loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Jens Leicht and Maritta Heisel

Affiliation: Paluno - The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg, Germany

Keyword(s): Access Control, Privacy Policy, P-LPL, Policy Enforcement.

Abstract: Privacy policies are used to inform end-users about the processing of their personal data by service providers on the Internet. These policies are, however, not systematically enforced. There could be discrepancies between the policy provided to the end-users and the actual access control policies applied by the service provider. We propose the Privacy Policy Based Access Control (P2BAC) system to tackle this issue. P2BAC uses computer-processable privacy policies expressed in the Prolog-Layered Privacy Language (P-LPL) to make decisions on whether some data may be accessed for a specific purpose. With P2BAC we extend the Privacy Policy Compliance Guidance (PriPoCoG) framework. Since P-LPL privacy policies can be customized by the end-user, we can consider end-users’ privacy preferences during access control. P2BAC uses query rewriting to perform the access control. The decision point is implemented in Prolog and directly operates on the P-LPL privacy policy.

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.149.250.1

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Leicht, J. and Heisel, M. (2023). P2BAC: Privacy Policy Based Access Control Using P-LPL. In Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP; ISBN 978-989-758-624-8; ISSN 2184-4356, SciTePress, pages 686-697. DOI: 10.5220/0011788500003405

@conference{icissp23,
author={Jens Leicht. and Maritta Heisel.},
title={P2BAC: Privacy Policy Based Access Control Using P-LPL},
booktitle={Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP},
year={2023},
pages={686-697},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011788500003405},
isbn={978-989-758-624-8},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP
TI - P2BAC: Privacy Policy Based Access Control Using P-LPL
SN - 978-989-758-624-8
IS - 2184-4356
AU - Leicht, J.
AU - Heisel, M.
PY - 2023
SP - 686
EP - 697
DO - 10.5220/0011788500003405
PB - SciTePress