Eduardo Takeo Ueda, Marcelo Moro Da Silva, Anderson Silva, Norisvaldo Ferraz · 8 authors
Transparency and security in an electoral process are fundamental to the legitimacy of the results and the confidence of voters. Thus, it is necessary to assess opportunities to improve traditional voting systems. Among the main problems is the lack of transparency, due to the impossibility of a voter checking their vote and the lack of access to the source from which the results are obtained. Another problem is mobility, due to the impossibility of performing remote voting, as traditional voting systems continue to require the physical presence of the voter in an electoral zone. Thus, the objective of this work is to propose a voting system that is functional, transparent, safe, and accessible to everyone. Voters can vote through a mobile application with biometric authentication using fingerprint and password access. In our proposal, votes are registered in an Ethereum Blockchain through a Smart Contract, allowing the voter to check their vote. The results are expected to collaborate with the evolution of studies necessary to improve traditional voting systems, especially in fundamental aspects such as security, transparency, and mobility.
Rainer Stütz, Johann Stockinger, Pedro Moreno-Sánchez, Bernhard Haslhofer · 5 authors
We present a first measurement study on the adoption and actual privacy of two popular decentralized CoinJoin implementations, Wasabi and Samourai, in the broader Bitcoin ecosystem. By applying highly accurate (> 99%) algorithms we can effectively detect 30,251 Wasabi and 223,597 Samourai transactions within the block range 530,500 to 725,348 (2018-07-05 to 2022-02-28). We also found a steady adoption of these services with a total value of mixed coins of ca. 4.74 B USD and average monthly mixing amounts of ca. 172.93 M USD) for Wasabi and ca. 41.72 M USD for Samourai. Furthermore, we could trace ca. 322 M USD directly received by cryptoasset exchanges and ca. 1.16 B USD indirectly received via two hops. Our analysis further shows that the traceability of addresses during the pre-mixing and post-mixing narrows down the anonymity set provided by these coin mixing services. It also shows that the selection of addresses for the CoinJoin transaction can harm anonymity. Overall, this is the first paper to provide a comprehensive picture of the adoption and privacy of distributed CoinJoin transactions. Understanding this picture is particularly interesting in the light of ongoing regulatory efforts that will, on the one hand, affect compliance measures implemented in cryptocurrency exchanges and, on the other hand, the privacy of end-users.
Shahzaib Tahir, Hasan Tahir, Ali Sajjad, Muttukrishnan Rajarajan · 5 authors
The outbreak of the COVID-19 virus has caused widespread panic and global initiatives are geared towards treatment and limiting its spread. With technological advancements, several mechanisms and mobile applications have been developed that attempt to trace the physical contact made by a person with someone who has been tested COVID-19 positive. While designing these apps, user's privacy has been an afterthought and has resulted in mass violations of privacy of the public and the patients. A total of 32 countries have designed apps and rely on them as a strategy to flatten the pandemic curve. Along with lack of privacy, these methodologies are centralized, where they are fully controlled by the government and the healthcare providers. Owing to these and many other concerns, people are hesitant in the adoption of these technologies. This paper presents a detailed analysis of user tracking apps belonging to 32 countries, thus demonstrating that they collect personal data and are a gross violation of user privacy. This paper presents a novel architecture for the efficient, effective and privacy-preserving contact tracing of COVID-19 patients using blockchain. The proposed architecture preserves the privacy of individuals and their contact history by encrypting all the data specific to an individual using a privacy-preserving Homomorphic encryption scheme and storing it on a permissioned blockchain network. The contacts made with a COVID-19 positive patient are identified by performing search queries directly over the Homomorphic encrypted data stored in the blocks. Therefore, only those contacts that are suspected to be COVID-19 positive may be decrypted by the healthcare professional or government for further contact tracing/diagnosis and COVID-19 testing; thereby leading to enhanced privacy.
Purpose This paper aims to help information professionals understand the foundational concepts of this technology and how these are related to libraries so that they can evolve services alongside it. Design/methodology/approach This column will define what a non-fungible tokens (NFT) is, explore the relevant trends impacting its development and examine how it intersects with the traditional roles of the library. Findings NFTs represent a new and growing technology that intersections with many of the same concepts that are core to librarianship. Libraries are community institutions that engender widespread trust, whereas NFTs are built atop cryptocurrency that seeks to enable anonymous peer-to-peer interactions. Originality/value Summary.
Philipp Winter, Anna Harbluk Lorimer, Peter Snyder, Benjamin Livshits
Much of the recent excitement around decentralized finance (DeFi) comes from hopes that DeFi can be a secure, private, less centralized alternative to traditional finance systems but the accuracy of these hopes has to date been understudied; people moving to DeFi sites to improve their privacy and security may actually end up with less of both.
In this work, we improve the state of DeFi by conducting the first measurement of the privacy and security properties of popular DeFi applications. We find that DeFi applications suffer from the same kinds of privacy and security risks that frequent other parts of the Web. For example, we find that one common tracker has the ability to record Ethereum addresses on over 56% of websites analyzed. Further, we find that many trackers on DeFi sites can trivially link a user's Ethereum address with PII (e.g., name or demographic information) or phish users.
This work also proposes remedies to the vulnerabilities we identify, in the form of improvements to the most common cryptocurrency wallet. Our wallet modification replaces the user's real Ethereum address with site-specific addresses, making it harder for DeFi sites and third parties to (i) learn the user's real address and (ii) track them across sites.
Philipp Winter, Anna Harbluk Lorimer, Peter J. Snyder, Benjamin Livshits
Much of the recent excitement around decentralized finance (DeFi) comes from hopes that DeFi can be a secure, private, less centralized alternative to traditional finance systems. However, people moving to DeFi sites in hopes of improving their security and privacy may end up with less of both as recent attacks have demonstrated. In this work, we improve the understanding of DeFi by conducting the first Web measurements of the security, privacy, and decentralization properties of popular DeFi front ends. We find that DeFi applications -- or dapps -- suffer from the same security and privacy risks that frequent other parts of the Web but those risks are greatly exacerbated considering the money that is involved in DeFi. Our results show that a common tracker can observe user behavior on over 56% of websites we analyzed and many trackers on DeFi sites can trivially link a user's Ethereum address with PII (e.g., user name or demographic information), or phish users by initiating fake Ethereum transactions. Lastly, we establish that despite claims to the opposite, because of companies like Amazon and Cloudflare operating significant Web infrastructure, DeFi as a whole is considerably less decentralized than previously believed.
Vincent Schlatt, Johannes Sedlmeir, Janina Traue, Fabiane Völter
The digital transformation of the medical sector requires solutions that are convenient and efficient for all stakeholders while protecting patients' sensitive data. One example that has already attracted design-oriented research are medical prescriptions. However, current implementations of electronic prescription management systems typically create centralized data silos, leaving user data vulnerable to cybersecurity incidents and impeding interoperability. Research has also proposed decentralized solutions based on blockchain technology, but privacy-related challenges have often been ignored. We conduct design science research to develop and implement a system for the exchange of electronic prescriptions that builds on two blockchains and a digital wallet app. Our solution combines the bilateral, verifiable, and privacy-focused exchange of information between doctors, patients, and pharmacies through verifiable credentials with a token-based, anonymized double-spending check. Our qualitative and quantitative evaluations as well as a security analysis suggest that this architecture can improve existing approaches to electronic prescription management by offering patients control over their data by design, a high level of security, sufficient performance and scalability, and interoperability with emerging digital identity management solutions for users, businesses, and institutions. We also derive principles on how to design decentralized, privacy-oriented information systems that require both the exchange of sensitive information and double-usage protection.
Background: Academic literature on blockchains has focused on Bitcoin, which is traditionally associated with right-wing libertarianism. This article looks at Ethereum, an alternative that emerged in Canada and is now the second most used blockchain technology after Bitcoin. Analysis: Using participatory observation supplemented with publicly available material, this article examines the ideologies and imaginaries surrounding Ethereum and how they are articulated with its technical design. Conclusion and implications: Ethereum’s design ostensibly widens the ideological spectrum of cryptocurrency while “masking” certain currency ideologies still prominent within it. This complicates the distinction seen in the literature between blockchain as currency and blockchain as media and points to the increasing need to study non-currency-based blockchain technologies.
