a privacy awareness system for ubicomp
play

A Privacy Awareness System for Ubicomp Marc Langheinrich ETH - PowerPoint PPT Presentation

A Privacy Awareness System for Ubicomp Marc Langheinrich ETH Zurich, Switzerland Motivation ! Ubicomp features real-world electronic services, often without user interface Privacy Awareness System ! Automated data transfer facilitates


  1. A Privacy Awareness System for Ubicomp Marc Langheinrich ETH Zurich, Switzerland

  2. Motivation ! Ubicomp features real-world electronic services, often without user interface Privacy Awareness System ! Automated data transfer facilitates interaction with such services ! Anonymous usage not always possible ! User should stay in control of data flow Control and Transparency Tools Ubicomp 2002

  3. Privacy Awareness System Privacy Proxie Privacy Proxies P r i v a c y P o l i c y Privacy Awareness System A c c e p t / D e c l i n e Privacy DB Privacy DB Privacy Beacons Privacy Beacons Ubicomp 2002

  4. 1. Privacy Beacons ! Let people (data subjects) know about collection Privacy Awareness System – “Software” beacons as part of service discovery – “Stand-alone” beacons for video, audio rec. ! Beacons describe data to be collected, purpose – Machine-readable privacy policies (P3P) – Extended with ubicomp-specific fields PA (Privacy P3P P3P Assistant) policy licy Privacy Beacon Ubicomp 2002

  5. 2. Privacy Proxies ! Service proxy solicits data subject’s consent – User proxy compares preferences (APPEL) with Privacy Awareness System policy obtained from service proxy ! Provide single entry point for data exchange – Allows automated data inspection, update, deletion User Privacy Proxy Service Privacy Proxy W h a t D o Y o u K n o w A b o u t M e ? D a t a : . . . Database Ubicomp 2002

  6. 3. Privacy Aware Database ! Store personal info together with P3P policy – Data and policy (metadata) form single logical unit Privacy Awareness System ! Requires usage policy for each data access – DB compares policies for data subject and data user and only releases records w/ matching policies – Each data usage recorded in usage log (auditing) <last name> <first name> <birthdate> <address> Data Usage Personal Data Policy Individual Privacy Policy Ubicomp 2002

  7. Privacy Awareness System User Privacy Proxy Printer Proxy Camera Proxy P r i v a c y P o l i c y Privacy Awareness System A c c e p t / D e c l i n e Privacy Beacon Devices PA (Privacy Assistant) Ubicomp 2002

  8. Privacy Awareness System ! Privacy Database – Oracle 8i, Java interface (no direct table access) Privacy Awareness System – P3P policies cached for speed ! Privacy Proxies Privacy Policy – Web service Accept / Decline (Apache Tomcat) – SOAP, SSH – Extended P3P ! Privacy Beacons – In the works – BT/IR, iPAQ Ubicomp 2002

  9. The Take Home Message ! Privacy is Possible in Ubiquitous Computing – Let people know about collections (beacons) Privacy Awareness System – Let people query, update, delete own data (proxies) – Let people know about (each) usage (database) ! Solutions Need Not be Perfect to be Useful – Trusting fair information practices – Trusting collectors to keep their promises – Trusting the legal system (rouge collectors) Ubicomp 2002

  10. Open Issues ! User Issues (Data Subject) – Can the average user specify preferences? Privacy Awareness System – How are multiple preferences merged? ! Service Issues (Data Collector) – Does anybody need that fine-grained control? – Efficiency, efficiency, efficiency ! Enforcement and trust – Incorporating anonymity, pseudonymity – How can we catch the bad guys? Ubicomp 2002

Recommend


More recommend