Project Final Report
Total Page:16
File Type:pdf, Size:1020Kb
PROJECT FINAL REPORT Grant Agreement number: 216483 Project acronym: PrimeLife Project title: Privacy and Identity Management in Europe for Life Funding Scheme: IP Period covered: from March 1, 2008 to June 30, 2011 Name of the scientific representative of the project's co-ordinator 1, Title and Organisation: Dr. Jan Camenisch, IBM Research GmbH Tel: +41 44 724 8279 Fax: +41 44 724 8953 E-mail: [email protected] Project website address: http://www.primelife.eu 1 Usually the contact person of the coordinator as specified in Art. 8.1. of the Grant Agreement. 4.1 Final publishable summary report Executive Summary The vision of the PrimeLife project is to enable individuals in the information society to protect their privacy and retain control over their personal information, irrespective of the activities they are performing. Indeed, individuals and businesses are increasingly using social networking, online collaboration applications, mesh-ups of different services, and the Internet in general, for both private and business purposes. Unfortunately, the new information technologies hardly consider the privacy requirements of the individuals. PrimeLife’s Approach PrimeLife’s approach was threefold. First, PrimeLife picked up the results and technologies from the PRIME project and helped with their adoption in the real world by providing materials for standardization and education. Second, PrimeLife eliminated many of the remaining hurdles for large-scale adoption of these results by addressing user interfaces, policy languages, and infrastructural components. Third, PrimeLife provides a number of solutions for privacy, identity, and trust management in cases where protecting privacy by data minimization fails. Privacy for Life – Beyond Data Minimization PrimeLife provides privacy-enhancing solutions for Web 2.0 applications such as wikis, blogs, and social software that allow the users to assess the trustworthiness and privacy setting of information provider and to protect their own privacy when interacting with Internet sites such as social networks or blogs. For instance, the project has implemented and piloted its own social network that supports the user in defining who should and who should not have access to their data. Furthermore, PrimeLife provides a Privacy Dashboard as a browser extension that informs the user about the privacy settings of websites the users are interacting with. PrimeLife has also investigated the long-term aspects of privacy and identity management and has identified life- time personal data management as a major issue. The project has made available a prototype of a tool that allows users to do just this, i.e., to define which other party should have the right to access that data under which conditions. Enabling Privacy-Enhancing Privacy, Identity and Trust Management PrimeLife has identified human-computer interaction, policy languages and access control technology as two main hurdles to overcome. To this end, the project has designed a policy language that fulfills requirements for privacy- enhancing access control and data management and embeds into the widely used XML and XACML frameworks. Also, the project’s HCI experts have iterated on all the user-interfaces, improved them, and established guidelines for the design of interfaces for privacy-enhancing mechanisms. In addition to these two main hurdles, PrimeLife has identified a large number of other issues and provides solutions for many of them. These solutions include new mechanisms for privacy-enhancing access to databases, reputation management, the composition of services, mobile infrastructures, and a methodology for the economic valuation of identity and privacy management assets and capabilities of organizations. Making Privacy Live We believe that PrimeLife has made substantial steps towards privacy protection in the digital world. The project has published an enormous number of papers at international conferences, workshops, and in journals to disseminate its results to the scientific community. The project participants have given even more talks and keynote speeches to disseminate PrimeLife’s results to the scientific community and, very successfully, to standardization bodies. Also, a book summarizing the results has been published and almost all prototypes are available as open source components ensuring sustainability of the results. In fact, we know already of a number of projects (including some EU-funded ones as well) that are or will be using results of the project. A less measurable, but very substantial, impact of the project is created by the workshops that the project has organized or participated in and which aimed at employing privacy-enhancing mechanisms in the real world. These workshops include political ones proclaiming that “privacy-by-design” must be employed in the future to concrete technical workshops discussing how to build privacy principles into browsers and social networks. We are convinced and proud that PrimeLife helped Europe to come closer to offering citizens a protection of their rights of privacy in electronic interactions. This makes Europe unique in the world, particularly when comparing with the United States or Asia. Project Context and Objectives Individuals in today’s information society want to safeguard their autonomy and retain control over their personal information for all on-line activities. Information technology requires users to disclose personal data in almost any kind of interaction performed online. Those information technologies do often not sufficiently consider the protection of users’ interests in their private sphere. The web has been changing from a purely client-server- oriented paradigm to a more collaborative one. This collaborative character of the Internet makes the privacy situation more complex as multiple new kinds of interactions have emerged, e.g., users creating online content and sharing it with others or social interactions taking place online. In terms of the users’ service delivery endpoints, the traditional web access device, the PC, is being gradually complemented or even replaced by mobile end-user platforms—mainly smartphones—which needs to be taken into consideration for addressing the privacy and identity management problems. With the increasing use of the Internet for business, government, and private purposes, personal data of users is released to and handled by an increasing set of parties, without it being clear to the user which parties hold their data in the end. Better transparency and data management for the user are to be provided. This situation raises substantial new technical privacy challenges, namely protecting privacy in new Internet application paradigms, how to maintain life-long privacy, and how to provide secure access to online services. PrimeLife’s goal is to provide solutions to those challenges and thereby to continue the work that has been started already in the PRIME project of the 6 th Framework Programme. The long-term nature of data storage on the Internet results in the major challenge of life-long protection of privacy and management of identities. This is addressed as one main goal of the project with impact to be expected in the mid term to long term. PrimeLife’s objectives relate to the abovementioned pervasiveness of the Web and Internet leading to a situation of those technologies and applications being relevant in all parts of peoples’ lives. People use the web with an increasing pace throughout their daily lives. All of this creates challenges related to identity management and privacy, shaping one main objective of the PrimeLife project: enhancing privacy throughout lifetime and for complex situations. The work within the whole project is aligned around this. We tackle the associated challenges by different lines of work: Privacy in Life deals with privacy in complex and increasingly relevant real-life scenarios and sustainability of privacy. Basic Research builds a foundation of privacy-enhancing technologies (PETs) to be applied for supporting our efforts on the core challenges. Our Usability efforts make the various user- facing technologies usable, thus are a necessary condition for a successful agenda in the privacy research space. The work we do on Policies is required for formally expressing every party’s (privacy) requirements and for allowing automated processing and user support. As a missing link towards deployment, our Infrastructure efforts are targeted at real-world deployment of privacy technologies which raises further challenges, e.g., the analyses of economic drivers, secure mobile devices, or complex service compositions. The aspects of privacy in peoples’ areas of life and throughout their lives are addressed not only by a dedicated line of work tackling those, but particularly also through the concerted approach of technology research throughout the areas PrimeLife is doing research in. Privacy in Life – Privacy in Complex Real-life Scenarios and Sustainability of Privacy The pervasive nature of the Web and resulting applications clearly show some of the key issues PrimeLife tackles: How can users inject trust into their or others’ content? How can the trustworthiness of content be assessed by other users? How can online collaborations be performed in a privacy-enhanced way? How can users be supported in their privacy management in social networking-like scenarios and be made aware of the associated privacy issues? How can we give users better overall control over their personal data in prominent