The Experts below are selected from a list of 2163 Experts worldwide ranked by ideXlab platform
Joan Feigenbaum - One of the best experts on this subject based on the ideXlab platform.
-
Reuse It Or Lose It: More Efficient Secure Computation Through Reuse of Encrypted Values
arXiv: Cryptography and Security, 2015Co-Authors: Benjamin Mood, Debayan Gupta, Kevin R. B. Butler, Joan FeigenbaumAbstract:Two-party secure function evaluation (SFE) has become significantly more feasible, even on resource-constrained devices, because of advances in server-aided computation systems. However, there are still bottlenecks, particularly in the input validation stage of a computation. Moreover, SFE research has not yet devoted sufficient attention to the important problem of retaining state after a computation has been performed so that expensive processing does not have to be repeated if a similar computation is done again. This paper presents PartialGC, an SFE system that allows the reuse of encrypted values generated during a garbled-circuit computation. We show that using PartialGC can reduce computation time by as much as 96% and bandwidth by as much as 98% in comparison with previous outsourcing schemes for secure computation. We demonstrate the feasibility of our approach with two sets of experiments, one in which the garbled circuit is evaluated on a mobile device and one in which it is evaluated on a server. We also use PartialGC to build a privacy-preserving "friend Finder" Application for Android. The reuse of previous inputs to allow stateful evaluation represents a new way of looking at SFE and further reduces computational barriers.
-
ACM Conference on Computer and Communications Security - Reuse It Or Lose It: More Efficient Secure Computation Through Reuse of Encrypted Values
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, 2014Co-Authors: Benjamin Mood, Debayan Gupta, Kevin R. B. Butler, Joan FeigenbaumAbstract:Two-party secure-function evaluation (SFE) has become significantly more feasible, even on resource-constrained devices, because of advances in server-aided computation systems. However, there are still bottlenecks, particularly in the input-validation stage of a computation. Moreover, SFE research has not yet devoted sufficient attention to the important problem of retaining state after a computation has been performed so that expensive processing does not have to be repeated if a similar computation is done again. This paper presents PartialGC, an SFE system that allows the reuse of encrypted values generated during a garbled-circuit computation. We show that using PartialGC can reduce computation time by as much as 96% and bandwidth by as much as 98% in comparison with previous outsourcing schemes for secure computation. We demonstrate the feasibility of our approach with two sets of experiments, one in which the garbled circuit is evaluated on a mobile device and one in which it is evaluated on a server. We also use PartialGC to build a privacy-preserving ``friend-Finder'' Application for Android. The reuse of previous inputs to allow stateful evaluation represents a new way of looking at SFE and further reduces computational barriers.
Norman Sadeh - One of the best experts on this subject based on the ideXlab platform.
-
user controllable learning of security and privacy policies
Proceedings of the 1st ACM workshop on Workshop on AISec, 2008Co-Authors: Patrick Gage Kelley, Norman Sadeh, Paul Hankes Drielsma, Lorrie Faith CranorAbstract:Studies have shown that users have great difficulty specifying their security and privacy policies in a variety of Application domains. While machine learning techniques have successfully been used to refine models of user preferences, such as in recommender systems, they are generally configured as "black boxes" that take control over the entire policy and severely restrict the ways in which the user can manipulate it. This article presents an alternative approach, referred to as user-controllable policy learning. It involves the incremental manipulation of policies in a context where system and user refine a common policy model. The user regularly provides feedback on decisions made based on the current policy. This feedback is used to identify (learn) incremental policy improvements which are presented as suggestions to the user. The user, in turn, can review these suggestions and decide which, if any, to accept. The incremental nature of the suggestions enhances usability, and because the user and the system manipulate a common policy representation, the user retains control and can still make policy modifications by hand. Results obtained using a neighborhood search implementation of this approach are presented in the context of data derived from the deployment of a friend Finder Application, where users can share their locations with others, subject to privacy policies they refine over time. We present results showing policy accuracy, which averages 60% upon initial definition by our users climbing as high as 90% using our technique.
-
Understanding and Capturing People’s Privacy Policies in a People Finder Application
2008Co-Authors: Norman Sadeh, Ian Fette, Madhu Prabaker, Jason Hong, Patrick Gage Kelley, Lorrie Faith Cranor, Jinghai RaoAbstract:s of CHI 2003, ACM Conference on Human Factors in Computing Systems. Fort Lauderdale, FL. pp. 724-725 2003. 20. Palen, L. and P. Dourish, Unpacking "Privacy" for a Networked World. CHI Letters (Human Factors in Computing Systems: CHI 2003), 2003. 5(1): p. 129-136. 21. Patil, S. and J. Lai. Who gets to know what when: configuring privacy permissions in an awareness Application. In Proceedings of The SIGCHI Conference on Human Factors in Computing Systems (CHI 2005). pp. 101-110 2005. 22. Priyantha, N.B., A. Chakraborty, and H. Balakrishnan. The Cricket Location-Support System. In Proceedings of MobiCom 2000: The Sixth Annual International Conference on Mobile Computing and Networking. Boston, Massachusetts: ACM Press. pp. 32-43 2000. 23. Rastogi, V., E. Walbourne, N. Khoussainova, R. Kriplean, M. Balazinska, G. Borriello, T. Kohno, and D. Suciu. Expressing Privacy Policies Using Authorization Views. In Proceedings of 9th International Conference on Ubiquitous Computing (Workshop on Privacy). Innsbruck, Austria, May 13-16, 2007 2007. 24. Sadeh, N., F. Gandon, and O.B. Kwon, Ambient Intelligence: The MyCampus Experience, in Ambient Intelligence and Pervasive Computing, T.V.a.W. Pedrycz, Editor. ArTech House, 2006. 25. Sohn, T., A. Varshavsky, A. LaMarca, M.Y. Chen, T. Choudhury, I. Smith, S. Consolvo, and W. Griswold. Mobility Detection Using Everyday GSM Traces. In Proceedings of 9th International Conference on Ubiquitous Computing (Ubicomp 2007). Irvine, CA 2006. 26. Tang, K.P., P. Keyani, J. Fogarty, and J.I. Hong. Putting people in their place: an anonymous and privacy-sensitive approach to collecting sensed data in location-based Applications. In Proceedings of Conference on Human Factors in Computing Systems. Montreal, Quebec, Canada: ACM Press, New York, NY. pp. 93-102 2006. http://doi.acm.org/10.1145/1124772.1124788 27. Want, R., A. Hopper, V. Falcao, and J. Gibbons, The Active Badge Location System. ACM Transactions on Information Systems 1992. 10(1): p. 91-102. 28. Wireless, S. http://www.skyhookwireless.com
-
understanding and capturing people s privacy policies in a people Finder Application
2008Co-Authors: Norman Sadeh, Ian Fette, Jason Hong, Patrick Gage Kelley, Lorrie Faith Cranor, Madhu PrabakerAbstract:s of CHI 2003, ACM Conference on Human Factors in Computing Systems. Fort Lauderdale, FL. pp. 724-725 2003. 20. Palen, L. and P. Dourish, Unpacking "Privacy" for a Networked World. CHI Letters (Human Factors in Computing Systems: CHI 2003), 2003. 5(1): p. 129-136. 21. Patil, S. and J. Lai. Who gets to know what when: configuring privacy permissions in an awareness Application. In Proceedings of The SIGCHI Conference on Human Factors in Computing Systems (CHI 2005). pp. 101-110 2005. 22. Priyantha, N.B., A. Chakraborty, and H. Balakrishnan. The Cricket Location-Support System. In Proceedings of MobiCom 2000: The Sixth Annual International Conference on Mobile Computing and Networking. Boston, Massachusetts: ACM Press. pp. 32-43 2000. 23. Rastogi, V., E. Walbourne, N. Khoussainova, R. Kriplean, M. Balazinska, G. Borriello, T. Kohno, and D. Suciu. Expressing Privacy Policies Using Authorization Views. In Proceedings of 9th International Conference on Ubiquitous Computing (Workshop on Privacy). Innsbruck, Austria, May 13-16, 2007 2007. 24. Sadeh, N., F. Gandon, and O.B. Kwon, Ambient Intelligence: The MyCampus Experience, in Ambient Intelligence and Pervasive Computing, T.V.a.W. Pedrycz, Editor. ArTech House, 2006. 25. Sohn, T., A. Varshavsky, A. LaMarca, M.Y. Chen, T. Choudhury, I. Smith, S. Consolvo, and W. Griswold. Mobility Detection Using Everyday GSM Traces. In Proceedings of 9th International Conference on Ubiquitous Computing (Ubicomp 2007). Irvine, CA 2006. 26. Tang, K.P., P. Keyani, J. Fogarty, and J.I. Hong. Putting people in their place: an anonymous and privacy-sensitive approach to collecting sensed data in location-based Applications. In Proceedings of Conference on Human Factors in Computing Systems. Montreal, Quebec, Canada: ACM Press, New York, NY. pp. 93-102 2006. http://doi.acm.org/10.1145/1124772.1124788 27. Want, R., A. Hopper, V. Falcao, and J. Gibbons, The Active Badge Location System. ACM Transactions on Information Systems 1992. 10(1): p. 91-102. 28. Wireless, S. http://www.skyhookwireless.com
