Abstract The facilitation of sharing and exchanging patients’ health records is a paramount opportunity in e-health, enabling healthcare providers to garner a comprehensive and clear perspective of patients’ medical histories without necessitating direct inquiries. Besides this great advantage, it introduces substantial issues on security and privacy, mainly related to unauthorized access to e-health records when different healthcare service providers maintain records. In this paper, we deal with this problem and propose using the blockchain technology (1) to obfuscate the linkage between patients’ identities and their e-health records and (2) to grant access to e-health records exclusively to entities authorized by patients themselves. Key outcomes include using a digital identity based on the Electronic Identification, Authentication, and Trust Services Regulation (eIDAS) to control access to these records, and a concrete implementation by adopting the Ethereum blockchain. Our solution relies on using a public blockchain, which is an improvement for the state of the art, in which only private or consortium blockchains have been proposed. The resulting solution has been analyzed, and the effectiveness and affordability of the proposal have been shown.
Vehicular fog computing (VFC) is a developing concept that utilizes the ideas of fog computing to facilitate immediate communication and cooperative decision-making among vehicles. However, guaranteeing safe authentication in VFC presents notable difficulties as a result of characteristics such as dynamic network topology, extensive mobility, and limitations on resources. This paper introduces D-BlockAuth, an innovative authentication mechanism for 5G-assisted VFC that utilizes a dual blockchain approach. To reach the most vehicles, this link makes use of all the features of the fifth-generation base station (5G-BS). D-BlockAuth employs two blockchains: a permissioned blockchain to handle long-term identities and a consortium blockchain to enable streamlined and effective authentication at the fog layer. The D-BlockAuth concept incorporates advanced cryptographic techniques such as ring signatures and group signatures, which provide improved privacy and anonymity for vehicles within the network. The study provides a comprehensive description of the architecture of D-BlockAuth, examines its security characteristics, and assesses its performance using simulations. The results indicate that D-BlockAuth successfully performs both efficient and safe authentication in VFC, while also maintaining user privacy.
Recently, most people have been looking for smart services that allow them to do their daily services directly without having to visit local businesses and providers [1]. As observed in recent times, citizens can now apply to open their own commercial file or obtain a passport without having to visit the country's economic institution or the Immigration and Passports headquarters. Additionally, applying or opening accounts in virtual banks also added a lot of services and facilities for users and transactions between countries that can be rapidly provisioned with minimal effort [2]. All these transactions require the user's authentication and identity verification to avoid any personal fraud and save the user's rights Blockchain technology stands out as one of the most secure technologies available enabling secure transactions without the need for a central authority. Starting in 2009 1, with Bitcoin leveraging blockchain technology, there has been an increasing number of blockchain technology-based solutions. The significance of this work compared to its predecessors is that it uses an existing product and technology to prove the solutions offered by Blockchain and find a solution for authorization and authentication.
Syed M. Aqleem Abbas, Muazzam A. Khan, Wadii Boulila, Anis Kouba · 6 authors
Unmanned aerial vehicles (UAVs) can be used as drones’ edge Intelligence to assist with data collection, training models, and communication over wireless networks. UAV use for smart cities is rapidly growing in various industries, including tracking and surveillance, military defense, managing healthcare delivery, wireless communications, and more. In traditional machine learning techniques, an enormous amount of sensor data from UAVs must be shared to central storage to perform model training, which poses serious privacy risks and risks of misuse of information. The federated learning technique (FL), which can be applied to UAVs, is a promising means of collaboratively training a global model while retaining local access to sensitive raw data. Despite this, FL is a significant communication burden for battery-constrained UAVs due to local model training and global synchronization frequency. In this article, we address the major challenges associated with UAV-based FL for smart cities, including single-point failure, privacy leakage, scalability, and global model verification. To tackle these challenges, we present a differentially private federated learning framework based on Accumulative Reputation-based Selection (ARS) for the edge-aided UAV network that utilizes blockchains to prevent single-point failures where we switched from central control to decentralized control, Interplanetary File System (IPFS) for off-chain model storage and their respective hash-keys on-chain to ensure model integrity. Due to IPFS, the size of the blockchain will be reduced, and local differential privacy will be applied to prevent privacy leakages. In the proposed framework, an aggregator will be selected based on its ARS score and model verification by the validators. After most validators approve it, it will be available for use. Several parameters are taken into consideration during evaluation, including accuracy, precision, recall, F1-score, and time consumption. It also evaluates the number of edge computers vs test accuracy, the number of edge computers vs time consumption for global model convergence, and the number of rounds vs test accuracy. This is done by considering two benchmark datasets: MNIST and CIFAR-10. The results show that the proposed work preserves privacy while achieving high accuracy. Moreover, it is scalable to accommodate many participants.
