The unique features of Non-Fungible Tokens (NFT) are becoming increasingly appealing as we spend more of our time online. This increased popularity is nevertheless not free of controversies, and there is a lack of clarity over the final form this digital asset will take. While there are some early adopters, the whole NFT ecosystem will have to be clarified for wider adoption, particularly the purchasing process. This research evaluates a model of the purchasing process of NFTs and the role of trust in this process. The validated model identified that the purchasing process of NFTs has four stages and each stage is affected by trust: (1) Trust in the cryptocurrency wallet, (2) trust in the cryptocurrency purchase, (3) trust in the NFT marketplace, and (4) trust in aftersales services.
In this work we explore the use of blockchain with Internet of Things (IoT) devices to provide visitor authentication and access control in a physical environment. We propose the use of a âbraceletâ based on a low-cost NodeMCU IoT platform that broadcasts visitor location information and cannot be removed without alerting a management system. We present the design, implementation, and testing of our system. Our results show the feasibility of implementing a physical access control system based on blockchain technology, and performance improvements over a similar system proposed in the literature.
V. Anitha, Orlando Juan Mårquez, R. Sudharsan, S. Yoganandan · 5 authors
The aim of this paper is to create a decentralized transparent voting and analysis system that can be implemented with blockchain to provide an efficient and highly secure justifiable method of election systems in countries where traditional physical voting with gameable securities is used, increasing the chances of rigged elections. This system is designed to focus on a secure voting system, lower costs, faster wait times, no disparities due to various erroneous proxies, high scalability, and geographic independence. Overall, an effective election mechanism to strengthen the democratic process. The proposed dApp allows voters to vote from the comfort of their own homes, saving time and reducing the number of false votes registered.
With the advancement in computing power and speed, the Internet is being transformed from screen-based information to immersive and extremely low latency communication environments in web 3.0 and the Metaverse. With the emergence of the Metaverse technology, more stringent demands are required in terms of connectivity such as secure access and data privacy. Future technologies such as 6G, Blockchain, and Artificial Intelligence (AI) can mitigate some of these challenges. The Metaverse is now on the verge where security and privacy concerns are crucial for the successful adaptation of such disruptive technology. The Metaverse and web 3.0 are to be decentralized, anonymous, and interoperable. Metaverse is the virtual world of Digital Twins and non-fungible tokens (NFTs). The control and possession of users' data on centralized servers are the cause of numerous security and privacy concerns. This paper proposes a solution for the security and interoperability challenges using Self-Sovereign Identity (SSI) integrated with blockchain. The philosophy of Self-Sovereign Identity, where the users are the only holders and owners of their identity, comes in handy to solve the questions of decentralization, trust, and interoperability in the Metaverse. This work also discusses the vision of a single, open standard, trustworthy, and interoperable Metaverse with initial design and implementation of SSI concepts.
Abstract Background Increasingly, hospitals and research institutes are developing technical solutions for sharing patient data in a privacy preserving manner. Two of these technical solutions are homomorphic encryption and distributed ledger technology. Homomorphic encryption allows computations to be performed on data without this data ever being decrypted. Therefore, homomorphic encryption represents a potential solution for conducting feasibility studies on cohorts of sensitive patient data stored in distributed locations. Distributed ledger technology provides a permanent record on all transfers and processing of patient data, allowing data custodians to audit access. A significant portion of the current literature has examined how these technologies might comply with data protection and research ethics frameworks. In the Swiss context, these instruments include the Federal Act on Data Protection and the Human Research Act. There are also institutional frameworks that govern the processing of health related and genetic data at different universities and hospitals. Given Switzerlandâs geographical proximity to European Union (EU) member states, the General Data Protection Regulation (GDPR) may impose additional obligations. Methods To conduct this assessment, we carried out a series of qualitative interviews with key stakeholders at Swiss hospitals and research institutions. These included legal and clinical data management staff, as well as clinical and research ethics experts. These interviews were carried out with two series of vignettes that focused on data discovery using homomorphic encryption and data erasure from a distributed ledger platform. Results For our first set of vignettes, interviewees were prepared to allow data discovery requests if patients had provided general consent or ethics committee approval, depending on the types of data made available. Our interviewees highlighted the importance of protecting against the risk of reidentification given different types of data. For our second set, there was disagreement amongst interviewees on whether they would delete patient data locally, or delete data linked to a ledger with cryptographic hashes. Our interviewees were also willing to delete data locally or on the ledger, subject to local legislation. Conclusion Our findings can help guide the deployment of these technologies, as well as determine ethics and legal requirements for such technologies.
