With the development of Blockchain, more and more distributed cryptocurrencies continue to emerge. Most of these currencies use cryptographic techniques (such as zero-knowledge proofs, ring signatures, etc.) to enhance privacy protection, but at the same time the regulatory authorities have no access to audit transactions. Most existing auditing schemes are based on centralized system and cannot be directly applied to distributed cryptocurrencies. Therefore, an Auditable Zerocoin with User Awareness (AZUA) scheme which supports privacy protection and auditability simultaneously is proposed in this paper. Aiming to ensure that auditors can audit Zerocoin's transactions, auditability is defined in this paper. Meanwhile, in order to prevent auditors from abusing their power, a new security property is proposed: user awareness auditing. Moreover, taking transaction privacy issue into consideration, indistinguishability of audit information is defined. The transaction auditing from auditors is achieved in AZUA through the encryption scheme, which ensures the honesty of the auditors by introducing a commitment mechanism and that the users can be aware of whether they have been audited according to randomized public keys. Finally, it is proved that the scheme can satisfy auditability, user awareness auditing and indistinguishability of audit information simultaneously.
The emergence of electronic medical records has provided great convenience for the storage and analysis of medical data. However, electronic medical records contain a large amount of personal privacy information, it is still very difficult to share medical information among various medical institutions. As the underlying technology of Bitcoin, blockchain technology has the characteristics of decentralization, security, trustworthiness, collective maintenance, and cannot be tampered, it is suitable for data protection and sharing. In this paper, data masking technology and Inter Planetary File System (IPFS) are introduced to build a safe and efficient electronic medical record sharing model based on blockchain. The model can not only guarantee the security of medical data, but also save resources in blockchain.
Dominic Deuber, Bernardo Magri, Sri Aravinda Krishnan Thyagarajan
Bitcoin is an immutable permissionless blockchain system that has been extensively used as a public bulletin board by many different applications that heavily relies on its immutability. However, Bitcoin's immutability is not without its fair share of demerits. Interpol exposed the existence of harmful and potentially illegal documents, images and links in the Bitcoin blockchain, and since then there have been several qualitative and quantitative analysis on the types of data currently residing in the Bitcoin blockchain. Although there is a lot of attention on blockchains, surprisingly the previous solutions proposed for data redaction in the permissionless setting are far from feasible, and require additional trust assumptions. Hence, the problem of harmful data still poses a huge challenge for law enforcement agencies like Interpol (Tziakouris, IEEE S&P'18). We propose the first efficient redactable blockchain for the permissionless setting that is easily integrable into Bitcoin, and that does not rely on heavy cryptographic tools or trust assumptions. Our protocol uses a consensus-based voting and is parameterised by a policy that dictates the requirements and constraints for the redactions; if a redaction gathers enough votes the operation is performed on the chain. As an extra feature, our protocol offers public verifiability and accountability for the redacted chain. Moreover, we provide formal security definitions and proofs showing that our protocol is secure against redactions that were not agreed by consensus. Additionally, we show the viability of our approach with a proof-of-concept implementation that shows only a tiny overhead in the chain validation of our protocol when compared to an immutable one.
Privacy was one of the key points mentioned in Nakamoto's Bitcoin whitepaper, and one of the selling points of Bitcoin in its early stages. In hindsight, however, de-anonymising Bitcoin users turned out to be more feasible than expected. Since then, privacy focused cryptocurrencies such as Zcash and Monero have surfaced. Both of these examples cannot be described as fully successful in their aims, as recent research has shown. Incentives are integral to the security of cryptocurrencies, so it is interesting to investigate whether they could also be aligned with privacy goals. A lack of privacy often results from low user counts, resulting in low anonymity sets. Could users be incentivised to use the privacy preserving implementations of the systems they use? Not only is Zcash much less used than Bitcoin (which it forked from), but most Zcash transactions are simply transparent transactions, rather than the (at least intended to be) privacy-preserving shielded transactions. This paper and poster briefly discusses how incentives could be incorporated into systems like cryptocurrencies with the aim of achieving privacy goals. We take Zcash as example, but the ideas discussed could apply to other privacy-focused cryptocurrencies. This work was presented as a poster at OPERANDI 2018, the poster can be found within this short document.
Mark Bell, Alex Green, John Sheridan, John Collomosse · 8 authors
Archives have well-established practices which have been developed over years of working with analogue records. Now they face huge challenges due to the inexorable development of digital technologies. Not only is the heterogeneous nature of the records, their instability and the rapid pace of technological development a threat to the records’ survival, but the ease with which digital records can be altered has put archives in a technology arms race with those parties who would seek to falsify our digital inheritance and undermine democracy.In order to tackle these challenges, the ARCHANGEL project is breaking new ground by using blockchain to record checksums (cryptographic hashes) and other metadata derived from either scanned physical records or born-digital records to allow verification of their integrity over decade- or century-long time spans. This data is permanently preserved through peer-to-peer distribution and consensus checking without the need for a trusted third party, thereby enabling archives to prove the authenticity of the records in their custody.
Farah Kandah, Brennan Huber, Anthony Skjellum, Amani Altarawneh
Advancement in communication technologies and the Internet of Things (IoT) is driving smart cities adoption that aims to increase operational efficiency and improve the quality of services and citizen welfare. It is estimated that by 2020, 75% of cars shipped globally will be equipped with hardware to facilitate vehicle connectivity. The privacy, reliability and integrity of communication must be ensured so that actions can be accurate and implemented promptly after receiving actionable information. Because vehicles are equipped with the ability to compute, communicate, and sense their environment, there is a concomitant critical need to create and maintain trust among network entities in the context of the network's dynamism, an issue that requires building and validating the trust between entities in a small amount of time before entities leave each other's range. In this work, we present a multi-tier scheme consisting of an authentication and trust building/distribution framework designed to ensure the safety and validity of the information exchanged in the system.
Data protection is about protecting information about per-sons, which is currently flowing without much control –individuals can-not easily exercise the rights granted by the EU General Data Protection Regulation (GDPR). Individuals benefit from “free” services offered by companies in exchange of their data, but these companies keep their users’ data in “silos” that impede transparency on their use and possibilities of easy interactions. The introduction of the GDPR warrants control rights to individuals and the free portability of personal data from one entity to another. However it is still beyond the individual’s capability to perceive whether their data is managed in compliance with GDPR. To this regard, in this work the proposed approach consists in using decentralized mechanisms to provide transparency through distributed ledgers, data flow governance by using smart contracts and interoperability relying on semantic web technologies.