<?xml version="1.0" encoding="ISO-8859-1"?><cms:container xmlns:cms="http://edoc.hu-berlin.de/diml/module/cms"><cms:document><cms:meta><cms:entry id="front" part="front" ref="front" type="front"/><cms:entry id="_Ref72590152" part="front" ref="_Ref72590152" type="link"/><cms:entry type="title">Privacy trade-offs in web-based services</cms:entry><cms:entry type="author">Claus Boyens</cms:entry><cms:entry id="N100FE" part="front" ref="N100FE" type="dedication"/><cms:entry id="chapter1" part="chapter1" ref="chapter1" type="chapter">1</cms:entry><cms:entry id="_Toc81287944" part="chapter1" ref="_Toc81287944" type="link"/><cms:entry id="N10116" part="chapter1" ref="N10116" type="citenumber">1</cms:entry><cms:entry id="N10124" part="chapter1" ref="N10124" type="section">1.1</cms:entry><cms:entry id="_Toc81287945" part="chapter1" ref="_Toc81287945" type="link"/><cms:entry id="N10131" part="chapter1" ref="N10131" type="citenumber">2</cms:entry><cms:entry id="N1015C" part="chapter1" ref="N1015C" type="citenumber">3</cms:entry><cms:entry id="N1015F" part="chapter1" ref="N1015F" type="mm">480#164</cms:entry><cms:entry id="_Toc81123947" part="chapter1" ref="_Toc81123947" type="link"/><cms:entry id="_Toc77593008" part="chapter1" ref="_Toc77593008" type="link"/><cms:entry id="_Ref67853259" part="chapter1" ref="_Ref67853259" type="link"/><cms:entry id="N10190" part="chapter1" ref="N10190" type="citenumber">4</cms:entry><cms:entry id="N101C2" part="chapter1" ref="N101C2" type="citenumber">5</cms:entry><cms:entry id="N101C5" part="chapter1" ref="N101C5" type="mm">480#289</cms:entry><cms:entry id="_Toc81123948" part="chapter1" ref="_Toc81123948" type="link"/><cms:entry id="_Toc77593009" part="chapter1" ref="_Toc77593009" type="link"/><cms:entry id="_Ref69560978" part="chapter1" ref="_Ref69560978" type="link"/><cms:entry id="N101FB" part="chapter1" ref="N101FB" type="citenumber">6</cms:entry><cms:entry id="_Toc81287946" part="chapter1" ref="_Toc81287946" type="link"/><cms:entry id="N10215" part="chapter1" ref="N10215" type="section">1.2</cms:entry><cms:entry id="N1021F" part="chapter1" ref="N1021F" type="citenumber">7</cms:entry><cms:entry id="_Toc81287947" part="chapter1" ref="_Toc81287947" type="link"/><cms:entry id="N10252" part="chapter1" ref="N10252" type="section">1.3</cms:entry><cms:entry id="N10263" part="chapter1" ref="N10263" type="citenumber">8</cms:entry><cms:entry id="N10283" part="chapter1" ref="N10283" type="citenumber">9</cms:entry><cms:entry id="N102A9" part="chapter1" ref="N102A9" type="mm">430#566</cms:entry><cms:entry id="_Toc81123949" part="chapter1" ref="_Toc81123949" type="link"/><cms:entry id="_Toc77593010" part="chapter1" ref="_Toc77593010" type="link"/><cms:entry id="_Ref76466800" part="chapter1" ref="_Ref76466800" type="link"/><cms:entry id="_Ref69883505" part="chapter1" ref="_Ref69883505" type="link"/><cms:entry id="_Toc81287948" part="chapter1" ref="_Toc81287948" type="link"/><cms:entry ref="chapter2" type="chapter">2</cms:entry><cms:entry ref="N102CE" type="helpercitenumber">9</cms:entry><cms:entry ref="_Ref79473503" type="link"/><cms:entry ref="OLE_LINK8" type="link"/><cms:entry ref="N102E6" type="citenumber">10</cms:entry><cms:entry ref="_Ref73250133" type="link"/><cms:entry ref="N102ED" type="section">2.1</cms:entry><cms:entry ref="_Toc81287949" type="link"/><cms:entry ref="_Ref79910332" type="link"/><cms:entry ref="N102FB" type="subsection">2.1.1</cms:entry><cms:entry ref="_Toc81287950" type="link"/><cms:entry ref="N10330" type="citenumber">11</cms:entry><cms:entry ref="_Toc81287951" type="link"/><cms:entry ref="N10347" type="subsection">2.1.2</cms:entry><cms:entry ref="N1036C" type="mm">483#80</cms:entry><cms:entry ref="_Toc81123950" type="link"/><cms:entry ref="_Toc77593011" type="link"/><cms:entry ref="_Ref70824659" type="link"/><cms:entry ref="N10380" type="citenumber">12</cms:entry><cms:entry ref="N103A9" type="citenumber">13</cms:entry><cms:entry ref="_Ref77481566" type="link"/><cms:entry ref="N103C5" type="table"/><cms:entry ref="_Toc81123993" type="link"/><cms:entry ref="N104C8" type="citenumber">14</cms:entry><cms:entry ref="_Toc81287952" type="link"/><cms:entry ref="N104F6" type="section">2.2</cms:entry><cms:entry ref="N104FB" type="subsection">2.2.1</cms:entry><cms:entry ref="_Toc81287953" type="link"/><cms:entry ref="N10505" type="citenumber">15</cms:entry><cms:entry ref="N10518" type="mm">386#116</cms:entry><cms:entry ref="_Toc81123951" type="link"/><cms:entry ref="_Toc77593012" type="link"/><cms:entry ref="_Ref67933555" type="link"/><cms:entry ref="_Ref67933540" type="link"/><cms:entry ref="_Toc81287954" type="link"/><cms:entry ref="N1054A" type="subsection">2.2.2</cms:entry><cms:entry ref="N10551" type="citenumber">16</cms:entry><cms:entry ref="N10584" type="citenumber">17</cms:entry><cms:entry ref="_Toc81287955" type="link"/><cms:entry ref="N105AF" type="subsection">2.2.3</cms:entry><cms:entry ref="N105BA" type="block">2.2.3.1</cms:entry><cms:entry ref="_Toc81287956" type="link"/><cms:entry ref="N105C4" type="citenumber">18</cms:entry><cms:entry ref="_Ref77248136" type="link"/><cms:entry ref="_Toc81287957" type="link"/><cms:entry ref="N105EF" type="block">2.2.3.2</cms:entry><cms:entry ref="N10628" type="citenumber">19</cms:entry><cms:entry ref="_Toc81287958" type="link"/><cms:entry ref="N10648" type="block">2.2.3.3</cms:entry><cms:entry ref="N10652" type="citenumber">20</cms:entry><cms:entry ref="_Toc81287959" type="link"/><cms:entry ref="N10666" type="section">2.3</cms:entry><cms:entry ref="N1066B" type="subsection">2.3.1</cms:entry><cms:entry ref="_Toc81287960" type="link"/><cms:entry ref="N1067C" type="citenumber">21</cms:entry><cms:entry ref="N1067F" type="mm">480#99</cms:entry><cms:entry ref="_Toc81123952" type="link"/><cms:entry ref="_Toc77593013" type="link"/><cms:entry ref="_Ref67933562" type="link"/><cms:entry ref="_Toc81287961" type="link"/><cms:entry ref="N106AF" type="subsection">2.3.2</cms:entry><cms:entry ref="N106B9" type="citenumber">22</cms:entry><cms:entry ref="_Toc81287962" type="link"/><cms:entry ref="N106DE" type="subsection">2.3.3</cms:entry><cms:entry ref="N106E3" type="block">2.3.3.1</cms:entry><cms:entry ref="_Toc81287963" type="link"/><cms:entry ref="_Ref75230489" type="link"/><cms:entry ref="_Toc81287964" type="link"/><cms:entry ref="N10718" type="block">2.3.3.2</cms:entry><cms:entry ref="N1071F" type="citenumber">23</cms:entry><cms:entry ref="N10753" type="citenumber">24</cms:entry><cms:entry ref="N1077F" type="citenumber">25</cms:entry><cms:entry ref="_Toc81287965" type="link"/><cms:entry ref="N10801" type="block">2.3.3.3</cms:entry><cms:entry ref="N10808" type="citenumber">26</cms:entry><cms:entry ref="_Toc81287966" type="link"/><cms:entry ref="N10835" type="block">2.3.3.4</cms:entry><cms:entry ref="N10846" type="citenumber">27</cms:entry><cms:entry ref="_Toc81287967" type="link"/><cms:entry ref="N10853" type="section">2.4</cms:entry><cms:entry ref="N10858" type="subsection">2.4.1</cms:entry><cms:entry ref="_Toc81287968" type="link"/><cms:entry ref="N10872" type="citenumber">28</cms:entry><cms:entry ref="_Ref77481592" type="link"/><cms:entry ref="N10892" type="table"/><cms:entry ref="_Toc81123994" type="link"/><cms:entry ref="N10962" type="citenumber">29</cms:entry><cms:entry ref="_Ref75141718" type="link"/><cms:entry ref="_Toc81287969" type="link"/><cms:entry ref="N10977" type="subsection">2.4.2</cms:entry><cms:entry ref="_Ref77664871" type="link"/><cms:entry ref="N1098F" type="table"/><cms:entry ref="_Toc81123995" type="link"/><cms:entry ref="_Ref77481690" type="link"/><cms:entry ref="N10ABC" type="citenumber">30</cms:entry><cms:entry ref="N10ABF" type="table"/><cms:entry ref="_Toc81123996" type="link"/><cms:entry ref="_Toc81287970" type="link"/><cms:entry ref="N10BDE" type="section">2.5</cms:entry><cms:entry ref="N10C12" type="citenumber">31</cms:entry><cms:entry ref="_Toc81287971" type="link"/><cms:entry id="chapter3" part="chapter3" ref="chapter3" type="chapter">3</cms:entry><cms:entry id="N10C2B" part="chapter3" ref="N10C2B" type="helpercitenumber">31</cms:entry><cms:entry id="_Ref72151191" part="chapter3" ref="_Ref72151191" type="link"/><cms:entry id="_Ref79473526" part="chapter3" ref="_Ref79473526" type="link"/><cms:entry id="_Ref79475777" part="chapter3" ref="_Ref79475777" type="link"/><cms:entry id="_Ref79909648" part="chapter3" ref="_Ref79909648" type="link"/><cms:entry id="N10C51" part="chapter3" ref="N10C51" type="section">3.1</cms:entry><cms:entry id="_Toc81287972" part="chapter3" ref="_Toc81287972" type="link"/><cms:entry id="N10C5B" part="chapter3" ref="N10C5B" type="citenumber">32</cms:entry><cms:entry id="OLE_LINK7" part="chapter3" ref="OLE_LINK7" type="link"/><cms:entry id="_Ref74468842" part="chapter3" ref="_Ref74468842" type="link"/><cms:entry id="_Toc81287973" part="chapter3" ref="_Toc81287973" type="link"/><cms:entry id="N10C89" part="chapter3" ref="N10C89" type="section">3.2</cms:entry><cms:entry id="N10C93" part="chapter3" ref="N10C93" type="citenumber">33</cms:entry><cms:entry id="_Ref77481746" part="chapter3" ref="_Ref77481746" type="link"/><cms:entry id="N10CA3" part="chapter3" ref="N10CA3" type="table"/><cms:entry id="_Toc81123997" part="chapter3" ref="_Toc81123997" type="link"/><cms:entry id="N10D99" part="chapter3" ref="N10D99" type="citenumber">34</cms:entry><cms:entry id="N10DB0" part="chapter3" ref="N10DB0" type="citenumber">35</cms:entry><cms:entry id="_Ref77186253" part="chapter3" ref="_Ref77186253" type="link"/><cms:entry id="_Toc81287974" part="chapter3" ref="_Toc81287974" type="link"/><cms:entry id="N10DC1" part="chapter3" ref="N10DC1" type="section">3.3</cms:entry><cms:entry id="N10DE3" part="chapter3" ref="N10DE3" type="citenumber">36</cms:entry><cms:entry id="N10E0E" part="chapter3" ref="N10E0E" type="citenumber">37</cms:entry><cms:entry id="N10E2F" part="chapter3" ref="N10E2F" type="citenumber">38</cms:entry><cms:entry id="N10EC8" part="chapter3" ref="N10EC8" type="citenumber">39</cms:entry><cms:entry id="_Ref73278508" part="chapter3" ref="_Ref73278508" type="link"/><cms:entry id="_Ref73278514" part="chapter3" ref="_Ref73278514" type="link"/><cms:entry id="N10F0A" part="chapter3" ref="N10F0A" type="mm">546#273</cms:entry><cms:entry id="_Toc81123953" part="chapter3" ref="_Toc81123953" type="link"/><cms:entry id="_Toc77593014" part="chapter3" ref="_Toc77593014" type="link"/><cms:entry id="_Ref73278589" part="chapter3" ref="_Ref73278589" type="link"/><cms:entry id="N10F68" part="chapter3" ref="N10F68" type="citenumber">40</cms:entry><cms:entry id="N10F72" part="chapter3" ref="N10F72" type="mm">585#494</cms:entry><cms:entry id="_Toc81123954" part="chapter3" ref="_Toc81123954" type="link"/><cms:entry id="_Toc77593015" part="chapter3" ref="_Toc77593015" type="link"/><cms:entry id="_Ref73285450" part="chapter3" ref="_Ref73285450" type="link"/><cms:entry id="_Toc81287975" part="chapter3" ref="_Toc81287975" type="link"/><cms:entry id="N10F8B" part="chapter3" ref="N10F8B" type="section">3.4</cms:entry><cms:entry id="_Ref77481768" part="chapter3" ref="_Ref77481768" type="link"/><cms:entry id="N10FB3" part="chapter3" ref="N10FB3" type="citenumber">41</cms:entry><cms:entry id="N10FB6" part="chapter3" ref="N10FB6" type="table"/><cms:entry id="_Toc81123998" part="chapter3" ref="_Toc81123998" type="link"/><cms:entry id="N11026" part="chapter3" ref="N11026" type="mm">19#17</cms:entry><cms:entry id="N110D1" part="chapter3" ref="N110D1" type="mm">19#25</cms:entry><cms:entry id="N110EE" part="chapter3" ref="N110EE" type="citenumber">42</cms:entry><cms:entry id="N111C2" part="chapter3" ref="N111C2" type="citenumber">43</cms:entry><cms:entry id="N111D0" part="chapter3" ref="N111D0" type="mm">377#246</cms:entry><cms:entry id="_Toc81123955" part="chapter3" ref="_Toc81123955" type="link"/><cms:entry id="_Toc77593016" part="chapter3" ref="_Toc77593016" type="link"/><cms:entry id="_Ref73293972" part="chapter3" ref="_Ref73293972" type="link"/><cms:entry id="N11266" part="chapter3" ref="N11266" type="citenumber">44</cms:entry><cms:entry id="N112A6" part="chapter3" ref="N112A6" type="citenumber">45</cms:entry><cms:entry id="N1130C" part="chapter3" ref="N1130C" type="citenumber">46</cms:entry><cms:entry id="_Ref77481840" part="chapter3" ref="_Ref77481840" type="link"/><cms:entry id="N11355" part="chapter3" ref="N11355" type="table"/><cms:entry id="_Toc81123999" part="chapter3" ref="_Toc81123999" type="link"/><cms:entry id="N113B6" part="chapter3" ref="N113B6" type="mm">123#23</cms:entry><cms:entry id="N113E8" part="chapter3" ref="N113E8" type="mm">131#45</cms:entry><cms:entry id="N11417" part="chapter3" ref="N11417" type="mm">124#23</cms:entry><cms:entry id="N1141E" part="chapter3" ref="N1141E" type="mm">123#23</cms:entry><cms:entry id="N1144C" part="chapter3" ref="N1144C" type="mm">124#23</cms:entry><cms:entry id="N11453" part="chapter3" ref="N11453" type="mm">124#23</cms:entry><cms:entry id="N1145A" part="chapter3" ref="N1145A" type="mm">123#23</cms:entry><cms:entry id="N11461" part="chapter3" ref="N11461" type="mm">124#23</cms:entry><cms:entry id="N11480" part="chapter3" ref="N11480" type="citenumber">47</cms:entry><cms:entry id="_Ref74459937" part="chapter3" ref="_Ref74459937" type="link"/><cms:entry id="_Toc81287976" part="chapter3" ref="_Toc81287976" type="link"/><cms:entry id="N11491" part="chapter3" ref="N11491" type="section">3.5</cms:entry><cms:entry id="N11496" part="chapter3" ref="N11496" type="subsection">3.5.1</cms:entry><cms:entry id="_Toc81287977" part="chapter3" ref="_Toc81287977" type="link"/><cms:entry id="_Toc77593017" part="chapter3" ref="_Toc77593017" type="link"/><cms:entry id="_Ref81122207" part="chapter3" ref="_Ref81122207" type="link"/><cms:entry id="_Toc81123956" part="chapter3" ref="_Toc81123956" type="link"/><cms:entry id="N114ED" part="chapter3" ref="N114ED" type="mm">585#351</cms:entry><cms:entry id="_Toc81287978" part="chapter3" ref="_Toc81287978" type="link"/><cms:entry id="N114FD" part="chapter3" ref="N114FD" type="subsection">3.5.2</cms:entry><cms:entry id="N11504" part="chapter3" ref="N11504" type="citenumber">48</cms:entry><cms:entry id="_Toc77593018" part="chapter3" ref="_Toc77593018" type="link"/><cms:entry id="_Toc81123957" part="chapter3" ref="_Toc81123957" type="link"/><cms:entry id="N11519" part="chapter3" ref="N11519" type="mm">585#194</cms:entry><cms:entry id="_Toc81287979" part="chapter3" ref="_Toc81287979" type="link"/><cms:entry id="N11548" part="chapter3" ref="N11548" type="subsection">3.5.3</cms:entry><cms:entry id="N1154F" part="chapter3" ref="N1154F" type="citenumber">49</cms:entry><cms:entry id="N1159D" part="chapter3" ref="N1159D" type="citenumber">50</cms:entry><cms:entry id="N115C4" part="chapter3" ref="N115C4" type="citenumber">51</cms:entry><cms:entry id="N11609" part="chapter3" ref="N11609" type="citenumber">52</cms:entry><cms:entry id="N1164B" part="chapter3" ref="N1164B" type="citenumber">53</cms:entry><cms:entry id="N11672" part="chapter3" ref="N11672" type="citenumber">54</cms:entry><cms:entry id="_Toc81287980" part="chapter3" ref="_Toc81287980" type="link"/><cms:entry id="N116A2" part="chapter3" ref="N116A2" type="section">3.6</cms:entry><cms:entry id="N116AF" part="chapter3" ref="N116AF" type="citenumber">55</cms:entry><cms:entry id="_Ref74555235" part="chapter3" ref="_Ref74555235" type="link"/><cms:entry id="N116C4" part="chapter3" ref="N116C4" type="subsection">3.6.1</cms:entry><cms:entry id="_Toc81287981" part="chapter3" ref="_Toc81287981" type="link"/><cms:entry id="N116D1" part="chapter3" ref="N116D1" type="citenumber">56</cms:entry><cms:entry id="N116F5" part="chapter3" ref="N116F5" type="citenumber">57</cms:entry><cms:entry id="N11701" part="chapter3" ref="N11701" type="citenumber">58</cms:entry><cms:entry id="N1171C" part="chapter3" ref="N1171C" type="citenumber">59</cms:entry><cms:entry id="N11737" part="chapter3" ref="N11737" type="citenumber">60</cms:entry><cms:entry