-
AISec - User-controllable learning of security and privacy policies
Proceedings of the 1st ACM workshop on Workshop on AISec - AISec '08, 2008Co-Authors: Patrick Gage Kelley, Norman Sadeh, Paul Hankes Drielsma, Lorrie Faith CranorAbstract:Studies have shown that users have great difficulty specifying their security and privacy policies in a variety of Application domains. While machine learning techniques have successfully been used to refine models of user preferences, such as in recommender systems, they are generally configured as "black boxes" that take control over the entire policy and severely restrict the ways in which the user can manipulate it. This article presents an alternative approach, referred to as user-controllable policy learning. It involves the incremental manipulation of policies in a context where system and user refine a common policy model. The user regularly provides feedback on decisions made based on the current policy. This feedback is used to identify (learn) incremental policy improvements which are presented as suggestions to the user. The user, in turn, can review these suggestions and decide which, if any, to accept. The incremental nature of the suggestions enhances usability, and because the user and the system manipulate a common policy representation, the user retains control and can still make policy modifications by hand. Results obtained using a neighborhood search implementation of this approach are presented in the context of data derived from the deployment of a friend Finder Application, where users can share their locations with others, subject to privacy policies they refine over time. We present results showing policy accuracy, which averages 60% upon initial definition by our users climbing as high as 90% using our technique.
-
User-Controllable Security and Privacy for Pervasive Computing
Eighth IEEE Workshop on Mobile Computing Systems and Applications, 2007Co-Authors: Jason Cornwell, Bruce McLaren, Mike Reiter, Ian Fette, Jinghai Rao, Karen Tang, Kami Vaniea, Lujo Bauer, Madhu Prabaker, Gary Hsieh, Jason Hong, Lorrie Cranor, Norman SadehAbstract:We describe our current work in developing novel mechanisms for managing security and privacy in pervasive computing environments. More specifically, we have developed and evaluated three different Applications, including a contextual instant messenger, a people Finder Application, and a phone-based Application for access control. We also draw out some themes we have learned thus far for user-controllable security and privacy.
Lorrie Faith Cranor - One of the best experts on this subject based on the ideXlab platform.
-
user controllable learning of security and privacy policies
Proceedings of the 1st ACM workshop on Workshop on AISec, 2008Co-Authors: Patrick Gage Kelley, Norman Sadeh, Paul Hankes Drielsma, Lorrie Faith CranorAbstract:Studies have shown that users have great difficulty specifying their security and privacy policies in a variety of Application domains. While machine learning techniques have successfully been used to refine models of user preferences, such as in recommender systems, they are generally configured as "black boxes" that take control over the entire policy and severely restrict the ways in which the user can manipulate it. This article presents an alternative approach, referred to as user-controllable policy learning. It involves the incremental manipulation of policies in a context where system and user refine a common policy model. The user regularly provides feedback on decisions made based on the current policy. This feedback is used to identify (learn) incremental policy improvements which are presented as suggestions to the user. The user, in turn, can review these suggestions and decide which, if any, to accept. The incremental nature of the suggestions enhances usability, and because the user and the system manipulate a common policy representation, the user retains control and can still make policy modifications by hand. Results obtained using a neighborhood search implementation of this approach are presented in the context of data derived from the deployment of a friend Finder Application, where users can share their locations with others, subject to privacy policies they refine over time. We present results showing policy accuracy, which averages 60% upon initial definition by our users climbing as high as 90% using our technique.
