Page 452 - 《软件学报》2026年第2期
P. 452
张源 等: 以用户为中心的云辅助跨应用数据安全流转 931
由于 CADC 在数据检索阶段对数据文件进行加解密时使用已授权设备的短效公私钥对完成, 这意味着在设
备短效公私钥对到期后, 需要对数据密文进行及时更新, 在应用过程中可能会造成额外的计算和通信开销; 此外,
在 CADC 的安全模型中没有考虑在线 DGA 和在线 KGA. 在未来的工作中, 我们将继续深入研究提高数据外包系
统效率, 保证数据跨应用流转安全性的方法.
References
[1] Khedker U, Sanyal A, Sathe B. Data Flow Analysis: Theory and Practice. Boca Raton: CRC Press, 2009. [doi: 10.1201/9780849332517]
[2] Pasquier TFJM, Singh J, Eyers D, Bacon J. CamFlow: Managed data-sharing for cloud services. IEEE Trans. on Cloud Computing, 2017,
5(3): 472–484. [doi: 10.1109/TCC.2015.2489211]
[3] Crooks N. Efficient data sharing across trust domains. ACM SIGMOD Record, 2023, 52(2): 36–37. [doi: 10.1145/3615952.3615962]
[4] van Kleek M, Liccardi I, Binns R, Zhao J, Weitzner DJ, Shadbolt N. Better the devil you know: Exposing the data sharing practices of
smartphone Apps. In: Proc. of the 2017 CHI Conf. on Human Factors in Computing Systems. Denver: ACM, 2017. 5208–5220. [doi: 10.
1145/3025453.3025556]
[5] Zhang Y, Xu CX, Li HW, Yang K, Cheng N, Shen XM. PROTECT: Efficient password-based threshold single-sign-on authentication for
mobile users against perpetual leakage. IEEE Trans. on Mobile Computing, 2021, 20(6): 2297–2312. [doi: 10.1109/TMC.2020.2975792]
[6] Zhang Y, Xu CX, Ni JB, Li HW, Shen XS. Blockchain-assisted public-key encryption with keyword search against keyword guessing
attacks for cloud storage. IEEE Trans. on Cloud Computing, 2021, 9(4): 1335–1348. [doi: 10.1109/TCC.2019.2923222]
[7] Brandtzaeg PB, Pultier A, Moen GM. Losing control to data-hungry Apps: A mixed-methods approach to mobile App privacy. Social
Science Computer Review, 2019, 37(4): 466–488. [doi: 10.1177/0894439318777706]
[8] Yu DJ, Wang JJ, Liu CF. Approach to optimal staff assignment in workflows based on collaboration patterns. Ruan Jian Xue Bao/Journal
of Software, 2018, 29(11): 3340–3354 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/5483.htm [doi: 10.13328/j.
cnki.jos.005483]
[9] Huckvale K, Torous J, Larsen ME. Assessment of the data sharing and privacy practices of smartphone Apps for depression and smoking
cessation. JAMA Network Open, 2019, 2(4): e192542. [doi: 10.1001/jamanetworkopen.2019.2542]
[10] Wang Y, Fan M, Tao JJ, Lei JY, Jin WX, Han DQ, Liu T. Compliance detection method for mobile application privacy policy statement.
Ruan Jian Xue Bao/Journal of Software, 2024, 35(8): 3668–3683 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
7121.htm [doi: 10.13328/j.cnki.jos.007121]
[11] Jobe W. Native Apps vs. mobile Web Apps. Int’l Journal of Interactive Mobile Technologies, 2013, 7(4): 27–32. [doi: 10.3991/ijim.v7i4.
3226]
[12] Zimmeck S, Story P, Smullen D, Ravichander A, Wang ZQ, Reidenberg J, Russell NC, Sadeh N. MAPS: Scaling privacy compliance
analysis to a million Apps. Proc. on Privacy Enhancing Technologies, 2019, 2019(3): 66–86. [doi: 10.2478/popets-2019-0037]
[13] Dell’Amico M, Michiardi P, Roudier Y. Password strength: An empirical analysis. In: Proc. of the 2010 IEEE INFOCOM. San Diego:
IEEE, 2010. 1–9. [doi: 10.1109/INFCOM.2010.5461951]
[14] Iqbal U, Wolfe C, Nguyen C, Englehardt S, Shafiq Z. Khaleesi: Breaker of advertising and tracking request chains. In: Proc. of the 31st
USENIX Security Symp. Boston: USENIX Association, 2022. 2911–2928.
[15] Wu JR, Nan YH, Xing LY, Cheng JT, Lin ZM, Zheng ZB, Yang M. Leaking the privacy of groups and more: Understanding privacy
risks of cross-App content sharing in mobile ecosystem. In: Proc. of the 2024 Network and Distributed System Security Symp. (NDSS).
San Diego, 2024. [doi: 10.14722/ndss.2024.24138]
[16] Wu LB, Wang J, Choo KKR, He DB. Secure key agreement and key protection for mobile device user authentication. IEEE Trans. on
Information Forensics and Security, 2019, 14(2): 319–330. [doi: 10.1109/TIFS.2018.2850299]
[17] Das A, Bonneau J, Caesar M, Borisov N, Wang XF. The tangled Web of password reuse. In: Proc. of the 2014 Network and Distributed
System Security. San Diego, 2014. [doi: 10.14722/ndss.2014.23357]
[18] Ma J, Yang WN, Luo M, Li NH. A study of probabilistic password models. In: Proc. of the 2014 IEEE Symp. on Security and Privacy.
Berkeley: IEEE, 2014. 689–704. [doi: 10.1109/SP.2014.50]
[19] Gao G, Zhang Y, Song YQ, Li SY. PrivSSO: Practical single-sign-on authentication against subscription/access pattern leakage. IEEE
Trans. on Information Forensics and Security, 2024, 19: 5075–5089. [doi: 10.1109/TIFS.2024.3392533]
[20] Song DX, Wagner D, Perrig A. Practical techniques for searches on encrypted data. In: Proc. of the 2000 IEEE Symp. on Security and
Privacy. Berkeley: IEEE, 2000. 44–55. [doi: 10.1109/SECPRI.2000.848445]
[21] Li JW, Jia CF, Liu ZL, Li J, Li M. Survey on the searchable encryption. Ruan Jian Xue Bao/Journal of Software, 2015, 26(1): 109–128
(in Chinese with English abstract). http://www.jos.org.cn/1000-9825/4700.htm [doi: 10.13328/j.cnki.jos.004700]
[22] Byun JW, Rhee HS, Park HA, Lee DH. Off-line keyword guessing attacks on recent keyword search schemes over encrypted data. In:

