Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,379 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,379 results · page 18 of 58

Clear filters
Jun 5, 2023·arXiv (Cornell University)
24 cites
deController: A Web3 Native Cyberspace Infrastructure Perspective

Hao Xu, Yunqing Sun, Zihao Li, Yao Sun · 6 authors

Web3 brings an emerging outlook for the value of decentralization, boosting the decentralized infrastructure. People can benefit from Web3, facilitated by the advances in distributed ledger technology, to read, write and own web content, services and applications more freely without revealing their real identities. Although the features and merits of Web3 have been widely discussed, the network architecture of Web3 and how to achieve complete decentralization considering law compliance in Web3 are still unclear. Here, we propose a perspective of Web3 architecture, deController, consisting of underlay and overlay network as Web3 infrastructures to underpin services and applications. The functions of underlay and overlay and their interactions are illustrated. Meanwhile, the security and privacy of Web3 are analyzed based on a novel design of three-tier identities cooperating with deController. Furthermore, the impacts of laws on privacy and cyber sovereignty to achieve Web3 are discussed.

Open access
3 source records
Peer-to-Peer Network Technologies
Privacy, Security, and Data Protection
Internet Traffic Analysis and Secure E-voting
Original source
Jun 1, 2023·IEEE Transactions on Computational Biology and Bioinformatics
12 cites
Blockchain-Based Data Access Security Solutions for Medical Wearables

Hui Lin, Quanwen He, Jia Hu, Xiaoding Wang

Digital healthcare services have become an integral part of our lives. There is an increasing number of healthcare professionals and patients using medical wearables for diagnosis and treatment, which simplifies and improves the diagnostic and therapeutic process. However, inappropriate use of medical data may result in the disclosure of private patient information. For protecting patients' privacy when using medical wearables, we propose a new blockchain-based data access security scheme. Specifically, the elliptic curve encryption algorithm and zero-knowledge authentication method are used to authenticate the identity of patients and doctors in the blockchain network. Furthermore, we develop a smart recommendation method based on deep reinforcement learning to recommend appropriate doctors for patients. Next, patients allow recommended doctors to access their medical data, and smart contracts specifically designed for secure data access to medical wearables will regulate subsequent data access. The security analysis and experimental results demonstrate that the proposed scheme can effectively protect patients' privacy during treatment through secure authentication and data access for medical wearables.

Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Jun 1, 2023·Computers & Electrical Engineering
33 cites
GDPR compliance verification through a user-centric blockchain approach in multi-cloud environment

Haris Ahmad, Gagangeet Singh Aujla

With cloud-hosted web applications becoming ubiquitous, the security risks presented for user personal data that is migrated to the cloud are at an all-time high. When using a cloud-hosted web application, users only ever interact with web interfaces of the web applications and are usually completely unaware of how their data is distributed amongst the multiple cloud service providers that the web application uses, making it difficult to verify the lawful use and ownership of personal data. The General Data Protection Regulation (GDPR) seeks to empower users to gain better control over their personal data. Blockchain-based approaches have risen in popularity over the recent years to tackle the challenge of verifying GDPR compliance in multi-cloud environments. By deploying smart contracts on the blockchain, we can create transparent and immutable logs of data processes in the hopes of automating GDPR compliance verification. However, the existing works are still limited to provide a user-centric compliance verification. To this end, we propose a user-centric, blockchain-based framework for data management in a cloud environment where all GDPR-relevant data operations take place on the blockchain through well-defined smart contracts.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Jun 1, 2023·International Journal of Scientific Research in Science Engineering and Technology
2 cites
Blockchain Based Electronic Voting System

N Jeenath Laila, M. Sathya, Sathya M Mariappan

In today’s digital environment, the voting system has moved from paper based to a digital system. A digital e-voting system has many properties such as transparency, decentralization, irreversibility, and non-repudiation. The growth in the digital e-voting system raises many security and transparency issues. In this paper, we used the blockchain technology in the digital electronic voting system to solve the security issues and ful?ll the system requirements. It offers new opportunities to deploy a secure e-voting system in any organization or country. The solution is far better as compared to other solutions because it is a decentralized system, containing the results in the form of bit-coins, having different locations. We will also analyze the security of our proposed voting system, which shows our protocol is more secure as compared to other solutions. The paper proposes a novel electronic voting system based on block chain that addresses some of the limitations in existing systems and evaluates some of the popular blockchain frameworks for the purpose of constructing a blockchain based e-voting system. In particular, we evaluate the potential of distributed ledger technologies through the description of a case study namely, the process of an election, and the implementation of a blockchain based application, which improves the security and decreases the cost of hosting a nation wide election.

