This study proposes a privacy preserving Blockchain-Based Ticketing Service (BB Tickets), which stores information about events and related tickets in the blockchain network. As the blockchain technologies can ensure information integrity, ticket buyers can use the data stored in the blockchain network to ensure the authenticity of the purchased tickets and to resolve related disputes. Furthermore, the Non-Interactive Zero-Knowledge (NIZK) scheme is utilized in the proposed system to protect user privacy. Therefore, this study contributes to providing a privacy-preserving means for users to enjoy the reliable ticketing service provided by the blockchain technologies.
Security of the Internet of Things represents a field that strongly attracts academia and industry since it represents one of the main obstacles in its adoption. In this area, authentication and authorization methods holds a golden place in priority rank. Indeed, current approaches suffers from numerous limits. Moreover, generally, deployment systems use separately two methods one dedicated to the authentication and the other to the authorization, while the number of methods that combine both requirements is limited. In this work we propose an adaptive blockchain based authentication and authorization approach for IoT use cases. We provided a real implementation of our approach using Java language. The extensive evaluation provided, shows clearly the ability of our scheme in meeting the different requirements, as well as its ability in ensuring a very lightweight cost.
Open banking brings both the opportunities and challenges to banks all over the world. Due to the different economic development levels of each country and the gaps among financial environment maturity, all countries have different strategies and regulations towards the privacy protection of data in financial scenes, such as the General Data Protection Regulation (GDPR) by European Union (EU). A blockchain as a continuously growing list of records managed by a peer-to-peer network is widely used in various application scenarios, and can protect the privacy of financial data. However, financial blockchain still poses some problems that cannot fully meet the data protection needs. In order to address the existing problems, this paper proposes a new blockchain-based data privacy management framework. The framework consists of three components: a data privacy classification method according to the characteristics of financial data and a new collaborative-filtering-based model and a confirmation data disclosure scheme for customer strategies based on the Nudge Theory. We implement a prototype and propose a set of algorithms for this management framework.
Blockchain technology, on which digital currencies are based, is poised to be the most important disruption business innovation since the Internet. Today researchers and renowned companies have proposed the use of this technology in other areas such as voting, identity management, smart city, and others. Regarding smart city, car navigation systems is one of the main research directions that aims to streamline traffic and calculate travel routes. Existing applications such as Google Traffic or Waze are often used, but for users worried about their personal data, these systems are something of a black box. Using blockchain technology, in this paper we describe the architecture of a car navigation system in which personal data protection is a major concern.
With the rapid development of information and communication technology, a vast amount of personal health data is generated, stored, and utilized in healthcare related services. However, there are many issues remained to be solved, such as data interoperability, security, and privacy concerns. On the other hand, blockchain, a decentralized peer-to-peer digital ledger, has attracted a lot of attention in recent years as a promising technology to protect privacy of personal data. By adopting blockchain, individuals can take advantage of personal health data for better healthcare. In this paper, after briefly summarizing the major features of blockchain, we describe blockchain-empowered solutions for utilization of personal health data in healthcare and discuss issues and challenges. We further propose i-Blockchain, an individual-centric framework for use of personal health data based on an extension of permissioned blockchain, present the basic architecture and protocols, and show several application scenarios.
Securing identities in online communities like Facebook and Google requires thinking beyond mobility and cloud as federation methods can be gamed. While use of adaptive authentication and biometrics on mobile devices has become the norm, its security can be bolstered lot more with a distributed ledger like blockchain. This paper presents an augmented security model based on the blockchain distributed ledger, depicting how blockchain can help us build decentralized identity ecosystem.
A portal into the public ledger cryptocurrency makes a competition of the best web sites and easily trusted by the public. These are believed to constitute a measurable dimensions of User Experience (UX). This study aims to evaluate the user experience of the use of the three web sites most frequenty accessed cryptocurrency from Indonesia. The evaluation conducted aimed at knowing the factors that influence user trust through the design of the interface and can be installed on a new design. Methods include Performance Metrics, Post-Task Rating, Post-Session Rating, and Experiential Overview and eye-tracking device. Based on the results of research, in the overall evaluation of the web site, the web site is the most superior of Indodax. The results of the evaluation are then applied on a new design using the software Invision and examined again to see a comparison of the respondent at the time of first use. The result of the research is the assessment, recommendations, and design the look of the web site cryptocurrency are trustworthy based on user experience.
Yazan Boshmaf, Husam Al Jawaheri, Mashael Al Sabah
Annotating blockchains with auxiliary data is useful for many applications. For example, e-crime investigations of illegal Tor hidden services, such as Silk Road, often involve linking Bitcoin addresses, from which money is sent or received, to user accounts and related online activities. We present BlockTag, an open-source tagging system for blockchains that facilitates such tasks. We describe BlockTag's design and present three analyses that illustrate its capabilities in the context of privacy research and law enforcement.
