Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

733 papersLast indexed Aug 31, 2026
Search papers

Paper index

733 results · page 11 of 31

Clear filters
May 29, 2023·2023 IEEE International Workshop on Metrology for Living Environment (MetroLivEnv)
1 cites
A tool for the data notarization with the Blockchain to ensure security and privacy

A. Rossi, Andrea Natalini, Lorenzo Cristofori, Marzia Mammina

This paper will describe a trustworthy blockchain-based framework to ensure secure, immutable and pseudo anonymized data collection at field level. This paper will describe the context in which the framework is being conceived and developed, starting from the analysis of the state of the art of DLT (Distributed Ledger Technology) and Blockchain, to highlight the potential uses cases in terms of data management, in particular. A specific focus will be given to the FIWARE framework, since the final objective is the creation of a tool for data gathering, as a FIWARE context broker extension. The core of the tool will be the two smart contracts implementing the PoE (Proof of Existence) and the RT-MDN (Reat Time-Monitoring Data Notarization). The smart contracts will be used for the certification of single documents and bulk of monitoring data, respectively. The second case is characterized by a periodicity of production and represent the most innovative part of the work. A first PoC (Proof of Concept) will be implemented, and first early results will be presented as well. The work is being developed in the framework of the EU co-funded “DigiBUILD” project.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
May 25, 2023·IEEE Transactions on Services Computing
37 cites
ChainDiscipline - Towards a Blockchain-IoT-Based Self-Sovereign Identity Management Framework

M. Popa, Sebastian Michael Stoklossa, Somnath Mazumdar

In today's complex Internet platform, online users need help to protect their online identity. Only sometimes, websites are very transparent about how user data will be collected, stored and processed by them. Sometimes Internet entities collect more online user information than required. These entities often share user identity-related data with third parties without consent. Existing traditional identity schemes need to be improved to stop and counter new ways of digital identity theft and fraud. Blockchain is a promising technology to strengthen the preservation of online users’ digital identity due to its decentralised nature and robust data security features. In this paper, we proposed and implemented a generic blockchain-IoT-based self-sovereign identity management framework called ChainDiscipline. We have demonstrated the framework's operability and functionality by implementing healthcare and smart home data management-based use cases.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cryptography and Data Security
Original source
May 17, 2023·International Journal on Recent and Innovation Trends in Computing and Communication
7 cites
Web3 Chain Authentication and Authorization Security Standard (CAA)

Nilesh P. Sable, Rahul Ganpatrao Sonkamble, Vijay U. Rathod, Swati Shirke · 6 authors

Web3 is the next evolution of the internet, which uses blockchains, cryptocurrencies, and NFTs to return ownership and authority to the consumers. The potential of Web3 is highlighted by the creation of decentralized applications (dApps), which are more secure, transparent, and tamper-proof than their centralized counterparts, allowing for new business models that were previously impossible on the traditional internet.Web3 also focuses on user privacy, where users have more control over their personal data and can choose to share only what they want. The emergence of Web3 represents an exciting new frontier in blockchain technology, and its focus on decentralization, user privacy, and trustless systems has the potential to transform the way we interact with the internet.Web3 authentication is required for enhanced security, increased privacy, and simplified user interface. Traditional login procedures and an authorization flow using web3 authentication work together seamlessly. However, there are several challenges associated with Web3, including scalability and regulatory issues. Chain Authentication and Authorization (CAA) is a multi-layer security mechanism that allows users to choose the security layer that suits them, just like a heavy iron chain, where the user and CAA developers act as blacksmith and form their security protocol that suits them. CAA is a solution to the challenges associated with Web3 authentication and authorization, and it focuses on creating a secure and decentralized authentication and authorization system that is scalable, flexible, and user-friendly.

Open access
Privacy, Security, and Data Protection
Spam and Phishing Detection
Access Control and Trust
Original source
May 9, 2023·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Bitcoin - Wie Social Media Privatanlegende in ihrem Handeln beeinflussen

