The design and applications of a privacy-preserving identity and trust-management system
Mohammed Abdulla Hussain · 2010
Identities are present in the interactions between individuals and organizations. On-line shopping requires credit card information, while e-government services require social security or passport numbers. The involvement of identities, however, makes them susceptible to theft and misuse. The most prominent approach for maintaining the privacy of individuals is the enforcement of privacy policies that regulate the flow and use of identity information. This approach suffers two drawbacks that severely limit its effectiveness. First, recent research in data-mining facilitates the fusion of partial identities into complete identities. That holds true even if the attributes examined are not, normally con-sidered, to be identifying. Second, policies are prone to human error, allowing for identity information to be released accidentally. This thesis presents a system that enables an individual to interact with organiza-tions, without allowing these organizations to link the interactions of that individual together. The system does not release individuals ’ identities to organizations. In-