Policy-Carrying Data: A Privacy Abstraction for Attaching Terms of Service to Mobile Data

被引:6
|
作者
Saroiu, Stefan [1 ]
Wolman, Alec [1 ]
Agarwal, Sharad [1 ]
机构
[1] Microsoft Res, Redmond, WA 98052 USA
关键词
D O I
10.1145/2699343.2699357
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Despite decades of work on privacy protecting systems, mobile user privacy remains at the mercy of cloud service providers. This paper proposes a different approach - let users attach Terms of Service (ToS) to their data before uploading it to the cloud. We propose an abstraction, called policy-carrying data (PCD), that lets users specify and attach ToS to their data. PCD guarantees that cloud providers claim they are compliant with the ToS policy before they are able to access the data. To offer this guarantee, PCD relies on attribute-based encryption. We present PCD's semantics, its properties, and describe how PCD can be added to JSON or REST. Our hope is that PCD opens a different research path - designing privacy abstractions that provide legal ammunition for mobile users against misuse of their data.
引用
收藏
页码:129 / 134
页数:6
相关论文
共 50 条
  • [1] Policy-Carrying Data: A Step Towards Transparent Data Sharing
    Padget, Julian
    Vasconcelos, Wamberto W.
    [J]. 6TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT-2015), THE 5TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2015), 2015, 52 : 51 - 58
  • [2] Fine-Grained Access Control via Policy-Carrying Data
    Padget, Julian A.
    Vasconcelos, Wamberto W.
    [J]. ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2018, 18 (03)
  • [3] Protecting Outsourced Data Privacy with Lifelong Policy Carrying
    Wang, Xiaoguang
    Yong, Qi
    Dai, Yuehua
    Ren, Jianbao
    Hang, Zhang
    [J]. 2013 IEEE 15TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2013 IEEE INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING (HPCC_EUC), 2013, : 896 - 905
  • [4] Learning Data Privacy and Terms of Service from Different Cloud Service Providers
    Bahrami, Mehdi
    Singhal, Mukesh
    Chen, Wei-Peng
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD), 2017, : 250 - 257
  • [5] Mobile apps and data privacy: when the service is free, the product is your data
    Polykalas, Spyros E.
    Prezerakos, George N.
    Chrysidou, Froso D.
    Pylarinou, Eleni D.
    [J]. 2017 8TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS & APPLICATIONS (IISA), 2017, : 444 - 448
  • [6] Protect privacy of mobile data
    Buckee, Caroline O.
    [J]. NATURE, 2014, 514 (7520) : 35 - 35
  • [7] Protect privacy of mobile data
    Caroline O. Buckee
    [J]. Nature, 2014, 514 : 35 - 35
  • [8] Privacy in Data Service Composition
    Barhamgi, Mahmoud
    Perera, Charith
    Yu, Chia-Mu
    Benslimane, Djamal
    Camacho, David
    Bonnet, Christine
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (04) : 639 - 652
  • [9] Secure and Privacy Preserving Mobile Healthcare Data Exchange Using Cloud Service
    Pal, Doyel
    Senchury, Gobinda
    Khethavath, Praveenkumar
    [J]. SECURITY IN COMPUTING AND COMMUNICATIONS, SSCC 2016, 2016, 625 : 213 - 224
  • [10] Policy and role based mobile RFID user privacy data management system
    Park, Namje
    Song, Youjin
    Won, Dongho
    [J]. 2008 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1 AND 2, 2008, : 1003 - +