With the continuous development of digital communication in Internet of Things(IOT) and the demand of IOT for advanced interoperability and collaboration, organizations and entities directly need to interact with data. Access control technology is the key to current data protection and system management. In this paper, we details the method framework, contract design, and execution process of the DID-based blockchain access control, and analyze for data leakage, security issues, data storage and system complexity in the current solution. In order to solve the current problems, this paper combines blockchain technology with identity access control scheme based on the application of distributed identification; Secondly, a detailed of DID mark and smart contract interaction mechanism are design. Finally, an implementation scheme is proposed on this scheme combined with the IoT scenario and is demonstrated to run in a real scenario. The usability, security and efficiency of the framework are evaluated in simulation tests and performance.
Τα τελευταία χρόνια έχει γίνει αντιληπτό ότι ο αποδοτικότερος τρόπος να εκπαιδευτεί κάποιο σύνθετο μοντέλο τεχνητής νοημοσύνης είναι η αξιοποίηση εξαιρετικά μεγάλων όγκων δεδομένων και μεγάλης υπολογιστικής ισχύος. Το γεγονός αυτό δίνει ένα ανυπέρβλητο προβάδισμα στις λίγες εταιρίες που κατέχουν αυτά τα στοιχεία, με αποτέλεσμα αυτές να τείνουν να κυριαρχήσουν στις εξελίξεις. Συνεπώς θα ήταν επιθυμητό να δημιουργήσουμε πρότυπα τα οποία: 1) Εγκαταλείπουν τη λογική των μεγάλων ιδιωτικών υπολογιστικών κέντρων. 2) Βασίζονται, όχι απλώς σε αποκεντρωμένο, αλλά σε πλήρως κατανεμημένο μοντέλο, υπό την έννοια ότι λειτουργούν δίχως την ανάγκη ενός κεντρικού συντονιστή. Ακολουθώντας αυτή την οδό μπορούν να δημιουργηθούν αρχιτεκτονικές οι οποίες: 1) Αξιοποιώντας πολυάριθμους κόμβους προσεγγίζουν (η ακόμα και ξεπερνούν) την υπολογιστική ισχύ ενός μεγάλου data center. 2) Λόγω ισοτιμίας των συμμετεχόντων δεν έχουν "single point of failure", το οποίο πρακτικά σημαίνει ότι η λειτουργία τους συνεχίζεται απρόσκοπτα ακόμα και μετά την αποσύνδεση ενός μεγάλου ποσοστού των κόμβων τους. 3) Είναι "εκδημοκρατισμένες", δηλαδή όλοι οι συμμετέχοντες έχουν ίση πρόσβαση στα παραγόμενα αποτελέσματα. Οι μέχρι τώρα υλοποιήσεις των αλγορίθμων ανάπτυξης νευρωνικών δικτύων επικεντρώνονται πρωτίστως στον τομέα της ταχύτητας εκπαίδευσης του μοντέλου. Παρόλο που έχουν αναπτυχθεί εκδοχές για κατανεμημένη επεξεργασία, αυτές έχουν ανάγκη από έναν κεντρικό κόμβο-διαχειριστή ο οποίος θα αναλαμβάνει τον συντονισμό των υπολοίπων. Δεν έχει όμως γίνει επαρκής μελέτη για μία υλοποίηση που δεν απαιτεί έναν τέτοιο διακομιστή. Η πρότασή μας αξιοποιεί νέας τεχνολογίας ομότιμες τοπολογίες που έχουν ως θεμέλιο λίθο την κρυπτογραφική επαλήθευση (Distributed Ledger Technology - DLT), με στόχο τη "διάχυση" του διαχειριστικού ρόλου σε ολόκληρο το δίκτυο. Κατά την εκπόνηση της έρευνας δοκιμάστηκαν διαφορετικές διαμορφώσεις της κατανεμημένης λειτουργίας και αποτιμήθηκαν οι επιπτώσεις που είχε αυτή η παραμετροποίηση, τόσο στην ταχύτητα εκπαίδευσης όσο και στην ποιότητα του παραγόμενου μοντέλου. Το αποτέλεσμα είναι ένα καινοτόμο οικοσύστημα νεοφυών τεχνολογιών, για εκδημοκρατισμένη εκπαίδευση βαθέων νευρωνικών δικτύων.
