Blockchain-based data governance for privacy-preserving in multi-stakeholder settings

Detalhes bibliográficos
Autor(a) principal: Garcia, Rodrigo Dutra
Data de Publicação: 2023
Tipo de documento: Dissertação
Idioma: eng
Título da fonte: Biblioteca Digital de Teses e Dissertações da USP
Texto Completo: https://www.teses.usp.br/teses/disponiveis/55/55134/tde-06092023-102200/
Resumo: In multi-stakeholder systems, such as healthcare, the internet of things, and supply chain management, there is frequent data generation, exchange, and sharing. As a result, data owners often desire control over their data and maintain privacy, while data consumers require methods to ascertain the origins and creators of the data. These conflicts of interest require developing data governance systems that guarantee data provenance, privacy protection, consent management, and selective disclosure. This research proposed a decentralized data governance system utilizing blockchain technology, proxy re-encryption (PRE), and Boneh, Boyen, and Shacham (BBS) signatures to address these challenges. The proposed system enables data owners to control, selectively share, and track their data through privacy-enhancing, consent management, and selective disclosure mechanisms while also allowing data consumers to understand the lineage of the data through a blockchain-based provenance mechanism. As a case study, the research examined and evaluated electronic prescriptions involving sensitive data and multiple stakeholders, including patients as data owners and doctors and pharmacists as data consumers. The research was structured as a collection of articles organized in the following sequence: problem formulation and developing smart contracts, implementing privacy and consent management through PRE, and applying BBS signatures for selective data sharing. The proof-of-concept implementation and evaluations, conducted using CosmWasm, Hyperledger Besu, Ethereum, pyUmbral PRE, and BBS signatures, demonstrate that the proposed decentralized system is platform-agnostic, scalable, and capable of providing a higher level of transparency, privacy, and trust with minimal overhead.
id USP_37447b27b2e947ad3726eda401703a19
oai_identifier_str oai:teses.usp.br:tde-06092023-102200
network_acronym_str USP
network_name_str Biblioteca Digital de Teses e Dissertações da USP
repository_id_str 2721
spelling Blockchain-based data governance for privacy-preserving in multi-stakeholder settingsGovernança de dados baseada em blockchain com preservação da privacidade em configurações com múltiplas partes interessadasBlockchainBlockchainCompartilhamento seletivoContratos inteligentesData governanceDecentralizedDescentralizaçãoE-prescriptionGovernança de dadosPrescrição eletrônicaPrivacidadePrivacyProxy re-encryptionRe-criptografia por proxySelective sharingSmart contractsIn multi-stakeholder systems, such as healthcare, the internet of things, and supply chain management, there is frequent data generation, exchange, and sharing. As a result, data owners often desire control over their data and maintain privacy, while data consumers require methods to ascertain the origins and creators of the data. These conflicts of interest require developing data governance systems that guarantee data provenance, privacy protection, consent management, and selective disclosure. This research proposed a decentralized data governance system utilizing blockchain technology, proxy re-encryption (PRE), and Boneh, Boyen, and Shacham (BBS) signatures to address these challenges. The proposed system enables data owners to control, selectively share, and track their data through privacy-enhancing, consent management, and selective disclosure mechanisms while also allowing data consumers to understand the lineage of the data through a blockchain-based provenance mechanism. As a case study, the research examined and evaluated electronic prescriptions involving sensitive data and multiple stakeholders, including patients as data owners and doctors and pharmacists as data consumers. The research was structured as a collection of articles organized in the following sequence: problem formulation and developing smart contracts, implementing privacy and consent management through PRE, and applying BBS signatures for selective data sharing. The proof-of-concept implementation and evaluations, conducted using CosmWasm, Hyperledger Besu, Ethereum, pyUmbral PRE, and BBS signatures, demonstrate that the proposed decentralized system is platform-agnostic, scalable, and capable of providing a higher level of transparency, privacy, and trust with minimal overhead.Em sistemas envolvendo múltiplas partes interessadas, como o setor da saúde, internet das coisas e o gerenciamento da cadeia de suprimentos, há uma geração, troca e compartilhamento frequente de dados. Como resultado, os proprietários dos dados geralmente precisam controlar e preservar a privacidade de suas informações, enquanto os consumidores dos dados exigem métodos para determinar as origens e os criadores dos registros. Esses conflitos exigem soluções de governança que garantam a proveniência dos dados, proteção da privacidade, gestão de consentimento e compartilhamento seletivo. Para responder a esses desafios, esta pesquisa apresentou um sistema descentralizado de governança de dados que utiliza a tecnologia blockchain, re-criptografia por proxy (PRE) e assinaturas de Boneh, Boyen e Shacham (BBS). A abordagem proposta permite que os proprietários dos dados controlem, compartilhem seletivamente e rastreiem seus dados, mantendo a privacidade dos registros. Além disso, o sistema proposto permite que os consumidores dos dados compreendam a linhagem dos registros por meio de um mecanismo de proveniência baseado em blockchain. Como estudo de caso, a pesquisa examinou e avaliou prescrições médicas eletrônicas envolvendo dados sensíveis e múltiplas partes interessadas, incluindo pacientes como proprietários dos dados, médicos e farmácias como consumidores dos dados. A pesquisa foi estruturada como uma coletânea de artigos organizados na seguinte ordem: formulação do problema e desenvolvimento de contratos inteligentes, implementação do gerenciamento de privacidade