-
Understanding and Capturing People’s Privacy Policies in a People Finder Application
2008Co-Authors: Norman Sadeh, Ian Fette, Madhu Prabaker, Jason Hong, Patrick Gage Kelley, Lorrie Faith Cranor, Jinghai RaoAbstract:s of CHI 2003, ACM Conference on Human Factors in Computing Systems. Fort Lauderdale, FL. pp. 724-725 2003. 20. Palen, L. and P. Dourish, Unpacking "Privacy" for a Networked World. CHI Letters (Human Factors in Computing Systems: CHI 2003), 2003. 5(1): p. 129-136. 21. Patil, S. and J. Lai. Who gets to know what when: configuring privacy permissions in an awareness Application. In Proceedings of The SIGCHI Conference on Human Factors in Computing Systems (CHI 2005). pp. 101-110 2005. 22. Priyantha, N.B., A. Chakraborty, and H. Balakrishnan. The Cricket Location-Support System. In Proceedings of MobiCom 2000: The Sixth Annual International Conference on Mobile Computing and Networking. Boston, Massachusetts: ACM Press. pp. 32-43 2000. 23. Rastogi, V., E. Walbourne, N. Khoussainova, R. Kriplean, M. Balazinska, G. Borriello, T. Kohno, and D. Suciu. Expressing Privacy Policies Using Authorization Views. In Proceedings of 9th International Conference on Ubiquitous Computing (Workshop on Privacy). Innsbruck, Austria, May 13-16, 2007 2007. 24. Sadeh, N., F. Gandon, and O.B. Kwon, Ambient Intelligence: The MyCampus Experience, in Ambient Intelligence and Pervasive Computing, T.V.a.W. Pedrycz, Editor. ArTech House, 2006. 25. Sohn, T., A. Varshavsky, A. LaMarca, M.Y. Chen, T. Choudhury, I. Smith, S. Consolvo, and W. Griswold. Mobility Detection Using Everyday GSM Traces. In Proceedings of 9th International Conference on Ubiquitous Computing (Ubicomp 2007). Irvine, CA 2006. 26. Tang, K.P., P. Keyani, J. Fogarty, and J.I. Hong. Putting people in their place: an anonymous and privacy-sensitive approach to collecting sensed data in location-based Applications. In Proceedings of Conference on Human Factors in Computing Systems. Montreal, Quebec, Canada: ACM Press, New York, NY. pp. 93-102 2006. http://doi.acm.org/10.1145/1124772.1124788 27. Want, R., A. Hopper, V. Falcao, and J. Gibbons, The Active Badge Location System. ACM Transactions on Information Systems 1992. 10(1): p. 91-102. 28. Wireless, S. http://www.skyhookwireless.com
-
understanding and capturing people s privacy policies in a people Finder Application
2008Co-Authors: Norman Sadeh, Ian Fette, Jason Hong, Patrick Gage Kelley, Lorrie Faith Cranor, Madhu PrabakerAbstract:s of CHI 2003, ACM Conference on Human Factors in Computing Systems. Fort Lauderdale, FL. pp. 724-725 2003. 20. Palen, L. and P. Dourish, Unpacking "Privacy" for a Networked World. CHI Letters (Human Factors in Computing Systems: CHI 2003), 2003. 5(1): p. 129-136. 21. Patil, S. and J. Lai. Who gets to know what when: configuring privacy permissions in an awareness Application. In Proceedings of The SIGCHI Conference on Human Factors in Computing Systems (CHI 2005). pp. 101-110 2005. 22. Priyantha, N.B., A. Chakraborty, and H. Balakrishnan. The Cricket Location-Support System. In Proceedings of MobiCom 2000: The Sixth Annual International Conference on Mobile Computing and Networking. Boston, Massachusetts: ACM Press. pp. 32-43 2000. 23. Rastogi, V., E. Walbourne, N. Khoussainova, R. Kriplean, M. Balazinska, G. Borriello, T. Kohno, and D. Suciu. Expressing Privacy Policies Using Authorization Views. In Proceedings of 9th International Conference on Ubiquitous Computing (Workshop on Privacy). Innsbruck, Austria, May 13-16, 2007 2007. 