Muhammad Nazmul Islam, Mubashir Husain Rehmani, Jinjun Chen
The integration of permissioned blockchain such as Hyperledger fabric (HF) and Industrial internet of Things (IIoT) has opened new opportunities for interdependent supply chain partners to improve their performance through data sharing and coordination. The multichannel mechanism, private data collection and querying mechanism of HF enable private data sharing, transparency, traceability, and verification across the supply chain. However, the existing querying mechanism of HF needs further improvement for statistical data sharing because the query is evaluated on the original data recorded on the ledger. As a result, it gives rise to privacy issues such as leaking of business secrets, tracking of resources and assets, and disclosing of personal information. Therefore, we solve this problem by proposing a differentially private enhanced permissioned blockchain for private data sharing in the context of supply chain in IIoT which is known as (EDH-IIoT). First, we integrate differential privacy into the chaincode (smart contract) of HF which evaluates the query and adds a calibrated noise into it. Second, we propose an algorithm to efficiently utilize ϔ through reuse of the privacy budget for the repeated queries. Third, we also propose an algorithm to track the privacy budget (ϔ) and avoid the degrade of privacy preservation in case of multiple queries on the same portion of the ledger's data. Furthermore, the reuse and tracking of ϔ enables the data owner to ensure that ϔ does not exceed the threshold which is the maximum privacy budget (ϔt). Finally, we model two privacy attacks namely linking attack and composition attack to evaluate and compare privacy preservation, and the efficiency of reuse of ϔ with the default chaincode of HF and traditional differential privacy model, respectively. The results confirm that EDH-IIoT obtains an accuracy of 97% in the shared data for ϔ = 1, and a reduction of 35.96% in spending of ϔ.
With the development of blockchain technology, the automatic generation of smart contract has become a hot research topic. The existing smart contract automatic generation technology still has improvement spaces in complex process, third-party specialized tools required, specific the compatibility of code and running environment. In this paper, we propose an automatic smart contract generation method, which is domain-oriented and configuration-based. It is designed and implemented with the application scenarios of government service. The process of configuration, public state database definition, code generation and formal verification are included. In the Hyperledger Fabric environment, the applicability of the generated smart contract code is verified. Furthermore, its quality and security are formally verified with the help of third-party testing tools. The experimental results show that the quality and security of the generated smart contract code meet the expect standards. The automatic smart contract generation will âelegantlyâ be applied on the work of anti-disclosure, privacy protection, and prophecy processing in government service. To effectively enable develop âprogrammable governmentâ.
Web 3.0 is the next-generation Internet that enables participants to read, write, and own contents in a decentralized manner. It is mainly driven by blockchain, semantic communication, edge computing, and artificial intelligence, which can construct value networks to achieve participatory economics based on participatory decision making. Web 3.0 can capture the characteristics of blockchain, semantic extraction, and communication to achieve decentralized semantic sharing and transfer information precisely. However, current Web 3.0 solutions focus on the blockchain while overlooking other new technologies' roles in Web 3.0. To further unleash the advantages of semantic extraction and communication in Web 3.0, in this article, we propose a blockchain-based semantic exchange framework to realize fair and efficient interactions. In this framework, we first attempt to tokenize semantic information into Non-Fungible Token (NFT) for semantic exchange. Then we utilize a Stackelberg game to maximize buying and pricing strategies for semantic trading. We also leverage Zero-Knowledge Proof to share authentic semantic information without publishing it before receiving payments, which can achieve a fair and privacy-preserving trading compared with current NFT marketplaces. A case study about urban planning is given to show clearly the proposed mechanisms. Finally, several challenges and opportunities are identified.
