论文标题

关于问责制的原则:智能家居和网络安全的挑战

On the Principle of Accountability: Challenges for Smart Homes & Cybersecurity

论文作者

Urquhart, Lachlan, Chen, Jiahong

论文摘要

本章介绍了问责制原则及其在数据保护治理中的作用。我们专注于在智能家庭中的网络安全管理的背景下,考虑到欧盟一般数据保护法要求确保个人数据的要求。该讨论是在数据保护法的两个主要新发展的背景下进行的。首先,由于所谓的家庭豁免,法律正在搬进房屋。同时,现在可能承担遵守GDPR的法律责任,因为他们发现自己是共同负责合规性的,因为他们可能被认为是为了确定与物联网设备供应商收集数据的手段和目的。作为一个复杂的社会技术空间,我们考虑了问责制要求与这类新型国内数据控制器(DDC)之间的互动。具体而言,我们考虑基于边缘的安全分析的价值和局限性,以管理智能家庭网络安全风险,审查一系列原型及其使用的研究。我们还反思了家庭环境中的人际交往动力学,例如设备控制;围绕智能家居隐私和安全管理的现有社会实践;以及可能会阻碍DDC依靠此类解决方案的可用性问题。最后,我们通过反思1)需要在房屋中进行集体安全管理以及2)设备用户,帐户持有人,IoT设备/软件/固件供应商和第三方之间越来越复杂的责任部门。

This chapter introduces the Accountability Principle and its role in data protection governance. We focus on what accountability means in the context of cybersecurity management in smart homes, considering the EU General Data Protection Law requirements to secure personal data. This discussion sits against the backdrop of two key new developments in data protection law. Firstly, the law is moving into the home, due to narrowing of the so called household exemption. Concurrently, household occupants may now have legal responsibilities to comply with the GDPR, as they find themselves jointly responsible for compliance, as they are possibly held to determine the means and purposes of data collection with IoT device vendors. As a complex socio-technical space, we consider the interactions between accountability requirements and the competencies of this new class of domestic data controllers (DDCs). Specifically, we consider the value and limitations of edge-based security analytics to manage smart home cybersecurity risks, reviewing a range of prototypes and studies of their use. We also reflect on interpersonal power dynamics in the domestic setting e.g. device control; existing social practices around privacy and security management in smart homes; and usability issues that may hamper DDCs ability to rely on such solutions. We conclude by reflecting on 1) the need for collective security management in homes and 2) the increasingly complex divisions of responsibility in smart homes between device users, account holders, IoT device/software/firmware vendors, and third parties.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源