1Department of Information and Communication Engineering, Sungkyul University, 53 Sungkyuldaehakro, Manan-gu, Anyang-city, Gyeonggi-do, Republic of Korea
2Department of Computer Engineering, Kangwon National University, Joongang-Ro, Samcheck-si, Kangwon-Do, Republic of Korea
Online published on 4 November, 2017.
The development of IoT contributes to individual's generating diversified information, who is the subject of the information, and providing various services by analyzing generated information.
As sensitive information, such as medical record, preferences, and gene information is not easy to be managed by individuals, it should be administered depending on trusted authority. However, in the case of entrustment of one's information to an authority, there is possibility for the user on the authority to abuse the information. Besides, when stored information is leaked, second and third damages can be incurred.
For security, personal information is encrypted using symmetric key but there is possibility of leakage and access from insiders because the key has to be stored inside to be decrypted. Providing sensitive and important information in an encrypted form to an authority and authorizing information subject to decrypt the information, we propose a method that allows one to access only when there is consent of the individual and the use of the information is requested by the authority.
Four methods to protect personal information stored in the ways based on symmetric and public key are presented. We compare and analyze four methods to allow an authority to choose a method suitable to its characteristics.
Personal Information, Encryption, Public Key, Privacy Protection, Subject Control