Geoffrey Goodell, Hazem Danny Al-Nakib, Paolo Tasca
Objective : to present the new approach to perform monetary transactions with digital currency. Methods : abstract-logical, analytical methods. Results : in recent years, electronic retail payment mechanisms, especially e-commerce and card payments at the point of sale, have increasingly replaced cash in many developed countries. As a result, societies are losing a critical public retail payment option, and retail consumers are losing important rights associated with using cash. To address this concern, we propose an approach to digital currency that would allow people without banking relationships to transact electronically and privately, including both e-commerce purchases and point-of-sale purchases that are required to be cashless. The article shows the advantages of cash payments compared to non-cash ones and defines the possibility to transform these advantages into the central bank digital currencies. The disputable issues of commercial banks development under the spread of digital currencies are discussed. The architecture of digital currencies is described, including distributed ledgers technology. It was shown that, for the digital currency to function effectively, it is necessary to include the privacy of end-users into its architecture; measures to achieve that are determined. Scientific novelty : the approached proposed in the article should be used to develop the digital currencies infrastructure. It should be government-backed, privately-operated and ensure that every transaction is registered by a bank or money services business, relying upon non-custodial wallets backed by privacy-enhancing technology, such as blind signatures or zero-knowledge proofs, to ensure that transaction counterparties are not revealed. This approach can also facilitate more efficient and transparent clearing, settlement, and management of systemic risk. We argue that our system can restore and preserve the salient features of cash, including privacy, owner-custodianship, fungibility, and accessibility, while also preserving fractional reserve banking and the existing two-tiered banking system. Practical significance : the proposed approach can be applied in the practical organization of perform monetary transactions using digital currencies. The article was first published in English language by Future Internet. For more information please contact the editorial office. For original publication: Goodell G., Al-Nakib H. D., Tasca P. A Digital Currency Architecture for Privacy and Owner-Custodianship, Future Internet, 2021, 13, 130. https://doi.org/10.3390/fi13050130 Publication URL: https://www.mdpi.com/1999-5903/13/5/130
The rapid development of wearable sensors and the 5G network empowers traditional medical treatment with the ability to collect patients’ information remotely for monitoring and diagnosing purposes. Meanwhile, the health‐related mobile apps and devices also generate a large amount of medical data, which is critical for promoting disease research and diagnosis. However, medical data is too sensitive to share, which is also a common issue for IoT (Internet of Things) data. The traditional centralized cloud‐based medical data sharing schemes have to rely on a single trusted third party. Therefore, the schemes suffer from single‐point failure and lack of privacy protection and access control for the data. Blockchain is an emerging technique to provide an approach for managing data in a decentralized manner. Especially, the blockchain‐based smart contract technique enables the programmability for participants to access the data. All the interactions are authenticated and recorded by the other participants of the blockchain network, which is tamper resistant. In this paper, we leverage the K‐anonymity and searchable encryption techniques and propose a blockchain‐based privacy‐preserving scheme for medical data sharing among medical institutions and data users. To be specific, the consortium blockchain, Hyperledger Fabric, is adopted to allow data users to search for encrypted medical data records. The smart contract, i.e., the chaincode, implements the attribute‐based access control mechanisms to guarantee that the data can only be accessed by the user with proper attributes. The K‐anonymity and searchable encryption ensure that the medical data is shared without privacy leaking, i.e., figuring out an individual patient from queries. We implement a prototype system using the chaincode of Hyperledger Fabric. From the functional perspective, security analysis shows that the proposed scheme satisfies security goals and precedes others. From the performance perspective, we conduct experiments by simulating different numbers of medical institutions. The experimental results demonstrate that the scalability and performance of our scheme are practical.
In der Anfangszeit der Distributed Ledger Technologies (DLT) waren die hauptsächlichen Betrachtungswinkel die der Disruption des Bank- und Finanzwesens. Mit dem Aufkommen des Systems Ethereum im Jahr 2015, hat die Auseinandersetzung mit der Anwendung von Blockchain in weiteren Branchen, an Bedeutung gewonnen. Eine davon ist die Logistik und das Supply Chain Management (SCM). Gerade in Deutschland spielt der Logistiksektor eine große Rolle, nach der Beschäftigtenzahl ist er die drittgrößte Branche und erzielt einen Umsatz von rund 258 Milliarden Euro. Im Beitrag werden konkrete Anwendungsfelder identifiziert und gezeigt welche potentiellen Vorteile sich dort, durch den Einsatz von DLT, erzielen lassen. Ein Schwerpunkt liegt dabei auf der Einschätzung der Technologie hinsichtlich ihrer Sicherheitseigenschaften. Im Beitrag wird den Fragen nachgegangen, ob Datensicherheit mithilfe von DLT verbessert werden kann und auf welchem Wege.
Central banks and governments all over the world are increasingly exploring digital versions of fiat money, known as retail Central Bank Digital Currencies (CBDCs). Most initiatives rely on Distributed Ledger Technologies and are presented as alternatives to physical cash. Consequently, anonymity-related regulatory questions have naturally started to arise in terms of Anti-Money Laundering and Counter-Terrorist Financing compliance. Against this backdrop, this paper provides a techno-legal taxonomy of approaches to balance privacy and transparency in CBDCs without thwarting accountability, but it also underlines cross-sectoral impacts. The contribution heeds regulation-by-design as its core methodological foundation, with Privacy-Enhancing Technologies as the relevant use case. Thus, it highlights that not only technology aids legal purposes, but also that some regulatory requirements ought to be designed into technology for one to reach agreed-upon results and/or standards.
Alexander A. Varfolomeev, Liwa H. Al-Farhani, Zahraa Ch. Oleiwi
Over time, our lives turn to digitization and technology and its multiple applications and uses. The smart city, its technologies and the services provided during it have become a way of life. The idea of smart cities relied on different mechanisms to provide reliable services. One of the important technologies is the blockchain that has proven to be extremely reliable and has a high security level technology. This paper presents a mechanism to explain the application of blockchain technology in smart contracts, how to increase reliability, data security, and many positive benefits as part of the multiple services provided by the smart city environment. This paper also provides important details about this technology and its impact on the overall administrative system of any service provided by smart governments. The paper dealt with an example of how to manage the real estate rental file electronically to explain the advantages of blockchain technology through which we overcome existing problems in this type of contract and service.
The development of artificial intelligence and worldwide epidemic events has promoted the implementation of smart healthcare while bringing issues of data privacy, malicious attack, and service quality. The Medical Internet of Things (MIoT), along with the technologies of federated learning and blockchain, has become a feasible solution for these issues. In this paper, we present a blockchain-based federated learning method for smart healthcare in which the edge nodes maintain the blockchain to resist a single point of failure and MIoT devices implement the federated learning to make full of the distributed clinical data. In particular, we design an adaptive differential privacy algorithm to protect data privacy and gradient verification-based consensus protocol to detect poisoning attacks. We compare our method with two similar methods on a real-world diabetes dataset. Promising experimental results show that our method can achieve high model accuracy in acceptable running time while also showing good performance in reducing the privacy budget consumption and resisting poisoning attacks.
The demand for IoT systems in healthcare services is increasing widely and the data generated from these networks should be transferred and stored in a highly secure manner. Blockchain technology helps in maintaining the privacy and integrity of the electronic health records (EHR) data with the help of smart contracts that authenticate the users and maintain confidentiality in the network. Integrating blockchain into IoT systems improves the overall security of the network. In this paper, we propose an architecture based on Hyperledger Fabric which is a private blockchain platform that is used for storing the EHR data which are collected from various IoT sensors. The deployed smart-contract helps in performing some of the basic database functionalities onto the blockchain.
Although blockchain-based digital services promise trust, accountability, and transparency, multiple paradoxes between blockchains and GDPR have been highlighted in the recent literature. Some of the recent literature also proposed possible solutions to these paradoxes. This article aims to conduct a systematic literature review on GDPR compliant blockchains and synthesize the findings. In particular, the goal was to identify 1) the GDPR articles that have been explored in prior literature; 2) the relevant research domains that have been explored, and 3) the research gaps. Our findings synthesized that the blockchains relevant GDPR articles can be categorized into six major groups, namely data deletion and modification (Article 16, 17, and 18), protection by design by default (Article 25), responsibilities of controllers and processors (Article 24, 26, and 28), consent management (Article 7), data processing principles and lawfulness (Article 5,6 and 12), and territorial scope (Article 3). We also found seven research domains where GDPR compliant blockchains have been discussed, which include IoT, financial data, healthcare, personal identity, online data, information governance, and smart city. From our analysis, we have identified a few key research gaps and present a future research direction.
Abdullah Al Omar, Abu Kaisar Jamil, Amith Khandakar, Abdur Razzak Uzzal · 7 authors
A smart city ensures quality maintenance in diverse sectors, namely citizen safety, security, healthcare, transportation, and energy. Besides, data privacy and security have become an uprising concern for Electronic Health Records (EHR) in smart cities. This is because the EHR platforms are constantly getting cyber threats from cybercriminals. On the other hand, health insurance companies offer certain specific policies that require the association of patients' financial data with EHRs. Thus, additional security concern arises as fraudulent entities can alter these insurance policies. An extra challenge is triggered as patients need to validate their identities separately while communicating with different smart healthcare entities. This is because these healthcare facilities and insurance companies ought to ensure authenticity before offering any service for an individual. Hence, we have implemented a blockchain framework to safeguard patients' personal information and insurance policy. In this paper, we propose a solution for the healthcare system that provides data privacy and transparency. Furthermore, in the proposed system, insurance policies are incorporated in blockchain via the Ethereum platform and data privacy is shielded with cryptographic tools.
Abstract Information security has become the focus problem in the Internet of Things, and the traditional centralized access control model is faced with threats such as single point failure, internal attack, and central leak. In this paper, we proposed a model to improve the access control security of the Internet of Things, which is based on zero-knowledge proof and smart contract technology in the blockchain. Firstly, we deployed the attribute information of access control in the blockchain, which relieves the pressure and credibility problem brought by the third-party information concentration; Secondly, the encrypted access control token is used to gain the access permission of the resources, which makes the user's identity invisible and effectively avoids the attribute ownership exposure problem; Besides, the use of smart contracts solves the problem of low computing efficiency of Internet of Things devices and the waste of blockchain computing power resources; Finally, a prototype of Internet of Things access control system based on blockchain and zero-knowledge proof technology is implemented. The test analysis results show that the model achieves effective attribute privacy protection, compared with the Attribute-Based Access Control model of the same security level, the access efficiency increases linearly with the increase of access scale.
The interconnection of private resources on public infrastructure, user mobility and the emergence of new technologies (vehicular networks, sensor networks, Internet of things, etc.) have added new requirements in terms of security on the server side as well as the client side. Examples include the processing time, mutual authentication, client participation in the choice of security settings and protection against traffic analysis. Internet of Things (IoT) is in widespread use and its applications cover many aspects of today's life, which results in a huge and continuously increasing number of objects distributed everywhere.Security is no doubt the element that will improve and strengthen the acceptability of IoT, especially that this large scale deployment of IoT systems will attract the appetite of the attackers. The current cyber-attacks that are operational on traditional networks will be projected towards the Internet of Things. Security is so critical in this context given the underlying stakes; in particular, authentication has a critical importance given the impact of the presence of malicious node within the IoT systems and the harm they can cause to the overall system. The research works in this thesis aim to advance the literature on IoT authentication by proposing three authentication schemes that satisfy the needs of IoT systems in terms of security and performance, while taking into consideration the practical deployment-related concerns. One-Time Password (OTP) is an authentication scheme that represents a promising solution for IoT and smart cities environments. This research work extends the OTP principle and propose a new approach to generate OTP based on Elliptic Curve Cryptography (ECC) and Isogeny to guarantee the security of such protocol. The performance results obtained demonstrate the efficiency and effectiveness of our approach in terms of security and performance.We also rely on blockchains in order to propose two authentication solutions: first, a simple and lightweight blockchain-based authentication scheme for IoT systems based on Ethereum, and second, an adaptive blockchain-based authentication and authorization approach for IoT use cases. We provided a real implementation of our proposed solutions. The extensive evaluation provided, clearly shows the ability of our schemes to meet the different security requirements with a lightweight cost in terms of performance.
