A privacy-aware access control system

被引:56
|
作者
Ardagna, C. [1 ]
Cremonini, M. [1 ]
di Vimercati, S. [1 ]
Samarati, P. [1 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, Via Bramante 65, I-26013 Crema, Italy
关键词
Access control; privacy; data handling policies;
D O I
10.3233/JCS-2008-0328
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The protection of privacy is an increasing concern in our networked society because of the growing amount of personal information that is being collected by a number of commercial and public services. Emerging scenarios of user-service interactions in the digital world are then pushing toward the development of powerful and flexible privacy-aware models and languages. This paper aims at introducing concepts and features that should be investigated to fulfill this demand. We identify different types of privacy-aware policies: access control, release and data handling policies. The access control policies govern access/release of data/services managed by the party (as in traditional access control), and release policies govern release of personal identifiable information (PII) of the party and specify under which conditions it can be disclosed. The data handling policies allow users to specify and communicate to other parties the policy that should be enforced to deal with their data. We also discuss how data handling policies can be integrated with traditional access control systems and present a privacy control module in charge of managing, integrating, and evaluating access control, release and data handling policies.
引用
收藏
页码:369 / 397
页数:29
相关论文
共 50 条
  • [31] Privacy aware decentralized access control system
    Shafeeq, Sehrish
    Alam, Masoom
    Khan, Abid
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 101 : 420 - 433
  • [32] A Contextual Privacy-Aware Access Control Model for Network Monitoring Workflows: Work in Progress
    Papagiannakopoulou, Eugenia I. .
    Koukovini, Maria N.
    Lioudakis, Georgios V.
    Garcia-Alfaro, Joaquin
    Kaklamani, Dimitra I.
    Venieris, Iakovos S.
    FOUNDATIONS AND PRACTICE OF SECURITY, 2011, 6888 : 208 - +
  • [33] A privacy-aware architecture for a Web rating system
    Viecco, C.
    Tsow, A.
    Camp, L. J.
    IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2009, 53 (02)
  • [34] A privacy-aware decentralized and personalized reputation system
    Bag, Samiran
    Azad, Muhammad Ajmal
    Hao, Feng
    COMPUTERS & SECURITY, 2018, 77 : 514 - 530
  • [35] An anonymous credential system and a privacy-aware PKI
    Persiano, P
    Visconti, I
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2003, 2727 : 27 - 38
  • [36] PACAS: A Privacy-Aware Smart Camera System
    Yu, Keyang
    Chen, Dong
    2024 IEEE CLOUD SUMMIT, CLOUD SUMMIT 2024, 2024, : 170 - 177
  • [37] Secure smart health with privacy-aware aggregate authentication and access control in Internet of Things
    Zhang, Yinghui
    Deng, Robert H.
    Han, Gang
    Zheng, Dong
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 123 : 89 - 100
  • [38] Privacy-Aware Wrappers
    Jafer, Yasser
    Matwin, Stan
    Sokolova, Marina
    ADVANCES IN ARTIFICIAL INTELLIGENCE (AI 2015), 2015, 9091 : 130 - 138
  • [39] Privacy-Aware Folksonomies
    Heidinger, Clemens
    Buchmann, Erik
    Huber, Matthias
    Boehm, Klemens
    Mueller-Quade, Joern
    RESEARCH AND ADVANCED TECHNOLOGY FOR DIGITAL LIBRARIES, 2010, 6273 : 156 - 167
  • [40] The user-centered privacy-aware control system PRICON: An interdisciplinary evaluation
    Walter, J.
    Abendroth, B.
    von Pape, T.
    Plappert, C.
    Zelle, D.
    Krauss, C.
    Gagzow, G.
    Decke, H.
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,