ACM Home Page
Please provide us with feedback. Feedback
An obligation model bridging access control policies and privacy policies
Full text PdfPdf (486 KB)
Source
Symposium on Access Control Models and Technologies archive
Proceedings of the 13th ACM symposium on Access control models and technologies table of contents
Estes Park, CO, USA
SESSION: Obligations table of contents
Pages 133-142  
Year of Publication: 2008
ISBN:978-1-60558-129-3
Authors
Qun Ni  Purdue University
Elisa Bertino  Purdue University
Jorge Lobo  IBM T.J. Watson
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 21,   Downloads (12 Months): 227,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1377836.1377857
What is a DOI?

ABSTRACT

In this paper, we present a novel obligation model for the Core Privacy-aware Role Based Access Control (P-RBAC), and discuss some design issues in detail. Pre-obligations, post-obligations, conditional obligations, and repeating obligations are supported by the obligation model. Interaction between permissions and obligations is discussed, and efficient algorithms are provided to detect undesired effects.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
M. Backes, B. Pfitzmann, and M. Schunter. A toolkit for managing enterprise privacy policies. In ESORICS, pages 162--180, 2003.
 
2
3
4
 
5
 
6
 
7
 
8
 
9
M. A. Brown. Conditional obligation and positive permission for agents in time. Nordic Journal of Philosophical Logic, 5(2):83--112, 2000.
 
10
 
11
D. J. Dougherty, K. Fisler, and S. Krishnamurthi. Obligations and their interaction with programs. In J. Biskup and J. Lopez, editors, ESORICS, volume 4734 of Lecture Notes in Computer Science, pages 375--389. Springer, 2007.
 
12
Federal Trade Commision. Children's online privacy protection act of 1998. Available at http://www.cdt.org/legislation/105th/privacy/coppa.html.
13
 
14
 
15
M. Hilty, D. A. Basin, and A. Pretschner. On obligations. In S. D. C. di Vimercati, P. F. Syverson, and D. Gollmann, editors, ESORICS, volume 3679 of Lecture Notes in Computer Science, pages 98--117. Springer, 2005.
 
16
IBM Zurich Research Laboratory,Switzerland. The enterprise privacy authorization language(epal 1.1). Available at http://www.zurich.ibm.com/security/enterprise-privacy/epal/.
17
 
18
 
19
 
20
Q. Ni, D. Lin, E. Bertino, and J. Lobo. Conditional privacy-aware role based access control. In ESORICS '07: Proceedings of the 12th European Symposium On Research In Computer Security, pages 72--89. Springer, 2007.
21
 
22
OASIS. extensible access control markup language (xacml) 2.0. Available at http://www.oasis-open.org/.
 
23
H. Prakken and M. J. Sergot. Contrary-to-duty obligations. Studia Logica, 57(1):91--115, 1996.
 
24
M. Sailer and M. Morciniec. Monitoring and execution for contract compliance. HPL-2001-261R1, HP LAB, HP. Available at http://www.hpl.hp.com/techreports/2001/HPL-2001-261R1.html.
 
25
P. Samarati, P. Y. A. Ryan, D. Gollmann, and R. Molva, editors. Computer Security - ESORICS 2004, 9th European Symposium on Research Computer Security, Sophia Antipolis, France, September 13-15, 2004, Proceedings, volume 3193 of Lecture Notes in Computer Science. Springer, 2004.
 
26
27
 
28
United State Department of Health. Health insurance portability and accountability act of 1996. Available at http://www.hhs.gov/ocr/hipaa/.
 
29
U.S. Senate Committee on Banking, Housing, and Urban Affairs. Information regarding the gramm-leach-bliley act of 1999. Available at http://banking.senate.gov/conf/.
 
30

Collaborative Colleagues:
Qun Ni: colleagues
Elisa Bertino: colleagues
Jorge Lobo: colleagues