首页> 外文会议>IEEE Symposium on Security and Privacy >Data Privacy in Trigger-Action Systems
【24h】

Data Privacy in Trigger-Action Systems

机译:触发器 - 动作系统中的数据隐私

获取原文

摘要

Trigger-action platforms (TAPs) allow users to connect independent web-based or IoT services to achieve useful automation. They provide a simple interface that helps end-users create trigger-compute-action rules that pass data between disparate Internet services. Unfortunately, TAPs introduce a large-scale security risk: if they are compromised, attackers will gain access to sensitive data for millions of users. To avoid this risk, we propose eTAP, a privacy-enhancing trigger-action platform that executes trigger-compute-action rules without accessing users’ private data in plaintext or learning anything about the results of the computation. We use garbled circuits as a primitive, and leverage the unique structure of trigger-compute-action rules to make them practical. We formally state and prove the security guarantees of our protocols. We prototyped eTAP, which supports the most commonly used operations on popular commercial TAPs like IFTTT and Zapier. Specifically, it supports Boolean, arithmetic, and string operations on private trigger data and can run 100% of the top-500 rules of IFTTT users and 93.4% of all publicly-available rules on Zapier. Based on ten existing rules that exercise a wide variety of operations, we show that eTAP has a modest performance impact: on average rule execution latency increases by 70 ms (55%) and throughput reduces by 59%.
机译:触发器 - 动作平台(TAPS)允许用户连接独立的基于Web或IoT服务以实现有用的自动化。它们提供了一个简单的界面,可帮助最终用户创建传递不同Internet服务之间的数据的触发器计算操作规则。不幸的是,水龙头引入了大规模的安全风险:如果它们受到损害,攻击者将获得数百万用户的敏感数据。为避免这种风险,我们提出了ETAP,一个隐私增强触发器 - 动作平台,该平台执行触发器计算 - 动作规则,而不在明文中以纯粹的私有数据或学习关于计算结果的任何内容。我们使用乱码作为原始的,并利用触发器计算行动规则的独特结构,使其实用。我们正式陈述并证明了我们协议的安全保障。我们原型的ETAP,它支持像IFTTT和Zapier这样的流行商业水龙头上最常用的操作。具体而言,它支持私有触发数据上的布尔,算术和字符串操作,可以运行IFTTT用户的100%,IFTTT用户的第500个规则以及Zapier上所有公开可用规则的​​93.4%。基于锻炼各种操作的十个现有规则,我们表明ETAP具有适度的性能影响:平均规则执行延迟增加70毫秒(55%),吞吐量减少59%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号