24. Sadeh, N., F. Gandon, and O.B. Kwon, Ambient Intelligence: The MyCampus Experience, in Ambient Intelligence and Pervasive Computing, T.V.a.W. Pedrycz, Editor. ArTech House, 2006. 25. Sohn, T., A. Varshavsky, A. LaMarca, M.Y. Chen, T. Choudhury, I. Smith, S. Consolvo, and W. Griswold. Mobility Detection Using Everyday GSM Traces. In Proceedings of 9th International Conference on Ubiquitous Computing (Ubicomp 2007). Irvine, CA 2006. 26. Tang, K.P., P. Keyani, J. Fogarty, and J.I. Hong. Putting people in their place: an anonymous and privacy-sensitive approach to collecting sensed data in location-based Applications. In Proceedings of Conference on Human Factors in Computing Systems. Montreal, Quebec, Canada: ACM Press, New York, NY. pp. 93-102 2006. http://doi.acm.org/10.1145/1124772.1124788 27. Want, R., A. Hopper, V. Falcao, and J. Gibbons, The Active Badge Location System. ACM Transactions on Information Systems 1992. 10(1): p. 91-102. 28. Wireless, S. http://www.skyhookwireless.com
-
AISec - User-controllable learning of security and privacy policies
Proceedings of the 1st ACM workshop on Workshop on AISec - AISec '08, 2008Co-Authors: Patrick Gage Kelley, Norman Sadeh, Paul Hankes Drielsma, Lorrie Faith CranorAbstract:Studies have shown that users have great difficulty specifying their security and privacy policies in a variety of Application domains. While machine learning techniques have successfully been used to refine models of user preferences, such as in recommender systems, they are generally configured as "black boxes" that take control over the entire policy and severely restrict the ways in which the user can manipulate it. This article presents an alternative approach, referred to as user-controllable policy learning. It involves the incremental manipulation of policies in a context where system and user refine a common policy model. The user regularly provides feedback on decisions made based on the current policy. This feedback is used to identify (learn) incremental policy improvements which are presented as suggestions to the user. The user, in turn, can review these suggestions and decide which, if any, to accept. The incremental nature of the suggestions enhances usability, and because the user and the system manipulate a common policy representation, the user retains control and can still make policy modifications by hand. Results obtained using a neighborhood search implementation of this approach are presented in the context of data derived from the deployment of a friend Finder Application, where users can share their locations with others, subject to privacy policies they refine over time. We present results showing policy accuracy, which averages 60% upon initial definition by our users climbing as high as 90% using our technique.
-
HotMobile - User-Controllable Security and Privacy for Pervasive Computing
Eighth IEEE Workshop on Mobile Computing Systems and Applications, 2007Co-Authors: Jason Cornwell, Ian Fette, Jinghai Rao, Kami Vaniea, Lujo Bauer, Madhu Prabaker, Gary Hsieh, Lorrie Faith Cranor, Karen P. Tang, Jason HongAbstract:We describe our current work in developing novel mechanisms for managing security and privacy in pervasive computing environments. More specifically, we have developed and evaluated three different Applications, including a contextual instant messenger, a people Finder Application, and a phone-based Application for access control. We also draw out some themes we have learned thus far for user-controllable security and privacy.
Jason Hong - One of the best experts on this subject based on the ideXlab platform.
