A New Privacy-Enhanced Technology for Fair Matchmaking With Identity Linked Wishes
Dwight Horne, Suku Nair · IEEE Systems Journal · 2019
Matchmaking problems such as coupling for a school dance, voting negotiations in legislative bodies, and recruiting of high level executives involve identity linked wishes (ILW), which are wishes that involve specific identities and are only valid if those particular entities share the common wishes. The challenge of fair and privacy-enhanced matchmaking with ILW, with conflicting goals of anonymity and authentication, was coined the prom problem (TPP). In this paper, we detail phases of the privacy engineering process used for development of a novel privacy-enhanced technology (PET) for TPP. Early stages consisted of problem framing, definition of security and privacy requirements, protocol development, and theoretical security and complexity analyses. A proof-of-concept implementation and feasibility evaluation including performance testing with real-world systems and networks demonstrated the correctness and practicality of the approach, thereby limiting risk prior to incurring the full costs of production system development. We highlight the system architecture, risks, and the regulatory environment. We conclude with lessons learned and recommendations for privacy engineering. In the rapidly evolving landscape of privacy regulations, PETs can afford competitive advantage, while simultaneously limiting compliance risks.