Simona‐Vasilica Oprea, Adela Bârã, Anca-Ioana Andreescu, Marian Pompiliu Cristescu
Digitalization advances in many fields due to its clear advantages and facilities especially in pandemic times when crowds are to be avoided. E-voting is gaining importance as voting using laptops, mobile phones or tablets is more practical. Hence, human counting which leads to unintentional errors or fraud could be eliminated. Furthermore, software applications can reduce the costs of the classic election process and physical infrastructure. In this paper, we propose to identify the most critical specifications of an e-voting application, find a solution for elections in universities and compare our solution with others. The goal is to propose a conceptual architecture using encrypted functions and two stages: voting and validation, separating layers and roles, that is based on blockchain tables and innovative interactions between actors (voters and voting committee) and the two software components (web application and database). For replicability, the conceptual architecture is depicted and formalized using several Unified Modeling Language (UML) diagrams. Furthermore, in order to provide proof of concept, the initial steps in implementing the proposed solution are showcased.
The rapid expansion of digital platforms, electronic health systems, IoT devices, and cross-organisational data-sharing environments have resulted in the exchanged amount and sensitivity of personal data growing. Conventional consent management models are centralised, non-transparent, and hard to audit, exposing threats of unauthorised distribution, poor interoperability, and substandard compliance with regulations. Traditional systems have a hard time delivering dynamic, fine-grained and verifiable user control over consent. They do not have transparent audit trails, do not support the use of multi-party authorization, and do not impose the use of data in a manner specific to purpose, particularly when regulated by laws like GDPR. The issue of scalability, the absence of automation, and immutable logging also contribute to the growth of trust and security concerns. The objective of the research is to assess in a critical manner the concept of blockchain-based and smart contract-based consent management models to determine the architectural designs, performance aspects, cryptographic techniques, and compliance measures that enhance personal data control within healthcare, fitness tracking, and wider data-sharing systems. Solution: This paper summarises the evidence regarding the benefits of hybrid on-chain/off-chain architectures, purpose-based access control, threshold cryptography, pseudonymization layers, and business-process-sensitive workflows in improving the transparency, auditability, and automation of consent management through the analytical review of nineteen blockchain-based consent systems. Smart contract systems give enforceability of rules, minimise risk of breach and enhance precision of consent revocation. The remaining issues are scalability, fluctuations in the cost of gas, GDPR-compatible deletion, and multidimensional approval. In general, consent systems based on smart contracts provide a technically plausible and legally consistent platform on which to build the systems of personal data-sharing in the future.
I. Román, Jorge Calvillo‐Arbizu, Vicente Mayor, German Madinabeitia-Luque · 6 authors
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual’s will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
Fear, Uncertainty, and Doubt or FUD, is relatively understudied in relation to cryptocurrency. It is a feeling derived from negative cryptocurrency-related information and it prompts adverse sentiment. This thesis addresses knowledge gaps on FUD by exploring its relationship with trust, and cryptocurrency information-seeking practices. We conducted 23 semi-structured interviews with cryptocurrency adopters and non-adopters to investigate triggers of FUD, FUD-induced behaviours, and how people form trust assessments of cryptocurrency information. Using thematic analysis, we classified FUD triggers found in our data across the personal, societal, and systemic level. Furthermore, we identified how participants make either cursory, extensive, or negative trust assessments of cryptocurrency information using attachment and depth. To illustrate this process, we proposed a model of trust assessment pathways. We then provide four recommendations on combating FUD, and suggest areas of future work.
The purpose of this article is to propose a framework named IoT-AC/Bc to secure smart cities. This article describes a new method that integrates Role-Based Access Control (RBAC) and Zero-Knowledge Proof (ZKP) models based on IoT and blockchain technologies. This method enables fast access authentication on smart city gates using ZKP, which provides an extra layer of security to address access control challenges. The framework consists of an Internet of Things Access Control-based Blockchain Smart Contract that manages user authentication, access session identities, and asset real-time interactions; and a Blockchain Ledger Management Smart Contract that implements distributed access control and tracks the ledger history of different activities. The framework achieves availability, scalability, multi-factor authentication, and decentralization, which strengthens distribution, role authority, access rights, and concurrent identity access requests. The results are demonstrated through a comparative analysis focused on the number of multithreaded requests, the cost of smart contract deployment, the multi-factor authentication performance for users’ interactions with the smart city gates, and the security strength levels. The framework’s performance effectiveness is evaluated through a case study that consists of various scenarios. The framework allows improving the security level by 94% under low and medium attack strength and 89% under high attack strength for 18 security attacks. This paper is novel because the framework uses ZKP over a blockchain network as an extra cryptographic technique with RBAC as a logical access control model to achieve fast accessibility authorization for users’ transactions while preserving their private identity on smart city gates. Keywords: Access Control, Blockchain, Internet of Things, Role-Based Access Control, Smart Cities, Multi-Factor Authentication DOI: https://doi.org/10.35741/issn.0258-2724.58.4.56
Abla El Bekkali, Mohamed Essaaidi, Mohammed Boulmalf
A smart city is one that uses digital technologies and other means to improve the quality of life of its citizens and reduce the cost of municipal services. Smart cities primarily use IoT to collect and analyze data to interact directly with the city’s infrastructure and monitor city assets and community developments in real time to improve operational efficiency and proactively respond to potential problems and challenges. Today, cybersecurity is considered one of the main challenges facing smart cities. Over the past few years, the cybersecurity research community has devoted a great deal of attention to this challenge. Among the different technologies proposed to address this challenge, Blockchain appears to offer the security and data privacy needed to enhance smart cities security. In this paper, we propose a comprehensive framework and architecture based on Blockchain, big data and artificial intelligence to improve smart cities cybersecurity. For the sake of illustration of the proposed framework, simulation results are presented for a smart grid dataset from the UCI Machine Learning Repository, demonstrating its potential and efficiency to deal with cybersecurity challenges in smart cities.
Egor Ermolaev, Iván Abellán Álvarez, Johannes Sedlmeir, Gilbert Fridgen
E-commerce has grown rapidly over the past years, with prevailing e-commerce platforms aggregating large amounts of customer data. This practice has several undesirable side effects, such as facilitating profiling that may lead to price discrimination and data feedback loops that can hamper competition. Moreover, data hoarding carries security risks through data breaches and undermines customers’ privacy expectations. On the other hand, convenience aspects and compliance regulation demand the processing and storage of user-related data. To address this tension field, we aim to conceptualize and iteratively refine a data-minimizinig e-commerce platform. Following a design science research approach, we identify design objectives and propose and implement a solution in which stakeholders receive only customer data that is indispensable for their part of the process. Our solution leverages digital identity wallets and general-purpose zero-knowledge proofs (zk-SNARKs). We aim to perform a criteria-based evaluation to assess our artifact’s feasibility and fitness from an interdisciplinary perspective. With our results, we hope to illustrate that combining state-of-the-art cryptographic techniques and an emerging digital identity paradigm allows reaching the user experience of incumbent e-commerce platforms while mitigating the undesirable socio-economic side effects of avoidable data disclosure.
Le Anh Nguyen Long, Shenja van der Graaf, Athanasios Votsis
Borrowing from insights produced in urban planning, media and governance studies thereby leveraging the Ostrom-nian ideas of institutions and polycentricity, this paper examines how to govern commons in the smart city. It offers a reflection upon whether Distributed Ledger Technologies (DLTs) could be a key notion for the commons discourse which centers around stakeholders, self-organization, and a rights-based framework. By decentralizing ledgers and enabling the interoperability of the various interfaces, DLTs make records more accessible, exchanges more transparent, and reduce costs while increasing efficiency, and permit automation, therefore commoning interactions both offline and online are facilitated. We argue that the use of DLTs to preserve the spatiotemporal integrity of key urban spaces is a common value question that needs to be elucidated or renegotiated in order to provide any useful guidance to DLTs integrity-preserving potential. In doing so, we draw attention to DLT-based urban commons and urban governance, and point to inherent incompatibilities that may lead to radical and not-so-smooth changes in urban institutions, while providing a way of thinking which can move the smart city closer towards a values-centered process and away from a preoccupation with technology and efficiency.
