Analysis of security and data control in smart personal assistants from the user's perspective

被引:4
|
作者
Valero, Cayetano [1 ]
Perez, Jaime [1 ]
Solera-Cotanilla, Sonia [2 ]
Vega-Barbas, Mario [2 ]
Suarez-Tangil, Guillermo [3 ]
Alvarez-Campana, Manuel [2 ]
Lopez, Gregorio [1 ]
机构
[1] Univ Pontificia Comillas, Inst Res Technol, ICAI Engn Sch, Madrid 28015, Spain
[2] Univ Politecn Madrid, ETSI Telecomunicac, Madrid 28040, Spain
[3] IMDEA Networks Inst, Leganes 28918, Spain
基金
欧盟地平线“2020”;
关键词
Cybersecurity; Data control; Internet of things; Minors; Smart personal assistants; Testing methodology;
D O I
10.1016/j.future.2023.02.009
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Advances in the fields of the Internet of Things, Speech Recognition and Artificial Intelligence have facilitated the development of Smart Personal Assistants. As a result, Smart Personal Assistants currently allow requesting a wide range of tasks naturally and intuitively through voice interaction. Their wide popularity, together with the high technological complexity of their environments, have made them an attractive target from a security point of view. Recent works have shown some of the security and privacy issues they stand upon. In this work, we propose a methodology to carry out a systematic security analysis of Smart Personal Assistants using a comprehensive set of tests designed to measure issues around the installation, the interaction, key functionality, and overall Security and Privacy controls. We apply this methodology to analyse security and data control in predominant commercial Smart Personal Assistants (SPA), including Apple HomePod, Google Home and Nest, Amazon Echo (Show and Dot), and Facebook Portal. The main findings of our research are: (i) SPA are not resilient to voice replay attacks; (ii) their skills activation mechanisms can be significantly improved to be more reliable in multi-user households; (iii) the users' control to restrict the collection and access of Personally Identifiable Information can be also improved; (iv) they lack configurations adapted to minors, which should be included to make them more appropriate for a segment of users who interact more and more with them and have especially high regulatory requirements regarding security and data protection. Among the many hot research topics within this area, we find voice authentication and authorization especially interesting since they may push the usability of Smart Personal Assistants further, as long as they are robust enough from the security perspective.(c) 2023 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:12 / 23
页数:12
相关论文
共 50 条
  • [1] Smart Home Personal Assistants: A Security and Privacy Review
    Edu, Jide S.
    Such, Jose M.
    Suarez-Tangil, Guillermo
    ACM COMPUTING SURVEYS, 2021, 53 (06)
  • [2] User Experience with Smart Voice Assistants: The Accent Perspective
    Pal, Debajyoti
    Arpnikanondt, Chonlameth
    Funilkul, Suree
    Varadarajan, Vijayakumar
    2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [3] More than Smart Speakers: Security and Privacy Perceptions of Smart Home Personal Assistants
    Abdi, Noura
    Ramokapane, Kopo M.
    Such, Jose M.
    PROCEEDINGS OF THE FIFTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY (SOUPS 2019), 2019, : 451 - 466
  • [4] Classifying Smart Personal Assistants: An Empirical Cluster Analysis
    Knote, Robin
    Janson, Andreas
    Soellner, Matthias
    Leimeister, Jan Marco
    PROCEEDINGS OF THE 52ND ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2019, : 2024 - 2033
  • [5] Privacy and data security in E-health: Requirements from the user's perspective
    Wilkowska, Wiktoria
    Ziefle, Martina
    HEALTH INFORMATICS JOURNAL, 2012, 18 (03) : 191 - 201
  • [6] Value Co-Creation in Smart Services: A Functional Affordances Perspective on Smart Personal Assistants
    Knote, Robin
    Janson, Andreas
    Soellner, Matthias
    Leimeister, Jan Marco
    JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2021, 22 (02): : 418 - 458
  • [7] Exploring the Usability, Security, and Privacy of Smart Locks from the Perspective of the End User
    Hazazi, Hussein
    Shehab, Mohamed
    PROCEEDINGS OF THE NINETEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, SOUPS 2023, 2023, : 559 - 577
  • [8] A Privacy-Driven Data Management Model for Smart Personal Assistants
    Nogueira, Danilo M.
    Maciel, Cristiano
    Viterbo, Jose
    Vecchiato, Daniel
    HUMAN ASPECTS OF INFORMATION SECURITY, PRIVACY AND TRUST (HAS 2017), 2017, 10292 : 722 - 738
  • [9] SoK: Analyzing Privacy and Security of Healthcare Data from the User Perspective
    Tazi, Faiza
    Nandakumar, Archana
    Dykstra, Josiah
    Rajivan, Prashanth
    Das, Sanchari
    ACM TRANSACTIONS ON COMPUTING FOR HEALTHCARE, 2024, 5 (02):
  • [10] Personal software process: A user's perspective
    CeberioVerghese, AC
    NINTH CONFERENCE ON SOFTWARE ENGINEERING EDUCATION, PROCEEDINGS, 1996, : 52 - 65