204
A. Solanas et al.
They identified the most common privacy protection mechanisms found in the
literature [352] as follows:
• Masking mechanisms that preserve individuals’ privacy by hiding their identities.
• Privacy protection layer for mobile apps, that imply security analyses, configuration and proper regulation of permissions. Especially when it has been repeatedly
proven that leaks are common [459].
• Obfuscation, based on deliberately degrading the quality of the information.
• Proximity detection schemes, that are founded on trust computation based on
encounters, which require a coincidence in space and time and a mutual interest
between the components performing the computation.
• Game-based approaches, to find the optimal privacy protection mechanism
depending on the requirements and needs of participants by following several
rounds in a game between the attacker and the user.
• Consents and notifications.
• Negotiation approaches, in which privacy settings may be modified and configured to enable different services.
• RFID-based methods, that use RFID devices that simulate multiple RFID tags
simultaneously.
• Other techniques such as tag identification schemes or recommendation systems
for private location-sharing services.
In this study, the authors found that 29% of the privacy measures were related to
masking mechanisms, these being the most frequently used. Although most research
on privacy in UCS is focused on the aforementioned privacy protection mechanisms,
it is worth noting that privacy may also be considered as a requirement by design.
Along this line, Duan and Canny[190] advocate for the principle of data discretion
in which, in their own words, “users should have access and control of data about
them, and should be able to determine how it is used.”.
Moreover, in [357] Langheinrich stresses the importance of including privacy
considerations in the early stages of system design. He proposes six principles to
guide the development of privacy-preserving ubiquitous systems as follows:
• Notice: Users should always be aware of what data is being collected.
• Choice and Consent: Users should be able to choose whether it is used.
• Anonymity, Pseudonymity: Should apply when identity is not needed.
• Meeting Expectations: Systems should mimic real-world norms.
• Security: Different amounts of protection depending on the situation.
• Access and Recourse: Users should have access to data about them.
Also, Langheinrich, in [358], proposed a privacy awareness system (PawS) to
enforce users’ participation and to give them the ability to respect other user’s
safety, property, or privacy, and to rely on social norms, legal deterrence, and law
enforcement to create a reasonable expectation that people will follow such rules.
A. Solanas et al.
They identified the most common privacy protection mechanisms found in the
literature [352] as follows:
• Masking mechanisms that preserve individuals’ privacy by hiding their identities.
• Privacy protection layer for mobile apps, that imply security analyses, configuration and proper regulation of permissions. Especially when it has been repeatedly
proven that leaks are common [459].
• Obfuscation, based on deliberately degrading the quality of the information.
• Proximity detection schemes, that are founded on trust computation based on
encounters, which require a coincidence in space and time and a mutual interest
between the components performing the computation.
• Game-based approaches, to find the optimal privacy protection mechanism
depending on the requirements and needs of participants by following several
rounds in a game between the attacker and the user.
• Consents and notifications.
• Negotiation approaches, in which privacy settings may be modified and configured to enable different services.
• RFID-based methods, that use RFID devices that simulate multiple RFID tags
simultaneously.
• Other techniques such as tag identification schemes or recommendation systems
for private location-sharing services.
In this study, the authors found that 29% of the privacy measures were related to
masking mechanisms, these being the most frequently used. Although most research
on privacy in UCS is focused on the aforementioned privacy protection mechanisms,
it is worth noting that privacy may also be considered as a requirement by design.
Along this line, Duan and Canny[190] advocate for the principle of data discretion
in which, in their own words, “users should have access and control of data about
them, and should be able to determine how it is used.”.
Moreover, in [357] Langheinrich stresses the importance of including privacy
considerations in the early stages of system design. He proposes six principles to
guide the development of privacy-preserving ubiquitous systems as follows:
• Notice: Users should always be aware of what data is being collected.
• Choice and Consent: Users should be able to choose whether it is used.
• Anonymity, Pseudonymity: Should apply when identity is not needed.
• Meeting Expectations: Systems should mimic real-world norms.
• Security: Different amounts of protection depending on the situation.
• Access and Recourse: Users should have access to data about them.
Also, Langheinrich, in [358], proposed a privacy awareness system (PawS) to
enforce users’ participation and to give them the ability to respect other user’s
safety, property, or privacy, and to rely on social norms, legal deterrence, and law
enforcement to create a reasonable expectation that people will follow such rules.
