anonymous statistical survey of attributes toru nakanishi and yuji sugiyama okayama univ., japan

20
Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Upload: dennis-byrd

Post on 19-Jan-2016

225 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Anonymous Statistical Surveyof Attributes

Toru Nakanishi and Yuji Sugiyama

Okayama Univ., Japan

Page 2: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Background

Distributor(Seller)User(Customer)

Man or Woman ?Man or Woman ?Man or Woman ?Man or Woman ?

Young or Old?Young or Old?. . .. . .

AnonymouslyAnonymously

MarketingMarketing

Page 3: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Background(Cont’d)

Woman, 30, engineer

Maybe useful for identifying the user.Maybe useful for identifying the user.

Man, 15, Student

Man, 48, Dealer

Offering many attributes…

Some distributors want attributes for each user.

Page 4: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Background(Cont’d)

Female90% 10%Male

Statistical results

Some distributors want only statistical results of attributes for all users.

Survey system to generate only the statistical results is in demand.

Page 5: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Requirements in the survey system

Anonymity of users– No extra information beyond statistical results

Correctness of results

Anonymous statistical survey system of attributes

Page 6: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Related Work

Sako proposed a protocol to generate statistical results of attributes

TTP in charge of gender

EncryptMale

Female

90% 10%

Male

No extrainformation No cheating

Trusted not to leak

CorrectnessCorrectness

Page 7: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

But, … Is single TTP really

trusted ?

Sako’s protocol may be simply applied to anonymous statistical survey.

Problem in simple application

Female90% 10%Male

Are users honest ?

Page 8: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Users cannot cheat.

Each TTP doesn’t have extra information.

Our anonymous statistical survey system of attributes

Assurance

Female

Trustees

Female90% 10%Male

trusted

Quorum is trusted

No extra information

Attribute Authority

Page 9: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Group

Tool 1: Camenisch-Stadler’s group signature

What’s a group signature ?

signature

Traceable by only TTP

Made by a group memberBut, who ?

Page 10: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Registration

Signing

Tool 1: Camenisch-Stadler’s group signature (Cont’d)

z, ID

Cert.

z

z Proof( )Cert.

z

Membership Authority

Page 11: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Tool 2: Threshold Cryptosystem

Only quorum of a group can decrypt a ciphertext.

Trustees

???

Not quorum Quorum

Page 12: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

No cheating

Link is unknown unless quorum is corrupted

Tool 3: Shuffle

Trustees

Randomized and randomly permuted

Page 13: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Model

Registration

Offering Generating

User TrusteesDistributor

Attribute Authority

Page 14: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

1. Registration in group signature is executed.1. Registration in group signature is executed.

2. z’s are published in lists of respective attributes.

Our survey system - Registration

z’s of malesz , z , ….1 4 z , z , ….

z’s of females

32

z, ID

Cert.

z

Female

UserAttribute Authority

Page 15: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

1. The group signature is offered.

Our survey system - Offering

z

Proof( )Cert.

z

Anonymousz linked to correct attribute

is committed

No users’ cheating

Page 16: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Male

Female

Male

AfterwardLinked

1. Sent ciphertexts are shuffled.

Our survey system - Generating

Trustees

Link between ciphertext (offering) and attribute is unknown for even each trustee.

Page 17: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

2. For each shuffled ciphertext, it’s linked to attribute, with no extra information of z.

a. Public z’s are shuffled by the same random r,

Our survey system – Generating (Cont’d)

( )r

Malesz , z , ….? ?

r r

Femalesz , z , ….? ?

r r

Malesz , z , ….1 4

Femalesz , z , ….2 3

Randomly permuted in each list

while the ciphertext is randomized by r.

Page 18: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

3. Count revealed attributes, and calculate

statistic.

Our survey system – Generating (Cont’d)

b. Decrypt the ciphertext,

( )r

Malesz , z , ….? ?

r rFemalesz , z , ….? ?

r r

=

rz

rz

Search

FemaleNo extra information

of z’s for even each trustee

and search in lists of z’s.

Page 19: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Correctness

Security

AnonymityAnonymity in offering:

Anonymity of group signature

No extra information in generating:Shuffles, threshold cryptosystem

Correctness of offering:Proving certificate

Correctness of generating:No cheating in shuffles and decryption

Page 20: Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

Conclusion

An anonymous statistical survey system of attributes is proposed. No extra information for each trustee No cheating