12 Privacy-Oriented Analysis of Ubiquitous Computing Systems: A 5-D Approach
205
In addition, PawS elaborates on four principles that complement the previous and
that are prevalent in a ubiquitous computing environment:
• Notice: The ability of the environment not only to set privacy policies but also to
implement efficient ways to communicate these to the user.
• Choice and consent: The provision to the data subject of the choice and ability to
agree or to oppose a policy in a functional way.
• Proximity and locality: Mechanisms to encode and use locality information for
collected data in order to achieve access restrictions based on the location of the
person.
• Access and recourse: The system must give access to the user’s data and also
provide him with all of the essential information regarding the activity history of
the usage of his data.
For the above principles to be fulfilled Langheinrich suggests a series of mechanisms, namely machine-readable privacy policies, policy announcement mechanisms, privacy proxies, policy-based data access.
In UCS we want technologies to fade into the background and become invisible
to the user, hence, the location of the user should not be an obstacle. In this sense,
Location Based Services (LBS) [346] are one of the main enablers of UCS. The
research on privacy protection in LBS is vast [29, 342, 460, 533, 573]. In this line,
several dimensions of privacy could be identified [395, 461] but in most cases,
research articles focus on only one at a time: identity [76, 85], data [454, 484, 571],
location [30, 408, 506, 599] and footprint [7, 123].
12.3 5-D Classification and Analysis of Privacy Risks
From Sect. 12.2 it can be derived that most of the efforts have been oriented towards
the suggestion of measures to protect privacy (fighting against specific privacy
issues). Also, some efforts have been devoted to the analysis and proposal of privacy
principles and properties to be fulfilled. However, there is a lack of conceptual
models that allow researchers and practitioners to analyze UCS privacy holistically.
With the aim to fill this gap we build upon the ideas of Martínez et al. in [395] to
suggest a 5-dimensional privacy model for UCS.
The 5-dimensional privacy model results from the combination of two simpler
privacy models (i.e., the 3-D Conceptual Framework for Database Privacy [187]
and the W 3 -privacy model for location-based services [461]), and it was already
used within the context of smart cities [395]. However, in this chapter we revisit
the model and adapt it to the nuances of UCS. Moreover, we provide more detailed
insights regarding the scope of each dimension with regard to individuals’ privacy, in
opposition to corporations’ privacy, which in the original model was called “owner
privacy” and we have renamed it for the sake of clarity as “intelligence privacy”.
In our model, we identify five privacy dimensions: (1) identity privacy, (2) query
privacy, (3) location privacy, (4) footprint privacy, and (5) intelligence privacy. Next,
Précédent

- 210/268

Suivant