This paper presents setup and results of a long-term outdoor range experiment carried out in a real environment. The objective was to explore long-range wireless communication in sub-GHz license-free radio bands, i.e., 169, 433, and 868 MHz under more realistic conditions. Not only transmission range, but also packet loss and received signal strength were evaluated. A large set of radio configurations was used to study the impact of transmission power, bit rate, and packet size. Also, the relationship between packet loss and received signal strength was investigated. A model could be developed that can help determine the expected packet loss rates as a function of the radio configurations and measured RSSI values.
Within pervasive intelligent environments, Wireless Sensor Networks (WSNs) will surround and serve us at any place and any time. A proper usability is considered essential for WSNs supporting real life applications. With this chapter, we aim at ease of use for specifying new applications that have to autonomously cope with expected and unexpected heterogeneity, sudden failures, and energy efficiency. Starting with general design criteria for applications in WSNs, we created a user-centric design flow for pervasive applications. The design flow provides very high abstraction and user guidance to refrain the user from implementation-, deployment- and hardware-details including heterogeneity of the available sensor nodes. Automatic event configuration is accomplished by using a flexible Event Specification Language (ESL) and Event Decision Trees (EDTs) for distributed detection and determination of real world phenomena. EDTs autonomously adapt to heterogeneous availability of sensing capabilities by pruning and subscription to other nodes for missing information. We present one of numerous simulated scenarios proving the robustness and energy efficiency with regard to the required network communications. From these, we learned how to deduce appropriate bounds for configuration of collaboration region and leasing time by asking for expected properties of the phenomena to be detected.
Social networks recently came under severe criticism for easy-going handling of user data. Millions of users voluntarily release private and business data without considering potential impacts on their real life that may come along with that. Used for personalized advertising or attendee profiling, user data are of utmost importance for economic success of the maintaining network. Hence, platform providers exploit all promising options to gather data while privacy and data security seem partially to be a pain for them. Dozens of security lacks and data thefts have emerged for almost every available platform. In addition, techniques and methods exist to secretly gather more user data, e.g., by proper fusion of miscellaneous information, analysis of visited websites, or social games. Even worse, misuse or rather sale of user data might be part of the marketing concept. This chapter analyzes the business networks LinkedIn and Xing, and the more leisure time related social communities Facebook and StudiVZ. In particular, differences in collecting and handling of user data are of interest. Based on that, we present and analyze reported criticism based on published and on own investigated data. Then we evaluate whether that criticism is justified, hypercritical, or understatement. On behalf of analyzing potential threats and pitfalls, we finally work out existing and potential privacy risks as well as resulting consequences for the real life of community members.
Mobile surveillance of patients vital data is of prominent use in today's e-health applications. Given the fact that smartphones provide Internet connectivity almost anywhere and at any time, these seem to be the perfect key device for such application. In contrast to available solutions, our approach described in this paper allows using almost any smartphone for such purpose. In addition, the system enables to dynamically reconfigure the e-health infrastructure without putting the privacy and data security of monitored patients at risk.
Wireless Sensor Networks are the key-enabler for low cost ubiquitous applications in the area of homeland security, health-care, and environmental monitoring. A necessary prerequisite is reliable and efficient event detection in spite of sudden failures and environmental changes. Due to the fact that the sensors need to be low cost, they have only scarce resources leading to a certain level of failures of sensor nodes or sensing devices attached to the nodes. Available fault tolerant solutions are mainly customized approaches that revealed several shortcomings, particularly in adaptability and energy efficiency. The authors present a complete event detection concept including all necessary steps from formal event definition to autonomous device configuration. It features an event definition language that allows defining complex events as well as enhance the reliability by tailor-made voting schemes and application constraints. Based on that, this paper introduces a novel approach for self-adapting on-node and in-network processing, called Event Decision Tree EDT. EDT autonomously adapts to available resources and environmental conditions, even though it requires to re-organize collaboration between neighboring nodes for evaluation. The authors' approach achieves fine-grained event-related fault tolerance with configurable adaptation rate while enhancing maintainability and energy efficiency.
Since wireless sensor networks are successfully deployed in real life scenarios, applications in medical health-care, structural control, homeland security etc. become feasible. In those envisioned applications, easy maintenance and usability become crucial to staff members, e.g., to doctors or nurses. Not only for widespread distribution of hundreds of sensors, but also in tele-medical applications, remotely-controlled sensing and maintenance without direct access to sensors is required. For this purpose we present a middleware abstraction based on the standard Java Mobile Sensor API (JSR-256). It allows transparent access to sensor measurements, sensor information and maintenance data, which appear as local sensor resources to the user even if the sensors are connected via network. Hence, the user neither requires technical skills nor location information to request sensor data. This paper gives an architectural and functional overview of our middleware within the context of telemedicine. We demonstrate how our middleware approach supports patient monitoring for pre- and post-operative treatment at home.
This paper introduces a technology convergence adaptor for a previously presented Inter-MAC architecture [1] for heterogeneous home area networks. Its main task is to translate technology-dependent link metrics into a machine readable common language. This language allows for the description of various service and application classes and provides means to describe link metrics of underlying MAC protocols. Based on this description technology-dependent conversion formulae can be integrated, which enable the calculation of technology-independent quality of service metrics. These metrics are essential for path selection and admission control in heterogeneous meshed home area networks. Example conversion formulae for wireless LAN based on IEEE 802.11 [2] are given, which can be well described in the proposed common language.
Wireless sensor networks (WSN) are considered to be the key-enabler for low cost highly distributed applications in the area of homeland security, healthcare, environmental monitoring etc. A necessary prerequisite is reliable and efficient event detection. This paper introduces a novel approach for event configuration and in network processing, called event decision trees (EDT). An EDT enables every node to self-divide event queries according to its resources. EDT autonomously adapt to the tasks assigned, even though it requires to organize collaboration between nodes to deliver expected results. The effort for maintain formal EDT is evaluated by analysis and simulations. Our results show that the proposed lease-based mechanism for maintaining producer/consumer pairs in an EDT outperforms even idealized acknowledgment-based approaches.
Privacy issues are becoming more and more important especially since the cyber and the real world are converging up to certain extent when using mobile devices. Means that really protect privacy are still missing. The problem is, as soon as a user provides data to a service provider the user looses control over her data. The simple solution is not to provide any data but then a lot of useful services e.g. navigation applications cannot be used. In order to remedy this problem we propose privacy guaranteeing execution containers (PGEC). Basically the concept is that the application gets access to the user data in a specially protected and certified environment, the PGEC. PGECs enable applications to access private user data locally and guarantee that the user data is deleted as soon as the service is quit. Thus, the PGEC guarantees a "one time use" of the provided private data. The PGECs also restrict the communication between the application and the service provider to what is explicitly allowed by the service user. In order to highlight the security provided by the PGEC, we discuss potential attacks such as modified execution environments as well as appropriate countermeasures.
Privacy has been a hot topic in research for several years. A lot of different approaches to protect privacy have been proposed recently. Among these there are several tools for negotiation of privacy contracts. In this paper we present our privacy negotiation framework called “The Privacy Advocate”. It consists of three main parts: the policy evaluation unit, the signature unit and the preferences. In addition, our framework supports an interface for negotiation strategies, so that they are independent of the framework. The preferences can be expressed with a combination of P3P and APPEL. The tests we executed using a state of the art PDA clearly indicate that our framework can be used on mobile devices. The completion of a successful negotiation usually takes about 2 sec. including message transfer via an 802.11b wireless link. This involves multiple evaluations of proposals. Each of them is done in less than 250 msec.
This chapter provides a survey of privacy-enhancing techniques and discusses their effect using a scenario in which a charged location-based service is used. We introduce four protection levels and discuss an assessment of privacy-enhancing techniques according to these protection levels.
In this paper, we discuss how diverging privacy requirements in a multiuser ubiquitous environment can be satisfied. We are investigating how to ensure that the requirements of concerned as well as open-minded users can be satisfied, simultaneously. In order to reduce overhead and increase granularity of the objects to be managed, we propose to cluster all available sensors, creating objects we denote as virtual sensors. All further operations are done on the virtual sensors. We will discuss our management architecture and present our simulation environment showing how the pervasive environment automatically adapts to user requirements and user locations.
