12 Privacy-Oriented Analysis of Ubiquitous Computing Systems: A 5-D Approach
209
the location data sent to the providers would not directly disclose the real location.
Similarly, if collaboration protocols are not suitable, real locations could be also
protected by means of cloaking services [248] or by determining the proximity to
entities without revealing their whereabouts [342, 460]. However, this could result
in a degradation of the quality of the results obtained and users might look for the
right balance between location details disclosure and the quality of the results.
12.3.4 Footprint Privacy
While providing clients with the requested services, service providers collect
information about them. They store the activities that individuals perform, mainly
for traceability and analytical purposes. As a result, large amounts of microdata
(i.e., individual records containing information collected from individuals) are
stored. Roughly speaking, UCS providers collect microdata sets with information
detailing the use and traffic on their services, that is, the footprint left by the
users on the services. Privacy concerns might emerge once these microdata sets
are published or released to external third parties, since these parties could be
able to retrieve meaningful information about individuals. In addition, if third
parties obtain microdata sets from several service providers used by the same user,
further knowledge could be inferred about the individuals’ actions. To address these
concerns, footprint privacy, considers the control of the information that can be
retrieved or inferred from microdata sets.
Any UCS service provider collecting and storing information about the activities
of their consumers might raise footprint privacy concerns. In previously discussed
privacy dimensions, users played a key role in protecting their privacy by putting
in place the right countermeasures. However, in the footprint privacy dimension,
most of the effort to guarantee privacy is handed over to the provider, and hence it
has to be enforced by law (as in fact it is). This privacy dimension will mainly be
preserved when service providers apply the proper countermeasures before releasing
microdata sets. Otherwise, the privacy of individuals whose data have been collected
would be jeopardized.
Statistical disclosure control (SDC) techniques have been used to protect the
privacy of users, whose data is stored in microdata sets. Footprint privacy is,
hence, normally preserved by applying those techniques. Proposed SDC techniques
(e.g., noise addition, rank swapping or micro-aggregation [534], to name a few)
aim to prevent linkage between individuals’ identities and some of their data (i.e.,
footprint data) by distorting it. It is worth noting that footprint data does not include
identifiers. However, the combination of quasi-identifier attributes might lead to the
reidentification of users. Yet, the distortion applied to the data to enhance privacy is
not free, since the quality and the utility of the data decrease. So, when using SDC
techniques a trade-off between privacy and data utility needs to be considered [287].
209
the location data sent to the providers would not directly disclose the real location.
Similarly, if collaboration protocols are not suitable, real locations could be also
protected by means of cloaking services [248] or by determining the proximity to
entities without revealing their whereabouts [342, 460]. However, this could result
in a degradation of the quality of the results obtained and users might look for the
right balance between location details disclosure and the quality of the results.
12.3.4 Footprint Privacy
While providing clients with the requested services, service providers collect
information about them. They store the activities that individuals perform, mainly
for traceability and analytical purposes. As a result, large amounts of microdata
(i.e., individual records containing information collected from individuals) are
stored. Roughly speaking, UCS providers collect microdata sets with information
detailing the use and traffic on their services, that is, the footprint left by the
users on the services. Privacy concerns might emerge once these microdata sets
are published or released to external third parties, since these parties could be
able to retrieve meaningful information about individuals. In addition, if third
parties obtain microdata sets from several service providers used by the same user,
further knowledge could be inferred about the individuals’ actions. To address these
concerns, footprint privacy, considers the control of the information that can be
retrieved or inferred from microdata sets.
Any UCS service provider collecting and storing information about the activities
of their consumers might raise footprint privacy concerns. In previously discussed
privacy dimensions, users played a key role in protecting their privacy by putting
in place the right countermeasures. However, in the footprint privacy dimension,
most of the effort to guarantee privacy is handed over to the provider, and hence it
has to be enforced by law (as in fact it is). This privacy dimension will mainly be
preserved when service providers apply the proper countermeasures before releasing
microdata sets. Otherwise, the privacy of individuals whose data have been collected
would be jeopardized.
Statistical disclosure control (SDC) techniques have been used to protect the
privacy of users, whose data is stored in microdata sets. Footprint privacy is,
hence, normally preserved by applying those techniques. Proposed SDC techniques
(e.g., noise addition, rank swapping or micro-aggregation [534], to name a few)
aim to prevent linkage between individuals’ identities and some of their data (i.e.,
footprint data) by distorting it. It is worth noting that footprint data does not include
identifiers. However, the combination of quasi-identifier attributes might lead to the
reidentification of users. Yet, the distortion applied to the data to enhance privacy is
not free, since the quality and the utility of the data decrease. So, when using SDC
techniques a trade-off between privacy and data utility needs to be considered [287].
