Maharshi Shah, Priyanka Kumar
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
2,533 results · page 93 of 106
Maharshi Shah, Priyanka Kumar
No abstract is available for this record.
Brandon Mendrick
Group signature schemes enable a set of members to anonymously sign data on behalf of the entire group. In order to prevent misuse, a designated group manager<br>has the ability to trace a given signature back to a member. Other extensions can also be realized in speci ffically designed schemes, such as veri fier local revocation (VLR) wherein only the verifi er needs information about the validity status of signing key pairs. This paper contributes two results towards group signature schemes. First, we present a new design for a group signature scheme that is secure under the standard<br>model, with common relaxations for anonymity. The scheme also enables VLR and allows for fully-dynamic groups; i.e. groups that allow members to both leave and join after creation. Secondly, we implement a preliminary version of the scheme to begin investigating the effi ciencies gained through utilizing one-time signing keys, instead of the traditional non-interactive, zero-knowledge proof systems.
Theodor Schnitzler, Markus Dürmuth, Christina Pöpper
No abstract is available for this record.
Imran Makhdoom, Ian Zhou, Mehran Abolhasan, Justin Lipman · 5 authors
Copyright © 2019 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved The ubiquitous use of Internet of Things (IoT) ranges from industrial control systems to e-Health, e-commerce, smart cities, supply chain management, smart cars, cyber-physical systems and a lot more. However, the data collected and processed by IoT systems especially the ones with centralized control are vulnerable to availability, integrity, and privacy threats. Hence, we present “PrivySharing,” a blockchain-based innovative framework for integrity and privacy-preserving IoT data sharing in a smart city environment. The proposed scheme is distinct from existing technologies on many aspects. The data privacy is preserved by dividing the blockchain network into various channels, where every channel processes a specific type of data such as health, smart car, smart energy or financial data. Moreover, access to user data within a channel is controlled by embedding access control rules in the smart contracts. In addition, users' data within a channel is further isolated and secured by using private data collection. Likewise, the REST API that enables clients to interact with the blockchain network has dual security in the form of an API Key and OAuth 2.0. The proposed solution also conforms to some of the significant requirements outlined in the European Union General Data Protection Regulation. Lastly, we present a system of reward in the form of a digital token “PrivyCoin” for the users for sharing their data with the stakeholders/third parties.
Shihan Bao, Yue Cao, Ao Lei, Philip Asuquo · 7 authors
Research into the established area of the intelligent transportation system is evolving into the Internet of Vehicles, a fast-moving research area, fuelled in part by rapid changes based on cyber-physical systems. It needs to be recognized that existing vehicular communication systems are susceptible to privacy vulnerabilities which require addressing. A practical challenge is that many vehicular communication applications and services make use of basic safety messages that contain the identity of the vehicle, location, and other personal data. A popular way of dealing with this privacy issue is to utilize a pseudonym change scheme to protect the vehicle's identity and location. However, many such schemes suffer that the cost grows and the certificate management difficulty raises with the number of pseudonyms generated and stored, casting doubt of the economic feasibility of that approach. We propose a decentralized blockchain-based solution for pseudonym management that overcomes these limitations. This scheme consists of pseudonym distribution and a shuffle operation, allowing the reuse of existing pseudonyms to different vehicles. The results reported here, including those from our simulations, demonstrate that the proposed scheme can reuse existing pseudonyms and achieve a better degree of anonymity at a lower cost than existing schemes.
Simon Farshid, Andreas Reitz, Peter Roßbach
Practitioners as well as academics expect that blockchain technology is a game changer for a variety of use cases. This is because of its feature of transaction immutability enabled by keeping a history of all transactions. Nevertheless, this strength can become its biggest weakness. There already exists a lively discussion on scenarios where it is necessary to delete submitted data from the chain after it is no longer needed. This becomes even more crucial with the introduction of the European General Data Protection Regulation (GDPR). In this paper we make use of a design science research (DSR) approach to design an IT artifact in form of a prototype that maintains most of the key features of blockchain technology but deletes old data. We evaluate the prototype with help of experts to investigate what to expect from blockchains that delete data and derive principles on how to design them.
Tong Sui Jun, Yong Yang, Wen Sun, Eryu Xia · 5 authors
Collection and management of clinical data for administration and analysis is a time-consuming and complex task, especially when multiple data providers been involved. Even if people are willing to take on the burden for it, there is still no mature solution to protect data privacy for distributed data providers. Distributed ledger is an emerging technology that supports decentralized data sharing and management. Based on this, we present a platform which enables distributed and truthful data collection and serves privacy-preserving needs in clinical data management. Our system, built on Hyperledger Fabric, used smart contract to execute data aggregation and provide basic analysis methods. The system used ledger and world status to record data access history and other metadata. This decentralized platform enables data providers to proactively share and protect their data, Thus can simplify clinical data collection procedure and promote efficient collaboration between providers.
Hongmin Gao, Zhaofeng Ma, Shoushan Luo, Zhen Wang
In a general secure multi-party computation (MPC) protocol, two or more participants who do not trust each other, use their respective secret inputs to calculate a joint function in a distributed environment without a centralized organization. They can get correct outputs on the premise of ensuring privacy and independence of input. In this paper, to solve the problem of fairness and robustness in MPC, a blockchain-based multi-party computation scheme (BFR-MPC) was proposed. The blockchain maintains an open reputation system for parties as a public ledger where a more reputable party has a greater chance to be selected. The block height is used as a trusted timestamp. In each round, parties must send the correct information before the deadline. In our scheme, all parties are considered to be foresighted, and an incentive mechanism encourages parties to cooperate rather than deviate from the protocol. Because of non-cooperative parties will be immediately expelled from the protocol and will be penalized financially, the proposed scheme is robust. The penalty will be used to reward honest parties. We also proved the fairness of our scheme through Game Theory. The comparison results of the proposed scheme with other schemes show that it is a more practical scheme for MPC with high fairness and robustness.
Pin Lv, Licheng Wang, Huijun Zhu, Wenbo Deng · 5 authors
In the Internet of Things (IoT), a cyber physical system (CPS) has achieved great success in a wide range of distributed integration environments. In the cyber physical system (CPS), interconnected sensing devices collect data in the surrounding environment and send data to all interested nodes through the network, thereby sharing all nodes data. This process can be implemented by using a publish/subscribe (pub/sub for short) system. Providing the basic security mechanisms such as authorization and confidentiality is a challenge due to the loose coupling of subscribers and publishers in such a pub/sub system. At the meanwhile, the existing IoT ecosystem mostly relies on a centralized server and thus faces the problem of single point failure. Thus, it is interesting to realize a brokerless or decentralized pub/sub model. Inspired by this motivation, this paper mainly proposes a privacy-preserving publish/subscribe model by using the blockchain technique, which evades the centralized trustroot setting and the problem of single point failure. Another key point of our proposal is that the primitive of public key encryption with equality test (PKEwET) is employed to enable all the required authorization, communication and topics matching can be finished in a confidential manner. Finally, a lightweight prototype of our proposal is implemented by using web3j, and the security and efficiency analysis are also presented.
Geoffroy Couteau, Michael Reichle
No abstract is available for this record.
Antonio Tenorio-Fornés, Viktor Jacynycz, David Llop-Vila, Antonio A. Sánchez‐Ruiz · 5 authors
The current processes of scientific publication and peer review raise concerns around fairness, quality, performance, cost, and accuracy. The Open Access movement has been unable to fulfill all its promises, and a few middlemen publishers can still impose policies and concentrate profits. This paper, using emerging distributed technologies such as Blockchain and IPFS, proposes a decentralized publication system for open science. The proposed system would provide (1) a distributed reviewer reputation system, (2) an Open Access by-design infrastructure, and (3) transparent governance processes. A survey is used to evaluate the problems, proposed solutions and possible adoption resistances, while a working prototype serves as a proof-of-concept. Additionally, the paper discusses the implementation, in a distributed context, of different privacy settings for both open peer review and reputation systems, introducing a novel approach supporting both anonymous and accountable reviews. The paper concludes reviewing the open challenges of this ambitious proposal.
