The Internet of Things (IoT) paradigm has integrated the sensor network silos to the Internet and enabled the provision of value-added services across these networks. These smart devices are now becoming socially conscious by following the social Internet of Things (SIoT) model that empowers them to create and maintain social relationships among them. The Social Internet of Vehicle (SIoV) is one application of SIoT in the vehicular domain that has evolved the existing intelligent transport system (ITS) and vehicular ad-hoc networks (VANETs) to the next phase of Intelligent by adding socializing aspect and constant connectivity. SIoV generates a massive amount of real-time data enriched with context and social relationship information about vehicles, drivers, passengers, and the surrounding environment. Therefore, the role of privacy management becomes essential in SIoV, as data is collected and stored at different layers of its architecture. The challenge of privacy is aggravated because the dynamic nature of SIoV poses a major threat in its adoption. Motivated by the need to address these aspects, this paper identifies the challenges involved in managing privacy in SIoV. Furthermore, the paper analyzes the privacy issues and factors that are essential to be considered for preserving privacy in SIoV environments from different perspectives including the privacy of a person, behavior and action, communication, data and image, thoughts and feelings, location and space, and association. In addition, the paper discusses the blockchain-based solutions to preserve privacy for SIoV.
Ahmed Raza Rajput, Qianmu Li, Milad Taleby Ahvanooey, Isma Masood
Personal health records (PHRs) are private and vital assets for every patient. There have been introduced many works on various aspects of managing and organizing the PHR so far. However, there is an uncertain remaining issue for the role of PHR in emergencies. In a traditional emergency access system, the patient cannot give consent to emergency staff for accessing his/her PHR. Moreover, there is no secured record management of patient's PHR, which reveals highly confidential personal information, such as what happened, when, and who has access to such information. This paper proposes an emergency access control management system (EACMS) based on permissioned blockchain hyperledger fabric and hyperledger composer. In the proposed system, we defined some rules using the smart contracts for emergency condition and time duration for the emergency access PHR data items that patient can assign some limitations for controlling the PHR permissions. We analyzed the performance of our proposed framework by implementing it through the hyperledger composer based on the response time, privacy, security, and accessibility. The experiments confirm that our framework provides better efficiency compared with the traditional emergency access system.
Blockchain startups are basing their business models on disrupting the centralized way of data storage by highlighting the value of data to the public. A distributed approach to storing data is the safer way to prevent attacks is what is being evangelized. GAFA (Google, Apple, Facebook, Amazon) have monopolized data, therefore bringing in the most revenue whilst depriving the data generators of any form of compensation. In our work, we propose a platform where a user can store his/her own personal data. Here, we present to the user the right to decide what happens to their data. These decisions include selling, renting, and deleting data. The deletion of data undermines the fundamentals the blockchain is built on (data immutability). We address the issues of personal data sharing and how a user's right to delete his/her data can be enforced in a blockchain based network such as ours.
Mohsin Ur Rahman, Fabrizio Baiardi, Barbara Guidi, Laura Ricci
Decentralized Online Social Networks (DOSNs) have been proposed as an alternative solution to the current centralized Online Social Networks (OSNs). Online Social Networks are based on centralized architecture (e.g., Facebook, Twitter, or Google+), while DOSNs do not have a service provider that acts as central authority and users have more control over their information. Several DOSNs have been proposed during the last years. However, the decentralization of the OSN requires efficient solutions for protecting the privacy of users, and to evaluate the trust between users. Blockchain represents a disruptive technology which has been applied to several fields, among these also to Social Networks. In this paper, we propose a manageable, user-driven and auditable access control framework for DOSNs using blockchain technology. In the proposed approach, the blockchain is used as a support for the definition of privacy policies. The resource owner uses the public key of the subject to define flexible role-based access control policies, while the private key associated with the subject's Ethereum account is used to decrypt the private data once access permission is validated on the blockchain. We evaluate our solution by exploiting the Rinkeby Ethereum testnet to deploy the smart contract, and to evaluate its performance. Experimental results show the feasibility of the proposed scheme in achieving auditable and user-driven access control via smart contract deployed on the Blockchain.
