CAREER: Privacy-Accountable Mobile Software Supply Chain
职业:隐私负责的移动软件供应链
基本信息
- 批准号:2339537
- 负责人:
- 金额:$ 56.7万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2024
- 资助国家:美国
- 起止时间:2024-07-01 至 2029-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Data protection regulations specify how personal data must be protected when used by others. Tracking and accounting for protections of data privacy has emerged as a pivotal requirement in contemporary data protection regulations. As a result, those who are responsible for using personal data, so-called data controllers, must actively enhance the privacy safeguards they provide. This project addresses the intricate challenges surrounding privacy accountability within the mobile software ecosystem, characterized by the opacity of third-party code modules, particularly third-party libraries. Existing methods for achieving privacy accountability primarily emphasize data transparency, often overlooking essential principles like data minimization and purpose limitation and facing integration challenges within mobile software development lifecycles. This research project seeks to address these limitations by presenting innovative approaches to enforce privacy accountability throughout the mobile software development process. The goal is to establish a more privacy-conscious and accountable mobile ecosystem, benefiting both users and data controllers. The outcomes of the research will contribute to educational curriculum and training to help developers achieve privacy goals plus additional outreach through workshop and bootcamp venues. The project's technical objectives are divided into three research thrusts: (1) understanding privacy accountability challenges in the mobile third-party code modules; (2) designing a privacy-accountable disclosure framework; (3) continuously enforcing privacy accountability properties in mobile software development lifecycle. The technical contribution of this research lies in advancing the socio-technical understanding of privacy non-compliance risks and accountability challenges within the mobile software supply chain. Additionally, it involves designing novel technical foundations that seamlessly integrate various methodologies and disciplines. This includes program analysis, formal methods, natural language processing, and human subject research, culminating in a privacy-accountable disclosure framework and continuous privacy accountability enforcement mechanism. These innovations are designed to be easily adoptable within the mobile software supply chain. The research will foster a holistic approach to enhancing privacy protection and accountability in mobile software development lifecycle and contribute to the creation of a safer and more privacy-conscious mobile ecosystem.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
数据保护法规规定了其他人使用个人数据时必须如何保护。数据隐私保护的跟踪和核算已成为当代数据保护法规的关键要求。因此,负责使用个人数据的人(即所谓的数据控制者)必须积极加强他们提供的隐私保护。该项目解决了移动软件生态系统中围绕隐私责任的复杂挑战,其特点是第三方代码模块(尤其是第三方库)的不透明性。实现隐私问责的现有方法主要强调数据透明度,往往忽视数据最小化和目的限制等基本原则,并面临移动软件开发生命周期内的集成挑战。该研究项目旨在通过提出创新方法来解决这些限制,以在整个移动软件开发过程中加强隐私责任。目标是建立一个更加注重隐私和负责任的移动生态系统,使用户和数据控制者都受益。研究成果将有助于教育课程和培训,帮助开发人员实现隐私目标,并通过研讨会和训练营场所进行额外的宣传。该项目的技术目标分为三个研究重点:(1)了解移动第三方代码模块中的隐私责任挑战; (2) 设计隐私负责任的披露框架; (3) 在移动软件开发生命周期中不断强化隐私责任属性。这项研究的技术贡献在于促进了对移动软件供应链中隐私不合规风险和责任挑战的社会技术理解。此外,它还涉及设计无缝集成各种方法和学科的新颖技术基础。这包括程序分析、形式化方法、自然语言处理和人类受试者研究,最终形成隐私问责披露框架和持续隐私问责执行机制。这些创新旨在在移动软件供应链中轻松采用。该研究将采用整体方法来加强移动软件开发生命周期中的隐私保护和问责制,并有助于创建更安全、更具隐私意识的移动生态系统。该奖项反映了 NSF 的法定使命,并通过使用评估结果被认为值得支持。基金会的智力价值和更广泛的影响审查标准。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Xiaojing Liao其他文献
