• No results found

Making the Net forget

N/A
N/A
Protected

Academic year: 2021

Share "Making the Net forget"

Copied!
14
0
0

Loading.... (view fulltext now)

Full text

(1)

The Net does not forget

– Copenhagen 2009

Stephan J. Engberg

Priway

Sje webmail at Priway com

Making the Net forget

- a Security by Design pathway project in Healthcare Addressing ”S & Marper vs. United Kingdom”

(2)

ICT Privacy –The Net will not forget

Privacy is NOT about right

Security

(avoiding bad)

Innovation

(needs-driven change)

Definition: Privcacy is security (& control)

from the point of view of one stakeholder

Source of problems

Anti-crime • Gatekeepers • Legacy ”security”

Command &

Control Economics

Lock-in • Kartel standards

• Profilling outside context

Accumulating Risks Creating the problems

Preventing change Power moving from demand to supplier

Problems

(3)

A choice - two worlds

”Trust me with your secrets”

A world where the databases control people

Identified connections – data is created for secondary abuse

Control is server-side and power concentrates

Rules, polices & obscure technologies to ”produce” trust (fail) When database security fails – bad happens

”Avoid creating secrets !”

A world where people control the databases

Context-specific connections - data is created for secondary use

Key Control is edge/client side and power is distributed

Creating trust by avoiding risks independant of jurisdiction

When database security fails – use the backup and go on

(4)

ICT Privacy –The Net will not forget

3 models co-existing improving

Anonymity

Identification

Surveillance

Cannot secure

Risks grow

Crime/fraud Id Theft etc. Interdependance Power concentrate Structured Pseudonyms

Main focus

Commerce

Government

Anarchic

Cannot prevent

Risks grow

Crime/fraud Lack of traces

Contextual Id

(5)

Case: ”S & Marper vs UK”

Dec 4, 2008 – DNA/biometrics/tissue most sensitive

– Verdict: privacy violation if related to non-sentenced citizens

Feb 20, 2009 – Ministry note to Danish parlament

Feb 24, 2009 – Annonce National DNA DB with Id

May 2009 – Legal article on ”S & Marper” - 10 years is fair

June 2009 – Hearing on collecting guests fingerprints on

discos

”The court finds, that storage of tissue, dna-profiles and

fingerprints is a violation of privacy according to EMRK’s article 8.”

”The Court also finds that storage of fingerprints concerning an identified or identifable individual is a violation of privacy."

http://www.ft.dk/samling/20081/almdel/REU/spm/254/svar/endeligt/20090220/646924.HTM

(6)

ICT Privacy –The Net will not forget

Healthcare security overview

Client-side Server-side

Virtual Healthcare

files Online Analysis LAB-analysis

physical tissue/fluids

Research

Pseudonymous

Anonymous Emergency

Non-invasive infrastructure

Selfcare Telemedicine Consultation Delegation

Patient

Doctor

Specialist support Context-linking only through CLIENT-side Key control

(7)

The simple version

Physical Flow Anonymous Drop Box Mixnet Digital Flow Pool Lab Anonymous Package

Provide keys & info

Patient / Doctor Requests / Results

(8)

ICT Privacy –The Net will not forget

Police don't need DNA with id

Lab

Police Mixnet

Request to Prove Innocence Purpose-encoded DNA Request Blinded Proof of innocence Personal Key Mgt.

DNA from forensics DNA from

anonymous Samples

(9)

Research perspecitives

Healthcare files LAB-analysis physical tissue/fluids

Research

Pseudonymous Anonymous Secondary Use Restricted Doctor Accessing HIS patients files Patient Id

Life Data

Citizen running Research Analysis Towards ALL HIS data Work Diet Exercise Environment Events Rollbased Access SSO Contextual Id

(10)

ICT Privacy –The Net will not forget

Compare Invasive model

with Security by Design

Question ”Trust me” Security by Design

Basic Tissue identified

Patient / Doctor known Tissue anonymousPatient/doctor unknown

Shipment From: Sender disclosed

To: ”HIV-test Lab” Sender anonymousReceiver gradually known

Requests Identified Request

Barcode verifiable Anonymous RequestEnd-to-end RFID authentication

Results Returned & stored Identifiable.

Lab can contact patient Deposited in online Drop BoxLab cannot contact doctor/patient

Research Restrictions trying to preserve

privacy Researchers are ”free”Further data require consent

Police checks

Specific Against identified DNA Against unidentified DNAInnocent DNA remain anonymous

Fast check against convicted

Police generel Fast search Checks involve citizens

(11)

Complex Challenges

Cloud

Health

Safety

Anti-crime

Ambient

Usability

No identifiable data No server identity people

Patient can control, access and delegate

(key controls) ”Legitimate anonymity” versus undefined Including RFIDs Citizen can Control end-to-end without leaking

(12)

ICT Privacy –The Net will not forget

Towards National Id 2.0

Identity

model

Needs-driven Government Sing le Id Unstr uctu red Scandinavia Str uctu red Scandinavian Challenge: Move from legacy Single National Id to Contextual id UK, Germany US Multi -Id General Challenge: Demand Pull Effectivization / innovation AND security UK challenge: Skip the traps of Single National Id moving straight to

(13)

Semantic Identity

Authentication

Negative Claims

e.g. NOT blacklisted, ”wanted”

Positive Claims

Accountability

Semantic

Identity

Contextual Id negotiated and customised to context

Consist of a random identifier and a set of attributes

e.g. authorization, payment

Virtualisation method

Client-side Key control

PKI plus

Conditional identification according to the context

E.g. Minimum Disclosure tokens Separating who from what

Vital

Semantic identity standard to enable interoperability between

(14)

ICT Privacy –The Net will not forget

Summary – Security by Design

There is (better) life after ”S & Marper vs. United Kingdom”

Trust less. Perimeter security fail and so does trust.

Focus on “legitimate” value-creating applications

Empowering Citizens & Design for ”secure” secondary use

Provide a sustainable security paradigme

Resolve trade-offs & barriers

Fokus on demand to drive change & innovation

Win-win Cases

Securing, improving & legalising Biometrics

References

Related documents

These concepts enabled decreased personnel and increased automation in the processes “New Software Fielded to Units,” “Remote Diagnostics Detect/Fix Anomaly,” and

The production of structured lipids (SLs) by the acidolysis of soybean oil (SO) with a free fatty acid (FFA) mixture obtained from Brazilian sardine oil, catalysed by Rhizomucor

Moreover, we observed that patients with a lower SSTR2 expression need a higher required PEGV dose in combination with LA-SSA to achieve normalized IGF-I levels after surgery,

For example, on the Home screen, available menu options may include Shop in Kindle Store, View Archived Items, View Special Offers, Search, Create New Collection, Sync & Check

4 shows that our THEMIS-derived thermal inertias for ILDs in region A, range from 500 tiu for portions of the flat embaying deposits to 650–700 tiu for exposures of

In addition, competitive pressures in motor insurance markets, which typically comprise a large portion of the non-life sector in many countries, continued to limit

In the public higher education sector, only 15 states improved on measures of college affordability for public two-year institutions; that is, in these states families would

Because of the more rapid productivity growth during the 1990s, Sweden’s figures for total factor productiv- ity growth in the business sector look considerably better for the