Building a secure electronic voting system is a difficult task. The US Pentagon dropped their proposed online voting system which would have given overseas military personnel the opportunity to vote in the elections in 2005, citing the inability to ensure the legitimacy of votes as the reason. There is however a new cry in the wild to deploy a voting blockchain. The blockchain serves as a public ledger of transactions which cannot be reversed. The all-important consensus of transaction (i.e. legitimate votes) is achieved through 'miners' agreeing to validate new records being added. Whenever a new insertion is to be made e.g. votes, then a new transaction record is created by a voter adding details of their cast vote to the blockchain. Should it be deemed a valid transaction then the new vote is added to the end of the blockchain and remains there forever. What is neat about this solution is the fact that no centralized authority is needed to approve the votes but rather a majority consensus. Here everyone agrees on the final tally as they can count the votes themselves & because of the blockchain audit trail, anyone can verify that no votes were tampered with and no illegitimate votes were inserted. This paper discusses the application of blockchain to voting.
A blockchain framework is presented for addressing the privacy and security challenges associated with the Big Data in smart mobility. It is composed of individuals, companies, government and universities where all the participants collect, own, and control their data. Each participant shares their encrypted data to the blockchain network and can make information transactions with other participants as long as both party agrees to the transaction rules (smart contract) issued by the owner of the data. Data ownership, transparency, auditability and access control are the core principles of the proposed blockchain for smart mobility Big Data.
Nasr Al-Zaben, Md. Mehedi Hassan Onik, Jinhong Yang, Nam Yong Lee · 5 authors
Surveillance and secrecy breaching incidents of users' privacy questioned the current third-parties data collection procedure. Massive amounts of Personally Identifiable Information (PII) are being exploited due to malpractice, identity theft, spamming, phishing and cyber-espionage. A large amount of data flow from users to enterprises for data-driven market analysis and prediction. Consequently, it is tough to track the flow and genuineness of PII. Blockchain technology, an ‘immutable’ distributed ledger which can efficaciously track PII exchange, store, and distribution. In contrast, ongoing EU General Data Protection Regulation (GDPR) demands ‘right to forget’ and ‘should be erasable’ rights. However, this paper proposes an off-chain Blockchain architecture which uses both local database and distributed ledgers to preserve a trustable PII life cycle. Considering the key factors of GDPR, prevailing Blockchain architecture were modified and a prototype was created to validate our proposed architecture using multichain 2.0. Proposed architecture stores PII and Non-PII physically separated location. Finally, with proposed architecture user will realm privacy and rigidity of Blockchain along with the privacy regulation of GDPR. Validation is done by comparing proposed system with existing methodology from technical aspects, future research scopes is also well advocated.
The public key infrastructure (PKI) based authentication protocol provides the basic security services for vehicular ad-hoc networks (VANETs). However, trust and privacy are still open issues due to the unique characteristics of vehicles. It is crucial for VANETs to prevent internal vehicles from broadcasting forged messages while simultaneously protecting the privacy of each vehicle against tracking attacks. In this paper, we propose a blockchain-based anonymous reputation system (BARS) to break the linkability between real identities and public keys to preserve privacy. The certificate and revocation transparency is implemented efficiently using two blockchains. We design a trust model to improve the trustworthiness of messages relying on the reputation of the sender based on both direct historical interactions and indirect opinions about the sender. Experiments are conducted to evaluate BARS in terms of security and performance and the results show that BARS is able to establish distributed trust management, while protecting the privacy of vehicles.
This Article, which takes into account developments up until summer 2017, evaluates the early days of regulatory engagement with blockchain technology. My analysis unfolds in three parts. First, I provide a cursory overview of the technology itself to highlight considerable uncertainties concerning its future. Regulators asked to engage with distributed ledgers are thus compelled to regulate the unknown. Second, I will introduce a typology of regulatory strategies adopted to date and highlight their respective advantages and shortcomings. Third, I will outline a number of guiding principles regulators should follow in respect of blockchain technology. I will make the argument that despite the technology's uncertain future, early regulatory engagement is warranted as a young technology is a malleable technology. As technology develops, law has to adapt. As a consequence, I put forward a number of regulatory techniques, including a process of polycentric co-regulation that relies on the regulatory potential of (blockchain) software and the adoption of a so-called “28 th regime” at the EU level which may help navigate the uncertainties of blockchain development and regulation.