Open access
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Jun 1, 2023·2023 IEEE International Conference on Metaverse Computing, Networking and Applications (MetaCom)
5 cites
An Implementation and Analysis of Zero Knowledge Based E-Voting Solution With Proof of Vote on Public Ethereum Blockchain

Roshan Singh, Sukumar Nandi, Sunit Kumar Nandi

Transparent e-voting is one of the applications that the turing complete public blockchain aspires to deliver by assuring verifiable votes. Public blockchains are much transparent, secure and have better auditing. In Blockchain based e-voting a voter identity is established with his account, whereas one account can cast a vote which leaves scope for user identity binding based on other activities on the blockchain. In this work we propose a privacy preserving and anonymous e-voting approach on the public blockchain. We introduce the concept of Proof of Vote.

Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Jun 1, 2023·2023 IEEE International Conference on Metaverse Computing, Networking and Applications (MetaCom)
7 cites
An Analysis of Zero-knowledge Proof-based Privacy-preserving Techniques for Non-fungible Tokens in the Metaverse

Dorottya Zelenyanszki, Zhé Hóu, Kamanashis Biswas, Vallipuram Muthukkumarasamy

Non-fungible tokens (NFTs) have huge potential to be included in metaverse-related applications such as digital ownership management and asset trading. However, existing research identified that privacy-preserving techniques and methods are essential for NFTs for large-scale adoption in the metaverse. This paper conducted an analysis of several existing research works that mainly use zero-knowledge proofs (ZKPs) and/or commitments to protect privacy for blockchain applications. Based on the results of this comparative analysis, we deducted several assumptions. This paper identifies the potential next steps to design new privacy-preserving techniques that will enable privacy-aware metaverse users to leverage the maximal benefits of the NFTs.

Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Ethics and Social Impacts of AI
Original source
Jun 1, 2023·2023 IEEE International Conference on Metaverse Computing, Networking and Applications (MetaCom)
13 cites
A Blockchain-based Authentication Protocol for Metaverse Environments using a Zero Knowledge Proof

Awaneesh Kumar Yadav, An Braeken, Mika Ylianttila, Madhusanka Liyanage

The metaverse, which consists of several universes called verses, is predicted to be the Internet of the future. Recently, this idea has received a lot of discussions, but not enough attention has been paid to the security concerns of these virtual worlds. Primarily when the user and platform server communicate with each other and share sensitive information using the public channel, any attacker can capture the message and can perform various types of attacks such as privacy attack, violation of perfect forward secrecy, impersonation attack, ephemeral secret leakage attack and traceability attack. Therefore, there is impelling need to design an authentication protocol for the metaverse environment that can secure the communication between the user and the platform server. Taking this into account, we designed a zero-knowledge proof authentication protocol based on blockchain for the metaverse environment. The security of the designed protocol is verified through the Burrows-Abadi-Needham (BAN) logic, Scyther tool, and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The outcome of the security verification demonstrates that the designed metaverse authentication protocol mitigates all the attacks mentioned above. Moreover, we evaluated the performance of the designed metaverse authentication protocol in terms of computational, communication, storage costs, and energy consumption and compared it with existing metaverse authentication protocols, showing good results taking into account the additional security strength.

Open access
2 source records
User Authentication and Security Systems
Advanced Authentication Protocols Security
Privacy, Security, and Data Protection
Original source
May 31, 2023·International Journal of Law and Management
20 cites
Assessing the viability of blockchain technology for enhancing court operations

Dinesh Kumar, Sunil Kumar, Akashdeep Joshi

Purpose The purpose of this paper is to provide an extensive examination and analysis of the current literature on the use of blockchain technology in courts. The paper aims to explore the potential benefits of implementing blockchain technology in courts, such as increasing transparency and accountability, improving the efficiency of court procedures and enhancing the security of court records. Additionally, the paper intends to identify the challenges and limitations of using blockchain technology in courts and propose potential solutions to overcome these obstacles. The ultimate goal is to provide a comprehensive understanding of the potential applications and implications of blockchain technology in the context of the court system. Design/methodology/approach The research design of this study is qualitative, involving a thorough examination and analysis of existing literature on the use of blockchain technology in courts. The data collection procedure involves gathering information from various sources, such as academic publications, official reports and other relevant records. Data analysis is conducted using a thematic analysis approach, which identifies and categorizes recurring themes that emerge from the data. This approach ensures that the results are credible, dependable and accurate representations of the experiences of the participants. By using these methodologies, the study is able to draw meaningful conclusions and insights into the use of blockchain technology in courts. Findings The major findings of this paper suggest that the implementation of blockchain technology in courts has the potential to bring significant benefits such as increased transparency, efficiency and security. The use of blockchain technology in courts can enable the creation of tamper-proof records that are immutable, secure and transparent, which can help prevent fraud, reduce costs and enhance trust in the judicial system. However, adopting this technology also poses challenges and limitations, such as interoperability, governance and scalability. Overall, the paper concludes that while there are challenges to be addressed, the benefits of blockchain technology in courts are significant and should be explored further. Research limitations/implications The study has several limitations that need to be taken into account. Firstly, the availability of data on blockchain implementation in the court system is limited, making it challenging to provide a comprehensive analysis of the topic. Thus, the study’s findings may not be generalizable to other contexts. Secondly, the study takes a technology-centric approach and does not consider blockchain technology’s social and legal implications in court operations. Thirdly, the case studies presented in this paper are limited to a few countries. Moreover, the implementation of blockchain technology in the court system is still in its early stages and lacks standardization, technical expertise and regulatory frameworks. Lastly, uncertainty around the legal framework may hinder its widespread adoption and use. Practical implications The practical implications of this study suggest that the use of blockchain technology in courts has the potential to improve efficiency, security, transparency and accountability in the court system. It can reduce the risk of data tampering, expedite case resolution and lower the cost of legal proceedings. Therefore, this study provides a framework for courts to consider blockchain technology’s potential benefits and explore its future adoption. Social implications The social implications of this study are significant, as the adoption of blockchain technology in the court system can have a profound impact on society. Firstly, by increasing transparency and accountability, blockchain technology can promote public trust in the court system and improve access to justice, particularly for disadvantaged communities (Liu et al. , 2020). Secondly, blockchain technology can reduce the reliance on intermediaries, such as lawyers, and streamline the case management process, making legal services more accessible and affordable for the general public (Khurana, 2020). Finally, the use of blockchain technology can create a more secure and efficient court system, enhancing the overall effectiveness of the judicial system and promoting public confidence. Originality/value This study provides an original contribution to the literature by exploring the use of blockchain technology in courts from a qualitative research design perspective. While there are a growing number of studies on the potential applications of blockchain technology in various fields, this study provides a comprehensive examination of the current literature on the use of blockchain in courts, identifying the benefits and limitations of its implementation. The study’s focus on the strengths and limitations of blockchain technology and its implications in court adds to the originality of this research.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Privacy, Security, and Data Protection
Original source
May 31, 2023·Future Internet
31 cites
Federated Learning and Blockchain Integration for Privacy Protection in the Internet of Things: Challenges and Solutions

Muneerah Al Asqah, Tarek Moulahi

The Internet of Things (IoT) compromises multiple devices connected via a network to perform numerous activities. The large amounts of raw user data handled by IoT operations have driven researchers and developers to provide guards against any malicious threats. Blockchain is a technology that can give connected nodes means of security, transparency, and distribution. IoT devices could guarantee data centralization and availability with shared ledger technology. Federated learning (FL) is a new type of decentralized machine learning (DML) where clients collaborate to train a model and share it privately with an aggregator node. The integration of Blockchain and FL enabled researchers to apply numerous techniques to hide the shared training parameters and protect their privacy. This study explores the application of this integration in different IoT environments, collectively referred to as the Internet of X (IoX). In this paper, we present a state-of-the-art review of federated learning and Blockchain and how they have been used in collaboration in the IoT ecosystem. We also review the existing security and privacy challenges that face the integration of federated learning and Blockchain in the distributed IoT environment. Furthermore, we discuss existing solutions for security and privacy by categorizing them based on the nature of the privacy-preservation mechanism. We believe that our paper will serve as a key reference for researchers interested in improving solutions based on mixing Blockchain and federated learning in the IoT environment while preserving privacy.

Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
May 29, 2023·2023 IEEE International Workshop on Metrology for Living Environment (MetroLivEnv)
1 cites
A tool for the data notarization with the Blockchain to ensure security and privacy

A. Rossi, Andrea Natalini, Lorenzo Cristofori, Marzia Mammina

This paper will describe a trustworthy blockchain-based framework to ensure secure, immutable and pseudo anonymized data collection at field level. This paper will describe the context in which the framework is being conceived and developed, starting from the analysis of the state of the art of DLT (Distributed Ledger Technology) and Blockchain, to highlight the potential uses cases in terms of data management, in particular. A specific focus will be given to the FIWARE framework, since the final objective is the creation of a tool for data gathering, as a FIWARE context broker extension. The core of the tool will be the two smart contracts implementing the PoE (Proof of Existence) and the RT-MDN (Reat Time-Monitoring Data Notarization). The smart contracts will be used for the certification of single documents and bulk of monitoring data, respectively. The second case is characterized by a periodicity of production and represent the most innovative part of the work. A first PoC (Proof of Concept) will be implemented, and first early results will be presented as well. The work is being developed in the framework of the EU co-funded “DigiBUILD” project.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
May 25, 2023·IEEE Transactions on Services Computing
37 cites
ChainDiscipline - Towards a Blockchain-IoT-Based Self-Sovereign Identity Management Framework

M. Popa, Sebastian Michael Stoklossa, Somnath Mazumdar

In today's complex Internet platform, online users need help to protect their online identity. Only sometimes, websites are very transparent about how user data will be collected, stored and processed by them. Sometimes Internet entities collect more online user information than required. These entities often share user identity-related data with third parties without consent. Existing traditional identity schemes need to be improved to stop and counter new ways of digital identity theft and fraud. Blockchain is a promising technology to strengthen the preservation of online users’ digital identity due to its decentralised nature and robust data security features. In this paper, we proposed and implemented a generic blockchain-IoT-based self-sovereign identity management framework called ChainDiscipline. We have demonstrated the framework's operability and functionality by implementing healthcare and smart home data management-based use cases.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Cryptography and Data Security
Original source
May 17, 2023·IEEE Transactions on Dependable and Secure Computing
63 cites
A Privacy-Preserving and Reputation-Based Truth Discovery Framework in Mobile Crowdsensing

Yudan Cheng, Jianfeng Ma, Zhiquan Liu, Zhetao Li · 7 authors

In mobile crowdsensing (MCS), truth discovery (TD) plays an important role in sensing task completion. Most of the existing studies focus on the privacy preservation of mobile users, and the reliability of mobile users is evaluated by their weights which are calculated based on the submitted sensing data. However, if mobile users are unreliable, the submitted sensing data and their weights are also unreliable, which may influence the accuracy of the ground truths of sensing tasks. Therefore, this article proposes a privacy-preserving and reputation-based truth discovery framework named PRTD which can generate the ground truths of sensing tasks with high accuracy while preserving privacy. Specifically, we first preserve sensing data privacy, weight privacy, and reputation value privacy by utilizing the Paillier algorithm and Pedersen commitment. Then, to verify whether the reputation values of mobile users are tampered with and select mobile users that satisfy the corresponding reputation requirements, we design a privacy-preserving reputation verification algorithm based on reputation commitment and zero-knowledge proof and propose a concept of reliability level to select mobile users. Finally, a general TD algorithm with reliability level is presented to improve the accuracy of the ground truths of sensing tasks. Moreover, theoretical analysis and performance evaluation are conducted, and the evaluation results demonstrate that the PRTD framework outperforms the existing TD frameworks in several evaluation metrics in the synthetic dataset and real-world dataset.

Mobile Crowdsensing and Crowdsourcing
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
May 17, 2023·International Journal on Recent and Innovation Trends in Computing and Communication
7 cites
Web3 Chain Authentication and Authorization Security Standard (CAA)

Nilesh P. Sable, Rahul Ganpatrao Sonkamble, Vijay U. Rathod, Swati Shirke · 6 authors

Web3 is the next evolution of the internet, which uses blockchains, cryptocurrencies, and NFTs to return ownership and authority to the consumers. The potential of Web3 is highlighted by the creation of decentralized applications (dApps), which are more secure, transparent, and tamper-proof than their centralized counterparts, allowing for new business models that were previously impossible on the traditional internet.Web3 also focuses on user privacy, where users have more control over their personal data and can choose to share only what they want. The emergence of Web3 represents an exciting new frontier in blockchain technology, and its focus on decentralization, user privacy, and trustless systems has the potential to transform the way we interact with the internet.Web3 authentication is required for enhanced security, increased privacy, and simplified user interface. Traditional login procedures and an authorization flow using web3 authentication work together seamlessly. However, there are several challenges associated with Web3, including scalability and regulatory issues. Chain Authentication and Authorization (CAA) is a multi-layer security mechanism that allows users to choose the security layer that suits them, just like a heavy iron chain, where the user and CAA developers act as blacksmith and form their security protocol that suits them. CAA is a solution to the challenges associated with Web3 authentication and authorization, and it focuses on creating a secure and decentralized authentication and authorization system that is scalable, flexible, and user-friendly.

Open access
Privacy, Security, and Data Protection
Spam and Phishing Detection
Access Control and Trust
Original source
May 9, 2023·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Bitcoin - Wie Social Media Privatanlegende in ihrem Handeln beeinflussen

Thierry Berger, Bernhard Schneider

Bitcoin ist, plakativ ausgedrückt, digitales Gold: Das Angebot ist fixiert und somit das härtere monetäre Gut als klassische Fiatwährungen. Der Wert gegenüber dem USD stieg zwischen 2011 und 2021 um durchschnittlich 230 % pro Jahr, was es zur erfolgreichsten Anlageklasse der Welt macht. Erfolg zieht Privatinvestorinnen und -investoren an. Diese informieren sich oftmals über Social-Media-Kanäle wie Twitter über Trends und lassen sich vom herrschenden Sentiment beeinflussen. Die Eintrittsbarrieren sind tief. Jeder hat schnell ein Bitcoin-Wallet erstellt und ist Teil der Bewegung. Wenn ein Preis ohne fundamentale Ursache stark steigt, erhöht sich dadurch der ebenfalls nicht fundamental bedingte Spielraum nach unten. Die hohe Volatilität ist ein Merkmal des noch jungen Marktes. Die Mehrheit der Privatinvestorinnen und -investoren kann mit diesem Druck nicht umgehen. Viele verlassen den Markt bereits nach wenigen Wochen oder Monaten in Panik, wenn ein satter Verlust anstelle eines hohen Gewinns eingetreten ist, um das übriggebliebene Investment vor einem Totalverlust in Sicherheit zu bringen. Mithilfe von Fachpersoneninterviews werden in der vorliegenden Arbeit theoretische Aspekte mit Erfahrungen aus der Praxis ergänzt, um einen ganzheitlichen Blick auf die Wechselwirkung des Verhaltens von Markt und Privatanlegenden zu erhalten. Indem verlässliche Twitter-Accounts mit Mehrwert gesucht werden, sich nicht auf eine einzige Informationsquelle verlassen sowie eine klare und langfristige Strategie verfolgt wird und das Investment auf fundierten Kenntnissen gründet, kann eine Neuinvestition in diesem Markt bestehen, denn der Markt geht mittel- und langfristig nach oben.

Open access
Digitalization, Law, and Regulation
Digital Innovation in Industries
Privacy, Security, and Data Protection
Original source
May 4, 2023·Alexandria Engineering Journal
63 cites
An efficient privacy-preserving control mechanism based on blockchain for E-health applications

Hanan Alsuqaih, Walaa Hamdan, Haythem Elmessiry, Hussein Abulkasim

The development of the Internet of Things (IoT) has opened up new horizons in the field of remote health data analysis to obtain smart healthcare. However, protecting patients’ data privacy seems challenging because medical files are so sensitive. There are significant risks to data confidentiality associated with storing patient health information on third-party servers. The covid-19 epidemic also enhanced the need for a temperature sensor-based respiratory monitoring device. Sharing electronic health records can aid with diagnostic accuracy when privacy and security protection are important system challenges. Due to the benefits of immutability, blockchain has been suggested as a possible option to enable personal health data exchange with privacy and security protection. This work suggests a safe and privacy-preserving diagnostic enhancement strategy for e-Health platforms based on blockchain technology, which addresses the inadequacy of previous work in these regards. The proposed work proposes an effective access control system that would let data owners specify their preferred access controls over their privacy-sensitive medical data. Users could utilize their user transactions for key generation to efficiently cancel or add authorized doctors. Experimental data and security analyses demonstrate the proposed Health-chain's suitability for use in smart healthcare systems. The thorough experimental investigation demonstrates the blockchain's effectiveness of computing and time consumption as well as its resistance to numerous security assaults.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Privacy, Security, and Data Protection
Original source
May 1, 2023·arXiv (Cornell University)
14 cites
Exploring the Privacy Concerns in Permissionless Blockchain Networks and Potential Solutions

Talgar Bayan, Richard Banach

In recent years, permissionless blockchains have gained significant attention for their ability to secure and provide transparency in transactions. The development of blockchain technology has shifted from cryptocurrency to decentralized finance, benefiting millions of unbanked individuals, and serving as the foundation of Web3, which aims to provide the next generation of the internet with data ownership for users. The rise of NFTs has also helped artists and creative workers to protect their intellectual property and reap the benefits of their work. However, privacy risks associated with permissionless blockchains have become a major concern for individuals and institutions. The role of blockchain in the transition from Web2 to Web3 is crucial, as it is rapidly evolving. As more individuals, institutions, and organizations adopt this technology, it becomes increasingly important to closely monitor the new risks associated with permissionless blockchains and provide updated solutions to mitigate them. This paper endeavors to examine the privacy risks inherent in permissionless blockchains, including Remote Procedure Call (RPC) issues, Ethereum Name Service (ENS), miner extractable value (MEV) bots, on-chain data analysis, data breaches, transaction linking, transaction metadata, and others. The existing solutions to these privacy risks, such as zero-knowledge proofs, ring signatures, Hyperledger Fabric, and stealth addresses, shall be analyzed. Finally, suggestions for the future improvement of privacy solutions in the permissionless blockchain space shall be put forward.

