This paper presents a new privacy negotiation mechanism for an IoT environment that is both efficient and practical to cope with the IoT special need of seamlessness. This mechanism allows IoT users to express and enforce their personal privacy preferences in a seamless manner while interacting with IoT deployments. A key contribution of the paper is that it addresses the privacy concerns of individual users as well as a group of users where privacy preferences of all individual users are combined into a group privacy profile to be negotiated with the IoT owner. In addition, the proposed mechanism satisfies the privacy requirements of the IoT deployment owner. Finally, the proposed privacy mechanism is agnostic to the actual IoT architecture and can be used over a user-managed, edge-managed or a cloud-managed IoT architecture. Prototypes of the proposed mechanism have been implemented for each of these three architectures, and the results show the capability of the protocol to negotiate privacy while adding insignificant time overhead.
翻译:本文介绍了一个新的隐私谈判机制,该机制既有效又实用,可以应对国际电话网的无缝性特殊需要。这一机制使国际电话网用户在与国际电话网部署人员互动时能够以无缝的方式表达和强制执行其个人隐私偏好。本文件的一个关键贡献是,它解决了个人用户以及一组用户的隐私关切,将所有个人用户的隐私偏好纳入与国际电话网所有人谈判的团体隐私概况。此外,拟议的机制满足了国际电话网部署所有人对隐私的要求。最后,拟议的隐私机制对实际的国际电话网架构具有不可知性,可以用于一个用户管理、边缘管理或云管理的国际电话网架构。提议的机制的原型已经针对这三种架构中的每一种,其结果显示协议在增加微不足道的时间管理费的同时谈判隐私的能力。