A Tag-Based, Logical Access-Control Framework for Personal File Sharing

People store and share ever-increasing numbers of digital documents, photos, and other files, both on personal devices and within online services. In this environment, proper access control is critical to help users obtain the benefits of sharing varied content with different groups of people while...

Full description

Bibliographic Details
Main Author: Mazurek, Michelle L.
Format: Others
Published: Research Showcase @ CMU 2014
Subjects:
Online Access:http://repository.cmu.edu/dissertations/325
http://repository.cmu.edu/cgi/viewcontent.cgi?article=1325&context=dissertations
id ndltd-cmu.edu-oai-repository.cmu.edu-dissertations-1325
record_format oai_dc
spelling ndltd-cmu.edu-oai-repository.cmu.edu-dissertations-13252014-07-24T15:36:16Z A Tag-Based, Logical Access-Control Framework for Personal File Sharing Mazurek, Michelle L. People store and share ever-increasing numbers of digital documents, photos, and other files, both on personal devices and within online services. In this environment, proper access control is critical to help users obtain the benefits of sharing varied content with different groups of people while avoiding trouble at work, embarrassment, identity theft, and other problems related to unintended disclosure. Current approaches often fail, either because they insufficiently protect data or because they confuse users about policy specification. Historically, correctly managing access control has proven difficult, timeconsuming, and error-prone, even for experts; to make matters worse, access control remains a secondary task most non-experts are unwilling to spend significant time on. To solve this problem, access control for file-sharing tools and services should provide verifiable security, make policy configuration and management simple and understandable for users, reduce the risk of user error, and minimize the required user effort. This thesis presents three user studies that provide insight into people’s access-control needs and preferences. Drawing on the results of these studies, I present Penumbra, a prototype distributed file system that combines semantic, tag-based policy specification with logicbased access control, flexibly supporting intuitive policies while providing high assurance of correctness. Penumbra is evaluated using a set of detailed, realistic case studies drawn from the presented user studies. Using microbenchmarks and traces generated from the case studies, Penumbra can enforce users’ policies with overhead less than 5% for most system calls. Finally, I present lessons learned, which can inform the further development of usable access-control mechanisms both for sharing files and in the broader context of personal data. 2014-05-01T07:00:00Z text application/pdf http://repository.cmu.edu/dissertations/325 http://repository.cmu.edu/cgi/viewcontent.cgi?article=1325&context=dissertations Dissertations Research Showcase @ CMU access control file systems usability
collection NDLTD
format Others
sources NDLTD
topic access control
file systems
usability
spellingShingle access control
file systems
usability
Mazurek, Michelle L.
A Tag-Based, Logical Access-Control Framework for Personal File Sharing
description People store and share ever-increasing numbers of digital documents, photos, and other files, both on personal devices and within online services. In this environment, proper access control is critical to help users obtain the benefits of sharing varied content with different groups of people while avoiding trouble at work, embarrassment, identity theft, and other problems related to unintended disclosure. Current approaches often fail, either because they insufficiently protect data or because they confuse users about policy specification. Historically, correctly managing access control has proven difficult, timeconsuming, and error-prone, even for experts; to make matters worse, access control remains a secondary task most non-experts are unwilling to spend significant time on. To solve this problem, access control for file-sharing tools and services should provide verifiable security, make policy configuration and management simple and understandable for users, reduce the risk of user error, and minimize the required user effort. This thesis presents three user studies that provide insight into people’s access-control needs and preferences. Drawing on the results of these studies, I present Penumbra, a prototype distributed file system that combines semantic, tag-based policy specification with logicbased access control, flexibly supporting intuitive policies while providing high assurance of correctness. Penumbra is evaluated using a set of detailed, realistic case studies drawn from the presented user studies. Using microbenchmarks and traces generated from the case studies, Penumbra can enforce users’ policies with overhead less than 5% for most system calls. Finally, I present lessons learned, which can inform the further development of usable access-control mechanisms both for sharing files and in the broader context of personal data.
author Mazurek, Michelle L.
author_facet Mazurek, Michelle L.
author_sort Mazurek, Michelle L.
title A Tag-Based, Logical Access-Control Framework for Personal File Sharing
title_short A Tag-Based, Logical Access-Control Framework for Personal File Sharing
title_full A Tag-Based, Logical Access-Control Framework for Personal File Sharing
title_fullStr A Tag-Based, Logical Access-Control Framework for Personal File Sharing
title_full_unstemmed A Tag-Based, Logical Access-Control Framework for Personal File Sharing
title_sort tag-based, logical access-control framework for personal file sharing
publisher Research Showcase @ CMU
publishDate 2014
url http://repository.cmu.edu/dissertations/325
http://repository.cmu.edu/cgi/viewcontent.cgi?article=1325&context=dissertations
work_keys_str_mv AT mazurekmichellel atagbasedlogicalaccesscontrolframeworkforpersonalfilesharing
AT mazurekmichellel tagbasedlogicalaccesscontrolframeworkforpersonalfilesharing
_version_ 1716709429653536768