{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T09:19:47Z","timestamp":1766135987259,"version":"3.41.0"},"reference-count":25,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2008,12,1]],"date-time":"2008-12-01T00:00:00Z","timestamp":1228089600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2008,12]]},"abstract":"<jats:p>Consider a pollster who wishes to collect private, sensitive data from a number of distrustful individuals. How might the pollster convince the respondents that it is trustworthy? Alternately, what mechanism could the respondents insist upon to ensure that mismanagement of their data is detectable and publicly demonstrable?<\/jats:p>\n          <jats:p>We detail this problem, and provide simple data submission protocols with the properties that a) leakage of private data by the pollster results in evidence of the transgression and b) the evidence cannot be fabricated without breaking cryptographic assumptions. With such guarantees, a responsible pollster could post a \u201cprivacy-bond,\u201d forfeited to anyone who can provide evidence of leakage. The respondents are assured that appropriate penalties are applied to a leaky pollster, while the protection from spurious indictment ensures that any honest pollster has no disincentive to participate in such a scheme.<\/jats:p>","DOI":"10.1145\/1455518.1477940","type":"journal-article","created":{"date-parts":[[2008,12,17]],"date-time":"2008-12-17T13:25:20Z","timestamp":1229520320000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Data Collection with Self-Enforcing Privacy"],"prefix":"10.1145","volume":"12","author":[{"given":"Philippe","family":"Golle","sequence":"first","affiliation":[{"name":"Palo Alto Research Center"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frank","family":"McSherry","sequence":"additional","affiliation":[{"name":"Microsoft Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ilya","family":"Mironov","sequence":"additional","affiliation":[{"name":"Microsoft Research"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,12]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-003-0097-x"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335438"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the Conference on Public Key Cryptography (PKC\u201904)","volume":"2947","author":"Ambainis A.","unstructured":"Ambainis , A. , Jakobsson , M. , and Lipmaa , H . 2004. Cryptographic randomized response techniques . In Proceedings of the Conference on Public Key Cryptography (PKC\u201904) . F. Bao, R. H. Deng, and J. Zhou Eds. Lecture Notes in Computer Science , vol. 2947 . Springer, 425--438. Ambainis, A., Jakobsson, M., and Lipmaa, H. 2004. Cryptographic randomized response techniques. In Proceedings of the Conference on Public Key Cryptography (PKC\u201904). F. Bao, R. H. Deng, and J. Zhou Eds. Lecture Notes in Computer Science, vol. 2947. Springer, 425--438."},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the Conference on Security and Privacy in Digital Rights Management (DRM\u201902)","volume":"2696","author":"Boldyreva A.","unstructured":"Boldyreva , A. and Jakobsson , M . 2003. Theft-protected proprietary certificates . In Proceedings of the Conference on Security and Privacy in Digital Rights Management (DRM\u201902) . J. Feigenbaum Ed. Lecture Notes in Computer Science , vol. 2696 . Springer, 208--220. Boldyreva, A. and Jakobsson, M. 2003. Theft-protected proprietary certificates. In Proceedings of the Conference on Security and Privacy in Digital Rights Management (DRM\u201902). J. Feigenbaum Ed. Lecture Notes in Computer Science, vol. 2696. Springer, 208--220."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/18.705568"},{"key":"e_1_2_1_6_1","unstructured":"Camenisch J. and Stadler M. 1997. Proof systems for general statements about discrete logarithms. Tech. rep. 260 Dept. of Computer Science ETH Zurich. Camenisch J. and Stadler M. 1997. Proof systems for general statements about discrete logarithms. Tech. rep. 260 Dept. of Computer Science ETH Zurich."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/358549.358563"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the Conference on Advances in Cryptology (CRYPTO\u201992)","volume":"740","author":"Chaum D.","unstructured":"Chaum , D. and Pedersen , T. P . 1993. Wallet databases with observers . In Proceedings of the Conference on Advances in Cryptology (CRYPTO\u201992) . E. F. Brickell Ed. Lecture Notes in Computer Science , vol. 740 . Springer, 89--105. Chaum, D. and Pedersen, T. P. 1993. Wallet databases with observers. In Proceedings of the Conference on Advances in Cryptology (CRYPTO\u201992). E. F. Brickell Ed. Lecture Notes in Computer Science, vol. 740. Springer, 89--105."