Analyzing GDPR compliance of named data networking

Analyzing GDPR compliance of named data networking
复制标题

DOI:
10.1145/3460417.3482979
复制
发表时间:
2021-09
期刊:
Proceedings of the 8th ACM Conference on Information-Centric Networking
影响因子:
--
通讯作者:
Casey Tran;R. Tourani;S. Misra;Travis Machacek;Gaurav Panwar
Casey Tran;R. Tourani;S. Misra;Travis Machacek;Gaurav Panwar
中科院分区:
其他
文献类型:
--
作者:
Casey Tran;R. Tourani;S. Misra;Travis Machacek;Gaurav Panwar

文献摘要

被引文献

相似文献

社交媒体平台、物联网 (IoT) 设备和无数智能手机应用程序的普及为公司和组织创造了收集个人数据并通过其共享高速获利的机会。一个突出的例子是 Facebook 与 Cambridge Analytica 的数据共享协议(2018 年),该协议允许 Cambridge Analytica 在未经用户同意的情况下收集数百万 Facebook 用户的个人数据用于政治广告。为了应对此类越权和侵犯隐私的行为,欧盟推出了《通用数据保护条例》(GDPR),该条例要求数据收集者保护个人数据隐私,并为用户提供对其个人数据的更多控制权。出于对个人隐私日益增长的兴趣,我们在命名数据网络 (NDN) 的背景下分析 GDPR 文章。感兴趣的背景是 NDN 作为服务提供商的网络架构,我们研究了与 GDPR 相关的 NDN 功能,包括命名、缓存、转发平面及其内置信任,以实现 GDPR 合规性,并提供有关如何在缺乏合规性时构建此类合规性的见解。我们还提供了显示合规性开销的实验结果,并通过确定未来潜在的工作来得出结论。
The popularity of social media platforms, Internet of Things (IoT) devices, and the myriad smartphone applications have created opportunities for companies and organizations to collect individuals' personal data and monetize its sharing at a high rate. A standout example was the Facebook--Cambridge Analytica data-sharing arrangement (2018), which allowed Cambridge Analytica to harvest millions of Facebook users' personal data without their consent for political advertisement. In response to such overreach and privacy violations, the European Union introduced the General Data Protection Regulation (GDPR), which mandates data collectors to protect individuals' data privacy and provide the user more control over their personal data. Motivated by this growing interest in personal privacy, we analyze GDPR articles in the context of Named Data Networking (NDN). The context of interest is NDN as the network architecture in a service provider and we investigate GDPR-pertinent NDN features, including naming, caching, forwarding plane, and its built-in trust, for GDPR compliance and present insights on how such compliance can be built, when lacking. We also present experimental results showing compliance overheads and conclude by identifying potential future work.