Contemporary smartphones are capable of generating and transmitting large amounts of data about their users. Recent advances in collaborative context modeling combined with a lack of adequate permission model for handling dynamic context sharing on mobile platforms have led to the emergence of a new class of mobile applications that can access and share embedded sensor and context data. Most of the time such data is used for providing tailored services to the user but it can lead to serious breaches of privacy. We use Semantic Web technologies to create a rich notion of context. We also discuss challenges for context aware mobile platforms and present approaches to manage data flow on these devices using semantically rich fine-grained context-based policies that allow users to define their privacy and security need using tools we provide.
We present our ongoing work on user data and contextual privacy preservation in mobile devices through semantic reasoning. Recent advances in context modeling, tracking and collaborative localization have led to the emergence of a new class of smart phone applications that can access and share embedded sensor data. Unfortunately, this also means significant amount of user context information is now accessible to applications and potentially others, creating serious privacy and security concerns. Mobile OS frameworks like Android lack mechanisms for dynamic privacy control. We show how data flow among applications can be successfully filtered at a much more granular level using semantic web driven technologies that model device location, surroundings, application roles as well as context-dependent information sharing policies.
Cyber-physical systems (CPSs) and cyber infrastructure are the key elements of the national infrastructure, and securing them is of vital importance to national security. There is ample evidence that these systems are vulnerable to disruption and damage due to natural disasters, social crises, and terrorism. CPS applications are becoming more widespread, ranging from health-care patient monitoring systems to autonomous vehicles to integrated electrical power grids. Often, the new application domains cross administrative boundaries and are not under the supervisory control of a single domain. This introduces critical issues of policy and trust that have not been traditionally addressed in their design and management. Most work in securing CPS and cyber infrastructure has focused on security of the communication links between the sensing and actuating elements. We describe a more holistic approach that is based on the concepts of situation awareness for monitoring the state of a CPS and high-level policies to manage its functioning and security. Such a framework can manage the trust relationship among entities as well as external contextual information when detecting, evaluating, and responding to threats. We illustrate the framework by showing how it can protect the traditional Internet backbone by automatically configuring BGP router systems, defending against attacks, and recovering from accidental or malicious damage. We also illustrate how the same framework can be used to secure devices and information in mobile networks.
The balance between privacy and security concerns is a hotly debated topic, especially as government (and private) entities are able to gather and analyze data from several disparate sources with ease. This ability to do large scale analytics of publicly accessible data leads to significant privacy concerns. In particular, for the government, there is the fear of a fishing expedition against individuals. The model in this paper describes a way to address these concerns in a multi-user and multi-database owner environment. The model provides an assurance system where database owners are able to test and audit the assurances given by users thereby increasing the trust in the system. The concept of segregating data used for processing from data needed for final end use and providing different levels of access to them through a mediator machine has been used. The audit component consisting of a justification mechanism increases the trust in the system.
A Cyber-Physical System (CPS) involves a tight coupling between the physical and computational elements. Security is a key challenge for the deployment of CPS. Therefore, it is highly desirable to extract correct information from a large volume of noisy data and properly evaluate the reputation of reporting devices in CPS. In this paper, we propose a Context-Aware tRust Evaluation scheme for wireless networks in CPS (CARE-CPS), and a set of policy rules are declared to accurately describe how we determine the reputation of each reporting device based on these factors. To validate the CARE-CPS scheme, we have conducted experiments in terms of both simulation and real deployment on smart phones. Experimental results show that the CARE-CPS scheme can properly evaluate the trustworthiness of the report devices in CPS.
We describe work on representing and using a rich notion of context that goes beyond current networking applications focusing mostly on location. Our context model includes location and surroundings, the presence of people and devices, inferred activities and the roles people fill in them. A key element of our work is the use of collaborative information sharing where devices share and integrate knowledge about their context. This introduces a requirement that users can set appropriate levels of privacy to protect the personal information being collected and the inferences that can be drawn from it. We use Semantic Web technologies to model context and to specify high-level, declarative policies specifying information sharing constraints. The policies involve attributes of the subject (i.e., information recipient), target (i.e., the information) and their dynamic context (e.g., are the parties copresent). We discuss our ongoing work on context representation and inference and present a model for protecting and controlling the sharing of private data in context-aware mobile applications.
Recent years have seen a confluence of two major trends--the increase of mobile devices such as smart phones as the primary access point to networked information and the rise of social media platforms that connect people. Their convergence supports the emergence of a new class of context-aware geosocial networking applications. While existing systems focus mostly on location, our work centers on models for representing and reasoning about a more inclusive and higher-level notion of context, including the user's location and surroundings, the presence of other people and devices, and the inferred activities in which they are engaged. A key element of our work is the use of collaborative information sharing where devices share and integrate knowledge about their context. This introduces the need for privacy and security mechanisms. We present a framework to provide users with appropriate levels of privacy to protect the personal information their mobile devices are collecting, including the inferences that can be drawn from the information. We use Semantic Web technologies to specify high-level, declarative policies that describe user information sharing preferences. We have built a prototype system that aggregates information from a variety of sensors on the phone, online sources, and sources internal to the campus intranet, and infers the dynamic user context. We show how our policy framework can be effectively used to devise better privacy control mechanisms to control information flow between users in such dynamic mobile systems.
Recent years have seen a confluence of two major trends - the increase of mobile devices such as smart phones as the primary access point to networked information and the rise of social media platforms that connect people. Their convergence supports the emergence of a new class of context-aware geo-social networking applications. While existing systems focus mostly on location, our work centers on models for representing and reasoning about a more inclusive and higher-level notion of context, including the user's location and surroundings, the presence of other people and devices, feeds from social networking systems they use, and the inferred activities in which they are engaged. A key element of our work is the use of collaborative information sharing where devices share and integrate knowledge about their context. This introduces the need for privacy and security mechanisms. We present a framework to provide users with appropriate levels of privacy to protect the personal information their mobile devices are collecting including the inferences that can be drawn from the information. We use Semantic Web technologies to specify high-level, declarative policies that describe user's information sharing preferences. We have built a prototype system that aggregates information from a variety of sensors on the phone, online sources, and sources internal to the campus intranet, and infers the dynamic user context. We show how our policy framework can be effectively used to devise better privacy control mechanisms to control information ow between users in such dynamic mobile systems.