0% found this document useful (0 votes)
10 views47 pages

Blockchain Framework for Secure Data Sharing

The document discusses a blockchain-based framework for secure data sharing, particularly in the healthcare sector, addressing issues with current data sharing systems such as security vulnerabilities and lack of patient consent. It outlines requirements for a secure framework, including the use of privacy-enhancing technologies and decentralized platforms like IPFS, Ocean Protocol, and Enigma. The proposed system emphasizes patient-driven interoperability and the use of smart contracts to ensure data privacy and control over sensitive information.

Uploaded by

Raj Shah
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views47 pages

Blockchain Framework for Secure Data Sharing

The document discusses a blockchain-based framework for secure data sharing, particularly in the healthcare sector, addressing issues with current data sharing systems such as security vulnerabilities and lack of patient consent. It outlines requirements for a secure framework, including the use of privacy-enhancing technologies and decentralized platforms like IPFS, Ocean Protocol, and Enigma. The proposed system emphasizes patient-driven interoperability and the use of smart contracts to ensure data privacy and control over sensitive information.

Uploaded by

Raj Shah
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

• Blockchain based Secure data sharing

• Issues with existing data sharing framework


• Requirements for secure blockchain based data sharing framework
• Blockchain based data sharing platforms and protocols
• Case studies on Inter Planetary File System (IPFS)
• Blockchain based data sharing platforms using IPFS
• Ocean Protocol and Enigma
• Privacy- enhancing technologies (PETs): zero-knowledge proofs,
homomorphic encryption, and ring signatures
Issues with existing data sharing framework

Different layers involved in healthcare data sharing framework based


on blockchain.
• They mentioned three layers of the system:
• institution-driven interoperability,
• patient-driven interoperability, and
• blockchain-enabled patient-driven interoperability. The three layers of the data interoperability are
depicted in Figure
• Moreover, the relationship between the actors can be observed horizontally and vertically throughout the
layers of the system.
• In the top-most layer of institutional blockchain-enabled patient-driven interoperability, a
relationship between the health organization with the Regional Health Information Organization
(RHIO) and other healthcare organizations is possible.
• In patient-driven interoperability, the patient can interact with healthcare organizations,
including pharmacy and other institutions through patients-facing API.
• Whereas, blockchain-based patient-driven interoperability has no business relationship between
different healthcare organizations. The relationship can only be developed through official
means possible through blockchain technology. This is due to the transparent nature of
blockchain. technology that protects the privacy of information and offers extra security to
patients’ records, including sensitive information.
• All relationships in this system go through patients due to smart contracts and have layers such
as clinical data authorization, patients’ keys, and credentials for access to data.
Issues with Current Data
Sharing Framework
• The security of the data and information resources is a major issue.

• The current electronic database systems lacks the security measure to protect the information from

hackers and other unauthorized accesses.

• It also significantly affects privacy of information, which can lead to severe financial and legal

consequences.

• Data sharing involves a consensus between different parties, sharing records through blockchain-assisted

technologies and sharing mediums also requires consensus among the parties

• The development of relevant data sharing policy along with the enforcement of smart contracts.

• There are issues with access control in the data sharing platform of the blockchain technology.
Issues with Current Data
Sharing Framework

• One of the main issues identified in data sharing application of blockchain for healthcare industry is
the lack of consent of patients.
• There is also a lack of international standards regarding interoperability of IT services in the
healthcare industry.
• It is necessary to provide a data sharing platform for different entities, such as the practitioners,
patients, and administrators.
• Administrators should have special rights to oversee the entire system.
• Administrators should also have the responsibility of establishing links between
• different parties and the stored data and information
• Proposed a peer-to-peer blockchain-based system for sharing of electronic health records and to
ensure a high level of privacy for sensitive data and to add accountability to the process of data
sharing.
• It is vital to introduce a new framework for the healthcare sector based on the blockchain technology.
Requirements for a Secure Blockchain-Based
Data Sharing Framework
• The following questions underpin the importance of adopting blockchain
technology within healthcare:
• How blockchain technology can be used to protect the sharing of data for
improved medical interventions?
• What are the requirements necessary for developing a data storing and sharing
mechanism based on blockchain technology for the healthcare sector?
• In order to develop a framework for medical data sharing, there are general
requirements that need to be followed –
• A primary need of healthcare system for data sharing is the requirement of a blockchain
system for controlling the process for data sharing.
• Blockchain will act as the main data sharing and controlling mechanism for electronic
database system. Moreover, the data involved in these healthcare records are sensitive
and private
Requirements for a Secure Blockchain-Based
Data Sharing Framework
• On top of security, the privacy requirements of different stakeholders also need
to be considered.
• To achieve the previously stated requirements, a new framework for the
requires technical compliance for highly secured blockchain system with the help
of security token.
• This can be achieved using credentials that can provide the authorized access to
records to all relevant authorities.
• In addition to basic credentials, other Information and Communication
technology (ICT) devices such as biometric verification can also be used to
improve the security of such systems.
• High-level privacy can be achieved through various data algorithms that can
ensure that the sensitive information cannot be distinguished when compared
with other records.
Requirements for a Secure Blockchain-Based
Data Sharing Framework
• Another requirement for the framework pertaining to blockchain technology for
record is big data management using the cloud system.
• Since data needs to be stored, the cloud system is by far the most commonly used
storage option.
• It protects the physical space of the organizational unit and also saves the cost of
storage devices (internal storage).
• However, it has security concerns due to the utilization of third-party for data
storage.
• The blockchain-based data sharing framework can mitigate such security concerns
owing to its inherent characteristic of transparency and immutable public ledgers.
• Moreover, cryptographic algorithms of blockchain technology are difficult to bypass
and add security to the blockchain system, which utilizes cloud storage for data
management.
Blockchain based data sharing platforms using IPFS
• To ensure digital data management.
• Blockchain is used to store the permanent record of agreements between data
owner and user.
• A user requests the data from the owner by making an agreement according the
terms and conditions stored in the blockchain.
• Each entity (owner and user) has been assigned a unique Ethereum address to
perform transactions
• Online publishing and distribution of digital content is ensured by using blockchain to
add transparency and trust in the model.
• Owner of the data shares its content with the publisher’s server.
• The server distributes the content to the users according to received request.
• When the user successfully receives the file, the participating entities get their fair
share according to defined criteria.
• A publisher’s server is a centralized server, which stores digital content of the owner
• Digital content provider and file server are responsible entities to
deliver the content to customer.
• After successful download of content by the customer, the
participating entities (owner and file server) are given incentives as a
reward.
• To solve downloading disputes between customer and file server,
arbitrator acts as an unbiased agent to resolve the conflicts.
• Decentralized storage, IPFS, Ethereum, and encryption mechanism
can be used for secure and trusted consolidated platform for sharing
of digital data between buyer and seller.
• To achieve data security, owner encrypts the hashes to avoid risk of
data leakage which is to be sold. So that data on IPFS can only be
accessed by verified customers, who belong to community and
submit the required deposit for digital content.
• In this way, owner can run his business with reasonable profit
• Case Study on online trading of data:Buying and selling of digital
content using blockchain
• Identity management: Users are first authenticated using RSA signatures
before giving them access to data.
• Security of digital assets: Adding encryption to the data hashes ensures
the security and avoids data leakage.
• Authenticity of owner: Seller can trust the owner by checking the reviews
about owner and its data.
• Quality of data: Rating or reviews depict the quality of data; therefore, by
checking the reviews, buyer will only get high quality data.
• Management of fake reviews: Fake reviews are being identified using
Watson analyzer.
• Dispute handling: Arbitrator is introduced to resolve downloading
disputes.
• User incentive: By giving incentives, sellers are being motivated to give
feedback on used data to aid future customers.
• The system model has the following entities.
• Owner:
• It may be a person or organization which owns the data to be shared among customers.
• It can also control the query and access of data by filtering out the requestors.
• Customer:
• Makes a Request for buying the data from the system.
• After receiving the desired content, the customer downloads the file from IPFS server by
reconstructing the hash and registers his reviews about data on the review system.
• Workers:
• It is the passive entity of system, provides decryption services on behalf of the
customers.
• Authenticates the new customers through signatures and query the smart contract for
requested data by customers.
• Arbitrator:
• A trusted entity is responsible for solving disputes between the buyer and seller
regarding the downloading of requested content.
• Based on the decision of arbitrator, a customer may be refunded the deposited amount.
• Data Sharing
• At first, owner initiates the digital data sharing by generating the meta
data of original file.
• Meta data would include the information such as name of file, type,
description, and size.
• Once the meta data is ready, it is uploaded to the IPFS along with
complete file of data.
• The snippet of file uploading to IPFS is given next:

The overall flow of file uploading on IPFS by owner is shown in Figure 1
• Once the file is uploaded to IPFS, hashes of that data are generated by IPFS and returned back to the
owner.
• In System model worker nodes are generated and their public–private key pair is stored in smart
contracts.
• When the owner gets the hash by IPFS, it searches in the smart contract for verified worker nodes, who
are responsible for providing decryption services to customers.
• Only that worker can provide the services, who is selected by the owner.
• When the owner receives the hash, Shamir’s secret sharing (SSS) algorithm is used to split the IPFS
hash of file into k number of shares.
• In response to these shares, owner decides the n number of random keys to be used for encryption.
• Once all the shares are encrypted, they are stored in the blockchain along with other important
information such as; authorized recipient for the file.
• Data security is ensured by encrypting the hashes.
• The reason behind this is that, hash itself is not secure.
• It just represents a unique finger print for some data.
• If any unauthorized customer, who has not submitted deposit for digital content gets access to hash,
then the complete file of data from IPFS can be fetched.
• In such a way, owner would be in complete loss of business.
• In the proposed model, only those customers are able to decrypt the hash, who have deposited the
fund and have seen authorized by the worker nodes
• Data Retrieval
• A detailed system model for customer requesting the digital content is shown in Figure 2.
• A customer first checks the existing review of data by previous customers, so that quality of data can be
properly verified before depositing the ethers.
Overview of Case Study
• Blockchain-based secure data sharing platform by leveraging the benefits of interplanetary file system
(IPFS).
• A meta data is uploaded to IPFS server by owner and then divided into n secret shares.
• The proposed scheme achieves security and access control by executing the access roles written in
smart contract by owner.
• Users are first authenticated through RSA signatures and then submit the requested amount as a price
of digital content.
• After the successful delivery of data, the user is encouraged to register the reviews about data.
• These reviews are validated through Watson analyzer to filter out the fake reviews.
• The customers registering valid reviews are given incentives. I
• n this way, maximum reviews are submitted against every file.
• In this scenario, decentralized storage, Ethereum blockchain, encryption, and incentive mechanism are
• combined.
• To implement the proposed scenario, smart contracts are written in solidity and deployed on local
Ethereum test network.
• The proposed scheme achieves transparency, security, access control, authenticity of owner, and
• The main components in the proposed frameworks include a
database for healthcare partners, such as clinics, hospitals, and so on.
• These partners are the main users of this healthcare system powered
by blockchain technology.
• The users either create new information or retrieve the already-
existing information from healthcare database.
• All these databases can be linked together with the help of blockchain
technology assisted by super peers that can provide P2P interactions
with external parties connected in a blockchain network.
• The blockchain technology for this system can be of any type, i.e.,
consortium or public.
• However, the most favorable type of blockchain-based framework for
sharing data among different healthcare partners, which can be
accessed by other parties, can be either consortium or public
blockchain.
• Whereas, the clinical database is the local data storage facility of
healthcare organizations.
• The information can later be shared on the main healthcare database,
which can be city-, district-, or country-based, depending on the scope
of the project.
• This database will ideally be a cloud-based storage option that allows
storage of large amount of data in a convenient manner.
• The following are some advantages of our proposed blockchain-based data
sharing framework in the healthcare:
• All information recorded in the blockchain node will be available to the entire
network of connected nodes. Thus, all stakeholders can use it following their
respective authorities.
• When the doctor writes a prescription, the hospital’s pharmacy department will
first read it, and then, the stock management department will manage whether
backorder is needed to add medical supplies.
