论文标题

评估与安全与隐私义务有关的可靠协议

Assessing the Solid Protocol in Relation to Security & Privacy Obligations

论文作者

Esposito, Christian, Hartig, Olaf, Horne, Ross, Sun, Chang

论文摘要

扎实的规范旨在通过在多个应用程序中对数据进行直接访问对数据的控制来赋予数据主题。由于政府对这一对公民授权和电子政务服务的框架表现出了他们的兴趣,因此安全和隐私是要解决的关键问题。通过分析相关立法,尤其是GDPR和国际标准,即ISO/IEC 27001:2011和15408,我们制定了此类框架的主要安全和隐私要求。此外,我们调查了当前有关它们如何涵盖突出显示要求的实体协议规范,并提请注意规格和要求之间的潜在差距。我们还指出了最近的学术工作的贡献,介绍了新方法,以提高稳固项目提供的安全性和隐私学位。本文有双重贡献,可以提高用户对固体如何帮助保护其数据的认识,并提出有关固体安全和隐私增强的未来研究行。

The Solid specification aims to empower data subjects by giving them direct access control over their data across multiple applications. As governments are manifesting their interest in this framework for citizen empowerment and e-government services, security and privacy represent pivotal issues to be addressed. By analyzing the relevant legislation, notably GDPR, and international standards, namely ISO/IEC 27001:2011 and 15408, we formulate the primary security and privacy requirements for such a framework. Furthermore, we survey the current Solid protocol specifications regarding how they cover the highlighted requirements, and draw attention to potential gaps between the specifications and requirements. We also point out the contribution of recent academic work presenting novel approaches to increase the security and privacy degree provided by the Solid project. This paper has a twofold contribution to improve user awareness of how Solid can help protect their data and to present possible future research lines on Solid security and privacy enhancements.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源