12 Privacy-Oriented Analysis of Ubiquitous Computing Systems: A 5-D Approach
203
12.1.1 Goal and Plan of the Chapter
In this chapter we analyze the current state of UCS from a privacy perspective. To do
so, we identify, describe and explain the most relevant privacy risks that derive from
the deployment and use of UCS. However, since privacy is a multifaceted topic,
understanding it holistically might be difficult for non-expert readers. Hence, we
propose the use of a 5-dimensional approach to analyze privacy and we classify the
identified privacy risks into five privacy dimensions: identity privacy, query privacy,
location privacy, footprint privacy, and intelligence privacy. This 5-D approach,
which has been previously used in the context of smart cities, will help readers
grasp the difficulties and nuances of privacy protection in a compartmental way,
which will finally lead to a wider and more comprehensive understanding of the
problem. Therefore, the ultimate goal of the chapter is to increase awareness on
privacy risks related to UCS.
The rest of the chapter is organized as follows: Sect. 12.2 summarizes previous
work related to the identification of threats in UCS and reports the most relevant
classifications and analysis of privacy-related issues. Section 12.3 describes our
5-D classification of privacy risks in UCS. Moreover, possible countermeasures,
some practical scenarios and privacy enhancing technologies will be discussed,
to better illustrate each privacy threat. Next, Sect. 12.4 provides readers with a
glimpse into the future of privacy protection in the context of UCS, by analyzing
the impact of new technologies and services. Finally, the chapter ends in Sect. 12.5
with a summary of the main contributions and with some thoughts regarding the
importance of increasing awareness on privacy-related issues in UCS.
12.2 Background and Previous Work on Privacy in UCS
Regardless of the context or application area of the UCS at hand, its design involves
several challenging steps, from the proper selection of hardware and technology (e.g., microelectronics, power supplies, sensors, communications, localization
technology, M2M interactions and human-machine interfaces [518]), to the implementation of a system that addresses security risks [119, 352] (e.g., large number of
nodes, resource constraints, authentication-related challenges, unauthorized access
to devices or networks) and privacy issues. Regarding the latter, some studies have
analyzed the privacy issues of UCS. Kušen and Strembeck published, very recently
(i.e., 2017), a systematic literature review on the security of UCS and they identified
vulnerabilities, threats, attacks, and some defenses. Within the last category they
consider several options (i.e., trust computation and management, cryptographic
protocols, authentication and access control, and privacy protection mechanisms).
203
12.1.1 Goal and Plan of the Chapter
In this chapter we analyze the current state of UCS from a privacy perspective. To do
so, we identify, describe and explain the most relevant privacy risks that derive from
the deployment and use of UCS. However, since privacy is a multifaceted topic,
understanding it holistically might be difficult for non-expert readers. Hence, we
propose the use of a 5-dimensional approach to analyze privacy and we classify the
identified privacy risks into five privacy dimensions: identity privacy, query privacy,
location privacy, footprint privacy, and intelligence privacy. This 5-D approach,
which has been previously used in the context of smart cities, will help readers
grasp the difficulties and nuances of privacy protection in a compartmental way,
which will finally lead to a wider and more comprehensive understanding of the
problem. Therefore, the ultimate goal of the chapter is to increase awareness on
privacy risks related to UCS.
The rest of the chapter is organized as follows: Sect. 12.2 summarizes previous
work related to the identification of threats in UCS and reports the most relevant
classifications and analysis of privacy-related issues. Section 12.3 describes our
5-D classification of privacy risks in UCS. Moreover, possible countermeasures,
some practical scenarios and privacy enhancing technologies will be discussed,
to better illustrate each privacy threat. Next, Sect. 12.4 provides readers with a
glimpse into the future of privacy protection in the context of UCS, by analyzing
the impact of new technologies and services. Finally, the chapter ends in Sect. 12.5
with a summary of the main contributions and with some thoughts regarding the
importance of increasing awareness on privacy-related issues in UCS.
12.2 Background and Previous Work on Privacy in UCS
Regardless of the context or application area of the UCS at hand, its design involves
several challenging steps, from the proper selection of hardware and technology (e.g., microelectronics, power supplies, sensors, communications, localization
technology, M2M interactions and human-machine interfaces [518]), to the implementation of a system that addresses security risks [119, 352] (e.g., large number of
nodes, resource constraints, authentication-related challenges, unauthorized access
to devices or networks) and privacy issues. Regarding the latter, some studies have
analyzed the privacy issues of UCS. Kušen and Strembeck published, very recently
(i.e., 2017), a systematic literature review on the security of UCS and they identified
vulnerabilities, threats, attacks, and some defenses. Within the last category they
consider several options (i.e., trust computation and management, cryptographic
protocols, authentication and access control, and privacy protection mechanisms).
