首页> 外文OA文献 >Privacy APIs: Access Control Techniques to Analyze and Verify Legal Privacy Policies
【2h】

Privacy APIs: Access Control Techniques to Analyze and Verify Legal Privacy Policies

机译:隐私权API:用于分析和验证法律隐私权政策的访问控制技术

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

There is a growing interest in establishing rules to regulate the privacy of citizens in the treatment of sensitive personal data such as medical and financial records. Such rules must be respected by software used in these sectors. The regulatory statements are somewhat informal and must be interpreted carefully in the software interface to private data. This paper describes techniques to formalize regulatory privacy rules and how to exploit this formalization to analyze the rules automatically. Our formalism, which we call privacy APIs, is an extension of access control matrix operations to include (1) operations for notification and logging and (2) constructs that ease the mapping between legal and formal language. We validate the expressive power of privacy APIs by encoding the 2000 and 2003 HIPAA consent rules in our system. This formalization is then encoded into Promela and we validate the usefulness of the formalism by using the SPIN model checker to verify properties that distinguish the two versions of HIPAA.
机译:建立规则以规范公民在处理敏感个人数据(例如医疗和财务记录)方面的隐私的兴趣与日俱增。这些部门中使用的软件必须遵守这些规则。法规声明有些非正式,必须在软件界面中仔细解释私人数据。本文介绍了用于规范监管隐私规则的技术,以及如何利用该规范来自动分析规则。我们的形式主义(我们称为隐私API)是访问控制矩阵操作的扩展,其中包括(1)通知和日志记录操作,以及(2)简化法律和形式语言之间映射的结构。我们通过在系统中编码2000和2003 HIPAA同意规则来验证隐私API的表达能力。然后,将此形式化编码到Promela中,我们通过使用SPIN模型检查器来验证区分两个HIPAA版本的属性,从而验证形式化的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号