Anthony Anyanwu, Samuel Onimisi Dawodu, Adedolapo Omotosho, Odunayo Josephine Akindote · 5 authors
This study examines blockchain applications in the USA's government systems, analyzing its effectiveness in public administration and governance. Blockchain technology, initially introduced as the underlying infrastructure for cryptocurrencies, has garnered substantial attention for its potential to transform various sectors, including government systems. This paper provides a comprehensive review of the applications and impacts of blockchain technology in the United States' governmental landscape. As governments worldwide seek innovative solutions to enhance transparency, efficiency, and security, blockchain emerges as a disruptive force with the capacity to reshape administrative processes. The study elucidates the fundamental principles of blockchain technology, emphasizing its decentralized and tamper-resistant nature. It also explores diverse applications within government systems, ranging from identity management and voting systems to supply chain traceability and public finance. The analysis delves into specific use cases, detailing how blockchain enhances data integrity, reduces fraud, and streamlines bureaucratic processes. Furthermore, the paper assesses the implications of blockchain adoption for government operations, highlighting potential benefits such as cost reduction, increased accountability, and enhanced citizen trust. Challenges and considerations, including scalability, interoperability, and regulatory frameworks, are scrutinized to provide a balanced understanding of the technology's limitations. The review extends to the United States' federal and state-level initiatives, examining pilot projects and ongoing implementations that leverage blockchain in areas such as land registries, healthcare data management, and procurement. Insights into the collaborative efforts between public and private sectors are explored, shedding light on the collaborative frameworks essential for successful blockchain integration. Ethical considerations and privacy concerns are addressed within the context of blockchain applications in government, emphasizing the need for robust safeguards to protect sensitive information while harnessing the transformative potential of the technology. This paper synthesizes the current state of blockchain technology in the United States' government systems, offering a nuanced understanding of its applications and impacts. As blockchain continues to mature and gain traction, this review contributes valuable insights for policymakers, researchers, and practitioners, fostering a deeper appreciation for the transformative potential of blockchain in shaping the future of government operations.
Blockchain technology (BT) is increasingly important in digital government as a means of efficient information management, decision making and an instrument for reform. This study presents a systematic review of BT's potential and application in land registration within low-income countries. The study uncovers diverse approaches to BT implementation that are influenced by local conditions and government structures. The study reveals that while there is a burgeoning interest in this field, actual implementations remain limited. The key barriers include resistance from government officials and a lack of local BT skills. Public blockchains have shown a high tendency for adoption, indicating a shift towards more transparent relationships between governments and citizens. The Hyperledger Fabric platform emerges as a popular choice due to its ability to provide secure, scalable, and robust solutions. However, there is a lack of clarity regarding the consensus mechanisms used, indicating a potential gap in current research practices. The study recommends an incremental approach to BT implementation, starting with non-threatening, transparent processes that could be expanded as part of broader government reform programs. Despite the potential of BT to revolutionize land registration systems and democratize tracking, it also poses a threat to existing power structures. Therefore, more robust empirical research is needed to evaluate the impacts and navigate the associated sociotechnical, legal, and institutional challenges. The study also proposes the establishment of a BT collaborative network among low-income countries to leverage shared experiences and develop a common framework for implementation. In the single instance where it was implemented in Georgia, public trust in government was restored. The study contributes to understanding how BT can be effectively harnessed to improve land registration systems in low-income countries.
This study explores the integration of Fast Healthcare Interoperability Resources (FHIR) standards in a system designed for secure and efficient management of Personal Health Records (PHRs). PHRs are crucial for patients to have control over their healthcare information and make informed decisions. Ensuring the security of this sensitive data is vital, and blockchain technology offers robust protection. However, the high cost of storing PHRs on the blockchain has led us to investigate the use of the Interplanetary File System (IPFS) alongside blockchain. Our proposed system comprises a PHR Decentralized Application (DAPPS), IPFS, Metamask, and the Ethereum Blockchain. Users input their PHR data through the DAPPS, which is stored in IPFS, and its location is registered on the Ethereum Blockchain via Metamask. Comprehensive testing validates the system's performance, with success across all test cases, confirming the feasibility of utilizing the Interplanetary File System and Ethereum Blockchain for secure PHR management while adhering to FHIR standards, fostering interoperability in healthcare data exchange.
