首页> 外文学位 >Designing for informed consent: A multi-domain, interdisciplinary analysis of the technological means to provide informed consent, in order to manage users' privacy and security.
【24h】

Designing for informed consent: A multi-domain, interdisciplinary analysis of the technological means to provide informed consent, in order to manage users' privacy and security.

机译:设计知情同意书:对提供知情同意书的技术手段进行多领域,跨学科的分析,以管理用户的隐私和安全。

获取原文
获取原文并翻译 | 示例

摘要

Continuously interconnected network devices are now a reality for the general public, from networked desktop computers, to mobile phones, to new and upcoming technologies such as RFID and Sensor Networks. In addition to the numerous benefits that these technologies provide, there is concern that computer devices continuously connected to the network could have strong implications for privacy and security. Understanding the effects that new networked technologies have on security and privacy has implications for a variety of domains, and crosses over many disciplines such as Law, Policy, Ubicomp, HCI, and Security.;The main area of concern is where the user interacts with the technologies' user interface. Questions and concerns regarding a user's mental model of a system include the design of the interfaces which consumers use to access personal information, and the interfaces used to inform consumers about their choices and obligations regarding the technology. Breakdowns in communication between technology and consumer are revealed when consumers unintentionally consent to reveal or divulge information which they did not believe the system was capable of obtaining and/or sharing.;The question of designing for informed consent is fundamental to the work performed in this thesis. I seek to understand the effects of various designs on a user's understanding when making informed decisions and using different networked technologies, and also, how that understanding, or lack of, may relate to intended or unintended consequences. Understanding these effects is inherently a multidisciplinary problem, which requires an interdisciplinary approach. To this end, I have employed a variety of methodologies, both qualitative and quantitative, to explore various aspects of this problem in varying technology domains. I look at how four different technologies which were designed for informed consent. I chose desktop technologies, technologies on mobile devices, and RFID technologies that are passive, embedded in our environment, and have no traditional user interface. Additionally, I looked at different types of information that users would want to manage, such as personal data and media (photos), and contextual information (location). I also looked at how users' motivations for using the technology have aligned with the technology's intended purpose, as well as any issues that may arise when conflicts exists.;While these technologies appear to be loosely connected, they all share the problem of informed consent, and all require that users be adequately informed to make decisions regarding private and potentially, sensitive, information. In addition, all of these technologies have had incidents in which users were not adequately informed, and consequently, have experienced embarrassing and potentially dangerous revelations of sensitive and personal information. In KaZaA, I describe how users have inadvertently shared personal tax documents, credit card information, and in some cases, national secrets. In ZoneTag, I describe examples where photos range from the amusing (making fun of someone's wedding picture) to the embarrassing (naked photo of self in the bathtub), and without regard, have been exposed on the internet. In my Spyware studies, I demonstrate how design of EULAs contributes to users' frequent agreement to program behavior, which they regret later. In RFID, I describe the inherent risks of RFID systems and how important it is to provide safeguards that prevent people from revealing too much information about their reading habits and location.;The contributions of my work are: (1) New methodologies and metrics for performing studies on informed consent; (2) A flexible experimental framework for testing informed consent notice designs; (3) A series of first time empirical studies and data gathered across several technology domains; (4) Analysis of qualitative and quantitative data providing new insights and understandings for online informed consent; (5) Influencing policy makers reception to design studies through congressional hearings and workshops.;In conclusion, I find that informed consent is an area of research that cannot be amended simply by using design methodologies. While significant improvements to current designs can be done by applying HCI methodologies, a combination of methods and incentives, from a variety of disciplines, is needed to make sustained long term improvements to informed consent.
机译:从联网的台式计算机到移动电话,再到诸如RFID和传感器网络等新的和即将出现的技术,连续互连的网络设备现在已成为普通大众的现实。除了这些技术提供的众多好处外,持续连接到网络的计算机设备可能会对隐私和安全性产生重大影响。了解新的网络技术对安全性和隐私的影响会影响到各个领域,并且跨越了法律,政策,Ubicomp,HCI和安全性等许多学科。;主要关注的领域是用户与之交互技术的用户界面。与用户的系统心理模型有关的问题和疑虑包括消费者用来访问个人信息的界面的设计,以及用于告知消费者有关技术的选择和义务的界面。当消费者无意中同意披露或泄露他们认为系统无法获得和/或共享的信息时,就会显示出技术与消费者之间的通信故障。设计知情同意的问题是此工作的基础论文。我试图了解在做出明智的决定并使用不同的联网技术时,各种设计对用户理解的影响,以及这种理解或缺乏理解如何与预期或非预期的后果相关。了解这些影响本质上是一个多学科的问题,需要跨学科的方法。为此,我采用了定性和定量的各种方法,以探讨不同技术领域中该问题的各个方面。我将研究为知情同意而设计的四种不同技术。我选择了桌面技术,移动设备技术和无源,嵌入在我们的环境中且没有传统用户界面的RFID技术。此外,我研究了用户想要管理的不同类型的信息,例如个人数据和媒体(照片)以及上下文信息(位置)。我还研究了用户使用该技术的动机如何与该技术的预期目的保持一致,以及存在冲突时可能出现的任何问题。虽然这些技术似乎是松散连接的,但它们都存在知情同意的问题。 ,并且都要求充分告知用户有关隐私和潜在敏感信息的决策。另外,所有这些技术都发生了事件,用户没有得到足够的信息,因此,经历了敏感和个人信息的尴尬和潜在危险的启示。在KaZaA中,我描述了用户无意间共享了个人税务文件,信用卡信息以及在某些情况下的国家机密的方式。在ZoneTag中,我描述了一些示例,这些示例从有趣的照片(取笑某人的结婚照)到令人尴尬的照片(在浴缸中暴露出自己的裸体照片),而这些照片在互联网上都没有受到关注。在我的间谍软件研究中,我演示了EULA的设计如何促进用户对程序行为的频繁同意,后来他们对此表示遗憾。在RFID中,我描述了RFID系统的固有风险以及提供保护措施以防止人们透露太多有关其阅读习惯和位置的信息有多重要。我的工作包括:(1)新的方法论和度量标准在知情同意下进行研究; (2)用于测试知情同意书设计的灵活实验框架; (3)跨多个技术领域的一系列首次实证研究和数据; (4)对定性和定量数据的分析,为在线知情同意提供了新的见解和理解; (5)通过国会听证会和讲习班影响决策者对设计研究的接受。总之,我发现知情同意是一个研究领域,不能仅仅通过使用设计方法来修改。尽管可以通过应用人机交互(HCI)方法对当前设计进行重大改进,但仍需要将各种学科的方法和激励措施结合起来,以对知情同意进行持续的长期改进。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号