XPACML eXtensible Privacy Access Control Markup Language
نویسندگان
چکیده
Privacy in the digital world is a critical problem which is becoming even more imperious with the growth of the Internet, accompanied by the proliferation of e-services (e.g. ecommerce, e-health). One research track for efficient privacy management is to make use of user’s and service provider’s (SP) privacy policies, and to perform an automatic comparison in between to help any (skilled or unskilled) users preserving their privacy. In this paper, we focus on the privacy policy comparison issues. We adopt the eXtensible Access Control Markup Language (XACML) as a policy description language for user’s preferences and SP’s policies. We enrich XACML with P3P main elements to permit a privacy aware access control on the user’s personal data elements, thus resulting in the new XPACML (eXtensible Privacy Access Control Markup Language) language. The paper describes first the XPACML language. Then, it presents the functional architecture at the user’s side where the automatic privacy policy compliance can be performed. Finally it discusses our contributions compared to the main proposed solutions in the literature to better identify the interest of them.
منابع مشابه
Security Issues in Context-Aware System
Web Services platform provides the functionality to build and interact with distributed application by sending eXtensible Markup Language (XML) message.But security management is a difficult work of balancing security and usability. This paper present a context-aware system for user access model. Context-aware computing system successfully undertaking by sensor data. The main objective of the c...
متن کاملA Work ow Reference Monitor for Enforcing Purpose-Based Policies
Purpose is a key concept in privacy policies. Based on the purpose framework developed in our earlier work [11] we present an access control model for a work ow-based information system in which a work ows reference monitor ( WfRM ) enforces purpose-based policies. We use a generic access control policy language and show how it can be connected to the purpose modal logic language ( PML ) to lin...
متن کاملA Self-Protecting Security Framework for CDA Documents
Clinical Document Architecture (CDA) is a standard for the exchange of electronic medical records. This paper describes a self-protecting security framework for protecting the security and privacy of CDA documents. The framework extends a CDA document with markups from XML based security standards including eXtensible Access Control Markup Language, XML Encryption, and XML Signature. This integ...
متن کاملEnhancing Security and Privacy of Healthcare Data using XML Schema
Information security and privacy in the health care sector is an issue of growing importance. Widespread use of digital data in health care industry has provided potentially immeasurable benefits by instant access to patient information practically from anywhere in the world. Connecting HIS to the network and making EHR available over the Internet put the data vulnerable to security threats and...
متن کاملRole-Based Access Control for Cyber-Physical Systems Using Shibboleth
In this paper, we propose a role-based access control (RBAC) system for the distributed resources in a cyber-physical system. Current identity-based access control systems cause substantial administration overhead for the resource managers in the cyberphysical system because of the direct mapping between individual users and the access privileges on the resources. Our RBAC system uses Shibbolet...
متن کامل