Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

733 papersLast indexed Aug 31, 2026
Search papers

Paper index

733 results ¡ page 27 of 31

Clear filters
Jan 1, 2019¡Frontiers in Blockchain
80 cites
Digital Identity and the Blockchain: Universal Identity Management and the Concept of the “Self-Sovereign” Individual

Andrej Zwitter, Oskar Josef Gstrein, Evan Yap

While ‘classical’ human identity has kept philosophers busy since millennia, ‘Digital Identity’ seems primarily machine related. Telephone numbers, E-Mail inboxes, or Internet Protocol (IP)-addresses are irrelevant to define us as human beings at first glance. However, with the omnipresence of digital space the digital aspects of identity gain importance. In this submission, we aim to put recent developments in context and provide a categorization to frame the landscape as developments proceed rapidly. First, we present selected philosophical perspectives on identity. Secondly, we explore how the legal landscape is approaching identity from a traditional dogmatic perspective both in national and international law. After blending the insights from those sections together in a third step, we will go on to describe and discuss current developments that are driven by the emergence of new tools such as ‘Distributed Ledger Technology’ and ‘Zero Knowledge Proof’. One of our main findings is that the management of digital identity is transforming from a purpose driven necessity towards a self-standing activity that becomes a resource for many digital applications. In other words, whereas traditionally identity is addressed in a predominantly sectoral fashion whenever necessary, new technologies transform digital identity management into a basic infrastructural service, sometimes even a commodity. This coincides with a trend to take the ‘control’ over identity away from governmental institutions and corporate actors to ‘self-sovereign individuals’, who have now the opportunity to manage their digital self autonomously. To make our conceptual statements more relevant, we present several already existing use cases in the public and private sector. Subsequently, we discuss potential risks that should be mitigated in order to create a desirable relationship between the individual, public institutions, and the private sector in a world where self-sovereign identity management has become the norm. We will illustrate these issues along the discussion around privacy, as well as the development of backup mechanisms for digital identities. Despite the undeniable potential for the management of identity, we suggest that particularly at this point in time there is a clear need to make detailed (non-technological) governance decisions impacting the general design and implementation of self-sovereign identity systems.

Open access
3 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cybersecurity and Cyber Warfare Studies
Original source
Jan 1, 2019¡IEEE Access
83 cites
Dynamic and Privacy-Preserving Reputation Management for Blockchain-Based Mobile Crowdsensing

Ke Zhao, Shaohua Tang, Bowen Zhao, Yiming Wu

Mobile crowdsensing (MCS) is an emerging data collection paradigm that exploits the potential of individual mobile devices to acquire mass data in a cost-effective manner. One of the important challenges in MCS application is to resist malicious users who provide false data to disturb the system. In the existing work, the reputation management scheme is an effective way to overcome the challenge. However, most reputation management schemes rely on a semi-honest server and process data in the plaintext domain without considering server security and user privacy. In this paper, we integrate the blockchain and edge computing in the MCS scenario to construct a credible and efficient blockchain-based MCS system, called BC-MCS. To resist malicious users, we present a privacy-preserving reputation management scheme based on the proposed system. Furthermore, we design a delegation protocol to solve the inherent problem of user dynamics in the MCS. The prototype system implemented on the Hyperledger Sawtooth and Android client demonstrates that our scheme can achieve higher utility and security levels in handling malicious users compared with the previous centralized reputation management schemes.

Open access
Mobile Crowdsensing and Crowdsourcing
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡Acta Informatica Medica
10 cites
The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project

Stefanos Malliaros, Christos Xenakis, George Moldovan, John Mantas ¡ 6 authors

INTRODUCTION: Individuals and healthcare providers need to trust that the EHRs are protected and that the confidentiality of their personal information is not at stake. AIM: Within CrowdHEALTH project, a security and privacy framework that ensures confidentiality, integrity, and availability of the data was developed. METHODS: The CrowdHEALTH Security and Privacy framework includes Privacy Enhancing Technologies (PETs) in order to comply with the GDPR EU laws of data protection. CrowdHEALTH deploys OpenID Connect, an authentication protocol to provide flexibility, scalability, and lightweight user authentication as well as the attribute-base access control (ABAC) mechanism which supports creating efficient access control policies. RESULTS: CrowdHEALTH integrates ABAC with OpenID Connect to build an effective and scalable base for end-users' authorization. CrowdHEALTH's security and privacy framework interacts with other CrowdHEALTH's components, for instance the Big Data Platform, that depends on user authentication and authorization. CrowdHEALTH users are able to access the CrowdHEALTH's database based on the result of an ABAC request. Moreover, due to the fact that the CrowdHEALTH system requires proofs during the interactions with data producers of low trust or low reputation level, the requirements for the Trust and Reputation Model have been identified. CONCLUSION: The CrowdHEALTH Integrated Holistic Security and Privacy framework meets the security criteria for an e-health cross-border system, due to the adoption of security mechanisms, such as user authentication, user authorization, access control, data anonymization, trust management and reputation modelling. The implemented framework remains to be tested to ensure its robustness and to evaluate its performance. The holistic security and privacy framework might be adapted during the project's life circle according to new legislations.

Open access
Access Control and Trust
Privacy, Security, and Data Protection
Information and Cyber Security
Original source
Jan 1, 2019¡Open Computer Science
60 cites
Privacy-aware blockchain for personal data sharing and tracking

Md. Mehedi Hassan Onik, Chul‐Soo Kim, Nam Yong Lee, Jinhong Yang

Abstract Secure data distribution is critical for data accountability. Surveillance caused privacy breaching incidents have already questioned existing personal data collection techniques. Organizations assemble a huge amount of personally identifiable information (PII) for data-driven market analysis and prediction. However, the limitation of data tracking tools restricts the detection of exact data breaching points. Blockchain technology, an ‘immutable’ distributed ledger, can be leveraged to establish a transparent data auditing platform. However, Art. 42 and Art. 25 of general data protection regulation (GDPR) demands ‘right to forget’ and ‘right to erase’ of personal information, which goes against the immutability of blockchain technology. This paper proposes a GDPR complied decentralized and trusted PII sharing and tracking scheme. Proposed blockchain based personally identifiable information management system (BcPIIMS) demonstrates data movement among GDPR entities (user, controller and processor). Considering GDPR limitations, BcPIIMS used off-the-chain data storing architecture. A prototype was created to validate the proposed architecture using multichain. The use of off-the-chain storage reduces individual block size. Additionally, private blockchain also limits personal data leaking by collecting fast approval from restricted peers. This study presents personal data sharing, deleting, modifying and tracking features to verify the privacy of proposed blockchain based personally identifiable information management system.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡Journal of Institutional and Theoretical Economics JITE
5 cites
Democratic Blockchain Design

Yoan HermstrĂźwer

Democracy requires rules that are designed to prevent the abuse of power and money. Blockchain technology is sometimes heralded as a solution to mitigate the problems associated with voting procedures, such as counting errors, fraud, or the improper use of money to influence the outcome of the collective choice procedure. In this article, I argue that the democratic potential of the blockchain hinges on the specific design of the rules governing the validation of blocks.In support of this argument, I shed light on the governance problems raised by standard protocols such as proof-of-work, proof-of-stake, and on-chain voting.

Open access
2 source records
Blockchain Technology Applications and Security
Digital Economy and Work Transformation
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡IEEE Access
150 cites
Privacy Management in Social Internet of Vehicles: Review, Challenges and Blockchain Based Solutions

Talal Ashraf Butt, Razi Iqbal, Khaled Salah, Moayad Aloqaily ¡ 5 authors

The Internet of Things (IoT) paradigm has integrated the sensor network silos to the Internet and enabled the provision of value-added services across these networks. These smart devices are now becoming socially conscious by following the social Internet of Things (SIoT) model that empowers them to create and maintain social relationships among them. The Social Internet of Vehicle (SIoV) is one application of SIoT in the vehicular domain that has evolved the existing intelligent transport system (ITS) and vehicular ad-hoc networks (VANETs) to the next phase of Intelligent by adding socializing aspect and constant connectivity. SIoV generates a massive amount of real-time data enriched with context and social relationship information about vehicles, drivers, passengers, and the surrounding environment. Therefore, the role of privacy management becomes essential in SIoV, as data is collected and stored at different layers of its architecture. The challenge of privacy is aggravated because the dynamic nature of SIoV poses a major threat in its adoption. Motivated by the need to address these aspects, this paper identifies the challenges involved in managing privacy in SIoV. Furthermore, the paper analyzes the privacy issues and factors that are essential to be considered for preserving privacy in SIoV environments from different perspectives including the privacy of a person, behavior and action, communication, data and image, thoughts and feelings, location and space, and association. In addition, the paper discusses the blockchain-based solutions to preserve privacy for SIoV.

