Project Details
Projekt Print View

Developing realistic attack models for privacy preserving record linkage and algorithms to prevent such attacks

Subject Area Empirical Social Research
Term from 2019 to 2023
Project identifier Deutsche Forschungsgemeinschaft (DFG) - Project number 407023611
 
Final Report Year 2024

Final Report Abstract

The project focused on attacks against methods that combine multiple databases containing personal data using specialized record linkage techniques (’privacy-preserving record-linkage’, PPRL). Initially, the effectiveness of existing attacks was examined under more realistic conditions than those typically used in literature scenarios. This particularly includes the assumption that the attacker possesses a plaintext dataset with an identical frequency distribution of identifiers. Under such real-world conditions, the probability of success is significantly lower than that suggested by previous literature. It was also demonstrated that the success probabilities of an attack can be significantly reduced by using subgroup-specific encryptions (’salting’). Subsequently, a new PPRL method was developed that leads to significantly greater security against attacks by applying a classical idea from cryptography: diffusion. This work provides the first analytical estimates of the security of such methods in general. Finally, it was shown that the method used by German cancer registries is more vulnerable to almost trivial attacks than previous publications had suggested.

Publications

 
 

Additional Information

Textvergrößerung und Kontrastanpassung