206
A. Solanas et al.
for each dimension, we detail the definition, risks, countermeasures and practical
scenarios within the context of UCS.
12.3.1 Identity Privacy
In the context of UCS, service providers cover some needs of their clients
through a variety of added-value services. In order to use such services, generally,
providers require clients to identify themselves using different kinds of identification
mechanism to control who is accessing the services. Although this requirement is
reasonable in most cases from the providers’ perspective, it might not be always
convenient from the users’ perspective, they might prefer to avoid the disclosure of
their identities.
Identity privacy refers to the preservation and non-disclosure of the identities
of individuals to service providers when using their UCS-based services. The
identification of users (e.g., by using their full name, the SSN) commonly improves
their experience since it enables the outcomes of the service to be personalized in
accordance with users’ preferences. However, identification procedures based on
this kind of personal data allow providers to uniquely identify their clients and track
their use of the provided service (or services). As a result, privacy advocates have
raised concern about user profiling.
Disclosing real identities to service providers enables the possibility for those
providers to create digital profiles with personal information and, as a result of
combining information from multiple providers (or from multiple services offered
by the same provider) they could infer personal information such as daily activities,
habits and routines. The more information providers collect and the more UCS
services deployed, the more accurate and realistic these digital profiles can become.
With the creation of users’ profiles, additional concerns such as the trustworthiness
of the providers, the purposes of the gathered data, and the potential privacy impact
in the case of misuse or theft arise.
Using pseudonyms might help to preserve identity privacy. However, this is a
choice that is frequently not in the hands of users but providers, who decide which
information they require for validation. The idea behind pseudonyms is simple and
builds upon linking a certain pseudonym or pseudonyms to an individual’s identity
in a secret, unique and non-trivial way. Users might create and control their own
pseudonyms, but this task might be difficult for most users and it is handed over
to pseudonymisers (i.e., third parties that do the job). In this case, the trust is
placed in those pseudonymisers. Hence, using a single pseudonymiser might not be
enough for some users. With the aim to improve the privacy-resistance of a singlepseudonymiser approach, multiple and geographically distributed pseudonymisers
can be used instead [462].
It is worth noting that often users are identified by means of the devices they
use. We observe several risk levels depending on the nature of the UCS device
in place. The riskier situation arises with UCS devices that normally belong to a
A. Solanas et al.
for each dimension, we detail the definition, risks, countermeasures and practical
scenarios within the context of UCS.
12.3.1 Identity Privacy
In the context of UCS, service providers cover some needs of their clients
through a variety of added-value services. In order to use such services, generally,
providers require clients to identify themselves using different kinds of identification
mechanism to control who is accessing the services. Although this requirement is
reasonable in most cases from the providers’ perspective, it might not be always
convenient from the users’ perspective, they might prefer to avoid the disclosure of
their identities.
Identity privacy refers to the preservation and non-disclosure of the identities
of individuals to service providers when using their UCS-based services. The
identification of users (e.g., by using their full name, the SSN) commonly improves
their experience since it enables the outcomes of the service to be personalized in
accordance with users’ preferences. However, identification procedures based on
this kind of personal data allow providers to uniquely identify their clients and track
their use of the provided service (or services). As a result, privacy advocates have
raised concern about user profiling.
Disclosing real identities to service providers enables the possibility for those
providers to create digital profiles with personal information and, as a result of
combining information from multiple providers (or from multiple services offered
by the same provider) they could infer personal information such as daily activities,
habits and routines. The more information providers collect and the more UCS
services deployed, the more accurate and realistic these digital profiles can become.
With the creation of users’ profiles, additional concerns such as the trustworthiness
of the providers, the purposes of the gathered data, and the potential privacy impact
in the case of misuse or theft arise.
Using pseudonyms might help to preserve identity privacy. However, this is a
choice that is frequently not in the hands of users but providers, who decide which
information they require for validation. The idea behind pseudonyms is simple and
builds upon linking a certain pseudonym or pseudonyms to an individual’s identity
in a secret, unique and non-trivial way. Users might create and control their own
pseudonyms, but this task might be difficult for most users and it is handed over
to pseudonymisers (i.e., third parties that do the job). In this case, the trust is
placed in those pseudonymisers. Hence, using a single pseudonymiser might not be
enough for some users. With the aim to improve the privacy-resistance of a singlepseudonymiser approach, multiple and geographically distributed pseudonymisers
can be used instead [462].
It is worth noting that often users are identified by means of the devices they
use. We observe several risk levels depending on the nature of the UCS device
in place. The riskier situation arises with UCS devices that normally belong to a