Byzantine consensus is a critical component in many permissioned Blockchains and distributed ledgers. We propose a new paradigm for designing BFT protocols called DQBFT that addresses three major performance and scalability challenges that plague past protocols: (i) high communication costs to reach geo-distributed agreement, (ii) uneven resource utilization hampering performance, and (iii) performance degradation under varying node and network conditions and high-contention workloads. Specifically, DQBFT divides consensus into two parts: 1) durable command replication without a global order, and 2) consistent global ordering of commands across all replicas. DQBFT achieves this by decentralizing the heavy task of replicating commands while centralizing the ordering process. Under the new paradigm, we develop a new protocol, Destiny that uses a combination of three techniques to achieve high performance and scalability: using a trusted subsystem to decrease consensus's quorum size, using threshold signatures to attain linear communication costs, reducing client communication. Our evaluations on 300-replica geo-distributed deployment reveal that DQBFT protocols achieve significant performance gains over prior art: $\approx$3x better throughput and $\approx$50\% better latency.
With the rapid development of blockchain technology, data sharing has been widely studied in academia and industry in recent years, and a series of important achievements have been made. At present, there is a security problem of data sharing in blockchain technology. Firstly, it summarizes the data security sharing. Then, the data security sharing is divided into three aspects: confidentiality, integrity and availability, and the existing challenges and corresponding solutions are analyzed. Finally, the development status and trend of data security sharing in blockchain are summarized, and the important research directions in the future are prospected.
In an oblivious transfer with access control (AC-OT) scheme, the database provider (DBP) can define different access control policies for each data record, and users are allowed to hide their choices from the DBP when accessing data. An accountable AC-OT (AAC-OT) scheme is an enhanced version of AC-OT that allows the DBP to revoke the access rights of malicious users. However, existing AAC-OT schemes have defects in their security model definition, malicious user revocation mechanism, and user-side performance. Therefore, the authors proposed an improved AAC-OT scheme that applies to the public cloud environment. In the definition of the security model, the definitions of access authorization and revocation are considered. By modifying the user tracing mechanism, the DBP can independently revoke the access rights of fraudulent users. In addition, the number of bilinear pairing operations performed by users in the transfer phase is kept constant by optimizing the generation of the underlying zero-knowledge proofs.
Secure cross-domain authorization and authentication (AA) enable application service providers (ASPs) to allow users for resource access from different trusted domains. In this article, we propose a unified blockchain-assisted secure cross-domain AA framework for smart city, which can guarantee transparent cross-domain resource access while preserving user privacy. In the framework, ASPs can flexibly delegate their authentication capabilities to the blockchain, and users authorized by different ASPs can be authenticated by the blockchain where the authentication events are publicly audited and traced. Since the blockchain is publicly accessible, users’ sensitive identity attributes may be exposed during the authentication process. To address privacy leakage caused by the authentication events, several privacy-preserving techniques, including threshold-based homomorphic encryption, zero-knowledge proof, and random permutation, are exploited to hide users’ sensitive information on the blockchain. Moreover, to improve user revocation efficiency, we integrate a cryptographic accumulator and secure hash functions into the framework where ASPs are allowed to revoke their users through a global revocation contract. Our security analysis shows that the proposed framework can achieve all desirable security and privacy properties, and a proof-of-concept prototype has been developed to demonstrate the correctness and efficiency of the proposed framework.
Visara Urovi, Vikas Jaiman, Arno Angerer, Michel Dumontier
Easy access to data is one of the main avenues to accelerate scientific research. As a key element of scientific innovations, data sharing allows the reproduction of results and helps prevent data fabrication, falsification, and misuse. Although the research benefits from data reuse are widely acknowledged, the data collections existing today are still kept in silos. Indeed, monitoring what happens to data once they have been handed to a third party is currently not feasible within the current data sharing practices. We propose a blockchain-based system to trace data collections and potentially create a more trustworthy data sharing process. In this paper, we present the LUCE (License accoUntability and CompliancE) architecture as a decentralized blockchain-based platform supporting data sharing and reuse. LUCE is designed to provide full transparency on what happens to the data after they are shared with third parties. The contributions of this work consist of i) the design of a decentralized data sharing solution with accountability and compliance by design and ii) the inclusion of a dynamic consent model for personalized data sharing preferences and for enabling legal compliance mechanisms. We test the scalability of the platform in a real-time environment where a growing number of users access and reuse different datasets. Compared to existing data sharing solutions, LUCE provides transparency over data sharing practices, enables data reuse, and supports regulatory requirements. The experimentation shows that the platform can be scaled for a large number of users.
