Jan 1, 2021·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Francesca Fallucchi, Marco Gerardi, Michele Petito, Ernesto William De Luca
In an ever more digitized world where information and data are increasingly dematerialized, the question of how to certify intellectual property and define when a document has been created or modified without the presence of any third-party guarantor inevitably arises. This document proposes a decentralized method that, by exploiting blockchain technology and distributed peer-to-peer (P2P) networks, makes it possible to historicize information in such a way that it is not possible for a user to alter its dating, attribute ownership or modify it by impersonating the author. The data certification (document, image, film, data archive, etc.) takes place through the creation of an immutable relationship between the owner and the data. At the legal level, many countries are beginning to regulate blockchain technology so that it can be used in many areas, such as the production chain, the Internet of Things or Public Administration. In this paper we present a solution to promote digital government and greater transparency, through the use of a framework based on the Ethereum blockchain, smart contracts and a decentralized application.
In this paper, we explore access control area as one of the most crucial aspect of security and privacy in IoT. Actually, conventional security and privacy solutions tend to be less tailored for IoT. Then, designing a distributed access control with user-driven approach and privacy-preserving awareness in an IoT environment is of paramount importance. In this direction, we have investigated in our previous work a new way to build a distributed access control framework based on the blockchain technology through our proposed framework, FairAccess. The first version of FairAccess was based on the Bitcoin's UTXO model. However, this version presented limitations in expressing more granular access control policies. To tackle this issue, this paper upgrades the proposed framework to FairAccess2.0 that uses SmartContract concept instead of the locking/unlocking scripts. Thus, we show a possible working implementation based on ABAC policies, deployed on the ethereum blockchain. The obtained results show the efficiency of FairAccess2.0 and its compatibility with a wide range of existing access control models mainly the ABAC model. Finally, a performance and cost evaluation, discussion and future work are elaborated.
The advent of a retail central bank digital currency (CBDC) could reshape the US payments system. A retail CBDC would be a digital representation of the US dollar in the form of an account or token that is widely accessible to the general public. It would be a third form of US fiat money that is created and issued by the Federal Reserve and complementary to physical cash. CBDC proposals have suggested a myriad of retail CBDC design models with an overwhelming interest in a retail CBDC that either implements a centralized ledger system or some form of a distributed ledger system to process payments. The technology of a retail CBDC would enable instantaneous payments for consumers and greater transparency for government officials. Additionally, CBDC proponents are championing retail CBDC as a tool to promote financial inclusion. However, antiquated US privacy protections may be inadequate to safeguard against the potential risks to individual privacy within digital payments and consequently undermine financial inclusion. A retail CBDC system that is under the control of the Federal Reserve could bolster regulatory compliance and oversight but also exacerbate workarounds by government entities in the current US privacy framework that are concerning for individual privacy in the age of big data and dataveillance. A proper privacy framework governing retail CBDC records would alleviate risks to privacy and enhance public trust in a retail CBDC system. Refining the Privacy Act of 1974 or creating a new regulatory framework that is informed by both the Privacy Act and the impact of innovative data analytics would help balance the inherent tension between privacy and transparency of user identity and transactions within a retail CBDC system under the control of the Federal Reserve.
Recently, the right to privacy has become an important global issue, and laws are being enacted in different countries to ensure that citizens have control over how their data are stored and used. In this scenario, corporates face an increasing burden to comply with these laws, while ensuring that their business models and workflows are interrupted to as little a degree as possible. This article presents blockchain as a potential technology that can help users keep their data under their control and yet allow companies to responsibly access the data they need to function. It begins with an overview of blockchain as a technology and the properties that make it useful as a tool for privacy compliance. It then explores more niche fields, such as Zero Knowledge Proofs, and considers two industries where blockchain can be of benefit to consumers and corporates from a privacy standpoint.
Oyinomomo-emi Emmanuel Akpe, Denis Kisina, Samuel Owoade, Abel Chukwuemeke Uzoka · 6 authors
The increasing complexity of digital platforms, driven by cloud-native architectures, distributed applications, and user-centric services, necessitates robust, scalable, and secure identity management frameworks. This paper explores recent advances in federated authentication and identity management, emphasizing their role in enabling seamless and secure access across interconnected digital ecosystems. Beginning with a foundational overview of identity management’s evolution—from traditional siloed systems to federated and decentralized models—the study outlines key technologies such as SAML, OAuth, OpenID Connect, and emerging paradigms like decentralized identity and blockchain-based verification. It further investigates the integration of artificial intelligence and machine learning for adaptive authentication, anomaly detection, and risk-based decision-making, alongside privacy-enhancing technologies ensuring compliance with data protection regulations such as GDPR. Through the examination of scalability, interoperability, and security challenges, the paper identifies best practices and architectural strategies critical for real-world implementations. The discussion culminates in practical implications for industry adoption across sectors such as healthcare, finance, and e-commerce, and highlights future research directions including the development of standardized identity frameworks, AI integration, and decentralized identity systems in multi-cloud and edge computing environments. This study offers a comprehensive synthesis of current trends and technologies that are shaping the next generation of identity management in scalable digital platforms.
Myeonghyun Kim, Joonyoung Lee, Kisung Park, Yohan Park · 6 authors
Car-sharing systems can solve various urban problems by providing shared vehicles to people and reducing the operation of personal vehicles. With the development of the Internet of Things, people can easily use a shared car through simple operations on their mobile devices. However, the car-sharing system has security problems. Sensitive information, such as the user’s identity, location information, and access code, is transmitted through a public channel for car-sharing. Hence, an attacker can access this information for illegal purposes, making the establishment of a secure authentication protocol essential. Furthermore, the traditional car-sharing system is established on the centralized structure, so there is a single point of failure. Thus, the design of a decentralized car-sharing scheme is vital for solving the centralized problem. This study designed a decentralized car-sharing scheme using blockchain. Specifically, blockchain technology was used to provide a decentralization car-sharing service and ensure data integrity. The participant entities of the proposed system can be authenticated anonymously. The proposed car-sharing system can be secured against various attacks and provide mutual authentication using informal analysis, automated validation of internet security protocols and applications (AVISPA) simulation, and BAN logic analysis. The computation costs and communication costs of the proposed scheme were also analyzed.
Geoffrey Goodell, Hazem Danny Al-Nakib, Paolo Tasca
Objective : to present the new approach to perform monetary transactions with digital currency. Methods : abstract-logical, analytical methods. Results : in recent years, electronic retail payment mechanisms, especially e-commerce and card payments at the point of sale, have increasingly replaced cash in many developed countries. As a result, societies are losing a critical public retail payment option, and retail consumers are losing important rights associated with using cash. To address this concern, we propose an approach to digital currency that would allow people without banking relationships to transact electronically and privately, including both e-commerce purchases and point-of-sale purchases that are required to be cashless. The article shows the advantages of cash payments compared to non-cash ones and defines the possibility to transform these advantages into the central bank digital currencies. The disputable issues of commercial banks development under the spread of digital currencies are discussed. The architecture of digital currencies is described, including distributed ledgers technology. It was shown that, for the digital currency to function effectively, it is necessary to include the privacy of end-users into its architecture; measures to achieve that are determined. Scientific novelty : the approached proposed in the article should be used to develop the digital currencies infrastructure. It should be government-backed, privately-operated and ensure that every transaction is registered by a bank or money services business, relying upon non-custodial wallets backed by privacy-enhancing technology, such as blind signatures or zero-knowledge proofs, to ensure that transaction counterparties are not revealed. This approach can also facilitate more efficient and transparent clearing, settlement, and management of systemic risk. We argue that our system can restore and preserve the salient features of cash, including privacy, owner-custodianship, fungibility, and accessibility, while also preserving fractional reserve banking and the existing two-tiered banking system. Practical significance : the proposed approach can be applied in the practical organization of perform monetary transactions using digital currencies. The article was first published in English language by Future Internet. For more information please contact the editorial office. For original publication: Goodell G., Al-Nakib H. D., Tasca P. A Digital Currency Architecture for Privacy and Owner-Custodianship, Future Internet, 2021, 13, 130. https://doi.org/10.3390/fi13050130 Publication URL: https://www.mdpi.com/1999-5903/13/5/130
The rapid development of wearable sensors and the 5G network empowers traditional medical treatment with the ability to collect patients’ information remotely for monitoring and diagnosing purposes. Meanwhile, the health‐related mobile apps and devices also generate a large amount of medical data, which is critical for promoting disease research and diagnosis. However, medical data is too sensitive to share, which is also a common issue for IoT (Internet of Things) data. The traditional centralized cloud‐based medical data sharing schemes have to rely on a single trusted third party. Therefore, the schemes suffer from single‐point failure and lack of privacy protection and access control for the data. Blockchain is an emerging technique to provide an approach for managing data in a decentralized manner. Especially, the blockchain‐based smart contract technique enables the programmability for participants to access the data. All the interactions are authenticated and recorded by the other participants of the blockchain network, which is tamper resistant. In this paper, we leverage the K‐anonymity and searchable encryption techniques and propose a blockchain‐based privacy‐preserving scheme for medical data sharing among medical institutions and data users. To be specific, the consortium blockchain, Hyperledger Fabric, is adopted to allow data users to search for encrypted medical data records. The smart contract, i.e., the chaincode, implements the attribute‐based access control mechanisms to guarantee that the data can only be accessed by the user with proper attributes. The K‐anonymity and searchable encryption ensure that the medical data is shared without privacy leaking, i.e., figuring out an individual patient from queries. We implement a prototype system using the chaincode of Hyperledger Fabric. From the functional perspective, security analysis shows that the proposed scheme satisfies security goals and precedes others. From the performance perspective, we conduct experiments by simulating different numbers of medical institutions. The experimental results demonstrate that the scalability and performance of our scheme are practical.
