首页> 外文OA文献 >Credential purpose-based access control for personal data protection in web-based applications
【2h】

Credential purpose-based access control for personal data protection in web-based applications

机译:基于凭据的访问控制,用于基于Web的应用程序中的个人数据保护

摘要

Web-based applications enable users to carry out their business transactions virtually at any time and place whereby users are required to disclose almost all their personal information which result in greater risks of information disclosure. Therefore, protecting personal information is of utmost importance. Enforcing personal information protection in databases requires controlled access to systems and resources and granted only to authorized users. Traditional access control systems cannot be used in achieving full personal data protection. Current purposebased access control systems provide insufficient protection of personal data especially in web-based applications. This is mainly due to the absence of user authentication in these systems and the fact that data subjects have less control over their information. This research is an effort to overcome this problem in which the Credential Purpose-Based Access Control (CrePBAC) system is introduced. This system implements a two-phase security and an access control mechanism with a model and security policy implementation. The two-phase security model involves user authentication using personal credential and data authorization based on purpose. The organization’s security and privacy policies are implemented using metadata technique in Hippocratic Databases. The metadata technique utilizes a data labeling scheme based on purpose and control data access through query modification. The model and mechanism were successfully implemented. The results from the two types of case studies tested showed that the access control mechanism provides users with more rights and control over their data. In conclusion, this research has introduced a new approach in purpose-based access control with a two-phase security model and mechanism that provides greater control for personal data protection in web-based applications.
机译:基于Web的应用程序使用户几乎可以在任何时间和地点进行业务交易,从而要求用户公开几乎所有的个人信息,从而导致更大的信息公开风险。因此,保护​​个人信息至关重要。在数据库中实施个人信息保护需要对系统和资源的受控访问,并且仅授予授权用户。传统的访问控制系统不能用于实现全面的个人数据保护。当前基于目的的访问控制系统不能提供足够的个人数据保护,尤其是在基于Web的应用程序中。这主要是由于这些系统中没有用户认证,以及数据主体对其信息的控制较少的事实。这项研究是为克服此问题而进行的一项工作,在此问题中引入了基于凭据目的的访问控制(CrePBAC)系统。该系统通过模型和安全策略实现来实现两阶段安全和访问控制机制。两阶段安全模型涉及使用个人证书的用户身份验证和基于目的的数据授权。该组织的安全和隐私政策是使用希波克拉底数据库中的元数据技术实施的。元数据技术利用基于目的的数据标记方案,并通过查询修改来控制数据访问。该模型和机制已成功实现。两种案例研究的结果表明,访问控制机制为用户提供了更多权限并对其数据进行控制。总之,这项研究引入了一种基于目的的访问控制的新方法,该方法具有两阶段的安全模型和机制,可以为基于Web的应用程序中的个人数据保护提供更好的控制。

著录项

  • 作者

    Abdul Ghani Norjihan;

  • 作者单位
  • 年度 2013
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号