Security and Privacy for Web and Mobile Services
Security and Privacy for Web and Mobile Services
批准号:
RGPIN-2017-04822
负责人:
Aiello, William
金额:
$1.46万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31
中文摘要
*今天,网络和云服务提供商向他们的客户提供浮士德式的交易:为了换取服务,您必须将您的所有数据提供给我们。云服务相对于“老式”的客户端软件有很多优势,包括:i.)普遍无障碍,二.)共享能力,III。)数据的高持久性,iv.)透明的代码更新,以及V.)除了高级功能之外,这些服务通常看起来都是免费的。*然而,这些好处是以巨大的代价为代价的:失去对用户自己数据的控制。首先,也是最重要的,用户放弃了其数据的隐私。服务提供商在他们的服务协议中授予自己将用户数据货币化的权利,这些服务协议对用户来说非常不透明。其次,用户无法审核数据的访问权限或保留,因为它们是由服务器端软件实现的。例如,虽然用户可以从她的主页移除照片,但是在假定的删除很久之后,可以通过直接URL引用来访问相同的照片。更令人不安的是,用户可能会因为纠纷或商业姿态的改变而无法访问他的数据。除此之外,当用户被允许提取他的数据时,他只剩下一大堆无法理解的东西,没有软件来导航。最后,由于用户经常使用许多云应用程序,他的数据分散在互联网上,检索相关项目的机制很少。*这里提出的研究集中在以下问题上。是否有可能构建既保留Web服务交付模式的优势,又改进用户对自己数据的控制的应用程序和服务?*我们认为答案是肯定的。在我的实验室里,我们正在努力了解这种功能,它将允许服务提供商在如何处理他们的数据方面为消费者提供更广泛的选择。到目前为止,在我们的研究中,我们已经开发了Web浏览器扩展的机制,以监控、干预客户端Web应用程序并为其提供新的API,这些应用程序允许丰富的应用程序,同时仍为用户提供隐私和数据控制。我们建议在几个方向上继续这方面的研究。*1.)我们建议扩展我们的网络介入技术,以建立一个个人网络分析平台。该平台将发挥两个重要作用。首先,它会将用户的网络会话记录到安全日志中。其次,它将允许分析应用程序访问日志,同时对应用程序进行沙箱保护,以防止隐私泄露。*2.)我们还将研究如何将这些平台扩展到移动软件。我们将调查ARM TrustZone机制是否足以克服Android操作系统带来的不安全性。*3.)我们将利用现有Web服务的规模来构建重要的安全基础设施,以支持更多样化的私有应用生态系统,例如强大的用户到用户公钥基础设施和匿名通信服务,作为TOR的替代方案。
英文摘要
***Today, web and cloud service providers offer a Faustian bargain to their customers: in exchange for service, you must give us all of your data. The advantages of cloud services over “old school” client-side software are many, including: i.) universal accessibility, ii.) share-ability, iii.) high durability of data, iv.) transparent code updates, and v.) often seemingly free service for all but premium functionality.******However, these benefits come at a large expense: loss of control of the user's own data. First and foremost, the user gives up the privacy of his data. Service providers grant themselves rights to monetize user data in their service agreements that are extremely opaque to the user. Second, the user has no means to audit the access permissions to, or retention of, the data as they are implemented by server side software. E.g., while a user may remove a photo from her home page, that same photo may be accessible via a direct URLreference long after the supposed deletion. Even more troubling, a user may simply lose access to his data due to a dispute or a change in business posture. Short of that, when a user is allowed to extract his data, he is left with an unintelligible mass without the software to navigate it. Finally, since a user often employs many cloud applications, his data is scattered across the Internet and the mechanisms for retrieving related items are few. ******The research proposed here is focused on the following question. Is it possible to build applications and services that retain the advantages of the web service delivery model but improve the control users have over their own data? ******We believe that the answer is yes. In my lab we are working to understand the functionality that would allow service providers to give consumers a broader range of choices in how their data is handled. In our research to date we have developed mechanisms for a web browser extension to monitor, interpose on, and provide new APIs for client-side web applications that allow for rich applications while still providing users privacy and control of their data. We propose to continue this line of research in several directions. ****** 1.) We propose to extend our web interposition techniques to build a platform for personal web analytics. The platform will perform two essential roles. First, it will record a user's web sessions to a secure log. Second, it will allow analysis applications access to the log while sandboxing the applications to prevent privacy leaks. ******2.) We will also examine how to extend these platforms to mobile software. We will investigate whether the ARM TrustZone mechanism is sufficient to overcome the insecurities introduced by the Android OS. ******3.) We will leverage the scale of existing Web services to build important security infrastructure for supporting a more diverse ecosystem of private applications such as a robust user--to--user public key infrastructure and an anonymity communication service as an alternative to TOR.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Security and Privacy for Web and Mobile Services
-
批准号:RGPIN-2017-04822
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2019
-
负责人:Aiello, William
-
依托单位:
Security and Privacy for Web and Mobile Services
-
批准号:RGPIN-2017-04822
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2017
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2015
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2012
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2011
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2010
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2009
-
负责人:Aiello, William
-
依托单位:
Security for enterprises and ISPs
-
批准号:355997-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.29万
-
财政年份:2008
-
负责人:Aiello, William
-
依托单位:
海外基金