The need for a privacy management layer in today's systems started to manifest with the emergence of new systems for privacy-preserving analytics and privacy compliance. As a result, we began to see many independent efforts emerge that try to provide system support for privacy. Recently, the scope of privacy solutions used in systems has expanded to encompass more complex techniques such as Differential Privacy (DP). The use of these solutions in large-scale systems imposes new challenges and requirements. Careful planning and coordination are necessary to ensure that privacy guarantees are maintained across a wide range of heterogeneous applications and data systems. This requires new solutions for managing shared application state and allocating scarce and non-replenishable privacy resources. In this paper, we introduce Cohere, a new data management system that simplifies the use of DP in large-scale systems. Cohere implements a unified interface that allows heterogeneous applications to operate on a unified view of users' data. Cohere further extends existing accounting systems with the ability to manage and optimally allocate shared privacy resources, i.e., budget, under complex preferences. We show that Cohere can effectively enable advanced privacy solutions in existing large-scale systems with minimal modifications to existing data management systems and with moderate overhead.
 翻译:当今系统中的隐私管理层的需要随着隐私保护分析和隐私合规新系统的出现而开始显现。因此,我们开始看到许多独立的努力出现,试图为隐私提供系统支持。最近,系统中使用的隐私解决方案的范围已经扩大,包括了更复杂的技术,如差异隐私(DP)等。在大型系统中使用这些解决方案带来了新的挑战和要求。必须仔细规划和协调,以确保隐私保障在各种各样的不同应用程序和数据系统中得到维护。这需要新的解决方案来管理共享应用状态,分配稀缺和不可耗尽的隐私资源。在本文件中,我们引入了Cohere,这是一个新的数据管理系统,简化了大型系统中对DP的使用。Cohere实施一个统一的界面,允许在用户数据统一视图上使用多种应用程序。Cohere进一步扩展了现有的会计系统,使其能够在复杂的选择下管理和最佳地分配共享的隐私资源,即预算。我们表明Cohere能够有效地在现有大型系统中采用先进的隐私解决方案,对现有的数据管理系统进行最低限度的改造。