Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
合作研究:EAGER:捍卫移动超级应用中新兴的小应用范式
基本信息
- 批准号:2330265
- 负责人:
- 金额:$ 15万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-07-01 至 2025-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
The rapidly evolving miniapp paradigm within mobile computing is revolutionizing user engagement with mobile applications. Super apps, functioning as hosts with multiple services, facilitate the installation and operation of miniapps within their platforms, thereby cultivating an ecosystem akin to that of Google Play and Apple App Store. This approach, already adopted by leading social apps like WeChat, TikTok, and SnapChat, greatly enhances user convenience and interactivity. However, alongside these advancements, the miniapp paradigm ushers in distinct security and privacy challenges demanding urgent resolution. As the prevalence of miniapps continues to escalate, the establishment of proper safeguards struggles to keep pace. Existing security policies for managing system resources across modern mobile operating systems (OSs) often exhibit opacity and dispersion, impeding effective isolation of miniapps and concealing complexities inherent to diverse mobile OSs. Additionally, super apps, with their capacity to amass substantial user data from numerous miniapps, frequently avoid recognizing themselves as data controllers. This lack of transparency in data practices generates potential privacy threats and regulatory issues. This proposal aims to take the first step towards systematic understanding and safeguarding of the security and privacy of the emerging miniapp paradigm in mobile super apps. We recognize the pressing concerns related to this paradigm and aim to investigate new security and privacy threats, such as cross-platform support, the design and implementation of miniapp APIs, and the management of sensitive data with respect to access control and security and privacy policies. Our research will also explore innovative techniques for risk assessment and vulnerability detection within the miniapp ecosystem. Moreover, we propose to employ formal methods to rigorously reason about these policies and standardize the design and implementation of the APIs, enabling a more secure and privacy-compliant miniapp ecosystem. Our research is expected to pave the way for the development of practical solutions that can be rapidly adopted by super apps and miniapp developers to tackle the urgent security and privacy challenges in this field.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
移动计算中快速发展的Miniapp范式正在彻底改变用户与移动应用程序的参与。超级应用程序作为带有多种服务的主机的运作,可促进Miniapps在其平台内的安装和操作,从而培养一个类似于Google Play和Apple App Store的生态系统。这种方法已经被带有微信,Tiktok和Snapchat等领先的社交应用所采用,极大地增强了用户的便利性和互动性。但是,除了这些进步之外,Miniapp范式在不同的安全和隐私方面挑战了需要紧急解决的问题。随着Miniapps的普遍性继续升级,建立适当的保障措施以保持步伐。现代移动操作系统(OSS)管理系统资源(OSS)的现有安全策略经常表现出不透明和分散,阻碍了Miniapps的有效隔离,并隐藏了多种移动OSS固有的复杂性。此外,超级应用程序具有从众多Miniapps积累大量用户数据的能力,经常避免将自己识别为数据控制器。数据实践缺乏透明度会产生潜在的隐私威胁和监管问题。该建议旨在迈出第一步,朝着系统的理解和维护移动超级应用程序中新兴Miniapp范式的安全性和隐私。我们认识到与此范式相关的紧迫问题,并旨在调查新的安全性和隐私威胁,例如跨平台支持,Miniapp API的设计和实施以及有关访问控制,安全和隐私政策的敏感数据的管理。我们的研究还将探索Miniapp生态系统中风险评估和脆弱性检测的创新技术。此外,我们建议采用正式的方法来严格理解这些政策,并标准化API的设计和实施,从而实现更安全和符合隐私的Miniapp生态系统。我们的研究有望为开发实用解决方案的开发铺平道路,这些解决方案可以迅速采用,超级应用程序和Miniapp开发人员可以应对该领域的紧急安全性和隐私挑战。该奖项反映了NSF的法定任务,并被认为是值得通过基金会的知识分子优点和更广泛的影响审查的评估来通过评估来支持的。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Luyi Xing其他文献
Superoxide radical mediated persulfate activation by nitrogen doped bimetallic MOF (FeCo/N-MOF) for efficient tetracycline degradation, , 282 (2022): 120124.