Open access
3 source records
cs.CR
cs.SE
Blockchain Technology Applications and Security
Original source
Apr 28, 2023·2023 11th International Conference on Emerging Trends in Engineering & Technology - Signal and Information Processing (ICETET - SIP)
5 cites
An Approach Towards Decentralized E-Voting

Chandu Vaidya, Chinmay Kirnapure, Jitesh Rithe, Devashish Sonkusare · 6 authors

Voting is an essential component of democratic regimes because it allows every member of a community to express their opinions. Voter turnout has decreased recently, while worries about the reliability, security, and accessibility of the current voting technologies have grown. Voting was introduced to address those concerns, however, it still requires full supervision by a central authority. The blockchain is an emerging, decentralized, and distributed technology. A shared, distributed record of all finished transactions or digital activities between all parties involved. Each vote is viewed as a separate transaction in this instance. We store voting transactions on a private blockchain that is built using a peer-to-peer network. Voting specifics are abstracted from the user by programming of this application. While system is running, users will have adequate time to cast their votes. This study is about (decentralized voting system) that protects voters privacy while maintaining transparency and security. The system has three implementation layers: a user interface for voters to register and vote a smart contract and MetaMask wallet for automatic vote transactions on the Ethereum blockchain, and an administrator function for managing the election. The smart contract is programmed to check for registration and validity, and once deployed on the blockchain, it cannot be tampered with. The administrator adds candidate information and manages the election.

Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy, Security, and Data Protection
Original source
Apr 26, 2023·Proceedings of the ACM Web Conference 2023
14 cites
Bad Apples: Understanding the Centralized Security Risks in Decentralized Ecosystems

Kailun Yan, Jilian Zhang, Xiangyu Liu, Wenrui Diao · 5 authors

The blockchain-powered decentralized applications and systems have been widely deployed in recent years. The decentralization feature promises users anonymity, security, and non-censorship, which is especially welcomed in the areas of decentralized finance and digital assets. From the perspective of most common users, a decentralized ecosystem means every service follows the principle of decentralization. However, we find that the services in a decentralized ecosystem still may contain centralized components or scenarios, like third-party SDKs and privileged operations, which violate the promise of decentralization and may cause a series of centralized security risks. In this work, we systematically study the centralized security risks existing in decentralized ecosystems. Specifically, we identify seven centralized security risks in the deployment of two typical decentralized services – crypto wallets and DApps, such as anonymity loss and overpowered owner. Also, to measure these risks in the wild, we designed an automated detection tool called Naga and carried out large-scale experiments. Based on the measurement of 28 Ethereum crypto wallets (Android version) and 110,506 on-chain smart contracts, the result shows that the centralized security risks are widespread. Up to 96.4% of wallets and 83.5% of contracts exist at least one security risk, including 260 well-known tokens with a total market cap of over $98 billion.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Spam and Phishing Detection
Original source
Apr 20, 2023·Distributed Ledger Technologies Research and Practice
8 cites
Decentralized Inverse Transparency With Blockchain

Valentin Zieglmeier, Gabriel Loyola Daiqui, Alexander Pretschner

Employee data can be used to facilitate work, but their misusage may pose risks for individuals. Inverse transparency therefore aims to track all usages of personal data, allowing individuals to monitor them to ensure accountability for potential misusage. This necessitates a trusted log to establish an agreed-upon and non-repudiable timeline of events. The unique properties of blockchain facilitate this by providing immutability and availability. For power asymmetric environments such as the workplace, permissionless blockchain is especially beneficial as no trusted third party is required. Yet, two issues remain: (1) In a decentralized environment, no arbiter can facilitate and attest to data exchanges. Simple peer-to-peer sharing of data, conversely, lacks the required non-repudiation. (2) With data governed by privacy legislation such as the GDPR, the core advantage of immutability becomes a liability. After a rightful request, an individual's personal data need to be rectified or deleted, which is impossible in an immutable blockchain. To solve these issues, we present Kovacs, a decentralized data exchange and usage logging system for inverse transparency built on blockchain. Its new-usage protocol ensures non-repudiation, and therefore accountability, for inverse transparency. Its one-time pseudonym generation algorithm guarantees unlinkability and enables proof of ownership, which allows data subjects to exercise their legal rights regarding their personal data. With our implementation, we show the viability of our solution. The decentralized communication impacts performance and scalability, but exchange duration and storage size are still reasonable. More importantly, the provided information security meets high requirements. We conclude that Kovacs realizes decentralized inverse transparency through secure and GDPR-compliant use of permissionless blockchain.

Open access
2 source records
cs.CR
cs.DC
Blockchain Technology Applications and Security
Original source
Apr 18, 2023·Universidad Politecnica de Madrid - University Library
1 cites
Decentralized Systems for the Protection and Portability of Personal Data

