본문 바로가기
  • Home

A Security Vulnerability Assessment of Personal Data Storage Technologies

  • Journal of Software Assessment and Valuation
  • Abbr : JSAV
  • 2025, 21(3), pp.1~10
  • Publisher : Korea Software Assessment and Valuation Society
  • Research Area : Engineering > Computer Science
  • Received : September 1, 2025
  • Accepted : September 20, 2025
  • Published : September 25, 2025

Dupyo Hong 1 Sung-Il Jang 2 Yong-Joon Joe 1 Dong-Myung Shin 1

1엘에스웨어
2엘에스웨어 (주)

Accredited

ABSTRACT

Against the backdrop of shifts in the digital economy and data-sovereignty regulation, Personal Data Stores (PDS) have emerged as a viable alternative; however, limitations persist—most notably security vulnerabilities and a lack of empirical validation in operational settings. This work identifies three principal attack surfaces—(1) authentication and access control, (2) third-party applications, and (3) leakage and inference via repetitive/compound queries—and argues for systematic, quantitative evaluation aligned with market and policy developments. We propose a security architecture that counters each vector through composite proof–based access control, static analysis with permission re-confirmation, and context-aware query monitoring with response-precision control. Scenario-based analyses indicate effectiveness in preventing impersonation and privilege-escalation attempts, preempting malicious code ingress, and detecting query-driven inference attacks at an early stage. The approach strengthens data integrity, privacy, and user agency while aligning with domestic regulatory requirements such as data portability and purpose/Scope specification. The architecture is applicable across healthcare, education, and media, and is deployable alongside standardized APIs, and authentication frameworks to support real-world adoption.

Citation status

* References for papers published after 2024 are currently being built.