id="N11758" part="chapter3" ref="N11758" type="citenumber">61</cms:entry><cms:entry id="_Ref77481911" part="chapter3" ref="_Ref77481911" type="link"/><cms:entry id="N1177B" part="chapter3" ref="N1177B" type="citenumber">62</cms:entry><cms:entry id="N1177E" part="chapter3" ref="N1177E" type="table"/><cms:entry id="_Toc81124000" part="chapter3" ref="_Toc81124000" type="link"/><cms:entry id="_Ref74555233" part="chapter3" ref="_Ref74555233" type="link"/><cms:entry id="_Toc81287982" part="chapter3" ref="_Toc81287982" type="link"/><cms:entry id="N11845" part="chapter3" ref="N11845" type="subsection">3.6.2</cms:entry><cms:entry id="N118A7" part="chapter3" ref="N118A7" type="citenumber">63</cms:entry><cms:entry id="N1193D" part="chapter3" ref="N1193D" type="citenumber">64</cms:entry><cms:entry id="N11A57" part="chapter3" ref="N11A57" type="citenumber">65</cms:entry><cms:entry id="N11B1A" part="chapter3" ref="N11B1A" type="citenumber">66</cms:entry><cms:entry id="_Ref77481924" part="chapter3" ref="_Ref77481924" type="link"/><cms:entry id="N11B29" part="chapter3" ref="N11B29" type="table"/><cms:entry id="_Toc81124001" part="chapter3" ref="_Toc81124001" type="link"/><cms:entry id="_Toc81287983" part="chapter3" ref="_Toc81287983" type="link"/><cms:entry id="N11C39" part="chapter3" ref="N11C39" type="section">3.7</cms:entry><cms:entry id="N11C40" part="chapter3" ref="N11C40" type="citenumber">67</cms:entry><cms:entry id="N11C6D" part="chapter3" ref="N11C6D" type="citenumber">68</cms:entry><cms:entry id="N11C7F" part="chapter3" ref="N11C7F" type="citenumber">69</cms:entry><cms:entry id="N11C96" part="chapter3" ref="N11C96" type="citenumber">70</cms:entry><cms:entry id="N11CC3" part="chapter3" ref="N11CC3" type="citenumber">71</cms:entry><cms:entry id="N11CEA" part="chapter3" ref="N11CEA" type="citenumber">72</cms:entry><cms:entry id="N11D3E" part="chapter3" ref="N11D3E" type="citenumber">73</cms:entry><cms:entry id="N11D8C" part="chapter3" ref="N11D8C" type="citenumber">74</cms:entry><cms:entry id="_Ref77510831" part="chapter3" ref="_Ref77510831" type="link"/><cms:entry id="_Toc81287984" part="chapter3" ref="_Toc81287984" type="link"/><cms:entry id="N11DA0" part="chapter3" ref="N11DA0" type="section">3.8</cms:entry><cms:entry id="N11DA5" part="chapter3" ref="N11DA5" type="subsection">3.8.1</cms:entry><cms:entry id="_Toc81287985" part="chapter3" ref="_Toc81287985" type="link"/><cms:entry id="N11DB6" part="chapter3" ref="N11DB6" type="citenumber">75</cms:entry><cms:entry id="N11DB9" part="chapter3" ref="N11DB9" type="mm">480#192</cms:entry><cms:entry id="_Toc81123958" part="chapter3" ref="_Toc81123958" type="link"/><cms:entry id="_Toc77593019" part="chapter3" ref="_Toc77593019" type="link"/><cms:entry id="_Ref77250703" part="chapter3" ref="_Ref77250703" type="link"/><cms:entry id="N11DD4" part="chapter3" ref="N11DD4" type="table"/><cms:entry id="_Toc81124002" part="chapter3" ref="_Toc81124002" type="link"/><cms:entry id="_Toc81287986" part="chapter3" ref="_Toc81287986" type="link"/><cms:entry id="N11EBE" part="chapter3" ref="N11EBE" type="subsection">3.8.2</cms:entry><cms:entry id="N11EC5" part="chapter3" ref="N11EC5" type="citenumber">76</cms:entry><cms:entry id="N11EE9" part="chapter3" ref="N11EE9" type="citenumber">77</cms:entry><cms:entry id="N11EF6" part="chapter3" ref="N11EF6" type="mm">551#299</cms:entry><cms:entry id="_Toc81123959" part="chapter3" ref="_Toc81123959" type="link"/><cms:entry id="_Toc77593020" part="chapter3" ref="_Toc77593020" type="link"/><cms:entry id="_Ref74509368" part="chapter3" ref="_Ref74509368" type="link"/><cms:entry id="N11F11" part="chapter3" ref="N11F11" type="citenumber">78</cms:entry><cms:entry id="N11F14" part="chapter3" ref="N11F14" type="mm">502#262</cms:entry><cms:entry id="_Toc81123960" part="chapter3" ref="_Toc81123960" type="link"/><cms:entry id="_Toc77593021" part="chapter3" ref="_Toc77593021" type="link"/><cms:entry id="_Ref74509412" part="chapter3" ref="_Ref74509412" type="link"/><cms:entry id="N11F31" part="chapter3" ref="N11F31" type="citenumber">79</cms:entry><cms:entry id="N11F34" part="chapter3" ref="N11F34" type="mm">502#293</cms:entry><cms:entry id="_Toc81123961" part="chapter3" ref="_Toc81123961" type="link"/><cms:entry id="_Toc77593022" part="chapter3" ref="_Toc77593022" type="link"/><cms:entry id="_Ref77446597" part="chapter3" ref="_Ref77446597" type="link"/><cms:entry id="_Ref77141550" part="chapter3" ref="_Ref77141550" type="link"/><cms:entry id="_Toc81287987" part="chapter3" ref="_Toc81287987" type="link"/><cms:entry id="N11F62" part="chapter3" ref="N11F62" type="subsection">3.8.3</cms:entry><cms:entry id="N11F6C" part="chapter3" ref="N11F6C" type="citenumber">80</cms:entry><cms:entry id="N11F7C" part="chapter3" ref="N11F7C" type="mm">586#234</cms:entry><cms:entry id="_Toc81123962" part="chapter3" ref="_Toc81123962" type="link"/><cms:entry id="_Toc77593023" part="chapter3" ref="_Toc77593023" type="link"/><cms:entry id="_Ref74465498" part="chapter3" ref="_Ref74465498" type="link"/><cms:entry id="N11F90" part="chapter3" ref="N11F90" type="citenumber">81</cms:entry><cms:entry id="_Toc81287988" part="chapter3" ref="_Toc81287988" type="link"/><cms:entry id="N11F9F" part="chapter3" ref="N11F9F" type="section">3.9</cms:entry><cms:entry id="N11FBA" part="chapter3" ref="N11FBA" type="citenumber">82</cms:entry><cms:entry id="_Ref72438087" part="chapter3" ref="_Ref72438087" type="link"/><cms:entry id="_Toc81287989" part="chapter3" ref="_Toc81287989" type="link"/><cms:entry id="chapter4" part="chapter4" ref="chapter4" type="chapter">4</cms:entry><cms:entry id="_Ref79475927" part="chapter4" ref="_Ref79475927" type="link"/><cms:entry id="N11FE5" part="chapter4" ref="N11FE5" type="helpercitenumber">82</cms:entry><cms:entry id="_Ref79473539" part="chapter4" ref="_Ref79473539" type="link"/><cms:entry id="N11FEC" part="chapter4" ref="N11FEC" type="citenumber">83</cms:entry><cms:entry id="N11FFA" part="chapter4" ref="N11FFA" type="section">4.1</cms:entry><cms:entry id="_Toc81287990" part="chapter4" ref="_Toc81287990" type="link"/><cms:entry id="N12002" part="chapter4" ref="N12002" type="subsection">4.1.1</cms:entry><cms:entry id="_Toc81287991" part="chapter4" ref="_Toc81287991" type="link"/><cms:entry id="N1201E" part="chapter4" ref="N1201E" type="mm">480#99</cms:entry><cms:entry id="_Toc81123963" part="chapter4" ref="_Toc81123963" type="link"/><cms:entry id="_Toc77593024" part="chapter4" ref="_Toc77593024" type="link"/><cms:entry id="_Ref74595041" part="chapter4" ref="_Ref74595041" type="link"/><cms:entry id="N12032" part="chapter4" ref="N12032" type="citenumber">84</cms:entry><cms:entry id="_Ref76980684" part="chapter4" ref="_Ref76980684" type="link"/><cms:entry id="_Toc81287992" part="chapter4" ref="_Toc81287992" type="link"/><cms:entry id="N1204C" part="chapter4" ref="N1204C" type="subsection">4.1.2</cms:entry><cms:entry id="N12061" part="chapter4" ref="N12061" type="mm">387#300</cms:entry><cms:entry id="_Toc81123964" part="chapter4" ref="_Toc81123964" type="link"/><cms:entry id="_Toc77593025" part="chapter4" ref="_Toc77593025" type="link"/><cms:entry id="_Ref74603678" part="chapter4" ref="_Ref74603678" type="link"/><cms:entry id="N1207B" part="chapter4" ref="N1207B" type="citenumber">85</cms:entry><cms:entry id="N120AF" part="chapter4" ref="N120AF" type="citenumber">86</cms:entry><cms:entry id="N120F9" part="chapter4" ref="N120F9" type="mm">374#232</cms:entry><cms:entry id="_Toc81123965" part="chapter4" ref="_Toc81123965" type="link"/><cms:entry id="_Toc77593026" part="chapter4" ref="_Toc77593026" type="link"/><cms:entry id="_Ref74934702" part="chapter4" ref="_Ref74934702" type="link"/><cms:entry id="N1210D" part="chapter4" ref="N1210D" type="citenumber">87</cms:entry><cms:entry id="_Ref77482139" part="chapter4" ref="_Ref77482139" type="link"/><cms:entry id="N1211D" part="chapter4" ref="N1211D" type="table"/><cms:entry id="_Toc81124003" part="chapter4" ref="_Toc81124003" type="link"/><cms:entry id="_Ref77482146" part="chapter4" ref="_Ref77482146" type="link"/><cms:entry id="N121C7" part="chapter4" ref="N121C7" type="table"/><cms:entry id="_Toc81124004" part="chapter4" ref="_Toc81124004" type="link"/><cms:entry id="N12260" part="chapter4" ref="N12260" type="citenumber">88</cms:entry><cms:entry id="_Ref74733576" part="chapter4" ref="_Ref74733576" type="link"/><cms:entry id="_Ref77225211" part="chapter4" ref="_Ref77225211" type="link"/><cms:entry id="_Toc81287993" part="chapter4" ref="_Toc81287993" type="link"/><cms:entry id="N12284" part="chapter4" ref="N12284" type="subsection">4.1.3</cms:entry><cms:entry id="N1228E" part="chapter4" ref="N1228E" type="citenumber">89</cms:entry><cms:entry id="N122BA" part="chapter4" ref="N122BA" type="citenumber">90</cms:entry><cms:entry id="OLE_LINK1" part="chapter4" ref="OLE_LINK1" type="link"/><cms:entry id="N122D3" part="chapter4" ref="N122D3" type="mm">520#308</cms:entry><cms:entry id="_Toc81123966" part="chapter4" ref="_Toc81123966" type="link"/><cms:entry id="_Toc77593027" part="chapter4" ref="_Toc77593027" type="link"/><cms:entry id="_Ref74934844" part="chapter4" ref="_Ref74934844" type="link"/><cms:entry id="_Ref77141190" part="chapter4" ref="_Ref77141190" type="link"/><cms:entry id="_Toc81287994" part="chapter4" ref="_Toc81287994" type="link"/><cms:entry id="N122F9" part="chapter4" ref="N122F9" type="subsection">4.1.4</cms:entry><cms:entry id="N12300" part="chapter4" ref="N12300" type="citenumber">91</cms:entry><cms:entry id="_Ref74745473" part="chapter4" ref="_Ref74745473" type="link"/><cms:entry id="_Toc81287995" part="chapter4" ref="_Toc81287995" type="link"/><cms:entry id="N1231A" part="chapter4" ref="N1231A" type="section">4.2</cms:entry><cms:entry id="N1231F" part="chapter4" ref="N1231F" type="subsection">4.2.1</cms:entry><cms:entry id="_Toc81287996" part="chapter4" ref="_Toc81287996" type="link"/><cms:entry id="_Toc81287997" part="chapter4" ref="_Toc81287997" type="link"/><cms:entry id="N12338" part="chapter4" ref="N12338" type="subsection">4.2.2</cms:entry><cms:entry id="N12353" part="chapter4" ref="N12353" type="citenumber">92</cms:entry><cms:entry id="N12363" part="chapter4" ref="N12363" type="table"/><cms:entry id="N1241F" part="chapter4" ref="N1241F" type="citenumber">93</cms:entry><cms:entry id="OLE_LINK2" part="chapter4" ref="OLE_LINK2" type="link"/><cms:entry id="_Toc81287998" part="chapter4" ref="_Toc81287998" type="link"/><cms:entry id="N12476" part="chapter4" ref="N12476" type="section">4.3</cms:entry><cms:entry id="N1247B" part="chapter4" ref="N1247B" type="subsection">4.3.1</cms:entry><cms:entry id="_Toc81287999" part="chapter4" ref="_Toc81287999" type="link"/><cms:entry id="_Ref77482115" part="chapter4" ref="_Ref77482115" type="link"/><cms:entry id="N1248E" part="chapter4" ref="N1248E" type="table"/><cms:entry id="_Toc81124005" part="chapter4" ref="_Toc81124005" type="link"/><cms:entry id="N12636" part="chapter4" ref="N12636" type="citenumber">94</cms:entry><cms:entry id="_Ref77482162" part="chapter4" ref="_Ref77482162" type="link"/><cms:entry id="N12669" part="chapter4" ref="N12669" type="table"/><cms:entry id="_Toc81124006" part="chapter4" ref="_Toc81124006" type="link"/><cms:entry id="_Ref77825867" part="chapter4" ref="_Ref77825867" type="link"/><cms:entry id="_Toc81288000" part="chapter4" ref="_Toc81288000" type="link"/><cms:entry id="N12871" part="chapter4" ref="N12871" type="subsection">4.3.2</cms:entry><cms:entry id="N12878" part="chapter4" ref="N12878" type="citenumber">95</cms:entry><cms:entry id="N128A8" part="chapter4" ref="N128A8" type="table"/><cms:entry id="N12A81" part="chapter4" ref="N12A81" type="citenumber">96</cms:entry><cms:entry id="N12A84" part="chapter4" ref="N12A84" type="table"/><cms:entry id="N12C47" part="chapter4" ref="N12C47" type="mm">116#51</cms:entry><cms:entry id="N12C54" part="chapter4" ref="N12C54" type="mm">120#51</cms:entry><cms:entry id="N12C61" part="chapter4" ref="N12C61" type="mm">119#51</cms:entry><cms:entry id="_Ref77482311" part="chapter4" ref="_Ref77482311" type="link"/><cms:entry id="N12CDE" part="chapter4" ref="N12CDE" type="table"/><cms:entry id="_Toc81124007" part="chapter4" ref="_Toc81124007" type="link"/><cms:entry id="N12DE1" part="chapter4" ref="N12DE1" type="citenumber">97</cms:entry><cms:entry id="_Ref77319160" part="chapter4" ref="_Ref77319160" type="link"/><cms:entry id="_Toc81288001" part="chapter4" ref="_Toc81288001" type="link"/><cms:entry id="N12DF2" part="chapter4" ref="N12DF2" type="subsection">4.3.3</cms:entry><cms:entry id="N12E44" part="chapter4" ref="N12E44" type="citenumber">98</cms:entry><cms:entry id="_Ref77482196" part="chapter4" ref="_Ref77482196" type="link"/><cms:entry id="N12E90" part="chapter4" ref="N12E90" type="table"/><cms:entry id="_Toc81124008" part="chapter4" ref="_Toc81124008" type="link"/><cms:entry id="N12F8A" part="chapter4" ref="N12F8A" type="citenumber">99</cms:entry><cms:entry id="_Toc81288002" part="chapter4" ref="_Toc81288002" type="link"/><cms:entry id="N12F9D" part="chapter4" ref="N12F9D" type="subsection">4.3.4</cms:entry><cms:entry id="_Ref77482265" part="chapter4" ref="_Ref77482265" type="link"/><cms:entry id="N12FC1" part="chapter4" ref="N12FC1" type="table"/><cms:entry id="_Toc81124009" part="chapter4" ref="_Toc81124009" type="link"/><cms:entry id="N131B8" part="chapter4" ref="N131B8" type="citenumber">100</cms:entry><cms:entry id="N131BE" part="chapter4" ref="N131BE" type="table"/><cms:entry id="N1338A" part="chapter4" ref="N1338A" type="mm">116#51</cms:entry><cms:entry id="N13397" part="chapter4" ref="N13397" type="mm">115#51</cms:entry><cms:entry id="N133A4" part="chapter4" ref="N133A4" type="mm">115#51</cms:entry><cms:entry id="_Ref77482293" part="chapter4" ref="_Ref77482293" type="link"/><cms:entry id="N13467" part="chapter4" ref="N13467" type="citenumber">101</cms:entry><cms:entry id="N1346A" part="chapter4" ref="N1346A" type="table"/><cms:entry id="_Toc81124010" part="chapter4" ref="_Toc81124010" type="link"/><cms:entry id="_Ref75685809" part="chapter4" ref="_Ref75685809" type="link"/><cms:entry id="_Toc81288003" part="chapter4" ref="_Toc81288003" type="link"/><cms:entry id="N13585" part="chapter4" ref="N13585" type="subsection">4.3.5</cms:entry><cms:entry id="N135C9" part="chapter4" ref="N135C9" type="citenumber">102</cms:entry><cms:entry id="N13649" part="chapter4" ref="N13649" type="citenumber">103</cms:entry><cms:entry id="N1364C" part="chapter4" ref="N1364C" type="mm">433#239</cms:entry><cms:entry id="_Toc81123967" part="chapter4" ref="_Toc81123967" type="link"/><cms:entry id="_Toc77593028" part="chapter4" ref="_Toc77593028" type="link"/><cms:entry id="_Ref75091891" part="chapter4" ref="_Ref75091891" type="link"/><cms:entry id="N13671" part="chapter4" ref="N13671" type="table"/><cms:entry id="_Toc81124011" part="chapter4" ref="_Toc81124011" type="link"/><cms:entry id="N13768" part="chapter4" ref="N13768" type="citenumber">104</cms:entry><cms:entry id="_Toc81288004" part="chapter4" ref="_Toc81288004" type="link"/><cms:entry id="N13774" part="chapter4" ref="N13774" type="section">4.4</cms:entry><cms:entry id="N1378D" part="chapter4" ref="N1378D" type="citenumber">105</cms:entry><cms:entry id="N13790" part="chapter4" ref="N13790" type="mm">383#193</cms:entry><cms:entry id="_Toc81123968" part="chapter4" ref="_Toc81123968" type="link"/><cms:entry id="_Toc77593029" part="chapter4" ref="_Toc77593029" type="link"/><cms:entry id="_Ref75162728" part="chapter4" ref="_Ref75162728" type="link"/><cms:entry id="N137A2" part="chapter4" ref="N137A2" type="subsection">4.4.1</cms:entry><cms:entry id="_Toc81288005" part="chapter4" ref="_Toc81288005" type="link"/><cms:entry id="N137C5" part="chapter4" ref="N137C5" type="citenumber">106</cms:entry><cms:entry id="N137DB" part="chapter4" ref="N137DB" type="mm">363#298</cms:entry><cms:entry id="_Toc81123969" part="chapter4" ref="_Toc81123969" type="link"/><cms:entry