Privacy-preserving mobility as a service supported by blockchain
The present disclosure provides a communication network node for providing data to a distributed ledger, wherein the node has circuitry configured to: provide a user data management part for separating sensitive user data and non-sensitive user data, and provide the non-sensitive user data to the distributed ledger.
1. A communication network node for providing data to a distributed ledger, wherein the node comprises circuitry configured to:
separate sensitive user data and non-sensitive user data,
provide the non-sensitive user data to the distributed ledger,
store the sensitive user data off-chain and only in a database of the node in which the sensitive user data originated, and
restrict access control based on a purpose of data use,
wherein in a case where the node is a mobility service provider, pseudonymization of the sensitive user data is required for a mobility service provider to write the sensitive user data to a blockchain,
wherein in a case the node is a ticket issuer, the ticket issuer is limited to predetermined information and pseudonymization of the sensitive user data is required for the ticket issuer to write the sensitive user data to a blockchain,
wherein in a case where the node is providing data to a third party for data analysis, anonymization is required for the third-party data analysis, and
wherein in a case where the node received a request from a passenger to delete their data, the node permits access to the passenger to delete their sensitive user data.
2. The communication network node of claim 1 , wherein the distributed ledger includes a blockchain.
3. The communication network node of claim 2 , wherein the blockchain includes multiple blocks, the blocks including the non-sensitive user data.
4. The communication network node of claim 1 , wherein the distributed ledger includes data for mobility as a service.
5. The communication network node of claim 1 , wherein access to the distributed ledger is granted based on a permission right.
6. The communication network node of claim 5 , wherein the node is part of a consortium.
7. A communication network comprising multiple nodes for providing a distributed ledger, wherein at least one node comprises circuitry configured to:
separate sensitive user data and non-sensitive user data,
provide the non-sensitive user data to the distributed ledger,
store the sensitive user data off-chain and only in a database of the node in which the sensitive user data originated. and
restrict access control based on a purpose of data use,
wherein in a case where the node is a mobility service provider, pseudonymization of the sensitive user data is required for a mobility service provider to write the sensitive user data to a blockchain,
wherein in a case the node is a ticket issuer, the ticket issuer is limited to predetermined information and pseudonymization of the sensitive user data is required for the ticket issuer to write the sensitive user data to a blockchain,
wherein in a case where the node is providing data to a third party for data analysis, anonymization is required for the third-party data analysis, and
wherein in a case where the node received a request from a passenger to delete their data, the node permits access to the passenger to delete their sensitive user data.
8. The communication network of claim 7 , wherein the distributed ledger includes a blockchain.
9. The communication network of claim 8 , wherein the blockchain includes multiple blocks, the block including the non-sensitive user data.
10. The communication network of claim 7 , wherein the distributed ledger includes data for mobility as a service.
11. The communication network of claim 7 , wherein access to the distributed ledger is granted based on a permission right.
12. The communication network of claim 11 , wherein the nodes are part of a consortium.
13. The communication network of claim 7 , wherein personal user data in the distributed ledger are pseudonymized or anonymized.
14. The communication network of claim 13 , wherein the personal user data are pseudonymized by scrambling the sensitive user data.
15. The communication network of claim 13 , wherein the personal user data are anonymized based on applying a hash algorithm.
16. The communication network of claim 7 , wherein an access control for the non-sensitive data is provided.
17. The communication network of claim 16 , wherein the access control is performed on the basis of a key. the key being used for encryption of the non-sensitive data.
18. The communication network of claim 7 , wherein personal user data or the non-sensitive user data can be erased in response to a request from at least one node.