通信学报 ›› 2019, Vol. 40 ›› Issue (7): 1-13.doi: 10.11959/j.issn.1000-436x.2019107

• 学术论文 •    下一篇

跨社交网络的隐私图片分享框架

李凤华1,2,3,孙哲1,2,牛犇1(),曹进3,李晖3   

  1. 1 中国科学院信息工程研究所,北京 100093
    2 中国科学院大学网络空间安全学院,北京 100049
    3 西安电子科技大学网络与信息安全学院,陕西 西安 710071
  • 修回日期:2019-04-04 出版日期:2019-07-25 发布日期:2019-07-30
  • 作者简介:李凤华(1966- ),男,湖北浠水人,博士,中国科学院信息工程研究所研究员、博士生导师,主要研究方向为网络与系统安全、信息保护、隐私计算。|孙哲(1987- ),男,安徽安庆人,中国科学院信息工程研究所博士生,主要研究方向为信息保护、隐私计算。|牛犇(1984- ),男,陕西西安人,博士,中国科学院信息工程研究所副研究员,主要研究方向为网络安全、隐私计算。|曹进(1985- ),男,陕西西安人,博士,西安电子科技大学副教授、硕士生导师,主要研究方向为应用密码学、安全协议分析、无线网络安全。|李晖(1968- ),男,河南灵宝人,博士,西安电子科技大学教授、博士生导师,主要研究方向为密码学、无线网络安全、云计算安全、信息论与编码理论。
  • 基金资助:
    国家重点研发计划基金资助项目(2017YFB0802203);国家自然科学基金资助项目(U1401251);国家自然科学基金资助项目(61672515);国家自然科学基金资助项目(61872441);工业和信息化部2018工业互联网创新发展工程项目“工业互联网标识解析数据管理技术标准制定与试验验证;中国科学院青年创新促进会人才资助项目(2018196)

Privacy-preserving photo sharing framework cross different social network

Fenghua LI1,2,3,Zhe SUN1,2,Ben NIU1(),Jin CAO3,Hui LI3   

  1. 1 Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China
    2 School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100049,China
    3 School of Cyber Engineering,Xidian University,Xi’an 710071,China
  • Revised:2019-04-04 Online:2019-07-25 Published:2019-07-30
  • Supported by:
    The National Key Research and Development Program of China(2017YFB0802203);The National Natural Science Foundation of China(U1401251);The National Natural Science Foundation of China(61672515);The National Natural Science Foundation of China(61872441);2018 Industrial Internet Innovation and Development Project of China - “Technical Standard Formulation and Verification of Identifier Data Management for Identification and Resolution System;Youth Innovation Promotion Association CAS(2018196)

摘要:

针对图片转发场景下隐私泄露的问题,提出了一种跨社交网络的隐私图片分享框架,可用于图片隐私信息的延伸控制和溯源取证。延伸控制方案利用基于传播链的访问控制模型限制后续用户的操作权限,并将隐私策略嵌入图片文件,通过图片加密算法保护图片隐私信息和隐私策略的机密性、完整性,确保用户隐私策略被正确执行。该方案不受限于任何现有社交网络图片分享平台,并且能够有效防止非授权转发造成的图片隐私信息泄露威胁。在此基础上,溯源取证方案记录用户的操作行为,并通过嵌套签名方案防止恶意用户篡改和伪造溯源记录,为跨社交网络的图片隐私侵犯行为溯源取证提供技术手段。实验结果验证了所提方案的有效性和效率。

关键词: 图片隐私, 延伸控制, 溯源取证, 社交网络

Abstract:

With rapid developments of digital photography and social networks,users of photo-sharing-supported social networking applications can easily forward photos across different social networks at the cost of their growing privacy concerns.To address this problem,a privacy-preserving photo sharing framework was proposed,which could apply to extended control and privacy invasion tracing.In extended control scheme,the following users on a dissemination chain was restrained by each user’s privacy policy.Then several privacy areas of photos were encrypted and the access control polices were bound to the uploaded photos,so that any privacy areas on the photos could be hidden away from unwanted viewers even across different social networks.On this basis,the behaviors of users were record by tracing scheme of privacy invasion,the integrality of records was protected by using nested signature algorithm.The correctness,security and performance of overhead of the scheme are then thoroughly analyzed and evaluated via detailed simulations.

Key words: photo privacy, extended control, privacy invasion tracing, social network

中图分类号: 

  • TN929