An Ontology Regulating Privacy Oriented Access Controls

An Ontology Regulating Privacy Oriented Access Controls
复制标题

监管面向隐私的访问控制的本体论

DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
3
通讯作者:
A. Bouhoula
A. Bouhoula
中科院分区:
医学3区
文献类型:
--
作者:
Maherzia Belaazi;H. B. Rahmouni;A. Bouhoula

文献摘要

被引文献

相似文献

访问控制是数据保护的重要传统安全武器之一。在互联网或云计算等开放且复杂的环境中,授予资源访问权限的决定必须确保安全管理,并特别关注隐私和数据保护法规。近年来,提出了许多访问控制模型和语言。尽管立法压力越来越大,但这些提议很少在其规范中考虑隐私要求。在本文中,我们建议在访问控制策略中强制执行隐私合规性。基于语义建模方法,特别是形式本体论,我们将尝试将数据保护立法要求纳入政策规范和实施中。这样做的目的是抽象法律要求表达的复杂性,并促进其在执行层面的自动化和执行。事实上,在运行时,不同信息的互操作性和对文本法的引用以一种新颖的方式得到解决。
Access Control is one of the essential and traditional security weapons of data protection. In open and complex environments such as the Internet or cloud computing, the decision to grant access to a resource must ensure a secure management with a specific attention to privacy and data protection regulations. In recent years, many access control models and languages were proposed. Despite increasing legislative pressure, few of these propositions take care of privacy requirements in their specifications. In this paper we propose to enforce privacy compliance in access control policies. Based on a semantic modeling approach, specifically formal ontology, we will try to incorporate data protection legislation requirements in policies specification and implementation. This aims to abstract the complexity of legal requirements expression and to facilitate their automation and enforcement at execution level. Indeed, at run time, the interoperability of diverse information and the reference to the text law are addressed in a novel manner.