Samuel Akwasi Frimpong, Han Mu, Edward Kwadwo Boahen, Rexford Nii Ayitey Sosu · 7 authors
Recommendation systems provide ease and convenience for users to address information overload problems while interacting with online platforms such as social media and e-commerce. However, it raises several questions about privacy, especially for users who prefer to remain anonymous, especially on online social networks (OSNs). Moreover, due to the commercialization of online users' data, some service providers sell users' data to third parties at the blind side of the users, which leads to trust issues between users and service providers. Such matters call for a system that gives online users much-needed control and autonomy of their data. With the advancement of blockchain technology, many research institutions are experimenting with decentralized technologies to resolve the OSN user dilemma of privacy intrusion against third parties and hacks. To resolve these limitations, we propose RecGuard, a privacy preservation blockchain-based network system. We developed two smart contracts, RG-SH and RG-ST, to ensure the security and privacy of user data. The RG-SH manages user data, whereas the RG-ST stores data. A graph convolutional network (GCN) was integrated with the blockchain-based system to detect malicious nodes. Finally, we implemented our framework prototype on a locally simulated network. The analysis and experiment results show that the proposed scheme demonstrates the effectiveness and privacy of users in our framework.
NBA (National Basketball Association) trading cards are a hot collector’s item, with sales increasing rapidly every year. However, with the popularity of online trading, some sellers have started to intentionally and unintentionally sell imitation trading cards, and even PwC (Pricewaterhouse Coopers) is not immune. However, the PSA (Professional Sports Authenticator), which is the authentication agency, is not liable for this. Faced with the above situation, we moved trading cards online and proposed a blockchain-based anti-counterfeit and traceable NBA digital trading card management system, using blockchain technology to protect digital trading cards, and special digital copyright, to move from relying on other regulators to achieve the fight against counterfeit cards and maintain the security of the digital trading card market. Finally, we analyzed the security of the system and compared it with other methods. Our system uses Hyperledger Fabric to share data while protecting corporate privacy. Proxy re-encryption enables secure and trusted access authorization for digital transaction cards. Asymmetric encryption protects the data and uses signatures to achieve traceability and non-repudiation. Overall, our system solves the problem of counterfeiting and traceability that can occur in the digital trading card process from production to purchase.
Mateusz Godyn, Michał Kędziora, Yingying Ren, Yongxin Liu · 5 authors
The aim of this paper was to perform an analysis of the state-of-the-art solutions of the permissioned blockchain compliance with the General Data Protection Regulation (GDPR), including the implementation of one of the analyzed methods and the own solution. This paper covers the subject of GDPR and its impact on already existing blockchain databases to determine the domain of the problem, including the necessity to introduce mutability in the data structure to comply with the "right to be forgotten". The performed analysis made it possible to discuss current research in technical terms as well as in the regulation itself. In the experimental part, attempts were made to research and implement the Reference-based Tree Structure (RBTS), including the performance tests. The proposed solution is efficient and easily reproducible. The deletion of unwanted content is quick and requires consent only from the owner of personal data; therefore, eliminating the dependency on the other blockchain network participants.
In this article, we explore the tension between abstraction and composability in web3 today, specifically within identity solutions, and argue that the current standard DID v1.0 is sufficiently under specified, allowing for many methods and instantiations, including blockchain based certificates. We view experiments today in web3 identity as additive and complementary, and argue that often cited differences are of degree and more in form, less in substance. By way of illustration, we compare decentralized naming services and blockchain based identity certificates such as soulbound tokens (SBTs) to decentralized identifiers (DIDs) and verifiable credentials (VCs). Both paradigms, to the extent they can be meaningfully differentiated, share similar potential as well as challenges. Specifically, we refer to fears about non consensual verification (scarlet letters) and show DID method iterations are not immune by issuing an innocuous public scarlet letter to a DIDs associated public address for anyone to see. Moreover, we argue that because SBTs are unspecified, one could characterize SBTs as an iteration, or extension, of VCs that additionally aspire to achieve composability with web3 smart contracts for correct execution of code, privacy, coercion resistance, and censorship resistance. We offer research paths for how VCs can also achieve these properties. We do not comment on cost, scalability, transferability, or common knowledge as they have been previously reviewed.
Mirko Zichichi, Stefano Ferretti, Victor Rodrı́guez-Doncel
Big Tech companies operating in a data-driven economy offer services that rely on their users' personal data and usually store this personal information in "data silos" that prevent transparency about their use and opportunities for data sharing for public interest. In this paper, we present a solution that promotes the development of decentralized personal data marketplaces, exploiting the use of Distributed Ledger Technologies (DLTs), Decentralized File Storages (DFS) and smart contracts for storing personal data and managing access control in a decentralized way. Moreover, we focus on the issue of a lack of efficient decentralized mechanisms in DLTs and DFSs for querying a certain type of data. For this reason, we propose the use of a hypercube-structured Distributed Hash Table (DHT) on top of DLTs, organized for efficient processing of multiple keyword-based queries on the ledger data. We test our approach with the implementation of a use case regarding the creation of citizen-generated data based on direct participation and the involvement of a Decentralized Autonomous Organization (DAO). The performance evaluation demonstrates the viability of our approach for decentralized data searches, distributed authorization mechanisms and smart contract exploitation.
A core concept within journalism is the demand for correctness and the ability to double-check news and its sources (Kovach & Rosenstiel, 2014). In this paper, we reflect on the development of a prototype to study the possible use of blockchain technology to create a global secure database of fact-checks that is open to the public. The prototype utilized Hyperledger fabric to create a permissioned blockchain that stores fact-checks created by its users. Through automated processes using smart contracts (chain code applications), we aimed to create a solution that would improve the reliability of fact-checking and keep track of each fact-checking process for digital content, including pictures and videos. Our conclusion is that it is indeed possible to create a blockchain-based system that allows the establishment of a network of fact-checkers that could collectively build and maintain a globally accessible fact-checking database. However, based on technical developments and the evaluation performed by the professional fact-checkers and data journalists in our study, we conclude that the cost, complexity, and rapid technological changes required in this domain indicate that blockchain technology is not yet ready to be directly applied to fact-checking processes in a real-world scenario.
Mirko Zichichi, Stefano Ferretti, Gabriele D’Angelo, Victor Rodrı́guez-Doncel
Abstract The centralization of control over the processing of personal data threatens the privacy of individuals due to the lack of transparency and the obstruction of easy access to their data. Individuals need the tools to effectively exercise their rights, enshrined in regulations such as the European Union General Data Protection Regulation (GDPR). Having direct control over the flow of their personal data would not only favor their privacy but also a “data altruism”, as supported by the new European proposal for a Data Governance Act. In this work, we propose a multi-layered architecture for the management of personal information based on the use of distributed ledger technologies (DLTs). After an in-depth analysis of the tensions between the GDPR and DLTs, we propose the following components: (1) a personal data storage based on a (possibly decentralized) file storage (DFS) to guarantee data sovereignty to individuals, confidentiality and data portability; (2) a DLT-based authorization system to control access to data through two distributed mechanisms, i.e. secret sharing (SS) and threshold proxy re-encryption (TPRE); (3) an audit system based on a second DLT. Furthermore, we provide a prototype implementation built upon an Ethereum private blockchain, InterPlanetary File System (IPFS) and Sia and we evaluate its performance in terms of response time.
The management, protection and sharing of sensitive data such as those associated with the health domain are crucial in enabling personal care and contributing to worldwide medical advancements. Distributed Ledger Technologies (DLTs) allow for data protection compliant solutions in untrusted contexts that guarantee data immutability, protection and transparency when needed. This paper proposes an architecture based on DLTs, Smart Contracts and Distributed File Storage (DFS), enabling user data sovereignty, confidentiality and secure access control. A use case on health data is presented, where we apply a combination of DLT, DFS and an access control mechanism to allow users to distribute their data. Finally, we show an experimental evaluation of the overall architecture to demonstrate the feasibility of implementing practical DLT-based healthcare solutions. The results are collected through independent tests, available opensource, that verify the system's response time in each of its functions and as the load increases. The results are promising and show that the system is feasible and can scale as the load increases.
The Bitcoin blockchain, a prime example of disruptive technology, has fundamentally altered the way various industries approach remote transactions. Bitcoin grants privacy to its users by anonymizing public keys, provides autonomy by eliminating the need for trusted third parties, and maintains transparency through its public disclosure protocol. Bitcoin is an innovative manifestation of the Fourth Amendment ideals of security and autonomy. It is, thus, no surprise that the Bitcoin blockchain presents unprecedented Fourth Amendment challenges for courts to consider.
 In United States v. Gratkowski, the Fifth Circuit addressed the novel issue of whether Fourth Amendment protections extend to an individual’s Bitcoin transactions. Notably, the court was the first to find that an individual does not have a privacy interest in their information located directly on the Bitcoin blockchain. However, the Fifth Circuit applied inconsistent and flawed reasoning in reaching this decision, demonstrating a fundamental misunderstanding of Bitcoin and its users.
 Accordingly, this Note argues that the Gratkowski decision should be applied narrowly and with caution, especially considering the Supreme Court’s warnings against the incompatibility of current Fourth Amendment doctrine with the digital age. It then suggests implementing a modified reasonable expectation-of-privacy standard, supplementing the current standard with an additional inquiry into what information an individual disclosed when initiating a transaction. This modified standard would preserve the integrity of Bitcoin, while simultaneously articulating a proper framework for assessing privacy concerns in the context of Bitcoin and blockchain technology.
In this article we provide a primer for blockchain technology (BT) and explain ways that it has been applied (or can be applied) to the field of advertising research and practice. We situate this primer inside a critical look at the evolution of digital advertising that has been driven largely by immediate technological need for the maximization of profit rather than considerations for societal well-being. We discuss arenas in which the current state of digital advertising is not well positioned to maximize societal well-being and has built a consumer distrust of digital advertising, specifically with regard to the areas of privacy invasion, value to consumers, technology companies’ power, inaccuracies of personalizations, and misinformation spread. Throughout this article we discuss how blockchain technologies can be used as a research environment for testing new paths for digital advertising that could tackle these issues and be more beneficial to society. We also provide an overview of avenues for future research on BT application in the digital advertising ecosystem.
This article attempts to critically review the applications of smart contracts in public procurement. The literature on the topic is characterized by an emphasis on potential advantages and uses of this emerging technology, while it lacks in the concrete practical implementations of smart contracts in public procurement. In this context, we wish to realistically outline the legal regime of smart public procurement contracts. For this, we analyze the potential use of blockchain and smart contracts in public procurement at two stages: contract award and contract execution. Our article also discusses case studies of smart public procurement contracts, in order to assess their compatibility with and their impact on the EU public procurement system.
Abstract - The whole concept of self-sovereign identity (SSI) is gaining a lot of optimism, with the emerging Blockchain Technology in the current tech-scenario. It is a major change in how online interactions will take place in the future considering the identity of each user. The different aspects of SSI are examined by various works in the literature This paper surveys the origin of identity, various digital identity models and how it leads to self-sovereign identity. It then goes on to discuss related research, as well as the SSI's building blocks, which include decentralized IDs, verifiable credentials, a distributed ledger, and a variety of privacy mechanisms. Finally, it proposes a solution for self-sovereign identity by using the Ethereum platform for blockchain and other technologies
The paper presents the construction of a proof-of-concept for a distributed and decentralized e-voting application in an IoT embedded device with the help of blockchain technology. A SoC board was used as an IoT embedded device for testing the PoC. This solution ensures complete voter anonymity and end-to-end security for all entities participating in the electronic voting process. The paper outlines the solution’s two layers. Implementation details are presented for the e-voting application, which was deployed inside of an IoT embedded device. The solution and presented protocols provide two major properties: privacy and verifiability. To ensure privacy, the proposed solution protects the secrecy of each electronic vote. As for implementing verifiability, the solution prevents a corrupt authority from faking in any way the process of counting the votes. Both properties are achieved in the presented solution e-VoteD-App.
Abstract In recent years, With the rapid development of blockchain technol- ogy, there has been an increased interest in solving various opera- tional challenges. For the e-voting system at present, voter’s privacy, immutability of votes and third party dependency are major issues. These issues can very well be solved by blockchain technology. In this paper, we have proposed a decentralized framework for e-voting based on blockchain technology that contributes significantly to the implementation paradigm. We have implemented it on the Ethereum platform and developed a fully functional smart contract to store and validate votes. The research provides deep insight into the design of smart contract transactions in an e-voting system from a computa- tional cost perspective. In order to authenticate the voters, We have done voter verification in two phases. In the first phase, the voter reg- isters through a secure code, whose(code) Keccak-256 hash is stored on the blockchain, and in the second phase, the voter is verified by the managing authority. Based on the literature review, we found a lack of standardization for blockchain-based e-voting systems. So we have tried to fill this gap of standardization. In addition, we have also inspectedour model against various security attacks and found that our model is robust against double-spend attack, re-entrancy attack, DDoS etc.
Decentralized electronic voting solutions represent a promising advancement in electronic voting. One of the e-voting paradigms, the self-tallying scheme, offers strong protection of the voters' privacy while making the whole voting process verifiable. Decentralized smart contract platforms became interesting practical instantiation of the immutable bulletin board that this scheme requires to preserve its properties. Existing smart contract-based approaches employing the self-tallying scheme (such as OVN or BBB-Voting) are only suitable for a boardroom voting scenario due to their scalability limitation. The goal of our work is to build on existing solutions to achieve scalability without losing privacy guarantees and verifiability. We present SBvote, a blockchain-based self-tallying voting protocol that is scalable in the number of voters and therefore suitable for large-scale elections. The evaluation of our proof-of-concept implementation shows that the protocol's scalability is limited only by the underlying blockchain platform. We evaluated the scalability of SBvote on two public smart contract platforms -- Gnosis and Harmony. Despite the limitations imposed by the throughput of the blockchain platform, SBvote can accommodate elections with millions of voters.
Siddharth Singh, Rohit Prasad, Usha Dhankhar, Seema Malik
The revolutionary concept of blockchain has given a rise to multiple facets of secure, accountable, online services. We witness the rise of E-voting as a critical topic related to online services. Blockchain with smart contracts emerges as a good candidate to use in the development of safer, cheaper, more secure, more transparent, and easier to use e-voting systems. Ethereum and its network are one of the most viable candidates for the implementation of an e-voting system using blockchain, due to their consistency, widespread use, and provision of smart contracts logic. An e-voting system must be secure, as it should prevent duplication of votes while being fully transparent and protecting the privacy of the voters involved. In this work, we have implemented and tested a sample voting web - application as a smart contract for the Ethereum network using the Ethereum wallets and the Solidity language. Eventually, when elections are held, the Ethereum blockchain will store votes and voting results. Users can connect their Ethereum wallet and vote for the candidate they want to, and these transaction requests are processed by the consensus of each Ethereum node. These agreements create a transparent voting environment.
Yousif Mohammed Wahab, Alaan Ghazi, Aras Al-dawoodi, Muthana Alisawi · 7 authors
Election is a basic democratic tool that offers an official mechanism for the people to express their opinions in order to form a government by democratic means. Electronic voting has evolved into the most significant application of e-governance and e-democracy. Few countries have recently taken the opportunity to test and use electronic voting systems. Also, many countries expect that internet voting will become a reality during the next decade. In the conventional voting system, the electors authenticate themselves by displaying credentials; this move is open to the public and is validated by poll workers. During this authentication, they are manually checked before being eligible to vote. The standard system of voting is more costly and needs more human capital. Because of these factors, the whole world is heading toward the trend of e-voting. Electronic voting devices are supposed to be the answer to the shortages. A secure e-voting system must meet many criteria, including uniqueness, performance, fairness, stability, safety, authentication, and anonymity. Blockchain is a modern security solution, which is capable of securing e-voting system. Blockchain is distributed ledger. Each block contains only one transaction. Block chain provides security using cryptography and hashing. Blockchain provides a perfect infrastructure to provide secure e-voting netwms.ork. Blockchain along with smart contracts need hour to improvise an e-voting system. This paper presents a secure blockchain based framework for an e-electronic voting in Iraq.
Roseline Oluwaseun Ogundokun, Sanjay Misra, Rytis Maskeliūnas, Robertas Damaševičius
Federated learning (FL) is a scheme in which several consumers work collectively to unravel machine learning (ML) problems, with a dominant collector synchronizing the procedure. This decision correspondingly enables the training data to be distributed, guaranteeing that the individual device’s data are secluded. The paper systematically reviewed the available literature using the Preferred Reporting Items for Systematic Review and Meta-analysis (PRISMA) guiding principle. The study presents a systematic review of appliable ML approaches for FL, reviews the categorization of FL, discusses the FL application areas, presents the relationship between FL and Blockchain Technology (BT), and discusses some existing literature that has used FL and ML approaches. The study also examined applicable machine learning models for federated learning. The inclusion measures were (i) published between 2017 and 2021, (ii) written in English, (iii) published in a peer-reviewed scientific journal, and (iv) Preprint published papers. Unpublished studies, thesis and dissertation studies, (ii) conference papers, (iii) not in English, and (iv) did not use artificial intelligence models and blockchain technology were all removed from the review. In total, 84 eligible papers were finally examined in this study. Finally, in recent years, the amount of research on ML using FL has increased. Accuracy equivalent to standard feature-based techniques has been attained, and ensembles of many algorithms may yield even better results. We discovered that the best results were obtained from the hybrid design of an ML ensemble employing expert features. However, some additional difficulties and issues need to be overcome, such as efficiency, complexity, and smaller datasets. In addition, novel FL applications should be investigated from the standpoint of the datasets and methodologies.
The use of low-cost sensors in IoT over high-cost devices has been considered less expensive. However, these low-cost sensors have their own limitations such as the accuracy, quality, and reliability of the data collected. Fog computing offers solutions to those limitations; nevertheless, owning to its intrinsic distributed architecture, it faces challenges in the form of security of fog devices, secure authentication and privacy. Blockchain technology has been utilised to offer solutions for the authentication and security challenges in fog systems. This paper proposes an authentication system that utilises the characteristics and advantages of blockchain and smart contracts to authenticate users securely. The implemented system uses the email address, username, Ethereum address, password and data from a biometric reader to register and authenticate users. Experiments showed that the proposed method is secure and achieved performance improvement when compared to existing methods. The comparison of results with state-of-the-art showed that the proposed authentication system consumed up to 30% fewer resources in transaction and execution cost; however, there was an increase of up to 30% in miner fees.
Abstract Emerging technologies permeate and potentially disrupt a wide spectrum of our social, economic, and political relations. Various state institutions, including education, law enforcement, and healthcare, increasingly rely on technical components, such as automated decision-making systems, e-government systems, and other digital tools to provide cheap, efficient public services, and supposedly fair, transparent, disinterested, and accountable public administration. The increased interest in various blockchain-based solutions from central bank digital currencies, via tokenized educational credentials, and distributed ledger-based land registries to self-sovereign identities is the latest, still mostly unwritten chapter in a long history of standardized, objectified, automated, technocratic, and technologized public administration. The rapid, (often) unplanned, and uncontrolled technologization of public services (as happened in the hasty adoption of distance-learning and teleconferencing systems during Corona Virus Disease (COVID) lockdowns) raises complex questions about the use of novel technological components, which may or may not be ultimately adequate for the task for which they are used. The question whether we can trust the technical infrastructures the public sector uses when providing public services is a central concern in an age where trust in government is declining: If the government’s artificial intelligence system that detects welfare fraud fails, the public’s confidence in the government is ultimately hit. In this paper, we provide a critical assessment of how the use of potentially untrustworthy (private) technological systems including blockchain-based systems in the public sector may affect trust in government. We then propose several policy options to protect the trust in government even if some of their technological components prove fundamentally untrustworthy.
The Coronavirus disease 2019 has manifested into a global pandemic spreading into almost all the countries and territories in the world. Contact tracing, followed by testing and isolation, have been identified as important tools in containing the proliferation of the disease. Because of manual contact tracing limitations, smartphone apps for digital contact tracing have been deployed by authorities in multiple countries. However, many of these apps have faced criticism because of interoperability, privacy and security issues. This paper proposes an open architecture based on blockchain technology that addresses some of these criticisms. It enables interoperability through a publicly-readable consortium blockchain database, preserving privacy by distributing users’ partial identities among multiple decentralised authorities and providing security through digital signature and asymmetric key encryption. In addition, the architecture provides a fast proof-of-authority based consensus algorithm using reputation as a stake to add and validate blocks on the blockchain efficiently and a swift contact tracing algorithm using Spatio-temporal and key-valued databases.
Komal Gilani, Fariba Ghaffari, E. Bertin, Noël Crespi
In centralized infrastructures, users are not capable of authenticating themselves, in identity management systems, beyond their application’s domain. Users are forced to trust their service providers for identification and data management. Such solutions have experienced large-scale data breaches and are cumbersome for users to remember the credentials for multiple sites. Furthermore, users have very little control over their data. The concept of decentralized identity has raised the possibility of better managing these concerns. It allows users to share only the relevant part of their personal information with a service provider to verify their digital identity. We propose OrgID, a decentralized identity and user-centric data management platform including identity registration and authorization procedures. Our approach supports self-sovereign identity architecture leveraged by blockchain. This method consists of a one-time proof-verification mechanism that facilitates the secure access and credibility of digital information. Moreover, users can maintain their identities associated with specific attributes and rely on a proof mechanism using smart contracts. It deploys a platform where user registration and authorization no longer involve a central service provider. We implemented the proposed solution using smart contracts on a private Ethereum blockchain. We further analyzed the performance of these processes regarding the system’s scalability to evaluate how they manage latency and the number of users. The results state that the system is highly scalable to manage a large number of users and the system’s latency is adjustable based on the application needs.
Internet of Things is a recent potential advancement in an IT arena, consists of multiple smart things (devices) which are connected through a physical network. Cisco incorporation predicts that IoT network will connect 50 billion devices by 2020. Most of the industries are adopting IoT technology and because of its fast spreading, immense adoption and deployment current authentication mechanisms have serious disadvantages. For numerous reasons the security issues are the major hurdle in adoption and deployment of IoT on a large scale since it is highly vulnerable to attacks. In this paper we propose a Blockchain based authentication mechanism i.e. Ethereum which is a public blockchain as it has emerged as a technology that possess great capabilities of providing secure authentication, management and access control for IoT devices in a decentralized, trusty and flexible manner by creating a secure environment where the devices can identify and trust each other and only authenticated users are given permission to access them.
Muhammad Asif, Zeeshan Aziz, Maaz Bin Ahmad, Adnan Khalid · 6 authors
Security has always been the main concern for the internet of things (IoT)-based systems. Blockchain, with its decentralized and distributed design, prevents the risks of the existing centralized methodologies. Conventional security and privacy architectures are inapplicable in the spectrum of IoT due to its resource constraints. To overcome this problem, this paper presents a Blockchain-based security mechanism that enables secure authorized access to smart city resources. The presented mechanism comprises the ACE (Authentication and Authorization for Constrained Environments) framework-based authorization Blockchain and the OSCAR (Object Security Architecture for the Internet of Things) object security model. The Blockchain lays out a flexible and trustless authorization mechanism, while OSCAR makes use of a public ledger to structure multicast groups for authorized clients. Moreover, a meteor-based application is developed to provide a user-friendly interface for heterogeneous technologies belonging to the smart city. The users would be able to interact with and control their smart city resources such as traffic lights, smart electric meters, surveillance cameras, etc., through this application. To evaluate the performance and feasibility of the proposed mechanism, the authorization Blockchain is implemented on top of the Ethereum network. The authentication mechanism is developed in the node.js server and a smart city is simulated with the help of Raspberry Pi B+. Furthermore, mocha and chai frameworks are used to assess the performance of the system. Experimental results reveal that the authentication response time is less than 100 ms even if the average hand-shaking time increases with the number of clients.