C. Kouzinopoulos, Konstantinos M. Giannoutakis, Konstantinos Votis, Dimitrios Tzovaras · 10 authors
The H2020 European research project Safe-Guarding Home IoT Environments with Personalised Real-time Risk Control (GHOST) aims to develop a cyber-security layer on IoT smart home installations. The proposed system analyses packet-level data flows for building patterns of communications between IoT devices and external entities. To ensure non-repudiation, integrity and authentication of the data captured, they are stored in a Blockchain, a distributed ledger network, as digitally-signed transactions. Since the data can potentially include sensitive user information, it is imperative to promote trust by informing users about the operating principles of the network as well as to request the acceptance of a consent form by them. This paper presents the design and implementation of a Forms of Consent application, a Distributed Application that interacts with a set of Smart Contracts deployed on a private Ethereum network. The application is being developed as part of the GHOST project.
Blockchain-enabled e-voting (BEV) could reduce voter fraud and increase voter access. Eligible voters cast a ballot anonymously using a computer or smartphone. BEV uses an encrypted key and tamper-proof personal IDs. This article highlights some BEV implementations and the approach’s potential benefits and challenges.
The present work deals with the inter relationships of blockchain technology and the new European General Data Protection Regulation, that will be intact after May 28th, 2018. The regulation harmonises personal data protection across the European Union and aims to return the ownership of personal data to the individual. This thesis, therefore, addresses the question how this new technology that is characterised by decentralisation, immutability and truly digitised values will be affected by the strict privacy regulation and vice versa. The aim of this work is to clarify whether blockchains can comply with the new regulation on the one hand and to identify how blockchain could support its compliance, on the other hand. The questions are validated through an extensive literature review and are further investigated by using a Delphi study that asks a panel of 25 renowned experts to find opportunities, limitations and general suggestions about both topics. In addition, a framework is proposed to support the assessment of privacy and related risks of blockchains. As a result, it becomes apparent that blockchains can become more privacy friendly and comply with the regulation if an active dialogue between blockchain developers and regulatory authorities helps to strengthen their mutual understanding and work. With the support of this work and the blockchain Privacy Impact Assessment canvas a foundation for the necessary next steps is laid to overcome the challenges of defining a data controller or deleting personal data within a blockchain.
Joaõ Pedro Dias, Hugo Sereno Ferreira, Ângelo Martins
Access control is a crucial part of a system's security, restricting what actions users can perform on resources. Therefore, access control is a core component when dealing with e-Health data and resources, discriminating which is available for a certain party. We consider that current systems that attempt to assure the share of policies between facilities are prone to system's and network's faults and do not assure the integrity of policies lifecycle. By approaching this problem with the use of a distributed ledger, namely a consortium blockchain, where the operations are stored as transactions, we ensure that the different facilities have knowledge about all the parties that can act over the e-Health resources while maintaining integrity, auditability, authenticity, and scalability.
The blockchain technology has evolved beyond traditional payment solutions in the finance sector and offers a potential for transforming many sectors including the public sector. The novel integration of technology and economy that open public block-chains have brought represents both challenges to and opportunities for enhancing digital public services. So far, the public sector has lagged behind other sectors in both research and exploration of this technology, but pilot cases show that there is a great potential for reforming and even transforming public service delivery.
The ability of blockchain technology to record transactions on distributed ledgers offers new opportunities for governments to improve transparency, prevent fraud, and establish trust in the public sector. However, blockchain adoption and use in the context of e-Government is rather unexplored in academic literature. In this paper, we systematically review relevant research to understand the current research topics, challenges and future directions regarding blockchain adoption for e-Government. The results show that the adoption of blockchain-based applications in e-Government is still very limited and there is a lack of empirical evidence. The main challenges faced in blockchain adoption are predominantly presented as technological aspects such as security, scalability and flexibility. From an organizational point of view, the issues of acceptability and the need of new governance models are presented as the main barriers to adoption. Moreover, the lack of legal and regulatory support is identified as the main environmental barrier of adoption. Based on the challenges presented in the literature, we propose future research questions that need to be addressed to inform how the public sector should approach the blockchain technology adoption.
