Novel Physical Protection of Personal Mobile Assets
个人移动资产的新颖物理保护
基本信息
- 批准号:RGPIN-2020-06647
- 负责人:
- 金额:$ 2.99万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2022
- 资助国家:加拿大
- 起止时间:2022-01-01 至 2023-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The design of physical security for smartphones and other mobile devices dates back to the first smartphones introduced more than 12 years ago, when they were intended to be little more than music players with calling capabilities and a more usable user interface. At that time, just a PIN (now known more generally as "passcode") was good enough to play music and make phone calls. Smartphones and other mobile devices are used these days for much more than that. A growing body of empirical evidence suggests that the physical security and privacy of mobile devices is not good enough any more. Smartphone apps have widely varying levels of sensitivity, yet unlocking the device is still necessary and sufficient for launching most of the apps. This all-or-nothing role of unlocking results in unnecessarily high overhead for accessing low-sensitivity apps (e.g., public information retrieval apps, such as weather, Wikipedia, IMDB) on the one hand, and insufficient security of high-sensitivity apps (e.g., financial, dating, medical, messaging) on the other hand. Smartphones and other mobile devices are commonly shared with others, yet the access control mechanisms support only single-user model, in which whoever unlocks the phone has access to its apps, data, and services. Snooping on mobile device by social insiders has been established as a real threat, which cannot be ignored. Yet, passcode (easily shoulder-surfed by social insiders) remains the primary authentication mechanism, knowledge of which is sufficient not only to unlock the device but also to change any settings on it. It's prime time to rethink physical security for mobile devices, particularly smartphones. I propose to explore the design space for improving physical security and privacy of mobile devices. My proposed research program for the next five years comprises investigation in systems design as well as human and social aspects of privacy and security. Together with the graduate students from my research group as well as my industry and academic collaborators, I will explore and evaluate alternative designs that support secure and usable device sharing, optimize usability and security in the context of apps and services of varying degrees of sensitivity, and address the threat of social insider.
智能手机和其他移动设备的物理安全设计可以追溯到12多年前推出的第一款智能手机,当时它们的初衷是充当音乐播放器,具有通话功能和更可用的用户界面。当时,只需一个PIN(现在更广为人知的密码)就足以播放音乐和打电话。如今,智能手机和其他移动设备的用途远远不止于此。越来越多的经验证据表明,移动设备的物理安全和隐私不再足够好。智能手机应用程序的敏感度差异很大,但解锁设备对于启动大多数应用程序来说仍然是必要的,也是足够的。这种要么全有要么全无的解锁角色一方面导致访问低敏感度应用程序(例如,公共信息检索应用程序,如天气、维基百科、IMDB)的不必要的高开销,另一方面导致高敏感度应用程序(例如,金融、约会、医疗、消息传递)的安全性不足。智能手机和其他移动设备通常与其他人共享,但访问控制机制只支持单用户模式,在这种模式下,无论谁解锁手机,都可以访问其应用程序、数据和服务。社交圈内人对移动设备的窥探已被确立为一种不容忽视的真正威胁。然而,密码(很容易被社交圈内人用肩膀冲浪)仍然是主要的身份验证机制,了解密码不仅足以解锁设备,还可以更改设备上的任何设置。现在是重新考虑移动设备,特别是智能手机的物理安全的最佳时机。我建议探索提高移动设备物理安全性和隐私的设计空间。我提出的未来五年的研究计划包括对系统设计以及隐私和安全的人类和社会方面的调查。我将与我的研究小组的研究生以及我的行业和学术合作者一起,探索和评估支持安全和可用的设备共享的替代设计,在不同程度敏感的应用程序和服务的背景下优化可用性和安全性,并应对社交内部人士的威胁。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Beznosov, Konstantin其他文献
Phishing threat avoidance behaviour: An empirical investigation
- DOI:
10.1016/j.chb.2016.02.065 - 发表时间:
2016-07-01 - 期刊:
- 影响因子:9.9
- 作者:
Arachchilage, Nalin Asanka Gamagedara;Love, Steve;Beznosov, Konstantin - 通讯作者:
Beznosov, Konstantin
Beznosov, Konstantin的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Beznosov, Konstantin', 18)}}的其他基金
Novel Physical Protection of Personal Mobile Assets
个人移动资产的新颖物理保护
- 批准号:
RGPIN-2020-06647 - 财政年份:2021
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Novel Physical Protection of Personal Mobile Assets
个人移动资产的新颖物理保护
- 批准号:
RGPIN-2020-06647 - 财政年份:2020
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Towards understanding the perception and management of risk and trust among cryptocurrency (non) users
理解加密货币(非)用户对风险和信任的感知和管理
- 批准号:
538930-2019 - 财政年份:2019
- 资助金额:
$ 2.99万 - 项目类别:
Engage Grants Program
Security & Privacy Support for Teenagers in Online Social Media
安全
- 批准号:
RGPIN-2014-03862 - 财政年份:2018
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
UBC CyberSecurity Summit 2018
2018 年 UBC 网络安全峰会
- 批准号:
521112-2017 - 财政年份:2017
- 资助金额:
$ 2.99万 - 项目类别:
Connect Grants Level 2
Security & Privacy Support for Teenagers in Online Social Media
安全
- 批准号:
RGPIN-2014-03862 - 财政年份:2017
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Security & Privacy Support for Teenagers in Online Social Media
安全
- 批准号:
RGPIN-2014-03862 - 财政年份:2016
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Investigating unlocking behavior and usage patterns of Android smartphone users
调查Android智能手机用户的解锁行为和使用模式
- 批准号:
491574-2015 - 财政年份:2015
- 资助金额:
$ 2.99万 - 项目类别:
Engage Grants Program
Security & Privacy Support for Teenagers in Online Social Media
安全
- 批准号:
RGPIN-2014-03862 - 财政年份:2015
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Android OS integration with KeyVault framework
Android 操作系统与 KeyVault 框架集成
- 批准号:
461957-2014 - 财政年份:2014
- 资助金额:
$ 2.99万 - 项目类别:
Engage Plus Grants Program
相似国自然基金
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
- 批准号:61300132
- 批准年份:2013
- 资助金额:23.0 万元
- 项目类别:青年科学基金项目
相似海外基金
Development and Validation of Physical and Biological Methods for Low Dose Radiation Protection
低剂量辐射防护物理和生物方法的开发和验证
- 批准号:
556287-2020 - 财政年份:2022
- 资助金额:
$ 2.99万 - 项目类别:
Alliance Grants
Cooperative Cyber Attack Protection, Fault Diagnosis, and Recovery Control of Autonomous Networked Unmanned Vehicles and Multi-Agent Cyber-Physical Systems (CPS)
自主网络化无人驾驶车辆和多智能体网络物理系统(CPS)的协同网络攻击防护、故障诊断和恢复控制
- 批准号:
RGPIN-2019-06996 - 财政年份:2022
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Detection of Cyber-Physical Attacks on Digital Substation Protection
数字化变电站保护网络物理攻击检测
- 批准号:
RGPIN-2022-05346 - 财政年份:2022
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Detection of Cyber-Physical Attacks on Digital Substation Protection
数字化变电站保护网络物理攻击检测
- 批准号:
DGDND-2022-05346 - 财政年份:2022
- 资助金额:
$ 2.99万 - 项目类别:
DND/NSERC Discovery Grant Supplement
Historical study on the protection and rehabilitation of prisoners with physical and mental disabilities in the prewar period
战前身心残疾囚犯保护与康复历史研究
- 批准号:
22K13565 - 财政年份:2022
- 资助金额:
$ 2.99万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Development and Validation of Physical and Biological Methods for Low Dose Radiation Protection
低剂量辐射防护物理和生物方法的开发和验证
- 批准号:
556287-2020 - 财政年份:2021
- 资助金额:
$ 2.99万 - 项目类别:
Alliance Grants
Novel Physical Protection of Personal Mobile Assets
个人移动资产的新颖物理保护
- 批准号:
RGPIN-2020-06647 - 财政年份:2021
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Cooperative Cyber Attack Protection, Fault Diagnosis, and Recovery Control of Autonomous Networked Unmanned Vehicles and Multi-Agent Cyber-Physical Systems (CPS)
自主网络化无人驾驶车辆和多智能体网络物理系统(CPS)的协同网络攻击防护、故障诊断和恢复控制
- 批准号:
RGPIN-2019-06996 - 财政年份:2021
- 资助金额:
$ 2.99万 - 项目类别:
Discovery Grants Program - Individual
Cooperative Cyber Attack Protection, Fault Diagnosis, and Recovery Control of Autonomous Networked Unmanned Vehicles and Multi-Agent Cyber-Physical Systems (CPS)
自主网络化无人驾驶车辆和多智能体网络物理系统(CPS)的协同网络攻击防护、故障诊断和恢复控制
- 批准号:
DGDND-2019-06996 - 财政年份:2021
- 资助金额:
$ 2.99万 - 项目类别:
DND/NSERC Discovery Grant Supplement
Development and Validation of Physical and Biological Methods for Low Dose Radiation Protection
低剂量辐射防护物理和生物方法的开发和验证
- 批准号:
556287-2020 - 财政年份:2020
- 资助金额:
$ 2.99万 - 项目类别:
Alliance Grants