Marco Alessi, Alessio CamillĂČ, Enza Giangreco, Marco Matera · 6 authors
Sharing personal data with service providers is a fundamental resource for the times we live in. But data sharing represents an unavoidable issue, due to improper data treatment, lack of users' awareness to whom they are sharing with, wrong or excessive data sharing from end users who ignore they are exposing personal information. The problem becomes even more complicate if we try to consider the devices around us: how to share devices we own, so that we can receive pervasive services, based on our contexts and device functionalities. The European Authority has provided the General Data Protection Regulation (GDPR), in order to implement protection of sensitive data in each EU member, throughout certification mechanisms (according to Art. 42 GDPR). The certification assures compliance to the regulation, which represent a mandatory requirement for any service which may come in contact with sensitive data. Still the certification is an open process and not constrained by strict rule. In this paper we describe our decentralized approach in sharing personal data in the era of smart devices, being those considered sensitive data as well. Having in mind the centrality of users in the ownership of the data, we have proposed a decentralized Personal Data Store prototype, which stands as a unique data sharing endpoint for third party services. Even if blockchain technologies may seem fit to solve the issue of data protection, because of the absence of a central authority, they lay to additional concerns especially relating such technologies with specifications described in the regulation. The current work offers a contribution in the advancements of personal data sharing management systems in a distributed environment by presenting a real prototype and an architectural blueprint, which advances the state of the art in order to meet the GDPR regulation. Address those arisen issues, from a technological perspective, stands as an important challenge, in order to empower end users in owning their personal data for real.
Anik Islam, Md. Fazlul Kader, Md Mofijul Islam, Soo Young Shin
In order to stay up to date with world issues and cutting-edge technol-ogies, the newspaper plays a crucial role. However, collecting news is not a very easy task. Currently, news publishers are collecting news from their correspond-ents through social networks, email, phone call, fax etc. and sometimes they buy news from the agencies. However, the existing news sharing networks may not provide security for data integrity and any third party may obstruct the regular flow of news sharing. Moreover, the existing news schemes are very vulnerable in case of disclosing the identity. Therefore, a universal platform is needed in the era of globalization where anyone can share and trade news from anywhere in the world securely, without the interference of third-party, and without disclosing the identity of an individual. Recently, blockchain has gained popularity because of its security mechanism over data, identity, etc. Blockchain enables a distrib-uted way of managing transactions where each participant of the network holds the same copy of the transactions. Therefore, with the help of pseudonymity, fault-tolerance, immutability and the distributed structure of blockchain, a scheme (termed as NEWSTRADCOIN) is presented in this paper in which not only news can be shared securely but also anyone can earn money by selling news. The proposed NEWSTRADCOIN can provide a universal platform where publishers can directly obtain news from news-gatherers in a secure way by main-taining data integrity, without experiencing the interference of a third-party, and without disclosing the identity of the news gatherer and publishers.
As the Internet of Vehicle (IOV) being widely applied throughout our daily life, how to secure data privacy of each vehicle is nowadays a hot topic. Taking an aim of solving this problem, a privacy protection system on double-layered chain basis is designed to eliminate the said security risk during vehicle data communication. At the same time, the nontampering nature of the block chain is used to realize reasonable arbitration in traffic accident disputes, vehicle insurance claims, and other states of affairs. Specifically, an IOV double-layered chain model is constructed to simulate a semicentralized system that is convenient for government to supervise; also, a RSA protocol based on zero-knowledge proof (ZKP) is designed to bring safety and zero-knowledge property to the system; finally, we give the application scenario of this IOV privacy protection system based on double-layered chain that it can be widely used in vehicle-sharing industry. The communication costs, respectively, under double-layered chain and single-layered chain frameworks, are compared to prove that the double-layered structure does save cost. Thus an IOV privacy scheme that is safer and more cost-efficient is given.
