Data utilization process can produce new value from a variety of data sources. Personal data is one of the valuable data sources, but its utilization has yet to reach its full potential due to the risk of data leakage. This paper proposes a decentralized data processing framework that leverages data usage control with trusted execution environments (TEEs) and distributed ledger technology. This framework allows data consumers to implement their data processing codes for flexible data utilization while data providers can control the use of data in those codes. Through this data usage control, data providers can control data disclosure or usage deadlines while preventing data leakage. We evaluate the proposed framework from both theoretical and practical perspectives. The results show that the proposed framework meets confidentiality requirements of provided data and that the prototype system using Intel SGX and Hyperledger Fabric can process small amounts of data, such as personal data, in acceptable time. While not suited for frequent data processing, it illustrates the potential for collecting and using personal data in advance, for example, to support disaster response.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Decentralized Data Usage Control with Confidential Data Processing on Trusted Execution Environment and Distributed Ledger Technology

  • Shota Tokuda,
  • Shohei Kakei,
  • Yoshiaki Shiraishi,
  • Shoichi Saito

摘要

Data utilization process can produce new value from a variety of data sources. Personal data is one of the valuable data sources, but its utilization has yet to reach its full potential due to the risk of data leakage. This paper proposes a decentralized data processing framework that leverages data usage control with trusted execution environments (TEEs) and distributed ledger technology. This framework allows data consumers to implement their data processing codes for flexible data utilization while data providers can control the use of data in those codes. Through this data usage control, data providers can control data disclosure or usage deadlines while preventing data leakage. We evaluate the proposed framework from both theoretical and practical perspectives. The results show that the proposed framework meets confidentiality requirements of provided data and that the prototype system using Intel SGX and Hyperledger Fabric can process small amounts of data, such as personal data, in acceptable time. While not suited for frequent data processing, it illustrates the potential for collecting and using personal data in advance, for example, to support disaster response.