We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo ScienceWISE logo

Computer Science > Cryptography and Security

Title: GDPR-Compliant Use of Blockchain for Secure Usage Logs

Abstract: The unique properties of blockchain enable central requirements of distributed secure logging: Immutability, integrity, and availability. Especially when providing transparency about data usages, a blockchain-based secure log can be beneficial, as no trusted third party is required. Yet, with data governed by privacy legislation such as the GDPR or CCPA, the core advantage of immutability becomes a liability. After a rightful request, an individual's personal data need to be rectified or deleted, which is impossible in an immutable blockchain. To solve this issue, we exploit a legal property of pseudonymized data: They are only regarded personal data if they can be associated with an individual's identity. We make use of this fact by presenting P3, a pseudonym provisioning system for secure usage logs including a protocol for recording new usages. For each new block, a one-time transaction pseudonym is generated. The pseudonym generation algorithm guarantees unlinkability and enables proof of ownership. These properties enable GDPR-compliant use of blockchain, as data subjects can exercise their legal rights with regards to their personal data. The new-usage protocol ensures non-repudiation, and therefore accountability and liability. Most importantly, our approach does not require a trusted third party and is independent of the utilized blockchain software.
Comments: Peer-reviewed version accepted for publication in the proceedings of the 2021 International Conference on Evaluation and Assessment in Software Engineering (EASE'21)
Subjects: Cryptography and Security (cs.CR); Distributed, Parallel, and Cluster Computing (cs.DC)
DOI: 10.1145/3463274.3463349
Cite as: arXiv:2104.09971 [cs.CR]
  (or arXiv:2104.09971v2 [cs.CR] for this version)

Submission history

From: Valentin Zieglmeier [view email]
[v1] Tue, 20 Apr 2021 14:03:01 GMT (98kb,D)
[v2] Mon, 21 Jun 2021 09:21:52 GMT (77kb,D)

Link back to: arXiv, form interface, contact.