Source-linked AI summary
Big Data Privacy in the Internet of Things Era
Charith Perera, Rajiv Ranjan, Lizhe Wang, Samee U. Khan, Albert Y. Zomaya
TL;DR
IoT data collection and large-scale analysis create valuable knowledge while raising privacy concerns for users. The article surveys IoT privacy challenges, public opinion, stakeholder responsibilities, and research efforts. It concludes that privacy protection remains insufficient across the data lifecycle and identifies scalable privacy-preserving algorithms as a future priority.
Problem
IoT data collection and large-scale analysis create valuable knowledge while raising privacy concerns for users.
Method
The article surveys IoT privacy challenges, public opinion, stakeholder responsibilities, and research and development efforts.
Results
Existing technologies and regulations do not yet sufficiently support privacy-guaranteed management from sensor capture through secure deletion.
Takeaways & Limitations
Protecting privacy throughout the data lifecycle is presented as necessary for IoT solutions to gain consumer confidence.
Takeaways & Limitations
Future work must develop efficient, scalable privacy-preserving algorithms across SQL/NoSQL, batch, and stream-processing systems.
Abstract
from arXiv · showhide
Over the last few years, we have seen a plethora of Internet of Things (IoT) solutions, products and services, making their way into the industry's market-place. All such solution will capture a large amount of data pertaining to the environment, as well as their users. The objective of the IoT is to learn more and to serve better the system users. Some of these solutions may store the data locally on the devices ('things'), and others may store in the Cloud. The real value of collecting data comes through data processing and aggregation in large-scale where new knowledge can be extracted. However, such procedures can also lead to user privacy issues. This article discusses some of the main challenges of privacy in IoT, and opportunities for research and innovation. We also introduce some of the ongoing research efforts that address IoT privacy issues.
Introduction
IoT connects vast numbers of devices to provide services and generate Big Data for knowledge extraction. This value must be balanced against privacy risks from collecting and analyzing sensitive user data.
- IoT and Big Data: IoT connects objects, sensors, and devices through information and communications infrastructure to provide value-added services.The paper describes IoT as a network of networks enabling connections among people and things across networks and services.
- IoT and Big Data: Aggregating data from physical devices and virtual sensors can support knowledge extraction for disaster management, smart cities, and biosurveillance.The paper also cites customer sentiment analysis as an application area.
- IoT and Big Data: Big Data is characterized by volume, variety, and velocity rather than size alone.These dimensions cover data scale, source and type diversity, and generation frequency.
- Privacy motivation: IoT data can improve recommendations and inform strategic city decisions, but sensitive personal data requires careful management to avoid privacy violations.Examples include personalized customer experiences, traffic-light placement, and future city planning.
- Paper scope: The article surveys IoT privacy, public opinion, research challenges, and ongoing research and development efforts.Its stated aim is to support a positive experience for users and businesses.
Privacy in Action: Looking Back
IoT privacy concerns arise because connected devices can collect more sensitive information than earlier online services. Public awareness and concern are substantial, creating a potential barrier to IoT growth and increasing the importance of consumer confidence.
- Expanded data collection: Wearables and connected health or home technologies may collect sensitive information about users’ health conditions, finances, and daily activities.Examples include Google Glass, Apple iWatch, Google Fit, Apple Health Kit, and Apple Home Kit.
- Expanded data collection: IoT is described as more vulnerable to privacy violations than the Web era, amid debates over government surveillance and the right to be forgotten.The paper links this vulnerability to the need for privacy-preserving data-management techniques.
- Public opinion: 60% of internet users had basic awareness that smart devices could collect personal-activity data, while 85% wanted to understand data collection better.The figures come from a TRUSTe survey summarized by the paper.
- Public opinion: 88% of respondents wanted control over smart-device data collection, and 87% were concerned about the type of personal information collected.These survey results indicate strong interest in control and information about collection practices.
- Implications: Privacy concerns could become a significant barrier to IoT growth, making consumer confidence important for IoT marketplace success.The first clause is attributed to TRUSTe, while the second is stated in the discussion of wearable technologies.
Trends, Predictions, and Opinions
Survey evidence suggests that consumers may support IoT data markets when privacy and security are guaranteed, but reject data exchange without explicit privacy assurance. The findings also describe substantial expectations for connected-home adoption.
- Sensing as a Service: 64% of 137 US survey participants favored a trading-based Sensing as a Service model under guaranteed privacy and security.Sensing as a Service is presented as a marketplace for exchanging contextually enriched sensor data.
- Sensing as a Service: 67% of respondents expected less than $500 in annual value from selling data through an IoT marketplace.This expectation was reported for an environment where IoT solution owners could sell data.
- Sensing as a Service: 66% supported the required investments when additional costs could be recovered within three months.The survey concerned investments supporting the Sensing as a Service model.
- Privacy assurance: 79% responded negatively to receiving financial returns without explicit assurances of user privacy.This result contrasts with support for the model when privacy and security were guaranteed.
- Connected-home expectations: 61% of surveyed homeowners considered a connected home extremely likely to become reality within five years.The Fortinet survey covered 1,801 homeowners across multiple countries.
Privacy Challenges in the IoT
IoT privacy challenges span consent, user control, secondary data uses, anonymity, security, and data-sharing models. The paper emphasizes that large-scale collection and inference require stronger technical and governance protections.
