Collaborative Research: EAGER: MedAn: A Framework for Investigating Live Medical Data against Privacy Laws
Collaborative Research: EAGER: MedAn: A Framework for Investigating Live Medical Data against Privacy Laws
批准号:
2335687
负责人:
Indrakshi Ray
金额:
$12.49万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-10-01 至 2025-09-30
中文摘要
该研究项目旨在开发一个框架,以评估和改善收集和使用个人健康数据的移动的健康应用程序(应用程序)的隐私和安全性。这些应用程序通常用于智能手机和智能设备,有可能大大改善医疗保健的可及性。然而,人们担心他们收集和生成的敏感用户数据的隐私和保护。该研究项目认识到需要一种以用户为中心的方法,以确保遵守隐私法规,提高法律的文件和应用程序描述的清晰度,并在应用程序设计过程中纳入隐私和安全措施。其目标是在使用健康应用程序时为用户提供对其个人数据的更多控制,并建立一个框架,指导应用程序开发人员创建安全透明的应用程序。该项目的创新之处包括:(i)开发模型,以弥合处理个人医疗数据的监管要求和技术规范之间的差距;(ii)开发一个框架,用于对移动的健康应用程序进行以隐私为中心的分析,为用户提供对其个人数据的细粒度透明度和控制。该项目更广泛的意义和重要性在于,在日益普遍使用的处理敏感个人数据的健康应用程序中保护用户隐私和安全。通过解决监管合规性问题、提高法律的文件的清晰度以及增强应用程序设计流程,这项研究可确保用户能够控制其数据并做出明智的决策。本研究的技术方法涉及开发能够跨体裁蕴涵和推理的自然语言处理模型,将法律的语言语义与软件设计和开发中的技术规范相连接。这些模型有助于识别隐私漏洞,从研究中得出隐私约束,并开发了一个正式的隐私模型,具有三个关键属性:完整性,最小性和一致性。最后,研究分析了移动的健康应用程序,以检查是否符合政策模型。为了确保对整个数据生命周期执行这种分析,使用了高级语言模型和特定于领域的语义相似性模型的组合。这些模型有助于框架根据隐私法分析移动的健康应用程序,并通过为用户提供对其个人数据的细粒度控制和透明度来增强用户的能力。这项研究的预期进展包括非专业人士和工程师更好地理解法律的语言,增强对移动的应用程序的隐私分析,并使用户能够获得有关数据收集,必要性和对实时个人数据进行更多控制的能力的明确信息。总体而言,它促进了用户在使用健康应用程序时的安全和隐私。项目网站将由斯托尼布鲁克大学计算机科学系主办,并由主要研究者定期维护和更新。该网站将提供可公开发布的数据、研究论文、会议和讲座材料以及软件产品。这项研究的软件产品也将在开发库中公开提供(例如,该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This research project aims to develop a framework to assess and improve the privacy and security of mobile health applications (apps) that collect and use personal health data. These apps, commonly used on smartphones and smart devices, have the potential to greatly improve access to healthcare. However, there are concerns about the privacy and protection of the sensitive user data they collect and generate. The research project recognizes the need for a user-centered approach that ensures compliance with privacy regulations, enhances clarity in legal documents and app descriptions, and incorporates privacy and security measures during the app design process. The goal is to provide users with more control over their personal data while using health apps and to establish a framework that guides app developers in creating safe and transparent applications. The project's novelties include the development of (i) models to bridge the gap between regulatory requirements and technical specifications for handling personal medical data, and (ii) a framework for privacy-focused analysis of mobile health apps that provides users with fine-grained transparency and control over their personal data. The project's broader significance and importance lie in safeguarding user privacy and security in the increasingly prevalent use of health apps, which handle sensitive personal data. By addressing regulatory compliance, improving clarity in legal documents, and enhancing app design processes, this research ensures that users have control over their data and can make informed decisions. Ultimately, it promotes trust in health apps, encourages responsible development, and contributes to the advancement of privacy protection in the digital healthcare landscape.The technical approach of this research involves developing natural language processing models capable of cross-genre entailment and inference, connecting the semantics of legal language to technical specifications in software design and development. These models help in identifying privacy vulnerabilities, from which the research derives privacy constraints and develops a formal privacy model with three key properties: completeness, minimality, and consistency. Finally, the research analyzes mobile health apps to check for conformity with the policy model. To ensure this analysis is performed for the entire data life cycle, a combination of advanced language models and domain-specific models of semantic similarity is used. These models help the framework to analyze mobile health apps in terms of privacy laws and empower users by providing them fine-grained control and transparency over their personal data. The expected advances due to this research include better comprehension of legal language by non-specialists and engineers, enhanced privacy-focused analysis of mobile apps, and enable users with clear information about data collections, necessity, and the ability to gain more control over their real-time personal data. Overall, it promotes user safety and privacy in the use of health applications. A project website will be hosted by the Department of Computer Science at Stony Brook University and regularly maintained and updated by the principal investigator. This website will provide access to publicly releasable data, research papers, conference and lecture material, and software products. The software products of this research will also be publicly available on development repositories (e.g., GitHub or Bitbucket).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/bigdata59044.2023.10386280
发表时间:
2023-11
期刊:
2023 IEEE International Conference on Big Data (BigData)
影响因子:
--
作者:
[Matt Gorbett;Hossein Shirazi;Indrakshi Ray]
通讯作者:
Matt Gorbett;Hossein Shirazi;Indrakshi Ray
RAPID: ENSURING INTEGRITY OF COVID-19 DATA AND NEWS ACROSS REGIONS
-
批准号:2027750
-
项目类别:Standard Grant
-
资助金额:$19.97万
-
财政年份:2020
-
负责人:Indrakshi Ray
-
依托单位:
IUCRC Phase II Colorado State University: Center for Cybersecurity Analytics and Automation CCAA
-
批准号:1822118
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2019
-
负责人:Indrakshi Ray
-
依托单位:
Colorado State University Site Addition: I/UCRC Center for Configuration Analytics and Automation
-
批准号:1650573
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2017
-
负责人:Indrakshi Ray
-
依托单位:
SaTC: CORE: Small: Collaborative: GOALI: Detecting and Reconstructing Network Anomalies and Intrusions in Heavy Duty Vehicles
-
批准号:1715458
-
项目类别:Standard Grant
-
资助金额:$27.57万
-
财政年份:2017
-
负责人:Indrakshi Ray
-
依托单位:
EAGER: Collaborative: Toward a Test Bed for Heavy Vehicle Cyber Security Experimentation
-
批准号:1619641
-
项目类别:Standard Grant
-
资助金额:$13.0万
-
财政年份:2016
-
负责人:Indrakshi Ray
-
依托单位:
Planning Grant: I/UCRC for Joining Center for Configuration Analytics and Automation
-
批准号:1540041
-
项目类别:Standard Grant
-
资助金额:$1.45万
-
财政年份:2015
-
负责人:Indrakshi Ray
-
依托单位:
SHF: Small: Scenario-Based Validation of Design Models
-
批准号:1018711
-
项目类别:Continuing Grant
-
资助金额:$49.99万
-
财政年份:2010
-
负责人:Indrakshi Ray
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: