• DocumentCode
    2789527
  • Title

    Transforming Privacy Policies to Auditing Specifications

  • Author

    Biswas, Debmalya ; Niemi, Valtteri

  • Author_Institution
    Nokia Res., Lausanne, Switzerland
  • fYear
    2011
  • fDate
    10-12 Nov. 2011
  • Firstpage
    368
  • Lastpage
    375
  • Abstract
    With more and more personal data being collected and stored by service providers, there is an increasing need to ensure that their usage is compliant with privacy regulations. We consider the specific scenario where policies are defined in metric temporal logic and audited against the database usage logs. Previous works have shown that this can indeed be achieved in an efficient manner for a very expressive set of policies. One of the main ingredients of such an auditing process is the availability of sufficient database logs. Currently, it is a manual process to first determine the logs needed, and then come up with the necessary auditing specifications to generate them. This is not only a time consuming process but can be erroneous as well, leading to either insufficient or redundant logging. Logging in general is costly as it is an overhead on the real-time database performance, and hence redundant logging is not an alternative either. Our contribution in this work is to streamline the log generation process by deriving the auditing specifications directly from the policies to be audited. We also show how the required logging can be minimized based on the temporal constraints specified in the policies. Given privacy policies as input, the output of the proposed tool is the corresponding auditing specifications that can be installed directly in the databases, to produce logs that are both minimal and sufficient to audit the given policies. The tool has been implemented and tested in a real-life scenario.
  • Keywords
    data privacy; formal specification; system monitoring; temporal logic; auditing specification; database usage logs; log generation process; metric temporal logic; minimal logging; personal data privacy regulation; privacy policies; temporal constraints; Data privacy; Databases; Monitoring; Semantics; Servers; Synchronization; Auditing; Minimal logging; Privacy policies; Temporal first order logic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High-Assurance Systems Engineering (HASE), 2011 IEEE 13th International Symposium on
  • Conference_Location
    Boca Raton, FL
  • ISSN
    1530-2059
  • Print_ISBN
    978-1-4673-0107-7
  • Type

    conf

  • DOI
    10.1109/HASE.2011.51
  • Filename
    6113921