12 Privacy-Oriented Analysis of Ubiquitous Computing Systems: A 5-D Approach
211
following this line, privacy protection has been mixed with related problems such as
access control, network and database security, and the like. However, to understand
privacy we have to put the focus on people and, from there, we should rethink the
whole architecture that aims at protecting it.
Although some people support the idea of companies’ privacy (i.e., our concept
of intelligence privacy), privacy issues mainly affect people. There is no doubt about
the importance of protecting people’s privacy and to do so we state that the focus
should be put on people and become personalized. In the years to come, we will
see many changes related to how privacy is understood, how the focus will shift
from data privacy to people’s privacy, and how the latter is protected in practice. We
see some fundamental changes that are taking place already and are going to fully
develop in the years to come.
12.4.1 Privacy by Design
The addition of privacy at the very beginning of the design process [357] is going
to change many ideas and bad practices that are common nowadays. This principle
is especially important when we consider the UCS that surround us all the time.
Take as an example the face recognition technology that allows access to our
mobile phones. In the early days of this technology (and similar ones), biometric
information was sent to servers over the Internet, analyzed, and the authentication
result was sent back to the edge device. Clearly, this procedure has many points of
failure from a privacy perspective. Now most of these technologies are executed on
the device, and as a result the data is privately stored by the user and privacy risks
are lessened. Emerging technologies based on context-awareness (e.g., smart homes,
smart cities, intelligent transportation systems, smart healthcare systems [535, 536])
must be designed with privacy at their core, otherwise we will make the same
mistakes of the past and we will need to address privacy as an additional layer
outside the system instead of an inner component.
12.4.2 Individual-Centred Privacy
We are shifting towards an individual-centred privacy in which the focus is on the
user of the technology and privacy is going to be protected by understanding the
personal dimensions of users. As we introduced in this chapter, those dimensions
respond to questions such as Who am I? (Identity Privacy), Where am I? (Location
Privacy), What do I need? (Query Privacy), What have I done? (Footprint Privacy).
This paradigm shift is especially relevant when we consider the impact of wearable
devices (e.g., smart phones, smart watches, smart glasses). Most of the data that they
generate are sensitive, personal data about their users, hence the important thing here
is not the data per se but its relationship to users and their privacy dimensions.
211
following this line, privacy protection has been mixed with related problems such as
access control, network and database security, and the like. However, to understand
privacy we have to put the focus on people and, from there, we should rethink the
whole architecture that aims at protecting it.
Although some people support the idea of companies’ privacy (i.e., our concept
of intelligence privacy), privacy issues mainly affect people. There is no doubt about
the importance of protecting people’s privacy and to do so we state that the focus
should be put on people and become personalized. In the years to come, we will
see many changes related to how privacy is understood, how the focus will shift
from data privacy to people’s privacy, and how the latter is protected in practice. We
see some fundamental changes that are taking place already and are going to fully
develop in the years to come.
12.4.1 Privacy by Design
The addition of privacy at the very beginning of the design process [357] is going
to change many ideas and bad practices that are common nowadays. This principle
is especially important when we consider the UCS that surround us all the time.
Take as an example the face recognition technology that allows access to our
mobile phones. In the early days of this technology (and similar ones), biometric
information was sent to servers over the Internet, analyzed, and the authentication
result was sent back to the edge device. Clearly, this procedure has many points of
failure from a privacy perspective. Now most of these technologies are executed on
the device, and as a result the data is privately stored by the user and privacy risks
are lessened. Emerging technologies based on context-awareness (e.g., smart homes,
smart cities, intelligent transportation systems, smart healthcare systems [535, 536])
must be designed with privacy at their core, otherwise we will make the same
mistakes of the past and we will need to address privacy as an additional layer
outside the system instead of an inner component.
12.4.2 Individual-Centred Privacy
We are shifting towards an individual-centred privacy in which the focus is on the
user of the technology and privacy is going to be protected by understanding the
personal dimensions of users. As we introduced in this chapter, those dimensions
respond to questions such as Who am I? (Identity Privacy), Where am I? (Location
Privacy), What do I need? (Query Privacy), What have I done? (Footprint Privacy).
This paradigm shift is especially relevant when we consider the impact of wearable
devices (e.g., smart phones, smart watches, smart glasses). Most of the data that they
generate are sensitive, personal data about their users, hence the important thing here
is not the data per se but its relationship to users and their privacy dimensions.
