Khalid Muhammad Irfan, Ahmed Mansoor, Kim Jungsuk
Department of Information and Electrical Engineering and Applied Mathematics, University of Salerno Fisciano, 84084 Fisciano, Italy.
ADAPT Centre, Innovative Value Institute, Maynooth University, W23 A3HY Maynooth, Ireland.
Sensors (Basel). 2023 Sep 1;23(17):7604. doi: 10.3390/s23177604.
Dynamic consent management allows a data subject to dynamically govern her consent to access her data. Clearly, security and privacy guarantees are vital for the adoption of dynamic consent management systems. In particular, specific data protection guarantees can be required to comply with rules and laws (e.g., the General Data Protection Regulation (GDPR)). Since the primary instantiation of the dynamic consent management systems in the existing literature is towards developing sustainable e-healthcare services, in this paper, we study data protection issues in dynamic consent management systems, identifying crucial security and privacy properties and discussing severe limitations of systems described in the state of the art. We have presented the precise definitions of security and privacy properties that are essential to confirm the robustness of the dynamic consent management systems against diverse adversaries. Finally, under those precise formal definitions of security and privacy, we have proposed the implications of state-of-the-art tools and technologies such as differential privacy, blockchain technologies, zero-knowledge proofs, and cryptographic procedures that can be used to build dynamic consent management systems that are secure and private by design.
动态同意管理允许数据主体动态地管理其对访问自身数据的同意。显然,安全和隐私保障对于动态同意管理系统的采用至关重要。特别是,可能需要特定的数据保护保障措施以遵守规则和法律(例如《通用数据保护条例》(GDPR))。由于现有文献中动态同意管理系统的主要实例化方向是开发可持续的电子医疗服务,因此在本文中,我们研究动态同意管理系统中的数据保护问题,确定关键的安全和隐私属性,并讨论现有技术中描述的系统的严重局限性。我们给出了安全和隐私属性的精确定义,这些定义对于确认动态同意管理系统抵御各种对手的稳健性至关重要。最后,在那些精确的安全和隐私形式定义下,我们提出了诸如差分隐私、区块链技术、零知识证明和加密程序等现有技术工具和技术的启示,这些技术可用于构建设计上安全且私密的动态同意管理系统。