The Senate's proposed infrastructure legislation includes a controversial section (Act § 80603) concerning information reporting for brokers and digital assets. If this (or similar) legislation is passed, the federal tax law concerning cryptocurrency will be significantly augmented. The provision is intended to generate $28 billion over 10 years, to help fund the infrastructure projects and reduce the tax gap.
Safely keeping the account’s private key is vital in blockchain technology, as there are no native blockchain mechanisms for recovering the account when the private key is lost. Therefore, this paper proposes a solution to this problem, running directly on the blockchain platform in the form of a smart contract, enabling deposit of digital assets into the contract for safekeeping, along with a list of security questions. The proposed solution can be used, for example, in online games. By providing proof of knowing answers to questions, a player can access his account without his private key. Furthermore, additional security measures are put in place to cope with malicious behaviour.
Traditional accounts and passwords mechanism usually needs to register multiple accounts for adopting different scenarios, which makes it difficult to manage passwords and handle privacy leakage issues. On the other hand, users have no real control over their identities under centralized trusted authorities or insecure third-party operators. In this paper, we propose a self-sovereign decentralized identity platform called SSIChain. SSIChain uses distributed infrastructure blockchain to replace authorities and third-party operators. In the proposed platform, the DID and a credential represent an user's digital identity. We define DID chaincode and credential protocol to cover the full lifecycle of a user's digital identity. We build a complete consortium blockchain and application environment, and implement a prototype as an App for Android-based phones. Moreover, we detect that SSIChain only takes at most 2.1 seconds for authentication with high TPS, which can meet users' demands for identity management well.
Ye Seul Bae, Yujin Park, Taekhoon Kim, Taehoon Ko · 8 authors
The concept of MyData emerged as a paradigm shift in personal data management and the process of seeking to transform the current organization-centered system. MyData enables the utilization of one’s own personal information that is scattered among various institutions as a system for data subjects to exercise rights of self-determination. We aimed to develop and demonstrate a MyData platform (MyHealthData) that allows data subjects to download and manage health-related personal data stored in various medical institutions. The platform consists of a mobile app for users, API (application–program interface) for data conversion and exchange installed in the hospital information system (HIS), and a relay server connected to the blockchain to ensure data integrity. User surveys were conducted to explore perceived usefulness, perceived ease of use, and satisfaction. We provided four services to users through the platform developed in this study: inquiring about medical and health checkup records, health coaching, checking conditions of participation in clinical research, and claims, all by using an app. A total of 1228 participants signed up for the service and the overall user satisfaction was high, especially with ‘inquire about medical and health checkup records’. MyData brings a user-centered paradigm in which data subjects can directly participate in the use of their own data. MyData will improve healthcare data interoperability, allowing it to be used not only in research areas but also in other areas by sharing and integrating various healthcare data.
Internet of Things (IoT) applications are becoming more integrated into our society and daily lives, although many of them can expose the user to threats against their privacy. Therefore, we find that it is crucial to address the privacy requirements of most of such applications and develop solutions that implement, as far as possible, privacy by design in order to mitigate relevant threats. While in the literature we may find innovative proposals to enhance the privacy of IoT applications, many of those only focus on the edge layer. On the other hand, privacy by design approaches are required throughout the whole system (e.g., at the cloud layer), in order to guarantee robust solutions to privacy in IoT. With this in mind, we propose an architecture that leverages the properties of blockchain, integrated with other technologies, to address security and privacy in the context of IoT applications. The main focus of our proposal is to enhance the privacy of the users and their data, using the anonymisation properties of blockchain to implement user-controlled privacy. We consider an IoT application with mobility for smart vehicles as our usage case, which allows us to implement and experimentally evaluate the proposed architecture and mechanisms as a proof of concept. In this application, data related to the user's identity and location needs to be shared with security and privacy. Our proposal was implemented and experimentally validated in light of fundamental privacy and security requirements, as well as its performance. We found it to be a viable approach to security and privacy in IoT environments.
Federico Daidone, Barbara Carminati, Elena Ferrari
The Internet of Things (IoT) pervades our lives every day and has given end users the opportunity of accessing personalized and advanced services based on the analysis of the sensed data. However, IoT services are also characterized by new challenges related to security and privacy because end users often share sensitive data with different consumers without precise knowledge of how they will be managed and used. To cope with these issues, we propose a blockchain-based privacy enforcement framework where users can define how their data can be used and check if their will is respected without relying on a centralized manager. The preliminary tests we performed, simulating different scenarios, show the feasibility of our approach.
Mwrwan Abubakar, Zakwan Jaroucheh, Ahmed Al Dubai, Bill Buchanan
Recent years have seen an increase in medical big data, which can be attributed to a paradigm shift experienced in medical data sharing induced by the growth of medical technology and the Internet of Things. The evidence of this potential has been proved during the recent covid-19 pandemic, which was characterised by the use of medical wearable devices to help with the medical data exchange between the healthcare providers and patients in a bid to contain the pandemic. However, the use of these technologies has also raised questions and concerns about security and privacy risks. To assist in resolving this issue, this paper proposes a blockchain-based access control framework for managing access to users’ medical data. This is facilitated by using a smart contract on the blockchain, which allows for delegated access control and secure user authentication. This solution leverages blockchain technology’s inherent autonomy and immutability to solve the existing access control challenges. We have presented the solution in the form of a medical wearable sensor prototype and a mobile app that uses the Ethereum blockchain in a real data sharing control scenario. Based on the empirical results, the proposed solution has proven effective. It has the potential to facilitate reliable data exchange while also protecting sensitive health information against potential threats. When subjected to security analysis and evaluation, the system exhibits performance improvements in data privacy levels, high security and lightweight access control design compared to the current centralised access control models.
After the General Data Protection Regulation (GDPR) was introduced, some organizations and big data companies shared data without conducting any privacy protection and compliance authentication, which endangered user data security, and were punished financially for this reason. This study proposes a blockchain-based GDPR compliance data sharing scheme, aiming to promote compliance with regulations and provide a tool for interaction between users and service providers to achieve data security sharing. The zero-knowledge Succinct Non-Interactive Arguments of Knowledge (zk-SNARK) algorithm is adopted for protecting data and ensure that the user’s private data can satisfy the individual requirements of the service provider without exposing user data. The proposed scheme ensures mutual authentication through the Proof of Authority consensus based on the Committee Endorsement Mechanism (CEM-PoA), and prevents nodes from doing evil using the reputation incentive mechanism. Theoretical analysis and performance comparison indicate that the scheme meets the confidentiality, availability, and other indicators. It has superiority in efficiency and privacy protection compared with other schemes.
It is widely argued that Blockchain Technology (BCT) is one of the most promising trends nowadays. The most prominent characteristic of this technology is the improved sense of trust to the shared information provided by BCT applications as well as the ubiquitous access to the data ledger. At the same time governments pursue amplified trust from their citizens increasing transparency through shared information and open data. Since BCT supports this strategic goal of governments worldwide, numerous governments try to capitalize on the advances of this technology through testing the results of pilot applications in different vertical governmental sectors. Even though there are several implementations in the Government sector, there is no comprehensive study towards the analysis of the major characteristics of these developments. This paper moves towards the fulfillment of this gap by conducting a thorough analysis of e-Government pilot applications of BCT at a European level providing information to policymakers and practitioners about the grey areas of this technology.
Siddhartha Sen, Sripati Mukhopadhyay, Sunil Karforma
In recent years, the most cutting edges and promising technology emerged is Blockchain. It has huge potential to impact various industries. The append-only distributed ledger technology (DLT) and the consensus mechanism of Blockchain can also change the dimension of E-Governance. The Electronic Property Record (EPR) systems of government have challenges like data security, integrity, secure storage of data and automated service delivery. In this paper, we discuss how Smart Contract based Blockchain technology can effectively be used to address the challenges of EPR System over the existing available systems. We propose a Smart Contract based permissioned blockchain framework which is an innovative approach, especially in the Electronic Property Registration domain of E-Governance in India. The objective of our proposed framework is firstly to implement Smart Contract solving the security problems like confidentiality, integrity, authentication, and secondly to ensure secure storage of electronic records by defining access rules for the stakeholders of the proposed framework. Moreover, we address the issues of single-point-of-failure, data inter-operability between the organizations involved for sharing and verification of property information among various stakeholders.
