E-voting is one of the valid use cases of blockchain technology with many blockchain e-voting systems already proposed. But efforts that focus on critical analysis of blockchain e-voting architectures for national elections from stakeholdersâ perspectives are mostly lacking in the literature. Therefore, government decision-makers and election stakeholders do not yet have a sufficient basis to understand the potential risks, challenges, and prospects that are associated with blockchain e-voting. This paper demonstrates how the use of the Architecture Trade-off Analysis Method (ATAM) can enable stakeholders in national elections to understand the risks, prospects, and challenges that could be associated with a blockchain e-voting system for national elections. By using a study context of South Africa, a proposed blockchain e-voting architecture was used as a basis to aid election stakeholders to reason on the concept of blockchain e-voting to get them to understand the potential risks, security threats, critical requirements attributes, and weaknesses that could be associated with using blockchain e-voting for national elections. The study found that blockchain e-voting can prevent many security attacks, internal vote manipulation, and promote transparency. However, voter validation and the security of the blockchain architecture are potential weaknesses that will need significant attention.
In order to contain the COVID-19 pandemic, several countries enforced extended social distancing measures for several weeks, effectively pausing the majority of economic activities. In an effort to resume economic activity safely, several Digital Contact Tracing applications and protocols have been introduced with success. However, DCT is a reactive method, as it aims to break existing chains of disease transmission in a population. Therefore DCT is not suitable for proactively preventing the spread of a disease; an approach that relevant to certain use cases, such as international tourism, where individuals travel across borders. In this work, we first identify the limitations characterising DCT related to privacy issues, unwillingness of the public to use DCT mobile apps due to privacy concerns, lack of interoperability among different DCT applications and protocols, and the assumption that there is limited, local mobility in the population. We then discuss the concept of a Health Passport as a means of verifying that individuals are disease risk-free and how it could be used to resume the international tourism sector. Following, we present the DHP Framework that uses a private blockchain and Proof of Authority for issuing Digital Health Passports. The framework provides a distributed infrastructure supporting the issuance of DHPs by foreign health systems and their verification by relevant stakeholders, such as airline companies and border control authorities. We discuss the attributes of the system in terms of its usability and performance, security and privacy. Finally, we conclude by identifying future extensions of our work on formal security and privacy properties that need to be rigorously guaranteed via appropriate security protocols.
Yi Liu, Jialiang Peng, Jiawen Kang, Abdullah M. Iliyasu ¡ 6 authors
Federated learning (FL) has recently been proposed as an emerging paradigm to build machine learning models using distributed training datasets that are locally stored and maintained on different devices in 5G networks while providing privacy preservation for participants. In FL, the central aggregator accumulates local updates uploaded by participants to update a global model. However, there are two critical security threats: poisoning and membership inference attacks. These attacks may be carried out by malicious or unreliable participants, resulting in the construction failure of global models or privacy leakage of FL models. Therefore, it is crucial for FL to develop security means of defense. In this article, we propose a blockchain-based secure FL framework to create smart contracts and prevent malicious or unreliable participants from being involved in FL. In doing so, the central aggregator recognizes malicious and unreliable participants by automatically executing smart contracts to defend against poisoning attacks. Further, we use local differential privacy techniques to prevent membership inference attacks. Numerical results suggest that the proposed framework can effectively deter poisoning and membership inference attacks, thereby improving the security of FL in 5G networks.
TomĂĄs Robles, Borja Bordel, RamĂłn Alcarria, Diego SĂĄnchez-de-Rivera
Users are each day more aware of their privacy and data protection. Although this problem is transversal to every digital service, it is especially relevant when critical and personal information is managed, as in eHealth and well-being services. During the last years, many different innovative services in this area have been proposed. However, data management challenges are still in need of a solution. In general, data are directly sent to services but no trustworthy instruments to recover these data or remove them from services are available. In this scheme, services become the usersâ data owners although users keep the rights to access, modify, and be forgotten. Nevertheless, the adequate implementation of these rights is not guaranteed, as services use the received data with commercial purposes. In order to address and solve this situation, we propose a new trustworthy personal data protection mechanism for well-being services, based on privacy-by-design technologies. This new mechanism is based on Blockchain networks and indirection functions and tokens. Blockchain networks execute transparent smart contracts, where usersâ rights are codified, and store the usersâ personal data which are never sent or given to external services. Besides, permissions and privacy restrictions designed by users to be applied to their data and services consuming them are also implemented in these smart contracts. Finally, an experimental validation is also described to evaluate the Quality of Experience (in terms of user satisfaction) and Quality of Service (in terms of processing delay) compared to traditional service provision solutions.