Open access
Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡IEEE Access
163 cites
EACMS: Emergency Access Control Management System for Personal Health Record Based on Blockchain

Ahmed Raza Rajput, Qianmu Li, Milad Taleby Ahvanooey, Isma Masood

Personal health records (PHRs) are private and vital assets for every patient. There have been introduced many works on various aspects of managing and organizing the PHR so far. However, there is an uncertain remaining issue for the role of PHR in emergencies. In a traditional emergency access system, the patient cannot give consent to emergency staff for accessing his/her PHR. Moreover, there is no secured record management of patient's PHR, which reveals highly confidential personal information, such as what happened, when, and who has access to such information. This paper proposes an emergency access control management system (EACMS) based on permissioned blockchain hyperledger fabric and hyperledger composer. In the proposed system, we defined some rules using the smart contracts for emergency condition and time duration for the emergency access PHR data items that patient can assign some limitations for controlling the PHR permissions. We analyzed the performance of our proposed framework by implementing it through the hyperledger composer based on the response time, privacy, security, and accessibility. The experiments confirm that our framework provides better efficiency compared with the traditional emergency access system.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡2019 Spring Simulation Conference (SpringSim)
14 cites
Pledge: A Private Ledger Based Decentralized Data Sharing Framework

Ronald Doku, Danda B. Rawat

Blockchain startups are basing their business models on disrupting the centralized way of data storage by highlighting the value of data to the public. A distributed approach to storing data is the safer way to prevent attacks is what is being evangelized. GAFA (Google, Apple, Facebook, Amazon) have monopolized data, therefore bringing in the most revenue whilst depriving the data generators of any form of compensation. In our work, we propose a platform where a user can store his/her own personal data. Here, we present to the user the right to decide what happens to their data. These decisions include selling, renting, and deleting data. The deletion of data undermines the fundamentals the blockchain is built on (data immutability). We address the issues of personal data sharing and how a user's right to delete his/her data can be enforced in a blockchain based network such as ours.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
IoT and Edge/Fog Computing
Original source
Jan 1, 2019¡Lecture notes in computer science
16 cites
Protecting Personal Data Using Smart Contracts

Mohsin Ur Rahman, Fabrizio Baiardi, Barbara Guidi, Laura Ricci

Decentralized Online Social Networks (DOSNs) have been proposed as an alternative solution to the current centralized Online Social Networks (OSNs). Online Social Networks are based on centralized architecture (e.g., Facebook, Twitter, or Google+), while DOSNs do not have a service provider that acts as central authority and users have more control over their information. Several DOSNs have been proposed during the last years. However, the decentralization of the OSN requires efficient solutions for protecting the privacy of users, and to evaluate the trust between users. Blockchain represents a disruptive technology which has been applied to several fields, among these also to Social Networks. In this paper, we propose a manageable, user-driven and auditable access control framework for DOSNs using blockchain technology. In the proposed approach, the blockchain is used as a support for the definition of privacy policies. The resource owner uses the public key of the subject to define flexible role-based access control policies, while the private key associated with the subject's Ethereum account is used to decrypt the private data once access permission is validated on the blockchain. We evaluate our solution by exploiting the Rinkeby Ethereum testnet to deploy the smart contract, and to evaluate its performance. Experimental results show the feasibility of the proposed scheme in achieving auditable and user-driven access control via smart contract deployed on the Blockchain.

Open access
3 source records
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡Journal of the Association for Information Systems
143 cites
"Blockchain for the IoT: Privacy-Preserving Protection of Sensor Data"

ETH Zurich, Switzerland, Mathieu Chanson, Andreas Bogner, ETH Zurich, Switzerland ¡ 8 authors