Privacy issues are becoming more and more important especially since the cyber and the real world are converging up to certain extent when using mobile devices. Means that really protect privacy are still missing. The problem is, as soon as a user provides data to a service provider the user looses control over her data. The simple solution is not to provide any data but then many useful services, e.g. navigation applications, cannot be used. In order to solve this problem, we propose privacy guaranteeing execution containers (PGEC). Basically the concept is that the application obtains access to the user data in a specially protected and certified environment, the PGEC. PGECs enable applications to access private user data and guarantee that the user data is deleted as soon as the service is quit. The PGEC also restricts the communication between the application and the service provider to what is explicitly allowed by the service user. In addition to those means the PGEC also implements countermeasures against malicious attacks such as modified host systems and covert channel attacks, which might be misusing CPU load to signal data out of the PGEC. Thus, the PGEC guarantees a "one time use" of the provided private data.
The electronic media of today requires users to authenticate or provide identifying properties which is usually done with login credentials or to present digitally signed certificates. Certificates are issued by a trusted certificate authority, which knows the content of a certificate and the identity of the owner. To provide a maximum level of privacy the identity of the owner must be separated from the certificate. Neither the service shall be able to determine the identity of the owner nor shall the certificate authority track the certificate throughout its use. The certificate authority may issue certificates with a known content for a pseudonymous identity that cannot be linked to the real identity of the owner. Hence the content is to be openly signed whereas the pseudonym is signed blindly. Both items have to be interweaved to ensure that the content is valid for this pseudonym only as well as to prevent from forging a certificate. After unblinding the pseudonym the certificate can be presented for use. Now the service can validate the content and the user can prove his ownership of the pseudonym in the certificate. Even with collaboration between the service and the certificate authority it is impossible to map the presented certificate to a certain identity. Thus, our approach allows a fully anonymous use of services.
Privacy has been a hot topic in research for several years. A lot of different approaches to protect privacy have been proposed recently. Among these are several tools for negotiation of privacy contracts. In this paper we present our privacy negotiation framework called “Privacy Advocat (PrivAd)”. It consists of three main parts: the policy evaluation unit, the signature unit and the preferences. In addition our frame supports an interface for negotiation strategies, so that they are independent of the framework. The preferences can be expressed with a combination of P3P and APPEL. The test we executed using a state of the art PDA clearly indicate that our framework can be used by mobile devices. The completion of a negotiation takes about 2 sec. including message transfer via an 802.11b wireless link. The processing itself is done in less
In today’s working and shopping environment a lot of sources are present that collect data of people located in those environments. The data gathered by devices such as video cameras, RFID tags, use of credit cards etc. can be combined in order to deduce information which cannot be “measured” directly. In this paper we introduce deduction rules that help to describe which information can be inferred from which sources. Using these rules all information that can be gathered by a pervasive system can be identified and linked to the sources of the raw input data. By that the pervasive system is represented as an information flow graph. In order to enhance privacy we use this graph to determine the data sources, e.g. video cameras or RFID tags, that need to be switched off to adapt a given system to privacy requirements of a certain person. Due to the fact that we do not consider an individual device a data source but cluster those devices into a single source of a certain type, our approach scales well even for large sensor networks. Our algorithms used to build and analyze the information flow graph offer low calculation complexities. Thus, they are well suited to be executed on mobile devices giving the end user back some control over her/his data. Even if she/he cannot influence the system, she/he at least knows which information is exposed to others.
In this paper we discuss how to configure a ubiquitous environment in such a way that diverging privacy requirements in a multi user environment can be satisfied. I.e. we are investigating how to make sure that concerned as well as open minded users can be satisfied, at the same time at the same place. In order to reduce overhead and increase granularity of objects to be managed we propose to cluster all available sensors to what we call virtual sensors. All further operations such as allowing or suppressing sensor data are done on the virtual sensors. This concept allows to adapt the environment to diverging needs of several users automatically. Users are enabled to configure the environment by a one stop approach. We will introduce the concept of virtual sensors and discuss our privacy management architecture that exploits this virtual sensor concept to adapt a pervasive system to contradicting privacy requirements.
Location aware services have been envisioned as the killer application for the wireless Internet. But they did not gain sufficient attention. We are convinced that one of the major pitfalls is that there is up to now no way to charge for this kind of services. In this paper we present an architecture which provides the basic mechanisms needed to realize charged location based services. The three major components are: a location aware middleware platform, an information server and a micro payment system. We provide performance data that clearly indicates that such a system can be deployed without exhausting the resources of mobile devices or infrastructure servers.