Generalised Context Privacy
Connectivity and automation are increasingly being introduced to physical systems that previously lacked them. This introduces new threats to these systems, including by revealing sensitive information to an adversary making observations on the system and the context in which the system takes actions. Many domains (e.g., wireless sensor networks, vehicles) have independently had context privacy preserving techniques developed for these threats (e.g., onion routing, change in identity, change in behaviour).
Importance
Developing context privacy preserving techniques is a lengthy process and does not allow for rapid responses to novel context privacy threats. This poses a danger to users of systems which operate without suitable context privacy controls and potentially leads to sensitive operational information being revealed. This project will work towards providing a capability to “prevent and resist cyber attacks more effectively”, which was highlighted in the UK’s National Cyber Strategy 2022.
Aims
This project will:
- develop a suite of context privacy controls for an arbitrary system,
- demonstrate their efficacy via suitable quantification, and then
- using example systems, develop domain-specific translators such that the general context privacy techniques can applied to real-world systems.
By doing so, when novel context privacy threats are identified, only domain-specific translators need to be developed. This allows for faster and more agile responses to novel context privacy threats, thus minimising information conveyed by system actions to an adversary — protecting both the system and its users.
Research Questions
This research project will address how controls should be introduced on actions taken by an arbitrary system to reduce the information revealed to an adversary observing that system. This can be divided into three focused research questions:
- What controls are required to reduce the information an arbitrary system reveals during its operation?
- How should context privacy the system and the cost of providing it be quantified?
- How should techniques for providing context privacy on an arbitrary system be translated to a real-world system?
Information
Role: Principle Investigator
Funder: Engineering and Physical Sciences Research Council [EP/X040038/1]
Duration: January 2024 – December 2026
Links:
Talks
- Generalised Context Privacy at Manchester University, Manchester, UK on 26 February 2024
- Generalised Context Privacy at Lancashire Cyber Festival, UCLAN, Preston, UK on 15 November 2023
- Generalised Context Privacy at Academic Centres of Excellence in Cyber Security Research Conference, Stratford-upon-Avon, UK on 23 June 2022