Archana Chhabra, Rahul Saha, Gulshan Kumar, Tai-hoon Kim
Blockchain networks provide a reliable and secure mode of communication due to their decentralized and distributed nature. The emergence of amalgamated blockchain-based internet-of-things (IoT) systems has generated a huge amount of data to be online. Though blockchains show potential for ensuring transparency, traceability, and immutable records, the privacy of online data in blockchains becomes a question. The privacy of blockchain transactions is at stake as various privacy breaching methods are used by attackers such as linking the transactions, deanonymization, etc. However, the benefits of blockchain make the technology a dominator in the present and future technological paradigms. The other side of the coin deals with privacy information retrieval (PIR), which is necessary to retrieve private information from servers without much revealing. However, the conjunction of blockchain privacy and PIR is very critical and an important aspect of blockchain solutions. In this present survey, we pioneer in analyzing the privacy factors of existing blockchain solutions. We discuss the privacy parameters and important privacy enhancement techniques for blockchains comprehensively. We show the applicability of privacy in various domains including e-commerce, supply chain, healthcare, and IoT. We also discuss PIR-related issues and solutions in the existing literature. We highlight open research problems and discuss the benefits of collaborating with PIR and blockchain systems to improve privacy in blockchains. Our survey is beneficial for academia and industries to be aware of the present status of privacy solutions in blockchains and to address the identified loopholes to make the systems better.
Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Advanced Steganography and Watermarking Techniques
As the metaverse gains traction, the importance of metaverse security research becomes increasingly evident. While there has been research on authenticating users in the metaverse, there is a notable gap in research concerning the authentication of specific spaces within the metaverse. This paper addresses this gap by proposing a novel user-centric blockchain-based authentication approach that incorporates space authentication. The proposed approach leverages blockchain smart contracts to authenticate users using cosine similarity metrics. A significant advantage of this approach its ability to establish user-centric authentication by seamlessly integrating metaverse and blockchain technologies, all without the need for a centralized authority. In this paper, we not only evaluate the security of our proposed approach but also conduct experiments to determine the cosine similarity threshold and assess its feasibility within a metaverse environment.
In the realm of digital advertising, trust and transparency are vital for sustainable and effective marketing strategies. However, the industry grapples with challenges such as ad fraud, data privacy violations, and opacity in ad placements. Blockchain technology emerges as a promising solution to decode trust and foster transparency in digital advertising. Blockchain, initially developed for cryptocurrencies like Bitcoin, offers a decentralized and immutable ledger, ensuring data integrity without intermediaries. Applied to digital advertising, blockchain can revolutionize transparency by providing a tamper-proof record of ad transactions. Smart contracts automate agreements, enhancing accountability and ensuring fair compensation. Key findings reveal the potential benefits of blockchain in digital advertising. Firstly, it enhances accountability and transparency by tracing advertising funds and verifying ad authenticity. Smart contracts automate payments, reducing ad fraud and increasing supply chain accountability. Secondly, blockchain mitigates ad fraud by providing transparent ad transaction records and leveraging decentralized identity verification to authenticate users. Thirdly, transparency fosters consumer trust and confidence, empowering informed decision-making and benefiting the entire ecosystem. However, challenges persist, including technical scalability, interoperability, and regulatory compliance. Adherence to data privacy regulations and integration with existing ad tech infrastructure are crucial considerations. Organizational and cultural barriers, along with industry fragmentation, hinder blockchain adoption. Future directions and opportunities lie in tokenization, decentralized identifiers, and zero-knowledge proofs, promising solutions to existing challenges. Collaboration among stakeholders is essential to develop standards and protocols, overcoming barriers to blockchain adoption. Continued research, innovation, and collaboration are necessary to realize the full potential of blockchain in promoting trust and transparency in digital advertising. DOI: https://doi.org/10.52783/eel.v14i2.1539
David Frempong, Chigozie Emmanuel Benson, Odunayo Oyasiji, Adeola Okesiji
The digitization of healthcare records and the proliferation of patient data across interconnected systems have raised significant concerns about privacy, regulatory compliance, and consent management. Traditional methods of obtaining and maintaining patient consent are often fragmented, static, and non-compliant with dynamic legal standards such as the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA). This paper explores a blockchain-enabled framework for consent management in healthcare, focusing on enforcing patient privacy preferences and regulatory compliance. Through a comprehensive review of existing literature and frameworks, this paper proposes a decentralized consent management architecture leveraging smart contracts and distributed ledger technologies to provide secure, transparent, and tamper-proof consent enforcement. The study also outlines the potential of blockchain to automate compliance tracking, enhance interoperability, and empower patients with granular control over their health data. Recommendations for future research directions and technical challenges are also presented.
This article explores the importance of putting users at the center of consent processes, in Single Sign On (SSO) systems to tackle privacy issues and empower user independence. It dives into the world of SSO systems shedding light on their privacy weaknesses and the need for users to have control over how their data is shared. By looking at privacy focused SSO solutions and their drawbacks the article suggests a plan to give users control over their data sharing preferences during authentication. The main elements of this plan include a user consent management interface, consent choices, educational materials, preference persistence and tracking logs. Additionally it talks about the obstacles in implementing consent driven SSO systems like creating consent APIs and incorporating privacy boosting technologies such as zero knowledge proofs and decentralized identity frameworks. By tackling these hurdles and promoting designs that prioritize users the article aims to help create authentication solutions that prioritize privacy in line, with changing regulations and user desires.
Vladimir Popov, Mikhail Krupin, Andrew Gross, Georgi Koreli
New advancements in zero-knowledge proof construction, including improvements in user experience, have made blockchain-based privacy applications more accessible than ever.However, additional measures are required to balance the needs of regulators, the basic privacy rights of users, and the constant threat of bad actors.To address these issues, privacy protocols can introduce features designed to increase transparency, encourage compliance, and prevent illicit use.In this paper, current privacy-preserving methods (privacy pools) are explained along with compliance measures designed to prevent illicit usage.These measures are divided into three broad categories: general restrictions, such as transaction limits, deposit quarantine, and geoblocking; selective disclosure, such as privacy-preserving KYC, proof of innocence, and opt-in reporting; and threat identification and prevention, including AML wallet screening.Each of these methods are described in detail along with examples of three privacypreserving protocols (Hinkal, RAILGUN, and zkBob) which utilize varying combinations of these methodologies to achieve privacy informed by selfregulatory compliance.
Building smart services for smart cities has become a significant focus of the Internet of Things (IoT). These IoT devices are able to sense their surroundings and react appropriately. Smart city applications emphasize the necessity of safe data sharing across heterogeneous devices. Certain behaviors taken while sharing could aim at compromising security, privacy, and integrity. The centralized repository that is currently in place made the majority of hacks possible. The sharing of sensitive data and authentication are essential stages in guaranteeing the security of applications associated with IoT. Blockchain and IoT are two widely used technologies, with IoT focusing on data collection via various devices and blockchain enabling data integrity. This paper introduces a novel blockchain-based framework to ensure the security and integrity aspects of IoT data. The proposed SecPrivPreserve framework ensures security through various phases including initialization, registration, data protection, authentication, data access control, validation, and data sharing and download. Diverse security mechanisms such as passwords (OTP), encryption, and hashing have been deployed in various phases to strengthen security merits confidentiality, privacy, and integrity. Since the SecPrivPreserve framework is simulated in a permissioned blockchain platform the merits and tamper-proof and non-repudiation are automatically considered. Moreover, data protection uses Chebyshev polynomials and interpolation. The presented framework has experimented with Fabric SDK. The experimental results of the proposed framework are compared with the BaseLine state-of-the-frameworks, The experimental analysis reveals that the proposed SecPrivPreserve approach achieved 34 Sec improvement in terms of responsiveness 94 Sec as computational time, encryption quality as 0.87 Sec and 0.82 Sec for detection rate.
Distributed Ledger Technology (DLT) has been contentious since the emergence of blockchain in 2008. Security and compatibility with the personal data rights in the EU General Data Protection Regulation (GDPR) are among the controversies that have erupted. Thus, various studies have concluded that the decentralisation and immutability of DLT conflict with personal data rights. This dissertation illustrates that the DLT can be compatible with the GDPR personal data rights.
This thesis tells the story of DTube, a blockchain-based social media (BSM) platform positioned as an alternative to YouTube. BSM platforms are situated at the intersection of the emergent Web3 discourse and the dominant platform paradigm. These novel initiatives attempt to develop community-led alternatives to mainstream commercial platforms by leveraging emergent Web3 technologies. Using the platform biography approach, the thesis traces DTube’s evolution between 2017-2022, locating these changes within the history of the web and digital media platforms. It contributes to a broader understanding of changing discourses, technologies, and practices of the web at a crucial historical juncture.
Smart cities represent a promising paradigm aimed at enhancing citizens’ quality of life through cutting-edge infrastructure and technological advancements. Collaborative services serve as a cornerstone for any smart city, fostering seamless cooperation among diverse entities, including government agencies, businesses, and individuals, thereby enhancing community outcomes. These services are pivotal, promoting seamless communication and collaboration among various smart applications, and facilitating data exchange, resource sharing, and functional interactions within smart city environments to optimize efficiency, effectiveness, and user experiences. However, the development and deployment of secure, interoperable services in smart cities present significant challenges. These issues encompass, ensuring data security compliance during interoperation, effective management of interconnected services, securely handling sensitive data across services, and addressing issues related to confidentiality, integrity, and availability (CIA) traits. To tackle these challenges, this research proposes an innovative adaptive security governance framework tailored for smart cities. This framework relies on dynamic security policies implemented through smart contracts to guarantee data security and privacy during smart service interoperation. Real-world use cases in collaborative smart city environments validate the framework, integrating multi-chain blockchain technology, smart services APIs, and Software-Defined Networking (SDN), showcasing its ability to enhance security and efficiency in collaborative services. This study contributes to the development of safe and efficient collaborative services inside smart cities, tackling administrative issues while emphasizing data security and privacy. Smart cities may improve citizens’ living conditions while successfully addressing crucial security problems in an ever-changing environment by using this architecture.
The increased digitalization of society raises concerns regarding data protection and user privacy, and criticism on how the companies handle user data without being transparent and without providing adequate mechanisms for users to control how their own data is being processed or shared. To address this problem and open the way for a secure and efficient society, where the privacy of citizens is paramount, the identity concept and proof of identity mechanisms need to be redesigned from the ground up. In this paper we discuss how the emerging Web3 technologies like distributed ledger technology (DLT), blockchain, smart contracts, decentralized storage systems, and crypto wallets can be leveraged to design and implement a decentralized digital identity system based on decentralized identifiers (DID) and self-sovereign identities (SSI). Such a system puts the users in full control over their own data while also providing a solid backbone for building interoperable systems that are secure, scalable, and efficient. We propose different architectures for the decentralized identity infrastructure and storage layer, and also discuss the mapping of these architectures on cloud platforms. The main goal is to provide an architectural blueprint for a scalable, secure, privacy-preserving and trusted system.
In the current digital landscape, almost everyone is on social media or various social media platforms. People use social media for a plethora of purposes, which include staying connected with friends and family, accessing information and updates about ongoing events, entertainment, networking with professionals, expressing themselves to a wide range of users, promoting businesses, joining online communities and engaging in various activities which has led to an increase in the consumption and usage of online social networks (OSN). One of the reasons for such a growth is their features such as ubiquitous access, on-demand service, friendship networks, user engagement strategies like recommendation engines, etc. However, there are various limitations to the current approach, such as the centralization of control, lack of data ownership, poor access control, fake news, bot accounts, censorship, digital rights management issues, etc. To address these limitations, a paradigm shift is necessary. This paper aims to develop a social media application where every post can be converted to a Non-Fungible Token (NFT) and be sold to earn money. Interplanetary File System (IPFS) is used as the decentralized storage. Algorithms for all the functionalities of the applications are given along with an algorithm for a reputation score for every user and their posts in social media are also proposed.
Open access
3 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Abstract This chapter has two purposes. First, we describe how information system (IS) scholars approach privacy research and summarize major findings. IS scholars are concerned with information privacy and have discovered that individuals have serious information privacy concerns. These concerns, however, do not prevent individuals from disclosing personal identifiable information (PII) with centralized platform providers, a phenomenon called the privacy paradox . We highlight four common explanations for the privacy paradox: privacy calculus, privacy fatigue, trust, and lack of choice. Most IS research investigated Web2 applications. Web2 is the foundation for today’s global economy. With Web2, users rely on centralized platforms for online searching, shopping, banking, data storage, social media, and other services. Second, we introduce readers to the new paradigm of Web3. Privacy protection has been the paramount logic behind the grand design of Web3 applications. Web3 is the era of the Internet that is based on decentralized infrastructures and applications, like Bitcoin and Ethereum. Web3 applications enhance information privacy compared to Web2 because individuals can access services without disclosing PII to a central authority. The privacy objective is achieved technically through a combination of digital wallets, cryptography, and distributed ledgers (a.k.a blockchain). While Web3 is still in its early days, education is an important driver of adoption.
Self-sovereign identity models and decentralized, blockchain-based identity management can prevent digital ecosystem data breaches and misuse, the study finds. As digital services proliferate and personal data becomes more valuable, central database-based identity systems expose users to single-point failures, unauthorized access, identity theft, and large-scale breaches. This paper analyzes how decentralized IDs, verifiable credentials, and cryptographic verification reduce middlemen, enable selective disclosure, and promote identity governance privacy. Important academic, industrial, and technical contributions show that blockchain anchors credentials in distributed ledgers rather than institutional repositories, improving authentication, traceability, and tamper resistance while limiting undesired access. Immutable audit trails, user-controlled credentials, and reduced central authority dependency have been touted, but empirical performance data, scalability, interoperability, and comparative evaluations of public and permissioned blockchain environments are lacking. These findings explain self-sovereign identity architecture, which lets trusted authority issue credentials but users store and control them directly through digital wallets utilizing cryptographic proofs instead of database lookups. Users can control or withdraw data sharing while maintaining identity. Transparency, limited disclosure, and contextual data presentation prevent cross-platform tracking and increase user autonomy. The research shows how zero-knowledge proofs and predicate-based validation verify credentials without disclosing sensitive data, protecting privacy. Birthdates and locations are not needed to verify age- and location-based limits. SSI master key-derived domain-specific identities reduce correlation hazards and prevent service surveillance. Consent-based sharing, selective disclosure, and cryptographic compartmentalization decrease data collection and profiling. Decentralised blockchain verification maintains credentials usable when the issuer is offline, preventing service disruptions and third-party participation.