Privacy Preserving Web-Based Email

被引:0
|
作者
Butler, Kevin R. B. [1 ]
Enck, William [1 ]
Traynor, Patrick [1 ]
Plasterr, Jennifer [1 ]
McDaniel, Patrick D. [1 ]
机构
[1] Penn State Univ, Syst & Informat Infrastruct Secur Lab, University Pk, PA 16802 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent web-based applications offer users free service in exchange for access to personal communication, such as on-line email services and instant messaging. The inspection and retention of user communication is generally intended to enable targeted marketing. However, unless specifically stated otherwise by the collecting service's privacy policy, such records have an indefinite lifetime and may be later used or sold without restriction. In this paper, we show that it is possible to protect a user's privacy from these risks by exploiting mutually oblivious, competing communication channels. We create virtual channels over online services (e.g., Google's Gmail, Microsoft's Hotmail) through which messages and cryptographic keys are delivered. The message recipient uses a shared secret to identify the shares and ultimately recover the original plaintext. In so doing, we create a wired "spread-spectrum" mechanism for protecting the privacy of web-based communication. We discuss the design and implementation of our open-source Java applet, Aquinas, and consider ways that the myriad of communication channels present on the Internet can be exploited to preserve privacy.
引用
收藏
页码:349 / 371
页数:23
相关论文
共 50 条
  • [1] Privacy preserving web-based email
    Butler, Kevin
    Enck, William
    Plasterr, Jennifer
    Traynor, Patrick
    McDaniel, Patrick
    [J]. INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2006, 4332 : 116 - +
  • [2] Privacy preserving web-based questionnaire
    Nakazato, J
    Fujimoto, K
    Kikuchi, H
    [J]. AINA 2005: 19th International Conference on Advanced Information Networking and Applications, Vol 2, 2005, : 285 - 288
  • [3] An approach for realizing privacy-preserving web-based services
    [J]. Xu, W. (weixu@cs.sunysb.edu), 1600, World Wide Web Consortium (W3C); Hitachi, Ltd.; NEC; Yahoo; Fuji Xerox Co., Ltd. (Association for Computing Machinery, 1515 Broadway, 17th Floor, New York, NY 10036-5701, United States):
  • [4] PPTP: Privacy-Preserving Traffic Padding in Web-Based Applications
    Liu, Wen Ming
    Wang, Lingyu
    Cheng, Pengsu
    Ren, Kui
    Zhu, Shunzhi
    Debbabi, Mourad
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2014, 11 (06) : 538 - 552
  • [5] Classification of web-based email traffic in Thailand
    Pukkawanna, Sirikam
    Visoottiviseth, Vasaka
    Pongpaibool, Panita
    [J]. 2006 INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES,VOLS 1-3, 2006, : 490 - +
  • [6] Privacy-preserving email forensics
    Armknecht, Frederik
    Dewald, Andreas
    [J]. DIGITAL INVESTIGATION, 2015, 14 : S127 - S136
  • [7] Background Knowledge-Resistant Traffic Padding for Preserving User Privacy in Web-Based Applications
    Liu, Wen Ming
    Wang, Lingyu
    Ren, Kui
    Debbabi, Mourad
    [J]. 2013 IEEE FIFTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), VOL 1, 2013, : 679 - 686
  • [8] A Web-based and email driven electronic contract management system
    Kwok, Thomas
    Nguyen, Thao
    Lam, Linh
    Chieu, Trieu
    [J]. ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 149 - 156
  • [9] Analysing Privacy Conflicts in Web-Based Systems
    Inglis, Peter
    Omoronyia, Inah
    [J]. 29TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2021), 2021, : 430 - 431
  • [10] Web-based practical privacy-preserving distributed image storage for financial services in cloud computing
    Xiaohong, Cai
    Yi, Sun
    Zhaowen, Lin
    Imran, Muhammad
    Keping, Yu
    [J]. WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2023, 26 (03): : 1223 - 1241