Zhenquan Qin, Ye Jin, Jie Meng, Bingxian Lu · 5 authors
The marine Internet of things (MIoT) is the application of the Internet of things technology in the marine field. Nowadays, with the arrival of the era of big data, the MIoT architecture has been transformed from cloud computing architecture to edge computing architecture. However, due to the lack of trust among edge computing participants, new solutions with higher security need to be proposed. In the current solutions, some use blockchain technology to solve data security problems while some use federated learning technology to solve privacy problems, but these methods neither combine with the special environment of the ocean nor consider the security of task publishers. In this article, we propose a secure sharing method of MIoT data under an edge computing framework based on federated learning and blockchain technology. Combining its special distributed architecture with the MIoT edge computing architecture, federated learning ensures the privacy of nodes. The blockchain serves as a decentralized way, which stores federated learning workers to achieve nontampering and security. We propose a concept of quality and reputation as the metrics of selection for federated learning workers. Meanwhile, we design a quality proof mechanism [proof of quality (PoQ)] and apply it to the blockchain, making the edge nodes recorded in the blockchain more high-quality. In addition, a marine environment model is built in this article, and the analysis based on this model makes the method proposed in this article more applicable to the marine environment. The numerical results obtained from the simulation experiments clearly show that the proposed scheme can significantly improve the learning accuracy under the premise of ensuring the safety and reliability of the marine environment.
Aisha Zahid Junejo, Manzoor Ahmed Hashmani, Mehak Maqbool Memon
With the widespread of blockchain technology, preserving the anonymity and confidentiality of transactions have become crucial. An enormous portion of blockchain research is dedicated to the design and development of privacy protocols but not much has been achieved for proper assessment of these solutions. To mitigate the gap, we have first comprehensively classified the existing solutions based on blockchain fundamental building blocks (i.e., smart contracts, cryptography, and hashing). Next, we investigated the evaluation criteria used for validating these techniques. The findings depict that the majority of privacy solutions are validated based on computing resources i.e., memory, time, storage, throughput, etc., only, which is not sufficient. Hence, we have additionally identified and presented various other factors that strengthen or weaken blockchain privacy. Based on those factors, we have formulated an evaluation framework to analyze the efficiency of blockchain privacy solutions. Further, we have introduced a concept of privacy precision that is a quantifiable measure to empirically assess privacy efficiency in blockchains. The calculation of privacy precision will be based on the effectiveness and strength of various privacy protecting attributes of a solution and the associated risks. Finally, we conclude the paper with some open research challenges and future directions. Our study can serve as a benchmark for empirical assessment of blockchain privacy.
Purpose Blockchain is evolving to become a platform for securing Internet of things (IoT) ecosystems. Still, challenges remain. The purpose of this literature review is to highlight the applicability of blockchain as a medium to secure IoT ecosystems. A two-dimensional framework anchored on (1) IoT layers and (2) security goals is used to organize the existent IoT security threats and their corresponding countermeasures identified in the reviewed literature. The framework helped in mapping the IoT security threats with the inherent features of blockchain and accentuate their prominence to IoT security. Design/methodology/approach An approach integrating computerized natural language processing (NLP) with a systematic literature review methodology was adopted. A large corpus of 2,303 titles and abstracts of blockchain articles was programmatically analyzed in order to identify the relevant literature. The identified literature was subjected to a systematic review guided by a well-established method in IS research. Findings The literature evidently highlights the prominence of blockchain as a mean to IoT security due to the distinctive features it encompasses. The authors’ investigation revealed that numerous existent threats are better addressed with blockchain than conventional mechanisms. Nevertheless, blockchain consumes resources such as electricity, time, bandwidth and disk space at a rate that is not yet easily accessible to common IoT ecosystems. Research limitations/implications Results suggest that a configurational approach that aligns IoT security requirements with the resource requirements of different blockchain features is necessary in order to realize the proper balance between security, efficiency and feasibility. Practical implications Practitioners can make use of the classified lists of convention security mechanisms and the IoT threats they address. The framework can help underline the countermeasures that best achieve their security goals. Practitioners can also use the framework to identify the most important features to seek for in a blockchain technology that can help them achieve their security goals. Originality/value This study proposes a novel framework that can help classify IoT threats based on the IoT layer impacted and the security goal at risk. Moreover, it applies a combined man-machine approach to systematically analyze the literature.