论文标题
询问专家:物联网隐私和安全标签应该有什么?
Ask the Experts: What Should Be on an IoT Privacy and Security Label?
论文作者
论文摘要
有关物联网(IoT)设备的隐私和安全性的信息,在做出购买决策之前想要考虑的消费者不容易获得。尽管立法者提出了添加简洁,可以访问消费者的标签,但他们并未就这些标签的内容提供指导。在本文中,我们报告了与隐私和安全专家以及消费者进行的一系列访谈和调查结果,我们在其中探索和测试内容的设计空间,以包括在IoT隐私和安全标签上。我们通过遵循22个隐私和安全专家的三轮Delphi流程来进行专家启发研究,以确定专家认为对消费者进行比较时,对消费者进行比较以告知其购买决策时对消费者很重要的因素。基于专家如何认为每个因素向消费者传达风险,我们将这些因素分配给了两个层 - 一个主要层以在产品软件包本身或网站上突出显示,以及通过Web链接或QR代码在线提供的辅助层。我们报告专家的理由和用于支持其因素选择的论点。此外,为了研究消费者如何感知专家指定的隐私和安全信息,我们对15名参与者进行了一系列半结构化访谈,他们购买了至少一个物联网设备(智能家居设备或可穿戴)。根据我们的专家启发和消费者研究的结果,我们提出了一个原型隐私和安全标签,以帮助消费者做出更明智的与IoT相关的购买决策。
Information about the privacy and security of Internet of Things (IoT) devices is not readily available to consumers who want to consider it before making purchase decisions. While legislators have proposed adding succinct, consumer accessible, labels, they do not provide guidance on the content of these labels. In this paper, we report on the results of a series of interviews and surveys with privacy and security experts, as well as consumers, where we explore and test the design space of the content to include on an IoT privacy and security label. We conduct an expert elicitation study by following a three-round Delphi process with 22 privacy and security experts to identify the factors that experts believed are important for consumers when comparing the privacy and security of IoT devices to inform their purchase decisions. Based on how critical experts believed each factor is in conveying risk to consumers, we distributed these factors across two layers---a primary layer to display on the product package itself or prominently on a website, and a secondary layer available online through a web link or a QR code. We report on the experts' rationale and arguments used to support their choice of factors. Moreover, to study how consumers would perceive the privacy and security information specified by experts, we conducted a series of semi-structured interviews with 15 participants, who had purchased at least one IoT device (smart home device or wearable). Based on the results of our expert elicitation and consumer studies, we propose a prototype privacy and security label to help consumers make more informed IoT-related purchase decisions.