May 1, 2020¡2020 IEEE 6th Intl Conference on Big Data Security on Cloud (BigDataSecurity), IEEE Intl Conference on High Performance and Smart Computing, (HPSC) and IEEE Intl Conference on Intelligent Data and Security (IDS)
Data Protection regulations, like GDPR, mandate security controls to secure Personal Identifiable Information (PII) of the users which they share with service providers. With the volume of shared data reaching exascale proportions, it is challenging to ensure GDPR compliance in real time. We propose a novel approach that integrates GDPR Ontology with Blockchain to facilitate real time automated data compliance. Our framework ensures data operation is allowed only when validated by data privacy policies in compliance with privacy rules in GDPR. When a valid transaction takes place the PII data is automatically stored off-chain in a database. Our system, built using Semantic Web and Ethereum Blockchain, includes an access-control system that enforces data privacy policy when data is shared with third parties.
For some time now, blockchain technology has been used for many purposes all over the world. The question arises â how do we regulate proving facts in a dispute between agreement parties when they use self-executing contracts? The answer to this question is explored in this research in the context of civil issues. Furthermore, the Polish law has introduced a new tool in the form of a âcontract of evidenceâ (similar to the parol evidence rule) which may increase the popularity of smart contracts. The research methodology is based on the analysis of the two existing regulations from the Civil Procedure Code and the Commercial Code. Moreover, legal scientific studies that indicate the risks associated with using self-executing contracts in such a way will be analysed. All efforts have been taken to obtain conclusions regarding the future of this type of solution in Poland and Polish smart cities.
Thomas Sødring, Petter Reinholdtsen, Svein Ălnes
Purpose This paper aims to examine the role blockchain can play for record-keeping by exploring what information from a record-keeping system it is possible to publish to a blockchain. A credible approach is presented, followed by a discussion on both benefits and limitations. Design/methodology/approach The approach is a combination of theorised possibilities verified with practical software implementation. The basis for the work is relevant record-keeping and blockchain literature. Findings The results show that it is possible to separate the formal record keeping structure from content, and this opens for new possibilities when integrating record keeping and block chain technologies. However, the approach does come with some limitations. Research limitations/implications The approach is beneficial where there is a record-keeping standard that has a clearly defined metadata model, and that also makes use of globally unique identifiers. Privacy legislation, for example, GDPR, may limit the scope of an implementation of the approach. Originality/value The originality lies in presenting an approach whereby a record-keeping standard is analysed, separating structural and content information to publish structural information to a blockchain.
Yan Zhuang, Yin-Wu Chen, ZonâYin Shae, ChiâRen Shyu
BACKGROUND Data coordination across multiple health care facilities has become increasingly important for many emerging health care applications. Distrust has been recognized as a key barrier to the success of such applications. Leveraging blockchain technology could provide potential solutions tobuild trust between data providers and receivers by taking advantage of blockchain properties such as security, immutability, anonymity, decentralization, and smart contracts. Many health technologies have empirically proven that blockchain designs fit well with the needs of health care applications with certain degrees of success. However, there is a lack of robust architecture to provide a practical framework for developers to implement applications and test the performance of stability, efficiency, and scalability using standard blockchain designs. A generalized blockchain model is needed for the health care community to adopt blockchain technology and develop applications in a timely fashion. OBJECTIVE This study aimed at building a generalized blockchain architecture that provides data coordination functions, including data requests, permission granting, data exchange, and usage tracking, for a wide spectrum of health care application developments. METHODS An augmented, 3-layered blockchain architecture was built on a private blockchain network. The 3 layers, from bottom to top, are as follows: (1) incorporation of fundamental blockchain settings and smart contract design for data collection; (2) interactions between the blockchain and health care application development environment using Node.js and web3.js; and (3) a flexible development platform that supports web technologies such as HTML, https, and various programing languages. Two example applications, health information exchange (HIE) and clinical trial recruitment, were developed in our design to demonstrate the feasibility of the layered architecture. Case studies were conducted to test the performance in terms of stability, efficiency, and scalability of the blockchain system. RESULTS A total of 331,142 simulated HIE requests from accounts of 40,000 patients were successfully validated through this layered blockchain architecture with an average exchange time of 11.271 (SD 2.208) seconds. We also simulated a clinical trial recruitment scenario with the same set of patients and various recruitment criteria to match potential subjects using the same architecture. Potential subjects successfully received the clinical trial recruitment information and granted permission to the trial sponsors to access their health records with an average time of 3.07 seconds. CONCLUSIONS This study proposes a generalized layered blockchain architecture that offers health technology community blockchain features for application development without requiring developers to have extensive experience with blockchain technology. The case studies tested the performance of our design and empirically proved the feasibility of the architecture in 2 relevant health application domains.