Jinming Shi, Jun Du, Yuan Shen, Jian Wang · 6 authors
Vehicular edge computing (VEC) is an effective method to increase the computing capability of vehicles, where vehicles share their idle computing resources with each other. However, due to the high mobility of vehicles, it is challenging to design an optimal task allocation policy that adapts to the dynamic vehicular environment. Further, vehicular computation offloading often occurs between unfamiliar vehicles, how to motivate vehicles to share their computing resources while guaranteeing the reliability of resource allocation in task offloading is one main challenge. In this paper, we propose a blockchain-enabled VEC framework to ensure the reliability and efficiency of vehicle-to-vehicle (V2V) task offloading. Specifically, we develop a deep reinforcement learning (DRL)-based computation offloading scheme for the smart contract of blockchain, where task vehicles can offload part of computation-intensive tasks to neighboring vehicles. To ensure the security and reliability in task offloading, we evaluate the reliability of vehicles in resource allocation by blockchain. Moreover, we propose an enhanced consensus algorithm based on practical Byzantine fault tolerance (PBFT), and design a consensus nodes selection algorithm to improve the efficiency of consensus and motivate base stations to improve reliability in task allocation. Simulation results validate the effectiveness of our proposed scheme for blockchain-enabled VEC.
The emerging blockchain technology, combined with the smart contract paradigm, is expected to transform traditional applications with decentralization. When the blockchain technology is applied to decentralize traditional applications, blockchain validators may need to take in sensitiveoff-chaindata to execute a smart contract. On the one hand, decentralized applications (DApps) require authentic off-chain input data to correctly execute a given business procedure. On the other hand, users are reluctant to expose their sensitive privacy on the blockchain. For example, for a decentralized medical insurance DApp that takes as input personal health data, it is critical to guarantee authenticity and privacy of the data sent to the smart contract, such that the data can be verified by validators without leaking sensitive information. However, no satisfactory solution has been proposed to attain privacy and authenticity at the same time. In this work, we first present a highly efficient authenticated zero knowledge proof protocol called zk-DASNARK by extending the classical zk-SNARK scheme with data authentication. Based on zk-DASNARK, we design zk-AuthFeed, a zero-knowledge authenticated off-chain data feed scheme to achieve both data privacy and authenticity for blockchain-based DApps. Following the strategy of “compute off-chain and verify on-chain”, zk-AuthFeed can significantly reduce computation cost of blockchain validators. We fully implement a prototype of zk-AuthFeed, and conduct comprehensive experiments on a medical insurance DApp. We consider 4 typical computation models for insurance premium/reimbursement in the experiments. It shows that zk-AuthFeed is highly efficient: key generation takes about 10 seconds only, proof generation takes less than 4 seconds, and proof verification takes less than 40 ms.
Abstract Vehicular Ad Hoc Networks (VANETs) are characterized by high mobility of nodes and volatility, which make privacy, trust management, and security challenging issues in VANETs' design. In such networks, data can be exposed to a variety of attacks, the most dangerous is false information dissemination, which threatens the safety and efficiency of transportation systems. False emergency messages can be injected by inside attackers to announce fake incidents such as traffic accidents, resulting in a false information attack. As the data in VANET is based on events, any trust mechanism must first identify the true events. To address these security challenges, a blockchain‐based authentication scheme and trust management model are proposed for VANETs. Using the authentication scheme, vehicles are enabled to send messages anonymously to the roadside units (RSUs) and the identity privacy of vehicles is protected. Besides, the proposed trust management model is designed to detect and deal with false information by evaluating the trustworthiness of vehicles and data. Using the trust model, when vehicles report an incident to the nearest RSU, the RSU is able to verify whether or not the incident took place. This mechanism ensures that RSUs send only verified event notifications. Finally, RSUs participate in updating the trust values of vehicles and store these values in the blockchain. The efficiency of the proposed authentication scheme is validated through analysis while the trust model is validated through simulations. The results obtained show that the proposed authentication scheme and the trust model provide better performance than other state‐of‐the‐art models where malicious vehicles can be identified efficiently and RSUs are enabled to broadcast only legitimate events.