This paper delves into the crucial aspects of authentication and authorization in modern web applications with a focus on enhancing data security. It explores the use of Node.js, a versatile server-side language, for building web applications and discusses the significance of a secure website for establishing trust between clients and servers. The research covers the implementation of authentication using packages and hashing algorithms, emphasizing the importance of "salt" and "pepper" for password security. Authorization methods, including cookies, sessions, and middleware, are also explored. The paper highlights the necessity of robust security measures to safeguard user data from the dark web and points to future directions in web security, including the role of blockchain and artificial intelligence in the WEB3 landscape.
Federated learning (FL) and blockchains exhibit significant commonality, complementarity, and alignment in various aspects, such as application domains, architectural features, and privacy protection mechanisms. In recent years, there have been notable advancements in combining these two technologies, particularly in data privacy protection, data sharing incentives, and computational performance. Although there are some surveys on blockchain-based federated learning (BFL), these surveys predominantly focus on the BFL framework and its classifications, yet lack in-depth analyses of the pivotal issues addressed by BFL. This work aims to assist researchers in understanding the latest research achievements and development directions in the integration of FL with blockchains. Firstly, we introduced the relevant research in FL and blockchain technology and highlighted the existing shortcomings of FL. Next, we conducted a comparative analysis of existing BFL frameworks, delving into the significant problems in the realm of FL that the combination of blockchain and FL addresses. Finally, we summarized the application prospects of BFL technology in various domains such as the Internet of Things, Industrial Internet of Things, Internet of Vehicles, and healthcare services, as well as the challenges that need to be addressed and future research directions.
Blockchain technology is increasingly being used in personal data protection. Inspired by the importance of data security, this paper proposes a personal data protection mechanism based on blockchain, combined with distributed hash tables and cryptography, to enhance users' control over the data generated using web applications. This paper designs this mechanism's system model and describes the three aspects in detail: data storage mechanism, data encryption mechanism, and data trading mechanism. Among them, the data storage mechanism restricts user data to be stored only in the local storage space of the user terminal, the decentralized blockchain network, and the distributed hash table network to ensure that enterprises providing network applications cannot privately store user interaction data, the encryption mechanism is responsible for encrypting all user data recorded in the network and allows users to control the key of the data to ensure the security of the user data in the blockchain and distributed hash tables, the data transaction mechanism allows users to trade their data, and to incentivize enterprises to assist users in collecting personal data, data transaction contracts are built into the data transaction mechanism, allowing enterprises to receive a share of the revenue from user data transactions. Then, for data transactions, use the Stackelberg game to simulate the revenue sharing between users and service providers in data trading to incentivize enterprises providing web services to assist users in collecting their data. The simulation results show that when the number of users is 1000, the revenues of this scheme for service providers are 31%, 561%, and 19% higher than the existing scheme. Finally, the personal data protection platform is implemented by code to verify the feasibility of the theory proposed in this paper in personal data protection.
Mobile crowdsourcing (MCS) is an emerging paradigm that enables the outsourcing of a complex task to a group of mobile devices. The ability to utilize the collective power of mobile devices and human intelligence makes MCS a significant tool in various scenarios. Nevertheless, it faces practical challenge in protecting user privacy due to the sensitive nature of information collected by mobile devices. Additionally, the inherent openness of MSC and the heterogeneity of mobile devices raise reliability concerns among participants. To address these challenges, by integrating Federated Learning with the pairwise additive masking technique and the Chinese Remainder Theorem, we propose a Blockchain-based Privacy-preserving Federated Learning (BPFL) framework for mobile crowdsourcing, which allows mobile participants to collaboratively solve a crowdsourced machine learning task while preserving privacy. Besides, it employs blockchain technology to record the training process in a transparent and tamper-proof ledger. This ledger guarantees the verifiability of aggregation results and the fair distribution of training rewards, thereby enhancing trust and fairness. We prove that our BPFL supports privacy protection and trust mechanism simultaneously and resists inference and collusion attacks. Experimental results show that our BPFL can achieve high performance in terms of computation cost, communication cost and model accuracy, which is friendly for mobile users with resource-constrained devices in MCS ecosystems.
The proliferation of Internet of Things (IoT) devices has ushered in a new era of connectivity, necessitating robust solutions for user authentication to address security and trust challenges. This paper explores an innovative approach to user authentication in IoT environments by leveraging the unique capabilities of Non-Fungible Tokens (NFTs) and 9NM (9NFTMANIA) tokens, with a specific focus on utilizing contract addresses. The proposed system involves the tokenization of user identities through the creation of contract addresses on blockchain networks. Each user is assigned a unique digital identity represented by an NFT or 9NM token, providing a tamper-proof association between the user and their cryptographic keys. Blockchain smart contracts are employed to manage authentication processes, dictating access control policies based on the user's contract address. The research underscores the importance of industry-wide collaboration to develop common standards for user authentication in IoT environments. By offering a comprehensive exploration of user authentication in IoT using contract address-based NFTs and 9NM tokens that are developed on Satoshi core based blockchain, this paper contributes to the advancement of secure and user-centric practices in the rapidly evolving landscape of IoT technology. The proposed framework not only enhances the overall security posture of IoT networks but also lays the foundation for a more transparent and interoperable authentication ecosystem. This paper has discussed the mechanism where web 3.0 based programming is made using Javascript, Python, ASP.NET and PHP for user authentication considering presence of smart contracts in user wallet.
Libertarian “exit” imaginaries project new social, political, and economic structures separate from existing institutions in which “sovereign individuals” can opt-in to the governing system that fits their ideals. This paper traces libertarian exit imaginaries through a variety of territorial and technological projects. Demonstrating how these imaginaries evolve, it describes a recent proposal to build a semi-autonomous, blockchain-based smart city in Nevada. Reflecting on these projects, the paper highlights (1) their inevitable failure as they confront reality, (2) their role as spectacle, spreading libertarian ideology, and (3) their real-life impacts on distinct places and communities even when they fail or never materialize.
Mansoor Ahmed Jumani, Du Yujie, Muhammad Owais Khan
A key component of democratic governance in modern countries is the election process. But due to worries about things like polling booth capturing, data manipulation, and vote rigging, a general mistrust in the electoral process has evolved. Because they put election data under the authority of outside organizations, both the traditional and computerized voting systems now in use lack the required transparency. Voters have few options to verify that election administrators will carefully and accurately count their votes due to a lack of openness. To create an electronic voting (e-voting) system that upholds the ideals of fairness and security, it is imperative to take advantage of developing technology, particularly blockchain. When correctly applied, blockchain technology's public distributed ledger holds the potential to make tampering almost impossible. In this regard, our research suggests a decentralized electronic voting system that makes use of blockchain technology as a remedy to deal with the aforementioned issues. Through the elimination of the possibility of centralized election control, this approach seeks to reduce the dangers connected with conventional election procedures and increase voter confidence. The suggested method offers a tamper-proof, transparent, verifiable, economical, and reliable voting process through the distribution of control across several governing and non-governing bodies. This paper examines the development and implementation of such a blockchain-based electronic voting system, shedding insight on how it may enhance the openness and accessibility of democratic elections in contemporary societies.
New digital technologies generate large amounts of information. This data is processed by Service Providers in order to improve and develop new services and products, but also to fund themselves. However, processing personal data may result in the extraction of sensitive information, which, in turn, may lead to jeopardizing the users’ privacy. To mitigate this significant risk, the European Parliament and Council of the European Union elaborated the General Data Protection Regulation (GDPR). This regulation forces Service Providers to obtain Data Subjects’ explicit consent prior to collecting and processing their personal data. Nevertheless, the GDPR’s legislative text does not define how Service Providers must transparently demonstrate that they already have these consents. Moreover, most individuals do not know the rights they have over their personal data, neither does this regulation provide them with efficient methods to be aware of what third parties are doing with such data. In order to address this situation, we propose a lightweight blockchain-based GDPR-compliant personal data management platform. The new solution provides public access to immutable evidences that reflect the reached agreements between Data Subjects and Service Providers. In this way, Service Providers can effectively demonstrate that they are fulfilling the regulation, and Data Subjects are able to control and manage their personal data according to their legitimate rights. We have implemented the new system, and we have performed a detailed study which includes: GDPR-compliance, provided functionality, security and privacy issues, and the cost in terms of gas and US dollars of the different operations to be run on the blockchain.
Ricardo Martins Gonçalves, Miguel Mira da Silva, Paulo Rupino da Cunha
Abstract Blockchain has been gaining significant interest in several domains. However, this technology also raises relevant challenges, namely in terms of data protection. After the General Data Protection Regulation (GDPR) has been published by the European Union, companies worldwide changed the way they process personal data. This project provides a model and implementation of a blockchain system to store personal data complying with GDPR. We examine the advantages and challenges and evaluate the system. We use Hyperledger Fabric as blockchain, Interplanetary File System to store personal data off-chain, and a Django REST API to interact with both the blockchain and the distributed file system. Olympus has three possible types of users: Data Subjects, Data Processors and Data Controllers and a fourth participant, Supervisor Authority, that, despite not being an explicit role, can perform all verifications that GDPR mandates. We conclude that it is possible to create a system that overcomes the major challenges of storing personal data in a blockchain (Right to be Forgotten and Right to Rectification), while maintaining its desirable characteristics (auditability, verifiability, tamper resistance, distributed—remove single points of failure) and complying with GDPR.
Nidhi Desai, Damiano Di Francesco Maesa, Nishanth Sastry, Steve Schneider · 5 authors
This paper is concerned with helping people who are vulnerable during important transitions in life, such as 'coming out' as LGBTQIA+, experiencing serious illness, undergoing relationship breakdown etc. Rich sensor streams derived from so-called 'smart' Internet of Things (IoT) devices can be highly beneficial, for example in ensuring the safety of such individuals during their sensitive life transitions, or in providing functionality that can mitigate some of the difficulties faced by them. However, the data that needs to be extracted to provide these benefits can itself be highly sensitive and needs to be processed with safeguards to protect privacy. We develop scenarios that highlight issues arising from having to merge data streams from multiple devices, including data governance issues that are relevant when the sensors are owned by multiple individuals. We propose a "Transition Guardian" architecture that leverages "Smart Experts" written as smart contracts operating on homomorphically encrypted sensor data streams to provide real-time protection without disclosing their sensitive information. We have also implemented a proof-of-concept on the Ethereum protocol to validate our proposed solution.
Abstract Privacy concerns the majority of individuals, governments, and organizations that share data over dissimilar networks of nodes. Every kind of participant requires awareness of the data journey that unfolds inside a blockchain network with its own trustworthy rules of data management and accessibility. This paper provides a methodological approach on privacy for data sharing within blockchain environments. Specific technological aspects of blockchains that relate to on‐chain privacy such as network nature, party join, smart contracts, blockchain states, transactions, and ledger flows, are analysed with respect to the involvement and impact of privacy in distributed ledgers. A high‐level architectural approach is suggested that is intended to address significant privacy concerns on data sharing among different kinds of users in the context of blockchain networks deployment and the broader Web 3.0 ecosystem building. Simultaneously, many pertinent challenges are discussed regarding network nature, configurable privacy, ownership, confidentiality, secured computation, and data monetization that appear in the field and ought to be carefully tackled for the future mass adoption of privacy‐matured distributed ledgers that interconnect delivering the future Internet.
A donation-tracking system leveraging smart contracts and blockchain technology holds transformative potential for reshaping the landscape of charitable giving, especially within the context of Web 3.0. This paper explores how smart contracts and blockchain can be used to create a transparent and secure ledger for tracking charitable donations. We highlight the limitations of traditional donation systems and how a blockchain-based system can help overcome these challenges. The functionality of smart contracts in donation tracking, offering advantages such as automation, reduced transaction fees, and enhanced accountability, is elucidated. The decentralized and tamper-proof nature of blockchain technology is emphasized for increased transparency and fraud prevention. While elucidating the benefits, we also address challenges in implementing such a system, including the need for technical expertise and security considerations. By fostering trust and accountability, a donation-tracking system in Web 3.0, empowered by smart blockchain networks, aims to catalyze a profound positive impact in the realm of philanthropy.
Electronic communications security has gained a considerable significance in parallel with the increasing usage of the information and communication technologies. Being one of these technologies, distributed ledger technologies (DLTs), more specifically the blockchains, are regarded as a revolution which propose a new era, called “blockchain of things” following the era of “internet of things”. While DLTs promoted the business functionalities and compliance with information security obligations, it has also some vulnerabilities. By the DLTs the cost of intermediaries could easily be eliminated while at the same time assets/transactions are recorded and secured digitally. Nevertheless, this has simultaneously resulted in decentralised power/anarchy. Besides, majority of the studies focus on the contributions of the DLTs. This article aims to concentrate on the security aspect of this technology, which is often disregarded. Thus, after addressing fundamental characteristics of DLTs, it will unfold their tools and advantages in terms of compliance to information security obligations, then, exercise its vulnerabilities and related risks with respect to information security legal frameworks from over the world.
The challenge of safeguarding user data privacy becomes pronounced when private data is outsourced to cloud services, potentially exposing it to unauthorized access. The challenge of centralized storage of user data introduces heightened security risks and a dependence on a single authority, posing difficulties in safeguarding against internal breaches. This study is dedicated to advancing user privacy and data security, especially in scenarios involving the sharing of sensitive information within or across organizations, including small enterprises functioning in a distributed environment. The research introduces a consent management framework built on Blockchain technology, with a particular focus on user consent management. This framework is designed to prioritize the principles of privacy, security, scalability, and data integrity. It utilizes Hyperledger Fabric which is a permissioned distributed ledger solution, and incorporates Hyperledger Composer to establish and maintain a secure record of user data. To enhance the security of stored data, the framework incorporates the Interplanetary File System (IPFS) and employs a unique cryptographic public key encryption algorithm for data encryption. The overarching aim of this research is to establish a robust security solutions foundation against cyber threats by harnessing the inherent capabilities of blockchain technology, ultimately strengthening the security landscape for sharing user information.
