Enforcing Privacy by Means of an Ontology Driven XACML Framework

Enforcing Privacy by Means of an Ontology Driven XACML Framework
复制标题

通过本体驱动的 XACML 框架强化隐私

DOI:
10.1109/ias.2007.52
复制
发表时间:
2007
期刊:
Third International Symposium on Information Assurance and Security
影响因子:
--
通讯作者:
U. Kelter
U. Kelter
中科院分区:
--
文献类型:
--
作者:
D. E. D. I. Abou;S. Berlik;U. Kelter

文献摘要

被引文献

相似文献

如今,加强企业隐私被认为是一个具有影响力的问题。事实上,在软件系统中适应规范的法律法规是一个很大的挑战。将正式的法律和规则纳入企业是一项具有挑战性的任务,因为例如不止一项法规可能会影响有关一种情况的隐私条款。传统的访问控制提供了向单个用户或角色分配权限的通用机制。就隐私而言,这是不够的;它没有提供满足某些方面的方法,例如限制私人数据的存储期限。为了加强企业的隐私保护,我们还需要对数据实体进行细粒度的访问控制机制,以确保隐私的各个方面都能得到体现。本文通过本体论为此提供了一种新颖的解决方案。我们的方法中本体的使用与传统形式不同,它侧重于生成访问控制策略,这些策略根据我们的软件框架进行调整,以提供对不同数据源的细粒度访问。
Nowadays enforcing privacy in enterprises is recognized as an issue of impact. Actually, it is a big challenge to adapt normative laws and regulations in a software system. It is a challenging task to include the formalized laws and rules in enterprises since e.g. more than one regulation may affect the terms of privacy concerning one situation. Traditional access control provides a general mechanism for assigning rights to individual users or roles. In the context of privacy this is insufficient; it offers no means to fulfil certain aspects such as limitations to the duration for which private data may be stored. To enforce privacy in enterprises we further need a fine granular access control mechanism on the data entities to ensure that every aspect of privacy can be reflected. This paper provides a novel solution for this by means of ontologies. The usage of ontologies in our approach differs from the conventional form in focusing on generating access control policies which are adapted from our software framework to provide fine granular access on the diverse data sources.