FlowFence: Practical Data Protection for Emerging IoT Application Frameworks

FlowFence: Practical Data Protection for Emerging IoT Application Frameworks
复制标题

DOI:
--
复制
发表时间:
2016-08
期刊:
影响因子:
3.7
通讯作者:
Earlence Fernandes;Justin Paupore;Amir Rahmati;Daniel Simionato;M. Conti;Atul Prakash
Earlence Fernandes;Justin Paupore;Amir Rahmati;Daniel Simionato;M. Conti;Atul Prakash
中科院分区:
综合性期刊3区
文献类型:
--
作者:
Earlence Fernandes;Justin Paupore;Amir Rahmati;Daniel Simionato;M. Conti;Atul Prakash

文献摘要

被引文献

相似文献

新兴的物联网编程框架使人们能够构建基于智能家居和可穿戴设备产生的敏感数据进行计算的应用程序。然而,这些框架只支持对敏感数据进行基于权限的访问控制,这在控制应用程序获得访问权限后如何使用数据方面无效。为了解决这一限制,我们提出了FlowFence,这是一个系统,它要求敏感数据的使用者声明他们想要的数据流模式,并以较低的开销强制执行,同时阻止所有其他未声明的流。FlowFence通过在应用程序结构中显式嵌入数据流和相关控制流来实现这一点。开发人员使用流屏障支持将他们的应用程序分成两个组件:(1)一组对沙箱中的敏感数据进行操作的隔离模块,以及(2)不对敏感数据进行操作但通过通过受污染跟踪的不透明句柄将隔离模块链接在一起来协调执行的代码-对只能在沙箱中解除引用的数据的引用。我们研究了三个现有的物联网框架,以得出Flow-Fence的关键功能目标,然后移植了三个现有的物联网应用程序。使用FlowFence保护这些应用程序会导致源代码的平均大小从232行增加到332行。在移植的应用程序上的性能结果表明,FlowFence是实用的:基于人脸识别的门控应用程序在识别人脸和打开门锁时花费了4.9%的延迟开销。
Emerging IoT programming frameworks enable building apps that compute on sensitive data produced by smart homes and wearables. However, these frameworks only support permission-based access control on sensitive data, which is ineffective at controlling how apps use data once they gain access. To address this limitation, we present FlowFence, a system that requires consumers of sensitive data to declare their intended data flow patterns, which it enforces with low overhead, while blocking all other undeclared flows. FlowFence achieves this by explicitly embedding data flows and the related control flows within app structure. Developers use Flow-Fence support to split their apps into two components: (1) A set of Quarantined Modules that operate on sensitive data in sandboxes, and (2) Code that does not operate on sensitive data but orchestrates execution by chaining Quarantined Modules together via taint-tracked opaque handles-references to data that can only be dereferenced inside sandboxes. We studied three existing IoT frameworks to derive key functionality goals for Flow-Fence, and we then ported three existing IoT apps. Securing these apps using FlowFence resulted in an average increase in size from 232 lines to 332 lines of source code. Performance results on ported apps indicate that FlowFence is practical: A face-recognition based door-controller app incurred a 4.9% latency overhead to recognize a face and unlock a door.