A privacy-aware access control system

被引:55
|
作者
Ardagna, C. [1 ]
Cremonini, M. [1 ]
di Vimercati, S. [1 ]
Samarati, P. [1 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, Via Bramante 65, I-26013 Crema, Italy
关键词
Access control; privacy; data handling policies;
D O I
10.3233/JCS-2008-0328
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The protection of privacy is an increasing concern in our networked society because of the growing amount of personal information that is being collected by a number of commercial and public services. Emerging scenarios of user-service interactions in the digital world are then pushing toward the development of powerful and flexible privacy-aware models and languages. This paper aims at introducing concepts and features that should be investigated to fulfill this demand. We identify different types of privacy-aware policies: access control, release and data handling policies. The access control policies govern access/release of data/services managed by the party (as in traditional access control), and release policies govern release of personal identifiable information (PII) of the party and specify under which conditions it can be disclosed. The data handling policies allow users to specify and communicate to other parties the policy that should be enforced to deal with their data. We also discuss how data handling policies can be integrated with traditional access control systems and present a privacy control module in charge of managing, integrating, and evaluating access control, release and data handling policies.
引用
收藏
页码:369 / 397
页数:29
相关论文
共 50 条
  • [1] Privacy-aware Role Based Access Control
    Ni, Qun
    Trombetta, Alberto
    Bertino, Elisa
    Lobo, Jorge
    [J]. SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 41 - 50
  • [2] A Semantic Framework for Privacy-Aware Access Control
    Lioudakis, Georgios V.
    Dellas, Nikolaos L.
    Koutsoloukas, Eleftherios A.
    Kapitsaki, Georgia M.
    Kaklamani, Dimitra I.
    Venieris, Iakovos S.
    [J]. 2008 INTERNATIONAL MULTICONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY (IMCSIT), VOLS 1 AND 2, 2008, : 757 - 764
  • [3] Access control in a privacy-aware eLearning environment
    Franz, Elke
    Wahrig, Hagen
    Boettcher, Alexander
    Borcea-Pfitzmann, Katrin
    [J]. FIRST INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2006, : 879 - +
  • [4] Privacy-Aware Role-Based Access Control
    Ni, Qun
    Bertino, Elisa
    Lobo, Jorge
    Calo, Seraphin B.
    [J]. IEEE SECURITY & PRIVACY, 2009, 7 (04) : 35 - 43
  • [5] Conditional privacy-aware role based access control
    Ni, Qun
    Lin, Dan
    Bertino, Elisa
    Lobo, Jorge
    [J]. COMPUTER SECURITY - ESORICS 2007, PROCEEDINGS, 2007, 4734 : 72 - +
  • [6] Privacy-Aware Role-Based Access Control
    Ni, Qun
    Bertino, Elisa
    Lobo, Jorge
    Brodie, Carolyn
    Karat, Clare-Marie
    Karat, John
    Trombetta, Alberto
    [J]. ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (03)
  • [7] The architecture of a privacy-aware access control decision component
    Ardagna, Claudio A.
    Cremonini, Marco
    Damiani, Ernesto
    De Capitani di Vimercati, Sabrina
    Samarati, Pierangela
    [J]. CONSTRUCTION AND ANALYSIS OF SAFE, SECURE, AND INTEROPERABLE SMART DEVICES, 2006, 3956 : 1 - 15
  • [8] Scalable Access Control For Privacy-Aware Media Sharing
    Ma, Changsha
    Yan, Zhisheng
    Chen, Chang Wen
    [J]. IEEE TRANSACTIONS ON MULTIMEDIA, 2019, 21 (01) : 173 - 183
  • [9] A Privacy-aware Graph-based Access Control System for the Healthcare Domain
    Tian, Yuan
    Song, Biao
    Hassan, M. Mehedi
    Huh, Eui-Nam
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2012, 6 (10): : 2708 - 2730
  • [10] Privacy-aware access control with trust management in web service
    Li, Min
    Sun, Xiaoxun
    Wang, Hua
    Zhang, Yanchun
    Zhang, Ji
    [J]. WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2011, 14 (04): : 407 - 430