Abstract Online voting is gaining traction in contemporary society to reduce costs and boost voter turnout, allowing individuals to cast their ballots from anywhere with an internet connection. This innovation is cautiously met due to the inherent security risks, where a single vulnerability can lead to widespread vote manipulation. Blockchain technology has emerged as a promising solution to address these concerns and create a trustworthy electoral process. Blockchain offers a decentralized network of nodes that enhances transparency, security, and verifiability. Its distributed ledger and nonârepudiation features make it a compelling alternative to traditional electronic voting systems, ensuring the integrity of elections. To further bolster the security of online voting, we propose DemocracyGuard platform on the Ethereum blockchain, which incorporates facial recognition technology to authenticate voters. By leveraging these advancements, DemocracyGuard aims to provide a secure and resilient platform for online voting, paving the way for its broader adoption and revolutionizing the electoral landscape.
Abstract A Web3 lifeworld consists of an imaginary and a shared commons. A Web3 imaginary is shown to include most, if not all, of the following: (i) the stated goal or purpose of the community, (ii) the behavioral norms, (iii) the lore or history, and (iv) what is opposed. A typical Web3 commons is shown to involve three elements: hash (technical), bash (social) and cash (finance). When changes come in Web3, the response is enacted using an available lever from the hash, bash, cash model of decentralized organization, but the response must not be in friction with the communityâs imaginary, or it will most likely grind to a halt. Effective response to change becomes part of the Web3 lifeworldâs toolkit.
This conceptual modelling research investigates infrastructure designs supporting decentralized social media leveraging blockchain verified identities and non-fungible token (NFT) facilitated content transactions.Diagrammatic analysis following the object-oriented methodology depicts economic and software mechanisms allowing participant monetization of original posts through cryptocurrency micropayments and resale royalties.Systematic ownership protections aim to foster trust and transparency deactivated in conventional models exploiting uncompensated user data.While limitations persist in underlying platform maturity, regulatory uncertainty, and mass adoption prerequisites, envisioned participatory architectures offer renewed pathways to reconcile open exchange with personal agency and value.
Federated learning (FL) represents an advanced approach to tackling the issues linked with training machine learning (ML) models using distributed data while upholding privacy and security. It functions by enabling collaborative model training across a network of edge devices or servers, all without the need to transfer raw data. In place of sending data to a central server, which could potentially compromise privacy, federated learning empowers individual devices to conduct local training on their respective data. These updates are subsequently combined to develop an enhanced global model over multiple iteration. Additionally, as artificial intelligence (AI) becomes pervasive in novel application areas, concerns about the privacy of data and users are on the rise. This article offers an in-depth analysis of the advancements in FL, covering a wide array of topics including methodologies, applications, and challenges. By sidestepping the need to transfer raw data and instead focusing on sharing model updates or gradients, FL ensures the preservation of privacy and the efficient utilization of resources. Additionally, we investigate the diverse spectrum of application domains where FL holds significance. Instances encompass healthcare, finance, agriculture, education, Internet of Things (IoT), and industrial processes, all benefiting from the capacity of federated learning to harness data from decentralized sources without compromising data security. This article addresses complications such as model diversity, Non-IID (independent and identically distributed) data distribution, communication complexities, and security vulnerabilities. Furthermore, we discuss considerations related to regulatory compliance and ethics within the context of federated learning, particularly as data privacy regulations intensify.
Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Artificial Intelligence in Healthcare and Education
Mobile crowdsourcing aims to recruit enough workers holding mobile devices to collect data. Nevertheless, the platform will have cold start problems when the number of workers is limited. Existing studies have proposed solving this problem by propagating tasks to social networks for social recruitment. However, they neglect to verify workersâ propagation, leading to malicious workers reducing the platform's utility. Furthermore, during propagation verification, it is imperative to protect the privacy of social relationships among workers, as it can significantly influence the propagation. Therefore, this paper proposes Zero-knowledge Propagation Verification based on Social Relationship Encryption (ZPV-SRE) to improve the platform's utility. Specifically, we transform the propagation verification problem into a problem of computing the solution of the function. Then, the Zero-knowledge proof is used to prove the propagation, in which the worker's social relationship is protected through homomorphic encryption. Considering that ZPV-SRE will incur a significant time cost, we propose Trust-guided Zero-knowledge Propagation Verification based on Social Relationship Encryption (TZPV-SRE), which updates the worker's trust based on the verification results and selects suspicious workers for verification. The experimental results show ZPV-SRE improves the platform's utility as high as 104.05% over the state-of-the-art methods, while TZPV-SRE reduces time costs and ensures improvement.
Charusheela Nehete, Anish Lohiya, Meet Mulik, V. H. Patil ¡ 5 authors
Decentralized social media is a social media platform that aims to transform the social networking platforms. This solution defines development of the decentralized social media platform. Using distributed ledger technology, smart contracts, and peer-to-peer networks, a platform was built that redistributes control and data ownership to users while avoiding the risks of censorship, data leaks in day-to-day social media. Through feedback, advantages of the decentralized model were showcased like enhanced privacy, reduced content manipulation, and resistance to centralized control of user content. By placing the ownership and governance of social networks into the hands of the community,a way for a more transparent, and user-centric digital social media application is paved.
The rapid growth of increasingly pervasive smart devices with smart applications has contributed to numerous wireless security vulnerabilities in consumer electronics, which compromises the integrity of the entire network. Attacks frequently involve unauthorized access to inadequate wireless Internet of Things(IoT) based consumer electronic devices, information security lapses, and hence leakage of private and sensitive data occurs. Due to the centralized architecture of IoT networks, data security depends on the ownersâ trust in the entities. With the potential advantages of blockchain technology, a distributed ledger eliminates the limitations of centralized architecture while establishing trust, privacy, and security with assured reliability. This paper proposes a smart contract-based decentralized Selective Ring-Role-based access control framework for real-time health monitoring in consumer electronic networks. The proposed framework incorporates off-chain AI-driven anomaly detection for reduced network load and latency. The experimental results show that the proposed smart contract framework is robust in proving the security and privacy of IoT-based consumer electronic networks with improved anomaly detection over the state-of-the-art methods.
Septovan Dwi Suputra Saian, Irwan Sembiring, Daniel Manongga
The Indonesian population reached 270,20 million in 2020. Each resident is equipped with various secret identities. The COVID-19 pandemic has made all activities use technology as a basis, causing residents' identities to be stored digitally. Some applications that keep these identities experience data leaks. However, with the advent of Web3 and its emphasis on decentralization through blockchain, a new era of secure data management is possible. Blockchain, with its inherent security features, ensures that data stored is secure, difficult to damage or lose due to mutual consensus. Every transaction is recorded, making it easy to carry out the audit process. Therefore, this research will design and implement prototype dApps for secure population management, leveraging the superior security of blockchain technology. The initial stage of research is to conduct a literature study. Furthermore, it is to create designs such as system, infrastructure, and activity diagrams. Then do the development of the dApps prototype. The last is testing using OWASP ZAP and cost analysis. A dApps prototype was implemented on a blockchain. Every transaction is recorded and publicly viewable through the Etherscan platform. Other data stored on a blockchain have gone through an AES-256 encryption process with the data owner's account key so that the owner can only see the data. The results of the tests performed show that there is no high-level warning. The cost analysis results show that the most used costs are when deploying smart contracts and making new data. For further development, it is implementing permissionless blockchain and multi-accounts.
