Aaliya Sarfaraz, Ripon K. Chakrabortty, Daryl Essam
In recent years, supply chains have evolved into huge ecosystems, demanding trust, provenance, and data privacy. Since blockchain technology (BCT) allows for the development of a distributed environment, it is ideal for supply chain management (SCM) applications. However, concerns regarding data privacy have impeded the development of blockchains. Despite the fact that some blockchains can restrict participants from reading and/or writing data, blockchain’s transparency makes protecting sensitive data challenging. To solve the data privacy challenge, this paper proposes a framework, AccessChain, that is an SCM access control framework that is based on an attribute-based access control (ABAC) model that restricts access to competing parties while allowing for network scalability. This proposed AccessChain model has two types of ledgers in its system: local and global. Local ledgers are used to store business contracts between stakeholders and the attribute-based access control model management, whereas the global ledger is used to record transaction data. AccessChain can enable decentralized, fine-grained and dynamic access control management in SCM when combined with the ABAC model and BCT. This paper’s experimental results illustrate that high throughput can be achieved in a large-scale request environment while maintaining data privacy and sustaining a scalable network.
Alina Khayretdinova, Michael Kubach, Rachelle Sellung, Heiko Roßnagel
Abstract New approaches to identity management based on technologies such as blockchain and distributed ledgers are promoted as a chance to give users full control over their own identity data. Despite being often called the future of digital identity management, Decentralized Identity Management (DIdM) and Self-sovereign Identities (SSI) are still facing a number of challenges, usability being a major one: their concepts are too sophisticated for users and do not fit their mental models. We address this by conducting a study that analyses and evaluates the usability and practical applicability of some of the most advanced DIdM solutions. The results of the user tests reveal existing usability issues and outline the way they deprive end users of experiencing the entire range of claimed privacy and security benefits of these identity solutions.
Data-driven applications play an important role in modern-time maritime transportation systems, for instance in facilitating decision-making relating to communication and safety. One example application is position data sharing between vessels within the maritime Internet of Things (IoT)-enabled context. When designing such applications, we need to also consider how to ensure data accuracy as well as privacy in a large scale deployment. In this paper, we demonstrate the potential of using blockchain to facilitate privacy-preserving data sharing. Specifically, we develop a zero-knowledge proof-based scheme to protect vessel identities while allowing data sharing, and a commitment-based approach to ensure relationship-related privacy in data trading between participants. Our security and performance evaluations demonstrate the utility of the proposed approach.
ABSTRACT The period from the mid-1990s to the mid-2000s saw the transformation of information and communication infrastructure. In the same period, TPRC evolved from a narrower focus on conventional telecommunications and information policy to “The Research Conference on Communications, Information, and Internet Policy.” Through the lens of my own interdisciplinary work on Internet policy and intersecting TPRC activity, this retrospective describes an arc of change that began at the 1994 TPRC and continued for about a decade. It combines description, commentary, and reflections on what this history might bode for TPRC as metaverses and Web3 progress from today’s hype to tomorrow’s Internet.
Individuals who wish to access a website or qualify for a loan are expected to expose personally identifying information, undermining their privacy and security. Firms share proprietary information in dealmaking negotiations which, if the deal fails, may be used by the negotiating partner for a competitive advantage. Regulators are expected to disclose their algorithmic tools to comply with public transparency and oversight requirements, a practice that risks rendering these tools circumventable and ineffective. Litigants might have to reveal trade secrets in court proceedings to prove a claim or defense. Such “verification dilemmas” — costly choices between opportunities that require the verification of some fact and risks of exposing sensitive information in order to perform that verification — appear across the legal landscape. Yet existing legal responses to them are imperfect. Legal responses often depend on ex post litigation procedures that can be prohibitively expensive for those most in need or are otherwise ineffective. Zero-knowledge proofs (ZKPs) — a class of cryptographic protocols that enables verification of a fact or characteristic of secret information without learning the actual secret — can help to avoid these verification dilemmas. ZKPs can provide a feasible means for a party who holds secret information to demonstrate desirable properties of this information while keeping the information otherwise hidden. Yet ZKPs have received scant notice in the legal literature. This Article fills that gap by providing the first deep dive into ZKPs’ broad relevance for law. It explains ZKPs’ conceptual power and technical operation to a legal audience. It then demonstrates how ZKPs can be applied as a governance tool to transform verification dilemmas in multiple legal contexts. Finally, the Article surfaces and provides a framework to address the policy issues implicated by introducing of ZKP governance tools into existing law and practice.
