Edna: Disguising and Revealing User Data in Web Applications

被引:0
作者
Tsai, Lillian [1 ]
Gross, Hannah [2 ]
Kaashoek, M. Frans [1 ]
Kohler, Eddie [3 ]
Schwarzkopf, Malte [2 ]
机构
[1] MIT, CSAIL, Cambridge, MA 02139 USA
[2] Brown Univ, Providence, RI 02912 USA
[3] Harvard Univ, Cambridge, MA 02138 USA
来源
PROCEEDINGS OF THE TWENTY-NINTH ACM SYMPOSIUM ON OPERATING SYSTEMS PRINCIPLES, SOSP 2023 | 2023年
关键词
Web Applications; Data Privacy; Anonymization; Data Encryption; GDPR; PII; LANGUAGE;
D O I
10.1145/3600006.3613146
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Edna is a system that helps web applications allow users to remove their data without permanently losing their accounts, anonymize their old data, and selectively dissociate personal data from public profiles. Edna helps developers support these features while maintaining application functionality and referential integrity via disguising and revealing transformations. Disguising selectively renders user data inaccessible via encryption, and revealing enables the user to restore their data to the application. Edna's techniques allow transformations to compose in any order, e.g., deleting a previously anonymized user's account, or restoring an account back to an anonymized state. Experiments with Edna that add disguising and revealing transformations to three real-world applications show that Edna enables new privacy features in existing applications with low developer effort, is simpler than alternative approaches, and adds limited overhead to applications.
引用
收藏
页码:434 / 450
页数:17
相关论文
共 64 条
  • [1] Albab Kinan Dak, 2023, P 17 USENIX S OPERAT
  • [2] Ali M, 2016, PROCEEDINGS OF USENIX ATC '16: 2016 USENIX ANNUAL TECHNICAL CONFERENCE, P181
  • [3] [Anonymous], Shonda Rhimes. Not hanging around for whatever Elon has planned
  • [4] Apple, 2023, Apple Platform Security.
  • [5] Arkin Daniel, 2022, Celebrities are starting to leave Twitter. Here's a running list
  • [6] Augus Daniel, 2022, Thinking of quitting Twitter? Here's the right way to do it
  • [7] Bellare Mihir, 2001, LNCS, P566
  • [8] Browder Kristy, 2002, Oracle Technical White Paper, Oracle Corporation, V500, P280
  • [9] Burkhalter L, 2021, PROCEEDINGS OF THE 15TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION (OSDI '21), P387
  • [10] California Legislature, 2018, California consumer privacy act of 2018