In the present techno-political moment it is clear that ignoring or dismissing the hype surrounding blockchain is unwise, and certainly for regulatory authorities and governments who must keep a grip on the technology and those promoting it, in order to ensure democratic accountability and regulatory legitimacy within the blockchain ecosystem and beyond. Blockchain is telling (and showing) us something very important about the evolution of capital and neoliberal economic reason, and the likely impact in the near future on forms and patterns of work, social organization, and, crucially, on communities and individuals who lack influence over the technologies and data that increasingly shape and control their lives. In this short essay I introduce some of the problems in the regulation of blockchain and offer counter-narratives aimed at cutting through the hype fuelling the ascendency of this most contemporary of technologies.
Kevin Liu, Harsh Desai, Lalana Kagal, Murat Kantarcıoğlu
As more and more data is collected for various reasons, the sharing of such data becomes paramount to increasing its value. Many applications ranging from smart cities to personalized health care require individuals and organizations to share data at an unprecedented scale. Data sharing is crucial in today's world, but due to privacy reasons, security concerns and regulation issues, the conditions under which the sharing occurs needs to be carefully specified. Currently, this process is done by lawyers and requires the costly signing of legal agreements. In many cases, these data sharing agreements are hard to track, manage or enforce. In this work, we propose a novel alternative for tracking, managing and especially enforcing such data sharing agreements using smart contracts and blockchain technology. We design a framework that generates smart contracts from parameters based on legal data sharing agreements. The terms in these agreements are automatically enforced by the system. Monetary punishment can be employed using secure voting by external auditors to hold the violators accountable. Our experimental evaluation shows that our proposed framework is efficient and low-cost.
In our research we introduce “the forensic smart contract” as a punishment alternative for tiny law violations. After studied the legislation boundaries and legal power transfer example for out of court applications, we evaluated three Blockchain applications covering three various cases in smart contracting. A smart-Law-script to eliminate illegal cellphone car use, with best punishment an Irrevocable prepayment in digi-money for a car phone kit. Then a “Lawscript” resolving the double taxation problem in international tax conventions. Finally a Court launches a community sentence through a “Rehabilitation Law sentence script”. After mass adoption of our methodologies we faced an unexpected globalization peace factor in Blockchain and much wide adoption of CBDC (Central Bank Digital Currency).
Since the invention of internet, identity has become a significant aspect for nearly every interaction that occurs online. In this position paper, we demonstrate and discuss current limitations of centralised Identity Management (IdM) systems by drawing from the cases of two of world’s largest biometric ID systems: India’s Unique Identification System Aadhar and China’s Social Credit system, Sesame Credit. This paper explores self-sovereign identity through innovative application from blockchain 3.0. We then identify some key characteristics of blockchain technologies to address the challenges centralised IdM services face and present opportunities for furthering HCI research around de-centralised IdM services to provoke workshop discussion.
Chris Elsden, Arthi Manohar, Jo Briggs, Mike Harding · 6 authors
Blockchain is an emerging infrastructural technology that is proposed to fundamentally transform the ways in which people transact, trust, collaborate, organize and identify themselves. In this paper, we construct a typology of emerging blockchain applications, consider the domains in which they are applied, and identify distinguishing features of this new technology. We argue that there is a unique role for the HCI community in linking the design and application of blockchain technology towards lived experience and the articulation of human values. In particular, we note how the accounting of transactions, a trust in immutable code and algorithms, and the leveraging of distributed crowds and publics around vast interoperable databases all relate to longstanding issues of importance for the field. We conclude by highlighting core conceptual and methodological challenges for HCI researchers beginning to work with blockchain and distributed ledger technologies.
A trusted electronic election system requires that all the involved information must go public, that is, it focuses not only on transparency but also privacy issues. In other words, each ballot should be counted anonymously, correctly, and efficiently. In this work, a lightweight E-voting system is proposed for voters to minimize their trust in the authority or government. We ensure the transparency of election by putting all message on the Ethereum blockchain, in the meantime, the privacy of individual voter is protected via an efficient and effective ring signature mechanism. Besides, the attractive self-tallying feature is also built in our system, which guarantees that everyone who can access the blockchain network is able to tally the result on his own, no third party is required after voting phase. More importantly, we ensure the correctness of voting results and keep the Ethereum gas cost of individual participant as low as possible, at the same time. Clearly, the pre-described characteristics make our system more suitable for large-scale election.
