{"title":"物联网应用中的数据和位置隐私问题","authors":"Amani Abuladel, O. Bamasag","doi":"10.1109/ICCAIS48893.2020.9096837","DOIUrl":null,"url":null,"abstract":"The Internet of Things (IoT) is an innovative interconnected framework where all objects can interact with each other and with other people. It enhances the quality of life, business growth and efficiency in multiple domains. However, the heterogeneity of the \"Things\" that can be associated in such conditions makes interoperability among them a difficult issue. Moreover, the data exchanged between IoT system components are normally not protected. This leads to users losing their privacy, hence, making it difficult to share and reuse data for purposes other than what they were originally set up for. In this paper, we address these challenges in the context of IoT applications considering user’s data and location privacy as not to be shared between these ‘Things’. We first describe two use case scenarios of IoT users in healthcare applications. The first scenario describes an attacker capturing the data traveling from/to the server. The second scenario describes the case of a server acting as a malicious party (i.e., an attacker). The two scenarios highlight data and location privacy issues of IoT users. Based on the use-case scenarios, the paper presents a generic framework for IoT data and location privacy, including a description of entities and interactions among them. The paper then analyzes potential privacy threats in this framework, in order to identify a set of general privacy requirements, with an emphasis on data and location privacy. These requirements will provide guidance to future solutions for secure IoT communication and/or risk assessment.","PeriodicalId":422184,"journal":{"name":"2020 3rd International Conference on Computer Applications & Information Security (ICCAIS)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Data and Location Privacy Issues in IoT Applications\",\"authors\":\"Amani Abuladel, O. Bamasag\",\"doi\":\"10.1109/ICCAIS48893.2020.9096837\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Internet of Things (IoT) is an innovative interconnected framework where all objects can interact with each other and with other people. It enhances the quality of life, business growth and efficiency in multiple domains. However, the heterogeneity of the \\\"Things\\\" that can be associated in such conditions makes interoperability among them a difficult issue. Moreover, the data exchanged between IoT system components are normally not protected. This leads to users losing their privacy, hence, making it difficult to share and reuse data for purposes other than what they were originally set up for. In this paper, we address these challenges in the context of IoT applications considering user’s data and location privacy as not to be shared between these ‘Things’. We first describe two use case scenarios of IoT users in healthcare applications. The first scenario describes an attacker capturing the data traveling from/to the server. The second scenario describes the case of a server acting as a malicious party (i.e., an attacker). The two scenarios highlight data and location privacy issues of IoT users. Based on the use-case scenarios, the paper presents a generic framework for IoT data and location privacy, including a description of entities and interactions among them. The paper then analyzes potential privacy threats in this framework, in order to identify a set of general privacy requirements, with an emphasis on data and location privacy. These requirements will provide guidance to future solutions for secure IoT communication and/or risk assessment.\",\"PeriodicalId\":422184,\"journal\":{\"name\":\"2020 3rd International Conference on Computer Applications & Information Security (ICCAIS)\",\"volume\":\"9 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 3rd International Conference on Computer Applications & Information Security (ICCAIS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCAIS48893.2020.9096837\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 3rd International Conference on Computer Applications & Information Security (ICCAIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCAIS48893.2020.9096837","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Data and Location Privacy Issues in IoT Applications
The Internet of Things (IoT) is an innovative interconnected framework where all objects can interact with each other and with other people. It enhances the quality of life, business growth and efficiency in multiple domains. However, the heterogeneity of the "Things" that can be associated in such conditions makes interoperability among them a difficult issue. Moreover, the data exchanged between IoT system components are normally not protected. This leads to users losing their privacy, hence, making it difficult to share and reuse data for purposes other than what they were originally set up for. In this paper, we address these challenges in the context of IoT applications considering user’s data and location privacy as not to be shared between these ‘Things’. We first describe two use case scenarios of IoT users in healthcare applications. The first scenario describes an attacker capturing the data traveling from/to the server. The second scenario describes the case of a server acting as a malicious party (i.e., an attacker). The two scenarios highlight data and location privacy issues of IoT users. Based on the use-case scenarios, the paper presents a generic framework for IoT data and location privacy, including a description of entities and interactions among them. The paper then analyzes potential privacy threats in this framework, in order to identify a set of general privacy requirements, with an emphasis on data and location privacy. These requirements will provide guidance to future solutions for secure IoT communication and/or risk assessment.