首页> 外文会议>International Conference on Networks >Privacy Token: A Mechanism for User's Privacy Specification in Identity Management Systems for the Cloud
【24h】

Privacy Token: A Mechanism for User's Privacy Specification in Identity Management Systems for the Cloud

机译:隐私令牌:云的身份管理系统中的用户隐私规范的机制

获取原文

摘要

With the increasing amount of personal data stored and processed in the cloud, economic and social incentives to collect and aggregate such data have emerged. Therefore, secondary use of data, including sharing with third parties, has become a common practice among service providers and may lead to privacy breaches and cause damage to users since it involves using information in a non-consensual and possibly unwanted manner. Despite numerous works regarding privacy in cloud environments, users are still unable to control how their personal information can be used, by whom and for which purposes. This paper presents a mechanism for identity management systems that instructs users about the possible uses of their personal data by service providers, allows them to set their privacy preferences and sends these preferences to the service provider along with their identification data in a standardized, machine-readable structure, called privacy token. This approach is based on a three-dimensional classification of the possible secondary uses of data, four predefined privacy profiles and a customizable one, and a secure token for transmitting the privacy preferences. The correct operation of the mechanism was verified through a prototype, which was developed in Java in order to be incorporated, in future work, to an implementation of the OpenId Connect protocol. The main contribution of this paper is the privacy token, which inverts the current scenario where users are forced to accept the policies defined by service providers by allowing the former to express their privacy preferences and requesting the latter to align their actions or ask for specific permissions.
机译:随着在云中储存和处理的个人数据的增加,经济和社会激励措施收集和汇总此类数据。因此,包括与第三方共享的数据的二次使用已成为服务提供商之间的常见做法,可能导致隐私违规并导致用户造成损害,因为它涉及以非自愿和可能不必要的方式使用信息。尽管有许多有关云环境隐私作品,但用户仍无法控制其个人信息如何,由谁和谁使用谁。本文为身份管理系统提供了一种机制,该机制指示用户通过服务提供商对其个人数据的可能用途,允许它们设置其隐私首选项,并将这些偏好发送到服务提供商以及标准化,机器中的标识数据以及它们的标识数据可读结构,称为隐私令牌。该方法基于数​​据的三维分类,数据的次要用途,四个预定义的隐私配置文件和可自定义的一个,以及用于传输隐私偏好的安全令牌。通过原型验证了该机制的正确操作,该原型是在Java中开发的,以便将来在未来的工作中加入OpenID连接协议的实现。本文的主要贡献是隐私令牌,它将当前的方案反转,其中用户被迫接受服务提供商定义的策略,允许前者表达其隐私首选项并请求后者对齐他们的操作或询问特定权限。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号