This paper explores the dynamics between value-added services, intermediary brands, and consumer privacy concerns in shaping attitudes toward blockchain-enabled consumer services. Grounded in the Antecedents-Privacy Concerns-Outcomes (APCO) framework, we develop a theoretical model that we test in three experimental studies with a total of 1613 participants, utilizing verbal scenarios featuring blockchain applications for international money transfer and hotel booking. Our research reveals that complete disintermediation via pure peer-to-peer blockchain transactions is unlikely. Consumers prefer blockchain applications offering supplementary services like call centers, password assistance, and cancellation options. As consumers become familiar with blockchain technology, privacy concerns intensify due to its distributed and immutable storage. The fears of data breaches are more pronounced when blockchain applications are offered by unknown startups as opposed to well-known Big Tech companies. However, privacy-conscious consumers also value the prospect of distancing themselves from big-data ecosystems by embracing blockchain solutions from startups. Our research extends the APCO framework by clarifying how privacy concerns, brand-based heuristics, and technological attributes interact. For managerial implications, blockchain applications necessitate re-intermediation to meet consumer preferences. Potential intermediaries, including Big Tech firms, startups, and industry incumbents, face unique challenges in developing and marketing blockchain-enabled consumer services.
In today's data-driven world, the convergence of advanced machine learning techniques with privacy concerns has prompted the development of innovative approaches to safeguard sensitive information while harnessing the power of data analytics.This research article delves into the realm of privacy-preserving machine learning algorithms, specifically focusing on methodologies that embrace the concept of local information privacy.The abstract provides a succinct overview of the key themes, methodologies, and implications elucidated within the paper.The abstract begins by contextualizing the contemporary landscape, emphasizing the proliferation of big data and the attendant privacy challenges it poses.It highlights the dichotomy between the utility of machine learning algorithms and the imperative of preserving individuals' privacy, setting the stage for exploring novel solutions.Central to the abstract is the conceptual framework of local information privacy, which forms the cornerstone of privacy-preserving machine learning algorithms discussed in the paper.The abstract delineates the theoretical foundations of this framework, elucidating how decentralized computation and differential privacy principles contribute to safeguarding sensitive data.Moving beyond theoretical underpinnings, the abstract provides insights into the methodologies employed in privacy-preserving machine learning.It outlines diverse approaches such as federated learning, secure multi-party computation, and homomorphic encryption, showcasing their utility in mitigating privacy risks while enabling collaborative model training and inference.Furthermore, the abstract underscores the practical implications of adopting privacy-preserving machine learning algorithms leveraging local information privacy.It cites examples across various sectors, including healthcare, finance, and IoT, where decentralized learning frameworks empower organizations to derive actionable insights from data while upholding privacy regulations and ethical standards.The abstract concludes by delineating potential avenues for future research and development in the field.It emphasizes the importance of scalability, efficiency, and robustness in privacy-preserving techniques, calling for interdisciplinary collaborations to address emerging challenges and navigate regulatory landscapes effectively.The abstract encapsulates the essence of the research article, providing a concise yet comprehensive overview of privacy-preserving machine learning algorithms using local information privacy.It serves as a gateway for readers to delve deeper into the nuances of the topic while highlighting its significance in addressing contemporary privacy challenges in the era of big data and advanced analytics.
Nicolas Oderbolz, Beatrix MarosvĂślgyi, Matthias Hafner
This paper examines the economic and security implications of Proof-of-Stake (POS) designs, providing a survey of POS design choices and their underlying economic principles in prominent POS-blockchains. The paper argues that POS-blockchains are essentially platforms that connect three groups of agents: users, validators, and investors. To meet the needs of these groups, blockchains must balance trade-offs between security, user adoption, and investment into the protocol. We focus on the security aspect and identify two different strategies: increasing the quality of validators (static security) vs. increasing the quantity of stakes (dynamic security). We argue that quality comes at the cost of quantity, identifying a trade-off between the two strategies when designing POS systems. We test our qualitative findings using panel analysis on collected data. The analysis indicates that enhancing the quality of the validator set through security measures like slashing and minimum staking amounts may decrease dynamic security. Further, the analysis reveals a strategic divergence among blockchains, highlighting the absence of a single, universally optimal staking design solution. The optimal design hinges upon a platform's specific objectives and its developmental stage. This research compels blockchain developers to meticulously assess the trade-offs outlined in this paper when developing their staking designs.