Trust in a smart city is fundamental to its transparency, the participation of its people in governance, entrepreneurial initiatives, trade, commerce and hence the growth of its economy. A city gets smart by transforming itself to a digital city, and a digital city runs on data, analytics, internet of things, artificial intelligence and machine learning. This inevitable transformation creates the fundamental need for trust. How does data remain sacrosanct and verifiable? How do people trust institutions? How do institutions trust each other? How do devices trust each other? This article explores blockchain as an essential layer of trust in a smart city. It explains the technology by drawing real-life examples to the âmemory gameâ that operates in an ecosystem of âtrust and consensus.â The article provides further insight into institutions that can be governed on blockchain through âsmart contractsâ in a sovereign and human independent manner. The use cases of blockchain have been corroborated with examples of successful blockchain implementation. The value for blockchain, in general, and smart cities, in particular, has been presented across four categories: (a) the network effect on trust on society, governments and industries; (b) empowering the individual and strengthening the economy; (c) the liquid economy and (d) the shareable economy. Given the current topology of technology innovations, there is no solution better than blockchain that embodies trust. It is a hope and expectation that this article will help smart city planners, developers, architects and thinkers implement blockchain as the embodiment of trust in smart cities that are increasingly becoming digital.
Eine Analyse von 1498 Artikeln aus sechs Tageszeitungen zeigt, dass im deutschsprachigen Raum vorwiegend negativ ĂŒber den Bitcoin berichtet wird. Eine Analyse von 1498 Artikeln aus sechs Tageszeitungen zeigt, dass im deutschsprachigen Raum vorwiegend negativ ĂŒber den Bitcoin berichtet wird. Zwischen den untersuchten Tageszeitungen bestehen nur geringe Unterschiede. Zwischen den untersuchten Tageszeitungen bestehen nur geringe Unterschiede. Zwischen der Berichterstattung zum Bitcoin und dem Kursverlauf gibt es einen Zusammenhang. Zwischen der Berichterstattung zum Bitcoin und dem Kursverlauf gibt es einen Zusammenhang.
Long Finance's Distributed Futures research programme has produced a report entitled âTo Be, To Have, To Know: Smart Ledgers & Identity Authenticationâ, the latest in a series of exciting projects in the programme. The event offered the opportunity to join the discussion on the findings of the report, which showed how identity management and authentication systems can make use of leading technology, such as smart ledgers, as well as to explore the social, economic, and political implications of their use.
The research provides alternative models for practical identity management and authentication, and suggests considerations for policy makers, regulators, businesses, and individuals, both for the present and looking forward.
IoT devices are widely used in the smart home, automobile, and aerospace areas. Note, however, that recent information on thefts and hacking have given rise to many problems. The aim of this study is to overcome the security weaknesses of existing Internet of Things (IoT) devices using Blockchain technology, which is a recent issue. This technology is used in Machine-to-Machine (M2M) access paymentâKYD (Know Your Device)âbased on the reliability of existing IoT devices. Thus, this paper proposes a BoT (Blockchain of Things) ecosystem to overcome problems related to the hacking risk of IoT devices to be introduced, such as logistics management and history management. There are also many security vulnerabilities in the sensor multi-platform from the IoT point of view. In this paper, we propose a model that solves the security vulnerability in the sensor multi-platform by using blockchain technology on an empirical model. The color spectrum chain mentioned in this paper suggests a blockchain technique completed by using the multiple-agreement algorithm to enhance Thin-Plate Spline (TPS) performance and measure various security strengths. In conclusion, we propose a radix of the blockchainâs core algorithm to overcome the weaknesses of sensor devices such as automobile, airplane, and close-circuit television (CCTV) using blockchain technology. Because all IoT devices use wireless technology, they have a fundamental weakness over wired networks. Sensors are exposed to hacking and sensor multi-platforms are vulnerable to security by multiple channels. In addition, since IoT devices have a lot of security weaknesses we intend to show the authentication strength of security through the color spectrum chain and apply it to sensor and multi-platform using Blockchain in the future.
