CAREER: User-Centered Multiparty Access Control for Collective Content Management
职业:以用户为中心的多方访问控制,用于集体内容管理
基本信息
- 批准号:1453080
- 负责人:
- 金额:$ 55万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2015
- 资助国家:美国
- 起止时间:2015-08-01 至 2023-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This CAREER project will develop models and techniques to facilitate controlled information sharing of users' data in domains where the data is associated with and co-managed by multiple users, such as bio-repositories, remote teleworking, and social computing. Specific research objectives are: 1) Building on the PI's prior work, develop a foundational model describing access control in terms of the decision making process of a single content manager or content owner, laying the groundwork for the second objective; 2) Develop new models to support synchronous, asynchronous, and combined joint specification of access control policies for shared content for multiple users and site administrators, and 3) Apply those solution concepts to two specific applications, group work and a biobank, and conduct user studies to test goodness of fit, suitability and feasibility of the resulting access setting mechanisms.This project takes an innovative user-centric approach to ensure that the rigorous models developed result in enforceable mechanisms that can be used on a variety of existing platforms in and multiple domains. To accomplish this, the proposed work draws from multiple disciplines, including access control, game theory for security and privacy, and decision support systems. For example, an individual in a group photo may prefer not to have the photo shared even though others do, but would accept it being shared only with friends; a social network operator wants to maximize use of the system through sharing information while keeping users happy so they remain active. The preferences thus constitute a multi-objective optimization problem. We use a game-theoretic approach to modeling this problem, allowing negotiation to determine access settings. This research will provide users with the ability to express preferred access control settings for shared multi-owned data, jointly influencing with that input the final access settings, while taking into account organizational constraints and existing laws.Further, we leverage the economic concept of first-mover advantage to create models suitable in scenarios where synchronous coordination among users is not practical. In particular, the models start with extensions and applications of Stackelberg games, and account for the unique constraints occurring with security decisions and uncertainty due to human-bounded rationality. As part of this task, we also develop a method for domain administrators to determine what set of access policy options should be offered to users. Through this administrator-centered model, we enable administrators to identify the set of options that satisfy users' predicted access control decisions and meet their administrator's own internal objectives. We also study hybrid models that build on strengths of synchronous and asynchronous multi-party approaches. The models and mechanisms developed will apply to a wide range of domains, including social computing, remote collaborative content co-authoring, personalized medicine, and genetic data sharing.The integrated education plan will focus on curriculum enhancement and expanded undergraduate research experiences. We establish a graduate visiting program to give students experience with different disciplines, recognizing the multidisciplinary challenges in information security. The ultimate goal is to produce diverse graduates with the multidisciplinary skills required to design and evaluate IT security solutions.
这个职业项目将开发模型和技术,以促进在数据与多个用户关联并由多个用户共同管理的域中进行受控的用户数据信息共享,例如生物存储库、远程远程工作和社会计算。具体的研究目标是:1)在PI以前工作的基础上,根据单个内容管理者或内容所有者的决策过程,开发一个描述访问控制的基本模型,为第二个目标奠定基础;2)开发新的模型以支持针对多个用户和站点管理员的共享内容的访问控制策略的同步、异步和组合联合规范,以及3)将这些解决方案概念应用于两个具体的应用,即小组工作和生物库,并进行用户研究以测试由此产生的访问设置机制的适合性、适宜性和可行性。该项目采用创新的以用户为中心的方法,以确保所开发的严格模型产生可执行的机制,该机制可在多个领域的各种现有平台上使用。为了实现这一目标,拟议的工作借鉴了多个学科,包括访问控制、安全和隐私的博弈论以及决策支持系统。例如,集体照片中的一个人可能不愿意分享照片,即使其他人这样做了,但会接受只与朋友分享;社交网络运营商希望通过分享信息来最大限度地利用系统,同时保持用户的快乐,以便他们保持活跃。因此,偏好构成了一个多目标优化问题。我们使用博弈论方法对这个问题进行建模,允许协商来确定访问设置。这项研究将为用户提供表达共享多个拥有的数据的首选访问控制设置的能力,在考虑组织约束和现有法律的同时,与该输入共同影响最终访问设置。此外,我们利用先发优势的经济学概念来创建适合于用户之间同步协调的场景的模型。特别是,这些模型从Stackelberg博弈的扩展和应用开始,并解释了由于人类有限理性而产生的安全决策和不确定性的独特约束。作为这项任务的一部分,我们还为域管理员开发了一种方法,以确定应该向用户提供哪组访问策略选项。通过这种以管理员为中心的模型,我们使管理员能够确定满足用户预测的访问控制决策并满足管理员自己的内部目标的选项集。我们还研究了建立在同步和异步多方方法优势基础上的混合模型。开发的模型和机制将应用于广泛的领域,包括社会计算、远程协同内容共同创作、个性化医学和基因数据共享。综合教育计划将侧重于课程改进和扩大本科生研究经验。我们建立了一个研究生访问计划,为学生提供不同学科的经验,认识到信息安全方面的多学科挑战。最终目标是培养具有设计和评估IT安全解决方案所需的多学科技能的多样化毕业生。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Dongwon Lee其他文献
Compensation as a Tool: Addressing Gender Inequality Among Women IT Professionals
以薪酬为工具:解决女性 IT 专业人员中的性别不平等问题
- DOI:
- 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Yao Zhao;Dongwon Lee;Sunil Mithas - 通讯作者:
Sunil Mithas
A Multi-Level Theory Approach to Understanding Price Rigidity in Internet Retailing
理解互联网零售价格刚性的多层次理论方法
- DOI:
10.17705/1jais.00230 - 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
R. Kauffman;Dongwon Lee - 通讯作者:
Dongwon Lee
Pragmatic XML Access Control Using Off-the-Shelf RDBMS
使用现成的 RDBMS 进行实用的 XML 访问控制
- DOI:
10.1007/978-3-540-74835-9_5 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Bo Luo;Dongwon Lee;Peng Liu - 通讯作者:
Peng Liu
Understanding emotions in SNS images from posters' perspectives
从海报的角度理解 SNS 图像中的情感
- DOI:
10.1145/3341105.3373923 - 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
Junho Song;Kyungsik Han;Dongwon Lee;Sang - 通讯作者:
Sang
Impedance Characterization and Modeling of Subcellular to Micro-sized Electrodes with Varying Materials and PEDOT:PSS Coating for Bioelectrical Interfaces
用于生物电接口的具有不同材料和 PEDOT:PSS 涂层的亚细胞至微米电极的阻抗表征和建模
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:4.7
- 作者:
Adam Y. Wang;Doohwan Jung;Dongwon Lee;Hua Wang - 通讯作者:
Hua Wang
Dongwon Lee的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Dongwon Lee', 18)}}的其他基金
Collaborative Research: CISE-MSI: RCBP-RF: SaTC: Building Research Capacity in AI Based Anomaly Detection in Cybersecurity
合作研究:CISE-MSI:RCBP-RF:SaTC:网络安全中基于人工智能的异常检测的研究能力建设
- 批准号:
2131144 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
EAGER: SaTC-EDU: A Framework for Developing Attributable Cybersecurity Case Studies
EAGER:SaTC-EDU:开发可归因网络安全案例研究的框架
- 批准号:
2114824 - 财政年份:2021
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Privacy protection of Vehicles location in Spatial Crowdsourcing under realistic adversarial models
合作研究:SaTC:核心:小:现实对抗模型下空间众包中车辆位置的隐私保护
- 批准号:
2029976 - 财政年份:2021
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
REU Site: Machine Learning in Cybersecurity
REU 网站:网络安全中的机器学习
- 批准号:
1950491 - 财政年份:2020
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Vertical Search Engine and Graph Homomorphism for Enhancing the Cybersecurity Workforce
用于增强网络安全劳动力的垂直搜索引擎和图同态
- 批准号:
1934782 - 财政年份:2019
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: Precision Learning: Data-Driven Experimentation of Learning Theories using Internet-of-Videos
协作研究:精准学习:使用视频互联网进行数据驱动的学习理论实验
- 批准号:
1940076 - 财政年份:2019
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Developing and Evaluating Fraud Informatics Curriculum among Institutions in the Appalachian Region
开发和评估阿巴拉契亚地区机构之间的欺诈信息学课程
- 批准号:
1820609 - 财政年份:2018
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Penn State's CyberCorps; Scholarship for Service Program
宾夕法尼亚州立大学的 CyberCorps;
- 批准号:
1663343 - 财政年份:2017
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
EAGER: Training Computers and Humans to Detect Misinformation by Combining Computational and Theoretical Analysis
EAGER:通过结合计算和理论分析来训练计算机和人类检测错误信息
- 批准号:
1742702 - 财政年份:2017
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
SBE TWC: Small: Collaborative: Privacy Protection in Social Networks: Bridging the Gap Between User Perception and Privacy Enforcement
SBE TWC:小型:协作:社交网络中的隐私保护:弥合用户感知和隐私执行之间的差距
- 批准号:
1422215 - 财政年份:2014
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
相似海外基金
CRII: SHF: An Automated and User-centered Framework for Reproducing System-level Concurrency Bugs by Analyzing Bug Reports
CRII:SHF:通过分析错误报告来重现系统级并发错误的自动化且以用户为中心的框架
- 批准号:
2348277 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
SCC-PG: Towards A User-Centered and Equity-Aware Micromobility Sharing Co-Design Network to Interact with A Distressed Municipality
SCC-PG:建立一个以用户为中心、具有公平意识的微交通共享协同设计网络,与陷入困境的城市进行互动
- 批准号:
2303575 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Supporting Unhealthy Substance use care Through a whole person Approach and user centered INtegration into primary care (SUSTAIN)
支持不健康药物使用护理 通过全人方法和以用户为中心 融入初级护理(持续)
- 批准号:
10827292 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Elevating Community Voices by Developing a User-centered Approach to Enable Self-testing and Remote Data Collection among Under-represented Populations (Project Elevate)
通过开发以用户为中心的方法来提高社区的声音,以在代表性不足的人群中进行自我测试和远程数据收集(Project Elevate)
- 批准号:
10820757 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
User-Centered Design of a Proactive RF-Based Wearable Bladder Monitor for Toilet Training of Children with ASD/IDD
以用户为中心的主动式射频可穿戴膀胱监测器设计,用于 ASD/IDD 儿童如厕训练
- 批准号:
10742670 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
User-centered approach to the development of a parent toolkit to improve willingness to participate in pediatric clinical research
以用户为中心的方法开发家长工具包,以提高参与儿科临床研究的意愿
- 批准号:
10663456 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Applying User-centered Design and Implementation Science to Enhance Prehabilitation for Frail Older Adults Undergoing Lung Cancer Surgery
应用以用户为中心的设计和实施科学来加强接受肺癌手术的体弱老年人的康复
- 批准号:
10727197 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Advancing Equity in Early Childhood Developmental Screening Through Item Response Theory and User-Centered Design
通过项目反应理论和以用户为中心的设计促进幼儿发展筛查的公平性
- 批准号:
10808542 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
TASK ORDER TITLED "NHLBI USER-CENTERED RESEARCH, ANALYTICS AND DIGITAL COMMUNICATION SOFTWARE TOOLS MANAGEMENT"
任务订单标题为“NHLBI 以用户为中心的研究、分析和数字通信软件工具管理”
- 批准号:
10974172 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Partnering with Canadian Youth and Families to Co-design a User-centered Digital Health Tool to Manage the Effects of the COVID-19 Pandemic and Future Public Health Crises on Youth Mental Wellbeing
与加拿大青少年和家庭合作,共同设计一个以用户为中心的数字健康工具,以管理 COVID-19 大流行和未来公共卫生危机对青少年心理健康的影响
- 批准号:
468879 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Operating Grants