Runtime and Design Time Completeness Checking of Dangerous Android App Permissions Against GDPR

许可 计算机科学 Android(操作系统) 通用数据保护条例 计算机安全 万维网 互联网隐私 1998年数据保护法 法学 操作系统 政治学
作者
Ryan McConkey,Oluwafemi Olukoya
出处
期刊:IEEE Access [Institute of Electrical and Electronics Engineers]
卷期号:12: 1-22 被引量:1
标识
DOI:10.1109/access.2023.3347194
摘要

Data and privacy laws, such as the GDPR, require mobile apps that collect and process the personal data of their citizens to have a legally-compliant policy. Since these mobile apps are hosted on app distribution platforms such as Google Play Store and App Store, the app publishers also require the app developers who wish to submit a new app or make changes to an existing app to be transparent about their app privacy practices regarding handling sensitive user data that requires sensitive permissions such as calendar, camera, microphone. To verify compliance with privacy regulators and app distribution platforms, the app privacy policies and permissions are investigated for consistency. However, little has been done to investigate GDPR completeness checking within the Android permission ecosystem. In this paper, we investigate the design and runtime approaches towards completeness checking of sensitive (’dangerous’) Android permission policy declarations against GDPR. In this paper, we investigate the design and runtime approaches towards completeness checking of dangerous Android permission policy declarations against GDPR. Leveraging the MPP-270 annotated corpus that describes permission declarations in application privacy policies, six natural language processing and language modelling algorithms are developed to measure permission completeness during runtime while a proof of concept Class Unified Modeling Language Diagram (UML) tool is developed to generate GDPR-compliant permission policy declarations using UML diagrams during design time. This paper makes a significant contribution to the identification of appropriate permission policy declaration methodologies that a developer can use to target particular GDPR laws, increasing GDPR compliance by 12% in cases during runtime using BERT word embedding, measuring GDPR compliance in permission policy sentences, and a UML-driven tool to generate compliant permission declarations.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
子唯完成签到,获得积分10
1秒前
hehe发布了新的文献求助10
1秒前
巫凝天完成签到,获得积分10
1秒前
liu完成签到,获得积分10
2秒前
2秒前
2秒前
七柒完成签到,获得积分20
3秒前
Lucas应助abc采纳,获得10
3秒前
4秒前
4秒前
心灵美又蓝关注了科研通微信公众号
5秒前
5秒前
wjj119完成签到,获得积分10
7秒前
七柒发布了新的文献求助10
8秒前
背后觅露完成签到,获得积分10
8秒前
gao发布了新的文献求助30
8秒前
vikki完成签到,获得积分10
9秒前
科研通AI5应助大笑的觅珍采纳,获得10
9秒前
9秒前
Gnor发布了新的文献求助10
9秒前
王泳茵完成签到,获得积分10
10秒前
10秒前
CipherSage应助乐观的妙芹采纳,获得10
10秒前
欢呼妙菱发布了新的文献求助10
10秒前
11秒前
11秒前
11秒前
drgaoying完成签到,获得积分10
11秒前
11秒前
hehe完成签到,获得积分10
12秒前
我是老大应助lqkcqmu采纳,获得10
12秒前
早安甜甜菌完成签到,获得积分10
12秒前
12秒前
12秒前
迅速友容完成签到 ,获得积分10
13秒前
赖不弱完成签到,获得积分10
13秒前
毕葛完成签到 ,获得积分10
13秒前
安文完成签到,获得积分10
14秒前
GJL完成签到,获得积分10
14秒前
ss13l完成签到,获得积分10
14秒前
高分求助中
A new approach to the extrapolation of accelerated life test data 1000
Handbook of Marine Craft Hydrodynamics and Motion Control, 2nd Edition 500
‘Unruly’ Children: Historical Fieldnotes and Learning Morality in a Taiwan Village (New Departures in Anthropology) 400
Indomethacinのヒトにおける経皮吸収 400
Phylogenetic study of the order Polydesmida (Myriapoda: Diplopoda) 370
基于可调谐半导体激光吸收光谱技术泄漏气体检测系统的研究 350
Robot-supported joining of reinforcement textiles with one-sided sewing heads 320
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 冶金 细胞生物学 免疫学
热门帖子
关注 科研通微信公众号,转发送积分 3987054
求助须知:如何正确求助?哪些是违规求助? 3529416
关于积分的说明 11244990
捐赠科研通 3267882
什么是DOI,文献DOI怎么找? 1803968
邀请新用户注册赠送积分活动 881257
科研通“疑难数据库(出版商)”最低求助积分说明 808650