This paper is a preliminary work in progress paper dealing with contract drafting for smart legal contracts. The paper describes how lawyers are taught to draft in a non-deterministic style which will not work for smart legal contracts. Smart legal contracts will be written in some computer code which will be in a deterministic language. This difference may also require lawyers to be trained in a new style of drafting and possibly being trained to produce appropriate pseudo-code. Finally contract interpretation could become complex as judges will now have to understand how the smart contract code corresponds to the natural language version and possible the intermediate step of pseudo-code analysis. The paper provides an outline of the difficulties that will confront the next generation of front-end contract lawyers.
Software Agents is a relatively new phenomenon. The first jurisdiction to recognize the legal impact of "software Agents" was the USA through the Uniform Electronic Transactions Act 1999. This paper analyses the legal ability of software agents to form contracts under Australia law but in do so also includes how other jurisdictions have attended to this mechanism.
Nakamoto proposed a new solution to transact value via the internet. And since 2009, blockchain technology has expanded and diversified. It has, however, proven to be inefficient in the way it achieves its outcomes, especially through the proof of work protocol. Other developers are promoting alternative methods but, as yet, none has superseded proof of work. The competing protocols illuminate a key feature of the blockchain community, namely, its inability to create consensus in a decentralized community. Because of this lack of consensus, the formation of standards is particularly difficult to achieve. At best standards are contested sites, and we examine three such sites where some form of agreement over standards will be essential if blockchain is to evolve successfully. These three sites are blockchain governance, smart contracts, and interoperability of blockchains. We argue that because standards' formation is a contested and contingent process, the blockchain community will persist in creating difficulties and barriers for itself until it is able to resolve internal conflicts.
Most start-ups find it difficult to raise finance. In the last few years a new form of funding has emerged—the initial coin offering (ICO). ICOs provide investors with cryptotokens that often have multiple roles as stored value token, pure utility token, security token, and hybrid token. ICOs attempt to create involvement in projects without giving away equity. However, as ICOs have risen in number regulators have become more interested and sought to provide rules for their proper functioning. In this paper we argue that the regulators often overlook the advantages of ICOs in order to focus on their faults. We propose ICOs ought to comprise a new asset class with their own rules.
The Australian Treasury has identified a number of challenges in FinTech, especially around Initial Coin Offerings (ICOs). In this paper we examine four types of tokens within ICOs: pure utility tokens, security tokens, stored value tokens, and hybrid tokens. There is considerable confusion surrounding what each means and signifies, and how each should be treated by both consumers and regulators. We explore the differences, noting what promoters should do to avoid falling into regulatory traps, and the consequences for selecting particular types of token. Because of the confusion around ICO tokens, we suggest there should be a new asset class of token recognised in the Australian Corporations Act. It would have its own funding limits and regulatory framework. Finally, we outline a new code of conduct for ICOs.
Nakamoto proposed a new solution to transact value via the internet. The internet prior to the advent of bitcoin was primarily a communications environment for non-face-to-face interaction. The Internet developed into a global publishing environment. To carry out a commercial transaction it was necessary to involve some third party who would validate the financial aspects of the transaction. The heart of the bitcoin solution was the blockchain construct, which was designed to dis-intermediate the involvement of the third-party validator, and thus reduce a fiction costs associated with the transaction.The blockchain as originally proposed, with its proof of work consensus protocol, has been shown to have some uncommercial aspects to which researchers globally are attempting to solve. Further, since the blockchain is a distributed environment, commercial compliance requirements can impact the architecture of a blockchain. The architecture of a blockchain must meet the regulatory compliance which could be industry specific such as financial and health regulatory obligations or general such as privacy compliance as in General Data Protection Rules (GDPR). An important issue with the development of new technology that has international reach is that such technology should not become siloed; that is technically isolated. This is where standards especially international standards can assist. Of course, standards by themselves will not necessarily obviate the impediments to interoperability, but if standard interfaces, data structures and standard communication structures can be developed or adopted, then the uptake of blockchain environment will be more likely to be achieved, which could financially benefit the global economy.This paper will analyse some of the issues confronting the further development of blockchain technology and how standards development can assist.
Lack of a universally accepted and comprehensive taxonomy of cybercrime seriously impedes international efforts to accurately identify, report and monitor cybercrime trends. There is, not surprisingly, a corresponding disconnect internationally on the cybercrime legislation front, a much more serious problem and one which the International Telecommunication Union (ITU) says requires ‘the urgent attention of all nations’. Yet, and despite the existence of the Council of Europe Convention on Cybercrime, a proposal for a global cybercrime treaty was rejected by the United Nations (UN) as recently as April 2010. This paper presents a refined and comprehensive taxonomy of cybercrime and demonstrates its utility for widespread use. It analyses how the USA, the UK, Australia and the UAE align with the CoE Convention and finds that more needs to be done to achieve conformance. We conclude with an analysis of the approaches used in Australia, in Queensland, and in the UAE, in Abu Dhabi, to fight cybercrime and identify a number of shared problems.