• Meanwhile, in other places, the distributors should update the needs of
medicines in the areas that are being reached.
• The pharmaceutical companies will ensure the transparency of the data as a way
to manage the associated risk. They can observe and analyze the possibility of
fraud.
• From the regulator’s point of view, the Ministry of Health can analyze and
monitor the possibility of deviations by health service providers such as hospitals
and healthcare professionals (e.g., doctors) against excessive prescription.
• Ocean Protocol and Enigma are both blockchain-based projects focused on
data privacy, sharing, and decentralized computation, but they approach
these goals with different architectures and focuses.
• Ocean Protocol
• Objective:
• Data Sharing Marketplace:
• Ocean Protocol is designed to create a decentralized data marketplace where
data owners can securely share and monetize their data, while maintaining
control over who can access it.
• The protocol is especially focused on enabling the sharing of data for AI and
machine learning applications.
• Data Control:
• It ensures that data owners retain control and authorize over their data,
allowing them to define specific usage policies and retain ownership even
when the data is being used.
• Ocean Key Features:
• Decentralized Data Exchange:
• Ocean Protocol provides an infrastructure for decentralized data exchanges,
where data providers and consumers can interact without intermediaries.
• Compute-to-Data:
• This feature allows algorithms to run on data in a secure environment
without exposing the data itself.
• This means data never leaves the owner's premises, addressing privacy
concerns while still enabling the use of data for training AI models.
• Data Tokens:
• Each dataset in the Ocean Protocol marketplace is tokenized.
• These data tokens can be traded and used within the ecosystem, facilitating
the buying and selling of access to data.
• Architecture:
• Blockchain and Smart Contracts:
• Ocean Protocol uses blockchain technology to manage permissions,
payments, and access to data.
• Smart contracts are used to automate transactions and ensure that
data providers are paid when their data is used.
• Ocean Marketplaces:
• Anyone can set up a marketplace on Ocean Protocol to facilitate data
exchange, and these marketplaces can be customized for specific
domains or industries.
• The flow of information for generating new patients’ records involves
the integration of blockchain technology into the local database,
which is then transferred to the main database through the
blockchain P2P network.
• The information stored in the main database is immutable and will be
available for further audit.
• Moreover, the framework requires immutable information that is
stored into a relevant database based on blockchain-assisted system.
Enigma
• Objectives:
• Privacy-Preserving Computation:
• Enigma, now known as Secret Network, focuses on enabling privacy-
preserving computation on decentralized networks.
• It allows for computations to be performed on encrypted data without
exposing the data itself, solving a major privacy issue in blockchain and
decentralized applications.
• Secret Contracts:
• Enigma's original vision was to create "secret contracts," which are
smart contracts that can process sensitive data without revealing it to
the network or any third parties.
• Key Features:
• Secret Contracts:
• These are the core feature of Secret Network (formerly Enigma).
• Unlike traditional smart contracts, secret contracts ensure that data processed within
the contract remains encrypted and private.
• Data Privacy:
• The platform allows developers to build decentralized applications (dApps) that can
handle sensitive user data in a private manner, ensuring that such data is never exposed
or leaked.
• Interoperability:
• Secret Network is designed to be interoperable with other blockchains, allowing for
privacy-preserving operations across multiple networks.
Architecture:
•Blockchain and Secure Multi-Party Computation (MPC):
•Enigma's technology is based on a combination of blockchain and MPC,
allowing multiple parties to compute functions over their inputs while
keeping those inputs private.
•Secret Nodes:
•Nodes in the Secret Network perform computations on encrypted data using
secure enclaves (e.g., Intel SGX), ensuring that even the nodes themselves
cannot access the raw data.
Privacy-enhancing technologies
(PETs)
• Privacy-enhancing technologies (PETs) are methods and tools that
help protect user privacy and data security, especially in environments
where sensitive information is handled.
