This paper examines the effects of inherent risks in the emerging technology of non-fungible tokens and proposes an actionable set of solutions for stakeholders in this ecosystem and observers. Web3 and NFTs are a fast-growing 300 billion dollar economy with some clear, highly publicized harms that came to light recently. We set out to explore the risks to understand their nature and scope, and if we could find ways to mitigate them. In due course of investigation, we recap the background of the evolution of the web from a client-server model to the rise of Web2.0 tech giants in the early 2000s. We contrast how the Web3 movement is trying to re-establish the independent style of the early web. In our research we discover a primary set of risks and harms relevant to the ecosystem, and classify them into a simple taxonomy while addressing their mitigations with solutions. We arrive at a set of solutions that are a combination of processes to be adopted, and technological changes or improvements to be incorporated into the ecosystem, to implement risk mitigations. By linking mitigations to individual risks, we are confident our recommendations will improve the security maturity of the growing Web3 ecosystem. We are not endorsing, or recommending specifically any particular product or service in our solution set. Nor are we compensated or influenced in any way by these companies to list these products in our research. The evaluations of products in our research have to simply be viewed as suggested improvements.
Johannes Sedlmeir, Jonathan Lautenschlager, Gilbert Fridgen, Nils Urbach
Abstract This position paper discusses the challenges of blockchain applications in businesses and the public sector related to an excessive degree of transparency. We first point out the types of sensitive data involved in different patterns of blockchain use cases. We then argue that the implications of blockchains’ information exposure caused by replicated transaction storage and execution go well beyond the often-mentioned conflicts with the GDPR’s “right to be forgotten” and may be more problematic than anticipated. In particular, we illustrate the trade-off between protecting sensitive information and increasing process efficiency through smart contracts. We also explore to which extent permissioned blockchains and novel applications of cryptographic technologies such as self-sovereign identities and zero-knowledge proofs can help overcome the transparency challenge and thus act as catalysts for blockchain adoption and diffusion in organizations.
Abstract Traditionally, governments and companies store data to identify persons for services provision and interactions. The rise of self-sovereign identities (SSIs) based on blockchain technologies provides individuals with ownership and control over their personal data and allows them to share their data with others using a sort of “digital safe.” Fundamentally, people have the sole ownership of their identity data and control when and how it is shared, protecting their privacy. As these data need to be validated to be trusted, they may become a more important data source for digital information sharing and transactions than the formal source of identity controlled by governments. Furthermore, SSIs can be used for interacting digitally with any organization. These developments change the relationship between government, companies, and individuals. We explore information sharing and governance in the digital society using blockchain-based SSIs. In addition, the impact of SSIs on data storage in the digital world is assessed. Technology enactment might result in no greater control or privacy and might only reinforce current practices. Finally, we argue that regulation and a combination of centralized and decentralized governance are still required to avoid misuse and ensure that envisaged benefits are realized.
Abstract Blockchain technology enables new kinds of decentralized systems. Thus, it has often been advocated as a “disruptive” technology that could have the potentiality of reshaping political, economic, and social relations, “solving” problems like corruption, power centralization, and distrust toward political institutions. Blockchain has been gradually gaining attention beyond finance and is thus applied by a range of different actors. This includes local, regional, and national governments interested in the potentiality of experimenting with blockchain-supported governance. This article contributes to identifying blockchain as a contested socio-political object prone to contradictory political imaginaries regarding its potentialities, particularly when applied to policy. The article explores some of the most praised of blockchain’s affordances (e.g., decentralization and transparency) in the context of Estonia, one of the most cited examples of blockchain governmental applications. Estonia has received international attention as the alleged first national infrastructure integrating blockchain. However, so far, few have asked: what kind of blockchain-based tools have been built by the Estonian government in practice and why? And to what extent do blockchain-based governmental applications reflect the original promises of disruption of the crypto-community? This article draws on a qualitative approach to explore several blockchain-based socio-technical objects to identify the narratives that have emerged in Estonia. The research shows clear contrasting views between stakeholders and technical experts from inside and outside the institutional sphere. The conflict revolves around two different social imaginaries associated with permissioned vs. public blockchains. The paper concludes with an analysis of the profound political implications of each vision.
Today’s online voting systems pose security concerns and cannot be used for public elections, while offline voting costs significantly more. As a result, a decentralized electronic voting system is emerging, backed by blockchain technology. With blockchain technology applied to online voting, the system can guarantee transparency and confidentiality because individual voter information and aggregate information are stored in a distributed fashion. Due to its decentralized nature, a blockchain-based voting system is more secure than the existing central server-based online voting system. In this study, an Ethereum-based electronic voting system was developed. This system resolves the issue of fraudulent voting by enhancing the safety and reliability of the electronic voting system.
The blockchain, with its key characteristics of decentralization, persistence, anonymity, and auditability, has become a solution to overcome the overdependence and lack of trust for a traditional public key infrastructure on third-party institutions. Because of these characteristics, the blockchain is suitable for solving certain open problems in the service-oriented social network, where the unreliability of submitted reviews of service vendors can cause serious security problems. To solve the unreliability problems of submitted reviews, this paper first proposes a blockchain-based identity authentication scheme and a new trusted service evaluation model by introducing the scheme into a service evaluation model. The new trusted service evaluation model consists of the blockchain-based identity authentication scheme, evaluation submission module, and evaluation publicity module. In the proposed evaluation model, only users who have successfully been authenticated can submit reviews to service vendors. The registration and authentication records of users' identity and the reviews for service vendors are all stored in the blockchain network. The security analysis shows that this model can ensure the credibility of users' reviews for service vendors, and other users can obtain credible reviews of service vendors via the review publicity module. The experimental results also show that the proposed model has a lower review submission delay than other models.
A movement for a more transparent and decentralized Internet is globally attracting more attention. People are becoming more privacy-aware of their online identities and data. The Internet is constantly evolving. Web2 focused on companies that provide services in exchange for personal user data. Web3 commits to user-centricity using decentralization and zero-server architectures. The current digital society demands a global change to empower citizens and take back control. Citizens are locked into big-tech for personal data storage and their for-profit digital identity. Protection of data has proven to be essential, especially due to increased home Internet traffic during the COVID pandemic. Citizens do not possess their own travel documents. The European Commission aims to transition this governmental property towards self-sovereign identity, introducing many new opportunities. Citizens are locked into banks with non-portable IBAN accounts and unsustainable legacy banking infrastructures. Migration to all-digital low-fraud infrastructures and healthier competitive ecosystems is essential. The overall challenge is to return the power to citizens and users again. The transition to a more decentralized Internet is the first crucial step in the realization of user-centricity. This thesis presents the first exploratory study that integrates governmental-issued travel documents into a (decentralized) societal infrastructure. These self-sovereign identities form the authentic base to a private and secure transfer of money and data, and can effectively provide trust in authenticity that is currently missing in online conversations. A fully operational zero-server infrastructure that incorporates all our requirements has been developed for Android using the P2P network overlay IPv8, and a personalized blockchain called TrustChain...
Ali Dorri, Clemence Roulin, Shantanu Pal, Sarah Baalbaki · 6 authors
In recent years, blockchain technology has received tremendous attention. Blockchain users are known by a changeable public key (PK) that introduces a level of anonymity; however, studies have shown that anonymized transactions can be linked to deanonymize the users. Most of the existing studies on user deanonymization focus on monetary applications; however, the blockchain has received extensive attention in nonmonetary applications such as the Internet of Things (IoT). In this article, we study the impact of deanonymization on the IoT-based blockchain. We populate a blockchain with data of smart home devices and then apply machine learning algorithms in an attempt to classify the transactions to a particular device that, in turn, risks the privacy of the users. Two types of attack models are defined: 1) informed attacks: where attackers know the type of devices installed in a smart home and 2) blind attacks: where attackers do not have this information. We show that machine learning algorithms can successful classify the transactions with 90% accuracy. To enhance the anonymity of the users, we introduce multiple obfuscation methods which include combining multiple packets into a transaction, merging ledgers of multiple devices, and delaying transactions. The implementation results show that these obfuscation methods significantly reduce the attack success rates to 20%–30% and, thus, enhance the user privacy.
Blockchain technology, recognized for its decentralized and privacy-preserving capabilities, holds potential for enhancing privacy in contact tracing applications. Existing blockchain-based contact tracing frameworks often overlook one or more critical design details, such as the blockchain data structure, a decentralized and lightweight consensus mechanism with integrated tracing data verification, and an incentive mechanism to encourage voluntary participation in bearing blockchain costs. Moreover, the absence of framework simulations raises questions about the efficacy of these existing models. To solve above issues, this article introduces a fully third-party independent blockchain-driven contact tracing (BDCT) framework, detailed in its design. The BDCT framework features an Rivest-Shamir-Adleman (RSA) encryption-based transaction verification method (RSA-TVM), achieving over 96% accuracy in contact case recording, even with a 60% probability of individuals failing to verify contact information. Furthermore, we propose a lightweight reputation corrected delegated proof of stake (RC-DPoS) consensus mechanism, coupled with an incentive model, to ensure timely reporting of contact cases while maintaining blockchain decentralization. Additionally, a novel simulation environment for contact tracing is developed, accounting for three distinct contact scenarios with varied population density. Our results and discussions validate the effectiveness, robustness of the RSA-TVM and RC-DPoS, and the low storage demand of the BDCT framework.
May Alhajri, Ahmad Salehi Shahraki, Carsten Rudolph
The rapid advances in fitness wearable devices are redefining privacy around interactions. Fitness wearables devices record a considerable amount of sensitive and private details about exercise, blood oxygen level, and heart rate. Privacy concerns have emerged about the interactions between an individual's raw fitness data and data analysis by the providers of fitness apps and wearable devices. This paper describes the importance of adopting and applying legal frameworks within the fitness tracker ecosystem. In this review, we describe the studies on the current privacy policies of fitness app providers, heuristically evaluate the methods for consent management by fitness providers, summarize the gaps identified in our review of these studies, and discuss potential solutions for filling the gaps identified. We have identified four main problems related to preserving the privacy of users of fitness apps: lack of system transparency, lack of privacy policy legibility, concerns regarding one-time consent, and issues of noncompliance regarding consent management. After discussing feasible solutions, we conclude by describing how blockchain is suitable for solving these privacy issues.
Ji Woong Kim, Su Jin Kim, Won Chul Cha, Taerim Kim
This study aims to introduce a novel blockchain-applied personal health records (PHR) application and validate its user experience. The system transmits the part corresponding to the patient’s personal information off-chain and prevents data forgery and falsification by storing encrypted data on-chain. Patients may easily trace the opt-in and opt-out history of their consent data and dynamically store the consent system for data exchange on the blockchain. A mixed-method study using a questionnaire, in-depth interviews, and usability evaluation were conducted for 30 participants. The system usability score was 74.0, indicating the high usability of the application. Those who were familiar with blockchain showed confidence in the application, but those unfamiliar wanted their data to be safe using another way. Most of the participants were interested in exchanging and using their medical data and considered security important but those unfamiliar wanted their data to be safe using another way. We found that participants were concerned about data security and considered a blockchain-based PHR as a novel way to store and exchange their medical information securely. Blockchain is not a visible technology. However, a blockchain-applied PHR must be able to win user trust through visualizations, certificates, and system descriptions.
Cryptocurrency systems can be subject to deanonimization attacks by exploiting the network-level communication on their peer-to-peer network. Adversaries who control a set of colluding node(s) within the peer-to-peer network can observe transactions being exchanged and infer the parties involved. Thus, various network anonymity schemes have been proposed to mitigate this problem, with some solutions providing theoretical anonymity guarantees. In this work, we model such peer-to-peer network anonymity solutions and evaluate their anonymity guarantees. To do so, we propose a novel framework that uses Bayesian inference to obtain the probability distributions linking transactions to their possible originators. We characterize transaction anonymity with those distributions, using entropy as metric of adversarial uncertainty on the originator's identity. In particular, we model Dandelion, Dandelion++ and Lightning Network. We study different configurations and demonstrate that none of them offers acceptable anonymity to their users. For instance, our analysis reveals that in the widely deployed Lightning Network, with 1% strategically chosen colluding nodes the adversary can uniquely determine the originator for about 50% of the total transactions in the network. In Dandelion, an adversary that controls 15% of the nodes has on average uncertainty among only 8 possible originators. Moreover, we observe that due to the way Dandelion and Dandelion++ are designed, increasing the network size does not correspond to an increase in the anonymity set of potential originators. Alarmingly, our longitudinal analysis of Lightning Network reveals rather an inverse trend -- with the growth of the network the overall anonymity decreases.