The term ‘Web3’ refers to the practices of participating in digital infrastructures through the ability to read, write and coordinate digital assets. Web3 is hailed as an alternative to the failings of big tech, offering a participatory mode of digital self-organizing and shared ownership of digital infrastructure through software-encoded governance rules and participatory practices. Yet, very few analytical frameworks have been presented in academic literature by which to approach Web3. This piece draws on the theoretical lens of infrastructure studies to offer an analytical framework to approach the emergent field of Web3 as an exploration in ‘how to infrastructure’ through prefigurative self-infrastructuring. Drawing on qualitative examples from digital ethnographic methods, I demonstrate how the origins of Web3 reveal the intentions of its creators as a political tool of prefiguration, yet its practices reveal the inherent tension of expressing these ideals in coherent technical and institutional infrastructure. Thus, I argue that one of the fundamental challenges Web3 is negotiating through technical and governance experiments is ‘how to self-infrastructure?’.
In a post-pandemic era with personal precautions and vaccination, the emergence of COVID-19 variants with higher transmissibility and the socio-economic reopening have raised new challenges to existing human-to-human digital contact tracing systems, where privacy, efficiency, and energy-consumption issues are major concerns. In this article, we propose a novel blockchain-based human-to-infrastructure contact tracing framework for the post-pandemic era. Specifically, our approach collects and records the interaction information between persons and predeployed anchor nodes to trace the possible contacts with confirmed patients, so as to capture the indirect contacts and reduces the energy consumption of users. To address the privacy leakage and reliability issues in contact tracing, we introduce a self-sovereign identity (SSI) model-based blockchain which enables users to gain full control of their own identities and eliminate the linkage between the identity and location information in interaction records. To further preserve the privacy of confirmed patients, we introduce the private set intersection cardinality (PSI-CA) protocol to estimate the risk of infection by only counting the number of encounters between users and confirmed patients. Two self-executed smart contracts are deployed on the SSI blockchain to perform contact tracing, which guarantees the robustness of the system. The performance analysis validates the effectiveness of our approach.
Social media (SM) 3.0 integrates SM platforms, such as Facebook and Twitter, with the Internet of Things (IoT), and has a great potential to change how we interact with mobile devices, online platforms, and the world around us. This integration with end users produces large-scale and heterogeneous data sources that demand machine learning (ML)-based data analytics for decision-making and to provide security against ML and data privacy attacks. The development of privacy-aware ML models within a federated learning (FL) ecosystem can empower an entire network to learn from data in a decentralized manner. In this article, we propose a differentially privacy blockchain-based explainable FL (DP-BFL) framework by harnessing the ever-evolving power of SM 3.0 networks. This framework permits any Internet empowered device to partake and contribute data to a global privacy preserved model. In this framework, participants will upload the differentially private local updates to the miners of blockchain, where the local updates will be evaluated and rewarded. The experimental results obtained from real-world datasets, namely, SM 3.0 and MNIST, demonstrated that the proposed framework could achieve high utility, enhanced privacy, and elevated efficiency. More Specifically, the experimental analysis of our proposed framework reveals the following two key properties. First, our proposed DP-BFL yields noticeable performance improvements in the applied learning models with high privacy and comparable utility levels, in terms of accuracy and f-measure metrics, to a standard FL and centralized learning approaches under the restriction of privacy preservation. Second, given a certain number of the malicious entities, DP-BFL allowed an enhanced recognition of users' preferences in the SM 3.0 dataset and precise prediction of images' class in the MNIST dataset while mitigating the impact of the malicious entities' poisoned updates. Moreover, as the proposed DP-BFL attains DP on the local model's update, it is considered the same as the standard FL-based setting, along with some kinds of privacy preservation on the uploaded model's updates.
