METHOD FOR FORMING AN INTER-REGISTRY INTERACTION PROTOCOL WITH MINIMAL PERSONAL DATA DISCLOSURE

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1381

Keywords:

government electronic registries, inter-registry interaction, personal data, data minimisation;, zero-knowledge proof, permissioned blockchain, protocol, access policy, audit commitment

Abstract

The article addresses the scientific and practical problem of excessive personal data disclosure during interactions between government electronic registries. In many cases, an administrative or legal decision requires only confirmation that a specified condition has been satisfied; nevertheless, the requesting system receives the value of the original attribute or a fragment of the registry record. This approach increases the amount of data available to the verifier, complicates control over its subsequent use, and creates additional risks of correlating information across different information systems. The aim of the study is to develop a method for constructing a policy-dependent inter-registry interaction protocol that verifies whether a request is permitted, confirms a specified predicate without disclosing the original attribute, and creates a verifiable audit record without storing personal data or persistent correlation data in a permissioned blockchain. The method combines a versioned minimum-disclosure profile; validation of the purpose, legal basis, audience, validity period, and predicate parameters; binding of the ZK proof to the context of a specific operation; and the generation of a keyed audit commitment. Only the minimum information required for subsequent integrity verification is recorded in the blockchain, whereas the complete evidentiary data are retained in a protected off-chain repository. The formal model is presented for a range predicate and supplemented with decision-acceptance conditions, replay protection, and policy freshness validation. Domain-specific conditions are checked before cryptographic operations are performed, preventing a cryptographically valid proof from being accepted for an unauthorised purpose. The study also defines the composition of on-chain and off-chain data, the procedure for recomputing the audit commitment, and scenarios for detecting proof modification, nonce reuse, outdated policy versions, and stale registry assertions. The reference prototype was implemented on the secp256k1 curve using Pedersen commitments, bit decomposition, non-interactive OR proofs, Ed25519, and HMAC-SHA-256. After 15 warm-up runs, 150 timing measurements and 2,000 functional tests across ten classes were conducted. The median proof generation time was 30.587 ms, while the median verification time was 34.663 ms; the corresponding 95th percentiles were 32.939 ms and 37.003 ms. The serialised proof size was 7,185 bytes. All valid requests were accepted, while violations involving the purpose, parameters, audience, validity period, policy version, status freshness, nonce uniqueness, and data integrity were detected. For the evaluated predicate, the original attribute was not transmitted to the verifier. The principal scientific contribution is the formalisation of an end-to-end relationship between an authorised purpose, a minimal predicate, a context-bound proof, and a private audit anchor. The proposed method can be used as a control layer between a policy service, a source registry, and a permissioned blockchain.

Downloads

Download data is not yet available.

References

Verkhovna Rada of Ukraine. (2010). Pro zakhyst personalnykh danykh [On personal data protection] (Law of Ukraine No. 2297-VI, June 1, 2010). https://zakon.rada.gov.ua/laws/show/2297-17#Text

Verkhovna Rada of Ukraine. (2021). Pro publichni elektronni reiestry [On public electronic registers] (Law of Ukraine No. 1907-IX, November 18, 2021). https://zakon.rada.gov.ua/laws/show/1907-20#Text

European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj

International Organization for Standardization & International Electrotechnical Commission. (2026). Information security, cybersecurity and privacy protection – Guidelines on privacy preservation based on zero-knowledge proofs (ISO/IEC 27565:2026). ISO. https://www.iso.org/standard/80398.html

International Organization for Standardization & International Electrotechnical Commission. (2021). Information security, cybersecurity and privacy protection – Requirements for attribute-based unlinkable entity authentication (ISO/IEC 27551:2021). ISO. https://www.iso.org/standard/72018.html

World Wide Web Consortium. (2025). Verifiable credentials data model v2.0 (W3C Recommendation, May 15, 2025). https://www.w3.org/TR/vc-data-model-2.0/

OpenID Foundation. (2025). OpenID for verifiable presentations 1.0 (OpenID Final Specification, July 9, 2025). https://openid.net/specs/openid-4-verifiable-presentations-1_0.html

Bernstein, G., & Sporny, M. (2026). Data integrity BBS cryptosuites v1.0 (W3C Candidate Recommendation Draft, April 7, 2026). World Wide Web Consortium. https://www.w3.org/TR/vc-di-bbs/

Flamini, A., Sciarretta, G., Scuro, M., Sharif, A., Tomasi, A., & Ranise, S. (2024). On cryptographic mechanisms for the selective disclosure of verifiable credentials. Journal of Information Security and Applications, 83, Article 103789. https://doi.org/10.1016/j.jisa.2024.103789

