Bridging the Gap between Computer Science and Legal Approaches to Privacy

Bridging the Gap between Computer Science and Legal Approaches to Privacy
复制标题

弥合计算机科学与隐私法律方法之间的差距

DOI:
--
复制
发表时间:
2018
期刊:
Harvard Journal of Law & Technology
影响因子:
--
通讯作者:
T. Steinke
T. Steinke
中科院分区:
--
文献类型:
--
作者:
Kobbi Nissim;A. Bembenek;Alexandra Wood;Mark Bun;Marco Gaboardi;Urs Gasser;David O'Brien;S. Vadhan;T. Steinke

文献摘要

被引文献

相似文献

法律和计算机科学领域在分析和发布个人统计数据方面产生了不同的隐私风险概念。来自理论计算机科学文献的新兴概念为量化和减轻隐私风险提供了正式的数学模型。这种模式考虑到的隐私风险概念比许多隐私法所设想的隐私风险要广泛得多。正式隐私模型的一个例子是差分隐私,它提供了一个具体的可证明的隐私保证,可以抵御各种潜在的攻击,包括目前未知或不可预见的攻击类型。许多理论研究的主题,新的隐私技术的基础上正式的模型,如差分隐私最近取得了重大进展,走向实际实施。要将这些工具用于敏感的个人信息,必须证明它们满足隐私保护的相关法律的要求。然而,由于在定义隐私的法律的方法和技术方法之间存在重大的概念差距,提出这样的论点是具有挑战性的。值得注意的是,信息隐私法通常需要解释,并具有一定程度的灵活性,这就给实施更正式的办法带来了不确定性。本条阐述了在公布个人统计数据时,对隐私采取的法律的办法和技术办法之间的差距的性质。它还提出了一个论点,即使用差异隐私足以满足1974年家庭教育权利和隐私法(FERPA),一个联邦法律,保护教育记录的隐私在美国的要求。这一论点说明了什么可能演变成一个更一般的方法,严格认为隐私保护的技术方法满足特定信息隐私法的要求。本文中详细介绍的论点有两个主要组成部分。首先,它涉及到提取一个正式的数学要求的隐私保护的基础上提出的标准FERPA。其次,它描述了一个严格的数学证明,建立差分隐私满足从FERPA提取的数学要求的建设。该论点采取了保守的"最坏情况"的方法,以提取一个数学要求,是强大的潜在的含糊之处,在法律的解释。通过这种方式,数学证明表明,使用差异隐私足以满足对FERPA的广泛合理解释,包括未来可能采用的解释。
The fields of law and computer science have generated different notions of privacy risks in the context of the analysis and release of statistical data about individuals. Emerging concepts from the theoretical computer science literature provide formal mathematical models for quantifying and mitigating privacy risks. Such models take into account a notion of privacy risk that is substantially broader than the privacy risks contemplated by many privacy laws. An example of a formal privacy model is differential privacy, which provides a concrete provable guarantee of privacy against a wide range of potential attacks, including types of attacks currently unknown or unforeseen. The subject of much theoretical investigation, new privacy technologies based on formal models such as differential privacy have recently been making significant strides towards practical implementation. For these tools to be used with sensitive personal information, it is important to demonstrate that they satisfy relevant legal requirements for privacy protection. However, making such an argument is challenging due to the significant conceptual gaps between the legal and technical approaches to defining privacy. Notably, information privacy laws are generally subject to interpretation and some degree of flexibility, which creates uncertainty for the implementation of more formal approaches. This Article articulates the nature of the gaps between legal and technical approaches to privacy in the release of statistical data about individuals. It also presents an argument that the use of differential privacy is sufficient to satisfy the requirements of the Family Educational Rights and Privacy Act of 1974 (FERPA), a federal law that protects the privacy of education records in the United States. This argument illustrates what may evolve to a more general methodology for rigorously arguing that technological methods for privacy protection satisfy the requirements of a particular information privacy law. The argument detailed in this article has two main components. First, it involves the extraction of a formal mathematical requirement of privacy protection based on the standard set forth by FERPA. Second, it describes the construction of a rigorous mathematical proof for establishing that differential privacy satisfies the mathematical requirement extracted from FERPA. The argument takes a conservative “worst-case” approach in order to extract a mathematical requirement that is robust to potential ambiguities in legal interpretation. In this way, the mathematical proof demonstrates that the use of differential privacy is sufficient to satisfy a broad range of reasonable interpretations of FERPA, including interpretations that may be adopted in the future.