James Brogan, Immanuel Baskaran, Navin Ramachandran
The on-demand digital healthcare ecosystem is on the near horizon. It has the potential to extract a wealth of information from "big data" collected at the population level, to enhance preventive and precision medicine at the patient level. This may improve efficiency and quality while decreasing cost of healthcare delivered by professionals. However, there are still security and privacy issues that need to be addressed before algorithms, data, and models can be mobilized safely at scale. In this paper we discuss how distributed ledger technologies can play a key role in advancing electronic health, by ensuring authenticity and integrity of data generated by wearable and embedded devices. We demonstrate how the Masked Authenticated Messaging extension module of the IOTA protocol can be used to securely share, store, and retrieve encrypted activity data using a tamper-proof distributed ledger.
The authors discuss the application of the EU General Data Protection Regulation’s transparency requirements to distributed ledger (DL) systems. In Section II. the relevant characteristics of DL systems are outlined. Section III. deals with the question of the applicability of the GDPR to DL systems. In Section IV., the authors discuss whether DL system participants can be considered controllers or even joint controllers that are obliged to determine their responsibilities in an arrangement pursuant to Art. 26 paras. 1, 2 GDPR. The conclusion in Section V. includes an outlook to possible approaches to improving transparency in DL systems.
Mobile security has become more and more important due to the boom of mobile commerce (m-commerce). However, the development of m-commerce is facing many challenges regarding data security problems. Recently, blockchain has been introduced as an effective security solution deployed successfully in many applications in practice, such as, Bitcoin, cloud computing, and Internet-of-Things. However, the blockchain technology has not been adopted and implemented widely in m-commerce because its mining processes usually require to be performed on standard computing units, e.g., computers. Therefore, in this paper, we introduce a new m-commerce application using blockchain technology, namely, MobiChain, to secure transactions in the m-commerce. Especially, in the MobiChain application, the mining processes can be executed efficiently on mobile devices using our proposed Android core module. Through real experiments, we evaluate the performance of the proposed model and show that blockchain will be an efficient security solution for future m-commerce.
Personal privacy protection issues has gradually caused widespread concernin society which will lead to economic and reputation losses, hinder networkand E-commerce innovation or some other consequences if not handled properly. Inthis paper, we make use of the de-centralization, permanent and audibility of theblockchain to propose a blockchain-based personal privacy protection mechanism,which uses Online taxi-hailing as the application scenario. We not only provide thedetails of the blockchain custom transaction domain used by the scene, but alsoexpound the information exchanging and blockchain auditing between passengers,Online taxi-hailing platform and drivers in Online taxi-hailing scene, providing acase model for the blockchain solution to personal privacy protection and a technicalmechanism solution for further study of personal privacy protection issues.
Shinsaku Kiyomoto, Anirban Basu, Mohammad Shahriar Rahman, Sushmita Ruj
This paper proposes a new conceptual architecture for authorization of mobile services based on blockchain technologies, and presents a design of procedures for heterogeneous mobile communication services. Furthermore, an extension of the procedures is considered in order to enhance privacy protection for users. The new architecture realizes the separation of mobile communication infrastructure and billing functions and multiple use of several mobile communication services under a single contract with a billing operator.
The cryptocurrency Monero implements confidential transactions in public blockchains. In this Master's Thesis we describe in detail all the cryptographic mechanisms needed to conceal amounts, senders and receivers in transactions, warranting transaction confidentiality.
Otto Julio Ahlert Pinno, André Grégio, Luis C. E. Bona
The IoT is pervading our daily activities and lives with devices scattered all over our cities, transport systems, buildings, homes and bodies. This invasion of devices with sensors and communication capabilities brings big concerns, mainly about the privacy and confidentiality of the collected information. These concerns hinder the wide adoption of the IoT. To overcome them, in this work, we present an Blockchain-based architecture for IoT access authorizations. Following the IoT tendency requirements, our architecture is user transparent, user friendly, fully decentralized, scalable, fault tolerant and compatible with a wide range of today's access control models used in the IoT. Finally, our architecture also has a secure way to establish relationships between users, devices and group of both, allowing the assignment of attributes for these relationships and their use in the access control authorization.
Cryptocurrency platforms such as Bitcoin and Ethereum have become more popular due to decentralized control and the promise of anonymity. Ethereum is particularly powerful due to its support for smart contracts which are implemented through Turing complete scripting languages and digital tokens that represent fungible tradable goods. It is necessary to understand whether de-anonymization is feasible to quantify the promise of anonymity. Cryptocurrencies are increasingly being used in online black markets like Silk Road and ransomware like CryptoLocker and WannaCry. In this paper, we propose a model for persisting transactions from Ethereum into a graph database, Neo4j. We propose leveraging graph compute or analytics against the transactions persisted into a graph database.
IntroductionIdentity verification and authentication has long been a critical component in service delivery for both the private and public sectors, but changing citizen demands in the digital age have stressed the need for new approaches to verify that an individual is who they say they are – with surety.
IntroductionStewart Macaulay’s seminal 1963 article “Non-Contractual Relations in Business” explored why merchants and manufacturers often fail to plan their commercial relationships and why they seldom resort to legal sanctions to settle disputes. Macaulay found that, in many business exchanges, detailed planning and legal sanctions play only a small role. His tentative
A recurring theme in the science-fiction series iBlack Mirror/i is the consequence for society of an over-focus on social networking. The episode iNosedive/i imagines a future in which every public interaction a person has is rated by the other parties, and every aspect of ones life depends on the overall rating computed from these. In this paper, we show how such a scenario is already technically possible using existing technologies such as idistributed ledgers/i, and discuss means by which the negative possibilities may be ameliorated using semantic approaches.
Remo Manuel Frey, Pascal Bühler, Alexander Gerdes, Thomas Hardjono · 6 authors
In light of digitalization, customers increasingly share private data through their online behaviors and actions. Yet, customers have become reluctant to share data due to privacy concerns. From a psychological perspective, a reduction of users' perceived risks should result in a higher willingness to share sensitive data. The development of blockchain-supported, multi-part computation thereby represents an interesting novel empirical context to study such willingness to disclose personal data, as such technologies involve a privacy-preserving approach that could not only technically solve privacy issues but also ought to address precisely the user's risk perception. Therefore, we conducted an online experiment with 420 participants to examine the willingness to disclose personal data dependent on different privacy protection mechanisms. A deception based experiment allowed to measure not only user intention, but also real user behavior. Surprisingly, our results demonstrate that participants shared similar amounts of personal data for blockchain-supported approaches and standard privacy policies. Even though an aversion to the blockchain system due to its novelty and potentially perceived complexity was not detected. Furthermore, we found that the willingness to share data increased significantly specifically for technically affine people when they were presented with the opportunity to monetize their data. We further discuss the effects of privacy awareness and whether prior knowledge of blockchain technology had a supporting effect for user acceptance.
To achieve privacy requirements, IoT application providers may need to spend a lot of money to replace existing IoT devices. To address this problem, this study proposes the Blockchain Connected Gateways (BC Gateways) to protect users from providing personal data to IoT devices without user consent. In addition, the gateways store user privacy preferences on IoT devices in the blockchain network. Therefore, this study can utilize the blockchain technology to resolve the disputes of privacy issues. In conclusion, this paper can contribute to improving user privacy and trust in IoT applications with legacy IoT devices.
Blockchain has been applied to study data privacy and network security recently. In this paper, we propose a punishment scheme based on the action record on the blockchain to suppress the attack motivation of the edge servers and the mobile devices in the edge network. The interactions between a mobile device and an edge server are formulated as a blockchain security game, in which the mobile device sends a request to the server to obtain real-time service or launches attacks against the server for illegal security gains, and the server chooses to perform the request from the device or attack it. The Nash equilibria (NEs) of the game are derived and the conditions that each NE exists are provided to disclose how the punishment scheme impacts the adversary behaviors of the mobile device and the edge server.
Xueping Liang, Juan Zhao, Sachin Shetty, Jihong Liu · 5 authors
Enabled by mobile and wearable technology, personal health data delivers immense and increasing value for healthcare, benefiting both care providers and medical research. The secure and convenient sharing of personal health data is crucial to the improvement of the interaction and collaboration of the healthcare industry. Faced with the potential privacy issues and vulnerabilities existing in current personal health data storage and sharing systems, as well as the concept of self-sovereign data ownership, we propose an innovative user-centric health data sharing solution by utilizing a decentralized and permissioned blockchain to protect privacy using channel formation scheme and enhance the identity management using the membership service supported by the blockchain. A mobile application is deployed to collect health data from personal wearable devices, manual input, and medical devices, and synchronize data to the cloud for data sharing with healthcare providers and health insurance companies. To preserve the integrity of health data, within each record, a proof of integrity and validation is permanently retrievable from cloud database and is anchored to the blockchain network. Moreover, for scalable and performance considerations, we adopt a tree-based data processing and batching method to handle large data sets of personal health data collected and uploaded by the mobile platform.
Sep 8, 2017·Proceedings of the 2017 ACM International Joint Conference on Pervasive and Ubiquitous Computing and Proceedings of the 2017 ACM International Symposium on Wearable Computers
Mathieu Chanson, Andreas Bogner, Felix Wortmann, Elgar Fleisch
Giving people ownership of the data they produce becomes more and more important in times of ever-growing capabilities to collect and analyze data of individuals. In light of this challenge, we show how blockchain technology can enable privacy by presenting an odometer fraud prevention system. It records mileage and GPS data of cars and secures that on the blockchain, which strongly hinders odometer fraud. Our users own and control their data while at the same time data integrity is ensured. This facilitates the certification of that data. We discuss the advantages of this approach compared to current systems and also highlight limitations of our architecture and the use of blockchain technology.
