k-anonymity:: A model for protecting privacy

k-anonymity:: A model for protecting privacy
复制标题

DOI:
10.1142/s0218488502001648
复制
发表时间:
2002-10-01
影响因子:
1.5
通讯作者:
Sweeney, L
Sweeney, L
中科院分区:
计算机科学4区
文献类型:
--
作者:
Sweeney, L

文献摘要

被引文献

相似文献

考虑一个数据持有者,例如医院或银行,拥有私人持有的特定于个人的现场结构化数据集合。假设数据持有者想要与研究人员共享数据的一个版本。数据持有者如何在发布其私人数据的版本时,以科学的方式保证数据主体的个人无法被重新识别,同时数据仍然具有实际用途?本文提供的解决方案包括一个名为 k-anonymity 的正式保护模型和一组随附的部署策略。如果发布中包含的每个人的信息无法与至少 k-l 个其信息也出现在发布中的个人区分开,则发布提供 k-匿名保护。本文还研究了可以在遵守 k-匿名的版本上实现的重新识别攻击,除非遵守随附的策略。 k-匿名保护模型很重要,因为它构成了 Datafly、mu-Argus 和 k-Similar 等现实世界系统提供隐私保护保证的基础。
Consider a data holder, such as a hospital or a bank, that has a privately held collection of person-specific, field structured data. Suppose the data holder wants to share a version of the data with researchers. How can a data holder release a version of its private data with scientific guarantees that the individuals who are the subjects of the data cannot be re-identified while the data remain practically useful? The solution provided in this paper includes a formal protection model named k-anonymity and a set of accompanying policies for deployment. A release provides k-anonymity protection if the information for each person contained in the release cannot be distinguished from at least k-l individuals whose information also appears in the release. This paper also examines re-identification attacks that can be realized on releases that adhere to k-anonymity unless accompanying policies are respected. The k-anonymity protection model is important because it forms the basis on which the real-world systems known as Datafly, mu-Argus and k-Similar provide guarantees of privacy protection.