课题基金 / 基金详情

Equitable privacy

Equitable privacy
公平的隐私
批准号:
EP/W025361/1
负责人:
Awais Rashid
金额:
$129.56万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2022
资助国家:
英国
项目状态:
未结题
起止时间:
2022 至 --
关键词:

项目摘要

项目成果

Awais Rashid的其他基金

相似基金

相关文献

中文摘要
翻译
数字技术在社会中变得无处不在,从网上购物和社交互动到金融、银行、交通。在实时、数据驱动的数字经济驱动下,智慧城市的未来愿景是,隐私至关重要。它对于建立对社会所依赖的数字结构的信任至关重要,并且在《世界人权宣言》和《通用数据保护条例》等法规中被视为一项基本人权。人们已经做出了重大努力——端到端加密、匿名通信、iOS和Android中的隐私营养标签——让用户在理解、控制和确保他们的数据和信息被处理和共享的方式方面有更多的自主权。然而,这种控制、理解和保证的能力在整个社会中并不是平等的。例子包括低收入群体的个人,他们必须共享设备才能访问可能包含敏感信息的服务,或者亲密伴侣暴力的受害者,他们可能会使用无害的应用程序(例如“找到我的手机”)或数字设备(例如智能门铃)来监控他们的活动,并且由于担心可追溯性而无法使用在线报告工具。这些易受伤害和边缘化的人群有特定的隐私和信息控制需求和威胁模式,因此不同类型的隐私控制既可以作为保护机制,也可以作为攻击媒介。软件开发人员通常不会考虑这些需求。开发者既不是隐私专家,也通常没有培训、工具、支持和指导来设计边缘化和弱势群体的各种隐私需求,这一事实使挑战更加复杂。我们认为,为了使隐私在我们无处不在的数字经济中具有有意义和公平的价值,每个人都必须能够轻松地控制他们如何共享个人信息,了解他们与谁共享信息,并确保共享仅限于预期目的。该项目将与支持此类社区的第三部门组织携手合作,共同开发:新方法:一种由一组威胁目录支持的威胁建模方法,可以实现不同的“模式”保护逻辑,从而可以切换攻击者,将漏洞置于环境中,并承认不同类型的控制既可以作为保护机制又可以作为攻击媒介。新的数字工具:使用中的隐私营养框架,促进弱势群体和边缘化人群的隐私素养,识别使用中的隐私问题,并通过新的应用程序编程接口促进开发人员的响应,并通过支持公平隐私的新指标进行评估。新流程:共同创建、由利益相关者主导的AREA负责任创新框架修订,为个人、团队和组织深入思考公平的数字未来提供结构。我们的研究将使边缘化和弱势群体的隐私需求在设计和开发软件应用程序和服务时优先考虑,以实现公平的隐私体验。反过来,这将使普遍的隐私响应能够协同工作,并支持对脆弱用户遇到的隐私问题的特定响应。
英文摘要
Digital technologies are becoming pervasive in society, from online shopping and social interactions through to finance, banking, transportation. With a future vision of smart cities, driven by a real-time, data-driven, digital economy, privacy is paramount. It is critical to engendering trust in the digital fabric on which society relies and is enshrined as a fundamental human right in the Universal Declation of Human Rights and regulations such as GDPR. Significant efforts have been made -- end-to-end encryption, anonymous communication, privacy nutrition labels in iOS and Android -- to provide users with more agency in understanding, controlling and assuring the way their data and information is processed and shared.However, this ability to control, understand and assure is not equitably experienced across society. Examples include individuals from lower-income groups who have to share devices to access services that may include sensitive information or victims of intimate partner violence whereby an innocuous app (such as find my phone) or digital device (such as a smart doorbell) may be used to monitor their activities and who cannot use online reporting tools for fear of traceability. Such vulnerable and marginalised populations have specific privacy and information control needs and threat models whereby different types of privacy controls may serve as both protection mechanisms and attack vectors. These needs and requirements are not typically foregrounded to software developers. The challenge is compounded by the fact developers are neither privacy experts nor typically have the training, tools, support and guidance to design for the diverse privacy needs of marginalised and vulnerable groups.We argue that, for privacy to be of meaningful and equitable value in our pervasive digital economy, everyone must be able to easily control how they share personal information, understand with whom they are sharing it, and ensure that sharing is limited to the intended purpose.The project will work hand-in-hand with third sector organisations supporting such communities to develop:New methods: a threat modelling approach, supported by a set of threat catalogues, that enables different "modalities" of protection logic whereby one can switch attackers, contextualise the vulnerabilities and acknowledge different types of controls as both protection mechanisms and attack vectors.New digital tools: a privacy-in-use nutrition framework that promotes privacy-literacy in vulnerable and marginalised populations, identifies privacy concerns in-use and facilitates developer responses built through new application programming interfaces and evaluated through novel metrics supporting equitable privacy.New processes: co-created, stakeholder-led revisions to the AREA framework for Responsible Innovation to lend structure to the way in which individuals, teams, and organisations approach deep thinking about equitable digital futures.Our research will make the privacy needs of marginalised and vulnerable populations first-class considerations in designing and developing software applications and services to enable equitable privacy experiences. This, in turn, will enable universal privacy responses to work together and support particular responses to privacy issues experienced by vulnerable users.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3633500.3633503
发表时间: 2023-08
期刊: Proceedings of the 2023 New Security Paradigms Workshop
影响因子: --
作者: [K. Ramokapane;A. Rashid]
通讯作者: K. Ramokapane;A. Rashid
Securing Convergent Ultra-large Scale Infrastructures
  • 批准号:
    EP/Z531315/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $864.03万
  • 财政年份:
    2024
  • 负责人:
    Awais Rashid
  • 依托单位:
REPHRAIN: Research centre on Privacy, Harm Reduction and Adversarial Influence online
  • 批准号:
    EP/V011189/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $888.45万
  • 财政年份:
    2020
  • 负责人:
    Awais Rashid
  • 依托单位:
Why Johnny doesn't write secure software? Secure software development by the masses
  • 批准号:
    EP/P011799/2
  • 项目类别:
    Research Grant
  • 资助金额:
    $108.77万
  • 财政年份:
    2018
  • 负责人:
    Awais Rashid
  • 依托单位:
DYPOSIT: Dynamic Policies for Shared Cyber-Physical Infrastructures under Attack
  • 批准号:
    EP/N021657/2
  • 项目类别:
    Research Grant
  • 资助金额:
    $24.93万
  • 财政年份:
    2018
  • 负责人:
    Awais Rashid
  • 依托单位:
国内基金
海外基金
面向MANET的密钥管理关键技术研究
  • 批准号:
    61173188
  • 项目类别:
    面上项目
  • 资助金额:
    52.0万元
  • 批准年份:
    2011
  • 负责人:
    仲红
  • 依托单位: