Uncircumventable Enforcement of Privacy Policies via Cryptographic Obfuscation
Arvind Narayanan, Vitaly Shmatikov · Auerbach Publications eBooks · 2007
Contents 8.1 Obfuscation and Its Uses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156 8.1.1 Obfuscation for “White-Box” Cryptography . . . . . . . . . . . . . . . . 156 8.1.2 Obfuscation for Copy Protection and Digital Rights Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 157 8.1.3 Obfuscation for Data Privacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 158 8.2 Cryptographic Obfuscation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159 8.3 Applications of Obfuscation to Digital Privacy . . . . . . . . . . . . . . . . . . . . 162 8.4 Obfuscation for Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 164 8.5 Obfuscation for Group Privacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167 8.5.1 Group Privacy Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168 8.5.2 Tradeoff between Privacy and Utility . . . . . . . . . . . . . . . . . . . . . . . 169 References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170 8.1 Obfuscation and Its Uses Obfuscation, when used as a technical term, refers to hiding information “in plain sight” inside computer code or digital data. The history of obfuscation in modern computing can be traced to two events that took place in 1976. The first was the publication of Diffie and Hellman’s seminal paper on public-key cryptography [DH76]. This paper is famous, of course, for introducing the first (or, at any rate, first publicly known) public-key cryptosystem. It also appears to be the first paper to describe software obfuscation. Diffie and Hellman suggested that making the encryption program incomprehensible might be a good way of converting a symmetric cryptosystem into a public-key one. Such a program would be an example of “white-box” cryptography because it would remain secure-in the sense that it would be hard for the adversary to invert the encryption function or to extract the symmetric key from it-even if the program were executed on a computer completely controlled by the adversary. This was the first instance of obfuscation for “white-box” cryptography.