M.E in Computer Engineering from SVBIT, GTU, Gandhinagar, India., Pratik Patel, Pinkal Chauhan, M.E in Computer Engineering from LDRP, Gandhinagar, India.
In our everyday lives, IoT plays a vital role. It is crucial to sense, capture and share data from connected devices via internet. Existing system proposed centralized client/server approach where central authority keeps a record of all the activities. Failure of such centralized authority makes the whole system fail. A decentralized / distributed approach is therefore needed if a single failure point is avoided. In this paper contains information to integrating Blockchain in IoT ecosystem in order to achieve access control. We proposed smart contract based architecture which consist multiple permission contract, one decision contract and one entry contract, to achieve distributed and secure IoT device access control. To conclude system framework, we provide a case study in an IoT system with two laptops and one Raspberry Pi single-board computers, where the PCs, DC and EC are implemented based on the Ethereum smart contract platform to achieve the access control.
Christian Killer, Bruno Rodrigues, Raphael Matile, Eder J. Scheid ¡ 5 authors
Digitization of electoral processes depends on confident systems that produce verifiable evidence. The design and implementation of voting systems has been widely studied in prior research, bringing together expertise in many fields. Switzerland is organized in a federal, decentralized structure of independent governmental entities. Thus, its decentralized structure is a real-world example for implementing an electronic voting system, where trust is distributed among multiple authorities.
This paper studies three existing technical solutions for a self-sovereign identity on blockchains and analyzes the arising issues related to the General Data Protection Regulation (GDPR) of the European Union (EU). In particular, the paper provides an overview of the existing Sovrin self-sovereign identity on the Hyperledger Indy public permissioned blockchain as well as uPort and Jolocom on the Ethereum public permissionless blockchain. The paper then concludes with a discussion on the GDPR-compliance of the blockchain-based identity concepts.
The security and accountability issues are a challenge to the traditional structure from still widespread elections. General e-voting system use a centralized system, where one organization manages overall system. These organisations have full control over the database and system, allowing manipulation of the database. There should be no e-voting system to secure data and potential attacks should be able to withstand. Blockchain technology should solve certain voting problems. In this paper we are implementing an ethereum blockchain based electronic voting system. Ethereum blockchain networks are used to transfer money and store data. Networks are organized by one or more machines. Every node is a machine that running an ethereum client. The eligible one can run the node. By adopting blockchain in e-voting system database distribution, one of the cheating sources of database manipulation and data loss can be reduced. This can be a better solution for the currently existing issues over rigging the electronic voting machines to win elections by the political parties in our government.
