Any organization providing services to users typically requires the users to share some degree of personal information in order to access these services. However, users seldom have complete visibility or control over their own data, justifiably raising serious privacy concerns. Additionally, organizations are often inhibited from collaboration due to the increased risk of privacy breaches, and corresponding reporting requirements. Increasing privacy focused legislation worldwide such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) create complex protection and reporting requirements that need to be systematically enforced. The Right To Be Forgotten (RTBF) recommendations included in GDPR essentially demand that every individual has the right to request for erasure of data pertaining to it, and thus in effect be forgotten from the system on demand. We propose a novel approach called CRISP (Consensus-enabled, Redactable, Immutable, Securely shareable, Provable) that uses permissioned enterprise blockchains for trustless interoperation among a network of identifiable organizations providing the ability to support RTBF. It combines off-chain data storage and distributed resource sharing with blockchain consensus mechanisms and decentralized access control. We describe the various components of CRISP and delineate the detailed steps of its operation. Results of an extensive set of experiments clearly establish the viability of our approach.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enabling Right to be Forgotten in a Collaborative Environment Using Permissioned Blockchains

  • Anand Manojkumar Parikh,
  • Shamik Sural,
  • Vijayalakshmi Atluri,
  • Jaideep Vaidya

摘要

Any organization providing services to users typically requires the users to share some degree of personal information in order to access these services. However, users seldom have complete visibility or control over their own data, justifiably raising serious privacy concerns. Additionally, organizations are often inhibited from collaboration due to the increased risk of privacy breaches, and corresponding reporting requirements. Increasing privacy focused legislation worldwide such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) create complex protection and reporting requirements that need to be systematically enforced. The Right To Be Forgotten (RTBF) recommendations included in GDPR essentially demand that every individual has the right to request for erasure of data pertaining to it, and thus in effect be forgotten from the system on demand. We propose a novel approach called CRISP (Consensus-enabled, Redactable, Immutable, Securely shareable, Provable) that uses permissioned enterprise blockchains for trustless interoperation among a network of identifiable organizations providing the ability to support RTBF. It combines off-chain data storage and distributed resource sharing with blockchain consensus mechanisms and decentralized access control. We describe the various components of CRISP and delineate the detailed steps of its operation. Results of an extensive set of experiments clearly establish the viability of our approach.