12 Privacy-Oriented Analysis of Ubiquitous Computing Systems: A 5-D Approach
207
unique individual (e.g., smart watches, smart glasses or fitness trackers). In this
situation, to preserve the identity privacy of individuals, the relationship between
each individual and his/her device must be unknown. Hence, pseudonyms could be
helpful but clearly are not enough to prevent the disclosure of identities. A similar,
though not so risky scenario is that where we have UCS devices providing services
to a controlled group of people, such as the UCS devices in a smart home or in
an autonomous vehicle. In this scenario, services are provided to their owners. As
in the previous situation, the relationship between individuals and devices should
be unknown. However, in this case, if the service identifies the device, it cannot
identify a single individual, since he/she is somehow anonymized within the group.
The more people using the same device, the more preserved their identities will be.
This example could be extended to larger systems such as smart cities in which
services are provide to the entire population in which case, the identity of the users
is practically guaranteed. Despite the above, we suggest the use of attribute based
credentials [84, 244] as the best option to protect identity privacy in the UCS context,
especially when using a single device.
12.3.2 Query Privacy
Usually, UCS provide services on demand, i.e., upon the reception of requests
from consumers. Normally, these requests can be understood as queries that users
create to obtain a specific service. Although queries do not necessarily include
personal identifiers, they have to be managed carefully since they could disclose
much personal information. In this context, query privacy refers to the privacy
preservation of the queries sent by users to UCS service providers.
By collecting queries from anonymous users, one could profile them and infer
their habits and preferences. More importantly, some queries could enable the
identification of such “anonymous” users [9]. In this situation, users tend to trust
providers, however, this has proven to be a suboptimal solution. Thus, with the
aim to avoid the need to trust providers, scenarios where services can be used by
providing minimal query information would be suitable from the privacy perspective
(i.e., putting in place the principle of data minimization). By doing so, users make
more difficult for service providers to learn information.
Most users are not trained to tune their queries, hence, in general, query privacy
concerns can be mitigated by using Private Information Retrieval (PIR) techniques.
By definition, PIR-based schemes are cryptographic protocols that retrieve records
from databases while masking the identity of the retrieved records from the database
owners [589]. From the UCS-based services perspective, PIR tools could be used by
consumers to query service providers. By doing so, the correlation between queries
and individuals could be broken and profiling becomes much more difficult.
Queries and their results can be easily analyzed by UCS-based service providers
unless the proper countermeasures are put in place. For example, providers of fitness
services could infer habits and routines when interacting with the fitness trackers
Précédent

- 212/268

Suivant