- User Consent Acquisition: IoT consent must cover users and non-users affected by devices or services, but current mechanisms can be ineffective or difficult to understand.Limited time, limited technical knowledge, and inaccurate or insufficient explanations complicate consent decisions.
- Control, Customization, and Freedom of Choice: Users should be able to control, delete, move, and selectively share their data, while changing or withdrawing previous consents.The paper also connects control with freedom to choose hardware and software from different vendors.
- Promise and Reality: Providers should obtain explicit consent before using already collected raw data for newly derived purposes.The paper calls for both regulation and technology to prevent such secondary use without permission.
- Anonymity Technology: Combining MAC addresses can create unique profiles that enable location tracking, while multidimensional IoT data remains difficult to anonymize.The paper calls for end-to-end anonymity across data, storage, routing, communication, analytics, and aggregation.
- Security: IoT security requires standardization, certification, stakeholder responsibility, and ongoing firmware and software updates.The paper places responsibility on manufacturers and other stakeholders to secure infrastructure, collection, transfer, and users.
- Privacy consequences: Releasing private data can enable targeted advertising or criminal activities affecting individuals and communities.Examples include identifying behavioral patterns to invade homes or timing attacks on critical infrastructure.
Stakeholder Responsibility
Protecting privacy in IoT is distributed across device manufacturers, cloud and platform providers, application developers, regulators, and individual stakeholders. Each group has distinct responsibilities spanning device controls, data portability, consent, standardization, and awareness of bystander impacts.
- Five stakeholder groups share responsibility for protecting user privacy: manufacturers, cloud and platform providers, application developers, regulators, and individual consumers or non-consumers.
- Device manufacturers should embed secure storage, data deletion, access control, collection transparency, processing disclosures, and hardware-disable controls into devices.
- Cloud and platform providers should use common interfaces and data formats so users can choose providers and delete or move their data.
- Application developers must certify apps against malware and provide clear information to obtain explicit consent for tasks, data, sensors, analysis, and derived knowledge.
- Governments or independent regulators should enforce certification, interoperability, fair competition, and standardized data transfer and storage without hindering innovation.
- Individual stakeholders include people affected by IoT devices without using them, such as bystanders within a camera-equipped device’s viewpoint.
State of the Art: Academic Research to Start-ups
Academic and industrial IoT platforms support sensing, connected-home experimentation, cloud connectivity, and personal-data markets, but their privacy coverage is uneven. Several initiatives leave privacy to deployers, application builders, or trusted intermediaries.
- OpenIoT supports Sensing as a Service through an adaptive cloud middleware framework but does not adequately address privacy, instead promoting public data sources.
- Lab of Things enables connected-home research, device interconnection, and sharing across diverse homes, but privacy must be handled manually through deployer agreements.
- Hub of All Things aims to create smart-home IoT data markets, but does not address privacy and primarily provides an API for sending home data to the cloud.
- Xively provides a Platform as a Service for connecting IoT devices to the cloud and secure storage, while assigning privacy protection to application and service builders.
- Datacoup enables users to sell personal data and pays $8 for each user who shares data, but users must trust the company to resell it through its servers.
Conclusions
Large-scale IoT data collection and analysis can benefit users, businesses, and society, but current technologies and regulations do not sufficiently support privacy across the data lifecycle. The paper points toward scalable privacy-preserving algorithms for heterogeneous big-data processing environments.
- IoT data collection and large-scale analysis can offer value to individuals and businesses and contribute to productivity and reduced wastage.
- Existing technologies and regulations are insufficient for privacy-guaranteed data management from sensor capture through knowledge extraction and secure raw-data deletion.
- Future research should develop efficient, scalable privacy-preserving algorithms across SQL/NoSQL datastores, batch systems, and stream-processing systems.
- These algorithms should adapt to uncertain data sizes and variety by exploiting workload and resource-performance features of big-data processing technologies.
Supplemental Material
The supplemental material includes a summary of research questions, stakeholders responsible for protecting user privacy, and a comparison of traditional and cloud computing models.
- Supplemental Figure 1 summarizes the paper’s research questions.
- Supplemental Figure 2 identifies major stakeholders responsible for protecting user privacy.
- Supplemental Table I compares the traditional computing model with cloud computing.
State of the Art: Academic Research to Start-ups
Research efforts address IoT privacy through distributed analytics and infrastructure that keeps personal data within household environments. These efforts also identify the need for generic platforms supporting multiple privacy-preserving analytical capabilities.
- Privacy-Preserving Analytics: Privacy-preserving analytics can aggregate data from multiple locations, while centralized analysis creates security and privacy risks from raw-data misuse.The proposed ideal platform analyzes data where it resides, such as within or outside the smart home, and aggregates it later.
- Academic Research: Dataware develops infrastructure to store and process personal data within the household environment.Its design treats user data as immovable and lets third-party applications operate wherever the data is stored.
- Academic Research: User Centric Networking develops a privacy-guaranteed content recommendation system based on household occupants’ personal data.The application-oriented system recommends books using the movies watched by household occupants.
- Research Direction: The research agenda calls for generic platforms supporting different privacy-preserving data analytical capabilities beyond application-specific systems.This contrasts with UCN’s focus on facilitating a particular recommendation function.