An Ontology-based Guidance for Privacy Enforcement in a Multi-Authority Cloud Environment

被引:0
作者
Belaazi, Maherzia [1 ]
Rahmouni, Hanen Boussi [1 ]
Bouhoula, Adel [1 ]
机构
[1] Higher Sch Commun Tunis, Digital Secur Res Unit, Tunis, Tunisia
来源
2015 INTERNATIONAL CONFERENCE ON CLOUD TECHNOLOGIES AND APPLICATIONS (CLOUDTECH 15) | 2015年
关键词
law enforcement; semantic web; ontology; data management; access control; privacy; security policies; public Cloud;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Despite its attractive benefits, cloud adoption is challenged by some criteria of security and privacy. Access Control is one of the traditional and essential security tools of data protection. The decision to grant access to a resource must ensure secure management with a specific attention to privacy and data protection regulations. In particular, the challenge is more important with public clouds as many governing authorities could be involved in one cloud scenario. This implies a difficulty to work out which regulation should be applicable in case of conflict. In recent years, many access control models were proposed. Despite increasing legislative pressure, few of these propositions take care of privacy requirements in their security policies specification and enforcement. In this paper, we propose to enforce privacy compliance in access control policies for the context of public cloud. Throughout the use of ontology tools, we propose an approach for checking privacy enforcement with access control conditions. We also suggest the use of privacy safeguards notification where the threat to privacy protection is related to the secondary usage of personal data more than just the data access itself.
引用
收藏
页码:373 / 379
页数:7
相关论文
共 18 条
[1]  
Benantar Messaoud, 2001, ACCESS CONTROL SYSTE
[2]  
CAN Ozgu, 2010, GAZI U J SCI
[3]  
Covington Michael J., 2006, MOV MEAN INT SYST 20, V4278
[4]  
ELKALAM AA, 2003, IEEE 4 INT WORKSH PO
[5]  
Ferraiolo D.F., 1992, 15 NATL COMPUTER SEC, P554
[6]  
Ferrari E., 2010, SYNTHESIS LECT DATA
[7]  
Gabillon A, 2010, NETW SYST SEC NSS 20
[8]  
Garcia D., 2009, IEEE INT C SERV OR C
[9]  
McCormick Michelle, 2011, NEW PRIVACY LEGISLAT
[10]  
OECD, 2011, 30 YEARS OECD PRIV G