80 likes | 91 Vues
Join the workshop on security in Ubiquitous Computing to discuss the integration of privacy-enhancing services, privacy laws, P3P, adaptive privacy management, and more. Explore design goals and the urgent need for privacy technologies in the Ubicomp environment.
E N D
UbiComp2002 Workshop on Security in Ubiquitous Computing Integrating Privacy Enhancing Services in Ubiquitous Computing Maomao WU and Adrian Friday Lancaster University
Introduction • Ubiquitous Computing research • Very early thoughts • Background • Scenario • Design Goals • Questions for discussion Workshop on Security in UbiComp
Background • Privacy Laws • US Privacy Act of 1974 • EU Directive on Protection of Personal Data • US Federal Trade Commission (FTC) • Survey in 1998: 14% web sites had privacy policy • W3C’s Privacy Preferences Project (P3P) • Privacy policy for websites • Collection, use, and distribution of personal information • Internet Privacy Enhancing Technologies (PETs) • Anonymous remailer; • Anonymizer.com; Crowds; Pseudonymity Networks; etc. • But what about UbiComp? Workshop on Security in UbiComp
Service advertisement, including privacy policy Negotiation Privacy Policy Pseudonumous Service Scenario Change to Adaptive Mode Workshop on Security in UbiComp
Design Goals • Privacy policies for UbiComp services • Different policy for different level of services • Minimising user interruption • Users specify their privacy preferences • Single point of privacy management at the user end, e.g. Privacy Agent • Automatic negotiation • Maximising service utilisation • What happens if services do not meet user’s privacy constraints? Workshop on Security in UbiComp
Design Goals: Adaptation • Non-adaptive mode • Accept, reject, or user intervention • Adaptive mode • More services, less user interruption • Make use of the Privacy Enhancing Services • Protect the user privacy adaptively Workshop on Security in UbiComp
Summary • Urgent need for privacy technologies in UbiComp environment • Scenario of privacy friendly UbiComp environment • Design Goals • Requirement for adaptive privacy management Workshop on Security in UbiComp
Open Discussion • Shall we take P3P with extensions into UbiComp environment? Or design a new one? • What kind of privacy enhancing services do we need in UbiComp? • Do we need privacy enforcement technologies? Or we just depend on legal enforcement? Workshop on Security in UbiComp