The rise of Web3 social ecosystems signifies the dawn of a new chapter in digital interaction, offering significant prospects for user engagement and financial advancement. Nonetheless, this progress is shadowed by potential privacy concessions, especially as these platforms frequently merge with existing Web2.0 social media accounts, amplifying data privacy risks for users. In this study, we investigate the nuanced dynamics between user engagement on Web3 social platforms and the consequent privacy concerns. We scrutinize the widespread phenomenon of fabricated activities, which encompasses the establishment of bogus accounts aimed at mimicking popularity and the deliberate distortion of social interactions by some individuals to gain financial rewards. Such deceptive maneuvers not only distort the true measure of the active user base but also amplify privacy threats for all members of the user community. We also find that, notwithstanding their attempts to limit social exposure, users remain entangled in privacy vulnerabilities. The actions of those highly engaged users, albeit often a minority group, can inadvertently breach the privacy of the larger collective. By casting light on the delicate interplay between user engagement, financial motives, and privacy issues, we offer a comprehensive examination of the intrinsic challenges and hazards present in the Web3 social milieu. We highlight the urgent need for more stringent privacy measures and ethical protocols to navigate the complex web of social exchanges and financial ambitions in the rapidly evolving Web3.
This study proposes a framework to enhance privacy in Blockchain-based Internet of Things (BIoT) systems used in the healthcare sector. The framework addresses the challenge of leveraging health data for analytics while protecting patient privacy. To achieve this, the study integrates Differential Privacy (DP) with Federated Learning (FL) to protect sensitive health data collected by IoT nodes. The proposed framework utilizes dynamic personalization and adaptive noise distribution strategies to balance privacy and data utility. Additionally, blockchain technology ensures secure and transparent aggregation and storage of model updates. Experimental results on the SVHN dataset demonstrate that the proposed framework achieves strong privacy guarantees against various attack scenarios while maintaining high accuracy in health analytics tasks. For 15 rounds of federated learning with an epsilon value of 8.0, the model obtains an accuracy of 64.50%. The blockchain integration, utilizing Ethereum, Ganache, Web3.py, and IPFS, exhibits an average transaction latency of around 6 seconds and consistent gas consumption across rounds, validating the practicality and feasibility of the proposed approach.
Tanusree Sharma, Vivek Nair, Henry Wang, Yang Wang ¡ 5 authors
Key management has long remained a difficult unsolved problem in the field of usable security. While password-based key derivation functions (PBKDFs) are widely used to solve this problem in centralized applications, their low entropy and lack of a recovery mechanism make them unsuitable for use in decentralized contexts. The multi-factor key derivation function (MFKDF) is a recently proposed cryptographic primitive that aims to address these deficiencies by incorporating commonly used authentication factors into the key derivation process. In this paper, we implement an MFKDF-based Ethereum wallet and perform a user study with 27 participants to directly compare its usability against traditional cryptocurrency wallet architectures. Our results show that MFKDF-based applications outperform conventional key management approaches on both subjective and objective metrics, with a 37% higher average SUS score (p < 0.0001) and 71% faster task completion times (p < 0.0001) for the MFKDF-based wallet.
Cryptocurrency wallets come in various forms, each with unique usability and security features. Through interviews with 24 users, we explore reasons for selecting wallets in different contexts. Participants opt for smart contract wallets to simplify key management, leveraging social interactions. However, they prefer personal devices over individuals as guardians to avoid social cybersecurity concerns in managing guardian relationships. When engaging in high-stakes or complex transactions, they often choose browser-based wallets, leveraging third-party security extensions. For simpler transactions, they prefer the convenience of mobile wallets. Many participants avoid hardware wallets due to usability issues and security concerns with respect to key recovery service provided by manufacturer and phishing attacks. Social networks play a dual role: participants seek security advice from friends, but also express security concerns in soliciting this help. We offer novel insights into how and why users adopt specific wallets. We also discuss design recommendations for future wallet technologies based on our findings.