氮掺杂双金属 MOF (FeCo/N-MOF) 介导的超氧自由基介导的过硫酸盐活化可有效降解四环素,, , 282 (2022): 120124。
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:8.6
- 作者:
Yifei Zhang;Jia Wei;Luyi Xing;Jiamei Li;Mengdie Xu;Guoping Pan;Jun Li - 通讯作者:
Jun Li
A chip thermal management method realizing integrated applications of cooling, power generation and heat flow measurement based on thermoelectric effect
- DOI:
10.1016/j.applthermaleng.2024.124739 - 发表时间:
2025-01-15 - 期刊:
- 影响因子:
- 作者:
Liuyijie Huang;Luyi Xing;Yihua Zheng;Huimin Yao - 通讯作者:
Huimin Yao
SmartPatch: Verifying the Authenticity of the Trigger-Event in the IoT Platform
SmartPatch:验证物联网平台中触发事件的真实性
- DOI:
10.1109/tdsc.2022.3162312 - 发表时间:
2023-03 - 期刊:
- 影响因子:7.3
- 作者:
Bin Yuan;Yuhan Wu;Maogen Yang;Luyi Xing;Xuchang Wang;Deqing Zou;Hai Jin - 通讯作者:
Hai Jin
Cloud repository as a malicious service: challenge, identification and implication
云存储库作为恶意服务:挑战、识别和影响
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Xiaojing Liao;Sumayah A. Alrwais;Kan Yuan;Luyi Xing;Xiaofeng Wang;S. Hao;R. Beyah - 通讯作者:
R. Beyah
Luyi Xing的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Luyi Xing', 18)}}的其他基金
CAREER: Foundations for IoT Cloud Security
职业:物联网云安全的基础
- 批准号:
2145675 - 财政年份:2022
- 资助金额:
$ 15万 - 项目类别:
Continuing Grant
FMitF: Track II: Usability, Scalability, and Deployment Improvement of VerioT
FMITF:轨道 II:VerioT 的可用性、可扩展性和部署改进
- 批准号:
2124225 - 财政年份:2021
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
相似国自然基金
支持二维毫米波波束扫描的微波/毫米波高集成度天线研究
- 批准号:62371263
- 批准年份:2023
- 资助金额:52 万元
- 项目类别:面上项目
腙的Heck/脱氮气重排串联反应研究
- 批准号:22301211
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
水系锌离子电池协同性能调控及枝晶抑制机理研究
- 批准号:52364038
- 批准年份:2023
- 资助金额:33 万元
- 项目类别:地区科学基金项目
基于人类血清素神经元报告系统研究TSPYL1突变对婴儿猝死综合征的致病作用及机制
- 批准号:82371176
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
FOXO3 m6A甲基化修饰诱导滋养细胞衰老效应在补肾法治疗自然流产中的机制研究
- 批准号:82305286
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: EAGER: The next crisis for coral reefs is how to study vanishing coral species; AUVs equipped with AI may be the only tool for the job
合作研究:EAGER:珊瑚礁的下一个危机是如何研究正在消失的珊瑚物种;
- 批准号:
2333604 - 财政年份:2024
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
EAGER/Collaborative Research: An LLM-Powered Framework for G-Code Comprehension and Retrieval
EAGER/协作研究:LLM 支持的 G 代码理解和检索框架
- 批准号:
2347624 - 财政年份:2024
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
EAGER/Collaborative Research: Revealing the Physical Mechanisms Underlying the Extraordinary Stability of Flying Insects
EAGER/合作研究:揭示飞行昆虫非凡稳定性的物理机制
- 批准号:
2344215 - 财政年份:2024
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
Collaborative Research: EAGER: Designing Nanomaterials to Reveal the Mechanism of Single Nanoparticle Photoemission Intermittency
合作研究:EAGER:设计纳米材料揭示单纳米粒子光电发射间歇性机制
- 批准号:
2345581 - 财政年份:2024
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
Collaborative Research: EAGER: Designing Nanomaterials to Reveal the Mechanism of Single Nanoparticle Photoemission Intermittency
合作研究:EAGER:设计纳米材料揭示单纳米粒子光电发射间歇性机制
- 批准号:
2345582 - 财政年份:2024
- 资助金额:
$ 15万 - 项目类别:
Standard Grant