Page 452 - 《软件学报》2026年第2期
P. 452

张源 等: 以用户为中心的云辅助跨应用数据安全流转                                                        931


                    由于  CADC  在数据检索阶段对数据文件进行加解密时使用已授权设备的短效公私钥对完成, 这意味着在设
                 备短效公私钥对到期后, 需要对数据密文进行及时更新, 在应用过程中可能会造成额外的计算和通信开销; 此外,
                 在  CADC  的安全模型中没有考虑在线         DGA  和在线  KGA. 在未来的工作中, 我们将继续深入研究提高数据外包系
                 统效率, 保证数据跨应用流转安全性的方法.


                 References
                  [1]   Khedker U, Sanyal A, Sathe B. Data Flow Analysis: Theory and Practice. Boca Raton: CRC Press, 2009. [doi: 10.1201/9780849332517]
                  [2]   Pasquier TFJM, Singh J, Eyers D, Bacon J. CamFlow: Managed data-sharing for cloud services. IEEE Trans. on Cloud Computing, 2017,
                     5(3): 472–484. [doi: 10.1109/TCC.2015.2489211]
                  [3]   Crooks N. Efficient data sharing across trust domains. ACM SIGMOD Record, 2023, 52(2): 36–37. [doi: 10.1145/3615952.3615962]
                  [4]   van Kleek M, Liccardi I, Binns R, Zhao J, Weitzner DJ, Shadbolt N. Better the devil you know: Exposing the data sharing practices of
                     smartphone Apps. In: Proc. of the 2017 CHI Conf. on Human Factors in Computing Systems. Denver: ACM, 2017. 5208–5220. [doi: 10.
                     1145/3025453.3025556]
                  [5]   Zhang Y, Xu CX, Li HW, Yang K, Cheng N, Shen XM. PROTECT: Efficient password-based threshold single-sign-on authentication for
                     mobile users against perpetual leakage. IEEE Trans. on Mobile Computing, 2021, 20(6): 2297–2312. [doi: 10.1109/TMC.2020.2975792]
                  [6]   Zhang Y, Xu CX, Ni JB, Li HW, Shen XS. Blockchain-assisted public-key encryption with keyword search against keyword guessing
                     attacks for cloud storage. IEEE Trans. on Cloud Computing, 2021, 9(4): 1335–1348. [doi: 10.1109/TCC.2019.2923222]
                  [7]   Brandtzaeg PB, Pultier A, Moen GM. Losing control to data-hungry Apps: A mixed-methods approach to mobile App privacy. Social
                     Science Computer Review, 2019, 37(4): 466–488. [doi: 10.1177/0894439318777706]
                  [8]   Yu DJ, Wang JJ, Liu CF. Approach to optimal staff assignment in workflows based on collaboration patterns. Ruan Jian Xue Bao/Journal
                     of Software, 2018, 29(11): 3340–3354 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/5483.htm [doi: 10.13328/j.
                     cnki.jos.005483]
                  [9]   Huckvale K, Torous J, Larsen ME. Assessment of the data sharing and privacy practices of smartphone Apps for depression and smoking
                     cessation. JAMA Network Open, 2019, 2(4): e192542. [doi: 10.1001/jamanetworkopen.2019.2542]
                 [10]   Wang Y, Fan M, Tao JJ, Lei JY, Jin WX, Han DQ, Liu T. Compliance detection method for mobile application privacy policy statement.
                     Ruan Jian Xue Bao/Journal of Software, 2024, 35(8): 3668–3683 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
                     7121.htm [doi: 10.13328/j.cnki.jos.007121]
                 [11]   Jobe W. Native Apps vs. mobile Web Apps. Int’l Journal of Interactive Mobile Technologies, 2013, 7(4): 27–32. [doi: 10.3991/ijim.v7i4.
                     3226]
                 [12]   Zimmeck S, Story P, Smullen D, Ravichander A, Wang ZQ, Reidenberg J, Russell NC, Sadeh N. MAPS: Scaling privacy compliance
                     analysis to a million Apps. Proc. on Privacy Enhancing Technologies, 2019, 2019(3): 66–86. [doi: 10.2478/popets-2019-0037]
                 [13]   Dell’Amico M, Michiardi P, Roudier Y. Password strength: An empirical analysis. In: Proc. of the 2010 IEEE INFOCOM. San Diego:
                     IEEE, 2010. 1–9. [doi: 10.1109/INFCOM.2010.5461951]
                 [14]   Iqbal U, Wolfe C, Nguyen C, Englehardt S, Shafiq Z. Khaleesi: Breaker of advertising and tracking request chains. In: Proc. of the 31st
                     USENIX Security Symp. Boston: USENIX Association, 2022. 2911–2928.
                 [15]   Wu JR, Nan YH, Xing LY, Cheng JT, Lin ZM, Zheng ZB, Yang M. Leaking the privacy of groups and more: Understanding privacy
                     risks of cross-App content sharing in mobile ecosystem. In: Proc. of the 2024 Network and Distributed System Security Symp. (NDSS).
                     San Diego, 2024. [doi: 10.14722/ndss.2024.24138]
                 [16]   Wu LB, Wang J, Choo KKR, He DB. Secure key agreement and key protection for mobile device user authentication. IEEE Trans. on
                     Information Forensics and Security, 2019, 14(2): 319–330. [doi: 10.1109/TIFS.2018.2850299]
                 [17]   Das A, Bonneau J, Caesar M, Borisov N, Wang XF. The tangled Web of password reuse. In: Proc. of the 2014 Network and Distributed
                     System Security. San Diego, 2014. [doi: 10.14722/ndss.2014.23357]
                 [18]   Ma J, Yang WN, Luo M, Li NH. A study of probabilistic password models. In: Proc. of the 2014 IEEE Symp. on Security and Privacy.
                     Berkeley: IEEE, 2014. 689–704. [doi: 10.1109/SP.2014.50]
                 [19]   Gao G, Zhang Y, Song YQ, Li SY. PrivSSO: Practical single-sign-on authentication against subscription/access pattern leakage. IEEE
                     Trans. on Information Forensics and Security, 2024, 19: 5075–5089. [doi: 10.1109/TIFS.2024.3392533]
                 [20]   Song DX, Wagner D, Perrig A. Practical techniques for searches on encrypted data. In: Proc. of the 2000 IEEE Symp. on Security and
                     Privacy. Berkeley: IEEE, 2000. 44–55. [doi: 10.1109/SECPRI.2000.848445]
                 [21]   Li JW, Jia CF, Liu ZL, Li J, Li M. Survey on the searchable encryption. Ruan Jian Xue Bao/Journal of Software, 2015, 26(1): 109–128
                     (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/4700.htm [doi: 10.13328/j.cnki.jos.004700]
                 [22]   Byun JW, Rhee HS, Park HA, Lee DH. Off-line keyword guessing attacks on recent keyword search schemes over encrypted data. In:
   447   448   449   450   451   452   453   454   455   456   457