Thierry Berger, Bernhard Schneider

Bitcoin ist, plakativ ausgedrĂŒckt, digitales Gold: Das Angebot ist fixiert und somit das hĂ€rtere monetĂ€re Gut als klassische FiatwĂ€hrungen. Der Wert gegenĂŒber dem USD stieg zwischen 2011 und 2021 um durchschnittlich 230 % pro Jahr, was es zur erfolgreichsten Anlageklasse der Welt macht. Erfolg zieht Privatinvestorinnen und -investoren an. Diese informieren sich oftmals ĂŒber Social-Media-KanĂ€le wie Twitter ĂŒber Trends und lassen sich vom herrschenden Sentiment beeinflussen. Die Eintrittsbarrieren sind tief. Jeder hat schnell ein Bitcoin-Wallet erstellt und ist Teil der Bewegung. Wenn ein Preis ohne fundamentale Ursache stark steigt, erhöht sich dadurch der ebenfalls nicht fundamental bedingte Spielraum nach unten. Die hohe VolatilitĂ€t ist ein Merkmal des noch jungen Marktes. Die Mehrheit der Privatinvestorinnen und -investoren kann mit diesem Druck nicht umgehen. Viele verlassen den Markt bereits nach wenigen Wochen oder Monaten in Panik, wenn ein satter Verlust anstelle eines hohen Gewinns eingetreten ist, um das ĂŒbriggebliebene Investment vor einem Totalverlust in Sicherheit zu bringen. Mithilfe von Fachpersoneninterviews werden in der vorliegenden Arbeit theoretische Aspekte mit Erfahrungen aus der Praxis ergĂ€nzt, um einen ganzheitlichen Blick auf die Wechselwirkung des Verhaltens von Markt und Privatanlegenden zu erhalten. Indem verlĂ€ssliche Twitter-Accounts mit Mehrwert gesucht werden, sich nicht auf eine einzige Informationsquelle verlassen sowie eine klare und langfristige Strategie verfolgt wird und das Investment auf fundierten Kenntnissen grĂŒndet, kann eine Neuinvestition in diesem Markt bestehen, denn der Markt geht mittel- und langfristig nach oben.

Open access
Digitalization, Law, and Regulation
Digital Innovation in Industries
Privacy, Security, and Data Protection
Original source
May 4, 2023·Alexandria Engineering Journal
63 cites
An efficient privacy-preserving control mechanism based on blockchain for E-health applications

Hanan Alsuqaih, Walaa Hamdan, Haythem Elmessiry, Hussein Abulkasim

The development of the Internet of Things (IoT) has opened up new horizons in the field of remote health data analysis to obtain smart healthcare. However, protecting patients’ data privacy seems challenging because medical files are so sensitive. There are significant risks to data confidentiality associated with storing patient health information on third-party servers. The covid-19 epidemic also enhanced the need for a temperature sensor-based respiratory monitoring device. Sharing electronic health records can aid with diagnostic accuracy when privacy and security protection are important system challenges. Due to the benefits of immutability, blockchain has been suggested as a possible option to enable personal health data exchange with privacy and security protection. This work suggests a safe and privacy-preserving diagnostic enhancement strategy for e-Health platforms based on blockchain technology, which addresses the inadequacy of previous work in these regards. The proposed work proposes an effective access control system that would let data owners specify their preferred access controls over their privacy-sensitive medical data. Users could utilize their user transactions for key generation to efficiently cancel or add authorized doctors. Experimental data and security analyses demonstrate the proposed Health-chain's suitability for use in smart healthcare systems. The thorough experimental investigation demonstrates the blockchain's effectiveness of computing and time consumption as well as its resistance to numerous security assaults.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
May 1, 2023·arXiv (Cornell University)
14 cites
Exploring the Privacy Concerns in Permissionless Blockchain Networks and Potential Solutions

Talgar Bayan, Richard Banach

In recent years, permissionless blockchains have gained significant attention for their ability to secure and provide transparency in transactions. The development of blockchain technology has shifted from cryptocurrency to decentralized finance, benefiting millions of unbanked individuals, and serving as the foundation of Web3, which aims to provide the next generation of the internet with data ownership for users. The rise of NFTs has also helped artists and creative workers to protect their intellectual property and reap the benefits of their work. However, privacy risks associated with permissionless blockchains have become a major concern for individuals and institutions. The role of blockchain in the transition from Web2 to Web3 is crucial, as it is rapidly evolving. As more individuals, institutions, and organizations adopt this technology, it becomes increasingly important to closely monitor the new risks associated with permissionless blockchains and provide updated solutions to mitigate them. This paper endeavors to examine the privacy risks inherent in permissionless blockchains, including Remote Procedure Call (RPC) issues, Ethereum Name Service (ENS), miner extractable value (MEV) bots, on-chain data analysis, data breaches, transaction linking, transaction metadata, and others. The existing solutions to these privacy risks, such as zero-knowledge proofs, ring signatures, Hyperledger Fabric, and stealth addresses, shall be analyzed. Finally, suggestions for the future improvement of privacy solutions in the permissionless blockchain space shall be put forward.

Open access
3 source records
cs.CR
cs.SE
Blockchain Technology Applications and Security
Original source
Apr 26, 2023·Proceedings of the ACM Web Conference 2023
14 cites
Bad Apples: Understanding the Centralized Security Risks in Decentralized Ecosystems

Kailun Yan, Jilian Zhang, Xiangyu Liu, Wenrui Diao · 5 authors

The blockchain-powered decentralized applications and systems have been widely deployed in recent years. The decentralization feature promises users anonymity, security, and non-censorship, which is especially welcomed in the areas of decentralized finance and digital assets. From the perspective of most common users, a decentralized ecosystem means every service follows the principle of decentralization. However, we find that the services in a decentralized ecosystem still may contain centralized components or scenarios, like third-party SDKs and privileged operations, which violate the promise of decentralization and may cause a series of centralized security risks. In this work, we systematically study the centralized security risks existing in decentralized ecosystems. Specifically, we identify seven centralized security risks in the deployment of two typical decentralized services – crypto wallets and DApps, such as anonymity loss and overpowered owner. Also, to measure these risks in the wild, we designed an automated detection tool called Naga and carried out large-scale experiments. Based on the measurement of 28 Ethereum crypto wallets (Android version) and 110,506 on-chain smart contracts, the result shows that the centralized security risks are widespread. Up to 96.4% of wallets and 83.5% of contracts exist at least one security risk, including 260 well-known tokens with a total market cap of over $98 billion.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Spam and Phishing Detection
Original source
Apr 20, 2023·Distributed Ledger Technologies Research and Practice
8 cites
Decentralized Inverse Transparency With Blockchain

