Privacy-preserving mobility as a service supported by blockchain
The present disclosure provides a communication network node for providing data to a distributed ledger, wherein the node has circuitry configured to: provide a user data management part for separating sensitive user data and non-sensitive user data, and provide the non-sensitive user data to the distributed ledger.
1. A method for controlling a communication network comprising multiple nodes for providing a distributed ledger, the comprising:
separating sensitive user data and nonsensitive user data associated with a mobility as a service transaction;
providing the non-sensitive user data to the distributed ledger;
storing the sensitive user data in a database of a node separate from the distributed ledger;
generating a hash of the sensitive user data and storing the hash on the distributed ledger;
verifying, using the hash, the sensitive user data without disclosing the sensitive user data on the distributed ledger;
encrypting the sensitive user data using a master encryption key that is accessible only to a mobility as a service provider having a contract with a user associated with the sensitive user data; and
encrypting the non-sensitive user data using a service provider encryption key that is shared among multiple mobility as a service providers having access to the distributed ledger.
2. The method of claim 1 , wherein the distributed ledger includes a blockchain.
3. The method of claim 2 , wherein the blockchain includes multiple blocks, the blocks including the non-sensitive user data.
4. The method of claim 1 , wherein the distributed ledger includes data for mobility as a service.
5. The method of claim 1 , wherein access to the distributed ledger is granted based on a permission right.
6. The method of claim 5 , wherein the nodes are part of a consortium.
7. The method of claim 1 , wherein personal user data in the distributed ledger are pseudonymized or anonymized.
8. The method of claim 7 , wherein the personal user data are pseudonymized by scrambling the sensitive user data.
9. The method of claim 7 , wherein the personal user data are anonymized based on applying a hash algorithm.
10. The method of claim 1 , wherein an access control for the non-sensitive data is provided.
11. The method of claim 10 , wherein the access control is performed on the basis of a key, the key being used for encryption of the non-sensitive data.
12. The method of claim 11 , wherein the access control provides different keys for different parties.
13. The method of claim 10 , wherein the access control gives access to the non-sensitive data over an application programming interface.
14. The method of claim 1 , wherein personal user data or the non-sensitive user data can be erased in response to a request from at least one node.
15. The method of claim 14 , wherein data is erased by invalidation of a key.
16. The method of claim 14 , wherein the data is erased by erasing data from the distributed ledger.
17. The method of claim 16 , wherein the distributed ledger includes a blockchain and wherein at least one block is erased.
18. Circuitry for a communication network node for providing data to a distributed ledger, configured to:
separate sensitive user data and non-sensitive user data associated with a mobility as a service transaction,
provide the non-sensitive user data to the distributed ledger,
store the sensitive user data in a database of a node separate from the distributed ledger,
generate a hash of the sensitive user data and storing the hash on the distributed ledger,
verify, using the hash, the sensitive user data without disclosing the sensitive user data on the distributed ledger,
encrypt the sensitive user data using a master encryption key that is accessible only to a mobility as a service provider having a contract with a user associated with the sensitive user data, and
encrypt the non-sensitive user data using a service provider encryption key that is shared among multiple mobility as a service providers having access to the distributed ledger.
19. A system, comprising:
a communication network including multiple nodes for providing a distributed ledger; and
circuitry configured to
separate sensitive user data and non-sensitive user data associated with a mobility as a service transaction, and
provide the non-sensitive user data to the distributed ledger,
store the sensitive user data in a database of a node separate from the distributed ledger,
generate a hash of the sensitive user data and storing the hash on the distributed ledger,
verify, using the hash, the sensitive user data without disclosing the sensitive user data on the distributed ledger,
encrypt the sensitive user data using a master encryption key that is accessible only to a mobility as a service provider having a contract with a user associated with the sensitive user data, and
encrypt the non-sensitive user data using a service provider encryption key that is shared among multiple mobility as a service providers having access to the distributed ledger.