
Research Article
A User-Centric Privacy-Preserving Approach to Control Data Collection, Storage, and Disclosure in Own Smart Home Environments
@INPROCEEDINGS{10.1007/978-3-030-94822-1_11, author={Chathurangi Ishara Wickramasinghe and Delphine Reinhardt}, title={A User-Centric Privacy-Preserving Approach to Control Data Collection, Storage, and Disclosure in Own Smart Home Environments}, proceedings={Mobile and Ubiquitous Systems: Computing, Networking and Services. 18th EAI International Conference, MobiQuitous 2021, Virtual Event, November 8-11, 2021, Proceedings}, proceedings_a={MOBIQUITOUS}, year={2022}, month={2}, keywords={Internet of Things IoT Social IoT and privacy Usability Data protection Data collection Smart objects Smart home Smart environments}, doi={10.1007/978-3-030-94822-1_11} }
- Chathurangi Ishara Wickramasinghe
Delphine Reinhardt
Year: 2022
A User-Centric Privacy-Preserving Approach to Control Data Collection, Storage, and Disclosure in Own Smart Home Environments
MOBIQUITOUS
Springer
DOI: 10.1007/978-3-030-94822-1_11
Abstract
The smart environments around us collect a vast amount of data and disclose those data to third parties, thus potentially endangering our privacy. Research works and the European General Data Protection Regulation (GDPR) call for more user involvement in the privacy-preserving process. Existing privacy-preserving solutions do not present a solution for the entire data collection and disclosure process, while fully putting the users in the center. Therefore, in this paper, we address four main weaknesses of the existing solutions. This led us to derive a user-centric privacy-preserving approach, which allows the end users to control the entire data collection, storage, and disclosure process in smart home environments. Our approach includes: (1) applying different minimization and aggregation levels to control the data collection, (2) mechanisms helping users to assess the sensitivity level of the collected data types, (3) a model balancing privacy risks with benefits allows users to make decisions by considering their attitude towards data collection and sharing, and (4) an approach presenting privacy risks and advantages arising from sharing collected context-data allows users to make context-dependent data sharing decisions. Our paper also outlines how the proposed privacy-preserving approach can be implemented in the existing IoT system architecture in the future.