PrivacyGuard: Enforcing Private Data Usage with Blockchain and Attested Execution

  • Ning Zhang
  • , Jin Li
  • , Wenjing Lou
  • , Y. Thomas Hou

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In the upcoming evolution of the Internet of Things (IoT), it is anticipated that billions of devices will be connected to the Internet. Many of these devices are capable of collecting information from individual users and their physical surroundings. They are also capable of taking smart actions, which are usually from a backend cloud server in the IoT system. While IoT promises a more connected and smarter world, this pervasive large-scale data collection, storage, sharing, and analysis raise many privacy concerns. In the current IoT ecosystem, IoT service providers have full control of the collected user data. While the original intended use of such data is primarily for smart IoT system and device control, the data is often used for other purposes not explicitly consented to by the users. We propose a novel user privacy protection framework, PrivacyGuard, that aims to empower users with full privacy control of their data. Privacy- Guard framework seamlessly integrates two new technologies, blockchain and trusted execution environment (TEE). By encoding data access policy and usage as smart contracts, PrivacyGuard can allow data owners to control who can have what access to their data, and be able to maintain a trustworthy record of their data usage. Using remote attestation and TEE, PrivacyGuard ensures that data is only used for the intended purposes approved by the data owner. Our approach represents a significant departure from traditional privacy protections which often rely on cryptography and pure software-based secure computation techniques. Addressing the fundamental problem of data usage control, PrivacyGuard will become the cornerstone for free market of private information.

Original languageEnglish
Title of host publicationData Privacy Management, Cryptocurrencies and Blockchain Technology - ESORICS 2018 International Workshops, DPM 2018 and CBT 2018, Proceedings
EditorsJoaquin Garcia-Alfaro, Jordi Herrera-Joancomartí, Giovanni Livraga, Ruben Rios
PublisherSpringer Science and Business Media Deutschland GmbH
Pages345-353
Number of pages9
ISBN (Print)9783030003043
DOIs
StatePublished - 2018
Event2nd International Workshop on Cryptocurrencies and Blockchain Technology, CBT 2018 held in conjunction with the 23rd European Symposium on Research in Computer Security, ESORICS 2018 - Barcelona, Spain
Duration: Sep 6 2018Sep 7 2018

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume11025 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference2nd International Workshop on Cryptocurrencies and Blockchain Technology, CBT 2018 held in conjunction with the 23rd European Symposium on Research in Computer Security, ESORICS 2018
Country/TerritorySpain
CityBarcelona
Period09/6/1809/7/18

Keywords

  • Blockchain
  • Private User Data
  • Remote Attestation
  • Smart Contracts
  • Trusted Execution Environment (TEE)

Fingerprint

Dive into the research topics of 'PrivacyGuard: Enforcing Private Data Usage with Blockchain and Attested Execution'. Together they form a unique fingerprint.

Cite this