92

PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 2: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 3: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 4: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 5: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 6: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 7: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 8: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 9: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 14: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 15: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 16: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 17: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 18: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 19: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Two case studies:

➢ anonymous e-petitions: no identity attached to petitions

➢ privacy-preserving road tolling: no fine grained data sent to server

Engineering Privacy by Design 1.0

Seda Gurses, Carmela Troncoso, Claudia Diaz. Engineering Privacy by Design.Computers, Privacy & Data Protection. 2011

Page 20: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Two case studies:

➢ anonymous e-petitions: no identity attached to petitions

➢ privacy-preserving road tolling: no fine grained data sent to server

Engineering Privacy by Design 1.0

The Key is “data minimization”

Seda Gurses, Carmela Troncoso, Claudia Diaz. Engineering Privacy by Design.Computers, Privacy & Data Protection. 2011

Page 21: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Two case studies:

➢ anonymous e-petitions: no identity attached to petitions

➢ privacy-preserving road tolling: no fine grained data sent to server

Engineering Privacy by Design 1.0

The Key is “data minimization”

Seda Gurses, Carmela Troncoso, Claudia Diaz. Engineering Privacy by Design.Computers, Privacy & Data Protection. 2011

Page 22: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Two case studies:

➢ anonymous e-petitions: no identity attached to petitions

➢ privacy-preserving road tolling: no fine grained data sent to server

but, it’s not “data” that is minimized (in the system as a whole)

➢ kept in user devices

➢ sent encrypted to a server (only client has the key)

➢ distributed over multiple servers: only the user, or colluding servers, can recover the data

Engineering Privacy by Design 1.0

The Key is “data minimization”

Seda Gurses, Carmela Troncoso, Claudia Diaz. Engineering Privacy by Design.Computers, Privacy & Data Protection. 2011

Page 23: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Two case studies:

➢ anonymous e-petitions: no identity attached to petitions

– privacy-preserving road tolling: no fine grained data sent to server

but, it’s not “data” that is minimized (in the system as a whole)

➢ kept in user devices

➢ sent encrypted to a server (only client has the key)

➢ distributed over multiple servers: only the user, or colluding servers, can recover the data

Engineering Privacy by Design 1.0

“data minimization” is a bad metaphor!!!“data minimization” is a bad metaphor!!!“data minimization” is a bad metaphor!!!

The Key is “data minimization”

Seda Gurses, Carmela Troncoso, Claudia Diaz. Engineering Privacy by Design.Computers, Privacy & Data Protection. 2011

Page 24: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 25: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 26: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 27: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 28: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 29: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 30: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 31: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Starting assumptions1) Well defined functionality

Charge depending on driving

2) Security, privacy & service integrity requirementsUser location should be privateNo cheating clients

3) Initial reference system

Case study: Electronic Toll Pricing

Page 32: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 33: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 34: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 35: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 36: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 37: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 38: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 39: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 40: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 41: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 42: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 43: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 44: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 45: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 46: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 47: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 48: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 49: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 50: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 51: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 52: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 53: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 54: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 55: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 56: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 57: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:

Pool-Based Anonymous Communications

Fernando Pérez-González, , Carmela Troncoso. "Understanding statistical disclosure: A least squares approach." PETS, 2012.Simon Oya, Carmela Troncoso, Fernando Pérez-González. "Do dummies pay off? limits of dummy traffic protection in anonymous communications." PETS, 2014

Pool

(1-α)

P = probability that sends a message to α = probability of message leaving the pool

λ = rate of messages

Page 58: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 59: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 60: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 61: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 62: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 63: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 64: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 65: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 66: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 67: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 68: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 69: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 70: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 71: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 72: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 73: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 74: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 75: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 76: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 77: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 78: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 79: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 80: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 81: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 82: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 83: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 84: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 85: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 86: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 87: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 88: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 89: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 90: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling:
Page 91: PowerPoint Presentationcarmela.troncoso/talks/... · 2016-09-23 · Two case studies: anonymous e-petitions: no identity attached to petitions – privacy-preserving road tolling: