CAREER: User-Centered Multiparty Access Control for Collective Content Management
CAREER: User-Centered Multiparty Access Control for Collective Content Management
批准号:
1453080
负责人:
Dongwon Lee
金额:
$55.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-08-01 至 2023-07-31
中文摘要
该CAREER项目将开发模型和技术,以促进数据与多个用户相关联并由多个用户共同管理的领域中的用户数据的受控信息共享,例如生物存储库,远程远程工作和社会计算。具体的研究目标是:1)在PI先前工作的基础上,开发一个描述单个内容管理者或内容所有者决策过程的访问控制的基础模型,为第二个目标奠定基础; 2)开发新的模型,以支持多个用户和站点管理员的共享内容的访问控制策略的同步、异步和组合联合规范,以及3)将这些解决方案概念应用于两个特定的应用,即小组工作和生物库,并进行用户研究以测试拟合度,适当性和可行性的访问设置机制。这个项目需要一个创新的用户-以中心为中心的方法,以确保开发的严格模型产生可执行的机制,这些机制可用于各种现有平台,域.为了实现这一目标,拟议的工作借鉴了多个学科,包括访问控制,安全和隐私的博弈论,以及决策支持系统。 例如,在一组照片中的一个人可能更喜欢不共享照片,即使其他人这样做,但会接受它只与朋友共享;社交网络运营商希望通过共享信息来最大化系统的使用,同时保持用户快乐,使他们保持活跃。 因此,偏好构成多目标优化问题。 我们使用博弈论的方法来模拟这个问题,允许谈判,以确定访问设置。 这项研究将为用户提供表达共享的多拥有的数据的首选访问控制设置的能力,共同影响与输入的最终访问设置,同时考虑到组织的约束和现有的laws.Further,我们利用先发优势的经济概念,创建模型,适用于用户之间的同步协调的情况下是不切实际的。特别是,该模型从Stackelberg博弈的扩展和应用开始,并考虑到由于人类有限理性而导致的安全决策和不确定性的独特约束。 作为此任务的一部分,我们还开发了一种方法,域管理员可以确定应该向用户提供哪组访问策略选项。通过这个以管理员为中心的模型,我们使管理员能够确定一组选项,满足用户的预测访问控制决策,并满足他们的管理员自己的内部目标。我们还研究了建立在同步和异步多方方法的优势上的混合模型。 开发的模型和机制将适用于广泛的领域,包括社会计算,远程协作内容共同创作,个性化医疗和遗传数据共享。综合教育计划将侧重于课程优化和扩大本科生研究经验。 我们建立了一个研究生访问计划,让学生与不同学科的经验,认识到在信息安全的多学科挑战。 最终目标是培养具有设计和评估IT安全解决方案所需的多学科技能的多样化毕业生。
英文摘要
This CAREER project will develop models and techniques to facilitate controlled information sharing of users' data in domains where the data is associated with and co-managed by multiple users, such as bio-repositories, remote teleworking, and social computing. Specific research objectives are: 1) Building on the PI's prior work, develop a foundational model describing access control in terms of the decision making process of a single content manager or content owner, laying the groundwork for the second objective; 2) Develop new models to support synchronous, asynchronous, and combined joint specification of access control policies for shared content for multiple users and site administrators, and 3) Apply those solution concepts to two specific applications, group work and a biobank, and conduct user studies to test goodness of fit, suitability and feasibility of the resulting access setting mechanisms.This project takes an innovative user-centric approach to ensure that the rigorous models developed result in enforceable mechanisms that can be used on a variety of existing platforms in and multiple domains. To accomplish this, the proposed work draws from multiple disciplines, including access control, game theory for security and privacy, and decision support systems. For example, an individual in a group photo may prefer not to have the photo shared even though others do, but would accept it being shared only with friends; a social network operator wants to maximize use of the system through sharing information while keeping users happy so they remain active. The preferences thus constitute a multi-objective optimization problem. We use a game-theoretic approach to modeling this problem, allowing negotiation to determine access settings. This research will provide users with the ability to express preferred access control settings for shared multi-owned data, jointly influencing with that input the final access settings, while taking into account organizational constraints and existing laws.Further, we leverage the economic concept of first-mover advantage to create models suitable in scenarios where synchronous coordination among users is not practical. In particular, the models start with extensions and applications of Stackelberg