Machine-Readable Privacy Certificates for Services
نویسندگان
چکیده
Privacy-aware processing of personal data on the web of services requires managing a number of issues arising both from the technical and the legal domain. Several approaches have been proposed to matching privacy requirements (on the clients side) and privacy guarantees (on the service provider side). Still, the assurance of effective data protection (when possible) relies on substantial human effort and exposes organizations to significant (non-)compliance risks. In this paper we put forward the idea that a privacy certification scheme producing and managing machine-readable artifacts in the form of privacy certificates can play an important role towards the solution of this problem. Digital privacy certificates represent the reasons why a privacy property holds for a service and describe the privacy measures supporting it. Also, privacy certificates can be used to automatically select services whose certificates match the client policies (privacy requirements). Our proposal relies on an evolution of the conceptual model developed in the Assert4Soa project and on a certificate format specifically tailored to represent privacy properties. To validate our approach, we present a worked-out instance showing how privacy property Retention-based unlinkability can be certified for a banking financial service. ∗A revised version of this manuscript will appear in the Proceedings of the International Conference on Secure Virtual Infrastructures (DOA Trusted Cloud ’13) to be held on 9-10 September 2013, in Graz, Austria. If you wish to refer to this work, please cite [2] instead. ar X iv :1 30 7. 69 80 v1 [ cs .C R ] 2 6 Ju l 2 01 3
منابع مشابه
ASSERT4SOA: Toward Security Certification of Service-Oriented Applications
ASSERT4SOA project proposes machine readable certificates to be used to allow Web service requesters to automatically assess the security properties of Web services (and their providers) as certified by some trusted third party. This vision promises to open up an entire new market for certification services.
متن کاملTowards Pattern-Based Reliability Certification of Services
On Service-Oriented Architectures (SOAs), the mechanism for run-time discovery and selection of services may conflict with the need to make sure that business process instances satisfy their reliability requirements. In this paper we describe a certification scheme based on machine-readable reliability certificates that will enable run-time negotiation. Service reliability is afforded by means ...
متن کاملTowards a Similarity Metric for Comparing Machine-Readable Privacy Policies
Current approaches to privacy policy comparison use strict evaluation criteria (e.g. user preferences) and are unable to state how close a given policy is to fulfil these criteria. More flexible approaches for policy comparison is a prerequisite for a number of more advanced privacy services, e.g. improved privacy-enhanced search engines and automatic learning of privacy preferences. This paper...
متن کاملPreventing Security and Privacy Attacks on Machine Readable Travel Documents (MRTDs)
After the tragic terror attacks of 9/11, the U.S. Congress resolved to bring about a major overhaul of the immigration process at border posts by passing the Enhanced Border Security and Visa Entry Reform Act of 2002. Section 303(c) of that act requires that countries that participate in the US Visa Waiver Program (VWP) have a program to issue machine readable passports that are tamper resistan...
متن کاملRequirements for a Policy-Enforceable Agent Architecture
Emerging legislation that governs consumer privacy presents a design challenge to multi-agent systems providing business, health-care and government services. As agents act on behalf of consumers and providers of goods and services, their compliance with laws governing information sharing and disclosure practices must be transparent and measurable to avoid prohibitive sanctions by regulators. H...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013