e consentimento por meio de re-criptografia por proxy e aplicação de assinaturas de Boneh, Boyen e Shacham para compartilhamento seletivo de dados. As avaliações de prova de conceito e implementação, utilizando CosmWasm, Hyperledger Besu, Ethereum, pyUmbral PRE e BBS, mostram que o sistema descentralizado proposto é independente de plataforma, escalável e capaz de fornecer uma maior transparência, privacidade e confiança com uma sobrecarga mínima.Biblioteca Digitais de Teses e Dissertações da USPUeyama, JoGarcia, Rodrigo Dutra2023-06-16info:eu-repo/semantics/publishedVersioninfo:eu-repo/semantics/masterThesisapplication/pdfhttps://www.teses.usp.br/teses/disponiveis/55/55134/tde-06092023-102200/reponame:Biblioteca Digital de Teses e Dissertações da USPinstname:Universidade de São Paulo (USP)instacron:USPLiberar o conteúdo para acesso público.info:eu-repo/semantics/openAccesseng2023-09-06T13:30:03Zoai:teses.usp.br:tde-06092023-102200Biblioteca Digital de Teses e Dissertaçõeshttp://www.teses.usp.br/PUBhttp://www.teses.usp.br/cgi-bin/mtd2br.plvirginia@if.usp.br|| atendimento@aguia.usp.br||virginia@if.usp.bropendoar:27212023-09-06T13:30:03Biblioteca Digital de Teses e Dissertações da USP - Universidade de São Paulo (USP)false
dc.title.none.fl_str_mv Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
Governança de dados baseada em blockchain com preservação da privacidade em configurações com múltiplas partes interessadas
title Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
spellingShingle Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
Garcia, Rodrigo Dutra
Blockchain
Blockchain
Compartilhamento seletivo
Contratos inteligentes
Data governance
Decentralized
Descentralização
E-prescription
Governança de dados
Prescrição eletrônica
Privacidade
Privacy
Proxy re-encryption
Re-criptografia por proxy
Selective sharing
Smart contracts
title_short Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
title_full Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
title_fullStr Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
title_full_unstemmed Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
title_sort Blockchain-based data governance for privacy-preserving in multi-stakeholder settings
author Garcia, Rodrigo Dutra
author_facet Garcia, Rodrigo Dutra
author_role author
dc.contributor.none.fl_str_mv Ueyama, Jo
dc.contributor.author.fl_str_mv Garcia, Rodrigo Dutra
dc.subject.por.fl_str_mv Blockchain
Blockchain
Compartilhamento seletivo
Contratos inteligentes
Data governance
Decentralized
Descentralização
E-prescription
Governança de dados
Prescrição eletrônica
Privacidade
Privacy
Proxy re-encryption
Re-criptografia por proxy
Selective sharing
Smart contracts
topic Blockchain
Blockchain
Compartilhamento seletivo
Contratos inteligentes
Data governance
Decentralized
Descentralização
E-prescription
Governança de dados
Prescrição eletrônica
Privacidade
Privacy
Proxy re-encryption
Re-criptografia por proxy
Selective sharing
Smart contracts
description In multi-stakeholder systems, such as healthcare, the internet of things, and supply chain management, there is frequent data generation, exchange, and sharing. As a result, data owners often desire control over their data and maintain privacy, while data consumers require methods to ascertain the origins and creators of the data. These conflicts of interest require developing data governance systems that guarantee data provenance, privacy protection, consent management, and selective disclosure. This research proposed a decentralized data governance system utilizing blockchain technology, proxy re-encryption (PRE), and Boneh, Boyen, and Shacham (BBS) signatures to address these challenges. The proposed system enables data owners to control, selectively share, and track their data through privacy-enhancing, consent management, and selective disclosure mechanisms while also allowing data consumers to understand the lineage of the data through a blockchain-based provenance mechanism. As a case study, the research examined and evaluated electronic prescriptions involving sensitive data and multiple stakeholders, including patients as data owners and doctors and pharmacists as data consumers. The research was structured as a collection of articles organized in the following sequence: problem formulation and developing smart contracts, implementing privacy and consent management through PRE, and applying BBS signatures for selective data sharing. The proof-of-concept implementation and evaluations, conducted using CosmWasm, Hyperledger Besu, Ethereum, pyUmbral PRE, and BBS signatures, demonstrate that the proposed decentralized system is platform-agnostic, scalable, and capable of providing a higher level of transparency, privacy, and trust with minimal overhead.
publishDate 2023
dc.date.none.fl_str_mv 2023-06-16
dc.type.status.fl_str_mv info:eu-repo/semantics/publishedVersion
dc.type.driver.fl_str_mv info:eu-repo/semantics/masterThesis
format masterThesis
status_str publishedVersion
dc.identifier.uri.fl_str_mv https://www.teses.usp.br/teses/disponiveis/55/55134/tde-06092023-102200/
url https://www.teses.usp.br/teses/disponiveis/55/55134/tde-06092023-102200/
dc.language.iso.fl_str_mv eng
language eng
dc.relation.none.fl_str_mv
dc.rights.driver.fl_str_mv Liberar o conteúdo para acesso público.
info:eu-repo/semantics/openAccess
rights_invalid_str_mv Liberar o conteúdo para acesso público.
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.coverage.none.fl_str_mv
dc.publisher.none.fl_str_mv Biblioteca Digitais de Teses e Dissertações da USP
publisher.none.fl_str_mv Biblioteca Digitais de Teses e Dissertações da USP
dc.source.none.fl_str_mv
reponame:Biblioteca Digital de Teses e Dissertações da USP
instname:Universidade de São Paulo (USP)
instacron:USP
instname_str Universidade de São Paulo (USP)
instacron_str USP
institution USP
reponame_str Biblioteca Digital de Teses e Dissertações da USP
collection Biblioteca Digital de Teses e Dissertações da USP
repository.name.fl_str_mv Biblioteca Digital de Teses e Dissertações da USP - Universidade de São Paulo (USP)
repository.mail.fl_str_mv virginia@if.usp.br|| atendimento@aguia.usp.br||virginia@if.usp.br
_version_ 1815256725880569856