Analysis of security and data control in smart personal assistants from the user's perspective

被引:4
|
作者
Valero, Cayetano [1 ]
Perez, Jaime [1 ]
Solera-Cotanilla, Sonia [2 ]
Vega-Barbas, Mario [2 ]
Suarez-Tangil, Guillermo [3 ]
Alvarez-Campana, Manuel [2 ]
Lopez, Gregorio [1 ]
机构
[1] Univ Pontificia Comillas, Inst Res Technol, ICAI Engn Sch, Madrid 28015, Spain
[2] Univ Politecn Madrid, ETSI Telecomunicac, Madrid 28040, Spain
[3] IMDEA Networks Inst, Leganes 28918, Spain
基金
欧盟地平线“2020”;
关键词
Cybersecurity; Data control; Internet of things; Minors; Smart personal assistants; Testing methodology;
D O I
10.1016/j.future.2023.02.009
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Advances in the fields of the Internet of Things, Speech Recognition and Artificial Intelligence have facilitated the development of Smart Personal Assistants. As a result, Smart Personal Assistants currently allow requesting a wide range of tasks naturally and intuitively through voice interaction. Their wide popularity, together with the high technological complexity of their environments, have made them an attractive target from a security point of view. Recent works have shown some of the security and privacy issues they stand upon. In this work, we propose a methodology to carry out a systematic security analysis of Smart Personal Assistants using a comprehensive set of tests designed to measure issues around the installation, the interaction, key functionality, and overall Security and Privacy controls. We apply this methodology to analyse security and data control in predominant commercial Smart Personal Assistants (SPA), including Apple HomePod, Google Home and Nest, Amazon Echo (Show and Dot), and Facebook Portal. The main findings of our research are: (i) SPA are not resilient to voice replay attacks; (ii) their skills activation mechanisms can be significantly improved to be more reliable in multi-user households; (iii) the users' control to restrict the collection and access of Personally Identifiable Information can be also improved; (iv) they lack configurations adapted to minors, which should be included to make them more appropriate for a segment of users who interact more and more with them and have especially high regulatory requirements regarding security and data protection. Among the many hot research topics within this area, we find voice authentication and authorization especially interesting since they may push the usability of Smart Personal Assistants further, as long as they are robust enough from the security perspective.(c) 2023 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:12 / 23
页数:12
相关论文
共 50 条
  • [41] The brave new world of digital personal assistants: benefits and challenges from an economic perspective
    Budzinski, Oliver
    Noskova, Victoriia
    Zhang, Xijie
    NETNOMICS, 2019, 20 (2-3): : 177 - 194
  • [42] Analysis on the Security Mechanisms of User Data Protection in Facebook
    Liu, Bo
    Zhang, Tian
    Xiao, Zhefeng
    Cao, Jienan
    2012 7TH INTERNATIONAL CONFERENCE ON COMPUTING AND CONVERGENCE TECHNOLOGY (ICCCT2012), 2012, : 532 - 536
  • [43] From Big Data to Smart Data: A Data Quality Perspective
    Baldassarre, Maria Teresa
    Caballero, Ismael
    Caivano, Danilo
    Garcia, Bibiano Rivas
    Piattini, Mario
    PROCEEDINGS OF THE 1ST ACM SIGSOFT INTERNATIONAL WORKSHOP ON ENSEMBLE-BASED SOFTWARE ENGINEERING (ENSEMBLE '18), 2018, : 19 - 24
  • [44] For the sake of personal security in the mountains - from the perspective of innovative agonology
    Piepiora, Zbigniew
    Pietrzak, Kamil
    Baginska, Justyna
    Piepiora, Pawel
    ARCHIVES OF BUDO, 2022, 18 : 259 - 268
  • [45] Polymer analysis from the perspective of the user
    不详
    NACHRICHTEN AUS CHEMIE TECHNIK UND LABORATORIUM, 1996, 44 : S60 - S61
  • [46] Personal Digital Assistants to Collect Data on Animal Carcass Removal from Roadways
    Donaldson, Bridget M.
    Lafon, Nelson W.
    TRANSPORTATION RESEARCH RECORD, 2010, (2147) : 18 - 24
  • [47] Impact of Domain and User's Learning Phase on Task and Session Identification in Smart Speaker Intelligent Assistants
    Hashemi, Seyyed Hadi
    Williams, Kyle
    El Kholy, Ahmed
    Zitouni, Imed
    Crook, Paul A.
    CIKM'18: PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, 2018, : 1193 - 1202
  • [48] Smart Grid Security: Attack Modeling from a CPS Perspective
    Luo, Bo
    Beuran, Razvan
    Tan, Yasuo
    2020 IEEE COMPUTING, COMMUNICATIONS AND IOT APPLICATIONS (COMCOMAP), 2021,
  • [49] Revisiting the Practicality of Search on Encrypted Data: From the Security Broker's Perspective
    Han, Peiyi
    Liu, Chuanyi
    Fang, Binxing
    Wang, Guofeng
    Song, Xiaobao
    Wan, Lei
    SCIENTIFIC PROGRAMMING, 2016, 2016
  • [50] It Is About What They Could Do with the Data: A User Perspective on Privacy in Smart Metering
    Jakobi, Timo
    Patil, Sameer
    Randall, Dave
    Stevens, Gunnar
    Wulf, Volker
    ACM TRANSACTIONS ON COMPUTER-HUMAN INTERACTION, 2019, 26 (01)