期刊论文详细信息
Technologies
Identity Management and Protection Motivated by the General Data Protection Regulation of the European Union—A Conceptual Framework Based on State-of-the-Art Software Technologies
Erik Krempel1  Pascal Birnstill1  Jürgen Beyerer1  PaulGeorg Wagner1 
[1] Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB, Fraunhoferstr.1, 76131 Karlsruhe, Germany;
关键词: data protection;    privacy;    GDPR;    identity management;    data provenance tracking;    usage control;    remote attestation;    trusted computing;   
DOI  :  10.3390/technologies6040115
来源: DOAJ
【 摘 要 】

In times of strongly (personal) data-driven economy, the inception of the European General Data Protection Regulation (GDPR) recently reinforced the call for transparency and informational self-determination—not only due to the penalties for data protection violations becoming significantly more severe. This paper recaps the GDPR articles that should be noticed by software designers and developers and explains how, from the perspective of computer scientists, the summarized requirements can be implemented based on state-of-the-art technologies, such as data provenance tracking, distributed usage control, and remote attestation protocols. For this, the challenges for data controllers, i.e., the service providers, as well as for the data subjects, i.e., the users whose personal data are being processed by the services, are worked out. As a result, this paper proposes the ideal functionality of a next-generation privacy dashboard interacting with data provenance and usage control infrastructure implemented at the service providers to operationalize the legal rights of the data subject granted by the GDPR. Finally, it briefly outlines the options for establishing trust in data provenance tracking and usage control infrastructures operated by the service providers themselves.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:13次