Valentin Zieglmeier, Gabriel Loyola Daiqui, Alexander Pretschner

Employee data can be used to facilitate work, but their misusage may pose risks for individuals. Inverse transparency therefore aims to track all usages of personal data, allowing individuals to monitor them to ensure accountability for potential misusage. This necessitates a trusted log to establish an agreed-upon and non-repudiable timeline of events. The unique properties of blockchain facilitate this by providing immutability and availability. For power asymmetric environments such as the workplace, permissionless blockchain is especially beneficial as no trusted third party is required. Yet, two issues remain: (1) In a decentralized environment, no arbiter can facilitate and attest to data exchanges. Simple peer-to-peer sharing of data, conversely, lacks the required non-repudiation. (2) With data governed by privacy legislation such as the GDPR, the core advantage of immutability becomes a liability. After a rightful request, an individual's personal data need to be rectified or deleted, which is impossible in an immutable blockchain. To solve these issues, we present Kovacs, a decentralized data exchange and usage logging system for inverse transparency built on blockchain. Its new-usage protocol ensures non-repudiation, and therefore accountability, for inverse transparency. Its one-time pseudonym generation algorithm guarantees unlinkability and enables proof of ownership, which allows data subjects to exercise their legal rights regarding their personal data. With our implementation, we show the viability of our solution. The decentralized communication impacts performance and scalability, but exchange duration and storage size are still reasonable. More importantly, the provided information security meets high requirements. We conclude that Kovacs realizes decentralized inverse transparency through secure and GDPR-compliant use of permissionless blockchain.

Open access
2 source records
cs.CR
cs.DC
Blockchain Technology Applications and Security
Original source
Apr 18, 2023·Universidad Politecnica de Madrid - University Library
1 cites
Decentralized Systems for the Protection and Portability of Personal Data

