Title :
A Policy Based Infrastructure for Social Data Access with Privacy Guarantees
Author :
Kodeswaran, Palanivel ; Viegas, Evelyne
Author_Institution :
Dept of CSEE, UMBC, Baltimore, MD, USA
Abstract :
We present a policy based infrastructure for social data access with the goal of enabling scientific research, while preserving privacy. We describe motivating application scenarios that could be enabled with the growing number of user datasets such as social networks, medical datasets etc. These datasets contain sensitive user information and sufficient caution must be exercised while sharing them with third parties to prevent privacy leaks. One of the goals of our framework is to allow users to control how their data is used, while at the same time enabling the aggregate data to be used for scientific research. We extend existing access control languages to explicitly model user intent in data sharing as well as supporting additional access modes that go beyond the traditional allow/deny binary semantics of access control. We describe our policy infrastructure and show how it can be used to enable the above scenarios while still guaranteeing individual privacy and present a prototype implementation of the framework extending the SecPAL authorization language to account for new roles and operations.
Keywords :
authorisation; data privacy; information retrieval; scientific information systems; social networking (online); SecPAL authorization language; access control language; aggregate data; allow/deny binary semantics; data sharing; policy based infrastructure; privacy guarantees; privacy leak; scientific research; sensitive user information; social data access; Access control; Aggregates; Data models; Data privacy; Privacy; Semantics; Social network services; Policy; Privacy; Social Networks;
Conference_Titel :
Policies for Distributed Systems and Networks (POLICY), 2010 IEEE International Symposium on
Conference_Location :
Fairfax, VA
Print_ISBN :
978-1-4244-8206-1
Electronic_ISBN :
978-0-7695-4238-6
DOI :
10.1109/POLICY.2010.25