Collaborative Research: DASS: Legally Accountable Cryptographic Computing Systems (LAChS)
Collaborative Research: DASS: Legally Accountable Cryptographic Computing Systems (LAChS)
批准号:
2131541
负责人:
Daniel Weitzner
金额:
$57.61万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30
中文摘要
社会正在艰难地管理数字系统,治理不善的系统导致社会在将敏感或高优先级任务委托给这些系统的意愿方面存在差距。这一挑战的部分原因是,法律和软件在非常不同的细节级别上处理规则和行为。法律在适用时必须是一般性的,因此将解释和详细要求留给软件开发人员自行决定。这使得软件开发人员,他们不能被期望成为法律专家,必须决定什么是适当的技术设计,以遵守往往复杂的法律规则。例如,当隐私法如一般数据保护条例(GDPR)要求用户有权删除其数据时,这是否意味着包括备份在内的所有数据?如果这些问题没有明确的答案,开发商就不能相信他们已经成功地遵守了法律要求,然后使用这些系统的公众就没有理由信任他们了。这个项目的创新之处在于引入了设计模式,帮助软件开发人员可靠而有目的地组装组件,因为他们知道这些组件有效地满足了政策要求,从而保证了公众的信心。该项目的影响在两个方面造福社会。首先,通过缩小法律和系统之间的抽象鸿沟,本项目中开发的方法和工具帮助软件开发人员构建符合法律义务的系统。其次,该项目进一步促进了计算机科学和法律研究社区的发展。Laches(发音为“lox”)项目对更好地理解如何构建负责任的软件系统做出了两项贡献。首先,策略概念允许软件开发人员确定他们正在开发的系统的功能方面,以便评估系统的功能是否符合与他们正在执行的计算相关的策略约束。除了政策概念,该项目还引入了政策标准--法律要求的功能描述。总而言之,政策概念和政策标准提供了一个软件工程框架,开发人员可以通过该框架更容易地构建对法律要求负责的系统。第二,该项目制定了一种综合的法律-技术方法,以评估一个系统在一系列法律要求方面的问责性质。以往的工作一般都试图将问责制仅仅定义为信息系统的一种属性。该项目表明,充分理解问责制需要考虑法律和计算机系统的性质。总而言之,这项研究的前提是,在隐私等关键社会优先事项方面,法律实际上在界定数字用户的关键权利方面取得了相当大的进展,而基础技术仍在努力适应这些挑战。因此,该项目旨在为法律和技术方法带来更明确的抽象化、模块化和可组合性,以更好地应对这些挑战。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Society is having a hard time governing digital systems, and poorly governed systems lead to gaps in society's willingness to trust these systems with sensitive or high-priority tasks. Part of this challenge arises from the fact that law and software address rules and behavior at very different levels of detail. Laws must be general in their application and thus leave interpretation and detailed requirements to the discretion of software developers. This leaves software developers, who cannot be expected to be legal experts, having to decide what is the proper technical design to comply with often-complex legal rules. For example, when a privacy law such as the General Data Protection Regulation (GDPR) requires that users have a right to delete their data, does that mean all data, including backups? Without clear answers to such questions, developers can’t be confident that they have successfully complied with legal requirements, and then the public who uses these systems has little reason to trust them. This project's novelties are to introduce design patterns that help software developers assemble components reliably and purposefully, in the knowledge that they meet policy requirements effectively and thus warrant the confidence of the public. The project's impact benefits society in two ways. First, by closing the abstraction gap between law and systems, methods and tools developed in this project help software developers build systems that comply with legal obligations. Second, the project furthers the development of a research community in computer science and law. The LAChS (pronounced "lox") project makes two contributions toward better understanding of how to build accountable software systems. First, policy concepts allow software developers to identify the functional aspects of systems they are developing in order to assess whether the functions of the system are consistent with the policy constraints associated with the computations they are performing. Along with policy concepts, the project introduces policy standards -- functional descriptions of the requirements of law. Together, policy concepts and policy standards provide a software-engineering framework through which developers can more easily build systems that are accountable to legal requirements. Second, the project develops an integrated legal-technical methodology for assessing the accountability properties of a system with respect to a set of legal requirements. Prior work has generally sought to define accountability solely as a property of information systems. The project shows that a full understanding of accountability requires considering the properties of both law and computing systems. In sum, this research is premised on the view that, with respect to key societal priorities such as privacy, the law has actually made considerable progress in defining key rights for the digital, while underlying technology is still struggling to adapt to these challenges. Thus the project aims to bring more clear abstraction, modularization and composability to legal and technical methodologies in order to better meet these challenges.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3531225
发表时间:
2022-04
期刊:
ACM Transactions on Privacy and Security
影响因子:
2.3
作者:
[Lihi Idan;J. Feigenbaum]
通讯作者:
Lihi Idan;J. Feigenbaum
Toward User Control over Information Access: A Sociotechnical Approach
用户对信息访问的控制:社会技术方法
DOI:
10.1145/3584318.3584327
发表时间:
2022
期刊:
Proceedings of the 2022 New Security Paradigms Workshop
影响因子:
--
作者:
[Malchik, Caleb, Feigenbaum, Joan]
通讯作者:
Feigenbaum, Joan
EAGER: Transparency Bridges: Exploring Transparency Requirements in Smartphone Ecosystems
-
批准号:1639994
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2016
-
负责人:Daniel Weitzner
-
依托单位:
CT-T: Transparent Accountable Datamining Initiative (TAMI)
-
批准号:0524481
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Daniel Weitzner
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: