Trusted and privacy-preserving sensor data onloading

Trusted and privacy-preserving sensor data onloading
复制标题

DOI:
10.1016/j.comcom.2023.04.027
复制
发表时间:
2023-05
期刊:
Comput. Commun.
影响因子:
--
通讯作者:
Yin Liu;Breno Dantas Cruz;E. Tilevich
Yin Liu;Breno Dantas Cruz;E. Tilevich
中科院分区:
其他
文献类型:
--
作者:
Yin Liu;Breno Dantas Cruz;E. Tilevich

文献摘要

相似文献

个性化他们的服务(例如,广告、导航、医疗保健),移动的应用程序收集传感器数据。通常,他们将收集的传感器数据上传到云,云返回个性化移动的服务所需的推断用户配置文件。然而,隐私问题和网络连接/拥塞问题可能使基于云的处理不适用。如果不同的应用程序收集相同类型的传感器数据,应用程序提供商可以通过组合其数据收集来进行协作,以推断个性化所需的设备上的用户配置文件。虽然主要的移动的平台提供了设备上的数据共享机制,但这些直接的数据交换没有提供隐私保护。作为直接数据共享的替代方案,我们提出了差异化的私有化传感器数据加载应用程序提供商的协作。通过我们的方法,应用程序提供商可以安全地使用共享的传感器数据来个性化他们的移动的服务。我们将我们的方法实现为充当可信中介的中间件。中间件聚合各个应用程序提供的传感器数据,这些应用程序对组合数据集执行统计查询。此外,中间件的自适应隐私保护方案(1)计算并向查询结果添加所需的噪声量,以便平衡效用和隐私;(2)引入信任数据理论,以便从组合集合中检测并移除虚假数据;(3)奖励积极贡献的应用程序提供商,以便激励数据贡献;(4)集成可信执行环境(TEE),以确保所有数据处理的安全。我们的评估表明,在保护数据隐私的同时个性化移动的服务是可行和有用的:查询的执行时间在10 ms以内;满足参与者不同的隐私/效用需求;有效地检测不可信的数据;个性化移动的服务,并保护应用程序提供商和用户的数据隐私。
To personalize their services (e.g., advertisement, navigation, healthcare), mobile apps collect sensor data. Typically, they upload the collected sensor data to the cloud, which returns the inferred user profiles required to personalize mobile services. However, privacy concerns and network connectivity/congestion issues can render cloud-based processing inapplicable. If different apps collect the same type of sensor data, app providers can collaborate by combining their data collections to infer on-device the user profiles required for personalization. Although major mobile platforms provide on-device data sharing mechanisms, these direct data exchanges provide no privacy protection. As an alternative to direct data sharing, we presentdifferentially privatized sensor data onloadingfor app providers’ collaboration. With our approach, app providers can safely collaborate by using shared sensor data to personalize their mobile services. We realize our approach as a middleware that acts as a trusted intermediary. The middleware aggregates the sensor data contributed by individual apps, which execute statistical queries against the combined datasets. Furthermore, the middleware’s adaptive privacy-preserving scheme (1) computes and adds the required amount of noise to the query results so as to balance utility and privacy; (2) introduces a Trust-Data Theory so as to detect and remove spurious data from the combined collections; (3) rewards active contributing app providers so as to incentivize data contribution; (4) integrates a Trusted Execution Environment (TEE) so as to secure all data processing. Our evaluation shows that it is feasible and useful to personalize mobile services while protecting data privacy: queries’ execution time is within 10 ms; participants’ dissimilar privacy/utility requirements are satisfied; untrustworthy data are effectively detected; mobile services are personalized, and data privacy of both app providers and users are preserved.1