...
首页> 外文期刊>International Journal of Information Security >PDGuard: an architecture for the control and secure processing of personal data
【24h】

PDGuard: an architecture for the control and secure processing of personal data

机译:PDGuard:用于控制和安全处理个人数据的架构

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Online personal data are rarely, if ever, effectively controlled by the users they concern. Worse, as demonstrated by the numerous leaks reported each week, the organizations that store and process them fail to adequately safeguard the required confidentiality. In this paper, we proposepdguard, a framework that defines prototypes and demonstrates an architecture and an implementation that address both problems. In the context ofpdguard, personal data are always stored encrypted as opaque objects. Processing them can only be performed through thepdguard application programming interface (api), under data and action-specific authorizations supplied online by third party agents. Through these agents, end-users can easily and reliably authorize and audit how organizations use their personal data. A static verifier can be employed to identify accidentalapimisuses. Following a security by design approach,pdguard changes the problem of personal data management from the, apparently, intractable problem of supervising processes, operations, personnel, and a large software stack to that of auditing the applications that use the framework for compliance. We demonstrate the framework's applicability through a reference implementation, by building apdguard-based e-shop, and by integratingpdguard into theThe Guardiannewspaper's website identity application.
机译:在线个人数据很少,如果有效地,有效地由他们关注的用户控制。更糟糕的是,正如每周报告的众多泄漏所证明的那样,存储和处理它们的组织未能充分保护所需的机密性。在本文中,我们Proposepdguard是一个定义原型的框架,并演示了一个解决这两个问题的架构和实现。在ofpdguard的上下文中,个人数据始终存储为不透明对象。处理它们只能通过第三方代理商在线提供的数据和特定于特定于数据的特定于特定于特定于特定于特定于特定于授权的处理。通过这些代理商,最终用户可以轻松且可靠地授权和审核组织如何使用其个人数据。可以采用静态验证者来识别意外突念。在通过设计方法的安全之后,PDGuard从监督程序,操作,人员和大型软件堆栈中的显现性,难以解决的问题的个人数据管理问题,以审核使用框架符合框架的应用程序。我们通过参考实现,通过建立基于APDGuard的电子产品商店,并将PuddiannewSpaper的网站标识应用程序集成到ContegingPdguard,展示了框架的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号