Loyalty programs in the form of punch cards that can be redeemed for benefits have long been a ubiquitous element of the consumer landscape. However, their increasingly popular digital equivalents, while providing more convenience and better bookkeeping, pose a considerable privacy risk. This paper introduces a privacy-preserving punch card protocol that allows firms to digitize their loyalty programs without forcing customers to submit to corporate surveillance. We also present a number of extensions that allow our scheme to provide other privacy-preserving customer loyalty features. Compared to the best prior work, we achieve a $14\times$ reduction in the computation and a $11\times$ reduction in the communication required to perform a "hole punch," a $55\times$ reduction in the communication required to redeem a punch card, and a $128\times$ reduction in the computation time required to redeem a card. Much of our performance improvement can be attributed to removing the reliance on pairings or range proofs present in prior work, which has only addressed this problem in the context of more general loyalty systems. By tailoring our scheme to punch cards and related loyalty systems, we demonstrate that we can reduce communication and computation costs by orders of magnitude.
翻译:长期以来,以可以兑现好处的拳击卡为形式的忠贞方案一直是消费者风景中普遍存在的一个要素。 但是,它们日益流行的数字等同物虽然提供了更多的方便和更好的账务,却构成相当大的隐私风险。 本文引入了保密拳击卡协议,允许企业将其忠诚方案数字化,而不会迫使客户向公司监督提交。 我们还提出了一系列扩展,允许我们的计划提供其他隐私保护客户忠诚的特点。 与以往的最佳工作相比,我们实现了14美元的计算削减,并减少了11美元的通信费用,以进行“打洞”、55美元减少用于赎回拳击卡的通信费用以及128美元减少用于赎回卡的计算时间。 我们的绩效改进在很大程度上可以归功于消除对配对的依赖或以往工作中存在的靶场证据,而这仅仅解决了更普遍的忠诚制度下的问题。 通过调整我们的计划来调整我们的拳击卡和相关忠诚系统,我们证明我们可以减少通信和计算费用,按数量排序。