Ait Bennacer Sara, Aaroud Abdessadek, Sabiri Khadija, Rguibi Mohamed Amine, Cherradi Bouchaib
LaROSERI Laboratory, Faculty of Sciences, Chouaib Doukkali University, El Jadida, 24000, Morocco.
Fraunhofer Portugal AICOS, Rua Alfredo Allen, 455/461, 4200-135, Porto, Portugal.
Inform Med Unlocked. 2022;35:101125. doi: 10.1016/j.imu.2022.101125. Epub 2022 Nov 3.
In the context of COVID-19 pandemic, the Moroccan Interior and Health Ministries have proposed to use the health pass with a QR code to identify vaccinated people. Additionally, the government suggested a mobile application to control the health passport authenticity. However, the key problem is the possibility of anyone scanning the QR code and figuring out citizens' private information, causing severe issues about individual privacy. In this work, the main contribution is integrating a private Blockchain-based digital health passport to ensure high protection of sensitive information, security and privacy among all the actors (Government, Ministry of Interior, Ministry of Health, verifiers) that comply with the CNDP (National Commission for the Control of Personal Data Protection) and the Moroccan Law 09-08. In our proposed architectural framework solution, we identify two types of actors: authorized and unauthorized, to limit and control access to the citizens' personal information. Besides, to preserve individuals' privacy, we adopt on-chain and off-chain storage (Interplanetary File Systems IPFS). In our case, smart contracts improve security and privacy in the health passport verification process. Our system implementation describes the proposed solution to grant individual privacy. To verify and validate our approach, we used Remix-IDE and Ethereum Blockchain to build smart contracts.
在新冠疫情背景下,摩洛哥内政部和卫生部提议使用带有二维码的健康通行证来识别已接种疫苗的人群。此外,政府还建议开发一款移动应用程序来查验健康通行证的真伪。然而,关键问题在于任何人都有可能扫描二维码并获取公民的私人信息,从而引发严重的个人隐私问题。在这项工作中,主要贡献在于集成了基于私有区块链的数字健康通行证,以确保在所有符合国家个人数据保护委员会(CNDP)和摩洛哥第09 - 08号法律的行为主体(政府、内政部、卫生部、验证者)之间高度保护敏感信息、安全和隐私。在我们提出的架构框架解决方案中,我们识别出两种类型的行为主体:授权和未授权的,以限制和控制对公民个人信息的访问。此外,为保护个人隐私,我们采用链上和链下存储(星际文件系统IPFS)。在我们的案例中,智能合约在健康通行证验证过程中提高了安全性和隐私性。我们的系统实现描述了所提出的保障个人隐私的解决方案。为验证和确认我们的方法,我们使用Remix - IDE和以太坊区块链来构建智能合约。