games, and account for the unique constraints occurring with security decisions and uncertainty due to human-bounded rationality. As part of this task, we also develop a method for domain administrators to determine what set of access policy options should be offered to users. Through this administrator-centered model, we enable administrators to identify the set of options that satisfy users' predicted access control decisions and meet their administrator's own internal objectives. We also study hybrid models that build on strengths of synchronous and asynchronous multi-party approaches. The models and mechanisms developed will apply to a wide range of domains, including social computing, remote collaborative content co-authoring, personalized medicine, and genetic data sharing.The integrated education plan will focus on curriculum enhancement and expanded undergraduate research experiences. We establish a graduate visiting program to give students experience with different disciplines, recognizing the multidisciplinary challenges in information security. The ultimate goal is to produce diverse graduates with the multidisciplinary skills required to design and evaluate IT security solutions.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CISE-MSI: RCBP-RF: SaTC: Building Research Capacity in AI Based Anomaly Detection in Cybersecurity
-
批准号:2131144
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2022
-
负责人:Dongwon Lee
-
依托单位:
EAGER: SaTC-EDU: A Framework for Developing Attributable Cybersecurity Case Studies
-
批准号:2114824
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2021
-
负责人:Dongwon Lee
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Privacy protection of Vehicles location in Spatial Crowdsourcing under realistic adversarial models
-
批准号:2029976
-
项目类别:Standard Grant
-
资助金额:$27.28万
-
财政年份:2021
-
负责人:Dongwon Lee
-
依托单位:
REU Site: Machine Learning in Cybersecurity
-
批准号:1950491
-
项目类别:Standard Grant
-
资助金额:$39.0万
-
财政年份:2020
-
负责人:Dongwon Lee
-
依托单位:
Vertical Search Engine and Graph Homomorphism for Enhancing the Cybersecurity Workforce
-
批准号:1934782
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2019
-
负责人:Dongwon Lee
-
依托单位:
Collaborative Research: Precision Learning: Data-Driven Experimentation of Learning Theories using Internet-of-Videos
-
批准号:1940076
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2019
-
负责人:Dongwon Lee
-
依托单位:
Developing and Evaluating Fraud Informatics Curriculum among Institutions in the Appalachian Region
-
批准号:1820609
-
项目类别:Standard Grant
-
资助金额:$49.96万
-
财政年份:2018
-
负责人:Dongwon Lee
-
依托单位:
Penn State's CyberCorps; Scholarship for Service Program
-
批准号:1663343
-
项目类别:Continuing Grant
-
资助金额:$448.03万
-
财政年份:2017
-
负责人:Dongwon Lee
-
依托单位:
EAGER: Training Computers and Humans to Detect Misinformation by Combining Computational and Theoretical Analysis
-
批准号:1742702
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2017
-
负责人:Dongwon Lee
-
依托单位:
SBE TWC: Small: Collaborative: Privacy Protection in Social Networks: Bridging the Gap Between User Perception and Privacy Enforcement
-
批准号:1422215
-
项目类别:Standard Grant
-
资助金额:$27.92万
-
财政年份:2014
-
负责人:Dongwon Lee
-
依托单位:
Unearthing Latent Information Segments of Academic Videos on the Web
-
批准号:0937891
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2009
-
负责人:Dongwon Lee
-
依托单位:
US-Singapore Planning Visit: Collaborative Research on Next Generation Bibliographic Search Engine
-
批准号:0610998
-
项目类别:Standard Grant
-
资助金额:$0.59万
-
财政年份:2006
-
负责人:Dongwon Lee
-
依托单位:
海外基金