As a service platform, blockchain has faced compliance issues since the General Data Protection Regulation (GDPR) came into effect in May 2018. Although many technical solutions have been proposed to solve the compatibility issues between blockchain and the GDPR, unresolved challenges remain. This study presents the gaps between the blockchain and the GDPR and explores solutions to bridge the gap.We review 91 previously published articles using a systematic literature review methodology. Then, we answer the following research questions: 1) Which solutions have been explored to allow the blockchain to comply with the GDPR? 2) What are the research gaps in the blockchain compliance field? Finally, we present five research gaps in this field: 1) development of a consent ontology model; 2) development of a methodology for monitoring fairness in the blockchain; 3) resolution of the contradiction between auditing and obfuscation; 4) development of a methodology for tracking controllers in the blockchain; and 5) integration of the different-purposed technical solutions without conflicts. Our research can raise the compatibility level of the blockchain and GDPR and guide the company adopting a blockchain to comply with the GDPR. Furthermore, it can advise the regulator to embrace new technologies into the GDPR while protecting a blockchain’s nature.
Mohammed Shuaib, Noor Hafizah Hassan, Sahnius Usman, Shadab Alam · 8 authors
The land registry system is one of the essential components of any governance model required to ascertain the ownership records uniquely. This paper reviews the existing literature and provides a detailed literature review consisting of 3 stages based on three research questions (RQ) that highlight the step by step evaluation and analysis. We selected 48 primary articles out of 477 extracted from different scientific databases based on criteria and RQ defined in the research method section. The majority of these papers focus on assessing the identity issues related to the land registry system and reviewing the existing identity models to find the best possible identity model to resolve the identified identity problems in the land registry. This paper examines the current land registry model and its shortcomings. It explains the various blockchain types and their characteristics. It further evaluates the usability of blockchain technology in different aspects of the land registry. Identity management is one of such weaknesses in the blockchain‐based land registry model that has been assessed in detail. Identity issues of blockchain‐based models have been further evaluated on defined criteria. The paper ends with a discussion on possible identity models and their comparative analysis to ascertain the most suitable identity model to resolve the identity issues of land registry systems.
As a kind of distributed, decentralized and peer-to-peer transmitted technology, blockchain technology has gradually changed people’s lifestyle. However, blockchain technology also faces many problems including selfish mining attack, which causes serious effects to the development of blockchain technology. Selfish mining is a kind of mining strategy where selfish miners increase their profit by selectively publishing hidden blocks. This paper builds the selfish mining model from the perspective of node state conversion and utilize the function extremum method to figure out the optimal profit of this model. Meanwhile, based on the experimental data of honest mining, the author conducts the simulation of selfish mining and discovers that selfish miners are able to acquire more revenue than honest miners when they account for more than 1/3 computing power of the whole system. Lastly, to defend the selfish mining attack, the author also summarizes the existing defending strategies and evaluates every kind of strategy briefly.
Abdullah Yousafzai, Latif U. Khan, Umer Majeed, Owais Hakeem · 5 authors
Federated learning (FL) enables the training of a shared collaborative machine learning model while keeping all the confidential training data on distributed devices. The FL state-of-the-art considers a monopolist FL task publisher. However, we present a FL marketplace where multiple FL task publishers and mobile devices co-exist for a set of diverse and varying learning tasks. Mobile devices participating in the training of FL models provides pay-as-you-go (i.e. using blockchain-based cryptocurrencies) FL training services to the FL task publishers. In the proposed framework, multiple FL task publishers may compete with each other and the participating workers (i.e. mobile devices) can choose one FL task publisher over another for participation in the training of a global model. We utilize code offloading for enabling customized FL pipelines in mobile devices and mitigating the model heterogeneity inherent in varying and changing FL tasks published by the task publishers. Experimental results indicate the efficacy of the proposed framework.
Silvia Gabrielli, Stephan Krenn, Donato Pellegrino, Juan Carlos Pérez Baún · 7 authors
Abstract The KRAKEN project aims to enable the sharing, brokerage, and trading of personal data including sensitive data (e.g., educational and health records and wellbeing data from wearable devices) by returning its control to both data subjects/data providers throughout the entire data lifecycle. The project is providing a data marketplace which will allow the sharing of personal data and its usage for research and business purposes, by using privacy-preserving cryptographic tools. KRAKEN is developing an advanced platform to share certified information between users and organizations by leveraging on distributed ledger technology, promoting the vision of self-sovereign identity solutions (ensuring users’ consent and data control in a privacy-friendly way), preserving security, privacy, and the protection of personal data in compliance with EU regulations (e.g., GDPR). The feasibility of the KRAKEN solution will be tested through two high-impact pilots in the education and healthcare fields.
