11 Information Hiding for Spatial and Geographical Data
237
a watermarking scheme, developed within the SPADA@WEB project [27], that is
based on the use of the SVD (singular value decomposition) transform by blocks,
while Sect. 11.6 illustrates a proposal for a steganography GIS model that is based
on the use of public keys with the aim to transmit sensitive content inside digital
maps, making the hidden content available only to authorized users. Finally, some
related works are presented in Sect. 11.7, and we conclude with Sect. 11.8.
11.2 Information Hiding: A Background on Watermarking
and Steganography
Security can be added to existent technology (hardware and software) in order to
minimize the risks that are related to the novel scenarios, improving robustness of
the system. Security concerns three main requirements: confidentiality, integrity, and
authentication. These properties were well addressed in Chap. 9 and 10. Cryptography and digital signatures can be used to achieve these requirements, thus making
the communication secure. When used in conjunction, they can be considered in
terms of a public-key infrastructure (PKI): each communicating entity owns a pair
of keys (public-key, secret-key); the entities are able to securely communicate with
each other with the help of a trusted certification authority (CA). Cryptography helps
people to achieve data confidentiality. Ciphered data are accessible to only legitimate
receivers that use a secret-key to decrypt the ciphered data and retrieve the original
data. The problem is that once data are deciphered, the original data may be captured
by adversaries that could use the captured information maliciously. Attacks are classified as passive or active, whether they leave the captured information unchanged
or modify it. Generally, active attacks are more dangerous than passive attacks since
they involve the integrity and the authenticity requirements, in addition to the confidentiality requirement. Moreover, legitimate users would not be able to recognize
that data are compromised. Legitimate users continue to work normally, while they
are actually feeding a malicious adversary. Another drawback related to the adoption
of cryptography is the fact that if cipher-text is easily recognizable, then, a passive
adversary (eavesdropper) that intercepts the communication traffic is acknowledged
about the use of cryptography.
So, we need additional protection mechanisms that can be used in conjunction
with the security mechanisms. Protection mechanisms should help content providers
and distributors to preserve the digital rights in the whole value chain, by regulating
access and usage of the resources. A digital rights management (DRM) system is a
framework that is used to control and manage digital rights, including the intellectual property ownership. Basic security and protection components are cryptography
and watermarking. DRM rules are enforced by policies that may be expressed by
rights expression languages. Two main approaches are the MPEG REL [23] and
the ODRL [24]. MPEG REL [23] expresses licences in terms of the following features: principals, identifying who is able to perform some actions; rights, specifying
actions; resources, identifying the objects that may be used by principals in order to
exercise some rights; and conditions; that should be validated before any action is
Précédent

- 230/317

Suivant