The financial sector's adoption of technology-driven data analysis has enhanced operational efficiency and revenue generation by leveraging personal sensitive data. However, the inherent characteristics of blockchain hinder decentralized finance (DeFi) from accessing necessary sensitive user data. To address this challenge, we introduce a protocol that both safeguards user privacy and ensures data availability through the incorporation of homomorphic encryption and zero-knowledge-proof techniques in blockchain technology. This novel protocol helps mitigate privacy risks caused by sensitive data leaks while improving the capital efficiency of the DeFi market. Furthermore, we explore the applicability of these privacy-preserving methods in on-chain ecosystems and cross-border financial applications. Our solution contributes to secure, user-centric solutions for DeFi while upholding principles of decentralization and privacy protection.
Abstract This paper argues that the widespread belief that interactions between blockchains and their users are trustâfree is inaccurate and misleading, since this belief not only overlooks the vital role played by trust in the lack of knowledge and control but also conceals the moral and normative relevance of relying on blockchain applications. The paper reaches this argument by providing a close philosophical examination of the concept referred to as trust in blockchain technology, clarifying the trustor group, the structure, and the normatively loaded nature of this trust relation. The paper ends by critically reflecting on two of the most promising values (decentralization and transparency) that can invite usersâ trust in blockchain technology, arguing that there is a tension between the pressing values that are intended to be achieved by developers and the predicament situations caused by current blockchain implementations.
Usman Khalil, Owais Ahmed Malik, Wee-Hong Ong, Mueen Uddin
Smart city architecture brings all the underlying architectures, i.e., Internet of Things (IoT), Cyber-Physical Systems (CPSs), Internet of Cyber-Physical Things (IoCPT), and Internet of Everything (IoE), together to work as a system under its umbrella. The goal of smart city architecture is to come up with a solution that may integrate all the real-time response applications. However, the cyber-physical space poses threats that can jeopardize the working of a smart city where all the data belonging to people, systems, and processes will be at risk. Various architectures based on centralized and distributed mechanisms support smart cities; however, the security concerns regarding traceability, scalability, security services, platform assistance, and resource management persist. In this paper, private blockchain-based architecture Decentralized Smart City of Things (DSCoT) is proposed. It actively utilizes fog computing for all the users and smart devices connected to a fog node in a particular management system in a smart city, i.e., a smart house or hospital, etc. Non-fungible tokens (NFTs) have been utilized for representation to define smart device attributes. NFTs in the proposed DSCoT architecture provide devices and user authentication (IoT) functionality. DSCoT has been designed to provide a smart city solution that ensures robust security features such as Confidentiality, Integrity, Availability (CIA), and authorization by defining new attributes and functions for Owner, User, Fog, and IoT devices authentication. The evaluation of the proposed functions and components in terms of Gas consumption and time complexity has shown promising results. Comparatively, the Gas consumption for minting DSCoT NFT showed approximately 27%, and a DSCoT approve() was approximately 11% more efficient than the PUF-based NFT solution.
Smart contracts are a method for implementing direct democracy in virtual worlds. However, it is not clear whether voting preferences in the virtual world will mirror real-world voting preferences. We present a within-subject study in which participants were asked to allocate voting power in two scenarios. The first scenario probed participantsâ opinion about the divisibility of voting rights. The second scenario presented participants with the case of unequal allocation of voting power in a virtual world, enforced by smart contracts. In both scenarios, participants allocated voting power and rated the fairness of their decision. Our study finds that participantsâ voting preferences in the virtual world scenario did not mirror their real-world preferences and beliefs. Voting systems in the metaverse need to be carefully designed to align with human values and ethics.
Securing and managing medical data in hospitals is one of the significant challenges still existing in healthcare. There can be different kinds of patients staying in hospitals with various diseases. All these medical data records need to be secured appropriately for future use and verification. In the hospital, there will be essential documents such as criminal cases and postmortem reports, although it is unclear if they are being handled properly or not. Even the hospital staff can alter these data. This paper proposes a blockchain-based secured medical data management system to manage access to each medical record in a network of hospitals. The proposed system has three main access management categories: one for securing general (fever or cold) medical report, category 2 for postmortem or crime reports security and category 3 for securing cancer /brain death /genetic disorder reports. Sensitive clinical data should not be visible to patients with cancer or genetic disorders as these patients have a higher rate of suicide attempts. Hence, the data is accessible only to doctors, family members, and researchers. The data related to the crime or postmortem reports have only limited access for those with legal permission to access and verify these types of reports. So through blockchain distributed ledger technology and smart contracts, we could store the data in a tamper-proof manner and manage the user access to these data.
Rickard Elsen, Muhammad Rikza Nashrulloh, Ade Sutedi
Since the widespread use of cryptocurrency, blockchain technology start to be adapted in various applications. Some businesses are already adopting blockchain technology because of its advantages such as data integrity and privacy. One of them is Web 3.0. Web 3.0 puts forward data decentralization so that users can choose what data will be sent to the server. User data is provided locally with the help of a crypto wallet and the server just receives wallet info. With this mechanism, user privacy can be maintained directly by the user himself. All data will be processed at the users' end first before being sent to the server. With the new mechanism of web 3.0 and the advantages of blockchain, we build an application to authenticate students' login activities and grant roles to them based on their wallets. In this paper, we use the prototyping model as the method to build the application. We managed to utilize studentsâ wallet addresses as credentials. And with the help of Web3 module, we managed to decentralize the authentication process. And as a result of the successful authentication process, students can access their data based on their roles.
Suzana Mesquita de Borba Maranhao Moreno, Jean-Marc Seigneur
The traditional way to prove someoneâs address using formal documents like utility bills may not be feasible for some people, like those living in very poor neighborhoods, because they do not have these documents. In this paper, we propose an alternative way to prove someoneâs address using a decentralized social trust solution. Because our design choices, this solution is able to work offline and does not need a logically centralized repository of all issued proof-of-address, in oppose to what would be achieved by using existing accretionary ID solutions. We validated this proposal by building a mobile application, using it in a real experiment in a Brazilian favela, and collecting mobile data. We also interviewed 20 people to complement our validation and help to guide the next steps of this work. The experiment showed that the solution is viable and easy to use. It is possible to adopt an approach like the one proposed to prove other facts, like gender, sex and income. These proofs may be used for different initiatives, like social programs, purpose-driven lending or other decentralized finance services.
Robin Singh Bhadoria, Arka Prabha Das, Abul Bashar, Mohammed Zikria
A democratic election is a crucial event in any country. Therefore, the government of the country is concerned with creating more competitive and fairer elections. This paper discusses the survey and scope of Blockchain technology adoptions in conducting elections. A distributed digital ledger is used in the Blockchain technology that is utilized for recording transactions happening between two parties. Ledger conducts this processing in an efficient and effective manner with latest secure mechanism of encryption algorithms. Therefore, the data stored in several blocks in each transaction is secure, transparent, and tamper-proof, which ultimately improves the transparency and voter confidentiality. This paper demonstrates how the benefits of the Blockchain technology such as immutability, transparency and end-to-end verifiability can be utilized by the national governments around the world to ensure fair democratic elections. In short, we aim to present a rigorous mechanism of a Blockchain based e-voting system, its efficiency based on different consensus algorithms and the overall progress and analysis based on some critical parameters to anticipate the feasibility of the successful implementation of the proposed e-voting system.
Smart healthcare systems provide user-centric medical services to patients based on collected information of patients inducing personal health information (PHI) and personal identifiable information (PII). The information (PII and PHI) flows into the smart healthcare system with or without any regulation and patient concern with the help of new information and communication technologies (ICT). The use of ICT comes with the security and privacy issues of collected PII and PHI data. The Europe Union has published the General Data Protection Regulation (GDPR) to regulate the flow of personal information. Towards this end, this paper proposes a blockchain-based data storage and sharing framework for a smart healthcare system that complies with the âPrivacy by Designâ rule of the GDPR. The personal information collected from patients is stored on off-chain storage (IPFS), and other information is stored on the blockchain ledger, which is visible to all participants. The smart contracts are designed to share the PII data with another participant based on prior permission of the data owner. The proposed framework also includes the deletion of PII and PHI in the system as per the âRight to be Forgottenâ GDPR rule. Security and privacy analyses are performed for the framework to demonstrate the security and privacy of data while sharing and at rest. The comparative performance analysis demonstrates the benefit of the proposed GDPR-compliant data storage and sharing framework using blockchain. It is evident from the reported results that the proposed framework outperforms the state-of-the-art techniques in terms of performance metrics in a smart healthcare system.
