0% found this document useful (0 votes)
11 views39 pages

Cryptography and Network Security Lessons

Courses

Uploaded by

micheal38901480
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views39 pages

Cryptography and Network Security Lessons

Courses

Uploaded by

micheal38901480
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

See discussions, stats, and author profiles for this publication at: [Link]

net/publication/371641373

Cryptography and Network Security Course Lessons

Presentation · February 2019

CITATIONS READS

0 1,128

1 author:

Asmelash Girmay
Mekelle University
6 PUBLICATIONS 1 CITATION

SEE PROFILE

All content following this page was uploaded by Asmelash Girmay on 19 June 2023.

The user has requested enhancement of the downloaded file.


Cryptography and Network Security
Chapter 7: Privacy

Asmelash Girmay
Department of Information Technology
Acknowledgement

This lesson is prepared based on Panos Papadimitratos (Professor)


resources.

2019-02-01 IT4201 Cryptography and Network Security 2


Privacy
• It depends on:
• Culture
• Time
• People

2019-02-01 IT4201 Cryptography and Network Security 3


Privacy…
• Informational self
determination:
• Keep control of information
concerning us
• Example: Browser asking to accept
a cookie
• Cookies can track personal
information

2019-02-01 IT4201 Cryptography and Network Security 4


Privacy…
• The right to be left alone: "The makers of our Constitution undertook to secure
conditions favorable to the pursuit of happiness. They recognized the significance
of man's spiritual nature, of his feelings and of his intellect. They knew that only
part of the pain, pleasure and satisfactions of life are to be found in material things.
• They sought to protect Americans in their beliefs, their thoughts, their emotions
and their sensations. They conferred against the government, the right to be let
alone—the most comprehensive of rights and the right most valued by civilized
men.“
• Olmstead v. United States (1928) - Right of privacy

2019-02-01 IT4201 Cryptography and Network Security 5


Privacy…
• Privacy includes three fundamental 2. Anonymity
aspects or properties • Make it impossible to identify who
(which machine) acted
• Confidentiality
• Anonymity can be conditional
• Anonymity
• Revocable under special conditions
• Unlinkability

1. Confidentiality
• Only those that are supposed to
(authorized) have access to data

2019-02-01 IT4201 Cryptography and Network Security 6


Privacy…
3. Unlinkability
• Any two or more actions (e.g.,
message transmissions) by the
same entity cannot be linked to
each other

2019-02-01 IT4201 Cryptography and Network Security 7


Privacy Notions
1. Pseudo-nimity
1. Instead of actual, long-term
identities, use pseudonyms
1. Pseudonyms can be short- or long-
term
2. Linkable actions when using the
same pseudonym
3. Pseudonimity can be
conditional/revocable too

2019-02-01 IT4201 Cryptography and Network Security 8


Privacy Notions…
2. Unobservability
• Information hiding
• Item of Interest (IOI) cannot be
observed
• Steganographic methods

2019-02-01 IT4201 Cryptography and Network Security 9


Privacy Notions…
3. Location Privacy
• Hide entity (user) location
information
• Obfuscate (add noise)
• Hide
• Anonymize
• Unlinkable
• Multiple locations of the same user
should not linkable

2019-02-01 IT4201 Cryptography and Network Security 10


Privacy Legal Requirements
• The European Union prohibits the processing of personal data unless:
• The owner of the data has given her consent
• Processing of personal data is a required for the fulfillment of a contract or
agreement
• Legal reasons require so (to the degree it is required → Proportionality)
• Data is required to protect the vital interests of the data owner
• Personal data is needed for the “public good”

2019-02-01 IT4201 Cryptography and Network Security 11


Privacy Legal Requirements…
• Privacy requirements in the context of Online Social Networks (OSNs)
• The right to be forgotten
• The right of accessing own data easily
• Explicit Privacy Policies, so that data subjects are knowledgeable when it comes
to giving their consent
• Data protection officers in big companies/organizations
• Privacy by design (PbD)

2019-02-01 IT4201 Cryptography and Network Security 12


Privacy by Design (PbD)
• Solely relying on legal frameworks is not enough
• Privacy Enhancing Technologies (PETs) should be augmented and used in a proactive way
• PbD principles to ensure privacy and permit control over personal data
• Proactive Privacy Design
• Privacy violations are to be taken into consideration during the design of networked and data-centric
systems
• Privacy solutions should be incorporated in the design of such systems and not applied as add-on
mechanisms
• Privacy as the Default Setting
• Personal information is by default protected in any data-centric system
• Privacy Embedded into Design
• PETs as core components of the architectures of networked systems

2019-02-01 IT4201 Cryptography and Network Security 13


Privacy by Design (PbD)…
• Privacy as an extension of Security
• Security is fundamental for privacy preserving systems; security mechanisms/protocols should
strengthen privacy
• Privacy should lead to a Positive Sum
• Privacy should accommodate all legitimate interests and not create trade-offs with other
requirements
• Privacy should be verifiable
• With PbD in place, all stakeholders or independent should be assured of compliance with
regulations and be able to verify the privacy preserving characteristics of a system
• Respect of user Privacy
• PbD should be user-centric

2019-02-01 IT4201 Cryptography and Network Security 14


Privacy by Design (PbD)…
• PbD implies that security is imperative
• Recall: Confidentiality is a fundamental component of privacy
• Security tools for privacy
• E.g., cryptography, secure channels, tunnels, VPNs
• Not sufficient by themselves
• Additional privacy enhancing technologies (PETs) needed

• Important message: do not see privacy and security at odds


• Design secure, accountable systems that protect privacy at the same time!
• Several examples of own research: vehicular systems, mobile crowdsensing, location
based services

2019-02-01 IT4201 Cryptography and Network Security 15


Privacy Enhancing Technologies (PETs)
• Mechanisms, methods, tools and protocols that protect user privacy
• Minimize personal information collected by service providers
• Empower users to have control over their personal data (self-determination of
information)
• Design to achieve/ensure unlinkability and anonymity

2019-02-01 IT4201 Cryptography and Network Security 16


Pretty Good Privacy
• Pretty Good Privacy (PGP) • PGP
• Confidentiality of: • Public key cryptography
• Emails • Keys are self-issued (each user
• Files generates an own pair)
• Hard-disks • Signature over the public key hash with
the corresponding private key (to
• Caution: misnomer, it does not
prove it has the private key)
provide unlinkability and anonymity
• Keys are self-signed
• Of course, one can be pseudonymous
• No Certification Authorities
• A Web of Trust (WOT) is formed
instead

2019-02-01 IT4201 Cryptography and Network Security 17


Pretty Good Privacy…

• Bob and Alice have created a key pair


• Public keys are self signed

• Let's assume that Bob and Alice know and trust each other
• Based on some previous interaction
• Information that e.g. Bob's key is actually Bob's (e.g., a hash provided in a verifiable manner)

2019-02-01 IT4201 Cryptography and Network Security 18


Pretty Good Privacy…

• Bob sends his public Key to Alice


• Alice assigns a level of trust on Bob's public key
• Alice singes off on Bob's keys, attesting to fact it is Bob's key

2019-02-01 IT4201 Cryptography and Network Security 19


Pretty Good Privacy…

• Bob sends his public Key to Alice


• Alice assigns a level of trust on Bob's public key
• Alice singes off on Bob's keys, attesting to fact it is Bob's key
• The same process happens the other way around (Alice sends her public key)

2019-02-01 IT4201 Cryptography and Network Security 20


Pretty Good Privacy…
• This creates a Web of Trust
• Transitive trust:
• “I don't trust you but I trust someone
that trusts you!”
• Signed (certified in a sense) keys can
be passed along by users or they can
uploaded to key servers
• With PGP we can
• Encrypt message content
• Digitally sign message content

2019-02-01 IT4201 Cryptography and Network Security 21


Mix-Nets
• Source-destination unlinkability
• Who talks with whom: privacy breach
• A patient sends an email to a doctor that is expert on one kind of disease (disease A) → probably, the patient
suffers from A → privacy violation
• Eavesdropper possibly not interested in the content
• Rather in the semantics of the communication
• Remedy: make it hard to link the source and the destination
• Popular approach: mix-nets
• Assume (or hope for) a lot of traffic
• Use a set of relay nodes that undertake the task to relay your data while mixing them with the data of others
• Set up a 'virtual circuit' across the (volunteer) relays
• Hide from these nodes the source and/or destination (to the extent possible)
• The entry node knows the source
• The exit node knows the destination

2019-02-01 IT4201 Cryptography and Network Security 22


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 23


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 24


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 25


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 26


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 27


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 28


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 29


Mix-Nets…
• We construct an onion with many encryption
layers to provide source-destination
unlinkability
• Each level can decrypt one layer
• Each level does not know if the previous level
was the originator of the message
• When the receiver receives, the random
numbers can serve as a proof of receipt
• But again we know that senders (patients) send
messages to receivers (doctors) → no
unobservability!

2019-02-01 IT4201 Cryptography and Network Security 30


Mix-Nets…
• With bogus messages we can
achieve unobservability!
• An external attacker cannot
understand who talks with whom!
• What about internal attackers?
• Compromised mixes?
• What if they forward messages the
time they receive it (instead of waiting
to send batches of messages)?

2019-02-01 IT4201 Cryptography and Network Security 31


Mix-Nets…

2019-02-01 IT4201 Cryptography and Network Security 32


Onion Routing
• A set of Tor routers
• Supplied with a private/public key pair and a certificate
• The sender picks a path (random path)
• The sender creates an onion

2019-02-01 IT4201 Cryptography and Network Security 33


Onion Routing…

2019-02-01 IT4201 Cryptography and Network Security 34


Onion Routing…

2019-02-01 IT4201 Cryptography and Network Security 35


Onion Routing…
• Tor offers
• Protection against censorship
• Anonymity
• Perfect forward secrecy
• Relays just know previous and next hop
• Session keys are used only once

• Tor is better than simple proxies

2019-02-01 IT4201 Cryptography and Network Security 36


The End ☺
End of the Course ☺
View publication stats

You might also like