Recent data protection regulations (such as GDPR and CCPA) grant consumers various rights, including the right to access, modify or delete any personal information collected about them (and retained) by a service provider. To exercise these rights, one must submit a verifiable consumer request proving that collected data indeed pertains to them. This action is relatively straightforward for consumers with active accounts with a service provider at the time of data collection, since they can use standard (e.g., password-based) means of authentication to validate their requests. However, a major conundrum arises from the need to support consumers without accounts to exercise their rights. To this end, some service providers began requiring these accountless consumers to reveal and prove their identities (e.g., using government-issued documents, utility bills or credit card numbers) as part of issuing a verifiable consumer request. While understandable as a short-term cure, this approach is, at the same time, cumbersome and expensive for service providers as well as very privacy-invasive for consumers. Consequently, there is a strong need to provide better means of authenticating requests from accountless consumers. To achieve this, we propose VICEROY, a privacy-preserving and scalable framework for producing proofs of data ownership, which can be used as a basis for verifiable consumer requests. Building upon existing web techniques and features (e.g., cookies), VICEROY allows accountless consumers to interact with service providers, and later prove -- in a privacy-preserving manner -- that they are the same person, with minimal requirements for both parties. We design and implement VICEROY with the emphasis on security/privacy, deployability and usability. We also thoroughly assess its practicality via extensive experiments.
翻译:最近的数据保护条例(如GDPR和CCPA)赋予消费者各种权利,包括获取、修改或删除服务提供者收集的(和保留)有关消费者的任何个人信息的权利。为了行使这些权利,必须提交一份可核查的消费者请求,证明所收集数据确实与消费者有关。这一行动对于在数据收集时与服务提供者有活跃账户的消费者来说相对简单,因为消费者可以使用标准(如基于密码的)认证手段来验证其请求。然而,一个重大难题是,需要支持消费者而无需账户来行使其权利。为此,一些服务供应商开始要求这些没有账户的消费者披露和证明其身份(例如,使用政府签发的文件、公用票据或信用卡号码),作为发出可核实消费者请求的一部分。虽然这种做法可以在短期内理解,但对于服务提供者来说,这个方法既麻烦又昂贵,而且费用昂贵,而且对消费者来说。因此,它们非常需要提供更好的验证无账户消费者请求的手段。为此,我们提议,使用VICERO的可操作性,同时使用一种可核实的用户设计、可核实性、可核实性数据格式,从而在客户使用的现有安全性设计、可验证性的基础上,可以对用户进行互动性要求。