Anonymity forms the basis of decentralized ecosystems, leading to an increase in criminal activities such as money laundering and illegal currency trading. Especially in blockchain-based metaverse services, activities such as preventing sexual crimes and verifying the identity of adults are becoming essential. Therefore, avatar authentication and the KYC (Know Your Customer) process have become crucial elements. This paper proposes a mechanism to achieve the KYC process by verifying user identity using smart contracts. Users obtain an SBT (Soul Bound Token) from the metaverse service provider through the DID (Decentralized Identity) credential issued during the KYC process. The identity verification of avatars occurs within smart contracts, ensuring user privacy and protection through ZKP (Zero Knowledge Proof). Tools for generating ZKP are also provided, enabling users, even those who are unfamiliar with ZKP, to use them conveniently. Additionally, an integrated wallet is offered to seamlessly manage DID credentials and SBTs. Furthermore, in case of avatar identity issues, users can request an audit by the issuer through the associated DID tokens.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
This paper provides an in-depth security and privacy analysis of the Solid protocol. Solid is a specification that allows user data to be stored decentralized in a personal online datastore (pod) independent from the application. This allows users to easily migrate to a different service and have more control over who data is shared with. We provide a comprehensive overview of the authentication, identification, and authorization protocols within Solid. We make use of the SPARTA threat modeling tool to assess the security and privacy aspects of Solid by modeling a realistic finance analytics application envisioned by the Solid community. This concrete use case allowed us to prioritize the residual threats in Solid. We employ methodologies such as STRIDE and LINDDUN for robust security and privacy threat modeling. The findings highlight the existence of several critical threats in the Solid specification. This is especially the case for privacy threats, which although it is an essential aspect of Solid, has so far not yet received enough attention, as our results indicate. These findings can be employed in future work to prioritize which residual threats to address and mitigate first.
Federated learning (FL) is a distributed learning process that uses a trusted aggregation server to allow multiple parties (or clients) to collaboratively train a machine learning model without having them share their private data. Recent research, however, has demonstrated the effectiveness of inference and poisoning attacks on FL. Mitigating both attacks simultaneously is very challenging. State-of-the-art solutions have proposed the use of poisoning defenses with Secure Multi-Party Computation (SMPC) and/or Differential Privacy (DP). However, these techniques are not efficient and fail to address the malicious intent behind the attacks, i.e., adversaries (curious servers and/or compromised clients) seek to exploit a system for monetization purposes. To overcome these limitations, we present a ledger-based FL framework known as FLEDGE that allows making parties accountable for their behavior and achieve reasonable efficiency for mitigating inference and poisoning attacks. Our solution leverages crypto-currency to increase party accountability by penalizing malicious behavior and rewarding benign conduct. We conduct an extensive evaluation on four public datasets: Reddit, MNIST, Fashion-MNIST, and CIFAR-10. Our experimental results demonstrate that (1) FLEDGE provides strong privacy guarantees for model updates without sacrificing model utility; (2) FLEDGE can successfully mitigate different poisoning attacks without degrading the performance of the global model; and (3) FLEDGE offers unique reward mechanisms to promote benign behavior during model training and/or model aggregation.
Blockchain architecture, originally designed for Bitcoin, has revolutionized finance through decentralized transactions and secured data management. It has been utilized to maintain private citizen records, allowing data owners to grant access via the blockchain for direct communication. Despite its potential, this technology remains relatively unexplored by both citizens and the public sector. By carrying out a thorough literature review, this article aims to shed light on this field. The research focus encompasses two key elements: (1) analyzing blockchain dimensions and (2) exploring its transformative impact on the public sector. The methodology involves an extensive meta-analysis of existing research on blockchain's analytical aspects and its role in reshaping public administration. Additionally, a questionnaire is administered to Information Technologies (IT) experts in public services, comparing their perceptions with established scientific studies. The research's core findings address various analysis dimensions, including regulatory risks, data management challenges, privacy concerns, and technological limitations. On the transformation front, organizations adopting blockchain technology anticipate enhanced networked services, fortified data security, operational efficiency, informed decision-making, and novel public services. The potential of blockchain to drive innovative services and safeguard data is widely acknowledged, yet organizations with blockchain are cautiously optimistic about its practical implications compared to those without.