The IMF has estimated that the extent of money laundering globally is between 2 to 5 percent of the world’s gross domestic product. This figure is larger than the GDP of all but a handful of countries and represents correspondingly huge risks to global financial stability and to the financial well-being and stability of many countries. This paper provides a comparative analysis of the extent of Money Laundering over the last decade across four countries which represent a spectrum of economic development and culture: Australia, the UAE, the UK and the USA. We do so with a view to understanding their anti-money laundering systems and their recent efforts to improve the effectiveness of those systems. In the case of the UAE, we examine also the cultural influences which differentiate it from the other three countries and which have necessarily been a factor in shaping those efforts and their current system. Money laundering and related statistics including the number of Suspicious Activity Reports (SARs) received from 1999 to 2008 are analyzed. The paper consolidates and analyses information made available by the government websites of these countries and information made available through other sources, both academic and non-academic. It is clear that international efforts to combat money laundering have achieved considerable success over the decade. It is also clear that there is more to be done, by policy makers, by regulators, and by evaluators, and in particular that success in combating money laundering globally must more precisely address cultural and historical differences amongst the international community.
This paper examines the anti-money laundering systems of Australia, the United Arab Emirates (UAE), the United Kingdom (UK) and the United States of America (USA), the extent to which they have implemented the Financial Action Task Force (FATF) recommendations, and how compliance with these recommendations is affected by local cultural and economic factors. The paper makes use of FATF evaluation reports to compare the countries’ compliance; it examines some of the underlying cultural considerations and culture-specific ethical issues that affect the extent of compliance, and how cultural and ethical considerations may affect good governance. The findings indicate that the UK and the USA are the most advanced with regards to their compliance with the FATF recommendations and Australia and the UAE less so. The UAE is in particular found to be least compliant. We relate this finding to previous work on how a country’s legal and financial systems develop in line with its religion, culture and socio-economic situation, and examine how such local factors have affected the UAE’s financial and anti-money laundering and combating the financing of terrorism (AML/CFT) systems. This research will be of interest to policy-makers and government agencies involved in addressing money laundering and its successful detection and prosecution.
Delegation, from a technical point of view, is widely considered as a potential approach in addressing the problem of providing dynamic access control decisions in activities with a high level of collaboration, either within a single security domain or across multiple security domains. Although delegation continues to attract significant attention from the research community, presently, there is no published work that presents a taxonomy of delegation concepts and models. This paper intends to address this gap.
Delegation is a powerful mechanism to provide flexible and dynamic access control decisions. Delegation is particularly useful in federated environments where multiple systems, with their own security autonomy, are connected under one common federation. Although many delegation schemes have been studied, current models do not seriously take into account the issue of delegation commitment of the involved parties. In order to address this issue, this paper introduces a new mechanism to help parties involved in the delegation process to express commitment constraints, perform the commitments and track the committed actions. This mechanism looks at two different aspects: pre-delegation commitment and post-delegation commitment. In pre-delegation commitment, this mechanism enables the involved parties to express the delegation constraints and address those constraints. The post-delegation commitment phase enables those parties to inform the delegator and service providers how the commitments are conducted. This mechanism utilises a modified SAML assertion structure to support the proposed delegation and constraint approach.
Current state-of-the art solutions for online banking authentication and identity management include methods for re-authenticating users via out-of-band channels for each transaction. SMS-based schemes belong to this category, and can provide strong authentication to protect against security attacks. Poor usability of these schemes is still a problem, which makes them vulnerable to other obvious attacks. This paper describes a method for improving the usability of typical SMS-based authentication schemes which thereby will improve their overall security.
Many jurisdictions have developed mature infrastructures, both administratively and legislatively, to promote competition. Substantial funds have been expended to monitor activities that are anticompetitive and many jurisdictions also have adopted a form of Cartel Leniency Program, first developed by the US Federal Trade Commission, to assist in cartel detection. Further, some jurisdictions are now criminalizing cartel behaviour so that cartel participants can be held criminally liable with substantial custodial penalties imposed. Notwithstanding these multijurisdictional approaches, a new form of possibly anticompetitive behaviour is looming. Synergistic monopolies („synopolies‟) involve not competitors within a horizontal market but complimentors within separate vertical markets. Where two complimentary corporations are monopolists in their own market they can, through various technologies, assist each other to expand their respective monopolies thus creating a barrier to new entrants and/or blocking existing participants from further participation in that market. The nature of the technologies involved means that it is easy for this potentially anti-competitive activity to enter and affect the global marketplace. Competition regulators need to be aware of this potential for abuse and ensure that their respective competition frameworks appropriately address this activity. This paper discusses how new technologies can be used to create a synopoly.