Mirko Zichichi

The transformation introduced by information communication technologies in the last decades significantly impacts the economy and society concerning the digital representation of one’s identity. The economics of exploiting personal information is assisted by the more pervasive nature of today’s digital world: data are at the center of this transformation, and individuals are the primary sources of information and the ones most affected by it. The General Data Protection Regulation (GDPR) is having a significant impact on the protection of personal data. It has been designed for European Union (EU) citizens to help promote a view in favor of the interests of individuals instead of large corporations. However, at a large scale, there need to be more dedicated technologies that can help companies comply with GDPR (and similar regulations) while enabling people to exercise their rights. We argue that such a dedicated solution must address two main issues: the need for more transparency towards individuals regarding the management of their personal information and their often hindered ability to access and make interoperable personal data in a way that the exercise of one’s rights would result in straightforward and not excessively burdensome. In this work, we make the first step toward these two objectives by designing a user-centered model for managing personal data, where storage is decoupled from the data management logic. We aim to provide a system that helps to push personal data management towards the individual’s control, i.e., a personal information management system (PIMS). By using distributed storage and decentralized computing networks to control online services, users’ personal information could be shifted towards those directly concerned, i.e., the data subjects. The use of Distributed Ledger Technologies (DLTs) and Decentralized File Storage (DFS) as an implementation of decentralized systems is of paramount importance in this case. The structure of this dissertation follows an incremental approach to describing a set of decentralized systems and models that revolves around personal data and their subjects. Each chapter of this dissertation builds up the previous one and discusses the technical implementation of a system and its relation with the corresponding regulations. Indeed, most of the time, implementations based on decentralized systems clash with laws such as GDPR. We refer to the EU regulatory framework, including GDPR, eIDAS, and Data Governance Act, to build our final system architecture’s functional and non-functional drivers. In our PIMS design, personal data is kept in a Personal Data Space (PDS) consisting of encrypted personal data referring to the subject stored in a DFS.We use a decentralized indexing system to guarantee the integrity, verifiability, linkability, searchability, and indexing of the encrypted personal data stored in the PDS. We follow the approach to reference data and their content on a DLT, i.e., on-chain hash pointers. Then, we associate to such hash pointer reference a keyword set that is exploited to lookup for specific kinds of contents. On top of that, a network of authorization servers acts as a data intermediary to provide access to potential data recipients. Access to the data stored on a PDS can be allowed by the data holder through smart contracts. These maintain a data structure to record eligible data recipients, i.e., those to whom to issue the keys needed to access the encrypted data. Also, in this case, the GDPR tensions with DLTs drove the architecture to be multi-DLT. Authorization servers use a “tightly controlled” permissioned DLT to handle personal data, while a permissionless “audit” DLT is used for system security and only holds non-personal data. After describing the design of a decentralized PIMS, we focus on enriching the expressiveness of the access control mechanism through privacy policies. These let data subjects and/or holders express privacy policies aligned with the GDPR legal bases to be enforced through smart contracts. We use a set of Semantic Web technologies and standards for this aim. Finally, we present a Self-Sovereign Identity (SSI) model for providing, requesting, and obtaining qualified data to negotiate and/or execute electronic transactions with a focus on the legal and operational context. RESUMEN La transformaciĂłn introducida por las tecnologĂ­as de la informaciĂłn y las comunicaciones en las Ășltimas dĂ©cadas repercute signifcativamente en la economĂ­a y la sociedad en lo que respecta a la representaciĂłn digital de la identidad personal. La explotaciĂłn econĂłmica de la informaciĂłn personal se ve favorecida por la naturaleza omnipresente del mundo digital actual: los datos estĂĄn en el centro de esta transformaciĂłn, y los individuos son las principales fuentes de informaciĂłn y los mĂĄs afectados por ella. El Reglamento General de ProtecciĂłn de Datos (RGPD) estĂĄ teniendo un impacto signifcativo en la protecciĂłn de los datos personales. Ha sido diseñado para los ciudadanos de la UniĂłn Europea (UE) con el f n de ayudar a promover una visiĂłn a favor de los intereses de los individuos en lugar de las grandes corporaciones. Sin embargo, a gran escala, es necesario que existan mĂĄs tecnologĂ­as dedicadas que puedan ayudar a las empresas a cumplir con el RGPD (y reglamentos similares) al tiempo que permiten a las personas ejercer sus derechos. Sostenemos que una soluciĂłn especĂ­fca de este tipo debe abordar dos cuestiones principales: la necesidad de una mayor transparencia hacia las personas en lo que respecta a la gestiĂłn de su informaciĂłn personal y su capacidad, a menudo obstaculizada, de acceder a los datos personales y hacerlos interoperables de forma que el ejercicio de los derechos propios resulte sencillo y no excesivamente oneroso. En este trabajo, damos el primer paso hacia estos dos objetivos diseñando un modelo de gestiĂłn de datos personales centrado en el usuario, en el que el almacenamiento se desvincula de la lĂłgica de gestiĂłn de datos. Pretendemos ofrecer un sistema que ayude a impulsar la gestiĂłn de datos personales hacia el control del individuo, es decir, un sistema de gestiĂłn de informaciĂłn personal (PIMS). Al utilizar el almacenamiento distribuido y las redes de computaciĂłn descentralizadas para controlar los servicios online, la informaciĂłn personal de los usuarios podrĂ­a desplazarse hacia los directamente interesados, es decir, los interesados. El uso de las Distributed Ledger Technologies (DLT) y del Decentralized File Storage (DFS) como implementaciĂłn de sistemas descentralizados es de vital importancia en este caso. La estructura de esta disertaciĂłn sigue un mĂ©todo incremental para describir un conjunto de sistemas y modelos descentralizados que gira en torno a los datos personales y sus sujetos. Cada capĂ­tulo de esta disertaciĂłn se basa en el anterior y analiza la implementaciĂłn tĂ©cnica de un sistema y su relaciĂłn con la normativa correspondiente. De hecho, la mayorĂ­a de las veces, las implementaciones basadas en sistemas descentralizados chocan con leyes como el RGPD. Nos referimos al marco normativo de la UE, incluidos el RGPD, el eIDAS y la Data Governance Act, para construir los impulsores funcionales y no funcionales de nuestra arquitectura fnal del sistema. En nuestro diseño de PIMS, los datos personales se guardan en un Espacio de Datos Personales (PDS) que consiste en datos personales cifrados referentes al sujeto almacenados en un DFS. Utilizamos un sistema de indexaciĂłn descentralizado para garantizar la integridad, verifcabilidad, vinculabilidad, capacidad de bĂșsqueda e indexaciĂłn de los datos personales cifrados almacenados en el PDS. Seguimos el enfoque para referenciar datos y su contenido en una DLT, es decir, on-chain hash pointers. A continuaciĂłn, asociamos a dicha referencia de hash pointer un conjunto de palabras clave que se explota para buscar tipos especĂ­fcos de contenidos. AdemĂĄs, una red de servidores de autorizaciĂłn actĂșa como intermediaria para facilitar el acceso a los posibles destinatarios de los datos. El acceso a los datos almacenados en un PDS puede ser permitido por el titular de los datos a travĂ©s de smart contracts. Estos mantienen una estructura de datos para registrar los destinatarios de datos elegibles, es decir, aquellos a quienes expedir las claves necesarias para acceder a los datos cifrados. AdemĂĄs, en este caso, las tensiones del RGPD con las DLT impulsaron a que la arquitectura fuera multi-DLT. Los servidores de autorizaciĂłn utilizan una permissioned DLT “estrechamente controlada” para manejar datos personales, mientras que una “audit” permissionless DLT se utiliza para la seguridad del sistema y sĂłlo contiene datos no personales. Tras describir el diseño de un PIMS descentralizado, nos centramos en enriquecer la expresividad del mecanismo de control de acceso mediante polĂ­ticas de privacidad. Éstas permiten a los titulares y /o sujetos de los datos expresar polĂ­ticas de privacidad alineadas con las bases legales del RGPD que se aplicarĂĄn a travĂ©s de smart contracts. Para ello utilizamos un conjunto de tecnologĂ­as y estĂĄndares de la Web SemĂĄntica. Por Ășltimo, presentamos un modelo de Self-Sovereign Identity (SSI) para proporcionar, solicitar y obtener datos cualifcados para negociar y /o ejecutar transacciones electrĂłnicas con un enfoque en el contexto legal y operativo.

Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Apr 17, 2023·Organizational Cybersecurity Journal Practice Process and People
7 cites
Privacy implications of blockchain systems: a data management perspective

Heng Xu, Nan Zhang

Purpose Privacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? Blockchain does not seem to neatly fit into any of these buckets that we traditionally use to gauge the privacy implications of information technologies. In this article, the authors argue that blockchain transcends the extant conceptualization of privacy because it modifies the nature of data flow upon which the modern concept of privacy is based. Design/methodology/approach The authors introduce a conceptualization of blockchain as a new mechanism for data management. Then, following this conceptualization, the authors present a functional review of blockchain, summarizing the features it provides for the data it manages. This review sets up the discussion of how blockchain redefines data flow by separating the power of collection, access and query of data to different entities. After illustrating how this change regrounds privacy concerns in a blockchain system, the authors conclude with a discussion of the recommendations for future privacy research on blockchain. Findings The authors demonstrate that blockchain, by design, separates three core data-centric operations that are assumed to be inextricably linked in the canonical conceptualization of privacy: the collection, access and query of data. Collection means to capture and then store the data; access means to modify or augment the data and query means the ability to test or verify certain properties of the data (e.g. whether a bank account has a zero balance). Traditionally, any entities that collect data can evidently read, modify or query the same data as they wish. With blockchain, however, an entity that stores the data may not be able to modify the data, yet an entity that cannot even read the data may be able to verify certain properties of the data. Originality/value Privacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? In this article, the authors aim to respond to this important question.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Apr 17, 2023·2023 19th International Conference on the Design of Reliable Communication Networks (DRCN)
12 cites
Blockchain-based Self-Sovereign Identity Solution for Vehicular Networks

Engin Zeydan, Josep Mangues, ƞuayb S. Arslan, Yekta TĂŒrk

Identity and access management frameworks address data governance and system access rights for users, organizations, and vendors. Emerging identity management models such as Self-Sovereign Identity (SSI) that is based on Distributed Ledger Technology (DLT) technology, have emerged to address the challenges associated with centralized authority. The main goal of SSI is to help users self-manage their data shared with services. In this paper, we explore a possible application of the SSI concept to vehicular networks. We propose a new methodology, that is alternative to the conventional blockchain-based SSI, which ensures confidentiality, authentication, and integrity of vehicle users identity and their data. At the end of the paper, we also compare SSI-based and Non-fungible token (NFT)-based blockchain solutions, the challenges and future directions of SSI solutions in the context of vehicular networks.

Open access
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
Privacy, Security, and Data Protection
Original source
Apr 16, 2023·arXiv
31 cites
FedBlockHealth: A Synergistic Approach to Privacy and Security in IoT-Enabled Healthcare through Federated Learning and Blockchain

Nazar Waheed, Ateeq Ur Rehman, Anushka Nehra, Mahnoor Farooq · 9 authors

The rapid adoption of Internet of Things (IoT) devices in healthcare has introduced new challenges in preserving data privacy, security and patient safety. Traditional approaches need to ensure security and privacy while maintaining computational efficiency, particularly for resource-constrained IoT devices. This paper proposes a novel hybrid approach by combining federated learning and blockchain technology to provide a secured and privacy-preserved solution for IoT-enabled healthcare applications. Our approach leverages a public-key cryptosystem that provides semantic security for local model updates, while blockchain technology ensures the integrity of these updates and enforces access control and accountability. The federated learning process enables a secure model aggregation without sharing sensitive patient data. We implement and evaluate our proposed framework using EMNIST datasets, demonstrating its effectiveness in preserving data privacy and security while maintaining computational efficiency. The results suggest that our hybrid approach can significantly enhance the development of secure and privacy-preserved IoT-enabled healthcare applications, offering a promising direction for future research in this field.