Mirko Zichichi

The transformation introduced by information communication technologies in the last decades significantly impacts the economy and society concerning the digital representation of one’s identity. The economics of exploiting personal information is assisted by the more pervasive nature of today’s digital world: data are at the center of this transformation, and individuals are the primary sources of information and the ones most affected by it. The General Data Protection Regulation (GDPR) is having a significant impact on the protection of personal data. It has been designed for European Union (EU) citizens to help promote a view in favor of the interests of individuals instead of large corporations. However, at a large scale, there need to be more dedicated technologies that can help companies comply with GDPR (and similar regulations) while enabling people to exercise their rights. We argue that such a dedicated solution must address two main issues: the need for more transparency towards individuals regarding the management of their personal information and their often hindered ability to access and make interoperable personal data in a way that the exercise of one’s rights would result in straightforward and not excessively burdensome. In this work, we make the first step toward these two objectives by designing a user-centered model for managing personal data, where storage is decoupled from the data management logic. We aim to provide a system that helps to push personal data management towards the individual’s control, i.e., a personal information management system (PIMS). By using distributed storage and decentralized computing networks to control online services, users’ personal information could be shifted towards those directly concerned, i.e., the data subjects. The use of Distributed Ledger Technologies (DLTs) and Decentralized File Storage (DFS) as an implementation of decentralized systems is of paramount importance in this case. The structure of this dissertation follows an incremental approach to describing a set of decentralized systems and models that revolves around personal data and their subjects. Each chapter of this dissertation builds up the previous one and discusses the technical implementation of a system and its relation with the corresponding regulations. Indeed, most of the time, implementations based on decentralized systems clash with laws such as GDPR. We refer to the EU regulatory framework, including GDPR, eIDAS, and Data Governance Act, to build our final system architecture’s functional and non-functional drivers. In our PIMS design, personal data is kept in a Personal Data Space (PDS) consisting of encrypted personal data referring to the subject stored in a DFS.We use a decentralized indexing system to guarantee the integrity, verifiability, linkability, searchability, and indexing of the encrypted personal data stored in the PDS. We follow the approach to reference data and their content on a DLT, i.e., on-chain hash pointers. Then, we associate to such hash pointer reference a keyword set that is exploited to lookup for specific kinds of contents. On top of that, a network of authorization servers acts as a data intermediary to provide access to potential data recipients. Access to the data stored on a PDS can be allowed by the data holder through smart contracts. These maintain a data structure to record eligible data recipients, i.e., those to whom to issue the keys needed to access the encrypted data. Also, in this case, the GDPR tensions with DLTs drove the architecture to be multi-DLT. Authorization servers use a “tightly controlled” permissioned DLT to handle personal data, while a permissionless “audit” DLT is used for system security and only holds non-personal data. After describing the design of a decentralized PIMS, we focus on enriching the expressiveness of the access control mechanism through privacy policies. These let data subjects and/or holders express privacy policies aligned with the GDPR legal bases to be enforced through smart contracts. We use a set of Semantic Web technologies and standards for this aim. Finally, we present a Self-Sovereign Identity (SSI) model for providing, requesting, and obtaining qualified data to negotiate and/or execute electronic transactions with a focus on the legal and operational context. RESUMEN La transformación introducida por las tecnologías de la información y las comunicaciones en las últimas décadas repercute signifcativamente en la economía y la sociedad en lo que respecta a la representación digital de la identidad personal. La explotación económica de la información personal se ve favorecida por la naturaleza omnipresente del mundo digital actual: los datos están en el centro de esta transformación, y los individuos son las principales fuentes de información y los más afectados por ella. El Reglamento General de Protección de Datos (RGPD) está teniendo un impacto signifcativo en la protección de los datos personales. Ha sido diseñado para los ciudadanos de la Unión Europea (UE) con el f n de ayudar a promover una visión a favor de los intereses de los individuos en lugar de las grandes corporaciones. Sin embargo, a gran escala, es necesario que existan más tecnologías dedicadas que puedan ayudar a las empresas a cumplir con el RGPD (y reglamentos similares) al tiempo que permiten a las personas ejercer sus derechos. Sostenemos que una solución específca de este tipo debe abordar dos cuestiones principales: la necesidad de una mayor transparencia hacia las personas en lo que respecta a la gestión de su información personal y su capacidad, a menudo obstaculizada, de acceder a los datos personales y hacerlos interoperables de forma que el ejercicio de los derechos propios resulte sencillo y no excesivamente oneroso. En este trabajo, damos el primer paso hacia estos dos objetivos diseñando un modelo de gestión de datos personales centrado en el usuario, en el que el almacenamiento se desvincula de la lógica de gestión de datos. Pretendemos ofrecer un sistema que ayude a impulsar la gestión de datos personales hacia el control del individuo, es decir, un sistema de gestión de información personal (PIMS). Al utilizar el almacenamiento distribuido y las redes de computación descentralizadas para controlar los servicios online, la información personal de los usuarios podría desplazarse hacia los directamente interesados, es decir, los interesados. El uso de las Distributed Ledger Technologies (DLT) y del Decentralized File Storage (DFS) como implementación de sistemas descentralizados es de vital importancia en este caso. La estructura de esta disertación sigue un método incremental para describir un conjunto de sistemas y modelos descentralizados que gira en torno a los datos personales y sus sujetos. Cada capítulo de esta disertación se basa en el anterior y analiza la implementación técnica de un sistema y su relación con la normativa correspondiente. De hecho, la mayoría de las veces, las implementaciones basadas en sistemas descentralizados chocan con leyes como el RGPD. Nos referimos al marco normativo de la UE, incluidos el RGPD, el eIDAS y la Data Governance Act, para construir los impulsores funcionales y no funcionales de nuestra arquitectura fnal del sistema. En nuestro diseño de PIMS, los datos personales se guardan en un Espacio de Datos Personales (PDS) que consiste en datos personales cifrados referentes al sujeto almacenados en un DFS. Utilizamos un sistema de indexación descentralizado para garantizar la integridad, verifcabilidad, vinculabilidad, capacidad de búsqueda e indexación de los datos personales cifrados almacenados en el PDS. Seguimos el enfoque para referenciar datos y su contenido en una DLT, es decir, on-chain hash pointers. A continuación, asociamos a dicha referencia de hash pointer un conjunto de palabras clave que se explota para buscar tipos específcos de contenidos. Además, una red de servidores de autorización actúa como intermediaria para facilitar el acceso a los posibles destinatarios de los datos. El acceso a los datos almacenados en un PDS puede ser permitido por el titular de los datos a través de smart contracts. Estos mantienen una estructura de datos para registrar los destinatarios de datos elegibles, es decir, aquellos a quienes expedir las claves necesarias para acceder a los datos cifrados. Además, en este caso, las tensiones del RGPD con las DLT impulsaron a que la arquitectura fuera multi-DLT. Los servidores de autorización utilizan una permissioned DLT “estrechamente controlada” para manejar datos personales, mientras que una “audit” permissionless DLT se utiliza para la seguridad del sistema y sólo contiene datos no personales. Tras describir el diseño de un PIMS descentralizado, nos centramos en enriquecer la expresividad del mecanismo de control de acceso mediante políticas de privacidad. Éstas permiten a los titulares y /o sujetos de los datos expresar políticas de privacidad alineadas con las bases legales del RGPD que se aplicarán a través de smart contracts. Para ello utilizamos un conjunto de tecnologías y estándares de la Web Semántica. Por último, presentamos un modelo de Self-Sovereign Identity (SSI) para proporcionar, solicitar y obtener datos cualifcados para negociar y /o ejecutar transacciones electrónicas con un enfoque en el contexto legal y operativo.

Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Original source
Apr 17, 2023·Organizational Cybersecurity Journal Practice Process and People
7 cites
Privacy implications of blockchain systems: a data management perspective

Heng Xu, Nan Zhang

Purpose Privacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? Blockchain does not seem to neatly fit into any of these buckets that we traditionally use to gauge the privacy implications of information technologies. In this article, the authors argue that blockchain transcends the extant conceptualization of privacy because it modifies the nature of data flow upon which the modern concept of privacy is based. Design/methodology/approach The authors introduce a conceptualization of blockchain as a new mechanism for data management. Then, following this conceptualization, the authors present a functional review of blockchain, summarizing the features it provides for the data it manages. This review sets up the discussion of how blockchain redefines data flow by separating the power of collection, access and query of data to different entities. After illustrating how this change regrounds privacy concerns in a blockchain system, the authors conclude with a discussion of the recommendations for future privacy research on blockchain. Findings The authors demonstrate that blockchain, by design, separates three core data-centric operations that are assumed to be inextricably linked in the canonical conceptualization of privacy: the collection, access and query of data. Collection means to capture and then store the data; access means to modify or augment the data and query means the ability to test or verify certain properties of the data (e.g. whether a bank account has a zero balance). Traditionally, any entities that collect data can evidently read, modify or query the same data as they wish. With blockchain, however, an entity that stores the data may not be able to modify the data, yet an entity that cannot even read the data may be able to verify certain properties of the data. Originality/value Privacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? In this article, the authors aim to respond to this important question.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Privacy-Preserving Technologies in Data
Original source
Apr 17, 2023·2023 19th International Conference on the Design of Reliable Communication Networks (DRCN)
12 cites
Blockchain-based Self-Sovereign Identity Solution for Vehicular Networks

Engin Zeydan, Josep Mangues, Şuayb S. Arslan, Yekta Türk

Identity and access management frameworks address data governance and system access rights for users, organizations, and vendors. Emerging identity management models such as Self-Sovereign Identity (SSI) that is based on Distributed Ledger Technology (DLT) technology, have emerged to address the challenges associated with centralized authority. The main goal of SSI is to help users self-manage their data shared with services. In this paper, we explore a possible application of the SSI concept to vehicular networks. We propose a new methodology, that is alternative to the conventional blockchain-based SSI, which ensures confidentiality, authentication, and integrity of vehicle users identity and their data. At the end of the paper, we also compare SSI-based and Non-fungible token (NFT)-based blockchain solutions, the challenges and future directions of SSI solutions in the context of vehicular networks.

Open access
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
Privacy, Security, and Data Protection
Original source