首页> 外文会议>IEEE Computer Security Foundations Workshop >A privacy policy model for enterprises
【24h】

A privacy policy model for enterprises

机译:企业隐私政策模型

获取原文

摘要

Privacy is an increasing concern in the marketplace. Although enterprises promise sound privacy practices to their customers, there is no technical mechanism to enforce them internally. In this paper we describe a privacy policy model that protects personal data from privacy violations by means of enforcing enterprise-wide privacy policies. By extending Jajodia et al's Flexible Authorization Framework (FAF) with grantors and obligations, we create a privacy control language that includes user consent, obligations, and distributed administration. Conditions impose restrictions on the use of the collected data, such as modeling guardian consent and options. Access decisions are extended with obligations, which list a set of activities that must be executed together with the access request. Grantors allow to define a separation of duty between the security, officer and the privacy officer.
机译:隐私是市场上越来越多的问题。虽然企业承诺给客户提供声音隐私措施,但没有技术机制在内部执行它们。在本文中,我们描述了一种隐私政策模型,通过实施企业范围的隐私政策,保护个人数据免受隐私违规行为。通过扩展Jajodia等人的灵活授权框架(FAF),我们创建了一种隐私控制语言,包括用户同意,义务和分布式管理。条件对使用收集的数据的限制施加限制,例如守护者同意和选项。访问决策延长了义务,其中列出了一组必须与访问请求一起执行的一组活动。制定者允许在安全,官员和隐私官之间定义义务的分离。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号