• DocumentCode
    2776953
  • Title

    Intelligent Reactive Access Control for Moving User Data

  • Author

    Wang, Yang ; Aghasaryan, Armen ; Shrihari, Arvind ; Pergament, David ; Kamga, Guy-Bertrand ; Betgè-Brezetz, Stèphane

  • Author_Institution
    Sch. of Comput. Sci., Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2011
  • fDate
    9-11 Oct. 2011
  • Firstpage
    942
  • Lastpage
    950
  • Abstract
    With the boom of social media, it has become increasingly easier for ordinary people to not only post their own content but share other people´s content on the Internet. In this paper, we conceptualize a growing problem of moving user data - once a user posts some content on the Internet, the data is largely out of her control, the content can be forwarded to or shared with other people, applications or websites, potentially causing various privacy issues. We present a technical solution that aims to provide users flexible fine-grained control over their moving data. Our system builds upon the ideas of data envelope with sticky policy, reactive access control, and privacy scores. Users can specify and enforce sticky policies of their data through our data envelope plug-ins. Our reactive access control mechanism allows users to grant access to their data on the fly, extending the pre-defined sticky policies to better fit with the dynamic nature of people´s sharing practices. Finally, the privacy score helps users make decisions about data requests by providing relevant privacy risk assessment information about the requesters.
  • Keywords
    Internet; authorisation; data privacy; Internet; Web site; data request; intelligent reactive access control; moving user data; privacy issue; privacy risk assessment; privacy score; social media; sticky policy; Access control; Data privacy; Electronic mail; Facebook; Privacy; Servers; access control; data envelope; privacy; privacy score; social media;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom), 2011 IEEE Third International Conference on
  • Conference_Location
    Boston, MA
  • Print_ISBN
    978-1-4577-1931-8
  • Type

    conf

  • DOI
    10.1109/PASSAT/SocialCom.2011.171
  • Filename
    6113244