id="_Toc77593030" part="chapter4" ref="_Toc77593030" type="link"/><cms:entry id="_Ref75233483" part="chapter4" ref="_Ref75233483" type="link"/><cms:entry id="N1380D" part="chapter4" ref="N1380D" type="citenumber">107</cms:entry><cms:entry id="_Toc81288006" part="chapter4" ref="_Toc81288006" type="link"/><cms:entry id="N13833" part="chapter4" ref="N13833" type="subsection">4.4.2</cms:entry><cms:entry id="N13841" part="chapter4" ref="N13841" type="citenumber">108</cms:entry><cms:entry id="_Toc81288007" part="chapter4" ref="_Toc81288007" type="link"/><cms:entry id="N1384C" part="chapter4" ref="N1384C" type="subsection">4.4.3</cms:entry><cms:entry id="_Ref77482413" part="chapter4" ref="_Ref77482413" type="link"/><cms:entry id="N1386C" part="chapter4" ref="N1386C" type="table"/><cms:entry id="_Toc81124012" part="chapter4" ref="_Toc81124012" type="link"/><cms:entry id="N13960" part="chapter4" ref="N13960" type="citenumber">109</cms:entry><cms:entry id="N13963" part="chapter4" ref="N13963" type="table"/><cms:entry id="N13A28" part="chapter4" ref="N13A28" type="mm">430#292</cms:entry><cms:entry id="_Toc81123970" part="chapter4" ref="_Toc81123970" type="link"/><cms:entry id="_Toc77593031" part="chapter4" ref="_Toc77593031" type="link"/><cms:entry id="_Ref75544944" part="chapter4" ref="_Ref75544944" type="link"/><cms:entry id="N13A3C" part="chapter4" ref="N13A3C" type="citenumber">110</cms:entry><cms:entry id="N13A46" part="chapter4" ref="N13A46" type="mm">155#49</cms:entry><cms:entry id="_Ref77482431" part="chapter4" ref="_Ref77482431" type="link"/><cms:entry id="N13A9B" part="chapter4" ref="N13A9B" type="table"/><cms:entry id="_Toc81124013" part="chapter4" ref="_Toc81124013" type="link"/><cms:entry id="N13B13" part="chapter4" ref="N13B13" type="mm">87#45</cms:entry><cms:entry id="N13B20" part="chapter4" ref="N13B20" type="mm">155#49</cms:entry><cms:entry id="_Toc81288008" part="chapter4" ref="_Toc81288008" type="link"/><cms:entry id="N13C12" part="chapter4" ref="N13C12" type="section">4.5</cms:entry><cms:entry id="N13C17" part="chapter4" ref="N13C17" type="subsection">4.5.1</cms:entry><cms:entry id="_Toc81288009" part="chapter4" ref="_Toc81288009" type="link"/><cms:entry id="N13C21" part="chapter4" ref="N13C21" type="citenumber">111</cms:entry><cms:entry id="N13C42" part="chapter4" ref="N13C42" type="citenumber">112</cms:entry><cms:entry id="_Toc81288010" part="chapter4" ref="_Toc81288010" type="link"/><cms:entry id="N13C51" part="chapter4" ref="N13C51" type="subsection">4.5.2</cms:entry><cms:entry id="N13CB8" part="chapter4" ref="N13CB8" type="citenumber">113</cms:entry><cms:entry id="_Ref77482532" part="chapter4" ref="_Ref77482532" type="link"/><cms:entry id="N13CD7" part="chapter4" ref="N13CD7" type="table"/><cms:entry id="_Toc81124014" part="chapter4" ref="_Toc81124014" type="link"/><cms:entry id="N13E04" part="chapter4" ref="N13E04" type="citenumber">114</cms:entry><cms:entry id="OLE_LINK3" part="chapter4" ref="OLE_LINK3" type="link"/><cms:entry id="_Toc81288011" part="chapter4" ref="_Toc81288011" type="link"/><cms:entry id="N13E9C" part="chapter4" ref="N13E9C" type="subsection">4.5.3</cms:entry><cms:entry id="N13EA3" part="chapter4" ref="N13EA3" type="citenumber">115</cms:entry><cms:entry id="N13EB3" part="chapter4" ref="N13EB3" type="mm">503#344</cms:entry><cms:entry id="_Toc81123971" part="chapter4" ref="_Toc81123971" type="link"/><cms:entry id="_Toc77593032" part="chapter4" ref="_Toc77593032" type="link"/><cms:entry id="_Ref75595073" part="chapter4" ref="_Ref75595073" type="link"/><cms:entry id="N13ECA" part="chapter4" ref="N13ECA" type="citenumber">116</cms:entry><cms:entry id="_Ref77589574" part="chapter4" ref="_Ref77589574" type="link"/><cms:entry id="_Toc81288012" part="chapter4" ref="_Toc81288012" type="link"/><cms:entry id="N13EDC" part="chapter4" ref="N13EDC" type="section">4.6</cms:entry><cms:entry id="N13F21" part="chapter4" ref="N13F21" type="subsection">4.6.1</cms:entry><cms:entry id="_Toc81288013" part="chapter4" ref="_Toc81288013" type="link"/><cms:entry id="N13F2B" part="chapter4" ref="N13F2B" type="citenumber">117</cms:entry><cms:entry id="_Ref75685202" part="chapter4" ref="_Ref75685202" type="link"/><cms:entry id="_Toc77593033" part="chapter4" ref="_Toc77593033" type="link"/><cms:entry id="_Toc81123972" part="chapter4" ref="_Toc81123972" type="link"/><cms:entry id="N13F55" part="chapter4" ref="N13F55" type="mm">585#396</cms:entry><cms:entry id="N13F60" part="chapter4" ref="N13F60" type="citenumber">118</cms:entry><cms:entry id="_Toc81288014" part="chapter4" ref="_Toc81288014" type="link"/><cms:entry id="N13F6F" part="chapter4" ref="N13F6F" type="subsection">4.6.2</cms:entry><cms:entry id="N13F74" part="chapter4" ref="N13F74" type="block">4.6.2.1</cms:entry><cms:entry id="_Toc81288015" part="chapter4" ref="_Toc81288015" type="link"/><cms:entry id="N13FEB" part="chapter4" ref="N13FEB" type="citenumber">119</cms:entry><cms:entry id="N13FEE" part="chapter4" ref="N13FEE" type="table"/><cms:entry id="N1401F" part="chapter4" ref="N1401F" type="mm">271#45</cms:entry><cms:entry id="N1404A" part="chapter4" ref="N1404A" type="mm">267#45</cms:entry><cms:entry id="N14075" part="chapter4" ref="N14075" type="mm">271#45</cms:entry><cms:entry id="N140A0" part="chapter4" ref="N140A0" type="mm">268#45</cms:entry><cms:entry id="N140B9" part="chapter4" ref="N140B9" type="mm">165#51</cms:entry><cms:entry id="N140CC" part="chapter4" ref="N140CC" type="table"/><cms:entry id="N140F4" part="chapter4" ref="N140F4" type="mm">176#47</cms:entry><cms:entry id="N140F9" part="chapter4" ref="N140F9" type="mm">348#47</cms:entry><cms:entry id="N1411B" part="chapter4" ref="N1411B" type="mm">175#47</cms:entry><cms:entry id="N14120" part="chapter4" ref="N14120" type="mm">345#47</cms:entry><cms:entry id="N14142" part="chapter4" ref="N14142" type="mm">176#47</cms:entry><cms:entry id="N14147" part="chapter4" ref="N14147" type="mm">353#47</cms:entry><cms:entry id="N14169" part="chapter4" ref="N14169" type="mm">175#47</cms:entry><cms:entry id="N1416E" part="chapter4" ref="N1416E" type="mm">349#47</cms:entry><cms:entry id="OLE_LINK5" part="chapter4" ref="OLE_LINK5" type="link"/><cms:entry id="N1418A" part="chapter4" ref="N1418A" type="citenumber">120</cms:entry><cms:entry id="N141A8" part="chapter4" ref="N141A8" type="citenumber">121</cms:entry><cms:entry id="N141CF" part="chapter4" ref="N141CF" type="citenumber">122</cms:entry><cms:entry id="_Ref77482640" part="chapter4" ref="_Ref77482640" type="link"/><cms:entry id="N141EF" part="chapter4" ref="N141EF" type="citenumber">123</cms:entry><cms:entry id="N141F2" part="chapter4" ref="N141F2" type="table"/><cms:entry id="_Toc81124015" part="chapter4" ref="_Toc81124015" type="link"/><cms:entry id="N1431B" part="chapter4" ref="N1431B" type="mm">43#37</cms:entry><cms:entry id="N14449" part="chapter4" ref="N14449" type="citenumber">124</cms:entry><cms:entry id="N14479" part="chapter4" ref="N14479" type="table"/><cms:entry id="N144DA" part="chapter4" ref="N144DA" type="citenumber">125</cms:entry><cms:entry id="_Ref75775598" part="chapter4" ref="_Ref75775598" type="link"/><cms:entry id="_Toc77593034" part="chapter4" ref="_Toc77593034" type="link"/><cms:entry id="_Toc81123973" part="chapter4" ref="_Toc81123973" type="link"/><cms:entry id="N144F9" part="chapter4" ref="N144F9" type="mm">585#353</cms:entry><cms:entry id="_Ref77589618" part="chapter4" ref="_Ref77589618" type="link"/><cms:entry id="_Toc81288016" part="chapter4" ref="_Toc81288016" type="link"/><cms:entry id="N14511" part="chapter4" ref="N14511" type="section">4.7</cms:entry><cms:entry id="N14518" part="chapter4" ref="N14518" type="citenumber">126</cms:entry><cms:entry id="N14557" part="chapter4" ref="N14557" type="mm">165#51</cms:entry><cms:entry id="N14567" part="chapter4" ref="N14567" type="citenumber">127</cms:entry><cms:entry id="N1456A" part="chapter4" ref="N1456A" type="table"/><cms:entry id="N14592" part="chapter4" ref="N14592" type="mm">329#47</cms:entry><cms:entry id="N145B7" part="chapter4" ref="N145B7" type="mm">324#47</cms:entry><cms:entry id="N145DC" part="chapter4" ref="N145DC" type="mm">331#47</cms:entry><cms:entry id="N14601" part="chapter4" ref="N14601" type="mm">327#47</cms:entry><cms:entry id="N1462C" part="chapter4" ref="N1462C" type="citenumber">128</cms:entry><cms:entry id="N1462F" part="chapter4" ref="N1462F" type="table"/><cms:entry id="_Toc81124016" part="chapter4" ref="_Toc81124016" type="link"/><cms:entry id="N1481F" part="chapter4" ref="N1481F" type="table"/><cms:entry id="N148D3" part="chapter4" ref="N148D3" type="citenumber">129</cms:entry><cms:entry id="_Ref76290068" part="chapter4" ref="_Ref76290068" type="link"/><cms:entry id="_Toc77593035" part="chapter4" ref="_Toc77593035" type="link"/><cms:entry id="_Toc81123974" part="chapter4" ref="_Toc81123974" type="link"/><cms:entry id="N148EF" part="chapter4" ref="N148EF" type="mm">586#216</cms:entry><cms:entry id="N14901" part="chapter4" ref="N14901" type="citenumber">130</cms:entry><cms:entry id="N1490D" part="chapter4" ref="N1490D" type="mm">360#430</cms:entry><cms:entry id="_Toc81123975" part="chapter4" ref="_Toc81123975" type="link"/><cms:entry id="_Toc77593036" part="chapter4" ref="_Toc77593036" type="link"/><cms:entry id="_Ref76270134" part="chapter4" ref="_Ref76270134" type="link"/><cms:entry id="_Ref76270150" part="chapter4" ref="_Ref76270150" type="link"/><cms:entry id="_Toc77593037" part="chapter4" ref="_Toc77593037" type="link"/><cms:entry id="_Toc81123976" part="chapter4" ref="_Toc81123976" type="link"/><cms:entry id="N14933" part="chapter4" ref="N14933" type="mm">585#393</cms:entry><cms:entry id="_Ref77563667" part="chapter4" ref="_Ref77563667" type="link"/><cms:entry id="_Toc81288017" part="chapter4" ref="_Toc81288017" type="link"/><cms:entry id="N14949" part="chapter4" ref="N14949" type="section">4.8</cms:entry><cms:entry id="N1494E" part="chapter4" ref="N1494E" type="subsection">4.8.1</cms:entry><cms:entry id="_Toc81288018" part="chapter4" ref="_Toc81288018" type="link"/><cms:entry id="N14958" part="chapter4" ref="N14958" type="citenumber">131</cms:entry><cms:entry id="_Toc81288019" part="chapter4" ref="_Toc81288019" type="link"/><cms:entry id="N14988" part="chapter4" ref="N14988" type="subsection">4.8.2</cms:entry><cms:entry id="N149A1" part="chapter4" ref="N149A1" type="citenumber">132</cms:entry><cms:entry id="N149A4" part="chapter4" ref="N149A4" type="mm">565#348</cms:entry><cms:entry id="_Toc81123977" part="chapter4" ref="_Toc81123977" type="link"/><cms:entry id="_Toc77593038" part="chapter4" ref="_Toc77593038" type="link"/><cms:entry id="_Ref76290597" part="chapter4" ref="_Ref76290597" type="link"/><cms:entry id="N149E8" part="chapter4" ref="N149E8" type="citenumber">133</cms:entry><cms:entry id="N149EE" part="chapter4" ref="N149EE" type="table"/><cms:entry id="_Toc81124017" part="chapter4" ref="_Toc81124017" type="link"/><cms:entry id="_Toc81288020" part="chapter4" ref="_Toc81288020" type="link"/><cms:entry id="N14B42" part="chapter4" ref="N14B42" type="subsection">4.8.3</cms:entry><cms:entry id="N14B4C" part="chapter4" ref="N14B4C" type="citenumber">134</cms:entry><cms:entry id="N14C5D" part="chapter4" ref="N14C5D" type="citenumber">135</cms:entry><cms:entry id="_Ref76354455" part="chapter4" ref="_Ref76354455" type="link"/><cms:entry id="_Ref76353419" part="chapter4" ref="_Ref76353419" type="link"/><cms:entry id="_Ref76354533" part="chapter4" ref="_Ref76354533" type="link"/><cms:entry id="N14CD8" part="chapter4" ref="N14CD8" type="mm">528#272</cms:entry><cms:entry id="_Toc81123978" part="chapter4" ref="_Toc81123978" type="link"/><cms:entry id="_Toc77593039" part="chapter4" ref="_Toc77593039" type="link"/><cms:entry id="_Ref77572444" part="chapter4" ref="_Ref77572444" type="link"/><cms:entry id="_Ref76711195" part="chapter4" ref="_Ref76711195" type="link"/><cms:entry id="N14CEF" part="chapter4" ref="N14CEF" type="citenumber">136</cms:entry><cms:entry id="_Toc81288021" part="chapter4" ref="_Toc81288021" type="link"/><cms:entry id="N14CFD" part="chapter4" ref="N14CFD" type="subsection">4.8.4</cms:entry><cms:entry id="_Ref76981845" part="chapter4" ref="_Ref76981845" type="link"/><cms:entry id="N14D08" part="chapter4" ref="N14D08" type="block">4.8.4.1</cms:entry><cms:entry id="_Toc81288022" part="chapter4" ref="_Toc81288022" type="link"/><cms:entry id="N14D2C" part="chapter4" ref="N14D2C" type="citenumber">137</cms:entry><cms:entry id="N14D38" part="chapter4" ref="N14D38" type="mm">197#67</cms:entry><cms:entry id="N14D48" part="chapter4" ref="N14D48" type="mm">203#67</cms:entry><cms:entry id="N14D58" part="chapter4" ref="N14D58" type="mm">237#67</cms:entry><cms:entry id="N14D5F" part="chapter4" ref="N14D5F" type="citenumber">138</cms:entry><cms:entry id="N14D6B" part="chapter4" ref="N14D6B" type="mm">239#67</cms:entry><cms:entry id="N14D76" part="chapter4" ref="N14D76" type="mm">403#67</cms:entry><cms:entry id="N14DAD" part="chapter4" ref="N14DAD" type="citenumber">139</cms:entry><cms:entry id="N14DB0" part="chapter4" ref="N14DB0" type="table"/><cms:entry id="N14E08" part="chapter4" ref="N14E08" type="table"/><cms:entry id="N14E36" part="chapter4" ref="N14E36" type="mm">317#52</cms:entry><cms:entry id="N14E4F" part="chapter4" ref="N14E4F" type="mm">283#32</cms:entry><cms:entry id="N14E5C" part="chapter4" ref="N14E5C" type="citenumber">140</cms:entry><cms:entry id="N14E5F" part="chapter4" ref="N14E5F" type="table"/><cms:entry id="N14E87" part="chapter4" ref="N14E87" type="mm">317#101</cms:entry><cms:entry id="N14EA0" part="chapter4" ref="N14EA0" type="mm">199#97</cms:entry><cms:entry id="N14EB0" part="chapter4" ref="N14EB0" type="mm">127#57</cms:entry><cms:entry id="N14EB7" part="chapter4" ref="N14EB7" type="citenumber">141</cms:entry><cms:entry id="_Toc81288023" part="chapter4" ref="_Toc81288023" type="link"/><cms:entry id="N14EC2" part="chapter4" ref="N14EC2" type="block">4.8.4.2</cms:entry><cms:entry id="N14F64" part="chapter4" ref="N14F64" type="citenumber">142</cms:entry><cms:entry id="N14F83" part="chapter4" ref="N14F83" type="mm">575#275</cms:entry><cms:entry id="_Toc81123979" part="chapter4" ref="_Toc81123979" type="link"/><cms:entry id="_Toc77593040" part="chapter4" ref="_Toc77593040" type="link"/><cms:entry id="_Ref77572456" part="chapter4" ref="_Ref77572456" type="link"/><cms:entry id="_Ref76703146" part="chapter4" ref="_Ref76703146" type="link"/><cms:entry id="N14FAF" part="chapter4" ref="N14FAF" type="citenumber">143</cms:entry><cms:entry id="N14FD2" part="chapter4" ref="N14FD2" type="mm">565#295</cms:entry><cms:entry id="_Toc81123980" part="chapter4" ref="_Toc81123980" type="link"/><cms:entry id="_Toc77593041" part="chapter4" ref="_Toc77593041" type="link"/><cms:entry id="_Ref77572457" part="chapter4" ref="_Ref77572457" type="link"/><cms:entry id="_Ref76704167" part="chapter4" ref="_Ref76704167" type="link"/><cms:entry id="N14FEC" part="chapter4" ref="N14FEC" type="citenumber">144</cms:entry><cms:entry id="_Ref76735080" part="chapter4" ref="_Ref76735080" type="link"/><cms:entry id="_Toc81288024" part="chapter4" ref="_Toc81288024" type="link"/><cms:entry id="N14FFE" part="chapter4" ref="N14FFE" type="subsection">4.8.5</cms:entry><cms:entry id="N15006" part="chapter4" ref="N15006" type="block">4.8.5.1</cms:entry><cms:entry id="_Toc81288025" part="chapter4" ref="_Toc81288025" type="link"/><cms:entry id="N15016" part="chapter4" ref="N15016" type="citenumber">145</cms:entry><cms:entry id="N15070" part="chapter4" ref="N15070" type="mm">557#309</cms:entry><cms:entry id="_Toc81123981" part="chapter4" ref="_Toc81123981" type="link"/><cms:entry id="_Toc77593042" part="chapter4" ref="_Toc77593042" type="link"/><cms:entry id="_Ref77572459" part="chapter4" ref="_Ref77572459" type="link"/><cms:entry id="_Ref76710235" part="chapter4" ref="_Ref76710235" type="link"/><cms:entry id="N15087" part="chapter4" ref="N15087" type="citenumber">146</cms:entry><cms:entry id="_Toc81288026" part="chapter4" ref="_Toc81288026" type="link"/><cms:entry id="N1509A" part="chapter4" ref="N1509A" type="block">4.8.5.2</cms:entry><cms:entry id="N150FE" part="chapter4" ref="N150FE" type="citenumber">147</cms:entry><cms:entry id="N151BC" part="chapter4" ref="N151BC" type="citenumber">148</cms:entry><cms:entry id="N151BF" part="chapter4" ref="N151BF" type="mm">554#305</cms:entry><cms:entry id="_Toc81123982" part="chapter4" ref="_Toc81123982" type="link"/><cms:entry id="_Toc77593043" part="chapter4" ref="_Toc77593043" type="link"/><cms:entry id="_Ref76728444" part="chapter4" ref="_Ref76728444" type="link"/><cms:entry id="_Toc81288027" part="chapter4" ref="_Toc81288027" type="link"/><cms:entry id="N151E3" part="chapter4" ref="N151E3" type="subsection">4.8.6</cms:entry><cms:entry id="N15202" part="chapter4" ref="N15202" type="citenumber">149</cms:entry><cms:entry id="_Toc81288028" part="chapter4" ref="_Toc81288028" type="link"/><cms:entry id="N15212" part="chapter4" ref="N15212" type="section">4.9</cms:entry><cms:entry id="N1522F" part="chapter4" ref="N1522F" type="citenumber">150</cms:entry><cms:entry id="chapter5" part="chapter5" ref="chapter5" type="chapter">5</cms:entry><cms:entry id="_Ref76735623" part="chapter5" ref="_Ref76735623" type="link"/><cms:entry id="_Ref77319713" part="chapter5" ref="_Ref77319713" type="link"/><cms:entry id="_Ref79473554" part="chapter5" ref="_Ref79473554" type="link"/><cms:entry id="_Toc81288029" part="chapter5" ref="_Toc81288029" type="link"/><cms:entry id="N1524D" part="chapter5" ref="N1524D" type="citenumber">151</cms:entry><cms:entry id="N15264" part="chapter5" ref="N15264" type="citenumber">152</cms:entry><cms:entry id="_Ref77319244" part="chapter5" ref="_Ref77319244" type="link"/><cms:entry id="N15271" part="chapter5" ref="N15271" type="section">5.1</cms:entry><cms:entry id="_Toc81288030" part="chapter5" ref="_Toc81288030" type="link"/><cms:entry id="N15279" part="chapter5" ref="N15279" type="subsection">5.1.1</cms:entry><cms:entry id="_Toc81288031" part="chapter5" ref="_Toc81288031" type="link"/><cms:entry id="N1528A" part="chapter5" ref="N1528A" type="block">5.1.1.1</cms:entry><cms:entry id="_Toc81288032" part="chapter5" ref="_Toc81288032" type="link"/><cms:entry id="N15294" part="chapter5" ref="N15294" type="citenumber">153</cms:entry><cms:entry id="N152B3" part="chapter5" ref="N152B3" type="table"/><cms:entry id="N152D2" part="chapter5" ref="N152D2" type="mm">140#61</cms:entry><cms:entry id="N152E8" part="chapter5" ref="N152E8" type="citenumber">154</cms:entry><cms:entry id="_Toc81288033" part="chapter5" ref="_Toc81288033" type="link"/><cms:entry id="N152F6" part="chapter5" ref="N152F6" type="block">5.1.1.2</cms:entry><cms:entry id="N15315" part="chapter5" ref="N15315" type="table"/><cms:entry id="N15334" part="chapter5" ref="N15334" type="mm">141#56</cms:entry><cms:entry id="N1534A" part="chapter5" ref="N1534A" type="citenumber">155</cms:entry><cms:entry id="N1535F" part="chapter5" ref="N1535F" type="table"/><cms:entry id="N1537E" part="chapter5" ref="N1537E" type="mm">339#56</cms:entry><cms:entry id="_Toc81288034" part="chapter5" ref="_Toc81288034" type="link"/><cms:entry id="N153A6" part="chapter5" ref="N153A6" type="subsection">5.1.2</cms:entry><cms:entry id="N153AD" part="chapter5" ref="N153AD" type="citenumber">156</cms:entry><cms:entry id="N153C1" part="chapter5" ref="N153C1" type="mm">318#209</cms:entry><cms:entry id="_Toc81123983" part="chapter5" ref="_Toc81123983" type="link"/><cms:entry id="_Toc77593044" part="chapter5" ref="_Toc77593044" type="link"/><cms:entry id="_Ref76975834" part="chapter5" ref="_Ref76975834" type="link"/><cms:entry id="_Ref77572831" part="chapter5" ref="_Ref77572831" type="link"/><cms:entry id="_Toc81288035" part="chapter5" ref="_Toc81288035" type="link"/><cms:entry id="N153EF" part="chapter5" ref="N153EF" type="subsection">5.1.3</cms:entry><cms:entry id="N153F6" part="chapter5" ref="N153F6" type="citenumber">157</cms:entry><cms:entry id="N15410" part="chapter5" ref="N15410" type="mm">12#23</cms:entry><cms:entry id="N15414" part="chapter5" ref="N15414" type="mm">208#53</cms:entry><cms:entry id="N1546D" part="chapter5" ref="N1546D" type="citenumber">158</cms:entry><cms:entry id="N15470" part="chapter5" ref="N15470" type="table"/><cms:entry id="N154A1" part="chapter5" ref="N154A1" type="mm">87#47</cms:entry><cms:entry id="N154B9" part="chapter5" ref="N154B9" type="mm">175#55</cms:entry><cms:entry id="N1552D" part="chapter5" ref="N1552D" type="citenumber">159</cms:entry><cms:entry id="N155FF" part="chapter5" ref="N155FF" type="citenumber">160</cms:entry><cms:entry id="N15602" part="chapter5" ref="N15602" type="mm">582#324</cms:entry><cms:entry id="_Toc81123984" part="chapter5" ref="_Toc81123984" type="link"/><cms:entry id="_Toc77593045" part="chapter5" ref="_Toc77593045" type="link"/><cms:entry id="_Ref77572927" part="chapter5" ref="_Ref77572927" type="link"/><cms:entry id="_Ref76996890" part="chapter5" ref="_Ref76996890" type="link"/><cms:entry id="N15632" part="chapter5" ref="N15632" type="citenumber">161</cms:entry><cms:entry id="N15635" part="chapter5" ref="N15635" type="table"/><cms:entry id="N15664" part="chapter5" ref="N15664" type="mm">45#41</cms:entry><cms:entry id="N15671" part="chapter5" ref="N15671" type="mm">396#85</cms:entry><cms:entry id="_Toc81288036" part="chapter5" ref="_Toc81288036" type="link"/><cms:entry id="N1568A" part="chapter5" ref="N1568A" type="subsection">5.1.4</cms:entry><cms:entry id="N1569B" part="chapter5" ref="N1569B" type="citenumber">162</cms:entry><cms:entry id="N1569E" part="chapter5" ref="N1569E" type="mm">586#316</cms:entry><cms:entry id="_Toc81123985" part="chapter5" ref="_Toc81123985" type="link"/><cms:entry id="_Toc77593046" part="chapter5" ref="_Toc77593046" type="link"/><cms:entry id="_Ref76998806" part="chapter5" ref="_Ref76998806" type="link"/><cms:entry id="_Toc81288037" part="chapter5" ref="_Toc81288037" type="link"/><cms:entry id="N156C5" part="chapter5" ref="N156C5" type="section">5.2</cms:entry><cms:entry id="N156D7" part="chapter5" ref="N156D7" type="citenumber">163</cms:entry><cms:entry id="N156DA" part="chapter5" ref="N156DA" type="mm">218#197</cms:entry><cms:entry id="_Toc81123986" part="chapter5" ref="_Toc81123986" type="link"/><cms:entry id="_Toc77593047" part="chapter5" ref="_Toc77593047" type="link"/><cms:entry id="_Ref76835076" part="chapter5" ref="_Ref76835076" type="link"/><cms:entry id="N15702" part="chapter5" ref="N15702" type="subsection">5.2.1</cms:entry><cms:entry id="_Toc81288038" part="chapter5" ref="_Toc81288038" type="link"/><cms:entry id="N15717" part="chapter5" ref="N15717" type="citenumber">164</cms:entry><cms:entry id="_Toc81288039" part="chapter5" ref="_Toc81288039" type="link"/><cms:entry id="N1573C" part="chapter5" ref="N1573C" type="subsection">5.2.2</cms:entry><cms:entry id="_Ref76999133" part="chapter5" ref="_Ref76999133" type="link"/><cms:entry id="N15756" part="chapter5" ref="N15756" type="block">5.2.2.1</cms:entry><cms:entry id="_Toc81288040" part="chapter5" ref="_Toc81288040" type="link"/><cms:entry id="N15760" part="chapter5" ref="N15760" type="citenumber">165</cms:entry><cms:entry id="_Toc81288041" part="chapter5" ref="_Toc81288041" type="link"/><cms:entry id="N1578F" part="chapter5" ref="N1578F" type="block">5.2.2.2</cms:entry><cms:entry id="_Ref76543330" part="chapter5" ref="_Ref76543330" type="link"/><cms:entry id="_Ref79473568" part="chapter5" ref="_Ref79473568" type="link"/><cms:entry id="_Toc81288042" part="chapter5" ref="_Toc81288042" type="link"/><cms:entry id="chapter6" part="chapter6" ref="chapter6" type="chapter">6</cms:entry><cms:entry id="N157BB" part="chapter6" ref="N157BB" type="citenumber">166</cms:entry><cms:entry id="N157EB" part="chapter6" ref="N157EB" type="citenumber">167</cms:entry><cms:entry id="N157FB" part="chapter6" ref="N157FB" type="citenumber">168</cms:entry><cms:entry id="N1580B" part="chapter6" ref="N1580B" type="citenumber">169</cms:entry><cms:entry id="_Toc81288043" part="chapter6" ref="_Toc81288043" type="link"/><cms:entry ref="N1581B" type="back"/><cms:entry id="N1581D" part="N1581D" ref="N1581D" type="acknowledgement">Acknowledgements</cms:entry><cms:entry id="N15835" part="N15835" ref="N15835" type="abbreviation">Abbreviations</cms:entry><cms:entry id="N1583C" part="N15835" ref="N1583C" type="table"/><cms:entry id="_Ref70329806" part="N15835" ref="_Ref70329806" type="link"/><cms:entry id="N15AD3" part="N15AD3" ref="N15AD3" type="bibliography">References</cms:entry><cms:entry id="_Toc81288045" part="N15AD3" ref="_Toc81288045" type="link"/><cms:entry id="_bib130" part="N15AD3" ref="_bib130" type="citation"/><cms:entry id="_bib85" part="N15AD3" ref="_bib85" type="citation"/><cms:entry id="_bib108" part="N15AD3" ref="_bib108" type="citation"/><cms:entry id="_bib43" part="N15AD3" ref="_bib43" type="citation"/><cms:entry id="_bib146" part="N15AD3" ref="_bib146" type="citation"/><cms:entry id="_bib44" part="N15AD3" ref="_bib44" type="citation"/><cms:entry id="_bib149" part="N15AD3" ref="_bib149" type="citation"/><cms:entry id="_bib198" part="N15AD3" ref="_bib198" type="citation"/><cms:entry id="_bib122" part="N15AD3" ref="_bib122" type="citation"/><cms:entry id="_bib140" part="N15AD3" ref="_bib140" type="citation"/><cms:entry id="_bib195" part="N15AD3" ref="_bib195" type="citation"/><cms:entry id="_bib109" part="N15AD3" ref="_bib109" type="citation"/><cms:entry id="_bib83" part="N15AD3" ref="_bib83" type="citation"/><cms:entry id="_bib49" part="N15AD3" ref="_bib49" type="citation"/><cms:entry id="_bib50" part="N15AD3" ref="_bib50" type="citation"/><cms:entry id="_bib104" part="N15AD3" ref="_bib104" type="citation"/><cms:entry id="_bib48" part="N15AD3" ref="_bib48" type="citation"/><cms:entry id="_bib81" part="N15AD3" ref="_bib81" type="citation"/><cms:entry id="_bib82" part="N15AD3" ref="_bib82" type="citation"/><cms:entry id="_bib156" part="N15AD3" ref="_bib156" type="citation"/><cms:entry id="_bib51" part="N15AD3" ref="_bib51" type="citation"/><cms:entry id="_bib167" part="N15AD3" ref="_bib167" type="citation"/><cms:entry id="_bib128" part="N15AD3" ref="_bib128" type="citation"/><cms:entry id="_bib134" part="N15AD3" ref="_bib134" type="citation"/><cms:entry id="_bib138" part="N15AD3" ref="_bib138" type="citation"/><cms:entry id="_bib86" part="N15AD3" ref="_bib86" type="citation"/><cms:entry id="_bib52" part="N15AD3" ref="_bib52" type="citation"/><cms:entry id="_bib53" part="N15AD3" ref="_bib53" type="citation"/><cms:entry id="_bib168" part="N15AD3" ref="_bib168" type="citation"/><cms:entry id="_bib142" part="N15AD3" ref="_bib142" type="citation"/><cms:entry id="_bib139" part="N15AD3" ref="_bib139" type="citation"/><cms:entry id="_bib55" part="N15AD3" ref="_bib55" type="citation"/><cms:entry id="_bib145" part="N15AD3" ref="_bib145" type="citation"/><cms:entry id="_bib189" part="N15AD3" ref="_bib189" type="citation"/><cms:entry id="_bib125" part="N15AD3" ref="_bib125" type="citation"/><cms:entry id="_bib200" part="N15AD3" ref="_bib200" type="citation"/><cms:entry id="_bib201" part="N15AD3" ref="_bib201" type="citation"/><cms:entry id="_bib56" part="N15AD3" ref="_bib56" type="citation"/><cms:entry id="_bib88" part="N15AD3" ref="_bib88" type="citation"/><cms:entry id="_bib165" part="N15AD3" ref="_bib165" type="citation"/><cms:entry id="_bib141" part="N15AD3" ref="_bib141" type="citation"/><cms:entry id="_bib148" part="N15AD3" ref="_bib148" type="citation"/><cms:entry id="_bib190" part="N15AD3" ref="_bib190" type="citation"/><cms:entry id="_bib59" part="N15AD3" ref="_bib59" type="citation"/><cms:entry id="_bib172" part="N15AD3" ref="_bib172" type="citation"/><cms:entry id="_bib110" part="N15AD3" ref="_bib110" type="citation"/><cms:entry id="_bib111" part="N15AD3" ref="_bib111" type="citation"/><cms:entry id="_bib174" part="N15AD3" ref="_bib174" type="citation"/><cms:entry id="_bib175" part="N15AD3" ref="_bib175" type="citation"/><cms:entry id="_bib197" part="N15AD3" ref="_bib197" type="citation"/><cms:entry id="_bib161" part="N15AD3" ref="_bib161" type="citation"/><cms:entry id="_bib185" part="N15AD3" ref="_bib185" type="citation"/><cms:entry id="_bib144" part="N15AD3" ref="_bib144" type="citation"/><cms:entry id="_bib182" part="N15AD3" ref="_bib182" type="citation"/><cms:entry id="_bib98" part="N15AD3" ref="_bib98" type="citation"/><cms:entry id="_bib180" part="N15AD3" ref="_bib180" type="citation"/><cms:entry id="_bib89" part="N15AD3" ref="_bib89" type="citation"/><cms:entry id="_bib147" part="N15AD3" ref="_bib147" type="citation"/><cms:entry id="_bib96" part="N15AD3" ref="_bib96" type="citation"/><cms:entry id="_bib136" part="N15AD3" ref="_bib136" type="citation"/><cms:entry id="_bib179" part="N15AD3" ref="_bib179" type="citation"/><cms:entry id="_bib65" part="N15AD3" ref="_bib65" type="citation"/><cms:entry id="_bib107" part="N15AD3" ref="_bib107" type="citation"/><cms:entry id="_bib192" part="N15AD3" ref="_bib192" type="citation"/><cms:entry id="_bib124" part="N15AD3" ref="_bib124" type="citation"/><cms:entry id="_bib157" part="N15AD3" ref="_bib157" type="citation"/><cms:entry id="_bib95" part="N15AD3" ref="_bib95" type="citation"/><cms:entry id="_bib166" part="N15AD3" ref="_bib166" type="citation"/><cms:entry id="_bib177" part="N15AD3" ref="_bib177" type="citation"/><cms:entry id="_bib126" part="N15AD3" ref="_bib126" type="citation"/><cms:entry id="_bib137" part="N15AD3" ref="_bib137" type="citation"/><cms:entry id="_bib133" part="N15AD3" ref="_bib133" type="citation"/><cms:entry id="_bib143" part="N15AD3" ref="_bib143" type="citation"/><cms:entry id="_bib191" part="N15AD3" ref="_bib191" type="citation"/><cms:entry id="_bib184" part="N15AD3" ref="_bib184" type="citation"/><cms:entry id="_bib159" part="N15AD3" ref="_bib159" type="citation"/><cms:entry id="_bib112" part="N15AD3" ref="_bib112" type="citation"/><cms:entry id="_bib67" part="N15AD3" ref="_bib67" type="citation"/><cms:entry id="_bib158" part="N15AD3" ref="_bib158" type="citation"/><cms:entry id="_bib94" part="N15AD3" ref="_bib94" type="citation"/><cms:entry id="_bib68" part="N15AD3" ref="_bib68" type="citation"/><cms:entry id="_bib151" part="N15AD3" ref="_bib151" type="citation"/><cms:entry id="_bib129" part="N15AD3" ref="_bib129" type="citation"/><cms:entry id="_bib154" part="N15AD3" ref="_bib154" type="citation"/><cms:entry id="_bib186" part="N15AD3" ref="_bib186" type="citation"/><cms:entry id="_bib120" part="N15AD3" ref="_bib120" type="citation"/><cms:entry id="_bib155" part="N15AD3" ref="_bib155" type="citation"/><cms:entry id="_bib131" part="N15AD3" ref="_bib131" type="citation"/><cms:entry id="_bib132" part="N15AD3" ref="_bib132" type="citation"/><cms:entry id="_bib163" part="N15AD3" ref="_bib163" type="citation"/><cms:entry id="_bib193" part="N15AD3" ref="_bib193" type="citation"/><cms:entry id="_bib181" part="N15AD3" ref="_bib181" type="citation"/><cms:entry id="_bib164" part="N15AD3" ref="_bib164" type="citation"/><cms:entry id="_bib113" part="N15AD3" ref="_bib113" type="citation"/><cms:entry id="_bib127" part="N15AD3" ref="_bib127" type="citation"/><cms:entry id="_bib196" part="N15AD3" ref="_bib196" type="citation"/><cms:entry id="_bib72" part="N15AD3" ref="_bib72" type="citation"/><cms:entry id="_bib73" part="N15AD3" ref="_bib73" type="citation"/><cms:entry id="_bib188" part="N15AD3" ref="_bib188" type="citation"/><cms:entry id="_bib106" part="N15AD3" ref="_bib106" type="citation"/><cms:entry id="_bib135" part="N15AD3" ref="_bib135" type="citation"/><cms:entry id="_bib176" part="N15AD3" ref="_bib176" type="citation"/><cms:entry id="_bib91" part="N15AD3" ref="_bib91" type="citation"/><cms:entry id="_bib183" part="N15AD3" ref="_bib183" type="citation"/><cms:entry id="_bib75" part="N15AD3" ref="_bib75" type="citation"/><cms:entry id="_bib121" part="N15AD3" ref="_bib121" type="citation"/><cms:entry id="_bib102" part="N15AD3" ref="_bib102" type="citation"/><cms:entry id="_bib77" part="N15AD3" ref="_bib77" type="citation"/><cms:entry id="_bib78" part="N15AD3" ref="_bib78" type="citation"/><cms:entry id="_bib170" part="N15AD3" ref="_bib170" type="citation"/><cms:entry id="_bib169" part="N15AD3" ref="_bib169" type="citation"/><cms:entry id="_bib117" part="N15AD3" ref="_bib117" type="citation"/><cms:entry id="_bib203" part="N15AD3" ref="_bib203" type="citation"/><cms:entry id="_bib178" part="N15AD3" ref="_bib178" type="citation"/><cms:entry id="_bib187" part="N15AD3" ref="_bib187" type="citation"/><cms:entry id="_bib160" part="N15AD3" ref="_bib160" type="citation"/><cms:entry id="_bib92" part="N15AD3" ref="_bib92" type="citation"/><cms:entry id="_bib194" part="N15AD3" ref="_bib194" type="citation"/><cms:entry id="_bib116" part="N15AD3" ref="_bib116" type="citation"/><cms:entry id="_bib199" part="N15AD3" ref="_bib199" type="citation"/><cms:entry id="_bib202" part="N15AD3" ref="_bib202" type="citation"/><cms:entry id="_bib162" part="N15AD3" ref="_bib162" type="citation"/><cms:entry id="_bib93" part="N15AD3" ref="_bib93" type="citation"/><cms:entry id="_bib100" part="N15AD3" ref="_bib100" type="citation"/><cms:entry id="_bib79" part="N15AD3" ref="_bib79" type="citation"/><cms:entry id="_bib150" part="N15AD3" ref="_bib150" type="citation"/><cms:entry id="_bib153" part="N15AD3" ref="_bib153" type="citation"/><cms:entry id="N1664E" part="N1664E" ref="N1664E" type="appendix">Appendix A: Data tables</cms:entry><cms:entry id="N16650" part="N1664E" ref="N16650" type="head"/><cms:entry id="N16653" part="N1664E" ref="N16653" type="p"/><cms:entry id="_Toc81288046" part="N1664E" ref="_Toc81288046" type="link"/><cms:entry id="N16659" part="N1664E" ref="N16659" type="freehead"/><cms:entry id="N1665C" part="N1664E" ref="N1665C" type="p"/><cms:entry id="N16663" part="N1664E" ref="N16663" type="p"/><cms:entry id="N16665" part="N1664E" ref="N16665" type="table"/><cms:entry id="N1671D" part="N1664E" ref="N1671D" type="p"/><cms:entry id="_Toc81124018" part="N1664E" ref="_Toc81124018" type="link"/><cms:entry id="N16723" part="N1664E" ref="N16723" type="p"/><cms:entry id="N16725" part="N1664E" ref="N16725" type="table"/><cms:entry id="N1683D" part="N1664E" ref="N1683D" type="p"/><cms:entry id="_Toc81124019" part="N1664E" ref="_Toc81124019" type="link"/><cms:entry id="N16843" part="N1664E" ref="N16843" type="p"/><cms:entry id="N16845" part="N1664E" ref="N16845" type="table"/><cms:entry id="N1695D" part="N1664E" ref="N1695D" type="p"/><cms:entry id="_Toc81288047" part="N1664E" ref="_Toc81288047" type="link"/><cms:entry id="N16963" part="N1664E" ref="N16963" type="freehead"/><cms:entry id="N16966" part="N1664E" ref="N16966" type="p"/><cms:entry id="N16968" part="N1664E" ref="N16968" type="mm">879#475</cms:entry><cms:entry id="N16971" part="N1664E" ref="N16971" type="p"/><cms:entry id="N16973" part="N1664E" ref="N16973" type="mm">895#471</cms:entry><cms:entry id="N1697C" part="N1664E" ref="N1697C" type="p"/><cms:entry id="N1697E" part="N1664E" ref="N1697E" type="mm">875#457</cms:entry><cms:entry id="N1698A" part="N1664E" ref="N1698A" type="p"/><cms:entry id="N1698C" part="N1664E" ref="N1698C" type="mm">890#489</cms:entry><cms:entry id="N16995" part="N1664E" ref="N16995" type="p"/><cms:entry id="_Toc81288048" part="N1664E" ref="_Toc81288048" type="link"/><cms:entry id="N1699B" part="N1664E" ref="N1699B" type="freehead"/><cms:entry id="N1699E" part="N1664E" ref="N1699E" type="p"/><cms:entry id="N169A5" part="N1664E" ref="N169A5" type="p"/><cms:entry id="N169A7" part="N1664E" ref="N169A7" type="mm">880#497</cms:entry><cms:entry id="N169B0" part="N1664E" ref="N169B0" type="p"/><cms:entry id="_Toc81288049" part="N1664E" ref="_Toc81288049" type="link"/><cms:entry id="N169B7" part="N169B7" ref="N169B7" type="appendix">Appendix B: Java classes and methods</cms:entry><cms:entry id="N169B9" part="N169B7" ref="N169B9" type="head"/><cms:entry id="N169BC" part="N169B7" ref="N169BC" type="p"/><cms:entry id="_Toc81288050" part="N169B7" ref="_Toc81288050" type="link"/><cms:entry id="N169C2" part="N169B7" ref="N169C2" type="freehead"/><cms:entry id="N169C5" part="N169B7" ref="N169C5" type="p"/><cms:entry id="N169CC" part="N169B7" ref="N169CC" type="p"/><cms:entry id="_Toc81124020" part="N169B7" ref="_Toc81124020" type="link"/><cms:entry id="N169D2" part="N169B7" ref="N169D2" type="p"/><cms:entry id="N169D4" part="N169B7" ref="N169D4" type="table"/><cms:entry id="N16B8E" part="N169B7" ref="N16B8E" type="p"/><cms:entry id="_Toc81124021" part="N169B7" ref="_Toc81124021" type="link"/><cms:entry id="N16B94" part="N169B7" ref="N16B94" type="p"/><cms:entry id="N16B96" part="N169B7" ref="N16B96" type="table"/><cms:entry id="N16BEB" part="N169B7" ref="N16BEB" type="p"/><cms:entry id="_Toc81288051" part="N169B7" ref="_Toc81288051" type="link"/><cms:entry id="N16BF1" part="N169B7" ref="N16BF1" type="freehead"/><cms:entry id="N16BF4" part="N169B7" ref="N16BF4" type="p"/><cms:entry id="N16BFB" part="N169B7" ref="N16BFB" type="p"/><cms:entry id="_Toc81124022" part="N169B7" ref="_Toc81124022" type="link"/><cms:entry id="N16C01" part="N169B7" ref="N16C01" type="p"/><cms:entry id="N16C03" part="N169B7" ref="N16C03" type="table"/><cms:entry id="N16D15" part="N169B7" ref="N16D15" type="p"/><cms:entry id="_Toc81288052" part="N169B7" ref="_Toc81288052" type="link"/><cms:entry id="N16D1C" part="N16D1C" ref="N16D1C" type="appendix">Appendix C: AMPL Files</cms:entry><cms:entry id="N16D1E" part="N16D1C" ref="N16D1E" type="head"/><cms:entry id="N16D21" part="N16D1C" ref="N16D21" type="p"/><cms:entry id="N16D24" part="N16D1C" ref="N16D24" type="p"/><cms:entry id="N16D36" part="N16D1C" ref="N16D36" type="p"/><cms:entry id="N16D39" part="N16D1C" ref="N16D39" type="p"/><cms:entry id="_Toc81124023" part="N16D1C" ref="_Toc81124023" type="link"/><cms:entry id="N16D3F" part="N16D1C" ref="N16D3F" type="p"/><cms:entry id="N16D41" part="N16D1C" ref="N16D41" type="table"/><cms:entry id="N16D9D" part="N16D1C" ref="N16D9D" type="p"/><cms:entry id="_Toc81288053" part="N16D1C" ref="_Toc81288053" type="link"/><cms:entry id="N16DA3" part="N16D1C" ref="N16DA3" type="freehead"/><cms:entry id="N16DA6" part="N16D1C" ref="N16DA6" type="p"/><cms:entry id="N16DA8" part="N16D1C" ref="N16DA8" type="mm">586#732</cms:entry><cms:entry id="N16DB1" part="N16D1C" ref="N16DB1" type="p"/><cms:entry id="_Toc77593048" part="N16D1C" ref="_Toc77593048" type="link"/><cms:entry id="N16DB7" part="N16D1C" ref="N16DB7" type="p"/><cms:entry id="_Toc81123987" part="N16D1C" ref="_Toc81123987" type="link"/><cms:entry id="N16DBD" part="N16D1C" ref="N16DBD" type="p"/><cms:entry id="_Toc81288054" part="N16D1C" ref="_Toc81288054" type="link"/><cms:entry id="N16DC3" part="N16D1C" ref="N16DC3" type="freehead"/><cms:entry id="N16DC6" part="N16D1C" ref="N16DC6" type="p"/><cms:entry id="N16DC8" part="N16D1C" ref="N16DC8" type="mm">1#1</cms:entry><cms:entry id="N16DD1" part="N16D1C" ref="N16DD1" type="p"/><cms:entry id="N16DD3" part="N16D1C" ref="N16DD3" type="table"/><cms:entry id="N16EDA" part="N16D1C" ref="N16EDA" type="p"/><cms:entry id="_Toc77593049" part="N16D1C" ref="_Toc77593049" type="link"/><cms:entry id="N16EE0" part="N16D1C" ref="N16EE0" type="p"/><cms:entry id="_Toc81123988" part="N16D1C" ref="_Toc81123988" type="link"/><cms:entry id="N16EE6" part="N16D1C" ref="N16EE6" type="p"/><cms:entry id="_Toc81288055" part="N16D1C" ref="_Toc81288055" type="link"/><cms:entry id="N16EED" part="N16EED" ref="N16EED" type="appendix">Appendix D: Screenshots</cms:entry><cms:entry id="N16EEF" part="N16EED" ref="N16EEF" type="head"/><cms:entry id="N16EF2" part="N16EED" ref="N16EF2" type="p"/><cms:entry id="N16EF8" part="N16EED" ref="N16EF8" type="p"/><cms:entry id="_Toc81288056" part="N16EED" ref="_Toc81288056" type="link"/><cms:entry id="N16EFE" part="N16EED" ref="N16EFE" type="freehead"/><cms:entry id="N16F01" part="N16EED" ref="N16F01" type="p"/><cms:entry id="N16F03" part="N16EED" ref="N16F03" type="mm">457#601</cms:entry><cms:entry id="N16F0C" part="N16EED" ref="N16F0C" type="p"/><cms:entry id="_Toc77593050" part="N16EED" ref="_Toc77593050" type="link"/><cms:entry id="N16F12" part="N16EED" ref="N16F12" type="p"/><cms:entry id="_Toc81123989" part="N16EED" ref="_Toc81123989" type="link"/><cms:entry id="N16F18" part="N16EED" ref="N16F18" type="p"/><cms:entry id="_Toc81288057" part="N16EED" ref="_Toc81288057" type="link"/><cms:entry id="N16F1E" part="N16EED" ref="N16F1E" type="freehead"/><cms:entry id="N16F21" part="N16EED" ref="N16F21" type="p"/><cms:entry id="N16F28" part="N16EED" ref="N16F28" type="p"/><cms:entry id="N16F2A" part="N16EED" ref="N16F2A" type="mm">539#378</cms:entry><cms:entry id="N16F33" part="N16EED" ref="N16F33" type="p"/><cms:entry id="_Toc77593051" part="N16EED" ref="_Toc77593051" type="link"/><cms:entry id="N16F39" part="N16EED" ref="N16F39" type="p"/><cms:entry id="_Toc81123990" part="N16EED" ref="_Toc81123990" type="link"/><cms:entry id="N16F3F" part="N16EED" ref="N16F3F" type="p"/><cms:entry id="_Toc81288058" part="N16EED" ref="_Toc81288058" type="link"/><cms:entry id="N16F45" part="N16EED" ref="N16F45" type="freehead"/><cms:entry id="N16F48" part="N16EED" ref="N16F48" type="p"/><cms:entry id="N16F4F" part="N16EED" ref="N16F4F" type="p"/><cms:entry id="N16F51" part="N16EED" ref="N16F51" type="mm">539#386</cms:entry><cms:entry id="N16F5A" part="N16EED" ref="N16F5A" type="p"/><cms:entry id="_Toc77593052" part="N16EED" ref="_Toc77593052" type="link"/><cms:entry id="N16F60" part="N16EED" ref="N16F60" type="p"/><cms:entry id="_Toc81123991" part="N16EED" ref="_Toc81123991" type="link"/><cms:entry id="N16F66" part="N16EED" ref="N16F66" type="p"/><cms:entry id="_Toc81288059" part="N16EED" ref="_Toc81288059" type="link"/><cms:entry id="N16F6D" part="N16F6D" ref="N16F6D" type="appendix">Appendix E: Relational model for the 3-party case implementation</cms:entry><cms:entry id="N16F6F" part="N16F6D" ref="N16F6F" type="head"/><cms:entry id="N16F72" part="N16F6D" ref="N16F72" type="p"/><cms:entry id="N16F79" part="N16F6D" ref="N16F79" type="p"/><cms:entry id="_Toc77593053" part="N16F6D" ref="_Toc77593053" type="link"/><cms:entry id="N16F7F" part="N16F6D" ref="N16F7F" type="p"/><cms:entry id="_Toc81123992" part="N16F6D" ref="_Toc81123992" type="link"/><cms:entry id="N16F85" part="N16F6D" ref="N16F85" type="p"/><cms:entry id="N16F87" part="N16F6D" ref="N16F87" type="mm">585#389</cms:entry><cms:entry id="N16F90" part="N16F6D" ref="N16F90" type="p"/><cms:entry id="N16F94" part="N16F94" ref="N16F94" type="appendix">Empfangene Unterstützung und Hilfe durch Kollegen</cms:entry><cms:entry id="N16F96" part="N16F94" ref="N16F96" type="head"/><cms:entry id="N16F99" part="N16F94" ref="N16F99" type="p"/><cms:entry id="N16FBD" part="N16F94" ref="N16FBD" type="p"/><cms:entry id="N16FC0" part="N16F94" ref="N16FC0" type="p"/><cms:entry id="N16FC3" part="N16F94" ref="N16FC3" type="p"/><cms:entry id="N16FC7" part="N16FC7" ref="N16FC7" type="declaration">Eidesstattliche Erklärung</cms:entry><cms:entry part="chapter2" type=":current"/><cms:entry type=":lang">en</cms:entry><cms:entry id=":contents" part="front" ref=":contents" type=":contents">Table of contents</cms:entry><cms:entry type=":help"><url href="http://...">Help</url></cms:entry></cms:meta><cms:content><chapter id="chapter2" label="2">
         <head>A classification of privacy issues in service architectures</head>
         <p><citenumber helper="true" id="N102CE" start="9"/>
               <link id="_Ref79473503"/>
            </p>
         <p>
            <blockquote>
               <p>
                  <em>The human animal needs a freedom seldom mentioned, freedom from intrusion. He needs a little privacy.</em> <br/>(<link id="OLE_LINK8"/>Phyllis McGinley, American writer)</p>
            </blockquote>
         </p>
         <p><citenumber id="N102E6" start="10"/>
            <link id="_Ref73250133"/>
         </p>
         <section id="N102ED" label="2.1">
            <head>
               <link id="_Toc81287949"/>Definitions and terminology</head>
            <p>
               <link id="_Ref79910332"/>
            </p>
            <subsection id="N102FB" label="2.1.1">
               <head>
                  <link id="_Toc81287950"/>Web-based services</head>
               <p>A service that is provided via any kind of wired or mobile network is called <em>net-based service</em> [<link ref="_bib203">Tamm and Günther, 2004</link>]. When these services are provided using technologies recommended by the World Wide Web Consortium<footnote numbering="arabic" start="2">
                     <p> www.w3.org</p>
                  </footnote> (such as HTTP [<link ref="_bib199">W3C, 1997</link>]) and using the underlying transport/network protocol TCP/IP [<link ref="_bib200">DARPA, 1981</link>; <link ref="_bib201">DARPA, 1981</link>] , we speak of <em>web-based services</em>. Net-based services that do not follow these standards include mobile services and services that are based on proprietary technologies (such as internal company networks). Note that because of their relative novelty, no unambiguous definition has been established yet. For reasons of simplicity, we will from now on use the terms net-based and web-based services synonymously and denominate them as the latter.</p>
               <p>An important subtype of web-based services are <em>web services</em> who are defined as "software systems identified by uniform resource identifiers, whose public interfaces and bindings are defined and described using XML. Its definition can be discovered by other software systems. These systems may then interact with the web service in a manner prescribed by its definition, using XML based messages conveyed by Internet protocols" [<link ref="_bib202">W3C, 2004</link>]. These services do not require a graphical user interface and are mainly used to improve the communcation and interoperability between applications.</p>
               <p>
                  <citenumber id="N10330" start="11"/>Complementary to this technological definition, web-based services can also be classified following their business model. For example, an <em color="000000">Application Service Provider (ASP)</em> "deploys, hosts and manages access to a packaged application to multiple parties from a centrally managed facility. The applications are delivered over networks on a subscription basis. This delivery model speeds implementation, minimizes the expenses and risks incurred across the application life cycle, and overcomes the chronic shortage of qualified technical personnel available in-house" [<link ref="_bib126">IDC, 1999</link>]. Usually, the ASP charges a flat fee per user from its client. We will refer to this business model further in Section <link ref="_Ref79909648">3.1</link>.</p>
               <p>
                  <link id="_Toc81287951"/>
               </p>
            </subsection>
            <subsection id="N10347" label="2.1.2">
               <head>Privacy issues</head>
               <p>For the purposes of this thesis, we speak of a (web-based) service <em>S</em> when a service provider <em>SP</em> stores, modifies, processes, publishes or forwards some confidential input data <em>D</em> given by the data holder (see <link ref="_Ref70824659">Figure 2-1</link>). We assume that the service provider creates a service result <em>S</em>(<em>D</em>) that is either returned to the data holder (2-party case) or forwarded to an authorized third party (3-party case). In the 2-party-case, the data holder is also the service user, see the solid service line in <link ref="_Ref70824659">Figure 2-1</link>. In the 3-party-case, this is not necessarily the case, as an external third party is involved, as depicted by the dashed line in <link ref="_Ref70824659">Figure 2-1</link>.</p>
               <p>
                  <mm entity="ID_d3e6365" file="image004.gif" id="N1036C" label="483#80">
                     <caption>
                        <link id="_Toc81123950"/>
                        <link id="_Toc77593011"/>
                        <link id="_Ref70824659"/>Figure 2-1: Input data and provided service</caption>
                  </mm>
               </p>
               <p>
                  <citenumber id="N10380" start="12"/>The input data <em>D</em> can be delivered <em>reactively</em>, e.g. by explicitly specifying weight and blood pressure for an online health check. Or it can be delivered <em>non-reactively / passively</em>, e.g. when a physician forwards patient data to a health service institution for research purposes.</p>
               <p>Roles of the service provider include online stores (<url href="http://www.amazon.com/" type="URL">www.amazon.com</url>), online service providers (such as financial services, e.g. <url href="http://www.citibank.com/" type="URL">www.citibank.com</url>), data mining providers (e.g. <url href="http://www.datashaping.com/" type="URL">www.datashaping.com</url>) or regional health initiatives (e.g. <url href="http://www.prhi.org/" type="URL">www.prhi.org</url>).</p>
               <p>Exemplary roles of the third party include direct marketing companies, medical researchers, patients or yet another service provider.</p>
               <p>
                  <citenumber id="N103A9" start="13"/>Based on the data holder's trust level of trust towards the service provider and towards the third party, we can distinguish four different privacy constellations. <link ref="_Ref77481566">Table 2-1</link> illustrates this. For a detailed discussion of what influences trust in web-based services, see [<link ref="_bib143">Jarvenpaa, et al., 2000</link>]<footnote numbering="arabic" start="3">
                     <p> [Jarvenpaa et al., 2000] found that the reputation and the perceived size have a significant impact on the trust in internet stores</p>
                  </footnote>.</p>
               <p>
                  <link id="_Ref77481566"/>
               </p>
               <p>
                  <table frame="all" id="N103C5" orient="port" tocentry="1">
                     <caption>
                        <link id="_Toc81123993"/>Table 2-1: The four privacy constellations depending on the data holder's trust</caption>
                     <tgroup align="left" char="" charoff="50" cols="4">
                        <colspec colname="1" colnum="1"/>
                        <colspec colname="2" colnum="2"/>
                        <colspec colname="3" colnum="3"/>
                        <colspec colname="4" colnum="4"/>
                        <tbody valign="top">
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" nameend="4" namest="3" rotate="0" valign="top">
                                 <p>Trust in 3<sup>rd</sup> party</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Yes<br/>(or 3<sup>rd</sup> party not existent)</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>No</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="1" rotate="0" valign="top">
                                 <p>Trust in<br/>service<br/>provider</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Yes</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <strong>Uncritical</strong>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <strong>Transform / protect </strong>
                                    <strong>
                                       <em>S(D)</em>
                                    </strong>
                                 </p>
                                 <p>
                                    <strong>Chapter </strong><link ref="_Ref79475927"><strong>4</strong></link></p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>No</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <strong>Transform / protect </strong>
                                    <strong>
                                       <em>D</em>
                                    </strong>
                                 </p>
                                 <p>
                                    <strong>Chapter 3</strong>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <strong>Transform / protect </strong>
                                    <strong>
                                       <em>D</em>
                                    </strong>
                                    <strong> and </strong>
                                    <strong>
                                       <em>S(D)</em>
                                    </strong>
                                 </p>
                                 <p>
                                    <strong>Chapter </strong><link ref="_Ref77141190"><strong>4.1.4</strong></link></p>
                              </entry>
                           </row>
                        </tbody>
                     </tgroup>
                  </table>
               </p>
               <p>The straight-forward case is when trust exists both towards the service provider and towards the 3<sup>rd</sup> party. Privacy is not an issue.</p>
               <p>
                  <citenumber id="N104C8" start="14"/>When there is no third party or the third party can be trusted, the data holder only has to make sure that his confidential data <em>D</em> is protected against potential misuse at the service provider's site. This case usually applies for the use of online services that require the input of confidential data such as income data or personal health data, and is explained in Chapter <link ref="_Ref72151191">3</link>.</p>
               <p>Things become more difficult if an untrusted third party comes in. This may be the case in the sketched example of a regional health initiative that collects and analyzes primary care data (this is the service <em>S</em>) and distributes health reports to their community (the 3<sup>rd</sup> party that is not necessarily trusted). This case is addressed in Chapter <link ref="_Ref72438087">4</link>.</p>
               <p>The most delicate case occurs when neither the service provider nor the third party can be trusted. The opportunities to deliver useful service results in this case are very limited. Consider e.g. online voting [<link ref="_bib149">Asonov, et al., 2001</link>]. Confidential data (the vote) is passed to the service provider (the state or another official voting institution) who aggregates the votes and publishes the election result to the public (i.e., the 3<sup>rd</sup> party). A voter would want to keep his vote secret both towards the state and towards the public. We elaborate shortly on this case in Section <link ref="_Ref77141190">4.1.4</link>.</p>
               <p>
                  <link id="_Toc81287952"/>
               </p>
            </subsection>
         </section>
         <section id="N104F6" label="2.2">
            <head>2-party service architectures</head>
            <subsection id="N104FB" label="2.2.1">
               <head>
                  <link id="_Toc81287953"/>Basic idea</head>
               <p>
                  <citenumber id="N10505" start="15"/>The data holder uses a service that is offered online (<em>web-based service</em>) that requires him to send input data to the service provider. The result of the service is returned to the data holder who is the service user at the same time (cf. <link ref="_Ref67933555">Figure 2-2</link>). A simple example is the query for specific share values. The name of the share (e.g. 'MERQ' for Mercury Interactive Group) is the input datum <em>D</em>, the result of the service request <em>S(D)</em> is ($42.46 24-Mar-04 3:58pm). Besides this basic kind of database query, there are more complex services such as wage accounting or online health checks. This case is particularly characterized by the absence of a third party, i.e. the data holder is simultaneously the service user and only has to protect his confidential data from the service provider. We assume for this case that the privacy policy of the service provider explicitly rules out the forwarding of customer / user information to a third party.</p>
               <p>
                  <mm entity="ID_d3e7531" file="image005.gif" id="N10518" label="386#116">
                     <caption>
                        <link id="_Toc81123951"/>
                        <link id="_Toc77593012"/>
                        <link id="_Ref67933555"/>
                        <link id="_Ref67933540"/>Figure 2-2: Confidential data flow in 2-party services</caption>
                  </mm>
               </p>
               <p>Note that in this case too, both input datum <em>D</em> and service result <em>S(D)</em> have to be protected from an untrusted service provider. Yet we will show in Section <link ref="_Ref77186253">3.3</link> that a transformation of <em>D</em> is sufficient to protect both <em>D</em> and <em>S(D)</em>.</p>
               <p>
                  <link id="_Toc81287954"/>
               </p>
            </subsection>
            <subsection id="N1054A" label="2.2.2">
               <head>Instances in real-world information systems</head>
               <p>
                  <citenumber id="N10551" start="16"/>Although there are many application areas for the 2-party case, we will motivate our work with two important instances.</p>
               <p>The <em>single-user web-based service </em>refers to the well-known case of a single person using popular web-based services e.g. when searching for information (e.g. at <url href="http://www.google.com/" type="URL">www.google.com</url>), buying digital goods (e.g. at <url href="http://www.amazon.com/" type="URL">www.amazon.com</url>) or managing financial assets (e.g. at <url href="http://www.citibank.com/" type="URL">www.citibank.com</url>). A concerned user who is very hesitant with sharing confidential information with the service provider may ask the following questions.</p>
               <p>
                  <ul>
                     <li>
                        <p>Can we look for information without letting the search provider know exactly what we are looking for?</p>
                     </li>
                     <li>
                        <p>Can we buy a digital good without letting the online store know which music file or e-book we are interested in?</p>
                     </li>
                     <li>
                        <p>Can we use an online portfolio service without letting the financial service provider know the total amount of our assets?</p>
                     </li>
                  </ul>
               </p>
               <p>
                  <citenumber id="N10584" start="17"/>Although at least some of these tasks sound infeasible we will show in Chapter <link ref="_Ref72151191">3</link> that for a selected range of applications, we can indeed obtain a desired service result without sharing confidential input information with the service provider.</p>
               <p>Opposed to the single-user web-based service, the <em>outsourced web-based service</em> refers to an <em>application service provider</em> (<em>ASP</em>) who offers "software as a service" usually to an entire company. An ASP "deploys, hosts and manages access to a packaged application for its customers from a centrally managed facility" (see [<link ref="_bib126">IDC, 1999</link>] for a definition). Contracting an ASP promises its customers to reduce capital investment, to make IT costs more transparent, to facilitate the focus on core competencies and to provide faster access to high-end software applications [<link ref="_bib117">Tamm, 2003</link>]. However, this also means that an ASP always hosts the (potentially confidential) business data of the customer with the corresponding implications for data security and privacy. An extensive survey by [<link ref="_bib134">Carter, 2000</link>] shows that this innovative kind of software provision is severely inhibited by privacy concerns of ASP customers. We elaborate on these concerns in Section <link ref="_Ref74468842">3.2</link> and show how this conflict can be resolved for some particular applications.</p>
               <p>
                  <link id="_Toc81287955"/>
               </p>
            </subsection>
            <subsection id="N105AF" label="2.2.3">
               <head>Related work</head>
               <p>Database services and arithmetic operations are core components of web-based services. Several approaches have been created to address related privacy problems in <em>database service provider architectures</em>.</p>
               <block id="N105BA" label="2.2.3.1">
                  <head>
                     <link id="_Toc81287956"/>Private Information Retrieval</head>
                  <p>
                     <citenumber id="N105C4" start="18"/>One promising research direction is <em>Private Information Retrieval (PIR) </em>which was first presented by [<link ref="_bib52">Chor, et al., 1995</link>]. It allows clients to query a database server, revealing neither the query nor the result of the query to the server. The model is simpler than that of traditional relational databases [<link ref="_bib139">Codd, 1970</link>] because the query consists of an array index and the answer is the contents of the indexed array field. Yet it is powerful enough to implement many different applications such as file systems and dictionaries. If there is only one database server, the proven most efficient algorithm that preserves the secrecy of the query is for the user to download the entire database for each query. There are more efficient algorithms for several servers that do not cooperate in an attack. More recently, a practical method assuming a trusted physical device (a <em>secure coprocessor</em>, see [<link ref="_bib75">Smith and Weingart, 1999</link>])in the server host has been proposed by [<link ref="_bib44">Asonov and Freytag, 2002</link>]. This approach is almost optimal in resource overhead, and the assumption that the coprocessor on the server site is not compromised is arguably weaker than the assumption that several servers do not cooperate in an attack. PIR-algorithms can be used as a building block in privacy-preserving database outsourcing methods, see [<link ref="_bib96">Fischmann and Günther, 2003</link>].</p>
                  <p>
                     <link id="_Ref77248136"/>
                  </p>
                  <p>
                     <link id="_Toc81287957"/>
                  </p>
               </block>
               <block id="N105EF" label="2.2.3.2">
                  <head>Partitioning and encryption</head>
                  <p>[<link ref="_bib192">Hacigumus, et al., 2002</link>; <link ref="_bib124">Hacigumus, et al., 2002</link>] present an approach that allows relational database operations on encrypted data. Before encryption, the data is aggregated to partitions on the customer side to decrease the amount of information that the service provider receives. The consequence is that the client needs to do some post-processing, as the provider can compute only an approximation of the result which can also be error-prone. Unfortunately, it is only efficient on a subset of relational algebra. For instance, each range query condition of the form <em>A</em> &lt; <em>x</em> needs to be transformed into a disjunction of conditions matching all concrete values smaller than <em>x</em> before being encrypted. Also, as [<link ref="_bib96">Fischmann and Günther, 2003</link>] show, even with aggregation this scheme is not very secure.</p>
                  <p>[<link ref="_bib125">Damiani, et al., 2003</link>] take a different route along the same line of reasoning. Instead of aggregating the data, each plaintext attribute is properly encrypted to a unique ciphertext, and a method is proposed to compute exposure coefficients that tell the data holder how much information he is giving away. Furthermore, it is explained how <em>B-trees</em> [<link ref="_bib140">Bayer and McCreight, 1972</link>] can be encrypted to allow for more efficient range queries on encrypted tables. However, even encrypting the B-trees for retrieving ranges of records only helps improve performance with respect to the naive approach, but information on the attribute in question is still leaked. Each time all records are retrieved that satisfy <em>A</em> &lt; <em>x</em>, the service provider learns a set of ciphertexts that represent values of <em>A</em> that are smaller than <em>x</em>.</p>
                  <p>
                     <citenumber id="N10628" start="19"/>[<link ref="_bib121">Song, et al., 2000</link>] have proposed a family of schemes for encrypting a text corpus such that it can be searched without decryption. These methods are efficient and proven secure, and certainly an interesting building block for privacy-preserving application distribution.</p>
                  <p>As essential theoretical foundations we should mention <em>secure multi-party computation </em>[<link ref="_bib65">Goldreich, 1998</link>], a generalization of privacy-preserving data mining and <em>oblivious transfer</em> [<link ref="_bib120">Naor and Pinkas, 2001</link>], a more rigid category of protocols related to private information retrieval, although neither is the subject of this work.</p>
                  <p>
                     <link id="_Toc81287958"/>
                  </p>
               </block>
               <block id="N10648" label="2.2.3.3">
                  <head>Our contribution</head>
                  <p>We can see that the privacy-preserving use of arithmetic operations and database services have been elaborated in more or less disjoint research fields. However, we believe that both arithmetic and database operations are core components for almost every web-based service and should be analyzed and developed jointly.</p>
                  <p>
                     <citenumber id="N10652" start="20"/>In Chapter <link ref="_Ref72151191">3</link> we present a comprehensive analysis of what kind of services are feasible given the security requirements of the data holders. We explore how database and arithmetic operations can be usefully combined to offer securely outsourced services. Obviously, the extent of services that can be conducted on encrypted data is limited and not plentiful enough for arbitrary use. Our aim is to explore the trade-off between "not secure enough" and "not useful enough".</p>
                  <p>To motivate our work, we show how the confidential data of an ASP customer can be compromised. We propose a service architecture that hides plain data from the service provider and we carry out sample services within this framework. We evaluate our framework with regard to time and memory requirements and discuss practical implementation issues.</p>
                  <p>
                     <link id="_Toc81287959"/>
                  </p>
               </block>
            </subsection>
         </section>
         <section id="N10666" label="2.3">
            <head>3-party service architectures</head>
            <subsection id="N1066B" label="2.3.1">
               <head>
                  <link id="_Toc81287960"/>Basic idea</head>
               <p>In a 3-party service architecture, the service user is not necessarily the data holder. This is the case in the scenario we sketched in the introduction, where a regional health initiative (the service provider) collects and analyzes data from patients (the data holders) to distribute results to medical researchers or, of course, to the patients (the service users). <link ref="_Ref67933562">Figure 2-3</link> displays this.</p>
               <p>
                  <citenumber id="N1067C" start="21"/>
                  <mm entity="ID_d3e8707" file="image006.gif" id="N1067F" label="480#99">
                     <caption>
                        <link id="_Toc81123952"/>
                        <link id="_Toc77593013"/>
                        <link id="_Ref67933562"/>Figure 2-3: Confidential data flow in 3-party services</caption>
                  </mm>
               </p>
               <p>The main threat in this scenario is that from the published report (i.e. the service result), confidential information about individuals can be inferred. The problem of obtaining the confidential datum <em>D</em> from the publicly available service result <em>S(D)</em> is the <em>inference problem</em> well-known in the <em>statistical disclosure control (SDC)</em> literature (for comprehensive surveys on SDC, see [<link ref="_bib85">Adam and Wortman, 1989</link>; <link ref="_bib91">Shoshani, 1982</link>]).</p>
               <p>
                  <link id="_Toc81287961"/>
               </p>
            </subsection>
            <subsection id="N106AF" label="2.3.2">
               <head>Instances in real-world information systems</head>
               <p>We will now give two examples for the 3-party service case.</p>
               <p>
                  <citenumber id="N106B9" start="22"/>
                  <em>Census bureaus </em>such as the U.S. Bureau of Census (<url href="http://www.census.gov/" type="URL">www.census.gov</url>) collect data and provide statistics to the public in order to characterize regions socially and economically. The main threat for the data holders is the risk of being re-identified in the published statistic, thus divulging confidential information such as income or debt.</p>
               <p>
                  <em>Regional health initiatives </em>such as the Pittsburgh Regional Healthcare Initiative (PRHI, <url href="http://www.prhi.org/" type="URL">www.prhi.org</url>) collect, analyze and disseminate chronic disease data to patients and researchers. Data holders include pharmacies, physicians, health maintenance organizations (<em>HMOs</em>), laboratories and patients. Besides the re-identification threat for patients, the other parties also fear a breach of their privacy. An HMO for instance may fear that internal data ends up in the hands of a competitor and is (mis-)used in marketing campaigns. We will elaborate on this case extensively in Chapter <link ref="_Ref72438087">4</link>.</p>
               <p>
                  <link id="_Toc81287962"/>
               </p>
            </subsection>
            <subsection id="N106DE" label="2.3.3">
               <head>Related work</head>
               <block id="N106E3" label="2.3.3.1">
                  <head>
                     <link id="_Toc81287963"/>Data integration</head>
                  <p>
                     <em>Data integration</em> deals with the technical integration of heterogeneous data sources. It is necessary for instance, when different HMOs provide data about the same diagnostic test in different formats. [<link ref="_bib93">Wiederhold, 1993</link>] introduced the notion of a <em>mediator</em> between data holders and data providers to resolve semantic conflicts, and later added a security component to his basic model [<link ref="_bib100">Wiederhold,et al., 1996</link>]. [<link ref="_bib127">Rezgui, et al., 2002</link>] proposed a privacy mediator based on the screening of external database queries for sensitive attributes and their eventual removal from processed queries. Complementary to the mediator approach is the <em>data warehouse</em> approach [<link ref="_bib138">Chaudhuri and Dayal, 1997</link>; <link ref="_bib137">Inmon, 1996</link>], where data from the different sources is extracted, transformed and then loaded into a read-only database. Queries are then no longer run on the multiple databases via the mediator but directly on the data warehouse database. For reasons of simplicity, we will call the intermediary system "mediator" from now on because it best incorporates the idea of negotiating between data holders and service users.</p>
                  <p>
                     <link id="_Ref75230489"/>
                  </p>
                  <p>
                     <link id="_Toc81287964"/>
                  </p>
               </block>
               <block id="N10718" label="2.3.3.2">
                  <head>Statistical disclosure control</head>
                  <p>
                     <citenumber id="N1071F" start="23"/>
                     <em>Statistical disclosure control</em>
                     <em>(SDC)</em> is concerned with providing access to high-quality statistics for business / policy purposes (i.e., the service <em>S</em>)while at the same time protecting the confidentiality of the individual data providers (i.e. the data holders, for instance survey or Census respondents). SDC distinguishes two principle approaches, <em>query restriction </em>and <em>data perturbation</em>. The query restriction family includes the following.</p>
                  <p>
                     <em>Query set size control</em> [<link ref="_bib89">Fellegi, 1972</link>] works by setting lower and upper bounds for the size of the query answer set based on the properties of the database and on the preferences fixed by the database administrator. If the number of returned records does not lie within these bounds, the information request would have to be rejected and the query answer is denied. As queries that are issued sequentially by one user often have a large number of entities in common, an improvement is the restriction of these entities to a maximum number, see [<link ref="_bib141">Dobkin, et al., 1979</link>]. Although popular, this method is not robust enough as a stand-alone solution, see [<link ref="_bib56">Denning, 1982</link>]. </p>
                  <p>
                     <em>Auditing </em>involves keeping up-to-date logs of all queries made by each user and constantly checking for possible disclosures whenever a new query is issued. One major drawback of this method is that it requires huge amounts of storage and CPU time to keep these logs updated. A well-known implementation of such an audit system is <em>Audit Expert</em> by [<link ref="_bib86">Chin and Özsoyoglu, 1982</link>]. It uses binary matrices to indicate whether or not a record was involved in a query.</p>
                  <p>
                     <citenumber id="N10753" start="24"/>
                     <em>Cell suppression</em> [<link ref="_bib55">Cox, 1980</link>] is an important method for categorical databases when information is published in tabular form. Census Bureaus often make use of tabular data and publish counts of individuals based on different categories. One of the main privacy objectives is to avoid answers of a small size. For example, if a snooper knows somebody's residence, age and employer, he can issue a query for (ZIP=10178, Age= 57, Employer= 'ABC'). If the answer is one entity, the snooper could go on and query for (ZIP= 10178, Age= 57, Employer= 'ABC', Diagnosis= 'Depression'). If the answer is one again, the database is compromised and the person with the diagnosis identified. The cells must be suppressed. A common criterion to decide whether or not to suppress a cell is the <em>N-k rule</em> where a cell is suppressed if the top <em>N</em> respondents contribute at least k% of the cell total. <em>N </em>and <em>k </em>are parameters that are fixed by the database administrator, i.e. the Census Bureau. In the exemplary case of <em>N</em>= 2 and <em>k</em>= 10%, a cell which indicates aggregated income ($10M) of 100 individuals would have to be suppressed if the top two earners&#8217; aggregate income exceeded $1M.</p>
                  <p>In the query restriction approach, either exact data is delivered from the original database or the query is denied. An alternative is to perturb the original values such that confidential, individual data become useless for a snooper while the statistical properties of the attribute are preserved. The manipulated data is stored in a second database and is then freely accessible for the users.</p>
                  <p>
                     <em>Data swapping</em> [<link ref="_bib56">Denning, 1982</link>] is the process of exchanging attribute values (like income) within a list of data holders such that no assignments from individuals to their income can be made anymore. However, the arithmetic average and the standard deviation of the attribute income stay the same. </p>
                  <p>
                     <citenumber id="N1077F" start="25"/>
                     <em>Noise addition </em>for numerical attributes [<link ref="_bib92">Traub, et al., 1984</link>] means adding a disturbing term to each value: <em>Y</em>
                     <em>
                        <sub>k</sub>
                     </em>
                     <em>= X</em>
                     <em>
                        <sub>k</sub>
                     </em>
                     <em>+e</em>
                     <em>
                        <sub>k</sub>
                     </em>, where <em>X</em>
                     <em>
                        <sub>k</sub>
                     </em> is the original value and <em>e</em>
                     <em>
                        <sub>k</sub>
                     </em> adheres to a given probability distribution with mean zero. As for every value <em>X</em>
                     <em>
                        <sub>k</sub>
                     </em>, the perturbation <em>e</em>
                     <em>
                        <sub>k</sub>
                     </em> is fixed; therefore conducting multiple queries does not refine the snooper's search for confidential single values.</p>
                  <p>A hybrid approach are <em>random-sample queries</em> [<link ref="_bib88">Denning, 1980</link>] where a sample is drawn from the query set in such a way that each entity of the complete set is included in the sample with probability <em>P</em>. If, for example, the sample of a COUNT query has <em>n</em> entities, then the size of the not perturbed query set can be estimated as <em>n/P</em>. If <em>P</em> is large, there should be a set-size restriction to avoid small query sets where all entities are included.</p>
                  <p>Another prominent approach to rule out re-identification in public databases is <em>k-anonymity</em> [<link ref="_bib78">Sweeney, 2001</link>; <link ref="_bib170">Sweeney, 2002</link>; <link ref="_bib169">Sweeney, 2002</link>]. This is an anonymization procedure after which each individual cannot be distinguished from another <em>(k-1)</em> individuals in the database. Thus every set of attribute values appears at least <em>k</em> times. As <em>k</em> increases, so too does the anonymity in the database.</p>
                  <p>
                     <link id="_Toc81287965"/>
                  </p>
               </block>
               <block id="N10801" label="2.3.3.3">
                  <head>Privacy-preserving data mining</head>
                  <p>
                     <citenumber id="N10808" start="26"/>
                     <em>Data Mining</em>, the science of efficiently discovering valuable, non-obvious information from large databases, may well be misused to intrude upon the privacy of organizations and individuals [<link ref="_bib142">Clifton and Marks, 1996</link>]. One research direction is the use of cryptographic protocols to calculate aggregates from several contributors without divulging individual information [<link ref="_bib167">Canny, 2002</link>; <link ref="_bib128">Canny, 2002</link>; <link ref="_bib168">Clifton, 2001</link>; <link ref="_bib129">Lindell and Pinkas, 2000</link>; <link ref="_bib116">Vaidya and Clifton, 2002</link>].</p>
                  <p>[<link ref="_bib108">Agrawal and Srikant, 2000</link>] present a new method for privacy-preserving data mining. Based on a database of perturbed values, they are able to reconstruct the original value distribution. Confidential information of individuals is not compromised.</p>
                  <p>
                     <link id="_Toc81287966"/>
                  </p>
               </block>
               <block id="N10835" label="2.3.3.4">
                  <head>Our contribution</head>
                  <p>We propose a new class of privacy mediators that go beyond the state of the art with regard to the privacy protection methods applied to the final service result <em>S(D)</em>. We propose extending the common query-rewriting approach by developing and integrating new methods of disclosure control. Our proposals for preventing inferences are not limited to mediator-based approaches and are applicable in the context of data warehousing and statistical databases as well, see Section <link ref="_Ref77225211">4.1.3</link>.</p>
                  <p>
                     <citenumber id="N10846" start="27"/>To motivate our work, we use a real-world example that shows how a snooping HMO is able to determine narrow bounds on confidential information of its competitors by analyzing the aggregate data published by the mediator. We propose a specific "audit and aggregate" methodology that helps detect and prevent this specific kind of disclosure. Furthermore, we evaluate our method within a framework that measures the trade-off between decreasing risk of privacy breaches on behalf of the data provider and the loss of information for the legitimate service user.</p>
                  <p>
                     <link id="_Toc81287967"/>
                  </p>
               </block>
            </subsection>
         </section>
         <section id="N10853" label="2.4">
            <head>A classification of typical services</head>
            <subsection id="N10858" label="2.4.1">
               <head>
                  <link id="_Toc81287968"/>Reactive vs. non-reactive data provision</head>
               <p>After distinguishing between the two-party and the three-party case in the preceding sections, we will now introduce another dimension that is important in the privacy context. Users of web-based services can provide data either <em>reactively</em> to the service provider or <em>non-reactively / passively</em> (see e.g. [<link ref="_bib48">Boyens, et al., 2002</link>]).</p>
               <p>Reactive data provision means that data holders explicitly provide their personal data (e.g. for their health data in an online health check). They actively fill in web forms or web questionnaires and submit the information to the service provider.</p>
               <p>
                  <citenumber id="N10872" start="28"/>Non-reactive or passive data provision means that data holders do not explicitly provide personal data but generate it automatically e.g. through their behavior. The best-known case for this is the tracking of web-shop customers with the help of cookies, a file stored on the user's hard disk that identifies the customer each time he visits a web site. For a more detailed description of cookies and their role in privacy protection see [<link ref="_bib144">EPIC, 2004</link>] or <url href="http://www.cookiecentral.com/" type="URL">www.cookiecentral.com</url>.</p>
               <p>For the case of Internet services, [<link ref="_bib178">Teltzrow and Kobsa, 2004</link>] distinguish between "user data" and "usage data", where user data refers to demographic data, user skills and knowledge, user interests and plans whereas usage data refers link selections, viewing behavior and purchase actions. Usually, online service users are much less aware of their passive data provision because it is often triggered by their web browser settings. For an overview of reactive and passive data provision, see <link ref="_Ref77481592">Table 2-2</link>.</p>
               <p>
                  <link id="_Ref77481592"/>
               </p>
               <p>
                  <table frame="all" id="N10892" orient="port" tocentry="1">
                     <caption>
                        <link id="_Toc81123994"/>Table 2-2: Data provision in different services (means of data provision in parenthesis)</caption>
                     <tgroup align="left" char="" charoff="50" cols="4">
                        <colspec colname="1" colnum="1"/>
                        <colspec colname="2" colnum="2"/>
                        <colspec colname="3" colnum="3"/>
                        <colspec colname="4" colnum="4"/>
                        <tbody valign="top">
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" nameend="4" namest="3" rotate="0" valign="top">
                                 <p>Data provision</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p/>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Reactive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Passive</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="1" rotate="0" valign="top">
                                 <p>Service</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>2-party</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Online health check<br/>Financial portfolio service<br/>ASP / ERP services<br/>(<strong>
                                       <em>Web forms</em>
                                    </strong>)</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Personalization services<br/> for shopping and travel (<strong>
                                       <em>Cookies</em>
                                    </strong>)</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>3-party</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Census<br/>(Questionnaires)</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Chronic disease reports<br/>(<strong>
                                       <em>Primary care data</em>
                                    </strong>)</p>
                              </entry>
                           </row>
                        </tbody>
                     </tgroup>
                  </table>
               </p>
               <p>
                  <citenumber id="N10962" start="29"/>Allowing the employment of cookies does not only yield privacy compromises. It also yields benefits in the form of personalized services. These services can include customized finance pages or news collections, customized recommendations or advertisements based on past purchase behavior, customized pricing, express transactions or tailored email alerts. In online book stores for instance, these personalized services include recommendations to recently published books of interest. The recommendations are based on clicking behavior and on preceding book or CD purchases. Unfortunately, many online stores do not offer an option to (de-)activate the tracking of the click and purchase history and thereby prevent the user from easily trading off his own privacy concerns with the potential benefit from an extended service [<link ref="_bib184">Kobsa, 2001</link>].</p>
               <p>
                  <link id="_Ref75141718"/>
               </p>
               <p>
                  <link id="_Toc81287969"/>
               </p>
            </subsection>
            <subsection id="N10977" label="2.4.2">
               <head>Sample services</head>
               <p>In <link ref="_Ref77664871">Table 2-3</link> and <link ref="_Ref77481690">Table 2-4</link> we give a short and, of course, incomplete list of examples of services with their respective fit into the dimensions number of parties and reactive vs. passive data provision. For each service, we name examples of sensitive data that is typically required as input data, and we name some major threats that these data may be subject to.</p>
               <p>
                  <link id="_Ref77664871"/>
               </p>
               <p>
                  <table frame="all" id="N1098F" orient="port" tocentry="1">
                     <caption>
                        <link id="_Toc81123995"/>Table 2-3: Typical services in 2-party architectures</caption>
                     <tgroup align="left" char="" charoff="50" cols="5">
                        <colspec colname="1" colnum="1"/>
                        <colspec colname="2" colnum="2"/>
                        <colspec colname="3" colnum="3"/>
                        <colspec colname="4" colnum="4"/>
                        <colspec colname="5" colnum="5"/>
                        <tbody valign="top">
                           <row>
                              <entry morerows="0" nameend="5" namest="1" rotate="0" valign="top">
                                 <p>
                                    <strong>2-party services</strong>
                                 </p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Service</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Sample service provider</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Data provision</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Sensitive data d<sub>i</sub>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Major threats / criticality</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Health check</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <url href="http://www.skolamed.de/" type="URL">www.skolamed.de</url>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>reactive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>age<br/>weight<br/>blood pressure<br/>cholesterol</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Forwarding of personal health information to 3<sup>rd</sup> parties</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Online store</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <url href="http://www.amazon.com/" type="URL">www.amazon.com</url>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>passive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>hobbies<br/>interests<br/>shopping behavior</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>"Profiling" of customers, tracking via cookies</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>ASP service<br/>Wage accounting</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <url href="http://www.internetworking.com/" type="URL"/>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>reactive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>birth date<br/>income<br/>illnesses<br/>absence<br/>overtime</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Disclosure of personal / corporate secrets (product launch dates)</p>
                              </entry>
                           </row>
                        </tbody>
                     </tgroup>
                  </table>
               </p>
               <p>
                  <link id="_Ref77481690"/>
               </p>
               <p>
                  <citenumber id="N10ABC" start="30"/>
                  <table frame="all" id="N10ABF" orient="port" tocentry="1">
                     <caption>
                        <link id="_Toc81123996"/>Table 2-4: Typical services in 3-party architectures</caption>
                     <tgroup align="left" char="" charoff="50" cols="5">
                        <colspec colname="1" colnum="1"/>
                        <colspec colname="2" colnum="2"/>
                        <colspec colname="3" colnum="3"/>
                        <colspec colname="4" colnum="4"/>
                        <colspec colname="5" colnum="5"/>
                        <tbody valign="top">
                           <row>
                              <entry morerows="0" nameend="5" namest="1" rotate="0" valign="top">
                                 <p>3 -party services</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Service</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Sample service provider</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Data provision</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Sensitive data d<sub>i</sub>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Major threats / criticality</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Census</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <url href="http://www.census.gov/" type="URL">www.census.gov/</url>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>reactive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>name<br/>address<br/>age<br/>profession<br/>religion</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Re-identification of individuals, disclosure of e.g. income</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Online voting</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <url href="http://www.internetworking.com/" type="URL"/>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>reactive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>election vote</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Disclosure of the confidential vote either to the state or to fellow citizens</p>
                              </entry>
                           </row>
                           <row>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Health reports</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>
                                    <url href="http://www.phc4.org/" type="URL">www.phc4.org</url>
                                 </p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>passive</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>address<br/>diagnosis<br/>blood test results, eye exam results, lipid profiles</p>
                              </entry>
                              <entry morerows="0" rotate="0" valign="top">
                                 <p>Re-identification of individuals / disclosure of e.g. confidential test values</p>
                              </entry>
                           </row>
                        </tbody>
                     </tgroup>
                  </table>
               </p>
               <p>
                  <link id="_Toc81287970"/>
               </p>
            </subsection>
         </section>
         <section id="N10BDE" label="2.5">
            <head>What this thesis is not about</head>
            <p>There are several areas of research that are outside the scope of this thesis. The most important one is technical data security. We assume that adequate measures for communication confidentiality (such as the Secure Socket Layer <em>SSL </em>[<link ref="_bib131">Netscape, 1996</link>]) and access control (such as Kerberos [<link ref="_bib132">Neumann and Ts'o, 1994</link>] or X.509 [<link ref="_bib133">ITU, 2000</link>]) are in place. For a detailed discussion of cryptography and network security, see [<link ref="_bib135">Schneier, 1996</link>; <link ref="_bib77">Stallings, 1999</link>].</p>
            <p>Another important area is the extension of privacy legislation. For purposes of this work we assume the validity of the current privacy laws and recommendations in place, in particular [<link ref="_bib95">HIPAA, 1996</link>; <link ref="_bib194">USPA, 1974</link>] for the USA and [<link ref="_bib98">EU, 1995</link>; <link ref="_bib180">EU, 2002</link>] for the European Union.</p>
            <p>
               <citenumber id="N10C12" start="31"/>A very important area of investigation of an individual's attitude towards privacy [<link ref="_bib130">Ackerman,et al., 1999</link>] and the behavior that is derived from this attitude (which often differs significantly from the attitude declared beforehand, see [<link ref="_bib102">Spiekermann,et al., 2001</link>]). Our work focuses on technical measures that are not affected by individual privacy behavior.</p>
            <p>
               <link id="_Toc81287971"/>
            </p>
         </section>
      </chapter></cms:content></cms:document></cms:container>