Proceedings Article10.1109/IAS.2007.5
A Purpose-Based Access Control Model
Naikuo Yang,Howard Barringer,Ning Zhang +2 more
- 29 Aug 2007
- Vol. 1, pp 143-148
86
TL;DR: This paper presents a mechanism to specify privacy policy using VDM, the entities in the purpose-based access control model are specified, the invariants corresponding to the privacy requirements in privacy policy arespecified, and the operations in the model and their proof obligations are defined and investigated.
read more
Abstract: Achieving privacy preservation in a data-sharing computing environment is a challenging problem. The requirements for a privacy preserving data access policy should be formally specified in order to be able to establish consistency between the privacy policy and its purported implementation in practice. Previous work has shown that when specifying a privacy policy, the notion of purpose should be used as the basis for access control. A privacy policy should ensure that data can only be used for its intended purpose, and the access purpose should be compliant with the data's intended purpose. This paper presents a mechanism to specify privacy policy using VDM. The entities in the purpose-based access control model are specified, the invariants corresponding to the privacy requirements in privacy policy are specified, and the operations in the model and their proof obligations are defined and investigated.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
A privacy preserving framework for RFID based healthcare systems
TL;DR: This paper proposes a framework (PriSens-HSAC) that is the first framework to provide increased privacy in RFID based healthcare systems, using RFID authentication along with access control technique.
99
An extended attribute based access control model with trust and privacy: Application to a collaborative crisis management system
TL;DR: This paper presents an extended access control model based on attributes associated with objects and subjects that incorporates trust and privacy issues in order to make access control decisions sensitive to the cross-organizational collaboration context.
96
Patient-centric authorization framework for sharing electronic health records
Jing Jin,Gail-Joon Ahn,Hongxin Hu,Michael J. Covington,Xinwen Zhang +4 more
- 03 Jun 2009
TL;DR: A unified access control scheme is proposed that supports patient-centric selective sharing of virtual composite EHRs using different levels of granularity, accommodating data aggregation and various privacy protection requirements.
On purpose and by necessity: Compliance under the GDPR
David Basin,Søren Debois,Thomas Hildebrandt +2 more
- 26 Feb 2018
TL;DR: The European General Data Protection Regulation (GDPR) gives primacy to purpose, which begs the question: how do the authors audit a computer system’s adherence to a purpose?
87
A conditional purpose-based access control model with dynamic roles
TL;DR: According to this model, more information from data providers can be extracted while at the same time assuring privacy that maximizes the usability of consumers' data, extending traditional access control models to a further coverage of privacy preserving in data mining atmosphere.
64
References
Flexible support for multiple access control policies
TL;DR: A unified framework that can enforce multiple access control policies within a single system and be enforced by the same security server is presented, based on a language through which users can specify security policies to be enforced on specific accesses.
Related Papers (5)
Ji-Won Byun,Elisa Bertino,Ninghui Li +2 more
- 01 Jun 2005
Ji-Won Byun,Ninghui Li +1 more
- 01 Jul 2008
Amirreza Masoumzadeh,James Joshi +1 more
- 09 Nov 2008
Rakesh Agrawal,Jerry Kiernan,Ramakrishnan Srikant,Yirong Xu +3 more
- 20 Aug 2002