Providing Location Privacy in Automated Fare Collection Systems

نویسندگان

  • Levente Buttyán
  • Tamás Holczer
  • István Vajda
چکیده

In many big cities around the world, public transport operators (PTOs) have introduced automated fare collection (AFC) systems, which greatly facilitate the collection and management of transactional data in their public transport systems. The benefits to the PTOs are clear: based on the fine grained data gathered on the usage of their services, they can optimize their transport systems, which may result in great savings, and thus, higher profit. AFC systems offer some benefits to the passengers too. For instance, they can enable the deployment of dynamic pricing schemes, which may be advantageous for passengers. But AFC systems also present serious privacy risks. The problem stems from the fact that electronic tickets have unique and fixed identifiers. Besides making the processing of transactional data easier for the PTO, unique and fixed identifiers are also the basis for many fraud detection and prevention techniques (e.g., blacklists). Unique and fixed ticket identifiers lead to at least two privacy problems. First, if the PTO can link particular tickets to particular persons, then it can track the whereabouts of some passengers. This could be possible, because many tickets (especially those for long term usage) may have some personal data associated with them, such as discounting rights (granted for students, elderly people, or disabled persons). By pulling together these personal data and the traces of the ticket observed in the past, the PTO may identify links between particular tickets and particular persons with high probability. Second, in many modern AFC systems, tickets are implemented on contactless smart cards. These cards execute their transactions with card readers (e.g., a ticket validating device) through wireless channels. Although the nominal range of typical contactless smart cards used in public transport applications is only a few centimeters, it has recently been demonstrated in [4] that they can be eavesdropped from a larger distance of a few meters. Hence, it is possible to install eavesdropping equipment in an unnoticeable way at places of transactions (e.g., at the entrance of metro stations), and collect transactional data, including the unique and fixed card identifers, for later off-line analysis. In this abstract, we address the second problem. Solutions to the first problem would require to substantially change the way AFC systems are engineered today, and PTOs would likely be reluctant to invest in that. On the other hand, the solutions that we propose for the second problem require changes only at the lowest layer of the AFC system architecture (i.e., in the protocols used between the contactless smart cards and the card readers), and they do not affect the higher layers (i.e., back-end processing).

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Fare Estimation using Automated Fare Collection System in Buses

Nowadays the public transportation system like the metro are well advanced. Passenger safety, convenience and the need to improve the performance of existing public transportation is driving demand for intelligent transportation system in the market. The paper we introduce, proposes a novel fare estimation technique using Automated Fare Collection (AFC) System and Radio Frequency Identification...

متن کامل

A Secure Automatic Fare Collection System for Time-Based or Distance-Based Services with Revocable Anonymity for Users

Automatic Fare Collection (AFC) systems calculate the fare that the users must pay depending on the time of service (time-based) or the points of entrance and exit of the system (distance-based). The progressive introduction of Information and Communication Technologies (ICT) allows the use of electronic tickets, which helps to reduce costs and improve the control of the infrastructures. Nevert...

متن کامل

Two-stage stochastic programming model for capacitated complete star p-hub network with different fare classes of customers

In this paper, a stochastic programming approach is applied to the airline network revenue management problem. The airline network with the arc capacitated single hub location problem based on complete–star p-hub network is considered. We try to maximize the profit of the transportation company by choosing the best hub locations and network topology, applying revenue management techniques to al...

متن کامل

Location Privacy in Wireless Sensor Networks

The insecure atmospheres makes easy for an adversary to eavesdrop the network in a wireless sensor network. An eclectic collection of protocols are available for providing content privacy but the contextual information remains unprotected. So an adversary can use this contextual information to carry out attack on source node or the sink node in sensor network. The current approaches for locatio...

متن کامل

Enhancing privacy of recent authentication schemes for low-cost RFID systems

Nowadays Radio Frequency Identification (RFID) systems have appeared in lots of identification and authentication applications. In some sensitive applications, providing secure and confidential communication is very important for end-users. To this aim, different RFID authentication protocols have been proposed, which have tried to provide security and privacy of RFID users. In this paper, we a...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006