论文标题

触发动作系统中的数据隐私

Data Privacy in Trigger-Action Systems

论文作者

Chen, Yunang, Chowdhury, Amrita Roy, Wang, Ruizhe, Sabelfeld, Andrei, Chatterjee, Rahul, Fernandes, Earlence

论文摘要

触发功能平台(TAPS)允许用户连接基于Web的独立物联网服务以实现有用的自动化。它们提供了一个简单的接口,可帮助最终用户创建触发触发功能规则,以在不同的Internet服务之间传递数据。不幸的是,TAPS引入了大规模的安全风险:如果遭到损害,攻击者将访问数百万用户的敏感数据。为了避免这种风险,我们提出了ETAP,这是一种增强隐私的触发触发器平台,该平台可以执行触发器 - 计算行动规则,而无需以明文访问用户的私人数据或了解计算结果。我们使用乱码的电路作为原始,并利用触发功能规则的独特结构使其实用。我们正式陈述并证明协议的安全保证。我们原型ETAP,该ETAP支持在IFTTT和Zapier等流行商业水龙头上最常用的操作。具体来说,它支持私人触发数据上的布尔,算术和字符串操作,并且可以运行IFTTT用户的前500名规则的100%,而Zapier上所有公共可用规则的​​93.4%。根据行使各种操作的十项现有规则,我们表明ETAP具有适度的性能影响:平均规则执行潜伏期增加了70毫秒(55%),吞吐量降低了59%。

Trigger-action platforms (TAPs) allow users to connect independent web-based or IoT services to achieve useful automation. They provide a simple interface that helps end-users create trigger-compute-action rules that pass data between disparate Internet services. Unfortunately, TAPs introduce a large-scale security risk: if they are compromised, attackers will gain access to sensitive data for millions of users. To avoid this risk, we propose eTAP, a privacy-enhancing trigger-action platform that executes trigger-compute-action rules without accessing users' private data in plaintext or learning anything about the results of the computation. We use garbled circuits as a primitive, and leverage the unique structure of trigger-compute-action rules to make them practical. We formally state and prove the security guarantees of our protocols. We prototyped eTAP, which supports the most commonly used operations on popular commercial TAPs like IFTTT and Zapier. Specifically, it supports Boolean, arithmetic, and string operations on private trigger data and can run 100% of the top-500 rules of IFTTT users and 93.4% of all publicly-available rules on Zapier. Based on ten existing rules that exercise a wide variety of operations, we show that eTAP has a modest performance impact: on average rule execution latency increases by 70 ms (55%) and throughput reduces by 59%.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源