MobCom Project Overview - 2nd Workshop, Feb 6, 2013

WiCa
rd
3
Workshop
MobCom
http://www.mobcom.org
Bart De Decker
iMinds-DistriNet
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Overview
•
•
•
•
•
•
•
Project goals
Challenges / opportunities
Work plan
Results
Future work
User Group
Conclusions
Project goals
Project goals
Data minimization
Unlinkability
Assurance
Privacy
Trustworthiness of data
Less personal data
Crime/abuse
Prevention / detection
Customization
Project goals
Application
Domains
Flexible
access
control
Loyalty
cards &
vouchers
Contextaware apps
Challenges / opportunities
Resource-limited device
Complex computations
Many comm. channels
Small screen
Many sensors
Stolen / abused ?
Secure Elements
Restricted use  policies
(context / history / multifactor)
Link credential/smartphone to owner
 biometric verification
Distance bounding
Challenges / opportunities
Development / prototyping
Privacy-Enhancing Technologies are COMPLEX
Framework
Flexible, open, high level
Technology-agnostic
Policy-driven
Modeling
Formal verification
 trust & privacy
properties
Work plan
Year 1
Year 2
Year 3
Year 4
Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4
Req
Reqs
Basic
Research
Architecture
Applications
Applications 2
Val. 1
Dissemination
Val 2
Results
• Technologies / Attestation / Biometrics
TPMs, TEE specification
o Accelerometer-based biometrics
• Protocols
o Anon. authentication (NFC) + distance bounding
o Location privacy
o Biometric credentials
o Smartphone authenticates user towards SP
o Universal loyalty & voucher schemes
o
Results
• Profiling / Customization
Local profiles
o Recommendation system
• Framework
o Desktop & Android version
o Secure storage component
o Policies (CARL & ABC4Trust)
• Modeling
o Trust assumptions & policies  privacy properties
o
Results
• Advanced scenarios
o
e-Poll application / app
• Anonymous but reliable
• Suitable for petitions, questionnaires, e-voting
• Universally verifiable
o
Shopping assistant InShopnito
• Anonymous but customizable
• User profile on the phone
• Compatible with loyalty systems & vouchers
Future work
• Backup & restore mechanisms
Local / remote / in the cloud
o Break-the-glass
Extension & evaluation of the framework
o Persistence / policies / API
Modeling tools
Features of smart phones
o Context, biometric binding, communication channels
Attestation
o
•
•
•
•
User group
Conclusion
• A Mobile Companion
A dream? 
A reality!
• PETs are feasible
• Advanced scenarios
o Flexibility, context-awareness, security, privacy
• Rapid prototyping & development
o Framework & policies
• Important?
TALK TO US!
Q&A
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa
Programme
14:00 – 14:15: Overview of MobCom
14:15 – 15:15: Android Security
Stefaan Seys, iMinds-COSIC
15:15 – 16:00: PriMan FW and Policies for context-aware and
policy-driven applications
Andreas Put, iMinds-DistriNet
16:30 – 16:50: Anonymous yet reliable ePoll application
Italo Dacosta, iMinds-DistriNet
16:50 – 17:10: A formal approach for analyzing privacy in loyalty sys.
Koen Decroix, KaHo SL-MSEC
17:10 – 18:00: MobCom Demo: inShopnito
iMinds-DistriNet, MSEC, iMinds-COSIC, iMinds-WiCa