CAREER: Privacy-Accountable Mobile Software Supply Chain
职业:隐私负责的移动软件供应链
基本信息
- 批准号:2339537
- 负责人:
- 金额:$ 56.7万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2024
- 资助国家:美国
- 起止时间:2024-07-01 至 2029-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Data protection regulations specify how personal data must be protected when used by others. Tracking and accounting for protections of data privacy has emerged as a pivotal requirement in contemporary data protection regulations. As a result, those who are responsible for using personal data, so-called data controllers, must actively enhance the privacy safeguards they provide. This project addresses the intricate challenges surrounding privacy accountability within the mobile software ecosystem, characterized by the opacity of third-party code modules, particularly third-party libraries. Existing methods for achieving privacy accountability primarily emphasize data transparency, often overlooking essential principles like data minimization and purpose limitation and facing integration challenges within mobile software development lifecycles. This research project seeks to address these limitations by presenting innovative approaches to enforce privacy accountability throughout the mobile software development process. The goal is to establish a more privacy-conscious and accountable mobile ecosystem, benefiting both users and data controllers. The outcomes of the research will contribute to educational curriculum and training to help developers achieve privacy goals plus additional outreach through workshop and bootcamp venues. The project's technical objectives are divided into three research thrusts: (1) understanding privacy accountability challenges in the mobile third-party code modules; (2) designing a privacy-accountable disclosure framework; (3) continuously enforcing privacy accountability properties in mobile software development lifecycle. The technical contribution of this research lies in advancing the socio-technical understanding of privacy non-compliance risks and accountability challenges within the mobile software supply chain. Additionally, it involves designing novel technical foundations that seamlessly integrate various methodologies and disciplines. This includes program analysis, formal methods, natural language processing, and human subject research, culminating in a privacy-accountable disclosure framework and continuous privacy accountability enforcement mechanism. These innovations are designed to be easily adoptable within the mobile software supply chain. The research will foster a holistic approach to enhancing privacy protection and accountability in mobile software development lifecycle and contribute to the creation of a safer and more privacy-conscious mobile ecosystem.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
数据保护法规规定了个人数据在被他人使用时必须如何保护。对数据隐私的保护进行跟踪和核算已成为当代数据保护法规的关键要求。因此,那些负责使用个人数据的人,即所谓的数据管制员,必须积极加强他们提供的隐私保护。该项目解决了移动软件生态系统中围绕隐私责任的复杂挑战,其特点是第三方代码模块,特别是第三方库的不透明。现有的实现隐私责任的方法主要强调数据透明度,往往忽略了数据最小化和目的限制等基本原则,并在移动软件开发生命周期中面临集成挑战。本研究项目试图通过提出在整个移动软件开发过程中加强隐私责任的创新方法来解决这些限制。目标是建立一个更具隐私意识和更负责任的移动生态系统,使用户和数据控制器都受益。研究结果将有助于教育课程和培训,以帮助开发人员实现隐私目标,并通过研讨会和训练营场所进行额外的推广。该项目的技术目标分为三个研究主题:(1)了解移动第三方代码模块中的隐私责任挑战;(2)设计隐私责任披露框架;(3)在移动软件开发生命周期中持续执行隐私责任属性。这项研究的技术贡献在于促进对移动软件供应链中的隐私、不合规风险和问责挑战的社会技术理解。此外,它还涉及设计无缝集成各种方法和学科的新型技术基础。这包括程序分析、正式方法、自然语言处理和人类主题研究,最终形成隐私责任披露框架和持续的隐私责任执行机制。这些创新设计为便于在移动软件供应链中采用。这项研究将促进在移动软件开发生命周期中加强隐私保护和责任的整体方法,并有助于创建一个更安全、更具隐私意识的移动生态系统。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Xiaojing Liao其他文献
Catching predators at watering holes: finding and understanding strategically compromised websites
在水坑中捕获掠夺者:查找和了解战略性受损网站
- DOI:
10.1145/2991079.2991112 - 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Sumayah A. Alrwais;Kan Yuan;Eihal Alowaisheq;Xiaojing Liao;Alina Oprea;Xiaofeng Wang;Zhou Li - 通讯作者:
Zhou Li
A novel heat dissipation structure for PSiP package
一种新型PSiP封装散热结构
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Zhaozheng Hou;Xiaojing Liao;Hao Peng;Yiyu Wang - 通讯作者:
Yiyu Wang
Cloud repository as a malicious service: challenge, identification and implication
云存储库作为恶意服务:挑战、识别和影响
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Xiaojing Liao;Sumayah A. Alrwais;Kan Yuan;Luyi Xing;Xiaofeng Wang;S. Hao;R. Beyah - 通讯作者:
R. Beyah
Price TAG: Towards Semi-Automatically Discovery Tactics, Techniques and Procedures OF E-Commerce Cyber Threat Intelligence
Price TAG:走向电子商务网络威胁情报的半自动发现策略、技术和程序
- DOI:
10.1109/tdsc.2021.3120415 - 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Yiming Wu;Qianjun Liu;Xiaojing Liao;Shouling Ji;Peng Wang;Xiaofeng Wang;Chunming Wu;Zhao Li - 通讯作者:
Zhao Li
Towards Secure Metering Data Analysis via Distributed Differential Privacy
通过分布式差分隐私实现安全计量数据分析
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Xiaojing Liao;David Formby;Carson Day;R. Beyah - 通讯作者:
R. Beyah
Xiaojing Liao的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Xiaojing Liao', 18)}}的其他基金
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
SaTC:核心:媒介:协作:通过自动分析在线文本痕迹理解和发现非法在线业务
- 批准号:
1850725 - 财政年份:2018
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
SaTC:核心:媒介:协作:通过自动分析在线文本痕迹理解和发现非法在线业务
- 批准号:
1801365 - 财政年份:2018
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
相似海外基金
Evolving privacy and utility in data storage and publishing
数据存储和发布中不断发展的隐私和实用性
- 批准号:
DE240100165 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Discovery Early Career Researcher Award
CAREER: Verifying Security and Privacy of Distributed Applications
职业:验证分布式应用程序的安全性和隐私
- 批准号:
2338317 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
CRII: SaTC: Privacy vs. Accountability--Usable Deniability and Non-Repudiation for Encrypted Messaging Systems
CRII:SaTC:隐私与责任——加密消息系统的可用否认性和不可否认性
- 批准号:
2348181 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Standard Grant
A Principled Framework for Explaining, Choosing and Negotiating Privacy Parameters of Differential Privacy
解释、选择和协商差异隐私的隐私参数的原则框架
- 批准号:
23K24851 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
Global Road Damage Detection with privacy-preserved collaboration
通过保护隐私的协作进行全球道路损坏检测
- 批准号:
24K17366 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
CAREER: Architectural Foundations for Practical Privacy-Preserving Computation
职业:实用隐私保护计算的架构基础
- 批准号:
2340137 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
Collaborative Research: SHF: Small: Efficient and Scalable Privacy-Preserving Neural Network Inference based on Ciphertext-Ciphertext Fully Homomorphic Encryption
合作研究:SHF:小型:基于密文-密文全同态加密的高效、可扩展的隐私保护神经网络推理
- 批准号:
2412357 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Standard Grant
Collaborative Research: CIF-Medium: Privacy-preserving Machine Learning on Graphs
合作研究:CIF-Medium:图上的隐私保护机器学习
- 批准号:
2402815 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Standard Grant
Collaborative Research: NeTS: Small: A Privacy-Aware Human-Centered QoE Assessment Framework for Immersive Videos
协作研究:NetS:小型:一种具有隐私意识、以人为本的沉浸式视频 QoE 评估框架
- 批准号:
2343619 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Standard Grant
SHF: Small: Hardware-Software Co-design for Privacy Protection on Deep Learning-based Recommendation Systems
SHF:小型:基于深度学习的推荐系统的隐私保护软硬件协同设计
- 批准号:
2334628 - 财政年份:2024
- 资助金额:
$ 56.7万 - 项目类别:
Standard Grant