ETH Zurich, Switzerland, Mathieu Chanson, Andreas Bogner, ETH Zurich, Switzerland · 8 authors
An ever growing variety of smart, connected Internet of Things (IoT) devices poses completely new challenges for businesses regarding security and privacy. In fact, the adoption of smart products may depend on the ability of organizations to offer systems that ensure adequate sensor data integrity while guaranteeing sufficient user privacy. In light of these challenges, previous research indicates that blockchain technology could be a promising means to mitigate issues of data security arising in the IoT. Building upon the existing body of knowledge, we propose a design theory, including requirements, design principles, and features, for a blockchain-based sensor data protection system (SDPS) that leverages data certification. To support this, we designed and developed an instantiation of an SDPS (CertifiCar) in three iterative cycles intented to prevent the fraudulent manipulation of car mileage data. Following the explication of our SDPS, we provide an ex post evaluation of our design theory considering CertifiCar and two additional use cases in the areas of pharmaceutical supply chains and energy microgrids. Our results suggest that the proposed design ensures the tamper-resistant gathering, processing, and exchange of IoT sensor data in a privacy-preserving, scalable, and efficient manner.
Current architectures to validate, certify, and manage identity are based on centralised, top-down approaches that rely on trusted authorities and third-party operators. We approach the problem of digital identity starting from a human rights perspective, with a primary focus on identity systems in the developed world. We assert that individual persons must be allowed to manage their personal information in a multitude of different ways in different contexts and that to do so, each individual must be able to create multiple unrelated identities. Therefore, we first define a set of fundamental constraints that digital identity systems must satisfy to preserve and promote privacy as required for individual autonomy. With these constraints in mind, we then propose a decentralised, standards-based approach, using a combination of distributed ledger technology and thoughtful regulation, to facilitate many-to-many relationships among providers of key services. Our proposal for digital identity differs from others in its approach to trust in that we do not seek to bind credentials to each other or to a mutually trusted authority to achieve strong non-transferability. Because the system does not implicitly encourage its users to maintain a single aggregated identity that can potentially be constrained or reconstructed against their interests, individuals and organisations are free to embrace the system and share in its benefits.
Jan 1, 2019·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Alexander Schoenhals, Thomas Hepp, Stephan Leible, Philip Ehret · 5 authors
The licensing of creative work is of broad and current interest. The European Commission proposes that when uploading a licensed digital work, the uploader should be checked by the system that one has the necessary rights. Technically this law is difficult to implement, as images with different intentions are shared, and even small changes like watermarks make it difficult to reveal similarities. The characteristics of distributed ledger technology could provide excellent support for the licensing and management of the rights of use. In this work, non-technical and technical criteria are defined to achieve an overview of the state-of-the-art solutions in the field of blockchain-based licensing platforms. Based on the criteria, different licensing platforms are reviewed, and the results are presented in a comparison matrix.
The challenge that journalism is facing these days in the Internet mobile environment is greater than ever before. Journalism is losing its revenue structure to platform operators favoring a certain markets, and also the trust of its readers in light of fake news and infected news. To alleviate this situation, we propose a blockchain technology that is applicable to journalism in order to achieve decentralization as a reasonable alternative. The journalism model based on hybrid blockchain aims to achieve the following: the delivery of articles with sharing value, what we call proof of sharing; the distribution of roles of personalized agenda settings; and finally, the use of agora to collect public opinions. With all these, we attempt to resolve the issues with current journalism with our proposed model based on blockchain.
