PDGuard: an architecture for the control and secure processing of personal data
Autor: | Dimitris Mitropoulos, Diomidis Spinellis, Thodoris Sotiropoulos, Nikos Koutsovasilis |
---|---|
Rok vydání: | 2019 |
Předmět: |
021110 strategic
defence & security studies Application programming interface Computer Networks and Communications business.industry Computer science Data management 0211 other engineering and technologies Context (language use) 02 engineering and technology Computer security computer.software_genre Encryption GeneralLiterature_MISCELLANEOUS Secure by design Identity (object-oriented programming) Reference implementation Safety Risk Reliability and Quality Software architecture business computer Software Information Systems |
Zdroj: | International Journal of Information Security |
ISSN: | 1615-5270 1615-5262 |
Popis: | Online personal data are rarely, if ever, effectively controlled by the users they concern. Worse, as demonstrated by the numerous leaks reported each week, the organizations that store and process them fail to adequately safeguard the required confidentiality. In this paper we propose PDGuard, a framework that defines, prototypes, and demonstrates an architecture and an implementation that address both problems. In the context of PDGuard, personal data are always stored encrypted as opaque objects. Processing them can only be performed through the PDGuard Application Programming Interface (API), under data and action-specific authorizations supplied online by third-party agents. Through these agents end-users can easily and reliably authorize and audit how organizations use their personal data. A static verifier can be employed to identify accidental API misuses. Following a security by design approach, PDGuard changes the problem of personal data management from the, apparently, intractable problem of supervising processes, operations, personnel, and a large software stack to that of auditing the applications that use the framework for compliance. We demonstrate the framework's applicability through a reference implementation, by building a PDGuard-based e-shop, and by integrating PDGuard into the The Guardian newspaper's website identity application. (Journal article preprint) |
Databáze: | OpenAIRE |
Externí odkaz: |