• No results found

Security and Privacy in Big Data, Blessing or Curse?

N/A
N/A
Protected

Academic year: 2021

Share "Security and Privacy in Big Data, Blessing or Curse?"

Copied!
29
0
0

Loading.... (view fulltext now)

Full text

(1)

Security and Privacy in Big Data,

Blessing or Curse?

2

nd

National Cryptography Days

9-11 April 2015

Dr. Zeki Erkin

Cyber Security Section

Department of Intelligent Systems Delft University of Technology

(2)

About me…

BSc and MSc @ITU, Istanbul, 2002, 2005 PhD @TU Delft, 2010

PostDoc @ TU Delft, 2010-2014

Assist. Prof. @ TU Delft, Cyber Security Group FET Signal Processing in the Encrypted Domain STW Kindred Spirits

Dutch/COMMIT Trusted Healthcare and Extreme Wireless Sensor Networks 3TU Big Software on the Run

Secure Signal Processing, Privacy Enhancing Technologies MPC, Homomorphic Encryption

(3)

Outline

• 

Security and Privacy in Big data

• 

Motivation

• 

Secure Signal Processing

• 

Face Recognition

• 

Recommender Systems

(4)

Privacy concerns…

(5)

Problem statement

• 

Sensitive Data

• 

Commercially valuable algorithm

1. 

Service provider trustworthy

• 

Bankruptcy, lost-theft of data, insiders

2. 

Service provider untrustworthy

• 

Malicious acts, selling-transfer of data to the 3

rd

parties

• 

Cloud computing: outsourcing computation and storage

• 

Where, when, by whom? Laws? Privacy? Espionage?

Can we protect privacy while processing data without

hampering services?

(6)

Players

• 

Government

• 

Regulation, legalization, protecting privacy, providing security

and safety (critical infrastructures), creating new business fields

• 

Citizens

• 

Demanding security and privacy. Economical benefits, job

opportunities

• 

Business

• 

Increasing profit, reducing costs, reaching out to more

customers, new business ideas

• 

Academia

(7)

Secure Data Processing

computational privacy

• 

Privacy Enhancing Technologies

• 

Privacy by Design

• 

Applied cryptography

• 

Homomorphic encryption

• 

Garbled circuits

• 

Secret sharing

• 

MPC techniques

(8)

Face Recognition

Database

Alice

Bob

Is he a criminal?

Yes, ID/No

Processing

(9)

with Privacy

Database

Alice

Bob

Is he a criminal?

[Yes], [ID]/[No]

Processing

•  Z. Erkin, M. Franz, J. Guajardo, S. Katzenbeisser, R. L. Lagendijk and T. Toft, Privacy- Preserving Face Recognition, 9th International Symposium on Privacy Enhancing Technologies, LNCS 5672, pp. 235-253, August 2009.

(10)
(11)
(12)

Homomorphic Encryption

• 

A number of schemes preserve structure after encryption.

(13)

Projection in the encrypted

domain

Input image

Alice

(sk)

Bob

(pk) Feature vectors in a database Encrypted pixel values

Apply projection and obtain the feature vector of the

(14)

Euclidean Distance

Secure Multiplication Protocol!

Homomorphism

Alice

(sk)

Bob

(pk)

(15)

Secure Multiplication Protocol

Alice

Bob

(16)

Finding the minimum

Alice

(sk)

Bob

(pk)

[D

2

(F

x

, F

y

)], [D

2

(F

x

, F

w

)], . . . , [D

2

(F

x

, F

z

)]

Find the minimum squared distance!

But…

[D

2

(F

x

, F

y

)] = g

D2(Fx,Fy)

r

n

1

mod n

2

(17)
(18)

Interactive Game

(19)

Comparison

[e

i

] = [1]

· [c

i

]

· [r

i

]

1

·

` 1

Y

j=i+1

(20)
(21)

Performance

• 

Implemented in 2009

• 

Integer arithmetic

• 

400 images (112x92)

• 

18 seconds

• 

Implementation in 2009 (hybrid approach)

• 

Garbled circuits

• 

1000 images

• 

13 seconds

(22)

Recommender Systems

• 

Problem: Privacy

• 

likes/dislikes: identification and tracking

(23)
(24)
(25)

Dynamic Execution Problem

•  Kononchuk, D., Z. Erkin, J. C. A. van der Lubbe, and R. L. Lagendijk, "Privacy-Preserving User Data Oriented Services For Groups With Dynamic Participation", ESORICS, Egham, UK, 09/2013.

(26)

Case Study: Ahold

320M visitors in NL per year

This is BIG

DATA

E(ID)||Data

Profiles

(27)

Curse or Blessing

• 

Curse

• 

Awareness - society

• 

Legalization - governments

• 

Limitations - industry

• 

Blessing

• 

Research questions!

• 

Privacy by design wins!

(28)

Research Challenges

•  Efficiency

•  Run-time, bandwidth, storage •  Security model

•  Semi-honest, covert, malicious •  Cryptographic tools

•  FHE, SHE, HE, GC, SS (additive, strong ramp) •  MPC techniques

•  Application setting

•  2-party, 3-party, N-party •  Static and Dynamic

•  Application domain

•  Cloud computing

•  Confidentiality(privacy), integrity (computation and storage) •  Smart grids

(29)

Opportunities

• 

Multi-disciplinary

• 

Cryptography, signal processing, pattern recognition, machine

learning, social sciences: social-technical solutions (H2020)

• 

Wide application domain

• 

Biometrics, smart grids, cloud computing, finance, defence..etc

• 

H2020

• 

Digital societies: Trust, Privacy

• 

ICT calls

References

Related documents