Skip to main content
QUICK REVIEW

[论文解读] Location Privacy in Mobile Edge Clouds: A Chaff-based Approach

Ting He, Ertuğrul Necdet Çiftçioğlu|arXiv (Cornell University)|Sep 10, 2017
Privacy-Preserving Technologies in Data参考文献 18被引用 3
一句话总结

本文提出一种基于碎屑(chaff)的防御机制,用于保护移动边缘云(MECs)中的用户位置隐私,其中攻击者可通过监控服务在MECs间的迁移来追踪用户。通过战略性地部署模仿合法用户移动模式的碎屑服务,最优策略可在用户移动足够随机时,使攻击者的追踪准确率降为零,即使面对使用最大似然检测的高级攻击者亦如此。

ABSTRACT

In this paper, we consider user location privacy in mobile edge clouds (MECs). MECs are small clouds deployed at the network edge to offer cloud services close to mobile users, and many solutions have been proposed to maximize service locality by migrating services to follow their users. Co-location of a user and his service, however, implies that a cyber eavesdropper observing service migrations between MECs can localize the user up to one MEC coverage area, which can be fairly small (e.g., a femtocell). We consider using chaff services to defend against such an eavesdropper, with focus on strategies to control the chaffs. Assuming the eavesdropper performs maximum likelihood (ML) detection, we consider both heuristic strategies that mimic the user's mobility and optimized strategies designed to minimize the detection or tracking accuracy. We show that a single chaff controlled by the optimal strategy or its online variation can drive the eavesdropper's tracking accuracy to zero when the user's mobility is sufficiently random. We further propose extended strategies that utilize randomization to defend against an advanced eavesdropper aware of the strategy. The efficacy of our solutions is verified through both synthetic and trace-driven simulations.

研究动机与目标

  • 解决移动边缘云中的网络监听威胁,即通过侧信道监控服务迁移暴露用户位置的问题。
  • 在MEC提供商不可信、可能监控服务迁移的情况下,保护用户位置隐私。
  • 设计碎屑服务策略,以最小化攻击者使用最大似然检测识别真实用户的能力。
  • 增强对已知晓碎屑策略并可自适应调整的高级攻击者的防御能力。

提出的方法

  • 作者将用户移动建模为马尔可夫链,并利用其生成模仿真实用户移动模式的碎屑服务轨迹。
  • 提出启发式策略(IM、ML、OO、MO)以及基于求解马尔可夫决策过程(MDP)的最优策略,以最小化检测准确率。
  • 通过动态规划推导最优策略,以最小化攻击者正确识别真实用户的可能性。
  • 提出最优策略的在线变体,以实现实时部署,无需预先知晓未来移动情况。
  • 通过随机化设计鲁棒策略(RML、ROO),以防御已知晓碎屑策略的攻击者。
  • 性能评估基于合成移动模型和真实出租车轨迹数据,包含959个Voronoi单元和174条用户轨迹。

实验结果

研究问题

  • RQ1碎屑服务能否有效隐藏用户真实位置,使其不被监控MEC间服务迁移的攻击者发现?
  • RQ2在何种条件下,最优碎屑策略可使攻击者的追踪准确率降为零?
  • RQ3在不同用户移动模型下(包括空间和时间上分布不均的模式),碎屑策略的性能如何变化?
  • RQ4鲁棒碎屑策略能否有效防御已知晓碎屑部署策略的高级攻击者?
  • RQ5碎屑服务数量如何影响隐私保护与系统成本之间的权衡?

主要发现

  • 当用户移动具有足够熵时,最优碎屑策略及其在线变体可使攻击者的追踪准确率降为零。
  • 在基础攻击者使用最大似然检测的情况下,ML和OO策略即使仅使用一个碎屑,也能显著降低追踪准确率,优于基线。
  • 当用户轨迹主导了短视路径的似然性时,MO策略表现不佳,因其未能偏离最大似然位置。
  • 当使用两个碎屑时,原始策略(IM、ML、OO、MO)对高级攻击者失效,但鲁棒策略RML和ROO能显著降低追踪准确率。
  • 基于真实出租车移动数据的追踪仿真结果表明,所提策略在空间和时间分布不均的移动环境中仍能保持高水平的隐私保护。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。