Browse > Article
http://dx.doi.org/10.13089/JKIISC.2008.18.5.149

P-RBACML : Privacy Enhancing Role-Based Access Control Policy Language Model  

Lee, Young-Lok (Chonnam National University)
Park, Jun-Hyung (Chonnam National University)
Noh, Bong-Nam (Chonnam National University)
Park, Hae-Ryong (Korea Information Security Agency)
Chun, Kil-Su (Korea Information Security Agency)
Abstract
As individual users have to provide more information than the minimum for using information communication service, the invasion of privacy of Individual users is increasing. That is why client/server based personal information security platform technologies are being developed such as P3P, EPAL and XACML. By the way enterprises and organizations using primarily role based access control can not use these technologies. because those technologies apply access control policies to individual subjects. In this paper, we suggest an expression language for privacy enhancing role-based access control policy. Suggested privacy enhancing role-based access control policy language model is a variation of XACML which uses matching method and condition, and separately contains elements of role, purpose, and obligation. We suggest policy language model for permission assignment in this paper, shows not only privacy policy scenario with policy document instance, but also request context and response context for helping understanding.
Keywords
Privacy; RBAC; XACML;
Citations & Related Records
연도 인용수 순위
  • Reference
1 노종혁, 진승헌, "웹 환경에서 정책 기반 개인정보보호 기술," 전자통신동향분석 제22권 제4호, 8월 2007년
2 OASIS, "Core and hierarchical role based access control(RBAC) profile of XACML v2.0", February 2005
3 PRIME White Paper V2 version 1.0 27 June 2007
4 U.S. Senate Commitee On Banking, Housing, and Urban Affairs. Information regarding the gramm-leach-bliley act of 1999
5 A. Rezgui, A. Bouguettaya, and M.Y. Eltoweissy, "Privacy on the Web:Facts, Challenges, and Solutions," IEEE Security & Privacy, Vol.1, 2003
6 United State Department of Health. Health insurance portability and Accountability act of 1996
7 W3C, "The Platform for Privacy Preferences 1.1(P3P 1.1) Specification," 2006
8 OASIS, eXtensible Access Control Markup Language(XACML) Version 2.0, Committee Draft 04, 2004
9 Qun Ni, "Privacy-aware Role Based Access Control," SACMAT'07, June, 2007
10 W3C, "The Enterprise Privacy Authorization Language(EPAL 1.2)," 2002