Formal specification and verification of user-centric privacy policies for ubiquitous systems

Formal specification and verification of user-centric privacy policies for ubiquitous systems
复制标题

DOI:
10.1145/3331076.3331105
复制
发表时间:
2019-06
期刊:
Proceedings of the 23rd International Database Applications & Engineering Symposium
影响因子:
--
通讯作者:
Rezvan Joshaghani;Stacy Black;Elena Sherman;Hoda Mehrpouyan
Rezvan Joshaghani;Stacy Black;Elena Sherman;Hoda Mehrpouyan
中科院分区:
其他
文献类型:
--
作者:
Rezvan Joshaghani;Stacy Black;Elena Sherman;Hoda Mehrpouyan

文献摘要

被引文献

相似文献

随着我们的社会变得更加信息化,每个人都被信息和信息技术所表达、定义和影响。虽然有价值,但目前的最先进技术大多被设计为保护企业/组织的隐私要求,并留下主要参与者,即,用户,不参与或具有有限的能力来控制他/她的信息共享实践。为了克服这些局限性,算法和工具,提供了一个以用户为中心的隐私管理系统,以不同的隐私问题的个人需要考虑到隐私政策的动态性质,这是不断变化的基础上的信息共享上下文和环境变量。本文扩展了上下文完整性的概念,提供数学模型和算法,使个人用户的隐私规范的创建和管理。该扩展包括环境变量的增加,即时间,日期等作为隐私规范的一部分,同时引入信息属性的抽象和部分关系。此外,提出了一种形式化的验证技术,以确保隐私规范执行每个信息共享行动。
As our society has become more information oriented, each individual is expressed, defined, and impacted by information and information technology. While valuable, the current state-of-the-art mostly are designed to protect the enterprise/ organizational privacy requirements and leave the main actor, i.e., the user, un-involved or with the limited ability to have control over his/her information sharing practices. In order to overcome these limitations, algorithms and tools that provide a user-centric privacy management system to individuals with different privacy concerns are required to take into the consideration the dynamic nature of privacy policies which are constantly changing based on the information sharing context and environmental variables. This paper extends the concept of contextual integrity to provide mathematical models and algorithms that enables the creations and management of privacy norms for individual users. The extension includes the augmentation of environmental variables, i.e. time, date, etc. as part of the privacy norms, while introducing an abstraction and a partial relation over information attributes. Further, a formal verification technique is proposed to ensure privacy norms are enforced for each information sharing action.