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/18.841169"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/237814.237997"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/28395.28420"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180416"},{"volume-title":"Public Key Cryptography (PKC\u201903)","author":"Groth J.","key":"e_1_2_1_15_1","unstructured":"Groth , J. 2002. A verifiable secret shuffle of homomorphic encryptions . In Public Key Cryptography (PKC\u201903) . Y. Desmedt Ed. Lecture Notes in Computer Science, vol. 2567 . Springer , 145--160. Groth, J. 2002. A verifiable secret shuffle of homomorphic encryptions. In Public Key Cryptography (PKC\u201903). Y. Desmedt Ed. Lecture Notes in Computer Science, vol. 2567. Springer, 145--160."},{"key":"e_1_2_1_16_1","volume-title":"Preneel Ed. Lecture Notes in Computer Science","volume":"2271","author":"Jakobsson M.","unstructured":"Jakobsson , M. , Juels , A. , and Nguyen , P. Q . 2002. Proprietary certificates. In Topics in Cryptology (CT-RSA\u201902). B . Preneel Ed. Lecture Notes in Computer Science , vol. 2271 . Springer, 164--181. Jakobsson, M., Juels, A., and Nguyen, P. Q. 2002. Proprietary certificates. In Topics in Cryptology (CT-RSA\u201902). B. Preneel Ed. Lecture Notes in Computer Science, vol. 2271. Springer, 164--181."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065167.1065183"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029146.1029153"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/501983.502000"},{"key":"e_1_2_1_20_1","volume-title":"Qing Eds. Lecture Notes in Computer Science","volume":"1334","author":"Ogata W.","unstructured":"Ogata , W. , Kurosawa , K. , Sako , K. , and Takatani , K . 1997. Fault tolerant anonymous channel. In Information and Communication Security (ICICS\u201997). Y. Han, T. Okamoto, and S . Qing Eds. Lecture Notes in Computer Science , vol. 1334 . Springer, 440--444. Ogata, W., Kurosawa, K., Sako, K., and Takatani, K. 1997. Fault tolerant anonymous channel. In Information and Communication Security (ICICS\u201997). Y. Han, T. Okamoto, and S. Qing Eds. Lecture Notes in Computer Science, vol. 1334. Springer, 440--444."},{"key":"e_1_2_1_21_1","volume-title":"Maurer Ed. Lecture Notes in Computer Science","volume":"1070","author":"Pfitzmann B.","unstructured":"Pfitzmann , B. and Schunter , M . 1996. Asymmetric fingerprinting (extended abstract). In Advances in Cryptology (EUROCRYPT\u201996). U. M . Maurer Ed. Lecture Notes in Computer Science , vol. 1070 . Springer, 84--95. Pfitzmann, B. and Schunter, M. 1996. Asymmetric fingerprinting (extended abstract). In Advances in Cryptology (EUROCRYPT\u201996). U. M. Maurer Ed. Lecture Notes in Computer Science, vol. 1070. Springer, 84--95."},{"key":"e_1_2_1_22_1","first-page":"918","article-title":"Monte Carlo methods for index computation (mod p)","volume":"32","author":"Pollard J. M.","year":"1978","unstructured":"Pollard , J. M. 1978 . Monte Carlo methods for index computation (mod p) . Math. Comput. 32 , 918 -- 924 . Pollard, J. M. 1978. Monte Carlo methods for index computation (mod p). Math. Comput. 32, 918--924.","journal-title":"Math. Comput."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF00196725"},{"key":"e_1_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Warner S. L. 1965. Randomized response: A survey technique for eliminating evasive answer bias. Amer. Stat. Assoc. 60 309 63--69. Warner S. L. 1965. Randomized response: A survey technique for eliminating evasive answer bias. Amer. Stat. Assoc. 60 309 63--69.","DOI":"10.1080\/01621459.1965.10480775"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/1382436.1382751"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1455518.1477940","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1455518.1477940","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:54:18Z","timestamp":1750287258000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1455518.1477940"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,12]]},"references-count":25,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2008,12]]}},"alternative-id":["10.1145\/1455518.1477940"],"URL":"https:\/\/doi.org\/10.1145\/1455518.1477940","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"type":"print","value":"1094-9224"},{"type":"electronic","value":"1557-7406"}],"subject":[],"published":{"date-parts":[[2008,12]]},"assertion":[{"value":"2007-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2007-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-12-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}