May Alhajri, Carsten Rudolph, Ahmad Salehi Shahraki
Wearable fitness devices are widely used to track an individual’s health and physical activities to improve the quality of health services. These devices sense a considerable amount of sensitive data processed by a centralized third party. While many researchers have thoroughly evaluated privacy issues surrounding wearable fitness trackers, no study has addressed privacy issues in trackers by giving control of the data to the user. Blockchain is an emerging technology with outstanding advantages in resolving consent management privacy concerns. As there are no fully transparent, legally compliant solutions for sharing personal fitness data, this study introduces an architecture for a human-centric, legally compliant, decentralized and dynamic consent system based on blockchain and smart contracts. Algorithms and sequence diagrams of the proposed system’s activities show consent-related data flow among various agents, which are used later to prove the system’s trustworthiness by formalizing the security requirements. The security properties of the proposed system were evaluated using the formal security modeling framework SeMF, which demonstrates the feasibility of the solution at an abstract level based on formal language theory. As a result, we have shown that blockchain technology is suitable for mitigating the privacy issues of fitness providers by recording individuals’ consent using blockchain and smart contracts.
Montassar Naghmouchi, Hella Kaffel Ben Ayed, Maryline Laurent
Nowadays, open standards for self-sovereign identity and access management enable portable solutions that are following the requirements of IoT systems. This paper proposes a blockchain-based identity and access management system for IoT -- specifically smart vehicles -- as an example of use-case, showing two interoperable blockchains, Ethereum and Hyperledger Indy, and a self-sovereign identity model.
Aaliya Sarfaraz, Ripon K. Chakrabortty, Daryl Essam
In recent years, supply chains have evolved into huge ecosystems, demanding trust, provenance, and data privacy. Since blockchain technology (BCT) allows for the development of a distributed environment, it is ideal for supply chain management (SCM) applications. However, concerns regarding data privacy have impeded the development of blockchains. Despite the fact that some blockchains can restrict participants from reading and/or writing data, blockchain’s transparency makes protecting sensitive data challenging. To solve the data privacy challenge, this paper proposes a framework, AccessChain, that is an SCM access control framework that is based on an attribute-based access control (ABAC) model that restricts access to competing parties while allowing for network scalability. This proposed AccessChain model has two types of ledgers in its system: local and global. Local ledgers are used to store business contracts between stakeholders and the attribute-based access control model management, whereas the global ledger is used to record transaction data. AccessChain can enable decentralized, fine-grained and dynamic access control management in SCM when combined with the ABAC model and BCT. This paper’s experimental results illustrate that high throughput can be achieved in a large-scale request environment while maintaining data privacy and sustaining a scalable network.
Alina Khayretdinova, Michael Kubach, Rachelle Sellung, Heiko Roßnagel
Abstract New approaches to identity management based on technologies such as blockchain and distributed ledgers are promoted as a chance to give users full control over their own identity data. Despite being often called the future of digital identity management, Decentralized Identity Management (DIdM) and Self-sovereign Identities (SSI) are still facing a number of challenges, usability being a major one: their concepts are too sophisticated for users and do not fit their mental models. We address this by conducting a study that analyses and evaluates the usability and practical applicability of some of the most advanced DIdM solutions. The results of the user tests reveal existing usability issues and outline the way they deprive end users of experiencing the entire range of claimed privacy and security benefits of these identity solutions.
ABSTRACT The period from the mid-1990s to the mid-2000s saw the transformation of information and communication infrastructure. In the same period, TPRC evolved from a narrower focus on conventional telecommunications and information policy to “The Research Conference on Communications, Information, and Internet Policy.” Through the lens of my own interdisciplinary work on Internet policy and intersecting TPRC activity, this retrospective describes an arc of change that began at the 1994 TPRC and continued for about a decade. It combines description, commentary, and reflections on what this history might bode for TPRC as metaverses and Web3 progress from today’s hype to tomorrow’s Internet.
Individuals who wish to access a website or qualify for a loan are expected to expose personally identifying information, undermining their privacy and security. Firms share proprietary information in dealmaking negotiations which, if the deal fails, may be used by the negotiating partner for a competitive advantage. Regulators are expected to disclose their algorithmic tools to comply with public transparency and oversight requirements, a practice that risks rendering these tools circumventable and ineffective. Litigants might have to reveal trade secrets in court proceedings to prove a claim or defense. Such “verification dilemmas” — costly choices between opportunities that require the verification of some fact and risks of exposing sensitive information in order to perform that verification — appear across the legal landscape. Yet existing legal responses to them are imperfect. Legal responses often depend on ex post litigation procedures that can be prohibitively expensive for those most in need or are otherwise ineffective. Zero-knowledge proofs (ZKPs) — a class of cryptographic protocols that enables verification of a fact or characteristic of secret information without learning the actual secret — can help to avoid these verification dilemmas. ZKPs can provide a feasible means for a party who holds secret information to demonstrate desirable properties of this information while keeping the information otherwise hidden. Yet ZKPs have received scant notice in the legal literature. This Article fills that gap by providing the first deep dive into ZKPs’ broad relevance for law. It explains ZKPs’ conceptual power and technical operation to a legal audience. It then demonstrates how ZKPs can be applied as a governance tool to transform verification dilemmas in multiple legal contexts. Finally, the Article surfaces and provides a framework to address the policy issues implicated by introducing of ZKP governance tools into existing law and practice.
Hafiz Humza Saeed, Abdullah Bin Masood, Hassaan Khaliq Qureshi
Smart cities utilize digital technologies for the improvement of its services’ quality and performance by reducing resources’ cost and consumption, with a commitment of action and efficiency to its citizens. The increased urban migration has led to many problems in cities, such as traffic congestion, waste management, noise pollution, energy consumption, air pollution, etc., as nowadays COVID-19 pandemic has seized the whole world. So, it is necessary to carry out its standard operating procedures (SOPs), including less human interaction. Thus, technology plays a vital role via Internet-of-Things (IoT) based systems. In this paper, a lightweight security mechanism (LSM) is proposed to enrich the IoT based systems. Blockchain technology is integrated, and its completely decentralized peer-to-peer (P2P) technology enables the users’ authentication and authorizes legitimate procedures. The IoT based management system is developed to monitor some of the aforementioned problems and solve solid waste, air, and noise monitoring systems. The Ethereum blockchain is used to implement a smart contract based framework for the system’s security and access control. The evaluation of performance of the LSM demonstrates that it is an efficient and lightweight tool in terms of cost, resources, and computation and superior over related security studies.
When building the large-scale distributed decision control system based on mobile terminal devices (MTDs), electronic voting (E-voting) is a necessary technique to settle the dispute among parties. Due to the inherent insecurity of Internet, it is difficult for E-voting to attain complete fairness and robustness. In this study, we argue that Bitcoin blockchain offers better options for a more practical E-voting. We first present a coin mixing-based E-voting system model, which can cut off the relationship between the voter’s real identity and its Bitcoin address to achieve strong anonymity. Moreover, we devise a secret sharing-based E-voting protocol, which can prevent voting number from being leaked ahead and further realize strong robustness. We establish the probable security theory to prove its security. In addition, we use the experimental evaluation to demonstrate its efficiency.
Manuel Valentin, Claus Pahl, Nabil El Ioini, Hamid R. Barzegar
Recent developments in distributed ledger technologies have created a whole new set of possibilities in the way of managing trust, security, privacy and traceability in computer-based transactions, principles which are increasingly gaining importance in the world of IoT. Currently, IoT devices are generally based on centralized, client-server systems, where digital service providers have complete control over user data and information generated by their devices. In this paper we present the development of a decentralized access and management system for IoT devices, where operations on these devices, such as the installation and management of apps are handled by a blockchain-based identification and record system. The system prototype consists of a smartphone application acting as a management hub for the whole system, an IoT device API implementation for allowing secure access to management and data functionalities, and a set of smart contracts on the Ethereum blockchain, where all necessary information for the functioning of the system is stored. The system allows app developers to provide their apps as Docker containers for IoT devices without the need to publish them on a centralized app store, and a regular user can subscribe to and access the available applications by paying in cryptocurrency without revealing any private information to the system. A cost and performance evaluation have been performed to assess the feasibility of the proposed solution.
This systematic review investigates consumer trust in blockchain applications and makes recommendations for future research. The review targeted papers focusing on blockchain applications, collecting data from a consumer perspective, and examining trust as an outcome variable. We excluded non-peer-reviewed papers written before 2008 or in languages other than English. Our search in 5 databases yielded 704 studies. 29 studies were retained for the full-text review and 5 studies were included after conflict resolution. The small number of studies retained for analysis highlights the need for further empirical research on consumer trust in blockchain technology. While blockchain remained a mysterious term for most consumers, trust was the main factor determining the use of blockchain applications. Additionally, interface design, service, and information quality, together with the platform's ability to allow consumers to investigate products using blockchain applications. Trust remains the central issue for blockchain as trust in this “trustless” system appears to be a prerequisite for actual use, creating a “trust paradox”. This systematic review on consumer trust in blockchain technology is the first to provide a preliminary synthesis of consumers' needs and expectations for blockchain developers and provides important directions for future research on blockchain applications.
