Publication View

Abstract (2008)

Abstract
We describe the design and implementation of a system for conducting surveys while hiding the information provided by the respondents. We use the CRA Taulbee Survey of faculty salaries in computer science departments as a concrete example in which there are real privacy concerns but in which participation is too large and uncoordinated for direct application of known secure multiparty function evaluation protocols. Our system extends earlier work considering privacy in auctions. We adopt the approach of designating a small number of parties to do the main secure computation, but we go farther in addressing the reality of haphazard input arrival, and possible non-arrival, so that “the function,” in the usual sense, is not known until it is decided at some point to cease collecting inputs, at which point the participants at large—humans and machines—cannot be expected to be available for any interaction. A major impediment to acceptance of secure-function-evaluation technology in practice is the fundamental incompatibility of privacy preservation without trusted parties with “sanity checking ” of inputs. For the CRA Taulbee Survey, we show that a reasonable partial remedy is possible. 1 Surveys and Privacy The term survey can reasonably and usefully be taken to be quite general, subsuming referenda, elections

Publication details
Download http://citeseerx.ist.psu.edu/viewdoc/summary?doi=?doi=10.1.1.100.3258
Source http://www.cs.yale.edu/homes/jf/SMP2004.pdf
Contributors CiteSeerX
Repository CiteSeerX - Scientific Literature Digital Library and Search Engine (United States)
Type text
Language English
Relation 10.1.1.102.5483, 10.1.1.102.6991, 10.1.1.59.824, 10.1.1.110.6928, 10.1.1.119.5031, 10.1.1.63.7109, 10.1.1.17.7459, 10.1.1.29.634, 10.1.1.131.2514, 10.1.1.21.2780, 10.1.1.28.8499, 10.1.1.129.6823, 10.1.1.100.4651, 10.1.1.61.1202, 10.1.1.4.1706, 10.1.1.133.5323, 10.1.1.102.787, 10.1.1.125.3429, 10.1.1.76.9764, 10.1.1.101.1111