Open access
2 source records
cs.CR
cs.AI
cs.LG
Original source
Apr 16, 2023·Software Practice and Experience
7 cites
A blockchain‐based privacy‐preserving advertising attribution architecture: Requirements, design, and a prototype implementation

Yang Liu, Liangjie Lin, Lin Jiang, Weizhe Zhang · 9 authors

Abstract In the era of digital marketing, advertisements have become an indispensable part. One of the central challenges is advertising attribution which explains the amount of contribution every publisher has with the conversions. However, through observation, we have found that current advertising platforms attribution, advertisers attribution, or third‐party platforms attribution all have the problems of trust, data leakage, and data forgery. To fill the gap, our work's main contribution is combining blockchain with advertising attribution to propose an architecture for improving the privacy‐preserving degree and amount. In the proposed architecture, publishers, and advertisers can store real‐time data on a blockchain. The attribution results are credible because blockchain is decentralized, tamper‐proof, and traceable. We combine privacy set intersection and zero‐knowledge proof technology to increase the privacy of flowing data. In addition, we describe a preliminary prototype in which publishers, advertisers, and advertising platforms can get the corresponding attribution details. To show its effectiveness, we analyze it from different perspectives, including communication cost, attribution accuracy, and time cost. The results show that our communication cost has significantly reduced compared to the recent studies.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Apr 13, 2023·Journal of Global Information Management
13 cites
The Paradoxes of Trust and Transparency of Blockchain Technologies

Cédric Baudet, Maximiliano Jeanneret Medina

The Republic and Canton of Jura has decided to adopt and integrate the CERTUS digital seal and the KSI blockchain as the central technological components of their e-government portal and of their digital government transformation program. However, this project is taking place in turbulent times. While blockchain suffers from a bad reputation for ecological reasons and while the Swiss Confederation has rejected the selected blockchain solution, this article seeks to answer how to grasp the paradoxes of blockchain technologies acceptance by state citizens in an extreme management situation. Through an action research that aims to solve practical problems and create scientific knowledge, this study highlights the paradox of trust and considers blockchain technologies to enhance trust between citizens in politically stable countries. Furthermore, it investigates the paradox of transparency of blockchain technologies in an extreme management situation and proposes communicating in two levels of abstraction to limit tensions in turbulent times.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
E-Government and Public Services
Original source
Apr 13, 2023·Journal of Sensor and Actuator Networks
40 cites
PbDinEHR: A Novel Privacy by Design Developed Framework Using Distributed Data Storage and Sharing for Secure and Scalable Electronic Health Records Management

Farida Habib Semantha, Sami Azam, Bharanidharan Shanmugam, Kheng Cher Yeo

Privacy in Electronic Health Records (EHR) has become a significant concern in today’s rapidly changing world, particularly for personal and sensitive user data. The sheer volume and sensitive nature of patient records require healthcare providers to exercise an intense quantity of caution during EHR implementation. In recent years, various healthcare providers have been hit by ransomware and distributed denial of service attacks, halting many emergency services during COVID-19. Personal data breaches are becoming more common day by day, and privacy concerns are often raised when sharing data across a network, mainly due to transparency and security issues. To tackle this problem, various researchers have proposed privacy-preserving solutions for EHR. However, most solutions do not extensively use Privacy by Design (PbD) mechanisms, distributed data storage and sharing when designing their frameworks, which is the emphasis of this study. To design a framework for Privacy by Design in Electronic Health Records (PbDinEHR) that can preserve the privacy of patients during data collection, storage, access and sharing, we have analysed the fundamental principles of privacy by design and privacy design strategies, and the compatibility of our proposed healthcare principles with Privacy Impact Assessment (PIA), Australian Privacy Principles (APPs) and General Data Protection Regulation (GDPR). To demonstrate the proposed framework, ‘PbDinEHR’, we have implemented a Patient Record Management System (PRMS) to create interfaces for patients and healthcare providers. In addition, to provide transparency and security for sharing patients’ medical files with various healthcare providers, we have implemented a distributed file system and two permission blockchain networks using the InterPlanetary File System (IPFS) and Ethereum blockchain. This allows us to expand the proposed privacy by design mechanisms in the future to enable healthcare providers, patients, imaging labs and others to share patient-centric data in a transparent manner. The developed framework has been tested and evaluated to ensure user performance, effectiveness, and security. The complete solution is expected to provide progressive resistance in the face of continuous data breaches in the patient information domain.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Apr 12, 2023·PLoS ONE
17 cites
BlockTicket: A framework for electronic tickets based on smart contract

Amjad Aldweesh

As the use of digital subscription services like electronic tickets (E-ticketing) has grown in the age of e-commerce, so too have instances of copyright and violation. Because it is dependent on the centralized authority administration of authoritative institutions, the traditional E-ticketing system has a significant cost associated with it. Blockchain, which is a distributed system, has the characteristics of decentralization, anonymity, auditability, security, and persistency. These attributes allow it to address the problems that are currently being experienced by the E-ticketing system. In this study, we present a framework for E-ticketing that makes use of blockchain technology. The blockchain-based electronic ticketing model eliminates the involvement of third parties while also lowering the potential of data leaks and improving users' levels of privacy. This is accomplished by separating the credential information of users from the financial transactions. In the meanwhile, a blockchain implementation of the existing E-ticketing architecture has the potential to improve throughput, reduce the amount of redundant work, and boost the efficiency of consensus. An examination of the experimental data shows that the framework has a number of advantages, some of which are a high throughput, flexible scalability, and efficient ticket holding times.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Privacy, Security, and Data Protection
Original source
Apr 10, 2023·INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
0 cites
Ecommerce DApp-A Decentralised Ecommerce Project

