After Brazil’s General Data Protection Law: Authorization in Decentralized Web Applications

Decentralized web applications do not offer fine-grained access controls to users’ data, which potentially creates openings for data breaches. For software companies that need to comply with Brazil’s General Data Protection Law (LGPD), data breaches not only might harm application users but also cou...

Whakaahuatanga katoa

I tiakina i:
Ngā taipitopito rārangi puna kōrero
Ngā kaituhi matua: Silva, Jefferson de Oliveira, Calegari, Newton Juniano, Gomes, Eduardo Savino
Hōputu: Artigos Científicos
Reo:Ingarihi
I whakaputaina: 2024
Ngā marau:
Urunga tuihono:https://bibliotecadigital.acervo.nic.br/handle/123456789/2217
https://doi.org/10.1145/3308560.3316461
Ngā Tūtohu: Tāpirihia he Tūtohu
Kāore He Tūtohu, Me noho koe te mea tuatahi ki te tūtohu i tēnei pūkete!
Whakaahuatanga
Whakarāpopototanga:Decentralized web applications do not offer fine-grained access controls to users’ data, which potentially creates openings for data breaches. For software companies that need to comply with Brazil’s General Data Protection Law (LGPD), data breaches not only might harm application users but also could expose the companies to hefty fines. In this context, engineering fine-grained authorization controls (that comply with the LGPD) to decentralized web application requires creating audit trails, possibly in the source code. Although the literature offers some solutions, they are scattered. We present Esfinge Guardian, an authorization framework that completely separates authorization from other concerns, which increases compliance with the LGPD. We conclude the work with a brief discussion.