Purpose Restrictions on Information Use

نویسندگان

  • Michael Carl Tschantz
  • Anupam Datta
  • Jeannette M. Wing
چکیده

Privacy policies in sectors as diverse as Web services, finance and healthcare often place restrictions on the purposes for which a governed entity may use personal information. Thus, automated methods for enforcing privacy policies require a semantics of purpose restrictions to determine whether a governed agent used information for a purpose. We provide such a semantics using a formalism based on planning. We model planning using Partially Observable Markov Decision Processes (POMDPs), which supports an explicit model of information. We argue that information use is for a purpose if and only if the information is used while planning to optimize the satisfaction of that purpose under the POMDP model. We determine information use by simulating ignorance of the information prohibited by the purpose restriction, which we relate to noninterference. We use this semantics to develop a sound audit algorithm to automate the enforcement of purpose restrictions.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Purpose Restrictions on Information Use (CMU-CyLab-13-005)

Privacy policies in sectors as diverse as Web services, finance and healthcare often place restrictions on the purposes for which a governed entity may use personal information. Thus, automated methods for enforcing privacy policies require a semantics of purpose restrictions to determine whether a governed agent used information for a purpose. We provide such a semantics using a formalism base...

متن کامل

Formalizing and Enforcing Purpose Restrictions in Privacy Policies (Full Version)

Privacy policies often place restrictions on the purposes for which a governed entity may use personal information. For example, regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), require that hospital employees use medical information for only certain purposes, such as treatment, but not for others, such as gossip. Thus, using formal or automated methods for ...

متن کامل

Barriers and restrictions on the activity of credit rating agencies of Tehran Secutities (in order to develop the capital market)

                                                                                                        Abstract Credit ratings reflect the publisher's ability and willingness to fulfill its financial obligations fully and in a timely manner, leading to increased confidence in listed corporations (publishers). The main purpose of the plan is to identify and present the obstacles and limitation...

متن کامل

Risk management of business tax compliance and related strategies in tax auditing

The present study is related to the management and strategy of dealing with the risk of business tax compliance in tax audits using the Grand Theory method. The statistical population of the study is managers, elites and experts in the field of taxation who have been selected from the snowball or chain sampling method for the interview according to the purpose of the research. After receiving t...

متن کامل

Confirming nasogastric tube position: methods & restrictions: A narrative review

Background and Purpose: Inserting a nasogastric tube, though a common clinical procedure with widespread use for critically ill patients, can produce unexpected complications so that tube misplacement into the lungs is a potential complication with serious consequences. The reliability of common bedside methods to differentiate between pulmonary and gastric placement has not been acceptable. Th...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013