Farhan Shikalgar, Farhaan Khan, Saud Kadiri, Anas Khan

Improving efficiency and performance is an important topic in the world today. As it is well-known, cooperative computing is an effective and traditional approach, and it is widely used in various fields. Inspired by this idea, take E- commerce for example, Security is one of its important indicators. In E-commerce, the security technology has become a major issue restricting the rapid development and popularization of E- commerce.With the advent of new technologies, Blockchain plays a major role in ecommerce sector.With the characteristics of decentralization, persistency, anonymity and auditability, blockchain technology is a new tool to solve the product traceability, information security and privacy, payment efficiency and cost reduction in cross- border e-business.Existing E-commerce models are trapped in a dilemma between the proof of ownership and privacy protection. To address this issue,We have made a platform Shoppingverse which is a blockchain based ecommerce.we design a privacy-preserving business protocol by employing private smart contracts in the negotiation phase. The protocol allows counterparties make deals without the disclosure of private information such as identities, addresses, and phone numbers. Moreover, we employ the zero- knowledge proof to guarantee the ownership. Key Words: Ethereum, Blockchain, Ecommerce, Smart Contract.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Privacy, Security, and Data Protection
Original source
Mar 30, 2023·Global Social Sciences Review
3 cites
What Drives Cryptocurrency Acceptance? Evidence from Pakistan

Khurram Ashfaq, Hafiz Tassawer Nadeem, Farhan Iftikhar

In this study, the proposed model of acceptance factors of cryptocurrencies was analyzed to recognize user behavioral intention by using; web quality, facilitating conditions, perceived risk, e-WOM, and perceived ease of use with the mediating role of the trust factor. An efficient and effective better arrangement of understanding this unique virtual delusion of the use of cryptocurrencies has become an essential part of the virtual world for each stakeholder. So many deliberations on the regulatory frameworks of cryptocurrencies have taken place among government regulators, financial advisors, tax consultants, politicians, thinkers, economists, and lawmakers, but there is inconclusive evidence on legislation in Pakistan.

Open access
Impact of Technology on Adolescents
Privacy, Security, and Data Protection
Digital Marketing and Social Media
Original source
Mar 27, 2023·International Journal for Research in Applied Science and Engineering Technology
0 cites
Execution of IoT System using Blockchain with Authentication and Data Protection

M Rubika, Prof. S. Senthilvelan, N. Sneka

Abstract: Blockchain allows users and data providers to ensure authentication, authorization and data validity with proper multi-key exchange authentication for user identity and hash key for Blockchain so that the data is not just stored but also validated each time the user access. In this paper, we apply Zero Knowledge proof to a Strong rooms using RFID Card reader and Camera module IoT systems to prove that a prover without disclosing information such as public key enhances the anonymity of Blockchain

Open access
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
Mar 25, 2023·Future Internet
25 cites
PVPBC: Privacy and Verifiability Preserving E-Voting Based on Permissioned Blockchain

Muntadher Sallal, Ruairí de Fréin, Ali Malik

Privacy and verifiability are crucial security requirements in e-voting systems and combining them is considered to be a challenge given that they seem to be contradictory. On one hand, privacy means that cast votes cannot be traced to the corresponding voters. On the other hand, linkability of voters and their votes is a requirement of verifiability which has the consequence that a voter is able to check their vote in the election result. These two contradictory features can be addressed by adopting privacy-preserving cryptographic primitives, which at the same time as achieving privacy, achieve verifiability. Many end-to-end schemes that support verifiability and privacy have the need for some voter action. This makes ballot casting more complex for voters. We propose the PVPBC voting system, which is an e-voting system that preserves privacy and verifiability without affecting voter usability. The PVPBC voting system uses an effective and distributed method of authorization, which is based on revocable anonymity, by making use of a permissioned distributed ledger and smart contract. In addition, the underlying PVPBC voting system satisfies election verifiability using the Selene voting scheme. The Selene protocol is a verifiable e-voting protocol. It publishes votes in plaintext accompanied by tracking numbers. This enables voters to confirm that their votes have been captured correctly by the system. Numerical experiments support the claim that PVPBC scales well as a function of the number of voters and candidates. In particular, PVPBC’s authorization time increases linearly as a function of the population size. The average latency associated with accessing the system also increases linearly with the voter population size. The latency incurred when a valid authentication transaction is created and sent on the DLT network is 6.275 ms. Empirical results suggest that the cost in GBP for casting and storing an encrypted ballot alongside a tracker commitment is a linear function of the number of candidates, which is an attractive aspect of PVPBC.

Open access
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Mar 22, 2023·arXiv (Cornell University)
2 cites
BlockChain and Decentralized Apps

Aakash Garg, Ankit Tyagi, Anant Patel, Divyansh Raj

Blockchain, the backbone of Bitcoin, has recently gained a lot of attention. Blockchain functions as an immutable record that enables decentralized transactions. Blockchain-based applications are sprouting up in a variety of industries, including financial services, reputation systems, and the Internet of Things (IoT), among others. However, many hurdles of blockchain technology, including scalability and security issues, have to be overcome. Many industries, including finance, medicine, manufacturing, and education, use blockchain applications to capitalize on this technology's unique set of properties. Blockchain technology (BT) has the potential to improve trustworthiness, collaboration, organization, identity, credibility, and transparency. We provide an overview of blockchain architecture, various different kinds of blockchain as well as information about the Decentralized apps which are also known as Dapps. This paper provides an in-depth look at blockchain technology

Open access
2 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Privacy, Security, and Data Protection
Original source
Mar 21, 2023·IEEE Internet of Things Journal
29 cites
Public Blockchain-Based Data Integrity Verification for Low-Power IoT Devices

Jing Huey Khor, Michail Sidorov, Ming Tze Ong, Shen Yik Chua

The integration of sensor nodes with public blockchains is possible with the help of low-power communication networks that use Bluetooth low energy and long range. However, power-consuming Wi-Fi is still the main means of communication for the existing sensor nodes, especially in urban environments. Typically high power consumption, private key disclosure, and high transaction fees are the issues that prevent battery-powered sensor nodes from being integrated with a public blockchain. Therefore, this article proposes a data protection protocol that is able to secure the data integrity of the stored sensor data, help to reduce transaction fees, and prolong battery life for IoT devices that are used with public blockchain networks. A proof of concept is presented using an ESP32S2 device to evaluate and verify the performance of the proposed data storage protocol. A smart contract is designed and analyzed using a formal smart contract analysis tool. A decentralized Web application is designed to display and verify the sensor data extracted from the public blockchain. The power consumption, memory usage, and security of the proposed solution are evaluated. The evaluation results show that data integrity can be achieved even for low-power sensor nodes that connect to public blockchains via Wi-Fi network.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
Mar 13, 2023·Frontiers in Blockchain
21 cites
Health Passport: A blockchain-based PHR-integrated self-sovereign identity system

Merlin George, Anu Mary Chacko

During the COVID-19 pandemic, it was necessary to validate a person’s health status along with their identity to permit travel. This was facilitated via paper-based certificates and centralized digital apps. Even after COVID-19, it is anticipated that such health status verifications will be required for travel and other purposes. As a result, there needs to be an additional credential, a “Health Passport,” that establishes whether a person satisfies the health requirements for various purposes. Digital credentials so prepared should be trustable, unforgeable, and verifiable. The Health Passport should be designed to protect the end-users’ privacy and give people control over the data they use to confirm their credentials. This article explores the requirements for a generalized Health Passport system and uses agent-oriented modeling (AOM) to design a blockchain-based self-sovereign identity (SSI) system integrated with the Personal Health Record (PHR) to address this requirement. The article demonstrates the feasibility of the solution by implementing a proof of concept on Hyperledger Indy and Aries, integrated with the PHR – MediTrans. Credential issuance and verification time were calculated, and it was observed that the time overhead was minimal. This solution allows users to verify their credentials with the verifier without revealing any significant personal information. Our solution can be integrated into any PHR solution as the SSI solution is added as a plugin to the PHR accessible via a mobile/web app.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Mar 6, 2023·Journal of Pharmaceutical Negative Results
2 cites
DRBAC-Healthchain (DRBAC-HC): Decentralized Role Based Access Control Framework For Achieving Security And Privacy Using Blockchain In Healthcare System

Dr.Hiren Patel Avani Dadhania

With the Internet of Things' (IoTs) rapid expansion, effect, and potential, the healthcare industry is shifting to a new paradigm that permits wearable devices to collect patient medical data and use it for monitoring and diagnosis. Tamper-proof data and avoidance of the centralized record-keeping mechanism are crucial requirements in any wellness system due to its exigent and precise necessity of data requests. Along with the same, transactions’ auditability and revocation of access rights upon certain records for specific stakeholders are also a few of the other prerequisites in the medical segment. Blockchain, as a distributed ledger, offers a solution for securely storing data while providing transparency in transactions and interactions among stakeholders. Synchronous interaction among patient, doctor, pharmacy, consultant, hospital, etc. with all possible data security is another concern that could be resolved through the usage of Blockchain’s smart contracts wherein interaction among these stakeholders is permitted in a traceable and irreversible mode. The purpose of this paper is to discuss the potential use of Blockchain technology in the healthcare sector to achieve data security, transparency, and reliability without the involvement of a trusted third party. In terms of security and privacy, we survey and provide an exhaustive review of Blockchain-based access control systems for the healthcare system. In addition, for the healthcare system, we propose and implemented a decentralized role-based access control model based on Ethereum smart contract.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source