PrimeLife Policy Language

PrimeLife Policy Language
复制标题

PrimeLife 政策语言

DOI:
--
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
Mario Verdicchio
Mario Verdicchio
中科院分区:
--
文献类型:
--
作者:
C. Ardagna;Laurent Bussard;S. Vimercati;G. Neven;S. Paraboschi;Eros Pedrini;Franz;D. Raggett;P. Samarati;S. Trabelsi;Mario Verdicchio

文献摘要

被引文献

相似文献

社交网络和Web 2.0应用的突然流行从根本上改变了互联网的格局以及用户的行为。如今的年轻人是第一代有能力快速、低成本地向大量人群传播信息的人。发布并存储在服务器上的个人和私密信息数量如此庞大,以至于传统的隐私概念受到了根本性的影响。为了缓解这些担忧,企业和服务提供商发布隐私声明,承诺公平的信息处理方式。这些声明用自然语言书写,或者使用诸如P3P[1]、EPAL[2]、XACML[3]等语言形式化表述……它们只是承诺,不一定有技术措施来强制执行。如果个人数据不仅被收集数据的企业使用,还被合作伙伴组织或政府机构等二级用户使用,这些问题就会更加严重。这些数据流动是复杂的。对数据隐私的威胁可能来自每个组织的内部(意外泄露、内部人员的好奇心和收买)以及外部(不受控制的二次使用)。将客户信息放在网上进一步增加了将私人和敏感信息暴露给外部人员的风险。在本文中,我们提出一种同时处理访问控制和数据使用的新策略语言。在欧洲信息与通信技术PrimeLife项目的背景下,我们提出对可扩展访问控制标记语言(XACML 3.0)的一种扩展,它是最流行的标准化策略语言之一。这种扩展提出了一种新的义务处理机制,该机制考虑到时间约束、前置义务、条件义务和重复义务,以及一个下游使用授权系统,该系统定义了访问控制规则,根据这些规则,一个实体收集的个人信息可以被转发给第三方。此外,我们的语言基于可信凭证的概念。
The sudden popularity of social networks and web 2.0 applications changed radically the Internet landscape and the users’ behavior. Today’s young people are the first generation with the ability to distribute information quickly, cheaply and to large groups of people. The amount of personal and private information published and stored in the servers becomes so huge that the traditional concepts of privacy were radically affected. To appease such concerns, enterprises and service providers publish privacy statements that promise fair information practices. Written in natural language or formalized using languages like P3P [1], EPAL [2], XACML [3] etc... they are only promises but not necessarily enforced by technical measures. These problems are amplified if personal data is used not only by the enterprise that collected the data, but also by secondary users such as partner organizations, or government agencies. These flows of data are complex. Threats to data privacy can come from inside (accidental disclosure, insider curiosity and subornation) as well as from the outside (uncontrolled secondary usage) of each organization. Putting customer information online further increases the risk of exposing private and sensitive information to outsiders. In this paper we propose a new policy language handling access control and data usage at the same time. In the context of the European ICT PrimeLife1 we propose an extension of the eXtensible access control markup language (XACML 3.0) offering one of the most popular standardized policy language. This extension suggests a new obligation handling mechanism taking into account temporal constraints, pre-obligations, conditional obligations, and repeating obligations together with a down-stream usage authorization system defining the access control rules under which personal information collected by an entity can be forwarded to a third party. Moreover, our language is based on the concept of trusted credentials.