Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs

Frank Pallas, David Hartmann, Paul Heinrich, Josefine Kipke, Elias Grünewald
{"title":"Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs","authors":"Frank Pallas, David Hartmann, Paul Heinrich, Josefine Kipke, Elias Grünewald","doi":"10.1145/3493369.3493601","DOIUrl":null,"url":null,"abstract":"The purpose of regulatory data minimization obligations is to limit personal data to the absolute minimum necessary for a given context. Beyond the initial data collection, storage, and processing, data minimization is also required for subsequent data releases, as it is the case when data are provided using query-capable Web APIs. Data-providing Web APIs, however, typically lack sophisticated data minimization features, leaving the task open to manual and all too often missing implementations. In this paper, we address the problem of data minimization for data-providing, query-capable Web APIs. Based on a careful analysis of functional and non-functional requirements, we introduce Janus, an easy-to-use, highly configurable solution for implementing legally compliant data minimization in GraphQL Web APIs. Janus provides a rich set of information reduction functionalities that can be configured for different client roles accessing the API. We present a technical proof-ofconcept along with experimental measurements that indicate reasonable overheads. Janus is thus a practical solution for implementing GraphQL APIs in line with the regulatory principle of data minimization.","PeriodicalId":91383,"journal":{"name":"Proceedings of the ... International Conference on Web Information Systems Engineering. International Conference on Web Information Systems Engineering","volume":"40 1","pages":"325-340"},"PeriodicalIF":0.0000,"publicationDate":"2022-03-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the ... International Conference on Web Information Systems Engineering. International Conference on Web Information Systems Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3493369.3493601","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

The purpose of regulatory data minimization obligations is to limit personal data to the absolute minimum necessary for a given context. Beyond the initial data collection, storage, and processing, data minimization is also required for subsequent data releases, as it is the case when data are provided using query-capable Web APIs. Data-providing Web APIs, however, typically lack sophisticated data minimization features, leaving the task open to manual and all too often missing implementations. In this paper, we address the problem of data minimization for data-providing, query-capable Web APIs. Based on a careful analysis of functional and non-functional requirements, we introduce Janus, an easy-to-use, highly configurable solution for implementing legally compliant data minimization in GraphQL Web APIs. Janus provides a rich set of information reduction functionalities that can be configured for different client roles accessing the API. We present a technical proof-ofconcept along with experimental measurements that indicate reasonable overheads. Janus is thus a practical solution for implementing GraphQL APIs in line with the regulatory principle of data minimization.
可配置的每查询数据最小化隐私兼容的Web api
监管数据最小化义务的目的是将个人数据限制在给定上下文所需的绝对最低限度。除了初始数据收集、存储和处理之外,后续数据发布也需要数据最小化,因为使用支持查询的Web api提供数据就是这种情况。然而,提供数据的Web api通常缺乏复杂的数据最小化特性,使得该任务需要手工完成,而且常常缺少实现。在本文中,我们解决了数据提供、查询功能的Web api的数据最小化问题。基于对功能性和非功能性需求的仔细分析,我们介绍了Janus,这是一个易于使用、高度可配置的解决方案,用于在GraphQL Web api中实现符合法律要求的数据最小化。Janus提供了一组丰富的信息缩减功能,可以针对访问API的不同客户端角色进行配置。我们提出了一个技术概念验证以及表明合理开销的实验测量。因此,Janus是实现GraphQL api的实用解决方案,符合数据最小化的监管原则。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信