节点文献

面向边缘计算场景的隐私保护策略研究

Research on Privacy Protection Strategies in Edge Computing Scenarios

【作者】 蒋涛;

【导师】 宋宇波; 汤红波;

【作者基本信息】 东南大学 , 网络空间安全, 2024, 硕士

【摘要】 随着5G/6G等通信技术的发展,用户对于应用服务多样化的需求不断增长,对于应用的服务质量与响应速度的要求逐渐提高,具备近用户侧、低时延等优良特性的边缘计算技术应运而生,并且目前已在各个领域得到了较为广泛的深入应用。然而,由于边缘计算网络本身与任务卸载机制的半开放性,以及边缘节点的半可信性,用户的隐私信息面临着极大的泄漏威胁。因此,在面向边缘计算网络的场景中,保证应用服务的质量与效率前提下,研究用户隐私的保护策略具有重大意义,有助于进一步提升边缘计算网络中用户隐私的安全性与服务内容的可信度。据此,本文立足于边缘计算场景下的用户隐私安全问题,展开了详细深入的研究。并以隐私泄漏原因为切入点,依据不同的业务场景提出了相应的隐私保护策略。研究内容具体可分为以下几个部分:(1)首先,针对边缘节点存在的半可信特性,可能导致用户隐私泄漏的安全威胁,本文提出了一种层次化的边缘节点信任评估模型,并合理量化节点交互产生的直接信任与间接信任,设计了相应的综合信任度评估算法。同时,该模型可提供边缘计算网络范围内全层次的动态信任评估,相较于目前大多数边缘计算信任评估方案的覆盖范围以及静态局限性,具备更全面的判定能力和更出色的执行性能。(2)其次,针对边缘计算网络环境中任务卸载特性导致的用户设备使用模式隐私泄漏威胁,本文设计了一种k-匿名隐私保护框架,通过构建匿名组的方式群体性泛化用户的卸载频率;同时,提出了一个基于深度强化学习的使用模式隐私保护的优化卸载算法,在保证边缘服务域内各用户的设备使用模式隐私的同时,实现系统设备平均能耗的最优化。与现有多数研究仅局限于单独保护个体用户的设备使用模式隐私相比,在同样的任务卸载环境下,本文所提出的方法具有更出色的能耗表现及设备使用模式隐私保护效果。(3)最后,针对边缘计算网络环境中涉及到基于位置的服务时,用户位置隐私易暴露的问题,本文分为快照服务请求与连续服务请求两种场景提出了位置隐私保护策略。在面向快照服务请求下,本文提出了一种基于改进假位置集的MEC快照位置隐私保护策略,不同于目前多数的假位置集隐私保护策略,该方法考虑了敌手可能具备的背景知识,在可接受的时延代价内生成隐私保护效果更优越的假位置集,同时保持快照请求的服务质量;在面向连续服务请求下,本文提出了一种基于差分隐私的敏感度个性化MEC轨迹隐私保护策略,该方法在保证轨迹应用服务质量的前提下实现了对于边缘用户的轨迹隐私的保护,并且相较于其他轨迹隐私保护方法,在轨迹扰动上具备更灵活的保护力度,成本开销也更少。

【Abstract】 With the advancement of communication technologies such as 5G/6G,users’demands for diversified application services are continuously growing.There is an increasing expectation for higher quality and faster response in applications.Edge computing,characterized by its proximity to users and low latency,has emerged and has been widely applied in various fields.However,due to the semi-open nature of edge computing networks and the semi-trustworthiness of edge nodes,users’privacy faces significant threats of leakage.Therefore,in the context of edge computing networks,researching privacy protection strategies for users holds paramount significance.This research aims to ensure the quality and efficiency of application services while enhancing the security of user privacy and the credibility of service content in edge com-puting networks.Based on this,the research is grounded in addressing user privacy in the context of edge computing.Taking privacy leakage reasons as the starting point,corresponding privacy pro-tection strategies are proposed.The research content can be categorized into the following sections:(1)Firstly,addressing the semi-trusted characteristics inherent in edge nodes that pose se-curity threats leading to potential user privacy breaches,a hierarchical trust assessment model for edge nodes is introduced.This model quantifies the direct and indirect trust generated from node interactions and devises a corresponding comprehensive trust evaluation algorithm.Si-multaneously,the model provides dynamic trust assessments across all levels within the edge computing network.In comparison to many existing edge computing trust assessment ap-proaches with limited coverage and static constraints,it exhibits more comprehensive discern-ment capabilities and superior execution performance.(2)Secondly,addressing the privacy threats stemming from the task offloading character-istics in the edge computing network that lead to potential privacy breaches in user device usage patterns,a k-anonymity privacy protection framework is devised.It achieves collective gener-alization of user offloading frequencies by constructing anonymous groups.Additionally,an optimization offloading algorithm based on deep reinforcement learning is proposed for privacy protection in device usage patterns.This algorithm ensures optimal energy consumption across all users in the edge service domain while preserving the privacy of their device usage patterns.In contrast to many existing studies that primarily focus on individually protecting the device usage patterns of users,the proposed method exhibits superior energy efficiency and effective-ness in device usage pattern privacy protection within the same task offloading environment.(3)Lastly,addressing the issue of user location privacy exposure in the context of edge computing networks,this research proposes location privacy protection strategies for two sce-narios:snapshot service requests and continuous service requests.For snapshot service re-quests,an improved dummy location selection-based MEC snapshot location privacy protec-tion strategy is introduced.Unlike conventional dummy location selection privacy protection strategies,this approach takes into account potential background knowledge possessed by ad-versaries.It generates dummy location selection with superior privacy protection effectiveness within acceptable latency costs while maintaining service quality for snapshot requests.For continuous service requests,a personalized MEC trajectory privacy protection strategy based on differential privacy sensitivity is proposed.This method ensures the privacy of edge users’trajectories while maintaining the quality of trajectory application services.Compared to other trajectory privacy protection methods,it offers more flexible protection intensity in trajectory perturbation and incurs lower costs.

  • 【网络出版投稿人】 东南大学
  • 【网络出版年期】2026年 03期
  • 【分类号】TP309
节点文献中: