Title
Towards Contractual Agreements For Revocation Of Online Data
Abstract
Once personal data is published online, it is out of the control of the user and can be a threat to users' privacy. Retroactively deleting data after it has been published is notoriously unreliable due to the distributed and open nature of the Internet. Cryptographic approaches implementing data revocation address this problem, but have serious limitations when considering practical deployment, and they have not been broadly adopted.In this paper, we tackle the problem of data revocation from a different perspective by examining how contractual agreements can be applied to create incentives for providers to conform to expiration regulations. Specifically, we propose a protocol to automate the handling of data revocation. We have implemented a prototype smart contract on a local Ethereum blockchain to demonstrate the feasibility of our approach. Our approach has distinct advantages over existing proposals: It can deal with a wide spectrum of revocation conditions, it can be applied retroactively after data has been published, and it does not require additional effort for users accessing the published data. It thus constitutes an interesting, novel approach to data revocation.
Year
DOI
Venue
2019
10.1007/978-3-030-22312-0_26
ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2019
Field
DocType
Volume
Internet privacy,Software deployment,Cryptography,Computer science,Computer security,Revocation,The Internet
Conference
562
ISSN
Citations 
PageRank 
1868-4238
0
0.34
References 
Authors
0
3
Name
Order
Citations
PageRank
Theodor Schnitzler102.37
Markus Dürmuth242325.28
Christina Pöpper347633.27