Edna: Disguising and Revealing User Data in Web Applications
Lillian Tsai, Hannah Gross, Eddie Kohler, M. Frans Kaashoek, Malte Schwarzkopf
Abstract
Edna is a system that helps web applications allow users to remove their data without permanently losing their accounts, anonymize their old data, and selectively dissociate personal data from public profiles. Edna helps developers support these features while maintaining application functionality and referential integrity via disguising and revealing transformations. Disguising selectively renders user data inaccessible via encryption, and revealing enables the user to restore their data to the application. Edna's techniques allow transformations to compose in any order, e.g., deleting a previously anonymized user's account, or restoring an account back to an anonymized state.
Experiments with Edna that add disguising and revealing transformations to three real-world applications show that Edna enables new privacy features in existing applications with low developer effort, is simpler than alternative approaches, and adds limited overhead to applications.
• Security and privacy → Data anonymization and sanitization; Management and querying of encrypted data; Information accountability and usage control; Usability in security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on5
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh et al.OSDI 2021 · 35 citations
- Blockaid: Data Access Policy Enforcement for Web ApplicationsWen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda et al.OSDI 2022 · 8 citations
- DELF: Safeguarding deletion correctness in Online Social NetworksKatriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova et al.USENIX Security 2020
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
Related papers
- Facial Identity Anonymization via Intrinsic and Extrinsic Attention DistractionZhenzhong Kuang, Xiaochen Yang, Yingjie Shen, Chao Hu et al.CVPR 2024
- Empowering IoT Developers with Privacy-Preserving End-User Development ToolsAtheer Aljeraisy, Omer F. Rana, Charith PereraUbiComp 2024 · 4 citations
- Going Incognito in the Metaverse: Achieving Theoretically Optimal Privacy-Usability Tradeoffs in VRVivek C. Nair, Gonzalo Munilla Garrido, Dawn SongUIST 2023 · 54 citations
- X-Stream: A Flexible, Adaptive Video Transformer for Privacy-Preserving Video Stream AnalyticsDou Feng, Lin Wang, Shutong Chen, Lingching Tung et al.INFOCOM 2024 · 8 citations
- eBind: Privacy-Enhanced and eIDAS 2.0-Compliant Binding of Anonymous Credentials to HumansYang Yang, Guomin Yang, Yingjiu Li, Minming Huang et al.CCS 2026