• PETs are technologies that integrate fundamental data protection
principles by minimizing personal data use, maximizing data security,
and/or empowering individuals
• Three significant PETs include Zero-Knowledge Proofs (ZKP),
Homomorphic Encryption, and Ring Signatures.
Benefits of PETs
• PETs can help reduce the risk to individuals, while enable further analysis
of personal data without a controller necessarily sharing it, or a
processor having access to it.
• The ability to share, link and analyze personal data in this way can
provide valuable insights while ensuring you comply with the data
protection principles.
• By using PETs, you can obtain insights from datasets without
compromising the privacy of the individuals whose data is in the dataset.
• Appropriate PETs can make it possible to give access to datasets which
would otherwise be too sensitive to share.
• 1. Zero-Knowledge Proofs (ZKP):
• A Zero-Knowledge Proof is a cryptographic technique that allows one party (the prover) to
prove to another party (the verifier) that a statement is true without revealing any
additional information beyond the fact that the statement is indeed true.
• Example: A user can prove they know a password without revealing the actual password.
• Use Cases: Authentication systems, blockchain transactions (e.g., zk-SNARKs in Zcash),
privacy-preserving identity systems.
• Key Features:
• Complete: If the statement is true, a valid proof can be generated.
• Sound: If the statement is false, a dishonest prover cannot convince the verifier otherwise.
• Zero Knowledge: The verifier gains no additional knowledge other than the statement
being true.
• Homomorphic Encryption allows computations to be performed on encrypted data
without decrypting it. After processing, the results can be decrypted to reveal the
correct output, all while keeping the data itself secure throughout the process.
• Example: A cloud server can perform operations on encrypted user data without
ever needing to decrypt it, ensuring data privacy.
• Use Cases: Secure cloud computing, private machine learning, financial data
analysis.
• Key Features:
• Partial Homomorphic Encryption (PHE): Allows specific operations (like addition or
multiplication) on encrypted data.
• Fully Homomorphic Encryption (FHE): Allows arbitrary computations on encrypted
data, which is a more advanced and computationally intensive form of encryption.
• Comparison:
• ZKP: Focuses on proving knowledge without revealing the knowledge
itself.
• Homomorphic Encryption: Protects data during processing by
keeping it encrypted.
• Ring Signatures: Provides group-level anonymity by obfuscating the
specific signer in a group.
Homomorphic encryption (HE)
• Homomorphic encryption (HE)
• What is homomorphic encryption and what does it do?
• Homomorphic encryption allows you to perform computations on encrypted data without first
decrypting it.
• The computations themselves are also encrypted.
• Once you decrypt them, the result is an output identical to what would have been produced if
you had performed the computation on the original plaintext data.
• There are three types of homomorphic encryption:
• fully (FHE);
• somewhat (SHE); and
• partial (PHE).
• The HE scheme you choose will depend on the nature, scale and the purpose of your processing
and the level of utility you require to fulfil your purposes.
• You also need to consider the number of different types of mathematical operations the HE
scheme supports, as well as any limit to how many operations the scheme can perform.
• 3. Ring Signatures:
• A Ring Signature allows a member of a group to sign a message on behalf of the
group without revealing which member actually signed it. This provides anonymity for
the signer while ensuring the validity of the signature.
• Example: In Monero cryptocurrency, ring signatures are used to make transactions
anonymous, hiding the sender's identity.
• Use Cases: Anonymous communication, secure voting systems, private
cryptocurrency transactions.
• Key Features:
• Unlinkability: It's impossible to determine which group member signed a message.
• Anonymity: The identity of the actual signer remains hidden while the signature can
be verified as legitimate.
Homomorphic encryption (HE)
Type of HE When would this type of HE be appropriate?
FHE FHE allows you to compute any function, as there are no limitations in terms of the types of
operations it supports or their complexity.
This flexibility means it provides good protection and utility.
However, the more complex the operation, the more resource and time may be required.