Blockchain systems come with a promise of decentralization that often stumbles on a roadblock when key decisions about modifying the software codebase need to be made. This is attested by the fact that both of the two major cryptocurrencies, Bitcoin and Ethereum, have undergone hard forks that resulted in the creation of alternative systems, creating confusion and opportunities for fraudulent activities. These events, and numerous others, underscore the importance of Blockchain governance, namely the set of processes that blockchain platforms utilize in order to perform decision-making and converge to a widely accepted direction for the system to evolve. While a rich topic of study in other areas, governance of blockchain platforms is lacking a well established set of methods and practices that are adopted industry wide. This makes the topic of blockchain governance a fertile domain for a thorough systematization that we undertake in this work. We start by distilling a comprehensive array of properties for sound governance systems drawn from academic sources as well as grey literature of election systems and blockchain white papers. These are divided into seven categories, confidentiality, verifiability, accountability, sustainability, Pareto efficiency, suffrage and liveness that capture the whole spectrum of desiderata of governance systems. We proceed to classify ten well-documented blockchain systems. While all properties are satisfied, even partially, by at least one system, no system that satisfies most of them. Our work lays out a foundation for assessing blockchain governance processes. While it highlights shortcomings and deficiencies in currently deployed systems, it can also be a catalyst for improving these processes to the highest possible standard with appropriate trade-offs, something direly needed for blockchain platforms to operate effectively in the long term.
Mike Wu, Will McTighe, Kaili Wang, István András Seres · 12 authors
A common misconception among blockchain users is that pseudonymity guarantees privacy. The reality is almost the opposite. Every transaction one makes is recorded on a public ledger and reveals information about one's identity. Mixers, such as Tornado Cash, were developed to preserve privacy through "mixing" transactions with those of others in an anonymity pool, making it harder to link deposits and withdrawals from the pool. Unfortunately, it is still possible to reveal information about those in the anonymity pool if users are not careful. We introduce Tutela, an application built on expert heuristics to report the true anonymity of an Ethereum address. In particular, Tutela has three functionalities: first, it clusters together Ethereum addresses based on interaction history such that for an Ethereum address, we can identify other addresses likely owned by the same entity; second, it shows Ethereum users their potentially compromised transactions; third, Tutela computes the true size of the anonymity pool of each Tornado Cash mixer by excluding potentially compromised transactions. A public implementation of Tutela can be found at https://github.com/TutelaLabs/tutela-app. To use Tutela, visit https://www.tutela.xyz.
Conventional electronic voting systems use a centralized scheme. A central administration of these systems manages the entire voting process and has partial or total control over the database and the system itself. This creates some problems, accidental or intentional, such as possible manipulation of the database and double voting. Many of these problems have been solved thanks to permissionless blockchain technologies in new voting systems; however, the classic consensus method of such blockchains requires specific computing power during each voting operation. This has a significant impact on power consumption, compromises the efficiency and increases the system latency. However, using a permissioned blockchain improves efficiency and reduces system energy consumption, mainly due to the elimination of the typical consensus protocols used by public blockchains. The use of smart contracts provides a secure mechanism to guarantee the accuracy of the voting result and make the counting procedure public and protected against fraudulent actions, and contributes to preserving the anonymity of the votes. Its adoption in electronic voting systems can help mitigate part of these problems. Therefore, this paper proposes a system that ensures high reliability by applying enterprise blockchain technology to electronic voting, securing the secret ballot. In addition, a flexible network configuration is presented, discussing how the solution addresses some of the security and reliability issues commonly faced by electronic voting system solutions.
With the development of the Internet of Things (IoT), the massive data sharing between IoT devices improves the Quality of Service (QoS) and user experience in various IoT applications. However, data sharing may cause serious privacy leakages to data providers. To address this problem, in this study, data sharing is realized through model sharing, based on which a secure data sharing mechanism, called BP2P-FL, is proposed using peer-to-peer federated learning with the privacy protection of data providers. In addition, by introducing the blockchain to the data sharing, every training process is recorded to ensure that data providers offer high-quality data. For further privacy protection, the differential privacy technology is used to disturb the global data sharing model. The experimental results show that BP2P-FL has high accuracy and feasibility in the data sharing of various IoT applications.
M. Francisca Hinarejos, Josep Lluís Ferrer Gomila, Amador Jaume Barcelo
Promotional schemes, such as promotional points and coupons, are highly effective marketing tools. Through these schemes, merchants can obtain customer loyalty or attract new customers, and customers can obtain benefits when purchasing goods or services. Therefore, the use of promotional schemes is considered to be a win-win strategy. Promotional points are becoming an increasingly popular way of providing customers with discounts or gifts to incentivise the purchase of some products. However, some security issues should be addressed: forgery, double-spending, privacy, etc. Blockchain is gaining popularity in academic research and business applications, as it has the potential to change business models in numerous sectors of the economy. The characteristics of blockchain (security, immutability, efficiency, etc.) can help to provide secure solutions for blockchain-based applications in the marketing field. In this paper, we propose a multimerchant, blockchain-based promotional point scheme that allows points to be transferred between customers and preserves customers’ privacy.
Daniel Maldonado-Ruiz, Jenny Torres, Nour El Madhoun, Mohamad Badra
Since the emergence of the Bitcoin cryptocurrency, the blockchain technology has become the new Internet tool with which researchers claim to be able to solve any existing online problem. From immutable log ledger applications to authorisation systems applications, the current technological consensus implies that most of Internet problems could be effectively solved by deploying some form of blockchain environment. Regardless this ‘consensus’, there are decentralised Internet-based applications on which blockchain technology can actually solve several problems and improve the functionality of these applications. The development of these new blockchain-based solutions is grouped into a new paradigm called Blockchain 3.0 and its concepts go far beyond the well-known cryptocurrencies. In this paper, we study the current trends in the application of blockchain on the paradigm of Public Key Infrastructures (PKI). In particular, we focus on how these current trends can guide the exploration of a fully Decentralised Identity System, with blockchain as be part of the core technology.
Compliance with the GDPR while using blockchain technology for data processing results in compliance issues, due to the fact that the blockchain and the GDPR employ different methods to ensure privacy-by-design and privacy-by-default. The blockchain is built on disintermediation and relative decentralization, whereas the GDPR aims for re-intermediation and relative centralization of the data protection process. This paper provides an overview of and suggestions on how to secure compliance with the GDPR while processing data using the blockchain. A focus is placed on the data protection impact assessment on the blockchain network, issues in identifying and determining the role(s) of sole and joint data controllers and data processors, obstacles to exercising the right to rectification and right to be forgotten when the data is recorded on the blockchain, GDPR data transfer requirements as applied to the blockchain, and the protection of privacy in the process of creating blockchain-based smart contracts.
Zusammenfassung In zunehmend vernetzten Systemen erstreckt sich die gesamte Datenwertschöpfungskette über eine Vielzahl an Systemen, wobei unterschiedliche Akteure mit unterschiedlichen und möglicherweise gegensätzlichen Interessen beteiligt sind. Es ist daher erforderlich, die Prozesse der Datenerfassung, Verarbeitung und Speicherung so abzusichern, dass Manipulationen durch externe Angriffe oder einzelne Akteure erkannt werden können. Dieser Beitrag legt den Fokus auf drei unterschiedliche technische Maßnahmen, durch welche Vertrauen in die ausgetauschten Daten selbst und letztendlich auch zwischen unterschiedlichen Akteuren hergestellt werden kann: Maßnahmen zur Kommunikationssicherheit schützen Daten während des Transports, digitale Kalibrierzertifikate erlauben eine Aussage über die Genauigkeit der erfassten Daten, Distributed-Ledger-Technologien wie zum Beispiel eine Blockchain erfassen Aktionen sowie beteiligte Akteure und legen diese Informationen manipulationsgeschützt ab. Dieser Beitrag bezieht sich auf das Forschungsprojekt GEMIMEG-II , das durch das Bundesministerium für Wirtschaft und Klimaschutz (BMWK) gefördert wird.
