首页> 外文会议>Privacy Enhancing Technologies; Lecture Notes in Computer Science; 4258 >A Systemic Approach to Automate Privacy Policy Enforcement in Enterprises
【24h】

A Systemic Approach to Automate Privacy Policy Enforcement in Enterprises

机译:一种自动执行企业隐私政策的系统方法

获取原文
获取原文并翻译 | 示例

摘要

It is common practice for enterprises and other organisations to ask people to disclose their personal data in order to grant them access to services and engage in transactions. This practice is not going to disappear, at least in the foreseeable future. Most enterprises need personal information to run their businesses and provide the required services, many of whom have turned to identity management solutions to do this in an efficient and automated way. Privacy laws dictate how enterprises should handle personal data in a privacy compliant way: this requires dealing with privacy rights, permissions and obligations. It involves operational and compliance aspects. Currently much is done by means of manual processes, which make them difficult and expensive to comply with. A key requirement for enterprises is being able to leverage their investments in identity management solutions. This paper focuses on how to automate the enforcement of privacy within enterprises in a systemic way, in particular privacy-aware access to personal data and enforcement of privacy obligations: this is still open to innovation. We introduce our work in these areas: core concepts are described along with our policy enforcement models and related technologies. Two prototypes have been built as a proof of concept and integrated with state-of-the-art (commercial) identity management solutions to demonstrate the feasibility of our work. We provide technical details, discuss open issues and our next steps.
机译:企业和其他组织的普遍做法是要求人们披露其个人数据,以便授予他们访问服务和进行交易的权限。至少在可预见的将来,这种做法不会消失。大多数企业都需要个人信息来经营自己的业务并提供所需的服务,其中许多企业已转向身份管理解决方案来以高效且自动化的方式进行此操作。隐私法规定了企业应如何以符合隐私的方式处理个人数据:这需要处理隐私权,权限和义务。它涉及运营和合规性方面。当前,许多工作是通过手动过程来完成的,这使得它们难以遵守且昂贵。企业的一项关键要求是能够利用其在身份管理解决方案中的投资。本文重点介绍如何以系统的方式自动执行企业内部的隐私保护,尤其是对隐私敏感的个人数据访问和隐私保护义务的执行:这仍然是创新的开端。我们在这些领域中介绍我们的工作:描述了核心概念以及我们的策略执行模型和相关技术。已构建了两个原型作为概念验证,并与最新的(商业)身份管理解决方案集成在一起,以证明我们工作的可行性。我们提供技术细节,讨论未解决的问题和我们的后续步骤。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号