SHE SHE permits fewer additions and multiplications on encrypted data.


The amount is also fixed in advance.
This in turn means that there is a limit on the types of functions it can support.

PHE PHE provides good performance and protection, but limited utility.
It supports only addition or multiplication operations, but not both.
As with SHE, there is a limit on the types of (but not the number of) functions it can support.
Homomorphic encryption (HE)
• HE uses a public key-generation algorithm to generate a pair of private
and public keys, and an evaluation key.
• The evaluation key is needed to perform computations on the
encrypted data when it is shared with the entity that will perform them.
• This entity does not need access to the private key to perform the
analysis.
• The client, who retains the private key, can then decrypt the output
obtain the result they require.
• Any entity that has only the public and the evaluation keys cannot learn
anything about the encrypted data in isolation.
HE can help you to ensure
• : security and confidentiality.
It can minimise the risk from data breaches if they occur, as personal
data remains encrypted at rest, in transit and during computation.
• accuracy.
It provides a level of assurance that the result of a computation is the
same as if you performed it on unencrypted data – providing you
ensure the inputs are correct prior to encryption taking place
Zero-knowledge proofs
• What is a zero-knowledge proof and what does it do?
• A zero-knowledge proof (ZKP) refers to any protocol where a prover (usually an
individual) is able to prove to another party (verifier) that they are in the 29
possession of a secret (information they know but is unknown to the verifier).
• For example, a prover can prove their age without revealing what it actually is.
• The prover can use a ZKP to prove to the verifier that they know a value X (eg
proof they are over 18), without conveying any information to the verifier apart
from the fact that the statement is true.
• The verifier challenges the prover such that the responses from the prover will
convince the verifier if the X is true (ie that the prover is over 18)
zero-knowledge proof

Existing applications of ZKPs include:


• confirmation a person is of a certain age (eg legally able to drive), without revealing their birth date;
• proving someone is financially solvent, without revealing any further information regarding their financial
status; or
• demonstrating ownership of an asset, without revealing or linking to past transactions; and
• to support biometric authentication methods such as facial recognition, fingerprint sensor and voice
authorisation on mobile devices.
ZKPs can be interactive, (ie require the service or verifier to interact with the prover), or non-interactive.
How do ZKPs assist with data
protection compliance?
• If you use a ZKP service, the information you receive (eg proof that an
individual is over a particular age), is likely to still relate to an
individual depending on the nature of the query.
• Therefore, it will still be personal data.
• ZKPs can be a used to help you achieve data protection compliance
with: • the data minimization principle as they limit the amount of
personal data to what is required; and 30
• the security principle as confidential data such as actual age does not
have to be shared with other parties
How does the use of ZKPs impact
the ability to achieve the purpose of
the processing?
• The algorithms and functions underpinning ZKPs provide a probable
certainty as to whether the information is correct or not.
• This means the secret can be proved with a very high degree of
certainty.
• When applying a ZKP to the design of a processing operation, you
should assess whether this uncertainty reaches sufficiently low value
for the risk to be accepted in the framework of that specific
processing.
PET Applications Standards Known weaknesses
Homomorphic encryption 1. Leverage cloud computing [Link] 1. Scalability and
and storage services [Link]/standard/ computation speed can
securely, as data held off- be an issue.
site is encrypted but can be
processed. 2. Fully homomorphic
2. Secure machine learning encryption is unsuitable for
as a service: data can be real-time data analysis.
processed without giving
processor access to
encrypted data.
3. Secure collaborative
computation

Zero knowledge proofs Proving claims about [Link] 1. Weaknesses in Zero-


personal data (eg [Link] knowledge proof
nationality, solvency, age, 2019 implementations can be
transactions). [Link] caused by poor
d/[Link]
Information technology — implementation of the
Security techniques — Entity protocol.
authentication — Part 5: [Link] protocols may
Mechanisms using zero- be more vulnerability to side
knowledge techniques. channel or timing attacks as
they require the prover to
send multiple messages.

You might also like