ARSpy: Breaking Location-Based Multi-Player Augmented Reality Application for User Location Tracking

被引:29
作者
Shang, Jiacheng [1 ]
Chen, Si [2 ]
Wu, Jie [1 ]
Yin, Shu [3 ]
机构
[1] Temple Univ, Dept Comp & Informat Sci, 1805 N Broad St, Philadelphia, PA 19122 USA
[2] Univ Penn, Dept Comp Sci, 25 Univ Ave, W Chester, PA 19383 USA
[3] Shanghai Tech Univ, Sch Informat Sci & Technol, Shanghai 201210, Peoples R China
关键词
Geology; Global Positioning System; Throughput; Databases; Servers; Cryptography; Augmented reality; localization; attack;
D O I
10.1109/TMC.2020.3007740
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Augmented reality (AR) applications that overlay the perception of the real world with digitally generated information are on the cusp of commercial viability. AR has appeared in several commercial platforms like Microsoft HoloLens and smartphones. They extend the user experience beyond two dimensions and supplement the normal 3D world of a user. A typical location-based multi-player AR application works through a three-step process, wherein the system collects sensory data from the real world, identifies objects based on their context, and finally, renders information on top of senses of a user. However, because these AR applications frequently exchange data with users, they have exposed new individual and public safety issues. In this paper, we develop ARSpy, a user location tracking system solely based on network traffic information of the user, and we test it on location-based multi-player AR applications. We demonstrate the effectiveness and efficiency of the proposed scheme via real-world experiments on 12 volunteers and show that we could obtain the geolocation of any target with high accuracy. We also propose three mitigation methods to mitigate these side channel attacks. Our results reveal a potential security threat in current location-based multi-player AR applications and serve as a critical security reminder to a vast number of AR users.
引用
收藏
页码:433 / 447
页数:15
相关论文
共 44 条
[1]  
[Anonymous], 2011, P 17 ANN INT C MOBIL, DOI [10.1145/2030613.2030630, DOI 10.1145/2030613.2030630]
[2]   Mobile Augmented Reality Survey: From Where We Are to Where We Go [J].
Chatzopoulos, Dimitris ;
Bermejo, Carlos ;
Huang, Zhanpeng ;
Hui, Pan .
IEEE ACCESS, 2017, 5 :6917-6950
[3]   Side-Channel Leaks in Web Applications: a Reality Today, a Challenge Tomorrow [J].
Chen, Shuo ;
Wang, Rui ;
Wang, XiaoFeng ;
Zhang, Kehuan .
2010 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2010, :191-206
[4]   Archeoguide:: System architecture of a mobile outdoor augmented reality system [J].
Dähne, P ;
Karigiannis, JN .
INTERNATIONAL SYMPOSIUM ON MIXED AND AUGMENTED REALITY, PROCEEDINGS, 2002, :263-264
[5]   Privacy-aware contextual localization using network traffic analysis [J].
Das, Aveek K. ;
Pathak, Parth H. ;
Chuah, Chen-Nee ;
Mohapatra, Prasant .
COMPUTER NETWORKS, 2017, 118 :24-36
[6]  
de Guzman J. A., 2018, ARXIV180205797
[7]   Unique in the Crowd: The privacy bounds of human mobility [J].
de Montjoye, Yves-Alexandre ;
Hidalgo, Cesar A. ;
Verleysen, Michel ;
Blondel, Vincent D. .
SCIENTIFIC REPORTS, 2013, 3
[8]   Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail [J].
Dyer, Kevin P. ;
Coull, Scott E. ;
Ristenpart, Thomas ;
Shrimpton, Thomas .
2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, :332-346
[9]  
Fiore Ugo, 2014, 2014 IEEE 11th Consumer Communications and Networking Conference (CCNC), P145, DOI 10.1109/CCNC.2014.6866562
[10]  
Fockler P., 2005, Proceedings of the 4th international conference on Mobile and ubiquitous multimedia, P3