Rahime Belen-Saglam, Enes Altuncu, Yang LĂŒ, Shujun Li
The blockchain technology has been rapidly growing since Bitcoin was invented in 2008. The most common type of blockchain systems, public (permisionless) blockchain systems have some unique features that lead to a tension with European Union's General Data Protection Regulation (GDPR) and other similar data protection laws. In this paper, we report the results of a systematic literature review (SLR) on 114 research papers discussing and/or addressing such a tension. To be the best of our know, our SLR is the most comprehensive review of this topic, leading a more in-depth and broader analysis of related research work on this important topic. Our results revealed that three main types of issues: (i) difficulties in exercising data subjects' rights such as the `right to be forgotten' (RTBF) due to the immutable nature of public blockchains; (ii) difficulties in identifying roles and responsibilities in the public blockchain data processing ecosystem (particularly on the identification of data controllers and data processors); (iii) ambiguities regarding the application of the relevant law(s) due to the distributed nature of blockchains. Our work also led to a better understanding of solutions for improving the GDPR compliance of public blockchain systems. Our work can help inform not only blockchain researchers and developers, but also policy makers and law markers to consider how to reconcile the tension between public blockchain systems and data protection laws (the GDPR and beyond).
As the digital ecosystem evolves, secure and efficient Digital IdentityManagement Systems (DIMS) have become pivotal in managing identities acrossgovernmental, financial, healthcare, and commercial sectors. This paper offers across-sectoral examination of DIMS, emphasizing security and privacy concerns andtheir mitigation strategies. Drawing on current technologies such as blockchain,biometrics, and zero-knowledge proofs, the study explores how these systems canprotect sensitive information while ensuring interoperability and compliance withregulatory frameworks. Through comparative analysis, graphical insights, and realworld case studies, the paper underscores the need for standardized and resilientidentity infrastructures that balance user privacy and system functionality
In the past few years, the main research efforts regarding General Data Protection Regulation (GDPR)-compliant data sharing have been focused primarily on informed consent (one of the six GDPR lawful bases for data processing). In cases such as Business-to-Business (B2B) and Business-to-Consumer (B2C) data sharing, when consent might not be enough, many small and medium enterprises (SMEs) still depend on contractsâa GDPR basis that is often overlooked due to its complexity. The contractâs lifecycle comprises many stages (e.g., drafting, negotiation, and signing) that must be executed in compliance with GDPR. Despite the active research efforts on digital contracts, contract-based GDPR compliance and challenges such as contract interoperability have not been sufficiently elaborated on yet. Since knowledge graphs and ontologies provide interoperability and support knowledge discovery, we propose and develop a knowledge graph-based tool for GDPR contract compliance verification (CCV). It binds GDPRâs legal basis to data sharing contracts. In addition, we conducted a performance evaluation in terms of execution time and test cases to validate CCVâs correctness in determining the overhead and applicability of the proposed tool in smart city and insurance application scenarios. The evaluation results and the correctness of the CCV tool demonstrate the toolâs practicability for deployment in the real world with minimum overhead.
Self-Sovereign Identity (SSI) is projected to become part of every person's life in some form. The ability to verify and authenticate that an individual is the actual person they are purported to be along with securing the personal attributes could have wide spread implications when engaging with third party organizations. Utilizing blockchains and other decentralized technologies, SSI is a growing area of research. The aspect of securing personal information within a decentralized structure has possible benefits to the public and private sectors. In this paper, we describe the SSI framework architecture as well as possible use cases across domains like healthcare, finance, retail, and government. The paper also contrasts SSI and its decentralized architecture with the current widely adopted model of Public Key Infrastructure (PKI).
Michael Sober, Giulia Scaffino, Stefan Schulte, Salil S. Kanhere
Abstract The (IoT) is growing steadily, and so is the number of data that is generated by (IoT) devices. This makes it difficult to find and leverage relevant data (and data sources) without a data marketplace. Such a marketplace provides a platform to enable different parties, e.g., sensor operators and service providers, to trade their data. Today, most data marketplaces are based on centralized solutions, which may become a single point of failure and come with expensive infrastructure, trust problems, and privacy issues. Therefore, we propose the application of blockchain technology to implement a data marketplace for the IoT. Within the proposed marketplace, smart contracts are used to implement various functionalities and enforce the rules of the data exchange. The marketplace also includes a proxy, a broker, and (GUIs) to enable data trading. To show the applicability of the proposed data marketplace, we analyze the costs arising from the utilization of smart contracts.