As data privacy continues to be a crucial human-right concern as recognized by the UN, regulatory agencies have demanded developers obtain user permission before accessing user-sensitive data. Mainly through the use of privacy policies statements, developers fulfill their legal requirements to keep users abreast of the requests for their data. In addition, platforms such as Android enforces explicit permission request using the permission model. Nonetheless, recent research has shown that service providers hardly make full disclosure when requesting data in these statements. Neither is the current permission model designed to provide adequate informed consent. Often users have no clear understanding of the reason and scope of usage of the data request. This paper proposes an unambiguous, informed consent process that provides developers with a standardized method for declaring Intent. Our proposed Intent-aware permission architecture extends the current Android permission model with a precise mechanism for full disclosure of purpose and scope limitation. The design of which is based on an ontology study of data requests purposes. The overarching objective of this model is to ensure end-users are adequately informed before making decisions on their data. Additionally, this model has the potential to improve trust between end-users and developers.
翻译:由于数据隐私仍然是联合国承认的一个关键的人类权利关切,监管机构要求开发商在获取用户敏感数据之前获得用户许可,主要是通过使用隐私政策声明,开发商满足其法律要求,使用户及时了解其数据请求;此外,安卓尔德等平台利用许可模式执行明确许可请求;然而,最近的研究表明,服务提供商在这些请求中请求数据时很难充分披露;目前的许可模式也不旨在提供充分的知情同意;用户往往对数据请求的使用原因和范围缺乏明确了解;本文件提议了一个明确、知情同意程序,为开发商提供一个标准化的意向申报方法;我们拟议的 " 内在意识 " 许可架构扩展了当前安卓尔特许可模式,并有一个精确的机制,以充分披露目的和范围限制;该模式的设计基于数据请求的理论研究目的;该模式的首要目标是确保终端用户在就其数据作出决定之前得到充分的知情。此外,这一模式有可能提高终端用户和开发商之间的信任。