The advent of Web3 technologies promises unprecedented levels of user control and autonomy. However, this decentralization shifts the burden of security onto the users, making it crucial to understand their security behaviors and perceptions. To address this, our study introduces a comprehensive framework that identifies four core components of user interaction within the Web3 ecosystem: blockchain infrastructures, Web3-based Decentralized Applications (DApps), online communities, and off-chain cryptocurrency platforms. We delve into the security concerns perceived by users in each of these components and analyze the mitigation strategies they employ, ranging from risk assessment and aversion to diversification and acceptance. We further discuss the landscape of both technical and human-induced security risks in the Web3 ecosystem, identify the unique security differences between Web2 and Web3, and highlight key challenges that render users vulnerable, to provide implications for security design in Web3.
Abstract The focus of this review article is on the societal problems and end user acceptance of blockchain technology. The paper begins by outlining the importance of blockchain in modernizing trust and data management systems and highlighting its rapid spread across numerous industries. Inâdepth analysis of the adoptionâinfluencing aspects is done, which also lists the advantages and typical endâuser problems. It examines the privacy implications, restrictions on pseudonymity, and function of technologies that improve privacy, such as zeroâknowledge proofs, while also exploring the legal and regulatory environment around blockchain, putting a focus on digital identity, intellectual property, and data ownership. It also evaluates blockchain security features, such as flaws and risks associated with smart contracts, discusses best practices for boosting security, discusses the societal effects of blockchain, and makes suggestions for legislators, companies, and scholars. The use of blockchain technology and its effects on privacy, rights, and security are discussed in realâworld case studies as well.
Patient care has certainly enriched by implementing digitalization in healthcare. This digital transformation has posed obstacles with data security and privacy. By the introduction of e-health, huge volumes of sensitive and classified data is digitally processed and the likelihood of numerous personal health records (PHR) rules infractions or breaches has drastically increased by implementation of digitalization. Even with the advancement in technologies, it will take due time before a system development can effectively address the security issues and give patients, who are the natural guardians of their health data a total control over their personal data. Hence, there is an urgent need for a patient-centric system that maintains data privacy and gives patients a total control over their PHR. To redefine E-Health security, the cutting-edge technologies comprising of Distributed Hash Table (DHT), Blockchain, Self-Sovereign Identity (SSI), and Inter Planetary File solution (IPFS) needs integration. IPFS and DHT enables in improving Data privacy by providing a reliable and effective decentralized and distributed storage solution. Enabling safe access control over this information, a Decentralized Ledger Technology (DLT) leverages the transparent and unchangeable characteristics of Blockchain. The idea of SSI, which gives patients control over their digital identities and to manage their E-Health data, is fundamental to this paradigm. This study advocates for the widespread implementation of patient-powered electronic health record management system. Additionally providing encouraging paths to improve data security and privacy in the domain of digital healthcare.
P. Chinnasamy, Ramesh Kumar Ayyasamy, Poovendran Alagarsundaram, S. Dhanasekaran ¡ 6 authors
In today's world, voting online is becoming increasingly popular. It has a lot of power to reduce administrative costs and increase the number of voters. Eliminates the need for ballot papers or polling stations, allowing citizens to vote anywhere via the Internet. Apart from these benefits, online voting methods are viewed with extreme caution as they pose additional risks. One mistake can easily lead to disaster. When used in elections, electronic voting systems must be legitimate, accurate, secure, and competent. However, the ability to have difficulty with computer voting methods can reduce acceptance. Blockchain technology is created to address these concerns and provides separate nodes for electronic voting. It is used to create electronic voting systems because of its ultimate verification benefits. With distributed, non-disposable features, and security protection, this technology is a great way to establish common electronic voting solutions. Blockchain is a system where each item is treated as a block, with a link that connects all these blocks, hence the name Block-Chain. Each block contains all possible data for one business, as well as a timestamp and, in exceptional cases, once. The hashing function is used to determine the hash value of all data in a block. All data blocks are accelerated with the same function. The field across all blockchain blocks contains the precedent block address. Improving security Face recognition is used. Face recognition helps to ensure that the voter is legal or not. It helps election planners identify fraudulent voters and removes them from participating in the voting process. Voting with E using the blockchain facilitates the proper distribution of votes and ensures the security of total data throughout the process. It makes the election clean and protects the vote of the affected people.
