Privacy: The Achilles Heel of Pervasive Computing?

Privacy: The Achilles Heel of Pervasive Computing?
复制标题

隐私:普适计算的致命弱点?

DOI:
10.1109/mprv.2003.10002
复制
发表时间:
2003
影响因子:
1.6
通讯作者:
M. Satyanarayanan
M. Satyanarayanan
中科院分区:
计算机科学4区
文献类型:
--
作者:
M. Satyanarayanan

文献摘要

被引文献

相似文献

无处不在的计算愿景的核心是一个内在的矛盾。一方面,计算环境必须高度了解用户,以符合他或她的需求和愿望,而无需显式交互-几乎是阅读用户的想法。另一方面,一个真正无处不在的系统将包含大量的用户、物理区域和服务提供商。在如此大的规模下,各方之间的完美信任是一个无法实现的理想。因此,信任边界代表了普适计算结构中的不连续接缝。隐私和安全已经是分布式系统中的棘手问题。各种各样的问题困扰着我们,从垃圾邮件到身份盗窃。普适计算提供了许多新的攻击途径。诸如位置跟踪、智能空间和使用替代等机制需要持续监控用户操作。随着用户变得更加依赖普适计算系统,系统变得更加了解该用户的移动、行为模式和习惯。如果系统要做到主动和自调优,利用这些信息是至关重要的。然而,对用户的这种详细了解的积累,对那些肆无忌惮的人来说是一个诱人的目标。除非我们能够开发出令人满意的解决方案,否则隐私严重丧失的可能性可能会阻止用户依赖普适计算系统。建立信任是一个双向的问题。正如用户必须确信其计算环境的可信性一样,基础设施在响应请求之前必须确信用户的身份和授权级别。很难以最低限度的侵扰方式建立这种相互信任。随着普适计算从实验室走向真实的世界,这将成为一个关键需求。如果没有一种可靠而准确的方法来建立身份和授权,服务提供商就不会有动力部署普及计算所需的基础设施和服务。与此同时,频繁地要求用户提供密码或其他真实性证明将破坏普适计算的本质也就是说,它消失在用户潜意识中的能力。开发平衡这些不同要求的技术至关重要。我能想到至少三种方法来开始寻找这样的技术。朝着正确方向迈出的一小步是让用户更加了解他们当前的隐私暴露水平。就像汽车的仪表板不断提供速度,燃油水平和外部温度等信息一样,手持...
t the heart of the ubiquitous computing vision lies an inherent contradiction. On the one hand, a computing environment must be highly knowledgeable about a user to conform to his or her needs and desires without explicit interaction—almost reading the user's mind. On the other hand, a system that is truly ubiquitous will encompass numerous users, physical regions, and service providers. At such large scale, perfect trust among all parties is an unattainable ideal. Trust boundaries thus represent seams of discontinuity in the fabric of pervasive computing. Privacy and security are already thorny problems in distributed systems. A variety of problems plague us, ranging from spam to identity theft. Pervasive computing provides many new avenues of attack. Mechanisms such as location tracking, smart spaces, and the use of sur-rogates require continuous monitoring of user actions. As a user becomes more dependent on a pervasive computing system , the system becomes more knowledgeable about that user's movements, behavior patterns, and habits. Exploiting this information is critical if the system is to be proactive and self-tuning. Yet this same build-up of detailed knowledge about a user represents a tempting target for the unscrupulous. Unless we can develop satisfactory solutions, the potential for serious loss of privacy might deter users from relying on a pervasive computing system. Establishing trust is a two-way problem. Just as users must be confident of their computing environment's trustwor-thiness, the infrastructure must be confident of a user's identity and authorization level before responding to requests. It is difficult to establish this mutual trust in a manner that is minimally intrusive. This will become a key requirement as pervasive computing moves from the lab to the real world. Without a reliable and accurate way to establish identity and authorization, service providers won't have incentives for deploying the infrastructures and services necessary for pervasive computing. At the same time, frequent demands for passwords or other proofs of authenticity from the user will destroy the essence of pervasive computing—namely, its ability to disappear into the user's subconscious. It is critical to develop techniques that balance these divergent requirements. I can think of at least three ways to begin the search for such techniques. A small step in the right direction would be to make users more aware of their current privacy exposure level. Just as a car's dashboard continuously provides information such as speed, fuel level, and outside temperatures, a hand-held …