PFirewall: Semantics-Aware Customizable Data Flow Control for Smart Home Privacy Protection

01/26/2021
by   Haotian Chi, et al.
0

Internet of Things (IoT) platforms enable users to deploy home automation applications. Meanwhile, privacy issues arise as large amounts of sensitive device data flow out to IoT platforms. Most of the data flowing out to a platform actually do not trigger automation actions, while homeowners currently have no control once devices are bound to the platform. We present PFirewall, a customizable data-flow control system to enhance the privacy of IoT platform users. PFirewall automatically generates data-minimization policies, which only disclose minimum amount of data to fulfill automation. In addition, PFirewall provides interfaces for homeowners to customize individual privacy preferences by defining user-specified policies. To enforce these policies, PFirewall transparently intervenes and mediates the communication between IoT devices and the platform, without modifying the platform, IoT devices, or hub. Evaluation results on four real-world testbeds show that PFirewall reduces IoT data sent to the platform by 97 mitigates user-activity inference/tracking attacks and other privacy risks.

READ FULL TEXT

page 14

page 18

research
10/17/2019

PFirewall: Semantics-Aware Customizable Data Flow Control for Home Automation Systems

Emerging Internet of Thing (IoT) platforms provide a convenient solution...
research
06/11/2020

Sovereign: User-Controlled Smart Homes

Smart homes made up of Internet of Things (IoT) devices have seen wide d...
research
08/11/2023

Tapping into Privacy: A Study of User Preferences and Concerns on Trigger-Action Platforms

The Internet of Things (IoT) devices are rapidly increasing in popularit...
research
03/10/2020

IoT Expunge: Implementing Verifiable Retention of IoT Data

The growing deployment of Internet of Things (IoT) systems aims to ease ...
research
09/26/2018

Brokering Policies and Execution Monitors for IoT Middleware

Event-based systems lie at the heart of many cloud-based Internet-of-Thi...
research
01/04/2022

OConsent – Open Consent Protocol for Privacy and Consent Management with Blockchain

In the current connected world - Websites, Mobile Apps, IoT Devices coll...
research
04/13/2019

Automatic Device Selection and Access PolicyGeneration based on User Preference for IoTActivity Workflow

The emerging Internet of Things (IoT) has lead to a dramatic increase in...

Please sign up or login with your details

Forgot password? Click here to reset