The Right to Be Zero-Knowledge Forgotten

被引:0
作者
Visconti, Ivan [1 ]
机构
[1] Univ Salerno, Fisciano, SA, Italy
来源
19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024 | 2024年
关键词
Right to Be Forgotten; Zero Knowledge Proofs; Security By Design;
D O I
10.1145/3664476.3669973
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The main goal of the EU GDPR is to protect personal data of individuals within the EU. This is expressed in several rights and, among them, in this work we focus on the Right to Erasure, more commonly known as the Right to Be Forgotten (RtBF). There is an intriguing debate about the affordable costs and the actual technical feasibility of satisfying the RtBF in digital platforms. We note that some digital platforms process personal data in order to derive and store correlated data raising two main issues: 1) removing personal data could create inconsistencies in the remaining correlated data; 2) correlated data could also be personal data. As such, in some cases, erasing personal data can trigger an avalanche on the remaining information stored in the platform. Addressing the above issues can be very challenging in particular when a digital platform has been originally built without embedding in its design specific methodologies to deal with the RtBF. This work aims at illustrating concrete scenarios where the RtBF is technically hard to guarantee with traditional techniques. On the positive side, we show how zero-knowledge (ZK) proofs can be leveraged to design affordable solutions in various use cases, especially when considered at design time. ZK proofs can be instrumental for compliance to the RtBF revolutionizing the current approaches to design compliant systems. Concretely, we show an assessment scheme allowing to check compliance with the RtBF leveraging the power of ZK proofs. We analyze the above assessment scheme considering specific hard-to-address use cases.
引用
收藏
页数:9
相关论文
共 34 条
  • [1] 2023, Arxiv, DOI [arXiv:2303.08774, 10.48550/arXiv.2303.08774]
  • [2] [Anonymous], 2016, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance), P1
  • [3] Redactable Blockchain - or - Rewriting History in Bitcoin and Friends
    Ateniese, Giuseppe
    Magri, Bernardo
    Venturi, Daniele
    Andrade, Ewerton R.
    [J]. 2017 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P), 2017, : 111 - 126
  • [4] Avitabile Gennaro, 2024, P 6 DISTR LEDG TECHN
  • [5] Bellare M., 1993, PROCEED INGS 1 ACM, P62, DOI [10.1145/168588.168596, DOI 10.1145/168588.168596]
  • [6] Ben-Sasson E., 2018, Cryptology ePrint Archive
  • [7] Zerocash: Decentralized Anonymous Payments from Bitcoin
    Ben-Sasson, Eli
    Chiesa, Alessandro
    Garmant, Christina
    Green, Matthew
    Miers, Ian
    Tromer, Eran
    Virza, Madars
    [J]. 2014 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2014), 2014, : 459 - 474
  • [8] Bitansky N, 2013, STOC'13: PROCEEDINGS OF THE 2013 ACM SYMPOSIUM ON THEORY OF COMPUTING, P111
  • [9] Towards Data Redaction in Bitcoin
    Botta, Vincenzo
    Iovino, Vincenzo
    Visconti, Ivan
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (04): : 3872 - 3883
  • [10] Buterin V., 2022, Proof of stake the making of ethereum and the philosophy of blockchains