Smart healthcare systems provide user-centric medical services to patients based on collected information of patients inducing personal health information (PHI) and personal identifiable information (PII). The information (PII and PHI) flows into the smart healthcare system with or without any regulation and patient concern with the help of new information and communication technologies (ICT). The use of ICT comes with the security and privacy issues of collected PII and PHI data. The Europe Union has published the General Data Protection Regulation (GDPR) to regulate the flow of personal information. Towards this end, this paper proposes a blockchain-based data storage and sharing framework for a smart healthcare system that complies with the âPrivacy by Designâ rule of the GDPR. The personal information collected from patients is stored on off-chain storage (IPFS), and other information is stored on the blockchain ledger, which is visible to all participants. The smart contracts are designed to share the PII data with another participant based on prior permission of the data owner. The proposed framework also includes the deletion of PII and PHI in the system as per the âRight to be Forgottenâ GDPR rule. Security and privacy analyses are performed for the framework to demonstrate the security and privacy of data while sharing and at rest. The comparative performance analysis demonstrates the benefit of the proposed GDPR-compliant data storage and sharing framework using blockchain. It is evident from the reported results that the proposed framework outperforms the state-of-the-art techniques in terms of performance metrics in a smart healthcare system.
Rahime Belen-Saglam, Enes Altuncu, Yang LĂŒ, Shujun Li
The blockchain technology has been rapidly growing since Bitcoin was invented in 2008. The most common type of blockchain systems, public (permisionless) blockchain systems have some unique features that lead to a tension with European Union's General Data Protection Regulation (GDPR) and other similar data protection laws. In this paper, we report the results of a systematic literature review (SLR) on 114 research papers discussing and/or addressing such a tension. To be the best of our know, our SLR is the most comprehensive review of this topic, leading a more in-depth and broader analysis of related research work on this important topic. Our results revealed that three main types of issues: (i) difficulties in exercising data subjects' rights such as the `right to be forgotten' (RTBF) due to the immutable nature of public blockchains; (ii) difficulties in identifying roles and responsibilities in the public blockchain data processing ecosystem (particularly on the identification of data controllers and data processors); (iii) ambiguities regarding the application of the relevant law(s) due to the distributed nature of blockchains. Our work also led to a better understanding of solutions for improving the GDPR compliance of public blockchain systems. Our work can help inform not only blockchain researchers and developers, but also policy makers and law markers to consider how to reconcile the tension between public blockchain systems and data protection laws (the GDPR and beyond).
As the digital ecosystem evolves, secure and efficient Digital IdentityManagement Systems (DIMS) have become pivotal in managing identities acrossgovernmental, financial, healthcare, and commercial sectors. This paper offers across-sectoral examination of DIMS, emphasizing security and privacy concerns andtheir mitigation strategies. Drawing on current technologies such as blockchain,biometrics, and zero-knowledge proofs, the study explores how these systems canprotect sensitive information while ensuring interoperability and compliance withregulatory frameworks. Through comparative analysis, graphical insights, and realworld case studies, the paper underscores the need for standardized and resilientidentity infrastructures that balance user privacy and system functionality
H. Jayasooriya, D. M. P. S. Bandara, N. Hemachandra, N. Kuruwitaarachchi · 5 authors
In order to reduce limitations and as a practical substitute for voting on paper, electronic voting has developed gradually as a feasible alternative. The last decade's worth of related studies implies that, building a secure e-voting system using web 2.0 technology that assures the integrity of the votes while also giving transparency has been a long-standing difficulty. In a network of centralized systems, a single party has the right to administer data sources. Since the centralized voting systems are more vulnerable to data manipulation issues, the trust has faded in the voters on behalf of the entire process. In this paper authors discuss the solution with blockchain which is secured. The proposed implementation is ideal for small or medium-scale elections, and this includes several basic components of our methodology in three fictitious modules: the administrative module, the Voters module, and the Blockchain module. Node JS, Ganache, and Web3 JS are used as the main technologies. In conclusion, it is expected to implement a secure system for conducting web-based digital voting that ensures the integrity of the votes registered. Furthermore, it intends to enhance the system in the future to accommodate large-scale elections with a viable solution to the blockchain trilemma issues.
Michael Froehlich, Benjamin Moser, Florian Alt, Albrecht Schmidt
There is an increasingly diverse range of smart-contract blockchains on which decentralized applications (dApps) are built. However, HCI research has so far failed to address them, focusing primarily on Bitcoin and Ethereum. This is problematic as these new blockchains come with an increasingly diverse set of properties that influence the usability of dApps for end-users. For blockchain interface design guidelines to be valuable for practitioners, they need to acknowledge the heterogeneity of blockchains. However, evaluating novel interface concepts across different blockchains is resource-intensive as each blockchain has to be integrated manually, slowing down research. To address this challenge, we propose a system to support interface experimentation for blockchain applications. The system allows researchers and developers to connect interfaces to a unified API simulating different blockchains and facilitates the configuration, distribution, and evaluation of online experiments. A preliminary evaluation showed promising results.
