RuleKeeper: GDPR-Aware Personal Data Compliance for Web Frameworks.

SP(2023)

引用 4|浏览7
暂无评分
摘要
Pressured by existing regulations such as the EU GDPR, online services must advertise a personal data protection policy declaring the types and purposes of collected personal data, which must then be strictly enforced as per the consent decisions made by the users. However, due to the lack of system-level support, obtaining strong guarantees of policy enforcement is hard, leaving the door open for software bugs and vulnerabilities to cause GDPR-compliance violations. We present RuleKeeper, a GDPR-aware personal data policy compliance system for web development frameworks. Currently ported for the MERN framework, RuleKeeper allows web developers to specify a GDPR manifest from which the data protection policy of the web application is automatically generated and is transparently enforced through static code analysis and runtime access control mechanisms. GDPR compliance is checked in a cross-cutting manner requiring few changes to the application code. We used our prototype implementation to evaluate RuleKeeper with four real-world applications. Our system can model realistic GDPR data protection requirements, adds modest performance overheads to the web application, and can detect GDPR violation bugs.
更多
查看译文
关键词
collected personal data,EU GDPR,GDPR compliance,GDPR manifest,GDPR violation bugs,GDPR-aware personal data compliance,GDPR-aware personal data policy compliance system,GDPR-compliance violations,MERN framework,personal data protection policy,policy enforcement,realistic GDPR data protection requirements,RuleKeeper,runtime access control mechanisms,software bugs,static code analysis,system-level support,web application,web developers,web development frameworks,web frameworks
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要