课题基金 / 基金详情

Collaborative Research: EAGER: MedAn: A Framework for Investigating Live Medical Data against Privacy Laws

Collaborative Research: EAGER: MedAn: A Framework for Investigating Live Medical Data against Privacy Laws
合作研究:EAGER:MedAn:根据隐私法调查实时医疗数据的框架
批准号:
2335687
负责人:
Indrakshi Ray
金额:
$12.49万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-10-01 至 2025-09-30

项目摘要

项目成果

Indrakshi Ray的其他基金

相似基金

相关文献

中文摘要
翻译
本研究项目旨在开发一个框架,以评估和改善收集和使用个人健康数据的移动健康应用程序(应用程序)的隐私和安全性。这些应用程序通常在智能手机和智能设备上使用,有可能极大地改善获得医疗保健的机会。然而,人们对他们收集和生成的敏感用户数据的隐私和保护表示担忧。该研究项目认识到需要以用户为中心的方法,以确保遵守隐私法规,提高法律文件和应用程序描述的清晰度,并在应用程序设计过程中纳入隐私和安全措施。其目标是让用户在使用健康应用程序时更好地控制自己的个人数据,并建立一个框架,指导应用程序开发人员创建安全透明的应用程序。该项目的新颖之处包括开发(i)模型,以弥合处理个人医疗数据的监管要求和技术规范之间的差距,以及(ii)一个以隐私为重点的移动健康应用程序分析框架,为用户提供细粒度的透明度和对其个人数据的控制。该项目更广泛的意义和重要性在于,在日益普遍使用的健康应用程序中,保护用户隐私和安全,这些应用程序处理敏感的个人数据。通过解决法规遵从性,提高法律文件的清晰度,并加强应用程序设计过程,这项研究确保用户能够控制他们的数据,并可以做出明智的决定。最终,它促进了对健康应用程序的信任,鼓励负责任的开发,并有助于提高数字医疗领域的隐私保护。本研究的技术方法包括开发能够跨类型蕴涵和推理的自然语言处理模型,将法律语言的语义与软件设计和开发中的技术规范联系起来。这些模型有助于识别隐私漏洞,从这些漏洞中推导出隐私约束,并开发出具有完整性、最小性和一致性三个关键属性的正式隐私模型。最后,研究分析了移动健康应用程序,以检查是否符合政策模型。为了确保在整个数据生命周期中执行这种分析,需要结合使用高级语言模型和特定于领域的语义相似度模型。这些模型有助于该框架根据隐私法分析移动健康应用程序,并通过为用户提供对其个人数据的细粒度控制和透明度来授权用户。这项研究的预期进展包括非专业人员和工程师更好地理解法律语言,增强以隐私为中心的移动应用程序分析,并使用户能够清楚地了解数据收集、必要性以及对其实时个人数据进行更多控制的能力。总的来说,它促进了用户在使用健康应用程序时的安全和隐私。项目网站将由石溪大学计算机科学系主持,并由首席研究员定期维护和更新。该网站将提供对公开发布的数据、研究论文、会议和讲座材料以及软件产品的访问。本研究的软件产品也将在开发存储库(例如,GitHub或Bitbucket)上公开提供。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This research project aims to develop a framework to assess and improve the privacy and security of mobile health applications (apps) that collect and use personal health data. These apps, commonly used on smartphones and smart devices, have the potential to greatly improve access to healthcare. However, there are concerns about the privacy and protection of the sensitive user data they collect and generate. The research project recognizes the need for a user-centered approach that ensures compliance with privacy regulations, enhances clarity in legal documents and app descriptions, and incorporates privacy and security measures during the app design process. The goal is to provide users with more control over their personal data while using health apps and to establish a framework that guides app developers in creating safe and transparent applications. The project's novelties include the development of (i) models to bridge the gap between regulatory requirements and technical specifications for handling personal medical data, and (ii) a framework for privacy-focused analysis of mobile health apps that provides users with fine-grained transparency and control over their personal data. The project's broader significance and importance lie in safeguarding user privacy and security in the increasingly prevalent use of health apps, which handle sensitive personal data. By addressing regulatory compliance, improving clarity in legal documents, and enhancing app design processes, this research ensures that users have control over their data and can make informed decisions. Ultimately, it promotes trust in health apps, encourages responsible development, and contributes to the advancement of privacy protection in the digital healthcare landscape.The technical approach of this research involves developing natural language processing models capable of cross-genre entailment and inference, connecting the semantics of legal language to technical specifications in software design and development. These models help in identifying privacy vulnerabilities, from which the research derives privacy constraints and develops a formal privacy model with three key properties: completeness, minimality, and consistency. Finally, the research analyzes mobile health apps to check for conformity with the policy model. To ensure this analysis is performed for the entire data life cycle, a combination of advanced language models and domain-specific models of semantic similarity is used. These models help the framework to analyze mobile health apps in terms of privacy laws and empower users by providing them fine-grained control and transparency over their personal data. The expected advances due to this research include better comprehension of legal language by non-specialists and engineers, enhanced privacy-focused analysis of mobile apps, and enable users with clear information about data collections, necessity, and the ability to gain more control over their real-time personal data. Overall, it promotes user safety and privacy in the use of health applications. A project website will be hosted by the Department of Computer Science at Stony Brook University and regularly maintained and updated by the principal investigator. This website will provide access to publicly releasable data, research papers, conference and lecture material, and software products. The software products of this research will also be publicly available on development repositories (e.g., GitHub or Bitbucket).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/bigdata59044.2023.10386280
发表时间: 2023-11
期刊: 2023 IEEE International Conference on Big Data (BigData)
影响因子: --
作者: [Matt Gorbett;Hossein Shirazi;Indrakshi Ray]
通讯作者: Matt Gorbett;Hossein Shirazi;Indrakshi Ray
RAPID: ENSURING INTEGRITY OF COVID-19 DATA AND NEWS ACROSS REGIONS
  • 批准号:
    2027750
  • 项目类别:
    Standard Grant
  • 资助金额:
    $19.97万
  • 财政年份:
    2020
  • 负责人:
    Indrakshi Ray
  • 依托单位:
IUCRC Phase II Colorado State University: Center for Cybersecurity Analytics and Automation CCAA
  • 批准号:
    1822118
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2019
  • 负责人:
    Indrakshi Ray
  • 依托单位:
Colorado State University Site Addition: I/UCRC Center for Configuration Analytics and Automation
  • 批准号:
    1650573
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2017
  • 负责人:
    Indrakshi Ray
  • 依托单位:
SaTC: CORE: Small: Collaborative: GOALI: Detecting and Reconstructing Network Anomalies and Intrusions in Heavy Duty Vehicles
  • 批准号:
    1715458
  • 项目类别:
    Standard Grant
  • 资助金额:
    $27.57万
  • 财政年份:
    2017
  • 负责人:
    Indrakshi Ray
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)