NFTs) are unique cryptographic assets representing the ownership of digital media. NFTs have soared in popularity and trading prices. However, there exists a large gap in the literature regarding NFTs, especially regarding the stakeholders and online communities that have formed around NFT projects. Bored Ape Yacht Club (BAYC) is one of the most influential NFT projects. Through an observational study of online BAYC communities across social media platforms and semi-structured interviews with four participants who owned BAYC NFTs, we explored the experiences of NFT collectors within the online NFT community. Positive community experiences, i.e., personal expression and identity, mutual support among BAYC holders, and exclusive access to online and offline events, were expressed. Encountered challenges included scams and "cash grab" NFT projects as well as trolling. The results of this study point towards the welcoming, positive nature of the NFT community, which is a possible causation factor of the initial rise in popularity of NFTs. Demotivators, on the other hand, countered the established trustworthiness of NFT technology among its consumers.
It is crucial to ensure the privacy and authenticity of the owner’s information in car insurance claims. However, the current traditional car insurance claims scenario suffers from inefficiency, complex service, unreliable data, and data leakage. Therefore, considering the privacy and sensitivity of insurance information and car owner data, we can use blockchain, smart contracts, and zero-knowledge proof technology to improve the current problems. This paper proposes a novel car insurance claim scheme based on smart contracts, blockchain, and zero-knowledge proof. Our scheme focuses on preserving privacy in the car insurance authorization and claim process. We design a private smart contract for the creation and revocation of car insurance and public smart contract for the authorization and validation of car insurance. By using ZoKrates, generating zero-knowledge proofs off chain and verifying the proofs on chain reduces the amount of data storage and computation on chain and provides privacy protection for sensitive information. Experimental results confirm the efficacy of our scheme in terms of security and performance.
Objective: In the ongoing digital era, digital rights are a major concern and demand measures to address challenges that encompass the management of effective law implementation. The following study aims at the contrivance and administration of international law to address digital rights. Method: Legal aspects of digital technology, also known as information technology law, is a practical field of law that has established a strong position among other legal fields in recent years, both in legal firms and educational institutions. Fresh technological advancements like massive data, the Web of Things, quantum computation, distributed ledger technology, and advanced formulas provoke inquiries concerning the governance of these technologies, such as the entitlements and safeguards that individuals possess or ought to possess. The growing utilization of electronic technologies by corporations and governments prompts various inquiries concerning the management of these technologies, specifically concerning the privileges and lawful safeguards individuals have a claim to. Result: The emphasis is primarily on the utilization and possible alteration of current (basic) entitlements. Nevertheless, the argument and lawful exploration in this domain needs a more extensive conversation regarding the novel entitlements that individuals ought to possess in the digital epoch. Occasionally, novel ideas emerge, like the concept of the 'right to erasure'. Conclusion: This piece of writing discusses the inquiry of what fresh, supplementary entitlements could be envisioned in the age of technology if we were to compose them anew, without being restricted to a predetermined collection of essential liberties. To initiate a more extensive lawful discussion on this matter, several novel entitlements for individuals in the electronic sphere are suggested.
Dynamic consent management allows a data subject to dynamically govern her consent to access her data. Clearly, security and privacy guarantees are vital for the adoption of dynamic consent management systems. In particular, specific data protection guarantees can be required to comply with rules and laws (e.g., the General Data Protection Regulation (GDPR)). Since the primary instantiation of the dynamic consent management systems in the existing literature is towards developing sustainable e-healthcare services, in this paper, we study data protection issues in dynamic consent management systems, identifying crucial security and privacy properties and discussing severe limitations of systems described in the state of the art. We have presented the precise definitions of security and privacy properties that are essential to confirm the robustness of the dynamic consent management systems against diverse adversaries. Finally, under those precise formal definitions of security and privacy, we have proposed the implications of state-of-the-art tools and technologies such as differential privacy, blockchain technologies, zero-knowledge proofs, and cryptographic procedures that can be used to build dynamic consent management systems that are secure and private by design.
The popularization of intelligent healthcare devices and big data analytics significantly boosts the development of Smart Healthcare Networks (SHNs). To enhance the precision of diagnosis, different participants in SHNs share health data that contain sensitive information. Therefore, the data exchange process raises privacy concerns, especially when the integration of health data from multiple sources (linkage attack) results in further leakage. Linkage attack is a type of dominant attack in the privacy domain, which can leverage various data sources for private data mining. Furthermore, adversaries launch poisoning attacks to falsify the health data, which leads to misdiagnosing or even physical damage. To protect private health data, we propose a personalized differential privacy model based on the trust levels among users. The trust is evaluated by a defined community density, while the corresponding privacy protection level is mapped to controllable randomized noise constrained by differential privacy. To avoid linkage attacks in personalized differential privacy, we design a noise correlation decoupling mechanism using a Markov stochastic process. In addition, we build the community model on a blockchain, which can mitigate the risk of poisoning attacks during differentially private data transmission over SHNs. Extensive experiments and analysis on real-world datasets have testified the proposed model, and achieved better performance compared with existing research from perspectives of privacy protection and effectiveness.
BACKGROUND: Blockchain is an emerging technology that enables secure and decentralized approaches to reduce technical risks and governance challenges associated with sharing data. Although blockchain-based solutions have been suggested for sharing health information, it is still unclear whether a suitable incentive mechanism (intrinsic or extrinsic) can be identified to encourage individuals to share their sensitive data for research purposes. OBJECTIVE: This study aimed to investigate how important extrinsic incentives are and what type of incentive is the best option in blockchain-based platforms designed for sharing sensitive health information. METHODS: In this study, we conducted 3 experiments with 493 individuals to investigate the role of extrinsic incentives (ie, cryptocurrency, money, and recognition) in data sharing with research organizations. RESULTS: The findings highlight that offering different incentives is insufficient to encourage individuals to use blockchain technology or to change their perceptions about the technology's premise for sharing sensitive health data. The results demonstrate that individuals still attribute serious risks to blockchain-based platforms. Privacy and security concerns, trust issues, lack of knowledge about the technology, lack of public acceptance, and lack of regulations are reported as top risks. In terms of attracting people to use blockchain-based platforms for data sharing in health care, we show that the effects of extrinsic motivations (cryptoincentives, money, and status) are significantly overshadowed by inhibitors to technology use. CONCLUSIONS: We suggest that before emphasizing the use of various types of extrinsic incentives, the users must be educated about the capabilities and benefits offered by this technology. Thus, an essential first step for shifting from an institution-based data exchange to a patient-centric data exchange (using blockchain) is addressing technology inhibitors to promote patient-driven data access control. This study shows that extrinsic incentives alone are inadequate to change users' perceptions, increase their trust, or encourage them to use technology for sharing health data.
Abstract Online presence is becoming an important part of everyday's life and online communities may represent a significant source of engagement for the elderlies. Nevertheless, many may struggle to be online due to a lack of expertise, and a decentralised architecture may provide a solution by removing intermediaries, such as a webmaster, while not requiring expensive cloud solutions. However, issues concerning accessibility, security, and user experience have to be tackled. The paper focuses mainly on three issues: providing a human‐readable domain, moderating content, and creating a reward system based on user reputation. An architecture is proposed based on Ethereum and Swarm. Smart contracts provide an automated set of rules to handle enterprise registration, content creation, and decision‐making process, while Swarm serves both as distributed storage and the web host. Besides, in combination with Ethereum Name Service, Swarm provides a secure, distributed, and human‐readable point of access to the web interface. The paper also describes an innovative two‐token system where one token is meant to be a trustworthy reputation metre and the other is a spendable coin to get rewards. The final result is a fully decentralised, authenticated and moderated platform where users can aggregate and share their content presentations on the Internet.
