Privacy Policy Negotiation at User’s Side Based on P3P Tag Value Classification
نویسندگان
چکیده
Concerns of users about privacy of their personal data are of higher and higher importance to online Service Providers (SPs), as they turn into a major barrier for broad acceptance by users of services that are known to collect and utilize their personal data. With the P3P standard (Platform for Privacy Preferences), in the context of web-based applications, users are allowed to keep control over the collection, use and sharing of their personal data. However, P3P still lacks a negotiation mechanism. In this paper, we address this limitation by proposing a novel scheme to permit users to automate the negotiation of the privacy terms related to their personal data in transactions. The original idea of our contribution is to establish a classification of P3P tag values, and to define negotiation rounds and phases during which the user is able to compare his privacy preferences against the set of privacy policies provided in order of preference by the SP. For that purpose, we extended the expressiveness of the P3P and XACML languages that help users and SPs to define in an orderly way their privacy preferences / policies for the same transaction. For illustration purpose, we designed a user interface for users to define their preferences according to the classification, and we proved the feasibility of the negotiation scheme through a simple prototype. Keywords— Privacy, privacy policy, negotiation, classification of
منابع مشابه
Personalized Services with Negotiable Privacy Policies
This paper examines how negotiation techniques can resolve the trade-off between service providers’ personalization efforts and users’ individual privacy concerns, how they lead to efficient contracts, and how they can be integrated into existing technologies to overcome the shortcomings of static privacy policies. The analysis includes the identification of relevant and negotiable privacy dime...
متن کاملPrivacy Negotiations with P3P
This paper examines how negotiation techniques can resolve the trade-off between service providers’ personalization efforts and users’ individual privacy concerns and demonstrates how they can be integrated into existing technologies to overcome the shortcomings of static privacy policies. The analysis includes the identification of relevant and negotiable privacy dimensions. An extension to P3...
متن کاملXPACML eXtensible Privacy Access Control Markup Language
Privacy in the digital world is a critical problem which is becoming even more imperious with the growth of the Internet, accompanied by the proliferation of e-services (e.g. ecommerce, e-health). One research track for efficient privacy management is to make use of user’s and service provider’s (SP) privacy policies, and to perform an automatic comparison in between to help any (skilled or uns...
متن کاملProtecting Privacy on the Internet using P3P and APPEL through Reconciliation of Server Policies with Client Preferences
This paper examines the issue of how server privacy policies can be reconciled with user privacy preferences. The P3P and APPEL privacy standards being written by the W3C are introduced and discussed. The problem of preference-policy reconciliation as yet has no satisfactory solution. Requirements for a general purpose solution are proposed. Early attempts to solve this problem include: Microso...
متن کاملSpontaneous Privacy Policy Negotiations in Pervasive Environments
Privacy issues are a major burden for the acceptance of pervasive applications. They may ultimately result in the rejection of new services despite their functional benefits. Especially excessive data collection scares the potential user away. Privacy Negotiations restore respect for the user’s privacy preferences because the kind and amount of personal data to be disclosed is settled individua...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011