Nikos Fotiou, Vasilios A. Siris, George C. Polyzos
Despite technological advances, most smart objects in the Internet of Things\n(IoT) cannot be accessed using technologies designed and developed for\ninteracting with powerful Internet servers. IoT use cases involve devices that\nnot only have limited resources, but also they are not always connected to the\nInternet and are physically exposed to tampering. In this paper, we describe\nthe design, development, and evaluation of a smart contract-based solution that\nallows end-users to securely interact with smart devices. Our approach enables\naccess control, Thing authentication, and payments in a fully decentralized\nsetting, taking at the same time into consideration the limitations and\nconstraints imposed by both blockchain technologies and the IoT paradigm. Our\nprototype implementation is based on existing technologies, i.e., Ethereum\nsmart contracts, which makes it realistic and fundamentally secure.\n
Medical care has become one of the most indispensable parts of human lives, leading to a dramatic increase in medical big data. To streamline the diagnosis and treatment process, healthcare professionals are now adopting Internet of Things (IoT)-based wearable technology. Recent years have witnessed billions of sensors, devices, and vehicles being connected through the Internet. One such technology-remote patient monitoring-is common nowadays for the treatment and care of patients. However, these technologies also pose grave privacy risks and security concerns about the data transfer and the logging of data transactions. These security and privacy problems of medical data could result from a delay in treatment progress, even endangering the patient's life. We propose the use of a blockchain to provide secure management and analysis of healthcare big data. However, blockchains are computationally expensive, demand high bandwidth and extra computational power, and are therefore not completely suitable for most resource-constrained IoT devices meant for smart cities. In this work, we try to resolve the above-mentioned issues of using blockchain with IoT devices. We propose a novel framework of modified blockchain models suitable for IoT devices that rely on their distributed nature and other additional privacy and security properties of the network. These additional privacy and security properties in our model are based on advanced cryptographic primitives. The solutions given here make IoT application data and transactions more secure and anonymous over a blockchain-based network.
This chapter addresses the myth of decentralized governance of public blockchains, arguing that certain people who create, operate, or reshape them function much like fiduciaries of those who rely on these powerful data structures. Explicating the crucial functions that leading software developers perform, the chapter compares the role to Tamar Frankelâs conception of a fiduciary, and finds much in common, as users of these technologies place extreme trust in the leading developers to be both competent and loyal (ie, to be free of conflicts of interest). The chapter then frames the cost-benefit analysis necessary to evaluate whether, on balance, it is a good idea to treat these parties as fiduciaries, and outlines key questions needed to flesh out the fiduciary categorization. For example, which software developers are influential enough to resemble fiduciaries? Are all users of a blockchain âentrustorsâ of the fiduciaries who operate the blockchain, or only a subset of those who rely on the blockchain? Finally, the chapter concludes with reflections on the broader implications of treating software developers as fiduciaries, given the existing accountability paradigm that largely shields software developers from liability for the code they create.
The current legal and economic infrastructure facilitating data collection practices and data analysis has led to extreme over-collection of data and the overall loss of personal privacy. Data over-collection has led to a secondary market for consumer data that is invisible to the consumer and results in a person's data being distributed far beyond their knowledge or control. In this paper, we propose a Data Market framework and design for personal data management and privacy protection in which the individual controls and profits from the dissemination of their data. Our proposed Data Market uses a market-based approach utilizing blockchain distributed ledgers for data distribution transparency and control and digital rights management technologies to provide for data confidentiality and secure distribution of the data. Our market framework and design provides an economic, legal, and advanced technology infrastructure that protects an individuals' right to privacy while nurturing a flourishing information economy.
Data protection is about protecting information about per-sons, which is currently flowing without much control âindividuals can-not easily exercise the rights granted by the EU General Data Protection Regulation (GDPR). Individuals benefit from âfreeâ services offered by companies in exchange of their data, but these companies keep their usersâ data in âsilosâ that impede transparency on their use and possibilities of easy interactions. The introduction of the GDPR warrants control rights to individuals and the free portability of personal data from one entity to another. However it is still beyond the individualâs capability to perceive whether their data is managed in compliance with GDPR. To this regard, in this work the proposed approach consists in using decentralized mechanisms to provide transparency through distributed ledgers, data flow governance by using smart contracts and interoperability relying on semantic web technologies.
