My research interests are in information privacy
and in computer and networks security. In particular, I study
security and privacy aspects of emerging mobile and distributed
computing systems, such as location-based services, delay-tolerant
networks, and online voting. Some sample topics that I have worked on
are:
A location-based service allows a person to learn information that
is relevant to her current location, such as nearby
restaurants. However, considering that a person's location might
allow conclusions about her interests or her activities, the person
could be reluctant to reveal her location to the location-based
service. We have designed and implemented privacy-enhancing algorithms
that allow a person to benefit from location-based services without
forcing her to reveal detailed location information to a service (palms-07, securecomm-08,
wpes-08,
percom-09).
Recently, social-networking applications have started to appear on
mobile phones. These applications exploit the phones' positioning
capabilities to facilitate interaction between people. From a privacy
point of view, this trend is troublesome, because it gives the provider
of a social-networking application real-time access to people's
location. We have designed and implemented privacy-enhancing
technologies that allow location-sensitive
interactions between people without requiring the continuous release
of location information to the application provider (Software, pets-07).
In developing regions, people often rely on public kiosks to access
the Internet. Securing this access raises many challenges. For
example, the employed hardware is often recycled, Internet access is
only intermittent, and funds are limited. We have designed and implemented a security architecture that
runs on constrained hardware and that is assembled entirely from
open-source software (Website, nsdr-08, tech-report).
Panic passwords allow a user to signal duress during authentication
(e.g., in a home security system, at an ATM, or in online voting). We
have studied different existing panic password schemes and introduced
new schemes (hotsec-08).
I am also interested in access control, applied
cryptography, location privacy, trust management, trusted computing,
usability, and voting systems. My long-term research plan is the
development of software techniques that increase the privacy of
individuals who want to benefit from emerging services that manage or
exploit personal information.