Airdrops are a popular method of distributing cryptocurrencies and tokens. While often considered risk-free from the point of view of recipients, their impact on privacy is easily overlooked. We examine the Clam airdrop of 2014, a forerunner to many of today's airdrops, that distributed a new cryptocurrency to every address with a non-dust balance on the Bitcoin, Litecoin and Dogecoin blockchains. Specifically, we use address clustering to try to construct the one-to-many mappings from entities to addresses on the blockchains, individually and in combination. We show that the sharing of addresses between the blockchains is a privacy risk. We identify instances where an entity has disclosed information about their address ownership on the Bitcoin, Litecoin and Dogecoin blockchains, exclusively via their activity on the Clam blockchain.
Building a secure electronic voting system is a difficult task. The US Pentagon dropped their proposed online voting system which would have given overseas military personnel the opportunity to vote in the elections in 2005, citing the inability to ensure the legitimacy of votes as the reason. There is however a new cry in the wild to deploy a voting blockchain. The blockchain serves as a public ledger of transactions which cannot be reversed. The all-important consensus of transaction (i.e. legitimate votes) is achieved through 'miners' agreeing to validate new records being added. Whenever a new insertion is to be made e.g. votes, then a new transaction record is created by a voter adding details of their cast vote to the blockchain. Should it be deemed a valid transaction then the new vote is added to the end of the blockchain and remains there forever. What is neat about this solution is the fact that no centralized authority is needed to approve the votes but rather a majority consensus. Here everyone agrees on the final tally as they can count the votes themselves & because of the blockchain audit trail, anyone can verify that no votes were tampered with and no illegitimate votes were inserted. This paper discusses the application of blockchain to voting.
Students at the University of Wyoming designed two blockchain-based voting systems during a class offered only once at the University. The first system (re-use) branched Ethereum to leverage its security and privacy benefits. The second system (re-invent) created a new blockchain voting system which used two separate chains, one for validating voters and another for securing votes. This research looked at the benefits and flaws of current election systems as well as benefits and flaws of blockchain technology to improve upon the current election infrastructure. These systems aim to provide integrity, privacy and security to its users. Further, they strive to be fault-tolerant. Finally, these systems could be extended to mobile voting platforms and smart contracts. Based on current decentralized services, this research demonstrates a proof-of-concept that elections could benefit from blockchain-based systems. These types of systems would be ideal in smart cities to ensure the reliability of the voting procedure.
Olga B. Mora, Rogelio Rivera, Víctor M. Larios, J. Raul Beltran-Ramirez · 6 authors
In today Smart Cities, the automation strategy based on massive IoT devices deployment to gather Big Data to get insights into city behavior to improve its services. The Smart IoT devices interconnected to the Cyberinfrastructure in a Smart City can be exposed to security threats. To overcome failures and Cyberinfrastructure hacker's attacks, surveillance systems to monitor every citizen activity, compromise their privacy rights. We propose in this paper a use case where Blockchain is a promise to conciliate security versus privacy. Moreover, we discuss how we can start implementing a control access system integrating Blockchain, and we discuss benefits and challenges briefly.
Health information exchanges have been popular for some time with their advantages known and widely researched. In spite of their utility in increasing provider efficiency and decreasing administrative costs, one challenge that has persisted is the data owners inability to control data after transmission. The lack of technical mechanisms to effectively control patients' health data in the network significantly affects participation of health and medical institutions while perpetrating the silo-based data management that locks value and potential inherent in the data. This not only affects researchers due to the lack of data for research and analysis but the quality of life of patients.We present a blockchain-supported architectural framework for secure control of personal data in a health information exchange by pairing user-generated acceptable use policies with smart contracts. We highlight the merits of our system, its user-centric focus and also show experimental results along with directions for extending our work. The framework introduces minimal risk to data by architecting a mechanism for controlling data after sharing. In adopting our framework, health service providers can deliver a stronger assurance for data management than is possible with current systems.
A blockchain framework is presented for addressing the privacy and security challenges associated with the Big Data in smart mobility. It is composed of individuals, companies, government and universities where all the participants collect, own, and control their data. Each participant shares their encrypted data to the blockchain network and can make information transactions with other participants as long as both party agrees to the transaction rules (smart contract) issued by the owner of the data. Data ownership, transparency, auditability and access control are the core principles of the proposed blockchain for smart mobility Big Data.
Aug 1, 2018·2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom/BigDataSE)
Emerging blockchain systems have been widely adopted in sharing economy, such as e-commerce, to allow mutually distrustful parties to transact fairly without trusted parties. Most blockchain systems, however, lack transactional privacy protection. All transactions, including trading relationship between pseudonyms and content transacted, are exposed on the blockchain. Although many existing privacy protection methods on the blockchain have been proposed, it is difficult to find a trade-off between keeping speed and protecting privacy of transactions. To address this limitation, we propose a novel privacy-preserving method RZKPB that does not store financial transactions in clear on the blockchain, thus retaining transactional privacy from the public's view. Meanwhile, these transactions are as proofs to solve disputes between trading partners. RZKPB ensures fairness and privacy of transactions between participants without adding a new trusted party and breaking the verifying protocol on the blockchain. We take the e-commerce as an example in sharing economy to introduce RZKPB in our paper. Our experimental results show that compared with existing privacy-preserving methods based on the blockchain, RZKPB is more efficient under different settings.