Federated learning (FL) offers a promising approach to efficient machine learning with privacy protection in distributed environments, such as Internet of Things (IoT) and mobile-edge computing (MEC). The effectiveness of FL relies on a group of participant nodes that contribute their data and computing capacities to the collaborative training of a global model. Therefore, preventing malicious nodes from adversely affecting the model training while incentivizing credible nodes to contribute to the learning process plays a crucial role in enhancing FL security and performance. Seeking to contribute to the literature, we propose a blockchain-empowered secure and incentive FL (BESIFL) paradigm in this article. Specifically, BESIFL leverages blockchain to achieve a fully decentralized FL system, where effective mechanisms for malicious node detections and incentive management are fully integrated in a unified framework. The experimental results show that the proposed BESIFL is effective in improving FL performance through its protection against malicious nodes, incentive management, and selection of credible nodes.
In mobile communication networks, when a user roams to and accesses a foreign network, the foreign operator needs to request the user’s subscription data from a centralized authentication server, which is managed by the user’s home operator. However, centralized authentication introduces single point of failure. Meanwhile, the real-time participation of the home operator and the trust relationship between the foreign operator and the home operator are difficult to guarantee. In this paper, by adopting blockchain and smart contracts, we propose a secure and efficient access control scheme of user subscription data in roaming scenarios. We further design a flexible user authentication scheme, which utilizes derivable tokens based on the proposed access control scheme. By using blockchain to store and manage user subscription data, access control can be decentralized without any trusted third party. Besides, by implementing automatic verification of access privilege through smart contracts, the limitation of the home operators’ real-time participation is eliminated. In addition, to further improve security and reduce the on-chain storage overhead, we optimize the data encryption and storage scheme utilizing threshold secret sharing. Our security and performance analysis show that the proposed user subscription data access control scheme for roaming service provides high-level security while causing acceptable time and storage overhead.
Hafiz Humza Saeed, Abdullah Bin Masood, Hassaan Khaliq Qureshi
Smart cities utilize digital technologies for the improvement of its services’ quality and performance by reducing resources’ cost and consumption, with a commitment of action and efficiency to its citizens. The increased urban migration has led to many problems in cities, such as traffic congestion, waste management, noise pollution, energy consumption, air pollution, etc., as nowadays COVID-19 pandemic has seized the whole world. So, it is necessary to carry out its standard operating procedures (SOPs), including less human interaction. Thus, technology plays a vital role via Internet-of-Things (IoT) based systems. In this paper, a lightweight security mechanism (LSM) is proposed to enrich the IoT based systems. Blockchain technology is integrated, and its completely decentralized peer-to-peer (P2P) technology enables the users’ authentication and authorizes legitimate procedures. The IoT based management system is developed to monitor some of the aforementioned problems and solve solid waste, air, and noise monitoring systems. The Ethereum blockchain is used to implement a smart contract based framework for the system’s security and access control. The evaluation of performance of the LSM demonstrates that it is an efficient and lightweight tool in terms of cost, resources, and computation and superior over related security studies.
Jehil Thakkar, Nigam Patel, Chailcy Patel, Kaushal Shah
In conventional voting systems, achieving transparency and reliability is challenging due to the centralized environment. With the advancement in technology, electronic voting has emerged. But in E-voting also, it is essential to maintain the privacy, confidentiality and integrity of the votes and voters, which is challenging. The blockchain technology that has triggered the start of a new era in the digital world is one possible solution. The immutability property and decentralized architecture of blockchain technology make it suitable to create a robust and secure E-voting system. It helps in conducting the elections by maintaining authentication, integrity, transparency, confidentiality and non-repudiation in the system. In this paper, we have evaluated the potential and feasibility of the blockchain system for electronic voting. We have addressed all the possible limitations in the current E-voting system. Using solidity language, we have implemented a small-scale sample E-voting system as a smart contract that includes everything from hosting the election, verifying the voters and counting the votes and have deployed it on an external network. The paper also shows how Zero-Knowledge Proof can help in creating privacy-preserving secure E-voting systems.
Cryptocurrencies have gained popularity in recent years. However, for many users, keeping ownership of their cryptocurrency is a complex task. News reports frequently bear witness to scams, hacked exchanges, and fortunes beyond retrieval. However, we lack a systematic understanding of user-centered cryptocurrency threats, as causes leading to loss are scattered across publications. To address this gap, we conducted a focus group (n=6) and an expert elicitation study (n=25) following a three-round Delphi process with a heterogeneous group of blockchain and security experts from academia and industry. We contribute the first systematic overview of threats cryptocurrency users are exposed to and propose six overarching categories. Our work is complemented by a discussion on how the human-computer-interaction community can address these threats and how practitioners can use the model to understand situations in which users might find themselves under the pressure of an attack to ultimately engineer more secure systems.
