Privacy implications of blockchain systems: a data management perspective

Heng Xu, N. Zhang
{"title":"Privacy implications of blockchain systems: a data management perspective","authors":"Heng Xu, N. Zhang","doi":"10.1108/ocj-01-2023-0003","DOIUrl":null,"url":null,"abstract":"PurposePrivacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? Blockchain does not seem to neatly fit into any of these buckets that we traditionally use to gauge the privacy implications of information technologies. In this article, the authors argue that blockchain transcends the extant conceptualization of privacy because it modifies the nature of data flow upon which the modern concept of privacy is based.Design/methodology/approachThe authors introduce a conceptualization of blockchain as a new mechanism for data management. Then, following this conceptualization, the authors present a functional review of blockchain, summarizing the features it provides for the data it manages. This review sets up the discussion of how blockchain redefines data flow by separating the power of collection, access and query of data to different entities. After illustrating how this change regrounds privacy concerns in a blockchain system, the authors conclude with a discussion of the recommendations for future privacy research on blockchain.FindingsThe authors demonstrate that blockchain, by design, separates three core data-centric operations that are assumed to be inextricably linked in the canonical conceptualization of privacy: the collection, access and query of data. Collection means to capture and then store the data; access means to modify or augment the data and query means the ability to test or verify certain properties of the data (e.g. whether a bank account has a zero balance). Traditionally, any entities that collect data can evidently read, modify or query the same data as they wish. With blockchain, however, an entity that stores the data may not be able to modify the data, yet an entity that cannot even read the data may be able to verify certain properties of the data.Originality/valuePrivacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? In this article, the authors aim to respond to this important question.","PeriodicalId":107089,"journal":{"name":"Organizational Cybersecurity Journal: Practice, Process and People","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Organizational Cybersecurity Journal: Practice, Process and People","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1108/ocj-01-2023-0003","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

PurposePrivacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? Blockchain does not seem to neatly fit into any of these buckets that we traditionally use to gauge the privacy implications of information technologies. In this article, the authors argue that blockchain transcends the extant conceptualization of privacy because it modifies the nature of data flow upon which the modern concept of privacy is based.Design/methodology/approachThe authors introduce a conceptualization of blockchain as a new mechanism for data management. Then, following this conceptualization, the authors present a functional review of blockchain, summarizing the features it provides for the data it manages. This review sets up the discussion of how blockchain redefines data flow by separating the power of collection, access and query of data to different entities. After illustrating how this change regrounds privacy concerns in a blockchain system, the authors conclude with a discussion of the recommendations for future privacy research on blockchain.FindingsThe authors demonstrate that blockchain, by design, separates three core data-centric operations that are assumed to be inextricably linked in the canonical conceptualization of privacy: the collection, access and query of data. Collection means to capture and then store the data; access means to modify or augment the data and query means the ability to test or verify certain properties of the data (e.g. whether a bank account has a zero balance). Traditionally, any entities that collect data can evidently read, modify or query the same data as they wish. With blockchain, however, an entity that stores the data may not be able to modify the data, yet an entity that cannot even read the data may be able to verify certain properties of the data.Originality/valuePrivacy scholars appear to struggle in conceptualizing blockchain from a privacy perspective: is it a privacy-enhancing mechanism like differential privacy, a privacy-intruding tool like third-party cookies or a technology orthogonal to the issue of privacy? In this article, the authors aim to respond to this important question.
区块链系统对隐私的影响:数据管理的视角
目的隐私学者似乎很难从隐私的角度对区块链进行概念化:它是一种像差异隐私一样的隐私增强机制,还是一种像第三方cookie一样的隐私侵犯工具,还是一种与隐私问题无关的技术?区块链似乎并不完全符合我们传统上用来衡量信息技术对隐私影响的任何一个范畴。在本文中,作者认为区块链超越了现有的隐私概念,因为它修改了现代隐私概念所基于的数据流的性质。设计/方法/方法作者介绍了区块链作为数据管理新机制的概念。然后,根据这一概念,作者对区块链进行了功能回顾,总结了它为其管理的数据提供的特性。本文将讨论区块链如何通过将收集、访问和查询数据的权力分离到不同的实体来重新定义数据流。在说明了这种变化如何引起区块链系统中的隐私问题之后,作者最后讨论了对区块链的未来隐私研究的建议。作者证明,b区块链在设计上分离了三个以数据为中心的核心操作:数据的收集、访问和查询,这些操作在隐私的规范概念中被认为是密不可分的。收集是指采集并存储数据;访问意味着修改或增加数据,查询意味着测试或验证数据的某些属性的能力(例如,银行账户是否有零余额)。传统上,收集数据的任何实体显然都可以按照自己的意愿读取、修改或查询相同的数据。但是,对于区块链,存储数据的实体可能无法修改数据,而甚至无法读取数据的实体可能能够验证数据的某些属性。原创/价值隐私学者似乎很难从隐私的角度对区块链进行概念化:它是一种像差异隐私一样的隐私增强机制,还是一种像第三方cookie一样的隐私侵犯工具,还是一种与隐私问题无关的技术?在本文中,作者旨在回答这个重要的问题。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信