In the past few years, the main research efforts regarding General Data Protection Regulation (GDPR)-compliant data sharing have been focused primarily on informed consent (one of the six GDPR lawful bases for data processing). In cases such as Business-to-Business (B2B) and Business-to-Consumer (B2C) data sharing, when consent might not be enough, many small and medium enterprises (SMEs) still depend on contractsâa GDPR basis that is often overlooked due to its complexity. The contractâs lifecycle comprises many stages (e.g., drafting, negotiation, and signing) that must be executed in compliance with GDPR. Despite the active research efforts on digital contracts, contract-based GDPR compliance and challenges such as contract interoperability have not been sufficiently elaborated on yet. Since knowledge graphs and ontologies provide interoperability and support knowledge discovery, we propose and develop a knowledge graph-based tool for GDPR contract compliance verification (CCV). It binds GDPRâs legal basis to data sharing contracts. In addition, we conducted a performance evaluation in terms of execution time and test cases to validate CCVâs correctness in determining the overhead and applicability of the proposed tool in smart city and insurance application scenarios. The evaluation results and the correctness of the CCV tool demonstrate the toolâs practicability for deployment in the real world with minimum overhead.
The evolution of social media has led to a trend of posting daily photos on online Social Network Platforms (SNPs). The privacy of online photos is often protected carefully by security mechanisms. However, these mechanisms will lose effectiveness when someone spreads the photos to other platforms. In this article, we propose Go-sharing, a blockchain-based privacy-preserving framework that provides powerful dissemination control for cross-SNP photo sharing. In contrast to security mechanisms running separately in centralized servers that do not trust each other, our framework achieves consistent consensus on photo dissemination control through carefully designed smart contract-based protocols. We use these protocols to create platform-free dissemination trees for every image, providing users with complete sharing control and privacy protection. Considering the possible privacy conflicts between owners and subsequent re-posters in cross-SNP sharing, we design a dynamic privacy policy generation algorithm that maximizes the flexibility of re-posters without violating formersâ privacy. Moreover, Go-sharing also provides robust photo ownership identification mechanisms to avoid illegal reprinting. It introduces a random noise black box in a two-stage separable deep learning process to improve robustness against unpredictable manipulations. Through extensive real-world simulations, the results demonstrate the capability and effectiveness of the framework across a number of performance metrics.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Self-Sovereign Identity (SSI) is projected to become part of every person's life in some form. The ability to verify and authenticate that an individual is the actual person they are purported to be along with securing the personal attributes could have wide spread implications when engaging with third party organizations. Utilizing blockchains and other decentralized technologies, SSI is a growing area of research. The aspect of securing personal information within a decentralized structure has possible benefits to the public and private sectors. In this paper, we describe the SSI framework architecture as well as possible use cases across domains like healthcare, finance, retail, and government. The paper also contrasts SSI and its decentralized architecture with the current widely adopted model of Public Key Infrastructure (PKI).
Michael Sober, Giulia Scaffino, Stefan Schulte, Salil S. Kanhere
Abstract The (IoT) is growing steadily, and so is the number of data that is generated by (IoT) devices. This makes it difficult to find and leverage relevant data (and data sources) without a data marketplace. Such a marketplace provides a platform to enable different parties, e.g., sensor operators and service providers, to trade their data. Today, most data marketplaces are based on centralized solutions, which may become a single point of failure and come with expensive infrastructure, trust problems, and privacy issues. Therefore, we propose the application of blockchain technology to implement a data marketplace for the IoT. Within the proposed marketplace, smart contracts are used to implement various functionalities and enforce the rules of the data exchange. The marketplace also includes a proxy, a broker, and (GUIs) to enable data trading. To show the applicability of the proposed data marketplace, we analyze the costs arising from the utilization of smart contracts.
