Security and Privacy for Web and Mobile Services
Security and Privacy for Web and Mobile Services
批准号:
RGPIN-2017-04822
负责人:
Aiello, William
金额:
$1.46万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31
中文摘要
* 今天,网络和云服务提供商向他们的客户提供浮士德式的交易:作为服务的交换,您必须向我们提供您的所有数据。 云服务相对于“老派”客户端软件的优势有很多,包括:i.普遍无障碍,二)分享能力,三)数据的高耐久性,iv.)透明的代码更新,以及v.)除了高级功能外,通常似乎所有服务都是免费的。*然而,这些好处是以巨大的代价来实现的:失去对用户自己数据的控制。 首先,用户放弃了他的数据隐私。 服务提供商在其服务协议中授予自己将用户数据货币化的权利,这些协议对用户来说非常不透明。 其次,用户无法审核对数据的访问权限或保留,因为它们是由服务器端软件实现的。 例如,在一个示例中,虽然用户可以从她的主页中删除照片,但是在假定的删除之后很长时间,可以经由直接URL引用来访问同一照片。更令人不安的是,用户可能会因为争议或业务姿态的变化而失去对数据的访问权。 除此之外,当用户被允许提取数据时,他会得到一堆无法理解的数据,而没有软件来导航它。最后,由于用户经常使用许多云应用程序,他的数据分散在互联网上,并且检索相关项目的机制很少。* *是否有可能构建既保留Web服务交付模型的优势,又提高用户对自己数据的控制的应用程序和服务?** 我们认为答案是肯定的。在我的实验室中,我们正在努力了解允许服务提供商为消费者提供更广泛的数据处理选择的功能。在我们迄今为止的研究中,我们已经开发了Web浏览器扩展的机制,以监控,监控,并为客户端Web应用程序提供新的API,这些应用程序允许丰富的应用程序,同时仍然为用户提供隐私和控制他们的数据。我们建议在几个方向上继续这一研究路线。** 1.)我们建议扩展我们的Web插入技术,以建立一个个人Web分析平台。 该平台将发挥两个重要作用。 首先,它将记录用户的Web会话到安全日志。 其次,它将允许分析应用程序访问日志,同时对应用程序进行沙箱化以防止隐私泄露。 **2.)我们还将研究如何将这些平台扩展到移动的软件。我们将研究ARM TrustZone机制是否足以克服Android操作系统引入的不安全性。**3。)我们将利用现有Web服务的规模来构建重要的安全基础设施,以支持更多样化的私有应用程序生态系统,例如强大的用户对用户公钥基础设施和匿名通信服务,作为TOR的替代方案。
英文摘要
***Today, web and cloud service providers offer a Faustian bargain to their customers: in exchange for service, you must give us all of your data. The advantages of cloud services over “old school” client-side software are many, including: i.) universal accessibility, ii.) share-ability, iii.) high durability of data, iv.) transparent code updates, and v.) often seemingly free service for all but premium functionality.******However, these benefits come at a large expense: loss of control of the user's own data. First and foremost, the user gives up the privacy of his data. Service providers grant themselves rights to monetize user data in their service agreements that are extremely opaque to the user. Second, the user has no means to audit the access permissions to, or retention of, the data as they are implemented by server side software. E.g., while a user may remove a photo from her home page, that same photo may be accessible via a direct URLreference long after the supposed deletion. Even more troubling, a user may simply lose access to his data due to a dispute or a change in business posture. Short of that, when a user is allowed to extract his data, he is left with an unintelligible mass without the software to navigate it. Finally, since a user often employs many cloud applications, his data is scattered across the Internet and the mechanisms for retrieving related items are few. ******The research proposed here is focused on the following question. Is it possible to build applications and services that retain the advantages of the web service delivery model but improve the control users have over their own data? ******We believe that the answer is yes. In my lab we are working to understand the functionality that would allow service providers to give consumers a broader range of choices in how their data is handled. In our research to date we have developed mechanisms for a web browser extension to monitor, interpose on, and provide new APIs for client-side web applications that allow for rich applications while still providing users privacy and control of their data. We propose to continue this line of research in several directions. ****** 1.) We propose to extend our web interposition techniques to build a platform for personal web analytics. The platform will perform two essential roles. First, it will record a user's web sessions to a secure log. Second, it will allow analysis applications access to the log while sandboxing the applications to prevent privacy leaks. ******2.) We will also examine how to extend these platforms to mobile software. We will investigate whether the ARM TrustZone mechanism is sufficient to overcome the insecurities introduced by the Android OS. ******3.) We will leverage the scale of existing Web services to build important security infrastructure for supporting a more diverse ecosystem of private applications such as a robust user--to--user public key infrastructure and an anonymity communication service as an alternative to TOR.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Security and Privacy for Web and Mobile Services
-
批准号:RGPIN-2017-04822
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2018
-
负责人:Aiello, William
-
依托单位:
Security and Privacy for Web and Mobile Services
-
批准号:RGPIN-2017-04822
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2017
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2015
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2012
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2011
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2010
-
负责人:Aiello, William
-
依托单位:
Enterprise security
-
批准号:355997-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2009
-
负责人:Aiello, William
-
依托单位:
Security for enterprises and ISPs
-
批准号:355997-2008
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.29万
-
财政年份:2008
-
负责人:Aiello, William
-
依托单位:
海外基金