| Literature DB >> 34226768 |
Amal Abid1, Saoussen Cheikhrouhou1,2, Slim Kallel1,2, Mohamed Jmaiel1,2.
Abstract
The COVID-19 pandemic has emerged as a highly transmissible disease which has caused a disastrous impact worldwide by adversely affecting the global economy, health, and human lives. This sudden explosion and uncontrolled worldwide spread of COVID-19 has revealed the limitations of existing healthcare systems regarding handling public health emergencies. As governments seek to effectively re-establish their economies, open workplaces, ensure safe travels and progressively return to normal life, there is an urgent need for technologies that may alleviate the severity of the losses. This article explores a promising solution for secure Digital Health Certificate, called NovidChain, a Blockchain-based privacy-preserving platform for COVID-19 test/vaccine certificates issuing and verifying. More precisely, NovidChain incorporates several emergent concepts: (i) Blockchain technology to ensure data integrity and immutability, (ii) self-sovereign identity to allow users to have complete control over their data, (iii) encryption of Personally Identifiable Information to enhance privacy, (iv) W3C verifiable credentials standard to facilitate instant verification of COVID-19 proof, and (v) selective disclosure concept to permit user to share selected pieces of information with trusted parties. Therefore, NovidChain is designed to meet a high level of protection of personal data, in compliant with the GDPR and KYC requirements, and guarantees the user's self-sovereignty, while ensuring both the safety of populations and the user's right to privacy. To prove the security and efficiency of the proposed NovidChain platform, this article also provides a detailed technical description, a proof-of-concept implementation, different experiments, and a comparative evaluation. The evaluation shows that NovidChain provides better financial cost and scalability results compared to other solutions. More precisely, we note a high difference in time between operations (i.e., between 46% and 56%). Furthermore, the evaluation confirms that NovidChain ensures security properties, particularly data integrity, forge, binding, uniqueness, peer-indistinguishability, and revocation.Entities:
Keywords: Blockchain; COVID‐19 pandemic; GDPR; KYC; W3C verifiable credentials; digital health certificate; privacy self‐sovereignty
Year: 2021 PMID: 34226768 PMCID: PMC8242505 DOI: 10.1002/spe.2983
Source DB: PubMed Journal: Softw Pract Exp ISSN: 0038-0644
FIGURE 1Illustration of the blockchain
FIGURE 2Main roles and workflow in W3C verifiable credentials
FIGURE 3uPort general architecture
FIGURE 4NovidChain infrastructure and involved actors
FIGURE 5NovidChain approach overview
FIGURE 6NovidChain verifiable credential model
FIGURE 7NovidChain in action
FIGURE 8NovidChain architecture
FIGURE 9Validation: Login to NovidChain dApp
FIGURE 10Validation: Creating and issuing COVID‐19 credentials
FIGURE 11Validation: Requesting and verifying COVID‐19 credentials
Comparative evaluation of COVID‐19 certificate solutions
| Approach | Type | Security properties | Low cost | Scalability | ||||
|---|---|---|---|---|---|---|---|---|
| Forge | Binding | Uniqueness | Peer‐Indistinguishability | Revocation | ||||
| SecureABC | Crypto‐graphy | +/‐ | ‐ | + | + | +/‐ | not available | not available |
| CATCApp | Blockchain‐based | + | + | + | ‐ | ‐ | + | ‐ |
| ImmuPass | Blockchain‐based | + | + | + | ‐ | +/‐ | ‐ | ‐ |
| NovidChain | Blockchain‐based | + | + | + | + | + | + | ++/‐ |
Cost of issuing a COVID‐19 certificate
| Approach | Gas | USD |
|---|---|---|
| ImmuPass | 131,398 | $11.89 |
| CATCApp | 24,128 | $2.18 |
| NovidChain | 24,128 | $2.18 |
Variable values of Equation (1)
|
| 12,500,000 gas units |
|---|---|
|
| 21,000 gas units |
|
| 68 gas units |
|
| 20,000 gas units |
|
| 46 bytes |
FIGURE 12Latency evaluation
Comparison of COVID‐19 certificate approaches
| Approach | Infrastructure | Security features | Implementation details | |||||
|---|---|---|---|---|---|---|---|---|
| No centralization | No third party | Blockchain | Privacy‐ preserving | Self‐ sovereignty | GDPR‐ compliant | KYC‐ compliant | ||
| CoronaPass | ‐ | + | ‐ | ‐ | ‐ | ‐ | + | ‐ |
| ChinaAlipayApp | + | ‐ | ‐ | ‐ | ‐ | ‐ | + | ‐ |
| ImmuPass | + | + | + | ‐ | ‐ | ‐ | + | + |
| CERTUS | + | + | + | ‐ | ‐ | ‐ | + | ‐ |
| VaccineGuard | + | + | + | + | + | + | + | ‐ |
| COVI‐Pass | + | + | + | + | + | + | + | ‐ |
| DigiLocker | + | + | + | + | + | + | + | ‐ |
| DigitalGreen Certificate | + | + | + | + | + | + | + | ‐ |
| DigitalHealthPass | + | + | + | + | + | + | + | ‐ |
| CATCApp | + | ‐ | + | ‐ | + | ‐ | + | + |
| SecureABC | + | + | ‐ | + | + | + | ‐ | + |
| NovidChain | + | + | + | + | + | + | + | + |