论文标题
可配置的符合隐私网络API
Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs
论文作者
论文摘要
监管数据最小化义务的目的是将个人数据限制为给定上下文所需的绝对最低限度。除初始数据收集,存储和处理外,随后的数据发行还需要数据最小化,因为使用具有查询功能的Web API提供了数据时。但是,提供数据的Web API通常缺乏复杂的数据最小化功能,使该任务开放到手册,并且常常缺少实现。在本文中,我们解决了数据最小化数据提供数据的问题,以提供数据提供数据,具有查询能力的Web API。基于对功能和非功能要求的仔细分析,我们介绍了Janus,这是一种易于使用的,高度可配置的解决方案,用于在GraphQl Web API中实现合法兼容的数据最小化。 Janus提供了一组丰富的信息减少功能,可以为访问API的不同客户端角色配置。我们提出了概念验证验证以及指示合理开销的实验测量。因此,Janus是根据数据最小化的调节原理实现GraphQl API的实用解决方案。
The purpose of regulatory data minimization obligations is to limit personal data to the absolute minimum necessary for a given context. Beyond the initial data collection, storage, and processing, data minimization is also required for subsequent data releases, as it is the case when data are provided using query-capable Web APIs. Data-providing Web APIs, however, typically lack sophisticated data minimization features, leaving the task open to manual and all too often missing implementations. In this paper, we address the problem of data minimization for data-providing, query-capable Web APIs. Based on a careful analysis of functional and non-functional requirements, we introduce Janus, an easy-to-use, highly configurable solution for implementing legally compliant data minimization in GraphQL Web APIs. Janus provides a rich set of information reduction functionalities that can be configured for different client roles accessing the API. We present a technical proof-of-concept along with experimental measurements that indicate reasonable overheads. Janus is thus a practical solution for implementing GraphQL APIs in line with the regulatory principle of data minimization.