• DocumentCode
    2777919
  • Title

    Privacy-Enhanced Trusted Location Based Services (PE-TLBS) framework based on Direct Anonymous Attestation (DAA) protocol

  • Author

    Othman, Hanunah ; Hashim, Habibah ; Razmi, Mohd Ameer Yuslan ; Manan, Jamalul-lail Ab

  • Author_Institution
    Fac. of Electr. Eng., Univ. Teknol. MARA (UiTM), Shah Alam, Malaysia
  • fYear
    2010
  • fDate
    5-8 Dec. 2010
  • Firstpage
    297
  • Lastpage
    303
  • Abstract
    The proliferation of heterogeneous mobile applications has overridden privacy and security issues. Since privacy threat in Location Based Services (LBS) is very hard to define, new approach of addressing the anonymity issues in Privacy Enhancing Technologies (PETs) using Trusted Computing technologies will result the privacy enhancement of user personal data and location information in mobile network services. In this paper we present a framework called Privacy Enhanced Trusted LBS (PE-TLBS) providing trusted services while protecting the client privacy. This paper mainly focuses on implementing a simplified protocol based on anonymous attestation that allows users to attest and authenticate an attribute while keeping their identity hidden under anonymity. The key idea behind the new approach is to hierarchically encrypt location information using RSA key pairs known as Endorsement Key (EK) and Attestation Identity Key (AIK), and distribute the appropriate keys only to Trusted Group of clients with the necessary permission. The trust-ability is measured based on Direct Anonymous Attestation (DAA) scheme supported by Trusted Platform Module (TPM) functionalities in terms of preserving anonymity, detecting rogue users/TPM and possible linkability complying with privacy requirements. We form Virtualized Secure Framework technique using TPM Emulator and TCG Software Stack (TSS) to simulate and make the accession to TPM much simpler while maintaining the functionality as well as provide Application Programming Interfaces (APIs).
  • Keywords
    application program interfaces; cryptographic protocols; data privacy; mobile computing; public key cryptography; RSA key pairs; TCG software stack; TPM emulator; application programming interfaces; attestation identity key; direct anonymous attestation protocol; endorsement key; location information; mobile network services; privacy enhancing technologies; privacy-enhanced trusted location based services framework; trusted computing technologies; trusted platform module; user personal data; virtualized secure framework technique; Authentication; Data privacy; Mobile communication; Privacy; Protocols; Servers; Software; Anonymous Attestation; DAA; Location Based Services (LBS); PE-TLBS; Privacy Threat; Trusted Group;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Applications and Industrial Electronics (ICCAIE), 2010 International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4244-9054-7
  • Type

    conf

  • DOI
    10.1109/ICCAIE.2010.5735093
  • Filename
    5735093