Health data sharing, as a booming demand, enables the patients with similar symptoms to connect with each other and doctors to obtain the medical history of patients. Health data are usually collected from edge-based Internet of medical things (IoMT) with devices such as smart wearable devices, smart watches, and smartphones. Since health data are highly private and have great financial value, adversaries ceaselessly launch diverse attacks to obtain private information. All these issues pose great challenges to health data sharing in edge-based IoMT scenarios. Existing research either lacks comprehensive consideration of privacy and security protection or fails to provide a proper incentive mechanism, which expels users from sharing data. In this study, we propose a novel blockchain-assisted data sharing scheme, which allows secure and privacy-preserving profile matching. A bloom filter with hash functions is designed to verify the authenticity of keyword ciphertext. Key-policy attribute-based encryption (KP-ABE) algorithm and smart contracts are employed to achieve secure profile matching. To incentivize users actively participating in profile matching, we devise an incentive mechanism and construct a two-phase Stackelberg game to address pricing problems for data owners and accessing problems of data requesters. The optimal pricing mechanism is specially designed for encouraging more users to participate in health data sharing and maximizing users’ profit. Moreover, security analysis illustrates that the proposed protocol is capable of satisfying various security goals, while performance evaluation shows high scalability and feasibility of the proposed scheme in edge-based IoMT scenarios.
The existing federated learning framework is based on the centralized model coordinator, which still faces serious security challenges such as device differentiated computing power, single point of failure, poor privacy, and lack of Byzantine fault tolerance. In this paper, we propose an asynchronous federated learning system based on permissioned blockchains, using permissioned blockchains as the federated learning server, which is composed of a main-blockchain and multiple sub-blockchains, with each sub-blockchain responsible for partial model parameter updates and the main-blockchain responsible for global model parameter updates. Based on this architecture, a federated learning asynchronous aggregation protocol based on permissioned blockchain is proposed that can effectively alleviate the synchronous federated learning algorithm by integrating the learned model into the blockchain and performing two-order aggregation calculations. Therefore, the overhead of synchronization problems and the reliability of shared data is also guaranteed. We conducted some simulation experiments and the experimental results showed that the proposed architecture could maintain good training performances when dealing with a small number of malicious nodes and differentiated data quality, which has good fault tolerance, and can be applied to edge computing scenarios.
As the confidentiality and scalability of smart contracts have become a crucial demand of blockchains, off-chain contract execution frameworks have been promising. Some have recently expanded off-chain contracts to Multi-Party Computation (MPC), which seek to transition the on-chain states by off-chain MPC. The most general problem among these solutions is MPT, since its off-chain MPC takes on- and off-chain inputs, delivers on- and off-chain outputs, and can be publicly verified by the blockchain, thus capable of covering more scenarios. However, existing Multi-Party Transaction (MPT) solutions lack at least one of data availability, financial fairness, delivery fairness, and delivery atomicity. These properties are crucially valued by communities, e.g., the Ethereum community, or users. Even worse, these solutions require high-cost interactions between the blockchain and off-chain systems. This paper proposes a novel MPT-enabled off-chain contract execution framework, DECLOAK. DECLOAK is the first to achieve data availability of MPT, and our method can apply to other fields that seek to persist user data on-chain. Moreover, DECLOAK solves all mentioned shortcomings with even lower gas costs and weaker assumptions. Specifically, DECLOAK tolerates all but one Byzantine party and TEE executors. Evaluating on 10 MPTs, DECLOAK reduces the gas cost of the SOTA, Cloak, by 65.6%. Consequently, we are the first to not only achieve such level secure MPT in practical assumption, but also demonstrate that evaluating MPT in the comparable gas cost to normal Ethereum transaction is possible. And the cost superiority of DECLOAK increases as the number of MPT parties grows.
Mahmoud Tayseer Al Ahmed, Fazirulhisyam Hashim, Shaiful Jahari Hashim, Azizol Abdullah
Internet of Things (IoT) networks are large peer-to-peer networks of small devices that require a competent security system that is scalable and adaptable to the limited resources of the IoT devices. Node authentication is a crucial part of IoT security. The current authentication solutions require a centralized trusted party for authentication, which presents a single point of failure. Blockchain as a peer-to-peer network with decentralized authentication can provide a decentralized solution for node authentication. In existing literature, most blockchain applications in IoT are connected to existing blockchain networks by more computationally capable devices, thereby limiting their adaptability for IoT networks and presenting single point of failure problem. Considering the issues, this paper proposes a blockchain-based decentralized structure for authentication by arranging the IoT devices into clusters based on their computational capability, energy reserve and their location. The devices in each cluster are authenticated by a hierarchical structure of interconnected blockchains. To reduce the processing load we introduced a consensus protocol based on verifying identity-based encryption key signature of the device and its related cluster. The proposed structure simulation has shown a reduction of the processor and memory load of IoT devices. Further testing using Docker container network and Raspberry Pi devices network has shown that the proposed blockchain structure and consensus algorithm have reduced computational load. The analysis of the structure security and performance shows it offers comprehensive security protection while being lightweight and scalable.