-
Understanding and Capturing People’s Privacy Policies in a People Finder Application
2008Co-Authors: Norman Sadeh, Ian Fette, Madhu Prabaker, Jason Hong, Patrick Gage Kelley, Lorrie Faith Cranor, Jinghai RaoAbstract:s of CHI 2003, ACM Conference on Human Factors in Computing Systems. Fort Lauderdale, FL. pp. 724-725 2003. 20. Palen, L. and P. Dourish, Unpacking "Privacy" for a Networked World. CHI Letters (Human Factors in Computing Systems: CHI 2003), 2003. 5(1): p. 129-136. 21. Patil, S. and J. Lai. Who gets to know what when: configuring privacy permissions in an awareness Application. In Proceedings of The SIGCHI Conference on Human Factors in Computing Systems (CHI 2005). pp. 101-110 2005. 22. Priyantha, N.B., A. Chakraborty, and H. Balakrishnan. The Cricket Location-Support System. In Proceedings of MobiCom 2000: The Sixth Annual International Conference on Mobile Computing and Networking. Boston, Massachusetts: ACM Press. pp. 32-43 2000. 23. Rastogi, V., E. Walbourne, N. Khoussainova, R. Kriplean, M. Balazinska, G. Borriello, T. Kohno, and D. Suciu. Expressing Privacy Policies Using Authorization Views. In Proceedings of 9th International Conference on Ubiquitous Computing (Workshop on Privacy). Innsbruck, Austria, May 13-16, 2007 2007. 24. Sadeh, N., F. Gandon, and O.B. Kwon, Ambient Intelligence: The MyCampus Experience, in Ambient Intelligence and Pervasive Computing, T.V.a.W. Pedrycz, Editor. ArTech House, 2006. 25. Sohn, T., A. Varshavsky, A. LaMarca, M.Y. Chen, T. Choudhury, I. Smith, S. Consolvo, and W. Griswold. Mobility Detection Using Everyday GSM Traces. In Proceedings of 9th International Conference on Ubiquitous Computing (Ubicomp 2007). Irvine, CA 2006. 26. Tang, K.P., P. Keyani, J. Fogarty, and J.I. Hong. Putting people in their place: an anonymous and privacy-sensitive approach to collecting sensed data in location-based Applications. In Proceedings of Conference on Human Factors in Computing Systems. Montreal, Quebec, Canada: ACM Press, New York, NY. pp. 93-102 2006. http://doi.acm.org/10.1145/1124772.1124788 27. Want, R., A. Hopper, V. Falcao, and J. Gibbons, The Active Badge Location System. ACM Transactions on Information Systems 1992. 10(1): p. 91-102. 28. Wireless, S. http://www.skyhookwireless.com
-
understanding and capturing people s privacy policies in a people Finder Application
2008Co-Authors: Norman Sadeh, Ian Fette, Jason Hong, Patrick Gage Kelley, Lorrie Faith Cranor, Madhu PrabakerAbstract:s of CHI 2003, ACM Conference on Human Factors in Computing Systems. Fort Lauderdale, FL. pp. 724-725 2003. 20. Palen, L. and P. Dourish, Unpacking "Privacy" for a Networked World. CHI Letters (Human Factors in Computing Systems: CHI 2003), 2003. 5(1): p. 129-136. 21. Patil, S. and J. Lai. Who gets to know what when: configuring privacy permissions in an awareness Application. In Proceedings of The SIGCHI Conference on Human Factors in Computing Systems (CHI 2005). pp. 101-110 2005. 22. Priyantha, N.B., A. Chakraborty, and H. Balakrishnan. The Cricket Location-Support System. In Proceedings of MobiCom 2000: The Sixth Annual International Conference on Mobile Computing and Networking. Boston, Massachusetts: ACM Press. pp. 32-43 2000. 23. Rastogi, V., E. Walbourne, N. Khoussainova, R. Kriplean, M. Balazinska, G. Borriello, T. Kohno, and D. Suciu. Expressing Privacy Policies Using Authorization Views. In Proceedings of 9th International Conference on Ubiquitous Computing (Workshop on Privacy). Innsbruck, Austria, May 13-16, 2007 2007. 24. Sadeh, N., F. Gandon, and O.B. Kwon, Ambient Intelligence: The MyCampus Experience, in Ambient Intelligence and Pervasive Computing, T.V.a.W. Pedrycz, Editor. ArTech House, 2006. 25. Sohn, T., A. Varshavsky, A. LaMarca, M.Y. Chen, T. Choudhury, I. Smith, S. Consolvo, and W. Griswold. Mobility Detection Using Everyday GSM Traces. In Proceedings of 9th International Conference on Ubiquitous Computing (Ubicomp 2007). Irvine, CA 2006. 26. Tang, K.P., P. Keyani, J. Fogarty, and J.I. Hong. Putting people in their place: an anonymous and privacy-sensitive approach to collecting sensed data in location-based Applications. In Proceedings of Conference on Human Factors in Computing Systems. Montreal, Quebec, Canada: ACM Press, New York, NY. pp. 93-102 2006. http://doi.acm.org/10.1145/1124772.1124788 27. Want, R., A. Hopper, V. Falcao, and J. Gibbons, The Active Badge Location System. ACM Transactions on Information Systems 1992. 10(1): p. 91-102. 28. Wireless, S. http://www.skyhookwireless.com
-
User-Controllable Security and Privacy for Pervasive Computing
Eighth IEEE Workshop on Mobile Computing Systems and Applications, 2007Co-Authors: Jason Cornwell, Bruce McLaren, Mike Reiter, Ian Fette, Jinghai Rao, Karen Tang, Kami Vaniea, Lujo Bauer, Madhu Prabaker, Gary Hsieh, Jason Hong, Lorrie Cranor, Norman SadehAbstract:We describe our current work in developing novel mechanisms for managing security and privacy in pervasive computing environments. More specifically, we have developed and evaluated three different Applications, including a contextual instant messenger, a people Finder Application, and a phone-based Application for access control. We also draw out some themes we have learned thus far for user-controllable security and privacy.