Cryptocurrency mining in the browser has the potential to provide a new pay-as-you-go monetisation mechanism for consuming digital media over the Web. However, browser mining has recently received strong criticism due to illegitimate use of mining scripts in several popular websites (a practice called cryptojacking). Here we provide the first feasibility study of browser mining as a legitimate means of monetisation in terms of revenue, user consent and user experience within a specially built website. Our results compare browser mining to display advertisement and indicate browser mining provides a preferable user experience to advertising when the hash rate is user-adjustable. Furthermore, over 60% of participants would select browser mining over advertisement if they were invested in the ecosystem by obtaining half of the mined cryptocurrency. Our estimations show that browser mining currently generates revenue at a rate 46 times less than advertisement, however we would expect that gap to decrease as we observed a significant drop in mining difficulty after our tested cryptocurrency implemented ASIC-resistant mining measures. Overall, based on our results we find browser mining to be a legitimate alternative to display advertisement and conclude by discussing its current limitations and potential applications.
With the gradual promotion, crowdsourcing has become an efficient way to solve problems that are very complicated for computers and simple for human crowd intelligence in recent years. Traditional crowdsourcing is based on a central system where requesters post tasks on a crowdsourcing central server or platform, however, this centralized model currently faces various challenges such as prohibitive cost, single point of failure, and vulnerability to malicious attacks. To this end, this paper proposes a smart contract-based decentralized online crowdsourcing mechanism, which includes task assignment rules and reward payment rules, etc. The mechanism has the characteristics like decentralization, unalterable, truthfulness and so on. In addition, the corresponding smart contract is designed, so that the mechanism can really run and process the actual data, and the effectiveness is shown by experiments. In this way, the entire crowdsourcing process no longer requires the participation of trusted third-party agencies, information and privacy security is guaranteed, and the cost is lower.
Thomas Buocz, Tina Ehrke-Rabel, Elisabeth Hödl, Iris Eisenberger
This article uses the example of the cryptocurrency Bitcoin and the General Data Protection Regulation (GDPR) to show how distributed networks challenge existing legal mechanisms of allocating responsibility. The Bitcoin network stores personal data by automated means. Furthermore, full nodes qualify as establishments and the network offers a service to citizens in the EU. The data processing within the Bitcoin network therefore falls into the material and territorial scope of the GDPR. To protect data subjects, the GDPR allocates responsibility to the controller, who determines the ‘how’ and the ‘why’ of the data processing. However, the distributed structure of the Bitcoin network blurs the lines between actors who are responsible and actors who are worth protecting. Neither the Bitcoin users running lightweight nodes or full nodes nor the miners determine the ‘how’ and the ‘why’ of the data processing. They carry out their network activities according to the Bitcoin protocol, which can only be adopted and enforced by a collective of full nodes and miners. Members of this collective are joint controllers under Article 26 GDPR, which obliges them to clearly and transparently determine their respective responsibilities for compliance with the GDPR. However, this mechanism fails because of the very structure it aims to eliminate. Therefore, a solution to allocating responsibility for data protection in distributed networks lies outside the GDPR.
Abstract Electronic government (e-government) uses information and communication technologies to deliver public services to individuals and organisations effectively, efficiently and transparently. E-government is one of the most complex systems which needs to be distributed, secured and privacy-preserved, and the failure of these can be very costly both economically and socially. Most of the existing e-government systems such as websites and electronic identity management systems (eIDs) are centralized at duplicated servers and databases. A centralized management and validation system may suffer from a single point of failure and make the system a target to cyber attacks such as malware, denial of service attacks (DoS), and distributed denial of service attacks (DDoS). The blockchain technology enables the implementation of highly secure and privacy-preserving decentralized systems where transactions are not under the control of any third party organizations. Using the blockchain technology, exiting data and new data are stored in a sealed compartment of blocks (i.e., ledger) distributed across the network in a verifiable and immutable way. Information security and privacy are enhanced by the blockchain technology in which data are encrypted and distributed across the entire network. This paper proposes a framework of a decentralized e-government peer-to-peer (p2p) system using the blockchain technology, which can ensure both information security and privacy while simultaneously increasing the trust of the public sectors. In addition, a prototype of the proposed system is presented, with the support of a theoretical and qualitative analysis of the security and privacy implications of such system.