Intelligent Connected Vehicles (ICVs) need to obtain real-time traffic data from nearby ICVs or remote content providers to ensure safe driving. However, providers are hesitant to share their data due to privacy and benefits concerns. To ensure privacy while improving efficiency of obtaining data, we proposed smart contract-based data sharing among ICVs, and content delivery between ICVs and remote content provider. To solve low willingness to vehicles due to untrustworthy third-party platforms, we use smart contracts to implement access control during data upload and transaction. Then, we propose a one-to-many sharing model based on Stackelberg game to model the interaction between consumers and owners. Consumers adjust their reward strategies with the ownersâ optimal strategies to maximize its utility, thus obtaining the nash equilibrium solution. To provide reliable quality of service (QoS) and security guarantee for content delivery, smart contracts regulate the delivery process, facilitating automatic execution under specific conditions. Transaction records audited and stored on blockchain enhance transparency and trustworthiness. Utilizing a delivery utility model that considers benefits, costs, and mining profits, proposed quantum particle swarm optimization (QPSO) algorithm is used to find the optimal solution. We built an EdgeChain testbed, and used BDD-100K dataset to evaluate the performance in utility, access delay, etc. Compared to CTM and MFPA, proposed data sharing algorithm achieves maximum consumer utility. Compared to LRU, PCCM and MARL, when content is 400, proposed content delivery algorithm reduces average access delay by 30.88%, 18.92% and 4.86%, and reduce backhaul load by 50.04%, 47.23% and 3.16%.
Recently, big data related to human movement, air quality, and meteorology have been generated in urban computing through sensing technology and the computing infrastructure. However, security problems arise as data utilization increases. If the sensing data from internet of things devices are constantly exposed, the usersâ private information can be determined, a critical security risk that could result in privacy breaches. This paper proposes a secure data processing system using the blockchain and differential privacy for data security and privacy protection in urban computing. When a service provider requests information, the system generates it from urban computing data using machine learning. We apply differential privacy to these data to protect privacy. However, if a query repeats, differential privacy may provide insufficient privacy protection. Therefore, we reduce the total privacy cost by reusing noise for the same data and privacy parameters using the blockchain. Machine learning accuracy may decrease when noisy data are used for training. Thus, we increase accuracy by storing and appropriately using the model parameters generated by the same data in the blockchain. We design, simulate, and analyze the results of an experimental environment for reusing noise for differential privacy and parameter utilization of machine learning using the blockchain. The proposed approach reduces privacy costs compared to the existing mechanism while protecting data privacy. We demonstrate that, through parameter utilization, the accuracy improves compared to conventional mechanisms.
Smart contracts are algorithmic descriptions of self-executing transaction protocols, that get automatically executed, based on the information provided by the entities involved. They are written in a specialized programming language for a specific domain and must adhere to relevant legislation. In addition to being formally correct and unambiguous, smart contracts rely on the trustworthiness, safety, and security of the platform on which they are executed. One of the emerging challenges is to protect the privacy of data. Privacy preserving in smart contracts refers to the ability of a smart contract to protect the personal information of the parties involved. Ensuring the security of sensitive data within Ethereum smart contracts is crucial due to the frequent use of these contracts for facilitating exchanges or transactions of sensitive information. If proper measures are not taken to protect this data, it may be susceptible to unauthorized access or disclosure, potentially leading to detrimental outcomes for the parties involved. This literature review work embarks on a comprehensive examination of the evolving landscape of data privacy within the realm of smart contracts, transcending the intrinsic transparency that characterizes blockchain technology.