“Code is law” became a buzz term in Web3 and blockchain reality. Despite the term being already used much earlier by Lawrence Lessig in the year 2000 in his book titled “Code and Other Laws of Cyberspace,” when the internet and Web2 were emerging, the rise of smart contracts and complex algorithmic power made the term genuinely resonate with the (idealised) Web3 reality. The entrainment of technological solutionism in the brains of members of society gives an impression that a world governed by algorithms will be a fairer one. However, research has shown that many members of society are not standard statistical representations of the majority and whilst algorithmic governance leaves room for “standard deviation,” individuals that fall outside this standard deviation are, in fact, very disadvantaged. There are numerous research papers as well as popular science books that address the issue of algorithmic bias and unfairness in Web 2. The proponents of blockchain and web3 technology argue that with a DAO-governed, decentralised society, problems of biased algorithmic governance are solved as power and decision-making are decentralised, and members use their governance tokens to collectively decide on the law encoded in the smart contracts that are the ultimate law enforcement apparatus. Web3 promises a shift of power from governments and corporations to people and token holders, arguing it will make a Web3-governed society fairer. This paper is based on decoding this promise and using Althusser’s model of a state apparatus to show how the power relations changed in Web2 and Web3 realities. It shows that Web3 promises of the code becoming the law were already present in the Web2 discourse and discovers a model of an ideological apparatus power struggle between states and Web2 giants. Next, the power relations in the blockchain society are researched, starting from the idealised model of decentralised, token-holder governed power, which regulates the governments and corporations, to a discussion on what the actual power relations and struggles might result from encoding the law in the smart contract. Research shows that in Web3, “code is law” society. There will be power struggles and opposition on a vertical and horizontal level. The vertical struggle is the power enforcement (originally in the hands of the state in Althusser’s (1970) model between the code and individuals, governments and corporations not willing to conform with the code-enforced law or falling outside the standard deviation of statistics-based AI algorithms hence being disadvantaged by the smart contract enforced laws. The horizontal power struggle is based on what Althusser describes as the ideological apparatus. Here, the struggle is based on a fight between individuals (the society), corporations, and the state for code-modifying resources and/or leverage over the governance token holders. Overall, the paper argues and shows that blockchain-based “code is law” reality does not solve the issue of unequal power relations within societies but only as any technological revolution shifts the power relations and power struggles between existing and new actors. Unlike the founder of Polkadot, Gavin Wood states that blockchain, DAOs, smart contracts, and Web3 overall do not result in the new social sphere with revolutionised power relations. Where Web3 is now is much more similar to where Web1 and Web2 were 25–30 years ago—Creating a new space for social interactions and discourse yet being stuck within the same social sphere and uneven power relations that have governed our societies for centuries.
Decentralized identity frameworks grant users full sovereignty over their digital assets in the Web3 ecosystem. However, allowing arbitrary creation of identifiers makes the system susceptible to Sybil attacks and puts assets at risk when keys are lost or compromised. Moreover, the lack of identification prevents anonymous credential schemes from deterring malicious transfers. While existing solutions attempt to address these issues by linking identifiers to entities through trusted intermediaries, these entities are not always accessible and require costly offline interactions. In this work, we introduce LinkDID, a decentralized identity scheme offering Sybil resistance, trustless key recovery, and nontransferable anonymous credentials. LinkDID creates blockchainbased bindings between identifiers and gradually combines identifiers belonging to the same holder into a unified associated identifier. As all identifiers within an association are presumed to belong to one individual, any fraudulent activity can be detected. The association grows larger as interactions increase, substantially reducing the likelihood of successful Sybil attacks. This mechanism allows holders to recover identifiers with lost or stolen keys by proving knowledge of specific association structures. Additionally, LinkDID prevents unauthorized transfers through blockchain-based identifier-key bindings and proofs of ownership for credentials. The evaluation shows that LinkDID effectively achieves progressive Sybil resistance while surpassing state-of-the-art anonymous credential schemes, achieving identifier association and credential presentation times of 2.41s and 3.31s on consumer-grade devices.
The development of an electronic voting system that would replace traditional election procedures is a research topic of great interest for many years. Blockchain technology could provide some guarantees and fulfill strong requirements for electronic voting platforms, such as transparency, immutability, and confidentiality. From time to time research is conducted to address problems in voting systems. Many research works attempt to implement secure and reliable voting systems, which address known security, anonymity, and fraud issues that might threaten such systems. This paper presents a proposal of a secure electronic voting system, the EtherVote, using the Ethereum Blockchain network that focuses deeply on the field of identification of eligible citizens. The proposed system will be entirely based on Blockchain without any central authority servers or databases, thus improving security, privacy, and election cost. Limitations, problems, and solutions are discussed, in order to make the proposed electronic voting system ideal and ready to use for national elections.