The emergence of a cryptocurrencies in the economic circulation is a challenge for legal systems. The response of a legal system depends on social, political and international determinants. The first attempts to understand cryptocurrencies usually concerns tax law, which, however, are related to the civilian understanding of the phenomenon. In the Polish legal system, we had a lack of regulation directly related to cryptocurrencies, which caused them to be strictly qualified as an instrument whose exchange for money was not exempt from VAT as Bitcoin was not classified as money. This situation has changed as a result of the case law of the Court of Justice of the European Union, which has recognized Bitcoin as an alternative means of payment. Recently, new statutory regulations have been introduced in non-European legal systems, i.e. in Japan and Arizona, which regulate cryptocurrencies in a wider way. This allows us to propose classification of legal systems based on the relationship they have towards cryptocurrencies.
Homomorphic Cryptography raised as a new solution used in electronic voting systems. In this research, Fully Homomorphic encryption used to design and implement an e-voting system. The purpose of the study is to examine the applicability of Fully Homomorphic encryption in real systems and to evaluate the performance of fully homomorphic encryption in evoting systems. Most of homomorphic cryptography evoting systems based on additive or multiplicative homomorphic encryption. In this research, fully homomorphic encryption used to provide both operations additive and multiplication, which ease the demonstration of none interactive zero-knowledge proof NIZKP. The proposed e-voting system achieved most of the important security issues of the internet-voting systems such as eligibility, privacy, accuracy, verifiability, fairness, and others. One of the most important properties of the implemented internet voting system its applicability to work on cloud infrastructure, while preserving its security characteristics. The implementation is done using homomorphic encryption library HELib. Addition and multiplication properties of fully homomorphic encryption were used to verify the correctness of vote structure as a NIZKP, and for calculating the results of the voting process in an encrypted way. The results show that the implemented internet voting system is secure and applicable for a large number of voters up to 10 million voters.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Hanyue Guo, Jiting Zhou, Jiaqi Wang, Xiaodong Wang
Leakage of user privacy and vandalism of the sharing bike have been the most serious problem since sharing bike came on the scene. Accordingly, it is very urgent to rebuild the underlying trust mechanism. Most bike sharing systems are centralized, leading to overpressure on the central server. This paper proposes a bike sharing system based on blockchain service platform and a shared operation mode of C2C. The system uses the blockchain system as the trust guarantee. The extra chain payment - lightning network is used to improve the efficiency of the blockchain system and the smart contract is used to provide the rights and interests of the two parties.
The current legal analysis on the blockchain technology focuses on the financial regulation of the cryptocurrencies and little investigation is done in the area of privacy regulation of this technology.
This research shows that the blockchains are much more nuanced than could be served by a one-size fits all approach from regulatory perspective. The GDPR implications for the types of blockchains differ. It is possible to achieve compliance with the GDPR if the authorities adopt a nuanced approach and make reliable advance assessments on specific features are afforded by this technology. In that regard, innovators ought to be assisted by the European Data Protection Supervisor, Article 29 Working Party and local Data Protection Authorities, in particular, on the question of recognition of the data subject as her own controller by way of implementing specific, electronic identity management techniques on top of blockchains. The utility of the blockchains depend on the GDPR regulators to understand and accept that this technological architecture is best regulated by other technological tools which establish the data subject’s agency on her personal data.
The public sector presents several promising applications for blockchain technology. Global organizations and innovative ministries in countries such as Dubai, Sweden, Finland, the Netherlands, and Germany have recognized these potentials and have initiated projects to evaluate the adoption of blockchain technology. As these projects can have a far-reaching impact on crucial government services and processes, they should involve a particularly thorough evaluation. In this paper, we provide insights into the development of a framework to support such an evaluation for the German asylum process. We built this framework evolutionarily together with the Federal Office for Migration and Refugees. Its final version consists of three levels and eighteen categories of evaluation criteria across the technical, functional and legal domains and allows specifying use-case specific key performance indicators or knockout criteria.