arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Proof-of-Retention:一种可审计的跨组织数据共享框架

Proof-of-Retention: A Framework for Auditable Cross-Organization Data Sharing

Kyle MacMillan, Sanjay Krishnan

arXiv 2609.26654首次发表:更新:

发表机构

The University of Chicago(芝加哥大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对跨组织数据共享中合规审计困难的问题,提出Proof-of-Retention框架,结合查询见证与加密持有证明,实现无需完整复制的可验证数据保留审计。

AI 中文摘要

人工智能在各行业的快速采用(例如用于微调和分析)加速了对高质量数据的需求。为了满足这一需求,公共和私人实体将与其他组织进行数据买卖。但这种数据共享可能并且确实会违反隐私规范和法律法规。欧盟和美国立法者已努力控制数据共享,限制哪些数据可以与谁共享以及在何种情况下共享。不幸的是,准确评估对新监管制度的合规性仍然是一个挑战,因为数据溯源(即关于数据共享的元数据)很少被保留。即使保留了溯源信息,单方面对一方数据库的更改也可能使溯源变得过时。为了填补这一空白,我们提出了Proof-of-Retention,一种新颖的框架和交互式协议,用于强制执行可审计的数据共享。我们的框架要求参与数据共享的每一方保留与每次数据交换相关的信息子集,并提供一种机制供审计员验证各方确实保留了该信息。我们的方法结合了数据库系统技术(包括查询见证生成)与加密的持有证明协议,以提供保留保证。该框架支持高效审计,无需完整数据复制或侵入式监控,从而保护隐私并保持实用性。我们形式化了该协议,分析了其安全性和性能特性,并提供了基于AWS基础设施构建的参考实现。

英文摘要

The rapid adoption of AI across industries for (e.g.) fine-tuning and analytics has accelerated the need for high-quality data. To satisfy this demand, public and private entities will buy and sell data with other organizations. But such data sharing can and does violate privacy norms and laws. EU and American lawmakers have endeavored to control data sharing, restricting what data may be shared with whom, and under what circumstances. Unfortunately, accurately assessing compliance with new regulatory regimes remains a challenge, as data provenance, that is, metadata about data sharing, is rarely preserved. And even when provenance information is retained, unilateral changes to one party's database can render the provenance stale. To fill this gap, we present Proof-of-Retention a novel framework and interactive protocol that enforces auditable data sharing. Our framework requires each party involved in data sharing to retain a subset of information associated with each data exchange, and provides a mechanism for auditors to verify that the parties have indeed retained that information. Our approach combines techniques from database systems, including query witness generation, with cryptographic proof-of-possession protocols to provide retention guarantees. The framework enables efficient auditing that does not require full data replication or intrusive monitoring, thereby preserving privacy and remaining practical. We formalize the protocol, analyze its security and performance properties, and provide a reference implementation built on AWS infrastructure.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