-
HotMobile - User-Controllable Security and Privacy for Pervasive Computing
Eighth IEEE Workshop on Mobile Computing Systems and Applications, 2007Co-Authors: Jason Cornwell, Ian Fette, Jinghai Rao, Kami Vaniea, Lujo Bauer, Madhu Prabaker, Gary Hsieh, Lorrie Faith Cranor, Karen P. Tang, Jason HongAbstract:We describe our current work in developing novel mechanisms for managing security and privacy in pervasive computing environments. More specifically, we have developed and evaluated three different Applications, including a contextual instant messenger, a people Finder Application, and a phone-based Application for access control. We also draw out some themes we have learned thus far for user-controllable security and privacy.
Benjamin Mood - One of the best experts on this subject based on the ideXlab platform.
-
Reuse It Or Lose It: More Efficient Secure Computation Through Reuse of Encrypted Values
arXiv: Cryptography and Security, 2015Co-Authors: Benjamin Mood, Debayan Gupta, Kevin R. B. Butler, Joan FeigenbaumAbstract:Two-party secure function evaluation (SFE) has become significantly more feasible, even on resource-constrained devices, because of advances in server-aided computation systems. However, there are still bottlenecks, particularly in the input validation stage of a computation. Moreover, SFE research has not yet devoted sufficient attention to the important problem of retaining state after a computation has been performed so that expensive processing does not have to be repeated if a similar computation is done again. This paper presents PartialGC, an SFE system that allows the reuse of encrypted values generated during a garbled-circuit computation. We show that using PartialGC can reduce computation time by as much as 96% and bandwidth by as much as 98% in comparison with previous outsourcing schemes for secure computation. We demonstrate the feasibility of our approach with two sets of experiments, one in which the garbled circuit is evaluated on a mobile device and one in which it is evaluated on a server. We also use PartialGC to build a privacy-preserving "friend Finder" Application for Android. The reuse of previous inputs to allow stateful evaluation represents a new way of looking at SFE and further reduces computational barriers.
-
ACM Conference on Computer and Communications Security - Reuse It Or Lose It: More Efficient Secure Computation Through Reuse of Encrypted Values
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, 2014Co-Authors: Benjamin Mood, Debayan Gupta, Kevin R. B. Butler, Joan FeigenbaumAbstract:Two-party secure-function evaluation (SFE) has become significantly more feasible, even on resource-constrained devices, because of advances in server-aided computation systems. However, there are still bottlenecks, particularly in the input-validation stage of a computation. Moreover, SFE research has not yet devoted sufficient attention to the important problem of retaining state after a computation has been performed so that expensive processing does not have to be repeated if a similar computation is done again. This paper presents PartialGC, an SFE system that allows the reuse of encrypted values generated during a garbled-circuit computation. We show that using PartialGC can reduce computation time by as much as 96% and bandwidth by as much as 98% in comparison with previous outsourcing schemes for secure computation. We demonstrate the feasibility of our approach with two sets of experiments, one in which the garbled circuit is evaluated on a mobile device and one in which it is evaluated on a server. We also use PartialGC to build a privacy-preserving ``friend-Finder'' Application for Android. The reuse of previous inputs to allow stateful evaluation represents a new way of looking at SFE and further reduces computational barriers.