Mpyana Mwamba Merlec, Youn Kyu Lee, Seng-Phil Hong, Hoh Peter In
A massive amount of sensitive personal data is being collected and used by scientists, businesses, and governments. This has led to unprecedented threats to privacy rights and the security of personal data. There are few solutions that empower individuals to provide systematic consent agreements on distinct personal information and control who can collect, access, and use their data for specific purposes and periods. Individuals should be able to delegate consent rights, access consent-related information, and withdraw their given consent at any time. We propose a smart-contract-based dynamic consent management system, backed by blockchain technology, targeting personal data usage under the general data protection regulation. Our user-centric dynamic consent management system allows users to control their personal data collection and consent to its usage throughout the data lifecycle. Transaction history and logs are recorded in a blockchain that provides trusted tamper-proof data provenance, accountability, and traceability. A prototype of our system was designed and implemented to demonstrate its feasibility. The acceptability and reliability of the system were assessed by experimental testing and validation processes. We also analyzed the security and privacy of the system and evaluated its performance.
Institutions in highly regulated domains such as finance and healthcare often have restrictive rules around data sharing. Federated learning is a distributed learning framework that enables multi-institutional collaborations on decentralized data with improved protection for each collaborator's data privacy. In this paper, we propose a communication-efficient scheme for decentralized federated learning called ProxyFL, or proxy-based federated learning. Each participant in ProxyFL maintains two models, a private model, and a publicly shared proxy model designed to protect the participant's privacy. Proxy models allow efficient information exchange among participants without the need of a centralized server. The proposed method eliminates a significant limitation of canonical federated learning by allowing model heterogeneity; each participant can have a private model with any architecture. Furthermore, our protocol for communication by proxy leads to stronger privacy guarantees using differential privacy analysis. Experiments on popular image datasets, and a cancer diagnostic problem using high-quality gigapixel histology whole slide images, show that ProxyFL can outperform existing alternatives with much less communication overhead and stronger privacy.
Internet of Things (IoT) applications bring evolved and intelligent services that can help improve users' daily lives. These applications include home automation, health care, and smart agriculture. However, IoT development and adoption face various security and privacy challenges that need to be overcome. As a promising security paradigm, context-aware security enables one to enforce security and privacy mechanisms adaptively. Moreover, with the advancements in edge computing, context-aware security services can dynamically be placed close to a user's location and enable the support of low latency communication and mobility. Therefore, the design of an adaptive and decentralized access control mechanism becomes a necessity. In this paper, we propose a decentralized context-aware authorization management as a service based on the blockchain. The proposed architecture extends the Authentication and Authorization for Constrained Environments (ACE) framework with blockchain technology and context-awareness capabilities. Instead of a classic Open Authorization 2.0 (OAuth) access token, it uses a new contextual access token. The evaluation results show our proposition's effectiveness and advantages in terms of usability, security, low latency, and energy consumption.
Vincent Schlatt, Johannes Sedlmeir, Simon Feulner, Nils Urbach
Know your customer (KYC) processes place a great burden on banks, because they are costly, inefficient, and inconvenient for customers. While blockchain technology is often mentioned as a potential solution, it is not clear how to use the technology's advantages without violating data protection regulations and customer privacy. We demonstrate how blockchain-based self-sovereign identity (SSI) can solve the challenges of KYC. We follow a rigorous design science research approach to create a framework that utilizes SSI in the KYC process, deriving nascent design principles that theorize on blockchain's role for SSI.
Purpose: The study aimed to determine why Turkish participants are voluntary or hesitant to use cryptocurrencies and to assess which factors affected cryptocurrencies usage. Method: Technology acceptance model (TAM) was used in the study to analyze Turkish individuals’ cryptocurrency usage behavior. Structural equation (regression) modeling (SEM) was used to test the research model. AMOS and SPSS programs were used for analysis. Findings: The study model showed that cryptocurrency usage was exposed to the most effect by perceived benefit. Contrary to expectations, perceived risk did not make any significant effect on usage behavior. A causality relation between perceived benefit and decentralization factor was found more than other benefit sub-factors. Perceived ease of use had no positive direct relation with usage behavior in the study. Perceived ease of use had a positive relation with perceived benefit in the study.