Machine-Readable Privacy Certificates for Services

نویسندگان

  • Marco Anisetti
  • Claudio Agostino Ardagna
  • Michele Bezzi
  • Ernesto Damiani
  • Antonino Sabetta
چکیده

Privacy-aware processing of personal data on the web of services requires managing a number of issues arising both from the technical and the legal domain. Several approaches have been proposed to matching privacy requirements (on the clients side) and privacy guarantees (on the service provider side). Still, the assurance of effective data protection (when possible) relies on substantial human effort and exposes organizations to significant (non-)compliance risks. In this paper we put forward the idea that a privacy certification scheme producing and managing machine-readable artifacts in the form of privacy certificates can play an important role towards the solution of this problem. Digital privacy certificates represent the reasons why a privacy property holds for a service and describe the privacy measures supporting it. Also, privacy certificates can be used to automatically select services whose certificates match the client policies (privacy requirements). Our proposal relies on an evolution of the conceptual model developed in the Assert4Soa project and on a certificate format specifically tailored to represent privacy properties. To validate our approach, we present a worked-out instance showing how privacy property Retention-based unlinkability can be certified for a banking financial service. ∗A revised version of this manuscript will appear in the Proceedings of the International Conference on Secure Virtual Infrastructures (DOA Trusted Cloud ’13) to be held on 9-10 September 2013, in Graz, Austria. If you wish to refer to this work, please cite [2] instead. ar X iv :1 30 7. 69 80 v1 [ cs .C R ] 2 6 Ju l 2 01 3

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

ASSERT4SOA: Toward Security Certification of Service-Oriented Applications

ASSERT4SOA project proposes machine readable certificates to be used to allow Web service requesters to automatically assess the security properties of Web services (and their providers) as certified by some trusted third party. This vision promises to open up an entire new market for certification services.

متن کامل

Towards Pattern-Based Reliability Certification of Services

On Service-Oriented Architectures (SOAs), the mechanism for run-time discovery and selection of services may conflict with the need to make sure that business process instances satisfy their reliability requirements. In this paper we describe a certification scheme based on machine-readable reliability certificates that will enable run-time negotiation. Service reliability is afforded by means ...

متن کامل

Towards a Similarity Metric for Comparing Machine-Readable Privacy Policies

Current approaches to privacy policy comparison use strict evaluation criteria (e.g. user preferences) and are unable to state how close a given policy is to fulfil these criteria. More flexible approaches for policy comparison is a prerequisite for a number of more advanced privacy services, e.g. improved privacy-enhanced search engines and automatic learning of privacy preferences. This paper...

متن کامل

Preventing Security and Privacy Attacks on Machine Readable Travel Documents (MRTDs)

After the tragic terror attacks of 9/11, the U.S. Congress resolved to bring about a major overhaul of the immigration process at border posts by passing the Enhanced Border Security and Visa Entry Reform Act of 2002. Section 303(c) of that act requires that countries that participate in the US Visa Waiver Program (VWP) have a program to issue machine readable passports that are tamper resistan...

متن کامل

Requirements for a Policy-Enforceable Agent Architecture

Emerging legislation that governs consumer privacy presents a design challenge to multi-agent systems providing business, health-care and government services. As agents act on behalf of consumers and providers of goods and services, their compliance with laws governing information sharing and disclosure practices must be transparent and measurable to avoid prohibitive sanctions by regulators. H...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013