A privacy-aware access control system

被引:56
|
作者
Ardagna, C. [1 ]
Cremonini, M. [1 ]
di Vimercati, S. [1 ]
Samarati, P. [1 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, Via Bramante 65, I-26013 Crema, Italy
关键词
Access control; privacy; data handling policies;
D O I
10.3233/JCS-2008-0328
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The protection of privacy is an increasing concern in our networked society because of the growing amount of personal information that is being collected by a number of commercial and public services. Emerging scenarios of user-service interactions in the digital world are then pushing toward the development of powerful and flexible privacy-aware models and languages. This paper aims at introducing concepts and features that should be investigated to fulfill this demand. We identify different types of privacy-aware policies: access control, release and data handling policies. The access control policies govern access/release of data/services managed by the party (as in traditional access control), and release policies govern release of personal identifiable information (PII) of the party and specify under which conditions it can be disclosed. The data handling policies allow users to specify and communicate to other parties the policy that should be enforced to deal with their data. We also discuss how data handling policies can be integrated with traditional access control systems and present a privacy control module in charge of managing, integrating, and evaluating access control, release and data handling policies.
引用
收藏
页码:369 / 397
页数:29
相关论文
共 50 条
  • [21] A Category-Based Framework for Privacy-Aware Collaborative Access Control
    Obrezkov, Denis
    Sohr, Karsten
    Malaka, Rainer
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS (TRUSTBUS 2021), 2021, 12927 : 126 - 139
  • [22] A Privacy-Aware Access Model on Anonymized Data
    Huang, Xuezhen
    Liu, Jiqiang
    Han, Zhen
    TRUSTED SYSTEMS, INTRUST 2014, 2015, 9473 : 201 - 212
  • [23] Multi-domain and Privacy-aware Role Based Access Control in eHealth
    Martino, Lorenzo D.
    Ni, Qun
    Lin, Dan
    Bertino, Elisa
    2008 2ND INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING TECHNOLOGIES FOR HEALTHCARE, 2008, : 123 - 126
  • [24] Privacy-aware access control for message exchange in vehicular ad hoc networks
    Sushama Karumanchi
    Anna Squicciarini
    Dan Lin
    Telecommunication Systems, 2015, 58 : 349 - 361
  • [25] Purpose fusion: The risk purpose based privacy-aware data access control
    Liu Y.-M.
    Zhou H.-F.
    Wang Z.-H.
    Wang W.
    Jisuanji Xuebao/Chinese Journal of Computers, 2010, 33 (08): : 1339 - 1348
  • [26] Privacy-aware collaborative access control in Web-based Social Networks
    Carminati, Barbara
    Ferrari, Elena
    DATA AND APPLICATIONS SECURITY XXII, 2008, 5094 : 81 - 96
  • [27] Privacy-aware access control for message exchange in vehicular ad hoc networks
    Karumanchi, Sushama
    Squicciarini, Anna
    Lin, Dan
    TELECOMMUNICATION SYSTEMS, 2015, 58 (04) : 349 - 361
  • [28] A privacy-aware continuous authentication scheme for proximity-based access control
    Agudo, Isaac
    Rios, Ruben
    Lopez, Javier
    COMPUTERS & SECURITY, 2013, 39 : 117 - 126
  • [29] Privacy-Aware and Context-Sensitive Access Control for Opportunistic Data Sharing
    Luis Herrera, Juan
    Chen, Hsiao-Yuan
    Berrocal, Javier
    Murillo, Juan M.
    Julien, Christine
    21ST IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING (CCGRID 2021), 2021, : 762 - 769
  • [30] Risk-Based Privacy-Aware Access Control for Threat Detection Systems
    Metoui, Nadia
    Bezzi, Michele
    Armando, Alessandro
    TRANSACTIONS ON LARGE-SCALE DATA- AND KNOWLEDGECENTERED SYSTEMS XXXVI: SPECIAL ISSUE ON DATA AND SECURITY ENGINEERING, 2018, 10720 : 1 - 30