Privacy at the Link Layer

Privacy at the Link Layer
复制标题

链路层的隐私

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Ian Brown
Ian Brown
中科院分区:
--
文献类型:
--
作者:
Ian Brown

文献摘要

被引文献

相似文献

现在,许多人至少携带一台设备,该设备通常使用全球唯一的链路层标识符来定位并连接到本地网络。此类链路层或 MAC 地址经常在各种情况下以无线方式发出。这种对唯一且有效的个人标识符的不加区别的广播允许通过个人设备对个人进行不受监管的大规模跟踪,无论这些设备是否使用了特定服务。这些地址通常在设备的生命周期内保持不变,从而创建持久的终身跟踪功能。这些界面标识符现在越来越多地被许多组织监控、整理和分析,没有有意义的监管,出于各种目的,没有得到个人的明确许可或通知。在堆栈的较高级别,在移动设备上,端点标识符通常是短暂的,并且在连接到不同网络时会发生变化。为了在 IP 级别提供隐私或不可链接性,我们做出了一些努力:私有寻址、IPv6 地址的隐私扩展以及网络地址转换器。然而,一旦设备试图连接到网络,有许多行为可能会进一步削弱或损害设备及其所有者的隐私,一个值得注意的例子是积极使用网络附件检测 (DNA) 服务。虽然在更高的层面上,用户在访问社交媒体或云服务等通信服务方面有一定程度的选择,但链路层标识对普通用户来说不太明显和难以访问。鉴于链路层标识符很容易被滥用,建议终端系统尽可能不使用不可变的唯一标识符来连接到网络。我们认为,在许多情况下,链路层唯一全局标识符的存在很大程度上是不合理的,并且日益成为严重潜在危害的根源。因此,终端系统应该能够在链路层使用临时地址,以防止设备和个人的长期跟踪和关联。我们认为,在许多现有网络的限制下,部署此类系统应该是可能且实用的。
Many people now carry at least one device that routinely uses globally-unique link layer identifiers to locate and attach to local networks. Such link layer, or MAC, addresses are frequently emitted wirelessly in a variety of scenarios. This indiscriminate broadcast of a unique and effectively personal identifier allows for unregulated and broad-scale tracking of individuals via their personal devices, whether or not those devices have made use of a particular service or not. These addresses typically remain unchanged for the lifetime of a device, creating a persistent, lifelong tracking capability. These interface identifiers are now increasingly being monitored, collated, and analysed by a number of organisations, without meaningful regulation, for a variety of purposes without explicit permission from, or notification to, the individual. At higher levels in the stack, on mobile devices, endpoint identifiers are generally ephemeral and change when attaching to different networks. Several efforts have been made to provide privacy or unlinkability at the IP level: private addressing, privacy extensions for IPv6 addresses, and Network Addresses Translators. Once a device seeks to connect to a network, however, there are a number of behaviours that can further weaken or compromise the privacy of devices and their owners, a notable example being the aggressive use of Detection of Network Attachment (DNA) services. Whilst, at a higher level, there is some level of user choice in access to communications services such as social media or cloud services, link layer identification is far less visible and accessible to normal users. Given the ease with which link layer identifiers can be abused it would be advisable for for end systems to connect to networks without utilising an immutable, unique identifier where possible. We contend that, in many cases, the existence of unique global identifiers at the link layer is largely unjustified, and is increasingly a source of serious potential harm. End systems should therefore have the capability to employ an ephemeral address at the link layer to prevent long-term tracking and correlation of devices and individuals. We consider that the deployment of such systems should be both possible and practical within the constraints of many existing networks.