Building a Privacy Web with SPIDEr -- Secure Pipeline for Information De-Identification with End-to-End Encryption

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chakraborty, Novoneel, Tandon, Anshoo, Reddy, Kailash, Kirpekar, Kaushal, Robert, Bryan Paul, Kumar, Hari Dilip, Venkatesh, Abhilash, Sharma, Abhay
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929627651375104
author Chakraborty, Novoneel
Tandon, Anshoo
Reddy, Kailash
Kirpekar, Kaushal
Robert, Bryan Paul
Kumar, Hari Dilip
Venkatesh, Abhilash
Sharma, Abhay
author_facet Chakraborty, Novoneel
Tandon, Anshoo
Reddy, Kailash
Kirpekar, Kaushal
Robert, Bryan Paul
Kumar, Hari Dilip
Venkatesh, Abhilash
Sharma, Abhay
contents Data de-identification makes it possible to glean insights from data while preserving user privacy. The use of Trusted Execution Environments (TEEs) allow for the execution of de-identification applications on the cloud without the need for a user to trust the third-party application provider. In this paper, we present \textit{SPIDEr - Secure Pipeline for Information De-Identification with End-to-End Encryption}, our implementation of an end-to-end encrypted data de-identification pipeline. SPIDEr supports classical anonymisation techniques such as suppression, pseudonymisation, generalisation, and aggregation, as well as techniques that offer a formal privacy guarantee such as k-anonymisation and differential privacy. To enable scalability and improve performance on constrained TEE hardware, we enable batch processing of data for differential privacy computations. We present our design of the control flows for end-to-end secure execution of de-identification operations within a TEE. As part of the control flow for running SPIDEr within the TEE, we perform attestation, a process that verifies that the software binaries were properly instantiated on a known, trusted platform.
format Preprint
id arxiv_https___arxiv_org_abs_2412_09222
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Building a Privacy Web with SPIDEr -- Secure Pipeline for Information De-Identification with End-to-End Encryption
Chakraborty, Novoneel
Tandon, Anshoo
Reddy, Kailash
Kirpekar, Kaushal
Robert, Bryan Paul
Kumar, Hari Dilip
Venkatesh, Abhilash
Sharma, Abhay
Cryptography and Security
Information Theory
Data de-identification makes it possible to glean insights from data while preserving user privacy. The use of Trusted Execution Environments (TEEs) allow for the execution of de-identification applications on the cloud without the need for a user to trust the third-party application provider. In this paper, we present \textit{SPIDEr - Secure Pipeline for Information De-Identification with End-to-End Encryption}, our implementation of an end-to-end encrypted data de-identification pipeline. SPIDEr supports classical anonymisation techniques such as suppression, pseudonymisation, generalisation, and aggregation, as well as techniques that offer a formal privacy guarantee such as k-anonymisation and differential privacy. To enable scalability and improve performance on constrained TEE hardware, we enable batch processing of data for differential privacy computations. We present our design of the control flows for end-to-end secure execution of de-identification operations within a TEE. As part of the control flow for running SPIDEr within the TEE, we perform attestation, a process that verifies that the software binaries were properly instantiated on a known, trusted platform.
title Building a Privacy Web with SPIDEr -- Secure Pipeline for Information De-Identification with End-to-End Encryption
topic Cryptography and Security
Information Theory
url https://arxiv.org/abs/2412.09222