Towards Accountable Management of Identity and Privacy: Sticky Policies and Enforceable Tracing Services
نویسندگان
چکیده
Digital identities and profiles are precious assets. On one hand they enable users to engage in transactions and interactions on the Internet. On the other hand, abuses and leakages of this information could violate the privacy of their owners, sometimes with serious consequences. Nowadays, most of the people have limited understanding of security and privacy polices when applied to their confidential information. In addition, people have little control over the destiny of this information once it has been disclosed to third parties. In most cases this is a matter of trust. This document describes an innovative approach and related mechanisms to enforce users' privacy by putting users in control and making organizations more accountable. We introduce a technical solution based on sticky policies and tracing services that leverages Identifier-based Encryption (IBE) and TCPA technologies. Work is in progress to build a full working prototype.
منابع مشابه
A Cloud Accountability Policy Representation Framework
Nowadays we are witnessing the democratization of cloud services. As a result, more and more endusers (individuals and businesses) are using these services for achieving their electronic transactions (shopping, administrative procedures, B2B transactions, etc.). In such scenarios, personal data is generally flowed between several entities and end-users need (i) to be aware of the management, pr...
متن کاملAutomating Compliance for Cloud Computing Services
We present an integrated approach for automating service providers’ compliance with data protection laws and regulations, business and technical requirements in cloud computing. The techniques we propose in particular include: natural-language analysis (of legislative and regulatory texts, and corporate security rulebooks) and extraction of enforceable rules, use of sticky policies, automated p...
متن کاملTraceable and Automatic Compliance of Privacy Policies in Federated Digital Identity Management
Digital identity is defined as the digital representation of the information known about a specific individual or organization. An emerging approach for protecting identities of individuals while at the same time enhancing user convenience is to focus on inter-organization management of identity information. This is referred to as federated identity management. In this paper we develop an appro...
متن کاملTraceable and Automatic Compliance of Privacy Policies in Federated Digital Identity Management
Digital identity is defined as the digital representation of the information known about a specific individual or organization. An emerging approach for protecting identities of individuals while at the same time enhancing user convenience is to focus on inter-organization management of identity information. This is referred to as federated identity management. In this paper we develop an appro...
متن کاملAutomatic Compliance of Privacy Policies in Federated Digital Identity
Privacy [13] in the digital world is an important problem which is becoming even more pressing as new collaborative applications are developed. The lack of privacy preserving mechanisms is particularly problematic in federated identity management contexts. In such a context, users can seamlessly interact with a variety of federated web services, through the use of single-sign-on mechanisms and ...
متن کامل