Αλεξάνδρα Γιαννοπούλου, Valeria Ferrari
Blockchains and the GDPR pursue similar objectives where they seek to grant users greater control over their personal data. While the latter pursues this goal by imposing duties of care to centralised controllers and collectors of data, blockchains go a step beyond by trying to eliminate these stakeholders and the need to trust them. Nevertheless, the rules set out by the GDPR apply whenever personal data are at stake, and various actors of the blockchain ecosystem risk liability for controlling of processing data in violation of privacy requirements. A possible solution is to re-contextualise the concepts of data controlling and responsibility, as framed by the GDPR, in light of blockchains’ enhanced individual autonomy. In this paper, we set the framework for a further inquiry on the role of users as both data subjects and data controllers of distributed ledgers.
Yiming Wu, Shaohua Tang, Bowen Zhao, Zhiniang Peng
Task matching in crowdsourcing is designed to provide convenient task information retrieval and has been extensively explored. In general, the task matching process is required to be reliable and to meet privacy requirements. However, most existing privacy-preserving task matching solutions for crowdsourcing focus on privacy issues but ignore the reliability of the process. In this paper, we propose a blockchain-based task matching scheme for crowdsourcing with a secure and reliable matching. Instead of utilizing a centralized cloud server, we employ smart contracts, an emerging blockchain technology, to provide reliable and transparent matching. In this way, data confidentiality and identity anonymity are achieved effectively and efficiently. The extensive privacy analysis and performance evaluation show that our solution is secure and feasible.
Jiasi Weng, Jian Weng, Jilian Zhang, Ming Li · 6 authors
Deep learning can achieve higher accuracy than traditional machine learning algorithms in a variety of machine learning tasks. Recently, privacy-preserving deep learning has drawn tremendous attention from information security community, in which neither training data nor the training model is expected to be exposed. Federated learning is a popular learning mechanism, where multiple parties upload local gradients to a server and the server updates model parameters with the collected gradients. However, there are many security problems neglected in federated learning, for example, the participants may behave incorrectly in gradient collecting or parameter updating, and the server may be malicious as well. In this article, we present a distributed, secure, and fair deep learning framework named DeepChain to solve these problems. DeepChain provides a value-driven incentive mechanism based on Blockchain to force the participants to behave correctly. Meanwhile, DeepChain guarantees data privacy for each participant and provides auditability for the whole training process. We implement a prototype of DeepChain and conduct experiments on a real dataset for different settings, and the results show that our DeepChain is promising.
Ke Zhao, Shaohua Tang, Bowen Zhao, Yiming Wu
Mobile crowdsensing (MCS) is an emerging data collection paradigm that exploits the potential of individual mobile devices to acquire mass data in a cost-effective manner. One of the important challenges in MCS application is to resist malicious users who provide false data to disturb the system. In the existing work, the reputation management scheme is an effective way to overcome the challenge. However, most reputation management schemes rely on a semi-honest server and process data in the plaintext domain without considering server security and user privacy. In this paper, we integrate the blockchain and edge computing in the MCS scenario to construct a credible and efficient blockchain-based MCS system, called BC-MCS. To resist malicious users, we present a privacy-preserving reputation management scheme based on the proposed system. Furthermore, we design a delegation protocol to solve the inherent problem of user dynamics in the MCS. The prototype system implemented on the Hyperledger Sawtooth and Android client demonstrates that our scheme can achieve higher utility and security levels in handling malicious users compared with the previous centralized reputation management schemes.
Rujia Li, David Galindo, Qi Wang
Anonymity revocation is an essential component of credential issuing systems since unconditional anonymity is incompatible with pursuing and sanctioning credential misuse. However, current anonymity revocation approaches have shortcomings with respect to the auditability of the revocation process. In this paper, we propose a novel anonymity revocation approach based on privacy-preserving blockchain-based smart contracts, where the code self-execution property ensures availability and public ledger immutability provides auditability. We describe an instantiation of this approach, provide an implementation thereof and conduct a series of evaluations in terms of running time, gas cost and latency. The results show that our scheme is feasible and efficient.