Nasr Al-Zaben, Md. Mehedi Hassan Onik, Jinhong Yang, Nam Yong Lee · 5 authors
Surveillance and secrecy breaching incidents of users' privacy questioned the current third-parties data collection procedure. Massive amounts of Personally Identifiable Information (PII) are being exploited due to malpractice, identity theft, spamming, phishing and cyber-espionage. A large amount of data flow from users to enterprises for data-driven market analysis and prediction. Consequently, it is tough to track the flow and genuineness of PII. Blockchain technology, an ‘immutable’ distributed ledger which can efficaciously track PII exchange, store, and distribution. In contrast, ongoing EU General Data Protection Regulation (GDPR) demands ‘right to forget’ and ‘should be erasable’ rights. However, this paper proposes an off-chain Blockchain architecture which uses both local database and distributed ledgers to preserve a trustable PII life cycle. Considering the key factors of GDPR, prevailing Blockchain architecture were modified and a prototype was created to validate our proposed architecture using multichain 2.0. Proposed architecture stores PII and Non-PII physically separated location. Finally, with proposed architecture user will realm privacy and rigidity of Blockchain along with the privacy regulation of GDPR. Validation is done by comparing proposed system with existing methodology from technical aspects, future research scopes is also well advocated.
The public key infrastructure (PKI) based authentication protocol provides the basic security services for vehicular ad-hoc networks (VANETs). However, trust and privacy are still open issues due to the unique characteristics of vehicles. It is crucial for VANETs to prevent internal vehicles from broadcasting forged messages while simultaneously protecting the privacy of each vehicle against tracking attacks. In this paper, we propose a blockchain-based anonymous reputation system (BARS) to break the linkability between real identities and public keys to preserve privacy. The certificate and revocation transparency is implemented efficiently using two blockchains. We design a trust model to improve the trustworthiness of messages relying on the reputation of the sender based on both direct historical interactions and indirect opinions about the sender. Experiments are conducted to evaluate BARS in terms of security and performance and the results show that BARS is able to establish distributed trust management, while protecting the privacy of vehicles.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Usage-based Insurance (UBI) for vehicles determines the insurance premiums according to actual usage and driving pattern. It can significantly reduce insurance costs for safe drivers, however, UBI schemes require detailed driving data to determine the insurance premiums, which may lead to serious privacy breach for drivers. Moreover, most existing UBI schemes require a centralized insurance company as the intermediary to manage insurances. Such a centralized solution incurs too much monetary costs as well as time cost. In this paper, we propose PRIDE, a privacy-preserving and decentralized UBI scheme using the blockchain to record encrypted driving data, and the smart contract running on the blockchain to calculate insurance premiums. Different from existing UBI schemes, PRIDE achieves security and privacy without relying on any centralized party or any trusted/tamper-proof hardware. We have analyzed security of PRIDE and evaluated its performance. The results show that PRIDE is very efficient in processing UBI insurances - each insurance request can be processed in about 898ms.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
George D. Webster, Ryan Harris, Zachary D. Hanif, Bruce A. Hembree · 6 authors
For decades it has been acknowledged that sharing security information and collaboration between security practitioners are a necessity. Yet, effective sharing and collaboration are rare. A gamut of legislative acts, executive orders, academic works, and private sector initiatives have discussed aspects of the problem and aimed to be the catalyst needed to fix the situation. But almost 30 years since these efforts started, the state of sharing and collaboration is still technically complicated, slow, untrusted, and impeded by bureaucratic woes. This work identifies the challenges of sharing security artifacts and uses real-world examples to illustrate our findings. Based on this knowledge, we propose a new model for sharing and collaboration, CARE. The CARE architecture eases many of the privacy, secrecy, lineage, and structure issues that plague current sharing communities and platforms. We then build upon this foundation to introduce a marketplace based on smart contracts with transactional privacy over a distributed blockchain. Therefore, CARE incentivizes sharing, combats free riding, and provides an immutable ledger for the attribution of events. This paradigm shift, overcomes the challenges of sharing while providing new opportunities for business models, insurance risk assessments, and government backed incentivisation.
In this paper, we propose a new authentication method to prevent authentication vulnerability of Claim Token method of Membership Service provide in Private BlockChain. We chose Hyperledger Fabric v1.0 using JWT authentication method of membership service. TOTP, which generate OTP tokens and user authentication codes that generate additional time-based password on existing authentication servers, has been applied to enforce security and two-factor authentication method to provide more secure services.