Top Banner
Enhancing Security and Privacy in Online Social Networks Sonia Jahid [email protected] University of Illinois at Urbana-Champaign PhD Forum
15

Enhancing Security and Privacy in Online Social Networks Sonia Jahid [email protected] University of Illinois at Urbana-Champaign PhD Forum.

Jan 05, 2016

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Enhancing Security and Privacy in Online

Social Networks

Sonia [email protected]

University of Illinois at Urbana-Champaign

PhD Forum

Page 2: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Online Social Network (OSN)

Page 3: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Motivating Examples

Page 4: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Our Goal …

A Private and Secure Online Social NetworkA Private and Secure Online Social Network

Shift the access enforcement point from the provider to the users

Shift the access enforcement point from the provider to the users

4

Page 5: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Decentralization

ProviderProvider Trusted Party

Myself

Hybrid

Untrusted Party

• Availability• Access control by others• Confidentiality/Integrity• Malicious activities

Page 6: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

WallWallStatusStatus

CommentComment

VideoVideo

LinkLink

Complicated OSN Data

and Access Control

Complicated OSN Data

and Access Control

Page 7: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

• Access Control– Attribute-based encryption with efficient

revocation

• Architecture Design– Distributed hash table– Object oriented data– Efficient algorithm for newsfeed

Our Contribution

7

EASiER – ASIACCS 2011, DECENT – SESOC 2012, CACHET – CoNEXT 2012

Page 8: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Example

GHC Rocks!

Friend|Alice|Friend

Reference

Alice’s Status

Bob’s Comment

Read

Write/Delete

Append

Page 9: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Application?

Page 10: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Our Goal

• Health Information Exchange– Patient-centric health data through a secure

distributed storage service

10

Page 11: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Challenges

• Confidentiality, Integrity, Availability• Private Audit• Anonymous search• Break the glass policy

11

Page 12: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Private Audit

• Properties– Authentication– Access Control– Auditing– Anonymity

• Concept– Revocable

Anonymity

StorageStorage

Data

Data

Access

Access

A0danc*#-3948sk3m4lksfmÂp

A0danc*#-3948sk3m4lksfmÂp

Logging Information

12

Doctor

Nurse

Page 13: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Anonymous Search

• Properties– Anonymity– Efficiency– Correctness

• Concept– Public Key Encryption

Keyword-based search– Private Information

Retrieval

StorageStorage

Alice, Lab

13

Page 14: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Break the Glass Policy

• Properties– Emergency access on

data– Auditing

Alice’s Data

Alice’s Data

14

Page 15: Enhancing Security and Privacy in Online Social Networks Sonia Jahid sjahid2@illinois.edu University of Illinois at Urbana-Champaign PhD Forum.

Research Summary

• Techniques to enhance security and privacy of a social network

• Challenges and application of such techniques in healthcare domain

Sonia Jahidhttp://[email protected]

15