Francisco José de Haro-Olmo, Ángel Jesús Varela‐Vaca, José Antonio Álvarez Bermejo
The research presented aims to investigate the relationship between privacy and anonymisation in blockchain technologies on different fields of application. The study is carried out through a systematic literature review in different databases, obtaining in a first phase of selection 199 publications, of which 28 were selected for data extraction. The results obtained provide a strong relationship between privacy and anonymisation in most of the fields of application of blockchain, as well as a description of the techniques used for this purpose, such as Ring Signature, homomorphic encryption, k-anonymity or data obfuscation. Among the literature researched, some limitations and future lines of research on issues close to blockchain technology in the different fields of application can be detected. As conclusion, we extract the different degrees of application of privacy according to the mechanisms used and different techniques for the implementation of anonymisation, being one of the risks for privacy the traceability of the operations.
Blockchain as a distributed system that confirms security and reliability have started a new era of a solid and consensus system.Blockchains focus on cryptocurrency is encouraging many other processes to follow the same reliable approach of security.Almost all procedures and operations are now invited to be electronically performed in the digital Ethereum network that has been presented. Moreover, this study proposed the use of an Ethereum network on a blockchain platform in the study when it was moved to a blockchain network to confirm transparency.An E-voting system sample has been tested by using an Ethereum network smart contracts inwhich solidity language and wallets were used. In the voting test, the Ethereum blockchain will be able to collect records in which voters can use their Ethereum wallets or android devices to submit their votes in a consensus node.The researchers studied the voting system taking Jordan as a case study.This study recommended the adaptation of e-voting to support transparency and voters trust to reduce corruption and unreliability in the voting processes. Moreover, the use of this system will allow a voter to vote from home in the time of the pandemic.\n\n
A tecnologia de registro distribuído (DLT – Distributed Ledger Technology) pode ser muito útil para o tratamento de dados pessoais em conformidade com a Lei Geral de Proteção de Dados Pessoais (LGPD), devido a características como transparência e segurança. No entanto, outras características como a imutabilidade e o caráter distribuído podem dificultar essa tarefa. Assim, este trabalho analisa os desafios da conciliação entre DLT e o tratamento de dados em conformidade com a LGPD. Como objeto de análise, utilizou-se o projeto Datavalid do SERPRO - Serviço Federal de Processamento de Dados, contratado pela Uber, em um cenário hipotético em que o tratamento de dados foi realizado utilizando-se o Hyperledger Fabric.
Pedro Ivo de Castro Oyama, Jó Ueyama, Paulo Matias
Social media has become part of our daily lives. It brought significant developments in the way we communicate, but it also raised some concerns, including privacy and censorship. In this context, this work presents a social media platform -- EtherYou -- that makes use of cryptographic primitives and an Ethereum smart contract to overcome these issues. Experiments were conducted to evaluate the operating costs involved. The results showed considerable values for senders, zero for receivers, and zero maintenance costs, indicating its potential in scenarios with a reduced number of content producers and a large number of consumers. The proposal offers users privacy over their data, transparency on the system behaviour and censorship resistance.
<title>Abstract</title> Data is the most important factor in building a smart city. City data is composed of many data islands, such as transportation, industry, and residents. In order to build a smart city, breaking data islands, achieving trusted and collaborative sharing of data, while protecting data privacy are essential. As a distributed ledger, the blockchain can solve the problem of data trust. Federated learning achieves data privacy protection by sharing model parameters instead of original data. However, it still has some problems such as malicious nodes and differential attacks. This paper proposes a data sharing mechanism that combines blockchain and federated learning over smart city. Firstly, the blockchain is combined to ensure the credibility of the performance information of the work nodes, then the work node selection algorithm is designed, and a consensus incentive mechanism IPoQ is proposed for efficient federated learning tasks. Finally, differential privacy technology is introduced to resist differential attack. Experimental results show that the methods proposed in this paper achieves an effective federated learning data sharing mechanism.
Blockchain is one of the most trending technologies in past five years and it is called the new generation of the internet. Bitcoin was the first technology that used blockchain concept in its system. Blockchain has intense attention from academic community, developers and programmers, because of its distinctive properties such as decentralization, persistency, anonymity and auditability. Blockchain technology has evolved and is applicable in various applications outside the field. This paper provides background on blockchain technology and presents a suitable and logical solution for user authentication based on blockchain via the unified smart pass platform that allows the user to login with all service providers channels.
Received wisdom portrays digital records as guaranteeing perpetuity; as the New York Times wrote a decade ago: "the web means the end of forgetting". The reality however is that digital records suffer similar risks of access loss as the analogue versions they replace. Often this risk is outsourced to specialised third parties. Common use cases include Personal Information Management (PIM): e.g. calendars, diaries, tasks, etc. Frequently these are outsourced at two removes - firstly by the individual to their employer (e.g. using a company system) and then by their employer to an external provider. So enters a new risk: organisational change; by the time the information is required the organisational chain that links user to data may be broken: the employer transitions to a different provider, the employee leaves the company, the IS provider pivots to new offerings. The advent of Distributed Ledger Technology (DLT) could help mitigate these risks; and has led to a re-evaluation of the relationship between data creation and ownership. Although DLT is an imprecise term, it typically involves data storage across organisationally separate entities in a cryptographically secure form; and therefore could present a partial solution to the risk. This project presents the first research that applies DLT to the field of PIM, furthering design science state of the art by a novel implementation of a calendar application on the Ethereum blockchain. It also extends current research in utilising DLT in digital preservation, namely by enacting a continuum approach within a DL that allows for transfer of ownership of digital objects as they transition from individual to collective relevance. Finally it provides guidelines for future use of DLT within digital preservation.
Blockchain is an especially promising and revolutionary technology that brings transparency in a scalable way for multiple organizations and this is thanks to its several features. There are some exciting blockchain features but among them, decentralization is undoubtedly the most interesting one. Organizations can share data within a distributed ledger. As a consequence, each one can access synchronized data stored in its local Blockchain node. This functionality improves transaction tracking and facilitates access to data within a private group of organizations. However, in some cases, even if organizations accept to share data, they require to hide some private information related to their users or their business model. To tackle privacy and trust issues between organizations, this paper presents a blockchain architecture based on the proxy re-encryption scheme. This scheme is integrated within smart contracts to provide a very efficient, fast, and secure platform. The proposed architecture is implemented in an Hyperledger Blockchain and tested in a real transport and mobility use case.
Pedro Elkind Velmovitsky, Pedro Augusto Da Silva E Souza Miranda, Hélène Vaillancourt, Tania Donovska · 6 authors
BACKGROUND: Recent advancements in active assisted living (AAL) technologies allow older adults to age well in place. However, sensing technologies increase the complexity of data collection points, making it difficult for users to consent to data collection. One possible solution for improving transparency in the consent management process is the use of blockchain, an immutable and timestamped ledger. OBJECTIVE: This study aims to provide a conceptual framework based on technology aimed at mitigating trust issues in the consent management process. METHODS: The consent management process was modeled using established methodologies to obtain a mapping of trust issues. This mapping was then used to develop a conceptual framework based on previous monitoring and surveillance architectures for connected devices. RESULTS: In this paper, we present a model that maps trust issues in the informed consent process; a conceptual framework capable of providing all the necessary underlining technologies, components, and functionalities required to develop applications capable of managing the process of informed consent for AAL, powered by blockchain technology to ensure transparency; and a diagram showing an instantiation of the framework with entities comprising the participants in the blockchain network, suggesting possible technologies that can be used. CONCLUSIONS: Our conceptual framework provides all the components and technologies that are required to enhance the informed consent process. Blockchain technology can help overcome several privacy challenges and mitigate trust issues that are currently present in the consent management process of data collection involving AAL technologies.
The on-demand mobility market, including ridesharing, is becoming increasingly important with e-hailing fares growing at a rate of approximately 130% per annum since 2013. By increasing utilization of existing vehicles and empty seats, ridesharing can provide many benefits including reduced traffic congestion and environmental impact from vehicle usage and production. However, the safety of riders and drivers has become of paramount concern and a method for privacy-preserving identity verification between untrusted parties is essential for protecting users. To this end, we propose a novel privacy-preserving identity verification system, extending zero-knowledge proof (ZKP) and blockchain for use in ridesharing applications. We design a permissioned blockchain network to perform the ZKP verification of a driver's identity, which also acts as an immutable ledger to store ride logs and ZKP records. For the ZKP module, we design a protocol to facilitate user verification without requiring the exchange of any private information. We prototype the proposed system on the Hyperledger Fabric platform, with the Hyperledger Ursa cryptography library, and conduct extensive experimentation. To measure the prototype's performance, we utilize the Hyperledger Caliper benchmark tool to perform extensive analysis and the results show that our system is suitable for use in real-world ridesharing applications.
Dick Carrillo, Lam Duc Nguyen, Pedro H. J. Nardelli, Evangelos Pournaras · 14 authors
In this paper, we propose a global digital platform to avoid and combat epidemics by providing relevant real-time information to support selective lockdowns. It leverages the pervasiveness of wireless connectivity while being trustworthy and secure. The proposed system is conceptualized to be decentralized yet federated, based on ubiquitous public systems and active citizen participation. Its foundations lie on the principle of informational self-determination. We argue that only in this way it can become a trustworthy and legitimate public good infrastructure for citizens by balancing the asymmetry of the different hierarchical levels within the federated organization while providing highly effective detection and guiding mitigation measures toward graceful lockdown of the society. To exemplify the proposed system, we choose a remote patient monitoring as use case. This use case is evaluated considering different numbers of endorsed peers on a solution that is based on the integration of distributed ledger technologies and NB-IoT (narrowband IoT). An experimental setup is used to evaluate the performance of this integration, in which the end-to-end latency is slightly increased when a new endorsed element is added. However, the system reliability, privacy, and interoperability are guaranteed. In this sense, we expect active participation of empowered citizens to supplement the more usual top-down management of epidemics.
Chang Lu, Danielle Alves Batista, Hoda Hamouda, Victoria L. Lemieux
BACKGROUND: Although researchers are giving increased attention to blockchain-based personal health records (PHRs) and data sharing, the majority of research focuses on technical design. Very little is known about health care consumers' intentions to adopt the applications. OBJECTIVE: This study aims to explore the intentions and concerns of health care consumers regarding the adoption of blockchain-based personal health records and data sharing. METHODS: Three focus groups were conducted, in which 26 participants were shown a prototype of a user interface for a self-sovereign blockchain-based PHR system (ie, a system in which the individual owns, has custody of, and controls access to their personal health information) to be used for privacy and secure health data sharing. A microinterlocutor analysis of focus group transcriptions was performed to show a descriptive overview of participant responses. NVivo 12.0 was used to code the categories of the responses. RESULTS: Participants did not exhibit a substantial increase in their willingness to become owners of health data and share the data with third parties after the blockchain solution was introduced. Participants were concerned about the risks of losing private keys, the resulting difficulty in accessing care, and the irrevocability of data access on blockchain. They did, however, favor a blockchain-based PHR that incorporates a private key recovery system and offers a health wallet hosted by government or other positively perceived organizations. They were more inclined to share data via blockchain if the third party used the data for collective good and offered participants nonmonetary forms of compensation and if the access could be revoked from the third party. CONCLUSIONS: Health care consumers were not strongly inclined to adopt blockchain-based PHRs and health data sharing. However, their intentions may increase when the concerns and recommendations demonstrated in this study are considered in application design.