课题基金 / 基金详情

Privacy-Protecting Mechanisms for Data Escrow and Transaction Monitoring

Privacy-Protecting Mechanisms for Data Escrow and Transaction Monitoring
数据托管和交易监控的隐私保护机制
批准号:
0430622
负责人:
Stanislaw Jarecki
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-09-15 至 2008-08-31

项目摘要

项目成果

Stanislaw Jarecki的其他基金

相似基金

相关文献

中文摘要
翻译
收集和监控个人和商业数据将帮助政府机构发现犯罪、欺诈、恐怖主义、自然灾害和其他紧急情况。另一方面,政府对海量数据的收集和监控将对人们的隐私造成巨大威胁,并可能造成不必要的滥用。虽然政府机构收集低技术水平的信息已成为一种公认的做法,但互联网带来的连接性和交易速度的提高,使得对各种交易活动的集中监督更可取,但也可能更危险。例如,银行和个人在很长一段时间内都被要求报告涉及超过1万美元现金的交易。9/11之后,爱国者法案要求每家银行报告更多可疑活动的模式,例如包括一系列小额现金交易或总额达1万美元的国际转账。然而,由于互联网银行使通过多个金融机构进行交易变得更加容易,犯罪打击者真正想要的是能够从所有金融机构收集数据,而且能够随意挖掘这些数据。当然,这将是公民隐私的噩梦。事实上,政府机构手中所有这些数据的可用性实际上必然会对银行系统的安全造成新的威胁,可能比集中监控试图解决的威胁更严重。然而,从密码学的角度来看,数据监控需求与数据隐私需求之间的冲突并非不可调和!我们的研究目标是创建一种机制,限制数据收集和监控应用程序带来的隐私威胁,同时仍能使其高效运行。我们相信新的加密技术可以帮助解决各种数据收集和监控场景所带来的利益和威胁之间的冲突。从根本上说,如果监视可疑模式的某些活动的任务需要对所有生成的数据进行无限制的访问,我们就没有希望解决这种冲突。但是,如果可以限制监控机构对数据的访问,例如,它只能访问满足某些预定义的可疑模式的数据,那么我们可以希望使用加密机制来强制执行(1)访问数据的正确性,以及(2)不符合搜索模式的数据的保密性和匿名性。换句话说,如果可以详细说明该机构应该了解数据的条件,那么我们就可以设计数据托管协议,允许该机构在不侵犯公民隐私的情况下进行监控工作,这是绝对必要的。在金融监控示例中,研究问题是找到一种有效的类似加密的托管方案,其属性是所有托管交易在默认情况下保持匿名和不可破译,例如,除了形成来自同一个人的国际汇款模式并累计达10,000美元的交易。我们的方法解决了集中收集和监控敏感私人数据所带来的威胁最小化的一般问题。这是一种新颖但自然的密码学场景。它也是开放式的:由于不同的监视应用程序具有不同类型的搜索数据模式,因此该任务将需要各种方法,这些方法可能会产生在其他加密应用程序中有用的隐私和/或正确性强制机制。我们的初步调查确定了非常简单的受隐私保护的数据托管应用程序与确定性加密、密文上的不可链接签名以及公平的概率功能的两方计算之间的联系。该项目为密码学工具和应用的研究开辟了一个新的领域。虽然很明显,对各种分布式活动的集中监控可能会带来社会效益,但我们的研究将有助于确定在什么条件和什么设置下,这种监控可以以安全和最大程度地私密的方式进行。这项研究对数据托管和监控、强大的PKI基础设施(如电子id)和容错加密服务的技术和政治可行性有很大的影响。
英文摘要
Collection and monitoring of personal and business data will help government agencies detect crime, fraud, terrorism, natural disasters, and other emergencies. On the other hand, government collection and monitoring of massive mounts of data would create tremendous threats to people's privacy and an unnecessary potential for abuse. While low-tech collection of information by government agencies has been an accepted practice, the increased connectivity and transaction speed enabled by the Internet make centralized oversight of various transactional activities both more desirable and potentially more dangerous. For example, banks and individuals were for a long time required to report transactions involving more than $10,000 in cash. After 9/11, the Patriot Act asked each bank to report more patterns of suspicious activities, including for example series of smaller cash transactions or international transfers adding up to $10,000. However, since Internet banking makes it easier to conduct transactions via multiple financial institutions, what the crime fighters would really like is an ability to collect data from all financial institutions, and moreover, an ability to mine this data at will. Of course, this would be a nightmare to citizens' privacy. Indeed, the availability of all this data at the hands of a government agency is in fact bound to create new threats to the security of the banking system, possibly more serious than the threats the centralized monitoring attempted to solve. And yet, from the standpoint of cryptography, the conflict between the needs for data monitoring and the need for data privacy is not irreconcilable!Our research objective is to create mechanisms that limit the privacy threats posed by the data collection and monitoring applications, while still enabling their efficient operation. We believe that new cryptographic techniques can help resolve the conflicts between the benefits and threats posed by various data collection and monitoring scenarios. Fundamentally, we have no hope of resolving this conflict if the task of monitoring some activity for suspicious patters requires an unconstrained access to all the generated data. However, if the monitoring agency can be restricted in its access to the data, for example it can access only the data that satisfies some pre-defined suspicious patterns, then we can hope to enforce, using cryptographic mechanisms, (1) the correctness of the accessed data, and (2) the secrecy and anonymity of the data that does not meet the searched-for patterns. In other words, if conditions under which the agency should learn the data can be spelled out, then we can design data escrow protocols that allow the agency to do its monitoring work with no more intrusion on citizens' privacy then is absolutely necessary.In the financial monitoring example, the research question is to find an efficient encryption-like escrow scheme with the property that all escrowed transactions remain anonymous and undecipherable by default, except of, for example, transactions which form a pattern of international money transfers originating from the same person and adding up to $10,000.Our approach addresses a general problem of minimizing the threats posed by centralized collection and monitoring of sensitive private data. This is a novel but natural scenario for cryptography. It is also open-ended: Since different monitoring applications have different types of searched-for data patterns, this task will require a variety of approaches which are likely to produce privacy and/or correctness-enforcing mechanisms useful in other cryptographic applications. Our preliminary investigations identified the link between quite simple privacy-protected data escrow applications and deterministic encryptions, unlinkable signatures on ciphertexts, and fair two-party computation of probabilistic functionalities.This project establishes a new area of research on cryptographic tools and applications. While it's clear that centralized monitoring of various distributed activities might bring societal benefits, our research will help determine under what conditions and in what settings such monitoring can be done in a secure and maximally private manner. This research has a strong potential to impact the technical and political feasibility of data escrow and monitoring, strong PKI infrastructures (e.g. electronic IDs), and fault-tolerant cryptographic services.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
  • 批准号:
    2030575
  • 项目类别:
    Standard Grant
  • 资助金额:
    $31.5万
  • 财政年份:
    2020
  • 负责人:
    Stanislaw Jarecki
  • 依托单位:
SaTC: CORE: Small: Secure Computation on Large Data
  • 批准号:
    1817143
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2018
  • 负责人:
    Stanislaw Jarecki
  • 依托单位:
CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
  • 批准号:
    1547435
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.96万
  • 财政年份:
    2016
  • 负责人:
    Stanislaw Jarecki
  • 依托单位:
CAREER: Secure Multi-Party Protocols
  • 批准号:
    0747541
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $45.0万
  • 财政年份:
    2008
  • 负责人:
    Stanislaw Jarecki
  • 依托单位:
海外基金