首页> 外文会议>IEEE International Requirements Engineering Conference Workshops >Privacy Impacts of IoT Devices: A SmartTV Case Study
【24h】

Privacy Impacts of IoT Devices: A SmartTV Case Study

机译:IOT设备的隐私影响:SmartTV案例研究

获取原文

摘要

The Internet of Things (IoT) enables the passive collection of personal data at an unprecedented scale by ubiquitous devices built into our daily lives. However, IoT devices neither provide notice or collect consent as recommended by the U. S. Federal Trade Commission (FTC) fair information practice principles. IoT devices may, based on their physical limitation, not even be capable of compliance. Requirements engineers need concrete methodologies to identify, understand, and limit risks to customer privacy posed by IoT devices. We conducted an exploratory case study of the privacy policy for an archetypical IoT device, a SmartTV. We employed the Goal-Based Requirements Analysis Method to extract goals from applicable Samsung U. S. privacy policy documents and classified the resulting goals with the Anto?n-Earp privacy goal taxonomy. The goal of this research is to characterize the privacy protections and vulnerabilities posed by this example IoT device and its associated policies. In particular, we seek to assess whether data collection is apparent to the average user and evaluate the extent to which a SmartTV exposes users to cloud computing's privacy vulnerabilities. Our results suggest that: (1) users face increased risk of privacy harms from SmartTVs, (2) most data collection by SmartTVs is not apparent to the average user, and (3) many SmartTV goals further compromise user privacy by requiring connection to manufacturer backend servers.
机译:事物互联网(IOT)通过普遍存在的设备,可以以前所未有的尺寸来实现个人数据的被动集合。但是,由于美国联邦贸易委员会(FTC)公平信息实践原则,IOT设备既不提供通知或收集同意。根据其物理限制,IOT设备可能甚至无法合规。需求工程师需要具体方法来识别,理解和限制IoT设备构成的客户隐私的风险。我们对Archetypical IoT设备,SmartTV进行了探索性案例研究。我们雇用了基于目标的需求分析方法,以提取来自适用的三星U. S.隐私政策文件的目标,并将其与Anto的目标分类为N-EARP隐私目标分类。本研究的目标是描述此示例IOT设备及其相关策略所构成的隐私保护和漏洞。特别是,我们寻求评估数据收集是否对普通用户显而易见,并评估SmartTV将用户公开到云计算的隐私漏洞的程度。我们的结果表明:(1)用户面临的隐私风险从SmartTVS的危害增加,(2)SmartTVS的大多数数据收集对于普通用户来说并不明显,并且(3)许多SmartTV目标通过要求与制造商进行连接进一步危及用户隐私后端服务器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号