Privacy leakage quantification in vehicular ad hoc networks

Loading...
Thumbnail Image

Publisher link

Rights

All items in Research Commons are provided for private study and research purposes and are protected by copyright with all rights reserved unless otherwise indicated.

Abstract

Vehicular Ad hoc Networks (VANETs) offer the benefits of enhancing road safety and efficiency through the frequent information exchange among vehicles through continuous broadcasting of their locations and kinematics. While VANETs can be a potential solution to reduce road accidents, frequently announcing locations raises concerns about user privacy, as vehicles may become targets of trajectory tracking, resulting in the exposure of sensitive locations visited by vehicle users. Several works in the literature have tackled the problem of privacy leakage and privacy preservation through mechanisms that use periodically changing pseudo-identities---known as pseudonyms in VANETs. However, most of this work was done before standards bodies, such as ETSI and SAE, developed VANET communication standards that described how messages should be formed and broadcast, and when pseudonyms should be changed. The use of VANET communication standards makes attempts by the research community to preserve users' privacy outdated and leaves the quantification of privacy leakage in VANETs unaddressed. By keeping communication standards as the context, this thesis aims to fill the gap in understanding potential privacy threats in VANETs and to quantify privacy leakage when these standards are enforced. We analyse potential VANET privacy threats using the LINDDUN framework — a privacy threat elicitation framework and uncover 13 privacy threats in VANET communication, ranging from unawareness of vehicle communication to privacy leakage through user reidentification when the full trajectory is reconstructed. The ability to reidentify a user's true identity from a reconstructed trajectory highlights two sides of the same coin in VANET privacy issues: privacy leakage through communication and the adversary's ability to reconstruct vehicle trajectories. Given the scarcity of real-world datasets, research on VANET privacy quantification can be hindered from being conducted in accordance with communication standardisations. We analyse two real-world VANET communication datasets and identify three limitations in these datasets that render them inadequate for VANET privacy quantification research. Therefore, we develop two VANET communication datasets based on the VANET communication standards from two major standards bodies, ETSI and SAE, to serve as substitutes for inadequate real-world datasets. Based on the findings from our privacy threat elicitation, three vehicle trajectory reconstruction models are developed to simulate privacy attacks against the standardised VANET communication. The three proposed trajectory reconstruction models include a path history-based approach, a Bayesian approach, and a Kalman filter approach. Our trajectory reconstruction models show that 65 to 98% of the trajectory can be fully reconstructed, where the amount of fully reconstructed trajectory depends on the tracking models and the communication standards. Our findings indicate that the VANET communication standards may not sufficiently protect users from privacy threats, as most of the trajectory can be reconstructed by the adversary, and highlight the need for enhanced privacy-preserving mechanisms that can be deployed alongside existing standards.

Citation

Type

Series name

Date

Publisher

The University of Waikato

Type of thesis