论文标题

Privframework:可配置和自动化隐私策略合规性的系统

PrivFramework: A System for Configurable and Automated Privacy Policy Compliance

论文作者

Khan, Usmann, Wang, Lun, Subramanian, Jithendaraa, Near, Joseph P., Song, Dawn

论文摘要

当今的数据收集大规模,加上最近的消费者数据泄漏的潮流导致人们对数据隐私和相关风险的关注增加了。常规数据隐私保护系统着重于降低托管风险,并且缺乏授权数据所有者的功能。作为最终用户,有限的选项可用于指定和执行与其数据相比自己的隐私偏好。为了解决这些问题,我们提出了Privframework,这是一种可自动化隐私策略合规性的用户配置框架。 Privframework允许数据所有者编写强大的隐私政策,以保护其数据并自动执行这些策略,以防止Python编写的分析程序。使用静态分析的Privframework自动检查授权分析程序,以符合用户定义的策略。

Today's massive scale of data collection coupled with recent surges of consumer data leaks has led to increased attention towards data privacy and related risks. Conventional data privacy protection systems focus on reducing custodial risk and lack features empowering data owners. As an end user there are limited options available to specify and enforce one's own privacy preferences over their data. To address these concerns we present PrivFramework, a user-configurable frame-work for automated privacy policy compliance. PrivFramework allows data owners to write powerful privacy policies to protect their data and automatically enforces these policies against analysis programs written in Python. Using static-analysis PrivFramework automatically checks authorized analysis programs for compliance to user-defined policies.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源