Cryptology ePrint Archive: Report 2015/1228

Privacy protection in electronic education based on polymorphic pseudonymization

Eric R. Verheul

Abstract: In [13.] Dutch government proposes an identity scheme supporting personal data exchange of pupils with private e-textbook publishers. This design propagates sharing personal numbers of pupils among private parties violating the data minimisation principle in privacy laws. We describe a privacy friendly alternative, giving pupils (and parents) control on exchange of their personal data. Three generic forms based on homomorphic encryption are used as building blocks. These forms do not yield personal numbers, or even personal data from a legal perspective, and have strong, unlinkability properties. Only if required a school provides a party with a party-specific {\em pseudonym} identifying a pupil. For this the school is provided an {\em encrypted pseudonym} by a central party based on a {\em polymorphic pseudonym} formed by the school. Only intended parties, not even schools, have access to pseudonyms. Different publishers can send pupil test results to a school without being able to assess whether pupils are identical. We also describe support for privacy friendly attributes and user inspection as required by privacy laws.

Category / Keywords: applications / e-textbooks, homomorphic encryption, pseudonyms, privacy enhancing technology

Date: received 23 Dec 2015, last revised 28 Dec 2015

Contact author: eric verheul at keycontrols nl

Available format(s): PDF | BibTeX Citation

Version: 20151228:083141 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]