论文标题

OCONSENT-与区块链有关隐私和同意管理的开放同意协议

OConsent -- Open Consent Protocol for Privacy and Consent Management with Blockchain

论文作者

Mitra, Subhadip

论文摘要

在当前的连接世界 - 网站,移动应用程序中,IoT设备收集了大量用户的个人身份活动数据。这些收集的数据用于分析,营销,服务个性化等的各种目的。这些跟踪和收集到的数据的使用中有许多发生在幕后,对于普通用户来说并不明显。因此,许多国家和地区已经制定了立法(例如GDPR,欧盟) - 使用户能够以可理解和用户友好的方式来控制其个人数据,并同意其处理。 本文提出了一个基于区块链技术的协议和一个平台,该协议可以使个人数据从捕获,谱系到修改进行透明的个人数据处理。该解决方案旨在帮助从单个最终用户到数据控制者和隐私官的多个利益相关者。它打算就如何以及何时捕获,访问和处理数据点提供整体而明确的看法。该框架还设想如何通过公共区块链制定和执行不同的访问控制策略,包括有关隐私数据泄露的实时警报。

In the current connected world - Websites, Mobile Apps, IoT Devices collect a large volume of users' personally identifiable activity data. These collected data is used for varied purposes of analytics, marketing, personalization of services, etc. Data is assimilated through site cookies, tracking device IDs, embedded JavaScript, Pixels, etc. to name a few. Many of these tracking and usage of collected data happens behind the scenes and is not apparent to an average user. Consequently, many Countries and Regions have formulated legislations (e.g., GDPR, EU) - that allow users to be able to control their personal data, be informed and consent to its processing in a comprehensible and user-friendly manner. This paper proposes a protocol and a platform based on Blockchain Technology that enables the transparent processing of personal data throughout its lifecycle from capture, lineage to redaction. The solution intends to help service multiple stakeholders from individual end-users to Data Controllers and Privacy Officers. It intends to offer a holistic and unambiguous view of how and when the data points are captured, accessed, and processed. The framework also envisages how different access control policies might be created and enforced through a public blockchain including real time alerts for privacy data breach.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源