Traceable and automatic compliance of privacy policies in federated digital identity management

被引:0
|
作者
Squicciarini, Anna [1 ]
Bhargav-Spantzel, Abhilasha [1 ]
Czeskis, Alexei [1 ]
Bertino, Elisa [1 ]
机构
[1] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
来源
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Digital identity is defined as the digital representation of the information known about a specific individual or organization. An emerging approach for protecting identities of individuals while at the same time enhancing user convenience is to focus on inter-organization management of identity information. This is referred to as federated identity management. In this paper we develop an approach to support privacy controlled sharing of identity attributes and harmonization of privacy policies in federated environments. Policy harmonizations mechanisms make it possible to determine whether or not the transfer of identity attributes from one entity to another violate the privacy policies stated by the former. We also provide mechanisms for tracing the release of user's identity attributes within the federation. Such approach entails a form of accountability since an entity non-compliant with the users original privacy preferences can be identified. Finally, a comprehensive security analysis details security properties is also offered.
引用
收藏
页码:78 / +
页数:3
相关论文
共 50 条
  • [31] Compliance checking of privacy policies for Semantic Web Services
    Denker, G
    Nguyen, S
    Proceedings of the 8th Joint Conference on Information Sciences, Vols 1-3, 2005, : 1421 - 1424
  • [32] Longitudinal Compliance Analysis of Android Applications with Privacy Policies
    Hashmi, Saad Sajid
    Waheed, Nazar
    Tangari, Gioacchino
    Ikram, Muhammad
    Smith, Stephen
    MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES, 2022, 419 : 280 - 305
  • [33] Analysis of Privacy Compliance by Classifying Multiple Policies on the Web
    Mori, Keika
    Nagai, Tatsuya
    Takata, Yuta
    Kamizono, Masaki
    2022 IEEE 46TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2022), 2022, : 1734 - 1741
  • [34] Automatic Classification of Web and IoT Privacy Policies
    Carson, Jasmine
    DiSalvo, Lisa
    Ray, Lydia
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 732 - 735
  • [35] Automatic Assessment of Privacy Policies under the GDPR
    Sanchez, David
    Viejo, Alexandre
    Batet, Montserrat
    APPLIED SCIENCES-BASEL, 2021, 11 (04): : 1 - 11
  • [36] Lifelong Privacy: Privacy and Identity Management for Life
    Pfitzmann, Andreas
    Borcea-Pfitzmann, Katrin
    PRIVACY AND IDENTITY MANAGEMENT FOR LIFE, 2010, 320 : 1 - 17
  • [37] The Venn of identity - Options and issues in federated identity management
    Maler, Eve
    Reed, Drummond
    IEEE SECURITY & PRIVACY, 2008, 6 (02) : 16 - 23
  • [38] On Identity Assurance in the Presence of Federated Identity Management Systems
    Baldwin, Adrian
    Mont, Marco Casassa
    Beres, Yolanta
    Shiu, Simon
    DIM'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON DIGITAL IDENTITY MANAGEMENT, 2007, : 27 - 35
  • [39] Federated identity-management protocols
    Pfitzmann, B
    Waidner, M
    SECURITY PROTOCOLS, 2005, 3364 : 153 - 177
  • [40] Adding Federated Identity Management to OpenStack
    David W. Chadwick
    Kristy Siu
    Craig Lee
    Yann Fouillat
    Damien Germonville
    Journal of Grid Computing, 2014, 12 : 3 - 27