Blockchain-based federated learning (BCFL) has recently gained tremendous attention because of its advantages, such as decentralization and privacy protection of raw data. However, there has been few studies focusing on the allocation of resources for the participated devices (i.e., clients) in the BCFL system. Especially, in the BCFL framework where the FL clients are also the blockchain miners, clients have to train the local models, broadcast the trained model updates to the blockchain network, and then perform mining to generate new blocks. Since each client has a limited amount of computing resources, the problem of allocating computing resources to training and mining needs to be carefully addressed. In this paper, we design an incentive mechanism to help the model owner (MO) (i.e., the BCFL task publisher) assign each client appropriate rewards for training and mining, and then the client will determine the amount of computing power to allocate for each subtask based on these rewards using the two-stage Stackelberg game. After analyzing the utilities of the MO and clients, we transform the game model into two optimization problems, which are sequentially solved to derive the optimal strategies for both the MO and clients. Further, considering the fact that local training related information of each client may not be known by others, we extend the game model with analytical solutions to the incomplete information scenario. Extensive experimental results demonstrate the validity of our proposed schemes.
Blockchain technology, recognized for its decentralized and privacy-preserving capabilities, holds potential for enhancing privacy in contact tracing applications. Existing blockchain-based contact tracing frameworks often overlook one or more critical design details, such as the blockchain data structure, a decentralized and lightweight consensus mechanism with integrated tracing data verification, and an incentive mechanism to encourage voluntary participation in bearing blockchain costs. Moreover, the absence of framework simulations raises questions about the efficacy of these existing models. To solve above issues, this article introduces a fully third-party independent blockchain-driven contact tracing (BDCT) framework, detailed in its design. The BDCT framework features an Rivest-Shamir-Adleman (RSA) encryption-based transaction verification method (RSA-TVM), achieving over 96% accuracy in contact case recording, even with a 60% probability of individuals failing to verify contact information. Furthermore, we propose a lightweight reputation corrected delegated proof of stake (RC-DPoS) consensus mechanism, coupled with an incentive model, to ensure timely reporting of contact cases while maintaining blockchain decentralization. Additionally, a novel simulation environment for contact tracing is developed, accounting for three distinct contact scenarios with varied population density. Our results and discussions validate the effectiveness, robustness of the RSA-TVM and RC-DPoS, and the low storage demand of the BDCT framework.
The purposes are to develop the patent data profoundly, control the data access process effectively, and protect the patent information and content. The traditional patent review systems are analyzed. For the present patent data security and privacy protection technologies and algorithms, the patent information data are stored on different block nodes after data fragmentation using blockchain technology. Then the data are shared using the data encryption algorism. In this way, data access control can be restricted to particular users. Finally, a patent data protection scheme based on privacy protection is proposed. The security of the scheme and the model performance are verified through simulation experiments. The time required to encrypt 10 MB files with 64-bit and 128-bit data is 35 ms and 105 ms, respectively. The proposed re-encryption algorithm only needs 1 s to decrypt 64 KB data, and only 1% of the data needs asymmetric encryption. This greatly reduces the computational overhead of encryption. Results demonstrate that the system can effectively control the access methods of users, efficiently protect the personal privacy and patent content of patent applicants, and reduce the patent office cloud computing overhead using the local resources of branches. The distributed storage methods can reduce the cloud system interaction of the patent office, thereby greatly improving the speed of encryption and ensuring data security. Compared with the state of the art methods, the proposed patent data access and protection system based on blockchain technology have greater advantages in data security and model performance. The research results can provide a research foundation and practical value for the protection and review systems of patent data.
Nowadays, there are a plethora of services that are provided and paid for online, such as video streaming subscriptions, car-share, vehicle parking, purchasing tickets for events, etc. Online services usually issue tokens that are directly related to the identities of their users after they sign up to a platform; users need to authenticate themselves by using the same credentials each time they use the service. Likewise, when using in-person services, such as going to a concert, after paying for this service, the user usually receives a ticket, which proves that he/she has the right to use that service. In both scenarios, the main concerns surround the centralization of these systems and that they do not ensure customers’ privacy. The involved service providers are trusted third parties—authorities that offer services and handle private data about users. In this paper, we designed and implemented FORT, a decentralized system that allows customers to prove their rights to use specific services (either online or in-person) without revealing sensitive information. To achieve decentralization, we proposed a solution where all of the data are handled by a blockchain. We describe and uniquely identify users’ rights using non-fungible tokens (NFTs), and possession of these rights is demonstrated by using zero-knowledge proofs—cryptographic primitives that allow us to guarantee customers’ privacy. Furthermore, we provide benchmarks of FORT, which show that our protocol is efficient enough to be used in devices with low computing resources, such as smartphones or smartwatches, which are devices commonly used in our use case scenario.
Abdullah Lakhan, Mazin Abed Mohammed, Dheyaa Ahmed Ibrahim, Seifedine Kadry · 5 authors
The advancement in transport applications increases at the everyday progress in technologies. Therefore, intelligent transport systems (ITS) gain a lot of progress at the different vehicle levels and in the vehicular area network. However, privacy and security at the network level are critical issues for ITS applications in the existing mechanism. In this paper, the study devises the cost-efficient and secure Serverless Blockchain Enable Task Scheduling (SBETS) ITS system and algorithm framework. The main goal is to reduce processing and security blockchian costs for ITS applications in the system. The processing cost minimizes based on the new proposed function-based price model and secures the data by a suggested deep graph convolutional neural network scheme in the network. The simulation results show that SBETS outperformed all existing ITS systems and minimized processing costs by 10% and fraud detection issues by 50% for transport applications.
Fan Yang, Yanan Qiao, Mohammad Zoynul Abedin, Cheng Huang
In this article, we aim to design an architecture for privacy-preserved credit data and model sharing to guarantee the secure storage and sharing of credit information in a distributed environment. The proposed architecture optimizes the data privacy by sharing the data model instead of revealing the actual data. This article also proposes an efficient credit data storage mechanism combined with a deletable Bloom filter to guarantee a uniform consensus for the training and computation process. In addition, we propose authority control contract and credit verification contract for the secure certification of credit sharing model results under federated learning. Extensive experimental results and security analysis demonstrate that our proposed credit model sharing system based on federated learning and blockchain is of high accuracy, efficiency, as well as stability. In particular, the findings of this article could alleviate the potential credit crisis under financial pressure that assist to economic recovery after the global COVID-19 pandemic. Our approach has further boosted up the demand for efficient, secure credit models for Industry 4.0.
This letter presents a federated learning-basd data-accumulation scheme that combines drones and blockchain for remote regions where Internet of Things devices face network scarcity and potential cyber threats. The scheme contains a two-phase authentication mechanism in which requests are first validated using a cuckoo filter, followed by a timestamp nonce. Secure accumulation is achieved by validating models using a Hampel filter and loss checks. To increase the privacy of the model, differential privacy is employed before sharing. Finally, the model is stored in the blockchain after consent is obtained from mining nodes. Experiments are performed in a proper environment, and the results confirm the feasibility of the proposed scheme.
May Alhajri, Ahmad Salehi Shahraki, Carsten Rudolph
The rapid advances in fitness wearable devices are redefining privacy around interactions. Fitness wearables devices record a considerable amount of sensitive and private details about exercise, blood oxygen level, and heart rate. Privacy concerns have emerged about the interactions between an individual's raw fitness data and data analysis by the providers of fitness apps and wearable devices. This paper describes the importance of adopting and applying legal frameworks within the fitness tracker ecosystem. In this review, we describe the studies on the current privacy policies of fitness app providers, heuristically evaluate the methods for consent management by fitness providers, summarize the gaps identified in our review of these studies, and discuss potential solutions for filling the gaps identified. We have identified four main problems related to preserving the privacy of users of fitness apps: lack of system transparency, lack of privacy policy legibility, concerns regarding one-time consent, and issues of noncompliance regarding consent management. After discussing feasible solutions, we conclude by describing how blockchain is suitable for solving these privacy issues.