Title :
Privacy-Enhanced Trusted Location Based Services (PE-TLBS) framework based on Direct Anonymous Attestation (DAA) protocol
Author :
Othman, Hanunah ; Hashim, Habibah ; Razmi, Mohd Ameer Yuslan ; Manan, Jamalul-lail Ab
Author_Institution :
Fac. of Electr. Eng., Univ. Teknol. MARA (UiTM), Shah Alam, Malaysia
Abstract :
The proliferation of heterogeneous mobile applications has overridden privacy and security issues. Since privacy threat in Location Based Services (LBS) is very hard to define, new approach of addressing the anonymity issues in Privacy Enhancing Technologies (PETs) using Trusted Computing technologies will result the privacy enhancement of user personal data and location information in mobile network services. In this paper we present a framework called Privacy Enhanced Trusted LBS (PE-TLBS) providing trusted services while protecting the client privacy. This paper mainly focuses on implementing a simplified protocol based on anonymous attestation that allows users to attest and authenticate an attribute while keeping their identity hidden under anonymity. The key idea behind the new approach is to hierarchically encrypt location information using RSA key pairs known as Endorsement Key (EK) and Attestation Identity Key (AIK), and distribute the appropriate keys only to Trusted Group of clients with the necessary permission. The trust-ability is measured based on Direct Anonymous Attestation (DAA) scheme supported by Trusted Platform Module (TPM) functionalities in terms of preserving anonymity, detecting rogue users/TPM and possible linkability complying with privacy requirements. We form Virtualized Secure Framework technique using TPM Emulator and TCG Software Stack (TSS) to simulate and make the accession to TPM much simpler while maintaining the functionality as well as provide Application Programming Interfaces (APIs).
Keywords :
application program interfaces; cryptographic protocols; data privacy; mobile computing; public key cryptography; RSA key pairs; TCG software stack; TPM emulator; application programming interfaces; attestation identity key; direct anonymous attestation protocol; endorsement key; location information; mobile network services; privacy enhancing technologies; privacy-enhanced trusted location based services framework; trusted computing technologies; trusted platform module; user personal data; virtualized secure framework technique; Authentication; Data privacy; Mobile communication; Privacy; Protocols; Servers; Software; Anonymous Attestation; DAA; Location Based Services (LBS); PE-TLBS; Privacy Threat; Trusted Group;
Conference_Titel :
Computer Applications and Industrial Electronics (ICCAIE), 2010 International Conference on
Conference_Location :
Kuala Lumpur
Print_ISBN :
978-1-4244-9054-7
DOI :
10.1109/ICCAIE.2010.5735093