...
首页> 外文期刊>Journal of information security and applications >Repositioning privacy concerns: Web servers controlling URL metadata
【24h】

Repositioning privacy concerns: Web servers controlling URL metadata

机译:重新定位隐私问题:控制URL元数据的Web服务器

获取原文
获取原文并翻译 | 示例
           

摘要

Uniform Resource Locators reveal a significant amount of metadata about user actions, in ways that inherently violate our natural expectations of privacy. Adequately protecting this information is an important issue tackled (sometimes partially) in areas such as secure transport protocols, terminal encryption and caching strategies. A different (and complementary) approach would be to design the application namespace to minimise privacy leakage. Our goal is to develop a different practical concept of this approach, where service providers enforce fully transient URL namespaces that intentionally conceal data through encryption. We aim to determine what would be the design challenges and required compromises to make this a feasible technique to protect data privacy. For starters, we gather requirements from the constraints of URLs in general and compatibility issues seen in web applications, and propose a mapping process for a namespace of encrypted URLs. We implement this approach over an existing web development framework, and analyse the outcome workload from different popular websites to measure its impact in various conditions. Based on our results, we discuss critical design and implementation choices, consider deployment issues that were encountered, and what compromises can be made to address them, if the web service providers want to embed user privacy in their services. Based on this analysis it can be concluded that this type of privacy approach is expensive, with a significant impact in performance and deployment costs that increases with the expected degree of privacy, but there is also room for improvement in various areas. Furthermore, privacy implemented in this way is not a replacement for other types of privacy solutions, but rather a complementary or even conflicting approach, driven by entirely different motives. (C) 2019 Elsevier Ltd. All rights reserved.
机译:统一资源定位器揭示了大量关于用户行动的元数据,以至于固有地违反我们对隐私的自然期望。充分保护此信息是在安全传输协议,终端加密和缓存策略等领域中解决(有时部分)的重要问题。不同(和互补的)方法是设计应用程序命名空间以最大限度地减少隐私泄漏。我们的目标是制定这种方法的不同实际概念,服务提供商强制强制通过加密隐藏数据的完全瞬态URL命名空间。我们的目标是确定设计挑战和所需的妥协,以保护数据隐私的可行技术。对于初学者,我们收集来自网址的约束的要求和Web应用程序中看到的兼容性问题,并为加密URL的命名空间提出了一个映射过程。我们通过现有的Web开发框架实现这种方法,并分析来自不同流行的网站的结果工作量,以测量其在各种条件下的影响。基于我们的结果,我们讨论了关键设计和实现选择,考虑遇到的部署问题,如果Web服务提供商希望在其服务中嵌入用户隐私,则可以对其进行妥协解决这些问题。基于该分析,可以得出结论,这种类型的隐私方法是昂贵的,对性能和部署成本的显着影响,随着预期的隐私程度增加,但还有各种领域的改进余地。此外,通过这种方式实施的隐私不是对其他类型的隐私解决方案的替代,而是一种由完全不同的动机驱动的互补甚至相互矛盾的方法。 (c)2019 Elsevier Ltd.保留所有权利。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号