While the digital layer of social interaction continues to evolve, the recently proclaimed hopes in the development of digital identity could be both naĂŻf and dangerous. Rather than just asking ourselves how we could digitize existing features of identity management, and corresponding financial transactions on a community or state level, we submit that truly useful and innovative digital identities need to be accompanied by some significant rethinking of the essential basics behind the organization of the world. Once digital technologies leave the realm of purely on-line or deeply local projects, the confrontation with the world of citizenshipâs biases and the random distribution of rights and duties precisely on the presumption of the lack of any choice and absolute pre-emption of any disagreement comes into a direct conflict with all the benefits Distributed Ledger Technology purports to enable. Some proponents of Distributed Ledger Technology-based identity systems envisage âcloud communitiesâ with truly âself-sovereignâ individuals picking and choosing which communities they belong to. We rather see a clear risk that when implemented at the global scale, digital identity systems could be deeply harmful, reinforcing and amplifying the most repugnant aspects of contemporary citizenship. In this contribution we present a categorization of existing digital identity systems from a governance perspective, and discuss it on basis of three corresponding case studies which allow us to infer opportunities and limitations of Distributed Ledger Technology based identity. Subsequently, we put our findings in the context of existing preconditions of citizenship law, and conclude with a suggestion of a combination of several tests which we propose to avoid the plunge into a neo-feudal âbrave new worldâ. We would like to draw attention to the perspective that applying digital identity without rethinking the totalitarian assumptions behind the citizenship status will result in perfecting the current inequitable system, which is a move away from striving towards justice and a more dignified future of humanity. We see the danger that those might be provided with plenty of opportunities who already do not lack such under current governance structures, while less privileged individuals will witness their already weak position becoming increasingly worse.
In the last year, the concept of distributed ledgers has entered mainstream company and policy agendas. Between different types of ledgers, it can be said that blockchain is the most notable. Different studies have shown that blockchain technology can reduce bureaucracy, increase the level of trust in public recordkeeping. In order to make further progress in its implementation in the different areas, it is necessary first of all that technological and ecosystem maturity of distributed ledgers have to increase in order to unlock the transformative power of blockchain; and in second instance the Policy agenda should focus on non-technological barriers, and create new administrative processes that can be re-engineered for blockchain. But, this new context, faces new legal challenges: personal data, free circulation of data..., which must to be analysed. The main objective of this paper is to analyse the new legal challenges from technical and methodological points of view.
Advanced wireless technology in Internet of Things (IoT) devices is increasing and facing various security threats. The authentication of IoT devices is the first line of defense for the wireless network. Especially in a Wi-Fi network, the existing authentication methods mainly use a password or digital certificate, these methods are inconvenient to manage due to certificate issuance or prone to be attacked because passwords are easily cracked. In this paper, we propose a location-aware authentication scheme using smart contracts to ensure that IoT devices can securely perform Wi-Fi network authentication. The scheme adopts the concept of secondary authentication and consists of two phases: the registration phase, which is mainly designed to complete the generation of the public and private keys, and to link the device information with its related device information; the authentication phase, which is mainly designed to determine whether the requesting device is within a legal location range. We use the smart contract to ensure the credibility and irreparability of the authentication process. Analysis of the attack model and the attacks at different stages proves that this certification scheme is assured, and the simulation results show that the overhead introduced by this scheme is acceptable, this scheme can provide greater security for the Wi-Fi authentication of IoT devices.
Venkata Marella, Bikesh Raj Upreti, Jani Merikivi, Virpi Kristiina Tuunainen
Abstract Contemporary cryptocurrencies lack legal, monetary, and institutional backing that traditional financial services employ. Instead, cryptocurrencies provide trust through technology. Despite the plethora of research in both trust and cryptocurrencies, the underlying attributes of the technologies that drive trust in cryptocurrencies are not well understood. To uncover these attributes, we analyze the corpus of 1.97 million discussion posts related to Bitcoin, the oldest and most widely used cryptocurrency. Based on earlier research, we identified functionality, reliability, and helpfulness as the focal constructs with which to evaluate usersâ trust in technology. In our analysis, we discovered 11 different attributes related to three technology constructs that are significant in creating and maintaining usersâ trust in Bitcoin. The findings are discussed in detail in the article.
Transgender community face serious socio-economic predicaments due to the discrepancy between their current gender expression and assigned gender identity at birth. Even though, a considerable amount work have been done to protect their basic human rights such as security, equality and social acceptance; trans people are still large victims of hate related crimes. With GDPR and other data protection laws and policies in place, now it is ever more important to protect the confidentiality of gender change information as well as to establish technical solutions that can prevent from inferring any sense of gender change from historical data. In this context, distributed ledger technologies such as blockchain present great opportunities for information integrity, security, privacy and access. However, at the same time provenance information extracted from immutable blockchain can be exploited to infer gender change. Addressing this paradox here we propose recommendations for managing gender change information in the blockchain environment in context of present sociopolitical, legislative and technical challenges associated with gender change.