Carlos Molina-Jiménez, Ioannis Sfyrakis, Linmao Song, Danny, Hazem · 5 authors
The hype about Bitcoin has overrated the potential of smart contracts deployed on-blockchains (on-chains) and underrated the potential of smart contracts deployed on-Trusted Third Parties (on-TTPs). As a result, current research and development in this field is focused mainly on smart contract applications that use on-chain smart contracts. We argue that there is a large class of smart contract applications where on-TTP smart contracts are a better alternative. The problem with on-chain smart contracts is that the fully decentralised model and indelible append-only data model followed by blockchains introduces several engineering problems that are hard to solve. In these situations, the inclusion of a TTP (assuming that the application can tolerate its inconveniences) instead of a blockchain to host the smart contract simplifies the problems and offers pragmatic solutions. The intention and contribution of this paper is to shed some light on this issue. We use a hypothetical use case of a car insurance application to illustrate technical problems that are easier to solve with on-TTP smart contracts than with on-chain smart contracts.
Wei She, Zhihao Gu, Xukang Lyu, Qi Liu · 6 authors
The relative low level of smart home system (SHS) device information security may threaten the privacy of users. In this paper, we propose a homomorphic consortium blockchain for SHS sensitive data privacy preserving (HCB-SDPP), which is based on the traditional smart home system. We add verification services, which are composed of verification nodes, to our model to verify working nodes and transactions in SHS. In order to record the SHS device information transaction, we propose a new block data structure based on homomorphic encryption (HEBDS). Using the HCB-SDPP model, we design an encrypted algorithm based on Paillier encrypted for privacy protection. To verify the validity of the HCB-SDPP model, we firstly encrypt sensitive data of all gateway peers and upload them to the consortium blockchain. Then, we validate the security of sensitive data after homomorphic encryption processing. In the experiment, we also design attack experiments to attack different types of peers on the consortium blockchain in the HCB-SDPP model. If these nodes are insecure, the influence on the whole model will be analyzed. The simulation result shows that the HCB-SDPP model can protect customer privacy more effectively than SHS.
Md. Mehedi Hassan Onik, Chul‐Soo Kim, Nam Yong Lee, Jinhong Yang
Abstract Secure data distribution is critical for data accountability. Surveillance caused privacy breaching incidents have already questioned existing personal data collection techniques. Organizations assemble a huge amount of personally identifiable information (PII) for data-driven market analysis and prediction. However, the limitation of data tracking tools restricts the detection of exact data breaching points. Blockchain technology, an ‘immutable’ distributed ledger, can be leveraged to establish a transparent data auditing platform. However, Art. 42 and Art. 25 of general data protection regulation (GDPR) demands ‘right to forget’ and ‘right to erase’ of personal information, which goes against the immutability of blockchain technology. This paper proposes a GDPR complied decentralized and trusted PII sharing and tracking scheme. Proposed blockchain based personally identifiable information management system (BcPIIMS) demonstrates data movement among GDPR entities (user, controller and processor). Considering GDPR limitations, BcPIIMS used off-the-chain data storing architecture. A prototype was created to validate the proposed architecture using multichain. The use of off-the-chain storage reduces individual block size. Additionally, private blockchain also limits personal data leaking by collecting fast approval from restricted peers. This study presents personal data sharing, deleting, modifying and tracking features to verify the privacy of proposed blockchain based personally identifiable information management system.
Martin Schanzenbach, Thomas Kilian, Julian Schütte, Christian Banse
In this paper we present ZKlaims: a system that allows users to present attribute-based credentials in a privacy-preserving way. We achieve a zero-knowledge property on the basis of Succinct Non-interactive Arguments of Knowledge (SNARKs). ZKlaims allow users to prove statements on credentials issued by trusted third parties. The credential contents are never revealed to the verifier as part of the proving process. Further, ZKlaims can be presented non-interactively, mitigating the need for interactive proofs between the user and the verifier. This allows ZKlaims to be exchanged via fully decentralized services and storages such as traditional peer-to-peer networks based on distributed hash tables (DHTs) or even blockchains. To show this, we include a performance evaluation of ZKlaims and show how it can be integrated in decentralized identity provider services.
