On Optimizing the Trade-off between Privacy and Utility in Data Provenance