Samuel Akwasi Frimpong, Han Mu, Edward Kwadwo Boahen, Rexford Nii Ayitey Sosu · 7 authors
Recommendation systems provide ease and convenience for users to address information overload problems while interacting with online platforms such as social media and e-commerce. However, it raises several questions about privacy, especially for users who prefer to remain anonymous, especially on online social networks (OSNs). Moreover, due to the commercialization of online users' data, some service providers sell users' data to third parties at the blind side of the users, which leads to trust issues between users and service providers. Such matters call for a system that gives online users much-needed control and autonomy of their data. With the advancement of blockchain technology, many research institutions are experimenting with decentralized technologies to resolve the OSN user dilemma of privacy intrusion against third parties and hacks. To resolve these limitations, we propose RecGuard, a privacy preservation blockchain-based network system. We developed two smart contracts, RG-SH and RG-ST, to ensure the security and privacy of user data. The RG-SH manages user data, whereas the RG-ST stores data. A graph convolutional network (GCN) was integrated with the blockchain-based system to detect malicious nodes. Finally, we implemented our framework prototype on a locally simulated network. The analysis and experiment results show that the proposed scheme demonstrates the effectiveness and privacy of users in our framework.
This paper presents a detailed analysis of the Voting System via Decentralized App using an upcoming well-received technology: Blockchain. In recent years, Blockchain has become the finest way to store data and transmit data safely without any involvement from a third party because of its key features, including anonymity, security, privacy, and reliability. This paper commences by analyzing Blockchain technology and identifying its advantages and disadvantages. The report explains the proposed steps we took to draw out a prototype of the Voting System on DAPP. It further analyzes and explains the problems with the current voting system and how this(Blockchain) technology could immensely contribute to bringing change in the election system of a country by enveloping all the disadvantages of the current system. It describes the advantages of using Blockchain for the voting system and highlights what could still play out as a major disadvantage and an obstruction in encouraging change in methodologies for the voting system. Probing further, it can be deduced how this technology could provide safe, secure, transparent, and decentralization data in the voting or election system. As security is the main highlight in choosing or not choosing a new platform, we also reveal the potential problems with this e-voting system and further propose some ideas that could help resolve the issue, making the system more safe and secure and favorable to rebuild the current system.
NBA (National Basketball Association) trading cards are a hot collectorâs item, with sales increasing rapidly every year. However, with the popularity of online trading, some sellers have started to intentionally and unintentionally sell imitation trading cards, and even PwC (Pricewaterhouse Coopers) is not immune. However, the PSA (Professional Sports Authenticator), which is the authentication agency, is not liable for this. Faced with the above situation, we moved trading cards online and proposed a blockchain-based anti-counterfeit and traceable NBA digital trading card management system, using blockchain technology to protect digital trading cards, and special digital copyright, to move from relying on other regulators to achieve the fight against counterfeit cards and maintain the security of the digital trading card market. Finally, we analyzed the security of the system and compared it with other methods. Our system uses Hyperledger Fabric to share data while protecting corporate privacy. Proxy re-encryption enables secure and trusted access authorization for digital transaction cards. Asymmetric encryption protects the data and uses signatures to achieve traceability and non-repudiation. Overall, our system solves the problem of counterfeiting and traceability that can occur in the digital trading card process from production to purchase.
The aim of this paper was to perform an analysis of the state-of-the-art solutions of the permissioned blockchain compliance with the General Data Protection Regulation (GDPR), including the implementation of one of the analyzed methods and the own solution. This paper covers the subject of GDPR and its impact on already existing blockchain databases to determine the domain of the problem, including the necessity to introduce mutability in the data structure to comply with the "right to be forgotten". The performed analysis made it possible to discuss current research in technical terms as well as in the regulation itself. In the experimental part, attempts were made to research and implement the Reference-based Tree Structure (RBTS), including the performance tests. The proposed solution is efficient and easily reproducible. The deletion of unwanted content is quick and requires consent only from the owner of personal data; therefore, eliminating the dependency on the other blockchain network participants.
The ability to capture and quantify any aspect of daily life via sensors, enabled by the Internet of Things ( IoT ), data have become one of the most important resources of the 21 st century. However, the high value of data also renders data an appealing target for criminals. Two key protection goals when dealing with data are therefore to maintain their permanent availability and to ensure their integrity. Blockchain technology provides a means of data protection that addresses both of these objectives. On that account, blockchains are becoming increasingly popular for the management of critical data. As blockchains are operated in a decentralized manner, they are not only protected against failures, but it is also ensured that neither party has sole control over the managed data. Furthermore, blockchains are immutable and tamper-proof data stores, whereby data integrity is guaranteed. While these properties are preferable from a data security perspective, they also pose a threat to privacy and confidentiality, as data cannot be concealed, rectified, or deleted once they are added to the blockchain. In this paper, we therefore investigate which features of the blockchain pose an inherent privacy threat when dealing with personal or confidential data. To this end, we consider to what extent blockchains are in compliance with applicable data protection laws, namely the European General Data Protection Regulation ( GDPR ). Based on our identified key issues, we assess which concepts and technical measures can be leveraged to address these issues in order to create a privacy-by-design blockchain system.
