Traceable and automatic compliance of privacy policies in federated digital identity management

被引:0
|
作者
Squicciarini, Anna [1 ]
Bhargav-Spantzel, Abhilasha [1 ]
Czeskis, Alexei [1 ]
Bertino, Elisa [1 ]
机构
[1] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
来源
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Digital identity is defined as the digital representation of the information known about a specific individual or organization. An emerging approach for protecting identities of individuals while at the same time enhancing user convenience is to focus on inter-organization management of identity information. This is referred to as federated identity management. In this paper we develop an approach to support privacy controlled sharing of identity attributes and harmonization of privacy policies in federated environments. Policy harmonizations mechanisms make it possible to determine whether or not the transfer of identity attributes from one entity to another violate the privacy policies stated by the former. We also provide mechanisms for tracing the release of user's identity attributes within the federation. Such approach entails a form of accountability since an entity non-compliant with the users original privacy preferences can be identified. Finally, a comprehensive security analysis details security properties is also offered.
引用
收藏
页码:78 / +
页数:3
相关论文
共 50 条
  • [1] Automatic compliance of privacy policies in federated digital identity management
    Squicciarini, Anna
    Mont, Marco Casassa
    Bhargav-Spantzel, Abhilasha
    Bertino, Elisa
    2008 IEEE WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2008, : 89 - +
  • [2] Privacy by Design in Federated Identity Management
    Hoerbe, Rainer
    Hoetzendorfer, Walter
    2015 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW), 2015, : 167 - 174
  • [3] Achieving Privacy in a Federated Identity Management System
    Landau, Susan
    Le Van Gong, Hubert
    Wilton, Robin
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, 2009, 5628 : 51 - 70
  • [4] TFPA: A traceable federated privacy aggregation protocol
    Xingyu Li
    Yucheng Long
    Li Hu
    Xin Tan
    Jin Li
    World Wide Web, 2023, 26 : 3275 - 3301
  • [5] User-centric privacy management for federated identity management
    Ahn, Gail-Joon
    Ko, Moonam
    2007 INTERNATIONAL CONFERENCE ON COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, 2008, : 187 - 195
  • [6] TFPA: A traceable federated privacy aggregation protocol
    Li, Xingyu
    Long, Yucheng
    Hu, Li
    Tan, Xin
    Li, Jin
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2023, 26 (5): : 3275 - 3301
  • [7] PrivacySmart: Automatic and Transparent Management of Privacy Policies
    Dauden-Esmel, Cristofol
    Castella-Roca, Jordi
    Viejo, Alexandre
    Josep Bel-Ribes, Eduard
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, PT I, 2024, 14398 : 216 - 231
  • [8] Compliance of privacy policies with legal regulations compliance of privacy policies with Canadian PIPEDA
    Zhang, Nolan
    Bodorik, Peter
    Jutla, Dawn
    ICE-B 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON E-BUSINESS, 2007, : 277 - +
  • [9] Federated Identity Management Systems: A Privacy-Based Characterization
    Birrell, Eleanor
    Schneider, Fred B.
    IEEE SECURITY & PRIVACY, 2013, 11 (05) : 36 - 48
  • [10] Digital Rights and Privacy Policies Management as a Service
    Delgado, Jaime
    Llorente, Silvia
    Rodriguez, Eva
    2012 IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE (CCNC), 2012, : 527 - 531