When a user registers a digital service, the service provider often asks for the user's personal information, such as name, phone number and so on. With the digital services gradually becoming an indispensable part of our lives, the abuse and misappropriation of personal information have caused people's attention to the protection of it. At present, The technical schemes for personal information protection mainly focus on preventing information leakage. We provide protection in a different way: propose a traceable method for personal information registration based on blockchain, which can distinguish the service provider obtained the information legally or illegally, by storing the personal information transaction records on the blockchain. The proposed method includes both direct and third-party personal information transaction scenarios. In different scenarios, the user will send the encrypted personal information data or authorization file to the service provider. After the transaction record is confirmed to be on the blockchain, the certification center will assist the service provider to decrypt the personal information. With this method, users can clearly understand which personal information has been delivered to which service providers. Moreover, the user's personal information data involving privacy are not stored on or transmitted through the blockchain. Hence, there is no additional risk of information disclosure, so as to achieve the purpose of personal information protection. Additionally, we analyze the proposed method using Kailar logic, and conduct a transaction performance simulation using NS-3. It shows that our method has properties of privacy, reliability, and accountability, and can meet the transaction performance requirements under the practical application scene.
In recent years, cryptocurrencies implemented on top of Blockchains became very popular, with Bitcoin as the most prominent example. However, novel Blockchain-based platforms such as Ethereum also support distributed applications beyond cryptocurrencies through so-called smart contracts. Technically, smart contracts are programs, whose code and execution state is stored in the Blockchain, inherently featuring the ability to transfer (electronic) money during their execution. In this Bachelor thesis, we investigate how smart contracts can be used to implement a distributed crowdsensing application for tracking mobile objects by a crowd of privately owned mobile devices. Such a system could be used, for instance, to nd lost or stolen objects, such as keys, vehicles (cars, bicycles, . . . ), or pets tagged with short-range radio transmitters implemented using readily available Bluetooth or RFID technology. These objects can then be detected by smartphones of private users in the vicinity of the object, effectively implementing a huge sensor network covering many parts of the world without any upfront investments by a central entity. Although highly attractive, implementing a crowdsensing application on top of a Blockchain platform such as Ethereum comes with several challenges. First of all, users need incentives to participate in searching for mobile objects. A natural incentive is a monetary reward that participants automatically receive through the smart contract when reporting sightings (timestamped positions) of wanted objects. However, this directly brings up the problem of malicious participants (attackers) who try to get the reward without actually executing the work of searching for the object by simply reporting fake positions. Therefore, one major goal of this Bachelor thesis is to counter such attacks by proposing effective counter-measures, and implementing and evaluating them for the Ethereum platform. In detail, we propose a basic reputation-based approach for detecting fake positions which judges each sighting made by a mobile devices according to the reputation of that device, implemented by a smart contract. Furthermore, advanced attacks are identified compromising the basic reputation-based approach and effective counter-measures to these advanced attacks are proposed. Identified advanced attacks include reputation farming, where the attacker tries to aggregate reputation first before launching the attack, and the so-called copycat attack, where the attacker simply copies already submitted valid sightings form honest participants, making his fake positions indistinguishable from valid positions. Our evaluations analyses the monetary cost of executing smart contracts with and without our security mechanisms. The results show that the overhead included by our reputation-based approach is at maximum 45% of the cost of a smart contract without implemented security mechanisms.
Blockchain is an innovative technology which is used by cryptocurrencies as a public, immutable ledger for recording transactions, while more recent versions of Blockchain can also record smart contracts and other assets. Blockchain can be viewed as a distributed platform that holds transactional records without the involvement of a central authority, and where ensuring decentralization, transparency and security is of paramount importance. But the transparency requirement, absolutely necessary for improving trust among the blockchainâs users, came with a price: lack of privacy. In most of the blockchains which are based on Bitcoinâs Blockchain, anyone can query the blockchain and see all the transactions. This introduces a privacy issue which needs to be addressed. Although there are a few solutions for mitigating the privacy concern, we consider that true anonymity must be built-in, not added on trough extensions to the base protocol. We propose a novel solution, called RandAdminSuite, that addresses the blockchain privacy problem through a comprehensive approach that covers the blockchain architecture itself, transaction mechanism and cryptocurrency as well. RandAdminSuite offers some improvements over the concept of currency rewards for transaction processing nodes.