The protection of privacy is an increasing concern in our networked society because of the growing amount of personal information that is being collected by a number of commercial and public services. Emerging scenarios of user-service interactions in the digital world are then pushing toward the development of powerful and flexible privacy-aware models and languages. This paper aims at introducing concepts and features that should be investigated to fulfill this demand. We identify different types of privacy-aware policies: access control, release and data handling policies. The access control policies govern access/release of data/services managed by the party (as in traditional access control), and release policies govern release of personal identifiable information (PII) of the party and specify under which conditions it can be disclosed. The data handling policies allow users to specify and communicate to other parties the policy that should be enforced to deal with their data. We also discuss how data handling policies can be integrated with traditional access control systems and present a privacy control module in charge of managing, integrating, and evaluating access control, release and data handling policies.

A privacy-aware access control system / C.A. Ardagna, M. Cremonini, S. De Capitani di Vimercati, P. Samarati. - In: JOURNAL OF COMPUTER SECURITY. - ISSN 0926-227X. - 16:4(2008), pp. 369-397. [10.3233/JCS-2008-0328]

A privacy-aware access control system

C.A. Ardagna
Primo
;
M. Cremonini
Secondo
;
S. De Capitani di Vimercati
Penultimo
;
P. Samarati
Ultimo
2008

Abstract

The protection of privacy is an increasing concern in our networked society because of the growing amount of personal information that is being collected by a number of commercial and public services. Emerging scenarios of user-service interactions in the digital world are then pushing toward the development of powerful and flexible privacy-aware models and languages. This paper aims at introducing concepts and features that should be investigated to fulfill this demand. We identify different types of privacy-aware policies: access control, release and data handling policies. The access control policies govern access/release of data/services managed by the party (as in traditional access control), and release policies govern release of personal identifiable information (PII) of the party and specify under which conditions it can be disclosed. The data handling policies allow users to specify and communicate to other parties the policy that should be enforced to deal with their data. We also discuss how data handling policies can be integrated with traditional access control systems and present a privacy control module in charge of managing, integrating, and evaluating access control, release and data handling policies.
English
Access control; Data handling policies; Privacy
Settore INF/01 - Informatica
Articolo
Sì, ma tipo non specificato
2008
IOS press
16
4
369
397
Periodico con rilevanza internazionale
info:eu-repo/semantics/article
A privacy-aware access control system / C.A. Ardagna, M. Cremonini, S. De Capitani di Vimercati, P. Samarati. - In: JOURNAL OF COMPUTER SECURITY. - ISSN 0926-227X. - 16:4(2008), pp. 369-397. [10.3233/JCS-2008-0328]
none
Prodotti della ricerca::01 - Articolo su periodico
4
262
Article (author)
no
C.A. Ardagna, M. Cremonini, S. De Capitani di Vimercati, P. Samarati
File in questo prodotto:
Non ci sono file associati a questo prodotto.
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/48811
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 81
  • ???jsp.display-item.citation.isi??? ND
social impact