Shangping Wang, Dan Zhang, Yaling Zhang
The sharing of personal health records can help to improve the accuracy of the doctor's diagnosis and to promote the progress of medical research. Currently, to reduce the maintenance cost of data, personal health records are usually outsourced to a third party such as the cloud service provider. In this case, patients may lose direct control over their personal health records and the semi-trusted cloud service provider may tamper with or reveal personal health records. Therefore, ensuring the privacy and integrity of personal health records and realizing the fine-grained access control are crucial issues when personal health records are shared. As a distributed architecture with decentralized and tamper-proof features, blockchain provides a new way to protect the personal health records sharing system. In this paper, we propose a new personal health records sharing scheme with data integrity verifiable based on blockchain. Aiming at the problems of privacy disclosure, limited keyword search ability and loss of control rights in the process of personal health record sharing, the new scheme uses searchable symmetric encryption and attribute-based encryption techniques to achieve privacy protection, keyword search, and fine-grained access control. Compared with the existing similar schemes, the new scheme allows patients to distribute attribute private key for users, avoiding many security problems caused by the existing of attribute authority in the scheme. Furthermore, the new scheme uses blockchain to manage keys in the scheme, avoiding the single point failure problem of centralized key management. In particular, the new scheme stores the hash values of encrypted personal health records in blockchain, and the related index set is stored in smart contract, which can further improve the efficiency of data integrity verification. Finally, performance evaluation and security analysis indicate that our scheme is secure and feasible for practical use.
Benedict Faber, Georg Cappelen Michelet, Niklas Weidmann, Raghava Rao Mukkamala · 5 authors
Recent scandals on the abuse of personal information from social media platforms and numerous user identity data breaches raise concerns about technical, commercial, and ethical aspects of privacy and security of user data. European Union’s new General Data Protection Regulation (GDPR) is one of the largest changes in data privacy regulation and entails several key regulatory measures for both data controllers and data processors to empower and protect EU citizens’ privacy. In this research work, we propose a conceptual design and high-level architecture for a Blockchain-based Personal Data and Identity Management System (BPDIMS), a human-centric and GDPR-compliant personal data and identity management system based on the blockchain technology. We describe how BPDIMS’s architecture utilizes blockchain technology to provide a high-level of security, trust and transparency. We discuss how BPDIM’s human-centric approach with GDPR compliance shifts the control over personal data to the end users and empowers them better.
Ahmed Raza Rajput, Qianmu Li, Milad Taleby Ahvanooey, Isma Masood
Personal health records (PHRs) are private and vital assets for every patient. There have been introduced many works on various aspects of managing and organizing the PHR so far. However, there is an uncertain remaining issue for the role of PHR in emergencies. In a traditional emergency access system, the patient cannot give consent to emergency staff for accessing his/her PHR. Moreover, there is no secured record management of patient's PHR, which reveals highly confidential personal information, such as what happened, when, and who has access to such information. This paper proposes an emergency access control management system (EACMS) based on permissioned blockchain hyperledger fabric and hyperledger composer. In the proposed system, we defined some rules using the smart contracts for emergency condition and time duration for the emergency access PHR data items that patient can assign some limitations for controlling the PHR permissions. We analyzed the performance of our proposed framework by implementing it through the hyperledger composer based on the response time, privacy, security, and accessibility. The experiments confirm that our framework provides better efficiency compared with the traditional emergency access system.
Ronald Doku, Danda B. Rawat
Blockchain startups are basing their business models on disrupting the centralized way of data storage by highlighting the value of data to the public. A distributed approach to storing data is the safer way to prevent attacks is what is being evangelized. GAFA (Google, Apple, Facebook, Amazon) have monopolized data, therefore bringing in the most revenue whilst depriving the data generators of any form of compensation. In our work, we propose a platform where a user can store his/her own personal data. Here, we present to the user the right to decide what happens to their data. These decisions include selling, renting, and deleting data. The deletion of data undermines the fundamentals the blockchain is built on (data immutability). We address the issues of personal data sharing and how a user's right to delete his/her data can be enforced in a blockchain based network such as ours.