In this article, we explore the tension between abstraction and composability in web3 today, specifically within identity solutions, and argue that the current standard DID v1.0 is sufficiently under specified, allowing for many methods and instantiations, including blockchain based certificates. We view experiments today in web3 identity as additive and complementary, and argue that often cited differences are of degree and more in form, less in substance. By way of illustration, we compare decentralized naming services and blockchain based identity certificates such as soulbound tokens (SBTs) to decentralized identifiers (DIDs) and verifiable credentials (VCs). Both paradigms, to the extent they can be meaningfully differentiated, share similar potential as well as challenges. Specifically, we refer to fears about non consensual verification (scarlet letters) and show DID method iterations are not immune by issuing an innocuous public scarlet letter to a DIDs associated public address for anyone to see. Moreover, we argue that because SBTs are unspecified, one could characterize SBTs as an iteration, or extension, of VCs that additionally aspire to achieve composability with web3 smart contracts for correct execution of code, privacy, coercion resistance, and censorship resistance. We offer research paths for how VCs can also achieve these properties. We do not comment on cost, scalability, transferability, or common knowledge as they have been previously reviewed.
Shopping platform increases service speed and reduces transaction cost. However, it also leads to issues of information asymmetry. Some sellers fabricate the price of promotional goods prior to promotion, not only affecting the reputation of sellers, but also viciously influencing the goodwill of the shopping websites. On this basis, a shopping decentralized Application (DApp) based on blockchain technology was designed; this research integrates the blockchain and shopping App. The App used the decentralized technology of distributed blockchain tamper resistance and its advantages of distributed ledger, decentralization, traceability, smart contract, and information tamper-proof to reduce the adverse impact of information asymmetry on consumers.
Uk Jo, Yustus Eko Oktian, Donggyu Kim, Sangbong Oh · 6 authors
Contact tracing is an effective strategy to slow down the COVID-19 pandemic. However, the use of digital footprints as supportive evidences in the contact tracing process rises the privacy problems since private information must be shared to the contact tracing providers. This paper proposed a novel privacy-preserving contact tracing procedure based on zero-knowledge-range-proof and blockchain platform, which helps users to prove whether they in contact with the confirmed patient without disclosing the exact location they have visited. The blockchain is used to guarantee anonymity through the use of address as an identity, and provide strong non-repudiation from transactions. Finally, we provide a proof-of-concept implementation of our proposal using Hyperledger Fabric and smartphone application. The evaluation showed that the proposed system can work as intended with minimal processing delay.
Mirko Zichichi, Stefano Ferretti, Victor RodrıÌguez-Doncel
Big Tech companies operating in a data-driven economy offer services that rely on their users' personal data and usually store this personal information in "data silos" that prevent transparency about their use and opportunities for data sharing for public interest. In this paper, we present a solution that promotes the development of decentralized personal data marketplaces, exploiting the use of Distributed Ledger Technologies (DLTs), Decentralized File Storages (DFS) and smart contracts for storing personal data and managing access control in a decentralized way. Moreover, we focus on the issue of a lack of efficient decentralized mechanisms in DLTs and DFSs for querying a certain type of data. For this reason, we propose the use of a hypercube-structured Distributed Hash Table (DHT) on top of DLTs, organized for efficient processing of multiple keyword-based queries on the ledger data. We test our approach with the implementation of a use case regarding the creation of citizen-generated data based on direct participation and the involvement of a Decentralized Autonomous Organization (DAO). The performance evaluation demonstrates the viability of our approach for decentralized data searches, distributed authorization mechanisms and smart contract exploitation.
A core concept within journalism is the demand for correctness and the ability to double-check news and its sources (Kovach & Rosenstiel, 2014). In this paper, we reflect on the development of a prototype to study the possible use of blockchain technology to create a global secure database of fact-checks that is open to the public. The prototype utilized Hyperledger fabric to create a permissioned blockchain that stores fact-checks created by its users. Through automated processes using smart contracts (chain code applications), we aimed to create a solution that would improve the reliability of fact-checking and keep track of each fact-checking process for digital content, including pictures and videos. Our conclusion is that it is indeed possible to create a blockchain-based system that allows the establishment of a network of fact-checkers that could collectively build and maintain a globally accessible fact-checking database. However, based on technical developments and the evaluation performed by the professional fact-checkers and data journalists in our study, we conclude that the cost, complexity, and rapid technological changes required in this domain indicate that blockchain technology is not yet ready to be directly applied to fact-checking processes in a real-world scenario.