Abstract: Recent publications on the data protection aspects of blockchain technology focus on the characteristics of the initial public (Bitcoin) blockchain, and do so in a generalized manner. The authors then conclude that the characteristics of a public blockchain are profoundly incompatible at a conceptual level with the principles of the EU General Data Protection Regulation (GDPR). The GDPR requires identification of a central ‘controller’ who is responsible for compliance with the GDPR, while a public blockchain decentralizes the storage and processing of personal data, as a result whereof there is no such central point of control. For lack of a better alternative, the authors conclude that all ‘nodes’ involved in operating a blockchain qualify as a controller under the GDPR, raising enforcement and jurisdictional issues that make it impossible for individuals to enforce their rights. The transparency and immutability of a public blockchain would further not sit well with principles of data confidentiality, data minimization, data accuracy and the rights of individuals to correction and deletion of their data. I disagree with the analysis of these authors for a host of different reasons, the main one being that the authors focus on the shortcomings of the initial public (Bitcoin) blockchain when already many new types of permissioned private and consortium blockchain have been developed that significantly diverge from the original, permissionless public blockchain. In fact, these types of permissioned blockchain have been developed in response to the shortcomings of public blockchain. The authors further consider the data processing implications of blockchain as if this technology constitutes in itself a data processing activity for which a controller has to be identified. Controllership is, however, decided based on a specific use or deployment of a certain technology. Blockchain, like the internet, is a general-purpose technology that is subsequently deployed by actors for a certain purpose in a specific context. Applying the question of controllership to the internet at large would pose similar data protection issues under the GDPR as identified by the authors in respect of blockchain. This publication explains why none of these issues are currently hampering application of the GDPR to the internet and are equally unlikely to pose issues for blockchain applications. This publication describes the issues in their broader context, as well as how each of these issues can be addressed to ensure compliance with the GDPR. The conclusion is that the GDPR is also well able to regulate this new technology. This does not, however, mean that blockchain will thus be suitable for all use and deployment cases.
Data breaches are an increasingly common part of consumers’ lives. No institution is immune to the possibility of an attack. Each breach inevitably risks the release of consumers’ personally identifiable information and the strong possibility of identity theft. Unfortunately, current solutions for handling these incidents are woefully inadequate. Private litigation like consumer class actions and shareholder lawsuits each face substantive legal and procedural barriers. States have their own data security and breach notification laws, but there is currently no unifying piece of legislation or strong enforcement mechanism. This Note argues that proactive solutions are required. First, a national data security law—setting minimum data security standards, regulating the use and storage of personal information, and expanding the enforcement role of the Federal Trade Commission—is imperative to protect consumers’ data. Second, a proactive solution requires reconsidering how to minimize the problem by going to its source: the collection of personally identifiable information in the first place. This Note suggests regulating companies’ collection of Social Security numbers, and, eventually, using a system based on distributed ledger technology to replace the ubiquity of Social Security numbers.
Bing Jia, Tao Zhou, Wuyungerile Li, Zhenchang Liu · 5 authors
Crowd sensing is a perception mode that recruits mobile device users to complete tasks such as data collection and cloud computing. For the cloud computing platform, crowd sensing can not only enable users to collaborate to complete large-scale awareness tasks but also provide users for types, social attributes, and other information for the cloud platform. In order to improve the effectiveness of crowd sensing, many incentive mechanisms have been proposed. Common incentives are monetary reward, entertainment & gamification, social relation, and virtual credit. However, there are rare incentives based on privacy protection basically. In this paper, we proposed a mixed incentive mechanism which combined privacy protection and virtual credit called a blockchain-based location privacy protection incentive mechanism in crowd sensing networks. Its network structure can be divided into three parts which are intelligence crowd sensing networks, confusion mechanism, and blockchain. We conducted the experiments in the campus environment and the results shows that the incentive mechanism proposed in this paper has the efficacious effect in stimulating user participation.
The rise of the Internet of Things (IoT) implies new technical challenges such as managing a universally vast number of IoT devices. Despite the fact that there are already a variety of secure management frameworks for IoT, they are based on centralized models, which limits their applicability in scenarios with a large number of IoT devices. In order to overcome those limitations, we have developed a distributed IoT management system based on blockchain. In this paper, we compare the performance of our solution with the existing access management solutions in IoT. We study the delays and the throughput rate associated with the systems and analyze different configurations of our solution to maximize its scalability. The objective of this paper is to find out whether our solution can scale as well as the existing management systems in IoT.
Nowadays, numerous applications of smart home systems provide recommendations for users, including reducing their energy consumption, warnings of defective devices, selecting reliable devices and software, diagnoses, etc [1]. The internet connected, dynamic and heterogeneous nature of the smart home environment creates new security, authentication, and privacy challenges [2]. To solve those challenges, an approach to data privacy in smart home using blockchain technology, which is called smart home based the IoT-Blockchain (SHIB), is proposed in this paper. In order to demonstrate the proposed architecture, an experimental scenario using Ganache, Remix, and web3. js is built among the user, service provider, and smart home to evaluate the performance of the smart contract in the SHIB. Based on the experiment results, the SHIB architecture brings the advantages like data privacy, trust access control, and high extension ability. In addition, the comparison between the proposed architecture and existing models in different parameters such as smart contract, the privacy of data, usage of tokens, updating the policies, and misbehavior judging are performed.
Puneet Puneet, Aman Chaudhary, Nitin Singh Chauhan, Abhishek Kumar
In centralized environments, the results of voting events have always been questionable and perceived differently by voters. Most existing E-Voting systems are based on centralized servers where the voters must trust the organizing authority for the integrity of the results. In this paper we propose a novel approach for a decentralized trustless voting platform that relies on Blockchain technology to solve the trust issues. The main features of this system include ensuring data integrity and transparency, and enforcing one vote per mobile phone number for every poll with ensured privacy. To accomplish this, the Ethereum Virtual Machine (EVM) is used as the Blockchain runtime environment, on which transparent, consistent and deterministic smart contracts will be deployed by organizers for each voting event to run the voting rules. Users are authenticated through their mobile phone numbers without the need of a third party server. Results showed that the system is feasible and may offer a step towards ideal environments for such experience.
3 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
This thesis focuses on the issues between a blockchain technology and the new European Union General Data Protection Regulation (GDPR). The Blockchain technology is a rather new technology which potential has been recognised only in the recent years. Essentially, a blockchain is a distributed database in which data is stored in blocks, which form a chronological chain of blocks. Blockchains have many types and possible use cases, but this research focuses on public and permissionless blockchains, which primary objective is to enable individuals to transact with each other without centralised intermediaries. \n \nThe GDPR entered into force on 25 May 2018. The GDPR was not drafted taking account of distributed ledger technologies, such as the blockchain technology, which has raised several points of tension between the regulation and the technology. The primary focus of this thesis is on the conflict between the ‘immutability’ of blockchain technology and the right to erasure under Article 17 of the GDPR. One of the main features of blockchains is the immutability, that is to say, data on old blocks is extremely difficult to modify or delete. This feature seems prima facie to conflict with Article 17 of the GDPR that provides data subjects with the right to request erasure of their personal data under certain conditions. \n \nFirstly, this thesis analyses the current state of the conflict. Before analysing the conflict, the research addresses two essential preliminary questions: the question about anonymisation and personal data and the question about allocation of responsibilities on blockchains. After that, different solutions proposed to reconcile the conflict are analysed to understand the current situation. While public and permissionless blockchains currently may infringe Article 17 of the GDPR, there are potential solutions for the conflict in the future. \n \nThe second purpose of this thesis is to identify relevant legal problems and propose how to address the problems in the future. Blockchain developers should consider data protection obligations already in the design phase. From the legal side, this research has provided flexible interpretations for the legal problems that could help to comply with the right to erasure. There is a need for a flexible approach to the problems between the regulation and the technology.