While the Internet provides enormous opportunities within development of communications and database systems it also endangers the processing of personal data unlawfully. With traditional database structure in focus the responsibility and accountability of said processed personal data was somewhat clear as the General Data Protection Regulation (GDPR) entered the legal framework of the European Unionâs member states in May 2018. Blockchain technology being the latest innovation in database structure challenges the applicability of the new regulation by introducing cryptography and a peer-to-peer distributed ledger technology. This thesis is the result of an attempt to analyze the personal data processed in public blockchains, i.e. Bitcoin, and its compliance with certain fundamental data protection rights stipulated in the GDPR such as the right to erasure of personal data. Furthermore, in relation to fundamental data protection rights violations are also subjects of accountability. While the new distributed ledger technology vastly increases the difficulty to determine a target for accountability the thesis also considers the traditional view on databases on which the GDPR was built upon. Thus, the thesis aims to further explore the relation between participants on the innovative blockchain and fundamental personal data protection rights in the GDPR.
This thesis aims to explore the compliance of blockchain technology and the GDPR. The GDPR was implemented for the EU member states in May 2018 with the purpose of harmonizing data protection regulation. However, the regulation is based on the notion that data is stored and processed in a centralized system. This causes an issue when it comes to distributed networks, and in particular with the distributed ledger technology (DLT), the underlying technology of blockchain. For this thesis, a literature review has been conducted to investigate the problems of GDPR compliance for blockchain projects, and what technical solutions exist to make a blockchain solution more GDPR compliant. In addition, interviews have been conducted to investigate the technical and legal perspectives on the current and future situations of regulation and technology. Compatibility problems mainly concern the immutability and transparency of a blockchain and examples of technical solutions that handle those problems can be found in the literature. Nevertheless, none of the discussed solutions are yet to guarantee full GDPR compliance. The technical and legal perspectives share ideas of the main compliance issues. However, differences such as interpretation of technical details can be identified, indicating problems to arise when regulating blockchains in the future. Further interdisciplinary work on guidelines for the GDPR is necessary for blockchain projects to be successful in complying with the regulation as well as to strengthen the technology neutrality of the GDPR.
Jan 1, 2019·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Practitioners as well as academics expect that blockchain technology is a game changer for a variety of use cases. This is because of its feature of transaction immutability enabled by keeping a history of all transactions. Nevertheless, this strength can become its biggest weakness. There already exists a lively discussion on scenarios where it is necessary to delete submitted data from the chain after it is no longer needed. This becomes even more crucial with the introduction of the European General Data Protection Regulation (GDPR). In this paper we make use of a design science research (DSR) approach to design an IT artifact in form of a prototype that maintains most of the key features of blockchain technology but deletes old data. We evaluate the prototype with help of experts to investigate what to expect from blockchains that delete data and derive principles on how to design them.
ÎÎ»Î”ÎŸÎŹÎœÎŽÏα ÎÎčÎ±ÎœÎœÎżÏÎżÏÎ»ÎżÏ , Valeria Ferrari
Blockchains and the GDPR pursue similar objectives where they seek to grant users greater control over their personal data. While the latter pursues this goal by imposing duties of care to centralised controllers and collectors of data, blockchains go a step beyond by trying to eliminate these stakeholders and the need to trust them. Nevertheless, the rules set out by the GDPR apply whenever personal data are at stake, and various actors of the blockchain ecosystem risk liability for controlling of processing data in violation of privacy requirements. A possible solution is to re-contextualise the concepts of data controlling and responsibility, as framed by the GDPR, in light of blockchainsâ enhanced individual autonomy. In this paper, we set the framework for a further inquiry on the role of users as both data subjects and data controllers of distributed ledgers.