A Framework for Expressing and Enforcing Purpose-Based Privacy Policies

作者:Jafari Mohammad*; Safavi Naini Reihaneh; Fong Philip W L; Barker Ken
来源:ACM Transactions on Information and System Security, 2014, 17(1): 3.
DOI:10.1145/2629689

摘要

Purpose is a key concept in privacy policies. Although some models have been proposed for enforcing purpose-based privacy policies, little has been done in defining formal semantics for purpose, and therefore an effective enforcement mechanism for such policies has remained a challenge. We have developed a framework for expressing and enforcing such policies by giving a formal definition of purpose and proposing a modal-logic language for formally expressing purpose constraints. The semantics of this language are defined over an abstract model of workflows. Based on this formal framework, we discuss some properties of purpose, show how common forms of purpose constraints can be formalized, how purpose-based constraints can be connected to more general access control policies, and how they can be enforced in a workflow-based information system by extending common access control technologies.

  • 出版日期2014-8