科技报告详细信息
Extending XACML Access Control Architecture for Allowing Preference-Based Authorisation
Kounga, Gina ; Casassa Mont, Marco ; Bramhall, Pete
HP Development Company
关键词: Privacy;    Access controls;   
RP-ID  :  HPL-2009-361
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

European data protection regulation states that organisations must have data subjects. consent to use their personally identifiable information (PII) for a variety of purposes. Solutions have been proposed which generally handle consent in a coarse-grained way, by means of opt in/out choices. However, we believe that consent.s representation should be extended to allow data subjects to express a rich set of conditions under which their PII can be used. In this paper we introduce and discuss an approach enabling the representation of consent as fine-grained preferences. To enforce such consent, we leverage and extend the current standard XACML architecture and framework. As data collectors maintain links between PII and associated preferences, preferences should also be considered as part of this PII. Therefore our solution prevents access control components from directly accessing any PII.

【 预 览 】
附件列表
Files Size Format View
RO201804100002483LZ 174KB PDF download
  文献评价指标  
  下载次数:34次 浏览次数:51次