<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DaPriM</title>
	<atom:link href="http://www.daprim.de/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.daprim.de</link>
	<description>A Privacy Enhancing Technology Project</description>
	<lastBuildDate>Thu, 11 Apr 2013 18:18:57 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>EU-Kommission: Datenschutzrechtliche Bedenken gegenüber intelligenten Stromzählern</title>
		<link>http://www.daprim.de/?p=177</link>
		<comments>http://www.daprim.de/?p=177#comments</comments>
		<pubDate>Tue, 14 Aug 2012 08:59:47 +0000</pubDate>
		<dc:creator>daprim</dc:creator>
				<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[Datenschutz (deutsch)]]></category>
		<category><![CDATA[EU-Kommission Smartmeter Datenschutz]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=177</guid>
		<description><![CDATA[&#8220;Die datenschutzbezüglichen Angriffspunkte werden seit Jahren immer größer, was im Wesentlichen der fortschreitenden Technik zugeschrieben wird, die sich durch Vernetzung und Kommunikationsmöglichkeiten immer häufiger von einfachen mechanischen Vorrichtungen zu interagierenden Rechnern entwickelt. Eines der neuesten Beispiele dafür dürften die von &#8230; <a href="http://www.daprim.de/?p=177">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>&#8220;Die datenschutzbezüglichen Angriffspunkte werden seit Jahren immer größer, was im Wesentlichen der fortschreitenden Technik zugeschrieben wird, die sich durch Vernetzung und Kommunikationsmöglichkeiten immer häufiger von einfachen mechanischen Vorrichtungen zu interagierenden Rechnern entwickelt. Eines der neuesten Beispiele dafür dürften die von der EU-Kommission zum Einsatz in ganz Europa geplanten intelligenten Stromzähler sein.</p>
<p>(&#8230;)&#8221;</p>
<p>Vollständiger Artikel auf datenschutzticker.de mit Bezug zum DaPriM-Projekt: <a href="http://www.datenschutzticker.de/index.php/2012/06/eu-kommission-datenschutzrechtliche-bedenken-gegenueber-intelligenten-stromzaehlern/">http://www.datenschutzticker.de/index.php/2012/06/eu-kommission-datenschutzrechtliche-bedenken-gegenueber-intelligenten-stromzaehlern/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=177</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forensic Content Detection through Power Consumption</title>
		<link>http://www.daprim.de/?p=174</link>
		<comments>http://www.daprim.de/?p=174#comments</comments>
		<pubDate>Fri, 10 Aug 2012 19:11:15 +0000</pubDate>
		<dc:creator>greveler</dc:creator>
				<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[Audiovisual Identification]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Smart Meters]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=174</guid>
		<description><![CDATA[Digital forensic investigators are facing challenging problems of finding clues and solving crimes involving digital data. Advanced metering devices (smart meters) are being installed throughout electric networks in Europe and in the United States. The high-resolution energy consumption data which &#8230; <a href="http://www.daprim.de/?p=174">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Digital forensic investigators are facing challenging problems of finding clues and solving crimes involving digital data. Advanced metering devices (smart meters) are being installed throughout electric networks in Europe and in the United States. The high-resolution energy consumption data which are transmitted by some smart meters to the utility company allow identification and monitoring of equipment within consumers’ homes. Our research shows that the analysis of the household’s electricity usage profile at a 0.5 Hz sample rate permits identification of audiovisual content.</p>
<p>Conference: IEEE International Workshop on Security and Forensics in Communication Systems, Ottawa, Canada. 2012.</p>
<p><a href="http://1lab.de/pub/ieee_forensics2012.pdf">PDF online.</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=174</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identifikation von Videoinhalten über granulare Stromverbrauchsdaten</title>
		<link>http://www.daprim.de/?p=170</link>
		<comments>http://www.daprim.de/?p=170#comments</comments>
		<pubDate>Tue, 10 Jul 2012 08:03:43 +0000</pubDate>
		<dc:creator>daprim</dc:creator>
				<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[Datenschutz (deutsch)]]></category>
		<category><![CDATA[Datenschutz Smartmeter Fernsehprogramm DVD Identifikation]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=170</guid>
		<description><![CDATA[Deutsche Zusammenfassung wichtiger Forschungsergebnisse bzgl. der Datenschutzproblematik bei Smartmetern, insbesondere der Möglichkeit, Videodaten über das Stromverbrauchsprofil zu identifizieren. Sekundenscharfe Ablese-Intervalle bei elektronischen Stromzahlern stellen einen erheblichen Eingriff in die Privatsphare der Stromkunden dar. Das datenschutzrechtliche Gebot der Datensparsamkeit und Datenvermeidung &#8230; <a href="http://www.daprim.de/?p=170">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><strong>Deutsche Zusammenfassung wichtiger Forschungsergebnisse bzgl. der Datenschutzproblematik bei Smartmetern, insbesondere der Möglichkeit, Videodaten über das Stromverbrauchsprofil zu identifizieren.</strong></p>