Nabil Rifi, Elie Rachkidi, Nazim Agoulmine, Nada Chendeb Taher
In the past few years, the number of wireless devices connected to the Internet has increased to a number that could reach billions in the next few years. While cloud computing is being seen as the solution to process this data, security challenges could not be addressed solely with this technology. Security problems will continue to increase with such a model, especially for private and sensitive data such as data personal and medical data collected with more and more sophisticated connected devices (forming the IoT). Thus the need for a fully decentralized peer to peer and secure technology to overcome these problems. The blockchain Technology is a promising approach giving the properties it brings to the field. This paper illustrates an architecture based on blockchain technology, and a protocol for data access, using smart contracts and a publisher-subscriber mechanism.
In this position paper, we discuss the early stages of design research conducted as part of a widely multidisciplinary inquiry involving social psychology, cyber security and deep learning (AI). TAPESTRY aims to: \n \ni. investigate online users’ approaches to establishing the trustworthiness of an interactor or organisation they are about to disclose personal information to, and \n \nii. ways of supporting judgements through the use of a Distributed Ledger Technology (DLT) service such as blockchain which operates as a form of personal identity credit rating. \n \nBuilding on prior work, we are utilising game design within our Participatory Design approach that involves creatively engaging with three user groups (crowdfunding, eHealth, online dating). Drawing from recent design-led research projects we highlight some of the value and challenges in using creative and innovative techniques in participatory design in technically sophisticated work. We present very early concept ideas and contribute from novel recent literatures to provoke workshop discussion.
Since its inception, the blockchain technology has shown promising application prospects. From the initial cryptocurrency to the current smart contract, blockchain has been applied to many fields. Although there are some studies on the security and privacy issues of blockchain, there lacks a systematic examination on the security of blockchain systems. In this paper, we conduct a systematic study on the security threats to blockchain and survey the corresponding real attacks by examining popular blockchain systems. We also review the security enhancement solutions for blockchain, which could be used in the development of various blockchain systems, and suggest some future directions to stir research efforts into this area.
Open access
4 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Steven Goldfeder, Harry Kalodner, Dillon Reisman, Arvind Narayanan
Abstract We show how third-party web trackers can deanonymize users of cryptocurrencies. We present two distinct but complementary attacks. On most shopping websites, third party trackers receive information about user purchases for purposes of advertising and analytics. We show that, if the user pays using a cryptocurrency, trackers typically possess enough information about the purchase to uniquely identify the transaction on the blockchain, link it to the user’s cookie, and further to the user’s real identity. Our second attack shows that if the tracker is able to link two purchases of the same user to the blockchain in this manner, it can identify the user’s cluster of addresses and transactions on the blockchain, even if the user employs blockchain anonymity techniques such as CoinJoin. The attacks are passive and hence can be retroactively applied to past purchases. We discuss several mitigations, but none are perfect.
Steven Goldfeder, Harry Kalodner, Dillon Reisman, Arvind Narayanan
We show how third-party web trackers can deanonymize users of\ncryptocurrencies. We present two distinct but complementary attacks. On most\nshopping websites, third party trackers receive information about user\npurchases for purposes of advertising and analytics. We show that, if the user\npays using a cryptocurrency, trackers typically possess enough information\nabout the purchase to uniquely identify the transaction on the blockchain, link\nit to the user's cookie, and further to the user's real identity. Our second\nattack shows that if the tracker is able to link two purchases of the same user\nto the blockchain in this manner, it can identify the user's entire cluster of\naddresses and transactions on the blockchain, even if the user employs\nblockchain anonymity techniques such as CoinJoin. The attacks are passive and\nhence can be retroactively applied to past purchases. We discuss several\nmitigations, but none are perfect.\n
The purpose of this study is to investigate to what degree usability and user experience are factors in the uptake and use of bitcoin. This paper investigates whether usability affects bitcoin adoption by beginners. To ascertain whether this is true, a pilot study was designed to gather rich qualitative data. Participants in this study were asked to provide commentary while completing an assigned task that was designed to emulate a common case that a person unfamiliar with bitcoin might encounter when dealing with the currency for the first time.
In this paper, we consider the issue of trust and trust-related factors in the context of decentralized applications running on public blockchain platforms such as Ethereum. These decentralized applications emphasize a lack of reliance on a trusted third party, and are marketed as applications that cannot be censored or stopped. To determine whether either social trust or technology trust applies in these cases, we examine the extent to which these applications could be considered to be out of the control of a third party, by qualitatively analyzing how developers define the characteristics of decentralization, trustlessness and autonomy. The results show that although decentralized applications' websites make reference to these concepts, they are not defined in the same way. In cases where there is no mention of either of these concepts, it is therefore difficult to say which definitions are assumed. In addition, we also found contradictions in the characterization of the level of developer control. We discuss these findings in the context of research on user trust and propose future research directions.