A formal model for blockchain-based consent management in data sharing

被引:1
|
作者
Peyrone, Neda [1 ]
Wichadakul, Duangdao [1 ,2 ]
机构
[1] Chulalongkorn Univ, Fac Engn, Dept Comp Engn, Bangkok 10330, Thailand
[2] Chulalongkorn Univ, Fac Med, Ctr Excellence Syst Biol, Bangkok 10330, Thailand
关键词
GDPR; Data protection; Privacy by design; Consent management; Event-B; Smart contracts; PRIVACY; DESIGN;
D O I
10.1016/j.jlamp.2023.100886
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Consent is one of six legal bases for personal data processing mentioned in the General Data Protection Regulation (GDPR). The GDPR is a privacy law giving European Union (EU) citizens authority over personal data. It enforces software systems to collect, analyze, and share only necessary information ('data minimization') following the specific purpose ('consent'). The GDPR defines consent as permission of individuals ('data subjects') to give organizations ('data controllers') processing their personal data. Without a data subject's consent, the data controller processes personal data unlawfully. Therefore, consent management is an essential component of a software system to build data subjects' trust and engagement. However, sharing data can lead to a potential loss of control over personal data, as data are across boundaries between software services. One of the significant risks is caused by a lack of developers' experience in data protection practices. Hence, in this paper, we propose to use blockchain technology to manage data subjects' informed consent for data sharing to build trust, transparency, and traceability to share data across software services. We formalized the semantics of smart contracts to extend the blockchain features to validate the consent authorization and manage the request-response interaction between the services. Furthermore, we used the Event-B method to describe the dynamic behavior of the proposed model and prove its correctness. Finally, we provided a mapping from the formal model to a smart contract class diagram and a prototype called SmartDataTrust implemented with solidity and Python REST API that developers can easily utilize. & COPY; 2023 Elsevier Inc. All rights reserved.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] A Consent Model for Blockchain-Based Health Data Sharing Platforms
    Jaiman, Vikas
    Urovi, Visara
    IEEE ACCESS, 2020, 8 : 143734 - 143745
  • [2] SecureConsent: A Blockchain-based Dynamic and Secure Consent Management for Genomic Data Sharing
    Javed, Ibrahim Tariq
    Lemieux, Victoria
    Regier, Dean A.
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [3] CrowdMed-II: a blockchain-based framework for efficient consent management in health data sharing
    Chaochen Hu
    Chao Li
    Guigang Zhang
    Zhiwei Lei
    Mira Shah
    Yong Zhang
    Chunxiao Xing
    Jinpeng Jiang
    Renyi Bao
    World Wide Web, 2022, 25 : 1489 - 1515
  • [4] CrowdMed-II: a blockchain-based framework for efficient consent management in health data sharing
    Hu, Chaochen
    Li, Chao
    Zhang, Guigang
    Lei, Zhiwei
    Shah, Mira
    Zhang, Yong
    Xing, Chunxiao
    Jiang, Jinpeng
    Bao, Renyi
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2022, 25 (03): : 1489 - 1515
  • [5] Heimdall: Blockchain-Based Consent Management Framework
    Vieira Filho, Francisco Mardonio
    de Alcantara Batista, Bruno Lopes
    Celestino Junior, Joaquim
    de Souza, Jose Neuman
    2023 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN, 2023, : 487 - 492
  • [6] Blockchain-Based Data Sharing and Trading Model for the Connected Car
    Jeong, Byeong-Gyu
    Youn, Taek-Young
    Jho, Nam-Su
    Shin, Sang Uk
    SENSORS, 2020, 20 (11)
  • [7] A Blockchain-Based IoT Data Management System for Secure and Scalable Data Sharing
    Wang, Yawei
    Wang, Chenxu
    Luo, Xiapu
    Zhang, Kaixiang
    Li, Huizhong
    NETWORK AND SYSTEM SECURITY, NSS 2019, 2019, 11928 : 167 - 184
  • [8] A framework for blockchain-based management of IoT-driven data sharing
    Alreshidi, Abdulrahman
    INTERNATIONAL JOURNAL OF ADVANCED AND APPLIED SCIENCES, 2025, 12 (01): : 208 - 219
  • [9] Research on a Blockchain-Based Medical Data Management Model
    Cao, Xudong
    Xu, Huifen
    Ma, Yuntao
    Xu, Bin
    Qi, Jin
    HEALTH INFORMATION SCIENCE, HIS 2019, 2019, 11837 : 35 - 44
  • [10] A Blockchain-Based Platform for Consent Management of Personal Data Processing in the IoT Ecosystem
    Rantos, Konstantinos
    Drosatos, George
    Kritsas, Antonios
    Ilioudis, Christos
    Papanikolaou, Alexandros
    Filippidis, Adam P.
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019