论文标题

意图感知的许可体系结构:重新思考Android应用的知情同意的模型

Intent-Aware Permission Architecture: A Model for Rethinking Informed Consent for Android Apps

论文作者

Rahman, Md Rashedur, Miller, Elizabeth, Hossain, Moinul, Ali-Gombe, Aisha

论文摘要

由于数据隐私仍然是联合国认可的至关重要的人权问题,因此监管机构要求开发人员在访问对用户敏感数据之前获得用户许可。主要是通过使用隐私政策声明,开发人员满足其法律要求,以使用户了解其数据请求。此外,诸如Android之类的平台使用权限模型强制执行明确的权限请求。但是,最近的研究表明,服务提供商在要求这些声明中的数据时几乎没有全面披露。当前的权限模型均不旨在提供足够的知情同意。通常,用户对数据请求使用的原因和范围没有明确的了解。本文提出了一个明确的知情同意程序,为开发人员提供了一种宣布意图的标准化方法。我们提出的意识意识许可体系结构将当前的Android许可模型扩展到完全披露目的和范围限制的精确机制。其设计基于数据请求目的的本体研究研究。该模型的总体目的是确保最终用户在对其数据做出决定之前得到足够的了解。此外,该模型有可能改善最终用户和开发人员之间的信任。

As data privacy continues to be a crucial human-right concern as recognized by the UN, regulatory agencies have demanded developers obtain user permission before accessing user-sensitive data. Mainly through the use of privacy policies statements, developers fulfill their legal requirements to keep users abreast of the requests for their data. In addition, platforms such as Android enforces explicit permission request using the permission model. Nonetheless, recent research has shown that service providers hardly make full disclosure when requesting data in these statements. Neither is the current permission model designed to provide adequate informed consent. Often users have no clear understanding of the reason and scope of usage of the data request. This paper proposes an unambiguous, informed consent process that provides developers with a standardized method for declaring Intent. Our proposed Intent-aware permission architecture extends the current Android permission model with a precise mechanism for full disclosure of purpose and scope limitation. The design of which is based on an ontology study of data requests purposes. The overarching objective of this model is to ensure end-users are adequately informed before making decisions on their data. Additionally, this model has the potential to improve trust between end-users and developers.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源