Secure Task Recommendation: Balancing Utility and Privacy in Crowdsourcing via Proxy Cryptography
Secure Task Recommendation in Crowdsourcing
This paper proposes a secure task recommendation scheme for crowdsourcing platforms using proxy re-encryption. It introduces two sub-schemes, Secure Matching (SM) and Encryption-Decryption (ED), to enable keyword-based task assignment and content delivery while preserving the privacy of both task requesters and workers in a multi-user environment.
TL;DR
Crowdsourcing platforms like Amazon MTurk or Waze face a critical dilemma: effective task recommendation requires access to sensitive worker interests and task details, but exposing this data to a "curious" broker creates privacy risks. This paper introduces a dual-structured cryptographic framework that enables keyword-based matching and secure content delivery. By splitting keys between users and the broker, the system achieves high efficiency (matching 10,000 users in under 60ms) without ever revealing plaintext data to the platform.
Background & Positioning
In the evolution of crowdsourcing, we have moved from "Pull" models (workers manually searching for tasks) to "Push" models (automatic recommendation). While Push models improve efficiency, they centralize sensitive data. This work identifies a gap in existing literature: while Searchable Encryption (SE) exists, it is typically built for one-to-one scenarios. This paper positions itself as a multi-user, privacy-preserving solution that addresses both task specification matching and task content decryption.
The Core Problem: The Trusted Broker Fallacy
Most crowdsourcing systems assume the broker is fully trusted. However, real-world platforms are "honest-but-curious"—they follow protocols but attempt to harvest data.
- Worker Privacy: Interests (e.g., "medical translation," "adult content tagging") reveal personal expertise and bias.
- Task Privacy: Proprietary task data or sensitive company information must remain confidential.
- Scalability: Standard Public Key Encryption (PKE) fails here because a requester cannot manage thousands of worker public keys dynamically.
Methodology: The Dual Sub-Scheme Architecture
The authors propose a system comprising four entities: Task Requesters, Workers, a Broker, and a Trusted Key Management Server (KMS). The innovation lies in splitting the secret key into a user-side key and a broker-side key .
1. Secure Matching (SM)
The goal is to match a task keyword with a worker interest .
- The Insight: Both parties encrypt their keywords using their respective . When these reach the broker, the broker uses its to transform them into a comparable format.
- The Matching Logic: The broker searches the index by testing a mathematical equality based on the hash of the re-encrypted tokens.
2. Encryption and Decryption (ED)
Once a match is found, the worker needs the full task content .
- Architecture: It uses an ElGamal-based proxy re-encryption. The requester encrypts once. The broker "partially decrypts" it using the requester's and then "re-encrypts" it (essentially shifting the encryption layer) so that only the targeted worker can finish the decryption with their .

Experiments & Performance
The scheme was evaluated on a synthetic dataset using a 160-bit prime for security.
- Latency: The time cost for the broker to match a task specification against a searchable index increases linearly with the number of keys. In a setup with 10,000 worker keys, matching took only 59ms, which is negligible for real-time applications.
- Throughput: Encryption of task content reached a throughput of 0.072 seconds/KB, making it feasible for standard text-based or small-file crowdsourcing tasks.
- Revocation: Unlike traditional systems where revocation might require re-encrypting all data, this scheme handles it by simply deleting the associated with the user at the broker level.

Critical Insight: Beyond Basic Encryption
The primary strength of this paper is its Inductive Bias toward the multi-user environment. By using Proxy Re-encryption, the authors solve the "n-to-n" key distribution problem. The requester doesn't need to know who the workers are at the time of encryption; the broker acts as a blind router that facilitates the handshake.
Limitations
- Collusion Resistance: The authors acknowledge that if a user colludes with the broker, the master secret key can be recovered. While they argue reputation protects against this, in a decentralized or adversarial setting, this remains a significant vulnerability.
- Single Keyword: The current evaluation focuses on single-keyword matching. In professional crowdsourcing, complex multi-attribute matching (skills, location, price, rating) is required, which adds significant overhead.
Conclusion
This paper provides a robust framework for bringing data sovereignty to the crowdsourcing industry. By moving away from the "all-or-nothing" trust model of current platforms, it paves the way for secure, automated labor markets where privacy is guaranteed by mathematics rather than policy.