An ever growing variety of smart, connected Internet of Things (IoT) devices poses completely new challenges for businesses regarding security and privacy. In fact, the adoption of smart products may depend on the ability of organizations to offer systems that ensure adequate sensor data integrity while guaranteeing sufficient user privacy. In light of these challenges, previous research indicates that blockchain technology could be a promising means to mitigate issues of data security arising in the IoT. Building upon the existing body of knowledge, we propose a design theory, including requirements, design principles, and features, for a blockchain-based sensor data protection system (SDPS) that leverages data certification. To support this, we designed and developed an instantiation of an SDPS (CertifiCar) in three iterative cycles intented to prevent the fraudulent manipulation of car mileage data. Following the explication of our SDPS, we provide an ex post evaluation of our design theory considering CertifiCar and two additional use cases in the areas of pharmaceutical supply chains and energy microgrids. Our results suggest that the proposed design ensures the tamper-resistant gathering, processing, and exchange of IoT sensor data in a privacy-preserving, scalable, and efficient manner.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Mobile Crowdsensing and Crowdsourcing
Original source
Jan 1, 2019¡Frontiers in Blockchain
40 cites
A Decentralised Digital Identity Architecture

Geoffrey Goodell, Tomaso Aste

Current architectures to validate, certify, and manage identity are based on centralised, top-down approaches that rely on trusted authorities and third-party operators. We approach the problem of digital identity starting from a human rights perspective, with a primary focus on identity systems in the developed world. We assert that individual persons must be allowed to manage their personal information in a multitude of different ways in different contexts and that to do so, each individual must be able to create multiple unrelated identities. Therefore, we first define a set of fundamental constraints that digital identity systems must satisfy to preserve and promote privacy as required for individual autonomy. With these constraints in mind, we then propose a decentralised, standards-based approach, using a combination of distributed ledger technology and thoughtful regulation, to facilitate many-to-many relationships among providers of key services. Our proposal for digital identity differs from others in its approach to trust in that we do not seek to bind credentials to each other or to a mutually trusted authority to achieve strong non-transferability. Because the system does not implicitly encourage its users to maintain a single aggregated identity that can potentially be constrained or reconstructed against their interests, individuals and organisations are free to embrace the system and share in its benefits.

Open access
3 source records
cs.CY
Access Control and Trust
Privacy, Security, and Data Protection
Original source
Jan 1, 2019¡Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
12 cites
Overview of Licensing Platforms based on Distributed Ledger Technology

Alexander Schoenhals, Thomas Hepp, Stephan Leible, Philip Ehret ¡ 5 authors

The licensing of creative work is of broad and current interest. The European Commission proposes that when uploading a licensed digital work, the uploader should be checked by the system that one has the necessary rights. Technically this law is difficult to implement, as images with different intentions are shared, and even small changes like watermarks make it difficult to reveal similarities. The characteristics of distributed ledger technology could provide excellent support for the licensing and management of the rights of use. In this work, non-technical and technical criteria are defined to achieve an overview of the state-of-the-art solutions in the field of blockchain-based licensing platforms. Based on the criteria, different licensing platforms are reviewed, and the results are presented in a comparison matrix.

Open access
Blockchain Technology Applications and Security
Transportation and Mobility Innovations
Privacy, Security, and Data Protection
Original source
Dec 27, 2018¡Symmetry
28 cites
Journalism Model Based on Blockchain with Sharing Space

Byeowool Kim, Yong-Ik Yoon

The challenge that journalism is facing these days in the Internet mobile environment is greater than ever before. Journalism is losing its revenue structure to platform operators favoring a certain markets, and also the trust of its readers in light of fake news and infected news. To alleviate this situation, we propose a blockchain technology that is applicable to journalism in order to achieve decentralization as a reasonable alternative. The journalism model based on hybrid blockchain aims to achieve the following: the delivery of articles with sharing value, what we call proof of sharing; the distribution of roles of personalized agenda settings; and finally, the use of agora to collect public opinions. With all these, we attempt to resolve the issues with current journalism with our proposed model based on blockchain.

Open access
Caching and Content Delivery
Privacy, Security, and Data Protection
FinTech, Crowdfunding, Digital Finance
Original source
Dec 10, 2018¡arXiv (Cornell University)
2 cites
On legitimate mining of cryptocurrency in the browser - a feasibility study

Saulius Venskutonis, Hao Feng, Matthew Collison

Cryptocurrency mining in the browser has the potential to provide a new pay-as-you-go monetisation mechanism for consuming digital media over the Web. However, browser mining has recently received strong criticism due to illegitimate use of mining scripts in several popular websites (a practice called cryptojacking). Here we provide the first feasibility study of browser mining as a legitimate means of monetisation in terms of revenue, user consent and user experience within a specially built website. Our results compare browser mining to display advertisement and indicate browser mining provides a preferable user experience to advertising when the hash rate is user-adjustable. Furthermore, over 60% of participants would select browser mining over advertisement if they were invested in the ecosystem by obtaining half of the mined cryptocurrency. Our estimations show that browser mining currently generates revenue at a rate 46 times less than advertisement, however we would expect that gap to decrease as we observed a significant drop in mining difficulty after our tested cryptocurrency implemented ASIC-resistant mining measures. Overall, based on our results we find browser mining to be a legitimate alternative to display advertisement and conclude by discussing its current limitations and potential applications.

Open access
2 source records
cs.CR
Sexuality, Behavior, and Technology
Blockchain Technology Applications and Security
Original source
Dec 3, 2018¡Wireless Networks
186 cites
A framework of blockchain-based secure and privacy-preserving E-government system

Noe Elisa, Longzhi Yang, Fei Chao, Yi Cao

Abstract Electronic government (e-government) uses information and communication technologies to deliver public services to individuals and organisations effectively, efficiently and transparently. E-government is one of the most complex systems which needs to be distributed, secured and privacy-preserved, and the failure of these can be very costly both economically and socially. Most of the existing e-government systems such as websites and electronic identity management systems (eIDs) are centralized at duplicated servers and databases. A centralized management and validation system may suffer from a single point of failure and make the system a target to cyber attacks such as malware, denial of service attacks (DoS), and distributed denial of service attacks (DDoS). The blockchain technology enables the implementation of highly secure and privacy-preserving decentralized systems where transactions are not under the control of any third party organizations. Using the blockchain technology, exiting data and new data are stored in a sealed compartment of blocks (i.e., ledger) distributed across the network in a verifiable and immutable way. Information security and privacy are enhanced by the blockchain technology in which data are encrypted and distributed across the entire network. This paper proposes a framework of a decentralized e-government peer-to-peer (p2p) system using the blockchain technology, which can ensure both information security and privacy while simultaneously increasing the trust of the public sectors. In addition, a prototype of the proposed system is presented, with the support of a theoretical and qualitative analysis of the security and privacy implications of such system.

Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Original source
Dec 1, 2018¡Duke Law Scholarship Repository (Duke University)
11 cites
The Data Breach Dilemma: Proactive Solutions for Protecting Consumers' Personal Information

Daniel J. Marcus

Data breaches are an increasingly common part of consumers’ lives. No institution is immune to the possibility of an attack. Each breach inevitably risks the release of consumers’ personally identifiable information and the strong possibility of identity theft. Unfortunately, current solutions for handling these incidents are woefully inadequate. Private litigation like consumer class actions and shareholder lawsuits each face substantive legal and procedural barriers. States have their own data security and breach notification laws, but there is currently no unifying piece of legislation or strong enforcement mechanism. This Note argues that proactive solutions are required. First, a national data security law—setting minimum data security standards, regulating the use and storage of personal information, and expanding the enforcement role of the Federal Trade Commission—is imperative to protect consumers’ data. Second, a proactive solution requires reconsidering how to minimize the problem by going to its source: the collection of personally identifiable information in the first place. This Note suggests regulating companies’ collection of Social Security numbers, and, eventually, using a system based on distributed ledger technology to replace the ubiquity of Social Security numbers.

Open access
Privacy, Security, and Data Protection
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Nov 12, 2018¡Sensors
126 cites
A Blockchain-Based Location Privacy Protection Incentive Mechanism in Crowd Sensing Networks

Bing Jia, Tao Zhou, Wuyungerile Li, Zhenchang Liu ¡ 5 authors

Crowd sensing is a perception mode that recruits mobile device users to complete tasks such as data collection and cloud computing. For the cloud computing platform, crowd sensing can not only enable users to collaborate to complete large-scale awareness tasks but also provide users for types, social attributes, and other information for the cloud platform. In order to improve the effectiveness of crowd sensing, many incentive mechanisms have been proposed. Common incentives are monetary reward, entertainment & gamification, social relation, and virtual credit. However, there are rare incentives based on privacy protection basically. In this paper, we proposed a mixed incentive mechanism which combined privacy protection and virtual credit called a blockchain-based location privacy protection incentive mechanism in crowd sensing networks. Its network structure can be divided into three parts which are intelligence crowd sensing networks, confusion mechanism, and blockchain. We conducted the experiments in the campus environment and the results shows that the incentive mechanism proposed in this paper has the efficacious effect in stimulating user participation.

Open access
Mobile Crowdsensing and Crowdsourcing
Privacy, Security, and Data Protection
Human Mobility and Location-Based Analysis
Original source
Nov 6, 2018¡IEEE Internet of Things Journal
122 cites
Scalable Access Management in IoT Using Blockchain: A Performance Evaluation

Oscar Novo

The rise of the Internet of Things (IoT) implies new technical challenges such as managing a universally vast number of IoT devices. Despite the fact that there are already a variety of secure management frameworks for IoT, they are based on centralized models, which limits their applicability in scenarios with a large number of IoT devices. In order to overcome those limitations, we have developed a distributed IoT management system based on blockchain. In this paper, we compare the performance of our solution with the existing access management solutions in IoT. We study the delays and the throughput rate associated with the systems and analyze different configurations of our solution to maximize its scalability. The objective of this paper is to find out whether our solution can scale as well as the existing management systems in IoT.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
Oct 23, 2018¡UTUPub (University of Turku)
2 cites
Reconciling the conflict between the ‘immutability’ of public and permissionless blockchain technology and the right to erasure under Article 17 of the General Data Protection Regulation

Jani-Pekka Jussila

This thesis focuses on the issues between a blockchain technology and the new European Union General Data Protection Regulation (GDPR). The Blockchain technology is a rather new technology which potential has been recognised only in the recent years. Essentially, a blockchain is a distributed database in which data is stored in blocks, which form a chronological chain of blocks. Blockchains have many types and possible use cases, but this research focuses on public and permissionless blockchains, which primary objective is to enable individuals to transact with each other without centralised intermediaries.
\n
\nThe GDPR entered into force on 25 May 2018. The GDPR was not drafted taking account of distributed ledger technologies, such as the blockchain technology, which has raised several points of tension between the regulation and the technology. The primary focus of this thesis is on the conflict between the ‘immutability’ of blockchain technology and the right to erasure under Article 17 of the GDPR. One of the main features of blockchains is the immutability, that is to say, data on old blocks is extremely difficult to modify or delete. This feature seems prima facie to conflict with Article 17 of the GDPR that provides data subjects with the right to request erasure of their personal data under certain conditions.
\n
\nFirstly, this thesis analyses the current state of the conflict. Before analysing the conflict, the research addresses two essential preliminary questions: the question about anonymisation and personal data and the question about allocation of responsibilities on blockchains. After that, different solutions proposed to reconcile the conflict are analysed to understand the current situation. While public and permissionless blockchains currently may infringe Article 17 of the GDPR, there are potential solutions for the conflict in the future.
\n
\nThe second purpose of this thesis is to identify relevant legal problems and propose how to address the problems in the future. Blockchain developers should consider data protection obligations already in the design phase. From the legal side, this research has provided flexible interpretations for the legal problems that could help to comply with the right to erasure. There is a need for a flexible approach to the problems between the regulation and the technology.

Open access
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Sep 17, 2018¡IFIP advances in information and communication technology
13 cites
BlockTag: Design and applications of a tagging system for blockchain analysis

Yazan Boshmaf, Husam Al Jawaheri, Mashael Al Sabah

Annotating blockchains with auxiliary data is useful for many applications. For example, e-crime investigations of illegal Tor hidden services, such as Silk Road, often involve linking Bitcoin addresses, from which money is sent or received, to user accounts and related online activities. We present BlockTag, an open-source tagging system for blockchains that facilitates such tasks. We describe BlockTag's design and present three analyses that illustrate its capabilities in the context of privacy research and law enforcement.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Sep 14, 2018¡arXiv
18 cites
Airdrops and Privacy: A Case Study in Cross-Blockchain Analysis

Martin Harrigan, Lei Shi, Jacob Illum

Airdrops are a popular method of distributing cryptocurrencies and tokens. While often considered risk-free from the point of view of recipients, their impact on privacy is easily overlooked. We examine the Clam airdrop of 2014, a forerunner to many of today's airdrops, that distributed a new cryptocurrency to every address with a non-dust balance on the Bitcoin, Litecoin and Dogecoin blockchains. Specifically, we use address clustering to try to construct the one-to-many mappings from entities to addresses on the blockchains, individually and in combination. We show that the sharing of addresses between the blockchains is a privacy risk. We identify instances where an entity has disclosed information about their address ownership on the Bitcoin, Litecoin and Dogecoin blockchains, exclusively via their activity on the Clam blockchain.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source