Faiza Loukil, Chirine Ghédira, Khouloud Boukadi, Aïcha Nabila Benharkat
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
733 results · page 29 of 31
Faiza Loukil, Chirine Ghédira, Khouloud Boukadi, Aïcha Nabila Benharkat
No abstract is available for this record.
Vincenzo Ferrari, João Pedro Quintais, Αλεξάνδρα Γιαννοπούλου, Balázs Bodó
The EU Blockchain Observatory and Forum (an initiative led by DG CONNECT) organized the “Workshop on GDPR, data policy and compliance” event in June 2018 to discuss data protection issues as well as privacy-enhancing features of blockchain technologies. The meeting gathered stakeholders and experts to examine the main challenges and opportunities of distributed ledger technologies (DLTs), so supporting the European Commission’s efforts to provide practical guidelines for the industry. Ms. Valeria Ferrari, of the Blockchain & Society Policy Research Lab participated in the workshop, and compiled this report.
Daniel Gregory Krawisz
This report describes two projects created by the author which are based on ideas which originate from the Bitcoin community. The first, bmd, is a re-implementation of the Bitmessage protocol in go. Bitmessage is an anonymous and secure messaging system invented by Jonathan Warren, who was inspired by the design of Bitcoin's p2p network. [WARR1] The second is Shufflepuff, an implementation of a protocol called CoinShuffle[RUFF1] which allows several people to construct a Bitcoin transaction with an input and an output for each participant without any participant knowing who owns which output. CoinShuffle was invented by Tim Ruffing et al, and it is an upgrade of a protocol called CoinJoin, invented by Gregory Maxwell. This paper discusses the background, properties, applications, and design of bmd and Shufflepuff. There is also a report of a performance analysis on bmd.
Luigi Castaldo, Vincenzo Cinque
On an EU level, the topic of electronic health data is a high priority. Many projects have been developed to realise a standard health data format to share information on a regional, national or EU level. All the projects favour and contribute to the development and improvement of the prerequisites for intra- and cross-border patient mobility. This work presents a new approach for the implementation of disruptive logging: an audit mechanism for cross-border exchange of eHealth data on OpenNCP, providing traceability and liability support within the OpenNCP infrastructure. Relevant parties could be legally obliged to keep a log of all privacy-critical operations performed by OpenNCP users.
Valeria Ferrari
No abstract is available for this record.
Benjamin Fabian, Tatiana Ermakova, Jonas Krah, Ephan Lando · 5 authors
No abstract is available for this record.
Nikos Fotiou, Vasilios A. Siris, George C. Polyzos
Despite technological advances, most smart objects in the Internet of Things (IoT) cannot be accessed using technologies designed and developed for interacting with powerful Internet servers. IoT use cases involve devices that not only have limited resources, but also they are not always connected to the Internet and are physically exposed to tampering. In this paper, we describe the design, development, and evaluation of a smart contract-based solution that allows end-users to securely interact with smart devices. Our approach enables access control, Thing authentication, and payments in a fully decentralized setting, taking at the same time into consideration the limitations and constraints imposed by both blockchain technologies and the IoT paradigm. Our prototype implementation is based on existing technologies, i.e., Ethereum smart contracts, which makes it realistic and fundamentally secure.
Christian Wirth, Michael Kolain
This paper takes an initial step forward in bringing to life the certification mechanisms according to Art. 42 of the General Data Protection Regulation (GDPR). These newly established methods of legal specification act not only as a central vehicle for overcoming widely articulated and discussed legal challenges, but also as a sandbox for the much needed close collaboration between computer sciences and legal studies. In order to illustrate, for example, what data protection seals could look like in the future, the authors propose a methodology for "translating" legal requirements into technical guidelines: architectural blueprints designed using legal requirements. The purpose of these blueprints is to show developers how their solutions might comply with the principle of Privacy by Design (Art. 25 GDPR). To demonstrate this methodology, the authors propose an architectural blueprint that embodies the legal concept of the data subject’s consent (Art. 6 sec. 1 lit. a GDPR) and elevates best practice to a high standard of Privacy by Design. Finally, the authors highlight further legal problems concerning blockchain technology under the GDPR that will have to be addressed in order to achieve a comprehensive certification mechanism for Privacy by Blockchain Design in the future.
Geoffrey Goodell, Tomaso Aste
Modern retail banking creates a kind of panopticon for consumer behaviour, ultimately promising to implement a mechanism that binds all of the financial activities undertaken by an individual to a single, unitary identity. In the age of Big Data, consumers have legitimate reasons to resist such surveillance, particularly in cases wherein monitoring is carried out without their knowledge and judgments based upon such monitoring are used to disincentivise or punish legitimate activities. The risk to consumers increases with the ever-increasing share of financial transactions that are performed electronically. Cryptocurrencies offer an alternative to traditional methods of electronic value exchange, promising anonymous, cash-like electronic transfers, but in practice they fall short for several key reasons. We consider the false choice between total surveillance, as represented by banking as currently implemented by institutions, and impenetrable lawlessness, as represented by privacy-enhancing cryptocurrencies as currently deployed. We identify a range of alternatives between those two extremes, and we consider two potential compromise approaches that offer both the auditability required for regulators and the anonymity required for users
Usman Chohan
No abstract is available for this record.
Shi-Cho Cha, Jyun-Fu Chen, Chunhua Su, Kuo‐Hui Yeh
Recently, the popularity of the Internet of Things (IoT) has led to a rapid development and significant advancement of ubiquitous applications seamlessly integrated within our daily life. Owing to the accompanying growth of the importance of privacy, a great deal of attention has focused on the issues of secure management and robust access control of IoT devices. In this paper, we propose the design of a blockchain connected gateway which adaptively and securely maintains user privacy preferences for IoT devices in the blockchain network. Individual privacy leakage can be prevented because the gateway effectively protects users' sensitive data from being accessed without their consent. A robust digital signature mechanism is proposed for the purposes of authentication and secure management of privacy preferences. Furthermore, we adopt the blockchain network as the underlying architecture of data processing and maintenance to resolve privacy disputes.
Marcelo Corrales Compagnucci, Paulius Jurčys, George Kousiouris
No abstract is available for this record.
James Brogan, Immanuel Baskaran, Navin Ramachandran
The on-demand digital healthcare ecosystem is on the near horizon. It has the potential to extract a wealth of information from "big data" collected at the population level, to enhance preventive and precision medicine at the patient level. This may improve efficiency and quality while decreasing cost of healthcare delivered by professionals. However, there are still security and privacy issues that need to be addressed before algorithms, data, and models can be mobilized safely at scale. In this paper we discuss how distributed ledger technologies can play a key role in advancing electronic health, by ensuring authenticity and integrity of data generated by wearable and embedded devices. We demonstrate how the Masked Authenticated Messaging extension module of the IOTA protocol can be used to securely share, store, and retrieve encrypted activity data using a tamper-proof distributed ledger.
Paulina Jo Pesch, Christian Sillaber
The authors discuss the application of the EU General Data Protection Regulation’s transparency requirements to distributed ledger (DL) systems. In Section II. the relevant characteristics of DL systems are outlined. Section III. deals with the question of the applicability of the GDPR to DL systems. In Section IV., the authors discuss whether DL system participants can be considered controllers or even joint controllers that are obliged to determine their responsibilities in an arrangement pursuant to Art. 26 paras. 1, 2 GDPR. The conclusion in Section V. includes an outlook to possible approaches to improving transparency in DL systems.
Kongrath Suankaewmanee, Dinh Thai Hoang, Dusit Niyato, Suttinee Sawadsitang · 6 authors
Mobile security has become more and more important due to the boom of mobile commerce (m-commerce). However, the development of m-commerce is facing many challenges regarding data security problems. Recently, blockchain has been introduced as an effective security solution deployed successfully in many applications in practice, such as, Bitcoin, cloud computing, and Internet-of-Things. However, the blockchain technology has not been adopted and implemented widely in m-commerce because its mining processes usually require to be performed on standard computing units, e.g., computers. Therefore, in this paper, we introduce a new m-commerce application using blockchain technology, namely, MobiChain, to secure transactions in the m-commerce. Especially, in the MobiChain application, the mining processes can be executed efficiently on mobile devices using our proposed Android core module. Through real experiments, we evaluate the performance of the proposed model and show that blockchain will be an efficient security solution for future m-commerce.
Ning Zhang, Shan Zhong, Tian Li
Personal privacy protection issues has gradually caused widespread concernin society which will lead to economic and reputation losses, hinder networkand E-commerce innovation or some other consequences if not handled properly. Inthis paper, we make use of the de-centralization, permanent and audibility of theblockchain to propose a blockchain-based personal privacy protection mechanism,which uses Online taxi-hailing as the application scenario. We not only provide thedetails of the blockchain custom transaction domain used by the scene, but alsoexpound the information exchanging and blockchain auditing between passengers,Online taxi-hailing platform and drivers in Online taxi-hailing scene, providing acase model for the blockchain solution to personal privacy protection and a technicalmechanism solution for further study of personal privacy protection issues.
Otto Julio Ahlert Pinno, André Grégio, Luis C. E. Bona
The IoT is pervading our daily activities and lives with devices scattered all over our cities, transport systems, buildings, homes and bodies. This invasion of devices with sensors and communication capabilities brings big concerns, mainly about the privacy and confidentiality of the collected information. These concerns hinder the wide adoption of the IoT. To overcome them, in this work, we present an Blockchain-based architecture for IoT access authorizations. Following the IoT tendency requirements, our architecture is user transparent, user friendly, fully decentralized, scalable, fault tolerant and compatible with a wide range of today's access control models used in the IoT. Finally, our architecture also has a secure way to establish relationships between users, devices and group of both, allowing the assignment of attributes for these relationships and their use in the access control authorization.
Greg Wolfond
IntroductionIdentity verification and authentication has long been a critical component in service delivery for both the private and public sectors, but changing citizen demands in the digital age have stressed the need for new approaches to verify that an individual is who they say they are – with surety.
Philippa Ryan
IntroductionStewart Macaulay’s seminal 1963 article “Non-Contractual Relations in Business” explored why merchants and manufacturers often fail to plan their commercial relationships and why they seldom resort to legal sanctions to settle disputes. Macaulay found that, in many business exchanges, detailed planning and legal sanctions play only a small role. His tentative
Remo Manuel Frey, Pascal Bühler, Alexander Gerdes, Thomas Hardjono · 6 authors
In light of digitalization, customers increasingly share private data through their online behaviors and actions. Yet, customers have become reluctant to share data due to privacy concerns. From a psychological perspective, a reduction of users' perceived risks should result in a higher willingness to share sensitive data. The development of blockchain-supported, multi-part computation thereby represents an interesting novel empirical context to study such willingness to disclose personal data, as such technologies involve a privacy-preserving approach that could not only technically solve privacy issues but also ought to address precisely the user's risk perception. Therefore, we conducted an online experiment with 420 participants to examine the willingness to disclose personal data dependent on different privacy protection mechanisms. A deception based experiment allowed to measure not only user intention, but also real user behavior. Surprisingly, our results demonstrate that participants shared similar amounts of personal data for blockchain-supported approaches and standard privacy policies. Even though an aversion to the blockchain system due to its novelty and potentially perceived complexity was not detected. Furthermore, we found that the willingness to share data increased significantly specifically for technically affine people when they were presented with the opportunity to monetize their data. We further discuss the effects of privacy awareness and whether prior knowledge of blockchain technology had a supporting effect for user acceptance.
Nabil Rifi, Elie Rachkidi, Nazim Agoulmine, Nada Chendeb Taher
In the past few years, the number of wireless devices connected to the Internet has increased to a number that could reach billions in the next few years. While cloud computing is being seen as the solution to process this data, security challenges could not be addressed solely with this technology. Security problems will continue to increase with such a model, especially for private and sensitive data such as data personal and medical data collected with more and more sophisticated connected devices (forming the IoT). Thus the need for a fully decentralized peer to peer and secure technology to overcome these problems. The blockchain Technology is a promising approach giving the properties it brings to the field. This paper illustrates an architecture based on blockchain technology, and a protocol for data access, using smart contracts and a publisher-subscriber mechanism.
Xiaoqi Li, Peng Jiang, Ting Chen, Xiapu Luo · 5 authors
Since its inception, the blockchain technology has shown promising application prospects. From the initial cryptocurrency to the current smart contract, blockchain has been applied to many fields. Although there are some studies on the security and privacy issues of blockchain, there lacks a systematic examination on the security of blockchain systems. In this paper, we conduct a systematic study on the security threats to blockchain and survey the corresponding real attacks by examining popular blockchain systems. We also review the security enhancement solutions for blockchain, which could be used in the development of various blockchain systems, and suggest some future directions to stir research efforts into this area.
Steven Goldfeder, Harry Kalodner, Dillon Reisman, Arvind Narayanan
Abstract We show how third-party web trackers can deanonymize users of cryptocurrencies. We present two distinct but complementary attacks. On most shopping websites, third party trackers receive information about user purchases for purposes of advertising and analytics. We show that, if the user pays using a cryptocurrency, trackers typically possess enough information about the purchase to uniquely identify the transaction on the blockchain, link it to the user’s cookie, and further to the user’s real identity. Our second attack shows that if the tracker is able to link two purchases of the same user to the blockchain in this manner, it can identify the user’s cluster of addresses and transactions on the blockchain, even if the user employs blockchain anonymity techniques such as CoinJoin. The attacks are passive and hence can be retroactively applied to past purchases. We discuss several mitigations, but none are perfect.
Steven Goldfeder, Harry Kalodner, Dillon Reisman, Arvind Narayanan
We show how third-party web trackers can deanonymize users of\ncryptocurrencies. We present two distinct but complementary attacks. On most\nshopping websites, third party trackers receive information about user\npurchases for purposes of advertising and analytics. We show that, if the user\npays using a cryptocurrency, trackers typically possess enough information\nabout the purchase to uniquely identify the transaction on the blockchain, link\nit to the user's cookie, and further to the user's real identity. Our second\nattack shows that if the tracker is able to link two purchases of the same user\nto the blockchain in this manner, it can identify the user's entire cluster of\naddresses and transactions on the blockchain, even if the user employs\nblockchain anonymity techniques such as CoinJoin. The attacks are passive and\nhence can be retroactively applied to past purchases. We discuss several\nmitigations, but none are perfect.\n