Semantic-based privacy settings negotiation and management

Semantic-based privacy settings negotiation and management
复制标题

基于语义的隐私设置协商和管理

DOI:
10.1016/j.future.2019.10.024
复制
发表时间:
2019
期刊:
Future Generation Computer Systems
影响因子:
--
通讯作者:
Knijnenburg, Bart P.
Knijnenburg, Bart P.
中科院分区:
--
文献类型:
--
作者:
Sanchez, Odnan Ref;Torre, Ilaria;Knijnenburg, Bart P.

文献摘要

相似文献

到2020年,预计每个人平均将拥有6.58台设备,这些设备共享并整合了大量个人用户数据。在这些设备上管理隐私偏好是一项复杂的任务,用户的设备也不完善,这增加了隐私风险。在本文中,我们提出了一种利用语义网(SW)技术来管理用户的物联网隐私偏好并与第三方协商数据共享权限的方法。软件技术包括一个数据网络,机器可以通过一个正式的、普遍共享的表示来处理这些数据。在我们的方法中,SW支持在个人数据管理器(PDM)和请求访问用户个人数据的第三方(tp)之间进行轻量级且可互操作的通信。PDM可以处理多个异构的个人物联网设备,并管理用户和TP之间的协商过程,从而减轻用户为每个TP指定隐私需求的负担。该方法的核心是物联网隐私偏好本体(PPIoT)的定义,该本体基于隐私偏好本体、W3C语义传感器网络本体、公平信息实践(FIP)原则和物联网隐私保护的最新推荐技术。该本体旨在根据欧盟最近的通用数据保护条例(GDPR)捕捉物联网范式中隐私管理的复杂性。在本文中,我们将提供一个关于如何使用PPIoT本体来管理健身物联网领域的隐私偏好的示例,我们将展示PDM如何处理用户和tp之间的协商过程。该方法基于交互式的基于ppiot的隐私偏好模型(PPM),该模型满足GDPR的要求,具有透明和简单的TP隐私策略。最后,我们将报告对实现此PPM的健身应用模型的评估结果。本文的主要贡献有:(i)提出了物联网背景下的隐私偏好本体,该本体覆盖了现有文献中的知识空白,可用于物联网隐私管理;(ii)提出了一个基于ppiot的交互式隐私偏好模型,该模型符合GDPR的目标。
By 2020, an individual is expected to own an average of 6.58 devices that share and integrate a wealth of personal user data. The management of privacy preferences across these devices is a complex task for which users are ill-equipped, which increases privacy risks. In this paper we propose an approach that exploits Semantic Web (SW) technology to manage the user’s IoT privacy preferences and negotiate the permissions for data sharing with third parties. SW technology comprises a web of data that can be processed by machines through a formal, universally shared representation. In our approach, SW enables a lightweight and interoperable communication between a Personal Data Manager (PDM) and the Third Parties (TPs) that request access to the user’s personal data. The PDM can handle multiple heterogeneous personal IoT devices and manages the negotiation process between the user and the TPs in a way that can relieve users from the burden of specifying their privacy requirement for each TP. The core of the approach is the definition of the Privacy Preference for IoT (PPIoT) Ontology which is based on the Privacy Preference Ontology, the W3C Semantic Sensor Network Ontology, the Fair Information Practices (FIP) principles, and state-of-the-art recommendation techniques for privacy protection in the IoT. This ontology aims to capture the complexity of privacy management in the IoT paradigm in light of the recent General Data Protection Regulation (GDPR) of the European Union. Along with presenting the ontology, in this paper we will provide an example on how to use the PPIoT ontology for the management of privacy preferences in the fitness IoT domain and we will show how the PDM handles the process of negotiation between the user and the TPs. The approach is based on an interactive PPIoT-based Privacy Preference Model (PPM) that meets the requirements of the GDPR to have transparent and simple TP privacy policies. Finally, we will report the results of an evaluation on a mockup fitness app that implements this PPM. The main contributions of this paper are: (i) to propose an ontology for privacy preference in the IoT context, which covers a knowledge gap in existing literature and can be used for IoT privacy management, (ii) to propose an interactive PPIoT-based Privacy Preference Model, which is in accordance with the GDPR objectives.