Enforcing P3P policies using a digital rights management system


Autoria(s): Salim, Farzad; Sheppard, Nicholas P.; Safavi-Naini, Rei
Data(s)

20/06/2007

Resumo

The protection of privacy has gained considerable attention recently. In response to this, new privacy protection systems are being introduced. SITDRM is one such system that protects private data through the enforcement of licenses provided by consumers. Prior to supplying data, data owners are expected to construct a detailed license for the potential data users. A license specifies whom, under what conditions, may have what type of access to the protected data. The specification of a license by a data owner binds the enterprise data handling to the consumer’s privacy preferences. However, licenses are very detailed, may reveal the internal structure of the enterprise and need to be kept synchronous with the enterprise privacy policy. To deal with this, we employ the Platform for Privacy Preferences Language (P3P) to communicate enterprise privacy policies to consumers and enable them to easily construct data licenses. A P3P policy is more abstract than a license, allows data owners to specify the purposes for which data are being collected and directly reflects the privacy policy of an enterprise.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/28176/

Publicador

Springer

Relação

http://eprints.qut.edu.au/28176/1/c28176a.pdf

DOI:10.1007/978-3-540-75551-7

Salim, Farzad, Sheppard, Nicholas P., & Safavi-Naini, Rei (2007) Enforcing P3P policies using a digital rights management system. In Privacy Enhancing Technologies, Springer, University of Ottawa, Ottawa, pp. 200-217.

Direitos

Copyright 2007 Springer

The original publication is available at www.springerlink.com

Fonte

Faculty of Science and Technology; Information Security Institute; School of Information Systems

Palavras-Chave #080302 Computer System Architecture #080308 Programming Languages #080303 Computer System Security #Digital Rights Management #Privacy Based Access Control #Formal Policy Language #Access Control System #MPEG REL
Tipo

Conference Paper