Catching predators at watering holes: finding and understanding strategically compromised websites
在水坑中捕获掠夺者:查找和了解战略性受损网站
- DOI:
10.1145/2991079.2991112 - 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Sumayah A. Alrwais;Kan Yuan;Eihal Alowaisheq;Xiaojing Liao;Alina Oprea;Xiaofeng Wang;Zhou Li - 通讯作者:
Zhou Li
A novel heat dissipation structure for PSiP package
一种新型PSiP封装散热结构
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Zhaozheng Hou;Xiaojing Liao;Hao Peng;Yiyu Wang - 通讯作者:
Yiyu Wang
Cloud repository as a malicious service: challenge, identification and implication
云存储库作为恶意服务:挑战、识别和影响
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Xiaojing Liao;Sumayah A. Alrwais;Kan Yuan;Luyi Xing;Xiaofeng Wang;S. Hao;R. Beyah - 通讯作者:
R. Beyah
Price TAG: Towards Semi-Automatically Discovery Tactics, Techniques and Procedures OF E-Commerce Cyber Threat Intelligence
Price TAG:走向电子商务网络威胁情报的半自动发现策略、技术和程序
- DOI:
10.1109/tdsc.2021.3120415 - 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Yiming Wu;Qianjun Liu;Xiaojing Liao;Shouling Ji;Peng Wang;Xiaofeng Wang;Chunming Wu;Zhao Li - 通讯作者:
Zhao Li
Towards Secure Metering Data Analysis via Distributed Differential Privacy
通过分布式差分隐私实现安全计量数据分析
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Xiaojing Liao;David Formby;Carson Day;R. Beyah - 通讯作者:
R. Beyah
Xiaojing Liao的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Xiaojing Liao', 18)}}的其他基金
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
SaTC:核心:媒介:协作:通过自动分析在线文本痕迹理解和发现非法在线业务
- 批准号:
1850725 - 财政年份:2018
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
SaTC:核心:媒介:协作:通过自动分析在线文本痕迹理解和发现非法在线业务
- 批准号:
1801365 - 财政年份:2018
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
相似国自然基金
云边端融合下隐私增强的高可用智能计算协同技术
- 批准号:62302207
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
隐私增强的智能网联汽车云控系统动态安全防护关键技术研究
- 批准号:62302033
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
云环境下具有隐私保护功能的图像检索方案研究
- 批准号:62302195
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于视觉匿名化的步态隐私保护关键技术研究
- 批准号:62372295
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
基于细粒度隐私预测的图像匿名保护方法研究
- 批准号:62372147
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
相似海外基金
Scalable & Accountable Privacy-Preserving Blockchain with Enhanced Security
可扩展
- 批准号:
DP220101234 - 财政年份:2023
- 资助金额:
$ 56.7万 - 项目类别:
Discovery Projects
A State-of-the-Art Automatic Speech Recognition and Conversational Platform to Enable Socially Assistive Robots for Persons with Alzheimer's Disease and Related Dementias
最先进的自动语音识别和对话平台,为阿尔茨海默病和相关痴呆症患者提供社交辅助机器人
- 批准号:
10699887 - 财政年份:2023
- 资助金额:
$ 56.7万 - 项目类别:
SaTC: CORE: Large: Collaborative: Accountable Information Use: Privacy and Fairness in Decision-Making Systems
SaTC:核心:大型:协作:负责任的信息使用:决策系统中的隐私和公平
- 批准号:
1704985 - 财政年份:2017
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
SaTC: CORE: Large: Collaborative: Accountable Information Use: Privacy and Fairness in Decision-Making Systems
SaTC:核心:大型:协作:负责任的信息使用:决策系统中的隐私和公平
- 批准号:
1704527 - 财政年份:2017
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant
SaTC: CORE: Large: Collaborative: Accountable Information Use: Privacy and Fairness in Decision-Making Systems
SaTC:核心:大型:协作:负责任的信息使用:决策系统中的隐私和公平
- 批准号:
1704845 - 财政年份:2017
- 资助金额:
$ 56.7万 - 项目类别:
Continuing Grant