Blockchain, also coined as decentralized AI, has the potential to empower AI to be more trustworthy by creating a decentralized trust of privacy, security, and audibility. However, systematic studies on the design principle of blockchain as a trust engine for an integrated society of cyber-physical-social-system (CPSS) are still absent. In this article, we provide an initiative for seeking the design principle of blockchain for a better digital world. Using a hybrid method of qualitative and quantitative studies, we examine the past origin, the current development, and the future directions of blockchain design principles. We have three findings. First, the answer to whether blockchain lives up to its original design principle as a distributed database is controversial. Second, the current development of the blockchain community reveals a taxonomy of 7 categories, namely, privacy and security, scalability, decentralization, applicability, governance and regulation, system design, and cross-chain interoperability. Both research and practice are more centered around the first category of privacy and security and the fourth category of applicability. Future scholars, practitioners, and policy-makers have vast opportunities in other, much less exploited facets and the synthesis at the interface of multiple aspects. Finally, in counter-examples, we conclude that a synthetic solution that crosses discipline boundaries is necessary to close the gaps between the current design of blockchain and the design principle of a trust engine for a truly intelligent world.
Metaverse, the core of the next-generation Internet, is a computer-generated holographic digital environment that simultaneously combines spatio-temporal, immersive, real-time, sustainable, interoperable, and data-sensitive characteristics. It cleverly blends the virtual and real worlds, allowing users to create, communicate, and transact in virtual form. With the rapid development of emerging technologies including augmented reality, virtual reality and blockchain, the metaverse system is becoming more and more sophisticated and widely used in various fields such as social, tourism, industry and economy. However, the high level of interaction with the real world also means a huge risk of privacy leakage both for individuals and enterprises, which has hindered the wide deployment of metaverse. Then, it is inevitable to apply privacy computing techniques in the framework of metaverse, which is a current research hotspot. In this paper, we conduct comprehensive research on the necessity, taxonomy and challenges when privacy computing meets metaverse. Specifically, we first introduce the underlying technologies and various applications of metaverse, on which we analyze the challenges of data usage in metaverse, especially data privacy. Next, we review and summarize state-of-the-art solutions based on federated learning, differential privacy, homomorphic encryption, and zero-knowledge proofs for different privacy problems in metaverse. Finally, we show the current security and privacy challenges in the development of metaverse and provide open directions for building a well-established privacy-preserving metaverse system. For easy access and reference, we integrate the related publications and their codes into a GitHub repository: https://github.com/6lyc/Awesome-Privacy-Computing-in-Metaverse.git.
As time progresses, the need for more secure applications grows exponentially. The different types of sensitive information that is being transferred virtually has sparked a rise in systems that leverage blockchain. Different sectors are beginning to use this disruptive technology to evaluate the risks and benefits. Sectors like finance, medicine, higher education, and wireless communication have research regarding blockchain. Futhermore, the need for security standards in this area of research is pivotal. In recent past, several attacks on blockchain infrastructures have resulted in hundreds of millions dollars lost and sensitive information compromised. Some of these attacks include DAO attacks, bZx attacks, and Parity Multisignature Wallet Double Attacks which targeted vulnerabilities within smart contracts on the Ethereum network. These attacks exposed the weaknesses of current smart contract development practices which has led to the increase in distrust and adoption of systems that leverage blockchain for its functionality. In this paper, I identify common software vulnerabilities and attacks on blockchain infrastructures, thoroughly detail the smart contract development process and propose a model for ensuring a stronger security standard for future systems leveraging smart contracts. The purpose for proposing a model is to promote trust among end users in the system which is a foundational element for blockchain adoption in the future.