Presentation is loading. Please wait.

Presentation is loading. Please wait.

Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan.

Similar presentations


Presentation on theme: "Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan."— Presentation transcript:

1 Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan

2 Background Distributor(Seller)User(Customer) Man or Woman ? Young or Old?... Anonymously Marketing

3 Background(Cont’d) Woman, 30, engineer Maybe useful for identifying the user. Man, 15, Student Man, 48, Dealer Offering many attributes… Some distributors want attributes for each user.

4 Background(Cont’d) Female 90% 10% Male Statistical results Some distributors want only statistical results of attributes for all users. Survey system to generate only the statistical results is in demand.

5 Requirements in the survey system Anonymity of users – No extra information beyond statistical results Correctness of results Anonymous statistical survey system of attributes

6 Related Work Sako proposed a protocol to generate statistical results of attributes TTP in charge of gender Encrypt Male Female 90% 10% Male No extra information No cheating Trusted not to leak Correctness

7 But, … Is single TTP really trusted ? Sako’s protocol may be simply applied to anonymous statistical survey. Problem in simple application Female 90% 10% Male Are users honest ?

8 Users cannot cheat. Each TTP doesn’t have extra information. Our anonymous statistical survey system of attributes Assurance Female Trustees Female 90%10% Male trusted Quorum is trusted No extra information Attribute Authority

9 Group Tool 1: Camenisch-Stadler’s group signature What’s a group signature ? signature Traceable by only TTP Made by a group member But, who ?

10 Registration Signing Tool 1: Camenisch-Stadler’s group signature (Cont’d) z, ID Cert. z z Proof( ) Cert. z Membership Authority

11 Tool 2: Threshold Cryptosystem Only quorum of a group can decrypt a ciphertext. Trustees ??? Not quorum Quorum

12 No cheatingLink is unknown unless quorum is corrupted Tool 3: Shuffle Trustees Randomized and randomly permuted

13 Model Registration Offering Generating User Trustees Distributor Attribute Authority

14 1. Registration in group signature is executed. 2. z’s are published in lists of respective attributes. Our survey system - Registration z’s of males z, z, …. 14 z’s of females 32 z, ID Cert. z Female User Attribute Authority

15 1. The group signature is offered. Our survey system - Offering z Proof( ) Cert. z Anonymous z linked to correct attribute is committed No users’ cheating

16 Male Female Male Afterward Linked 1. Sent ciphertexts are shuffled. Our survey system - Generating Trustees Link between ciphertext (offering) and attribute is unknown for even each trustee.

17 2. For each shuffled ciphertext, it’s linked to attribute, with no extra information of z. a. Public z’s are shuffled by the same random r, Our survey system – Generating (Cont’d) ( ) r Males z, z, …. ?? rr Females z, z, …. ?? rr Males z, z, …. 14 Females z, z, …. 23 Randomly permuted in each list while the ciphertext is randomized by r.

18 3. Count revealed attributes, and calculate statistic. Our survey system – Generating (Cont’d) b. Decrypt the ciphertext, ( ) r Males z, z, …. ?? rr Females z, z, …. ?? rr = r z r z Search Female No extra information of z’s for even each trustee and search in lists of z’s.

19 Correctness Security Anonymity Anonymity in offering: Anonymity of group signature No extra information in generating: Shuffles, threshold cryptosystem Correctness of offering: Proving certificate Correctness of generating: No cheating in shuffles and decryption

20 Conclusion An anonymous statistical survey system of attributes is proposed. No extra information for each trustee No cheating


Download ppt "Anonymous Statistical Survey of Attributes Toru Nakanishi and Yuji Sugiyama Okayama Univ., Japan."

Similar presentations


Ads by Google