Arnab Mukherjee, Souvik Majumdar, Anup Kumar Kolya, S. Nandi
Within a modern democratic nation, elections play a significant role in the nation's functioning. However, with the existing infrastructure for conducting elections using Electronic Voting Systems (EVMs), many loopholes exist, which illegitimate entities might leverage to cast false votes or even tamper with the EVMs after the voting session is complete. The need of the hour is to introduce a robust, auditable, transparent, and tamper-proof e-voting system, enabling a more reliable and fair election process. To address such concerns, we propose a novel solution for blockchain-based e-voting, focusing on the security and privacy aspects of the e-voting process. We consider the security risks and loopholes and aim to preserve the anonymity of the voters while ensuring that illegitimate votes are properly handled. Additionally, we develop a prototype as a proof of concept using the Ethereum blockchain platform. Finally, we perform experiments to demonstrate the performance of the system.
We propose a middleware solution designed to facilitate seamless integration of privacy using zero-knowledge proofs within various multi-chain protocols, encompassing domains such as DeFi, gaming, social networks, DAOs, e-commerce, and the metaverse. Our design achieves two divergent goals. zkFi aims to preserve consumer privacy while achieving regulation compliance through zero-knowledge proofs. These ends are simultaneously achievable. zkFi protocol is designed to function as a plug-and-play solution, offering developers the flexibility to handle transactional assets while abstracting away the complexities associated with zero-knowledge proofs. Notably, specific expertise in zero-knowledge proofs (ZKP) is optional, attributed to zkFi's modular approach and software development kit (SDK) availability.
Stanisław Barański, Julian Szymański, Higinio Mora
Abstract Lawyers, laboratories, auditors, and banks often need access to sensitive personal data to provide services such as genetic testing, paternity testing, STD testing, credit scoring, or legal advice. Processing such data exposes both service providers (SPs) and users to privacy risks: SPs risk violating laws like the General Data Protection Regulation (GDPR) and the Consumer Protection Act (CPA), while users risk losing their privacy. We observe that personal data is often only needed for logistical purposes like payment or communication and could be provided anonymously if suitable methods existed. To address this, we present a solution that enables services to be delivered without collecting personal data. Our protocol combines anonymous payment methods (e.g., cash, privacy-preserving cryptocurrencies), blockchain for fairness, and distributed content-addressable storage networks to deliver results. Compared to existing approaches, our protocol achieves anonymity under weaker assumptions, supports the transfer of physical materials and conflict resolution, and eliminates the need for customer interaction with a trusted arbiter in conflict-free cases-making it more practical. We analyze the protocol’s fairness and implement a prototype using Ethereum as a message board, Monero for anonymous payments, and Powergate (IPFS/Filecoin) as a decentralized storage solution.
With the recent hype around the Metaverse and NFTs, Web3 is getting more and more popular. The goal of Web3 is to decentralize the web via decentralized applications. Wallets play a crucial role as they act as an interface between these applications and the user. Wallets such as MetaMask are being used by millions of users nowadays. Unfortunately, Web3 is often advertised as more secure and private. However, decentralized applications as well as wallets are based on traditional technologies, which are not designed with privacy of users in mind. In this paper, we analyze the privacy implications that Web3 technologies such as decentralized applications and wallets have on users. To this end, we build a framework that measures exposure of wallet information. First, we study whether information about installed wallets is being used to track users online. We analyze the top 100K websites and find evidence of 1,325 websites running scripts that probe whether users have wallets installed in their browser. Second, we measure whether decentralized applications and wallets leak the user's unique wallet address to third-parties. We intercept the traffic of 616 decentralized applications and 100 wallets and find over 2000 leaks across 211 applications and more than 300 leaks across 13 wallets. Our study shows that Web3 poses a threat to users' privacy and requires new designs towards more privacy-aware wallet architectures.
Hao Xu, Yunqing Sun, Zihao Li, Yao Sun · 6 authors
Web3 brings an emerging outlook for the value of decentralization, boosting the decentralized infrastructure. People can benefit from Web3, facilitated by the advances in distributed ledger technology, to read, write and own web content, services and applications more freely without revealing their real identities. Although the features and merits of Web3 have been widely discussed, the network architecture of Web3 and how to achieve complete decentralization considering law compliance in Web3 are still unclear. Here, we propose a perspective of Web3 architecture, deController, consisting of underlay and overlay network as Web3 infrastructures to underpin services and applications. The functions of underlay and overlay and their interactions are illustrated. Meanwhile, the security and privacy of Web3 are analyzed based on a novel design of three-tier identities cooperating with deController. Furthermore, the impacts of laws on privacy and cyber sovereignty to achieve Web3 are discussed.