Podda, E., Hölzmer, P., Amard, A., Sedlmeir, J., & Fridgen, G. (2025). The impact of zero-knowledge proofs on data minimisation compliance of digital identity wallets. Internet Policy Review, 14(3), 1–29. https://doi.org/10.14763/2025.3.2019

Pedersen, T. P. (1992). Non-interactive and information-theoretic secure verifiable secret sharing. In Advances in Cryptology – CRYPTO ’91 (Lecture Notes in Computer Science, Vol. 576, pp. 129–140). Springer. https://doi.org/10.1007/3-540-46766-1_9

Cramer, R., Damgård, I., & Schoenmakers, B. (1994). Proofs of partial knowledge and simplified design of witness hiding protocols. In Advances in Cryptology – CRYPTO ’94 (Lecture Notes in Computer Science, Vol. 839, pp. 174–187). Springer. https://doi.org/10.1007/3-540-48658-5_19

Fiat, A., & Shamir, A. (1987). How to prove yourself: Practical solutions to identification and signature problems. In Advances in Cryptology – CRYPTO ’86 (Lecture Notes in Computer Science, Vol. 263, pp. 186–194). Springer. https://doi.org/10.1007/3-540-47721-7_12

Rundgren, A., Jordan, B., & Erdtman, S. (2020). JSON Canonicalization Scheme (JCS) (RFC 8785). Internet Engineering Task Force. https://www.rfc-editor.org/rfc/rfc8785

Josefsson, S., & Liusvaara, I. (2017). Edwards-Curve Digital Signature Algorithm (EdDSA) (RFC 8032). Internet Engineering Task Force. https://www.rfc-editor.org/rfc/rfc8032

Krawczyk, H., Bellare, M., & Canetti, R. (1997). HMAC: Keyed-hashing for message authentication (RFC 2104). Internet Engineering Task Force. https://www.rfc-editor.org/rfc/rfc2104

Rescorla, E. (2026). The Transport Layer Security (TLS) Protocol Version 1.3 (RFC 9846). Internet Engineering Task Force. https://doi.org/10.17487/RFC9846

Androulaki, E., Barger, A., Bortnikov, V., et al. (2018). Hyperledger Fabric: A distributed operating system for permissioned blockchains. In Proceedings of the Thirteenth EuroSys Conference (Article 30, pp. 1–15). ACM. https://doi.org/10.1145/3190508.3190538

Putz, B., Menges, F., & Pernul, G. (2019). A secure and auditable logging infrastructure based on a permissioned blockchain. Computers & Security, 87, Article 101602. https://doi.org/10.1016/j.cose.2019.101602

National Institute of Standards and Technology. (2020). NIST Privacy Framework: A tool for improving privacy through enterprise risk management (Version 1.0). https://www.nist.gov/privacy-framework/privacy-framework

Balatska, V. S., & Opirskyy, I. R. (2023). Ensuring personal data confidentiality and cybersecurity support using blockchain. Cybersecurity: Education, Science, Technique, 4(20), 6–19. https://doi.org/10.28925/2663-4023.2023.20.619

Balatska, V., & Poberezhnyk, V. (2024). Concept of using blockchain technologies to enhance personal data security of the Diia platform: Compliance with GDPR and Ukrainian legislation. Cybersecurity: Education, Science, Technique, 2(26), 268–290. https://doi.org/10.28925/2663-4023.2024.26.681

Balatska, V., Slobodian, N., & Opirskyy, I. (2024). Blockchain for enhancing transparency and trust in government registries. CEUR Workshop Proceedings, 3826, 50–59. https://ceur-ws.org/Vol-3826/

Balatska, V., & Dmytriv, N. (2025). Interorganizational exchange of confidential personal data based on permissioned blockchain. Cybersecurity: Education, Science, Technique, 1(29), 178–193. https://doi.org/10.28925/2663-4023.2025.29.875

Balatska, V. (2026). Blockchain-oriented approach to ensuring traceability and verifiability of information protection system policy implementation. Cybersecurity: Education, Science, Technique, 4(32), 674–685. https://doi.org/10.28925/2663-4023.2026.32.1136

Balatska, V. S., Ivanusa, A. I., & Panovyk, U. M. (2025). Method for integrating information security policies, standards, and protocols into the process of building a comprehensive information protection system in an organization. Cybersecurity: Education, Science, Technique, 3(31), 283–297. https://doi.org/10.28925/2663-4023.2025.31.1021

Downloads


Abstract views: 10

Published

2026-09-24

How to Cite

Balatska, V. (2026). METHOD FOR FORMING AN INTER-REGISTRY INTERACTION PROTOCOL WITH MINIMAL PERSONAL DATA DISCLOSURE. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 806–819. https://doi.org/10.28925/2663-4023.2026.34.1381

Most read articles by the same author(s)