The idea of smart contracts has been around for a long time. The introduction of Ethereum has taken the concept of smart contracts to new heights because of its integration with Blockchain technology. As a result, the applications of smart contracts have also surged in areas such as e-Voting, Insurance, Crowdfunding, etc. In this paper, we aim to present the construction of a “Fully Anonymous e-Voting” protocol using the concepts of zkHawk and Zcash. zkHawk is a novel smart contract protocol designed during this Ph.D. that improves upon the Hawk protocol by solving the underlying anonymity problem of a trusted manager. We will leverage the concept of zk-SNARKs in Zcash to carry out the voting phase of the election and the zkHawk smart contract protocol to tally the results of the election. The voting phase employing Zcash will be initially designed with Non-Universal zk-SNARKs and improved upon with Universal zk-SNARKs.
2 source records
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
In der Anfangszeit der Distributed Ledger Technologies (DLT) waren die hauptsächlichen Betrachtungswinkel die der Disruption des Bank- und Finanzwesens. Mit dem Aufkommen des Systems Ethereum im Jahr 2015, hat die Auseinandersetzung mit der Anwendung von Blockchain in weiteren Branchen, an Bedeutung gewonnen. Eine davon ist die Logistik und das Supply Chain Management (SCM). Gerade in Deutschland spielt der Logistiksektor eine große Rolle, nach der Beschäftigtenzahl ist er die drittgrößte Branche und erzielt einen Umsatz von rund 258 Milliarden Euro. Im Beitrag werden konkrete Anwendungsfelder identifiziert und gezeigt welche potentiellen Vorteile sich dort, durch den Einsatz von DLT, erzielen lassen. Ein Schwerpunkt liegt dabei auf der Einschätzung der Technologie hinsichtlich ihrer Sicherheitseigenschaften. Im Beitrag wird den Fragen nachgegangen, ob Datensicherheit mithilfe von DLT verbessert werden kann und auf welchem Wege.
In this paper, we explore access control area as one of the most crucial aspect of security and privacy in IoT. Actually, conventional security and privacy solutions tend to be less tailored for IoT. Then, designing a distributed access control with user-driven approach and privacy-preserving awareness in an IoT environment is of paramount importance. In this direction, we have investigated in our previous work a new way to build a distributed access control framework based on the blockchain technology through our proposed framework, FairAccess. The first version of FairAccess was based on the Bitcoin's UTXO model. However, this version presented limitations in expressing more granular access control policies. To tackle this issue, this paper upgrades the proposed framework to FairAccess2.0 that uses SmartContract concept instead of the locking/unlocking scripts. Thus, we show a possible working implementation based on ABAC policies, deployed on the ethereum blockchain. The obtained results show the efficiency of FairAccess2.0 and its compatibility with a wide range of existing access control models mainly the ABAC model. Finally, a performance and cost evaluation, discussion and future work are elaborated.
In recent years, the use of the internet to vote has become popular and several governments in Europe and worldwide are intending to experiment with it. Online voting is becoming more popular in today’s culture. Many people are currently benefiting from cold digital technologies. Unlike the election system, it makes far more frequent use of paper. A standard (offline) method poses a security and transparency risk to popular elections. National elections are still centralized, with only one political party in authority. One of the main issues with traditional election systems is the organization that has complete control over the website and system, which might disrupt the database of many opportunities. Because we accept a separate system and the complete database is handled by many people, blockchain technology is one of the answers. The blockchain technology has been employed in a Bitcoin system called as a separate Bank. One of the most fraudulent sources on a website can be reduced by using a blockchain in the distribution of information on electronic voting systems. This research examines the use of a blockchain algorithm to record vote results at all polling sites. It’s no longer necessary to print ballot sheets or open polling stations. The goal of this research is to look into the use of blockchain as an electronic voting mechanism.In this paper, an e-trust voting system is divided into blockchain. The classification system means that the calculation depends on the blockchain segmentation. The voter does not have to trust the election administration in an unreliable system, and the trust is divided among all voters. The entire protocol affects system accuracy. Furthermore, all voters will have cryptographic assurance that their privacy will be safeguarded. The article covers the needs for developing electronic voting systems and identifies legal and technical barriers to employing blockchain as a monitoring service for such systems.
N. Banupriya, G. Pooja, S. Nevetha, J. Roopini · 5 authors
In the expeditiously advancing technological world, with the advent of IoT and big data, every day new people and devices which store highly sensitive personal data are getting connected. For instance, your Google home is listening to you and collecting data, your Facebook knows a lot about you; Amazon's Alexa gets to know our everyday wants. This implies that our data is used to spy on us for advertising purposes, hence these siren servers make the overall profit off us. This paper throws light on developing a dApp (decentralised application) that could be used in a voting system. Everything around us is digitising which does not mean we are moving towards a safe and secured scheme, thus the revolutionary Blockchain technology is used to deploy an e-voting system (Giorgino, 2018) and this is done using the Ethereum Blockchain (Wang et al., 2018).
Central banks and governments all over the world are increasingly exploring digital versions of fiat money, known as retail Central Bank Digital Currencies (CBDCs). Most initiatives rely on Distributed Ledger Technologies and are presented as alternatives to physical cash. Consequently, anonymity-related regulatory questions have naturally started to arise in terms of Anti-Money Laundering and Counter-Terrorist Financing compliance. Against this backdrop, this paper provides a techno-legal taxonomy of approaches to balance privacy and transparency in CBDCs without thwarting accountability, but it also underlines cross-sectoral impacts. The contribution heeds regulation-by-design as its core methodological foundation, with Privacy-Enhancing Technologies as the relevant use case. Thus, it highlights that not only technology aids legal purposes, but also that some regulatory requirements ought to be designed into technology for one to reach agreed-upon results and/or standards.
Alexander A. Varfolomeev, Liwa H. Al-Farhani, Zahraa Ch. Oleiwi
Over time, our lives turn to digitization and technology and its multiple applications and uses. The smart city, its technologies and the services provided during it have become a way of life. The idea of smart cities relied on different mechanisms to provide reliable services. One of the important technologies is the blockchain that has proven to be extremely reliable and has a high security level technology. This paper presents a mechanism to explain the application of blockchain technology in smart contracts, how to increase reliability, data security, and many positive benefits as part of the multiple services provided by the smart city environment. This paper also provides important details about this technology and its impact on the overall administrative system of any service provided by smart governments. The paper dealt with an example of how to manage the real estate rental file electronically to explain the advantages of blockchain technology through which we overcome existing problems in this type of contract and service.
The development of artificial intelligence and worldwide epidemic events has promoted the implementation of smart healthcare while bringing issues of data privacy, malicious attack, and service quality. The Medical Internet of Things (MIoT), along with the technologies of federated learning and blockchain, has become a feasible solution for these issues. In this paper, we present a blockchain-based federated learning method for smart healthcare in which the edge nodes maintain the blockchain to resist a single point of failure and MIoT devices implement the federated learning to make full of the distributed clinical data. In particular, we design an adaptive differential privacy algorithm to protect data privacy and gradient verification-based consensus protocol to detect poisoning attacks. We compare our method with two similar methods on a real-world diabetes dataset. Promising experimental results show that our method can achieve high model accuracy in acceptable running time while also showing good performance in reducing the privacy budget consumption and resisting poisoning attacks.
The demand for IoT systems in healthcare services is increasing widely and the data generated from these networks should be transferred and stored in a highly secure manner. Blockchain technology helps in maintaining the privacy and integrity of the electronic health records (EHR) data with the help of smart contracts that authenticate the users and maintain confidentiality in the network. Integrating blockchain into IoT systems improves the overall security of the network. In this paper, we propose an architecture based on Hyperledger Fabric which is a private blockchain platform that is used for storing the EHR data which are collected from various IoT sensors. The deployed smart-contract helps in performing some of the basic database functionalities onto the blockchain.
Although blockchain-based digital services promise trust, accountability, and transparency, multiple paradoxes between blockchains and GDPR have been highlighted in the recent literature. Some of the recent literature also proposed possible solutions to these paradoxes. This article aims to conduct a systematic literature review on GDPR compliant blockchains and synthesize the findings. In particular, the goal was to identify 1) the GDPR articles that have been explored in prior literature; 2) the relevant research domains that have been explored, and 3) the research gaps. Our findings synthesized that the blockchains relevant GDPR articles can be categorized into six major groups, namely data deletion and modification (Article 16, 17, and 18), protection by design by default (Article 25), responsibilities of controllers and processors (Article 24, 26, and 28), consent management (Article 7), data processing principles and lawfulness (Article 5,6 and 12), and territorial scope (Article 3). We also found seven research domains where GDPR compliant blockchains have been discussed, which include IoT, financial data, healthcare, personal identity, online data, information governance, and smart city. From our analysis, we have identified a few key research gaps and present a future research direction.