Title
After Brazil’s General Data Protection Law: Authorization in Decentralized Web Applications
Abstract
Decentralized web applications do not offer fine-grained access controls to users’ data, which potentially creates openings for data breaches. For software companies that need to comply with Brazil’s General Data Protection Law (LGPD), data breaches not only might harm application users but also could expose the companies to hefty fines. In this context, engineering fine-grained authorization controls (that comply with the LGPD) to decentralized web application requires creating audit trails, possibly in the source code. Although the literature offers some solutions, they are scattered. We present Esfinge Guardian, an authorization framework that completely separates authorization from other concerns, which increases compliance with the LGPD. We conclude the work with a brief discussion.
Year
DOI
Venue
2019
10.1145/3308560.3316461
Companion Proceedings of The 2019 World Wide Web Conference
Keywords
Field
DocType
Access control, Decentralized Web Applications, Frameworks, Guardian, Solid
Computer science,Source code,Audit trail,Harm,Access control,Web application,Data breach,Guardian,Data Protection Act 1998,Law
Conference
ISBN
Citations 
PageRank 
978-1-4503-6675-5
0
0.34
References 
Authors
0
3
Name
Order
Citations
PageRank
Jefferson de Carvalho Silva1184.73
Newton Calegari200.68
Eduardo R. Gomes3292.58