Technology Review - Published By MIT
Advertisement

Blindfolding Big Brother, Sort of

Continued from page 2

By Kate Greene

Monday, January 30, 2006

smaller text tool iconmedium text tool iconlarger text tool icon

TR: What were the challenges with developing this software?

JJ: One of the challenges is when you one-way hash the data, it becomes "infinitely sensitive." What I mean by that is that the word robert, if you one-way hash it, and take Robert, where the r is capital and not lowercase, the one-way hash generated by this subtle difference is completely different.

One of the reasons people didn't try to do this before, or it was believed that maybe it wasn't useful, is that people's identity data is always quite different -- sometimes with a middle initial, sometimes without. Identities just don't show up the same. That was the trick we had to solve: allowing it to match data that's fuzzy while only using one-way hashed values.

The trick is in how we prepare the data. Here's a simple example. One list says Bob and one says Rob. Well, we know that both Bob and Rob belong to the same root name, in this case, Robert. So before we anonymize each side, we throw in the most rooted form, which is Robert. So we've added Robert to both lists, and we then one-way hash both lists so it turns out the Robert matches.

TR: How is this is based on earlier work you did for Las Vegas casinos?

JJ: The ability to figure out if two people are the same despite all the natural variability of how people express their identity is something we really got a good understanding of assisting the gaming industry. We also learned how people try to fabricate fake identities and how they try to evade systems. It was learning how to do that at high speed that opened the door to make this next thing possible. Had we not solved that in the 1990s, we would not have been able to conjure up a method to do anonymous resolution.

TR: You've said that 40 percent of your time is spent on privacy and civil liberties issues and that a privacy strategist works with you. Could you give me an example of the sort of things you and your privacy strategist discuss?

JJ: When the government has a watch list –- this, by the way, doesn't have to do with our tech, this is about responsible usage of tech and improved processes -- when you have a watch list, the questions come up: Who's on the list? How can people find out if they're on the list? How can they get off the list if they're not supposed be on it? If a government has a list and they're sharing it, making copies of it, and somebody's removed from the list because they've made a mistake, how can you be sure that they're removed from everywhere else they shared it?

Another thing that my privacy strategist and I have been talking about is called an "immutable audit log."

TR: What's that?

JJ: You want to make sure that someone who is using a secret government system isn't putting their ex-wife in a watch list or searching for their ex-wife or their neighbor just because they're curious. That would be a misuse. An immutable audit log is the notion that every time a user queries for a record, this new kind of audit log records it in an indelible way that's like etching it into stone. In other words, even if a database administrator was in cahoots with them, or the database administrator was a corrupt entity, they couldn't erase their own footprints.

Comments

  • Who Knew?
    One of the best articles I've read.

    Database Append - One Way Hashing - Reasonable & Sensative - and my fav, Immutable Audit Log?

    Well done.
    Rate this comment: 12345
    Guest (Colin)
    01/30/2006
    Posts:1
  • Blindfolding Big Brother
    the only thing I would say about the corrupt individual may exist on either side, so the intergrity may be lost. I do believe that this is a defenite step forward in resolving the encrypt and decrypt hassels, but we need to monitor data offloads. Data offloads are primarily a big problem we need to electronically monitor this type of event.
    I want to congratulate you it was a very good article and great idea.
    Jay Pons
    jesuspons@bellsouth.net
    Rate this comment: 12345
    Guest (Jay Pons)
    02/08/2006
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Making 3D Maps on the Move
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.