Muhammad Zilal Hamzah, Diyanatul Husna, F. Astha Ekadiyanto, I Ketut Eddy Purnama · 10 authors
To fulfill health as basic human needs, health care services technology is always improved but also must maintain security and privacy of the data due to huge amount of data is created and distributed. Telemedicine with telecommunication technology offers convenience and cheaper cost, but still is vulnerable to cyber attacks, making it a threat for patients’ data's privacy. One approach that can be used to secure the data is applying access control to the data. Immutable blockchain can helps to enforce access control so it cannot be violated. We propose a system which implements Ethereum for the blockchain and React web application for the interface of the system. Data management and the access control are provided through Ethereum smart contracts, and the access control requires different role-based permission to upload and access the patients’ data. The system works successfully with average time taken to verify the role is 1.8033 seconds per session. The privacy of the patients’ data is ensured because only the patients that are allowed to keep the ID of their own data.
Nazia Abrar, Muhammad Faraz Hyder, Muhammad Kamran, Muhammad Mubashir Khan
Abstract - Smart contracts are essentially agreements between two parties, and the information included within them must be kept private and not shared with the outside community. Simultaneously, the most typical smart contract systems’ public nature limits the meaning of contracts. Smart contract confidentiality problems are a major impediment to their widespread adoption. A viable technique to protecting sensitive information is to hide it with cryptographic primitives or a hashing algorithm, however, hashing is irreversible, thus to address these issues, we first observed the privacy leakage of public smart contracts in this study. We next introduced our technique for privacy-preserving smart contracts, which includes encrypted user output values and defines holders of private values to prevent unintentional data leakage.
When building the large-scale distributed decision control system based on mobile terminal devices (MTDs), electronic voting (E-voting) is a necessary technique to settle the dispute among parties. Due to the inherent insecurity of Internet, it is difficult for E-voting to attain complete fairness and robustness. In this study, we argue that Bitcoin blockchain offers better options for a more practical E-voting. We first present a coin mixing-based E-voting system model, which can cut off the relationship between the voter’s real identity and its Bitcoin address to achieve strong anonymity. Moreover, we devise a secret sharing-based E-voting protocol, which can prevent voting number from being leaked ahead and further realize strong robustness. We establish the probable security theory to prove its security. In addition, we use the experimental evaluation to demonstrate its efficiency.
Yuye Han, Hong Chen, Zhijie Qiu, Lei Luo · 5 authors
As an essential means of privacy protection technology, zero-knowledge proof has gradually been applied into various fields with the development of blockchain technology, such as the Internet of Vehicles and Bitcoin. Personal comprehensive credit score as a measure to promote social governance is closely related to personal privacy. Although there are currently credit score calculation systems for various application scenarios, these systems almost ignore user privacy protection, which leads to user information leakage or abuse. The combination of zero-knowledge proof and personal credit score calculation has been studied by a number of researchers at the present stage. However, all data are provided by users directly in the current schemes, which did not consider the data authenticity under the situation that users provided false data. In this paper, we utilize zero-knowledge proof to design a novel privacy protection scheme for personal credit score calculation, taking into account the authenticity verification of multi-dimensional user data. In addition, our scheme also proposes the concept of a universal verification platform based on blockchain for personal credit scores. This platform has more substantial applicability and versatility for any qualified institution that requires querying and verifying user’s credit scores. At the end of the paper, we conducted a security analysis and performance evaluation for the overall scheme.
With the development of big data and blockchain, an increasing number of scholars have begun to study blockchain for data sharing. By studying data sharing models that are based on blockchain, we find that almost all of them have the following problems: 1) it is difficult to protect the privacy and integrity of users’ data, along with users’ data ownership; 2) the storage burden of blockchain is heavy, and blockchain lacks a mechanism for dealing with data with diverse types and inconsistent formats; and 3) the consensus mechanism has low fairness or low efficiency. Therefore, we propose a data-sharing privacy protection model (DS2PM) that is based on blockchain and a federated learning mechanism for solving these problems. The safety analysis and experimental results show that the DS2PM outperforms the previously established schemes.