With cloud-hosted web applications becoming ubiquitous, the security risks presented for user personal data that is migrated to the cloud are at an all-time high. When using a cloud-hosted web application, users only ever interact with web interfaces of the web applications and are usually completely unaware of how their data is distributed amongst the multiple cloud service providers that the web application uses, making it difficult to verify the lawful use and ownership of personal data. The General Data Protection Regulation (GDPR) seeks to empower users to gain better control over their personal data. Blockchain-based approaches have risen in popularity over the recent years to tackle the challenge of verifying GDPR compliance in multi-cloud environments. By deploying smart contracts on the blockchain, we can create transparent and immutable logs of data processes in the hopes of automating GDPR compliance verification. However, the existing works are still limited to provide a user-centric compliance verification. To this end, we propose a user-centric, blockchain-based framework for data management in a cloud environment where all GDPR-relevant data operations take place on the blockchain through well-defined smart contracts.
In today’s digital environment, the voting system has moved from paper based to a digital system. A digital e-voting system has many properties such as transparency, decentralization, irreversibility, and non-repudiation. The growth in the digital e-voting system raises many security and transparency issues. In this paper, we used the blockchain technology in the digital electronic voting system to solve the security issues and ful?ll the system requirements. It offers new opportunities to deploy a secure e-voting system in any organization or country. The solution is far better as compared to other solutions because it is a decentralized system, containing the results in the form of bit-coins, having different locations. We will also analyze the security of our proposed voting system, which shows our protocol is more secure as compared to other solutions. The paper proposes a novel electronic voting system based on block chain that addresses some of the limitations in existing systems and evaluates some of the popular blockchain frameworks for the purpose of constructing a blockchain based e-voting system. In particular, we evaluate the potential of distributed ledger technologies through the description of a case study namely, the process of an election, and the implementation of a blockchain based application, which improves the security and decreases the cost of hosting a nation wide election.
Awaneesh Kumar Yadav, An Braeken, Mika Ylianttila, Madhusanka Liyanage
The metaverse, which consists of several universes called verses, is predicted to be the Internet of the future. Recently, this idea has received a lot of discussions, but not enough attention has been paid to the security concerns of these virtual worlds. Primarily when the user and platform server communicate with each other and share sensitive information using the public channel, any attacker can capture the message and can perform various types of attacks such as privacy attack, violation of perfect forward secrecy, impersonation attack, ephemeral secret leakage attack and traceability attack. Therefore, there is impelling need to design an authentication protocol for the metaverse environment that can secure the communication between the user and the platform server. Taking this into account, we designed a zero-knowledge proof authentication protocol based on blockchain for the metaverse environment. The security of the designed protocol is verified through the Burrows-Abadi-Needham (BAN) logic, Scyther tool, and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The outcome of the security verification demonstrates that the designed metaverse authentication protocol mitigates all the attacks mentioned above. Moreover, we evaluated the performance of the designed metaverse authentication protocol in terms of computational, communication, storage costs, and energy consumption and compared it with existing metaverse authentication protocols, showing good results taking into account the additional security strength.
The Internet of Things (IoT) compromises multiple devices connected via a network to perform numerous activities. The large amounts of raw user data handled by IoT operations have driven researchers and developers to provide guards against any malicious threats. Blockchain is a technology that can give connected nodes means of security, transparency, and distribution. IoT devices could guarantee data centralization and availability with shared ledger technology. Federated learning (FL) is a new type of decentralized machine learning (DML) where clients collaborate to train a model and share it privately with an aggregator node. The integration of Blockchain and FL enabled researchers to apply numerous techniques to hide the shared training parameters and protect their privacy. This study explores the application of this integration in different IoT environments, collectively referred to as the Internet of X (IoX). In this paper, we present a state-of-the-art review of federated learning and Blockchain and how they have been used in collaboration in the IoT ecosystem. We also review the existing security and privacy challenges that face the integration of federated learning and Blockchain in the distributed IoT environment. Furthermore, we discuss existing solutions for security and privacy by categorizing them based on the nature of the privacy-preservation mechanism. We believe that our paper will serve as a key reference for researchers interested in improving solutions based on mixing Blockchain and federated learning in the IoT environment while preserving privacy.