<p>Sekundenscharfe Ablese-Intervalle bei elektronischen Stromzahlern stellen einen erheblichen Eingriff in die Privatsphare der Stromkunden dar. Das datenschutzrechtliche Gebot der Datensparsamkeit und Datenvermeidung steht einer feingranularen Messgenauigkeit und der vollständigen Speicherung der Stromverbrauchsdaten entgegen. Wir können experimentell nachweisen, dass neben der Erkennung von im Haushalt befindlichen Geräten eine Erkennung des Fernsehprogramms und eine Identifikation des abgespielten Videoinhalts möglich ist. Alle Mess- und Testergebnisse wurden mithilfe eines geeichten und operativen Smart Meters, der alle zwei Sekunden Messwerte aufzeichnet, gewonnen.</p>
<p>Konferenz: Sicherheit 2012 &#8211; Sicherheit, Schutz und Zuverlässigkeit, Darmstadt. 2012.<br />
GI Proceedings 195, ISBN 978-3885792895</p>
<p>PDF ist <a href="http://1lab.de/pub/GrJuLo_Smartmeter.pdf">online</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=170</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multimedia Content Identification Through Smart Meter Power Usage Profiles</title>
		<link>http://www.daprim.de/?p=155</link>
		<comments>http://www.daprim.de/?p=155#comments</comments>
		<pubDate>Thu, 12 Jan 2012 12:19:20 +0000</pubDate>
		<dc:creator>greveler</dc:creator>
				<category><![CDATA[DaPriM]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=155</guid>
		<description><![CDATA[Using granular smart metering data it is possible to identify multimedia content by analyzing smart meter generated consumption data. We will discuss our findings at the conference Computers, Privacy and Data Protection (CPDP 2012) on Wednesday, 25 January 2012 in Brussels, &#8230; <a href="http://www.daprim.de/?p=155">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Using granular smart metering data it is possible to identify multimedia content by analyzing smart meter generated consumption data. We will discuss our findings at the conference Computers, Privacy and Data Protection (<a href="http://www.cpdpconferences.org/index.html">CPDP 2012</a>) on Wednesday, 25 January 2012 in Brussels, Belgium.</p>
<p>Our research shows that the analysis of the household&#8217;s electricity usage profile at a 2s sample rate does reveal what content was displayed on a CRT, a Plasma display TV or a LCD television set with dynamic backlighting. Our test results show that two 5 minutes-chunks of consecutive viewing without major interference by other appliances is sufficient to identify the content (e. g. DVD movie).</p>
<p>A preprint online publication can be found here (<a href="http://www.its.fh-muenster.de/greveler/pubs/preprint_online.pdf">PDF</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=155</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Selbstauskunft für Discovergy-Kunden</title>
		<link>http://www.daprim.de/?p=158</link>
		<comments>http://www.daprim.de/?p=158#comments</comments>
		<pubDate>Thu, 12 Jan 2012 11:30:58 +0000</pubDate>
		<dc:creator>greveler</dc:creator>
				<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[Datenschutz (deutsch)]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=158</guid>
		<description><![CDATA[Kunden des Smart-Meter-Dienstleisters Discovergy können seit heute über unseren experimentellen Selbstauskunftsdienst ihre Verbrauchsdaten grafisch abfragen und als Tabellendaten herunterladen. Hintergrund: Das Kundenportal zeigt die Verbrauchsdaten derzeit konsolidiert an. Es ist daher für die Kunden nicht möglich, alle über sie gespeicherten Daten &#8230; <a href="http://www.daprim.de/?p=158">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Kunden des Smart-Meter-Dienstleisters <a href="http://www.discovergy.com" target="_blank">Discovergy</a> können seit heute über unseren experimentellen <a href="https://www.its.fh-muenster.de/discovergy/">Selbstauskunftsdienst</a> ihre Verbrauchsdaten grafisch abfragen und als Tabellendaten herunterladen.</p>
<p>Hintergrund: Das Kundenportal zeigt die Verbrauchsdaten derzeit konsolidiert an. Es ist daher für die Kunden nicht möglich, alle über sie gespeicherten Daten im Detail über diesen Weg abzufragen. Da wir für unsere Forschungsarbeiten ohnehin ein Abfragetool erstellen mussten, um über die volle Datenmenge zu verfügen, stellen wir über diesen Dienst nun diese Möglichkeit auch anderen Kunden zur Verfügung.</p>
<p>Wir danken an dieser Stelle dem Projektmitarbeiter Dennis Löhr MSc, der die zugrundeliegende Software erstellt und für diesen experimentellen Webdienst zur Verfügung gestellt hat.</p>
<p>Beachten Sie: Der Dienst wurde experimentell und ohne Kooperation mit der Discovergy GmbH eingerichtet. Es ist nicht absehbar, inwieweit die Funktionsfähigkeit mittelfristig gegeben ist bzw. ob oder wann diese Abfrage unterbunden werden wird. Alle Angaben erfolgen ohne Gewähr.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=158</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beitrag über DaPriM (Smart-Meter und Datenschutz) in 3SAT.</title>
		<link>http://www.daprim.de/?p=147</link>
		<comments>http://www.daprim.de/?p=147#comments</comments>
		<pubDate>Thu, 12 Jan 2012 07:58:22 +0000</pubDate>
		<dc:creator>greveler</dc:creator>
				<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[Datenschutz (deutsch)]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=147</guid>
		<description><![CDATA[&#8220;Verräterische Daten: Smartmeter können Nutzungsverhalten preisgeben&#8221;. 11. Januar 2012, 18.30h. Wissenschaftssendung nano. &#160;]]></description>
				<content:encoded><![CDATA[<p>&#8220;Verräterische Daten: Smartmeter können Nutzungsverhalten preisgeben&#8221;.<br />
11. Januar 2012, 18.30h. <a title="nano" href="http://www.3sat.de/page/?source=/nano/technik/159522/index.html" target="_blank">Wissenschaftssendung nano.</a></p>
<p>&nbsp;<br />
<object style="height: 390px; width: 640px;" width="640" height="360" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/lk3z9S3OYJo?version=3&amp;feature=player_detailpage" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><embed style="height: 390px; width: 640px;" width="640" height="360" type="application/x-shockwave-flash" src="http://www.youtube.com/v/lk3z9S3OYJo?version=3&amp;feature=player_detailpage" allowFullScreen="true" allowScriptAccess="always" allowfullscreen="true" allowscriptaccess="always" /></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=147</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>28C3 lecture video: Smart Hacking for Privacy</title>
		<link>http://www.daprim.de/?p=134</link>
		<comments>http://www.daprim.de/?p=134#comments</comments>
		<pubDate>Sat, 31 Dec 2011 08:01:41 +0000</pubDate>
		<dc:creator>greveler</dc:creator>
				<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[Datenschutz (deutsch)]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=134</guid>
		<description><![CDATA[On the 28th Chaos Communication Congress  (annual conference of the Chaos Computer Club Germany) in Berlin a lecture on smart meter security and privacy issues was given. The video is available via Youtube below. &#160; &#160;]]></description>
				<content:encoded><![CDATA[<p>On the <a href="http://events.ccc.de/congress/2011/Fahrplan/events/4754.en.html">28th Chaos Communication Congress</a>  (annual conference of the Chaos Computer Club Germany) in Berlin a lecture on smart meter security and privacy issues was given. The video is available via Youtube below.</p>
<p><object style="height: 390px; width: 640px;" width="640" height="360" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/xOArwu3lziQ?version=3&amp;feature=player_detailpage" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><embed style="height: 390px; width: 640px;" width="640" height="360" type="application/x-shockwave-flash" src="http://www.youtube.com/v/xOArwu3lziQ?version=3&amp;feature=player_detailpage" allowFullScreen="true" allowScriptAccess="always" allowfullscreen="true" allowscriptaccess="always" /></object></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=134</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Hacking for Privacy (Vortrag am 30.12.2011)</title>
		<link>http://www.daprim.de/?p=124</link>
		<comments>http://www.daprim.de/?p=124#comments</comments>
		<pubDate>Tue, 27 Dec 2011 15:19:04 +0000</pubDate>
		<dc:creator>loehr</dc:creator>
				<category><![CDATA[DaPriM]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=124</guid>
		<description><![CDATA[Smart Hacking for Privacy: Smart Meter and Privacy Concerns. At the 28th Chaos Communication Congress  Stephan Brinkhaus BSc. gives a lecture on smart meter security issues at 16:00h 30.Dec.2011. Advanced metering devices (aka smart meters) are nowadays being installed throughout &#8230; <a href="http://www.daprim.de/?p=124">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<h2>Smart Hacking for Privacy: Smart Meter and Privacy Concerns.</h2>
<p>At the <a href="http://events.ccc.de/congress/2011/Fahrplan/events/4754.en.html">28th Chaos Communication Congress</a>  Stephan Brinkhaus BSc. gives a lecture on smart meter security issues at 16:00h 30.Dec.2011.</p>
<p>Advanced metering devices (aka smart meters) are nowadays being installed throughout electric networks in Germany, in other parts of Europe and in the United States. Due to a recent amendment especially in Germany they become more and more popular and are obligatory for new and refurbished buildings.</p>
<p>Unfortunately, smart meters are able to become surveillance devices that monitor the behavior of the customers leading to unprecedented invasions of consumer privacy. High-resolution energy consumption data is transmitted to the utility company in principle allowing intrusive identification and monitoring of equipment within consumers&#8217; homes (e. g., TV set, refrigerator, toaster, and oven) as was already shown in different reports.</p>
<p>This talk is about the Discovergy / EasyMeter smart meter used for electricity metering in private homes in Germany. During our analysis we found several security bugs that range from problems with the certificate management of the website to missing security features for the metering data in transit. For example (un)fortunately the metering data is unsigned and unencrypted, although otherwise stated explicitly on the manufacturer&#8217;s homepage. It has to be pointed out that all tests were performed on a sealed, fully functionally device.</p>
<p>In our presentation we will mainly focus on two aspects which we revealed during our analysis: first the privacy issues resulting in even allowing to identify the TV program out of the metering data and second the &#8220;problem&#8221; that one can easily alter data transmitted even for a third party and thereby potentially fake the amount of consumed power being billed.</p>
<p>In the first part of the talk we show that the analysis of the household’s electricity usage profile can reveal what channel the TV set in the household is displaying. We will also give some test-based assessments whether it is possible to scan for copyright-protected material in the data collected by the smart meter.</p>
<p>In the second part we focus on the data being transmitted by the smart meter via the Internet. We show to what extent the consumption data can be altered and transmitted to the server and visualize this by transmitting some kind of picture data to Discovergy’s consumption data server in a way that the picture content will become visible in the electricity profile. Moreover, we show what happens if the faked power consumption data reflects unrealistic extreme high or negative power consumptions and how that might influence the database and service robustness</p>
<h2><a href="http://www.daprim.de/wp-content/uploads/2011/12/1968_28c3-abstract-smart_hacking_for_privacy.pdf">abstract</a></h2>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=124</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Direct Anonymous Attestation: Enhancing Cloud Service User Privacy (paper)</title>
		<link>http://www.daprim.de/?p=117</link>
		<comments>http://www.daprim.de/?p=117#comments</comments>
		<pubDate>Wed, 02 Nov 2011 11:07:13 +0000</pubDate>
		<dc:creator>justus</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[DaPriM]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=117</guid>
		<description><![CDATA[We introduce a privacy enhancing cloud service architecture based on the Direct Anonymous Attestation (DAA) scheme. In order to protect user data, the architecture provides cloud users with the abilities of controlling the extent of data sharing among their service &#8230; <a href="http://www.daprim.de/?p=117">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>We introduce a privacy enhancing cloud service architecture based on the Direct Anonymous Attestation (DAA) scheme. In order to protect user data, the architecture provides cloud users with the abilities of controlling the extent of data sharing among their service accounts.</p>
<p>A user is then enabled to link Cloud Service applications in such a way, that his/her personal data are shared only among designated applications. The anonymity of the platform identity is preserved while the integrity of the hardware platform (represented by Trusted Computing conﬁguration register values) is proven to the remote servers. Moreover, the cloud service provider can assess user account activities, which leads to efficient security enforcement measures.</p>
<p>Read full paper <a href="http://1lab.de/pub//CloudServiceUserPrivacy.pdf">here</a> (PDF).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=117</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Privacy Preserving System for Cloud Computing (paper)</title>
		<link>http://www.daprim.de/?p=113</link>
		<comments>http://www.daprim.de/?p=113#comments</comments>
		<pubDate>Tue, 04 Oct 2011 16:02:56 +0000</pubDate>
		<dc:creator>daprim</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[DaPriM]]></category>
		<category><![CDATA[prototype]]></category>

		<guid isPermaLink="false">http://www.daprim.de/?p=113</guid>
		<description><![CDATA[Cloud computing is changing the way that organizations manage their data, due to its robustness, low cost and ubiquitous nature. Privacy concerns arise whenever sensitive data is outsourced to the cloud. Our paper introduces a cloud database storage architecture that &#8230; <a href="http://www.daprim.de/?p=113">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Cloud computing is changing the way that organizations manage their data, due to its robustness, low cost and ubiquitous nature. Privacy concerns arise whenever sensitive data is outsourced to the cloud. Our paper introduces a cloud database storage architecture that prevents the local administrator as well as the cloud administrator to learn about the outsourced database content.</p>
<p>Moreover, machine readable rights expressions are used in order to limit users of the database to a need-to-know basis. These limitations are not changeable by administrators after the database related application is launched, since a new role of rights editors is deﬁned once an application is launced. Furthermore, trusted computing is applied to bind cryptographic key information to trusted states. By limiting the necessary trust in both corporate as well as external administrators and service providers, we counteract the often criticized privacy and conﬁdentiality risks of corporate cloud computing.</p>
<p>Read full paper <a title="full paper" href="http://1lab.de/pub/privacyCloud.pdf">here</a> (PDF).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daprim.de/?feed=rss2&#038;p=113</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
