K9db: Privacy-Compliant Storage For Web Applications By Construction
Kinan Dak Albab, Ishan Sharma, Justus Adam, Benjamin Kilimnik, Aaron R. Jeyaraj, Raj Paul, Artem Agvanian, Leonhard F. Spiegelberg, Malte Schwarzkopf
摘要
Data privacy laws like the EU's GDPR grant users new rights, such as the right to request access to and deletion of their data. Manual compliance with these requests is error-prone and imposes costly burdens especially on smaller organizations, as non-compliance risks steep fines.
K9db is a new, MySQL-compatible database that complies with privacy laws by construction. The key idea is to make the data ownership and sharing semantics explicit in the storage system. This requires K9db to capture and enforce applications' complex data ownership and sharing semantics, but in exchange simplifies privacy compliance. Using a small set of schema annotations, K9db infers storage organization, generates procedures for data retrieval and deletion, and reports compliance errors if an application risks violating the GDPR.
Our K9db prototype successfully expresses the data sharing semantics of real web applications, and guides developers to getting privacy compliance right. K9db also matches or exceeds the performance of existing storage systems, at the cost of a modest increase in state size.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Sesame: Practical End-to-End Privacy Compliance with Policy Containers and Privacy RegionsKinan Dak Albab, Artem Agvanian, Allen Aby, Corinn Tiffany 等SOSP 2024 · 被引用 2 次
- Meaningful Data Erasure in the Presence of DependenciesVishal Chakraborty, Youri Kaminsky, Sharad Mehrotra, Felix Naumann 等VLDB 2025
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad 等S&P 2025
它引用的顶会 Paper7
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh 等OSDI 2021 · 被引用 35 次
- Shared Arrangements: practical inter-query sharing for streaming dataflowsFrank McSherry, Andrea Lattuada, Malte Schwarzkopf, Timothy RoscoeVLDB 2020 · 被引用 25 次
- Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!Zsolt István, Soujanya Ponnapalli, Vijay ChidambaramVLDB 2021 · 被引用 19 次
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 被引用 16 次
相关 Paper
- RuleKeeper: GDPR-Aware Personal Data Compliance for Web FrameworksMafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno SantosS&P 2023
- Control, Confidentiality, and the Right to be ForgottenAloni Cohen, Adam D. Smith, Marika Swanberg, Prashant Nalini VasudevanCCS 2023 · 被引用 6 次
- Kamino: Constraint-Aware Differentially Private Data SynthesisChang Ge, Shubhankar Mohapatra, Xi He, Ihab F. IlyasVLDB 2021 · 被引用 55 次
- Enabling Personal Consent in DatabasesGeorge Konstantinidis, Jet Holt, Adriane ChapmanVLDB 2022 · 被引用 17 次
- C3PA: An Open Dataset of Expert-Annotated and Regulation-Aware Privacy Policies to Enable Scalable Regulatory Compliance AuditsMaaz Bin Musa, Steven M. Winston, Garrison Allen, Jacob Schiller 等EMNLP 2024 · 被引用 3 次
