Edna: Disguising and Revealing User Data in Web Applications
Lillian Tsai, Hannah Gross, Eddie Kohler, M. Frans Kaashoek, Malte Schwarzkopf
摘要
Edna is a system that helps web applications allow users to remove their data without permanently losing their accounts, anonymize their old data, and selectively dissociate personal data from public profiles. Edna helps developers support these features while maintaining application functionality and referential integrity via disguising and revealing transformations. Disguising selectively renders user data inaccessible via encryption, and revealing enables the user to restore their data to the application. Edna's techniques allow transformations to compose in any order, e.g., deleting a previously anonymized user's account, or restoring an account back to an anonymized state.
Experiments with Edna that add disguising and revealing transformations to three real-world applications show that Edna enables new privacy features in existing applications with low developer effort, is simpler than alternative approaches, and adds limited overhead to applications.
• Security and privacy → Data anonymization and sanitization; Management and querying of encrypted data; Information accountability and usage control; Usability in security and privacy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg 等USENIX Security 2017 · 被引用 46 次
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh 等OSDI 2021 · 被引用 35 次
- Blockaid: Data Access Policy Enforcement for Web ApplicationsWen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda 等OSDI 2022 · 被引用 8 次
- DELF: Safeguarding deletion correctness in Online Social NetworksKatriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova 等USENIX Security 2020
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
相关 Paper
- Facial Identity Anonymization via Intrinsic and Extrinsic Attention DistractionZhenzhong Kuang, Xiaochen Yang, Yingjie Shen, Chao Hu 等CVPR 2024
- Empowering IoT Developers with Privacy-Preserving End-User Development ToolsAtheer Aljeraisy, Omer F. Rana, Charith PereraUbiComp 2024 · 被引用 4 次
- Going Incognito in the Metaverse: Achieving Theoretically Optimal Privacy-Usability Tradeoffs in VRVivek C. Nair, Gonzalo Munilla Garrido, Dawn SongUIST 2023 · 被引用 54 次
- X-Stream: A Flexible, Adaptive Video Transformer for Privacy-Preserving Video Stream AnalyticsDou Feng, Lin Wang, Shutong Chen, Lingching Tung 等INFOCOM 2024 · 被引用 8 次
- eBind: Privacy-Enhanced and eIDAS 2.0-Compliant Binding of Anonymous Credentials to HumansYang Yang, Guomin Yang, Yingjiu Li, Minming Huang 等CCS 2026