Phuc Nguyen Trong, Hong Khanh Vo, Huong Hoang Luong, Khiem Huynh Gia · 13 authors
YouTube connects people with each other through an online video sharing service platform. With the great devel-opment of the entertainment industry, content on YouTube is accessible to many people of different ages. However, verifying the content posted on YouTube is clean or not is a difficult problem. Dirty content is violent, pornographic and vulgar content that causes serious psychological harm to the segment of users under the age of 18, i.e., especially those of an age who are not yet aware of the harmful effects of content. Toxic will bring to the child’s behavior. Agree that Google (i.e., YouTube) has developed a YouTube Kid application where the videos are only for children under the age of 13. However, cultural and educational differences between regions strongly influence the choice of children. Select content for children. Therefore, the content restrictions on the YouTube Kid application have not yet met all the requirements of parents around the world. There have been many development directions to identify videos containing malicious content based on deep learning. However, there is no method to build a tool to support parents of children to share and identify videos with objectionable content (e.g., violence, pornography, obscene words) on the YouTube platform. In this research paper, we introduce YVC, a YouTube-verified content platform by applying blockchain’s distributed, public validation. This tool helps parents validate YouTube content and issue a report to reduce dirty content on YouTube. To demonstrate the effectiveness of our approach, we implement the proof-of-concept in the three most popular EVM platforms: Ethereum, Fantom, and the Binance smart chain. Compared to the YouTube Kids (i.e., the most common shared video platform for the under 13-year-old kid), our approach is able to capture the video preferences of the parents covering the difference areas/countries.
Abstract Trust is a key resource in financial transactions. Traditional financial institutions, and novel blockchain‐based decentralized financial (DeFi) services rely on fundamentally different sources of trust and confidence. The former relies on heavy regulation, trusted intermediaries, clear rules (and restrictions) on market competition, and long‐standing informal expectations on what banks and other financial intermediaries are supposed to do or not to do. The latter rely on blockchain technology to provide confidence in the outcome of rules encoded in protocols and smart contracts. Their main promise is to create confidence in the way the blockchain architecture enforces rules, rather than to trust banks, regulators, and markets. In this article, we compare the trust architectures surrounding these two financial systems. We provide a deeper analysis of how proposed regulation in the blockchain space affects the code‐ and confidence‐based architectures which so far have underwrote DeFi. We argue that despite the solid safeguards and guarantees which code can offer, the confidence in DeFi is still very much dependent on more traditional trust‐enhancing mechanisms, such as code governance, and antifraud regulation to address some of the issues which currently plague this domain, and which have no immediate, purely software‐based solutions. What is more, given the risks of bugs or scams in the DeFi space, regulation and trusted intermediaries may need to play a more active role, in order for DeFi to gain the trust of the next generation of users.
This thesis presents a generalised comprehensive framework for evaluating anonymity of cryptocurrency schemes. The framework was developed using security modelling with emphasis on a wide range of factors affecting anonymity, irrespective of the underlying implementation. The case studies presented in the thesis demonstrate how this framework facilitates the evaluation of anonymity of different cryptocurrencies in a standardised manner and the analysis of these findings reveals the complexity of the notion of anonymity.
The ever-increasing acceptance of cryptocurrencies has fueled applications beyond investment purposes. Crypto-payment is one such application that can bring radical changes to financial transactions in many industries, particularly e-commerce and online retail. However, characteristics of the technology such as transaction disintermediation, lack of central authority, and lack of adequate regulations may introduce new privacy and security concerns among the users. This coincides with another trend of rising individuals’ concerns pertaining to information privacy and security issues in online transactions. The current paper investigates how consumer trust in crypto-payment, a key determinant of consumer intentions and relational exchanges over the long-term, is formed based on their perceptions towards privacy and security aspects of the technology. Using data from 327 survey participants, the study found that perceived information privacy risk, perceived anonymity, and perceived traceability of transactions are significant determinants of consumer trust in crypto-payment; but their perceptions of information security fraud risk have no significant effect. It also provided support for the hypothesis that perceived trust contributes to consumers’ intention to adopt crypto-payment. The findings highlight the need to enhance consumer understanding and awareness of information privacy and potential security issues in crypto-payment as well as what needs to be done to address consumer concerns in this regard. The paper creates novel insights into the requirements of trust in crypto-payment services and the consequences of consumers’ perceptions of privacy and security in this domain.