CRII: SaTC: Multi-User Authentication and Access Control in the Internet of Things
CRII:SaTC:物联网中的多用户身份验证和访问控制
基本信息
- 批准号:1756011
- 负责人:
- 金额:$ 19.1万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-07-01 至 2020-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Computing is transitioning from single-user devices, such as laptops and phones, to the Internet of Things (IoT), in which numerous users interact with a particular device, such as an Amazon Echo or Internet-connected door lock. The desired level of access to particular capabilities, such as ordering items using a shared voice assistant, likely differs across members of a household (e.g., children and parents). Widely deployed devices and the existing research literature lack mechanisms for specifying who should be able to perform which actions with which household Internet-connected devices. Complicating matters, the users of a given device often have complex social relationships to each other. Our goal is to develop techniques and interfaces that enable non-technical users to specify who should be able to perform what actions using which Internet-connected devices in the home, as well as to verify the identity of the person trying to perform those actions. Misconfigured devices can open the home to attackers, yet may also disenfranchise members of the household. Our approach to authentication and authorization directly impacts security for consumers of an array of household IoT devices. A core objective of this proposal is also to train first-time student researchers in a tangible domain that is ideal for a first research experience.On a technical level, the work comprises three phases. The first phase aims to characterize the access-control policies users will want to express for multi-user IoT devices, focusing on the unique characteristics and capabilities of the IoT. To do so, we will conduct an online user study that elicits users' desired access-control policies for the home IoT, that is, who should be allowed to use particular capabilities, as well as in what circumstances. Having identified the primitives necessary for users to express their desired access-control policies for the home IoT, the second phase will systematize authentication mechanisms and authorization interfaces appropriate for the constraints of these home IoT environments, proposing mechanisms commensurate with the risks of unauthorized use of different capabilities. In the third phase of the research, we will implement our proposed mechanisms and evaluate them through an in-situ field study, allowing us to gauge how effectively these interfaces and mechanisms minimize both unauthorized access and incorrect access denials in the realistic setting of users' homes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
计算正在从笔记本电脑和手机等单用户设备过渡到物联网(IoT),在物联网中,许多用户与特定设备交互,如Amazon Echo或联网门锁。对特定功能的期望访问级别,例如使用共享语音助手订购物品,可能在家庭成员(例如,孩子和父母)之间有所不同。广泛部署的设备和现有的研究文献缺乏指定谁应该能够对哪些家庭连接互联网的设备执行哪些操作的机制。让事情变得复杂的是,特定设备的用户彼此之间往往有复杂的社会关系。我们的目标是开发技术和界面,使非技术用户能够指定谁应该能够使用家庭中哪些连接互联网的设备执行哪些操作,并验证试图执行这些操作的人的身份。错误配置的设备可能会向攻击者敞开大门,但也可能剥夺家庭成员的权利。我们的身份验证和授权方法直接影响一系列家用物联网设备消费者的安全。这项提议的一个核心目标也是在一个有形的领域培训第一批学生研究人员,这是第一次研究经验的理想选择。在技术层面上,这项工作包括三个阶段。第一阶段旨在描述用户希望为多用户物联网设备表达的访问控制策略,重点是物联网的独特特征和功能。为此,我们将进行一项在线用户研究,得出用户对家庭物联网所需的访问控制策略,即谁应该被允许使用特定功能,以及在什么情况下。在确定了用户表达其期望的家庭物联网访问控制策略所需的原语后,第二阶段将系统化适合这些家庭物联网环境限制的身份验证机制和授权接口,提出与未经授权使用不同功能的风险相称的机制。在研究的第三阶段,我们将实施我们建议的机制,并通过现场实地研究对其进行评估,使我们能够衡量这些接口和机制在用户家庭的现实环境中如何有效地将未经授权的访问和不正确的访问拒绝降至最低。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Clap On, Clap Off: Usability of Authentication Methods in the Smart Home
拍手,拍手关闭:智能家居中身份验证方法的可用性
- DOI:
- 发表时间:2018
- 期刊:
- 影响因子:0
- 作者:He, Weijia;Hainline, Juliette;Padhi, Roshni;Ur, Blase
- 通讯作者:Ur, Blase
Rethinking Access Control and Authentication for the Home Internet of Things (IoT)
- DOI:
- 发表时间:2018
- 期刊:
- 影响因子:13.5
- 作者:Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur
- 通讯作者:Weijia He;Maximilian Golla;Roshni Padhi;Jordan Ofek;Markus Dürmuth;Earlence Fernandes;Blase Ur
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Blase Ur其他文献
Forgotten But Not Gone: Identifying the Need for Longitudinal Data Management in Cloud Storage
被遗忘但并未消失:确定云存储中纵向数据管理的需求
- DOI:
10.1145/3173574.3174117 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Mohammad Taha Khan;Maria Hyun;Chris Kanich;Blase Ur - 通讯作者:
Blase Ur
Evaluating the Security Risks of Freedom on Social Networking Websites
评估社交网站上自由的安全风险
- DOI:
10.7282/t30v8h8j - 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
Blase Ur;Crystal Maung;V. Ganapathy - 通讯作者:
V. Ganapathy
Measuring the Effectiveness of Privacy Tools for Limiting Behavioral Advertising
衡量限制行为广告的隐私工具的有效性
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Rebecca Balebako;P. Leon;Richard Shay;Blase Ur;Yang Wang - 通讯作者:
Yang Wang
Comprehension from Chaos: What Users Understand and Expect from Private Computation
从混沌中领悟:用户对私有计算的理解和期望
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Bailey Kacsmar;Vasisht Duddu;Kyle Tilbury;Blase Ur;F. Kerschbaum - 通讯作者:
F. Kerschbaum
Towards Supporting and Documenting Algorithmic Fairness in the Data Science Workflow
致力于支持和记录数据科学工作流程中的算法公平性
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Galen Harrison;Julia Hanson;Blase Ur - 通讯作者:
Blase Ur
Blase Ur的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Blase Ur', 18)}}的其他基金
Collaborative Research: Conference: 2024 Aspiring PIs in Secure and Trustworthy Cyberspace
协作研究:会议:2024 年安全可信网络空间中的有抱负的 PI
- 批准号:
2404950 - 财政年份:2024
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
EAGER: DCL: SaTC: Enabling Interdisciplinary Collaboration: Efficient Human-in-the-Loop Redaction of Language Development Corpora
EAGER:DCL:SaTC:实现跨学科协作:语言开发语料库的高效人机交互编辑
- 批准号:
2210193 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Methods and Tools for Effective, Auditable, and Interpretable Online Ad Transparency
协作研究:SaTC:核心:媒介:有效、可审核和可解释的在线广告透明度的方法和工具
- 批准号:
2149680 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
CAREER: Usable, Data-Driven Transparency and Access for Consumer Privacy
职业:可用、数据驱动的透明度和消费者隐私访问
- 批准号:
2047827 - 财政年份:2021
- 资助金额:
$ 19.1万 - 项目类别:
Continuing Grant
FMitF: Collaborative Research: User-Centered Verification and Repair of Trigger-Action Programs
FMITF:协作研究:以用户为中心的触发操作程序验证和修复
- 批准号:
1837120 - 财政年份:2018
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Enabling Long-Term Security and Privacy through Retrospective Data Management
SaTC:核心:媒介:协作:通过回顾性数据管理实现长期安全和隐私
- 批准号:
1801663 - 财政年份:2018
- 资助金额:
$ 19.1万 - 项目类别:
Continuing Grant
相似海外基金
SaTC: CORE: Small: Compilation and Backend-Independent Optimization for Multi-Party Computation
SaTC:CORE:小型:多方计算的编译和后端独立优化
- 批准号:
2232061 - 财政年份:2023
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Secure and Robust Machine Learning in Multi-Tenant Cloud FPGA
协作研究:SaTC:CORE:小型:多租户云 FPGA 中安全且稳健的机器学习
- 批准号:
2411207 - 财政年份:2023
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Secure and Robust Machine Learning in Multi-Tenant Cloud FPGA
协作研究:SaTC:CORE:小型:多租户云 FPGA 中安全且稳健的机器学习
- 批准号:
2153525 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Foundations of Trust-Centered Multi-Agent Distributed Coordination
协作研究:SaTC:核心:媒介:以信任为中心的多智能体分布式协调的基础
- 批准号:
2147641 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Foundations of Trust-Centered Multi-Agent Distributed Coordination
协作研究:SaTC:核心:媒介:以信任为中心的多智能体分布式协调的基础
- 批准号:
2147631 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
SaTC: TTP: Small: Experimental Platform for Rapid Prototyping and Deployment of Secure Multi-Party Protocols
SaTC:TTP:小型:安全多方协议快速原型设计和部署的实验平台
- 批准号:
2213057 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
EAGER: DCL: SaTC: Enabling Interdisciplinary Collaboration: Improving Human Discernment of Audio Deepfakes via Multi-level Information Augmentation
EAGER:DCL:SaTC:实现跨学科合作:通过多级信息增强提高人类对音频深赝品的识别能力
- 批准号:
2210011 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Foundations of Trust-Centered Multi-Agent Distributed Coordination
协作研究:SaTC:核心:媒介:以信任为中心的多智能体分布式协调的基础
- 批准号:
2147694 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Secure and Robust Machine Learning in Multi-Tenant Cloud FPGA
协作研究:SaTC:CORE:小型:多租户云 FPGA 中安全且稳健的机器学习
- 批准号:
2153690 - 财政年份:2022
- 资助金额:
$ 19.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Large: Multi-Disciplinary Analyses of the Nature and Spread of Unsubstantiated Information Online
协作研究:SaTC:核心:大型:对未经证实的在线信息的性质和传播进行多学科分析
- 批准号:
2123635 - 财政年份:2021
- 资助金额:
$ 19.1万 - 项目类别:
Continuing Grant