In this paper we propose a privacy-friendly eHealth system design providing pervasive care for the elderly or stay-at-home patients. The system integrates services of health status monitoring, organizing assistance and remote access to medical data. The proposed architecture is open and allows seamless integration of new services, service providers and users. The focus of this paper is on privacy preserving mechanisms that provide protection of the sensitive data handled by the system.
This paper presents a novel approach for advanced personalized care and health services. It consists of four tiers and presents a high level of openness, privacy and manageability compared to existing systems. Moreover, the architecture is driven by realistic underlying business opportunities and is validated through the design of multiple scenarios.
In an increasing information-driven society, preserving privacy is essential. Anonymous credentials promise a solution to protect the user's privacy. However, to ensure accountability, efficient revocation mechanisms are essential. Having classified existing revocation strategies, we implemented one variant for each. In this paper we describe our classification and compare our implementations. Finally, we present a detailed analysis and pragmatic evaluation of the strategies.
PriMan is presented; privacy-preserving user-centric identity management middleware which defines and groups the required functionality. It offers the application developer a uniform technology-agnostic interface to use and combine different types of privacy enhancing technologies. Moreover, the PriMan framework defines all the components and their functionality required to raise the development of privacy enhanced client-server applications to a higher level.
During the last decades, multiple initiatives have formulated various fair data practice principles. Today, privacy policies are used to define how personal data can be created, disclosed, stored, used, shared, and destroyed by entities other than the data subject. However, there was a lack of comprehensive framework to reason about the fundamentals of privacy policy-based private data protection schemes. This paper presents a comprehensive yet generic set of fair data practice requirements. Next, the requirements are used as a consistent framework to reason about the capabilities, limitations and challenges of privacy policy-based private data protection in general and privacy policy languages in particular. More specifically, the paper discusses which fair data practice principles can be expressed by P3P.
This report presents the basic research results of the ADAPID project from in 2007 and 2008. It summarizes twenty research papers, most of which have been published in scientific journals of conferences, while the rest are still subject to submission or review processes. Our research results can be classified in five main areas, corresponding to each of the chapters in this report. First, we present our work on digital credential systems that provide special security and privacy properties. These digital credentials are a key technology for building privacy friendly user-centric identity management systems. Our results improve the flexibility, efficiency and functionalities offered by these digital credentials. Moreover, we show how these credentials can be useful in e-health systems. Second, we describe our contributions to the formalization of privacy properties, and propose improvements to both information theoretic as well as combinatorial anonymity metrics. We also present an evaluation of mix based communication systems by proposing a new attack methodology that is far more effective than previous work, and further demonstrates the difficulty of achieving privacy when the communication layer is taken into account. Third, we introduce a diverse set of techniques to fulfill security goals for data storage and retrieval. The research problems tackled include secure long-term archiving, negative databases, steganographic file systems, private data search, private data retrieval, and priced oblivious transfer. Fourth, we present our work on secure and privacy enhanced applications , using the e-ID as basic authentication token. The researched applications include electronic petitions, pay-as-you-drive insurance systems, electronic ticketing, and credential vaults. We also include a study on the integration of biometric authentication in e-ID cards. Finally, we analyze from a legal perspective the privacy risks presented by the Belgian e-ID card, the data controllers' security obligations according to data protection law, the roles and liabilities of the users of user-centric identity management applications, and the regulation surrounding the use and offering of anonymous communication services. Due processing of personal data in eGovernment? A Case Study of the Belgian electronic identity card.
Although many believe that we have lost the battle for privacy, protection of what's left of the user's privacy is all the more important. Not only should a user be able to minimize the disclosure of her personal data, she should also have rights to decide what happens with her data once they have been disclosed. In order to minimize user interaction when deciding whether or not to reveal personal data, privacy policy languages were developed. However, these languages are inadequate and cannot properly deal with the complex interactions between users, service providers, third parties, identity providers and others. Also, tool support for composing and verifying these policies and mechanisms for enforcing them are lagging behind. This paper argues the need for better privacy policies and proposes some solutions. Throughout the paper, our statements are applied to three sample applications in three different domains: e-health, banking and social networks.
An auction is an inevitable market mechanism to setup prices of goods or services in a competitive and dynamic environment. Anonymity of bidders is required to conceal their business strategies from competitors. However, it is also essential to provide the seller guarantees that a bidder is trustworthy and competent enough to perform certain tasks (e.g transports). This paper proposes an auction protocol where bidders will participate anonymously, yet prove to be trustworthy and competent and can be held accountable towards auctioneers and sellers. Moreover, the protocol introduces promises, bonuses and compensations to ensure the best price for the sellers, extra profit for bidders and opportunities for newcomers in the business. It also handles ties, and copes with last minute bidding. Finally, the auction's fair proceedings and outcome can be verified by everyone.
The domain of digital rights management (DRM) is currently lacking a generic architecture that supports interoperability and reuse of specific DRM technologies. This lack of architectural support is a serious drawback in light of the rapid evolution of a complex domain like DRM. It is highly unlikely that a single DRM technology or standard will be able to support the diversity of devices, users, platforms, and media, or the wide variety of system requirements concerning security, flexibility, and efficiency. This paper analyses state-of-the-art DRM technologies and extracts from them high level usage scenarios according to content consumers, producers, and publishers. In addition, the key services are identified both from a functional and security perspective. Identifying key DRM services and locating them in an overall structure brings us one step closer to a software architecture for DRM. Having available a software architecture should help the DRM community in reasoning about DRM systems, and in achieving reuse and interoperability of multiple domain-specific DRM technologies and standards.
The combination of aspect-oriented programming and framework technology boosts software reuse and brings separation of concerns to a new, more generic level. On the one hand, AOP enables the separate implementation of crosscutting concerns. Frameworks, on the other hand, allow us to reuse and customize a particular implementation in different applications. By means of a security example, we show the ease and power of the AOP language AspectJ to analyze and design a solution in terms of a framework. We also suggest a number of improvements.
Hermix is a distributed system currently being designed at the Department of Computer Science of the K.U.Leuven. Sofware development techniques for distributed systems have not kept pace with the ever evolving hardware technology. Not only are distributed systems more difficult to understand, they are also more difficult to implement. In this paper we look at the two different levels of communication: the language level (or how communication is seen by the programmer), and the system level (or how the language level is supported by the system). Both levels are not completely independent. The first part of the paper examines the requirements for communication and describes the underlying system. In the second part, we look more closely at the interface description language and show what a C++ language veneer might look like.
Electronic Health Records (EHRs) are becoming the ubiquitous technology for managing patients' records in many countries. They allow for easier transfer and analysis of patient data on a large scale. However, privacy concerns linked to this technology are emerging. Namely, patients rarely fully understand how EHRs are managed. Additionally, the records are not necessarily stored within the organization where the patient is receiving her healthcare. This service may be delegated to a remote provider, and it is not always clear which health-provisioning entities have access to this data. Therefore, in this chapter the authors propose an alternative where users can keep and manage their records in their existing eHealth systems. The approach is user-centric and enables the patients to have better control over their data while still allowing for special measures to be taken in case of emergency situations with the goal of providing the required care to the patient.