Title :
Subject-Wise Policy Based Access Control Mechanism for Protection of Personal Information
Author :
Mun, Hyung-Jin ; Um, Nam-Kyoung ; Sun, Ning ; Li, Yong-zhen ; Lee, Sang-ho
Author_Institution :
Chungbuk Nat. Univ., Cheongju
Abstract :
These days, personal information privacy and security is getting an important issue. In various commercial and other application cases, because of convenience and efficiency, personal information is always stored and used by organizations and companies systems. These information have different sensitivity level of privacy among each subject. Usually, the organizations and companies protect the information in a simply way, regarding all the information as the same level. For seeking a more reasonable and flexible resolvable way, in this paper, we propose a policy-based access control mechanism which strictly verifies accessing users so that to ensure the privacy and security of personal information. In our proposed mechanism, information subjects establish their own access control policy for the sensitive personal information, and the individuals´ personal information stored in the database of organizations and companies is encrypted with different keys. By this way, we can easily control the access of information users according to personal and organizational privacy policy.
Keywords :
authorisation; business data processing; cryptography; data privacy; encryption techniques; organizational privacy policy; personal information privacy; personal information protection; personal information security; subject-wise policy based access control mechanism; Access control; Communication system control; Cryptography; Data security; Databases; Information security; Information technology; Permission; Privacy; Protection;
Conference_Titel :
Convergence Information Technology, 2007. International Conference on
Conference_Location :
Gyeongju
Print_ISBN :
0-7695-3038-9
DOI :
10.1109/ICCIT.2007.398