Security for online banking has changed considerably during the relatively short period that online banking has been in use. In particular, authentication and identity management in the early implementations were, and sometimes still are, vulnerable to various attacks such as phishing. Current state-of-the art solutions include methods for re-authenticating users via out-of-band channels for each transaction. This paper describes a security investigation of this type of solution. The investigation concludes that it protects against certain attacks while still being vulnerable to other obvious attacks. In the near future, it is expected that the remaining vulnerabilities will be exploited as the attackers get more sophisticated. Possible ways of protecting against these future attacks are outlined.
It is not enough to succeed. Others must fail." 1
Identity theft restricts victims' lives, even if the stolen identity is not used for criminal purposes, as victims may be unable to obtain documents or benefits until the thief is prosecuted. The issue for regulators and consumers is that with the expansion of digital technologies identity theft is at once easier to perpetrate and harder to detect. This paper reviews the regulation of identity theft in Australia in light of the introduction by the Queensland Government on 7 February 2007 of a specific offence of identity theft. Aligned with this is the introduction on the same day by the Australian Government of the Human Services (Enhanced Service Delivery) Bill 2007 under which a smart 'Access Card' will be issued to Australian residents who receive Federal benefits. This paper discusses issues that will influence the effectiveness of these schemes.
In a federated system, it is not uncommon for a user profile registered to a particular system to contain enough attributes to request services from that system. Other attributes may be missing from that profile when services are requested from another system. The problem is that currently, when a change in user attributes happens, it is very difficult for the federation to incorporate the changes in order to resolve the conflict of attributes and maintain the consistency of attributes of users between different systems. Currently ready-for-deploy systems such as Liberty Alliance, Microsoft Windows CardSpace (formerly InfoCard) and Shibboleth do not address this issue efficiently. In general, consistency issues of user attributes in federated system via a 2-dimentional view: consistency between member systems (horizontal consistency) and consistency between federation and local system (vertical consistency). In this paper, we discuss the issue of horizontal consistency to achieve better interoperability and fine-granularity for access control decisions in a federated system by analysing the two approaches to achieve the consistency of user attributes: attribute synchronisation and delegation.
A high reliability computer system includes a first processing engine (PE), a first memory and a third memory both accessible by the first PE, a second PE, and a second memory and a fourth memory both accessible by the second PE. The first memory contains initialization information for the first PE. The third memory has a location for storing an enable password or a surrogate therefor for the first PE. The second memory contains initialization information for the second PE. The computer system also includes circuitry for switching control of the system from the first PE to the second PE upon detection of a failure of the first PE, and a password passer writing the enable password or a surrogate therefor of the first PE to the fourth memory. Alternatively, a network system includes an authentication, authorization and accounting (AAA) or any other password server having a database for maintaining an enable password for a high reliability computer system. The high reliability computer system includes an interface capable of communicating with the password server over an information bus. The interface obtains the enable password from the password server in response to a request from either one of the first and second PEs.
Since Wang et al. announced their results regarding the susceptibility of MD5 (Crypto’04) and SHA-1 (Crypto’05) hash functions to collision attacks, there have been many papers advancing further aspects of these attacks. What has been lacking is an analysis of the legal effect of these attacks upon electronic commerce transactions. As technological advancements are made, the law will need to adjust so as to take account of these attacks so that there does not arise a total undermining of the electronic commerce environment. The legal implications of these attacks need to be understood so that the courts do not over react and thus destroy any confidence commerce currently has in operating in the electronic commerce environment. This paper explores the legal implications of these attacks where certain software applications rely, in part, upon either MD5 or SHA-1.
Since Wang et al. announced their results regarding the susceptibility of MD5 (Crypto'04) and SHA-1 (Crypto'05) hash functions to collision attacks, there have been many papers ad- vancing further aspects of these attacks. What has been lacking is an analysis of the legal effect of these attacks upon electronic commerce transactions. As technological advancements are made, the law will need to adjust so as to take account of these attacks so that there does not arise a total undermining of the electronic commerce environment. The legal implications of these attacks need to be understood so that the courts do not over react and thus destroy any confidence commerce currently has in operating in the electronic commerce environment. This paper explores the legal implications of these attacks where certain software applications rely, in part, upon either MD5 or SHA-1.