论文标题

基于注释的个人数据保护的静态分析

Annotation-Based Static Analysis for Personal Data Protection

论文作者

Hjerppe, Kalle, Ruohonen, Jukka, Leppänen, Ville

论文摘要

本文详细阐述了在数据保护的背景下使用静态源代码分析。该主题对于软件工程很重要,以便软件开发人员在软件开发过程中改善个人数据的保护。为此,本文提出了处理个人数据的注释类和功能的设计。该设计实现了两个主要目的:一方面,它为软件开发人员提供了记录其意图的手段;另一方面,它提供了用于自动检测潜在违规行为的工具。这种双重理由有助于遵守《通用数据保护法规》(GDPR)和其他新兴数据保护和隐私法规。除了对数据保护环境中静态分析的最新分析和提议分析方法的设计进行简要审查外,还提出了一种具体的工具,以证明针对Java编程语言的实际实现。

This paper elaborates the use of static source code analysis in the context of data protection. The topic is important for software engineering in order for software developers to improve the protection of personal data during software development. To this end, the paper proposes a design of annotating classes and functions that process personal data. The design serves two primary purposes: on one hand, it provides means for software developers to document their intent; on the other hand, it furnishes tools for automatic detection of potential violations. This dual rationale facilitates compliance with the General Data Protection Regulation (GDPR) and other emerging data protection and privacy regulations. In addition to a brief review of the state-of-the-art of static analysis in the data protection context and the design of the proposed analysis method, a concrete tool is presented to demonstrate a practical implementation for the Java programming language.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源