Abstract
Blockchain has attracted tremendous attention for solving the security problems of customer personal data in various domains via transparency, immutability, traceability, and decentralization properties. Unfortunately, inherent openness and immutability in traditional blockchain pose significant challenges to customers’ data privacy, also conflicts with the General Data Protection Regulation (GDPR) requirements, including “right to rectification” and “right to forgotten.” In order to solve the aforementioned issues, this paper introduces RedactChain: a novel redactable blockchain-enabled, privacy-protected personal data management scheme that allows data redactions without compromising the structural integrity of the blockchain. The RedactChain employs verifiable chameleon hash function and distributed trapdoor recovery mechanism that allows on-chain data modification and avoids the security problems faced by the centralized organization. Additionally, this scheme offers secure communication and fine-grained access control by applying attribute-based encryption(ABE). The comprehensive formal security analysis and empirical evaluation validate the efficacy of the proposed system and prove that the suggested framework ensures decentralization, integrity, and security of the data with optimal processing time.