• DocumentCode
    2824785
  • Title

    Policy Negotiation System Architecture for Privacy Protection

  • Author

    Jang, In Joo ; Shi, Wenbo ; Yoo, Hyeong Seon

  • Author_Institution
    Dept. of Comput. Sci., Inha Univ., Incheon
  • Volume
    2
  • fYear
    2008
  • fDate
    2-4 Sept. 2008
  • Firstpage
    592
  • Lastpage
    597
  • Abstract
    Data sharing and information exchange have grown exponentially with the information explosion in the last few years. More and more data are being shared among different type of users residing in different places, performing different kinds of tasks for different kinds of services. However, these technological advances pose a serious risk on individuals ´privacy rights. In this paper, we consider a problem of monopolistic information management technologies. Most service providers have an access to any information. Even though the information is really a personal data, service providers can access to it merely with the user´s first subscription. In order to limit the disclosure and avoid the misuse of personal data, this paper discusses an architectural proposal for a policy negotiation system. This proposed architecture mediates among the three actors: the users, the service providers and the law. The central unit of the proposed architecture is a policy negotiation engine. A negotiation engine undertakes the enforcement of user´s privacy preference, by matching the service provider´s disclosure policy and user´s privacy policy. Several additional components assigned with supporting functional tasks complement the architecture, while the formal definition of personal data type and services type. This architecture provides more powerful right to each user. Finally, this paper discusses the formalization how users can express their privacy preferences and how regulations can be expressed in this system.
  • Keywords
    data privacy; data sharing; information exchange; monopolistic information management; policy negotiation system; privacy protection; Computer architecture; Data privacy; Data security; Databases; Engines; Guidelines; Information management; Information security; Ontologies; Protection; information management; privacy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networked Computing and Advanced Information Management, 2008. NCM '08. Fourth International Conference on
  • Conference_Location
    Gyeongju
  • Print_ISBN
    978-0-7695-3322-3
  • Type

    conf

  • DOI
    10.1109/NCM.2008.244
  • Filename
    4624210